A flow processing method, apparatus, electronic device, and storage medium
By adopting regional division and sub-region division strategies in large-scale network scenarios, the traffic scale that traffic collectors need to be exported is reduced, the problem of excessive traffic export scale is solved, and more efficient traffic processing is achieved.
Patent Information
- Application Number
- CN202110723001.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-06-28
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2041-06-28
AI Technical Summary
In large-scale network scenarios, how to reduce the export scale of traffic, especially due to the huge network traffic, the traffic exported by the stream collector is also very large.
By receiving control messages and traffic export messages sent by the controller, a region division policy and a sub-region division policy are adopted to divide multiple hosts into multiple regions, and the traffic within each host is divided into multiple sub-regions. Each host includes multiple traffic collectors, and each traffic collector is used to collect traffic in the corresponding sub-region and export it to the corresponding traffic collector or traffic analyzer.
Through area division and sub-region division, the traffic scale that each traffic collector needs to export is reduced, thereby effectively reducing the traffic export scale.
Smart Images

Figure CN115604137B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and more specifically, to a traffic processing method, apparatus, an electronic device, and a computer-readable storage medium. Background Art
[0002] For large-scale network scenarios with a large number of nodes, new or concurrent traffic, etc., the total traffic scale is huge. The flow statistical information collected by the flow collector is packaged and exported according to a certain protocol format and sent to the traffic collector or traffic analyzer. Due to the huge network traffic scale, the traffic exported by the flow collector is also huge.
[0003] Therefore, how to reduce the export scale of traffic is a technical problem that needs to be solved by those skilled in the art. Summary of the Invention
[0004] The purpose of this application is to provide a traffic processing method, apparatus, an electronic device, and a computer-readable storage medium, which reduce the export scale of traffic.
[0005] To achieve the above purpose, this application provides a traffic processing method, including:
[0006] Receiving a control message sent by a controller; wherein, the control message includes a region division policy and a sub-region division policy, the region division policy is used to divide multiple hosts into multiple regions, the sub-region division policy is used to divide the traffic within each host into multiple sub-regions, and the traffic collector included in each host is used to collect the traffic within the corresponding sub-region;
[0007] Receiving a traffic export message sent by the controller, the traffic export message carrying a target traffic export policy, the target traffic export policy being used to export a target data stream;
[0008] Based on the target traffic export policy, the region division policy, and the sub-region division policy, determining the traffic collector corresponding to the target data stream;
[0009] Using the traffic collector corresponding to the target data stream to export the target data stream.
[0010] Wherein, after using the traffic collector corresponding to the target data stream to export the target data stream, it further includes:
[0011] Exporting the target data stream collected by the traffic collector corresponding to the target data stream and the flow feature information corresponding to the target data stream to the corresponding traffic collector or traffic analyzer.
[0012] Among them, the area division strategy is used to divide all the hosts into multiple areas based on the host information of all the hosts;
[0013] The host information includes any one or a combination of several of hardware parameters, traffic scale, geographical location, and the environment where it is located.
[0014] Among them, the sub-area division strategy is used to divide the traffic within each host into multiple sub-areas based on the traffic information of the data stream passing through each host;
[0015] The traffic information includes any one or a combination of several of source IP address, destination IP address, source port number, destination port number, and transport protocol.
[0016] Among them, the target traffic export strategy includes the index information of the target data stream, and the index information includes a five-tuple or a six-tuple;
[0017] The five-tuple includes source IP address, destination IP address, source port number, destination port number, and transport protocol;
[0018] The six-tuple includes source IP address, destination IP address, source port number, destination port number, transport protocol, and priority.
[0019] Among them, the flow feature information includes any one or a combination of several of the number of data packets, the total data size, the number of data packets within a preset time period, the total data size within a preset time period, the data packet transmission information within a preset time period, and the data transmission information within a preset time period;
[0020] The data packet transmission information includes any one or a combination of several of the maximum data packet transmission rate, the minimum data packet transmission rate, and the average data packet transmission rate;
[0021] The data transmission information includes any one or a combination of several of the maximum data transmission rate, the minimum data transmission rate, and the average data transmission rate.
