Network device protection method, electronic device, and computer-readable storage medium
By obtaining the link status information of the control plane to generate feedback information and dynamically update the access control list, the problem of network message attacks under static policies is solved and the security protection of network equipment is achieved.
Patent Information
- Application Number
- CN202010611666.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-06-29
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2040-06-29
AI Technical Summary
In the prior art, network message attacks based on the TCP protocol are difficult to be effectively prevented. Static access control list strategies enable attackers to send targeted attack messages, causing network devices to be unable to distinguish normal protocol messages.
By obtaining the link status information of the control plane, generating feedback information and sending it to the forwarding plane, the access control list is dynamically updated, so that the forwarding plane can adjust the policy according to the feedback information.
Effectively prevent network message attacks, ensure the security of network devices, and prevent targeted sending of attack messages.
Smart Images

Figure CN113949521B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to, but are not limited to, the field of communication technology, and in particular to a network device protection method, an electronic device, and a computer-readable storage medium. Background Art
[0002] With the development and popularization of network technology, network devices have brought more convenience to people's daily lives. At the same time, with the continuous improvement of network openness, network devices are also facing more and more network attacks, such as increasingly complex network message attacks.
[0003] Among the various types of network packet attacks, the most common attack method is based on the TCP (Transmission Control Protocol) protocol. In order to suppress this type of TCP-based network packet attack, an access control list (ACL) is usually used to limit the bandwidth of protocol packets sent from the forwarding plane to the control plane, thereby preventing attack packets from attacking the control plane of network devices.
[0004] However, this method of suppressing network packet attacks usually adopts a strategy of manually and statically configuring access control lists, that is, matching fixed packet characteristics. Therefore, network packet attackers can often send targeted attack packets based on this static access control list, resulting in network devices being unable to distinguish normal protocol packets. Summary of the Invention
[0005] The embodiments of the present application provide a network device protection method, electronic device and computer-readable storage medium, which can dynamically update the access control list strategy, so that the network message attacker cannot send attack messages in a targeted manner, thereby effectively preventing network message attacks and ensuring the security of network devices.
[0006] This embodiment of the present application provides a network device protection method, which is applied to a control plane and includes:
[0007] Get link status information;
[0008] generating feedback information according to the link state information;
[0009] The feedback information is sent to the forwarding plane, so that the forwarding plane updates the access control list according to the feedback information.
[0010] Embodiments of the present application include a network device protection method, which is applied to a control plane. The method obtains link state information from the control plane, generates feedback information based on the link state information, and sends the feedback information to a forwarding plane, thereby enabling the forwarding plane to update an access control list based on the feedback information. This network device protection method dynamically updates access control list policies, preventing network packet attackers from sending targeted attack packets, thereby effectively preventing network packet attacks and ensuring the security of network devices.
[0011] The present application also provides a network device protection method, which is applied to a forwarding plane and includes:
[0012] Get feedback from the control plane;
[0013] The access control list is updated according to the feedback information.
[0014] Embodiments of the present application also include a network device protection method, which is applied to the forwarding plane and updates the access control list of the forwarding plane based on feedback information obtained from the control plane. This network device protection method can dynamically update the access control list policy, making it impossible for network packet attackers to send targeted attack packets, thereby effectively preventing network packet attacks and ensuring the security of network devices.
[0015] The present invention provides a network device protection method, which is applied to the control plane and the forwarding plane, including:
[0016] The control plane obtains link state information, generates feedback information according to the link state information, and sends the feedback information to the forwarding plane;
[0017] The forwarding plane receives the feedback information and updates the access control list according to the feedback information.
[0018] The present invention includes a method for protecting network devices. The method is applied to a control plane and a forwarding plane. The method obtains link state information from the control plane through the control plane, generates feedback information based on the link state information, and sends the feedback information to the forwarding plane. After receiving the feedback information, the forwarding plane updates the access control list based on the feedback information. This method can dynamically update the access control list policy, making it impossible for network packet attackers to send targeted attack packets, thereby effectively preventing network packet attacks and ensuring the security of network devices.
[0019] An embodiment of the present application provides an electronic device, including:
[0020] A memory, a processor, and a computer program stored in the memory and operable on the processor, wherein when the processor executes the program, the computer program:
[0021] The network device protection method applied to the control plane mentioned in the above embodiment;
[0022] or,
[0023] The network device protection method applied to the forwarding plane mentioned in the above embodiment;
[0024] or,
[0025] The network device protection method applied to the control plane and forwarding plane mentioned in the above embodiment.
[0026] An embodiment of the present application includes: an electronic device, the electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, it implements the network device protection method applied to the control plane mentioned in the above embodiment, or the network device protection method applied to the forwarding plane mentioned in the above embodiment, or the network device protection method applied to the control plane and the forwarding plane mentioned in the above embodiment. This electronic device can dynamically update the access control list policy, making it impossible for a network packet attacker to send targeted attack packets, thereby effectively preventing network packet attacks and ensuring the security of network devices.
[0027] An embodiment of the present application provides an electronic device, including:
[0028] The computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to cause a computer to execute:
[0029] The network device protection method applied to the control plane mentioned in the above embodiment;
[0030] or,
[0031] The network device protection method applied to the forwarding plane mentioned in the above embodiment;
[0032] or,
[0033] The network device protection method applied to the control plane and forwarding plane mentioned in the above embodiment.
[0034] The embodiments of the present application include: a computer-readable storage medium, the computer-readable storage medium including computer-executable instructions, the computer-executable instructions being used to cause a computer to execute the network device protection method applied to the control plane mentioned in the above embodiments, or the network device protection method applied to the forwarding plane mentioned in the above embodiments, or the network device protection method applied to the control plane and forwarding plane mentioned in the above embodiments. This computer-readable storage medium can dynamically update the access control list policy, making it impossible for a network packet attacker to send targeted attack packets, thereby effectively preventing network packet attacks and ensuring the security of network devices.
