Network traffic collection method and system based on cloud-based environment

By creating mirrored virtual switches and virtualized instance agent nodes in a cloud environment, the accurate collection and analysis of network traffic is achieved, and the problems of missed reports, false alarms and device dependence in the existing technology are solved, and are suitable for multi-network cards and cloud computing environments.

WO2025107780A1PCT designated stage expired Publication Date: 2025-05-30HUAXIN CONSULTATING CO LTD

Patent Information

Application Number
PCT/CN2024/114667
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-24
Filing Date
2024-08-27
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing technology cannot effectively capture network traffic in a cloud-based environment, resulting in missing security incident information and unable to restore the collected traffic, resulting in false alarms, misreports, and misreports of security incidents, as well as certain requirements for the equipment, resulting in limited application scenarios.

Method used

By creating mirrored virtual switches and virtualized instance agent nodes in the computing node, using the patch port of the virtual switch to mirror traffic, traffic is diverted to the virtualized instance agent node, converted into packet files and sent to the data security monitoring platform, and the traffic is securely collected and analyzed.

Benefits of technology

It realizes accurate collection of network traffic in a cloud-based environment, reduces false alarms and missed reports of security incidents, avoids invasive requirements for devices, has strong adaptability, and supports automatic monitoring of shrinking events of multi-network card environments and cloud computing virtual instances.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024114667_30052025_PF_FP_ABST
    Figure CN2024114667_30052025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the present invention are a network traffic collection method and system based on a cloud-based environment. The present invention solves the problems of existing traffic collection being invasive to a monitored system, and having system and software dependency requirements, poor adaptability, and high consumption of computing and network transmission resources. A mirror virtual switch and a virtualized instance agent node are created at a computing node. By mirroring traffic by means of a patch port of a virtual switch, monitoring node data is diverted to the mirror virtual switch, and then is forwarded to the virtualized instance agent node by means of the mirror virtual switch; network traffic data is stored as in a file format, and is forwarded to a data security monitoring platform for monitoring a virtualized instance event in real time, and when the event changes, a flow table of the virtual switch is adjusted on the basis of a monitoring policy. According to the present invention, traffic monitoring is implemented in a software manner, and virtualized instance traffic is collected before packet modification, facilitating the accuracy of security event judgment, involving no intrusive modification to an instance, and no system requirement, and occupying few resources.
Need to check novelty before this filing date? Find Prior Art

Description

A network traffic collection method and system based on cloud environment Technical Field

[0001] The present invention relates to the field of data collection technology, and in particular to a network traffic collection method and system based on a cloud environment. Background Art

[0002] With the development of the Internet, network security issues are increasing day by day. Security monitoring of network traffic and reporting of early warning events in operation, maintenance and network protection work have become topics that enterprises cannot ignore. Since the bypass monitoring mode has the advantages of flexible and convenient deployment and will not affect the existing network, network monitoring mainly adopts the bypass monitoring mode. The bypass monitoring mode mainly uses the "port mirroring" function of network devices such as switches to achieve monitoring. In this mode, the data security monitoring platform only needs to be connected to the mirror port specified by the switch to collect, parse and analyze network traffic. In a physical environment, mirrored traffic is generally mirrored from the ports of upper-layer devices such as core switches, and there are specific requirements for physical topology and hardware configuration. However, with the popularization and development of cloud computing technology, in cloud environments (virtual machines, containers, etc.), the solution of directly mirroring traffic on switches is no longer applicable. The main reasons are:

[0003] (1) Traffic between virtual machines flows only within the compute nodes (the physical machines where the virtualized instances run) and cannot be captured by switches. Or, traffic flows only between compute nodes, terminates at the access layer, and cannot be captured by the aggregation layer. The original solution cannot capture this part of the traffic, resulting in the omission of a lot of security incident information.

