An FTP-based connection communication method and device
By analyzing and hashing the ftp data request, determining the connection type of the ftp data request, the problem that the proxy server cannot distinguish between control connections and data connections is solved, and the file security release and status recognition is realized, and the processing efficiency of the proxy server is improved.
Patent Information
- Application Number
- CN202211453428.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-21
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2042-11-21
AI Technical Summary
When multiple users transfer files at the same time, the proxy server cannot distinguish between control connections and data connections, resulting in file name judgment errors and transmission status unknown, and the server cannot determine the data connection when responding abnormally.
By analyzing the ftp data request, the hash value is calculated to detect the control connection information, determine the data connection request, and the pointer of the connection data structure points to the data connection structure, receives the data file, and performs legality detection and hash value association storage at the same time.
It improves the efficiency of connection type detection, realizes file security release and status recognition, solves the problems of file name judgment errors and unknown transmission status, and improves the processing efficiency of proxy servers.
Smart Images

Figure CN115834570B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to an FTP-based connection communication method and apparatus. Background Art
[0002] When there are multiple users transmitting files simultaneously in the current forward proxy method, the proxy server usually receives multiple packets at the same time, but cannot determine which control connection the packet belongs to, resulting in the inability to determine the file name and whether it is an upload or download for the subsequent received file content. At the same time, when blocking a file, the current method also cannot inform the client of the current transmission status through the control connection, causing the client to become unresponsive due to continuously waiting for the transmission result. Additionally, when the server sends an abnormal response code and needs to close the data transmission, the current method cannot determine which data connection to close. Summary of the Invention
[0003] The purpose of the embodiments of this application is to provide an FTP-based connection communication method and apparatus, which can determine the association between the control connection and the data connection based on the connect content and the control connection information, thereby solving various problems caused by the current inability to distinguish between the control connection and the data connection.
[0004] The first aspect of the embodiments of this application provides an FTP-based connection communication method, including:
[0005] Parse the obtained FTP data request to obtain the connect content;
[0006] Perform a hash operation based on the connect content to obtain a first hash value;
[0007] Detect whether there is first control connection information associated with the first hash value;
[0008] When the first control connection information exists, determine that the FTP data request is a data connection request, control the pointer of the data connection data structure to point to the control connection data structure, and then control the pointer of the control connection data structure to point to the data connection data structure;
[0009] Receive the transmitted data file through the data connection.
[0010] In the above implementation process, the method can first parse the obtained ftp data request to obtain the connect content. It can be seen that the method can start from the connect message content in the ftp data to provide basic data information for subsequent analysis of whether it is a data connection or a control connection. Then, the method performs a hash operation based on the connect content to obtain a first hash value. It can be seen that the method can calculate the hash value based on the connect content, thereby avoiding retrieving connect and greatly improving the efficiency of connection type detection. Next, it is detected whether there is first control connection information associated with the first hash value. It can be seen that the method can detect whether there is first control connection information corresponding to the first hash value in the database, thereby implementing hash value association detection. Then, when there is no same hash value, it is considered that there is no corresponding control connection information, and when there is the same hash value, it is considered that there is corresponding control connection information. Among them, when there is first control connection information, it is determined that the ftp data request is a data connection request, and the pointer of the data connection data structure is controlled to point to the control connection data structure, and then the pointer of the control connection data structure is controlled to point to the data connection data structure. It can be seen that when the method determines that the hash value exists in the database, it records that the connection is a control connection, and further controls the pointers of both the data connection data structure and the control connection data structure to point to each other, thereby determining the association between the two connections. Finally, the method receives the transmitted data file through the data connection, so that it can perform subsequent communication based on an associated connection result, thereby facilitating the identification of the connection type and making it applicable to a multi-core working environment.
[0011] Further, the method further includes:
[0012] Detect the data file to obtain a detection result;
[0013] Judge whether the detection result meets the release condition;
[0014] When the detection result meets the release condition, release the data file;
[0015] When the detection result does not meet the release condition, block the data file.
