Flow statistical method and device, vehicle and storage medium
By mounting the hook function on the network protocol stack of the terminal device, the traffic data corresponding to the target IP address of the network message is obtained and statistics, the problem of difficulty in accurately managing network service traffic in the prior art is solved, and traffic statistics and management based on IP addresses are realized, which improves the accuracy and efficiency of traffic management.
Patent Information
- Application Number
- CN202510331510.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-06-06
AI Technical Summary
It is difficult for the prior art to accurately identify and manage specific services or resources in the application in network service traffic management, which makes it difficult to achieve accurate flow-free traffic for system-type traffic in scenarios such as on-board terminals, and the list of flow-free applications is updated slowly, which may lead to problems such as traffic stolen.
By pre-mounting the hook function on the network protocol stack of the terminal device, all messages flowing into or out of the network protocol stack are obtained, and their target IP address is determined for each message, and the uplink and downlink packet length statistics of each target IP address are counted, so that traffic statistics based on the IP address dimension can be realized.
It realizes accurate monitoring and management of network traffic of terminal equipment, avoids traffic data omissions, simplifies traffic statistics process, improves statistical efficiency, and better meets the needs of network traffic management and analysis.
Smart Images

Figure CN120110995A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of communication technology, and are related to but not limited to a traffic statistics method and device, a vehicle, and a storage medium. Background Art
[0002] With the continuous development of Internet technology and terminal equipment, the types of services that users obtain through the Internet, such as video, audio, games, and information, are gradually increasing. In order to lower the threshold for users to use various network services and enhance the stickiness of service products, network service providers and operators can adopt a strategy of providing directional traffic for designated services or implementing free traffic to improve user experience and promote the promotion and use of services.
[0003] In related technologies, traffic management of network services is often performed on an application-by-application basis. For example, after negotiation between network service providers and operators, directional traffic or free traffic services can be provided for specific applications, such as designated video service applications, to attract users to use these applications. However, with the diversification and complexity of network services, a single application may indirectly access other services through web page jumps, embedded services, or third-party resource calls, making it difficult to accurately identify traffic attribution. Summary of the invention
[0004] In view of this, the traffic statistics method and device, vehicle, and storage medium provided in the embodiments of the present application can determine the corresponding uplink message length statistics and downlink message length statistics for each target IP address, thereby realizing traffic statistics based on the IP address dimension. The traffic statistics method and device, vehicle, and storage medium provided in the embodiments of the present application are realized as follows:
[0005] The first aspect of the present application provides a traffic statistics method, which is applied to a terminal device, including:
[0006] Acquire multiple messages flowing into or out of the network protocol stack through a hook function pre-mounted by the network protocol stack of the terminal device;
[0007] For each acquired message, acquire a target IP address and a message length corresponding to the message, wherein, when the message is a message flowing into the network protocol stack, the target IP address is the source IP address of the message, and when the message is a message flowing out of the network protocol stack, the target IP address is the destination IP address of the message;
[0008] For each target IP address obtained, the uplink message length statistics and downlink message length statistics corresponding to the target IP address are counted, wherein the uplink message length statistics are the sum of the message lengths of all messages whose destination IP address is the target IP address among the multiple messages, and the downlink message length statistics are the sum of the message lengths of all messages whose source IP address is the target IP address among the multiple messages.
[0009] As an optional implementation manner, in the first aspect of the embodiment of the present application, the method further includes:
[0010] Obtain a first domain name mapping relationship, wherein the first domain name mapping relationship includes a mapping relationship between a domain name and an IP address, and each domain name corresponds to at least one IP address;
[0011] After counting the uplink message length statistics and the downlink message length statistics corresponding to each target IP address obtained, the method further includes:
[0012] Determine the target domain name corresponding to each target IP address according to the first domain name mapping relationship;
[0013] For each target domain name, the uplink domain name traffic statistics and downlink domain name traffic statistics corresponding to the target domain name are counted, wherein the uplink domain name traffic statistics are the sum of the uplink message length statistics of all target IP addresses corresponding to the target domain name, and the downlink domain name traffic statistics are the sum of the downlink message length statistics of all target IP addresses corresponding to the target domain name.
[0014] As an optional implementation manner, in the first aspect of the embodiment of the present application, after counting the uplink domain name traffic statistics and the downlink domain name traffic statistics corresponding to each target domain name, the method further includes:
[0015] Calculate the sum of the uplink domain name traffic statistics value and the downlink domain name traffic statistics value corresponding to each target domain name to obtain the total domain name traffic statistics value corresponding to each target domain name;
[0016] The target statistical value corresponding to each target domain name is sent to the platform server, wherein the target statistical value includes at least one of an uplink domain name traffic statistical value, a downlink domain name traffic statistical value or a total domain name traffic statistical value.
[0017] As an optional implementation manner, in the first aspect of the embodiment of the present application, the method further includes:
[0018] According to a preset second domain name mapping relationship, a target domain name category corresponding to each target domain name is obtained, wherein the preset second domain name mapping relationship includes a mapping relationship between a domain name and a domain name category;
[0019] Count the category traffic statistics corresponding to each target domain name category.
[0020] As an optional implementation manner, in the first aspect of the embodiment of the present application, obtaining the target domain name category corresponding to each target domain name according to the preset second domain name mapping relationship includes:
[0021] For each target domain name, when the second domain name mapping relationship includes the mapping relationship of the target domain name, determine that the target domain name category corresponding to the target domain name is the domain name category indicated by the second domain name mapping relationship; or, when the second domain name mapping relationship does not include the mapping relationship of the target domain name, determine that the target domain name category corresponding to the target domain name is the preset domain name category.
[0022] As an optional implementation manner, in the first aspect of the embodiment of the present application, the method further includes:
[0023] All target domain names are sorted according to target sorting parameters, and a sorting result is output, wherein the target sorting parameters include an upstream domain name traffic statistics value, a downstream domain name traffic statistics value, or a total domain name traffic statistics value.
[0024] As an optional implementation manner, in the first aspect of the embodiment of the present application, obtaining the first domain name mapping relationship includes:
[0025] For each target domain name, the IP address set corresponding to the target domain name is obtained through the target server, thereby obtaining the first domain name mapping relationship. The target server includes an HTTPDNS server or an operator DNS server, and the IP address set includes at least one IP address corresponding to the target domain name.
