A message processing method, system, and device

By detecting the bandwidth consumption of high-priority packets in network devices and obtaining the characteristic information of attack packets, a processing strategy is generated, which solves the congestion problem of network devices under high-priority attacks and realizes the effective forwarding of normal packets and performance improvement.

CN114268592BActive Publication Date: 2025-10-31HUAWEI TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202010966693.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-09-15
Publication Date
2025-10-31
Estimated Expiration
2040-09-15

AI Technical Summary

Technical Problem

In existing technologies, network devices are unable to effectively identify and process high-priority attack packets, resulting in bandwidth being occupied, affecting the forwarding of normal packets, and even preventing the network devices from providing normal services.

Method used

By setting conditions in network devices to detect the bandwidth occupied by packets with the highest forwarding priority, when a certain threshold is reached, the characteristic information of the attack packets is obtained and sent to the control and management entity to generate packet processing policies and implement packet loss or rate limiting to suppress the attack packets.

Benefits of technology

Effectively identify and process attack packets, avoid network device congestion, ensure the forwarding of high-priority normal packets, reduce forwarding latency, and improve the forwarding performance of network devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114268592B_ABST
    Figure CN114268592B_ABST
Patent Text Reader

Abstract

This application discloses a message processing method, system, and device, including: a first communication device determining that when the bandwidth occupied by a message with the highest forwarding priority transmitted through a first port meets a first condition, it acquires the feature information of a first attack message included in the message with the highest forwarding priority transmitted through the first port, and sends the feature information of the first attack message to a control management entity. In this way, the control management entity can generate a message processing strategy based on the message features of the received attack message. Thus, the communication device can perform packet loss and / or rate limiting on messages that match the feature information of the attack message based on the message processing strategy, avoiding network device congestion caused by attacks based on high-priority messages, ensuring that normal messages with the highest forwarding priority can be effectively forwarded, and enabling the communication device to provide normal services.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a message processing method, system and device. Background Technology

[0002] Network devices typically forward packets in an orderly manner according to their forwarding priority. Packets with higher forwarding priority are forwarded first. For protocol packets, network device detection packets, and critical data packets, proper forwarding is essential for the normal operation of the network devices. Therefore, these packets are usually set to the highest forwarding priority to ensure effective processing and thus guarantee the normal operation of the network devices.

[0003] However, if a network device receives an attack packet with the highest forwarding priority, these attack packets will also be processed first. Since the total bandwidth of each network device is limited, if the number of attack packets surges and the total bandwidth of the highest forwarding priority packets exceeds the total bandwidth of the network device, the network device will drop packets corresponding to the highest forwarding priority. This could result in the loss of protocol packets, network device detection packets, or important data packets, causing the network device to be unable to provide normal services.

[0004] Currently, by manually configuring security policy templates on network devices, the devices can identify secure packets from received messages, forward them normally, and discard unidentified packets, thus defending against attack packets and improving network security. However, this technical solution, because the security policy templates are fixed, cannot effectively defend against ever-changing attack packets.

[0005] Therefore, there is an urgent need to provide a message processing method that enables network devices to effectively identify and process attack messages, ensuring that the highest priority security messages are effectively forwarded. Summary of the Invention

[0006] Based on this, embodiments of this application provide a message processing method, system, and device. Before the network device becomes congested due to an attack message with the highest forwarding priority, the network device can identify and process the attack message, ensuring that the security message with the highest forwarding priority is effectively forwarded, thus enabling the network device to provide normal services.

[0007] In a first aspect, embodiments of this application provide a message processing method, which may include: when a first communication device determines that the bandwidth occupied by a message with the highest forwarding priority transmitted through a first port meets a first condition, it acquires feature information of a first attack message included in the message with the highest forwarding priority transmitted through the first port, and sends the feature information of the first attack message to a control and management entity. The first condition is a condition configured by the first communication device for the first port to determine whether to process the attack message on the first port. In this way, the control and management entity can generate a message processing strategy based on the message features of the received first attack message. Therefore, the first communication device can, based on the message processing strategy, perform packet loss and / or rate limiting on messages matching the feature information of the first attack message, avoiding network device congestion caused by attacks based on high-priority messages, ensuring that normal messages with the highest forwarding priority can be effectively forwarded, and enabling the first communication device to provide normal services.

[0008] In some possible implementations, after the first communication device sends the characteristics of the first attack message to the control and management entity, the control and management entity can also generate a message processing strategy based on the characteristic information of the first attack message. The first communication device obtains the message processing strategy, which is used to process messages that match the characteristic information of the first attack message. If the control and management entity is a functional module within the first communication device, the first communication device can acquire the message processing strategy through internal data transmission. If the control and management entity and the first communication device are two different devices, the first communication device can acquire the message processing strategy through messages. These messages can be any of the following: Border Gateway Protocol (BGP) messages, Path Computation Element Communication Protocol (PCEP) messages, Telemetry messages, or Network Configuration Protocol (NETCONF) messages. For example, the message processing strategy can carry the characteristic information of the first attack message in the extended Type Length Value (TLV) field of the instruction message. In this way, by acquiring the message processing strategy generated by the control and management entity, a prerequisite is provided for subsequent processing of messages matching the characteristic information of the first attack message, making it possible to effectively forward normal messages with the highest forwarding priority on the network device. It should be noted that the following description uses the example of the control and management entity and the first communication device being two independent network devices.

[0009] In other possible implementations, after the first communication device receives the message processing policy, it can process the first message based on the policy. This first message is one whose feature information matches that of the first attack message. In this way, by setting conditions and triggering related operations, attack messages with the highest forwarding priority can be effectively suppressed before causing severe network congestion. This prevents a large number of attack messages with the highest forwarding priority from monopolizing the bandwidth resources of normal messages on the network device, thus avoiding the dropping of normal messages with the highest forwarding priority and affecting the normal operation of the network. Furthermore, as attack messages are effectively suppressed, the forwarding latency of normal messages with the highest forwarding priority can be reduced, improving forwarding performance.

[0010] As an example, the first communication device processes the first message based on a message processing strategy, which may include: performing packet loss processing on the first message based on the message processing strategy. Alternatively, as another example, the first communication device may process the first message based on a message processing strategy, which may also include: performing rate limiting processing on the first message based on the message processing strategy. In this way, by performing suppression processing such as packet loss or rate limiting on the first message that matches the feature information of the first attack message, the attack message is effectively prevented from preempting a large amount of bandwidth resources of normal messages with the highest forwarding priority, thus reducing the forwarding latency of normal messages with the highest forwarding priority.

[0011] In this system, the first communication device, in addition to sending the characteristic information of the first attack message to the control and management entity, can also send indication information to the control and management entity. This indication information is used to instruct the control and management entity to generate a message processing strategy. In one scenario, the first communication device can send the indication information and the characteristic information of the first attack message separately in different indication messages to the control and management entity. In another scenario, the first communication device can send the indication information and the characteristic information of the first attack message together in the same indication message to the control and management entity. This indication message can be any of the following types of messages: BGP message, PCEP message, Telemetry message, or NETCONF message. For example, the indication information and the characteristic information of the first attack message can be carried through the extended TLV field in any of the above-mentioned message types. Alternatively, the indication information and the characteristic information of the first attack message can also be carried through other available fields such as the Reserved field in any of the above-mentioned message types.

[0012] The first condition may include the proportion of bandwidth occupied by the highest forwarding priority packets transmitted through the first port being greater than or equal to a first threshold. For example, if the first threshold is 70%, the bandwidth of the first port is 20 megabytes per second (Gb / s), and the first communication device obtains that the highest forwarding priority packets transmitted through the first port are at a rate of 15 Gb / s, then the first communication device determines that the proportion of bandwidth occupied by the highest forwarding priority packets on the first port is (15 ÷ 20) = 75%, which is greater than the first threshold of 70%, thus determining that the bandwidth occupied by the highest forwarding priority packets transmitted through the first port satisfies the first condition. Alternatively, the first condition may also include the proportion of highest forwarding priority packets transmitted through the first port being greater than or equal to a second threshold. For example, if the second threshold is 15Gb / s and the bandwidth of the first port is 20Gb / s, and the first communication device obtains that the highest forwarding priority message transmitted through the first port is 15Gb / s, then the first communication device determines that the size of the highest forwarding priority message on the first port is equal to the second threshold of 15Gb / s, thereby determining that the highest forwarding priority message transmitted through the first port occupies the bandwidth of the first port and satisfies the first condition.

