System and method of reducing false responses when detecting network attack
Abstract
FIELD: information technology. SUBSTANCE: system comprises the following modules: a control module for storing statistics on previous network attacks for correcting filtering rules for filtering centres; collectors for compiling filtering rules based on traffic information from the filter centres and sensors; filter centres for filtering traffic based on filtering rules; sensors for aggregating traffic information for further transmission to collectors. EFFECT: reduced false responses when detecting network attack. 14 cl, 6 dwg
Term
No projected expiry on record.
- Priority and filed
- Granted
- Today
14 claims: 2 independent, 12 dependent
- 1The system of network traffic filtering service to protect against network attacks, comprising:a) the control unit is connected to the collectors, treatment centers, and sensors and is designed to store the statistics of previous network attacks to adjust the filtering rules for purification centers, and b) said manifold connected to the center cleaning and sensors are designed to produce filtering rules based on the traffic information from the centers of purification and sensors, c) said centers of purification intended to filter traffic based on filtering rules, with the centers of purification connected to the main channels on channels with a high bandwidth;g) said sensors are designed to aggregate data traffic for transmission to the collectors. 1. Система фильтрации сетевого трафика для защиты сервиса от сетевых атак, содержащая:а) управляющий модуль связан с коллекторами, центрами очистки и сенсорами и предназначен для хранения статистики предыдущих сетевых атак для корректировки правил фильтрации для центров очистки;б) упомянутые коллекторы связаны с центрами очистки и сенсорами и предназначены для составления правил фильтрации на основании информации о трафике от центров очистки и сенсоров;в) упомянутые центры очистки предназначены для фильтрации трафика на основании правил фильтрации, при этом центры очистки подключены к магистральным каналам связи по каналам с высокой пропускной способностью;г) упомянутые сенсоры предназначены для агрегирования информации о трафике для дальнейшей передачи на коллекторы. 1. Система фильтрации сетевого трафика для защиты сервиса от сетевых атак, содержащая:а) управляющий модуль связан с коллекторами, центрами очистки и сенсорами и предназначен для хранения статистики предыдущих сетевых атак для корректировки правил фильтрации для центров очистки;б) упомянутые коллекторы связаны с центрами очистки и сенсорами и предназначены для составления правил фильтрации на основании информации о трафике от центров очистки и сенсоров;в) упомянутые центры очистки предназначены для фильтрации трафика на основании правил фильтрации, при этом центры очистки подключены к магистральным каналам связи по каналам с высокой пропускной способностью;г) упомянутые сенсоры предназначены для агрегирования информации о трафике для дальнейшей передачи на коллекторы.
- 8A method of filtering network traffic to protect the service against network attacks, comprising the steps of:(i). redirect traffic to the service on sensors and purification centers;(ii). treated at all sensors service requests with the received information further aggregation;(iii). updating filter rules at the collectors, using information obtained from sensors;(iv). correcting rules updated filtering by the control module based on historical statistical network attacks;(v). filtered traffic for purification centers using predetermined filter rules, and the purification centers connected to the main channels on channels with a high bandwidth. 8. Способ фильтрации сетевого трафика для защиты сервиса от сетевых атак, содержащий этапы, на которых:(i). перенаправляют трафик к сервису на сенсоры и центры очистки;(ii). обрабатывают на сенсорах все запросы к сервису с дальнейшим агрегированием полученной информации;(iii). обновляют правила фильтрации на коллекторах, используя полученную от сенсоров информацию;(iv). корректируют обновленные правила фильтрации с помощью управляющего модуля на основании статистики предыдущих сетевых атак;(v). фильтруют трафик на центрах очистки, используя заданные правила фильтрации, при этом центры очистки подключены к магистральным каналам связи по каналам с высокой пропускной способностью. 8. Способ фильтрации сетевого трафика для защиты сервиса от сетевых атак, содержащий этапы, на которых:(i). перенаправляют трафик к сервису на сенсоры и центры очистки;(ii). обрабатывают на сенсорах все запросы к сервису с дальнейшим агрегированием полученной информации;(iii). обновляют правила фильтрации на коллекторах, используя полученную от сенсоров информацию;(iv). корректируют обновленные правила фильтрации с помощью управляющего модуля на основании статистики предыдущих сетевых атак;(v). фильтруют трафик на центрах очистки, используя заданные правила фильтрации, при этом центры очистки подключены к магистральным каналам связи по каналам с высокой пропускной способностью.