[0026] A second aspect of the present application provides a flow statistics device, including:
[0027] An acquisition module, used to acquire a plurality of messages flowing into or out of the network protocol stack through a hook function pre-mounted by the network protocol stack of the device;
[0028] A message processing module, used for obtaining, for each acquired message, a target IP address and a message length corresponding to the message, wherein, when the message is a message flowing into the network protocol stack, the target IP address is the source IP address of the message, and when the message is a message flowing out of the network protocol stack, the target IP address is the destination IP address of the message;
[0029] A statistical module is used to count the uplink message length statistics and downlink message length statistics corresponding to each acquired target IP address, wherein the uplink message length statistics is the sum of the message lengths of all messages whose destination IP address is the target IP address among the multiple messages, and the downlink message length statistics is the sum of the message lengths of all messages whose source IP address is the target IP address among the multiple messages.
[0030] A third aspect of the present application provides a vehicle, the vehicle comprising the flow statistics device provided in the second aspect of the embodiment of the present application.
[0031] A fourth aspect of the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method described in the first aspect of the present application.
[0032] Compared with the related art, the embodiments of the present application have at least the following beneficial effects:
[0033] The traffic statistics method applied to terminal devices provided by the present application, first, can obtain all messages flowing into or out of the network protocol stack through the hook function pre-mounted by the network protocol stack, ensure the comprehensiveness of traffic statistics, and avoid missing traffic data. Then, for each message obtained, the corresponding target IP address is determined by its inflow or outflow direction, so that the message length of each message is attributed to the specified direction of the corresponding target IP address. Then, for multiple target IP addresses obtained by multiple messages, the statistics of the uplink and downlink message lengths corresponding to each target IP address are counted to reflect the traffic used by the terminal device to access each target IP address, and realize traffic statistics based on the IP address dimension, which provides data basis for the management of network traffic and helps to implement refined traffic management strategies. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] The drawings herein are incorporated into the specification and constitute a part of the specification. These drawings illustrate embodiments consistent with the present application and are used together with the specification to illustrate the technical solution of the present application.
[0035] Figure 1 A schematic diagram of an application scenario of the traffic statistics method provided in an embodiment of the present application;
[0036] Figure 2 A flow chart of a traffic statistics method provided in an embodiment of the present application;
[0037] Figure 3 A schematic diagram of a message and a target IP address provided in an embodiment of the present application;
[0038] Figure 4 Another flow chart of the flow statistics method provided in the embodiment of the present application;
[0039] Figure 5 A schematic diagram of obtaining a first domain name mapping relationship provided in an embodiment of the present application;
[0040] Figure 6 A schematic diagram of obtaining domain name traffic statistics of a target domain name provided in an embodiment of the present application;
[0041] Figure 7 A schematic diagram of sending a target statistical value to a platform server in the traffic statistics method provided in an embodiment of the present application;
[0042] Figure 8 A schematic diagram of another flow chart of the traffic statistics method provided in the embodiment of the present application;
[0043] Fig. 9 A schematic diagram of the structure of a flow statistics device provided in an embodiment of the present application;
[0044] Fig.10 A schematic diagram of the structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0045] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the specific technical solution of the present application will be further described in detail below in conjunction with the drawings in the embodiments of the present application. The following embodiments are used to illustrate the present application, but are not used to limit the scope of the present application.
[0046] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.
[0047] In the following description, reference is made to “some embodiments”, which describe a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.
[0048] It should be pointed out that the terms "first\second\third" involved in the embodiments of the present application are used to distinguish similar or different objects, and do not represent a specific ordering of the objects. It can be understood that "first\second\third" can be interchanged in a specific order or sequence where permitted, so that the embodiments of the present application described here can be implemented in an order other than that illustrated or described here.
[0049] With the continuous development of Internet technology and terminal equipment, the types of services that users can obtain through the Internet are gradually increasing. In order to lower the threshold for users to use various network services and enhance the stickiness of service products, network service providers and operators can adopt strategies such as providing directional traffic for designated services or implementing free traffic to improve user experience and promote the promotion and use of services.
[0050] In related technologies, traffic management of network services is usually performed on an application-by-application basis. When executing traffic management strategies such as directional traffic or free traffic, only specific applications can be managed, and specific services or resources within the application cannot be accurately identified and managed. This results in some scenarios, such as vehicle-mounted terminal networking scenarios, where free traffic measures can only be implemented for some applications, and it is difficult to accurately implement free traffic for system-class traffic (such as navigation, vehicle remote control, etc.) according to service categories.
[0051] In addition, when traffic management is performed on an application-by-application basis, the list of free-flow applications may be updated slowly, resulting in services that should be free-flow not being able to enjoy the free-flow policy in a timely manner, resulting in traffic leakage and other situations, affecting user experience. Alternatively, users in free-flow applications may exempt different types of traffic through web page jumps, embedded services, or third-party resource calls, increasing operating costs.
[0052] In view of this, an embodiment of the present application provides a traffic statistics method, which is applied to a terminal device and can determine the corresponding uplink message length statistics and downlink message length statistics for each target IP address, thereby realizing traffic statistics based on the IP address dimension.
[0053] It should be noted that the terminal device in the embodiment of the present application may include but is not limited to mobile phones, wearable devices (such as smart watches, smart bracelets, smart glasses, etc.), tablet computers, laptops, vehicle terminals, PCs (Personal Computers), etc. The functions implemented by the method can be implemented by calling program codes by the processor in the terminal device. Of course, the program codes can be stored in a computer storage medium. It can be seen that the terminal device at least includes a processor and a storage medium.
[0054] An application scenario of the traffic statistics method provided in an embodiment of the present application will be introduced below to facilitate understanding of the traffic statistics method provided in the present application.
[0055] See also Figure 1 , Figure 1 A schematic diagram of an application scenario of the traffic statistics method provided in the embodiment of the present application, such as Figure 1 As shown, the terminal device 10 can be connected to a network device such as a router or a modem ( Figure 1The terminal device 10 may connect to the Internet 20 (not shown) and selectively establish connections with servers of different service providers in the Internet according to actual needs of the user. The Internet 20 may include multiple servers of multiple service providers. For example, the terminal device 10 may communicate with the server 21 (such as a server of a video streaming service provider) to obtain or transmit specific service data and generate corresponding traffic data.
[0056] In some possible embodiments, when the terminal device 10 is a vehicle-mounted terminal, as shown in FIG. Figure 1 The application scenario shown may also include a platform server, which is used to obtain traffic statistics of the terminal device 10 and then perform corresponding billing operations for designated categories of traffic, such as entertainment traffic.
