An auditing method based on traffic proxies
By configuring a traffic proxy module on the server side and using Walsh code identification, efficient traffic packetization and transmission are achieved, solving the problems of low auditing efficiency and data security risks under 5G networks, and improving user experience and channel resource utilization.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-18
- Publication Date
- 2026-03-10
AI Technical Summary
Existing traffic auditing solutions are inefficient and provide a poor user experience under 5G networks. When multiple auditing users audit simultaneously, they consume a large amount of channel resources, and data risks increase in the cloud environment.
Configure a traffic proxy module on the server side, use Walsh codes to identify data traffic for grouping, and guide traffic to the audit channel according to the audit end's requirements and permissions. Use orthogonal detection and encapsulation technology for traffic grouping and sending.
It improved auditing efficiency, enhanced user experience, reduced data security risks, and optimized channel resource utilization.
Smart Images

Figure CN115632853B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to network data security technology, specifically to traffic auditing technology. Background Technology
[0002] Traditional network traffic auditing equipment collects traffic from audited targets by configuring mirrored ports on switches; then, it analyzes the collected traffic to achieve auditing objectives. This process requires acquiring all network traffic data each time and then using a series of techniques to audit all the network traffic.
[0003] With the continuous development of network technologies, such as 5G networks which decouple software and hardware through virtualization technology and the deployment of NFV (Network Functions Virtualization) technology, some functional network elements are deployed on cloud-based infrastructure as virtual functional network elements. Furthermore, in cloud environments, massive amounts of data traffic are generated, with numerous users accessing and using cloud platform resources at high speed anytime, anywhere. This brings many challenges to traffic auditing.
[0004] Existing traffic auditing solutions have the following main problems in practical applications:
[0005] (1) Under the 5G network architecture, data traffic is surging. Under the traditional auditing method, traffic auditing audits all network traffic data every time, which is inefficient and affects user experience.
[0006] (2) When multiple audit users need to audit traffic at the same time, all traffic needs to be sent to each audit user separately, which occupies a lot of channel or network resources, resulting in low audit efficiency and increased data risk during transmission.
[0007] (3) The cloud environment contains a large number of servers, and audit users can obtain all server data traffic, which further amplifies the data risks in the cloud environment.
[0008] Therefore, providing a highly efficient and secure traffic auditing solution is a problem that urgently needs to be solved in this field. Summary of the Invention
[0009] To address the problems of existing traffic auditing solutions in terms of auditing efficiency and data security, the present invention aims to provide an auditing method based on traffic proxy, which can improve auditing efficiency and data auditing security based on the traffic proxy model.
[0010] To achieve the above objectives, the present invention provides an auditing method based on traffic proxy, which configures a traffic proxy module on the server to be audited and sets traffic identifiers and user permissions in the data packet header. The traffic proxy module groups the data traffic and directs the traffic to the audit channel according to the audit requirements of the auditing end. The auditing end audits the traffic backup according to the requirements and / or according to the permissions.
[0011] Furthermore, the auditing method uses orthogonal Walsh codes to identify various data traffic types for grouping.
[0012] Furthermore, the auditing method includes the following steps:
[0013] (1) Configure a traffic proxy module on the switch and send the traffic proxy module information back to the server to be audited and the auditing end respectively;
[0014] (2) The auditing end sends a traffic audit request, wherein the data packet of the audit request is encapsulated with traffic identifier and user permissions;
[0015] (3) After receiving the audit request, the switch will directly feed back the audit request to the configured traffic proxy module. The traffic proxy module will detect the received traffic audit request data packet and feed back the detected audit traffic requirement to the server.
[0016] (4) The server will send data traffic to the switch as needed based on the received audit traffic requirements. The traffic proxy module of the switch will encapsulate the received data traffic and send it to the audit end.
[0017] (5) The auditing end audits the data traffic after receiving the data traffic packet.
[0018] Furthermore, in step (3), the traffic proxy module performs orthogonal detection on the orthogonal walsh code in the received traffic audit request data packet. If the orthogonal detection value is 0, the traffic identified by the corresponding walsh code that has undergone orthogonal detection is sent; otherwise, no processing is performed.
