Data packet processing

The packet processing system, composed of programmable logic modules and a private cloud service gateway, solves the problems of low resource utilization and rapid expansion in existing technologies, realizes on-demand optical splitting and elastic scaling, and improves the stability and security of traffic mirroring.

WO2026108553A1PCT designated stage Publication Date: 2026-05-28CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD +1
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
Filing Date
2025-10-28
Publication Date
2026-05-28

Smart Images

  • Figure CN2025130611_28052026_PF_FP_ABST
    Figure CN2025130611_28052026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure provide a data packet processing system, a method and an apparatus. The data packet processing system comprises a programmable logic module, a private cloud service gateway and a replication module. The programmable logic module receives an original data packet associated with a cloud computing service, and sends to the private cloud service gateway original description information corresponding to the original data packet; the private cloud service gateway updates the original description information to target description information according to a preset data detection policy, and feeds back the target description information to the programmable logic module; the programmable logic module sends to the replication module the original data packet and the target description information; and when it is determined by means of detecting the target description information that the original data packet satisfies a detection condition, the replication module constructs a mirrored data packet corresponding to the original data packet, configures detection information for the mirrored data packet, and submits the mirrored data packet to a virtual server according to the detection information for detecting the mirrored data packet.
Need to check novelty before this filing date? Find Prior Art

Description

Packet processing Technical Field

[0001] This disclosure relates to the field of cloud computing technology, and in particular to data packet processing. Background Technology

[0002] With the development of computer and internet technologies, cloud computing services are being applied in an increasing number of scenarios. To ensure stable cloud computing services, service providers can use traffic mirroring to copy normally processed data packets. This allows for testing services with actual generated traffic without affecting the production environment, enabling early detection of problems and optimization of the cloud computing service to guarantee its stability. Current technologies primarily implement traffic mirroring through splitter point selection, dual-path splitting, and a primary / backup mode. Splitter point selection allows for the mirroring of all data packets entering and leaving the service gateway. The primary optical path can then transmit the data packets, while the secondary optical path forms a primary / backup link to improve service availability. However, this implementation requires a primary / backup link mutual backup mode, resulting in only half the resource utilization and high construction costs. Furthermore, when public network traffic surges, the splitter device, as a physical device, cannot be rapidly expanded, leading to intrusion detection failing to handle lost traffic, ultimately resulting in missing traffic billing and security detection issues. Therefore, an effective solution is urgently needed to address these problems. Summary of the Invention

[0003] In view of the above, embodiments of this disclosure provide a data packet processing system. One or more embodiments of this disclosure also relate to a data packet processing method, a data packet processing apparatus, a computing device, a computer-readable storage medium, and a computer program product, to address the technical deficiencies existing in the prior art.

[0004] According to a first aspect of the present disclosure, a data packet processing system is provided, including a programmable logic module, a private cloud service gateway, and a replication module. The system includes: the programmable logic module, configured to receive an original data packet associated with a cloud computing service and send original description information corresponding to the original data packet to the private cloud service gateway; the private cloud service gateway, configured to update the original description information to target description information according to a preset data detection strategy and feed back the target description information to the programmable logic module; the programmable logic module, configured to send the original data packet and the target description information to the replication module; and the replication module, configured to, if the original data packet meets detection conditions by detecting the target description information, construct a mirror data packet corresponding to the original data packet, configure detection information for the mirror data packet, and submit the mirror data packet to a virtual server according to the detection information for detecting the mirror data packet.

[0005] According to a second aspect of the present disclosure, a data packet processing method is provided, comprising: determining an original data packet associated with a cloud computing service through a programmable logic module, and sending original description information corresponding to the original data packet to a private cloud service gateway; updating the original description information using a data detection strategy preset by the private cloud service gateway to obtain target description information; detecting the target description information through a replication module, and constructing a mirror data packet corresponding to the original data packet if the original data packet meets the detection conditions based on the detection results; configuring detection information for the mirror data packet, and detecting the mirror data packet according to the detection information.

[0006] According to a third aspect of the present disclosure, a data packet processing apparatus is provided, comprising: a determining unit configured to determine an original data packet associated with a cloud computing service through a programmable logic module, and send original description information corresponding to the original data packet to a private cloud service gateway; an updating unit configured to update the original description information using a data detection strategy preset by the private cloud service gateway to obtain target description information; a constructing unit configured to detect the target description information through a replication module, and construct a mirror data packet corresponding to the original data packet if the original data packet meets the detection conditions based on the detection result; and a detection unit configured to configure detection information for the mirror data packet and detect the mirror data packet according to the detection information.

[0007] According to a fourth aspect of the present disclosure, a computing device is provided, comprising: a memory and a processor; the memory is configured to store computer-executable instructions, and the processor is configured to execute the computer-executable instructions, wherein the computer-executable instructions, when executed by the processor, implement the steps of the above-described data packet processing method.

[0008] According to a fifth aspect of the present disclosure, a computer-readable storage medium is provided that stores computer-executable instructions that, when executed by a processor, implement the steps of the above-described data packet processing method.

[0009] According to a sixth aspect of the present disclosure, a computer program product is provided, including a computer program or instructions that, when executed by a processor, implement the steps of the above-described data packet processing method.

[0010] The packet processing system provided in this embodiment aims to improve resource utilization while reducing costs and achieving rapid scaling to cope with sudden surges in public network traffic, thereby addressing issues such as low billing rates and missed security attacks. It comprises a programmable logic module (PLM) module, a private cloud service gateway, and a replication module. For raw data packets associated with cloud computing services, the PLM module determines the original description information corresponding to the raw data packet. After sending this information to the private cloud service gateway, the gateway updates the original description information to target description information according to a preset data detection strategy and feeds the target description information back to the PLM module. The PLM module then sends the raw data packet and target description information to the replication module. This ensures that only raw data packets requiring traffic mirroring carry the target description information, achieving on-demand splitting and avoiding the problem of processing all data packets, thus reducing the transmission of invalid traffic. After the replication module receives the original data packet and the target description information, and determines that the original data packet meets the detection conditions by detecting the target description information, the replication module can then construct a mirror data packet corresponding to the original data packet separately. Detection information is configured for the mirror data packet. Based on this, the mirror data packet is submitted to the virtual server according to the detection information for detection. This allows the detection of the mirror data packet to be completed on the virtual server, achieving the goal of elastic scaling of the traffic mirroring function, unaffected by objective factors of physical devices, thus solving the bottleneck of insufficient performance. Attached Figure Description

[0011] Figure 1 is a schematic diagram of a data packet processing system provided in an embodiment of this disclosure;

[0012] Figure 2 is a schematic diagram of the structure of a data packet processing system provided in an embodiment of this disclosure;

[0013] Figure 3 is a schematic diagram of traffic mirroring processing in a data packet processing system according to an embodiment of the present disclosure;

[0014] Figure 4 is a flowchart of the processing procedure of a data packet processing system provided in an embodiment of this disclosure;

[0015] Figure 5 is a flowchart of a data packet processing method provided in an embodiment of this disclosure;

[0016] Figure 6 is a schematic diagram of the structure of a data packet processing device provided in an embodiment of the present disclosure;

[0017] Figure 7 is a structural block diagram of a computing device provided in an embodiment of this disclosure. Detailed Implementation

[0018] Numerous specific details are set forth in the following description to provide a full understanding of this disclosure. However, this disclosure can be implemented in many other ways than those described herein, and those skilled in the art can make similar extensions without departing from the spirit of this disclosure. Therefore, this disclosure is not limited to the specific implementations disclosed below.

[0019] The terminology used in one or more embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the one or more embodiments of this disclosure. The singular forms “a,” “the,” and “the” as used in one or more embodiments of this disclosure and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in one or more embodiments of this disclosure refers to and includes any or all possible combinations of one or more associated listed items.