[0057] In the related art, traffic statistics and management of the terminal device 10 are usually based on applications as the basic unit, and traffic management strategies are implemented for designated applications. For example, a user can purchase a directional traffic package for a designated application A from an operator, agreeing that the traffic generated by application A is not included in the total amount of the user package. In this case, the terminal device 10 can mark the communication interface (socket) of application A and / or the application message sent by application A with the user identifier (UID) of application A, and then report the traffic based on the tag. However, although this traffic statistics method can separately count the traffic of different applications in the terminal device 10, since the application itself may simultaneously have multiple types of traffic such as entertainment traffic and system traffic, it is difficult to classify the traffic generated by the terminal device 10 in detail according to the type of traffic.
[0058] Through the method provided by this application, traffic statistics based on the IP address dimension can be achieved without relying on the UID of each application. In this way, statistics of different traffic categories can be achieved by simply determining the traffic category corresponding to each IP address. Moreover, there is no need to mark each message, which simplifies the traffic statistics process, improves statistical efficiency, makes traffic statistics more accurate and convenient, and can better meet the needs of network traffic management and analysis, providing users with a better and more accurate network service experience.
[0059] The following is an introduction to an implementation process of the traffic statistics method provided in an embodiment of the present application.
[0060] See also Figure 2 , Figure 2 A flow chart of a traffic statistics method provided in an embodiment of the present application, which can be applied to terminal devices, such as Figure 2 As shown, the method may include the following steps:
[0061] S201, obtaining multiple messages flowing into or out of the network protocol stack through a hook function pre-mounted by the network protocol stack of the terminal device.
[0062] In an embodiment of the present application, the terminal device can obtain multiple messages flowing into or out of the network protocol stack through a hook function pre-mounted on the network protocol stack.
[0063] It should be noted that a hook function is a function used in computer programming to monitor and process specific events. It allows developers to intercept and modify certain behaviors in the system or application to implement customized functions. Hook functions are usually used for the expansion, debugging and optimization of operating systems or applications. Hook functions can be dynamically mounted during the initialization phase of the network protocol stack to ensure that the data of the original message (such as IP header, transport layer protocol type, port number, etc.) is captured in real time during the routing, encapsulation or disassembly process without the need to deeply parse the data content of the message payload (such as data related to network services).
[0064] In some possible embodiments, a hook function may be mounted in the network protocol stack of the terminal device kernel through the eBPF mechanism. The eBPF mechanism is a technology that can run sandbox programs in the kernel, and provides a mechanism for safely injecting code when kernel events and user program events occur, so that non-kernel developers can also control the kernel.
[0065] In some possible embodiments, the hook function may also be mounted through the netfilter framework. The netfilter framework is a framework in the Linux kernel that is used to implement functions such as custom packet filtering, network address translation (NAT), and connection tracking, allowing developers to insert custom code into the kernel's network processing path. This application does not limit the way the hook function is mounted.
[0066] In the embodiment of the present application, the terminal device can be a device running Android or other Linux-based operating systems, the network protocol stack of the terminal device can be a TCP / IP protocol stack, and the multiple messages flowing into or out of the TCP / IP protocol stack obtained by the hook function can be various types of data messages, such as HTTP messages, FTP messages, SMTP messages and other application layer protocol messages, or TCP messages, UDP messages and other transport layer protocol messages, or IP messages, ICMP messages and other network layer protocol messages, which are not limited here. By analyzing and processing these messages, accurate monitoring, management and optimization of the network traffic of the terminal device can be achieved.
[0067] Messages flowing into or out of the network protocol stack of a terminal device will occupy certain network resources and generate traffic charges corresponding to the length of the message. Among them, messages flowing into the network protocol stack, that is, data transmission sent from the network to the terminal device, can be called downlink traffic. Messages flowing out of the network protocol stack, that is, data transmission sent from the terminal device to the network, can be called uplink traffic.
[0068] By calculating the total message length of all messages flowing into and out of the network protocol stack, the total traffic consumed by the terminal device can be obtained. The method provided in the embodiment of the present application can calculate the traffic usage corresponding to each IP address separately to implement a refined traffic management strategy.
[0069] S202: For each acquired message, acquire the target IP address and message length corresponding to the message.
[0070] In the embodiment of the present application, the target IP address of each message refers to the source IP address of the message when the message is a message flowing into the network protocol stack, and the destination IP address of the message when the message is a message flowing out of the network protocol stack. Each IP address can be in IPv4 or IPv6 format, which is not limited here.
[0071] For any message obtained by the hook function, if the message is a message flowing out of the network protocol stack, then the destination IP address of the message is the IP address of the network service provider. For example, when the user of the terminal device requests to watch a video on a video website, the destination IP address of the message flowing out of the network protocol stack can be the IP address of the server of the video website. If the message is a message flowing into the network protocol stack, then the source IP address of the message is the IP address of the network service provider. For example, when the terminal device receives video data sent by the video website, the source IP address of the message flowing into the network protocol stack can be the IP address of the server of the video website.
[0072] It should be noted that, during the use of the terminal device, the target IP address of any message may also become the target IP address of other messages. At the same time, for any specific target IP address, it may appear as a source IP address or a destination IP address in different messages, depending on the flow direction of the message, which is not limited here.
[0073] In some possible embodiments, the target IP address and message length corresponding to each message can be obtained and stored through a preset function. The message header usually contains key information such as the source IP address and the destination IP address. By parsing this information through a preset function, the target IP address corresponding to the message can be obtained. At the same time, the message length of the message can be obtained by reading the length field in the message header or calculating according to the protocol format of the message.
[0074] Optionally, the preset function may be a function mounted on the network protocol stack of the terminal device kernel, or may be implemented as a component of a hook function, which is not limited here.
[0075] S203: For each acquired target IP address, statistics are collected on the uplink message length statistics and the downlink message length statistics corresponding to the target IP address.
[0076] In the embodiment of the present application, after obtaining the target IP address and message length corresponding to each message, the uplink message length statistics and downlink message length statistics corresponding to each target IP address can be counted. The uplink message length statistics are the sum of the message lengths of all messages whose destination IP address is the target IP address among multiple messages, and the downlink message length statistics are the sum of the message lengths of all messages whose source IP address is the target IP address among multiple messages.
[0077] For each target IP address, by accumulating the message lengths of all messages whose destination IP address is the target IP address in the multiple messages obtained by the hook function, the statistical value of the uplink message length corresponding to the target IP address can be obtained, reflecting the total amount of data sent by the terminal device to the target IP address. By accumulating the message lengths of all messages whose source IP address is the target IP address in the multiple messages obtained by the hook function, the statistical value of the downlink message length corresponding to the target IP address can be obtained, reflecting the total amount of data received by the terminal device from a specific target IP address. By performing the same operation on each target IP address, the statistical value of the uplink message length and the statistical value of the downlink message length corresponding to each target IP address can be obtained. It is helpful to understand the amount of data downloaded or uploaded by the terminal device from a specific network service, evaluate the traffic usage of the terminal device, etc.