[0013] In some possible implementations, the first communication device can poll the bandwidth usage of each port. Taking the first port as an example, the first communication device can poll the bandwidth usage of the first port. For example, this can be achieved through a timer in the traffic management (TM) module of the first communication device. The TM module sets the timer interval to 1 second, and when the timer reaches 1 second, it obtains the size of a packet transmitted through the first port. In specific implementation, the first communication device polls the bandwidth usage of the first port, obtains the size of all packets transmitted through the first port, and then determines whether the bandwidth occupied by all packets transmitted through the first port meets the second condition. If not, it continues to poll. If it meets the condition, it continues to obtain the size of the highest forwarding priority packet transmitted through the first port and determines whether the bandwidth occupied by the highest forwarding priority packet transmitted through the first port meets the first condition; otherwise, it continues to poll. The second condition can refer to the proportion of bandwidth occupied by all packets transmitted through the first port being greater than or equal to the third threshold, or it can refer to the proportion of bandwidth occupied by all packets transmitted through the first port being greater than or equal to the fourth threshold. Therefore, when the first communication device determines through polling that all packets transmitted through the first port meet the second condition, it indicates that there are many packets transmitted through the first port, posing a risk of congestion. It is necessary to focus on the bandwidth occupancy of the most important highest forwarding priority packets. At this point, when it is determined that the bandwidth occupied by the highest forwarding priority packets transmitted through the first port meets the first condition, it can be assumed that there may be attack packets among the highest forwarding priority packets transmitted on the first port. In other words, the polling mechanism and the two judgment conditions provide the prerequisite and guarantee for the normal forwarding of the highest forwarding priority packets transmitted through the first port on the first communication device.

[0014] In some other possible implementations, a third condition corresponding to the first condition of the first port is also set for the second port of the first communication device. The message processing on the second port may include, for example, the following: when the first communication device determines that the bandwidth occupied by the highest forwarding priority message transmitted through the second port meets the third condition, it acquires the feature information of the second attack message included in the highest forwarding priority message transmitted through the second port, and sends the feature information of the second attack message to the control and management entity. The third condition may refer to the proportion of bandwidth occupied by the highest forwarding priority message transmitted through the second port being greater than or equal to a fifth threshold; or, the third condition may refer to the highest forwarding priority message transmitted through the second port being greater than or equal to a sixth threshold. It should be noted that the second port can also achieve the processing of spoofed highest forwarding priority attack messages through one or more of the above implementation methods; the relevant descriptions will not be repeated.

[0015] It should be noted that the characteristic information of an attack message can refer to the characteristic information that can identify the attack message and the attack flow to which it belongs. Specifically, the characteristic information of an attack message can be all or part of the five-tuple of the attack message. For example, if the attack message is an Internet Protocol (IP) message, its characteristic information may include one or more of the following: source IP address, destination IP address, source port number, destination port number, or transport layer protocol number. As another example, if the attack message is a Multiprotocol Label Switching (MPLS) message, its characteristic information may include one or more of the following: MPLS label, the source Media Access Control (MAC) address of the attack message, the destination MAC address, the source IP address, and the destination IP address.

[0016] It should be noted that the first communication device can process the highest forwarding priority packets transmitted through the first port in the network scenario according to different operating network scenarios, using the processing method provided in the embodiments of this application. For example, the first communication device can operate in Internet Protocol version 4 (IPv4) networks, Internet Protocol version 6 (IPv6) networks, Virtual Private Network (VPN) networks, Multiprotocol Label Switching (MPLS) networks, Virtual Extensible Local Area Network (VXLAN) and other network environments.

[0017] It should be noted that the first communication device can refer to any network device capable of message forwarding, such as a switch, router, etc.; or, the first communication device can also be a single board, chip, etc. within a network device that has message forwarding functionality. The TM module can refer to the TM chip in the first communication device or a functional module capable of implementing TM functionality. The port of the first communication device can be either a physical port or a logical port of the first communication device.

[0018] Secondly, embodiments of this application also provide a message processing method, the method comprising: when a first communication device determines that a message with the highest forwarding priority transmitted through a first port occupies the bandwidth of the first port in accordance with a first condition, analyzing the message with the highest forwarding priority transmitted through the first port, and determining that the message transmitted through the first port includes an attack message with the highest forwarding priority.

[0019] As an example, when the first communication device determines that the packets transmitted on the first port include an attack packet with the highest forwarding priority, the first communication device can also send an alarm signal to the network management system. This alarm signal indicates that the first communication device contains an attack packet, allowing the network management system to perform security defenses and prevent the attack packet from posing a greater threat to the network. Furthermore, to enable the network management system to perform targeted security defenses, the alarm signal can also carry attack characteristic information.

[0020] As an example, the first communication device can also obtain the characteristic information of the attack message after determining that the message transmitted on the first port includes an attack message with the highest forwarding priority. At this time, the first communication device can also send the characteristic information of the attack message to a control management entity and obtain a message processing policy generated by the control management entity. This message processing policy is used to process messages that match the characteristic information of the attack message. Thus, the first communication device can perform packet loss and / or rate limiting on the first message, which is the message matching the characteristic information of the attack message, based on the message processing policy.

[0021] The first condition may include the proportion of bandwidth occupied by the highest forwarding priority packets transmitted through the first port being greater than or equal to a first threshold. Alternatively, the first condition may also include the proportion of the highest forwarding priority packets transmitted through the first port being greater than or equal to a second threshold.

[0022] It should be noted that the specific implementation method and the effects achieved by the method provided in the second aspect can be found in the relevant description in the first aspect above, and will not be repeated here.

[0023] Thirdly, embodiments of this application also provide a message processing method, which may include: when a first communication device determines that the bandwidth occupied by a message with the highest forwarding priority transmitted through a first port meets a first condition, it obtains the feature information of an attack message in the message with the highest forwarding priority and sends the feature information of the attack message to a control management entity; at this time, the control management entity can generate a message processing strategy based on the feature information of the attack message, and the message processing strategy is used to process messages that match the feature information of the attack message.

[0024] As an example, the method may further include: a first communication device acquiring a message processing strategy generated by a control and management device, thereby the first communication device processing a first message based on the message processing strategy, wherein the first message is a message that matches the feature information of an attack message.

[0025] As another example, the method may further include: the control management device sending a message processing strategy to the second communication device, thereby the second communication device processing a second message based on the message processing strategy, wherein the second message is a message that matches the feature information of the attack message.

[0026] The first condition may include the proportion of bandwidth occupied by the highest forwarding priority packets transmitted through the first port being greater than or equal to a first threshold. Alternatively, the first condition may also include the proportion of the highest forwarding priority packets transmitted through the first port being greater than or equal to a second threshold.

[0027] It should be noted that the specific implementation method and the effects achieved by the method provided in this third aspect can be found in the relevant descriptions of the first or second aspect above, and will not be repeated here.

[0028] Fourthly, embodiments of this application also provide a message processing system, which may include at least a first communication device and a control management entity. The first communication device is configured to, when determining that the highest forwarding priority message transmitted through a first port occupies the bandwidth of the first port in accordance with a first condition, acquire and send to the control management entity the feature information of the attack message in the highest forwarding priority message. The control management entity is configured to, based on the message feature information of the attack message, generate a message processing strategy, which is used to process messages that match the feature information of the attack message.

[0029] As an example, the control and management device is further configured to send the message processing strategy to the first communication device. Then, the first communication device is further configured to process a first message based on the message processing strategy, wherein the first message is a message matching the feature information of the attack message.

[0030] As another example, the system may also include a second communication device and a control management device, which are further configured to send the message processing strategy to the second communication device. Then, the second communication device is further configured to process a second message based on the message processing strategy, wherein the second message is a message matching the feature information of the attack message.

[0031] The first condition may include the proportion of bandwidth occupied by the highest forwarding priority packets transmitted through the first port being greater than or equal to a first threshold. Alternatively, the first condition may also include the proportion of the highest forwarding priority packets transmitted through the first port being greater than or equal to a second threshold.

[0032] It should be noted that the specific implementation method and the effects achieved by the system provided in this fourth aspect can be found in the relevant descriptions of the first, second or third aspects above, and will not be repeated here.

[0033] Fifthly, this application also provides a first communication device, including a transceiver unit and a processing unit. The transceiver unit is used to perform the transceiver operations in the methods provided by the first aspect, any possible implementation of the first aspect, the second aspect, or any possible implementation of the second aspect, or to perform the transceiver operations of the first communication device in the methods provided by the third aspect or any possible implementation of the third aspect. The processing unit is used to perform other operations besides the transceiver operations in the methods provided by the first aspect, any possible implementation of the first aspect, the second aspect, or any possible implementation of the second aspect, or to perform other operations besides the transceiver operations of the first communication device in the methods provided by the third aspect or any possible implementation of the third aspect. For example, when the first communication device performs the method described in the first aspect, the transceiver unit is used to send characteristic information of a first attack message to a control management entity; the processing unit is used to determine that the bandwidth occupied by the highest forwarding priority message transmitted through the first port satisfies a first condition; the processing unit is also used to obtain the characteristic information of the first attack message included in the highest forwarding priority message transmitted through the first port.

