Message Processing Method, Apparatus and Electronic Device
By creating a message transfer information table and forwarding response messages, the problem of incomplete SSLVPN session connection under multi-core concurrent processing on the service board is solved, and stable message processing is achieved in large traffic scenarios.
Patent Information
- Application Number
- CN202210951150.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-09
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2042-08-09
AI Technical Summary
In large traffic scenarios, when the service board has multiple cores and concurrent processing, the integrity of the SSLVPN session connection cannot be guaranteed, resulting in the request packet and response packet cannot be processed on the same service board.
By obtaining the characteristic information of the response message, a message transfer information table is created, and the response message is forwarded to the service board where the request message is located according to the table, thereby ensuring that the request message and the response message are processed on the same service board.
It effectively avoids packet loss caused by timing problems, ensures the integrity of SSLVPN session connection, and provides a stable packet processing mechanism in large traffic scenarios.
Smart Images

Figure CN115412308B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of border security technologies, and in particular, to a message processing method, apparatus, electronic device, and computer-readable storage medium. Background Art
[0002] SSLVPN (Secure Session Layer Virtual Private Network) is used for remote users to securely and efficiently access enterprise internal network resources through the Internet.
[0003] In a distributed system, multiple service boards simultaneously provide data processing functions, and each service board uses multiple multi-core processors to concurrently process service data. Due to the characteristic of multi-core concurrent data processing on the service board, when the traffic load is large, there is a situation where the forwarding feature information of the request message has not been sent to the service board where the response message is located, and the response message has already been fed back to the service board of the response message. At this time, since the message forwarding information table is not established on the service board of the response message or the corresponding node information does not exist, it is impossible to forward the response message to the service board where the request message is located according to the forwarding information table, thus it is impossible to process the request message and the response message on the same service board, and thus it is impossible to ensure the integrity of the session connection.
[0004] Therefore, how to ensure the integrity of the SSLVPN session connection during multi-core concurrent processing of the service board in a large-traffic scenario is an urgent problem to be solved currently. Summary of the Invention
[0005] In order to solve the above technical problems or at least partially solve the above technical problems, the present disclosure provides a message processing method, which solves the problem that in a large-traffic scenario, relying on the feature information of the message to create a forwarding information table to guide the forwarding of SSLVPN messages, resulting in packet loss due to the timing problem of multi-core concurrent processing of the service board, and further leading to the incomplete SSLVPN session connection.
[0006] To achieve the above object, the embodiments of the present disclosure provide the following technical solutions:
[0007] In a first aspect, an embodiment of the present disclosure provides a message processing method, which is applied to a network security device. The network security device includes: a switching board and at least two service boards. The method includes:
[0008] Obtain the feature information of a first response message; the feature information of the first response message includes: the five-tuple information of the first response message and the slot number of the first service board; the slot number of the first service board is the slot number of the service board corresponding to the first request message after hash splitting;
[0009] Create a message transfer board information table according to the feature information of the first response message; the message transfer board information table consists of the five-tuple information of at least one first response message and at least one first service board slot number;
[0010] Send the first request message to the resource server;
[0011] Receive the first response message sent by the resource server; the first response message carries target five-tuple information; the target five-tuple information is used to represent the five-tuple information of the first response message;
[0012] Query the message transfer board information table according to the target five-tuple information;
[0013] If the target five-tuple information hits the five-tuple information corresponding to any first response message in the message transfer board information table, then according to the table entry information corresponding to the message transfer board information table, transfer the first response message to the first service board for sending, so that both the first request message and the first response message are processed by the first service board.
[0014] As an optional implementation manner of the embodiments of the present disclosure, the obtaining the feature information of the first response message includes:
[0015] Receive the first tunnel message sent by the switching board;
[0016] Decrypt the first tunnel message to obtain the first service board slot number and the second service board slot number;
[0017] Judge whether the second service board slot number is consistent with the first service board slot number;
[0018] If the second service board slot number is not consistent with the first service board slot number, the first service board transfers and sends the first request message to the second service board;
[0019] The second service board receives the first request message, and the first request message carries the first service board slot number;
[0020] Obtain the five-tuple information of the first response message according to the five-tuple correspondence between the first request message and the first response message;
[0021] Determine the feature information of the first response message according to the five-tuple information of the first response message and the first service board slot number.
[0022] As an optional implementation manner of the embodiments of the present disclosure, before receiving the first tunnel message sent by the switching board, the method further includes:
[0023] The switching board receives a first tunnel message sent by a client; the first tunnel message carries an outer source IP, an outer destination IP, an inner source IP, and an inner destination IP;
[0024] Based on the outer source IP and the outer destination IP, the first tunnel message is sent to a first service board.
