A data processing method and apparatus based on an IP address

By combining the Bloom filter algorithm and the binary tree algorithm to generate a matching table, the problem of difficult to meet the efficiency and accuracy of IP address matching in the prior art is solved, and efficient and accurate IP address matching is achieved.

CN115412304BActive Publication Date: 2025-06-10CHINA TELECOM CORP LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210936855.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-05
Publication Date
2025-06-10
Estimated Expiration
2042-08-05

AI Technical Summary

Technical Problem

In the prior art, it is difficult to meet the requirements of efficiency and accuracy when performing IP address matching. Especially when IPV6 addresses are widely used, the number of IP addresses is large and the user's IP address matching needs are increasing.

Method used

Two matching tables are generated using a method combining the Bloom filter algorithm and the binary tree algorithm. The Bloom filter algorithm is used to quickly filter out data packets that do not belong to the IP address pool, while the binary tree algorithm is used to accurately determine whether the IP address to be matched exists in the IP address pool and find the sub-IP address pool to which it belongs.

Benefits of technology

While ensuring the efficiency of IP address matching, it improves the accuracy of IP address matching and can effectively handle matching requests in large-scale IP address pools.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115412304B_ABST
    Figure CN115412304B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides a data processing method and apparatus based on an IP address. The method includes: obtaining IP address information configured in an IP address pool; generating a first matching table corresponding to the IP address information based on the Bloom filter algorithm, and generating a second matching table corresponding to the IP address information based on the binary tree algorithm; obtaining a target IP address, and combining the first matching table and the second matching table to determine a matching result of the target IP address in the IP address pool. Through the embodiment of the present invention, the combination of the Bloom filter algorithm and the binary tree algorithm is realized for IP address matching, which improves the accuracy of IP address matching while ensuring the efficiency of IP address matching.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet technologies, and particularly to a method and apparatus for processing data based on IP addresses. Background Art

[0002] In the field of the Internet, some services rely on the matching of IP addresses. For example, in an anti-DDoS (Distributed Denial of Service Attack) platform, it is responsible for collecting, summarizing, and analyzing relevant data of network security devices, and presenting them to customers in a graphical manner or the like. And these data usually contain IP addresses. The anti-DDoS platform needs to perform IP address matching to find relevant information about the IP address, such as the customer to which the IP address belongs.

[0003] However, with the rapid development of computer technologies and the popularization of network applications, especially the gradual wide use of IPv6 addresses, the number of IP addresses is huge and the demand for IP address matching by users is also increasing gradually. However, the existing methods for IP address matching using algorithms such as hash algorithms and binary search algorithms are difficult to meet the efficiency requirements and accuracy requirements for IP address matching. Summary of the Invention

[0004] In view of the above problems, a method and apparatus for processing data based on IP addresses are proposed to provide a solution to overcome or at least partially solve the above problems, including:

[0005] A method for processing data based on IP addresses, the method including:

[0006] Obtaining IP address information configured in an IP address pool;

[0007] Generating a first matching table corresponding to the IP address information based on the Bloom filter algorithm, and generating a second matching table corresponding to the IP address information based on the binary tree algorithm;

[0008] Obtaining a target IP address, and determining a matching result of the target IP address in the IP address pool by combining the first matching table and the second matching table.

[0009] Optionally, the IP address pool is composed of multiple sub-IP address pools. The determining the matching result of the target IP address in the IP address pool by combining the first matching table and the second matching table includes:

[0010] Matching the target IP address in the first matching table;

[0011] When the target IP address is successfully matched in the first matching table, match the target IP address in the second matching table.

[0012] Optionally, generating the first matching table corresponding to the IP address information based on the Bloom filter algorithm includes:

[0013] Convert the IP address included in the IP address information into a number in a specified base and input it into the Bloom filter to generate the first matching table;

[0014] The matching the target IP address in the first matching table includes:

[0015] Convert the target IP address into a number in a specified base and match the number obtained by converting the target IP address in the first matching table.

[0016] Optionally, generating the second matching table corresponding to the IP address information based on the binary tree algorithm includes:

[0017] Generate a plurality of IP address sets according to the IP address information and configure the plurality of IP address sets as a tree structure to obtain the second matching table;

[0018] The matching the target IP address in the second matching table includes:

[0019] In the second matching table, match the target IP address according to the configured tree structure.

