Stream information completion method and device, cloud host device and computer storage medium
By obtaining and analyzing the data flow information uploaded by the traffic acquisition device, and finding and adding the identification and attribute information of the peer virtual machine, the problem of inaccurate acquisition of virtual machine identification in the cloud environment is solved, and the completion of flow information and network analysis support is achieved.
Patent Information
- Application Number
- CN202110688835.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-06-25
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2041-06-25
AI Technical Summary
The existing technology cannot accurately obtain the virtual machine ID in a cloud environment, resulting in the inability to obtain the source and destination addresses of the peer cloud host, affecting network analysis.
By obtaining the data flow information uploaded by the traffic acquisition device, a first virtual machine identity is obtained, and a second virtual machine identity corresponding to the first virtual machine identity is found based on the address information in the data flow information, and a virtual machine attribute information corresponding to the second virtual machine identity is added to the data flow information.
It realizes the completion of flow information without knowing the virtual cloud topology, solves the problem of inaccurate acquisition of virtual machine identification, and promotes network analysis.
Smart Images

Figure CN115529245B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to a stream information completion method and device, a cloud host device, and a computer storage medium. Background Art
[0002] In a cloud environment, especially in a multi-VPC (Virtual Private Cloud) scenario, private IP addresses are often used for networking. This solution relies on knowing the connection relationship between VPC topologies, which may not be available in many cases. At the same time, the same private IP address is used by multiple different cloud hosts, and the private IP address can no longer be used as a unique identifier for the cloud host. Therefore, the prior art uses VM ID (Virtual Machine Identifier) as the unique identifier of the host. When performing IPFIX (IP Flow Information Export Protocol) sampling, the source address and destination address of the network flow are used in combination with the 5-tuple information to determine a unique network flow. However, the prior art has the disadvantage that on the same network flow, each IPFIX sampling point can only obtain the source address and destination address of the cloud host directly connected to the sampling point, but cannot obtain the source address and destination address of the opposite cloud host, which affects subsequent network analysis. Summary of the invention
[0003] The main purpose of the present invention is to provide a flow information completion method and device, a cloud host device and a computer storage medium, aiming to solve the problem that the virtual machine identifier cannot be accurately obtained in the prior art.
[0004] To achieve the above object, the present invention provides a flow information completion method. In one embodiment, the flow information completion method includes the following steps:
[0005] Obtaining data flow information uploaded by a traffic collection device, and obtaining a first virtual machine identifier in the data flow information;
[0006] Acquire a second virtual machine identifier corresponding to the first virtual machine identifier according to address information in the data flow information, wherein the data flow information includes communication data between a virtual machine corresponding to the first virtual machine identifier and a virtual machine corresponding to the second virtual machine identifier;
[0007] Add the attribute information of the virtual machine corresponding to the second virtual machine identifier to the data flow information.
[0008] In one embodiment, the step of acquiring the second virtual machine identifier corresponding to the first virtual machine identifier according to the address information in the data flow information includes:
[0009] Obtaining a virtual cloud identifier of a virtual cloud where the virtual machine corresponding to the first virtual machine identifier is located;
[0010] The second virtual machine identifier is searched in the virtual cloud according to the address information and the virtual cloud identifier.
[0011] In one embodiment, after obtaining the virtual cloud identifier of the virtual cloud where the virtual machine corresponding to the first virtual machine identifier is located, the method includes:
[0012] If the second virtual machine identifier cannot be found in the virtual cloud, determining whether the virtual machine uses an elastic address;
[0013] If the virtual machine uses an elastic address, the attribute information of the virtual machine corresponding to the elastic address is added to the data flow information.
[0014] In one embodiment, after the step of determining whether the virtual machine uses an elastic address if the second virtual machine identifier cannot be found in the virtual cloud, the method further includes:
[0015] If the virtual machine does not use the elastic address, then obtaining configuration parameters of the current data flow information;
[0016] Searching for matching preset data stream information according to the configuration parameters;
[0017] The virtual machine identifier corresponding to the pre-stored data flow information is used as the second virtual machine identifier of the data flow information.
[0018] In one embodiment, the configuration parameters of the data flow information include at least: a quintuple, number of bytes, number of packets and flow direction; the quintuple includes at least: source address, destination address, source port number, destination port number and protocol type.
[0019] In one embodiment, if the virtual machine does not use the elastic address, the steps include:
[0020] If the corresponding preset data flow information is not matched within the preset time, the data flow information is recorded in the behavior log.
[0021] In one embodiment, the attribute information includes at least one of security group information and a tenant identifier.