[0025] As an optional implementation manner of an embodiment of the present disclosure, decrypting the first tunnel message to obtain a first service board slot number and a second service board slot number includes:
[0026] Decrypting based on the first tunnel message to obtain an outer source IP, an outer destination IP, an inner source IP, an inner destination IP, an inner source port, an inner destination port, an inner transport protocol, and a first request message;
[0027] Performing hash-based traffic splitting according to the outer source IP and the outer destination IP to obtain a first service board slot number of the first request message;
[0028] Determine that the inner source IP is the first source IP of the first request message, the inner destination IP is the first destination IP of the first request message, the inner source port is the first source port, the inner destination port is the first destination port, and the inner transport protocol is the first transport protocol;
[0029] Based on the first source IP and the first destination IP, determine a second service board slot number; the second service board slot number is the service board slot number responsible for processing the first response message.
[0030] As an optional implementation manner of an embodiment of the present disclosure, the determining the second service board slot number based on the first source IP and the first destination IP includes:
[0031] Convert the first source IP and the first destination IP to obtain a second source IP and a second destination IP;
[0032] Performing hash-based traffic splitting according to the second source IP and the second destination IP to obtain a second service board slot number.
[0033] As an optional implementation manner of an embodiment of the present disclosure, after creating a message transfer board information table according to the characteristic information of the first response message, the method further includes:
[0034] Sending the first request message to a resource server through a second service board.
[0035] As an optional implementation manner of an embodiment of the present disclosure, the method further includes:
[0036] If the first service board slot number is the same as the second service board slot number, the first request message is sent to the resource server through the first service board.
[0037] In a second aspect, an embodiment of the present disclosure provides a message processing device, including:
[0038] A feature information acquisition module, configured to acquire feature information of a first response message; the feature information of the first response message includes: five-tuple information of the first response message and a first service board slot number; the first service board slot number is the service board slot number corresponding to the first request message after hash-based traffic splitting;
[0039] A transfer board information table creation module, configured to create a message transfer board information table according to the feature information of the first response message; the message transfer board information table is composed of at least one five-tuple information of the first response message and at least one first service board slot number;
[0040] A request message sending module, configured to send a first request message to the resource server;
[0041] A response message receiving module, configured to receive a first response message sent by the resource server; the first response message carries target five-tuple information; the target five-tuple information is used to represent the five-tuple information of the first response message;
[0042] A five-tuple information query module, configured to query the message transfer board information table according to the target five-tuple information;
[0043] A transfer board sending module, configured to, if the target five-tuple information hits the five-tuple information corresponding to any first response message in the message transfer board information table, transfer and send the first response message to the first service board according to the table entry information corresponding to the message transfer board information table, so that both the first request message and the first response message are processed by the first service board.
[0044] As an optional implementation manner of an embodiment of the present disclosure, the feature information acquisition module includes:
[0045] A tunnel message receiving unit, configured to receive a first tunnel message sent by a switching board;
[0046] A service board slot number acquisition unit, configured to decrypt the first tunnel message to obtain a first service board slot number and a second service board slot number;
[0047] A judgment unit, configured to judge whether the second service board slot number is the same as the first service board slot number;
[0048] A first sending unit, configured to, if the second service board slot number is inconsistent with the first service board slot number, the first service board forwards the first request message to the second service board by cross-board transmission;
[0049] A first receiving unit, configured to receive, by the second service board, the first request message, where the first request message carries the first service board slot number;
[0050] A five-tuple information obtaining unit, configured to obtain the five-tuple information of the first response message according to the five-tuple correspondence between the first request message and the first response message;
[0051] A feature information determining unit, configured to determine the feature information of the first response message according to the five-tuple information of the first response message and the first service board slot number.
[0052] As an optional implementation manner of an embodiment of the present disclosure, the apparatus further includes a tunnel message sending module, specifically configured to:
[0053] The switching board receives a first tunnel message sent by a client; the first tunnel message carries an outer source IP, an outer destination IP, an inner source IP, and an inner destination IP;
[0054] Based on the outer source IP and the outer destination IP, the first tunnel message is sent to the first service board.
[0055] As an optional implementation manner of an embodiment of the present disclosure, the service board slot number obtaining unit includes:
[0056] A tunnel message decryption unit, configured to decrypt based on the first tunnel message to obtain the outer source IP, the outer destination IP, the inner source IP, the inner destination IP, the inner source port, the inner destination port, the inner transport protocol, and the first request message;
[0057] A first service board slot number obtaining unit, configured to perform hash splitting according to the outer source IP and the outer destination IP to obtain the first service board slot number of the first request message;
[0058] A determining unit, configured to determine that the inner source IP is the first source IP of the first request message, the inner destination IP is the first destination IP of the first request message, the inner source port is the first source port, the inner destination port is the first destination port, and the inner transport protocol is the first transport protocol;
[0059] A second service board slot number obtaining unit, configured to determine a second service board slot number based on the first source IP and the first destination IP; the second service board slot number is the service board slot number responsible for processing the first response message.
[0060] As an alternative implementation manner of an embodiment of the present disclosure, the second service board slot number acquisition unit is specifically configured to:
[0061] Convert the first source IP and the first destination IP to obtain a second source IP and a second destination IP;
[0062] Perform hash splitting based on the second source IP and the second destination IP to obtain the second service board slot number.