[0020] Optionally, each IP address set includes a start address and an end address, and the configuring the plurality of IP address sets as a tree structure to obtain the second matching table includes:

[0021] For each IP address set, configure it as a tree node;

[0022] According to the start address and end address of each IP address set, configure a plurality of tree nodes as a tree structure to obtain the second matching table;

[0023] The matching the target IP address in the second matching table according to the configured tree structure includes:

[0024] In the second matching table, starting from the root node of the tree structure, compare the target IP address with the start address and end address of each tree node in turn;

[0025] When the target IP address is within the range of the start address and end address of the current tree node, it is determined that the matching of the target IP address in the second matching table is successful.

[0026] Optionally, each set of IP addresses is associated with the identifier of the sub-IP address pool to which it belongs, and further includes:

[0027] When the target IP address is successfully matched in the second matching table, determine the set of target IP addresses corresponding to the target IP address;

[0028] According to the identifier of the target sub-IP address pool associated with the set of target IP addresses, determine the target sub-IP address pool to which the target IP address belongs.

[0029] Optionally, before configuring the multiple sets of IP addresses as a tree structure to obtain the second matching table, it further includes:

[0030] Merge the sets with duplicates among the multiple sets of IP addresses.

[0031] A data processing device based on IP addresses, the device includes:

[0032] An IP address information acquisition module, configured to acquire the IP address information configured in the IP address pool;

[0033] A matching table generation module, configured to generate a first matching table corresponding to the IP address information based on the Bloom filter algorithm, and generate a second matching table corresponding to the IP address information based on the binary tree algorithm;

[0034] A matching result determination module, configured to acquire a target IP address, and combine the first matching table and the second matching table to determine the matching result of the target IP address in the IP address pool.

[0035] An electronic device, including a processor, a memory, and a computer program stored on the memory and capable of running on the processor, where when the computer program is executed by the processor, it implements the above-mentioned data processing method based on IP addresses.

[0036] A computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the above-mentioned data processing method based on IP addresses.

[0037] The embodiments of the present invention have the following advantages:

[0038] In an embodiment of the present invention, by obtaining the IP address information configured in the IP address pool, generating a first matching table corresponding to the IP address information based on the Bloom filter algorithm, and generating a second matching table corresponding to the IP address information based on the binary tree algorithm, then obtaining the target IP address, and combining the first matching table and the second matching table to determine the matching result of the target IP address in the IP address pool, it realizes IP address matching by combining the Bloom filter algorithm and the binary tree algorithm, improving the accuracy of IP address matching while ensuring the efficiency of IP address matching. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the technical solutions of the present invention, the drawings required for the description of the present invention will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0040] Figure 1 is a flowchart of the steps of a data processing method based on an IP address provided by an embodiment of the present invention;

[0041] Figure 2 is a schematic diagram of a data processing system based on an IP address provided by an embodiment of the present invention;

[0042] Figure 3 is a schematic diagram of a first matching table provided by an embodiment of the present invention;

[0043] Figure 4 is a schematic diagram of a second matching table provided by an embodiment of the present invention;

[0044] Figure 5 is a block diagram of the structure of a data processing device based on an IP address provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0045] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the drawings and specific embodiments. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments of the present invention belong to the scope of protection of the present invention.

[0046] In the Internet field, the same customer can be configured with different types of IP address resources, which can include single IP addresses, such as IPv4 addresses and IPv6 addresses, or can include consecutive IP addresses, such as address segments and network segments. All the IP address resources of the same customer can be merged into a sub-IP address pool, that is, the sub-IP address pool can contain IP address resources such as IPv4 addresses, IPv6 addresses, address segments, and network segments. The sub-IP address pools of all customers can be aggregated into the same IP address pool.

[0047] For IP address matching, it is to check whether the IP address to be matched exists in the IP address pool, and then find the sub-IP address pool corresponding to the IP address to be matched, that is, to determine information such as the customer to which it belongs.

[0048] In practical applications, the hash algorithm, binary search algorithm, and Bloom filter algorithm can be used to implement IP address matching to provide relevant information about IP address association for platforms such as anti-DDoS.

