Method, device, electronic device and storage medium for analyzing traffic data packets
By automating the acquisition and analysis of traffic data packets, this technology solves the problems of rigid manual operation and cloud analysis in existing technologies, and achieves efficient traffic data packet analysis and visualization result generation, meeting the network security, compliance and performance requirements of Internet products.
Patent Information
- Application Number
- CN202211343778.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-31
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2042-10-31
AI Technical Summary
In the development of internet products, existing technologies have limited capabilities for troubleshooting client-side network security, compliance, and performance issues. Manually operated packet analysis tools have different functionalities, leading to difficulties in data integration, while cloud-based analysis methods are rigid and cannot meet actual business needs.
This paper provides a traffic data packet analysis method that automatically acquires traffic data packets of target network devices by obtaining traffic analysis tasks, analyzes them using traffic analysis items, and generates visualized analysis results, thereby achieving automated and on-demand analysis.
It enables automated traffic packet analysis without manual operation, improving analytical capabilities, meeting actual business needs, and enhancing analytical efficiency and accuracy.
Smart Images

Figure CN115665013B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of data analysis, and more particularly to a method, apparatus, electronic device, and storage medium for analyzing traffic data packets. Background Technology
[0002] Currently, in the development of internet products, addressing network-related security, compliance, performance, and degradation prevention issues on the client side is becoming increasingly important, but the ability to troubleshoot these problems remains limited. This primarily relies on the following two solutions:
[0003] (1) Manual packet analysis using tools such as Charles and Wireshark. (2) Analysis based on uploading packets to the cloud. However, the first method lacks process automation, requires manual operation, and different tools have different functionalities, making data integration difficult. The second method has relatively rigid analytical capabilities and cannot be analyzed according to actual business needs. Summary of the Invention
[0004] To solve the above-mentioned technical problems, or at least partially solve them, this disclosure provides a method, apparatus, electronic device, and storage medium for analyzing traffic data packets.
[0005] According to one aspect of the present disclosure, a method for analyzing traffic data packets is provided, characterized in that it includes:
[0006] Obtain a traffic analysis task and determine the target network device to be analyzed based on the traffic analysis task, wherein the traffic analysis task includes at least one traffic analysis item;
[0007] Obtain the traffic data packets transmitted by the target network device within the current time period;
[0008] Extract data content associated with the traffic analysis item from the traffic data packet, and analyze the data content to obtain the traffic analysis data corresponding to the traffic analysis item;
[0009] Based on the traffic analysis data corresponding to each of the traffic analysis items, a visual analysis result corresponding to the target network device is generated.
[0010] According to another aspect of the present disclosure, a traffic data packet analysis apparatus is also provided, comprising:
[0011] The first acquisition module is used to acquire traffic analysis tasks and determine the target network device to be analyzed based on the traffic analysis tasks, wherein the traffic analysis tasks include at least one traffic analysis item.
[0012] The second acquisition module is used to acquire the traffic data packets transmitted by the target network device within the current time period;
[0013] An extraction module is used to extract data content associated with the traffic analysis item from the traffic data packet, and analyze the data content to obtain the traffic analysis data of the traffic analysis item;
[0014] The display module is used to generate a visual analysis result for the target network device based on the traffic analysis data corresponding to each of the traffic analysis items.
[0015] According to another aspect of the embodiments of this disclosure, a storage medium is also provided, the storage medium including a stored program that executes the above steps when the program is run.
[0016] According to another aspect of the present disclosure, an electronic device is also provided, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; wherein: the memory is used to store computer programs; and the processor is used to execute the steps in the above method by running the programs stored in the memory.
[0017] This disclosure also provides a computer program product containing instructions that, when run on a computer, cause the computer to perform the steps in the above-described method.
[0018] Compared with the prior art, the technical solution provided in this disclosure has the following advantages: The method provided in this disclosure can automatically obtain traffic data packets of the target network device according to the traffic analysis task, eliminating the need for manual operation. Simultaneously, it utilizes the traffic analysis items in the traffic analysis task to analyze the traffic data packets, achieving analysis based on actual needs and improving analysis capabilities. Attached Figure Description
[0019] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.