[0004] (2) After the traffic in the cloud environment leaves the virtual machine, it is processed by the virtual machine network (switches, routers, gateways, firewalls), which may involve operations such as NAT, flow table conversion, and tunnel message encapsulation, resulting in the replacement of message fields. The analysis node cannot restore the original message and cannot accurately analyze risk nodes and events, leading to problems such as false alarms, omissions, and erroneous reports of security incidents.

[0005] (3) Obtaining mirrored traffic through network devices such as switches. This method has certain limitations, such as requiring network devices to support mirroring, which limits its application scenarios.

[0006] To address the traffic collection problem, some solutions have been proposed, such as the Chinese invention application with application number CN202210043683.3, titled "Network Traffic Collection Method." This patent proposes a method for capturing network traffic on monitored nodes (applicable to both virtual and physical nodes), saving it as a file, and sending the traffic file to a data security monitoring platform to implement traffic monitoring, addressing the network traffic collection problem in specialized scenarios. However, this solution has the following disadvantages:

[0007] 1. It requires that all monitored nodes deploy monitoring software to generate traffic files, which is invasive to the monitored system and has system and software dependencies on the monitored nodes, making it not very adaptable.

[0008] 2. As the number of monitored nodes increases, the deployment scale and workload increase. In a cloud computing environment, virtual machine creation and destruction operations are relatively frequent. Each newly added monitored node requires manual installation of the monitoring program, which is not conducive to automated implementation.

[0009] 3. Each monitored node must transmit files to the data security monitoring platform, occupying additional network bandwidth resources. If the monitoring scale is large, the network overhead may be unacceptable.

[0010] Summary of the Invention

[0011] The present invention mainly solves the problems in the existing technology of traffic collection that cannot capture traffic, misses security event information, and cannot restore the collected traffic, resulting in false alarms, omissions, and errors in security events, as well as certain requirements for equipment, which leads to limited application scenarios. It provides a network traffic collection method and system based on a cloud environment.

[0012] The present invention also solves the problems in the prior art that traffic collection is invasive to the monitored system, has system and software dependence requirements, is not adaptable, is not conducive to automated implementation, and occupies a large amount of computing resources and network transmission resources. It provides a network traffic collection method and system based on a cloud environment.

[0013] The solution of the present invention uses the virtual switch patch port to mirror the traffic, diverts the monitoring node data to the mirrored virtual switch, and then forwards it to the virtualization instance agent node through the mirrored virtual switch, converts the network traffic data into a file format, and forwards it to the data security monitoring platform for security analysis.

[0014] This invention solves the problem of collecting traffic from virtualized instances in cloud environments. It automatically sends traffic data from monitored nodes to a data security monitoring platform, adapting to environments where the number of monitored virtual nodes dynamically changes. It can uniformly collect traffic for a specific virtualized instance or all virtualized instances of a compute node, and also supports traffic collection on systems with multiple network cards. It also supports automatic monitoring of scaling events for cloud computing virtual instances, adapting to changing scenarios in cloud computing environments, automatically issuing and clearing flow tables, and collecting traffic according to preconfigured policies.

[0015] The above technical problems of the present invention are mainly solved by the following technical solutions: a network traffic collection method based on a cloud environment, creating a mirror virtual switch and a virtualization instance agent node on a computing node, the mirror virtual switch and the virtual switch are interconnected, the traffic of the monitored virtual instance is mirrored to the mirror virtual switch through the virtual switch, the virtualization instance agent node and the mirror virtual switch are interconnected, the received traffic is directed to the virtualization instance agent node through the mirror virtual switch, and the virtualization instance agent node converts the received traffic into a message file and sends it to the monitoring platform.