[0022] To achieve the above object, the present invention further provides a stream information completion device, the device comprising:
[0023] an acquisition module, configured to acquire data flow information uploaded by a traffic collection device, acquire a first virtual machine identifier in the data flow information, and acquire a second virtual machine identifier corresponding to the first virtual machine identifier according to address information in the data flow information, wherein the data flow information includes communication data between a virtual machine corresponding to the first virtual machine identifier and a virtual machine corresponding to the second virtual machine identifier;
[0024] A data stream completion module is used to add attribute information of the virtual machine corresponding to the second virtual machine identifier to the data stream information.
[0025] To achieve the above-mentioned purpose, the present invention also provides a cloud host device, which includes a memory, a processor, and a flow information completion program stored in the memory and executable on the processor, and the flow information completion program implements the various steps of the flow information completion method described above when executed by the processor.
[0026] To achieve the above object, the present invention further provides a computer storage medium, wherein the computer storage medium stores a flow information completion program, and when the flow information completion program is executed by a processor, the various steps of the flow information completion method described above are implemented.
[0027] The flow information completion method and device, cloud host device and computer storage medium provided by the present invention have at least the following technical effects:
[0028] By adopting a technical solution of obtaining data flow information uploaded by a traffic collection device, obtaining a first virtual machine identifier in the data flow information, obtaining a second virtual machine identifier corresponding to the first virtual machine identifier according to address information in the data flow information, and adding attribute information of the virtual machine corresponding to the second virtual machine identifier to the data flow information, the problem of being unable to accurately obtain virtual machine identifiers in the prior art is solved, and completing data flow information is conducive to network analysis. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] Figure 1 A schematic diagram of a cloud host device architecture according to an embodiment of the present invention;
[0030] Figure 2 It is a flowchart of a first embodiment of a method for completing stream information of the present invention;
[0031] Figure 3 This is a detailed flow chart of step S120 in the second embodiment of the flow information completion method of the present invention;
[0032] Figure 4 It is a flowchart of a third embodiment of the method for completing stream information of the present invention;
[0033] Figure 5 Schematic diagram of a flow chart of a fourth embodiment of a method for completing stream information of the present invention;
[0034] Figure 6 It is a schematic diagram of the flow information collection device of the present invention;
[0035] Figure 7 This is a schematic diagram of the virtual cloud topology structure of the present invention;
[0036] Figure 8 Schematic diagram of the flow of the flow information completion method of the present invention;
[0037] The realization of the purpose, functional features and advantages of the present invention will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0038] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.
[0039] In order to solve the problem that the virtual machine identifier cannot be accurately obtained in the prior art, the present application adopts the method of obtaining data flow information uploaded by a traffic collection device, and obtaining a first virtual machine identifier in the data flow information; obtaining a second virtual machine identifier corresponding to the first virtual machine identifier according to address information in the data flow information, wherein the data flow information includes communication data between a virtual machine corresponding to the first virtual machine identifier and a virtual machine corresponding to the second virtual machine identifier; and adding attribute information of the virtual machine corresponding to the second virtual machine identifier to the data flow information. The technical solution is conducive to network analysis.
[0040] In order to better understand the above technical solution, exemplary embodiments of the present application will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present application are shown in the accompanying drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments described herein. On the contrary, these embodiments are provided to enable a more thorough understanding of the present application and to fully convey the scope of the present application to those skilled in the art.
[0041] like Figure 1 As shown, Figure 1 It is a schematic diagram of the structure of the hardware operating environment involved in the embodiment of the present invention.
[0042] It should be noted that Figure 1 This is a schematic diagram of the architecture of the hardware operating environment of the cloud host device.
[0043] like Figure 1As shown, the cloud host device may include: a processor 1001, such as a CPU, a memory 1005, a user interface 1003, a network interface 1004, and a communication bus 1002. Among them, the communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen (Display), an input unit such as a keyboard (Keyboard), and the optional user interface 1003 may also include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 1005 may be a high-speed RAM memory, or a stable memory (non-volatile memory), such as a disk memory. The memory 1005 may also be a storage device independent of the aforementioned processor 1001.
[0044] Those skilled in the art will understand that Figure 1 The cloud host device structure shown does not constitute a limitation on the cloud host device. The cloud host device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0045] like Figure 1 As shown, the memory 1005 as a computer storage medium may include an operating system, a network communication module, a user interface module, and a flow information completion program. Among them, the operating system is a program that manages and controls the hardware and software resources of the cloud host device, and the flow information completion program and other software or programs are running.