[0034] Sixthly, embodiments of this application also provide a first communication device, including a first communication interface and a processor. The first communication interface is used to perform a transmission operation in the methods provided by the first aspect, any possible implementation of the first aspect, the second aspect, or any possible implementation of the second aspect, or to perform a transmission operation of the first communication device in the methods provided by the third aspect or any possible implementation of the third aspect. The processor is used to perform other operations besides the receiving and transmission operations in the methods provided by the first aspect, any possible implementation of the first aspect, the second aspect, or any possible implementation of the second aspect, or to perform other operations besides the receiving and transmission operations of the first communication device in the methods provided by the third aspect or any possible implementation of the third aspect. Furthermore, the first communication device may also include a second communication interface, which is used to perform the aforementioned receiving operation of the first communication device.

[0035] In a seventh aspect, embodiments of this application also provide a first communication device, which includes a memory and a processor. The memory includes computer-readable instructions; the processor, communicating with the memory, executes the computer-readable instructions, causing the first communication device to perform the methods provided by the first aspect, any possible implementation of the first aspect, the second aspect, or any possible implementation of the second aspect, or to perform the method implemented by the first communication device in the methods provided by the third aspect or any possible implementation of the third aspect.

[0036] Eighthly, embodiments of this application also provide a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the methods provided by the first aspect, any possible implementation of the first aspect, the second aspect, or any possible implementation of the second aspect, or to perform the method implemented by the first communication device in the methods provided by the third aspect or any possible implementation of the third aspect.

[0037] Ninthly, embodiments of this application also provide a computer program product, including a computer program or computer-readable instructions, which, when the computer program or the computer-readable instructions are run on a computer, cause the computer to perform the methods provided by the first aspect, any possible implementation of the first aspect, the second aspect, or any possible implementation of the second aspect, or the method implemented by the first communication device in the method provided by the third aspect or any possible implementation of the third aspect.

[0038] In a tenth aspect, embodiments of this application also provide a communication system, which includes the first communication device provided in the fifth, sixth or seventh aspects and the corresponding control management entity in the method provided in the third aspect (or the control management entity in the system provided in the fourth aspect).

[0039] It should be noted that the communication device in the above embodiments can be a network device used to perform the above method, or it can refer to a single board, line card, chip, etc. used to perform the above method. Attached Figure Description

[0040] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings.

[0041] Figure 1 This is a schematic diagram of the structure of network 10 to which this application embodiment applies;

[0042] Figure 2 This is a schematic diagram illustrating the process of message processing performed in network 10 according to an embodiment of this application;

[0043] Figure 3 This is a flowchart illustrating a message processing method 100 in an embodiment of this application.

[0044] Figure 4 This is a flowchart illustrating another message processing method 200 in an embodiment of this application.

[0045] Figure 5 This is a flowchart illustrating another message processing method 300 in an embodiment of this application.

[0046] Figure 6 This is a flowchart illustrating another message processing method 400 in an embodiment of this application.

[0047] Figure 7 This is a schematic diagram of the structure of a message processing system 700 according to an embodiment of this application;

[0048] Figure 8 This is a schematic diagram of the structure of a first communication device 800 in an embodiment of this application;

[0049] Figure 9 This is a schematic diagram of the structure of a first communication device 900 in an embodiment of this application;

[0050] Figure 10 This is a schematic diagram of the structure of a first communication device 1000 in an embodiment of this application. Detailed Implementation

[0051] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings. The network architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0052] In this application, ordinal numbers such as “1”, “2”, “3”, “first”, “second”, and “third” are used to distinguish multiple objects, not to limit the order of multiple objects.

[0053] The reference to "A and / or B" in this application should be understood to include the following situations: including only A, including only B, or including both A and B.

[0054] After the source network device includes the priority in the message, each network device forwards the message according to the priority. More important messages have higher priority, and network devices prioritize forwarding higher-priority messages compared to lower-priority messages. To ensure the network provides normal service, protocol messages, network device detection messages, and important data messages—messages that affect the normal operation of network devices—are typically assigned the highest priority to ensure effective processing. Since the priority carried in the message is used to guide the network device to forward the message with priority, the priority is referred to as forwarding priority in this application embodiment. The forwarding priority mentioned in this application refers to the priority of the message indicated by the priority field carried in the message. For example, when the message is an Internet Protocol (IP) message, the forwarding priority of the message can be indicated by the value of the Type of Service (TOS) field in the IP message; as another example, when the message is a Multiprotocol Label Switching (MPLS) message, the forwarding priority of the message can be indicated by the value of the Experimental Bits (EXP) field in the MPLS message.

[0055] If a network device receives an attack packet carrying the highest forwarding priority, this attack packet will become a priority for the network device, consuming its bandwidth. Since each network device has a limited total bandwidth, the received attack packets will quickly cause congestion. For example, if the total bandwidth of received packets to be forwarded exceeds the network device's total bandwidth, even packets with the highest forwarding priority will be dropped, leading to the loss of protocol packets, detection packets, or critical data packets. This results in the network device being attacked by a large number of attack packets, impacting its normal operation.

[0056] In the face of the above scenario, current security defense mechanisms involve manually configuring security policy templates on network devices. These templates are used to identify secure packets, allowing network devices to forward them normally and discard packets that cannot be identified by the template as attack packets. However, this security defense mechanism has several drawbacks. First, if an attack packet spoofs into a format that the security policy template can recognize, it cannot effectively defend against the attack. Second, if a new service is introduced to the network, the security policy template needs to be modified so that the security policy module can identify packets corresponding to the new service; otherwise, all packets corresponding to the new service will be discarded. This implementation process is quite complex.

[0057] Based on this, embodiments of this application provide a message processing method. When a communication device determines that the bandwidth occupied by a message with the highest forwarding priority transmitted through a certain port meets the condition—that is, before the network device congestion is caused by an attack message configured with the highest forwarding priority—it obtains the feature information of the attack message in the message with the highest forwarding priority and sends the feature information of the attack message to a control and management entity. Thus, the control and management entity can generate a message processing strategy based on the message features of the received attack message and send the message processing strategy to the communication device. The communication device processes messages that match the feature information of the attack message based on the message processing strategy (e.g., packet loss and / or rate limiting). Through the security defense mechanism provided by this application, attack messages can be effectively identified and processed, effectively avoiding network device congestion caused by attacks based on high-priority messages, thereby ensuring that normal messages with the highest forwarding priority can be effectively forwarded, making it possible for the communication device to provide normal services.

[0058] For example, with Figure 1Taking network 10 as an example, network 10 includes network devices 110, 120, ..., 130, and a control and management entity 200. Each network device includes a Traffic Management (TM) module; for example, network device 110 includes TM module 111, network device 120 includes TM module 121, and network device 130 includes TM module 131. The TM module is used to manage traffic within its network device, such as calculating the bandwidth of packets with different forwarding priorities for each port on the network device. Each network device has at least packet forwarding functionality; the control and management entity 200 can interact with each network device to manage and control the network devices. It should be noted that the number of network devices included in network 10 is not specifically limited in this embodiment. For example, there may be more than three network devices, that is, in addition to the aforementioned network devices 110, 120, and 130, other network devices may also be included; or, the number of network devices included in network 10 may be less than three.