[0016] The present invention deploys a mirror virtual switch and a virtualization instance agent node at the computing node, and realizes traffic monitoring through software. It can intercept the original traffic at the access layer, and collect the virtualization instance traffic before the cloud environment NAT, tunnel and other message modification links, which is beneficial to the accuracy of security event judgment. The present invention does not make immersive modifications to the monitoring instance, does not need to deploy software on the monitoring virtualization instance, and has no system or software dependency requirements on the monitoring node. It can realize traffic collection for environments such as x86, arm, linux, windows, mac, etc., and has promotion and strong scalability in environments with a large number of virtual nodes and complex shapes. The present invention completes the traffic collection of all virtualization instances of physical nodes by deploying virtualization instance agent nodes, and occupies the best computing resources and network transmission resources. The present invention supports traffic collection in a multi-network card environment.

[0017] As a preferred solution, a patch port is created on the virtual switch where the monitored virtualized instance exists, and a corresponding patch port is created on the mirror virtual switch, so as to interconnect the monitored virtual switch and the mirror virtual switch.

[0018] As a preferred solution, by parsing the monitoring policy configuration, a flow table is issued to the virtual switch, and the traffic of the virtual switch's designated port or the entire virtual switch traffic is mirrored to the mirror virtual switch.

[0019] As an optimal solution, by issuing a flow table under the mirror virtual switch, the traffic received by the patch port is forwarded to the virtual port connected to the virtualization instance agent node, and then directed to the virtualization instance agent node.

[0020] As a preferred solution, a program is deployed on the virtualized instance agent node to capture packets on the virtual port. The obtained traffic is converted into a message file and periodically sent to the monitoring platform through a scheduled task. The virtualized instance agent node only requires the ability to deploy software programs and can be set to occupy only the minimum computing resources. There is no operating system requirement and it can run as long as the software program has the necessary dependencies. For example, if the software is implemented in Java, only the Java basic package needs to be installed to support the relevant functions. This makes the virtualized instance agent node occupy less computing resources. The size of the traffic file generated by the virtualized instance agent node, the packet capture time, the file sending cycle and other parameters can be configured according to needs. The virtualized instance agent node sends the file to the data security monitoring platform. After receiving the traffic file, the platform parses it and reports the security alarm event.

[0021] As a preferred solution, a virtualization instance agent node monitors virtualization instance events in real time. When events change, it adjusts the virtual switch flow table based on the monitoring policy to dynamically collect the required virtualization instance traffic. This invention supports automatic monitoring of cloud computing virtualization instance scaling events, adapting to changes in virtualization instance scenarios in the cloud computing environment, automatically adjusting the flow table, and collecting traffic according to preconfigured policies.

[0022] As an optimal solution, the monitored virtualization instance events are virtualization instance life cycle change events, including new virtual machines, power-on, new network card events, as well as virtual machine deletion, power-off, and network card deletion events. For new virtual machines, power-on, and new network card events, flow tables are issued according to the monitoring policy; for virtual machines, power-off, and network card deletion events, flow tables are deleted according to the monitoring policy.

[0023] Automatically monitor virtualized instance events. When virtualized instances are added or deleted, powered on or off, or network cards are added or removed in the cloud computing environment, the system automatically issues or deletes flow tables, and dynamically collects network traffic of required instances based on policies.

[0024] As an optimal solution, for the events of creating a new virtual machine, starting up the machine, and adding a new network card, the traffic monitoring granularity policy associated with the virtualization instance is analyzed. If traffic monitoring is performed at the virtual switch granularity, the virtual switch granularity mirror flow table is sent to the virtual switch associated with the virtualization instance. If traffic monitoring is performed at the port granularity, the port mirror flow table is sent based on the specified port on the virtual switch where the virtualization instance port is located.

[0025] In this solution, when a new virtual machine, power-on, or new network card event is detected, the system determines whether the configuration associated with the virtualization instance is to monitor traffic at the virtual switch granularity. If so, the system then determines whether the virtual switch where the virtualization instance is located has issued a flow table in accordance with the policy for monitoring traffic at the virtual switch granularity. If a flow table has been issued, the system continues to monitor the traffic of the corresponding virtualization instance. If a flow table has not been issued, the virtualization instance agent node calls the compute node interface to issue a virtual switch granularity mirror flow table to the virtual switch associated with the virtualization instance, and the monitoring event processing ends. If not, it means that the configuration associated with the virtualization instance where the event occurred is to monitor traffic at the port granularity. In this case, the virtual switch where the virtualization instance port is located issues a port mirror flow table based on the specified port, and the monitoring event processing ends.