[0063] As an alternative implementation manner of an embodiment of the present disclosure, the request message sending module is further configured to:
[0064] Send the first request message to the resource server through the second service board.
[0065] As an alternative implementation manner of an embodiment of the present disclosure, the apparatus further includes:
[0066] A second sending unit, configured to, if the first service board slot number is the same as the second service board slot number, send the first request message to the resource server through the first service board.
[0067] In a third aspect, an embodiment of the present disclosure provides an electronic device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the message processing method described in the first aspect or any implementation manner of the first aspect is implemented.
[0068] In a fourth aspect, an embodiment of the present disclosure provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the message processing method described in the first aspect or any implementation manner of the first aspect is implemented.
[0069] The message processing method provided by the embodiments of the present disclosure is applied to a network security device. First, the feature information of the first response message is obtained, then a message transfer board information table is created according to the feature information of the first response message, and then the first request message is sent to the resource server. The first response message sent by the resource server carries target five-tuple information. The message transfer board information table is queried according to the target five-tuple information. If the target five-tuple information hits the five-tuple information corresponding to any first response message in the message transfer board information table, the first response message is transferred and sent to the first service board according to the table entry information corresponding to the message transfer board information table, so that both the first request message and the first response message are processed by the first service board. Since the second service board has obtained the feature information of the first response message and established a message transfer board information table according to the feature information of the first response message before sending the first request message to the resource server, and the message transfer board information table includes the five-tuple information of multiple response messages and the slot number of the service board where the corresponding request message is located, when multiple service data are processed in a multi-core concurrent manner, it is possible to find the table entry information that is consistent with the five-tuple information of the response messages of each service data in the message transfer board information table according to the five-tuple information of the response messages of each service data, and then transfer and send each response message to the slot number of the service board where the corresponding request message is located according to the slot number of the service board where the request message corresponding to each response message is located, so that each response message and its corresponding request message are processed on the same service board, ensuring that in a large-traffic scenario, the creation of the message transfer board information table is completed before the response message reaches the destination service board, avoiding the packet loss phenomenon caused by timing problems in the case of multi-core concurrent processing of the service board, and further ensuring the integrity of the SSLVPN session. Brief Description of the Drawings
[0070] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present disclosure and used together with the specification to explain the principles of the present disclosure.
[0071] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0072] Figure 1 It is a schematic diagram of the application scenario of the message processing method in an embodiment;
[0073] Figure 2 It is a schematic diagram of the flow of the message processing method in an embodiment;
[0074] Figure 3 It is a schematic diagram of the structure of the message processing device in an embodiment;
[0075] Figure 4 A structural schematic diagram of the electronic device according to an embodiment of the present disclosure. Detailed implementation manners
[0076] In order to more clearly understand the above objects, features and advantages of the present disclosure, the solutions of the present disclosure will be further described below. It should be noted that, without conflict, the embodiments of the present disclosure and the features in the embodiments may be combined with each other.
[0077] Many specific details are set forth in the following description in order to fully understand the present disclosure, but the present disclosure may also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only a part of the embodiments of the present disclosure, rather than all of the embodiments.
[0078] The relational terms such as "first" and "second" in the description and claims of the present disclosure are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations.
[0079] In the embodiments of the present disclosure, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present disclosure should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner. In addition, in the description of the embodiments of the present disclosure, unless otherwise specified, the meaning of "a plurality" refers to two or more.
[0080] The present application provides a message processing method, which can be applied to an application environment as Figure 1 shown. Figure 1 FIG. is an application scenario diagram of the message processing method in an embodiment; the application environment includes a client 11, a network security device 12, and a resource server 13. Among them, the network security device 12 includes a switching board and at least two service boards ( Figure 1Taking N service boards as an example (shown in the figure). For example, the network security device 12 can be an SSL VPN server. Specifically, the second service board of the network security device obtains the feature information of the first response message; the feature information of the first response message includes: the five-tuple information of the first response message and the slot number of the first service board; the slot number of the first service board is the slot number of the service board corresponding to the first request message after being hashed and shunted; the second service board creates a message transfer board information table according to the feature information of the first response message; the message transfer board information table consists of at least one five-tuple information of the first response message and at least one slot number of the first service board; the second service board sends the first request message to the resource server; the second service board receives the first response message sent by the resource server; the first response message carries the target five-tuple information; the target five-tuple information is used to represent the five-tuple information of the first response message; the second service board queries the message transfer board information table according to the target five-tuple information; if the target five-tuple information hits the five-tuple information corresponding to any first response message in the message transfer board information table, the first response message is transferred and sent to the first service board according to the corresponding table entry information of the message transfer board information table, so that both the first request message and the first response message are processed by the first service board. Among them, the first request message can be an inner-layer forward message obtained by parsing the tunnel message, and the first response message can be a reverse message corresponding to the inner-layer forward message. Forward and reverse messages: Usually, the message sent from the client to the server is called a forward message; the message responded by the server is called a reverse message. Specifically, the forward message is obtained by decrypting the tunnel message, and the tunnel message contains two-layer IP feature information; the source IP of the outer layer refers to the IP of the actual physical network card, and the destination IP of the outer layer refers to the IP of the network security device; the source IP of the inner layer refers to the IP assigned by the virtual network card, and the destination IP of the inner layer refers to the IP of the resource server. The reverse message is a normal message, which only contains one-layer IP feature information; the reverse message corresponds to the forward message (only containing the inner-layer IP feature information) after the tunnel message is decrypted and unpacked.