[0020] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1 A flowchart illustrating a method for analyzing traffic data packets provided in this embodiment of the disclosure;
[0022] Figure 2A flowchart illustrating a method for analyzing traffic data packets, provided as another embodiment of this disclosure;
[0023] Figure 3 A schematic diagram of a traffic data packet analysis system provided in an embodiment of this disclosure;
[0024] Figure 4 A block diagram of a traffic data packet analysis apparatus provided in an embodiment of this disclosure;
[0025] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present disclosure. Detailed Implementation
[0026] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this disclosure. The illustrative embodiments and their descriptions are used to explain this disclosure and do not constitute an improper limitation of this disclosure. All other embodiments obtained by those skilled in the art based on the embodiments of this disclosure without creative effort are within the scope of protection of this disclosure.
[0027] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another similar entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0028] This disclosure provides a method, apparatus, electronic device, and storage medium for analyzing traffic data packets. The method provided in this disclosure can be applied to any electronic device as needed, such as a server, terminal, or other electronic device. No specific limitation is made here, and for ease of description, it will be referred to as an electronic device below.
[0029] According to one aspect of the present disclosure, a method embodiment for analyzing traffic data packets is provided. Figure 1 A flowchart of a traffic data packet analysis method provided in this disclosure embodiment is shown below. Figure 1As shown, the method includes:
[0030] Step S11: Obtain the traffic analysis task and determine the target network device to be analyzed based on the traffic analysis task, wherein the traffic analysis task includes at least one traffic analysis item.
[0031] The method provided in this disclosure is applied to a traffic analysis device. The specific process by which the traffic analysis device obtains a traffic analysis task includes: the traffic analysis device generates a traffic analysis task based on the user's traffic analysis requirements. The traffic analysis task includes at least one traffic analysis item and a device identifier. The traffic analysis device can determine the network device corresponding to the device identifier as the target network device for traffic analysis. The target network device can be a server, mobile device, router, or other device deployed on the user's side. Traffic analysis items can include geographic location, duplicate requests, domain name resolution time, etc.
[0032] Step S12: Obtain the traffic data packets transmitted by the target network device within the current time period.
[0033] In this embodiment of the disclosure, the traffic analysis device sends a packet capture instruction to the target network device based on the traffic analysis task. The target network device uploads the traffic data packets transmitted within the current time period to the cloud server according to the packet capture instruction. The traffic data packets include: source address, source port, destination address, destination port, transmission protocol, transmission content, etc.
[0034] Step S13: Extract the data content associated with the traffic analysis item from the traffic data packet, and analyze the data content to obtain the traffic analysis data corresponding to the traffic analysis item.
[0035] In this embodiment of the disclosure, after receiving traffic data packets uploaded by the target network transmission device, the traffic analysis device parses the traffic data packets to obtain multiple raw data contents carried by the traffic data packets. Then, it extracts data content matching the traffic analysis item from these multiple raw data contents. For example, if the traffic analysis item is geolocation, the associated data content could be the source address and destination address. If the traffic analysis item is a sensitive field, the associated data content could be the transmission content.
[0036] In this embodiment of the disclosure, after obtaining the data content associated with each traffic analysis item, the data content is analyzed based on the analysis strategy corresponding to each traffic analysis item to obtain the traffic analysis data corresponding to each traffic analysis item. For example, when the traffic analysis item is geolocation, the corresponding analysis strategy may be to detect whether the source address and the destination address are correct. If the destination address is an overseas address, then the geolocation is determined to be abnormal, and the destination address and the geolocation abnormality are identified as traffic analysis data.
[0037] Step S14: Based on the traffic analysis data corresponding to each traffic analysis item, generate the visualization analysis results corresponding to the target network device.
[0038] In this embodiment of the disclosure, after obtaining the traffic analysis data corresponding to each traffic analysis item, the traffic analysis device summarizes the traffic analysis data corresponding to each traffic analysis item to generate a visual analysis result corresponding to the target network device. The traffic analysis device can then display the generated visual analysis result.
[0039] The method provided in this disclosure can automatically acquire traffic data packets of a target network device based on a traffic analysis task, eliminating the need for manual operation. Simultaneously, it utilizes traffic analysis items within the traffic analysis task to analyze the traffic data packets, enabling analysis based on actual needs and improving analytical capabilities.
[0040] Figure 2 A flowchart of a traffic data packet analysis method provided in this disclosure embodiment is shown below. Figure 2 As shown, the method includes:
[0041] Step S21: Obtain the traffic analysis task and determine the target network device to be analyzed based on the traffic analysis task, wherein the traffic analysis task includes at least one traffic analysis item.