[0046] exist Figure 1 In the cloud host device shown, the user interface 1003 is mainly used to connect to the terminal and communicate data with the terminal; the network interface 1004 is mainly used for the background server and communicates data with the background server; the processor 1001 can be used to call the flow information completion program stored in the memory 1005.
[0047] In this embodiment, the cloud host device includes: a memory 1005, a processor 1001, and a flow information completion program stored in the memory and executable on the processor, wherein:
[0048] In the embodiment of the present application, the processor 1001 may be used to call the stream information completion program stored in the memory 1005 and perform the following operations:
[0049] Obtaining data flow information uploaded by a traffic collection device, and obtaining a first virtual machine identifier in the data flow information;
[0050] Acquire a second virtual machine identifier corresponding to the first virtual machine identifier according to address information in the data flow information, wherein the data flow information includes communication data between a virtual machine corresponding to the first virtual machine identifier and a virtual machine corresponding to the second virtual machine identifier;
[0051] Add the attribute information of the virtual machine corresponding to the second virtual machine identifier to the data flow information.
[0052] In the embodiment of the present application, the processor 1001 may be used to call the stream information completion program stored in the memory 1005 and perform the following operations:
[0053] Obtaining a virtual cloud identifier of a virtual cloud where the virtual machine corresponding to the first virtual machine identifier is located;
[0054] The second virtual machine identifier is searched in the virtual cloud according to the address information and the virtual cloud identifier.
[0055] In the embodiment of the present application, the processor 1001 may be used to call the stream information completion program stored in the memory 1005 and perform the following operations:
[0056] If the second virtual machine identifier cannot be found in the virtual cloud, determining whether the virtual machine uses an elastic address;
[0057] If the virtual machine uses an elastic address, the attribute information of the virtual machine corresponding to the elastic address is added to the data flow information.
[0058] In the embodiment of the present application, the processor 1001 may be used to call the stream information completion program stored in the memory 1005 and perform the following operations:
[0059] If the virtual machine does not use the elastic address, then obtaining configuration parameters of the current data flow information;
[0060] Searching for matching preset data stream information according to the configuration parameters;
[0061] The virtual machine identifier corresponding to the pre-stored data flow information is used as the second virtual machine identifier of the data flow information.
[0062] In the embodiment of the present application, the processor 1001 may be used to call the stream information completion program stored in the memory 1005 and perform the following operations:
[0063] If the corresponding preset data flow information is not matched within the preset time, the data flow information is recorded in the behavior log.
[0064] Since the cloud host device provided in the embodiment of the present application is a cloud host device used to implement the method of the embodiment of the present application, based on the method introduced in the embodiment of the present application, the person skilled in the art can understand the specific structure and deformation of the cloud host device, so it is not repeated here. All cloud host devices used in the method of the embodiment of the present application belong to the scope of protection of this application. The serial number of the above-mentioned embodiment of the present invention is only for description and does not represent the advantages and disadvantages of the embodiment.
[0065] like Figure 6 As shown, Figure 6 This is a schematic diagram of the flow information collection device of the present invention. In addition to the cloud host device, the flow information collection device also includes a router, an IPFIX flow information collector, a message middleware, a correlation analysis engine, a database, a network flow analysis platform, and a platform controller. The IPFIX flow collection device, such as a switch, uploads the IPFIX flow information to the IPFIX flow collector, and the collector transmits the information to the message middleware after parsing the information. The correlation analysis engine continuously obtains the flow information from the message middleware, performs correlation analysis operations, completes the network flow information, and then stores the results of the correlation analysis in the database for analysis by the network flow analysis platform. When performing the correlation analysis, the correlation analysis engine also needs to obtain some tenant identification, security group information and other information from the platform controller to complete the flow information.