Independent claims2
60 paragraphs in 4 sections, as filed
TECHNICAL FIELD
The invention relates to a system for determining the distributed network attacks, and more specifically, to reduce false positives in the determination of net attack by analyzing the behavior of user interaction with the protected resource.
BACKGROUND
Currently, almost all the companies and organizations that somehow represented on the Internet, and many people use the Internet as a business tool. At the same time, the Internet does not provide adequate protection services "by default." In addition, a number of Internet threats today, it is impossible to protect personal protective equipment, like firewalls, intrusion prevention systems, antivirus, etc. A vivid example of such threats are DDoS attacks.
DoS-attack is an attack on a computer system with a view to bring it to failure, that is to create conditions under which legitimate (lawful) system users can not get access to the provided system resources (servers), or the access is difficult. Motives for such attacks can be very different - they can serve as elements of competition, a means of blackmail, revenge, an expression of discontent, demonstrations and opportunities to attract attention, which often treated as cyberterrorism. If the attack is carried out simultaneously with a large number of computers that talk about DDoS-attack (from the English. Distributed Denial of Service, attacks such as distributed "denial of service"). There are two types of DDoS-attacks: attacks on bandwidth and application attacks.
Attacks on bandwidth - the attacker acts by filling the channels of communication, bandwidth allocation, and a large number of equipment packages. Selected as the victim routers, servers and firewalls, each of which has only limited processing resources, under the effect of the attack may not be available to process valid transactions or fail under heavy load. The most common form of attack with the filling of the bandwidth - a flood attack to sending packages in which a large number of seemingly legitimate packet protocol TCP, User Datagram Protocol (UDP) or Control Message Protocol Internet (ICMP) is sent to a specific point.
Application attacks - an attacker exploiting behaviors computer interaction protocols (TCP, HTTP, etc.), as well as the behavior of services and applications, captures the computing resources of the computer on which operates the object of attack, which does not allow the latter to process legitimate transactions and queries . Examples of applications are attacks on the attack with half-open connections to HTTP and erroneous connections HTTP. More details about this attack can be found in an article on the website of Cisco http://www.cisco.com/web/RU/products/ps5887/products_white_paper0900aecd80 lle927.html.
Typically, DDoS-attack is carried out using a botnet, also known as a network of kompyuterov- "zombies." Botnet (also botnet) - a network of infected computers infected with malicious software that allows you to remotely control infected computers without the knowledge of their users. Programs that allow you to perform these actions are called bots.
Figure 1 shows an algorithm such attacks. With the host computer 100 botnets sent signals to the computer 110 control botnets, each of which monitors a much larger number of computers 120, which established the bots. Computer use 110 control botnets greatly complicates the determination of the host computer 100 botnets are also increasing the potential size of the botnet to a million cars and more. Further, 120 bots on computers start DDoS-attack on the service 130. Under service means any web service that provides users with specific services or resources. Examples of services may be an online store or a file server. It may seem that, for example, at a time online store is experiencing an influx of buyers, with whom he is unable to cope. When DDoS-attack on the 130 service in the first to suffer its owners, and its potential customers.
It should be noted that in order to solve the problem of DDoS-attacks using various technologies, for example, using the collection of statistics collected data to build user profiles. Gathering such statistics can be used to separate potential bots. In US Patent Application 20090031244 describes a method of collecting statistics in the transmission of data by the user. In US Patent Application 20080010247 describes a system for collecting information about user actions and preparation of the final profile using a set of rules. The patent EP 2109282 describes the possibility of constructing a histogram requests (like profiles) user for further action by cutting off traffic.