[0026] As an optimal solution, for the events of deleting a virtual machine, shutting down the computer, and deleting a network card, the traffic monitoring granularity policy associated with the virtualization instance is analyzed. If traffic monitoring is performed at the virtual switch granularity, the associated virtual switch mirror flow table is deleted when the virtualization instance is the last virtualization instance associated with the virtual switch, and monitoring of the traffic of the virtual switch is ended. If traffic monitoring is performed at the port granularity, the specified port mirror flow table is deleted on the virtual switch where the virtualization instance port is located.

[0027] In this solution, when the events of deleting a virtual machine, shutting down the computer, or deleting a network card are detected, it is determined whether the configuration associated with the virtualization instance is to monitor at the virtual switch granularity. If so, it is determined whether there are other virtualization instances on the virtual switch where the virtualization instance is located. If not, it means that the virtualization instance where the event occurred is the last virtualization instance on this virtual switch. All mirror flow tables of the virtual switch are directly deleted, and the traffic on this virtual switch is no longer monitored. The processing of this monitoring event is completed. If yes, it means that there are other virtualization instances. No processing is performed on the detected event, and the processing of this monitoring event is completed. If not, it means that the configuration associated with the virtualization instance where the event occurred is to monitor traffic at the port granularity. In this case, the mirror flow table of the specified port is deleted on the virtual switch where the virtualization instance port is located, and the processing of this monitoring event is completed.

[0028] A network traffic collection system based on a cloud environment includes several virtual switches, mirror virtual switches and virtualized instance agent nodes set up on computing nodes.

[0029] A virtual switch connects to multiple virtualized instances through virtual ports, connects to a mirrored virtual switch through a patch port, monitors all traffic on the virtual switch or traffic on a specified port, and mirrors all traffic on the virtual switch or traffic on a specified port to the mirrored virtual switch.

[0030] The mirror virtual switch connects to the virtualization instance agent node through the virtual port and directs the received traffic to the virtualization instance agent node;

[0031] The virtualization instance agent node parses the monitoring policy configuration, issues flow tables to the virtual switch and mirrored virtual switch, monitors virtualization instance events in real time, and adjusts the virtual switch flow table according to the monitoring policy when an event changes, dynamically collecting the required virtualization instance traffic. The monitoring policy configuration is pre-configured by the user based on their needs, including whether to enable traffic monitoring, the monitoring scope (a specific virtualization instance or port on a compute node, or all traffic on a specific virtual switch), the traffic monitoring period, the size of the generated traffic file packet, and the destination information for the traffic file transfer (such as the IP address and port of the data security monitoring platform). The virtualization instance agent node parses the configuration file.

[0032] Therefore, the advantages of the present invention are:

[0033] 1. Traffic monitoring implemented through software can intercept original traffic at the access layer and collect virtualized instance traffic before message modification steps such as NAT and tunneling in the cloud environment, which is conducive to the accuracy of security incident judgment.

[0034] 2. There is no immersive modification to the monitoring instance, no need to deploy software on the monitoring virtualization instance, and no system or software dependency requirements for the monitoring node. Traffic collection can be achieved for environments such as x86, ARM, Linux, Windows, and Mac. It is scalable and has strong scalability in environments with a large number of virtual nodes and complex shapes.

[0035] 3. By deploying virtualized instance agent nodes, traffic collection of all virtualized instances of physical nodes is completed, and both computing resources and network transmission resources are optimized.