[0035] Other features and advantages of the present application will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present application. The purposes and other advantages of the present application can be achieved and obtained through the structures particularly pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 This is a flowchart of a network device protection method provided by an embodiment of the present application;
[0037] Figure 2 This is a schematic diagram of the relationship between link status information in a network device protection method provided by an embodiment of the present application;
[0038] Figure 3 This is a diagram illustrating an application example of feedback information in a network device protection method provided by an embodiment of the present application;
[0039] Figure 4 This is a diagram illustrating an application example of the first control sub-table in the network device protection method provided by one embodiment of the present application;
[0040] Figure 5 This is a diagram illustrating an application example of system header information in a network device protection method provided by an embodiment of the present application;
[0041] Figure 6 This is a diagram illustrating an application example of the second control sub-table in the network device protection method provided by one embodiment of the present application;
[0042] Figure 7 This is a flowchart of a network device protection method provided by another embodiment of the present application;
[0043] Figure 8 This is a flowchart of a network device protection method provided by another embodiment of the present application;
[0044] Figure 9This is a schematic diagram of a specific flow of step S2300 in the network device protection method provided by one embodiment of the present application;
[0045] Figure 10 This is an application example diagram of forwarding messages in a network device protection method provided by an embodiment of the present application;
[0046] Figure 11 This is a schematic diagram of a specific flow of step S2400 in the network device protection method provided by one embodiment of the present application;
[0047] Figure 12 This is a module block diagram of a network device protection method provided by an embodiment of the present application;
[0048] Figure 13 This is a module block diagram of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0049] In order to make the purpose, technical solutions and advantages of this application more clearly understood, this application is further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application. In the absence of conflict, the embodiments and features in the embodiments of this application can be combined with each other in any manner.
[0050] It should be noted that although the functional modules are divided in the device schematics and the logical order is shown in the flowcharts, in some cases, the steps shown or described may be performed in a different order than the module division in the device or the order in the flowcharts. The terms "first", "second", etc. in the specification, claims, and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or precedence. If "several" is mentioned, it means more than one; if "a plurality" is mentioned, it means more than two; if "below" is mentioned, it should be understood to include the number itself.
[0051] A common network packet attack method is based on the TCP protocol. Because the TCP protocol requires a three-way handshake to establish a connection, packet attacks targeting the handshake process can occur. Attackers exploit security flaws in the handshake process to send large numbers of SYN packets, maliciously occupying limited hardware resources of network devices, such as network device memory, network device bandwidth, and the TCP available connection queue, thereby preventing the network device from providing normal services to legitimate users.
[0052] To suppress TCP-based network packet attacks, network devices like Layer 3 switches typically use access control lists (ACLs) to limit the bandwidth used to send protocol packets from the forwarding plane to the control plane, thereby preventing attack packets from reaching the control plane. However, this method typically relies on manually configuring static access control lists, which match fixed packet characteristics. Therefore, attackers can often send targeted attack packets based on these static access control lists, making it impossible for network devices to distinguish legitimate protocol packets.
[0053] Based on this, embodiments of the present application provide a network device protection method, electronic device, and computer-readable storage medium that can dynamically update access control list policies, preventing network packet attackers from sending targeted attack packets, thereby effectively preventing network packet attacks and ensuring the security of network devices. For example, when an attacker sends targeted attack packets, the access control list can be updated based on the link status of the TCP protocol, preventing the attack packets sent by the attacker from achieving their intended purpose.
[0054] It's important to note that within a Layer 3 switch, network devices operate on two planes: the control plane and the forwarding plane. The control plane is where various network protocols operate. By controlling and managing the operation of these protocols, network devices like Layer 3 switches gain an accurate understanding of the network's devices, links, and protocols, allowing them to detect and adapt to network changes. The control plane provides the necessary information for the forwarding plane to forward data. The forwarding plane processes and forwards various types of data on the different ports of the Layer 3 switch, encapsulating and forwarding data packets. The forwarding plane handles tasks such as receiving, decapsulating, encapsulating, and forwarding data packets. For example, upon receiving a protocol packet, the system needs to decapsulate it, look up the routing table, and forward it through the outgoing interface, all of which fall under the responsibility of the forwarding plane.
[0055] In a first aspect, an embodiment of the present application provides a network device protection method for a control plane.
[0056] In some embodiments, by acquiring link state information from the control plane, generating feedback information based on the link state information, and sending the feedback information to the forwarding plane, the forwarding plane can update the access control list based on the feedback information. This network device protection method can dynamically update the access control list policy, making it impossible for network packet attackers to send targeted attack packets, thereby effectively preventing network packet attacks and ensuring the security of network devices.
[0057] In some embodiments, reference Figure 1The network device protection method applied to the control plane in the embodiment of the present application includes the following steps:
[0058] S1100, obtaining link status information;
[0059] S1200: Generate feedback information according to link status information.
[0060] S1300: Send feedback information to the forwarding plane, so that the forwarding plane updates the access control list according to the feedback information.
[0061] In step S1100, each TCP link in the control plane is monitored to obtain current link state information. Link state information refers to the link state information of the current TCP link in the control plane. Taking a TCP protocol packet as an example, the link state information of the TCP protocol packet in the control plane will change over time.