[0078] In some possible embodiments, the multiple packets obtained by the hook function exist in the form of sk_buff structure skb, and the IP statistics field in the hook function can be defined as:
[0079] StatsMap <string ip,map<int txBytes,intrxBytes> >value.
[0080] Use the map container to save the statistics of the uplink message length (txBytes) and the downlink message length (rxBytes) of each target IP address. After the hook function obtains any message, for the tx message flowing out of the network protocol stack, obtain the destination IP address of the tx message as the target IP address, calculate the message length of the tx message, and add its length to the txBytes corresponding to the target IP address of the tx message. For the rx message flowing into the network protocol stack, obtain the source IP address of the rx message as the target IP address, calculate the message length of the rx message, and add its length to the rxBytes corresponding to the target IP address of the rx message.
[0081] It should be noted that the hook function can count the uplink message length statistics and downlink message length statistics corresponding to each target IP address in real time.
[0082] Optionally, the uplink message length statistics and downlink message length statistics corresponding to each target IP address may be cleared according to a preset period, such as one week or one month, so as to restart counting traffic data in a new period.
[0083] See also Figure 3 , Figure 3 A schematic diagram of a message and a target IP address provided in an embodiment of the present application, such as Figure 3 As shown in the figure, within a period of time, there are 5 messages flowing into or out of the network protocol stack of the terminal device, among which messages 1, 3 and 4 flow out of the network protocol stack, and messages 2 and 5 flow into the network protocol stack. By obtaining the target IP address and message length corresponding to each message, it can be known that the target IP address corresponding to message 1 is target IP address A, and the message length is 110 bytes. The target IP address corresponding to message 2 is target IP address B, and the message length is 120 bytes. The target IP address corresponding to message 3 is target IP address C, and the message length is 90 bytes. The target IP address corresponding to message 4 is target IP address B, and the message length is 140 bytes. The target IP address corresponding to message 5 is target IP address A, and the message length is 80 bytes.
[0084] Taking the target IP address A as an example, through the traffic statistics method provided by the embodiment of the present application, the destination IP address is the target IP address A, and the source IP address is the target IP address A, and the message is message 5. Therefore, the statistical value of the uplink message length corresponding to the target IP address A is 110 bytes, and the statistical value of the downlink message length corresponding to the target IP address A is 80 bytes. Figure 3It can be seen that the uplink message length statistics corresponding to the target IP address B is 140 bytes, and the downlink message length statistics is 120 bytes. The uplink message length statistics corresponding to the target IP address C is 90 bytes, and the downlink message length statistics is zero.
[0085] It is understandable that different target IP addresses correspond to network devices of different service providers in the network. By obtaining the uplink message length statistics and downlink message length statistics corresponding to each target IP address, the communication status between the terminal device and different network devices can be understood, providing data basis for network optimization and traffic management.
[0086] For example, in the case where the terminal device is an on-board terminal of a vehicle, through the traffic statistics method provided in the embodiment of the present application, the on-board terminal can obtain the uplink message length statistics and downlink message length statistics corresponding to different IP addresses of different network services when its users use network services, so that the manufacturer or operator of the on-board terminal can perform network optimization and traffic management based on these data, such as implementing different traffic billing strategies according to different IP addresses.
[0087] In the traffic statistics method provided in the embodiment of the present application, first, through the hook function pre-mounted by the network protocol stack, all messages flowing into or out of the network protocol stack can be obtained to ensure the comprehensiveness of traffic statistics and avoid missing traffic data. Then, for each message obtained, the corresponding target IP address is determined by its inflow or outflow direction, so that the message length of each message is attributed to the specified direction of the corresponding target IP address. Next, for multiple target IP addresses obtained by multiple messages, the statistics of the uplink and downlink message lengths corresponding to each target IP address are counted to reflect the traffic used by the terminal device to access each target IP address, and to achieve traffic statistics based on the IP address dimension, which provides a data basis for the management of network traffic and helps to implement refined traffic management strategies.
[0088] The following describes how to obtain the uplink domain name traffic statistics and downlink domain name traffic statistics corresponding to different domain names after obtaining the uplink message length statistics and downlink message length statistics corresponding to each target IP address in an embodiment of the present application, so as to realize traffic statistics in the domain name dimension.
[0089] See also Figure 4 , Figure 4 Another flow chart of the flow statistics method provided in the embodiment of the present application, the flow statistics method can be applied to terminal devices, such as Figure 4 As shown, the method may include the following steps:
[0090] S401, obtaining multiple messages flowing into or out of the network protocol stack through a hook function pre-mounted by the network protocol stack of the terminal device.
[0091] S402: For each acquired message, acquire the target IP address and message length corresponding to the message.
[0092] S403: For each acquired target IP address, statistics are collected on the uplink message length statistics and the downlink message length statistics corresponding to the target IP address.
[0093] It should be noted that steps S401 to S403 are similar to steps S201 to S203 and will not be described in detail here.
[0094] S404: Determine a target domain name corresponding to each target IP address according to the first domain name mapping relationship.
[0095] In some possible embodiments, the traffic statistics method provided in the embodiments of the present application further includes:
[0096] A first domain name mapping relationship is obtained, wherein the first domain name mapping relationship includes a mapping relationship between a domain name and an IP address, and each domain name corresponds to at least one IP address.
[0097] It should be noted that since domain names are easier to remember and use than IP addresses, terminal devices usually use domain names to address when accessing network services on the Internet. During the addressing process, the terminal device resolves the domain name into a corresponding IP address through a Domain Name System (DNS) server so that the relevant message data can be accurately sent to the network service server.
[0098] In addition, to ensure smooth network operation, each domain name can correspond to multiple IP addresses to improve network availability and load balancing capabilities. In this way, when a certain IP address is inaccessible, DNS can automatically forward user requests to other available IP addresses, thereby ensuring that users can continue to access network services or resources.
[0099] The method provided in the embodiment of the present application can associate the uplink message length statistics and the downlink domain name statistics corresponding to each target IP address with each other by acquiring the first mapping relationship, thereby realizing traffic statistics in the domain name dimension.
[0100] Optionally, the first domain name mapping relationship can be pre-stored in the terminal device. For some terminal devices with more specific functions, such as smart home devices, dedicated terminals for specific industries, etc., they may frequently access a relatively fixed set of network services or resources. Therefore, the first domain name mapping relationship between the domain names corresponding to these services or resources and the IP addresses is pre-stored in the terminal device, and the domain name mapping relationship can be directly obtained locally without having to resolve it through the domain name DNS server every time, thereby reducing the delay of DNS queries and improving access speed.