[0036] 4. Automatically monitor virtualized instance events and support traffic collection in multi-network card environments. When events in the cloud computing environment change, the configuration can be automatically updated and the network traffic of the required instances can be dynamically collected according to the strategy. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] FIG1 is a schematic structural diagram of the system of the present invention;

[0038] FIG2 is a schematic flow chart of the method of the present invention. DETAILED DESCRIPTION

[0039] The technical solution of the present invention will be further specifically described below through embodiments and in conjunction with the accompanying drawings.

[0040] Example:

[0041] This embodiment provides a network traffic collection method based on a cloud environment. By creating a mirror virtual switch and a virtualization instance agent node on a computing node, as shown in FIG1 , a patch port is created on the virtual switch where the monitored virtualization instance exists, and a corresponding patch port is created on the mirror virtual switch. The mirror virtual switch is interconnected with the virtual switch, and the virtualization instance agent node is interconnected with the mirror virtual switch.

[0042] The virtualization instance agent node parses the monitoring policy configuration and issues a flow table to the virtual switch. It then mirrors traffic on a specified virtual switch port or the entire virtual switch to the mirrored virtual switch. The mirrored virtual switch then issues a flow table to forward traffic received on the patch port to the virtual port connected to the virtualization instance agent node, directing the traffic to the virtualization instance agent node. The virtualization instance agent node deploys software to capture packets on the virtual port, converting the captured traffic into message files that are periodically sent to the data security monitoring platform via a scheduled task. The virtualization instance agent node monitors virtualization instance events in real time. When events change, it adjusts the virtual switch flow table based on the monitoring policy, dynamically collecting the required virtualization instance traffic. Implementing traffic monitoring through software allows for intercepting raw traffic at the access layer, collecting virtualization instance traffic before any packet modification steps such as NAT and tunneling occur in the cloud environment, facilitating accurate security incident assessment. There's no need to deploy software on the monitoring virtualized instances, no invasive modifications to the monitoring virtualized instances, and no system or software dependencies on the monitoring nodes. Traffic collection is available for x86, ARM, Linux, Windows, and Mac environments, making it highly scalable and applicable to environments with a large number of virtual nodes and complex configurations. Traffic collection for all virtualized instances on physical nodes is accomplished by deploying virtualized instance agent nodes, which consume less computing and network transmission resources, reducing overhead.

[0043] This method includes automatically monitoring virtual instance traffic scaling events, specifically monitoring virtual instance lifecycle change events, including virtual machine creation, startup, and network card addition events, as well as virtual machine deletion, shutdown, and network card deletion events. For virtual machine creation, startup, and network card addition events, a flow table is issued according to the monitoring policy. Issuing the flow table specifically includes analyzing the traffic monitoring granularity policy associated with the virtualization instance configuration. If traffic monitoring is performed at the virtual switch granularity, a virtual switch granularity mirror flow table is issued to the virtual switch associated with the virtualization instance. If traffic monitoring is performed at the port granularity, a port mirror flow table is issued based on the designated port on the virtual switch where the virtualization instance port is located. For virtual machine deletion, shutdown, and network card deletion events, the flow table is deleted according to the monitoring policy. Deleting the flow table specifically includes analyzing the traffic monitoring granularity policy associated with the virtualization instance configuration. If traffic monitoring is performed at the virtual switch granularity, the associated virtual switch mirror flow table is deleted if the virtualization instance is the last virtualization instance associated with the virtual switch, thereby ending monitoring of the traffic of the virtual switch. If traffic monitoring is performed at the port granularity, the designated port mirror flow table is deleted on the virtual switch where the virtualization instance port is located.

[0044] The following example explains this method in detail. As shown in Figure 1, assume that the traffic of the following virtualization instances needs to be collected: virtualization instance 1, all virtualization instances on virtual switch 2, namely virtualization instance 3 and virtualization instance 4, where virtualization instance 3 has multiple network cards, and different networks are connected to different virtual switches. Assume that virtual switch 1 is the management network and only the management network traffic of the specified virtualization instance is required to be monitored, corresponding to vport1 and vport3 in Figure 1. Virtual switch 2 is the storage network and the storage network traffic of all virtualization instances needs to be monitored. The specific implementation of the method is as follows:

[0045] Create a mirrored virtual switch and a virtualization instance agent node, create a patch port pair, connect virtual switch 1 and virtual switch 2 to the mirrored virtual switch, create a vport port pair, and connect the mirrored virtual switch to the virtualization instance agent node.

