Security defense method based on cloud service system, and cloud service system and computing device
Patent Information
- Application Number
- PCT/CN2026/084179
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-26
- Filing Date
- 2026-03-18
- Publication Date
- 2026-10-01
Smart Images

Figure CN2026084179_01102026_PF_FP_ABST
Abstract
Description
Security defense methods based on cloud service systems, cloud service systems and computing devices
[0001] This application claims priority to Chinese Patent Application No. 202510377107.6, filed on March 26, 2025, entitled "Security Defense Method, Cloud Service System and Computing Device Based on Cloud Service System", the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of cybersecurity, and more specifically, to a security defense method based on a cloud service system, a cloud service system, and a computing device. Background Technology
[0003] With the widespread use of automated web crawlers and attack tools, an increasing number of web services are falling victim to challenge collapsing (CC) attacks. CC attacks involve attackers exhausting the resources of a target website or server, such as the central processing unit (CPU), memory, and network bandwidth, by sending a large number of forged requests. Therefore, how to defend against CC attacks has become a crucial issue in the field of cybersecurity.
[0004] One defense against CC attacks is frequency limiting. This involves learning from the normal request volume over a period of time to obtain a baseline value for normal business traffic, and then using this baseline value to limit the request frequency per unit of time. If an internet protocol (IP) address or user account initiates too many requests in a short period (e.g., exceeding the baseline value), then the requests sent by that IP address or account may be considered a CC attack, resulting in blocking or access restrictions.
[0005] The aforementioned frequency limiting solutions require, on the one hand, human experts to analyze business logs, identify attack patterns, extract protection signatures, and configure protection rules. Therefore, their defense costs are high and they cannot cope with new types of attacks. On the other hand, due to social hot topics or specific customer activities causing a surge in traffic for normal business operations, the traffic for normal business operations may far exceed the baseline value. In such cases, using the baseline value for protection may result in false blocking of legitimate users, thus reducing the user experience.
[0006] Therefore, how to effectively improve the accuracy of baseline defense and avoid false blocking of normal users has become an urgent technical problem to be solved. Summary of the Invention
[0007] This application provides a security defense method, cloud service system, and computing device based on a cloud service system, which can effectively improve the accuracy of baseline defense, avoid false blocking of normal users, and thus improve the user experience.
[0008] Firstly, a security defense method based on a cloud service system is provided. The cloud service system includes infrastructure providing cloud services to users and a cloud management platform managing the infrastructure. The infrastructure includes cloud instances. The method includes: the cloud management platform receiving traffic to be identified; the cloud management platform sending the traffic to be identified to the cloud instance; the cloud instance acquiring feature information of the traffic to be identified, wherein the feature information of the traffic to be identified includes feature information of the client sending the traffic and / or a feature vector corresponding to the traffic to be identified, the feature vector being used to characterize user behavior of the traffic to be identified through at least one dimension; the cloud instance matching the feature information of the traffic to be identified with feature information of normal traffic contained in a normal traffic feature library to determine the matching degree between the traffic to be identified and the normal traffic, wherein the feature information of the normal traffic includes feature information of the normal client sending the normal traffic and / or a feature vector corresponding to the normal traffic, the feature vector being used to characterize user behavior of the normal traffic through at least one dimension; and the cloud instance intercepting the traffic to be identified if the matching degree between the traffic to be identified and the normal traffic is less than or equal to a preset matching degree.
[0009] In the above technical solution, the feature information of the traffic to be identified can be matched with the feature information of normal traffic. If the matching degree between the traffic to be identified and normal traffic is less than or equal to the preset matching degree, the traffic to be identified can be blocked. This can avoid false blocking of sudden normal traffic, thereby improving the user experience.
[0010] In conjunction with the first aspect, in some implementations of the first aspect, before the cloud management platform receives the traffic to be identified, the method further includes: the cloud management platform receiving normal traffic, the quantity of which is less than the first baseline value; the cloud management platform sending the normal traffic to the cloud instance; the cloud instance extracting feature information of the normal traffic; and the cloud instance generating a normal traffic feature library based on the feature information of the normal traffic, wherein the normal traffic feature library includes a first feature library and / or a second feature library, the first feature library including feature information of the normal client, and the second feature library including feature vectors corresponding to the normal traffic.
[0011] In the above technical solution, characteristic information of normal traffic can be extracted and saved before the traffic to be identified is acquired, so that after the traffic to be identified is acquired, the characteristic information of normal traffic can be used to determine whether the traffic to be identified is normal traffic, thereby accurately implementing corresponding handling measures for the traffic to be identified.
[0012] In conjunction with the first aspect, in some implementations of the first aspect, the normal traffic feature library includes the first feature library and the second feature library. The cloud instance matches the feature information of the client of the traffic to be identified with the feature information of the normal client contained in the first feature library to obtain a first matching result; the cloud instance matches the feature vector corresponding to the traffic to be identified with the feature vector corresponding to the normal traffic contained in the second feature library to obtain a second matching result; the cloud instance determines the matching degree between the traffic to be identified and the normal traffic based on the first matching result and the second matching result.
[0013] In conjunction with the first aspect, in some implementations of the first aspect, the cloud instance determines that the quantity of the traffic to be identified is greater than or equal to the first baseline value, and matches the feature information of the traffic to be identified with the feature information of normal traffic.
[0014] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: the cloud instance determines that the matching degree between the traffic to be identified and the normal traffic is greater than the preset matching degree, and intercepts the traffic to be identified when the origin server instance is overloaded, wherein the origin server instance is used to respond to the traffic to be identified.
[0015] In conjunction with the first aspect, in some implementations of the first aspect, the origin instance is the origin server.
[0016] In the above technical solution, if the matching degree between the traffic to be identified and the normal traffic exceeds the preset matching degree, it can be determined whether to block the traffic to be identified based on the pressure of the origin server. This can avoid the situation where the origin server is under too much pressure and the response of the origin server is slow, thereby improving the user experience.
[0017] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: the cloud instance determining that the number of traffic to be identified is less than a first baseline value, and updating the characteristic information of the normal traffic based on the characteristic information of the traffic to be identified.
[0018] In the above technical solution, if the number of traffic to be identified is less than the first baseline value, the feature information of normal traffic can be updated according to the number of traffic to be identified, so that the subsequently acquired traffic to be identified can be matched according to the updated feature information of normal traffic, thereby improving the matching accuracy.
[0019] In conjunction with the first aspect, in some implementations of the first aspect, the characteristic information of the normal client includes at least one of the following: the Internet Protocol IP address, username, user ID, and account ID of the normal client, and the at least one dimension includes at least one of the following: whether the normal traffic accesses the target Uniform Resource Locator URL, whether the request header field of the normal traffic carries a target header field, and the analysis results of the normal client's IP address in at least one security database.
[0020] Secondly, a cloud service system is provided, comprising infrastructure for providing cloud services to users and a cloud management platform for managing the infrastructure. The infrastructure includes cloud instances. The cloud management platform is used to receive traffic to be identified; the cloud management platform is also used to send the traffic to be identified to the cloud instance; the cloud instance is used to obtain feature information of the traffic to be identified, wherein the feature information of the traffic to be identified includes feature information of the client sending the traffic and / or a feature vector corresponding to the traffic to be identified, the feature vector corresponding to the traffic to be identified being used to characterize the user behavior of the traffic to be identified through at least one dimension; the cloud instance is also used to match the feature information of the traffic to be identified with the feature information of normal traffic contained in a normal traffic feature library to determine the matching degree between the traffic to be identified and the normal traffic, wherein the feature information of the normal traffic includes feature information of the normal client sending the normal traffic and / or a feature vector corresponding to the normal traffic, the feature vector corresponding to the normal traffic being used to characterize the user behavior of the normal traffic through at least one dimension; the cloud instance is also used to determine that the matching degree between the traffic to be identified and the normal traffic is less than or equal to a preset matching degree, and then intercepts the traffic to be identified.
[0021] In conjunction with the second aspect, in some implementations of the second aspect, the cloud management platform is further configured to receive normal traffic, the quantity of which is less than the first baseline value; the cloud management platform is further configured to send the normal traffic to the cloud instance; the cloud instance is further configured to extract feature information of the normal traffic; the cloud instance is further configured to generate a normal traffic feature library based on the feature information of the normal traffic, wherein the normal traffic feature library includes a first feature library and / or a second feature library, the first feature library including feature information of the normal client, and the second feature library including feature vectors corresponding to the normal traffic.