[0066] The router is a layer 3 router. Different virtual clouds can communicate with each other using a virtual cloud router or a virtual private network to obtain other dedicated lines. When communicating through a virtual cloud router, the two virtual clouds generally belong to different network segments. Figure 7 As shown, Figure 7 is a schematic diagram of the virtual cloud topology structure of the present invention, Figure 7 The network segments of VPC 1 and VPC 3 shown in the figure are 192.168.1.0 / 24 and 192.168.3.0 / 24 respectively. When connected through a virtual private network or a similar dedicated line, the two virtual clouds generally belong to the same network segment, such as Figure 7 VPC 1 and VPC 2 shown in the figure both belong to the 192.168.1.0 / 24 network segment;
[0067] The IPFIX in the IPFIX flow information collector is a standard flow information export protocol developed based on Netflow v9 and launched by IETF. The IPFIX flow information collector collects and processes data flow information based on the standard IPFIX protocol. Each flow collection device only obtains the data flow information of the virtual machine connected to it, for example, Figure 6The schematic diagram of the flow information collection device shown includes two flow collection devices, each of which is connected to a virtual machine through an interface to collect data flow information sent by the virtual machine. The types of these flow collection devices can be software switches or hardware switches, or routers, firewalls, etc. If the types of flow collection devices are different, the connection methods of the flow collection devices and the virtual machines are also different;
[0068] The correlation analysis engine is used to correlate the data flow information collected by different flow collection devices to obtain complete data flow information;
[0069] The platform controller can obtain other information about network nodes in the virtual cloud, such as tenant identification, security group information, IP address of the virtual machine, virtual machine identification, and the subordinate relationship between the virtual machine and the tenant.
[0070] For software implementation, the technology described in the embodiments of the present invention can be implemented by a module (such as a process, function, etc.) that performs the functions described in the embodiments of the present invention. The software code can be stored in a memory and executed by a processor. The memory can be implemented in the processor or outside the processor.
[0071] Based on the above structure, an embodiment of the present invention is proposed, wherein: Figure 8 The flow diagram of the flow information completion method of the present invention is divided into 6 modules, wherein module 1 is a process of completing the destination virtual machine identification and other information when the source virtual machine identification is known, and module 6 is a process of completing the source virtual machine identification and other information when the destination virtual machine identification information is known. The functions of module 6 and module 1 are comparable, so they are not described in detail, and modules 2, 3, 4, and 5 are refinements of module 1.
[0072] Generally, the source virtual machine identifier and the destination virtual machine identifier are determined according to the flow direction of the streaming data flow. If there are two virtual machines, namely the first virtual machine and the second virtual machine, assuming that the flow direction of the data flow is from the first virtual machine to the second virtual machine, the flow direction of the data flow is defined as forward. At this time, the virtual machine identifier corresponding to the first virtual machine is the source virtual machine identifier, and the virtual machine identifier corresponding to the second virtual machine is the destination virtual machine identifier; conversely, assuming that the flow direction of the data flow is from the second virtual machine to the first virtual machine, the flow direction of the data flow is defined as reverse. At this time, the virtual machine identifier corresponding to the first virtual machine is the destination virtual machine identifier, and the virtual machine identifier corresponding to the second virtual machine is the source virtual machine identifier.
[0073] Reference Figure 2 , Figure 2 The flowchart of the first embodiment of the flow information completion method of the present invention includes the following steps:
[0074] Step S110, obtaining data flow information uploaded by the traffic collection device, and obtaining the first virtual machine identifier in the data flow information.
[0075] In this embodiment, in the same virtual cloud network, there are multiple virtual machines, and every two virtual machines are associated through complete flow entries. In this process, the traffic collection device is used to collect data flow information output by the virtual machines connected to it, and send the collected data flow information to the flow information collector and the association analysis engine to associate the data flow information. At the same time, the association analysis engine also obtains tenant identification, security group information and other information from the platform controller to improve the flow information, thereby forming a complete flow entry. Because there are multiple virtual machines and a flow entry is generated correspondingly between the virtual machines, a list containing all flow entry information of the same virtual cloud network is formed, such as Figure 7 As shown, in the virtual cloud VPC1, the flow entry information list formed is shown in the following table:
[0076]
[0077] In this embodiment, the data flow information is also called network flow information. The data flow information includes not only the identification of the virtual machine, but also the traditional 5-tuple information, the start time of the data flow, the end time of the data flow, the port where the data flow enters the collector, the port where the data flow leaves the collector, the reason for the end of the data flow, the maximum lifetime of the data flow, the flow direction of the data flow, the number of bytes and data packets within the collection time period, etc.; the first virtual machine identification is used to uniquely identify a virtual machine in a network domain, and is generally represented by UUID. The UUID (Universally Unique Identifier) is a 128-bit identifier used in a computer system to identify the number of information. It is generated according to a standard method and does not rely on registration and allocation by a central agency. The UUID is unique.
[0078] Step S120: Acquire a second virtual machine identifier corresponding to the first virtual machine identifier according to the address information in the data flow information.