[0042] In this embodiment of the disclosure, step S21, obtaining a traffic analysis task, includes the following steps: receiving a traffic analysis request. In response to the traffic analysis request, a task configuration interface is displayed. Based on the task configuration interface, a target device identifier and traffic analysis requirements are obtained, and at least one traffic analysis item matching the traffic analysis requirements is obtained from a set of traffic analysis items, wherein the target device identifier is used to determine the target network device to be analyzed. A traffic analysis task is generated based on the target device identifier and the traffic analysis requirements.
[0043] In this embodiment, the traffic analysis device receives a traffic analysis request created by a user, responds to the request, and displays a task configuration interface. The task configuration interface includes a device identifier list. The currently selected device identifier can be determined by detecting selection operations in the device identifier list, and this selected device identifier is identified as the target device identifier. Additionally, the task configuration interface includes a requirement input box. The user-inputted traffic analysis requirement is obtained through this input box, and the analysis type and at least one requirement information are retrieved from the requirement. The classification types include content analysis and performance analysis. Next, the set of traffic analysis items corresponding to the analysis type is obtained, and the traffic analysis items associated with the requirement information are queried from the set of traffic analysis items.
[0044] In this embodiment, when no traffic analysis item matches the required information in the traffic analysis item set, the traffic analysis device displays an analysis item customization page. Based on the customization page, the device can obtain the user-uploaded configuration file, determine the currently customized traffic analysis item, and configure the analysis strategy for that traffic analysis item. Finally, the configured traffic analysis item is updated to the traffic analysis item set. Ultimately, a traffic analysis task is generated based on the obtained target device identifier and traffic analysis item.
[0045] Step S22: Obtain the traffic data packets transmitted by the target network device within the current time period.
[0046] In this embodiment of the disclosure, step S22, obtaining the traffic data packets transmitted by the target network device within the current time period, includes the following steps A1-A4:
[0047] Step A1: Obtain the target device identifier corresponding to the target network device from the traffic analysis task.
[0048] Step A2: Generate packet capture instructions based on the target device identifier.
[0049] Step A3: Send a packet capture command to the agent program deployed on the target network device, so that the agent program can capture the traffic data packets of the target network device in the current time period based on the packet capture command and upload the traffic data packets.
[0050] Step A4: Receive the traffic data packets uploaded by the proxy program based on the packet capture command.
[0051] In this embodiment, during the acquisition of traffic data packets, the traffic analysis device obtains the target device identifier corresponding to the target network device from the traffic analysis task and generates a packet capture command based on the target device identifier. The packet capture command is then sent to the agent program deployed on the target network device. The agent program uses the libpcap network packet capture function to collect traffic data packets. Specifically, the libpcap network packet capture function first uses pre-created Socket bytecode to copy the traffic data packets transmitted in the current time period from the link layer driver of the target network device and copies the copied traffic data packets to the kernel buffer. Upon receiving the packet capture command, the agent program directly obtains the traffic data packets from the kernel buffer and uploads them to the traffic analysis device using the GRPC Stream mode.
[0052] Step S23: Extract the data content associated with the traffic analysis item from the traffic data packet, and analyze the data content to obtain the traffic analysis data corresponding to the traffic analysis item.
[0053] In this embodiment of the disclosure, data content associated with traffic analysis items is extracted from traffic data packets, and the data content is analyzed to obtain traffic analysis data corresponding to the traffic analysis items, including the following steps B1-B4:
[0054] Step B1: Determine the target type of the traffic data packet based on its format information.
[0055] Step B2: Based on the correspondence between preset types and processing strategies, determine the target processing strategy corresponding to the target type.
[0056] Step B3: Use the target processing strategy to map traffic data packets into transmission data, and generate a data stream based on the transmission data.
[0057] Step B4: Extract the data content associated with each traffic analysis item from the data stream, and analyze the data content to obtain the traffic analysis results.
[0058] In this embodiment of the disclosure, to ensure the accuracy of traffic analysis results, the traffic analysis device first parses the format information of the traffic data packets and determines the corresponding target type of the traffic data packets based on the format information. The target type includes Transmission Control Protocol (TCP) and User Datagram Protocol (UDP). For example, TCP traffic data packets have a 20-byte header, while UDP traffic data packets have an 8-byte header. Based on this, the target type of the traffic data packets can be determined.