[0062] On the one hand, the link status information includes: unlinked state, semi-linked state, link completed state and link released state, which can be referred to Figure 2 When the control plane receives a new TCP protocol message from the forwarding plane, the TCP protocol message prepares to start the three-way handshake process. At this time, the link status information is in the unestablished state; when the three-way handshake process is in progress and has not yet been completed, the link status information is in the semi-connected state; when the TCP protocol message completes the three-way handshake process, the link status information is in the completed state; when the TCP protocol message times out during the three-way handshake process, resulting in incomplete link establishment, or after the TCP protocol message completes link establishment and completes corresponding business processing, or the TCP protocol message has not been used for a long time, the TCP protocol link will be released. At this time, the link status information is in the released link state. On the other hand, link status information also includes: link congestion status and retransmission status. The link congestion status means that there is a maximum number of link establishments in the control plane. When the number of established TCP links in the control plane has reached the maximum number of link establishments, it means that no more TCP protocol packets can be established in the control plane. At this time, the link status information is the link congestion status; the retransmission status means that when the TCP protocol packet is lost, repeated or out of order, the TCP protocol belongs to the retransmission message, and the link status information is the retransmission status.
[0063] In some embodiments, the control plane periodically monitors the link status information of each TCP protocol message to ensure the real-time nature of the acquired link status information, so that it can respond to and process the link status information in a timely and effective manner.
[0064] In step S1200, the control plane generates feedback information based on the acquired link state information. Figure 3The feedback information includes multiple information identifiers, including but not limited to: message characteristics, link establishment identifier, retransmission identifier, release identifier, and congestion identifier. These information identifiers can accurately express the link status information of the TCP protocol message.
[0065] It should be noted that in a possible application instance, the message feature is generated by extracting the five-tuple information of the TCP protocol message pointed to by the link state information, and using the extracted five-tuple information as the message feature of the feedback information, where the five-tuple information refers to the source IP address, source port, destination IP address, destination port and transport layer protocol of the TCP protocol message. For example, "192.168.1.1 10000 TCP 121.14.88.76 80" is a five-tuple. "192.168.1.1" is the source IP address of the protocol packet, "10000" is the source port number of the protocol packet, "TCP" indicates that the protocol packet is a TCP protocol packet, "121.14.88.76" is the destination IP address of the protocol packet, and "80" is the destination port number of the protocol packet. This means that a terminal with an IP address of 192.168.1.1 is connected to a terminal with an IP address of 121.14.88.76 and a port number of 80 via TCP through port 10000. This five-tuple effectively distinguishes different sessions, ensuring the reliability of communication services and preventing errors such as message errors, loss, delays, duplication, and reordering. The five-tuple information in the TCP protocol message is extracted as the message feature of the feedback information, so that the forwarding plane determines the TCP protocol message object according to the message feature.
[0066] The link establishment flag, retransmission flag, release flag, and congestion flag in the feedback information all default to 0 in the initial state. The information flags in the feedback information are adjusted according to different link status information. The link establishment flag is used to identify whether the TCP protocol message has established a link. If the link has not been established, the value is 0, and if the link has been established, the value is 1. The retransmission flag is used to identify whether the TCP protocol message is a retransmission message, that is, if the TCP protocol message is lost, repeated, or out of order, the value is 1, otherwise the value is 0. The release flag is used to identify the situation where the TCP protocol message has timed out during the three-way handshake process, resulting in incomplete link establishment, or after the TCP protocol message has completed link establishment and corresponding business processing, or the TCP protocol message has not been used for a long time. If any of the above situations occur, the value is 1, otherwise the value is 0. The congestion flag is used to identify whether the preset maximum number of links has been reached in the control plane. If so, the value is 1, otherwise the value is 0.
[0067] In some embodiments, feedback information is generated based on link status information, and the feedback information includes one or more of the following: retransmission flag information, congestion information, unestablished link information, established link information, and release information, and different feedback information is generated based on different link status information.
[0068] Example A1
[0069] Taking a TCP protocol message as an example, the corresponding feedback information is as follows:
[0070] When the link status information is in the unestablished state or semi-linked state and is not in the congested state, the feedback information is the unestablished link information. In this case, the message characteristics in the feedback information are the five-tuple information of the TCP protocol message, with the link establishment flag value being 0, the retransmission flag value being 0, the release flag value being 0, and the congestion flag value being 0.
[0071] When the link status information is in the link completion state, the feedback information is the link establishment information. In this case, the message characteristics in the feedback information are the five-tuple information of the TCP protocol message, with the link establishment flag value being 1, the retransmission flag value being 0, the release flag value being 0, and the congestion flag value being 0.
[0072] When the link status information indicates link congestion, the feedback information is congestion information. In this case, the message characteristics in the feedback information are the five-tuple information of the TCP protocol message. The link establishment flag can be 0 or 1, the retransmission flag is 0, the release flag is 0, and the congestion flag is 1.
[0073] When the link status information is in the retransmission state, the feedback information is the retransmission flag information. In this case, the message feature in the feedback information is the five-tuple information of the TCP protocol message. The link establishment flag can be 1, the retransmission flag is 1, the release flag is 0, and the congestion flag is 0.
[0074] When the link status information is in the link release state, the feedback information is the release information. At this time, the message characteristics in the feedback information are the five-tuple information of the TCP protocol message. The link establishment flag can be 0 or 1, the retransmission flag is 0, the release flag is 1, and the congestion flag is 0.
[0075] In some embodiments, the control plane obtains the TCP protocol message sent by the forwarding plane. In actual applications, after receiving the protocol message, the control plane will perform TCP protocol message link building or business processing on the TCP protocol message based on the number of TCP protocol links established by the control plane and the link building status of the TCP protocol message. If the TCP protocol message starts to establish a link, completes the link establishment, or completes the business processing of the TCP protocol message, the message features of the TCP protocol message, that is, the five-tuple information of the TCP protocol message, are extracted. In addition, feedback information is generated based on the extracted message features and the current link status information. The specific generation process has been discussed in detail in the above feedback information, so it will not be repeated here.