[0081] In one embodiment, as Figure 2 shown, a message processing method is provided. In this embodiment, mainly taking the application of this method to a network security device as an example for illustration, the network security device includes a switching board and at least two service boards, and the method includes the following steps:
[0082] S21. Obtain the feature information of the first response message.
[0083] Among them, the feature information of the first response message includes: the five-tuple information of the first response message and the slot number of the first service board; the slot number of the first service board is the slot number of the service board corresponding to the first request message after being hashed and shunted.
[0084] Specifically, the second service board receives the first request message sent by the first service board. Based on the five-tuple relationship between the first request message and the first response message, it obtains the five-tuple information of the first response message and the slot number of the first service board. Among them, the five-tuple information of the first request message includes: the first source IP, the first destination IP, the first source port, the first destination port, and the transport protocol. Since the source IP and destination IP of the first request message and the first response message are opposite, the source port and destination port are opposite, and the transport protocol is the same. Therefore, the five-tuple information of the first response message can be obtained.
[0085] In addition, the slot number of the first service board is used to represent the slot number of the service board corresponding to the first request message after hash splitting. In this embodiment, hash splitting can be understood as calculating a hash value based on the input first source IP and first destination IP according to a certain calculation method. It should be noted that the slot number of the first service board can be the slot number of the service board corresponding to the calculated hash value according to a preset method. For example, when the hash value is aabbb, the slot number of the service board corresponding to the first service board is 01; when the hash value is vvhhh, the slot number of the service board corresponding to the first service board is 02.
[0086] S22. Create a message transfer board information table according to the characteristic information of the first response message.
[0087] Among them, the message transfer board information table is composed of at least the five-tuple information of one first response message and at least one slot number of the first service board.
[0088] Specifically, the message transfer board information table exists in the form of a linked list. The linked list contains multiple nodes, and each node stores one table entry information. For the sake of understanding, taking Table 1 as an example, the message transfer board information table may contain the content shown in Table 1. It should be noted that when processing services in a multi-core concurrent manner, Table 1 may contain more table entry information. This is only an example here, and no specific restrictions are imposed on the table entry information.
[0089] Table 1
[0090] Table entry Slot number of the first service board Five-tuple information of the response message 1 01 192.168.1.1, 121.14.88.76, 80, 1000, TCP 2 02 121.14.88.76, 192.168.1.1, 1000, 80, TCP 3 03 192.168.1.8, 124.13.82.71, 80, 1000, TCP
[0091] S23. Send the first request message to the resource server.
[0092] Among them, the first request message can be the inner-layer forward message obtained by parsing the tunnel message. The tunnel message contains two-layer IP characteristic information; the source IP of the outer layer refers to the IP of the actual physical network card, and the destination IP of the outer layer refers to the IP of the network security device; the source IP of the inner layer refers to the IP assigned by the virtual network card, and the destination IP of the inner layer refers to the IP of the resource server.
[0093] Optionally, the first request message is sent to the resource server through the second service board.
[0094] Specifically, after creating a message transfer board information table on the second service board according to the characteristic information of the first response message, the first request message is sent to the resource server.
[0095] S24. Receive the first response message sent by the resource server.
[0096] Among them, the first response message carries target five-tuple information; the target five-tuple information is used to represent the five-tuple information of the first response message.
[0097] Correspondingly, the second service board receives the first response message sent by the resource server. The first response message is a message corresponding to the first request message. The first request message is sent by the network security device to the resource server, and the first response message is returned by the resource server to the network security device.
[0098] S25. Query the message transfer board information table according to the target five-tuple information.
[0099] Exemplarily, if the target five-tuple information is: 192.168.1.8, 124.13.82.71, 80, 1000, TCP. Query whether the message transfer board information table contains the corresponding entry information of the message transfer board information table according to the target five-tuple information.
[0100] S26. If the target five-tuple information hits the five-tuple information corresponding to any first response message in the message transfer board information table, then according to the corresponding entry information of the message transfer board information table, the first response message is transferred and sent to the first service board, so that both the first request message and the first response message are processed by the first service board.
[0101] Exemplarily, referring to Table 1, the information corresponding to entry 3 in the message transfer board information table is: 192.168.1.8, 124.13.82.71, 80, 1000, TCP. It can be seen that entry 3 in Table 1 is consistent with the target five-tuple information, so the first response message is transferred and sent from the second service board to the first service board. The slot number of the first service board corresponding to the first service board is 03, so that both the first request message and the first response message are processed by the first service board with slot number 03.