[0022] In conjunction with the second aspect, in some implementations of the second aspect, the normal traffic feature library includes the first feature library and the second feature library. The cloud instance is specifically used to: match the feature information of the client of the traffic to be identified with the feature information of the normal client contained in the first feature library to obtain a first matching result; match the feature vector corresponding to the traffic to be identified with the feature vector corresponding to the normal traffic contained in the second feature library to obtain a second matching result; and determine the matching degree between the traffic to be identified and the normal traffic based on the first matching result and the second matching result.
[0023] In conjunction with the second aspect, in some implementations of the second aspect, the cloud instance is specifically used to: determine that the number of traffic to be identified is greater than or equal to the first baseline value, and match the feature information of the traffic to be identified with the feature information of the normal traffic.
[0024] In conjunction with the second aspect, in some implementations of the second aspect, the cloud instance is also used to determine that the matching degree between the traffic to be identified and the normal traffic is greater than the preset matching degree, and to intercept the traffic to be identified when the origin server instance is overloaded, wherein the origin server instance is used to respond to the traffic to be identified.
[0025] In conjunction with the second aspect, in some implementations of the second aspect, the cloud instance is also used to determine that the number of traffic to be identified is less than the first baseline value, and to update the characteristic information of the normal traffic based on the characteristic information of the traffic to be identified.
[0026] In conjunction with the second aspect, in some implementations of the second aspect, the characteristic information of the normal client includes at least one of the following: the Internet Protocol IP address, username, user ID, and account ID of the normal client, and the at least one dimension includes at least one of the following: whether the normal traffic accesses the target Uniform Resource Locator URL, whether the request header field of the normal traffic carries a target header field, and the analysis results of the normal client's IP address in at least one security database.
[0027] It should be understood that for the beneficial effects of the second aspect and its various implementations, please refer to the first aspect and its various implementations; they will not be repeated here.
[0028] Thirdly, a security defense device based on a cloud service system is provided. This cloud service system includes infrastructure providing cloud services to users and a cloud management platform for managing the infrastructure. The infrastructure includes cloud instances, and the device is deployed within these cloud instances. The device includes: an acquisition module, a determination module, and an interception module. The acquisition module acquires feature information of the traffic to be identified, including feature information of the client sending the traffic and / or a feature vector corresponding to the traffic. The feature vector represents the user behavior of the traffic through at least one dimension. The determination module matches the feature information of the traffic to be identified with feature information of normal traffic contained in a normal traffic feature library to determine the matching degree between the traffic to be identified and the normal traffic. The feature information of the normal traffic includes feature information of the normal client sending the normal traffic and / or a feature vector corresponding to the normal traffic. The feature vector represents the user behavior of the normal traffic through at least one dimension. The interception module determines that the matching degree between the traffic to be identified and the normal traffic is less than or equal to a preset matching degree, and then intercepts the traffic to be identified.
[0029] In conjunction with the third aspect, in some implementations of the third aspect, the device further includes: an extraction module and a generation module, wherein the extraction module is used to extract feature information of the normal traffic; the generation module is used to generate a normal traffic feature library based on the feature information of the normal traffic, wherein the normal traffic feature library includes a first feature library and / or a second feature library, the first feature library includes feature information of the normal client, and the second feature library includes feature vectors corresponding to the normal traffic.
[0030] In conjunction with the third aspect, in some implementations of the third aspect, the normal traffic feature library includes the first feature library and the second feature library. The determining module is specifically used to: match the feature information of the client of the traffic to be identified with the feature information of the normal client contained in the first feature library to obtain a first matching result; match the feature vector corresponding to the traffic to be identified with the feature vector corresponding to the normal traffic contained in the second feature library to obtain a second matching result; and determine the matching degree between the traffic to be identified and the normal traffic based on the first matching result and the second matching result.
[0031] In conjunction with the third aspect, in some implementations of the third aspect, the determining module is specifically used to: determine that the number of traffic to be identified is greater than or equal to the first baseline value, match the feature information of the traffic to be identified with the feature information of the normal traffic, and determine the matching degree between the traffic to be identified and the normal traffic.
[0032] In conjunction with the third aspect, in some implementations of the third aspect, the interception module is also used to determine that the matching degree between the traffic to be identified and the normal traffic is greater than the preset matching degree, and to intercept the traffic to be identified when the origin server instance is overloaded, wherein the origin server instance is used to respond to the traffic to be identified.
[0033] In conjunction with the third aspect, in some implementations of the third aspect, the device further includes: an update module, configured to determine that the number of traffic to be identified is less than a first baseline value, and update the characteristic information of the normal traffic based on the characteristic information of the traffic to be identified.
[0034] In conjunction with the third aspect, in some implementations of the third aspect, the characteristic information of the normal client includes at least one of the following: the Internet Protocol IP address, username, user ID, and account ID of the normal client, and the at least one dimension includes at least one of the following: whether the normal traffic accesses the target Uniform Resource Locator URL, whether the request header field of the normal traffic carries a target header field, and the analysis results of the normal client's IP address in at least one security database.
[0035] It should be understood that for the beneficial effects of the third aspect and its various implementations, please refer to the first aspect and its various implementations; they will not be repeated here.
[0036] Fourthly, a computing device is provided, including a processor and a memory, and optionally, an input / output interface. The processor controls the input / output interface to send and receive information, the memory stores a computer program, and the processor retrieves and runs the computer program from the memory, causing the computing device to execute the methods of the first aspect or any possible implementation thereof.
[0037] Optionally, the processor can be a general-purpose processor, which can be implemented in hardware or software. When implemented in hardware, the processor can be a logic circuit, integrated circuit, etc.; when implemented in software, the processor can be a general-purpose processor that reads software code stored in memory. This memory can be integrated into the processor or located outside the processor and exist independently.
[0038] Fifthly, a computing device cluster is provided, including at least one computing device, each computing device including a processor and a memory; the processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, such that the computing device cluster performs the method of the first aspect or any possible implementation thereof.
[0039] In a sixth aspect, a chip is provided that acquires and executes instructions to implement the methods in the first aspect and any implementation thereof.
[0040] Optionally, as one implementation, the chip includes a processor and a data interface, through which the processor reads instructions stored in the memory and executes the methods in the first aspect and any implementation thereof.
[0041] Optionally, as one implementation, the chip may further include a memory storing instructions, and the processor is used to execute the instructions stored in the memory. When the instructions are executed, the processor is used to perform the method in the first aspect and any implementation thereof.
[0042] In a seventh aspect, a computer program product containing instructions is provided, which, when executed by a computing device, cause the computing device to perform the methods described in the first aspect and any implementation thereof.
[0043] Eighthly, a computer program product containing instructions is provided, which, when run by a cluster of computing devices, causes the cluster of computing devices to perform the methods described in the first aspect and any implementation thereof.
[0044] A ninth aspect provides a computer-readable storage medium including computer program instructions that, when executed by a computing device, perform the method as described in the first aspect and any implementation thereof.
[0045] As examples, these computer-readable storage devices include, but are not limited to, one or more of the following: read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), flash memory, electrically EPROM (EEPROM), and hard drive.
[0046] Alternatively, as one implementation method, the aforementioned storage medium can specifically be a non-volatile storage medium.
[0047] In a tenth aspect, a computer-readable storage medium is provided, including computer program instructions that, when executed by a cluster of computing devices, perform the method as described in the first aspect and any implementation thereof.
[0048] As examples, these computer-readable storage devices include, but are not limited to, one or more of the following: read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), flash memory, electrically EPROM (EEPROM), and hard drive.
[0049] Alternatively, as one implementation method, the aforementioned storage medium can specifically be a non-volatile storage medium. Attached Figure Description
[0050] Figure 1 is a schematic block diagram of a cloud service system applicable to an embodiment of this application.
[0051] Figure 2 is a schematic block diagram of a security defense system applicable to an embodiment of this application.
[0052] Figure 3 is a schematic flowchart of a method for creating a normal traffic feature database based on a cloud service system, provided in an embodiment of this application.
[0053] Figure 4 is a schematic flowchart of a security defense method based on a cloud service system provided in an embodiment of this application.
[0054] Figure 5 is a logic block diagram of a security defense system provided in an embodiment of this application.
[0055] Figure 6 is a schematic block diagram of a security defense device 600 based on a cloud service system provided in an embodiment of this application.