[0020] It should be understood that although the terms first, second, etc., may be used to describe various information in one or more embodiments of this disclosure, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first may also be referred to as second without departing from the scope of one or more embodiments of this disclosure, and similarly, second may also be referred to as first. Depending on the context, the word “if” as used herein may be interpreted as “when”, “in response to a determination”, or “when…”.

[0021] Furthermore, it should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in one or more embodiments of this disclosure are all information and data authorized by the user or fully authorized by all parties. Moreover, the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.

[0022] First, the terms and concepts involved in one or more embodiments of this disclosure will be explained.

[0023] FPGA (Field-Programmable Gate Array): Programmable logic module. FPGA is a product of further development based on programmable devices such as programmable array logic and general-purpose array logic. It is a semi-custom circuit in the field of application-specific integrated circuits (ASIC).

[0024] Metadata: Metadata refers to the metadata in a message. It is used to record relevant internal data information for message forwarding.

[0025] NIS (Network Intelligence Service) is a cloud service that performs network health analysis, performance monitoring, diagnosis and repair, traffic analysis, and measurement simulation.

[0026] DDoS (Distributed Denial of Service): A DDoS attack refers to the use of client / server technology to combine multiple computers as an attack platform to launch an attack against one or more targets, thereby multiplying the power of the denial-of-service attack.

[0027] VxLAN (Virtual Extensible LAN): A technology used to extend LAN segments within a virtual network. It uses a VxLAN header to encapsulate data packets within UDP packets, thereby enabling virtual network interconnection between different physical networks. VNI (Virtual Network Identifier): In VxLAN, the VNI is a unique identifier used to identify different virtual networks (or VxLAN networks), enabling isolation and differentiation between them.

[0028] XGW: In VPC (Virtual Private Cloud), XGW is the gateway device of VPC, which consists of a cluster of servers.

[0029] This disclosure provides a data packet processing system, and also relates to a data packet processing method, a data packet processing apparatus, a computing device, a computer-readable storage medium, and a computer program product, which will be described in detail in the following embodiments.

[0030] In practical applications, as shown in Figure 3, the working mode of mirrored traffic is as follows: Splitting point selection: The interconnecting fiber optic link between the Switch and the Core switch is selected as the splitting point, allowing for mirrored acquisition of all data packets entering and leaving the gateway. Dual-path splitting: Service-related splitting devices are set up at the splitting point, splitting the original optical data carrying the service into three paths in a 3:3:4 ratio. The 4 / 10 primary path continues to transmit service data, while the other two 3 / 10 paths serve as bypass paths. In primary / backup mode, the 3 / 10 bypass paths connect to TAP-SW1 (splitter 1) and TAP-SW2 (splitter 2). TAP-SW1 is the primary link, and TAP-SW2 is the backup link. Both splitting links operate in primary / backup mode, with only one working at a time. Normally, the primary link operates while the backup link is in cold standby mode. When the primary link fails, it quickly switches to the backup link, and the primary link stops working, significantly improving service high availability. However, this public cloud deployment has a primary and backup link mutual backup mode, which results in lower utilization and higher construction costs. It also has risks such as missing billing and missed attacks. Therefore, we need to find an effective solution to solve the above problems.

[0031] Referring to the schematic diagram in Figure 1, the data packet processing system provided in this embodiment, in order to improve resource utilization while reducing costs and achieve rapid scaling capabilities to cope with sudden surges in public network traffic and thus solve the problems of low billing and missed security attacks, can be composed of a programmable logic module, a private cloud service gateway, and a replication module. For the original data packets associated with cloud computing services, the programmable logic module can determine the original description information corresponding to the original data packet. After sending it to the private cloud service gateway, the private cloud service gateway can update the original description information to the target description information according to a preset data detection strategy and feed the target description information back to the programmable logic module. At this time, the programmable logic module sends the original data packet and the target description information to the replication module. This achieves the goal of carrying the target description information only for the original data packets that need traffic mirroring, thereby achieving on-demand splitting and avoiding the problem of processing all data packets, thus reducing the transmission of invalid traffic. After the replication module receives the original data packet and the target description information, and determines that the original data packet meets the detection conditions by detecting the target description information, the replication module can then construct a mirror data packet corresponding to the original data packet separately. Detection information is configured for the mirror data packet. Based on this, the mirror data packet is submitted to the virtual server according to the detection information for detection. This allows the detection of the mirror data packet to be completed on the virtual server, achieving the goal of elastic scaling of the traffic mirroring function, unaffected by objective factors of physical devices, thus solving the bottleneck of insufficient performance.

[0032] Referring to Figure 2, Figure 2 shows a schematic diagram of the structure of a packet processing system provided according to an embodiment of the present disclosure. The packet processing system 200 includes a programmable logic module 210, a private cloud service gateway 220, and a replication module 230, which are implemented as follows.

[0033] The programmable logic module 210 is used to receive the original data packet associated with the cloud computing service and send the original description information corresponding to the original data packet to the private cloud service gateway; the private cloud service gateway 220 is used to update the original description information to target description information according to a preset data detection strategy and feed the target description information back to the programmable logic module; the programmable logic module 210 is used to send the original data packet and the target description information to the replication module; the replication module 230 is used to construct a mirror data packet corresponding to the original data packet when the original data packet meets the detection conditions by detecting the target description information, configure detection information for the mirror data packet, and submit the mirror data packet to the virtual server according to the detection information for detecting the mirror data packet.

[0034] The packet processing system provided in this embodiment addresses issues such as the inability of physical devices to scale flexibly, insufficient traffic billing, and missed security attacks when implementing traffic mirroring functionality through a combination of software and hardware. The packet processing system in this embodiment processes data packets generated and transmitted using cloud computing services. The service type described in the data packets can be set according to actual needs, and this embodiment does not impose any limitations on it.

[0035] Specifically, the programmable logic module refers to FPGA hardware. Correspondingly, the private cloud service gateway refers to the gateway of the private cloud network associated with the user whose original data packet is linked, used to handle public network traffic entering and leaving that private cloud network. Correspondingly, the replication module refers to a virtual module used to implement mirroring functionality. It can be configured in the data packet processing system or within the programmable logic module to mirror the original data packet. By detecting the mirrored data packet, the original data packet can be detected, for example, for traffic billing, distributed denial-of-service attacks, and network health checks.

[0036] Accordingly, cloud computing services specifically refer to services that provide cloud network resources to tenants, enabling them to deploy applications or services on the cloud to provide corresponding service functions to users. The cloud network resources used include, but are not limited to, virtual machines, databases, and computing resources; this embodiment does not impose any limitations on these resources. Accordingly, the original data packet specifically refers to the data packet required to be transmitted by the currently triggered service function. Accordingly, the original description information specifically refers to the data descriptor corresponding to the original data packet, used to record information related to the original data packet, including but not limited to the public IP address corresponding to the original data packet, information regarding whether mirroring is required, and information related to the data packet content.

[0037] Accordingly, the data detection strategy specifically refers to the strategy used to detect and update the original description information corresponding to the original data packets. This strategy can determine the relevant information about the original data packets recorded in the original description information, and can update the information triggering the mirroring traffic function in the original description information according to the mirroring traffic function, such as updating the mirroring flag and updating network device index information, to obtain the target description information. The target description information is the description information obtained after updating the original information according to the mirroring traffic function. By sending this information and the data packets to the replication module, the mirroring traffic function can be triggered to complete detection operations such as traffic billing for the original data packets.

[0038] Accordingly, the detection conditions specifically refer to the conditions for determining whether the original data packet needs to be mirrored after detecting the target description information, and for detecting the data packet. Correspondingly, the mirrored data packet specifically refers to the data packet obtained after mirroring the original data packet. Correspondingly, the detection information specifically refers to the information for selecting a virtual server for the mirrored data packet to complete the data packet detection through virtual resources, achieving elastic scaling on virtual resources to achieve traffic mirroring functionality without relying on physical devices, thus enabling traffic mirroring to have cross-address disaster recovery capabilities.

