A network security access device

Through dynamic Hash tables and recursive zipper methods, the TCP connection tracking of network service devices is optimized, the Hash conflict problem is solved, the device's concurrency processing capability and the query efficiency of security policies are improved, and efficient network access and security protection are achieved.

CN115801283BActive Publication Date: 2025-07-18WUHAN MARITIME COMMUNICATION RESEARCH INSTITUTE
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211510333.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-29
Publication Date
2025-07-18
Estimated Expiration
2042-11-29

AI Technical Summary

Technical Problem

When the number of concurrent connections of existing network service equipment reaches a certain order of magnitude, the number of Hash conflict table entries increases sharply, resulting in the inability to achieve the table lookup rate of O(1), affecting the equipment processing efficiency and service quality.

Method used

Dynamic Hash tables are used for TCP connection tracking, Hash values are calculated through subnet classification, secondary Hash table structure is established, and conflicts are resolved using recursive zipper method, and security policy tables are optimized based on policy conflict detection and auxiliary decision-making technology.

Benefits of technology

It improves the Hash table access hit rate, enhances the device's concurrent access processing capability and throughput requested by network user, optimizes the device's running speed and the real-time access query efficiency of security policies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115801283B_ABST
    Figure CN115801283B_ABST
Patent Text Reader

Abstract

The present invention discloses a network security access device, belonging to the field of computer IP network security applications. The network security access device performs TCP connection tracking based on a dynamic Hash table, including: classifying the maintained TCP connections once according to the subnets where the IP addresses are located, calculating the Hash value according to the subnets, and storing the subnet information in the nodes of the root Hash table; calculating the Hash value using the five-tuple (source IP, destination IP, source port, destination port, protocol number) of the TCP connection, and storing the TCP connection information in the sub-Hash table pointed to by the corresponding node of the root Hash. The dynamic two-level Hash table can reduce the occurrence of Hash value conflicts, improve the access hit rate of the Hash table, and achieve the main purpose of improving the access throughput of network user requests and the concurrent access processing capacity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer IP network security applications, and more specifically, relates to a network security access device. Background Art

[0002] Network service devices (such as network firewalls, switches, etc.) generally manage and maintain two tables: a user connection request table and a security policy table. The user connection table records user TCP / UDP connection request information. The two tables usually exist in a cache area in the form of a common two-dimensional table or a Hash table; the policy table stores boundary protection policy information, which usually consists of three parts: a rule number, a rule domain, and an action, where the rule domain contains five-tuple information (source IP, destination IP, source port, destination port, protocol). In actual business, as the number of customers of the network service device increases and the running time grows, the quantity of the above table information will increase sharply, and the number of conflicting table entries will also increase sharply, so that it is impossible to achieve an O(1) table lookup rate, difficult to achieve wire speed processing, and further cause the device running speed to decrease, affecting the device processing efficiency and service quality. Summary of the Invention

[0003] Aiming at the defects of the prior art, the purpose of the present invention is to provide a network security access device, aiming to solve the problem that when the number of concurrent connections processed by the device reaches a certain order of magnitude, the number of Hash conflict table entries will increase sharply, so that it is impossible to achieve an O(1) table lookup rate, and thus difficult to achieve wire speed processing.

[0004] To achieve the above purpose, the present invention provides a network security access device, and the network security access device performs TCP connection tracking based on a dynamic Hash table, specifically as follows:

[0005] The user connection request table maintains TCP connection information, classifies it once according to the subnet where the IP address is located, calculates the Hash value according to the subnet, and stores the subnet information in the node of the root Hash table;

[0006] Calculate the Hash value using the five-tuple (source IP, destination IP, source port, destination port, protocol number) of the TCP connection, and store the TCP connection information in the sub-Hash table pointed to by the corresponding node of the root Hash.

[0007] Preferably, create a Hash index table according to the corresponding relationship between the subnet and the Hash table. The Hash index table resides in memory and forms a two-level storage structure with the Hash storage table on the hard disk.

