The invention discloses a snapshot
attack identification and
processing method, device and equipment and a medium, is applied to a
processing node in a distributed cluster, and relates to the technical field of computers, and the method comprises the steps: adding a received to-be-processed snapshot operation of a first target
client to a target snapshot operation
queue in real time, judging whether the
queue length is greater than a preset
queue threshold value or not; if yes, the snapshot operation frequency of the first target
client in the preset time interval is determined; determining whether the first target
client is an abnormal client initiating a snapshot
attack based on the snapshot operation frequency, and if yes, alarming the first target client and / or adding the first target client to a target
blacklist; and if an
exception handling request of the storage node to the second target client is received, correspondingly alarming the second target client or adding the second target client to the target
blacklist. Therefore, real-time detection, alarm and blocking of the abnormal snapshot behavior can be realized, so that the risk of sudden increase of cluster load is effectively relieved.