[0039] Based on this, in order to improve resource utilization while reducing costs and achieve rapid scaling capabilities to cope with sudden surges in public network traffic and thus solve the problems of low billing and missed security attacks, a packet processing system can be composed of a programmable logic module, a private cloud service gateway, and a replication module. For the original data packets associated with cloud computing services, the programmable logic module can determine the original description information corresponding to the original data packets. After sending it to the private cloud service gateway, the private cloud service gateway can update the original description information to the target description information according to the preset data detection strategy and feed the target description information back to the programmable logic module.

[0040] Furthermore, the programmable logic module sends the original data packets and target description information to the replication module; this enables the target description information to be carried only on the original data packets that need to be mirrored, thereby achieving on-demand splitting and avoiding the problem of processing all data packets, thus reducing the transmission of invalid traffic.

[0041] Furthermore, after the replication module receives the original data packet and the target description information, and determines that the original data packet meets the detection conditions by detecting the target description information, the replication module can then construct a mirror data packet corresponding to the original data packet separately. Detection information is configured for the mirror data packet. Based on this, the mirror data packet is submitted to the virtual server according to the detection information for detection. This allows the detection of the mirror data packet to be completed on the virtual server, achieving the goal of elastic scaling of the traffic mirroring function, unaffected by objective factors of physical devices, thereby solving the bottleneck of insufficient performance.

[0042] For example, after receiving raw data packets related to cloud computing services, the FPGA device can determine the corresponding data descriptor. This data descriptor can then be sent to the private cloud network service gateway (XGW) associated with the user of the raw data packet. Upon receiving the data descriptor, the XGW determines that the raw data packet meets the service billing and NIS service requirements. Therefore, it needs to perform traffic mirroring on the raw data packet for subsequent processing. Based on this, the XGW can update the data descriptor, recording the information triggering the traffic mirroring of the raw data packet in the updated data descriptor. The updated data descriptor can then be fed back to the FPGA device.

[0043] Furthermore, after receiving the updated data descriptor, the FPGA device can send the updated data descriptor and the original data packet to the traffic mirroring module. The traffic mirroring module, by detecting the updated data descriptor, determines that the original data packet needs traffic mirroring. Therefore, it first copies the original data packet to obtain a mirrored data packet. Then, it configures detection information for the mirrored data packet to trigger the traffic mirroring function. At this point, the mirrored data packet can be sent to ECS1 according to the detection information. On ECS1, traffic billing, NIS, and DDoS detection services can be performed on the mirrored data packet. The original data packet can then be submitted to the remote end for normal processing according to service processing requirements.

[0044] In summary, the data packet processing system provided in this embodiment can tag data packets that need to be mirrored according to service characteristics through a combination of hardware and software, and pass the description information of the data packets to the hardware along with the data packets. The hardware can efficiently complete the mirroring and copying of data packets. At the same time, when the mirroring traffic function is implemented, based on the scalable transmission method of the virtual server, it breaks through the physical limitations of the device and realizes the rapid expansion of processing such as public network billing and network detection, thereby enabling cloud computing services to provide more stable and reliable services.

[0045] Furthermore, in order to achieve rapid expansion by combining hardware and software to overcome the limitations of physical devices, it is necessary to configure image information for the programmable logic module. In this embodiment, the programmable logic module is also used to receive image configuration information issued by the management module of the cloud computing service, determine network device index information, virtual scalable LAN information, network address information, and physical machine information based on the image configuration information, and cache the network device index information, the virtual scalable LAN information, the network address information, and the physical machine information for executing the data packet detection task corresponding to the original data packet.

[0046] Specifically, the management module refers to the module with management and configuration permissions for the traffic mirroring function, and it is managed by the service provider corresponding to the cloud computing service. Correspondingly, the mirroring configuration information refers to the information issued to the programmable logic module for implementing the traffic mirroring function, which includes network device index information, virtual scalable LAN information, network address information, and physical machine information. Among these, the network device index information records the Bond-ENI index value used for traffic mirroring, the virtual scalable LAN information records the network identifier in the VXLAN, the network address information records the IP address of the physical network, and the physical machine information records the physical machine address to which the virtual server belongs.

[0047] Therefore, in order to enable scalable traffic mirroring functionality for the programmable logic module, private cloud service gateway, and replication module in the packet processing system, mirroring information needs to be configured for the programmable logic module before packet processing. During this process, the programmable logic module can first receive the mirroring configuration information issued by the cloud computing service management module. At this point, it can parse the network device index information, virtual Scalable LAN information, network address information, and physical machine information from the mirroring configuration information. Then, it can cache the network device index information, virtual Scalable LAN information, network address information, and physical machine information, so that it can subsequently execute the packet detection task corresponding to the original packet.

[0048] In practical applications, when sending image configuration information to the programmable logic module (PLM), a pre-configuration method can be used, that is, the image configuration information is sent to the PLM in advance. Alternatively, the information can be sent at other stages, such as after the software has completed the detection information configuration, by including this information in the metadata of the data packet and sending it along with the replication module for subsequent processing.

[0049] Following the previous example, during the FPGA device configuration phase, the cloud computing service can send the mirror configuration information Mirror to the FPGA's traffic mirroring module via the API provided by the network card driver. The mirror configuration information Mirror includes the following information: Bond-ENI-index:1; sys-VNI:2048; IP_addr:192.168.100.1; member:[{nc-ip:10.10.1.1}, {nc-ip:10.10.1.2}, {nc-ip:10.10.1.3}, {nc-ip:10.10.1.4}]. Here, `Bond-ENI-index:1` indicates that the Bond-ENI used for traffic mirroring has an index of 1, a VXLAN network ID of 2048, and an overlay IP address of 192.168.100.1. This Bond-ENI contains four members, each located on a physical machine with IP addresses 10.10.1.1, 10.10.1.2, 10.10.1.3, and 10.10.1.4. Subsequently, if a data packet requiring traffic mirroring is received, the traffic mirroring function can be implemented according to this configuration information.

[0050] In summary, by configuring mirroring information for programmable logic modules, the programmable logic modules can be equipped with traffic mirroring capabilities to facilitate subsequent processing.

[0051] Furthermore, considering that the programmable logic module is an FPGA device, in order to enable it to work with the private cloud service gateway and replication module to implement the mirroring traffic function, it needs to combine with the network interface card (NIC) device and NIC driver to determine and send data packets and description information. In this embodiment, the programmable logic module is also used to receive raw data packets associated with the cloud computing service through the NIC device, store the raw data packets in the server memory using a memory access strategy, determine the raw description information corresponding to the raw data packets using the NIC driver corresponding to the NIC device, and send the raw description information to the private cloud service gateway.

[0052] Specifically, a network interface card (NIC) device refers to the network card on a programmable logic module (PLC) used to receive data packets sent from the external network. Correspondingly, a NIC driver refers to the software driver for the NIC device, used for processing related to the NIC, such as determining the description information of data packets and forwarding that description information. Similarly, server memory refers to the memory space accessible by the PLC, which belongs to the server. And the memory access strategy specifically refers to the Direct Memory Access (DMA) mechanism.

[0053] Based on this, when the programmable logic module receives the original data packet associated with the cloud computing service through the network interface card (NIC), it indicates that the original data packet needs to be processed and transmitted for service purposes. In order to perform traffic mirroring on the data packet under the premise of service requirements, the original data packet can be stored in the server memory using a memory access strategy. At the same time, the original description information corresponding to the original data packet can be determined using the NIC driver corresponding to the NIC. Based on this, the original description information can be sent to the private cloud service gateway to enable the private cloud service gateway to update the original description information.

[0054] In summary, by storing the raw data packets in the server's memory, the number of times the raw data packets are transmitted can be reduced during the description information extraction and transmission stage, thereby saving more network resources.