[0056] Figure 7 is a schematic diagram of another cloud service system provided in one embodiment of this application.
[0057] Figure 8 is a schematic diagram of the architecture of a computing device 1500 provided in an embodiment of this application.
[0058] Figure 9 is a schematic diagram of the architecture of a computing device cluster provided in an embodiment of this application.
[0059] Figure 10 is a schematic diagram of the connection between computing devices 1500A and 1500B via a network according to an embodiment of this application. Detailed Implementation
[0060] The technical solutions in this application will now be described with reference to the accompanying drawings.
[0061] This application will present various aspects, embodiments, or features relating to systems comprising multiple devices, components, modules, etc. It should be understood and appreciated that individual systems may include additional devices, components, modules, etc., and / or may not include all devices, components, modules, etc. discussed in conjunction with the accompanying drawings. Furthermore, combinations of these approaches are also possible.
[0062] Furthermore, in the embodiments of this application, the words "exemplary," "for example," etc., are used to indicate that they are examples, illustrations, or descriptions. Any embodiment or design scheme described as "exemplary" in this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the term "exemplary" is intended to present the concept in a concrete manner.
[0063] In the embodiments of this application, "corresponding" and "corresponding" can sometimes be used interchangeably. It should be noted that when the distinction is not emphasized, their intended meanings are consistent.
[0064] The business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0065] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.
[0066] In this application, "at least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A alone, A and B simultaneously, and B alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple.
[0067] For ease of description, the relevant concepts involved in the embodiments of this application will be explained below.
[0068] 1. Web crawler
[0069] Web crawlers, also known as web spiders or web robots, are programs that retrieve information from the internet according to certain rules. The basic principle of web crawlers is based on website protocols, using URLs to retrieve information from web pages in batches. Simply put, it's using computer programs to simulate the process of manually clicking on web pages to obtain data.
[0070] Web crawlers can be broadly categorized into two types: general-purpose crawlers and focused crawlers. General-purpose crawlers crawl as many websites as possible while maintaining a certain level of content quality. Their main purpose is to download web pages from the internet to a local machine, creating a mirror backup of internet content. Focused crawlers, also known as topic-based web crawlers, are crawlers designed for specific topics. Their goal is to crawl a smaller number of websites while maintaining accurate content quality. Focused crawlers include link and content evaluation modules, allowing users to evaluate page content.
[0071] Typically, the purpose of web crawlers is to obtain information from websites, such as articles, search results, and product details. Once they have this information, the crawler designers can maintain their own websites or profit from it.
[0072] 2. Challenge Collapsar (CC) Attack
[0073] With the widespread use of automated web crawlers and attack tools, an increasing number of web services are falling victim to CC attacks. A CC attack refers to an attacker exhausting the resources of a target website or server, such as CPU, memory, and network bandwidth, by sending a large number of forged requests.
[0074] CC attacks often target network entities that provide important services, have a large number of users, or process sensitive information, such as e-commerce websites, news portals, and social media platforms—websites with high traffic and many users; application programming interfaces (APIs) endpoints that provide external services, especially those that process complex or sensitive data; and website login pages and various submission forms, which are often the focus of CC attacks because they require user authentication or data processing.
[0075] The main impacts of CC attacks on target websites or services include:
[0076] 1) Service interruption: CC attacks may overload the target website or application server, making it unable to handle legitimate user requests, thus rendering the service partially or completely unavailable.
[0077] 2) Performance degradation: Even if the website or service does not completely crash, an attack may cause a significant performance degradation, such as longer loading times and slow response times.
[0078] 3) Impaired user experience: Service interruption or performance degradation severely impacts user experience, potentially leading to user dissatisfaction and churn.
[0079] 4) Economic losses: For commercial websites, service interruption means direct economic losses, including lost sales revenue and potential compensation costs.
[0080] 5) Damage to brand image: Prolonged service interruptions or frequent attacks can damage the brand image and market reputation of a company or organization.
[0081] Therefore, how to defend against CC attacks has become an important issue in the field of cybersecurity.
[0082] One defense against CC attacks is frequency limiting. This involves learning from the normal request volume over a period of time to obtain a baseline value for normal business traffic, and then using this baseline value to limit the request frequency per unit of time. If an internet protocol (IP) address or user account initiates too many requests in a short period (e.g., exceeding the baseline value), then the requests sent by that IP address or account may be considered a CC attack, resulting in blocking or access restrictions.
[0083] The aforementioned frequency limiting solutions require, on the one hand, human experts to analyze business logs, identify attack patterns, extract protection signatures, and configure protection rules. Therefore, their defense costs are high and they cannot cope with new types of attacks. On the other hand, due to social hot topics or specific customer activities causing a surge in traffic for normal business operations, the traffic for normal business operations may far exceed the baseline value. In such cases, using the baseline value for protection may result in false blocking of legitimate users, thus reducing the user experience.
[0084] In view of this, the embodiments of this application provide a security defense method based on a cloud service system, which can effectively improve the accuracy of baseline defense, avoid false blocking of normal users, and thus improve the user experience.
[0085] In one possible implementation, the method provided in this application embodiment can be applied to a cloud service system. For ease of description, the cloud service system will be described in detail below with reference to Figure 1.
[0086] Figure 1 is a schematic block diagram of a cloud service system applicable to an embodiment of this application. As shown in Figure 1, the cloud service system may include: a cloud management platform 110, an Internet 120, and a client 130.
[0087] As shown in Figure 1, the cloud management platform 110 is used to manage the infrastructure that provides multiple cloud services, including cloud instances. For example, the infrastructure includes multiple cloud data centers, each cloud data center includes multiple servers, and each server includes cloud service resources to provide corresponding cloud services to tenants.
[0088] The cloud management platform 110 can be located in a cloud data center and provides access interfaces (such as user interfaces or application program interfaces, APIs). Tenants can use client 130 to remotely access the cloud management platform 110, register a cloud account and password, and log in. After successful authentication of the cloud account and password, the tenant can further select and purchase virtual machines of specific specifications (processor, memory, disk) on the cloud management platform 110. After successful purchase, the cloud management platform 110 provides the remote login account and password for the purchased virtual machine, allowing client 130 to remotely log in and install and run the tenant's applications. Therefore, tenants can create, manage, log in to, and operate virtual machines in the cloud data center through the cloud management platform 110. Virtual machines can also be referred to as Elastic Compute Service (ECS) or Elastic Instances (different cloud service providers may use different names).
[0089] It should be understood that cloud service tenants can be individuals, businesses, schools, hospitals, government agencies, etc.
[0090] The cloud management platform 110 includes, but is not limited to, a user console, compute management services, network management services, storage management services, authentication services, and image management services. The user console provides an interface or API for interaction with tenants. The compute management services manage servers running virtual machines and containers, as well as bare metal servers. The network management services manage network services (such as gateways and firewalls). The storage management services manage storage services (such as data bucket services). The authentication services manage tenant account passwords. The image management services manage virtual machine images. Tenants can log in to the cloud management platform 110 via client 130 and the internet 120 to manage their rented cloud services.
[0091] For ease of description, the security defense system applicable to the embodiments of this application will be described in detail below.
[0092] Figure 2 is a schematic block diagram of a security defense system applicable to an embodiment of this application. As shown in Figure 2, the security defense system may include a client, a proxy, and an origin server, wherein the client communicates with the origin server through the proxy.
[0093] The aforementioned clients may include, but are not limited to: browsers, mobile applications based on Hypertext Markup Language 5 (HTML5 APP), mini-programs, etc.
[0094] For example, the client described above can be deployed on an edge device, which may include, but is not limited to: desktop computer, portable computer (e.g., laptop, tablet), cellular phone (e.g., smartphone), personal digital assistant (PDA), etc.
[0095] The aforementioned proxy clients may include, but are not limited to: Web application firewall (WAF) engines, Nginx, Openresty, etc.
[0096] For example, taking the cloud service system shown in Figure 1 as an example, the aforementioned agent can be deployed in the infrastructure that provides cloud services to users. For instance, the agent is deployed in a cloud instance, which is deployed on a server in the cloud data center of the infrastructure.
[0097] The aforementioned origin server may include, but is not limited to: Tomcat, hypertext preprocessor (PHP), etc.
[0098] For example, taking the cloud service system shown in Figure 1 as an example, the aforementioned origin server can be deployed on the infrastructure that provides cloud services to users. For instance, the origin server is located in the cloud data center of that infrastructure.