[0022] Among them, the flow collector corresponds one-to-one with the traffic collector or the traffic analyzer.
[0023] Among them, exporting the target data stream collected by the traffic collector corresponding to the target data stream and the flow feature information corresponding to the target data stream to the corresponding traffic collector or traffic analyzer includes:
[0024] Merging the target data stream collected by the traffic collector corresponding to the target data stream to obtain a corresponding merged data stream, and merging the flow feature information corresponding to the target data stream to obtain the merged flow feature information corresponding to the merged data stream;
[0025] Export the merged data stream and the corresponding merged stream feature information to the corresponding traffic collector or traffic analyzer.
[0026] To achieve the above object, the present application provides a traffic export device, which is applied to a host and includes:
[0027] A first receiving module, configured to receive a control message sent by a controller; wherein, the control message includes a region division policy and a sub-region division policy, the region division policy is used to divide multiple hosts into multiple regions, and the sub-region division policy is used to divide the traffic in each host into multiple sub-regions, and a traffic collector included in each host is used to collect the traffic in the corresponding sub-region;
[0028] A second receiving module, configured to receive a traffic export message sent by the controller, the traffic export message carrying a target traffic export policy, and the target traffic export policy is used to export a target data stream;
[0029] A determination module, configured to determine a traffic collector corresponding to the target data stream based on the target traffic export policy, the region division policy, and the sub-region division policy;
[0030] A first export module, configured to export the target data stream by using the traffic collector corresponding to the target data stream.
[0031] To achieve the above object, the present application provides an electronic device, including:
[0032] A memory, configured to store a computer program;
[0033] A processor, configured to implement the steps of the above traffic processing method when executing the computer program.
[0034] To achieve the above object, the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above traffic processing method are implemented.
[0035] As can be seen from the above solution, a traffic processing method provided by the present application includes: receiving a control message sent by a controller; wherein, the control message includes a region division policy and a sub-region division policy, the region division policy is used to divide multiple hosts into multiple regions, the sub-region division policy is used to divide the traffic in each host into multiple sub-regions, and a traffic collector included in each host is used to collect the traffic in the corresponding sub-region; receiving a traffic export message sent by the controller, the traffic export message carrying a target traffic export policy, the target traffic export policy is used to export a target data stream; determining the traffic collector corresponding to the target data stream based on the target traffic export policy, the region division policy and the sub-region division policy; and exporting the target data stream by using the traffic collector corresponding to the target data stream.
[0036] In the present application, all hosts connected to the same controller are divided into multiple regions, and the traffic in the same host is divided into multiple sub-regions. Each host includes multiple traffic collectors, and each traffic collector is used to collect the traffic in the corresponding sub-region and export it to the corresponding traffic collector or traffic analyzer, that is, each traffic collector only exports the traffic in the corresponding sub-region, so that the traffic exported by each traffic collector is less. It can be seen that the traffic processing method provided by the present application reduces the export scale of traffic through region division and sub-region division. The present application also discloses a traffic export device, an electronic device and a computer-readable storage medium, which can also achieve the above technical effects.
[0037] It should be understood that the above general description and the following detailed description are only exemplary and do not limit the present application. Description of the Drawings
[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings. The drawings are used to provide a further understanding of the present disclosure and constitute a part of the specification, and are used together with the following specific embodiments to explain the present disclosure, but do not constitute a limitation to the present disclosure. In the drawings:
[0039] Figure 1 It is a flowchart of a traffic processing method shown according to an exemplary embodiment;
[0040] Figure 2 It is a flowchart of a traffic export system shown according to an exemplary embodiment;
[0041] Figure 3 Flow chart of another traffic processing method shown according to an exemplary embodiment;
[0042] Figure 4 Structural diagram of a traffic export device shown according to an exemplary embodiment;
[0043] Figure 5 Structural diagram of an electronic device shown according to an exemplary embodiment. Detailed implementation manners
[0044] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the scope of protection of the present application. Additionally, in the embodiments of the present application, "first", "second", etc. are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence.