[0016] In the above implementation process, the method can detect the data file after obtaining it to get a detection result. It can be seen that the method can further perform a legality check on the data file after receiving it, so as to facilitate the method to control the release of the data file. Then, the method determines whether the detection result meets the release conditions; when the detection result meets the release conditions, the data file is released; or when the detection result does not meet the release conditions, the data file is blocked. It can be seen that the method can release the file when it is legal and block it when it is illegal, thus effectively achieving the effect of secure file release.
[0017] Furthermore, the method further includes:
[0018] When the first control connection information does not exist, determine that the ftp data request is a control connection request, and identify the ftp data request to obtain second control connection information and communication information;
[0019] Perform a hash operation based on the communication information to obtain a second hash value;
[0020] Associate and store the second hash value and the second control connection information.
[0021] In the above implementation process, the method can also determine that the ftp data request is a control connection request when the first control connection information does not exist, and identify the ftp data request to obtain second control connection information and communication information. It can be seen that the method can determine that the ftp data request is a control connection request when the control connection information does not exist in the database, so as to establish a connection based on the control connection request and back up relevant data. Specifically, the method can perform a hash operation based on the communication information to obtain a second hash value; then associate and store the second hash value and the second control connection information. It can be seen that the method can store the second control information in the database based on the calculation of the hash value, so that it can be determined based on the hash value that the control connection has been established subsequently, thus realizing the distinction between the data connection and the control connection, and being able to replace the conventional detection with hash value detection to improve the overall detection efficiency.
[0022] Furthermore, the second control connection information includes upload operation information or download operation information, and the second control connection information also includes response information replied by the server; the communication information includes the server IP, the client IP, and the open data port information.
[0023] In the above implementation process, the control connection information can show the communication connection status and whether the proxy function is ready, so as to determine the status of the control connection. And the IP address and the open data port information of the input and output ends in the communication information can be used to establish and detect the connection, so as to realize the distinction of the control connection.
[0024] Further, the step of performing a hash operation on the communication information to obtain a second hash value includes:
[0025] Concatenate the data port information in integer form to obtain a concatenation result;
[0026] Perform an exclusive OR operation on the concatenation result and a random number to obtain an operation result;
[0027] Calculate the remainder between the budget result and a preset maximum hash value to obtain the second hash value.
[0028] In the above implementation process, when the method performs a hash operation on the communication information to obtain a second hash value, it can first concatenate the data port information in integer form to obtain a concatenation result; then perform an exclusive OR operation on the concatenation result and a random number to obtain an operation result; finally, calculate the remainder between the budget result and a preset maximum hash value to obtain the second hash value. It can be seen that the method can achieve a more suitable effect through this hash algorithm, thereby more efficiently detecting whether the current connection is a control connection.
[0029] Further, before the step of parsing the obtained ftp data request to obtain the connect content, the method further includes:
[0030] Pre-define a control connection data structure and a data connection data structure;
[0031] Initialize a data shared memory and encapsulate a hash algorithm interface; wherein, the hash algorithm interface is used to provide hash operation capabilities.
[0032] In the above implementation process, before the step of parsing the obtained ftp data request to obtain the connect content, the method pre-defines a control connection data structure and a data connection data structure; then, initializes the data shared memory and encapsulates the hash algorithm interface; wherein, the hash algorithm interface is used to provide hash operation capabilities. It can be seen that the method can define the data structures of the control connection and the data connection in advance, and at the same time initialize the data shared memory, thereby realizing data sharing when multiple cores process ftp connections; at the same time, the method can also implement the storage and acquisition functions of the control connection information by encapsulating the hash algorithm interface.
[0033] Further, the control connection data structure at least includes the connection information of ngx_connection_t provided by Nginx itself, file operation information, file name information, file size information, and a pointer to the data connection data structure; the data connection data structure at least includes the connection information of ngx_connection_t, file content information, and a pointer to the control connection data structure.
[0034] In the above implementation process, this method can define the control connection data structure and the data connection data structure, so that this method can more effectively implement the determination of the control connection or the data connection.
[0035] A second aspect of the embodiments of the present application provides an ftp-based connection communication device, and the ftp-based connection communication device includes:
[0036] A parsing unit, configured to parse the obtained ftp data request to obtain the connect content;
[0037] An operation unit, configured to perform a hash operation based on the connect content to obtain a first hash value;
[0038] A first detection unit, configured to detect whether there is first control connection information associated with the first hash value;
[0039] A determination unit, configured to, when there is the first control connection information, determine that the ftp data request is a data connection request, control the pointer of the data connection data structure to point to the control connection data structure, and then control the pointer of the control connection data structure to point to the data connection data structure;
[0040] A receiving unit, configured to receive the transmitted data file through the data connection.