[0046] Issue a flow table under virtual switch 1 to mirror the traffic of vport 1 and vport 3 to patch 1. Issue a flow table under virtual switch 2 to mirror the traffic of all vports to patch 2.

[0047] The flow table is issued on the mirrored virtual switch to forward the traffic of the patch1' and patch2' ports directly to the vportx port and direct it to the virtualization instance agent node.

[0048] The virtualized instance agent node deploys software programs to convert received traffic into message files and send them to the data security monitoring platform according to the management policy.

[0049] As shown in Figure 2, the execution process of the method of this embodiment is specifically described in conjunction with the automatic monitoring of virtual instance traffic expansion and contraction events. First, a virtualized instance agent node is created, and the virtualized instance agent node interacts with the computing node. The method process runs on the virtualized instance agent node. The method includes the following steps:

[0050] S1. The virtualized instance agent node starts and runs normally.

[0051] S2. Analyze monitoring policy configuration. The user configures monitoring policies in advance based on their needs, such as whether to enable traffic monitoring, the monitoring scope (a specific virtualization instance or port on a compute node, or all traffic on a specific virtual switch), the traffic monitoring period, the size of generated traffic file packets, and the destination of traffic file transmissions (such as the IP address and port of the data security monitoring platform).

[0052] S3. Determine whether the current configuration enables the traffic monitoring function. If not, end. If so, proceed to the next step.

[0053] S4. The virtualization instance agent node calls the computing node interface to notify the computing node to create a mirrored virtual switch;

[0054] Create a vportx port pair to interconnect the virtualization instance agent node with the mirror virtual switch, and create a patch port pair to interconnect the monitored virtual switch with the mirror virtual switch.

[0055] Based on the parsed configuration, the default flow table is deployed on the relevant virtual switches and mirrored virtual switches. The structure shown in Figure 1 is used as an example to illustrate the following:

[0056] (1) Monitor all traffic on virtual switch 2, issue a flow table on virtual switch 2, mirror the inbound and outbound traffic of all vports on virtual switch 2 to the patch2 port, and pass it to the mirrored virtual switch through the patch2' port.

[0057] (2) Monitor the traffic of the designated port on virtual switch 1, send and receive port mirroring flow tables on virtual switch 1, mirror the traffic of vport1 and vport3 to the patch1 port, and transmit it to the mirrored virtual switch through the patch1' port.

[0058] (3) Flow tables are posted on the mirror virtual switch, and traffic from all ports is forwarded to the vportx port and directed to the virtualization instance agent node.

[0059] S5. Monitor virtualization instance lifecycle events;

[0060] The virtualization instance agent node calls the computing node interface or registration interface to monitor the computing node virtualization instance lifecycle change events in real time, including the addition, restart, suspension, and deletion of virtualization instances, as well as the addition and deletion of their ports.

[0061] S6. If a virtualization instance event is detected, determine whether the changed virtualization instance is the monitored virtualization instance based on the configuration file. If not, return to step S5. If so, proceed to the next step.

[0062] S7. Determine whether the event is a newly added virtual machine, a virtual machine startup, or a newly added network card event. If so, proceed to step S8; otherwise, proceed to step S11.

[0063] S8. Determine whether the configuration associated with the virtualization instance is "traffic monitoring at the virtual switch granularity". If so, proceed to step S9. If not, it means that the configuration associated with the virtualization instance where the event occurred is "traffic monitoring at the port granularity". Then, the port mirror flow table is sent up and down on the virtual switch where the virtualization instance port is located, and proceed to step S16.