[0079] In this embodiment, the data flow information includes communication data between a virtual machine corresponding to a first virtual machine identifier and a virtual machine corresponding to a second virtual machine identifier. The second virtual machine identifier is opposite to the first virtual machine identifier. The first virtual machine identifier and the second virtual machine identifier can be source virtual machine identifiers or destination virtual machine identifiers. When the first virtual machine identifier is the source virtual machine identifier, the second virtual machine identifier is the destination virtual machine identifier. Conversely, when the first virtual machine identifier is the destination virtual machine identifier, the second virtual machine identifier is the source virtual machine identifier. That is, the first virtual machine identifier and the second virtual machine identifier cannot be the source virtual machine identifier or the destination virtual machine identifier at the same time. This application takes the first virtual machine identifier as the source virtual machine identifier and the second virtual machine identifier as the destination virtual machine identifier as an example to discuss data flow information completion. When the first virtual machine identifier is the destination virtual machine identifier and the second virtual machine identifier is the source virtual machine identifier, the principle of data flow information completion is the same as the former, and will not be repeated here.
[0080] In this embodiment, virtual machine address reuse is allowed in different virtual cloud scenarios, but in the same virtual cloud scenario, if virtual machine address reuse will cause virtual machine address conflict, the data flow information of the first virtual machine collected and uploaded by the traffic collection device is used, and the first virtual machine identifier in the data flow information is obtained by parsing the data flow information. When the first virtual machine identifier is known, since the virtual machine identifier corresponding to each virtual machine in the same virtual cloud scenario is unique, the virtual cloud identifier in the virtual cloud scenario can be reversely checked through the platform controller. In the same virtual cloud scenario, the tenant identifier, the address of the second virtual machine, and the virtual cloud identifier are used as matching conditions to query the second virtual machine identifier. If the matching condition exists in the flow entry information list described in step S110, the virtual machine identifier found is the second virtual machine identifier, and it indicates that the second virtual machine identifier and the first virtual machine identifier belong to the same virtual cloud scenario.
[0081] Step S130: Add the attribute information of the virtual machine corresponding to the second virtual machine identifier to the data flow information.
[0082] In this embodiment, by querying the flow entry information list described in step S110, the attribute information of the virtual machine corresponding to the second virtual machine identifier can be obtained, and finally the attribute information is added to the data flow information and stored in the database to complete the flow entry.
[0083] By obtaining the data flow information uploaded by the traffic collection device and obtaining the first virtual machine identifier in the data flow information, searching the flow entry information list for the second virtual machine identifier corresponding to the matching first virtual machine identifier according to the address information in the data flow information, and proving that the first virtual machine identifier and the second virtual machine identifier belong to the same virtual cloud scenario, the attribute information of the virtual machine corresponding to the second virtual machine identifier is added to the data flow information, thereby achieving completion of the flow information without knowing the virtual cloud topology structure.
[0084] Reference Figure 3 , Figure 3 This is a detailed flow chart of step S120 in the second embodiment of the flow information completion method of the present invention. In this embodiment, step S120 in the first embodiment includes:
[0085] Step S121, obtaining the virtual cloud identifier of the virtual cloud where the virtual machine corresponding to the first virtual machine identifier is located.
[0086] In this embodiment, the virtual machine is located in a virtual cloud. When the first virtual machine identifier is known, the virtual machine corresponding to the first virtual machine identifier is obtained, and the virtual cloud scene where the virtual machine is located is determined, thereby obtaining the virtual cloud identifier corresponding to the virtual cloud scene. The virtual cloud builds an isolated virtual network environment for the virtual machine that is independently configured and managed by the user. The user can freely configure sub-services such as address segments, subnets, and security groups in the virtual cloud; Figure 8 As shown in module 2, a network flow information is obtained, the direction of the network flow is checked, and the network flow information is collected through a flow information collector. When the source virtual machine identifier is known, the virtual cloud identifier of the virtual cloud can be reversed through the platform controller due to the uniqueness of the source virtual machine identifier.
[0087] Step S122: searching the virtual cloud for the second virtual machine identifier according to the address information and the virtual cloud identifier.
[0088] In this embodiment, within the same virtual cloud scenario, the tenant identifier, destination address, and virtual cloud identifier are used as matching conditions to query the destination virtual machine identifier. If the matching condition exists in the flow entry information list within the virtual cloud scenario, the virtual machine identifier found is the destination virtual machine identifier, and it indicates that the destination virtual machine identifier and the source virtual machine identifier belong to the same virtual cloud scenario. Then, the flow entry information list is queried to obtain the tenant identifier, security group list and other information of the destination virtual machine. Finally, the destination virtual machine identifier, tenant identifier, security group list and other information are added to the flow information for completion, and the completed flow information is stored in the database for subsequent matching of flow information.