[0049] Among them, the method of using the hash algorithm is to construct the IP address pool into a hash table through a hash function, and perform hash matching with the IP address to be matched to determine whether the IP address to be matched exists in the IP address pool. However, when using a hash table to store a large amount of data, the space efficiency is very low, and hash conflicts are also likely to occur.

[0050] The method of using the binary search algorithm can achieve a halving query, but in the case of a large amount of data, it needs to be traversed each time, and the efficiency is very low.

[0051] The method of using the Bloom filter algorithm is to map the IP address pool into a binary array. It is a binary vector with high space and time efficiency and can determine whether an element belongs to a certain set. However, there is a certain probability of false judgment, that is, the Bloom filter algorithm can determine that a certain element definitely does not exist in a certain set, but cannot determine whether a certain element definitely exists in a certain set. Therefore, the Bloom filter algorithm is not suitable for scenarios where zero tolerance for misjudgment is required.

[0052] Based on this, the embodiments of the present invention propose to combine the Bloom filter algorithm and the binary tree algorithm for IP address matching. By generating two matching tables according to the preset IP address pool, one matching table is generated based on the Bloom filter algorithm and is used to quickly filter out data packets that do not belong to the IP address pool under a large amount of data, but it cannot determine that the IP address to be matched definitely exists in the IP address pool. The other matching table is generated based on the binary tree algorithm and can accurately determine whether the IP address to be matched exists in the IP address pool, and then find the sub-IP address pool to which it belongs to obtain relevant customer information.

[0053] Specifically, the first matching table generated based on the Bloom filter algorithm is used to quickly filter out the data packets that do not belong to the IP address pool. Regarding the possible false positive rate of the Bloom filter, the second matching table generated based on the binary tree algorithm is used to accurately determine whether the IP address to be matched belongs to the preset IP address pool and find out the position of its affiliated sub-IP address pool.

[0054] The following further describes the embodiments of the present invention:

[0055] Refer to Figure 1 , which shows the flowchart of the steps of a data processing method based on IP addresses provided by an embodiment of the present invention. This method can be applied to the Linux system. The database involved can adopt the Mongo database, the message middleware can adopt Kafka, and the development language can adopt Python.

[0056] Specifically, it can include the following steps:

[0057] Step 101, obtain the IP address information configured in the IP address pool.

[0058] For platforms such as anti-DDoS, it can preset the IP address pool. The IP address information in the IP address pool can include individual IP addresses, such as IPV4 addresses and IPV6 addresses, or can also include continuous IP addresses, such as address segments and network segments.

[0059] Specifically, the same customer can be configured with different types of IP address resources, which can include individual IP addresses, such as IPV4 addresses and IPV6 addresses, or can also include continuous IP addresses, such as address segments and network segments. All the IP address resources of the same customer can be merged into a sub-IP address pool, that is, the sub-IP address pool can contain IP address resources such as IPV4 addresses, IPV6 addresses, address segments, and network segments. The sub-IP address pools of all customers can be aggregated into the same IP address pool.

[0060] In an example, such as Figure 2 , the IP address pool can be set on the platform side, such as an anti-DDoS platform. Users can perform operations such as addition, deletion, modification, and query on the preset IP address pool through the WebAPI.

[0061] Step 102, generate the first matching table corresponding to the IP address information based on the Bloom filter algorithm, and generate the second matching table corresponding to the IP address information based on the binary tree algorithm.

[0062] As an example, the binary tree algorithm can be a balanced binary tree algorithm.

[0063] After obtaining the IP address information of the IP address pool, based on the Bloom filter algorithm, the IP address information can be used to generate a first matching table, which can be used to quickly filter out data packets that do not belong to the IP address pool under a large amount of data, but it cannot determine that the IP address to be matched must exist in the IP address pool.

[0064] Moreover, based on the binary tree algorithm, the IP address information can also be used to generate a second matching table, which can be used to accurately determine whether the IP address to be matched exists in the IP address pool, and then find out the information of the sub-IP address pool to which it belongs to obtain relevant customer information.

[0065] In an embodiment of the present invention, the step of generating the first matching table corresponding to the IP address information based on the Bloom filter algorithm may include:

[0066] Sub-step 11: Convert the IP addresses included in the IP address information into numbers in a specified base and input them into the Bloom filter to generate a first matching table.