[0102] In this embodiment, before sending the first request message to the resource server, the purpose of establishing the message transfer board information table is to avoid the timing problem that when the first service board sends the first request message to the resource server under multi-core concurrent processing of services, and the resource server has already sent the first response message to the second service board, but at this time the message transfer board information table has not been established, resulting in the inability to find the corresponding table entry information in the message transfer board information table according to the destination five-tuple information of the first response message, and unable to forward the first response message to the first service board where the first request message is located, and further unable to achieve the integrity of the SSLVPN session.
[0103] The message processing method provided by the embodiments of the present disclosure is applied to a network security device. First, obtain the feature information of the first response message, then create a message transfer board information table according to the feature information of the first response message, and then send the first request message to the resource server, receive the first response message sent by the resource server, the first response message carries destination five-tuple information, query the message transfer board information table according to the destination five-tuple information. If the destination five-tuple information hits the five-tuple information corresponding to any first response message in the message transfer board information table, then according to the corresponding table entry information of the message transfer board information table, transfer the first response message to the first service board, so that both the first request message and the first response message are processed by the first service board. Since before sending the first request message to the resource server, the second service board has already obtained the feature information of the first response message and established a message transfer board information table according to the feature information of the first response message, and the message transfer board information table includes the five-tuple information of multiple response messages and the slot number of the service board where the corresponding request message is located, so when multi-core concurrently processes multiple service data, it is possible to find the table entry information that is consistent with the five-tuple information of the response messages of each service data in the message transfer board information table, and then according to the slot number of the service board where the request message corresponding to each response message is located, transfer each response message to the slot number of the service board where the corresponding request message is located, so that each response message and its corresponding request message are processed on the same service board, ensuring that in a large-traffic scenario, the creation of the message transfer board information table is before the response message reaches the destination service board, avoiding the packet loss phenomenon caused by timing problems in the case of multi-core concurrent processing of service boards, and further ensuring the integrity of the SSLVPN session.
[0104] In some embodiments, the implementation manner of the above step S21 (obtain the feature information of the first response message) may include the following steps a-g:
[0105] a. Receive the first tunnel message sent by the switching board.
[0106] Among them, the first tunnel message includes: outer source IP, outer destination IP, inner source IP, inner destination IP.
[0107] b. Decrypt the first tunnel message to obtain the first service board slot number and the second service board slot number.
[0108] Optionally, the above step b (obtaining the first service board slot number of the first request message) can be implemented in the following manner:
[0109] b-1. Decrypt based on the first tunnel message to obtain the outer source IP, outer destination IP, inner source IP, inner destination IP, inner source port, inner destination port, inner transport protocol, and the first request message.
[0110] b-2. Perform hash-based traffic splitting according to the outer source IP and the outer destination IP to obtain the first service board slot number of the first request message.
[0111] b-3. Determine that the inner source IP is the first source IP of the first request message, the inner destination IP is the first destination IP of the first request message, the inner source port is the first source port, the inner destination port is the first destination port, and the inner transport protocol is the first transport protocol.
[0112] b-4. Determine the second service board slot number based on the first source IP and the first destination IP. Here, the second service board slot number is the slot number of the service board responsible for processing the first response message.
[0113] Optionally, step b-4 (determining the second service board slot number based on the first source IP and the first destination IP) can be implemented in the following manner:
[0114] Convert the second source IP and the second destination IP according to the first source IP and the first destination IP;
[0115] Perform hash-based traffic splitting according to the second source IP and the second destination IP to obtain the second service board slot number.
[0116] Specifically, the five-tuple information of the first request message includes: the first source IP, the first destination IP, the first source port, the first destination port, and the first transport protocol. The five-tuple information of the first response message includes: the second source IP, the second destination IP, the second source port, the second destination port, and the second transport protocol. Among them, the first source IP and the first destination IP are respectively opposite to the second source IP and the second destination IP, the first source port and the first destination port are respectively opposite to the second source port and the second destination port, and the first transport protocol is the same as the second transport protocol. Therefore, convert the second source IP and the second destination IP according to the first source IP and the first destination IP, and then perform hash-based traffic splitting according to the second source IP and the second destination IP to obtain the second service board slot number.
[0117] c. Determine whether the second service board slot number is the same as the first service board slot number.
[0118] d. If the second service board slot number is different from the first service board slot number, the first service board forwards the first request message to the second service board.
[0119] Exemplarily, assume that the first request message is hashed and shunted to the first service board with slot number 01, and the first response message is hashed and shunted to the second service board with slot number 02. Then, the first service board forwards the first request message to the second service board.
[0120] e. The second service board receives the first request message, and the first request message carries the first service board slot number.
[0121] Correspondingly, the second service board with slot number 02 receives the first request message sent by the first service board with slot number 01.
[0122] f. Obtain the five-tuple information of the first response message according to the five-tuple correspondence between the first request message and the first response message.
[0123] Specifically, since the first source IP and the first destination IP are respectively opposite to the second source IP and the second destination IP, the first source port and the first destination port are respectively opposite to the second source port and the second destination port, and the first transport protocol is the same as the second transport protocol. Therefore, after obtaining the five-tuple information of the first request message, the five-tuple information of the first response message can be further obtained.