[0055] In practical applications, after receiving the original description information, if the private cloud service gateway determines that the original data packet needs to be mirrored, it needs to update the original description information according to the data detection strategy so that it can be mirrored and detected after being sent to the replication module. In this embodiment, the private cloud service gateway is also used to convert the public network address contained in the original description information to a private network address according to a preset data detection strategy, set the mirror flag bit in the metadata contained in the original description information, and configure the network device index information contained in the original description information. Based on the address conversion result, the setting result, and the configuration result, it generates target description information and calls the sending function to feed the target description information back to the programmable logic module.

[0056] Specifically, the public IP address refers to the address of the original data packet on the public network, while the private IP address refers to the address of the user's private cloud network. Correspondingly, the metadata is the metadata corresponding to the original data packet. The mirroring flag indicates whether the original data packet needs to be mirrored. The network device index information records the index value used by the original data packet when it is mirrored.

[0057] Based on this, after the private cloud service gateway receives the original description information corresponding to the original data packet, and determines that the original data packet needs to be mirrored according to service requirements, it can first convert the public network address contained in the original description information to a private network address according to the preset data detection strategy, set the mirroring flag bit in the metadata contained in the original description information, and configure the network device index information contained in the original description information. After completing the above operations, it can be determined that the data packet has the attribute of traffic mirroring. Then, the target description information can be generated according to the address conversion result, the setting result, and the configuration result. After that, the sending function is called to feed the target description information back to the programmable logic module for subsequent processing.

[0058] In summary, by updating the mirroring identifier, network device index information, and address through a private cloud service gateway, the updated target description information can be made to have the attributes to trigger traffic mirroring, so that the original data packets can be detected subsequently.

[0059] After receiving the target description information, the programmable logic module can read the original data packet from the server memory and send it to the replication module for processing in conjunction with the target description information. In this embodiment, the programmable logic module is further configured to read the original data packet from the server memory according to the target description information via the network interface card (NIC) device, and send the original data packet and the target description information to the replication module using the NIC driver.

[0060] Based on this, when the private cloud service gateway feeds back the target description information to the programmable logic module, the programmable logic module can read the original data packet from the server memory according to the target description information through the network card device. After reading the original data packet, the network card driver can then be used to send the original data packet and the target description information to the replication module, which will then perform traffic mirroring on the original data packet.

[0061] Continuing with the previous example, after the FPGA device's network interface card (NIC) receives a data packet, it can send the packet to the server's memory for storage via DMA. The FPGA device's NIC driver can then extract the data descriptor of the original data packet and send it to XGW for processing. Upon receiving the data descriptor, XGW needs to convert the public IP address of the data packet in the data descriptor to the private IP address corresponding to the client within the VPC, and simultaneously determine that the original data packet requires traffic metering and NIS processing. Therefore, the mirroring flag in the Meta path of the data packet in the data descriptor can be set, and the Bond address's index can be set to 1, ensuring that the original data packet has traffic mirroring attributes. XGW can then call the send function to send the processed data descriptor to the FPGA device's NIC driver. After receiving the updated data descriptor, the FPGA device can read the original data packet from the server's memory using DMA according to the updated data descriptor, move it into the hardware, process it through the service module, and then send it to the traffic mirroring module to achieve traffic mirroring of the original data packet.

[0062] In summary, by adopting a combination of hardware and software to support traffic mirroring in cloud computing services, the elasticity of traffic mirroring can be effectively improved, thereby giving it stronger disaster recovery capabilities.

[0063] Furthermore, after receiving the target description information and the original data packet, the replication module needs to detect whether the original data packet needs to be mirrored. This detection can be determined by the mirror flag bit and network device index information in the detection information. In this embodiment, the replication module is also used to determine if the original data packet meets the detection conditions if the mirror flag bit is set in the metadata contained in the target description information and the configured network device index information is stored in the configuration table entry, and then execute the step of constructing the mirror data packet corresponding to the original data packet.

[0064] Based on this, after the replication module receives the original data packet and the target description information, the replication module needs to detect the original data packet. If the mirror flag is set in the metadata contained in the target description information and the configured network device index information is stored in the configuration table entry, it means that the original data packet has the requirement for mirror replication. Therefore, it can be determined that the original data packet meets the detection conditions, and the step of constructing the mirror data packet corresponding to the original data packet can be executed.

[0065] Furthermore, if the original data packet does not meet the detection conditions, the packet statistics can be updated for the original data packet, and the target description information corresponding to the original data packet can be released. Then, the original data packet can be sent to the remote end for direct processing via the physical link. Conversely, if the detection conditions are met, the mirrored data packet will be processed subsequently, while the original data packet will not be affected by the processing of the mirrored data packet. The packet statistics can be updated, the target description information corresponding to the original data packet can be released, and then the original data packet can be sent to the remote end for direct processing via the physical link.

[0066] In summary, by detecting the mirroring flag and network device index information of the target description information, it is possible to accurately determine whether the original data packet has the attribute of traffic mirroring. This allows for selective processing of data packets instead of performing this operation on all data packets, thereby saving more resources and reducing the transmission of invalid traffic.

[0067] Furthermore, after determining that the original data packet needs to be mirrored, the replication module can select a data detection node through network device configuration information to ensure accurate selection of a suitable virtual server for detection of the mirrored data packet. In this embodiment, the replication module is also used to select network device configuration information based on the configured network device index information, perform hash calculation on the five-tuple information corresponding to the mirrored data packet to obtain a hash value, select a data detection node in the network device configuration information according to the hash value, and execute the step of configuring detection information for the mirrored data packet if the detection parameters of the mirrored data packet are less than the preset parameter threshold of the data detection node.

[0068] Specifically, the network device configuration information refers to the Bond configuration selected for the mirrored data packet based on the configured network device index information. Correspondingly, the hash value refers to the hash value obtained by performing a hash operation on the five-tuple information corresponding to the mirrored data packet. Correspondingly, the data detection conditions refer to the member selected in the Bond configuration to process the mirrored data packet. Correspondingly, the detection parameters refer to the data volume or required computation amount corresponding to the mirrored data packet, and the parameter threshold refers to the upper limit of the data volume or computation amount that the data detection node can process.

[0069] Based on this, after the replication module constructs a mirror data packet from the original data packet, it is determined that traffic mirroring is required for the mirror data packet. Therefore, the network device configuration information can be selected based on the configured network device index information, and a hash calculation can be performed on the five-tuple information corresponding to the mirror data packet to obtain a hash value. Based on this, a data detection node can be selected from the network device configuration information according to the hash value, and it can be checked whether the data detection node can process the mirror data packet. If the detection parameters of the mirror data packet are less than the preset parameter threshold of the data detection node, it indicates that subsequent processing can proceed, and therefore the step of configuring detection information for the mirror data packet can be executed.

[0070] In summary, before inspecting the image data packets, the data inspection nodes can be determined through configuration information, which facilitates the subsequent sending of the data to a pre-configured virtual server for processing, thereby saving more computing resources.

[0071] Furthermore, when configuring detection information for mirrored data packets, a Virtual Scalable Local Area Network (VSDN) header containing various types of information is actually added to the original data packet. In this embodiment, the replication module is also used to add a VSDN header to the mirrored data packet as detection information configured for the mirrored data packet; wherein, the VSDN header contains virtual server information and physical machine information.

[0072] Specifically, the Virtual Extensible LAN header refers to the header defined for mirrored data packets, which contains virtual server information and physical machine information. The virtual server information is used to identify the virtual server that processes the mirrored data packets, and the physical machine information is used to identify the physical machine to which the virtual server belongs.

[0073] Based on this, the replication module can complete the construction of the image data packet and add a Virtual Scalable Local Area Network (VSDN) header to the image data packet as detection information for the configuration of the image data packet; and the VSDN header contains virtual server information and physical machine information, so that it can be sent to the virtual machine server running on the physical machine for detection and processing of the image data packet.