[0101] Optionally, the first domain name mapping relationship can be dynamically recorded each time the terminal device accesses a network service or resource. Due to the constant changes in the network environment, for example, the IP address corresponding to the domain name may change due to server migration, load balancing policy adjustment, or DNS record update. Therefore, in order to ensure the accuracy and timeliness of the domain name mapping relationship, the terminal device needs to re-acquire and update the stored domain name mapping relationship at every preset time interval. Exemplarily, the terminal device can record the IP address currently resolved to the domain name each time a domain name is successfully accessed, and update the first domain name mapping relationship.
[0102] In some possible embodiments, obtaining the first domain name mapping relationship includes:
[0103] For each target domain name, the IP address set corresponding to the target domain name is obtained through the target server, thereby obtaining the first domain name mapping relationship. The target server includes an HTTPDNS server or an operator DNS server, and the IP address set includes at least one IP address corresponding to the target domain name.
[0104] It should be noted that the DNS server may include an HTTP DNS server or an operator DNS server, wherein the operator DNS server is a DNS service provided by a network operator, and the HTTP DNS server is a DNS service based on the HTTP protocol, which can be selected according to actual needs and is not limited here.
[0105] When a terminal device accesses the Internet, it must first perform DNS resolution on the target server to obtain the resolution result, that is, convert the domain name into an IP address. These resolution results can be saved to form a set of IP addresses corresponding to each domain name. Ultimately, these sets constitute the first domain name mapping relationship required for domain name dimension traffic statistics.
[0106] See also Figure 5 , Figure 5 A schematic diagram of obtaining a first domain name mapping relationship provided in an embodiment of the present application, such as Figure 5As shown, when the terminal device needs to access the network service, its built-in network module (the module responsible for processing network communications) will send a resolution request for the target domain name to the target server. The target server here can be an HTTPDNS server or an operator DNS server. After receiving the resolution request, the target server will communicate with the server of the network service to query and obtain the IP address corresponding to the target domain name. After completing the query, the target server will send the resolution result to the network module of the terminal device. It should be noted that when the target server is an HTTPDNS server, the HTTPDNS server will first send the resolution result to the network process of the terminal device, and then the network process will forward the resolution result to the DNS manager (DNS-Manager, DNS-mgr). In the end, whether through the operator DNS server or the HTTPDNS server, the terminal device can obtain the IP address corresponding to the target domain name, and save these resolution results to the DNS manager to form a mapping relationship between the domain name and the IP address, that is, the first domain name mapping relationship.
[0107] After obtaining the first domain name mapping relationship, the target domain name corresponding to each target IP address can be obtained. Since each domain name may be associated with multiple IP addresses, in the first domain name mapping relationship, each unique target IP address uniquely corresponds to a target domain name, and a target domain name may correspond to multiple target IP addresses.
[0108] S405: For each target domain name, statistics are collected on the uplink domain name traffic statistics and the downlink domain name traffic statistics corresponding to the target domain name.
[0109] It is understandable that an application may access multiple domain names during operation, and these domain names may belong to different categories. For example, when using office applications, they may access the domain names corresponding to video, audio and other services through web page jumps, embedded services or third-party resource calls, making it impossible to accurately know the traffic consumption of each service category, and thus it is difficult to implement traffic management strategies such as free traffic or providing directional traffic for services of specified categories.
[0110] In some possible embodiments, after obtaining the first domain name mapping relationship and the uplink message length statistics and downlink message length statistics corresponding to each target IP address, the traffic usage of each target domain name can be counted to realize traffic statistics in the domain name dimension, wherein the uplink domain name traffic statistics value is the sum of the uplink message length statistics values of all target IP addresses corresponding to the target domain name, and the downlink domain name traffic statistics value is the sum of the downlink message length statistics values of all target IP addresses corresponding to the target domain name.
[0111] See also Figure 6 , Figure 6 A schematic diagram of obtaining domain name traffic statistics of a target domain name provided in an embodiment of the present application, such as Figure 6 As shown, in one embodiment, according to the first domain name mapping relationship, the target IP addresses corresponding to the target domain name A include target IP address A, target IP address B and target IP address C. According to the uplink message length statistics and downlink message length statistics corresponding to each target IP address, the uplink domain name traffic statistics corresponding to the target domain name A can be obtained as 16000 bytes, and the downlink domain name traffic statistics are 18000 bytes.
[0112] In this way, the traffic consumption of each domain name can be accurately grasped, providing data support for the formulation of more refined traffic management strategies. For example, traffic restrictions, priority adjustments, or cost optimization measures can be implemented for specific domain names.
[0113] In some possible embodiments, after counting the uplink domain name traffic statistics and the downlink domain name traffic statistics corresponding to each target domain name, the method further includes:
[0114] Calculate the sum of the uplink domain name traffic statistics value and the downlink domain name traffic statistics value corresponding to each target domain name to obtain the total domain name traffic statistics value corresponding to each target domain name;
[0115] The target statistical value corresponding to each target domain name is sent to the platform server, wherein the target statistical value includes at least one of an uplink domain name traffic statistical value, a downlink domain name traffic statistical value or a total domain name traffic statistical value.
[0116] It should be noted that when performing traffic billing, both the uplink and downlink traffic of the terminal device will be included in the billing scope. Therefore, for each target domain name, the sum of the uplink domain name traffic statistics and the downlink domain name traffic statistics of the target domain name can be calculated to obtain the corresponding domain name traffic statistics, so that users can more comprehensively and accurately understand the traffic usage corresponding to each target domain name and arrange network usage reasonably. At the same time, it is convenient for operators or service providers to perform traffic billing.
[0117] In addition, after the terminal device obtains the uplink domain name traffic statistics, downlink domain name traffic statistics, and total domain name traffic statistics corresponding to each target domain name, these statistics can be sent to the platform server according to actual needs, so that the platform server can perform traffic billing or further analysis and processing based on the obtained statistics. For example, the platform server can generate a traffic usage report based on these statistics, provide users with detailed traffic usage analysis, and help users better manage network resources. At the same time, the platform server can also use these statistics to perform network optimization and traffic scheduling to improve network performance and user experience.
[0118] See also Figure 7 , Figure 7 A schematic diagram of sending a target statistical value to a platform server in the traffic statistics method provided in an embodiment of the present application.