[0008] Preferably, when querying, query the index table according to the subnet information to find the corresponding Hash storage table address, read and load the Hash storage table from the hard disk space into the memory, and retrieve the result from the Hash storage table using the Hash algorithm function.

[0009] Preferably, when keyword conflicts occur, the chaining method is used again to calculate the address, which is stored in an array space pointed to.

[0010] Preferably, the rules in the security policy table on the network security access device include: rule serial number, filtering field, action field, total rule hit rate, and rule hit rate in the most recent time period;

[0011] The total rule hit rate is the total number of hits corresponding to the rule / the total number of rule hits of the device;

[0012] The rule hit rate in the most recent time period is the total number of hits corresponding to the rule in the most recent time period / the total number of rule hits of the device in the most recent time period.

[0013] Preferably, the network security access device makes policy-assisted decisions in the following way: automatically polling, counting, and monitoring the total rule hit rate and / or the rule hit rate in the most recent time period through a background program, and merging or deleting the rules that meet the screening conditions.

[0014] Preferably, the network security access device detects policy conflicts in the following way:

[0015] Each rule is converted into a filtering field set A = {source IP address, source port, destination IP address, destination port, protocol type} and an action field set B = {action};

[0016] If the filtering field sets of two rules are completely matched or inclusively matched, further determine whether their action field sets are the same. If they are the same, it is a redundant exception; otherwise, it is a shielding exception;

[0017] If the filtering field sets of two rules are cross-matched and the action field sets are different, it is a cross exception;

[0018] Other situations are all normal.

[0019] Generally speaking, compared with the prior art by the above technical solutions conceived by the present invention, the following beneficial effects are achieved:

[0020] The present invention provides a network security access device. The network security access device performs TCP connection tracking based on a dynamic Hash table as follows: The user connection request table maintains TCP connection information, classifies it once according to the subnet where the IP address is located, calculates the Hash value according to the subnet, and stores the subnet information in the nodes of the root Hash table; calculates the Hash value using the five-tuple (source IP, destination IP, source port, destination port, protocol number) of the TCP connection, and stores the TCP connection information in the sub-Hash table pointed to by the corresponding node of the root Hash. The dynamic two-level Hash table reduces the occurrence of Hash value conflicts, improves the access hit rate of the Hash table, and achieves the main purpose of improving the throughput of network user request access and the concurrent access processing ability. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 FIG. is a schematic diagram of the session storage principle of the two-dimensional Hash table provided by the present invention.

[0022] Figure 2 FIG. is a schematic diagram of the fast query of the Hash table provided by the present invention.

[0023] Figure 3 FIG. is a schematic diagram of the recursive zipper method provided by the present invention.

[0024] Figure 4 FIG. is a schematic diagram of the process of the linear traversal method for policy anomaly detection provided by the present invention.

[0025] Figure 5 FIG. is a schematic diagram of the process of the tree matching method for policy anomaly detection provided by the present invention.

[0026] Figure 6 FIG. is a schematic diagram of the intelligent optimization of the policy rules provided by the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0027] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0028] As Figure 1 shown, the present invention adopts the idea of a dynamic Hash table (DHT, Dynamic Hash Table), uses the subnet of the user IP address as the key value to create a first-level Hash root table (Root, Hash), and then uses the five-tuple as the key value within the root Hash table to create a second-level Hash sub-table, thereby avoiding most Hash table conflicts, greatly reducing the occurrence probability of conflicts, and improving the device throughput.

[0029] Through this method, first, the TCP connection information maintained in the user connection table is classified once according to the subnet where the IP address is located, and the Hash value is calculated according to the subnet. The subnet information is stored in a certain node NodeA of the root Hash table (primary Hash table). Then, the Hash value is calculated using the five-tuple of the TCP connection, and the TCP connection information is stored in the secondary Hash table pointed to by node Node A. This technology can effectively improve the concurrent processing ability in the case of weak processing power of domestic CPUs.