[0067] As an example, the specified base may be hexadecimal.

[0068] For the Bloom filter algorithm, it can first split the IP address information such as address segments and network segments included in the IP address pool into individual IP addresses, and then store them together with the original individual IP addresses in the Bloom filter, and then the Bloom filter can generate a first matching table.

[0069] Since there are multiple representation methods for IPv6 addresses, such as colon-hexadecimal representation, 0-bit compression representation, and embedded IPv4 address representation, they can be uniformly converted into hexadecimal digital representation according to the binary form of IPv4 addresses and IPv6 addresses, and then input into the Bloom filter. After obtaining the converted numbers, a first matching table can be generated from the converted numbers, such as Figure 3 .

[0070] In an example, to solve the possible conflict between the IPv6 address and the IPv4 address after conversion into a number, 2^32 can be added to the hexadecimal number converted from the IPv6 address.

[0071] For example, if the IP address segment in the preset IP address pool is 192.168.0.253 - 192.168.0.255, it will be split into three IP addresses: 192.168.0.253, 192.168.0.254, and 192.168.0.255. The converted hexadecimal numbers are: C0A800FD, C0A800FE, C0A800FF.

[0072] For another example, the IP network segment 192.168.1.0 / 31 will be split into 192.168.1.0 and 192.168.1.1. The converted hexadecimal numbers are: C0A80100 and C0A80101.

[0073] For another example, the IPV6 address FF01::1101. The converted hexadecimal number is: FF010000000000000000000100001101.

[0074] For another example, the IPV4 address 192.168.0.250. The converted hexadecimal number is: C0A800FA.

[0075] In an embodiment of the present invention, generating the second matching table corresponding to the IP address information based on the binary tree algorithm may include:

[0076] Sub-step 21: Generate a plurality of IP address sets according to the IP address information, and configure the plurality of IP address sets as a tree structure to obtain the second matching table.

[0077] For the binary tree algorithm, it can generate a plurality of IP address sets according to the IP address information of each sub-IP address pool in the preset IP address pool. For example, convert an IP address segment, network segment, and a single IP address into an IP address set respectively.

[0078] Among them, each IP address set may include a plurality of IP addresses. There is a start address and an end address. The start address and the end address are the first IP address and the last IP address after arranging all IP addresses in order. The start address and the end address of a single IP address are both itself. Each IP address set can be identified by the start address and the end address.

[0079] In an example, for the convenience of subsequent matching, the start address and the end address can be converted into hexadecimal numbers, and then a set can be identified by the hexadecimal start address and end address.

[0080] For example, the sub-IP address pool 01 contains IP address segments 192.168.0.253 - 192.168.0.255, IP network segment 192.168.1.0 / 31, IP address FF01::1101, and IP address 192.168.0.250, which are respectively converted into IP address sets containing their start addresses and end addresses (C0A800FD, C0A800FF), (C0A80100, C0A80101), (FF010000000000000000000100001101, FF010000000000000000000100001101), (C0A800FA, C0A800FA).

[0081] After obtaining multiple IP address sets, the multiple IP address sets can be expanded into a tree structure to obtain a second matching table, such as expanding according to the size of the start addresses in the IP address sets.

[0082] In an embodiment of the present invention, before configuring the multiple IP address sets into a tree structure to obtain a second matching table, it may further include:

[0083] Merging the sets with duplicates among the multiple IP address sets.

[0084] Since there may be duplicate IP addresses among the multiple IP address sets, the sets with duplicates can be merged, that is, if any two sets have an intersection, their union is taken to merge them into one set.

[0085] For example, for the multiple IP address sets (C0A800FD, C0A800FF), (C0A80100, C0A80101), (FF010000000000000000000100001101, FF010000000000000000000100001101), (C0A800FA, C0A800FA) obtained above, since there are duplicate IP addresses among them, their union can be taken for merging, and then the merged IP address sets (C0A800FD, C0A80101), (FF010000000000000000000100001101, FF010000000000000000000100001101) can be obtained.

[0086] In an example, since different IP address sets belong to different sub-IP address pools, that is, different customers, in addition to using the start address and end address in the expression form of the IP address set, the identifier of the sub-IP address pool to which it belongs can also be added to facilitate subsequent query of the sub-IP address pool to which it belongs and the associated customer information.