After determining the working potential of bots, botnet can be determined on the basis of identifying their specific requests or to determine anomalies in traffic. For example, in the patents and patent applications WO 06039529, US 20090037592, WO 06039529, US 7478429 fact working bots is determined by identifying duplicates GET requests, wrong carriage return or overload a DNS server. US Patent No. 7426634 describes a method for the ban of new connections in determining the attack. Possible COMPUTERS- "zombie" (bots) are identified by their MAC addresses. The patent EP 2109279 is determined attack by comparing the average number of requests from the current number of requests. In US Patent 7626940, US 7602731 is considered an option analysis of DNS queries and identification of anomalies for further attacks possible counteractions. In GB 2393607 describes a method for the detection of anomalies and subsequent filtration. In US Patent Application 20080022405 definition of anomalies based on finding executable parts of queries.
One method of solving the problem of DDoS-attacks is to clean the traffic directed to the service. For example, in the patents and patent applications WO 06039529, US 20090037592, WO 06039529, US 7478429 describes a system for detecting the state of the server overload (service) with the SYN-Flood attacks. US Patent No. 7058015 describes a system of sensors, which are responsible for traffic monitoring, routers, and the control unit, which is engaged in forwarding traffic based on defined policies. Described in US Patent Application 20040064738 method involves the use of a proxy server to analyze traffic to the server. In US Patent Application 20030172289 describes a method for controlling the flow of traffic using its routing and processing.
Another option for controlling unwanted traffic is routed to the "black holes". The process of routing "black hole" is used by the service provider to block all traffic addressed to the target object, in the earliest possible point. "Cut from the route" traffic is routed to the "black hole" for network security provider and its other clients. Routing "black hole" can not be called a good solution, because along with malicious attack traffic packets are discarded and trustworthy.
Also described are methods and systems that allow us to determine the attack on the application. US Patent No. 7272854 is a definition of the type of application (IM type), to which is possible DoS attacks. In US Patent Application 20070258438 describes the ability to detect a possible attack on the Web service. KR Patent 7061017, KR 7077517 describes a method for determining the attacks on the web application.
You can also use a firewall (firewall) to deal with DDoS-attacks. This has its advantages as well as firewalls are in the immediate vicinity of the protected resource, which, however, did not save us from the attacks on the exhaustion of bandwidth. Filtering methods in this case, quite primitive, and if the DDoS-attack will be carried out by authorized ports and protocols, the firewall will be in front of her completely helpless.
Finally, one of the most long-used technology is the use of "black" and "white" lists (we will use these words without quotation marks), which are used to separate access for the ban (blacklist, http://en.wikipedia.org: / wiki / Blacklist (computing)), and to allow (white list, http://en.wikipedia.org/wiki/Whitelist).
However, one of the main problems of existing systems and methods is the problem of false positives. False positives may disrupt Web services - for example, not allowing the usual visitors to the online store to use its services. Thus a system that can deal with possible DDoS-attacks, while at the same time allowing ordinary users to seamlessly harness the power of Web services.
An analysis of the prior art and the opportunities that appear when combining them in a single system, allows to obtain a new result, namely a system to reduce false positives in the determination of net attack.
SUMMARY OF THE INVENTION
Thus, the object of the present invention is to reduce false positives in the determination of net attack by analyzing the behavior of user interaction with the protected resource.
In one embodiment, a system is provided filtering network traffic, comprising: a control module connected to the collectors, treatment centers, and sensors and for storing previous network attack statistics to adjust the filter rules for purification centers; said manifold connected to the centers of cleaning and sensors are designed to produce filtering rules based on the traffic information from the centers of purification and sensors; mentioned purification centers are designed to filter traffic based on filter rules; mentioned sensors are used to aggregate traffic information for transmission to the collectors.
In one embodiment, the service is a web service that provides users with specific services or resources.
In another embodiment of the statistics of previous network attacks include: Statistics average and peak load channel during a network attack, information on malicious activity on the Internet, the number of participating in the network attack bot networks, the time since the start of network attack, the duration of a network attack, geography network attack.
In yet another embodiment of the control module uses white and black lists of IP-addresses to adjust the filtering rules.
In one embodiment of the white and black lists of IP-addresses are given on the basis of behavioral criteria, which include the analysis of queries and sessions established with the same IP-address, the number of requests without confirmation from the same IP-address, the number of requests of the same type of data from one IP-addresses, the number of connections without continuing information exchange.