[0124] g. Determine the characteristic information of the first response message according to the five-tuple information of the first response message and the first service board slot number.
[0125] Specifically, after obtaining the five-tuple information of the first response message and the first service board slot number, the characteristic information of the first response message can be determined.
[0126] In some embodiments, if the first service board slot number is the same as the second service board slot number, the first service board sends the first request message to the resource server.
[0127] Exemplarily, assume that the first request message is hashed and shunted to the first service board with slot number 01, and the first response message is also hashed and shunted to the first service board with slot number 01. Then, the first service board sends the first request to the resource server.
[0128] In some embodiments, before performing the above step a (receiving the first tunnel packet sent by the switching board), the following steps may also be performed:
[0129] ①. The switching board receives the first tunnel packet sent by the client.
[0130] Among them, the first tunnel packet carries the outer source IP, outer destination IP, inner source IP, and inner destination IP.
[0131] ②. Based on the outer source IP and the outer destination IP, the first tunnel packet is sent to the first service board.
[0132] Specifically, the switching board receives the first tunnel packet sent by the client and distributes the first tunnel packet to the first service board for processing.
[0133] The packet processing method provided by the embodiments of the present disclosure is applied to a network security device. First, the characteristic information of the first response packet is obtained, then a packet transfer board information table is created according to the characteristic information of the first response packet, and then the first request packet is sent to the resource server. The first response packet sent by the resource server carries the target five-tuple information. The packet transfer board information table is queried according to the target five-tuple information. If the target five-tuple information hits the five-tuple information corresponding to any first response packet in the packet transfer board information table, then according to the table entry information corresponding to the packet transfer board information table, the first response packet is transferred and sent to the first service board, so that both the first request packet and the first response packet are processed by the first service board. Since before the first request packet is sent to the resource server, the second service board has already obtained the characteristic information of the first response packet and established a packet transfer board information table according to the characteristic information of the first response packet, and the packet transfer board information table includes the five-tuple information of multiple response packets and the slot number of the service board where the corresponding request packet is located, so when multiple service data are processed in a multi-core concurrent manner, it is possible to find the table entry information that is consistent with the five-tuple information of the response packets of each service data in the packet transfer board information table according to the five-tuple information of the response packets of each service data, and then according to the slot number of the service board where the request packet corresponding to each response packet is located, transfer and send each response packet to the slot number of the service board where the corresponding request packet is located, so that each response packet and its corresponding request packet are processed on the same service board, ensuring that in a large-traffic scenario, the creation of the packet transfer board information table is before the response packet reaches the destination service board, avoiding the packet loss phenomenon caused by timing problems in the case of multi-core concurrent processing of the service board, and thus ensuring the integrity of the SSLVPN session.
[0134] In one embodiment, as Figure 3 shown, a packet processing apparatus 300 is provided, including:
[0135] A feature information acquisition module 310 is configured to acquire the feature information of the first response message; the feature information of the first response message includes: the five-tuple information of the first response message and the first service board slot number; the first service board slot number is the service board slot number corresponding to the first request message after hash-based traffic splitting.
[0136] A transfer board information table creation module 320 is configured to create a message transfer board information table according to the feature information of the first response message; the message transfer board information table is composed of at least one five-tuple information of the first response message and at least one first service board slot number.
[0137] A request message sending module 330 is configured to send the first request message to the resource server.
[0138] A response message receiving module 340 is configured to receive the first response message sent by the resource server; the first response message carries target five-tuple information; the target five-tuple information is used to represent the five-tuple information of the first response message.
[0139] A five-tuple information query module 350 is configured to query the message transfer board information table according to the target five-tuple information.
[0140] A transfer board sending module 360 is configured to, if the target five-tuple information hits the five-tuple information corresponding to any first response message in the message transfer board information table, transfer and send the first response message to the first service board according to the table entry information corresponding to the message transfer board information table, so that both the first request message and the first response message are processed by the first service board.
[0141] As an optional implementation manner of the embodiment of the present disclosure, the feature information acquisition module 310 includes:
[0142] A tunnel message receiving unit is configured to receive a first tunnel message sent by the switching board.
[0143] A service board slot number acquisition unit is configured to decrypt the first tunnel message to obtain the first service board slot number and the second service board slot number.
[0144] A judgment unit is configured to judge whether the second service board slot number is the same as the first service board slot number.
[0145] A first sending unit is configured to, if the second service board slot number is different from the first service board slot number, the first service board transfers and sends the first request message to the second service board.
[0146] A first receiving unit is configured to receive the first request message by the second service board, and the first request message carries the first service board slot number.
[0147] A five - tuple information acquisition unit, configured to acquire the five - tuple information of the first response message according to the five - tuple correspondence between the first request message and the first response message;
[0148] A feature information determination unit, configured to determine the feature information of the first response message according to the five - tuple information of the first response message and the first service board slot number.