[0087] For example, for IP address sets identified by a start address and an end address, (C0A800FD, C0A80101), (FF010000000000000000000100001101, FF010000000000000000000100001101), after adding the identifier 01 of the sub-IP address pool, the IP address sets can be {(C0A800FD, C0A80101), 01}, {(FF010000000000000000000100001101, FF010000000000000000000100001101), 01}.

[0088] In an embodiment of the present invention, each IP address set may include a start address and an end address. Configuring the multiple IP address sets into a tree structure to obtain a second matching table may include:

[0089] For each IP address set, configure it as a tree node; according to the start address and end address of each IP address set, configure multiple tree nodes into a tree structure to obtain a second matching table.

[0090] For the tree structure, it may include multiple tree nodes. Each tree node may correspond to an IP address set, and according to the size relationship between the start address and end address of each IP address set, configure multiple tree nodes into a tree structure, and then form a second matching table, such as Figure 4 .

[0091] Step 103, obtain a target IP address, and combine the first matching table and the second matching table to determine the matching result of the target IP address in the IP address pool.

[0092] When performing IP address matching, the IP address to be matched, that is, the target IP address, can be obtained, and then the target IP address can be matched in the first matching table and the second matching table.

[0093] When the matching result is successful, it indicates that the target IP address is included in the IP address pool. When the matching result is failed, it indicates that the target IP address is not included in the IP address pool.

[0094] For the anti-DDoS platform, the target IP address may be the IP address of the data packet collected by the network security device, such as Figure 2, it is possible to establish monitoring for security devices through protocols such as HTTP / HTTPS and SYSLOG. Furthermore, data of each network security device can be obtained on the server side via a collector. After processing, the processed data packets can be forwarded to a Kafka data cluster for storage.

[0095] Among them, the processing process may include parsing each data packet according to preset fields, adding information such as the current timestamp and the IP address of the peer device to the parsed data. The preset fields include the destination IP address, time, upstream traffic, downstream traffic, attack traffic, and normal traffic.

[0096] When IP address matching is required, the data packets stored in the Kafka data cluster can be retrieved. Furthermore, the data packets can be parsed by a parser into a unified format including fields such as the target IP address to be matched, in order to obtain the target IP address for IP address matching.

[0097] Among them, the specific expression of the unified format is: including the target IP address to be matched, the device IP address, time, upstream traffic, downstream traffic, attack traffic, and normal traffic.

[0098] In an embodiment of the present invention, the IP address pool may be composed of multiple sub-IP address pools. Combining the first matching table and the second matching table to determine the matching result of the target IP address in the IP address pool may include:

[0099] Sub-step 31, matching the target IP address in the first matching table.

[0100] In a specific implementation, the target IP address can be first matched in the first matching table to check whether the target IP address exists in the first matching table. Furthermore, data packets that do not belong to the IP address pool can be quickly filtered out under a large amount of data.

[0101] In an embodiment of the present invention, sub-step 31 may include:

[0102] Sub-step 311, converting the target IP address into a number in a specified base and matching the converted number of the target IP address in the first matching table.

[0103] As an example, the specified base may be hexadecimal.

[0104] Since the first matching table stores numbers converted into a specified base, for the convenience of matching, the target IP address can also be converted into a number in the specified base. Furthermore, the converted number of the target IP address can be matched in the first matching table.

[0105] Sub-step 32: When the target IP address is successfully matched in the first matching table, match the target IP address in the second matching table.

[0106] When the target IP address fails to be matched in the first matching table, that is, the target IP address is not found in the first matching table, it indicates a matching failure, meaning the target IP address is not in the IP address pool, and the corresponding data packet can be discarded.

[0107] When the target IP address is successfully matched in the first matching table, that is, the target IP address is found in the first matching table. Since the Bloom filter algorithm can determine that a certain element must not exist in a certain set, but cannot determine whether a certain element must exist in a certain set, it cannot be determined for sure that the target IP address is in the IP address pool.

[0108] Based on this, the target IP address can be further matched in the second matching table, so as to accurately determine whether the IP address to be matched belongs to the IP address pool. Further, the information of the sub-IP address pool to which it belongs can be found to obtain relevant customer information.

[0109] In an embodiment of the present invention, sub-step 32 may include:

[0110] Sub-step 321: In the second matching table, match the target IP address according to the configured tree structure.