[0076] In step S1300, the control plane sends feedback information generated by encapsulating the link state information to the forwarding plane, which then updates the access control list (ACL) based on the feedback information. ACLs are used in network devices such as routers and Layer 3 switches to filter protocol packets based on preset entry conditions, such as source IP address, destination address, and port number, allowing or discarding them. Using ACLs, network devices can effectively control user access to the network, thereby maximizing network security.
[0077] In some embodiments, the forwarding plane access control list includes a first control sub-table and a second control sub-table, wherein the first control sub-table includes packet characteristics and system header information; the second control sub-table includes matching characteristics and control information. In practical applications, the first control sub-table includes several packet characteristics and corresponding system header information; the second control sub-table includes several matching characteristics and corresponding control information, the specific number of which is determined by the number of established links in the control plane.
[0078] The first control subtable is used to match received protocol messages based on message features and, based on the matching results, generate a forwarding message with system header information. Specifically, the message features are matched against protocol messages received by the forwarding plane, and the protocol messages are distinguished by matching the quintuple information of the protocol messages. The system header information corresponds to the message features, and based on the matching results of the message features and the quintuple information of the protocol messages, the system header information is encapsulated with the protocol message to generate a forwarding message with the system header information.
[0079] The second control subtable is used to perform flow control on forwarded messages generated after being processed by the first control subtable. The second control subtable matches the forwarded messages based on matching characteristics, deriving corresponding control information based on the matching results. This control information is then used to perform flow control on the forwarded messages. Specifically, the matching characteristics are matched against the system header and quintuple information in the forwarded messages, and the corresponding control information is derived based on the matching results. This control information can be adjusted based on actual needs to implement flow control on the forwarded messages.
[0080] In some embodiments, step S1300 further includes:
[0081] The feedback information is sent to the forwarding plane, so that the forwarding plane updates the first control sub-table and / or the second control sub-table according to the feedback information.
[0082] The forwarding plane updates the message characteristics and / or system header information of the first control sub-table according to the feedback information. Different feedback information updates the message characteristics and / or system header information of the first control table in different contents.
[0083] The forwarding plane updates the matching characteristics and / or control information of the second control sub-table according to the feedback information. Different feedback information updates the matching characteristics and / or control information of the first control table in different contents.
[0084] In a possible implementation example, the number of TCP protocol links established in the control plane is N. Therefore, refer to Figure 4 , the first control subtable in the forwarding plane has N+1 message features and N+1 system header information. Among them, message features 1 to message features N are updated according to the feedback information sent by the control plane, and the message features record the five-tuple information of the TCP protocol message that has been linked in the control plane, while the system header information 1 to system header information N match the information identifier in the feedback information; the message feature N+1 records the default information (i.e., coarse-grained matching information), and the default information records incomplete five-tuple information. The default information (i.e., coarse-grained matching information) here refers to setting the corresponding incomplete five-tuple information according to actual needs to match the five-tuple information in the protocol message. In this embodiment, the default information is matched with the five-tuple information in the protocol message. For example, the default information only contains the destination IP address in the five-tuple information. Then, when the destination IP address in the five-tuple information in the protocol message is the same as the destination IP address in the default information, a successful match can be achieved. Otherwise, a match cannot be achieved. The selection of the five-tuple information of the default information can be set according to actual needs.
[0085] refer to Figure 5The system header information includes but is not limited to the link establishment flag, retransmission flag, and congestion flag. The values of the link establishment flag, retransmission flag, and congestion flag are the same as those in the feedback information.
[0086] Example A2
[0087] Taking different feedback information as an example, and when the number of TCP protocol links established in the control plane is N, the system header information is updated as follows:
[0088] When the feedback information is link establishment information, the message features in the feedback information are matched with the message features of the established link in the first control subtable to obtain the corresponding system header information, and the system header information is updated to the link establishment system header. At this time, the value of the link establishment flag in the system header information is 1, the value of the retransmission flag is 0, and the value of the congestion flag is 0.
[0089] When the feedback information is retransmission information, the message characteristics in the feedback information are matched with the message characteristics of the established link in the first control subtable to obtain the corresponding system header information, and the system header information is updated to the retransmission system header. At this time, the value of the link establishment flag in the system header information is 1, the value of the retransmission flag is 1, and the value of the congestion flag is 0.
[0090] When the feedback information is congestion information, the packet characteristics in the feedback information and the unconnected packet characteristics in the first control subtable are compared. Figure 4 The system header information is matched with the message feature N+1 in the packet to obtain the corresponding system header information, which is then updated to the congestion system header. At this time, the value of the link establishment flag in the system header information is 0, the value of the retransmission flag is 0, and the value of the congestion flag is 1.
[0091] When the feedback information is release information, the message features in the feedback information are matched with the message features of the established link in the first control subtable. At this time, the first control subtable will delete the matched message features and corresponding system header information in the first control subtable according to the release information.
[0092] When the feedback information is information about unestablished links, the message features in the feedback information are matched with the message features of the unestablished links in the first control subtable to obtain the corresponding system header information, and the system header information is updated to the unestablished link system header. At this time, the value of the link establishment flag in the system header information is 0, the value of the retransmission flag is 0, and the value of the congestion flag is 0.
[0093] In a possible application example, the matching features in the second control subtable include message features, link establishment flag, retransmission flag and congestion flag. These three matching features are used to synchronously update the message features, link establishment flag, retransmission flag and congestion flag in the feedback information, and to match the message features, link establishment flag, retransmission flag and congestion flag in the system header information in the forwarded message.