[0019] Furthermore, in step (4), the server performs orthogonal detection on the traffic audit request received from the switch. If the orthogonal detection value is 0, the server sends the corresponding traffic identified by the walsh code that performed the orthogonal detection; otherwise, no processing is performed.
[0020] Furthermore, in step (4), when encapsulating the received data traffic, a field is added before each type of data traffic to identify the data traffic. This field is an orthogonal Walsh code.
[0021] Furthermore, in step (4), when sending the encapsulated data traffic, if the network environment is good, the traffic sending method is selected autonomously; if the network environment is congested, the traffic data packets are sent simultaneously in a packaged manner.
[0022] The auditing scheme based on traffic proxy provided by this invention has the following advantages compared with the prior art:
[0023] 1. High auditing efficiency and improved user experience: This solution groups traffic through a traffic proxy module and enables the auditing end to extract data traffic on demand, thereby improving the efficiency of auditing data traffic.
[0024] 2. Data Audit Security: This solution sets user permissions in the data packet header, parses out the audit end's permission information, and the traffic proxy module sends data traffic to the audit end based on the comprehensive user permissions and user audit request ID. Attached Figure Description
[0025] The present invention will be further described below with reference to the accompanying drawings and specific embodiments.
[0026] Figure 1 This is a flowchart illustrating the traffic proxy workflow in an example of the present invention.
[0027] Figure 2 This is the data traffic packet format for audit requirements in this invention example;
[0028] Figure 3 This refers to the time-division data traffic packet format used in the examples of this invention;
[0029] Figure 4 This refers to the frequency division multiplexing (FDM) data traffic packet format used in this invention example;
[0030] Figure 5 This is the time-frequency division data traffic packet format used in the examples of this invention. Detailed Implementation
[0031] To make the technical means, creative features, objectives and effects of this invention easier to understand, the invention will be further described below with reference to specific illustrations.
[0032] This invention innovatively configures a traffic proxy module on the server to be audited. Simultaneously, for all data transmitted between the server and the auditing end, traffic identifiers and user permissions are set in the data packet headers. Based on this, the traffic proxy module groups the data traffic and, according to the auditing end's requirements, uses the traffic proxy to direct traffic to the audit channel. The auditing end then audits the traffic backup according to its needs and / or permissions, thereby improving audit efficiency and addressing data risk issues in cloud environments.
[0033] Specifically, the traffic proxy module configured in this invention is used for traffic identification and serves as a virtual mirror of the switch.
[0034] When configuring such a traffic proxy module, it connects directly to the server. After configuration, it starts running upon receiving a traffic audit request.
[0035] When the traffic proxy module configured in this invention groups data traffic, it uses orthogonal Walsh codes to identify various types of data traffic for grouping.
[0036] This invention uses orthogonal Walsh codes to identify various data traffic types for packetization, and also uses orthogonal Walsh codes to identify different users. The specific implementation scheme is as follows:
[0037] (1) Codeword allocation to users: When a user requests traffic auditing, the traffic proxy module on the switch assigns each user an orthogonal 2n-order Walsh code (n is a positive integer, determined by the total number of auditing users) as an identifier; User detection: The traffic proxy module on the switch packages and sends the audit traffic required by multiple users to different users based on the traffic auditing requests received from multiple users.
[0038] (2) Codewords are assigned to different traffic types: Orthogonal walsh codes are used to identify different traffic types, such as video traffic and audio traffic. Traffic can be classified according to specific needs.
[0039] See Figure 1 The diagram illustrates the implementation process of this solution for auditing network traffic data based on the traffic proxy mode.
[0040] As shown in the diagram, the process of network traffic data auditing based on the traffic proxy mode in this solution mainly includes the following steps:
[0041] (1) Configure the traffic proxy module on the switch and feed back the traffic proxy module information to the server and the auditing end respectively.
[0042] In this step, the traffic proxy module provides feedback by directly sending communication data packets.
[0043] (2) The auditing end sends a traffic audit request, in which the data packet of the audit request is encapsulated with the ID that identifies the traffic and the user's permissions.