[0064] S9. Determine whether the virtual switch where the virtualization instance is located has issued a flow table in accordance with the "traffic monitoring at the virtual switch granularity" policy. If not, proceed to step S10. If so, it means that the virtual switch granularity mirror flow table already exists and the traffic of the corresponding virtualization instance can be monitored, and proceed to step S16.

[0065] S10. If the corresponding virtual switch has not yet issued a virtual switch granular mirror flow table, the virtualization instance agent node calls the computing node interface to issue a virtual switch granular mirror flow table to the virtual switch associated with the virtualization instance, and then proceeds to step S16.

[0066] S11. Determine whether the event is a virtual machine deletion, virtual machine shutdown, or virtual machine network card deletion event. If so, proceed to step S12; otherwise, proceed to step S15.

[0067] S12. Determine whether the configuration associated with the virtualization instance is "traffic monitoring at the virtual switch granularity". If so, proceed to step S13. If not, it means that the configuration associated with the virtual instance where the event occurred is "traffic monitoring at the port granularity". In this case, delete the specified port mirror flow table on the virtual switch where the virtualization instance port is located and proceed to step S16.

[0068] S13. Determine whether there are other virtualized instances in the virtual switch where the virtualized instance is located. If not, proceed to step S14. If so, it means that there are other virtualized instances in the virtual switch. No processing is performed on this event, and proceed to step S16.

[0069] S14. The virtualization instance where the event occurs is the last virtualization instance on this virtual switch. All mirror flow tables of the virtual switch can be directly deleted, and the traffic on this virtual switch is no longer monitored, and the process proceeds to step S16.

[0070] S15. The event that occurs in the virtualized instance is not related to the network card and is not processed. The process returns to step S5 and waits for the next event to occur.

[0071] S16. The monitoring event processing is completed, and the process returns to step S5 to wait for the next event to occur.

[0072] This embodiment also provides a network traffic collection system based on a cloud environment, as shown in FIG1 , which includes several virtual switches, mirrored virtual switches, and virtualized instance agent nodes set up on computing nodes.

[0073] A virtual switch connects to multiple virtualized instances through virtual ports, connects to a mirrored virtual switch through a patch port, monitors all traffic on the virtual switch or traffic on a specified port, and mirrors all traffic on the virtual switch or traffic on a specified port to the mirrored virtual switch.

[0074] The mirror virtual switch connects to the virtualization instance agent node through the virtual port and directs the received traffic to the virtualization instance agent node;

[0075] The virtualization instance agent node parses the monitoring policy configuration, sends flow tables to the virtual switch and mirror virtual switch, monitors virtualization instance events in real time, and adjusts the virtual switch flow table according to the monitoring policy when the event changes, dynamically collecting the required virtualization instance traffic.

[0076] The specific embodiments described herein are merely illustrative of the spirit of the present invention. Persons skilled in the art may make various modifications, additions, or substitutions to the described specific embodiments without departing from the spirit of the present invention or exceeding the scope of the appended claims.

Claims

1. A network traffic collection method based on a cloud environment, characterized in that: Create a mirror virtual switch and a virtualization instance agent node on the computing node. The mirror virtual switch is interconnected with the virtual switch. The traffic of the monitored virtual instance is mirrored to the mirror virtual switch through the virtual switch. The virtualization instance agent node is interconnected with the mirror virtual switch. The received traffic is directed to the virtualization instance agent node through the mirror virtual switch. The virtualization instance agent node converts the received traffic into a message file and sends it to the monitoring platform.

2. According to the method for collecting network traffic based on a cloud environment according to claim 1, it is characterized in that A patch port is created on the virtual switch of the monitored virtualized instance, and a corresponding patch port is created on the mirror virtual switch to interconnect the monitored virtual switch with the mirror virtual switch.