[0111] Since the data in the second matching table is stored according to the tree structure, the target IP address can be matched in the second matching table according to the tree structure.

[0112] In an embodiment of the present invention, sub-step 321 may include:

[0113] In the second matching table, starting from the root node of the tree structure, compare the target IP address with the start address and end address of each tree node in turn; when the target IP address is within the range of the start address and end address of the current tree node, it is determined that the target IP address is successfully matched in the second matching table.

[0114] When storing multiple IP address sets according to the tree structure, the IP address set with a start address smaller than the start address of the current IP address set can be set in the left subtree of the tree node corresponding to the current IP address set, and the IP address set with a start address larger than the start address of the current IP address set can be set in the right subtree of the tree node corresponding to the current IP address set.

[0115] Based on this, the target IP address to be matched first can be compared with the set of IP addresses corresponding to the root node in the second matching table. If the target IP address is less than the first address in the set, then continue to search in the left subtree. If the target IP address is greater than both the first address and the last address in the set, then continue to search in the right subtree. If the target IP address is within the range of the first address and the last address, it indicates a successful search.

[0116] During the search in the left subtree, if the target IP address is greater than the last address in the set of IP addresses corresponding to the current tree node, it indicates a failed search. If the target IP address is less than the first address, continue to search to the left.

[0117] During the search in the right subtree, if the target IP address is less than the first address in the set of IP addresses corresponding to the current tree node, it indicates a failed search. If the target IP address is greater than the last address, continue to search to the right.

[0118] For example, assume the root node is R. In the expression "A < B", the "<" sign means that A is numerically less than B. In the expression "A = B", the "=" sign means that A is numerically equal to B. The value converted from the target IP address to be matched is I, the left subtree is N l , and the right subtree is N r , and N l < R < N r , the current tree node is N, the first address of the structure in N is N b , the last address is N e , and the sub-IP address pool is N d .

[0119] If N = R and N b <= I <= N e , return N d ;

[0120] If N = R and I > N e , enter N r to search. If I < N b , enter N l to search;

[0121] If N = N l and I < N b , then continue to search to the left. If I > N e then turn to search to the right until it is found that there exists N such that N b <= I <= N e and then return N d ;

[0122] If N = N r and I > N e , then continue to search to the right. If I < Nb Then turn to search left until an N is found such that N b <= I <= N e and then return Nd;

[0123] If the returned result is N d , it indicates that the matching is successful, and the target IP address to be matched is in the IP address pool. Otherwise, it indicates that the target IP address to be matched is not in the IP address pool.

[0124] In an embodiment of the present invention, each IP address set is associated with the identifier of its affiliated sub-IP address pool, and it may further include:

[0125] When the matching of the target IP address in the second matching table is successful, determine the target IP address set corresponding to the target IP address; according to the identifier of the target sub-IP address pool associated with the target IP address set, determine the target sub-IP address pool to which the target IP address belongs.

[0126] As described above, the IP address set can be identified by the start address, end address, and the identifier of the affiliated sub-IP address pool. Then, when the matching of the target IP address in the second matching table is successful, the target IP address set corresponding to the target IP address can be determined, and the target sub-IP address pool to which the target IP address belongs can be determined, and thus the corresponding customer information can be obtained.

[0127] In an example, when the matching is successful, the data packet and related information (such as the target sub-IP address pool, affiliated customer information) can be saved to the database for subsequent use, such as Figure 2 , first store the original data in MongoDB1, and then after a period of time, merge the data according to a certain dimension and store the merged data in MongoDB1 to provide it to users through WebAPI.

[0128] In the embodiment of the present invention, by obtaining the IP address information configured in the IP address pool, generating the first matching table corresponding to the IP address information based on the Bloom filter algorithm, and generating the second matching table corresponding to the IP address information based on the binary tree algorithm, then obtaining the target IP address, and combining the first matching table and the second matching table to determine the matching result of the target IP address in the IP address pool, it realizes IP address matching by combining the Bloom filter algorithm and the binary tree algorithm, improving the accuracy of IP address matching while ensuring the efficiency of IP address matching.

[0129] It should be noted that, for method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described action sequences, because according to the embodiments of the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential for the embodiments of the present invention.