[0089] By adopting the technical solution of obtaining the virtual cloud identifier of the virtual cloud where the virtual machine corresponding to the source virtual machine identifier is located, and using the tenant identifier, destination address, and virtual cloud identifier as matching conditions to search for a matching destination virtual machine identifier in the virtual cloud flow entry information list, and finally adding the destination virtual machine identifier, tenant identifier, security group list and other information to the flow information for completion, the technical problem of how to obtain the second virtual machine identifier is solved, and the effect of completing the data flow information is achieved.
[0090] Reference Figure 4 , Figure 4 : This is a flow chart of a third embodiment of the method for completing stream information of the present invention. In this embodiment, after step S121 in the second embodiment, the following steps are included:
[0091] Step S221: If the second virtual machine identifier cannot be found in the virtual cloud, it is determined whether the virtual machine uses an elastic address.
[0092] In this embodiment, the elastic address is EIP (Elastic IP). Generally, an elastic address is a public IP address resource that can be purchased and held independently and is unique throughout the entire network. EIP is different from the private IP address used in the virtual cloud. The private IP address, also known as a private network address, is an unregistered IP address specifically for use within an organization. It is within the scope of a local area network. Private IP addresses are prohibited from appearing in the Internet. Virtual machines in a virtual cloud generally use private IP addresses. When the corresponding destination virtual machine identifier cannot be queried in module 2, it indicates that the destination virtual machine identifier and the source virtual machine identifier are not in the same virtual cloud scenario. At this time, module 4 is entered for processing to determine whether the virtual machine uses an elastic address.
[0093] Step S222: If the virtual machine uses an elastic address, the attribute information of the virtual machine corresponding to the elastic address is added to the data flow information.
[0094] In this embodiment, the attribute identifier includes at least one of the security group information and the tenant identifier. The security group information is a logical grouping, which provides access policies for virtual machines with the same security protection requirements and mutual trust in the same virtual cloud scenario. After the security group is created, various access rules can be defined in the security group. When the virtual machine joins the security group, it is protected by these access rules. The access rules include outbound and inbound rules, which will perform access control on the data flow in and out of the virtual machine within the security group; the tenant identifier represents the user identity. By default, each user can create 100 security groups, and a security group is only allowed to be used for 50 security group rules at most. A virtual machine can only be added to 5 security groups at most. Module 4 is the processing of EIP. If the IP address is EIP, the EIP processing logic is entered, and the virtual machine identifier to which the EIP belongs, the EIP security group information, the tenant identifier to which the EIP belongs, and other information are stored in the database to complete the data flow information.
[0095] The invention adopts a technical solution in which if the destination virtual machine identifier cannot be found in the virtual cloud, it is determined whether the virtual machine adopts an elastic address. When the virtual machine adopts an elastic address, the attribute information of the virtual machine corresponding to the elastic address is added to the data flow information to complete the data flow information. This solves the technical problem of how to complete the data flow information when the destination virtual machine identifier and the source virtual machine identifier are not in the same virtual cloud scenario, and realizes the completion of the data flow information by determining whether an elastic address exists and, if so, completing the data flow information.
[0096] Reference Figure 5 , Figure 5 This is a flow chart of a fourth embodiment of the flow information completion method of the present invention. In this embodiment, after step S221 in the third embodiment, the following steps are included:
[0097] Step S321: If the virtual machine does not use elastic address, the configuration parameters of the current data flow information are obtained.
[0098] In one embodiment, when the destination virtual machine identifier and the source virtual machine identifier are not in the same virtual cloud scenario, and the destination virtual machine address is not EIP, the module 5 processing logic is entered to perform association analysis to obtain the configuration parameters of the current data flow information, and the configuration parameters of the data flow information include at least: a five-tuple, a number of bytes, a number of data packets, and a flow direction; the five-tuple includes at least: a source address, a destination address, a source port number, a destination port number, and a protocol type.
[0099] Step S322: searching for matching preset data stream information according to the configuration parameters.
[0100] In this embodiment, the data flow information is first stored in a cache data structure, which can be a queue or a shared memory, depending on the specific implementation. Then, the five-tuple, number of bytes, number of packets, and reverse value of the flow direction in the data flow information are extracted as matching conditions, and the existing data flow information in the cache data structure is searched for matching preset data flow information.
[0101] Step S323: Use the virtual machine identifier corresponding to the pre-stored data flow information as the second virtual machine identifier of the data flow information.