[0045] The embodiments of the present application disclose a traffic processing method, which reduces the scale of traffic export.
[0046] See Figure 1 , a flow chart of a traffic processing method shown according to an exemplary embodiment, as Figure 1 shown, including:
[0047] S101: Receive a control message sent by a controller; wherein, the control message includes a region division strategy and a sub-region division strategy, the region division strategy is used to divide multiple hosts into multiple regions, the sub-region division strategy is used to divide the traffic in each host into multiple sub-regions, and a traffic collector included in each host is used to collect the traffic in the corresponding sub-region;
[0048] The execution subject of this embodiment is a host, and the purpose is to export the traffic in the host. The above host can be a physical host or a cloud computing virtual host, and no specific limitation is made here. In this embodiment, as Figure 2 shown, multiple hosts connected to the same controller are divided into multiple regions, and the traffic in the same host is divided into multiple sub-regions. It can be understood that the traffic in different regions is isolated from each other, and the traffic in different sub-regions is isolated from each other.
[0049] It should be noted that the region division method and the sub-region division method can be preset in the controller in advance, or can be dynamically modified and dynamically sent by the controller to each host. In addition, the specific region division method and sub-region division method are not limited in this embodiment. As a feasible implementation method, the region division strategy is used to divide all hosts into multiple regions based on the host information of all hosts. The host information here can include hardware parameters, traffic scale, geographical location, and the environment where the hosts are located, etc. For example, hosts with similar geographical locations can be divided into the same region. As a feasible implementation method, the sub-region division strategy is used to divide the traffic in each host into multiple sub-regions based on the traffic information of the data stream passing through each host. The traffic information here can include source IP address, destination IP address, source port number, destination port number, and transport protocol, etc. For example, traffic with the same traffic information can be divided into the same sub-region.
[0050] In specific implementation, each host includes multiple traffic collectors, and each traffic collector is used to collect the traffic in the corresponding sub-region, so that the traffic collected by each traffic collector is reduced. Preferably, the number of traffic collectors included in each host is the same as the number of sub-regions included in the host, that is, the traffic collectors in each host correspond one-to-one with the sub-regions included in the host.
[0051] S102: Receive the traffic export message sent by the controller. The traffic export message carries a target traffic export strategy, and the target traffic export strategy is used to export the target data stream;
[0052] In specific implementation, the controller sends a traffic export message to all hosts connected to it, which includes the target traffic export strategy and may also include the flow feature information of interest. Each host determines the target data stream from the traffic collected by each of its traffic collectors based on the target traffic export strategy, and can determine the flow feature information corresponding to the target data stream.
[0053] As a feasible implementation method, the target traffic export strategy in this embodiment can include the index information of the target data stream. This index information can specifically be the five-tuple or six-tuple of the target data stream. The five-tuple includes source IP address, destination IP address, source port number, destination port number, and transport protocol, and the six-tuple includes source IP address, destination IP address, source port number, destination port number, transport protocol, and priority.
[0054] As a feasible implementation manner, the flow feature information in this embodiment may include the number of data packets, the total data size, the number of data packets within a preset time period, the total data size within a preset time period, the data packet transmission information within a preset time period, and the data transmission information within a preset time period, etc. The data packet transmission information may include the maximum data packet transmission rate, the minimum data packet transmission rate, and the average data packet transmission rate, etc. The data transmission information may include the maximum data transmission rate, the minimum data transmission rate, and the average data transmission rate, etc.
[0055] S103: Based on the target traffic export policy, the region division policy, and the sub-region division policy, determine the traffic collector corresponding to the target data stream;
[0056] S104: Use the traffic collector corresponding to the target data stream to export the target data stream.
[0057] In specific implementation, based on the target traffic export policy, the region division policy, and the sub-region division policy, determine the traffic collector corresponding to the target data stream, and use this traffic collector to export the target data stream. Of course, the flow feature information corresponding to the target data stream can also be exported.