[0130] Referring to Figure 5 , a schematic structural diagram of a data processing device based on an IP address provided by an embodiment of the present invention is shown, which may specifically include the following modules:

[0131] An IP address information acquisition module 501, configured to acquire IP address information configured in an IP address pool.

[0132] A matching table generation module 502, configured to generate a first matching table corresponding to the IP address information based on the Bloom filter algorithm, and generate a second matching table corresponding to the IP address information based on the binary tree algorithm.

[0133] A matching result determination module 503, configured to acquire a target IP address, and combine the first matching table and the second matching table to determine a matching result of the target IP address in the IP address pool.

[0134] In an embodiment of the present invention, the IP address pool is composed of multiple sub-IP address pools. The combining the first matching table and the second matching table to determine a matching result of the target IP address in the IP address pool includes:

[0135] Matching the target IP address in the first matching table;

[0136] When the matching of the target IP address in the first matching table is successful, matching the target IP address in the second matching table.

[0137] In an embodiment of the present invention, the generating the first matching table corresponding to the IP address information based on the Bloom filter algorithm includes:

[0138] Converting the IP address included in the IP address information into a number in a specified base, and inputting it into the Bloom filter to generate a first matching table;

[0139] The matching the target IP address in the first matching table includes:

[0140] Converting the target IP address into a number in a specified base, and matching the number obtained by converting the target IP address in the first matching table.

[0141] In one embodiment of the present invention, generating the second matching table corresponding to the IP address information based on a binary tree algorithm includes:

[0142] Generate multiple IP address sets according to the IP address information, and configure the multiple IP address sets into a tree structure to obtain a second matching table;

[0143] The matching the target IP address in the second matching table includes:

[0144] In the second matching table, the target IP address is matched according to the configured tree structure.

[0145] In one embodiment of the present invention, each IP address set includes a first address and a last address, and configuring the multiple IP address sets into a tree structure to obtain a second matching table includes:

[0146] For each IP address set, configure it as a tree node;

[0147] According to the first address and the last address of each IP address set, multiple tree nodes are configured into a tree structure to obtain a second matching table;

[0148] The step of matching the target IP address in the second matching table according to the configured tree structure includes:

[0149] In the second matching table, starting from the root node of the tree structure, the target IP address is compared with the first address and the last address of each tree node in sequence;

[0150] When the target IP address is within the range of the first address and the last address of the current tree node, it is determined that the target IP address is successfully matched in the second matching table.

[0151] In one embodiment of the present invention, each IP address set is associated with an identifier of the sub-IP address pool to which it belongs, and the apparatus is further used for:

[0152] When the target IP address is successfully matched in the second matching table, determining a target IP address set corresponding to the target IP address;

[0153] The target sub-IP address pool to which the target IP address belongs is determined according to the target sub-IP address pool identifier associated with the target IP address set.

[0154] In one embodiment of the present invention, before configuring the multiple IP address sets into a tree structure to obtain a second matching table, the apparatus is further configured to:

[0155] Merge the sets with duplicates in the multiple IP address sets.

[0156] In an embodiment of the present invention, by obtaining the IP address information configured in the IP address pool, based on the Bloom filter algorithm, a first matching table corresponding to the IP address information is generated, and based on the binary tree algorithm, a second matching table corresponding to the IP address information is generated. Then, the target IP address is obtained, and in combination with the first matching table and the second matching table, the matching result of the target IP address in the IP address pool is determined, realizing IP address matching by combining the Bloom filter algorithm and the binary tree algorithm, improving the accuracy of IP address matching while ensuring the efficiency of IP address matching.

[0157] An embodiment of the present invention further provides an electronic device, which may include a processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, the above data processing method based on IP addresses is implemented.

[0158] An embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by the processor, the above data processing method based on IP addresses is implemented.

[0159] For the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For the relevant parts, refer to the partial description of the method embodiment.

[0160] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other.

[0161] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a device, or a computer program product. Therefore, the embodiments of the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0162] Embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate a device for implementing the specified functions in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or a device for implementing the specified functions in multiple blocks.

[0163] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the specified functions in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or a device for implementing the specified functions in multiple blocks.

[0164] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process. Therefore, the instructions executed on the computer or other programmable terminal device provide steps for implementing the specified functions in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or a device for implementing the specified functions in multiple blocks.