[0059] In this embodiment of the disclosure, when the target type is a transmission control protocol type, the traffic data packets are mapped to transmission data using a target processing strategy, and a data stream is generated based on the transmission data. This includes: filtering abnormal traffic data packets belonging to the retransmission type and / or packet loss type from the traffic data packets to obtain remaining traffic data packets; obtaining at least one key component information in each remaining traffic data packet, generating transmission data based on the key component information, and determining the transmission sequence number of the transmission data based on the data packet identifier of the remaining traffic data packets; and arranging the transmission data according to the transmission sequence number to generate a data stream.
[0060] It should be noted that when the target type is TCP, some retransmitted or lost packets in the traffic data may affect the accuracy of the traffic analysis results. For example, the traffic data in the current time period may include: traffic data P1, traffic data P2, traffic data P3, and traffic data P5. Filtering these traffic data results in the remaining traffic data including: traffic data P1, traffic data P2, and traffic data P3. Then, the key component information of each remaining traffic data is obtained, and the corresponding transmission data is generated based on this information. The key component information includes: source address, destination address, source port, destination port, and transmission protocol. Finally, the sequence number of the transmitted data is determined using the packet identifier of the remaining traffic data, and the transmitted data is arranged according to the sequence number to generate a data stream.
[0061] In this embodiment of the disclosure, when the target type is a user data packet, the traffic data packet is split into a data stream arranged according to a preset time interval using a target processing strategy, including: obtaining at least one key component information in each traffic data packet, generating transmission data based on the key component information, and determining the transmission sequence number of the transmission data based on the data packet identifier of the traffic data packet; and arranging the transmission data according to the transmission sequence number to generate a data stream.
[0062] It should be noted that due to the nature of UDP, traffic analysis devices cannot distinguish whether UDP traffic packets are retransmitted. Therefore, they directly extract the key components of each traffic packet, including: source address, destination address, source port, destination port, and transport protocol. This key component information is used to generate transmission data. Finally, the packet identifier of the traffic packet is used to determine the sequence number of the transmitted data, and the transmitted data is arranged according to the sequence number to generate a data stream.
[0063] Step S24: Based on the traffic analysis data corresponding to each traffic analysis item, generate the visualized analysis results corresponding to the target network device. For detailed explanation, please refer to the relevant descriptions in the above embodiments; they will not be repeated here.
[0064] In this embodiment of the disclosure, after generating the visual analysis results corresponding to the target network device based on the traffic analysis data corresponding to each traffic analysis item, the method further includes the following steps C1-C4:
[0065] Step C1: Obtain at least one target traffic problem currently existing in the target network device from the visualization analysis results. The target traffic problem includes a traffic problem label and a traffic problem description corresponding to the traffic problem label.
[0066] Step C2: Based on the pre-defined correspondence between traffic problem tags and priorities, determine the priority corresponding to the traffic problem tag, and display the target traffic problem according to the priority.
[0067] Step C3: Determine the traffic problem to be processed from at least one target traffic problem based on the processing request, wherein the processing request is generated based on the triggering operation applied to the currently displayed target traffic problem.
[0068] Step C4: Send the traffic problem to be processed to the target processing device so that the target processing device can obtain the problem repair strategy corresponding to the target problem description in the traffic problem to be processed, and perform traffic repair operation using the problem repair strategy.
[0069] In this embodiment of the disclosure, at least one target traffic problem currently existing in the target network device is obtained from the visualization analysis results. The target traffic problem includes: a traffic problem label and a traffic problem description corresponding to the traffic problem label.
[0070] For example: Target traffic issues include: (1) Traffic issue tag: API request uses HTTP, the corresponding traffic issue description is: if the corresponding Mine application and json are not used, and HTTP is not used. (2) Traffic issue tag: IP geolocation, the corresponding traffic issue description is the geolocation of the access request. (3) Traffic issue tag: Duplicate request, the corresponding traffic issue description is: repeatedly initiating a connection to the same URL within 1 second. (4) Traffic issue tag: DNS resolution result is empty, the corresponding traffic issue description is: there is no resolution result in the DNS resolution response packet. (5) Traffic issue tag: HTTP response packet body is too large, the corresponding traffic issue description is: HTTP response image class is greater than 50k, JSON is greater than 10k, video is greater than 20000K. (6) Traffic issue tag: DNS resolution time is too long, the corresponding traffic issue description is: DNS resolution time exceeds 100ms.