[0059] As an example, assume network device 120 includes port 1 with bandwidth c. The threshold Th1 for all packets transmitted through port 1 to occupy 80% of its bandwidth is Th1, and the threshold Th2 for the highest forwarding priority packets transmitted through port 1 to occupy 70% of its bandwidth is Th2. For specific implementation details, see [link to implementation details]. Figure 2The flowchart shown illustrates that the processing of attack packets may include: S11, the TM module 121 of network device 120 periodically acquires (e.g., every 1 second) the bandwidth 'a' of packets transmitted through port 1; S12, the TM module 121 determines whether (a÷c)≥Th1 is satisfied. If satisfied, proceed to S13; otherwise, return to S11; S13, the TM module 121 acquires the bandwidth 'b' of the highest forwarding priority packets transmitted through port 1; S14, the TM module 121 determines whether (b÷c)≥Th2 is satisfied. If satisfied, proceed to S15; otherwise, return to S11; S15, the TM module 121 acquires the 5-tuple of the attack packet in the highest forwarding priority packets transmitted through port 1 (i.e., the source Internet Protocol (IP) of the attack packet). Protocol (abbreviated as IP) address, destination IP address, source port number, destination port number, and protocol version number); S16, network device 120 sends the five-tuple of the attack packet to control management entity 200; S17, control management entity 200 generates a packet processing policy based on the five-tuple of the attack packet; S18, control management entity 200 sends the packet processing policy to network device 120; S19, network device 120 performs packet loss or rate limiting on packets received through port 1 that match the five-tuple of the attack packet based on the packet processing policy. In this way, by setting thresholds and the above-described processing flow, attack packets with the highest forwarding priority can be effectively suppressed before causing serious network congestion. This prevents a large number of attack packets with the highest forwarding priority from seizing bandwidth resources of normal packets on the network device, causing normal packets with the highest forwarding priority to be dropped and thus affecting the normal operation of the network. Moreover, as attack packets are effectively suppressed, the forwarding latency of normal packets with the highest forwarding priority can be reduced, and forwarding performance can be improved. It can be seen that the method provided by the embodiments of this application makes it possible for network devices to continue to operate normally when attack packets are present.

[0060] It is understood that the above scenario is only one example provided by the embodiments of this application, and the embodiments of this application are not limited to this scenario.

[0061] It should be noted that the communication device in the embodiments of this application can refer to any network device capable of implementing message forwarding function. For example, the communication device can be a switch, router, etc.; or, the communication device can also be a single board, chip, etc. with message forwarding function within a network device. The control and management entity can be any device or functional entity capable of controlling the communication device. For example, the control and management entity can be a Network Cloud Engine (NCE), server, or router with control function; or, the control and management entity can also be a functional entity integrated within any communication device, which can be implemented in hardware or software. The TM module in the communication device can refer to the TM chip or a functional module capable of implementing TM function within the communication device.

[0062] It should be noted that, in the embodiments of this application, the port of the communication device can be either the physical port or the logical port of the communication device.

[0063] The following detailed description, in conjunction with the accompanying drawings, illustrates the specific implementation of a message processing method according to an embodiment of this application.

[0064] This application provides a message processing method 100, which is implemented by a first communication device. The first communication device can be any network device with message forwarding functionality in the network, or a single board, chip, etc., within the network device. For example, in... Figure 1 In the scenario shown, network device 110, network device 120, and network device 130 can all serve as the first communication device to implement the method 100. Figure 3 This is a flowchart illustrating a message processing method 100 according to an embodiment of this application. See also... Figure 3 The method 100 may include, for example:

[0065] S101, determine that the highest forwarding priority message transmitted through the first port occupies the bandwidth of the first port to satisfy the first condition.

[0066] The forwarding priority carried in the message indicates the priority of the communication device forwarding the message. The higher the forwarding priority, the more important the message is, and the more priority the communication device should give to forwarding the message. For example, the forwarding priority of a message can be divided into priorities 0 to 7, then a message with priority 7 is a message with the highest forwarding priority. It should be noted that the forwarding priority of a message and the highest forwarding priority are backward compatible. The highest forwarding priority referred to in this embodiment can be the highest message priority in any subsequent scenario.

[0067] The forwarding priority of a message can be carried in the priority field of the message. The first communication device can determine the forwarding priority of the message by parsing the priority field of the received message.

[0068] The first condition is a condition defined by the first communication device for the first port, used to determine whether it is necessary to process the attack message on the first port. Furthermore, the first communication device can also set corresponding conditions for each port. For example, the first communication device can set a corresponding third condition for the second port. This third condition can be the same as or different from the first condition. In this embodiment, a port on the first communication device is used as an example for illustration.

[0069] As an example, the first condition may be that the proportion of bandwidth occupied by the highest forwarding priority message transmitted through the first port is greater than or equal to a first threshold. The first threshold is a trigger condition pre-set on the first communication device for the first port, corresponding to the execution of S102 and S103 below. For example, if the first threshold is 70%, the bandwidth of the first port is 20 megabytes per second (Gb / s), and the first communication device obtains that the highest forwarding priority message transmitted through the first port is 15 Gb / s, then the first communication device determines that the proportion of bandwidth occupied by the highest forwarding priority message on the first port is (15 ÷ 20) = 75%, which is greater than the first threshold of 70%, thus determining that the bandwidth occupied by the highest forwarding priority message on the first port satisfies the first condition. Correspondingly, the third condition may be that the proportion of bandwidth occupied by the highest forwarding priority message transmitted through the second port is greater than or equal to a fifth threshold, where the fifth threshold may or may not be equal to the first threshold.

[0070] As another example, the first condition could also be that the highest forwarding priority message transmitted through the first port is greater than or equal to a second threshold. Here, the second threshold is a trigger condition pre-set on the first communication device for the first port, executing the following steps S102 and S103. For example, if the second threshold is 15Gb / s and the bandwidth of the first port is 20Gb / s, and the first communication device obtains that the highest forwarding priority message transmitted through the first port is 15Gb / s, then the first communication device determines that the size of the highest forwarding priority message on the first port is equal to the second threshold of 15Gb / s, thereby determining that the highest forwarding priority message occupies the bandwidth of the first port, satisfying the first condition. Correspondingly, the third condition could be that the highest forwarding priority message transmitted through the second port is greater than or equal to a sixth threshold, where the sixth threshold may or may not be equal to the second threshold.

[0071] In some possible implementations, the first communication device can periodically (e.g., every 100 milliseconds) acquire the size of the highest forwarding priority message transmitted through the first port and determine whether the bandwidth occupied by the highest forwarding priority message transmitted through the first port meets a first condition. Similarly, the first communication device can also periodically acquire the size of the highest forwarding priority message transmitted through the second port and determine whether the bandwidth occupied by the highest forwarding priority message transmitted through the second port meets a second condition. In this way, the first communication device can promptly detect the bandwidth occupied by the highest forwarding priority messages transmitted through each port. If it finds that the highest forwarding priority messages transmitted on a certain port occupy a large amount of bandwidth on that port, it will perform the following processing steps S102 to S103 on that port to prevent congestion from affecting the forwarding of normal highest forwarding priority messages.

[0072] In other possible implementations, the first communication device may also be event-triggered to obtain the size of the highest forwarding priority message transmitted through the first port and determine whether the bandwidth occupied by the highest forwarding priority message transmitted through the first port meets a first condition. For example, the event that triggers the execution of S101 includes, but is not limited to, the first communication device determining that all messages transmitted through the first port meet a second condition, wherein the second condition is a condition defined by the first communication device for the first port to determine whether it is necessary to measure the highest forwarding priority message on the first port. When it is determined that the bandwidth occupied by all messages transmitted through the first port meets the second condition, it indicates that the occupancy rate on the first port is high, and it is necessary to obtain the highest forwarding priority message transmitted through the first port and determine whether the bandwidth occupied by the highest forwarding priority message on the first port meets the first condition, so as to ensure that the normal messages with the highest forwarding priority can be forwarded normally. In addition, the first communication device can also set corresponding event triggering conditions for each port. For example, the first communication device can set a corresponding fourth condition for the second port. The fourth condition and the second condition can be the same or different. In this embodiment, a certain port on the first communication device is used as an example for illustration.

[0073] As an example, the second condition could be that the proportion of bandwidth occupied by all messages transmitted through the first port is greater than or equal to a third threshold. The third threshold is a threshold pre-set on the first communication device for the first port. For example, if the third threshold is 80%, the bandwidth of the first port is 20 megabytes per second (Gb / s), and the first communication device obtains that all messages transmitted through the first port are at a rate of 17 Gb / s, then the first communication device determines that the proportion of bandwidth occupied by all messages on the first port is (17 ÷ 20) = 85%, which is greater than the third threshold of 80%, thus determining that the bandwidth occupied by all messages transmitted through the first port satisfies the second condition. The relationship between the third and first thresholds is not specifically limited. Correspondingly, the fourth condition could be that the proportion of bandwidth occupied by all messages transmitted through the second port is greater than or equal to a seventh threshold, where the seventh threshold may or may not be equal to the third threshold.

[0074] As another example, the second condition could also be that all messages transmitted through the first port are greater than or equal to a fourth threshold. Here, the fourth threshold is a threshold pre-set on the first communication device for the corresponding first port. For example, if the fourth threshold is 18Gb / s, the bandwidth of the first port is 20Gb / s, and the first communication device obtains that all messages transmitted through the first port are at a rate of 18.5Gb / s, then the first communication device determines that the size of all messages transmitted on the first port is greater than the fourth threshold of 18Gb / s, thereby determining that the bandwidth occupied by all messages transmitted through the first port satisfies the second condition. The relationship between the fourth threshold and the second threshold is not specifically limited. Correspondingly, the fourth condition could also be that all messages transmitted through the second port are greater than or equal to an eighth threshold, where the eighth threshold may or may not be equal to the fourth threshold.