[0119] In some possible embodiments, Figure 7 As shown, sending the target statistical value corresponding to each target domain name to the platform server may include:
[0120] Through the hook function of the network protocol stack mounted on the kernel of the terminal device, multiple messages flowing into or out of the network protocol stack are obtained, and then the data processed by the hook function, such as the target IP address of each message, the message length or the calculated message length statistics, are sent to the statistical algorithm of the DNS manager outside the kernel. The target statistical value of each target domain name can be obtained by the statistical algorithm, and then the target statistical value obtained by the statistical algorithm is sent to the trafficStats middleware through the DNS manager, and then the trafficStats middleware sends the target statistical value to the traffic tracking APP, and finally the target statistical value is sent to the platform server through the traffic tracking APP.
[0121] It should be noted that the trafficStats middleware is a tool class used to count network traffic in the system. It provides multiple static methods for obtaining network traffic data of applications, including the number of bytes sent and received and traffic statistics. The traffic tracking APP is an application used to collect and send traffic data. It can obtain traffic data from the trafficStats middleware and send it to the platform server for further analysis and processing.
[0122] Optionally, in addition to the target statistics corresponding to each target domain name, you can also use Figure 7 The structure shown sends other traffic-related information to the platform server, such as the message length statistics corresponding to each target IP address, the traffic ranking between each target domain name, etc., which are not limited here.
[0123] In some possible embodiments, the hook function can obtain the packets flowing into or out of the network protocol stack in real time, and count the packet length statistics corresponding to each target IP address. The DNS manager can obtain data from the hook function of the network protocol stack according to a preset first interval, and the trafficStats middleware can obtain data from the DNS manager according to a preset second interval.
[0124] Optionally, the preset second interval may be greater than the preset first interval. Exemplarily, the preset first interval may be two minutes, and the preset second interval may be 10 minutes, so as to reduce the pressure of data processing and meet the monitoring and management requirements of different levels.
[0125] In some possible embodiments, the traffic statistics method provided in the embodiments of the present application further includes:
[0126] All target domain names are sorted according to target sorting parameters, and a sorting result is output, wherein the target sorting parameters include an upstream domain name traffic statistics value, a downstream domain name traffic statistics value, or a total domain name traffic statistics value.
[0127] It should be noted that the terminal device can output the sorting results through a display screen, sound prompts, or a network interface, so that the user can intuitively view the traffic usage ranking of each target domain name. For example, the terminal device can display the sorting results in the form of a list through a display screen, and the list can include information such as the target domain name, the corresponding upstream domain name traffic statistics, downstream domain name traffic statistics, and the total domain name traffic statistics, which helps users discover potential traffic anomalies or help users plan traffic usage.
[0128] By implementing the above technical solution, traffic statistics based on the domain name dimension are realized by obtaining the message status flowing into or out of the network protocol stack in real time, and the target statistical value of each target domain name can be sent to the platform server according to actual needs, so as to monitor the traffic statistics of each target domain name.
[0129] The following describes how to collect statistics on traffic of different domain name categories in an embodiment of the present application.
[0130] See also Figure 8 , Figure 8 Another flow chart of the flow statistics method provided in the embodiment of the present application is provided. The flow statistics method can be applied to terminal devices, such as Figure 8 As shown, the method may include the following steps:
[0131] S801, obtaining multiple messages flowing into or out of the network protocol stack through a hook function pre-mounted by the network protocol stack of the terminal device.
[0132] S802: For each acquired message, acquire the target IP address and message length corresponding to the message.
[0133] S803: For each acquired target IP address, statistics are collected on the uplink message length statistics and the downlink message length statistics corresponding to the target IP address.
[0134] S804: Determine the target domain name corresponding to each target IP address according to the first domain name mapping relationship.
[0135] S805: For each target domain name, count the uplink domain name traffic statistics and the downlink domain name traffic statistics corresponding to the target domain name.
[0136] It should be noted that steps S801 to S805 are similar to steps S401 to S405 and will not be described in detail here.
[0137] S806: Obtain a target domain name category corresponding to each target domain name according to a preset second domain name mapping relationship.
[0138] In some possible embodiments, the preset second domain name mapping relationship includes a mapping relationship between a domain name and a domain name category.
[0139] By determining the target domain name category corresponding to each target domain name, traffic statistics and management of domain names of different categories can be achieved. For example, the domain name categories can include video, audio, office, social, etc., and then the traffic is classified and counted according to these categories. In this way, users, operators or service providers can negotiate according to actual needs to implement exemptions or separate billing for the traffic of the specified domain name category, which improves the flexibility and accuracy of traffic management compared to the traffic statistics method based on applications.
[0140] In some possible embodiments, obtaining the target domain name category corresponding to each target domain name according to the preset second domain name mapping relationship includes:
[0141] For each target domain name, when the second domain name mapping relationship includes the mapping relationship of the target domain name, the target domain name category corresponding to the target domain name is determined to be the domain name category indicated by the second domain name mapping relationship; or, when the second domain name mapping relationship does not include the mapping relationship of the target domain name, the target domain name category corresponding to the target domain name is determined to be the preset domain name category.
[0142] It is understandable that there are many domain names on the Internet and new domain names are constantly appearing. In the process of traffic statistics, some target domain names may not be included in the second domain name mapping relationship. In this case, those target domain names that cannot find the corresponding domain name category in the second domain name mapping relationship can be uniformly determined as the preset domain name category. Ensure that all target domain names can be reasonably classified for subsequent traffic statistics and management.
[0143] Optionally, the preset domain name category can be "other" or "unknown", and after the platform server obtains the target domain name of the preset domain name category, it can be reclassified and managed through manual or algorithmic identification. For example, if the platform server finds that a target domain name classified as "unknown" actually belongs to a specific domain name category, it can remove the target domain name from the "unknown" category, reclassify it into the corresponding domain name category, and update the second domain name mapping relationship. This can not only improve the accuracy of traffic statistics, but also provide users with more refined traffic management services.
[0144] In some possible embodiments, the domain name category may include two categories: entertainment category and system category. Since the domain names of the system category corresponding to the terminal device are relatively few, multiple domain names corresponding to the system category may be pre-set, so that when domain name traffic statistics are performed on multiple target domain names, all target domain names that do not belong to the system category are determined as entertainment category to improve the classification efficiency of the domain name category.
[0145] S807, counting the category traffic statistics corresponding to each target domain name category.
[0146] It should be noted that the category traffic statistics value includes at least one of the category uplink traffic statistics value, the category downlink traffic statistics value or the category traffic total statistics value.
[0147] Exemplarily, when the terminal device is an on-board terminal of a vehicle, and the domain name categories include entertainment category and system category, through the traffic statistics method provided in the embodiment of the present application, the on-board terminal can obtain the traffic used by its users to access the entertainment category or system category domain names respectively, and report the category traffic statistics to the manufacturer or operator, so as to accurately count and manage different categories of traffic, for example, to reduce fees for system category traffic and to perform billing statistics for entertainment category traffic.