[0102] In this embodiment, the virtual machine identifier corresponding to the matched pre-stored data flow information is used as the destination virtual machine identifier of the data flow information, and then the security group information, tenant identifier and other information are obtained in the flow entry information list, and these information are completed to the flow information and stored in the database. In the matching process, a timeout period is set for the data flow information. If the match fails, the flow information corresponding to the data flow may not have arrived yet, and the matching data flow information is searched again in the cache data structure until the match succeeds or times out. If a timeout occurs, the data flow information is recorded in the behavior log, indicating that the data flow information is not matched, or the destination IP is an offline IP, not an IP on the cloud, etc.
[0103] By adopting a technical solution in which, if the virtual machine does not adopt an elastic address, the configuration parameters of the current data flow information are obtained, the matching preset data flow information is searched according to the configuration parameters, and the virtual machine identifier corresponding to the pre-stored data flow information is used as the second virtual machine identifier of the data flow information, this solves the technical problem of how to complete the data flow information when the destination virtual machine identifier and the source virtual machine identifier are not in the same virtual cloud scenario and the destination virtual machine address is not an elastic address, thereby achieving the effect of completing the data flow information.
[0104] Based on the same inventive concept, the present invention also provides a stream information completion device, which includes: an acquisition module, a data stream completion module, etc. Each module will be described in detail below:
[0105] An acquisition module is used to acquire data flow information uploaded by a traffic collection device, and to acquire a first virtual machine identifier in the data flow information, and to acquire a second virtual machine identifier corresponding to the first virtual machine identifier according to address information in the data flow information, wherein the data flow information includes communication data between a virtual machine corresponding to the first virtual machine identifier and a virtual machine corresponding to the second virtual machine identifier; specifically, the acquisition module is also used to acquire a virtual cloud identifier of a virtual cloud where the virtual machine corresponding to the first virtual machine identifier is located, and to search for the second virtual machine identifier in the virtual cloud according to the address information and the virtual cloud identifier; if the second virtual machine identifier cannot be found in the virtual cloud, then determine whether the virtual machine uses an elastic address; if the virtual machine uses an elastic address, then add attribute information of the virtual machine corresponding to the elastic address to the data flow information; if the virtual machine does not use an elastic address, then acquire configuration parameters of the current data flow information, search for matching preset data flow information according to the configuration parameters, and use the virtual machine identifier corresponding to the pre-stored data flow information as the second virtual machine identifier of the data flow information.
[0106] A data stream completion module is used to add attribute information of the virtual machine corresponding to the second virtual machine identifier to the data stream information.
[0107] The invention adopts the method of obtaining data flow information uploaded by a traffic collection device, obtaining a first virtual machine identifier in the data flow information, obtaining a virtual cloud identifier of a virtual cloud where a virtual machine corresponding to the first virtual machine identifier is located, searching for the second virtual machine identifier in the virtual cloud according to the address information and the virtual cloud identifier, and if the second virtual machine identifier cannot be found in the virtual cloud, determining whether the virtual machine adopts an elastic address, and if the virtual machine adopts an elastic address, adding the attribute information of the virtual machine corresponding to the elastic address to the data flow information; if the virtual machine does not adopt an elastic address, obtaining configuration parameters of the current data flow information, searching for matching preset data flow information according to the configuration parameters, using the virtual machine identifier corresponding to the pre-stored data flow information as the second virtual machine identifier of the data flow information, and adding the attribute information of the virtual machine corresponding to the second virtual machine identifier to the data flow information. In the case of not knowing the virtual cloud topology connection relationship, the data flow information is completed according to the characteristics of the collected flow information.
[0108] Based on the same inventive concept, an embodiment of the present application also provides a computer storage medium, which stores a flow information completion program. When the flow information completion program is executed by a processor, it implements the various steps of the flow information completion method as described above and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0109] Since the computer storage medium provided in the embodiments of the present application is the computer storage medium used to implement the method of the embodiments of the present application, based on the method introduced in the embodiments of the present application, the person skilled in the art can understand the specific structure and deformation of the computer storage medium, so it is not repeated here. All computer storage media used in the methods of the embodiments of the present application belong to the scope of protection of this application.
[0110] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.
[0111] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable computer storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0112] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0113] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0114] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1A step that specifies a function in one or more boxes.
[0115] It should be noted that in the claims, any reference signs placed between brackets shall not be construed as limiting the claims. The word "comprising" does not exclude the presence of components or steps not listed in the claims. The word "a" or "an" preceding a component does not exclude the presence of a plurality of such components. The present invention may be implemented by means of hardware comprising several different components and by means of a suitably programmed computer. In a unit claim enumerating several means, several of these means may be embodied by the same item of hardware. The use of the words first, second, and third etc. does not indicate any order. These words may be interpreted as identifiers.