[0094] Example A3
[0095] Taking different feedback information as an example, the matching characteristics and control information update content of the second control sub-table are as follows:
[0096] When the feedback information is link establishment information, the message features in the matching features of the second control subtable are updated to the message features in the feedback information. At this time, the value of the link establishment flag in the matching features is 1, the value of the retransmission flag is 0, the value of the congestion flag is 0, and the corresponding control information is set to allocate the maximum bandwidth.
[0097] When the feedback information is retransmission information, the message features in the matching features of the second control subtable are updated to the message features in the feedback information. In this case, the link establishment flag in the matching features is set to 1, the retransmission flag is set to 1, and the congestion flag is set to 0. The corresponding control information is set to sample and send messages. The retransmission flag is used to identify protocol messages in the forwarding plane as retransmission messages, and these retransmission messages are sampled and sent. This reduces the number of retransmission messages sent to the control plane, effectively preventing unnecessary hardware resource waste caused by receiving a large number of retransmission messages, which can affect the processing performance of network devices.
[0098] When the feedback information is congestion information, the message features in the matching features of the second control subtable are default information. At this time, the value of the link establishment flag in the matching features is 0, the value of the retransmission flag is 0, and the value of the congestion flag is 1. The corresponding control information is set to close the message sending channel.
[0099] When the feedback information indicates that the link is not established, the message feature in the matching feature of the second control sub-table is the default information (i.e., coarse-grained matching information). At this time, the value of the link establishment flag in the matching feature is 0, the value of the retransmission flag is 0, and the value of the congestion flag is 0. The corresponding control information is set to allocate low bandwidth.
[0100] The method for protecting network equipment in the control plane provided in the embodiments of the present application comprises the following steps: obtaining link state information of the control plane; generating feedback information according to the link state information; and sending the feedback information to the forwarding plane, so that the forwarding plane can update an access control list according to the feedback information. Through the method for protecting network equipment, the policy of the access control list can be dynamically updated, so that an attack message sender cannot send attack messages in a targeted manner, thereby effectively preventing network message attacks and ensuring the security of network equipment.
[0101] In the second aspect, the embodiments of the present application provide a method for protecting network equipment in the forwarding plane.
[0102] In some embodiments, feedback information from the control plane is obtained, and an access control list of the forwarding plane is updated according to the feedback information. Through the method for protecting network equipment, the policy of the access control list can be dynamically updated, so that an attack message sender cannot send attack messages in a targeted manner, thereby effectively preventing network message attacks and ensuring the security of network equipment.
[0103] In some embodiments, the feedback information from the control plane comprises one or more of the following: retransmission flag information, congestion information, un-established link information, established link information, and release information. Figure 7 The method for protecting network equipment in the forwarding plane provided in the embodiments of the present application comprises the following steps:
[0104] S2100, obtaining feedback information from the control plane;
[0105] S2200, updating an access control list according to the feedback information.
[0106] In step S2100, the forwarding plane obtains feedback information from the control plane, wherein the feedback information comprises one or more of the following: retransmission flag information, congestion information, un-established link information, established link information, and release information.
[0107] The specific encapsulation and generation of the feedback information such as the retransmission flag information, the congestion information, the un-established link information, the established link information, and the release information have been described in detail in the example A1 of the first aspect, and thus will not be described again.
[0108] In step S2200, the forwarding plane updates an access control list according to the received feedback information, wherein the access control list comprises a first control sub-table and a second control sub-table, and the first control sub-table comprises a plurality of message characteristics and a plurality of corresponding system header information; and the second control sub-table comprises a plurality of matching characteristics and a plurality of corresponding control information. Figure 4 Figure 6
[0109] In some embodiments, the forwarded message updates the message characteristics and / or system header information of the first control sub-table based on the received feedback information; the forwarded message updates the matching characteristics and / or control information of the second control sub-table based on the received feedback information. The specific update content has been discussed in detail in Example A2 and Example A3 of the first aspect embodiment, so it will not be repeated here.
[0110] In some embodiments, reference Figure 8 In the embodiment of the present application, the network device protection method further includes the following steps:
[0111] S2300: The forwarding plane encapsulates the acquired protocol message according to the first control subtable to generate a forwarding message.
[0112] S2400: The forwarding plane performs flow control on the forwarded message according to the second control subtable.
[0113] In some embodiments, reference Figure 9 , step S2300 further includes the steps of:
[0114] S2310: extracting message features of the protocol message and matching them with message features in the first control subtable;
[0115] S2320: Encapsulate the corresponding system header information and the protocol message to obtain a forwarding message with the system header information.
[0116] S2330: reject the protocol message.
[0117] S2340: Send the forwarding message carrying the system header information to the second control subtable.
[0118] In step S2310, after receiving the protocol message transmitted by the network, the forwarding plane extracts the message features of the protocol message, that is, the five-tuple information of the protocol message, and matches the five-tuple information with the message features in the first control subtable. Different protocol messages have different matching message features. For example, when the protocol message is in an unlinked state in the control plane, the five-tuple information of the protocol message is matched with the message features representing the default information in the first control sub-table, wherein the default information (i.e., coarse-grained matching information) refers to incomplete five-tuple information. The default information here (i.e., coarse-grained matching information) refers to setting the corresponding incomplete five-tuple information according to actual needs to match the five-tuple information in the protocol message. For example, if the default information only contains the destination IP address in the five-tuple information, then the match can be successful only when the destination IP address in the five-tuple information in the protocol message is the same as the destination IP address in the default information. Otherwise, the match cannot be made. The selection of the five-tuple information of the default information can be set according to actual needs. When the protocol message is in a link-established state in the control plane, the five-tuple information of the protocol message is matched with the message features representing the complete five-tuple information in the first control sub-table.
[0119] If the message features of the protocol message match the message features of the first control subtable, proceed to step S2320; if the message features of the protocol message do not match the message features of the first control subtable, proceed to step S2330.