[0149] As an optional implementation manner of an embodiment of the present disclosure, the device further includes a tunnel message sending module, which is specifically configured to:
[0150] The switching board receives a first tunnel message sent by a client; the first tunnel message carries an outer - layer source IP, an outer - layer destination IP, an inner - layer source IP, and an inner - layer destination IP;
[0151] Send the first tunnel message to the first service board based on the outer - layer source IP and the outer - layer destination IP.
[0152] As an optional implementation manner of an embodiment of the present disclosure, the service board slot number acquisition unit includes:
[0153] A tunnel message decryption unit, configured to decrypt based on the first tunnel message to obtain the outer - layer source IP, the outer - layer destination IP, the inner - layer source IP, the inner - layer destination IP, the inner - layer source port, the inner - layer destination port, the inner - layer transport protocol, and the first request message;
[0154] A first service board slot number acquisition unit, configured to perform hash - based traffic splitting according to the outer - layer source IP and the outer - layer destination IP to obtain the first service board slot number of the first request message;
[0155] A determination unit, configured to determine that the inner - layer source IP is the first source IP of the first request message, the inner - layer destination IP is the first destination IP of the first request message, the inner - layer source port is the first source port, the inner - layer destination port is the first destination port, and the inner - layer transport protocol is the first transport protocol;
[0156] A second service board slot number acquisition unit, configured to determine a second service board slot number based on the first source IP and the first destination IP; the second service board slot number is the service board slot number responsible for processing the first response message.
[0157] As an optional implementation manner of an embodiment of the present disclosure, the second service board slot number acquisition unit is specifically configured to:
[0158] Convert the first source IP and the first destination IP to obtain a second source IP and a second destination IP;
[0159] Perform hash-based traffic splitting according to the second source IP and the second destination IP to obtain the second service board slot number.
[0160] As an optional implementation manner of the embodiments of the present disclosure, the request message sending module 330 is further configured to:
[0161] Send the first request message to the resource server through the second service board.
[0162] As an optional implementation manner of the embodiments of the present disclosure, the apparatus further includes:
[0163] A second sending unit, configured to, if the first service board slot number is the same as the second service board slot number, send the first request message to the resource server through the first service board.
[0164] The message processing apparatus provided by the embodiments of the present disclosure is applied to a network security device. First, obtain the feature information of the first response message, then create a message transfer board information table according to the feature information of the first response message, and then send the first request message to the resource server, receive the first response message sent by the resource server, where the first response message carries target five-tuple information. Query the message transfer board information table according to the target five-tuple information. If the target five-tuple information hits the five-tuple information corresponding to any first response message in the message transfer board information table, then according to the table entry information corresponding to the message transfer board information table, transfer and send the first response message to the first service board, so that both the first request message and the first response message are processed by the first service board. Since before sending the first request message to the resource server, the second service board has already obtained the feature information of the first response message and established a message transfer board information table according to the feature information of the first response message, and the message transfer board information table includes the five-tuple information of multiple response messages and the service board slot numbers where the corresponding request messages are located, so when multiple service data are processed in a multi-core concurrent manner, it is possible to find the table entry information that is the same as the five-tuple information of the response messages of each service data in the message transfer board information table, and then according to the service board slot numbers where the request messages corresponding to each response message are located, transfer and send each response message to the corresponding service board slot number, so that each response message and its corresponding request message are processed on the same service board, ensuring that in a large-traffic scenario, the creation of the message transfer board information table is before the response message reaches the destination service board, avoiding packet loss phenomena caused by timing problems in the case of multi-core concurrent processing of service boards, and further ensuring the integrity of the SSLVPN session.
[0165] The embodiments of the present disclosure further provide an electronic device, Figure 4 which is a schematic structural diagram of the electronic device provided by the embodiments of the present disclosure. As Figure 4As shown in the figure, the electronic device provided in this embodiment includes: a memory 41 and a processor 42. The memory 41 is used to store a computer program. The processor 42 is used to execute the steps in the packet processing method provided in the above method embodiment when calling the computer program.
[0166] The embodiment of the present disclosure further provides a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, the steps in the packet processing method provided in the above method embodiment are implemented.
[0167] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects.
[0168] The processor can be a Central Processing Unit (CPU), or can also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc.
[0169] The memory may include non-permanent memory in the computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0170] Computer-readable media include both permanent and non-permanent, removable and non-removable storage media. The storage media can implement information storage by any method or technology, and the information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information accessible by a computing device. As defined herein, computer-readable media do not include transitory media such as modulated data signals and carrier waves.
[0171] It should be noted that, in this document, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the said element.
[0172] The above are only specific embodiments of the present disclosure, enabling those skilled in the art to understand or implement the present disclosure. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present disclosure. Therefore, the present disclosure will not be limited to these embodiments described herein, but rather will conform to the broadest scope consistent with the principles and novel features disclosed herein.