[0074] Continuing with the previous example, after the replication module receives the original data packet and the updated data descriptor, it can determine whether the mirror flag in the Meta information record of the updated data descriptor is set. If not, it can directly update the packet statistics, release the data descriptor, and send the original data packet from the physical link to the remote processing end. If the mirror flag is set and the Bond index exists in the configuration table, it can replicate the original data packet to obtain the mirror data packet. The original data packet can then directly update the packet statistics, release the data descriptor, and be sent from the physical link to the remote processing end.

[0075] Furthermore, for mirrored data packets, the corresponding Bond configuration can be selected first based on the Bond index. Then, the hash value (Hash1) can be calculated based on the packet's five-tuple information (sip, dip, proto, sport, dport). Based on Hash1, the corresponding member of the mirrored data packet can be selected in the Bond configuration. If member1 matches, its physical machine address (10.10.1.1) can be determined.

[0076] Furthermore, if it is determined that the mirrored data packet does not exceed the protective rate limit of member1, a VXLAN header can be appended to the outer layer of the mirrored data packet. This header contains VNI of 2048, the source IP address of XGW, and the destination address of 10.10.1.1. The mirrored data packet can then be sent to the physical network underlay network according to this information, for transmission to the physical machine corresponding to physical address 10.10.1.1 for further processing.

[0077] In summary, by configuring the Virtual Scalable LAN header for the mirrored data packet, the packet can be sent to a designated virtual server for processing, thereby achieving the purpose of dynamically scaling up and down traffic mirroring.

[0078] Based on this, the virtual server needs to be determined. First, the target physical machine corresponding to the physical machine information can be determined. Then, the target physical machine flexibly selects a virtual server to complete the data packet detection. In this embodiment, the system also includes a target physical machine corresponding to the physical machine information. The target physical machine is used to receive the mirrored data packets submitted by the replication module through the physical network corresponding to the target physical machine, determine the virtual server according to the virtual server information, and send the mirrored data packets to the virtual server for detection.

[0079] Specifically, the target physical machine refers to the physical machine corresponding to the physical machine information, which is used to receive the image data packet and send it to the virtual server corresponding to the detection information for processing.

[0080] Based on this, once the target physical machine is determined according to the physical machine information, the mirror data packet can be sent to the target physical machine through the physical network. At this time, after the target physical machine receives the mirror data packet submitted by the replication module through the physical network corresponding to the target physical machine, it can first determine the virtual server according to the virtual server information, so as to send the mirror data packet to the virtual server for detection of the mirror data packet.

[0081] In summary, by clearly identifying the target physical machine and virtual server through physical machine information and virtual server information, it is possible to ensure that mirrored data packets are selectively mirrored by traffic, thereby saving the transmission of invalid traffic.

[0082] In practice, when the virtual server detects the mirrored data packets, it can perform traffic billing, network detection, or network testing. In this embodiment, the virtual server is used to receive the mirrored data packets, perform traffic billing, network detection, or network testing on the mirrored data packets, and feed back the traffic billing results, network detection results, or network test results to the management platform corresponding to the cloud computing service.

[0083] Based on this, once the virtual server receives the image data packet, it can perform traffic billing, network detection, or network testing on the image data packet according to the preset service policy. The traffic billing results, network detection results, or network test results are then fed back to the management platform corresponding to the cloud computing service for maintenance. Specifically, network detection refers to NIS detection of the image data packet, and network testing refers to DDoS detection of the image data packet.

[0084] Continuing with the previous example, the mirrored data packet is routed through the switches in the physical network and sent to the physical machine with the physical address 10.10.1.1. Upon receiving the mirrored data packet, this physical machine, according to pre-configured information, forwards it to ECS1, which has a VNI of 2048 and an IP address of 192.168.100.1. After receiving the mirrored data packet, ECS1 can then perform services such as traffic metering, NIS, or DDoS detection on it.

[0085] The packet processing system provided in this embodiment aims to improve resource utilization while reducing costs and achieving rapid scaling to cope with sudden surges in public network traffic, thereby addressing issues such as low billing rates and missed security attacks. It comprises a programmable logic module (PLM) module, a private cloud service gateway, and a replication module. For raw data packets associated with cloud computing services, the PLM module determines the original description information corresponding to the raw data packet. After sending this information to the private cloud service gateway, the gateway updates the original description information to target description information according to a preset data detection strategy and feeds the target description information back to the PLM module. The PLM module then sends the raw data packet and target description information to the replication module. This ensures that only raw data packets requiring traffic mirroring carry the target description information, achieving on-demand splitting and avoiding the problem of processing all data packets, thus reducing the transmission of invalid traffic. After the replication module receives the original data packet and the target description information, and determines that the original data packet meets the detection conditions by detecting the target description information, the replication module can then construct a mirror data packet corresponding to the original data packet separately. Detection information is configured for the mirror data packet. Based on this, the mirror data packet is submitted to the virtual server according to the detection information for detection. This allows the detection of the mirror data packet to be completed on the virtual server, achieving the goal of elastic scaling of the traffic mirroring function, unaffected by objective factors of physical devices, thus solving the bottleneck of insufficient performance.

[0086] The following description, in conjunction with Figure 4, uses the application of the packet processing system provided in this disclosure in a cloud computing scenario as an example to further illustrate the packet processing system. Figure 4 shows a flowchart of the processing procedure of a packet processing system according to an embodiment of this disclosure, specifically including the following steps.

[0087] In step S402, the programmable logic module receives the image configuration information issued by the management module of the cloud computing service, determines the network device index information, virtual scalable LAN information, network address information and physical machine information based on the image configuration information, and caches the network device index information, virtual scalable LAN information, network address information and physical machine information.

[0088] During the FPGA device configuration phase, cloud computing services can be used to send the mirror configuration information to the FPGA's traffic mirroring module via the API provided by the network card driver. The mirror configuration information includes the following: Bond-ENI-index:1; sys-VNI:2048; IP_addr:192.168.100.1; member:[{nc-ip:10.10.1.1}, {nc-ip:10.10.1.2}, {nc-ip:10.10.1.3}, {nc-ip:10.10.1.4}]. Here, `Bond-ENI-index:1` indicates that the Bond-ENI used for traffic mirroring has an index of 1, a VXLAN network ID of 2048, and an overlay IP address of 192.168.100.1. This Bond-ENI contains four members, each located on a physical machine with IP addresses 10.10.1.1, 10.10.1.2, 10.10.1.3, and 10.10.1.4. Subsequently, if a data packet requiring traffic mirroring is received, the traffic mirroring function can be implemented according to this configuration information.

[0089] In step S404, the programmable logic module receives the original data packet associated with the cloud computing service through the network interface card (NIC) device, stores the original data packet in the server memory using the memory access strategy, determines the original description information corresponding to the original data packet using the NIC driver corresponding to the NIC device, and sends the original description information to the private cloud service gateway.

[0090] In step S406, the private cloud service gateway converts the public network address contained in the original description information into a private network address according to the preset data detection strategy, sets the mirror flag bit in the metadata contained in the original description information, configures the network device index information contained in the original description information, generates target description information based on the address conversion result, the setting result and the configuration result, and calls the sending function to feed the target description information back to the programmable logic module.

[0091] In step S408, the programmable logic module reads the original data packet from the server memory according to the target description information through the network card device, and sends the original data packet and target description information to the replication module using the network card driver.

[0092] After receiving a data packet, the FPGA device's network interface card (NIC) can send the packet to the server's memory for storage via DMA. The FPGA device's NIC driver can then extract the data descriptor of the original data packet and send it to XGW for processing. Upon receiving the data descriptor, XGW needs to convert the public IP address of the data packet in the data descriptor to the private IP address corresponding to the client within the VPC, and determine if the original data packet requires traffic metering and NIS processing. Therefore, the mirroring flag in the Meta path of the data packet in the data descriptor can be set, and the Bond address's index can be set to the index corresponding to any member, for example, setting the current Bond address's index to 1, thus ensuring that the original data packet has traffic mirroring attributes. XGW can then call the send function to send the processed data descriptor to the FPGA device's NIC driver. After receiving the updated data descriptor, the FPGA device can read the original data packet from the server's memory using DMA according to the updated data descriptor, move it into the hardware, process it through the service module, and then send it to the traffic mirroring module to achieve traffic mirroring of the original data packet.