[0041] Further, the ftp-based connection communication device further includes:
[0042] A second detection unit, configured to detect the data file to obtain a detection result;
[0043] A judgment unit, configured to judge whether the detection result meets the release condition;
[0044] A processing unit, configured to release the data file when the detection result meets the release condition;
[0045] The processing unit is further configured to block the data file when the detection result does not meet the release condition.
[0046] Further, the ftp-based connection communication device further includes:
[0047] The determining unit is configured to, when the first control connection information does not exist, determine that the ftp data request is a control connection request, and identify the ftp data request to obtain second control connection information and communication information;
[0048] The computing unit is configured to perform a hash operation based on the communication information to obtain a second hash value;
[0049] The association unit is configured to associatively store the second hash value and the second control connection information.
[0050] Further, the second control connection information includes upload operation information or download operation information, and the second control connection information further includes response information replied by the server; the communication information includes server IP, client IP, and open data port information.
[0051] Further, the computing unit includes:
[0052] The splicing subunit is configured to splice the data port information in integer form to obtain a splicing result;
[0053] The computing subunit is configured to perform an exclusive OR operation based on the splicing result and a random number to obtain an operation result;
[0054] The computing subunit is further configured to calculate the remainder between the budget result and a preset maximum hash value to obtain the second hash value.
[0055] Further, the ftp-based connection communication device further includes:
[0056] The predefined unit is configured to predefine a control connection data structure and a data connection data structure before parsing the obtained ftp data request to obtain the connect content;
[0057] The initialization unit is configured to initialize a data shared memory and encapsulate a hash algorithm interface; wherein, the hash algorithm interface is used to provide hash operation capabilities.
[0058] Further, the control connection data structure at least includes the ngx_connection_t connection information provided by Nginx, file operation information, file name information, file size information, and a pointer to the data connection data structure; the data connection data structure at least includes the ngx_connection_t connection information, file content information, and a pointer to the control connection data structure.
[0059] In a third aspect of the embodiments of the present application, an electronic device is provided, including a memory and a processor. The memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the FTP-based connection communication method according to any one of the first aspects of the embodiments of the present application.
[0060] In a fourth aspect of the embodiments of the present application, a computer-readable storage medium is provided, which stores computer program instructions. When the computer program instructions are read and run by a processor, the FTP-based connection communication method according to any one of the first aspects of the embodiments of the present application is executed. BRIEF DESCRIPTION OF THE DRAWINGS
[0061] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required to be used in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0062] Figure 1 It is a schematic flowchart of an FTP-based connection communication method provided by an embodiment of the present application;
[0063] Figure 2 It is a schematic structural diagram of an FTP-based connection communication device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0064] The technical solutions in the embodiments of the present application will be described below with reference to the drawings in the embodiments of the present application.
[0065] It should be noted that similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, the terms "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0066] Embodiment 1
[0067] Please refer to Figure 1 , Figure 1 which is a schematic flowchart of an FTP-based connection communication method provided by this embodiment. Among them, the FTP-based connection communication method includes:
[0068] S101. Pre-define a control connection data structure and a data connection data structure.
[0069] In this embodiment, the control connection data structure includes at least Nginx's own ngx_connection_t connection information, file operation information, file name information, file size information and a pointer to the data connection data structure; the data connection data structure includes at least ngx_connection_t connection information, file content information and a pointer to the control connection data structure.
[0070] S102, initialize the data shared memory and encapsulate the hash algorithm interface; wherein the hash algorithm interface is used to provide hash operation capability.
[0071] S103: Parse the acquired ftp data request to obtain connect content.
[0072] S104. Perform a hash operation based on the connect content to obtain a first hash value.
[0073] S105 , detecting whether there is first control connection information associated with the first hash value, if so, executing steps S106 to S109 ; if not, executing steps S112 to S116 .