[0075] For example, if the first communication device is equipped with a first threshold of 70% and a third threshold of 80%, then before S101, the method 100 may further include: S21, the first communication device polls the first port to obtain the size of all messages transmitted through the first port; S22, the first communication device determines whether the proportion of all messages transmitted through the first port to the bandwidth of the first port is greater than or equal to the third threshold. If it is greater than or equal to the third threshold, then S23 is executed; otherwise, polling continues according to S21; S23, the first communication device obtains the size of the highest forwarding priority message transmitted through the first port; S24, the first communication device determines whether the proportion of the highest forwarding priority message to the bandwidth of the first port is greater than or equal to the first threshold. If it is greater than or equal to the first threshold, then S101 is executed, that is, it is determined that the highest forwarding priority message to the first port occupies the bandwidth of the first port to meet the first condition.

[0076] The polling in S21 can be implemented through the timer of the TM module of the first communication device. For example, the timer is set to a timeout of 1 second. When the timer reaches 1 second, the size of the highest forwarding priority message transmitted through the first port is obtained.

[0077] The first communication device can obtain the size of all messages transmitted through the first port, and obtain the size of the message with the highest forwarding priority transmitted through the first port, by performing a measurement operation on the first port through its own TM module.

[0078] The first communication device can monitor and process the highest-priority forwarding packets transmitted through the first port in different network scenarios, depending on the operating network environment. For example, the first communication device can operate in Internet Protocol version 4 (IPv4) networks, Internet Protocol version 6 (IPv6) networks, Virtual Private Network (VPN) networks, Multiprotocol Label Switching (MPLS) networks, Virtual Extensible Local Area Network (VXLAN) networks, and other network environments. Taking the first communication device operating in an IPv6 network as an example, the first condition could be that the proportion of bandwidth occupied by the highest-priority IPv6 packets transmitted through the first port is greater than or equal to a first threshold; or, the first condition could also be that the proportion of the highest-priority IPv6 packets transmitted through the first port is greater than or equal to a second threshold. In this embodiment, the second condition may be that the proportion of bandwidth occupied by all IPv6 packets transmitted through the first port is greater than or equal to a third threshold; or, the second condition may be that all IPv6 packets transmitted through the first port are greater than or equal to a fourth threshold.

[0079] Therefore, when the first communication device determines that the highest forwarding priority message transmitted through the first port occupies the bandwidth of the first port and meets the first condition, it can be considered that a large number of messages are transmitted on the first port, and that attack messages may exist among the messages transmitted on the first port. Important messages such as the highest forwarding priority protocol messages and test messages on the first port may be lost, thereby affecting the normal operation of the first communication device. In order to ensure that the normal messages with the highest forwarding priority transmitted through the first port on the first communication device can be forwarded normally, the first communication device can process attack messages by executing the following S102 to S103.

[0080] S102, Obtain the feature information of the first attack packet in the highest forwarding priority packet transmitted through the first port.

[0081] The characteristic information of an attack packet refers to the information that identifies the attack packet and the attack flow to which it belongs. Specifically, the characteristic information of an attack packet can be all or part of the five-tuple of the attack packet. For example, if the attack packet is an IP packet, its characteristic information may include one or more of the following: source IP address, destination IP address, source port number, destination port number, or transport layer protocol number. As another example, if the attack packet is an MPLS packet, its characteristic information may include one or more of the following: MPLS label, the source Media Access Control (MAC) address of the attack packet, destination MAC address, source IP address, and destination IP address.

[0082] As an example, the characteristic information of the attack message may be the source IP address, destination IP address, source port number, destination port number, and transport layer protocol number. The first communication device determines the first attack message from the highest forwarding priority messages transmitted through the first port according to the source IP address, destination IP address, source port number, destination port number, and transport layer protocol number of each message, thereby obtaining the source IP address, destination IP address, source port number, destination port number, and transport layer protocol number of the first attack message as the characteristic information of the first attack message in the highest forwarding priority messages obtained in S102.

[0083] As another example, the characteristic information of the attack message can be the source port number and the destination port number. The first communication device determines the first attack message from the highest forwarding priority messages transmitted through the first port, based on the source port number and destination port number of each message, thereby obtaining the source port number and destination port number of the first attack message as the characteristic information of the first attack message among the highest forwarding priority messages obtained in S102. For example, a message whose source port number and destination port number are constantly changing can be identified as the first attack message by the first communication device.

[0084] As another example, the characteristic information of an attack message can be its source MAC address and destination MAC address. The first communication device determines the first attack message from the highest-priority forwarding messages transmitted through the first port based on the source and destination MAC addresses of each message, thereby obtaining the source and destination MAC addresses of the first attack message as the characteristic information of the first attack message among the highest-priority forwarding messages obtained in S102. For example, a message whose source and destination MAC addresses change can be identified as the first attack message by the first communication device.

[0085] In specific implementation, the TM module of the first communication device can identify the first attack message from the highest forwarding priority message transmitted through the first port and obtain the characteristic information of the first attack message, which provides a basis for subsequent processing of the first attack message, enabling the first attack message to be detected and suppressed, and providing conditions for the normal operation of the first communication device.

[0086] S103, send the characteristic information of the first attack message to the control and management entity.

[0087] In a specific implementation, S103 may be, for example, the first communication device sending an instruction message to the control and management entity, the instruction message carrying the characteristic information of the first attack message obtained in S102.

[0088] The instruction message can be any of the following: Border Gateway Protocol (BGP) message, Path Computation Element Communication Protocol (PCEP) message, Telemetry message, or Network Configuration Protocol (NETCONF) message. For example, the characteristic information of the first attack message can be carried through the extended Type Length Value (TLV) field in any of the above message types. Alternatively, the characteristic information of the first attack message can also be carried through other available fields such as the Reserved field in any of the above message types.

[0089] If the control and management entity and the first communication device belong to two different devices, taking the indication message as a Telemetry message as an example, before executing S103, the first communication device and the control and management entity need to achieve network layer connectivity through a routing protocol, and the Telemetry function needs to be configured and enabled on the first communication device and the control and management entity. In this way, after S102, the first communication device can send the characteristic information of the first attack message to the control and management entity in the Telemetry message.

[0090] In some possible implementations, the first communication device can periodically send attack detection results to the control and management entity. After the control and management entity determines that the received attack detection results include the characteristic information of the first attack packet, it can proactively generate a message processing strategy for the first attack packet. Alternatively, the first communication device can send the characteristic information of the first attack packet to the control and management entity only when the first attack packet is detected. In this case, the control and management entity can also proactively generate a message processing strategy for the first attack packet.

[0091] In other possible implementations, in addition to sending the characteristic information of the first attack message to the control and management entity, the first communication device may also send indication information to the control and management entity to instruct it to generate a message processing strategy. This message processing strategy is used to process messages that match the characteristic information of the first attack message. It should be noted that the first communication device may send the indication information and the characteristic information of the first attack message in a single indication message to the control and management entity, or the first communication device may send the indication information and the characteristic information of the first attack message in separate indication messages to the control and management entity. The indication message carrying the indication information can be any of the following messages: BGP message, PCEP message, Telemetry message, or NETCONF message.

[0092] If the control and management entity and the first communication device belong to the same network device, taking the indication message as a Telemetry message as an example, before executing S103, the Telemetry function needs to be configured and enabled on both the first communication device and the control and management entity. In this way, after S102, the first communication device can send the feature information of the first attack message to the control and management entity in the form of Telemetry data.

[0093] As can be seen, through the method 100 provided in this application embodiment, when the first communication device determines that the bandwidth occupied by the highest forwarding priority message transmitted through the first port meets the first condition, it can obtain the feature information of the first attack message in the highest forwarding priority message and send the feature information of the first attack message to the control and management entity. Thus, the control and management entity can generate a message processing strategy based on the message features of the received first attack message and send the message processing strategy to the communication device. The communication device receiving the message processing strategy can then process messages matching the feature information of the first attack message based on the message processing strategy (e.g., packet loss and / or rate limiting). In this way, if the first attack message does not cause port congestion of the first communication device or threaten the security of the first communication device, this security defense mechanism effectively identifies and processes the attack message, ensuring that the attack message does not cause congestion of the communication device, thereby guaranteeing that the highest forwarding priority security message can be effectively forwarded, making it possible for the first communication device to provide normal services.