[0093] In step S410, if the mirror flag is located in the metadata of the target description information and the configured network device index information is stored in the configuration table, the copy module determines that the original data packet meets the detection conditions and constructs the mirror data packet corresponding to the original data packet.

[0094] In step S412, the replication module selects the network device configuration information based on the configured network device index information, performs hash calculation on the five-tuple information corresponding to the mirror data packet to obtain the hash value, and selects the data detection node in the network device configuration information according to the hash value.

[0095] In step S414, if the detection parameters of the mirror data packet are less than the preset parameter threshold of the data detection node, the replication module adds a Virtual Scalable Local Area Network (VSDN) header to the mirror data packet. The VSDN header contains virtual server information and physical machine information. The mirror data packet is then sent to the target physical machine according to the physical machine information.

[0096] After receiving the original data packet and the updated data descriptor, the replication module can determine whether the mirror flag in the Meta information record of the updated data descriptor is set. If not, it can directly update the packet statistics, release the data descriptor, and send the original data packet from the physical link to the remote processing end. If the mirror flag is set and the Bond index exists in the configuration table, it can replicate the original data packet to obtain the mirror data packet. The original data packet can then directly update the packet statistics, release the data descriptor, and be sent from the physical link to the remote processing end.

[0097] Furthermore, for mirrored data packets, the corresponding Bond configuration can be selected first based on the Bond index. Then, the hash value (Hash1) can be calculated based on the packet's five-tuple information (sip, dip, proto, sport, dport). Based on Hash1, the corresponding member of the mirrored data packet can be selected in the Bond configuration. If member1 matches, its physical machine address (10.10.1.1) can be determined.

[0098] Furthermore, if it is determined that the mirrored data packet does not exceed the protective rate limit of member1, a VXLAN header can be appended to the outer layer of the mirrored data packet. This header contains VNI of 2048, the source IP address of XGW, and the destination address of 10.10.1.1. The mirrored data packet can then be sent to the physical network underlay network according to this information, for transmission to the physical machine corresponding to physical address 10.10.1.1 for further processing.

[0099] In step S416, the target physical machine receives the mirror data packet via Ethernet, determines the virtual server based on the virtual server information, and sends the mirror data packet to the virtual server.

[0100] In step S418, the virtual server receives the image data packet, performs traffic billing, network detection, or network testing on the image data packet, and feeds back the traffic billing results, network detection results, or network testing results to the management platform corresponding to the cloud computing service.

[0101] The mirrored data packet is routed through switches in the physical network and sent to a physical machine with a physical address of 10.10.1.1. Upon receiving the mirrored data packet, this physical machine forwards it to ECS1 with a VNI of 2048 and an IP address of 192.168.100.1, according to pre-configured information. After receiving the mirrored data packet, ECS1 can then perform services such as traffic metering, NIS, or DDoS detection on it.

[0102] In summary, to improve resource utilization while reducing costs and achieving rapid scaling to cope with sudden surges in public network traffic and address issues such as low billing costs and missed security attacks, a packet processing system can be constructed using a programmable logic module (PLM), a private cloud service gateway, and a replication module. For raw data packets associated with cloud computing services, the PLM determines the original description information corresponding to the raw data packet. After sending this information to the private cloud service gateway, the gateway updates the original description information to target description information according to a preset data detection strategy and feeds the target description information back to the PLM. The PLM then sends the raw data packet and target description information to the replication module. This ensures that only raw data packets requiring traffic mirroring carry the target description information, achieving on-demand splitting and avoiding the problem of processing all data packets, thus reducing the transmission of invalid traffic. After the replication module receives the original data packet and the target description information, and determines that the original data packet meets the detection conditions by detecting the target description information, the replication module can then construct a mirror data packet corresponding to the original data packet separately. Detection information is configured for the mirror data packet. Based on this, the mirror data packet is submitted to the virtual server according to the detection information for detection. This allows the detection of the mirror data packet to be completed on the virtual server, achieving the goal of elastic scaling of the traffic mirroring function, unaffected by objective factors of physical devices, thus solving the bottleneck of insufficient performance.

[0103] Corresponding to the above system embodiments, this disclosure also provides a data packet processing method embodiment. Figure 5 shows a flowchart of a data packet processing method provided by an embodiment of this disclosure. As shown in Figure 5, the method includes: step S502, determining the original data packet associated with the cloud computing service through a programmable logic module, and sending the original description information corresponding to the original data packet to a private cloud service gateway; step S504, updating the original description information using a preset data detection strategy of the private cloud service gateway to obtain target description information; step S506, detecting the target description information through a replication module, and constructing a mirror data packet corresponding to the original data packet if the original data packet meets the detection conditions based on the detection results; step S508, configuring detection information for the mirror data packet, and detecting the mirror data packet according to the detection information.

[0104] In one optional embodiment, the programmable logic module receives image configuration information issued by the management module of the cloud computing service, determines network device index information, virtual Scalable LAN information, network address information, and physical machine information based on the image configuration information, and caches the network device index information, the virtual Scalable LAN information, the network address information, and the physical machine information for executing the packet detection task corresponding to the original data packet.

[0105] In one optional embodiment, the programmable logic module receives the original data packets associated with the cloud computing service through the network interface card (NIC) device, stores the original data packets in the server memory using a memory access policy, determines the original description information corresponding to the original data packets using the NIC driver corresponding to the NIC device, and sends the original description information to the private cloud service gateway.

[0106] In one optional embodiment, the private cloud service gateway converts the public network address contained in the original description information into a private network address according to a preset data detection strategy, sets the mirror flag bit in the metadata contained in the original description information, configures the network device index information contained in the original description information, generates target description information based on the address conversion result, the setting result, and the configuration result, and calls a sending function to feed the target description information back to the programmable logic module.

[0107] In an optional embodiment, the programmable logic module reads the original data packet from the server memory according to the target description information through the network interface card (NIC) device, and sends the original data packet and the target description information to the copying module using the NIC driver.

[0108] In an optional embodiment, if the replication module detects that the mirror flag is located in the metadata contained in the target description information and the configured network device index information is stored in the configuration table entry, it determines that the original data packet meets the detection conditions and performs the step of constructing the mirror data packet corresponding to the original data packet.

[0109] In an optional embodiment, the replication module selects network device configuration information based on the configured network device index information, performs hash calculation on the five-tuple information corresponding to the mirrored data packet to obtain a hash value, selects a data detection node in the network device configuration information according to the hash value, and executes the step of configuring detection information for the mirrored data packet if the detection parameters of the mirrored data packet are less than the preset parameter threshold of the data detection node.

[0110] In an optional embodiment, the replication module adds a Virtual Scalable Local Area Network (VSDN) header to the mirrored data packet as detection information configured for the mirrored data packet; wherein the VSDN header includes virtual server information and physical machine information.

[0111] In one optional embodiment, the target physical machine corresponding to the physical machine information receives the image data packet submitted by the replication module through the physical network corresponding to the target physical machine, determines the virtual server according to the virtual server information, and sends the image data packet to the virtual server for detection of the image data packet.

[0112] In one optional embodiment, the virtual server receives the image data packet, performs traffic billing, network detection, or network testing on the image data packet, and feeds back the traffic billing results, network detection results, or network test results to the management platform corresponding to the cloud computing service.