[0044] (3) After receiving the audit request, the switch will directly feed back the request to the configured traffic proxy module. The traffic proxy module will detect the traffic audit request data packet received by the switch and feed back the detected audit traffic requirements to the server.
[0045] Specifically, in this step, the traffic proxy module performs orthogonal detection on the orthogonal walsh codes in the received traffic audit request data packets. If the orthogonal detection value is 0, the traffic identified by the corresponding walsh code that underwent orthogonal detection is sent; otherwise, no processing is performed.
[0046] (4) The server will send data traffic to the switch as needed based on the received audit traffic requirements. The traffic proxy module in the switch will encapsulate the received data traffic according to the current channel or network environment and send it to the audit end.
[0047] In this step, the server sends audit traffic of the corresponding type based on the traffic category identified by the walsh code carried in the audit traffic packet requested by the user. Specifically, the server performs orthogonal detection on the received traffic audit request from the switch. If the orthogonal detection value is 0, the server sends the corresponding traffic identified by the walsh code that underwent orthogonal detection; otherwise, no processing is performed.
[0048] In this step, when the traffic proxy module on the switch encapsulates the received data traffic, it identifies the data traffic by adding a field before each type of data traffic. Specifically, this solution preferably adds a WASH code field before the data traffic packet to identify the type of traffic or the user's traffic.
[0049] In this step, when sending encapsulated data traffic, if the network environment is good, the traffic sending method is selected autonomously; if the network environment is congested, the traffic data packets are packaged and sent simultaneously.
[0050] Preferably, under good channel conditions, the traffic proxy module can send audit traffic in batches; if the channel environment is congested, it can send audit traffic to multiple users simultaneously.
[0051] (5) The auditing end audits the data traffic after receiving the data traffic packet.
[0052] It should be noted that, in the specific implementation of this solution, when encapsulating the data traffic packets involved, it is preferable to encapsulate the audit user permissions in the data packet header and encapsulate the corresponding traffic data packet ID or demand data packet ID in the data segment.
[0053] For audit request data traffic packets generated by the auditing end, the audit user permissions are encapsulated in the data packet header, and the request data packet ID corresponding to different traffic data types is encapsulated in the data segment.
[0054] For encapsulating audit user permissions in the data packet header, it is preferable to have the settings uniformly configured by the main server in the cloud environment.
[0055] The encapsulated requirement data packet ID is used to identify different traffic auditing requirements or different auditing users, such as video traffic and audio traffic.
[0056] Specifically, the data packet ID is uniformly assigned by the traffic proxy module, and this assignment information is fed back to the auditing end and the server. Thus, when the auditing end generates a traffic audit request, it can encapsulate the corresponding audit request data packet based on the ID assigned by the traffic proxy module.
[0057] For the returned traffic data packets, the audit user's permissions are encapsulated in the packet header, and the traffic data packet ID corresponding to different traffic data types is encapsulated in the data segment. The specific implementation scheme is the same as above.
[0058] Identifier ID: Orthogonal Walsh codes can be used for identification. Since Walsh codes are ordered, data packets can be bundled in order using Walsh codes and sent to users. Users can parse different types of traffic data according to the order of Walsh codes, which can save channel or network resources and improve auditing efficiency.
[0059] The identifier ID, traffic packet ID, and request packet ID here are all orthogonal Walsh codes. In the specific implementation, the number of orthogonal Walsh code bits can be selected according to the number of users to automatically generate Walsh codes.
[0060] Based on this data format, when generating and sending traffic audit requests, the auditing end of this solution can send multiple types of data traffic audit requests at once. The corresponding audit request traffic packet format can be as follows: Figure 2 The audit requirement data traffic packet format shown encapsulates the audit user's permissions in the packet header, and in the data segment, according to the type of traffic data required, it sequentially encapsulates the corresponding requirement data packet IDs for different types of traffic data.
[0061] As an example, if the auditing end needs to send N types of data traffic audit requests at once, the auditing end can generate a data traffic audit request data packet containing the audit user's permissions and the N data type requirements. For example... Figure 2 As shown, the header of this data traffic audit request data packet encapsulates the audit user's permissions, and the data segment sequentially encapsulates the corresponding N types of traffic data type request data packet ID1...request data packet ID. N .