[0099] It should be understood that the aforementioned source server and the cloud instance with the agent deployed can be a server in a cloud data center, or they can be different servers. This application embodiment does not make any specific limitation.
[0100] The aforementioned different servers may be located in the same cloud data center of the infrastructure, or they may be located in different cloud data centers of the infrastructure. This application embodiment does not specifically limit this.
[0101] Referring to Figure 2, the proxy is responsible for receiving requests from clients and forwarding them to the origin server. Upon receiving the client's request, the origin server retrieves the resource corresponding to the request and forwards it to the client as a response through the proxy.
[0102] The following describes in detail, using the system shown in Figure 2 as an example and in conjunction with Figure 3, a method for creating a normal traffic feature database based on a cloud service system provided by an embodiment of this application. It should be understood that the example in Figure 3 is merely to help those skilled in the art understand the embodiments of this application, and is not intended to limit the embodiments to the specific values or scenarios illustrated in Figure 3. Those skilled in the art can obviously make various equivalent modifications or variations based on the examples given below in Figure 3, and such modifications and variations also fall within the scope of the embodiments of this application.
[0103] Figure 3 is a schematic flowchart of a method for creating a normal traffic feature database based on a cloud service system, according to an embodiment of this application. As shown in Figure 3, the method may include steps 310-340, which will be described in detail below.
[0104] Step 310: The cloud management platform receives normal traffic.
[0105] In this embodiment of the application, the cloud management platform can receive normal traffic, for example, the cloud management platform receives normal traffic over a period of time.
[0106] For example, as shown in Figure 5, the cloud management platform can receive normal traffic through the protected entry point.
[0107] In one possible implementation, the cloud management platform can employ a baseline protection scheme to receive normal traffic over a period of time. For example, the cloud management platform can determine the user traffic received within that period based on a first baseline value, classifying traffic whose quantity does not exceed (i.e., is less than) the first baseline value as normal traffic.
[0108] For example, as shown in Figure 5, the first baseline value mentioned above can be determined by the baseline learning module based on the amount of normal traffic received over a past period. For instance, the baseline value of normal traffic for the service can be obtained by learning from the amount of normal traffic received over a past period.
[0109] For example, the aforementioned past period can be divided into different time windows, and the normal traffic acquired within each time window can be counted and statistically analyzed to obtain the traffic baseline value for each time window. Then, based on the weight value of each time window, the traffic baseline values of each time window are weighted and averaged to obtain the first baseline value.
[0110] It should be understood that in each of the above time windows, the closer the time, the greater its corresponding weight value.
[0111] Step 320: The cloud management platform sends normal traffic to the cloud instance.
[0112] In this embodiment of the application, after receiving normal traffic, the cloud management platform can send the normal traffic to cloud instances in the infrastructure managed by the cloud management platform.
[0113] It should be understood that the aforementioned cloud instance is a computing instance deployed in a server in a cloud data center, and the aforementioned agent runs in this computing instance.
[0114] Step 330: Extract characteristic information of normal traffic from cloud instances.
[0115] In this embodiment of the application, after the cloud instance obtains normal traffic, it can analyze the characteristics of the normal traffic and extract the characteristic information of the normal traffic.
[0116] For example, as shown in Figure 5, the feature analysis module can analyze the characteristics of the normal traffic and extract the feature information of the normal traffic.
[0117] For example, the characteristic information of the normal traffic mentioned above may include at least one of the following: characteristic information of the normal client sending the normal traffic, and the characteristic vector corresponding to the normal traffic.
[0118] For example, the characteristic information of a normal client sending normal traffic includes at least one of the following: the Internet Protocol (IP) address of the normal client, the username, user ID, account ID, etc. contained in the normal client's cookie.
[0119] For example, the feature vector corresponding to the normal traffic mentioned above is used to characterize the user behavior of normal traffic through at least one dimension. This at least one dimension may include, but is not limited to: whether the user accessed certain Uniform Resource Locators (URLs), whether the user's request header fields carried a certain header field, and the analysis results of the user's client source IP in various security databases, etc.
[0120] For example, consider a 400-bit feature vector corresponding to normal traffic. Bits 1 to 200 of this feature vector indicate whether a normal user visited certain URLs (e.g., Login.html, home.html, etc.) within a day; bits 201 to 300 indicate whether the header fields of the requests sent by the normal user contained a certain header field; and bits 301 to 400 indicate the analysis results of the source IP of the client used by the normal user in various security databases (e.g., the analysis result shows that the source IP of the client is the IP of a certain data center).
[0121] Optionally, in some embodiments, since different services have different characteristics, in order to achieve better protection, different tenants can customize the number of at least one dimension in the feature vector, the length of each dimension in the at least one dimension, and the meaning of each dimension according to different service scenarios.
[0122] Step 340: The cloud instance generates a normal traffic feature database based on the characteristic information of normal traffic.
[0123] In this embodiment of the application, after extracting the feature information of normal traffic, the cloud instance can generate a normal traffic feature library based on the feature information of normal traffic.
[0124] For example, as shown in Figure 5, the feature analysis module can analyze the characteristics of the normal traffic, extract the feature information of the normal traffic, and send the feature information of the normal traffic to the normal traffic feature library management module, which is responsible for generating the normal traffic feature library.
[0125] For example, taking the characteristic information of normal traffic as including the characteristic information of normal clients sending normal traffic as an example, the above-mentioned normal traffic characteristic library includes a first characteristic library, which includes the characteristic information of normal clients.
[0126] For example, taking the feature information of normal traffic as including the feature vector corresponding to the normal traffic as an example, the above-mentioned normal traffic feature library includes a second feature library, which includes the feature vector corresponding to the normal traffic.
[0127] For example, taking the characteristic information of normal traffic, which includes the characteristic information of the normal client sending normal traffic and the feature vector corresponding to normal traffic, as an example, the above-mentioned normal traffic feature library includes the first feature library and the second feature library.
[0128] The following section describes in detail the specific implementation of generating the first feature library based on the characteristic information of normal clients sending normal traffic.
[0129] For example, assuming that the feature information of a normal client includes n dimensions of feature information of a normal client, the first feature library mentioned above can include n feature sub-libraries, where each sub-feature library contains feature information of one dimension of a normal client.
[0130] It should be understood that n is a positive integer greater than or equal to 1.
[0131] Example 1: Taking the characteristic information of a normal client, which includes the source IP address of the normal client, as an example, the source IP address of a client that has been sending normal traffic for a long period of time can be added to one of the n characteristic sub-databases.
[0132] Example 2: Taking the characteristic information of a normal client, which includes the username of the normal client, as an example, the username of a client that has been sending normal traffic for a long period of time can be added to another feature sub-library in the n feature sub-libraries.
[0133] Example 3: Taking the characteristic information of a normal client, which includes the user ID of the normal client, as an example, the user ID of a client that has been sending normal traffic for a long period of time can be added to another feature sub-database in the n feature sub-databases.
[0134] Example 4: Taking the characteristic information of a normal client, which includes the account ID of the normal client, as an example, the account ID of a client that has been sending normal traffic for a long period of time can be added to another characteristic sub-database in the n characteristic sub-databases.
[0135] Optionally, in some embodiments, in order to achieve better protection, tenants can also customize the weights corresponding to each of the above n feature sub-libraries.
[0136] The following section describes in detail the specific implementation method for generating the second feature library based on the feature vectors corresponding to normal traffic.
[0137] For example, suppose a cloud instance receives m normal traffic flows. The cloud instance can generate feature vectors corresponding to each of the m normal traffic flows based on at least one dimension of the user behavior mentioned above, and store the generated m feature vectors in a second feature library.
[0138] In the above technical solution, the characteristic information of normal traffic can be learned and extracted, and a normal user characteristic database can be generated based on the characteristic information of normal traffic. This allows for the determination of whether sudden traffic is abnormal based on the normal user characteristic database, and the execution of corresponding handling measures based on the determination result. This can avoid the false blocking of sudden normal traffic, thereby improving the user experience.
[0139] The following description, with reference to Figure 4, details a security defense method based on a cloud service system provided in this application. It should be understood that the examples in Figure 4 are merely to help those skilled in the art understand the embodiments of this application, and are not intended to limit the embodiments to the specific values or scenarios illustrated in Figure 4. Those skilled in the art can obviously make various equivalent modifications or variations based on the examples given in Figure 4, and such modifications and variations also fall within the scope of the embodiments of this application.