[0074] S106: Determine that the FTP data request is a data connection request, and control the pointer of the data connection data structure to point to the control connection data structure, and then control the pointer of the control connection data structure to point to the data connection data structure.
[0075] S107: Receive the transmitted data file through the data connection.
[0076] S108: Detect the data file to obtain the detection result.
[0077] S109, determine whether the test result meets the release conditions, if so, execute step S110; if not, execute step S111.
[0078] S110. Release the data file.
[0079] S111. Block the data file.
[0080] S112: Determine that the ftp data request is a control connection request, identify the ftp data request, and obtain second control connection information and communication information.
[0081] In this embodiment, the second control connection information includes upload operation information or download operation information, and the second control connection information also includes response information replied by the server; the communication information includes server IP, client IP and open data port information.
[0082] S113. Concatenate the data port information in integer form to obtain a concatenation result.
[0083] S114. Perform an exclusive OR operation based on the splicing result and the random number to obtain an operation result.
[0084] S115. Calculate the remainder between the budget result and the preset maximum hash value to obtain a second hash value.
[0085] S116. Associatively store the second hash value and the second control connection information.
[0086] In this embodiment, the basic idea of the method is that both the control connection and the data connection client will send an HTTP proxy request message with the content of CONNECT. The difference between the two contents is that the control connection content is the server ip plus port 21 (standard port), and the data connection sends the CONNCET content with the ip and random port responded by the control connection server. Therefore, if the proxy server wants to know the current connection type, it can first parse the IP and random port responded by the ftp server, and then store the control connection information as a keyword. When parsing a new CONNECT message, parse the carried content IP and port, and then perform a hash calculation to find the stored control connection information. If found, the relationship between the two can be bound; if not, the current connection is the control connection.
[0087] In this embodiment, the method provides an example process for obtaining the associated information between the ftp control connection and the data connection in a forward proxy:
[0088] ① Define the control connection data structure, including: the ngx_connection_t provided by Nginx containing connection information, file operation information, file name information, file size information, the data structure pointer of the data connection, etc. At the same time, define the data connection data structure, including: the ngx_connection_t connection information, file content information, the data structure pointer of the control connection, etc.;
[0089] ② Initialize the data, allocate shared memory, which can realize data sharing when processing ftp connections with multiple cores;
[0090] ③ Package the hash algorithm interface to implement the storage and acquisition functions of the control connection information;
[0091] ④ Receive the HTTP proxy request header information sent by the ftp client and parse the CONNECT content;
[0092] ⑤ Based on the parsed CONNECT data, perform a hash operation, and find whether there is associated control connection information according to the hash value; among them, if there is, this request is the data connection and the control connection information is obtained; if not, it is the control connection. After that, call their respective processing functions to process the request content;
[0093] ⑥ Process the control connection handling, identify FTP requests and responses, record whether it is an upload operation or a download operation, and at the same time obtain the response from the server, parse the response content to obtain the IP specified by the server and the open data port, and record the client IP;
[0094] ⑦ Use the client IP, server IP, and open data port to perform a hash calculation and store the control connection information;
[0095] ⑧ Process the data connection. After obtaining the control connection information, the data connection data structure pointer points to the control connection data structure, and the control connection data structure pointer points to the data connection data structure;
[0096] ⑨ Continuously receive data on the data connection, obtain the content of the transmitted file, and calculate the size of the received file;
[0097] ⑩ After the data reception is completed and the binding relationship between the two has been determined, according to the actual business requirements, the detection of the file content, file name, and file size can be completed, and it is decided whether to release the file data or block the file data.
[0098] Based on the above process, this method can be applied to the FTP proxy module in the data leakage prevention system. Combining with the FTP forward proxy function, by obtaining the binding relationship between the control connection and the data connection, the forward proxy function of FTP can be improved, and the problem that the file name and file operation type cannot be determined during content inspection can be solved. When the server processing is abnormal, the proxy server does not know which data connection to close when receiving the response. Specifically, this method can be designed in the data leakage prevention system as follows:
[0099] ① Define the data structures of the control connection information and the data connection information, which need to be able to find each other between the two connections;
[0100] ② Allocate shared memory, design a hash operation, and encapsulate the storage and acquisition interfaces of the control connection information;
[0101] ③ Parse the FTP connection request, calculate the hash value according to the 227 or 229 response content replied by the FTP server, and store the current control connection information;
[0102] ④ Parse the CONNECT content, calculate the hash value to obtain the control connection information;
[0103] ⑤ Use the defined data structure of the connection information to associate the two connection information;
[0104] ⑥ After the connection information is associated, continue to perform the subsequent operations of the forward proxy.