[0116] Although the preferred embodiments of the present invention have been described, those skilled in the art may make other changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.
[0117] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.
Claims
1. A method for completing stream information, characterized in that: The method comprises: Obtaining data flow information uploaded by a traffic collection device, and obtaining a first virtual machine identifier in the data flow information; Obtaining a virtual cloud identifier of a virtual cloud where the virtual machine corresponding to the first virtual machine identifier is located; searching for a second virtual machine identifier in the virtual cloud according to the address information in the data flow information and the virtual cloud identifier, wherein the data flow information includes communication data between a virtual machine corresponding to a first virtual machine identifier and a virtual machine corresponding to the second virtual machine identifier, the virtual cloud is a virtual private cloud, and the virtual machine corresponding to the first virtual machine identifier and the virtual machine corresponding to the second virtual machine identifier are located in a virtual private cloud network; If the second virtual machine identifier cannot be found in the virtual cloud, determining whether the virtual machine uses an elastic address, wherein the elastic address is a public network address resource that is independently purchased and held; If the virtual machine does not use elastic address, obtain the configuration parameters of the current data flow information, wherein the configuration parameters of the data flow information at least include: a five-tuple, a number of bytes, a number of data packets, and a flow direction; the five-tuple at least includes: a source address, a destination address, a source port number, a destination port number, and a protocol type; Searching for matching preset data stream information according to the configuration parameters; Using the virtual machine identifier corresponding to the preset data flow information as the second virtual machine identifier of the data flow information; Add the attribute information of the virtual machine corresponding to the second virtual machine identifier to the data flow information to complete the data flow information.
2. The method for completing stream information according to claim 1, characterized in that: If the second virtual machine identifier cannot be found in the virtual cloud, then after determining whether the virtual machine uses an elastic address, the method includes: If the virtual machine uses an elastic address, the attribute information of the virtual machine corresponding to the elastic address is added to the data flow information.
3. The method for completing stream information according to claim 1, characterized in that: If the virtual machine does not use the elastic address, the method includes: If the corresponding preset data flow information is not matched within the preset time, the data flow information is recorded in the behavior log.
4. The method for completing stream information according to claim 1, wherein: The attribute information includes at least one of security group information and a tenant identifier.
5. A stream information completion device, characterized in that: The device comprises: An acquisition module is used to acquire data flow information uploaded by a traffic collection device, and acquire a first virtual machine identifier in the data flow information, and acquire a virtual cloud identifier of a virtual cloud where the virtual machine corresponding to the first virtual machine identifier is located; searching for a second virtual machine identifier in the virtual cloud according to the address information in the data flow information and the virtual cloud identifier, wherein the data flow information includes communication data between a virtual machine corresponding to the first virtual machine identifier and a virtual machine corresponding to the second virtual machine identifier, the virtual cloud is a virtual private cloud, and the virtual machine corresponding to the first virtual machine identifier and the virtual machine corresponding to the second virtual machine identifier are located in a virtual private cloud network; if the second virtual machine identifier cannot be found in the virtual cloud, determining whether the virtual machine uses an elastic address, wherein the elastic address is a public network address resource purchased and held independently; if the virtual machine does not use an elastic address, acquiring configuration parameters of the current data flow information, wherein the configuration parameters of the data flow information include at least: a five-tuple, a number of bytes, a number of data packets, and a flow direction; the five-tuple includes at least: a source address, a destination address, a source port number, a destination port number, and a protocol type; searching for matching preset data flow information according to the configuration parameters; using the virtual machine identifier corresponding to the preset data flow information as the second virtual machine identifier of the data flow information; The data flow completion module is used to add the attribute information of the virtual machine corresponding to the second virtual machine identifier to the data flow information to complete the data flow information.
6. A cloud host device, characterized in that: The cloud host device includes a memory, a processor, and a flow information completion program stored in the memory and executable on the processor. When the flow information completion program is executed by the processor, each step of the flow information completion method as described in any one of claims 1 to 4 is implemented.
7. A computer storage medium, characterized in that: The computer storage medium stores a flow information completion program, and when the flow information completion program is executed by a processor, each step of the flow information completion method according to any one of claims 1 to 4 is implemented.
Citation Information
Patent Citations
Hybrid cloud management method and apparatus, and computing device
CN108347493A