[0030] In addition, as Figure 2 shown, a Hash index table can be created between the subnet and the Hash table. This index table resides in memory permanently and forms a secondary storage structure with the Hash storage table on the hard disk. When a query is made, the corresponding Hash storage table address is found by querying the index table according to the subnet information. The Hash storage table is read from the hard disk space and loaded into memory, and the result is quickly retrieved from the Hash storage table using the Hash algorithm function, improving the retrieval rate of key resources and greatly shortening the query time of the Hash table.

[0031] Two different keywords are mapped to the same table position due to the same hash function, which is called conflict or collision. The chaining method is a traditional method to solve the conflict problem. All nodes with synonymous keywords are placed in the same linked list. However, the chaining method has some disadvantages. If a conflict occurs in a single linked list, the problem cannot be solved.

[0032] As Figure 3 shown, the present invention adopts the recursive chaining method to solve the above problems. Its basic idea is as follows: when a keyword conflict occurs, the chaining method is used again to calculate the address and store it in an array space pointed to. The recursive chaining method is to recursively apply the chaining method in a hash table, which can well solve the address conflict problem in the hash table. It can not only well solve the storage method problem of synonyms in the backup space but also well solve the address conflict problem among synonyms, improving the chaining method and making full use of and optimizing the chaining method.

[0033] In practical applications, in addition to the user request table, as the device runs for a longer time, the entries in the security policy table will also increase sharply, which will bring two types of problems: one is the conflict of security protection policies. It is difficult to consider all firewall policies during deployment and operation, and it is easy to cause conflicts between the firewall security protection policies formulated at different times. The other is that it is difficult for the device to judge and delete useless policies, resulting in an increase in the device's table lookup time operation and a decrease in the running speed.

[0034] To address the above problems, the present invention adopts the following two technologies: one is the policy conflict detection technology, and the other is the policy-assisted decision-making technology.

[0035] Common methods for policy conflict detection technology currently include: rule detection algorithms based on decision tree models, anomaly detection algorithms based on induction, anomaly detection algorithms based on Trie trees, etc. These algorithms are currently relatively commonly used, and their basic idea is to introduce the concept of sets. The policy conflict detection technology proposed in the present invention defines each line of the policy rule as a series of sets, detects the rule conflict situation by judging the relationship between the sets, and adopts two implementation methods of linear traversal and non-linear decision tree respectively according to the scale of the policy rule, and automatically adapts and applies according to the rule scale.

[0036] As Figure 4 shown, the basic idea of the linear traversal method is as follows: Assume any two rules r and s in the policy rule library, then after analyzing them, a judgment can be made. When the number of policy rules is less than 1000, due to the low real-time requirement for policy addition and working on the control plane, the above linear traversal method can be used for policy conflict detection, so it will not affect the device performance.

[0037] When the number of policy rules is greater than 1000 or the number of rules is larger, the performance of the linear matching method is very poor. Through test data, it shows that when the number of rules reaches 2000, the system performance drops significantly by 40%. In the case of the reduction of the main frequency and performance of the domestic processor, the performance bottleneck of this linear matching method becomes more prominent. At this time, the non-linear decision tree rule matching method can be adopted, and by means of the tree structure to search the tree, the matching algorithm can be optimized in terms of performance. Implementation steps:

[0038] 1) Rule definition:

[0039] 1: equal(syn, 0) & contain(load, “Drop”);

[0040] 2: equal(syn, 0) & contail(load, “Alert”);

[0041] 3: equal(syn, 1) & equal(port, 5001);

[0042] 4: equal(syn, 1) & equal(port, 5002).

[0043] Among them, the equal(A, B) function represents judging whether A and B are equal, and the contain(C, D) function represents judging whether field D is contained in C.

[0044] 2) Organize the rules into a rule tree, as Figure 5 shown.