[0105] In this embodiment, the execution subject of the method can be a computing device such as a computer or a server, and no limitation is made in this embodiment.
[0106] In this embodiment, the execution subject of the method can also be a smart device such as a smart phone or a tablet computer, and no limitation is made in this embodiment.
[0107] In this embodiment, the method can solve the following multiple technical problems:
[0108] ① Due to the limitation of the network environment, the client may not be able to directly access the ftp server through the proxy server. At this time, the client needs to configure the proxy IP and proxy port to access, and generally uses the HTTP proxy service. On the proxy server side, it is necessary to parse the HTTP proxy request information to obtain the IP and port of the ftp server that the client wants to access;
[0109] ② In the FTP forward proxy mode, the content formats of the proxy request messages for the control connection and the data connection are the same. They both perform a TCP three-way handshake with the proxy port, and then send an HTTP proxy request message with CONNECT. The same format needs to determine the connection type and whether it belongs to the received control connection;
[0110] ③ The problem of how to store the control connection data structure information and the data connection data structure information;
[0111] ④ The problem of how to obtain the uploaded and downloaded file names in the control connection, obtain the file content transmitted in the data connection, determine the corresponding file content of the transmitted file name, and the relationship between the connections.
[0112] It can be seen that implementing the ftp-based connection communication method described in this embodiment can easily determine the file content being transmitted, whether it is an upload operation or a download operation, and what the file name is by determining the relationship between the data connection and the control connection in the ftp proxy module. When introducing the policy detection module and the event sending module, these information can intuitively present the illegal file names, file uploads or downloads, and illegal file content. And when the current file content needs to be blocked if it is illegal, in the processing of the data connection, the proxy server needs to actively send a response of transmission completion to the client, and this response needs to be sent through the control connection. At this time, through the association of the two, the response can be directly sent to the corresponding control connection. And when storing or obtaining the control connection information through the hash algorithm, compared with traversing the linked list, it is efficient and accurate, and can greatly improve the efficiency in the processing of this instant message. And using shared memory to store the control connection information, when multiple cores process the ftp connection, even when the control connection data and the data connection data are not processed on the same core, the stored information can be obtained accurately.
[0113] Example 2
[0114] Please refer to Figure 2 , Figure 2 , which is a schematic structural diagram of a connection communication device based on ftp provided for this embodiment. As Figure 2 shown, the connection communication device based on ftp includes:
[0115] A parsing unit 210, configured to parse the obtained ftp data request to obtain the connect content;
[0116] An operation unit 220, configured to perform a hash operation based on the connect content to obtain a first hash value;
[0117] A first detection unit 230, configured to detect whether there is first control connection information associated with the first hash value;
[0118] A determination unit 240, configured to, when there is first control connection information, determine that the ftp data request is a data connection request, control the pointer of the data connection data structure to point to the control connection data structure, and then control the pointer of the control connection data structure to point to the data connection data structure;
[0119] A receiving unit 250, configured to receive the transmitted data file through the data connection.
[0120] As an optional implementation manner, the connection communication device based on ftp further includes:
[0121] A second detection unit 260, configured to detect the data file to obtain a detection result;
[0122] A judgment unit 270, configured to judge whether the detection result meets the release condition;
[0123] A processing unit 280, configured to release the data file when the detection result meets the release condition;
[0124] The processing unit 280 is further configured to block the data file when the detection result does not meet the release condition.
[0125] As an optional implementation manner, the connection communication device based on ftp further includes:
[0126] A determination unit 240, configured to, when there is no first control connection information, determine that the ftp data request is a control connection request, and identify the ftp data request to obtain second control connection information and communication information;
[0127] An operation unit 220, configured to perform a hash operation based on the communication information to obtain a second hash value;
[0128] An association unit 290 for associating and storing the second hash value and the second control connection information.