Claims
1. A message processing method, characterized in that, it is applied to a network security device, and the network security device includes: a switching board and at least two service boards, and the method includes: Obtain the feature information of the first response message; the feature information of the first response message includes: the five-tuple information of the first response message and the first service board slot number; the first service board slot number is the service board slot number corresponding to the first request message after being hashed and shunted; the first request message is a message sent by the network security device to the resource server, and the first response message is a message returned by the resource server to the network security device; Create a message transfer board information table according to the feature information of the first response message; the message transfer board information table is composed of the five-tuple information of at least one first response message and at least one first service board slot number; Send the first request message to the resource server; Receive the first response message sent by the resource server; the first response message carries target five-tuple information; the target five-tuple information is used to represent the five-tuple information of the first response message; Query the message transfer board information table according to the target five-tuple information; If the target five-tuple information hits the five-tuple information corresponding to any first response message in the message transfer board information table, then according to the table item information corresponding to the message transfer board information table, transfer the first response message to the first service board, so that both the first request message and the first response message are processed by the first service board; The obtaining of the feature information of the first response message includes: Receive the first tunnel message sent by the switching board; Decrypt the first tunnel message to obtain the first service board slot number and the second service board slot number; Judge whether the second service board slot number is the same as the first service board slot number; If the second service board slot number is different from the first service board slot number, the first service board transfers the first request message to the second service board; The second service board receives the first request message, and the first request message carries the first service board slot number; Obtain the five-tuple information of the first response message according to the five-tuple correspondence between the first request message and the first response message; Determine the feature information of the first response message according to the five-tuple information of the first response message and the first service board slot number.
2. The method according to claim 1, characterized in that, before receiving the first tunnel message sent by the switching board, the method further includes: The switching board receives the first tunnel message sent by the client; the first tunnel message carries the outer layer source IP, the outer layer destination IP, the inner layer source IP, and the inner layer destination IP; Send the first tunnel message to the first service board based on the outer layer source IP and the outer layer destination IP.
3. The method according to claim 1, characterized in that, the decrypting the first tunnel message to obtain the first service board slot number and the second service board slot number includes: Decrypt based on the first tunnel message to obtain the outer source IP, outer destination IP, inner source IP, inner destination IP, inner source port, inner destination port, inner transport protocol, and the first request message; Perform hash-based traffic splitting according to the outer source IP and the outer destination IP to obtain the first service board slot number of the first request message; Determine that the inner source IP is the first source IP of the first request message, the inner destination IP is the first destination IP of the first request message, the inner source port is the first source port, the inner destination port is the first destination port, and the inner transport protocol is the first transport protocol; Determine the second service board slot number based on the first source IP and the first destination IP; the second service board slot number is the service board slot number responsible for processing the first response message.
4. The method according to claim 3, wherein, the determining the second service board slot number based on the first source IP and the first destination IP includes: Converting the first source IP and the first destination IP to obtain a second source IP and a second destination IP; Perform hash-based traffic splitting according to the second source IP and the second destination IP to obtain the second service board slot number.
5. The method according to claim 1, wherein, after creating the message transfer board information table according to the characteristic information of the first response message, the method further includes: Sending the first request message to the resource server through the second service board.
6. The method according to claim 1, wherein, the method further includes: If the first service board slot number is the same as the second service board slot number, send the first request message to the resource server through the first service board.
7. A message processing device, wherein, comprises: A characteristic information acquisition module for acquiring the characteristic information of the first response message; The characteristic information of the first response message includes: the five-tuple information of the first response message and the first service board slot number; the first service board slot number is the service board slot number corresponding to the first request message after hash-based traffic splitting; A transfer board information table creation module for creating a message transfer board information table according to the characteristic information of the first response message; the message transfer board information table is composed of at least one five-tuple information of the first response message and at least one first service board slot number; A request message sending module for sending the first request message to the resource server; A response message receiving module for receiving the first response message sent by the resource server; the first response message carries target five-tuple information; the target five-tuple information is used to represent the five-tuple information of the first response message; A five-tuple information query module for querying the message transfer board information table according to the target five-tuple information; The transfer board sending module is used to, if the target quintuple information hits the quintuple information corresponding to any first response message in the message transfer board information table, transfer and send the first response message to the first service board according to the entry information corresponding to the message transfer board information table, so that both the first request message and the first response message are processed by the first service board; The feature information acquisition module is specifically used for: Receiving a first tunnel message sent by the switching board; Decrypting the first tunnel message to obtain the slot number of the first service board and the slot number of the second service board; Judging whether the slot number of the second service board is the same as the slot number of the first service board; If the slot number of the second service board is different from the slot number of the first service board, the first service board transfers and sends the first request message to the second service board; The second service board receives the first request message, and the first request message carries the slot number of the first service board; Obtaining the quintuple information of the first response message according to the quintuple correspondence between the first request message and the first response message; Determining the feature information of the first response message according to the quintuple information of the first response message and the slot number of the first service board.
8. An electronic device, including a memory and a processor, where the memory stores a computer program, characterized in that, When the processor executes the computer program, the message processing method according to any one of claims 1 to 6 is implemented.
9. A computer-readable storage medium, characterized in that, A computer program is stored thereon, and when the computer program is executed by a processor, the message processing method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Message forwarding processing method and device
CN115277213A