[0071] In this embodiment, the priority of each traffic problem label is determined based on the predefined correspondence between traffic problem labels and priorities. The target traffic problem (1), target traffic problem (2), target traffic problem (3), and target traffic problem (4) have the first priority. The target traffic problem (5) and target traffic problem (6) have the second priority. The first priority is greater than the second priority. Then, the target traffic problems are displayed based on their priorities.
[0072] In this embodiment of the disclosure, after displaying the target traffic problem, a triggering operation acting on the target traffic problem is detected. The triggering operation may be a selection operation. A processing request is generated based on the triggering operation, and the traffic problem to be processed is determined based on the processing request. Then, the traffic analysis device sends the traffic problem to be processed to the target processing device, which may be a device for handling traffic anomalies. After obtaining the traffic problem to be processed, the target processing device extracts the target problem description from the traffic problem to be processed, obtains the problem repair strategy corresponding to the target problem description, and executes the traffic repair operation using the problem repair strategy.
[0073] This disclosure embodiment displays traffic issues in the visualization results, enabling users to intuitively identify which issues are abnormal. It also facilitates users in sending traffic issues to be processed to the corresponding processing devices, effectively improving the processing efficiency of abnormal traffic.
[0074] Figure 3 A traffic data packet analysis system provided in this disclosure embodiment, such as Figure 3 As shown, the system includes a traffic analysis device and a target network device. The traffic analysis device includes a smart terminal 100 and a cloud server 200. The target network device 300 can be a server, a mobile device, or a router.
[0075] The smart terminal 100 generates a traffic analysis task and sends the traffic analysis task to the cloud server 200. The traffic analysis task includes: target device identifier and at least one traffic analysis item.
[0076] The cloud server 200 receives the traffic analysis task, determines the target network device to be analyzed based on the target device identifier in the traffic analysis task, and sends a packet capture command to the target network device.
[0077] After the agent program in the target network device 300 listens to the packet capture command, it captures the traffic data packets transmitted by the target network device 300 in the current time period according to the packet capture command, and uploads the traffic data packets to the cloud server.
[0078] The cloud server 200 extracts data content associated with traffic analysis items from traffic data packets and analyzes the data content to obtain traffic analysis data for each traffic analysis item. Based on the traffic analysis data corresponding to each traffic analysis item, it generates a visual analysis result for the target network device and sends the visual analysis result to a smart terminal for display.
[0079] Figure 4 This is a block diagram of a traffic data packet analysis apparatus provided in an embodiment of the present disclosure. This apparatus can be implemented as part or all of an electronic device through software, hardware, or a combination of both. Figure 4 As shown, the device includes:
[0080] The first acquisition module 41 is used to acquire traffic analysis tasks and determine the target network device to be analyzed based on the traffic analysis tasks, wherein the traffic analysis tasks include at least one traffic analysis item.
[0081] The second acquisition module 42 is used to acquire the traffic data packets transmitted by the target network device within the current time period.
[0082] Extraction module 43 is used to extract data content associated with traffic analysis items from traffic data packets and analyze the data content to obtain traffic analysis data of traffic analysis items.
[0083] Display module 44 is used to generate visual analysis results for the target network device based on the traffic analysis data corresponding to each traffic analysis item.
[0084] In this embodiment of the disclosure, the first acquisition module 41 is configured to receive a traffic analysis request; respond to the traffic analysis request and display a task configuration interface based on the traffic analysis request; acquire the target device identifier and traffic analysis requirements based on the task configuration interface, and acquire at least one traffic analysis item matching the traffic analysis requirements from the traffic analysis item set, wherein the target device identifier is used to determine the target network device to be analyzed; and generate a traffic analysis task based on the device identifier and traffic analysis requirements.
[0085] In this embodiment of the disclosure, the second acquisition module 42 is used to acquire the device identifier corresponding to the target network device from the traffic analysis task; generate a packet capture instruction based on the device identifier; send the packet capture instruction to the agent program deployed on the target network device, so that the agent program captures the traffic data packets of the target network device in the current time period based on the packet capture instruction and uploads the traffic data packets; and receive the traffic data packets uploaded by the agent program based on the packet capture instruction.
[0086] In this embodiment of the disclosure, the extraction module 43 is used to determine the target type corresponding to the traffic data packet based on the format information of the traffic data packet; determine the target processing strategy corresponding to the target type based on the correspondence between the preset type and the processing strategy; map the traffic data packet to the transmission data using the target processing strategy, and generate a data stream based on the transmission data; extract the data content associated with each traffic analysis item from the data stream, and analyze the data content to obtain the traffic analysis result.