[0094] The above describes the implementation and effect of the packet processing method provided in this application embodiment, taking the processing of attack packets in the highest forwarding priority packets transmitted on the first port as an example. Similarly, this method can be applied to other ports. For example, when it is determined that the bandwidth occupied by the highest forwarding priority packets transmitted through the second port meets the third condition, the characteristic information of the second attack packet in the highest forwarding priority packets transmitted through the second port is obtained, and the characteristic information of the second attack packet is sent to the control and management entity. The terms "first" and "second" in "first attack packet" and "second attack packet" are only used to distinguish the highest forwarding priority attack packets transmitted on different ports and do not specifically refer to any particular packet.

[0095] In other possible implementations, the first communication device may, when it determines that the highest forwarding priority message transmitted through the first port occupies the bandwidth of the first port in a manner that satisfies a first condition, analyze the highest forwarding priority message transmitted through the first port to determine that the highest forwarding priority message transmitted through the first port includes an attack message. In this implementation, the first communication device may also send an alarm signal to the network management system to notify the system that an attack message is present on the first communication device, so that the network management system can manage and control the first communication device and other communication devices that may transmit attack messages, thereby ensuring network security.

[0096] In addition, this application embodiment also provides another method 200 for processing attack packets, such as... Figure 4 As shown, in method 200, after S103 of method 100 above, it may further include:

[0097] S104, the control and management entity generates a message processing strategy based on the feature information of the first attack message. This message processing strategy is used to process messages that match the feature information of the first attack message.

[0098] The message processing strategy may include, for example, the characteristic information of the first attack message and the processing strategy. The characteristic information of the first attack message describes the characteristics of the message to be processed, enabling the second communication device executing the message processing strategy to determine the attack message to be processed according to the strategy. The processing strategy refers to the specific processing operation performed on the message to be processed. For example, it could be a packet dropping operation, i.e., dropping packets that match the characteristic information of the first attack message; or it could be a rate limiting operation, i.e., limiting the rate of packets that match the characteristic information of the first attack message. Both packet dropping and rate limiting can effectively reduce the preemption of network resources by attack messages, especially reducing the probability of insufficient bandwidth resources for normal messages with the highest forwarding priority.

[0099] The processing strategy can be any current algorithm for handling packet loss and / or rate limiting, and is not specifically limited in this embodiment.

[0100] S105, the control management entity sends the message processing strategy to the second communication device.

[0101] The second communication device and the first communication device may belong to the same network device or to two different network devices.

[0102] Specifically, the control and management entity can send the message processing strategy to the second communication device in BGP messages, PCEP messages, Telemetry messages, or NETCONF messages.

[0103] In addition, the control and management entity can also send instruction information to the second communication device to instruct the second communication device to process messages that match the feature information of the first attack message in accordance with the message processing strategy.

[0104] S106, the second communication device processes messages that match the feature information of the first attack message based on the message processing strategy.

[0105] In a specific implementation, S106 may include, for example, the second communication device acquiring a first message; then, determining whether the message characteristics of the first message match the message characteristics of the first attack message in the message processing strategy; if they match, then processing the first message based on the processing strategy in the message processing strategy. Processing the first message based on the message processing strategy may, for example, include: performing packet loss processing on the first message based on the processing strategy in the message processing strategy, or performing rate limiting processing on the first message based on the processing strategy in the message processing strategy.

[0106] When the first communication device and the second communication device belong to the same network device, step S106 may include, for example, the second communication device determining that a message transmitted through the first port matches the message characteristics of a first attack message in the message processing policy. If a match is found, the second communication device performs packet loss or rate limiting on the message transmitted through the first port based on the processing policy in the message processing policy. This avoids the first communication device from losing normal messages with the highest forwarding priority due to the first attack message, ensuring the effective forwarding of normal messages by the first communication device.

[0107] When the first communication device and the second communication device belong to different network devices, the second communication device can be any network device under the control of the control and management entity. In this way, even if the first attack message attacks other communication devices in the network, it can prevent other communication devices from losing normal messages with the highest forwarding priority due to the first attack message, and ensure the effective forwarding of normal messages by other communication devices.

[0108] As an example, the second communication device may be the upstream node of the network device where the first communication device is located on the transmission path of the attack message. In this way, the control and management entity sends the message processing policy to the second communication device, which can suppress the first attack message from the source as much as possible for the first communication device, so that the first attack message no longer occupies the bandwidth resources of the first communication device and eliminates the impact of the first attack message on the first communication device.

[0109] In this example, in order to more effectively and thoroughly suppress the first attack message, while executing S106, the control management entity can also send the message processing strategy to the first communication device; then, the first communication device can also process the message received from the first port that matches the feature information of the attack message based on the message processing strategy.

[0110] To prevent other communication devices in the network from being affected by the first attack message, the control and management entity can also send the message processing policy to all communication devices connected to the control and management entity in the network. This allows each communication device to identify a message matching the characteristic information of the first attack message in the message processing policy as an attack message and to perform packet dropping or rate limiting on the identified attack message based on the processing policy. This effectively prevents the first attack message from being transmitted between multiple communication devices in the network to attack multiple communication devices, greatly improving network security.

[0111] As can be seen, through the method 200 provided in this application embodiment, the control management entity generates a message processing strategy based on the feature information of the first attack message reported by the first communication device and sends it to the second communication device. The second communication device can then process messages that match the feature information of the first attack message. In this way, if the attack message does not cause port congestion of the first communication device or threaten the security of the first communication device, the security defense mechanism can effectively identify and process the attack message, ensuring that the attack message will not cause congestion of the communication device, thereby ensuring that the security message with the highest forwarding priority can be effectively forwarded, making it possible for the first communication device to provide normal services.

[0112] The above describes the implementation and effect of the packet processing method provided in this application embodiment, taking the processing of attack packets in the highest forwarding priority packets transmitted on the first port as an example. Similarly, this method 200 can be applied to other ports. For example, after executing the embodiment shown in method 100 on the second port, it may further include: a control management entity generating a packet processing strategy based on the feature information of the second attack packet, the packet processing strategy being used to process packets that match the feature information of the second attack packet; the control management entity sending the packet processing strategy to a third communication device; and the third communication device processing packets that match the feature information of the second attack packet based on the packet processing strategy. The third communication device and the first communication device may belong to the same network device or two different network devices.

[0113] Figure 5 A flowchart illustrating a message processing method 300 according to an embodiment of this application is shown. See also... Figure 5 The method 300 uses the first communication device as the executing entity, and the method 300 may include, for example:

[0114] S301, the first communication device determines that the highest forwarding priority message transmitted on the first port occupies the bandwidth of the first port, which satisfies the first condition;

[0115] S302, Analyze the highest forwarding priority message transmitted through the first port;

[0116] S303, It is determined that the packets transmitted on the first port include an attack packet with the highest forwarding priority.

[0117] As an example, when the first communication device determines that the packets transmitted on the first port include an attack packet with the highest forwarding priority, the first communication device can also send an alarm signal to the network management system. This alarm signal indicates that the first communication device contains an attack packet, allowing the network management system to perform security defenses and prevent the attack packet from posing a greater threat to the network. Furthermore, to enable the network management system to perform targeted security defenses, the alarm signal can also carry attack characteristic information.

[0118] As another example, the first communication device can also obtain the characteristic information of the attack message after determining that the message transmitted on the first port includes an attack message with the highest forwarding priority. At this time, the first communication device can also send the characteristic information of the attack message to the control and management entity and obtain a message processing policy generated by the control and management entity. This message processing policy is used to process messages that match the characteristic information of the attack message. Thus, the first communication device can perform packet loss and / or rate limiting on the first message, which is the message matching the characteristic information of the attack message, based on the message processing policy.

[0119] The first condition may include the proportion of bandwidth occupied by the highest forwarding priority packets transmitted through the first port being greater than or equal to a first threshold. Alternatively, the first condition may also include the proportion of the highest forwarding priority packets transmitted through the first port being greater than or equal to a second threshold.

[0120] It should be noted that the specific implementation method and the effect achieved by method 300 can be found in the relevant descriptions of method 100 and method 200 above, and will not be repeated here.

[0121] Figure 6 A flowchart illustrating a message processing method 400 according to an embodiment of this application is shown. See also... Figure 6 The method 400 is described in terms of the interaction between the first communication device and the control management entity, and the method 400 may include, for example:

[0122] S401, when the first communication device determines that the bandwidth occupied by the highest forwarding priority message transmitted through the first port meets the first condition, it obtains the characteristic information of the attack message in the highest forwarding priority message.