[0148] By implementing the above technical solution, it is possible to accurately count and manage traffic of different domain name categories, effectively improving the accuracy of traffic statistics for designated category services and facilitating the formulation and implementation of more flexible traffic billing and management strategies.
[0149] It should be understood that, although the steps in the above-mentioned flowcharts are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a part of the steps in the above-mentioned flowcharts may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these sub-steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the sub-steps or stages of other steps.
[0150] Based on the foregoing embodiments, an embodiment of the present application provides a traffic statistics device, which includes the modules included and the units included in the modules, which can be implemented by a processor; of course, it can also be implemented by a specific logic circuit; in the implementation process, the processor can be a central processing unit (CPU), a microprocessor (MPU), a digital signal processor (DSP) or a field programmable gate array (FPGA), etc.
[0151] See also Fig. 9 , Fig. 9 A schematic diagram of the structure of a flow statistics device provided in an embodiment of the present application is shown in FIG. Fig. 9 As shown, the traffic statistics device includes an acquisition module 901, a message processing module 902 and a statistics module 903, wherein:
[0152] The acquisition module 901 is used to acquire multiple messages flowing into or out of the network protocol stack through a hook function pre-mounted by the network protocol stack of the device;
[0153] The message processing module 902 is used to obtain, for each acquired message, a target IP address and a message length corresponding to the message, wherein, when the message is a message flowing into the network protocol stack, the target IP address is the source IP address of the message, and when the message is a message flowing out of the network protocol stack, the target IP address is the destination IP address of the message;
[0154] The statistical module 903 is used to count the uplink message length statistics and downlink message length statistics corresponding to each acquired target IP address, wherein the uplink message length statistics is the sum of the message lengths of all messages whose destination IP address is the target IP address among multiple messages, and the downlink message length statistics is the sum of the message lengths of all messages whose source IP address is the target IP address among multiple messages.
[0155] In some possible embodiments, the statistical module 903 is further used to obtain a first domain name mapping relationship, wherein the first domain name mapping relationship includes a mapping relationship between a domain name and an IP address, and each domain name corresponds to at least one IP address.
[0156] In some possible embodiments, the statistical module 903 is also used to determine the target domain name corresponding to each target IP address based on the first domain name mapping relationship; for each target domain name, the uplink domain name traffic statistics and the downlink domain name traffic statistics corresponding to the target domain name are counted, wherein the uplink domain name traffic statistics are the sum of the uplink message length statistics of all target IP addresses corresponding to the target domain name, and the downlink domain name traffic statistics are the sum of the downlink message length statistics of all target IP addresses corresponding to the target domain name.
[0157] In some possible embodiments, the statistical module 903 is also used to calculate the sum of the uplink domain name traffic statistics and the downlink domain name traffic statistics corresponding to each target domain name, and obtain the total domain name traffic statistics corresponding to each target domain name; and send the target statistics corresponding to each target domain name to the platform server, wherein the target statistics include at least one of the uplink domain name traffic statistics, the downlink domain name traffic statistics or the total domain name traffic statistics.
[0158] In some possible embodiments, the statistical module 903 is further used to obtain a target domain name category corresponding to each target domain name based on a preset second domain name mapping relationship, wherein the preset second domain name mapping relationship includes a mapping relationship between a domain name and a domain name category; and to count the category traffic statistics corresponding to each target domain name category.
[0159] In some possible embodiments, the statistical module 903 is further used to determine, for each target domain name, that the target domain name category corresponding to the target domain name is the domain name category indicated by the second domain name mapping relationship when the second domain name mapping relationship includes the mapping relationship of the target domain name, or to determine that the target domain name category corresponding to the target domain name is the preset domain name category when the second domain name mapping relationship does not include the mapping relationship of the target domain name.
[0160] In some possible embodiments, the traffic statistics device also includes an output module, which is used to sort all target domain names according to target sorting parameters and output the sorting results, wherein the target sorting parameters include upstream domain name traffic statistics, downstream domain name traffic statistics or total domain name traffic statistics.
[0161] In some possible embodiments, the statistical module 903 is also used to obtain, for each target domain name, a set of IP addresses corresponding to the target domain name through a target server, thereby obtaining a first domain name mapping relationship, the target server includes an HTTPDNS server or an operator DNS server, and the IP address set includes at least one IP address corresponding to the target domain name.
[0162] The description of the above device embodiment is similar to the description of the above method embodiment, and has similar beneficial effects as the method embodiment. For technical details not disclosed in the device embodiment of the present application, please refer to the description of the method embodiment of the present application for understanding.
[0163] It should be noted that in the embodiments of this application Fig. 9 The division of modules in the traffic statistics device shown is schematic and is only a logical function division. There may be other division methods in actual implementation. In addition, each functional unit in each embodiment of the present application may be integrated into a processing unit, or may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of a software functional unit. It may also be implemented in the form of a combination of software and hardware.
[0164] It should be noted that in the embodiment of the present application, if the above method is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiment of the present application can be essentially or partly embodied in the form of a software product that contributes to the relevant technology. The computer software product is stored in a storage medium, including several instructions to enable an electronic device to execute all or part of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a U disk, a mobile hard disk, a read-only memory (ROM), a magnetic disk or an optical disk. In this way, the embodiment of the present application is not limited to any specific combination of hardware and software.
[0165] The present application embodiment provides a vehicle, the transportation tool comprising: Fig. 9 The traffic statistics device shown.
[0166] The embodiment of the present application provides a computer device, which may be a server, and its internal structure diagram may be as follows: Fig.10As shown. The computer device includes a processor, a memory and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the above method is implemented.
[0167] An embodiment of the present application provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps in the method provided in the above embodiment are implemented.
[0168] An embodiment of the present application provides a computer program product including instructions, which, when executed on a computer, enables the computer to execute the steps of the method provided in the above method embodiment.
[0169] Those skilled in the art will understand that Fig.10 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0170] In one embodiment, the traffic statistics device provided by the present application can be implemented in the form of a computer program. The computer program can be Fig.10 The computer device shown in the figure can be run. The memory of the computer device can store various program modules constituting the above-mentioned device. The computer program composed of various program modules enables the processor to execute the steps of the method of each embodiment of the present application described in this specification.
[0171] It should be noted here that the description of the above storage medium and device embodiments is similar to the description of the above method embodiments, and has similar beneficial effects as the method embodiments. For technical details not disclosed in the storage medium, storage medium and device embodiments of this application, please refer to the description of the method embodiments of this application for understanding.