[0140] Figure 4 is a schematic flowchart of a security defense method based on a cloud service system provided in an embodiment of this application. As shown in Figure 4, the method may include steps 410-450, which will be described in detail below.
[0141] Step 410: The cloud management platform receives the traffic to be identified.
[0142] In this embodiment of the application, the cloud management platform can receive traffic to be identified from the client.
[0143] For example, as shown in Figure 5, the cloud management platform can receive traffic to be identified from the client through the protection portal.
[0144] The traffic to be identified can be a request sent by a user. For example, the request could be a GET request sent by the user.
[0145] Step 420: The cloud management platform sends the traffic to be identified to the cloud instance.
[0146] In this embodiment of the application, after receiving the traffic to be identified, the cloud management platform can send the traffic to be identified to cloud instances in the infrastructure managed by the cloud management platform.
[0147] Step 430: The cloud instance obtains the feature information of the traffic to be identified.
[0148] In this embodiment, after receiving traffic to be identified from the cloud management platform, the cloud instance can obtain the feature information of the traffic to be identified. The feature information of the traffic to be identified includes the feature information of the client sending the traffic and / or the feature vector corresponding to the traffic. The feature vector corresponding to the traffic to be identified is used to characterize the user behavior of the traffic to be identified through at least one of the aforementioned dimensions.
[0149] For example, as shown in Figure 5, cloud instances can obtain the characteristic information of the traffic to be identified through the burst traffic analysis module.
[0150] For example, taking the normal traffic feature library as an example, the feature information of the traffic to be identified obtained by this cloud instance includes the feature information of the client that sent the traffic to be identified.
[0151] Another example, taking the normal traffic feature library as an example, the feature information of the traffic to be identified obtained by the cloud instance includes the feature vector corresponding to the traffic to be identified.
[0152] Another example, taking the normal traffic feature library as an example, which includes a first feature library and a second feature library, the feature information of the traffic to be identified obtained by this cloud instance includes the feature information of the client that sent the traffic to be identified and the feature vector corresponding to the traffic to be identified.
[0153] In some embodiments, the cloud instance may also obtain the characteristic information of the traffic to be identified if the number of traffic to be identified is greater than or equal to the first baseline value mentioned above.
[0154] For example, as shown in Figure 5, the cloud instance can use the baseline protection module to determine whether the number of traffic to be identified is greater than or equal to the first baseline value. If the baseline protection module determines that the number of traffic to be identified is greater than or equal to the first baseline value, the burst traffic analysis module then obtains the characteristic information of the traffic to be identified.
[0155] It should be understood that if the amount of traffic to be identified is greater than or equal to the first baseline value, the traffic to be identified can be referred to as burst traffic.
[0156] Optionally, in some embodiments, as shown in Figure 5, if the baseline protection module determines that the number of traffic to be identified is less than the first baseline value, the baseline protection module can identify the traffic to be identified as normal traffic and send the normal traffic to the baseline learning module. The baseline learning module can count and calculate the number of received normal traffic to obtain a new baseline value (e.g., a second baseline value), and the subsequent baseline learning module will perform baseline defense based on this new baseline value (e.g., the second baseline value).
[0157] Optionally, in some embodiments, as shown in Figure 5, if the baseline protection module determines the traffic to be identified as normal traffic, it can also send the feature information of the normal traffic to the normal traffic feature database management module. The normal traffic feature database management module can update the feature information of normal traffic contained in the normal traffic feature database based on the feature information of normal traffic sent by the feature analysis module.
[0158] Step 440: The cloud instance matches the feature information of the traffic to be identified with the feature information of normal traffic contained in the normal traffic feature library to determine the matching degree between the traffic to be identified and normal traffic.
[0159] In this embodiment of the application, the cloud instance can match the feature information of the traffic to be identified with the feature information of normal traffic contained in the normal traffic feature database to determine the matching degree between the traffic to be identified and normal traffic.
[0160] For example, as shown in Figure 5, the cloud instance can use the normal traffic feature library management module to match the feature information of the traffic to be identified with the feature information of normal traffic contained in the normal traffic feature library to determine the degree of matching between the traffic to be identified and normal traffic.
[0161] In some embodiments, the cloud instance may also match the feature information of the traffic to be identified with the feature information of normal traffic to determine the degree of matching between the traffic to be identified and normal traffic if the number of traffic to be identified is greater than or equal to the first baseline value mentioned above.
[0162] For example, as shown in Figure 5, if the baseline protection module determines that the number of traffic to be identified is greater than or equal to the first baseline value, the normal traffic feature library management module will then match the feature information of the traffic to be identified with the feature information of the normal traffic contained in the normal traffic feature library to determine the matching degree between the traffic to be identified and the normal traffic.
[0163] The following section describes in detail the specific implementation method for determining the matching degree between the traffic to be identified and normal traffic.
[0164] Implementation method 1 involves a first feature library included in the normal user feature library, which contains n feature sub-libraries (e.g., P1-P2). nA feature sub-library, P1-P n Taking a feature sub-library (containing n dimensions of feature information from a normal client) as an example, a cloud instance can extract n dimensions of feature information from the client sending the traffic to be identified, and then compare the n dimensions of feature information from the client sending the traffic to be identified with P1-P... n Each feature sub-database contains n dimensions of feature information of normal clients, which are matched one-to-one to obtain the n dimensions of feature information of the client sending the traffic to be identified, and respectively matched with P1-P n The matching results of each feature sub-library, and based on P1-P n The weights of each feature sub-library and the traffic to be identified relative to P1-P n The first matching result is determined by the matching results of each feature sub-library.
[0165] For example, the flow rate to be identified and P1-P can be determined according to formula (1). n The first matching result of each feature sub-library. R1 = ∑ (1,n) (a i *f p (T Pi ,P i )) (1)
[0166] Where R1 represents the traffic to be identified and P1-P n The first matching result of the feature sub-library;
[0167] P i Represents P1-P n The i-th feature sub-library in the feature sub-library, where the value of i ranges from (1 to n);
[0168] T Pi This represents the feature information of the i-th dimension of the traffic to be identified;
[0169] f p (T Pi ,P i ) represents the matching result between the feature information of the i-th dimension of the traffic to be identified and the feature information of the i-th dimension of normal users contained in the i-th feature sub-library. If they match, return 1; otherwise, return 0.
[0170] a i Represents P1-P n The weight corresponding to the i-th feature sub-database in the feature sub-database.
[0171] Implementation method 2, taking the normal user feature library including a second feature library, which contains m feature vectors corresponding to m normal traffic flows as an example, allows the cloud instance to extract the feature vector of the traffic to be identified according to the tenant-defined dimensions, and then match the feature vector of the traffic to be identified with the m feature vectors included in the second feature library to determine the second matching result.
[0172] For example, the distance between the feature vector corresponding to the traffic to be identified and the m feature vectors included in the second feature library can be calculated separately, and the minimum distance can be taken as the second matching result.
[0173] It should be understood that, in this embodiment of the application, the distances obtained by the above calculations need to be normalized to floating-point numbers of 0 to 1. The closer the distance, the larger the value of the second matching result.
[0174] The embodiments of this application do not specifically limit the algorithm for calculating the distance between feature vectors. The algorithm may include, but is not limited to, Euclidean distance algorithm, cosine distance algorithm, etc.
[0175] For example, the second matching result between the traffic to be identified and the second feature library can be determined according to formula (2). R2 = f q (T Q ,Q) (2)
[0176] Wherein, R2 represents the second matching result between the traffic to be identified and the second feature library;
[0177] Q represents the second feature library;
[0178] T Q This represents the feature vector corresponding to the traffic to be identified;
[0179] f q (T Q Q) represents the minimum distance between the feature vector corresponding to the traffic to be identified and the m feature vectors contained in the second feature library.
[0180] Implementation method 3, taking the normal user feature database as an example including the first feature database and the second feature database, the cloud instance can determine the third matching result based on the first matching result and the second matching result.
[0181] For example, the third matching result between the traffic to be identified and the normal user feature database can be determined according to formula (3). R3=∑ (1,n) (a i *f p (T Pi ,P i ))*f q (T Q,Q) (3)
[0182] R3 represents the third matching result between the traffic to be identified and the first and second feature libraries.
[0183] Step 450: The cloud instance determines that the matching degree between the traffic to be identified and normal traffic is less than or equal to the preset matching degree, and then blocks the traffic to be identified.