[0087] In this embodiment of the disclosure, when the target type is a transmission control protocol type, the extraction module 43 is used to filter abnormal traffic data packets belonging to the retransmission type and / or packet loss type from the traffic data packets to obtain the remaining traffic data packets; obtain at least one key component information in each remaining traffic data packet, generate transmission data based on the key component information, and determine the transmission sequence number of the transmission data based on the data packet identifier of the remaining traffic data packets; and arrange the transmission data according to the transmission sequence number to generate a data stream.
[0088] In this embodiment of the disclosure, when the target type is a user data packet, the extraction module 43 is used to obtain at least one key component information in each traffic data packet, generate transmission data based on the key component information, and determine the transmission sequence number of the transmission data based on the data packet identifier of the traffic data packet; and arrange the transmission data according to the transmission sequence number to generate a data stream.
[0089] In this embodiment of the present disclosure, the apparatus further includes: a processing module, configured to obtain at least one target traffic problem currently existing in the target network device from the visualization analysis results, wherein the target traffic problem includes a traffic problem label and a traffic problem description corresponding to the traffic problem label; determine the priority corresponding to the traffic problem label based on a preset correspondence between traffic problem labels and priorities, and display the target traffic problems according to the priority; determine a traffic problem to be processed from the at least one target traffic problem according to a processing request, wherein the processing request is generated based on a trigger operation acting on the currently displayed target traffic problem; and send the traffic problem to be processed to the target processing device, so that the target processing device obtains the problem repair strategy corresponding to the target problem description in the traffic problem to be processed, and performs a traffic repair operation using the problem repair strategy.
[0090] This disclosure also provides an electronic device, such as... Figure 5 As shown, the electronic device may include: a processor 1501, a communication interface 1502, a memory 1503, and a communication bus 1504, wherein the processor 1501, the communication interface 1502, and the memory 1503 communicate with each other through the communication bus 1504.
[0091] Memory 1503 is used to store computer programs;
[0092] When the processor 1501 executes the computer program stored in the memory 1503, it implements the steps of the above embodiments.
[0093] The communication bus mentioned in the above terminal can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 5 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0094] The communication interface is used for communication between the aforementioned terminal and other devices.
[0095] The memory may include random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.
[0096] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0097] In another embodiment provided in this disclosure, a computer-readable storage medium is also provided, which stores instructions that, when executed on a computer, cause the computer to perform the traffic data packet analysis method described in any of the above embodiments.
[0098] In yet another embodiment provided in this disclosure, a computer program product containing instructions is also provided, which, when run on a computer, causes the computer to execute the traffic data packet analysis method described in any of the above embodiments.
[0099] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this disclosure are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk).
[0100] The above description is merely a preferred embodiment of this disclosure and is not intended to limit the scope of protection of this disclosure. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure are included within the scope of protection of this disclosure.
[0101] The above description is merely a specific embodiment of this disclosure, enabling those skilled in the art to understand or implement it. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this disclosure. Therefore, this disclosure is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.
Claims
1. A method for analyzing traffic data packets, characterized in that, include: Obtain a traffic analysis task and determine the target network device to be analyzed based on the traffic analysis task, wherein the traffic analysis task includes at least one traffic analysis item; Obtain the traffic data packets transmitted by the target network device within the current time period; Extract data content associated with the traffic analysis item from the traffic data packet, and analyze the data content to obtain the traffic analysis data corresponding to the traffic analysis item; Based on the traffic analysis data corresponding to each of the traffic analysis items, a visual analysis result corresponding to the target network device is generated. After generating a visual analysis result for the target network device based on the traffic analysis data corresponding to each traffic analysis item, the method further includes: obtaining at least one target traffic problem currently existing in the target network device from the visual analysis result, wherein the target traffic problem includes a traffic problem label and a traffic problem description corresponding to the traffic problem label; determining the priority corresponding to the traffic problem label based on a preset correspondence between traffic problem labels and priorities, and displaying the target traffic problem according to the priority; determining a traffic problem to be processed from at least one of the target traffic problems according to a processing request, wherein the processing request is generated based on a trigger operation applied to the currently displayed target traffic problem; sending the traffic problem to be processed to the target processing device, so that the target processing device obtains the problem repair strategy corresponding to the target problem description in the traffic problem to be processed, and performs a traffic repair operation using the problem repair strategy.