[0172] It should be understood that "one embodiment" or "an embodiment" or "some embodiments" mentioned throughout the specification means that specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, "in one embodiment" or "in one embodiment" or "in some embodiments" appearing throughout the specification may not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It should be understood that in various embodiments of the present application, the size of the sequence number of the above-mentioned processes does not mean the order of execution, and the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiment of the present application. The above-mentioned sequence numbers of the embodiments of the present application are only for description and do not represent the advantages and disadvantages of the embodiments. The above description of each embodiment tends to emphasize the differences between the various embodiments, and the same or similar aspects can be referenced to each other. For the sake of brevity, this article will not repeat them.
[0173] The term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there may be three relationships. For example, object A and / or object B can represent three situations: object A exists alone, object A and object B exist at the same time, and object B exists alone.
[0174] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or device including the element.
[0175] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The embodiments described above are only schematic. For example, the division of the modules is only a logical function division. There may be other division methods in actual implementation, such as: multiple modules or components can be combined, or can be integrated into another system, or some features can be ignored, or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of devices or modules can be electrical, mechanical or other forms.
[0176] The modules described above as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules; they may be located in one place or distributed on multiple network units; some or all of the modules may be selected according to actual needs to achieve the purpose of the present embodiment.
[0177] In addition, all functional modules in the embodiments of the present application may be integrated into one processing unit, or each module may be a separate unit, or two or more modules may be integrated into one unit; the above-mentioned integrated modules may be implemented in the form of hardware or in the form of hardware plus software functional units.
[0178] A person skilled in the art can understand that all or part of the steps of implementing the above method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above method embodiment; and the aforementioned storage medium includes: mobile storage devices, read-only memories (ROM), magnetic disks or optical disks, etc., various media that can store program codes.
[0179] Alternatively, if the above-mentioned integrated unit of the present application is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application can essentially or in other words, the part that contributes to the relevant technology can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling an electronic device to execute all or part of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROMs, magnetic disks, or optical disks.
[0180] The methods disclosed in several method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments.
[0181] The features disclosed in several product embodiments provided in this application can be arbitrarily combined without conflict to obtain new product embodiments.
[0182] The features disclosed in several method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments or device embodiments.
[0183] The above is only an implementation method of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A traffic statistics method, characterized in that: Applied to terminal equipment, including: Acquire multiple messages flowing into or out of the network protocol stack through a hook function pre-mounted by the network protocol stack of the terminal device; For each acquired message, acquire a target IP address and a message length corresponding to the message, wherein, when the message is a message flowing into the network protocol stack, the target IP address is the source IP address of the message, and when the message is a message flowing out of the network protocol stack, the target IP address is the destination IP address of the message; For each target IP address obtained, the uplink message length statistics and downlink message length statistics corresponding to the target IP address are counted, wherein the uplink message length statistics are the sum of the message lengths of all messages whose destination IP address is the target IP address among the multiple messages, and the downlink message length statistics are the sum of the message lengths of all messages whose source IP address is the target IP address among the multiple messages.
2. The method according to claim 1, characterized in that The method further comprises: Obtain a first domain name mapping relationship, wherein the first domain name mapping relationship includes a mapping relationship between a domain name and an IP address, and each domain name corresponds to at least one IP address; After counting the uplink message length statistics and the downlink message length statistics corresponding to each target IP address obtained, the method further includes: Determine the target domain name corresponding to each target IP address according to the first domain name mapping relationship; For each target domain name, the uplink domain name traffic statistics and downlink domain name traffic statistics corresponding to the target domain name are counted, wherein the uplink domain name traffic statistics are the sum of the uplink message length statistics of all target IP addresses corresponding to the target domain name, and the downlink domain name traffic statistics are the sum of the downlink message length statistics of all target IP addresses corresponding to the target domain name.
3. The method according to claim 2, characterized in that After counting the uplink domain name traffic statistics and the downlink domain name traffic statistics corresponding to each target domain name, the method further includes: Calculate the sum of the uplink domain name traffic statistics value and the downlink domain name traffic statistics value corresponding to each target domain name to obtain the total domain name traffic statistics value corresponding to each target domain name; The target statistical value corresponding to each target domain name is sent to the platform server, wherein the target statistical value includes at least one of an uplink domain name traffic statistical value, a downlink domain name traffic statistical value or a total domain name traffic statistical value.
4. The method according to claim 2, characterized in that: The method further comprises: According to a preset second domain name mapping relationship, a target domain name category corresponding to each target domain name is obtained, wherein the preset second domain name mapping relationship includes a mapping relationship between a domain name and a domain name category; Count the category traffic statistics corresponding to each target domain name category.
5. The method according to claim 4, characterized in that The step of obtaining the target domain name category corresponding to each target domain name according to the preset second domain name mapping relationship includes: For each target domain name, when the second domain name mapping relationship includes the mapping relationship of the target domain name, determine that the target domain name category corresponding to the target domain name is the domain name category indicated by the second domain name mapping relationship; or, when the second domain name mapping relationship does not include the mapping relationship of the target domain name, determine that the target domain name category corresponding to the target domain name is the preset domain name category.
6. The method according to claim 3, characterized in that The method further comprises: All target domain names are sorted according to target sorting parameters, and a sorting result is output, wherein the target sorting parameters include an upstream domain name traffic statistics value, a downstream domain name traffic statistics value, or a total domain name traffic statistics value.
7. The method according to claim 2, characterized in that The obtaining of the first domain name mapping relationship includes: For each target domain name, the IP address set corresponding to the target domain name is obtained through the target server, thereby obtaining the first domain name mapping relationship. The target server includes an HTTPDNS server or an operator DNS server, and the IP address set includes at least one IP address corresponding to the target domain name.
8. A flow statistics device, characterized in that: include: An acquisition module, used to acquire a plurality of messages flowing into or out of the network protocol stack through a hook function pre-mounted by the network protocol stack of the device; A message processing module, used for obtaining, for each acquired message, a target IP address and a message length corresponding to the message, wherein, when the message is a message flowing into the network protocol stack, the target IP address is the source IP address of the message, and when the message is a message flowing out of the network protocol stack, the target IP address is the destination IP address of the message; A statistical module is used to count the uplink message length statistics and downlink message length statistics corresponding to each acquired target IP address, wherein the uplink message length statistics is the sum of the message lengths of all messages whose destination IP address is the target IP address among the multiple messages, and the downlink message length statistics is the sum of the message lengths of all messages whose source IP address is the target IP address among the multiple messages.
9. A vehicle, characterized in that: The vehicle comprises the traffic counting device according to claim 8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.