[0120] In step S2320, the system header information corresponding to the first control sub-table is obtained according to the matching result, such as Figure 4 As shown in , different message features correspond to different system header information. The obtained system header information is encapsulated with the protocol message to generate Figure 10 The forwarded message shown includes a system header message, wherein the forwarded message includes a protocol message and system header information. The system header information includes, but is not limited to, a link establishment flag, a retransmission flag, and a congestion flag. Different protocol messages have different link states in the control plane, and therefore the values of the link establishment flag, retransmission flag, and congestion flag in the system header information also vary. The specific values have been discussed in detail in Example A2 of the first aspect of the application embodiment and will not be repeated here.
[0121] In some embodiments, the forwarding plane matches the protocol message based on the message characteristics of the first control subtable and generates a forwarding message with system header information based on the matching result. This is accomplished by extracting quintuple information from the protocol message and matching it with the message characteristics of the first control table. Based on the matching result, corresponding system header information is obtained, and the system header information is encapsulated with the protocol message to generate a forwarding message with the system header information.
[0122] In step S2330, if the message characteristics of the protocol message do not match the message characteristics of the first control subtable, it means that the protocol message is an illegal protocol message and there is a certain risk. Therefore, the first control table will reject the transmission of the protocol message, thereby protecting the network device.
[0123] In step S2340, after the first control subtable matches the protocol message according to the message characteristics and generates a forwarding message with the system header information, the forwarding message is sent to the second control subtable.
[0124] In some embodiments, reference Figure 11 , step S2400 further includes the steps of:
[0125] S2410, receiving a forwarding message from the first control subtable;
[0126] S2420, extracting message features and system header information of the forwarded message;
[0127] S2430, matching the extracted message features and system header information with the matching features of the second control sub-table to obtain corresponding control information;
[0128] S2440: Perform flow control according to the obtained control information.
[0129] In step S2410, the second control sub-table receives the forwarding message sent from the first control sub-table. Figure 10 The diagram shows protocol packets and system header information, wherein the system header information includes but is not limited to a link establishment flag, a retransmission flag, and a congestion flag.
[0130] In step S2420, the second control subtable extracts the message features and system header information in the forwarded message for use in step S2430.
[0131] In step S2430, the matching characteristics of the second control sub-table are matched with the message characteristics and system header information in the forwarded message to obtain the corresponding control information. Figure 6 As shown, the matching features and the control information are one-to-one corresponding.
[0132] In step S2440, corresponding flow control is performed according to the obtained control information, wherein the control information can be set according to actual needs.
[0133] In Example A3 of the first aspect of the embodiment, it is mentioned that the matching features are updated according to different feedback information, thereby being updated to different matching features. The different matching features are matched with the message features and system header information of the forwarded message to obtain different control information.
[0134] In some embodiments, when the feedback information sent by the control plane to the forwarding plane is retransmission flag information, the corresponding system header information of the first control subtable will be updated to retransmission information, and the matching feature of the second control subtable will be updated to the retransmission feature. Therefore, when the forwarding plane receives the protocol message, it will go through the first control subtable in turn for traffic differentiation and the second control subtable for traffic control.
[0135] Correspondingly, when a received protocol message matches the message signature of the first control subtable, a forwarding message with retransmission information is generated based on the matching result. The forwarding message with retransmission information is then matched with the retransmission signature of the second control subtable to obtain control information, where the control information is set to sample and send. The protocol message is sampled and sent based on this control information. The retransmission flag is used to identify protocol messages within the forwarding plane as retransmission messages, and these retransmission messages are sampled and sent based on the control information. This reduces the number of retransmission messages sent to the control plane, effectively preventing unnecessary hardware resource waste caused by receiving a large number of retransmission messages, which can impact the processing performance of network devices.
[0136] Example A4
[0137] Taking the matching features and control information mentioned in Example A3 of the embodiment of the first aspect as an example, it is described as follows:
[0138] When a forwarded message is determined to be an established link message based on the system header information, the forwarded message successfully matches the matching characteristics of the second control subtable, the link establishment flag of the system header information is 1, and the retransmission flag is 0. The obtained control information allocates the maximum bandwidth for the TCP protocol message to ensure that TCP service traffic does not experience packet loss on the forwarding plane and prompts the control plane to complete service processing as quickly as possible;
[0139] When the forwarded message is determined to be an unconnected message based on the system header information and the number of TCP links maintained in the control plane has not reached the maximum number of connected links, the forwarded message successfully matches the matching characteristics of the second control subtable. At this time, the quintuple information of the forwarded message matches the default information in the matching characteristics, the connection flag of the system header information is 0, and the congestion flag is 0. The obtained control information allocates low bandwidth to the TCP protocol message, so that the TCP protocol message does not occupy too many resources during the connection establishment process;
[0140] When the forwarded message is determined to be an unconnected message based on the system header information and the number of TCP links maintained in the control plane has reached the maximum number of established links, the forwarded message successfully matches the matching characteristics of the second control subtable. At this time, the quintuple information of the forwarded message matches the default information in the matching characteristics, the connection flag in the system header information is 0, and the congestion flag is 1. The control information obtained is to close the sending channel, so that the TCP protocol message can no longer be sent to the control plane;
[0141] When the forwarded message is determined to be a retransmitted message based on the system header information, the forwarded message successfully matches the matching features of the second control subtable, the link establishment flag of the system header information is 1, and the retransmission flag is 1, then the control information obtained is sampled and uploaded for the TCP protocol message to avoid a large number of retransmitted messages being sent to the control plane, thereby avoiding the occupation of network device resources.