[0184] In this embodiment of the application, the cloud instance intercepts the traffic to be identified when the matching degree between the traffic to be identified and normal traffic is less than or equal to a preset matching degree.
[0185] The aforementioned matching degree can be the first matching result, or the second matching result, or the third matching result; this application embodiment does not specifically limit this.
[0186] In some embodiments, if the matching degree between the traffic to be identified and normal traffic is greater than a preset matching degree, the cloud instance can identify the traffic to be identified as normal traffic and determine whether to block the normal traffic based on the pressure of the origin server.
[0187] For example, if the origin server is not overloaded, there is no need to block the normal traffic; it is sufficient to monitor the origin server's load in a timely manner.
[0188] For example, if the source server is detected to be overloaded, then normal traffic needs to be blocked.
[0189] For example, a cloud instance can determine the pressure on the origin server based on its ability to process query requests per unit time (e.g., queries per second (QPS)), or it can determine the pressure on the origin server based on the number of response codes sent by the origin server. This application embodiment does not specifically limit this.
[0190] Optionally, in some embodiments, since different services have different characteristics, in order to achieve better protection, different tenants can configure the following parameters according to different service scenarios.
[0191] 1)R min : Preset matching degree;
[0192] 2)Q i The meaning of each dimension representing user behavior contained in the second feature library;
[0193] 3)a i P1-P n The weight corresponding to the i-th feature sub-database in the feature sub-database.
[0194] It should be understood that when a tenant configures, i You can fill in any integer; the cloud instance will handle 'a'. i Normalization is performed so that: ∑ (1,n) a i =1.
[0195] In the above technical solution, the feature information of the traffic to be identified can be matched with the feature information of normal traffic. If the matching degree between the traffic to be identified and normal traffic is less than or equal to the preset matching degree, the traffic to be identified can be blocked. This can avoid false blocking of sudden normal traffic, thereby improving the user experience.
[0196] The methods provided by the embodiments of this application have been described in detail above with reference to Figures 1 to 5. The embodiments of the apparatus of this application will be described in detail below with reference to Figures 6 to 10. It should be understood that the descriptions of the method embodiments correspond to the descriptions of the apparatus embodiments; therefore, any parts not described in detail can be referred to the preceding method embodiments.
[0197] Figure 6 is a schematic block diagram of a security defense device 600 based on a cloud service system provided in an embodiment of this application. The cloud service system includes infrastructure providing cloud services to users and a cloud management platform for managing the infrastructure. The infrastructure includes cloud instances, and the device 600 is deployed within these cloud instances. The device 600 can be implemented through software, hardware, or a combination of both. The device 600 provided in this embodiment of the application can implement the method flow shown in Figure 3 or Figure 4 of this embodiment of the application.
[0198] For example, the device 600 includes: an acquisition module 610, a determination module 620, and an interception module 630. The acquisition module 610 is used to acquire feature information of the traffic to be identified, wherein the feature information of the traffic to be identified includes feature information of the client sending the traffic and / or a feature vector corresponding to the traffic to be identified, and the feature vector corresponding to the traffic to be identified is used to characterize the user behavior of the traffic to be identified through at least one dimension. The determination module 620 is used to match the feature information of the traffic to be identified with the feature information of normal traffic contained in a normal traffic feature library to determine the matching degree between the traffic to be identified and the normal traffic, wherein the feature information of the normal traffic includes feature information of the normal client sending the normal traffic and / or a feature vector corresponding to the normal traffic, and the feature vector corresponding to the normal traffic is used to characterize the user behavior of the normal traffic through at least one dimension. The interception module 630 is used to determine that the matching degree between the traffic to be identified and the normal traffic is less than or equal to a preset matching degree, and then intercepts the traffic to be identified.
[0199] Optionally, the device 600 further includes: an extraction module and a generation module, wherein the extraction module is used to extract feature information of the normal traffic; the generation module is used to generate a normal traffic feature library based on the feature information of the normal traffic, wherein the normal traffic feature library includes a first feature library and / or a second feature library, the first feature library includes feature information of the normal client, and the second feature library includes feature vectors corresponding to the normal traffic.
[0200] Optionally, the normal traffic feature library includes the first feature library and the second feature library. The determining module 620 is specifically used to: match the feature information of the client of the traffic to be identified with the feature information of the normal client contained in the first feature library to obtain a first matching result; match the feature vector corresponding to the traffic to be identified with the feature vector corresponding to the normal traffic contained in the second feature library to obtain a second matching result; and determine the matching degree between the traffic to be identified and the normal traffic based on the first matching result and the second matching result.
[0201] Optionally, the determining module 620 is specifically used to: determine that the number of traffic to be identified is greater than or equal to the first baseline value, match the feature information of the traffic to be identified with the feature information of the normal traffic, and determine the matching degree between the traffic to be identified and the normal traffic.
[0202] Optionally, the interception module 630 is further configured to determine that the matching degree between the traffic to be identified and the normal traffic is greater than the preset matching degree, and to intercept the traffic to be identified when the origin server instance is overloaded, wherein the origin server instance is used to respond to the traffic to be identified.
[0203] Optionally, the device 600 further includes: an update module, configured to determine that the number of traffic to be identified is less than a first baseline value, and update the characteristic information of the normal traffic based on the characteristic information of the traffic to be identified.
[0204] Optionally, the characteristic information of the normal client includes at least one of the following: the Internet Protocol IP address, username, user ID, and account ID of the normal client, and the at least one dimension includes at least one of the following: whether the normal traffic accesses the target Uniform Resource Locator URL, whether the request header field of the normal traffic carries a target header field, and the analysis results of the IP address of the normal client in at least one security database.
[0205] The device 600 here can be embodied in the form of a functional module. The term "module" here can be implemented in software and / or hardware, without specific limitations.
[0206] For example, a "module" can be a software program, a hardware circuit, or a combination of both that implements the above functions. For instance, the implementation of module 610 will be described below using module 610 as an example. Similarly, the implementation of other modules, such as module 620, module 630, module extracting, module generating, and module updating, can refer to the implementation of module 610.
[0207] As an example of a software functional unit, the acquisition module 610 may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, or a container. Further, the aforementioned computing instance may be one or more. For example, the acquisition module 610 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed in the same region or in different regions. Further, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same availability zone (AZ) or in different AZs, each AZ including one or more geographically proximate data centers. Typically, a region may include multiple AZs.
[0208] Similarly, multiple hosts / virtual machines / containers used to run this code can be distributed within the same Virtual Private Cloud (VPC) or across multiple VPCs. Typically, a VPC is set up within a region. Communication between two VPCs within the same region, as well as between VPCs in different regions, requires a communication gateway to be set up within each VPC to enable interconnection between VPCs.
[0209] As an example of a hardware functional unit, the acquisition module 610 may include at least one computing device, such as a server. Alternatively, the acquisition module 610 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be implemented using a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), generic array logic (GAL), or any combination thereof.
[0210] The multiple computing devices included in the acquisition module 610 can be distributed in the same region or in different regions. Similarly, the multiple computing devices included in the acquisition module 610 can be distributed in the same Availability Zone (AZ) or in different AZs. Likewise, the multiple computing devices included in the acquisition module 610 can be distributed in the same Virtual Private Cloud (VPC) or in multiple VPCs. These multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0211] Therefore, the modules of the various examples described in the embodiments of this application can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0212] It should be noted that the above embodiments of the device, when executing the above methods, are only illustrative examples of the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. For example, the acquisition module 610 can be used to execute any step in the above methods, the determination module 620 can be used to execute any step in the above methods, the interception module 630 can be used to execute any step in the above methods, the extraction module can be used to execute any step in the above methods, the generation module can be used to execute any step in the above methods, and the update module can be used to execute any step in the above methods. The steps implemented by the acquisition module 610, determination module 620, interception module 630, extraction module, generation module, and update module can be specified as needed. By implementing different steps in the above methods through the acquisition module 610, determination module 620, interception module 630, extraction module, generation module, and update module, all the functions of the above device can be realized.
[0213] Furthermore, the apparatus and method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process can be found in the method embodiments above, which will not be repeated here.
[0214] Figure 7 is a schematic diagram of another cloud service system provided in this application. As shown in Figure 7, the cloud service system includes infrastructure that provides cloud services to users and a cloud management platform that manages the infrastructure. The infrastructure includes cloud instances, and the cloud instances run devices 600.