2. The method according to claim 1, characterized in that, The traffic analysis task includes: Receive traffic analysis requests; In response to the traffic analysis request, the task configuration interface is displayed; Based on the task configuration interface, the target device identifier and traffic analysis requirements are obtained, and at least one traffic analysis item matching the traffic analysis requirements is obtained from the traffic analysis item set, wherein the target device identifier is used to determine the target network device to be analyzed. The traffic analysis task is generated based on the target device identifier and the traffic analysis requirements.
3. The method according to claim 1, characterized in that, The step of obtaining the traffic data packets transmitted by the target network device within the current time period includes: Obtain the target device identifier corresponding to the target network device from the traffic analysis task; Generate packet capture instructions based on the target device identifier; The packet capture command is sent to the agent program deployed on the target network device, so that the agent program captures the traffic data packets of the target network device in the current time period based on the packet capture command and uploads the traffic data packets; Receive the traffic data packets uploaded by the agent program based on the packet capture command.
4. The method according to claim 1, characterized in that, The step of extracting data content associated with the traffic analysis item from the traffic data packet and analyzing the data content to obtain traffic analysis data corresponding to the traffic analysis item includes: The target type corresponding to the traffic data packet is determined based on the format information of the traffic data packet. Based on the correspondence between preset types and processing strategies, the target processing strategy corresponding to the target type is determined; The target processing strategy is used to map the traffic data packets into transmission data, and a data stream is generated based on the transmission data; Extract the data content associated with each of the traffic analysis items from the data stream, and analyze the data content to obtain the traffic analysis results.
5. The method according to claim 4, characterized in that, When the target type is a Transmission Control Protocol type, the step of mapping the traffic data packets to transmission data using the target processing strategy and generating a data stream based on the transmission data includes: Filter out abnormal traffic data packets belonging to the retransmission type and / or packet loss type from the traffic data packets to obtain the remaining traffic data packets; Obtain at least one key component information from each of the remaining traffic data packets, generate transmission data based on the key component information, and determine the transmission sequence number of the transmission data based on the data packet identifier of the remaining traffic data packets; The transmitted data is arranged according to the transmission sequence number to generate the data stream.
6. The method according to claim 4, characterized in that, When the target type is a user datagram, the step of splitting the traffic data packet into a data stream arranged according to a preset time interval using the target processing strategy includes: Obtain at least one key component information from each traffic data packet, generate transmission data based on the key component information, and determine the transmission sequence number of the transmission data based on the data packet identifier of the traffic data packet; The transmitted data is arranged according to the transmission sequence number to generate the data stream.
7. A device for analyzing traffic data packets, characterized in that, include: The first acquisition module is used to acquire traffic analysis tasks and determine the target network device to be analyzed based on the traffic analysis tasks, wherein the traffic analysis tasks include at least one traffic analysis item. The second acquisition module is used to acquire the traffic data packets transmitted by the target network device within the current time period; An extraction module is used to extract data content associated with the traffic analysis item from the traffic data packet, and analyze the data content to obtain the traffic analysis data of the traffic analysis item; The display module is used to generate a visual analysis result corresponding to the target network device based on the traffic analysis data corresponding to each of the traffic analysis items; The device further includes: a processing module, configured to obtain at least one target traffic problem currently existing in the target network device from the visualization analysis results, wherein the target traffic problem includes a traffic problem label and a traffic problem description corresponding to the traffic problem label; determine the priority corresponding to the traffic problem label based on a preset correspondence between traffic problem labels and priorities, and display the target traffic problem according to the priority; determine a traffic problem to be processed from at least one of the target traffic problems according to a processing request, wherein the processing request is generated based on a trigger operation acting on the currently displayed target traffic problem; and send the traffic problem to be processed to a target processing device, so that the target processing device obtains the problem repair strategy corresponding to the target problem description in the traffic problem to be processed, and performs a traffic repair operation using the problem repair strategy.
8. A storage medium, characterized in that, The storage medium includes a stored program, wherein the program executes the method according to any one of claims 1 to 6 when it is run.
9. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, communication interface, and memory communicate with each other through the communication bus; wherein: Memory, used to store computer programs; A processor for performing the method of any one of claims 1 to 6 by running a program stored in memory.
Citation Information
Patent Citations
Network traffic feature generation method and device
CN111565311A
Abnormal traffic detection method and device and storage medium
CN111756706A