[0142] The present invention provides a control plane network device protection method that obtains feedback from the control plane and updates the access control list of the forwarding plane based on the feedback information. This network device protection method can dynamically update the access control list policy, making it impossible for network packet attackers to send targeted attack packets, thereby effectively preventing network packet attacks and ensuring the security of network devices.
[0143] In a third aspect, the present invention provides a method for protecting network devices for control plane and forwarding.
[0144] In some embodiments, the control plane obtains link state information from the control plane, generates feedback information based on the link state information, and sends the feedback information to the forwarding plane. After receiving the feedback information, the forwarding plane updates the access control list based on the feedback information. This network device protection method can dynamically update the access control list policy, making it impossible for network packet attackers to send targeted attack packets, thereby effectively preventing network packet attacks and ensuring the security of network devices.
[0145] In the possible application examples, refer to Figure 12 The control plane 100 generates feedback information based on the link status information obtained by the generation module 120, and sends the generated feedback information to the forwarding plane 200. The forwarding plane 200 updates the access control list 210 according to the received feedback information, wherein the access control list 210 includes a first control sub-table 211 and a second control sub-table 212. The introduction of the first control sub-table 211 and the second control sub-table 212 and the specific update of the first control sub-table 211 and the second control sub-table 212 have been discussed in detail in the embodiments of the first aspect and the second aspect, so they will not be repeated here.
[0146] On the one hand, the control plane 100 processes the protocol messages received from the forwarding plane 200 through the processing module 110, establishes a link for the protocol message according to the queue status of the current protocol message, and periodically calculates the link status information of each TCP protocol in the control plane 100, generates feedback information based on the link status information, and sends the feedback information to the forwarding plane 200. After receiving the feedback information, the forwarding plane 200 updates the access control list 210, thereby dynamically updating the policy of the access control list 210, so that the network message attacker cannot send targeted attack messages, thereby effectively preventing network message attacks and ensuring the security of network devices.
[0147] On the other hand, the forwarding plane 200 includes an access control list 210, wherein the access control list 210 includes a first control sub-table 211 and a second control sub-table 212. The first control sub-table 211 distinguishes the received protocol messages and encapsulates them to generate forwarding messages, and sends the forwarding messages to the second control sub-table 212. The second control sub-table 212 matches the forwarding messages and implements flow control of the protocol messages based on the matching results. The specific processing flow has been discussed in detail in the first and second aspect embodiments, so it will not be repeated here.
[0148] In a fourth aspect, the present application also provides an electronic device, referring to Figure 13 , comprising: at least one processor 1000, and a memory 2000 communicatively connected to the at least one processor 1000;
[0149] In which, the processor 1000 is used to execute the network device protection method applied to the control plane in the first aspect embodiment, the network device protection method applied to the forwarding plane in the second aspect embodiment, or the network device protection method applied to the control plane and forwarding plane in the third aspect embodiment by calling the computer program stored in the memory 2000.
[0150] The memory 2000, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer executable programs, such as the network device protection method applied to the control plane in the first embodiment of the present application, the network device protection method applied to the forwarding plane in the second embodiment of the present application, or the network device protection method applied to the control plane and forwarding plane in the third embodiment of the present application. The processor 1000 implements the network device protection method applied to the control plane in the first embodiment, the network device protection method applied to the forwarding plane in the second embodiment of the present application, or the network device protection method applied to the control plane and forwarding plane in the third embodiment of the present application by running the non-transitory software programs and instructions stored in the memory 2000.
[0151] The memory 2000 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store the execution of the network device protection method applied to the control plane in the first embodiment or the network device protection method applied to the forwarding plane in the second embodiment or the network device protection method applied to the control plane and forwarding plane in the third embodiment. In addition, the memory 2000 may include a high-speed random access memory 2000, and may also include a non-volatile memory 2000, such as at least one disk storage 2000 piece, a flash memory device, or other non-volatile solid-state memory 2000 piece. In some embodiments, the memory 2000 may optionally include a memory 2000 remotely arranged relative to the processor 1000, and these remote memories 2000 may be connected to the terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0152] The non-transient software programs and instructions required to implement the network device protection method applied to the control plane in the first aspect embodiment or the network device protection method applied to the forwarding plane in the second aspect embodiment or the network device protection method applied to the control plane and forwarding plane in the third aspect embodiment are stored in the memory 2000. When executed by one or more processors 1000, the network device protection method applied to the control plane in the first aspect embodiment or the network device protection method applied to the forwarding plane in the second aspect embodiment or the network device protection method applied to the control plane and forwarding plane in the third aspect embodiment are executed.
[0153] In a fifth aspect, an embodiment of the present application further provides a computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are used to: execute the network device protection method applied to the control plane in the embodiment of the first aspect, the network device protection method applied to the forwarding plane in the embodiment of the second aspect, or the network device protection method applied to the control plane and forwarding plane in the embodiment of the third aspect;
[0154] In some embodiments, the computer-readable storage medium stores computer-executable instructions, which are executed by one or more control processors 1000, for example, by a processor 1000 in the electronic device of the fourth aspect embodiment, so that the one or more processors 1000 can execute the network device protection method applied to the control plane in the first aspect embodiment or the network device protection method applied to the forwarding plane in the second aspect embodiment or the network device protection method applied to the control plane and forwarding plane in the third aspect embodiment.
[0155] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of this embodiment.
[0156] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of this embodiment.
[0157] Those skilled in the art will appreciate that all or some of the steps and systems in the method disclosed above can be implemented as software, firmware, hardware, and appropriate combinations thereof. Some physical components or all physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, and the computer-readable medium can include computer storage media (or non-transitory media) and communication media (or temporary media). As known to those skilled in the art, the term computer storage media is included in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data) and is volatile and non-volatile, removable, and non-removable. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory, or other memory technology, CD-ROM, digital versatile disks (DVD), or other optical disk storage, magnetic cassettes, magnetic tapes, disk storage, or other magnetic storage devices, or any other medium that can be used to store desired information and can be accessed by a computer. Furthermore, as is well known to those skilled in the art, communication media typically embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.