[0113] The data packet processing method provided in this embodiment aims to improve resource utilization while reducing costs and achieving rapid scaling capabilities to cope with sudden surges in public network traffic, thereby addressing issues such as low billing rates and missed security attacks. It utilizes a data packet processing system comprised of a programmable logic module (PLM) module, a private cloud service gateway, and a replication module. For raw data packets associated with cloud computing services, the PLM module determines the original description information corresponding to the raw data packet. After sending this information to the private cloud service gateway, the gateway updates the original description information to target description information according to a preset data detection strategy and feeds the target description information back to the PLM module. The PLM module then sends the raw data packet and target description information to the replication module. This ensures that only raw data packets requiring traffic mirroring carry the target description information, achieving on-demand splitting and avoiding the processing of all data packets, thus reducing the transmission of invalid traffic. After the replication module receives the original data packet and the target description information, and determines that the original data packet meets the detection conditions by detecting the target description information, the replication module can then construct a mirror data packet corresponding to the original data packet separately. Detection information is configured for the mirror data packet. Based on this, the mirror data packet is submitted to the virtual server according to the detection information for detection. This allows the detection of the mirror data packet to be completed on the virtual server, achieving the goal of elastic scaling of the traffic mirroring function, unaffected by objective factors of physical devices, thus solving the bottleneck of insufficient performance.

[0114] The above is an illustrative scheme of a data packet processing method according to this embodiment. It should be noted that the technical solution of this data packet processing method and the technical solution of the data packet processing system described above belong to the same concept. For details not described in detail in the technical solution of the data packet processing method, please refer to the description of the technical solution of the data packet processing system described above.

[0115] Corresponding to the above method embodiments, this disclosure also provides a data packet processing device embodiment. Figure 6 shows a schematic diagram of the structure of a data packet processing device provided in one embodiment of this disclosure. As shown in Figure 6, the device includes: a determining unit 602, configured to determine the original data packet associated with the cloud computing service through a programmable logic module, and send the original description information corresponding to the original data packet to a private cloud service gateway; an updating unit 604, configured to update the original description information using a data detection strategy preset by the private cloud service gateway to obtain target description information; a constructing unit 606, configured to detect the target description information through a replication module, and construct a mirror data packet corresponding to the original data packet if the original data packet meets the detection conditions based on the detection result; and a detection unit 608, configured to configure detection information for the mirror data packet and detect the mirror data packet according to the detection information.

[0116] In one optional embodiment, the programmable logic module receives image configuration information issued by the management module of the cloud computing service, determines network device index information, virtual Scalable LAN information, network address information, and physical machine information based on the image configuration information, and caches the network device index information, the virtual Scalable LAN information, the network address information, and the physical machine information for executing the packet detection task corresponding to the original data packet.

[0117] In one optional embodiment, the programmable logic module receives the original data packets associated with the cloud computing service through the network interface card (NIC) device, stores the original data packets in the server memory using a memory access policy, determines the original description information corresponding to the original data packets using the NIC driver corresponding to the NIC device, and sends the original description information to the private cloud service gateway.

[0118] In one optional embodiment, the private cloud service gateway converts the public network address contained in the original description information into a private network address according to a preset data detection strategy, sets the mirror flag bit in the metadata contained in the original description information, configures the network device index information contained in the original description information, generates target description information based on the address conversion result, the setting result, and the configuration result, and calls a sending function to feed the target description information back to the programmable logic module.

[0119] In an optional embodiment, the programmable logic module reads the original data packet from the server memory according to the target description information through the network interface card (NIC) device, and sends the original data packet and the target description information to the copying module using the NIC driver.

[0120] In an optional embodiment, if the replication module detects that the mirror flag is located in the metadata contained in the target description information and the configured network device index information is stored in the configuration table entry, it determines that the original data packet meets the detection conditions and performs the step of constructing the mirror data packet corresponding to the original data packet.

[0121] In an optional embodiment, the replication module selects network device configuration information based on the configured network device index information, performs hash calculation on the five-tuple information corresponding to the mirrored data packet to obtain a hash value, selects a data detection node in the network device configuration information according to the hash value, and executes the step of configuring detection information for the mirrored data packet if the detection parameters of the mirrored data packet are less than the preset parameter threshold of the data detection node.

[0122] In an optional embodiment, the replication module adds a Virtual Scalable Local Area Network (VSDN) header to the mirrored data packet as detection information configured for the mirrored data packet; wherein the VSDN header includes virtual server information and physical machine information.

[0123] In one optional embodiment, the target physical machine corresponding to the physical machine information receives the image data packet submitted by the replication module through the physical network corresponding to the target physical machine, determines the virtual server according to the virtual server information, and sends the image data packet to the virtual server for detection of the image data packet.

[0124] In one optional embodiment, the virtual server receives the image data packet, performs traffic billing, network detection, or network testing on the image data packet, and feeds back the traffic billing results, network detection results, or network test results to the management platform corresponding to the cloud computing service.

[0125] The above is an illustrative scheme of a data packet processing apparatus according to this embodiment. It should be noted that the technical solution of this data packet processing apparatus and the technical solution of the data packet processing method described above belong to the same concept. For details not described in detail in the technical solution of the data packet processing apparatus, please refer to the description of the technical solution of the data packet processing method described above.

[0126] Figure 7 shows a structural block diagram of a computing device 700 according to an embodiment of the present disclosure. The components of the computing device 700 include, but are not limited to, a memory 710 and a processor 720. The processor 720 is connected to the memory 710 via a bus 730, and a database 750 is used to store data.

[0127] The computing device 700 also includes an access device 740, which enables the computing device 700 to communicate via one or more networks 760. Examples of these networks include Public Switched Telephone Network (PSTN), Local Area Network (LAN), Wide Area Network (WAN), Personal Area Network (PAN), or combinations of communication networks such as the Internet. The access device 740 may include one or more of any type of wired or wireless network interface (e.g., a network interface controller (NIC)), such as an IEEE 802.11 Wireless Local Area Network (WLAN) wireless interface, a Wi-MAX (Worldwide Interoperability for Microwave Access) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, or a Near Field Communication (NFC) interface.

[0128] In one embodiment of this disclosure, the aforementioned components of the computing device 700, as well as other components not shown in FIG. 7, may be interconnected, for example, via a bus. It should be understood that the computing device block diagram shown in FIG. 7 is merely for illustrative purposes and is not intended to limit the scope of this disclosure. Those skilled in the art can add or replace other components as needed.

[0129] The computing device 700 can be any type of stationary or mobile computing device, including mobile computers or mobile computing devices (e.g., tablet computers, personal digital assistants, laptop computers, notebook computers, netbooks, etc.), mobile phones (e.g., smartphones), wearable computing devices (e.g., smartwatches, smart glasses, etc.) or other types of mobile devices, or stationary computing devices such as desktop computers or personal computers (PCs). The computing device 700 can also be a mobile or stationary server.

[0130] The processor 720 is configured to execute the following computer-executable instructions, which, when executed by the processor, implement the steps of the above-described data packet processing method.

[0131] The above is an illustrative scheme of a computing device according to this embodiment. It should be noted that the technical solution of this computing device and the technical solution of the above-described data packet processing method belong to the same concept. For details not described in detail in the technical solution of the computing device, please refer to the description of the technical solution of the above-described data packet processing method.

[0132] An embodiment of this disclosure also provides a computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the steps of the above-described data packet processing method.

[0133] The above is an illustrative scheme of a computer-readable storage medium according to this embodiment. It should be noted that the technical solution of this storage medium and the technical solution of the above-described data packet processing method belong to the same concept. For details not described in detail in the technical solution of the storage medium, please refer to the description of the technical solution of the above-described data packet processing method.

[0134] An embodiment of this disclosure also provides a computer program, wherein when the computer program is executed in a computer, it causes the computer to perform the steps of the above-described data packet processing method.

[0135] The above is an illustrative example of a computer program according to this embodiment. It should be noted that the technical solution of this computer program and the technical solution of the aforementioned data packet processing method belong to the same concept. Details not described in detail in the computer program's technical solution can be found in the description of the technical solution of the aforementioned data packet processing method.

[0136] An embodiment of this disclosure also provides a computer program product, including a computer program or instructions that, when executed by a processor, implement the steps of the above-described data packet processing method.