[0045] When the number of rules is N, the complexity of the tree matching algorithm is O(log N), and the complexity of the linear matching algorithm is O(N). As the number of rules increases, the growth rate of the consumption time of tree matching is much lower than that of linear matching. Test data shows that when the number of rules reaches 2000, the system performance drops by less than 15% compared with the system performance when the number of rules is 1, which is much better than the performance of the linear algorithm.

[0046] The policy-assisted decision-making technology proposed by the present invention. The effect evaluation after policy addition is one of the important functions of future network devices. Therefore, the rule optimization is carried out in the manner as Figure 6 shown. After the optimization of the protection policy table of the rules, see Table 1, and two indicators, namely the rule hit rate and the recent (the time period can be configured, such as the recent 1 week or recent 1 month up to the current date) rule hit rate, are added.

[0047] Table 1

[0048]

[0049] During network access detection, when a policy rule is hit, the "recent rule hit count" and "total hit count" stored in the database are updated. The rule hit rate is the overall rule hit rate of the device, and the calculation method is the total number of hits corresponding to the rule / the total number of rule hits of the device. The rule hit rate in the recent 1 month is the total number of hits corresponding to the rule in the recent 1 month / the total number of rule hits of the device in the recent 1 month. Through the above two indicators, the service background program running in the device automatically polls, statistics, and monitors the database table fields, and performs optimization processing such as merging and deleting rules, which will provide great help for eliminating invalid rules, effectively reducing the number of rules for device maintenance, and thus improving the real-time access query and processing efficiency of the security protection policy during identity authentication and secure access services between network devices.

[0050] Those skilled in the art can easily understand that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A network security access device, characterized in that, The network security access device performs TCP connection tracking based on a dynamic Hash table, as follows: The user connection request table maintains TCP connection information, classifies it once according to the subnet where the IP address is located, calculates the Hash value according to the subnet, and stores the subnet information in the nodes of the root Hash table; Calculate the Hash value using the five-tuple of the TCP connection (source IP, destination IP, source port, destination port, protocol number), and store the TCP connection information in the sub-Hash table pointed to by the corresponding node of the root Hash; Create a Hash index table according to the corresponding relationship between the subnet and the root Hash table. The Hash index table resides in memory permanently and forms a two-level storage structure with the Hash storage table on the hard disk; When querying, query the index table according to the subnet information to find the corresponding Hash storage table address, read and load the Hash storage table from the hard disk space into memory, and retrieve the result from the Hash storage table using the hash algorithm function.

2. The network security access device according to claim 1, characterized in that, When a keyword conflict occurs, the zipper method is used again to calculate the address and store it in an array space pointed to.

3. The network security access device according to claim 1 or 2, characterized in that The rules in the security policy table on the network security access device include: rule serial number, filtering domain, action domain, total rule hit rate, and rule hit rate in the most recent time period; The total rule hit rate is the total number of hits corresponding to this rule / the total number of rule hits of the device; The rule hit rate in the most recent time period is the total number of hits corresponding to this rule in the most recent time period / the total number of rule hits of the device in the most recent time period.

4. The network security access device according to claim 3, characterized in that, The network security access device makes policy-assisted decisions in the following way: automatically poll, count, and monitor the total rule hit rate and / or the rule hit rate in the most recent time period through a background program, and merge or delete the rules that meet the screening conditions.

5. The network security access device according to claim 3, characterized in that, The network security access device detects policy conflicts in the following way: Convert each rule into a filtering domain set A = {source IP address, source port, destination IP address, destination port, protocol type} and an action domain set B = {action}; If the filtering domain sets of two rules are completely matched or inclusively matched, further determine whether their action domain sets are the same. If they are the same, it is a redundant exception; otherwise, it is a shielding exception; If the filtering domain sets of two rules are cross-matched and the action domain sets are different, it is a cross exception; Other situations are all normal.

Citation Information

Patent Citations

  • Method and device for searching IP (Internet Protocol) address

    CN102307250A

  • Flow table rapid searching method and system under high-concurrency network environment

    CN106059957A