[0158] The above is a specific description of the preferred implementation of the present application, but the present application is not limited to the above implementation mode. Technical personnel familiar with the field can also make various equivalent modifications or substitutions without violating the spirit of the present application. These equivalent modifications or substitutions are all included in the scope defined by the claims of the present application.
Claims
1. A network device protection method, characterized in that: Applied to the control plane, including: Obtain link state information; the link state information refers to the link state information of the current TCP link in the control plane; generating feedback information according to the link state information; Sending the feedback information to the forwarding plane, so that the forwarding plane updates the access control list according to the feedback information; The access control list includes: a first control subtable, the first control subtable including message features and system header information, the first control subtable being used to match protocol messages received by the forwarding plane according to the message features and generate forwarding messages with the system header information based on the matching results; the first control subtable being further used to differentiate traffic flows after the forwarding plane receives the protocol message using the first control subtable; the system header information being updated based on link state information when corresponding message features in the first control subtable match message features in feedback information; a second control subtable, the second control subtable including a matching feature and control information, the second control subtable being used to match the forwarded message according to the matching feature to obtain the control information, and perform flow control on the forwarded message according to the control information, wherein the matching feature is matched with system header information and quintuple information carried in the forwarded message; The matching feature of the second control sub-table is updated by the forwarding plane according to the feedback information.
2. The network device protection method according to claim 1, characterized in that: The feedback information is used to identify the link status information, and the feedback information includes one or more of the following: retransmission flag information, congestion information, unestablished link information, established link information, and release information.
3. The network device protection method according to claim 2, characterized in that: Also includes: Obtain protocol packets sent by the forwarding plane; Extracting message features of the protocol message; The generating feedback information according to the link state information includes: The feedback information is generated according to the message characteristics and the link status information.
4. The network device protection method according to any one of claims 1 to 3, characterized in that: The message features stored in the first control subtable include default information, which records part of the five-tuple information; the default information is at least used to update the system header information corresponding to the default information to an unlinked system header when the feedback information is unlinked information and the default information matches the protocol message sent by the forwarding plane; when the feedback information is unlinked information, the message features in the matching features of the second control subtable are default information.
5. The network device protection method according to claim 4, characterized in that: The sending the feedback information to the forwarding plane so that the forwarding plane updates the access control list according to the feedback information includes: The feedback information is sent to a forwarding plane, so that the forwarding plane updates the first control sub-table and / or the second control sub-table according to the feedback information.
6. A network device protection method, characterized in that: Applicable to the forwarding plane, including: Obtaining feedback information from the control plane; the feedback information is generated based on link state information; the link state information refers to the link state information of the current TCP link in the control plane; updating the access control list according to the feedback information; The access control list includes: a first control subtable, the first control subtable including message features and system header information, the first control subtable being used to match protocol messages received by the forwarding plane according to the message features and generate forwarding messages with the system header information based on the matching results; the first control subtable being further used to differentiate traffic flows after the forwarding plane receives the protocol message using the first control subtable; the system header information being updated based on link state information when corresponding message features in the first control subtable match message features in feedback information; The second control subtable includes a matching feature and control information. The second control subtable is used to match the forwarded message according to the matching feature to obtain the control information, and perform flow control on the forwarded message according to the control information. The matching feature is matched with the system header information and quintuple information contained in the forwarded message. The matching feature is updated by the forwarding plane based on the feedback information.
7. The network device protection method according to claim 6, characterized in that: The feedback information includes one or more of the following: retransmission flag information, congestion information, link unestablished information, link establishment information, and release information.
8. The network device protection method according to claim 6, characterized in that: The updating of the access control list according to the feedback information further includes: The forwarding plane updates the message feature of the first control subtable according to the feedback information; The forwarding plane updates the control information according to the feedback information.
9. The network device protection method according to claim 6, characterized in that: include: When the feedback information includes retransmission flag information, the corresponding system header information includes retransmission information, and the matching feature includes a retransmission feature; Correspondingly, The forwarding plane matches the protocol message according to the message feature in the first control subtable, and encapsulates and generates the forwarding message with the retransmission information according to the matching result; The forwarding plane matches the forwarding message with the retransmission information according to the retransmission feature of the second control subtable to obtain the control information, and samples and uploads the protocol message according to the control information.
10. A network device protection method, characterized in that: A control plane for executing the network device protection method according to any one of claims 1 to 5 and a forwarding plane for executing the network device protection method according to any one of claims 6 to 9, comprising: The control plane obtains link state information, generates feedback information according to the link state information, and sends the feedback information to the forwarding plane; The forwarding plane receives the feedback information and updates the access control list according to the feedback information.
11. Electronic equipment, including: A memory, a processor, and a computer program stored in the memory and operable on the processor, wherein when the processor executes the program, the computer program: The network device protection method according to any one of claims 1 to 5; or, The network device protection method according to any one of claims 6 to 9; or, The network device protection method as described in claim 10.
12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to cause a computer to execute: The network device protection method according to any one of claims 1 to 5; or, The network device protection method according to any one of claims 6 to 9; or, The network device protection method as described in claim 10.
Citation Information
Patent Citations
SDN (self-defending network) firewall state detecting method and system based on OpenFlow protocol
CN104104561A
A network traffic scheduling method and device
CN109743259A
Method for message access control, forwarding engine and communication device
CN1996939A
Securing devices using network traffic analysis and software-defined networking (SDN)
US20180234454A1