In yet another embodiment of the cleaning centers connected to the main channels on channels with a high bandwidth.
In another embodiment of each treatment facility comprises at least proxying server to redirect traffic router and filter for filtering traffic.
In one embodiment, the sensors are located in the immediate vicinity of the service.
According to another embodiment of the filtering method is provided of network traffic, comprising the steps of: rearranging the traffic to the service centers, and sensors for cleaning; treated in sensors all service requests with further aggregation of the information received; update the filter rules on the collectors, using the information received from the sensors; adjust the updated filter rule by the control module based on the statistics of the previous network attacks; filtered traffic to purification centers, using the specified filtering rules.
In one embodiment, the service is a web service that provides users with specific services or resources.
In yet another embodiment of the statistics of previous network attacks include: Statistics average and peak load channel during a network attack, information on malicious activity on the Internet, the number of participating in the network attack bot networks, the time since the start of network attack, the duration of a network attack, the geography of a network attack.
In another embodiment, the control module uses white and black lists of IP-addresses to adjust the filtering rules.
In one embodiment of the white and black lists of IP-addresses are given on the basis of behavioral criteria, which include the analysis of queries and sessions established with the same IP-address, the number of requests without confirmation from the same IP-address, the number of requests of the same type of data from one IP-addresses, the number of connections without continuing information exchange.
In yet another embodiment of the cleaning centers connected to the main channels on channels with a high bandwidth.
In another embodiment of each treatment facility comprises at least proxying server to redirect traffic router and filter for filtering traffic.
In one embodiment, the sensors are located in the immediate vicinity of the service.
BRIEF DESCRIPTION OF DRAWINGS
Additional objects, features and advantages of the present invention will become apparent from reading the following description of embodiments with reference to the accompanying drawings, in which:
Figure 1 shows the algorithm of DDoS attacks.
Figure 2 shows a simplified scheme of the present system.
Figure 3 is a detailed diagram of the present system.
Figure 4 illustrates the use of black and white lists when filtering traffic.
5 illustrates a method of operating a system for detection of DDoS-attacks.
6 illustrates the use of different levels of aggregation of the data.
Description of Embodiments
Objects and features of the present invention, the methods to achieve these objects and features will become apparent by reference to the exemplary embodiments. However, the present invention is not limited to the exemplary embodiments disclosed below, it may be embodied in various forms. The essence contained in the description, is nothing but the specific details, secured to assist a person skilled in the art in a comprehensive understanding of the invention, and the present invention is defined only in the scope of the appended claims.
Figure 2 shows a simplified scheme of the present system. To protect service centers 130 used Cleaning 210 that filter traffic - both on the PC 120, which is installed on boats, and from ordinary users 220 who are trying to gain access to the service 130.
For protection against attacks on the bandwidth, the traffic to the service 130 will be redirected through the centers of cleaning 210, which should be connected as close as possible to the main channels on channels with a high bandwidth. Due to this supposed substantially to distribute traffic without overloading communications channels leading to the 130 service.
For protection against attacks on the application 230, the system will generate a model of the average traffic to the service 130, and then, during an attack, to be cut off on the basis of such a model the parasitic traffic. Further, under the spurious traffic will mean traffic generated by bots on computers 120. Legitimate traffic is the flow of data from 220 normal users.
Figure 3 is a detailed diagram of the present system. It consists of a control unit 320, 310 reservoirs, purification centers 210 and sensors 330. Let us more detail on their interaction.
Traffic And the service 130 can go both on the PC 120, which is mounted on boats, and from ordinary users 220. The traffic itself is duplicated to redirect it to a purification centers 210 and the sensors 330 to the sensor 330 is processed all requests for service 130 further aggregating the received information. As a result, from the sensors 330 to the collector 310 is already a brief compilation of information on all requests. Before you consider the main functions of the collector 310, it is worth mentioning about the second stream of traffic that goes to the treatment centers themselves 210. purification centers 210 in the form of two devices - proxied server 210a and the filtering router 210B. The objective is proxied server 210a is the transmission of the filtered traffic to the service B to 130. The decision on traffic from a particular computer (it may be a computer 120 with the bot, and a regular user 220) is received by the filtering router 210B. The filtering rules filtering router 210B transmitted from the collector 310. Let us now consider each element of the system in more detail.