3. According to the method for collecting network traffic based on a cloud environment according to claim 2, it is characterized by: By parsing the monitoring policy configuration, the flow table is issued to the virtual switch, and the traffic of the specified port of the virtual switch or the traffic of the entire virtual switch is mirrored to the mirror virtual switch.

4. The method for collecting network traffic based on a cloud environment according to claim 2 is characterized in that By issuing a flow table on the mirror virtual switch, the traffic received by the path port is forwarded to the virtual port connected to the virtualization instance agent node and directed to the virtualization instance agent node.

5. A network traffic collection method based on a cloud environment according to any one of claims 1 to 4, characterized in that The virtualized instance agent node deploys a program to capture packets on the virtual port, converts the obtained traffic into message files, and periodically sends them to the monitoring platform through a scheduled task.

6. The method for collecting network traffic based on a cloud environment according to claim 3 is characterized in that It also includes a virtualization instance agent node that monitors virtualization instance events in real time. When an event changes, the virtual switch flow table is adjusted according to the monitoring strategy to dynamically collect the required virtualization instance traffic.

7. The method for collecting network traffic based on a cloud environment according to claim 6 is characterized in that The monitored virtualization instance events are events of changes in the life cycle of the virtualization instance, including new virtual machines, power-on, new network card events, as well as virtual machine deletion, power-off, and network card deletion events. For new virtual machines, power-on, and new network card events, flow tables are issued according to the monitoring policy; for virtual machines, power-off, and network card deletion events, flow tables are deleted according to the monitoring policy.

8. The method for collecting network traffic based on a cloud environment according to claim 7, characterized in that For events such as creating a new virtual machine, starting the machine, and adding a new network card, analyze the traffic monitoring granularity policy associated with the virtualization instance. If traffic monitoring is performed at the virtual switch granularity, send the virtual switch granularity mirror flow table to the virtual switch associated with the virtualization instance. If traffic monitoring is performed at the port granularity, send the port mirror flow table based on the specified port on the virtual switch where the virtualization instance port is located.

9. The method for collecting network traffic based on a cloud environment according to claim 7, characterized in that For events such as deleting a virtual machine, shutting down a computer, and deleting a network card, analyze the traffic monitoring granularity policy associated with the virtualization instance. If traffic monitoring is performed at the virtual switch granularity, delete the associated virtual switch mirror flow table when the virtualization instance is the last virtualization instance associated with the virtual switch, and stop monitoring the traffic of the virtual switch. If traffic monitoring is performed at the port granularity, delete the specified port mirror flow table on the virtual switch where the virtualization instance port is located.

10. A network traffic collection system based on a cloud environment, used to implement the method described in any one of claims 1 to 9, characterized in that: It includes several virtual switches set up on the computing nodes, mirror virtual switches, virtualized instance agent nodes, The virtual switch connects multiple virtualized instances through virtual ports, connects to the mirror virtual switch through the patch port, monitors all traffic of the virtual switch or the traffic of the specified port, and mirrors all traffic of the virtual switch or the traffic of the specified port to the mirror virtual switch; The mirror virtual switch connects to the virtualized instance agent node through the virtual port and directs the received traffic to the virtualized instance agent node; The virtualization instance agent node parses the monitoring policy configuration, sends flow tables to the virtual switch and mirror virtual switch, monitors virtualization instance events in real time, and adjusts the virtual switch flow table according to the monitoring policy when the event changes, and dynamically collects the required virtualization instance traffic.

Citation Information

Patent Citations

  • Virtual machine mirror image flow transmission control method and virtual machine mirror image flow transmission control device

    CN105743734A

  • Method and system for monitoring cloud computing virtual tenant network

    CN106330602A

  • Management system of mirror network flow in virtual network environment and control method

    CN106375384A

  • Network traffic acquisition method and system based on clouded environment

    CN117294533A

  • Establishing Relationships Among Elements In A Computing System

    US20120233607A1

Cited By

  • Microservice architecture-oriented network security detection method and device

    CN121396574A