[0058] As a preferred implementation manner, after using the traffic collector corresponding to the target data stream to export the target data stream, it further includes: exporting the target data stream collected by the traffic collector corresponding to the target data stream and the flow feature information corresponding to the target data stream to the corresponding traffic collector or traffic analyzer. In specific implementation, each traffic collector exports the collected data stream and the corresponding flow feature information to the corresponding traffic collector or traffic analyzer. Since each traffic collector only exports the data stream within the corresponding sub-region, the scale of traffic export is small. Preferably, the traffic collector in each host corresponds one-to-one with the traffic collector or traffic analyzer, that is, each traffic collector or traffic analyzer is only used to collect or analyze the target data stream exported from the corresponding sub-region, improving the traffic collection or analysis efficiency.
[0059] In the embodiment of the present application, all hosts connected to the same controller are divided into multiple regions, and the traffic within the same host is divided into multiple sub-regions. Each host includes multiple traffic collectors, and each traffic collector is used to collect the traffic within the corresponding sub-region and export it to the corresponding traffic collector or traffic analyzer, that is, each traffic collector only exports the traffic within the corresponding sub-region, so that the traffic exported by each traffic collector is less. It can be seen that the traffic processing method provided by the embodiment of the present application reduces the scale of traffic export through region division and sub-region division.
[0060] An embodiment of the present application discloses a traffic processing method. Compared with the previous embodiment, the technical solution in this embodiment is further described and optimized. Specifically:
[0061] Refer to Figure 3 , a flowchart of another traffic processing method shown according to an exemplary embodiment, as Figure 3 shown, including:
[0062] S201: Receive a control message sent by a controller; wherein, the control message includes a region division policy and a sub-region division policy, the region division policy is used to divide multiple hosts into multiple regions, the sub-region division policy is used to divide the traffic in each host into multiple sub-regions, and a traffic collector included in each host is used to collect the traffic in the corresponding sub-region;
[0063] S202: Receive a traffic export message sent by the controller, the traffic export message carrying a target traffic export policy, the target traffic export policy being used to export a target data stream;
[0064] S203: Based on the target traffic export policy, the region division policy, and the sub-region division policy, determine the traffic collector corresponding to the target data stream;
[0065] S204: Use the traffic collector corresponding to the target data stream to export the target data stream and the flow feature information corresponding to the target data stream;
[0066] S205: Merge the target data stream collected by the traffic collector corresponding to the target data stream to obtain a corresponding merged data stream, and merge the flow feature information corresponding to the target data stream to obtain the merged flow feature information corresponding to the merged data stream;
[0067] S206: Export the merged data stream and the corresponding merged flow feature information to a corresponding traffic collector or traffic analyzer.
[0068] In this embodiment, if the scale of the target data stream collected by the traffic collector is large, it can be merged and then exported to the corresponding traffic collector or traffic analyzer. That is, the traffic collector exports the target data stream to the corresponding traffic collector or traffic analyzer through the traffic merging module. The traffic merging module is used to merge the target data stream based on the traffic merging policy to obtain a merged data stream, and at the same time merge the flow feature information corresponding to the target data stream to obtain the merged flow feature information corresponding to the merged data stream. The traffic merging policy here can include any one or more items in the index information, that is, a subset of the five-tuple or six-tuple, such as the destination IP address of interest. Similarly, the traffic merging policy can be set in the controller in advance, or can be dynamically modified and dynamically sent by the controller to each host.
[0069] It can be seen that based on the regional division and sub-regional division, this embodiment merges the target data streams that need to be exported within the sub-regions. The scale of the merged data stream is smaller than the sum of all target data streams before merging, further reducing the scale of the traffic exported to each traffic collector or traffic analyzer.
[0070] Next, a traffic export device provided by an embodiment of the present application will be introduced. The traffic export device described below can be referred to in mutual reference with the traffic processing method described above.