[0215] The aforementioned device 600 can be abstracted into a cloud service by a cloud service provider on a cloud management platform and provided to users. After users purchase the cloud service on the cloud management platform, the cloud environment uses the cloud service to provide users with cloud services for web application protection.
[0216] For example, a tenant logs into the cloud management platform via a pre-registered account and password on the public cloud access page. After successful login, the tenant selects and purchases a cloud service for Web Application Protection (WA). If the tenant purchases the WA service, they can then utilize that service to provide WA-enabled computing functionality.
[0217] For example, a cloud management platform is primarily used to manage the infrastructure for running cloud services that provide Web Application Protection (WAP). This infrastructure may include multiple data centers located in different regions, each containing multiple servers. Data centers can provide basic resources for the Web Application Protection (WAP) cloud services, such as computing resources and storage resources. Therefore, when tenants purchase and use Web Application Protection (WAP) cloud services, they primarily pay for the resources they use.
[0218] As shown in Figure 7, taking a tenant's purchase of a cloud service for Web Application Protection as an example, the user can upload traffic to be identified to the cloud environment through an application program interface (API) or a web interface provided by the cloud management platform. The cloud service invocation device 600 for Web Application Protection then determines whether to intercept the traffic to be identified.
[0219] In this embodiment of the application, when the device 600 is a software device, the device can be deployed on a computing device in any environment, or on a computing device cluster consisting of multiple computing devices in any environment.
[0220] The method provided in this application can be executed by a computing device, which can also be referred to as a computer system. It includes a hardware layer, an operating system layer running on top of the hardware layer, and an application layer running on the operating system layer. The hardware layer includes hardware such as processing units, memory, and memory control units; the functions and structure of this hardware will be described in detail later. The operating system can be any one or more computer operating systems that implement business processing through processes, such as Linux, Unix, Android, iOS, or Windows. The application layer includes applications such as browsers, address books, word processing software, and instant messaging software. Optionally, the computer system can be a handheld device such as a smartphone, or a terminal device such as a personal computer; this application does not particularly limit this, as long as the method provided in this application can be used. The executing entity of the method provided in this application can be a computing device, or a functional module within the computing device capable of calling and executing programs.
[0221] The following describes in detail, with reference to Figure 8, a computing device provided in an embodiment of this application.
[0222] Figure 8 is a schematic diagram of the architecture of a computing device 1500 provided in an embodiment of this application. The computing device 1500 can be a server, a computer, or other device with computing capabilities. The computing device 1500 shown in Figure 8 includes at least one processor 1510 and a memory 1520.
[0223] It should be understood that this application does not limit the number of processors and memories in the computing device 1500.
[0224] The processor 1510 executes instructions in the memory 1520, causing the computing device 1500 to implement the method provided in this application. Alternatively, the processor 1510 executes instructions in the memory 1520, causing the computing device 1500 to implement the various functional modules provided in this application, thereby implementing the method provided in this application.
[0225] Optionally, the computing device 1500 also includes a communication interface 1530. The communication interface 1530 uses a transceiver module, such as, but not limited to, a network interface card or a transceiver, to enable communication between the computing device 1500 and other devices or communication networks.
[0226] Optionally, the computing device 1500 also includes a system bus 1540, wherein the processor 1510, memory 1520, and communication interface 1530 are respectively connected to the system bus 1540. The processor 1510 can access the memory 1520 through the system bus 1540; for example, the processor 1510 can perform data read / write or code execution in the memory 1520 through the system bus 1540. The system bus 1540 is a peripheral component interconnect express (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The system bus 1540 is divided into an address bus, a data bus, a control bus, etc. For ease of illustration, only one thick line is used in Figure 8, but this does not mean that there is only one bus or one type of bus.
[0227] In one possible implementation, the processor 1510 primarily functions to interpret the instructions (or code) of a computer program and process data within the computer software. The instructions of the computer program and the data within the computer software can be stored in memory 1520 or cache 1516.
[0228] Optionally, processor 1510 may be an integrated circuit chip with signal processing capabilities. By way of example and not limitation, processor 1510 may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. Among these, a general-purpose processor is a microprocessor, etc. For example, processor 1510 may be a central processing unit (CPU).
[0229] Optionally, each processor 1510 includes at least one processing unit 1512 and a memory control unit 1514.
[0230] Optionally, the processing unit 1512, also known as the core, is the most important component of the processor. The processing unit 1512 is manufactured from single-crystal silicon using a specific production process. All calculations, command reception, command storage, and data processing are performed by the core. Each processing unit independently executes program instructions, utilizing parallel computing capabilities to accelerate program execution. Various processing units have fixed logical structures; for example, a processing unit includes logical units such as a Level 1 cache, a Level 2 cache, an execution unit, an instruction-level unit, and a bus interface.
[0231] In one implementation example, the memory control unit 1514 controls the data interaction between the memory 1520 and the processing unit 1512. Specifically, the memory control unit 1514 receives memory access requests from the processing unit 1512 and controls access to memory based on the memory access requests. By way of example and not limitation, the memory control unit is a device such as a memory management unit (MMU).
[0232] In one implementation example, each memory control unit 1514 addresses the memory 1520 via the system bus. An arbitrator (not shown in Figure 8) is configured on the system bus to handle and coordinate contention for access by the multiple processing units 1512.
[0233] In one implementation example, the processing unit 1512 and the memory control unit 1514 are connected via internal chip connection lines, such as address lines, thereby enabling communication between the processing unit 1512 and the memory control unit 1514.
[0234] Optionally, each processor 1510 also includes a cache 1516, which is a buffer for data exchange (called a cache). When the processing unit 1512 needs to read data, it first looks for the required data in the cache. If the data is found, it is executed directly; otherwise, it looks for the data in memory. Since the cache operates much faster than memory, its purpose is to help the processing unit 1512 run faster.
[0235] The memory 1520 provides runtime space for processes in the computing device 1500. For example, the memory 1520 stores the computer program (specifically, the program code) used to generate the process. After the computer program is run by the processor to generate a process, the processor allocates corresponding storage space for the process in the memory 1520. Furthermore, the aforementioned storage space further includes text segments, initialized data segments, bit initialized data segments, stack segments, heap segments, etc. The memory 1520 stores data generated during the process's execution, such as intermediate data or process data, in the aforementioned process-specific storage space.
[0236] Optionally, the memory, also known as RAM, is used to temporarily store the data processed by the processor 1510, as well as data exchanged with external storage devices such as hard disks. As long as the computer is running, the processor 1510 will load the data that needs to be processed into RAM for processing, and after the processing is completed, the processing unit 1512 will send the result out.
[0237] By way of example and not limitation, memory 1520 is volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Non-volatile memory is read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory is random access memory (RAM) used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM). It should be noted that the memory 1520 of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0238] The structure of the computing device 1500 listed above is merely illustrative and is not limited thereto. The computing device 1500 in this application includes various hardware components in existing computer systems. For example, the computing device 1500 also includes other memories besides memory 1520, such as disk storage. Those skilled in the art should understand that the computing device 1500 may also include other devices necessary for normal operation. Furthermore, depending on specific needs, those skilled in the art should understand that the computing device 1500 may also include hardware devices for implementing other additional functions. In addition, those skilled in the art should understand that the computing device 1500 may only include the devices necessary for implementing the embodiments of this application, and not necessarily all the devices shown in FIG8.
[0239] This application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device may be a server. In some embodiments, the computing device may also be a desktop computer, a laptop computer, or a smartphone, or other terminal device.
[0240] As shown in Figure 9, the computing device cluster includes at least one computing device 1500. The memory 1520 of one or more computing devices 1500 in the computing device cluster may store the same instructions for performing the above-described methods.
[0241] In some possible implementations, the memory 1520 of one or more computing devices 1500 in the computing device cluster may also each store a portion of the instructions for executing the above-described methods. In other words, a combination of one or more computing devices 1500 can jointly execute the instructions of the above-described methods.
[0242] It should be noted that the memory 1520 in different computing devices 1500 within the computing device cluster can store different instructions, each used to execute a portion of the functions of the aforementioned device. That is, the instructions stored in the memory 1520 of different computing devices 1500 can implement the functions of one or more modules within the aforementioned device.
[0243] In some possible implementations, one or more computing devices in a computing device cluster can be connected via a network. This network can be a wide area network (WAN) or a local area network (LAN), etc. Figure 10 illustrates one possible implementation. As shown in Figure 10, two computing devices, 1500A and 1500B, are connected via a network. Specifically, they are connected to the network through communication interfaces in each computing device.