The control module 320 controls the operation of all other modules (in the first place, collectors 310), tracking their likely congestion. The control module 320 is able to track download statistics of the channel (the current day, day of week, month), as well as malicious activity on the Internet, allowing you to build the geography of current attacks and carrying out the storage and collection of statistics of previous attacks (amount, duration, peak and average load). Based on this information, for every attack you can get it descriptive characteristics, such as: the number of bot networks involved, the time since the start of the attack, the geography of the attacks. Based on this information the control unit can correct the filtering rules ("filtering profile") used cleaning centers 210. For this purpose, calculated allowable amount of data transmitted allowable number of packets depending on the protocol, etc. Types of parameters considered are shown in the table. Also, the control unit 320 stores a list of black / white address. About them it is worth mentioning separately.
4 shows that by using black and white lists of addresses (or - black and white lists), they are prevailing over the filter rules. This means that if the address of the computer is in the whitelist (check at step 440), the traffic from it will never be blocked (i.e. not subjected to filtering in step 450), and when in the black list (step 420) opposite - all traffic is blocked (step 430).
White and black lists can be generated manually by both the system administrator or automatically on the basis of statistical and behavioral criteria. Examples of formation of and correction of these lists are, for example, in patent US 7640589. Under the behavioral criteria analysis can be considered the number of requests and sessions established with the same IP-address, the number of requests without confirmation from the same IP-address, the number of requests of the same type of data from a single IP URLs, the number of connections without the continued exchange of information.
Collector 310 performs statistical processing and aggregation of data traffic coming from the cleaning of 210 centers, as well as the collection of aggregate information from the sensors 330. This collector 310 performs a statistical generalization of legitimate traffic (both from cleaning centers 210 and 330 of the sensor) in the so-called "filter profile" (without the quotes below), according to which in case of attack center clean 210 the decision to filter spurious traffic. At the same time, the control unit 320 is able to adjust the active filtering profile that avoids false positives.
Center cleaning 210 is typically a separate server connected as close to the main channels on channels with a high bandwidth. In one embodiment, the purification center 210 may comprise a server 210a proxies and filtering router 210B to separate the functions, to achieve higher efficiency. Proxied server 210 redirects traffic to the service 130. The filtering router 210B decides to pass on this or that traffic on the basis of data transmitted from the reservoir 310 (ie, removal of parasitic traffic, which generate bots). Thus, the center clean 210 traffic filters A, leaving redirect traffic B only legitimate requests from regular users 220.
The sensors 330 are in close proximity to the 130 service, which is a mirror retraction traffic (shown on Figure 3 of another form of traffic arrow A), and perform statistical processing on the traffic data to aggregate traffic information for providing its collector 310.
It should be noted that the present system can work both during the DDoS-attacks, and outside of it (5). Outside attack operation of the system is aimed at gathering statistical information and tracking abnormalities (step 510). Collecting the statistical information is required to create a profile of the filtering (step 520). In the event of significant deviations of traffic in step 530 from the profile, the system switches to counter DDoS-attack and begins to filter traffic in steps 540-550. In step 560, it is checked whether the actual current profile filtering that creates manifold 310 and may be amended at step 570 by the control module 320, which has the necessary statistical information on the last known attack. When determining whether to end the attack stage 580, the algorithm returns to step 510.
In one embodiment, the filter profile is constructed in relation to traffic originating from a particular individual user resource and evaluates the parameters of such traffic for compliance with the calculated normal parameters. In order to detect anomalies profile is used anomaly detection, which is built against traffic directed towards resource and evaluates the overall parameters of the traffic for compliance with the threshold. To build a profile using the same set of data that is interpreted differently for both profiles.
The data are used to construct the profile have different levels of aggregation, which can analyze the input data at different levels.