[0165] Although the preferred embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications to these embodiments once they know the basic creative concepts. Therefore, the appended claims are intended to be construed as including the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present invention.

[0166] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising the said element.

[0167] The above provides a detailed introduction to a data processing method and apparatus based on an IP address. Specific examples are used in this text to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A data processing method based on IP addresses, characterized in that, the method includes: Obtain the IP address information configured in the IP address pool; Based on the Bloom filter algorithm, generate a first matching table corresponding to the IP address information, and based on the binary tree algorithm, generate a second matching table corresponding to the IP address information; Obtain a target IP address, and combine the first matching table and the second matching table to determine the matching result of the target IP address in the IP address pool; The IP address pool consists of multiple sub-IP address pools. The combining the first matching table and the second matching table to determine the matching result of the target IP address in the IP address pool includes: Match the target IP address in the first matching table; When the matching of the target IP address in the first matching table is successful, match the target IP address in the second matching table; Generate multiple IP address sets according to the IP address information, and each IP address set is associated with the identifier of the sub-IP address pool to which it belongs. The method further includes: When the matching of the target IP address in the second matching table is successful, determine the target IP address set corresponding to the target IP address; Determine the target sub-IP address pool to which the target IP address belongs according to the target sub-IP address pool identifier associated with the target IP address set.

2. The method according to claim 1, characterized in that, the generating the first matching table corresponding to the IP address information based on the Bloom filter algorithm includes: Convert the IP addresses included in the IP address information into numbers in a specified base, and input them into the Bloom filter to generate a first matching table; The matching the target IP address in the first matching table includes: Convert the target IP address into a number in a specified base, and match the number obtained by converting the target IP address in the first matching table.

3. The method according to claim 2, characterized in that, the generating the second matching table corresponding to the IP address information based on the binary tree algorithm includes: Generate multiple IP address sets according to the IP address information, and configure the multiple IP address sets as a tree structure to obtain a second matching table; The matching the target IP address in the second matching table includes: In the second matching table, match the target IP address according to the configured tree structure.

4. The method according to claim 3, characterized in that, each IP address set includes a start address and an end address. The configuring the multiple IP address sets as a tree structure to obtain a second matching table includes: For each IP address set, configure it as a tree node; According to the start address and end address of each IP address set, configure multiple tree nodes as a tree structure to obtain a second matching table; The matching the target IP address according to the configured tree structure in the second matching table includes: In the second matching table, starting from the root node of the tree structure, the target IP address is sequentially compared with the start address and the end address of each tree node; When the target IP address is within the range of the start address and the end address of the current tree node, it is determined that the matching of the target IP address in the second matching table is successful.

5. The method according to claim 3, wherein, before configuring the multiple IP address sets as a tree structure to obtain a second matching table, further comprising: merging the sets with duplicates in the multiple IP address sets.

6. An IP address-based data processing device, wherein, the device includes: an IP address information acquisition module for acquiring the IP address information configured in the IP address pool; a matching table generation module for generating a first matching table corresponding to the IP address information based on the Bloom filter algorithm and generating a second matching table corresponding to the IP address information based on the binary tree algorithm; a matching result determination module for acquiring a target IP address and determining the matching result of the target IP address in the IP address pool in combination with the first matching table and the second matching table; the IP address pool is composed of multiple sub-IP address pools, and the matching result determination module includes: matching the target IP address in the first matching table; when the matching of the target IP address in the first matching table is successful, matching the target IP address in the second matching table; generating multiple IP address sets according to the IP address information, and each IP address set is associated with the identifier of the sub-IP address pool to which it belongs, and the device is further configured to: when the matching of the target IP address in the second matching table is successful, determining the target IP address set corresponding to the target IP address; determining the target sub-IP address pool to which the target IP address belongs according to the target sub-IP address pool identifier associated with the target IP address set.

7. An electronic device, wherein, comprising a processor, a memory, and a computer program stored on the memory and capable of running on the processor, and when the computer program is executed by the processor, it implements the IP address-based data processing method according to any one of claims 1 to 5.

8. A computer-readable storage medium, wherein, a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, it implements the IP address-based data processing method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Probabilistic tracking of host characteristics

    US20180034849A1