[0244] It should be understood that the functions of computing device 1500A shown in Figure 10 can also be performed by multiple computing devices 1500. Similarly, the functions of computing device 1500B can also be performed by multiple computing devices 1500.
[0245] In this embodiment, a computer program product containing instructions is also provided. The computer program product may be a software or program product containing instructions capable of running on a computing device or stored on any usable medium. When run on a computing device, it causes the computing device to perform the methods provided above, or causes the computing device to perform the functions of the apparatus provided above.
[0246] In this embodiment, a computer-readable storage medium is also provided. This computer-readable storage medium can be any available medium that a computing device can store, or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive). The computer-readable storage medium includes instructions that, when executed on a computing device, cause the computing device to perform the method described above.
[0247] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0248] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0249] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0250] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0251] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0252] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0253] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0254] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A security defense method based on a cloud service system, characterized in that, The cloud service system includes infrastructure for providing cloud services to users and a cloud management platform for managing the infrastructure. The infrastructure includes cloud instances. The method includes: The cloud management platform receives traffic to be identified; The cloud management platform sends the traffic to be identified to the cloud instance; The cloud instance acquires the feature information of the traffic to be identified, wherein the feature information of the traffic to be identified includes the feature information of the client that sent the traffic to be identified and / or the feature vector corresponding to the traffic to be identified, and the feature vector corresponding to the traffic to be identified is used to characterize the user behavior of the traffic to be identified through at least one dimension; The cloud instance matches the feature information of the traffic to be identified with the feature information of normal traffic contained in the normal traffic feature library to determine the matching degree between the traffic to be identified and the normal traffic. The feature information of the normal traffic includes the feature information of the normal client that sends the normal traffic and / or the feature vector corresponding to the normal traffic. The feature vector corresponding to the normal traffic is used to characterize the user behavior of the normal traffic through at least one of the dimensions. The cloud instance determines that the matching degree between the traffic to be identified and the normal traffic is less than or equal to a preset matching degree, and then intercepts the traffic to be identified.
2. The method according to claim 1, characterized in that, Before the cloud management platform receives the traffic to be identified, the method further includes: The cloud management platform receives normal traffic, and the amount of normal traffic is less than the first baseline value. The cloud management platform sends the normal traffic to the cloud instance; The cloud instance extracts the characteristic information of the normal traffic; The cloud instance generates a normal traffic feature library based on the feature information of the normal traffic. The normal traffic feature library includes a first feature library and / or a second feature library. The first feature library includes the feature information of the normal client, and the second feature library includes the feature vector corresponding to the normal traffic.
3. The method according to claim 2, characterized in that, The normal traffic feature library includes the first feature library and the second feature library. The cloud instance matches the feature information of the traffic to be identified with the feature information of normal traffic contained in the normal traffic feature database to determine the matching degree between the traffic to be identified and the normal traffic, including: The cloud instance matches the feature information of the client of the traffic to be identified with the feature information of the normal client contained in the first feature library to obtain a first matching result; The cloud instance matches the feature vector corresponding to the traffic to be identified with the feature vector corresponding to the normal traffic contained in the second feature library to obtain a second matching result; The cloud instance determines the matching degree between the traffic to be identified and the normal traffic based on the first matching result and the second matching result.
4. The method according to any one of claims 1 to 3, characterized in that, The cloud instance matches the feature information of the traffic to be identified with the feature information of normal traffic contained in the normal traffic feature database, including: The cloud instance determines that the number of traffic to be identified is greater than or equal to a first baseline value, and matches the feature information of the traffic to be identified with the feature information of the normal traffic.
5. The method according to any one of claims 1 to 4, characterized in that, The method further includes: The cloud instance determines that the matching degree between the traffic to be identified and the normal traffic is greater than the preset matching degree, and intercepts the traffic to be identified when the origin server instance is overloaded. The origin server instance is used to respond to the traffic to be identified.
6. The method according to claim 4 or 5, characterized in that, The method further includes: The cloud instance determines that the number of traffic to be identified is less than the first baseline value, and updates the feature information of the normal traffic based on the feature information of the traffic to be identified.
7. The method according to any one of claims 1 to 6, characterized in that, The characteristic information of the normal client includes at least one of the following: the Internet Protocol IP address, username, user ID, and account ID of the normal client. The at least one dimension includes at least one of the following: whether the normal traffic accesses the target Uniform Resource Locator URL, whether the request header field of the normal traffic carries a target header field, and the analysis results of the IP address of the normal client in at least one security database.
8. A cloud service system, characterized in that, The cloud service system includes infrastructure that provides cloud services to users and a cloud management platform that manages the infrastructure. The infrastructure includes cloud instances, wherein... The cloud management platform is used to receive traffic to be identified; The cloud management platform is also used to send the traffic to be identified to the cloud instance; The cloud instance is used to obtain the feature information of the traffic to be identified, wherein the feature information of the traffic to be identified includes the feature information of the client that sent the traffic to be identified and / or the feature vector corresponding to the traffic to be identified, and the feature vector corresponding to the traffic to be identified is used to characterize the user behavior of the traffic to be identified through at least one dimension; The cloud instance is further configured to match the feature information of the traffic to be identified with the feature information of normal traffic contained in the normal traffic feature library to determine the matching degree between the traffic to be identified and the normal traffic. The feature information of the normal traffic includes the feature information of the normal client that sends the normal traffic and / or the feature vector corresponding to the normal traffic. The feature vector corresponding to the normal traffic is used to characterize the user behavior of the normal traffic through at least one of the dimensions. The cloud instance is also used to determine that the matching degree between the traffic to be identified and the normal traffic is less than or equal to a preset matching degree, and to intercept the traffic to be identified.
9. The cloud service system according to claim 8, characterized in that, The cloud management platform is also used to receive normal traffic, the amount of which is less than the first baseline value; The cloud management platform is also used to send the normal traffic to the cloud instance; The cloud instance is also used to extract feature information of the normal traffic; The cloud instance is further configured to generate a normal traffic feature library based on the feature information of the normal traffic, wherein the normal traffic feature library includes a first feature library and / or a second feature library, the first feature library includes feature information of the normal client, and the second feature library includes feature vectors corresponding to the normal traffic.
10. The cloud service system according to claim 8 or 9, characterized in that, The normal traffic feature library includes the first feature library and the second feature library. The cloud instance is specifically used for: The feature information of the client of the traffic to be identified is matched with the feature information of the normal client contained in the first feature library to obtain a first matching result; The feature vector corresponding to the traffic to be identified is matched with the feature vector corresponding to the normal traffic contained in the second feature library to obtain a second matching result; The matching degree between the traffic to be identified and the normal traffic is determined based on the first matching result and the second matching result.
11. The cloud service system according to any one of claims 8 to 10, characterized in that, The cloud instance is specifically used for: If the number of traffic to be identified is greater than or equal to a first baseline value, the feature information of the traffic to be identified is matched with the feature information of the normal traffic.
12. The cloud service system according to any one of claims 8 to 11, characterized in that, The cloud instance is further configured to determine that the matching degree between the traffic to be identified and the normal traffic is greater than the preset matching degree, and to intercept the traffic to be identified when the origin server instance is overloaded, wherein the origin server instance is configured to respond to the traffic to be identified.
13. The cloud service system according to claim 11 or 12, characterized in that, The cloud instance is also used to determine that the number of traffic to be identified is less than the first baseline value, and to update the feature information of the normal traffic based on the feature information of the traffic to be identified.
14. The cloud service system according to any one of claims 8 to 13, characterized in that, The characteristic information of the normal client includes at least one of the following: the Internet Protocol IP address, username, user ID, and account ID of the normal client. The at least one dimension includes at least one of the following: whether the normal traffic accesses the target Uniform Resource Locator URL, whether the request header field of the normal traffic carries a target header field, and the analysis results of the IP address of the normal client in at least one security database.
15. A computing device cluster, characterized in that, It includes at least one computing device, each computing device including a processor and memory; The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device to cause the cluster of computing devices to perform the method as described in any one of claims 1 to 7.
16. A computer program product containing instructions, characterized in that, When the instruction is executed by the computing device cluster, the computing device cluster performs the method as described in any one of claims 1 to 7.
17. A computer-readable storage medium, characterized in that, It includes computer program instructions, which, when executed by a cluster of computing devices, perform the method as described in any one of claims 1 to 7.