[0137] The above is an illustrative scheme of a computer program product according to this embodiment. It should be noted that the technical solution of this computer program product and the technical solution of the above-described data packet processing method belong to the same concept. For details not described in detail in the technical solution of the computer program product, please refer to the description of the technical solution of the above-described data packet processing method.

[0138] The foregoing has described specific embodiments of this disclosure. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired results. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0139] The computer instructions include computer program code, which may be in the form of source code, object code, executable file, or certain intermediate forms. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium may be appropriately added or removed according to the requirements of patent practice. For example, in some regions, according to patent practice, computer-readable media may not include electrical carrier signals and telecommunication signals.

[0140] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of this disclosure are not limited to the described order of actions, because according to the embodiments of this disclosure, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments of this disclosure.

[0141] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0142] The preferred embodiments disclosed above are merely illustrative of this disclosure. The optional embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the embodiments of this disclosure. These embodiments are selected and specifically described in this disclosure to better explain the principles and practical applications of the embodiments of this disclosure, thereby enabling those skilled in the art to better understand and utilize this disclosure. This disclosure is limited only by the claims and their full scope and equivalents.

Claims

1. A packet processing system, comprising a programmable logic module, a private cloud service gateway, and a replication module, including: The programmable logic module is used to receive the raw data packet associated with the cloud computing service and send the original description information corresponding to the raw data packet to the private cloud service gateway. The private cloud service gateway is used to update the original description information to target description information according to a preset data detection strategy, and to feed back the target description information to the programmable logic module. The programmable logic module is used to send the original data packet and the target description information to the copy module; The replication module is used to construct a mirror data packet corresponding to the original data packet when the original data packet meets the detection conditions by detecting the target description information, configure detection information for the mirror data packet, and submit the mirror data packet to the virtual server according to the detection information for detection of the mirror data packet.

2. The data packet processing system according to claim 1, wherein the programmable logic module is further configured to receive image configuration information issued by the management module of the cloud computing service, determine network device index information, virtual Scalable Local Area Network information, network address information and physical machine information according to the image configuration information, cache the network device index information, the virtual Scalable Local Area Network information, the network address information and the physical machine information, and execute the data packet detection task corresponding to the original data packet.

3. The data packet processing system according to claim 1, wherein the programmable logic module is further configured to receive raw data packets associated with cloud computing services through a network interface card (NIC) device, store the raw data packets in server memory using a memory access strategy, determine the raw description information corresponding to the raw data packets using the NIC driver corresponding to the NIC device, and send the raw description information to the private cloud service gateway.

4. The data packet processing system according to claim 1, wherein the private cloud service gateway is configured to convert the public network address contained in the original description information into a private network address according to a preset data detection strategy, set the mirror flag bit in the metadata contained in the original description information, configure the network device index information contained in the original description information, generate target description information based on the address conversion result, the setting result and the configuration result, and call the sending function to feed back the target description information to the programmable logic module.

5. The data packet processing system according to claim 3, wherein the programmable logic module is configured to read the original data packet from the server memory according to the target description information via the network interface card (NIC) device, and send the original data packet and the target description information to the copying module using the NIC driver.

6. The packet processing system according to claim 4, wherein the copying module is configured to determine that the original packet satisfies the detection conditions and execute the step of constructing the mirror packet corresponding to the original packet when the mirror flag is located in the metadata contained in the target description information and the configured network device index information is stored in the configuration table entry.

7. The packet processing system according to claim 4 or 6, wherein the replication module is further configured to select network device configuration information according to the configured network device index information, perform hash calculation on the five-tuple information corresponding to the mirrored packet to obtain a hash value, select a data detection node in the network device configuration information according to the hash value, and perform the step of configuring detection information for the mirrored packet when the detection parameter of the mirrored packet is less than the preset parameter threshold of the data detection node.

8. The packet processing system according to claim 4 or 6, wherein the copying module is further configured to add a Virtual Extensible Local Area Network (VEX) header to the mirrored data packet as detection information configured for the mirrored data packet; wherein, The Virtual Scalable Local Area Network (VLAN) header contains virtual server information and physical machine information.

9. The data packet processing system according to claim 8, further comprising a target physical machine corresponding to the physical machine information, the target physical machine being used to receive the mirror data packet submitted by the replication module through the physical network corresponding to the target physical machine, determine a virtual server according to the virtual server information, and send the mirror data packet to the virtual server for detecting the mirror data packet.

10. The data packet processing system according to any one of claims 1 to 6, wherein the virtual server is configured to receive the mirrored data packet, perform traffic billing, network detection, or network testing on the mirrored data packet, and feed back the traffic billing result, network detection result, or network testing result to the management platform corresponding to the cloud computing service.

11. A data packet processing method, comprising: The programmable logic module determines the original data packet associated with the cloud computing service and sends the original description information corresponding to the original data packet to the private cloud service gateway. The original description information is updated using the data detection strategy preset by the private cloud service gateway to obtain the target description information; The target description information is detected by the copying module. If the original data packet meets the detection conditions based on the detection results, a mirror data packet corresponding to the original data packet is constructed. Configure detection information for the image data packet, and perform detection on the image data packet according to the detection information.

12. The data packet processing method according to claim 11, wherein the programmable logic module receives image configuration information issued by the management module of the cloud computing service, determines network device index information, virtual Scalable Local Area Network information, network address information and physical machine information according to the image configuration information, and caches the network device index information, the virtual Scalable Local Area Network information, the network address information and the physical machine information for executing the data packet detection task corresponding to the original data packet.

13. The data packet processing method according to claim 11, wherein the programmable logic module receives the original data packet associated with the cloud computing service through a network interface card (NIC) device, stores the original data packet in the server memory using a memory access strategy, determines the original description information corresponding to the original data packet using the NIC driver corresponding to the NIC device, and sends the original description information to the private cloud service gateway.

14. The data packet processing method according to claim 11, wherein the private cloud service gateway converts the public network address contained in the original description information into a private network address according to a preset data detection strategy, sets the mirror flag bit in the metadata contained in the original description information, configures the network device index information contained in the original description information, generates the target description information according to the address conversion result, the setting result and the configuration result, and calls the sending function to feed back the target description information to the programmable logic module.

15. The data packet processing method according to claim 13, wherein the programmable logic module reads the original data packet from the server memory according to the target description information through the network card device, and sends the original data packet and the target description information to the copying module using the network card driver.

16. The data packet processing method according to claim 14, wherein if the copying module detects that the mirror flag is set in the metadata contained in the target description information and the configured network device index information is stored in the configuration table entry, it determines that the original data packet meets the detection conditions and performs the step of constructing the mirror data packet corresponding to the original data packet.

17. A data packet processing apparatus, comprising: The determining unit is configured to determine the original data packet associated with the cloud computing service through a programmable logic module, and send the original description information corresponding to the original data packet to the private cloud service gateway. The update unit is configured to update the original description information using a preset data detection strategy of the private cloud service gateway to obtain the target description information; The construction unit is configured to detect the target description information through the replication module, and if the original data packet meets the detection conditions based on the detection results, construct a mirror data packet corresponding to the original data packet. The detection unit is configured to configure detection information for the image data packet and to detect the image data packet according to the detection information.

18. A computing device, comprising: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the method according to any one of claims 11 to 16.

19. A computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the steps of the method according to any one of claims 11 to 16.

20. A computer program product comprising a computer program or instructions that, when executed by a processor, implement the steps of the method of any one of claims 11 to 16.

Citation Information

Patent Citations

  • Method and device for sending fragmented message

    CN112968844A

  • Mirror image data processing method and device of cloud network and electronic equipment

    CN115580563A

  • Mirror image storage method, mirror image generation method and mirror image generation system

    CN117762552A

  • Data packet processing system, method and device

    CN119211164A

  • Mirroring network traffic of virtual networks at a service provider network

    US20200186600A1