[0062] Furthermore, when multiple auditing endpoints simultaneously send various types of data traffic auditing requests, the traffic proxy module configured in the switch sends only one traffic data packet. When the auditing endpoint receives this traffic data packet, it will parse the traffic data it needs to audit based on the assigned Walsh code.
[0063] Furthermore, the traffic proxy module in this solution can feed back different traffic data packet formats based on the current channel environment. For example, it can feed back time-division traffic data packets, such as... Figure 3 As shown; it can provide feedback on frequency-division traffic data packets, such as Figure 4 It can provide feedback on time-frequency divided traffic data packets, such as... Figure 5 As shown.
[0064] The traffic proxy-based auditing scheme proposed in this invention, in its specific implementation, registers the traffic proxy module to the server to be audited, groups the data traffic, and performs traffic auditing on demand at the auditing end, thereby improving auditing efficiency and enhancing the auditing user experience; thus effectively overcoming the problems of low auditing efficiency and poor user experience of existing schemes under 5G networks.
[0065] This solution addresses the issue of multiple auditing endpoints simultaneously sending the same traffic data packet to all auditing endpoints. This allows each auditing endpoint to parse its own traffic data as needed based on its own permissions. This effectively overcomes the problems of existing solutions consuming large amounts of channel or network resources, resulting in low auditing efficiency and increased data security risks when multiple auditing users are simultaneously auditing data in 5G networks.
[0066] This solution filters traffic packets and sets permissions, directing traffic according to actual needs. Only traffic backups that are of interest to the auditing end are sent to the auditing platform. The auditing end captures traffic packets based on permissions or actual needs, thereby performing traffic auditing. This effectively overcomes the problem of further amplification of audit data risks in the cloud environment.
[0067] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of this invention is defined by the appended claims and their equivalents.
Claims
1. A method of auditing based on a traffic proxy, characterized in that, The traffic proxy module is configured at the switch end, and the traffic identifier and user authority are set in the data packet header. The data traffic is grouped by the traffic proxy module, and the traffic is led to the audit channel according to the audit demand of the audit end. The audit end audits the traffic backup according to the demand and / or authority. The audit method comprises the following steps: (1) The traffic proxy module is configured at the switch end, and the traffic proxy module information is fed back to the server end and the audit end to be audited respectively; (2) The audit end sends a traffic audit request, and the data packet of the audit request is encapsulated with the traffic identifier and user authority; (3) The switch receives the audit request, feeds back the audit request to the configured traffic proxy module, detects the received traffic audit request data packet, and feeds back the detected audit traffic demand to the server end; (4) The server end sends the data traffic to the switch end according to the received audit traffic demand. The traffic proxy module configured at the switch end first encapsulates the received data traffic, and then sends the encapsulated data traffic to the audit end; (5) The audit end audits the data traffic after receiving the data traffic packet.
2. The traffic proxy based auditing method of claim 1, wherein, The orthogonal Walsh code is used to identify and group multiple data traffics in the audit method.
3. The traffic proxy based auditing method of claim 1, wherein, In step (3), the traffic proxy module performs orthogonal detection on the orthogonal Walsh code in the received traffic audit request data packet. If the orthogonal detection value is 0, the corresponding Walsh code identifier of the orthogonal detection is sent. Otherwise, no processing is performed.
4. The traffic proxy based auditing method of claim 1, wherein, In step (4), the server end performs orthogonal detection on the received traffic audit request of the switch. If the orthogonal detection value is 0, the corresponding Walsh code identifier of the orthogonal detection is sent. Otherwise, no processing is performed. In step (4), when the received data traffic is encapsulated, a field is added in front of each type of data traffic to identify the data traffic. The field is an orthogonal Walsh code.
5. The traffic proxy based auditing method of claim 1, wherein, In step (4), when the encapsulated data traffic is sent, in the case of good network environment, the autonomous traffic sending mode is used; in the case of network congestion, the traffic data packet is packaged and sent simultaneously.
6. The traffic proxy based auditing method of claim 1, wherein,
Citation Information
Patent Citations
Traffic auditing method, device and equipment and computer readable storage medium
CN113904787A