Number level agregatsiiKlyuch latched znacheniyFiksiruemye znacheniya11) IP-address of the client of the protected resource 1) The number of bytes received 2) IP-address of the protected resursa2) Number of bytes sent 3) Protocol / Port (service) 3) The number of packets received 4) Tag time4) Number of sent packets 5) The number of packets received with a single flag set SYN (protocol TCP) 21) The country code for IP-address of the client protected resource1) Number of bytes received 2) IP-address of the protected resursa2) Number of bytes sent 3) Protocol / Port (service) 3 ) The number of packets received 4) Tag time4) Number of sent packets 5) Number of received packets with a single flag set SYN (protocol TCP) 6) Number of unique IP-addresses of clients protected resursa31) IP-address of the protected resource1) Number of bytes received 2) Protocol / port (service) 2) The number of bytes sent 3) Tag time.3) The number of packets received 4) The number of packets sent 5) Number of received packets with a single flag set SYN (protocol TCP) 6) Number of unique IP-addresses of clients protected resursa41) ID Group resources.1) Number of bytes received 2) protocol / port (service) 2) The number of bytes sent 3) Tag time.3) The number of packets received 4) The number of packets sent 5) Number of received packets with a single flag set SYN (protocol TCP) 6) Number unique IP-addresses of clients protected resursa51) ID klienta1) Number of bytes received 2) protocol / port (service) 2) The number of bytes sent 3) Tag time.3) The number of packets received 4) The number of packets sent 5) Number of received packets with only the SYN flag set (protocol TCP) 6) Number of unique IP-addresses of clients protected resource
6 illustrates the use of different levels of aggregation (in this example, 3 to 5), which monitors the data at different levels - from selected customer, and down to levels below the certain services. For example, it is possible not only to track statistics for Client 1, but also by one of its HTTP services such as site 1.
Viewing Anomaly Detection represents a set of threshold values of a quantity S, describing the normal traffic for one of the levels of aggregation (eg, client or service). The threshold value can be set for each hour of the day or certain days of the week to eliminate possible false positives. As the value of S can perform any of the latched values, such as the total number of inbound packets or the number of unique IP-addresses members.
This description sets out the basic inventive concept of the authors, who can not be limited by the hardware devices that were mentioned earlier. It should be noted that the hardware device is primarily intended to solve problems narrow. With the passage of time and technological progress, this problem is complicated and evolving. There are new tools, which are able to meet the new requirements. In this sense, the data should be considered hardware devices from the point of view of the class of solved technical problems, rather than purely technical implementation on a certain element base.
Contents4
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US9501742B2 | Cited by | United States of America | Applicant |
| RU2636640C2 | Cited by | Russian Federation | Search report |
| RU2685994C1 | Cited by | Russian Federation | Search report |
| RU2612275C1 | Cited by | Russian Federation | Search report |
| US10050993B2 | Cited by | United States of America | Applicant |
| RU2685989C1 | Cited by | Russian Federation | Search report |
| RU2675900C1 | Cited by | Russian Federation | Search report |
| RU2718650C1 | Cited by | Russian Federation | Search report |
| RU2644537C2 | Cited by | Russian Federation | Search report |
| US10574673B2 | Cited by | United States of America | Applicant |
| RU2679219C1 | Cited by | Russian Federation | Search report |
| RU2663473C1 | Cited by | Russian Federation | Search report |
| US20100162350A1 | Cites | United States of America | – |
| US7058015B1 | Cites | United States of America | – |
| RU2364933C2 | Cites | Russian Federation | – |
| RU2277261C1 | Cites | Russian Federation | – |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2011115361 | Russian Federation | A | |
| RU20110115361 | – | – | – |
Numbers
- Publication
- 0002480937
- Publication, DOCDB
- 2480937
- Publication, EPODOC
- RU2480937
- Application
- 11536108
- Application, DOCDB
- 2011115361
- Application, EPODOC
- RU20110115361
Titles2
- English
- SYSTEM AND METHOD OF REDUCING FALSE RESPONSES WHEN DETECTING NETWORK ATTACK
- Russian
- ??????? ? ?????? ?????????? ?????? ???????????? ??? ??????????? ??????? ?????