[0071] See Figure 4 , a structural diagram of a traffic export device shown according to an exemplary embodiment, as Figure 4 shown, includes:
[0072] A first receiving module 401, configured to receive a control message sent by the controller; wherein, the control message includes a regional division policy and a sub-regional division policy. The regional division policy is used to divide multiple hosts into multiple regions, and the sub-regional division policy is used to divide the traffic in each host into multiple sub-regions. The traffic collector included in each host is used to collect the traffic in the corresponding sub-region;
[0073] A second receiving module 402, configured to receive the traffic export message sent by the controller. The traffic export message carries a target traffic export policy, and the target traffic export policy is used to export the target data stream;
[0074] A determination module 403, configured to determine the traffic collector corresponding to the target data stream based on the target traffic export policy, the regional division policy, and the sub-regional division policy;
[0075] A first export module 404, configured to export the target data stream by using the traffic collector corresponding to the target data stream.
[0076] In the embodiments of the present application, all hosts connected to the same controller are divided into multiple regions, and the traffic within the same host is divided into multiple sub-regions. Each host includes multiple traffic collectors, and each traffic collector is used to collect the traffic within the corresponding sub-region and export it to the corresponding traffic collector or traffic analyzer. That is, each traffic collector only exports the traffic within the corresponding sub-region, so that the traffic exported by each traffic collector is relatively small. It can be seen that the traffic export device provided by the embodiments of the present application reduces the scale of traffic export through region division and sub-region division.
[0077] Based on the above embodiments, as a preferred embodiment, it further includes:
[0078] A second export module, configured to export the target data stream collected by the traffic collector corresponding to the target data stream and the flow feature information corresponding to the target data stream to the corresponding traffic collector or traffic analyzer.
[0079] Based on the above embodiments, as a preferred embodiment, the region division strategy is used to divide all the hosts into multiple regions based on the host information of all the hosts;
[0080] The host information includes any one or a combination of several of hardware parameters, traffic scale, geographical location, and the environment where it is located.
[0081] Based on the above embodiments, as a preferred embodiment, the sub-region division strategy is used to divide the traffic within each host into multiple sub-regions based on the traffic information of the data stream passing through each host;
[0082] The traffic information includes any one or a combination of several of source IP address, destination IP address, source port number, destination port number, and transport protocol.
[0083] Based on the above embodiments, as a preferred embodiment, the target traffic export strategy includes index information of the target data stream, and the index information includes a five-tuple or a six-tuple;
[0084] The five-tuple includes source IP address, destination IP address, source port number, destination port number, and transport protocol;
[0085] The six-tuple includes source IP address, destination IP address, source port number, destination port number, transport protocol, and priority.
[0086] Based on the above embodiments, as a preferred embodiment, the flow feature information includes any one or any combination of the number of data packets, the total data size, the number of data packets within a preset time period, the total data size within a preset time period, the data packet transmission information within a preset time period, and the data transmission information within a preset time period;
[0087] The data packet transmission information includes any one or any combination of the maximum data packet transmission rate, the minimum data packet transmission rate, and the average data packet transmission rate;
[0088] The data transmission information includes any one or any combination of the maximum data transmission rate, the minimum data transmission rate, and the average data transmission rate.
[0089] Based on the above embodiments, as a preferred embodiment, the flow collector corresponds one-to-one with the traffic collector or the traffic analyzer.
[0090] Based on the above embodiments, as a preferred embodiment, the second export module includes:
[0091] A merging unit, configured to merge the target data stream collected by the flow collector corresponding to the target data stream to obtain a corresponding merged data stream, and merge the flow feature information corresponding to the target data stream to obtain the merged flow feature information corresponding to the merged data stream;
[0092] An export unit, configured to export the merged data stream and the corresponding merged flow feature information to a corresponding traffic collector or traffic analyzer.
[0093] Regarding the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated herein.