[0123] S402, the first communication device sends the characteristic information of the attack message to the control and management entity;

[0124] S402, the control management entity generates a message processing strategy based on the feature information of the attack message. The message processing strategy is used to process messages that match the feature information of the attack message.

[0125] As an example, the method 400 may further include: the first communication device acquiring a message processing strategy generated by the control and management device, thereby the first communication device processing a first message based on the message processing strategy, wherein the first message is a message that matches the feature information of the attack message.

[0126] As yet another example, the method 400 may further include: the control management device sending a message processing strategy to the second communication device, thereby the second communication device processing a second message based on the message processing strategy, wherein the second message is a message that matches the feature information of the attack message.

[0127] The first condition may include the proportion of bandwidth occupied by the highest forwarding priority packets transmitted through the first port being greater than or equal to a first threshold. Alternatively, the first condition may also include the proportion of the highest forwarding priority packets transmitted through the first port being greater than or equal to a second threshold.

[0128] It should be noted that the specific implementation method and the effect achieved by method 400 can be found in the relevant descriptions of methods 100 to 300 above, and will not be repeated here.

[0129] Furthermore, embodiments of this application also provide a message processing system 700, see [link to relevant documentation]. Figure 7 As shown. The system 700 may include at least a first communication device 701 and a control and management entity 702. Wherein,

[0130] The first communication device 701 is used to determine that when the bandwidth occupied by the highest forwarding priority message transmitted through the first port meets a first condition, it acquires and sends the characteristic information of the attack message in the highest forwarding priority message to the control management entity 702.

[0131] The control management entity 702 is used to generate a message processing policy based on the message characteristic information of the attack message. The message processing policy is used to process messages that match the characteristic information of the attack message.

[0132] As an example, the control and management device 702 is further configured to send the message processing strategy to the first communication device. Then, the first communication device 701 is further configured to process a first message based on the message processing strategy, wherein the first message is a message matching the feature information of the attack message.

[0133] As another example, the system 700 may further include a second communication device, and a control management device 702, which is also used to send the message processing strategy to the second communication device. Then, the second communication device is further used to process a second message based on the message processing strategy, wherein the second message is a message that matches the feature information of the attack message.

[0134] The first condition may include the proportion of bandwidth occupied by the highest forwarding priority packets transmitted through the first port being greater than or equal to a first threshold. Alternatively, the first condition may also include the proportion of the highest forwarding priority packets transmitted through the first port being greater than or equal to a second threshold.

[0135] It should be noted that the specific implementation method and achieved effect of system 700 can be found in the relevant descriptions of methods 100 to 400 above, or you can also refer to... Figure 1 and Figure 2 The relevant descriptions of the embodiments shown will not be repeated here.

[0136] In addition, embodiments of this application also provide a first communication device 800, see [link to relevant documentation]. Figure 8 As shown. The first communication device 800 includes a processing unit 801 and a transmitting unit 802. The processing unit 801 is used to perform the above-described... Figures 3-6 In any of the embodiments shown, the first communication device performs the processing operation; the sending unit 802 is used to perform the above-mentioned processing operation. Figures 3-6 The transmission operation performed by the first communication device in any of the embodiments shown. For example, the processing unit 801 can perform... Figure 3 The operation in the middle embodiment is as follows: determining that the highest forwarding priority packet transmitted through the first port occupies the bandwidth of the first port and satisfies a first condition; obtaining the characteristic information of the first attack packet included in the highest forwarding priority packet transmitted through the first port. For example, the sending unit 802 can perform the following: Figure 3 Operation in the Chinese embodiment: Send the characteristic information of the first attack message to the control and management entity.

[0137] In addition, embodiments of this application also provide a first communication device 900, see [link to relevant documentation]. Figure 9 As shown. The first communication device 900 includes a first communication interface 901, a second communication interface 902, and a processor 903. The first communication interface 901 is used to perform the aforementioned functions. Figures 3-6 In any of the embodiments shown, the first communication device performs the receiving operation; the second communication interface 902 is used to perform the aforementioned... Figures 3-6 In any of the embodiments shown, the first communication device performs the transmission operation; the processor 903 is used to perform the above-described transmission operation. Figures 3-6 In any of the embodiments shown, the first communication device performs operations other than receiving and transmitting. For example, processor 903 can perform... Figure 3 In the middle embodiment, the operation determines that the highest forwarding priority packet transmitted through the first port occupies the bandwidth of the first port to satisfy a first condition; and obtains the feature information of the first attack packet included in the highest forwarding priority packet transmitted through the first port.

[0138] In addition, this application also provides a first communication device 1000, see [link to relevant documentation]. Figure 10 As shown. The first communication device 1000 includes a memory 1001 and a processor 1002 communicating with the memory 1001. The memory 1001 includes computer-readable instructions; the processor 1002 executes the computer-readable instructions, causing the first communication device 1000 to perform the aforementioned... Figures 3-6 The method performed by the first communication device in any of the embodiments shown.

[0139] It is understood that in the above embodiments, the processor can be a central processing unit (CPU), a network processor (NP), or a combination of a CPU and an NP. The processor can also be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD can be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. A processor can refer to a single processor or may include multiple processors. The memory may include volatile memory, such as random-access memory (RAM); it may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); and it may also include combinations of the above types of memory. A memory may refer to a single memory or may include multiple memories. In one specific embodiment, the memory stores computer-readable instructions, which include multiple software modules, such as a sending module, a processing module, and a receiving module. After executing each software module, the processor can perform corresponding operations according to the instructions of each software module. In this embodiment, the operation performed by a software module actually refers to the operation performed by the processor according to the instructions of the software module. After executing the computer-readable instructions in the memory, the processor can perform all the operations that the first communication device can perform in the message processing method according to the instructions of the computer-readable instructions.

[0140] It is understood that, in the above embodiments, the second communication interface 902 of the first communication device 900 can be specifically used as the sending unit 802 in the first communication device 800 to realize data communication between the first communication device and the control and management entity; the first communication interface 901 of the first communication device 900 can be specifically used as the receiving unit in the first communication device 800, for example, it can be used to receive messages sent by upstream network devices.

[0141] Furthermore, this application embodiment also provides a communication system, in which the first communication device can be, for example, the first communication device 800, 900, or 1000 described above. For example, if the communication system is the message processing system 700 described above, then the first communication device is the first communication device 701, and the control management entity is the control management entity 702.

[0142] Furthermore, embodiments of this application also provide a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the above-mentioned actions. Figures 3-6 The message processing method in the illustrated embodiment.

[0143] Furthermore, embodiments of this application also provide a computer program product, including a computer program or computer-readable instructions, which, when executed on a computer, cause the computer to perform the aforementioned... Figures 3-6 The message processing method in the illustrated embodiment.

[0144] As can be seen from the above description of the embodiments, those skilled in the art can clearly understand that all or part of the steps in the methods of the above embodiments can be implemented by means of software plus a general-purpose hardware platform. Based on this understanding, the technical solution of this application can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as a read-only memory (ROM) / RAM, magnetic disk, optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, a server, or a network communication device such as a router) to execute the methods described in various embodiments or some parts of the embodiments of this application.

[0145] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the system and device embodiments are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions in the method embodiments. The device and system embodiments described above are merely illustrative. Modules described as separate components may or may not be physically separate, and components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0146] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application. It should be noted that those skilled in the art can make various improvements and modifications without departing from this application, and these improvements and modifications should also be considered within the scope of protection of this application.

Claims

1. A message processing method, characterized in that, The method is executed by a first communication device and includes: The highest forwarding priority message transmitted through the first port is determined to occupy the bandwidth of the first port, satisfying the first condition. Obtain the feature information of the first attack packet included in the highest forwarding priority packet transmitted through the first port. The feature information of the first attack packet is used to identify the first attack packet and the attack flow to which the first attack packet belongs. Send the characteristic information of the first attack message to the control and management entity; The message processing policy generated by the control and management entity is obtained. The message processing policy is used to process messages that match the feature information of the first attack message.

2. The method according to claim 1, characterized in that, The method further includes: Based on the message processing strategy, the first message is processed, and the first message is a message whose feature information matches that of the first attack message.

3. The method according to claim 2, characterized in that, The processing of the first message based on the message processing strategy includes: Based on the aforementioned message processing strategy, the first message is processed for packet loss.

4. The method according to claim 2, characterized in that, The processing of the first message based on the message processing strategy includes: Based on the message processing strategy, the first message is rate-limited.

5. The method according to claim 1, characterized in that, The method further includes: Send instruction information to the control and management entity, the instruction information being used to instruct the control and management entity to generate a message processing strategy.