[0094] Based on the hardware implementation of the above program modules, and in order to implement the method of the embodiments of the present application, the embodiments of the present application further provide an electronic device, Figure 5 As shown in the structural diagram of an electronic device according to an exemplary embodiment, such as Figure 5 shown, the electronic device includes:
[0095] A communication interface 1, capable of interacting with other devices such as network devices;
[0096] A processor 2, connected to the communication interface 1 to implement information interaction with other devices, and when running a computer program, execute the traffic processing method provided by the above one or more technical solutions. And the computer program is stored on the memory 3.
[0097] Of course, in practical applications, the various components in the electronic device are coupled together through the bus system 4. It can be understood that the bus system 4 is used to achieve connection and communication between these components. In addition to the data bus, the bus system 4 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clear illustration, in Figure 5 all kinds of buses are labeled as the bus system 4.
[0098] The memory 3 in the embodiment of the present application is used to store various types of data to support the operation of the electronic device. Examples of these data include: any computer program for operating on the electronic device.
[0099] It can be understood that the memory 3 can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM, Read Only Memory), a programmable read-only memory (PROM, Programmable Read-Only Memory), an erasable programmable read-only memory (EPROM, Erasable Programmable Read-Only Memory), an electrically erasable programmable read-only memory (EEPROM, Electrically Erasable Programmable Read-Only Memory), a ferromagnetic random access memory (FRAM, ferromagnetic random access memory), a flash memory (Flash Memory), a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM, Compact Disc Read-Only Memory); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM, Random Access Memory), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as a static random access memory (SRAM, Static Random Access Memory), a synchronous static random access memory (SSRAM, Synchronous Static Random Access Memory), a dynamic random access memory (DRAM, Dynamic Random Access Memory), a synchronous dynamic random access memory (SDRAM, Synchronous Dynamic Random Access Memory), a double data rate synchronous dynamic random access memory (DDR SDRAM, Double Data Rate Synchronous Dynamic Random Access Memory), an enhanced synchronous dynamic random access memory (ESDRAM, Enhanced Synchronous Dynamic Random Access Memory), a sync link dynamic random access memory (SLDRAM, SyncLink Dynamic Random Access Memory), and a direct rambus random access memory (DRRAM, Direct Rambus Random Access Memory).The memory 2 described in the embodiments of the present application is intended to include, but is not limited to, these and any other suitable types of memories.
[0100] The method disclosed in the embodiments of the present application above can be applied to the processor 2 or implemented by the processor 2. The processor 2 may be an integrated circuit chip with the ability to process signals. During implementation, the steps of the above method can be completed by the integrated logic circuit in hardware or instructions in software form in the processor 2. The above-mentioned processor 2 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 2 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. Combining the steps of the method disclosed in the embodiments of the present application, it can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by the combination of the hardware and software modules in the decoding processor. The software module may be located in the storage medium, and this storage medium is located in the memory 3. The processor 2 reads the program in the memory 3 and combines its hardware to complete the steps of the foregoing method.
[0101] When the processor 2 executes the program, it implements the corresponding processes in the various methods of the embodiments of the present application. For the sake of brevity, it will not be elaborated here.
[0102] In an exemplary embodiment, the embodiments of the present application also provide a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, such as a memory 3 including a stored computer program. The above computer program can be executed by the processor 2 to complete the steps of the foregoing method. The computer-readable storage medium may be a FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM, etc.
[0103] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps including the above method embodiments; and the foregoing storage medium includes: various media such as mobile storage devices, ROM, RAM, magnetic disks, or optical discs that can store program codes.
[0104] Alternatively, if the above integrated units of the present application are implemented in the form of software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing an electronic device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes such as removable storage devices, ROM, RAM, magnetic disks, or optical discs.
[0105] As described above, the foregoing is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A flow processing method, characterized in that, Including: Receiving a control message sent by a controller; wherein, the control message includes a region division policy and a sub-region division policy, the region division policy is used to divide multiple hosts into multiple regions, the sub-region division policy is used to divide the traffic in each host into multiple sub-regions, each host includes multiple traffic collectors, the traffic collectors in each host correspond one-to-one with the sub-regions included in the host, and the traffic collectors included in each host are used to collect the traffic in the corresponding sub-region; Receiving a traffic export message sent by the controller, the traffic export message carrying a target traffic export policy, the target traffic export policy being used to export a target data stream; Based on the target traffic export policy, the region division policy and the sub-region division policy, determining the traffic collector corresponding to the target data stream; Using the traffic collector corresponding to the target data stream to export the target data stream.