6. The method according to any one of claims 1-5, characterized in that, The first condition includes that the proportion of bandwidth occupied by the highest forwarding priority message transmitted through the first port is greater than or equal to a first threshold.

7. The method according to any one of claims 1-5, characterized in that, The first condition includes the fact that the highest forwarding priority message transmitted through the first port occupies a bandwidth of the first port that is greater than or equal to a second threshold.

8. The method according to any one of claims 1-5, characterized in that, Before determining that the bandwidth occupied by the highest forwarding priority packet transmitted through the first port satisfies the first condition, the method further includes: It is determined that all messages transmitted through the first port satisfy the second condition.

9. The method according to claim 8, characterized in that, The second condition includes the proportion of bandwidth occupied by all messages transmitted through the first port being greater than or equal to a third threshold.

10. The method according to claim 8, characterized in that, The second condition includes that all packets transmitted through the first port are greater than or equal to the fourth threshold.

11. The method according to any one of claims 1-5, characterized in that, Before determining that the bandwidth occupied by the highest forwarding priority packet transmitted through the first port satisfies the first condition, the method further includes: Poll to detect the bandwidth usage of the first port.

12. The method according to any one of claims 1-5, characterized in that, The method further includes: The packet with the highest forwarding priority transmitted through the second port is determined to occupy the bandwidth of the second port, satisfying the third condition; Obtain the characteristic information of the second attack packet included in the highest forwarding priority packet transmitted through the second port; The characteristic information of the second attack message is sent to the control and management entity.

13. The method according to claim 12, characterized in that, The third condition includes the proportion of bandwidth occupied by the highest forwarding priority message transmitted through the second port being greater than or equal to the fifth threshold.

14. The method according to claim 12, characterized in that, The third condition includes that the highest forwarding priority message transmitted through the second port is greater than or equal to the sixth threshold.

15. The method according to any one of claims 1-5, characterized in that, The characteristic information of sending the first attack message to the control and management entity includes: A message is sent to the control and management entity, the message carrying the characteristic information of the first attack message.

16. The method according to claim 15, characterized in that, The message is any one of the following: Border Gateway Protocol (BGP) messages, Path Calculation Unit Communication Protocol (PCEP) messages, Telemetry messages, or Network Configuration Protocol (NETCONF) messages.

17. The method according to any one of claims 1-5, characterized in that, The characteristic information of the first attack message includes one or more of the following: The source Internet Protocol (IP) address, destination IP address, source port number, destination port number, or transport layer protocol number of the first attack message.

18. The method according to any one of claims 1-5, characterized in that, The first communication device operates on an Internet Protocol version 4 (IPv4) network, an Internet Protocol version 6 (IPv6) network, or a Virtual Private Network (VPN).

19. A method for processing messages, characterized in that, The method is executed by a first communication device and includes: The packet with the highest forwarding priority transmitted on the first port occupies the bandwidth of the first port, satisfying the first condition. Analyze the highest-priority forwarding packets transmitted through the first port; It is determined that the packets transmitted on the first port include attack packets with the highest forwarding priority; The feature information of the attack packet is obtained, and the feature information of the attack packet is used to identify the attack packet and the attack flow to which the attack packet belongs.

20. The method according to claim 19, characterized in that, The method further includes: In response to determining that the packets transmitted on the first port include an attack packet with the highest forwarding priority, an alarm signal is sent.

21. The method according to claim 20, characterized in that, The method further includes: The characteristic information of the attack message is sent to the control and management entity.

22. The method according to claim 21, characterized in that, The method further includes: The message processing policy generated by the control and management entity is obtained. The message processing policy is used to process messages that match the feature information of the attack message.

23. The method according to claim 19, characterized in that, The method further includes: Based on the feature information of the attack message, a message processing strategy is generated, which is used to process messages that match the feature information of the attack message.

24. The method according to claim 22 or 23, characterized in that, The method further includes: Based on the message processing strategy, the first message is processed, and the first message is a message whose feature information matches that of the attack message.

25. The method according to claim 24, characterized in that, The processing of the first message based on the message processing strategy includes: Based on the aforementioned message processing strategy, the first message is processed for packet loss.

26. The method according to claim 24, characterized in that, The processing of the first message based on the message processing strategy includes: Based on the message processing strategy, the first message is rate-limited.

27. The method according to any one of claims 19-23, characterized in that, The first condition includes that the proportion of bandwidth occupied by the highest forwarding priority message transmitted through the first port is greater than or equal to a first threshold.

28. The method according to any one of claims 19-23, characterized in that, The first condition includes that the highest forwarding priority of the packet transmitted through the first port is greater than or equal to the second threshold.

29. A method for processing messages, characterized in that, The method includes: When the first communication device determines that the highest forwarding priority message transmitted through the first port occupies the bandwidth of the first port and meets the first condition, it obtains the feature information of the attack message in the highest forwarding priority message. The feature information of the attack message is used to identify the attack message and the attack flow to which the attack message belongs. The first communication device sends the characteristic information of the attack message to the control and management entity; The control and management entity generates a message processing strategy based on the message feature information of the attack message. The message processing strategy is used to process messages that match the feature information of the attack message. The control and management entity sends the message processing strategy to the first communication device.

30. The method according to claim 29, characterized in that, The method further includes: The first communication device processes the first message based on the message processing strategy. The first message is a message whose feature information matches that of the attack message.

31. The method according to claim 29, characterized in that, The method further includes: The control and management entity sends the message processing strategy to the second communication device.

32. The method according to claim 31, characterized in that, The method further includes: The second communication device processes the second message based on the message processing strategy. The second message is a message that matches the feature information of the attack message.

33. The method according to any one of claims 29-32, characterized in that, The first condition includes that the proportion of bandwidth occupied by the highest forwarding priority message transmitted through the first port is greater than or equal to a first threshold.

34. The method according to any one of claims 29-32, characterized in that, The first condition includes that the highest forwarding priority of the packet transmitted through the first port is greater than or equal to the second threshold.

35. A message processing system, characterized in that, The system includes a first communication device and a control and management entity, wherein, The first communication device is configured to, when determining that the highest forwarding priority message transmitted through the first port occupies the bandwidth of the first port to meet a first condition, acquire and send to the control and management entity the feature information of the attack message in the highest forwarding priority message, wherein the feature information of the attack message is used to identify the attack message and the attack flow to which the attack message belongs. The control and management entity is used to generate a message processing strategy based on the message feature information of the attack message. The message processing strategy is used to process messages that match the feature information of the attack message. The control and management entity is also used to send the message processing strategy to the first communication device.

36. The system according to claim 35, characterized in that, The first communication device is further configured to process a first message based on the message processing strategy, wherein the first message is a message that matches the feature information of the attack message.

37. The system according to claim 35, characterized in that, The system also includes a second communication device. The control and management entity is also used to send the message processing strategy to the second communication device.

38. The system according to claim 37, characterized in that, The second communication device is further configured to process a second message based on the message processing strategy, wherein the second message is a message that matches the feature information of the attack message.

39. The system according to any one of claims 35-38, characterized in that, The first condition includes that the proportion of bandwidth occupied by the highest forwarding priority message transmitted through the first port is greater than or equal to a first threshold.

40. The system according to any one of claims 35-38, characterized in that, The first condition includes that the highest forwarding priority of the packet transmitted through the first port is greater than or equal to the second threshold.

41. A communication device, characterized in that, include: Memory, which includes computer-readable instructions; A processor communicating with the memory, the processor being configured to execute the computer-readable instructions, causing the communication device to perform the method according to any one of claims 1-18.

42. A communication device, characterized in that, include: Memory, which includes computer-readable instructions; A processor communicating with the memory, the processor being configured to execute the computer-readable instructions, causing the communication device to perform the method according to any one of claims 19-28.

43. A communication system, characterized in that, The communication system includes a first communication device and a control and management entity. The first communication device is used to perform the operation implemented by the first communication device in the method of any one of claims 29-34; The control management entity is used to perform the operations implemented by the control management entity in any one of claims 29-34.

44. A computer-readable storage medium comprising computer-readable instructions, characterized in that, When the computer-readable instructions are executed on a computer, the computer causes the computer to perform the method according to any one of claims 1-34.

45. A computer program product comprising a computer program or computer-readable instructions that, when the computer program or the computer-readable instructions are executed on a computer, cause the computer to perform the method of any one of claims 1-34.

Citation Information

Patent Citations

  • Method and apparatus for network address conversion

    CN101459699A

  • Processing method and device aiming at denial of service attack

    CN103618718A

  • Processing strategy generation method and system and storage medium

    CN111092840A