2. The flow processing method according to claim 1, characterized in that, After using the traffic collector corresponding to the target data stream to export the target data stream, further including: Exporting the target data stream collected by the traffic collector corresponding to the target data stream and the flow feature information corresponding to the target data stream to a corresponding traffic collector or traffic analyzer.
3. The flow processing method according to claim 1, characterized in that, The region division policy is used to divide all the hosts into multiple regions based on the host information of all the hosts; The host information includes any one or a combination of several of hardware parameters, traffic scale, geographical location, and the environment where it is located.
4. The flow processing method according to claim 1, characterized in that, The sub-region division policy is used to divide the traffic in each host into multiple sub-regions based on the traffic information of the data stream passing through each host; The traffic information includes any one or a combination of several of source IP address, destination IP address, source port number, destination port number, and transport protocol.
5. The flow processing method according to claim 1, characterized in that, The target traffic export policy includes index information of the target data stream, the index information including a five-tuple or a six-tuple; The five-tuple includes source IP address, destination IP address, source port number, destination port number, and transport protocol; The six-tuple includes source IP address, destination IP address, source port number, destination port number, transport protocol, and priority.
6. The flow processing method according to claim 2, characterized in that, The flow feature information includes any one or a combination of several of the number of data packets, the total data size, the number of data packets within a preset time period, the total data size within a preset time period, the data packet transmission information within a preset time period, and the data transmission information within a preset time period; The data packet transmission information includes any one or a combination of several of the maximum data packet transmission rate, the minimum data packet transmission rate, and the average data packet transmission rate; The data transmission information includes any one or a combination of several of the maximum data transmission rate, the minimum data transmission rate, and the average data transmission rate.
7. The flow processing method according to claim 2, characterized in that, The traffic collector corresponds one-to-one with the traffic collector or the traffic analyzer.
8. The flow processing method according to claim 2, characterized in that, Exporting the target data stream collected by the traffic collector corresponding to the target data stream and the flow feature information corresponding to the target data stream to a corresponding traffic collector or traffic analyzer includes: Merge the target data stream collected by the traffic collector corresponding to the target data stream to obtain a corresponding merged data stream, and merge the flow feature information corresponding to the target data stream to obtain the merged flow feature information corresponding to the merged data stream; Export the merged data stream and the corresponding merged flow feature information to a corresponding traffic collector or traffic analyzer.
9. A flow processing device, characterized in that, Comprising: A first receiving module, configured to receive a control message sent by a controller; wherein, the control message includes a region division policy and a sub-region division policy, the region division policy is used to divide multiple hosts into multiple regions, and the sub-region division policy is used to divide the traffic in each host into multiple sub-regions. Each host includes multiple traffic collectors, and the traffic collectors in each host correspond one-to-one with the sub-regions included in the host. The traffic collectors included in each host are used to collect the traffic in the corresponding sub-region; A second receiving module, configured to receive a traffic export message sent by the controller, where the traffic export message carries a target traffic export policy, and the target traffic export policy is used to export a target data stream; A determination module, configured to determine the traffic collector corresponding to the target data stream based on the target traffic export policy, the region division policy, and the sub-region division policy; A first export module, configured to export the target data stream by using the traffic collector corresponding to the target data stream.
10. An electronic device, characterized in that, Comprising: A memory, configured to store a computer program; A processor, configured to implement the steps of the traffic processing method according to any one of claims 1 to 8 when executing the computer program.
11. A computer-readable storage medium, characterized in that,A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the traffic processing method according to any one of claims 1 to 8 are implemented.
Citation Information
Patent Citations
Flow collection system, and method and device thereof
CN101854305A
Network traffic monitoring method and device
CN109150647A