[0129] In this embodiment, the second control connection information includes upload operation information or download operation information, and the second control connection information further includes response information replied by the server; the communication information includes the server IP, the client IP, and the open data port information.
[0130] As an alternative embodiment, the operation unit 220 includes:
[0131] A splicing subunit 221 for splicing the data port information in integer form to obtain a splicing result;
[0132] An operation subunit 222 for performing an exclusive OR operation based on the splicing result and a random number to obtain an operation result;
[0133] The operation subunit 222 is further configured to calculate the remainder between the budget result and a preset maximum hash value to obtain the second hash value.
[0134] As an alternative embodiment, the ftp-based connection communication device further includes:
[0135] A predefined unit 300 for predefined a control connection data structure and a data connection data structure before parsing the obtained ftp data request to obtain the connect content;
[0136] An initialization unit 310 for initializing the data shared memory and encapsulating a hash algorithm interface; wherein, the hash algorithm interface is used to provide hash operation capabilities.
[0137] In this embodiment, the control connection data structure at least includes the ngx_connection_t connection information provided by Nginx, file operation information, file name information, file size information, and a pointer to the data connection data structure; the data connection data structure at least includes the ngx_connection_t connection information, file content information, and a pointer to the control connection data structure.
[0138] In the embodiments of the present application, the explanation of the ftp-based connection communication device may refer to the description in Embodiment 1, and thus will not be elaborated herein.
[0139] It can be seen that by implementing the FTP-based connection communication device described in this embodiment, the relationship between the data connection and the control connection can be determined in the FTP proxy module, and it is very convenient to determine the content of the currently transmitted file, whether it is an upload operation or a download operation, and what the file name is. When the policy detection module and the event sending module are introduced, these information can intuitively present the illegal file name, file upload or download, and illegal file content. And when the current file content needs to be blocked if it is illegal, in the processing of the data connection, the proxy server needs to actively send a transmission complete response to the client, and this response needs to be sent through the control connection. At this time, through the association of the two, the response can be directly sent to the corresponding control connection. And when storing or obtaining the control connection information through the hash algorithm, compared with traversing the linked list, it is efficient and accurate, and can greatly improve the efficiency in the processing of this instant message. And using shared memory to store the control connection information, when processing FTP connections with multiple cores, even when the control connection data and the data connection data are not processed on the same core, the stored information can be obtained accurately without error.
[0140] An embodiment of the present application provides an electronic device, including a memory and a processor. The memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the FTP-based connection communication method in Embodiment 1 of the present application.
[0141] An embodiment of the present application provides a computer-readable storage medium, which stores computer program instructions. When the computer program instructions are read and run by a processor, the FTP-based connection communication method in Embodiment 1 of the present application is executed.
[0142] In the several embodiments provided by the present application, it should be understood that the disclosed device and method can also be implemented in other ways. The device embodiments described above are only illustrative. For example, the flowcharts and block diagrams in the drawings show the possible architectures, functions, and operations of the device, method, and computer program product according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0143] In addition, in each embodiment of the present application, the functional modules can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.
[0144] If the above functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.
[0145] The above are only the embodiments of the present application and are not used to limit the protection scope of the present application. For those skilled in the art, the present application can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0146] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, and all of them should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0147] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the said element.
Claims
1. A connection communication method based on FTP, characterized in that, include: Parse the acquired FTP data request to get the connect content; The connect content includes server IP, client IP and open data port information; Perform a hash operation based on the connect content to obtain a first hash value; Detecting whether there is first control connection information associated with the first Hash value; When the first control connection information exists, determining that the FTP data request is a data connection request, and controlling the pointer of the data connection data structure to point to the control connection data structure, and then controlling the pointer of the control connection data structure to point to the data connection data structure; Receive the transmitted data files through the data connection.
2. The FTP-based connection communication method according to claim 1, wherein The method further comprises: Testing the data file to obtain a test result; Determine whether the test results meet the release conditions; When the test result meets the release condition, releasing the data file; When the detection result does not meet the release condition, the data file is blocked.
3. The FTP-based connection communication method according to claim 1, wherein The method further comprises: When the first control connection information does not exist, determining that the ftp data request is a control connection request, and identifying the ftp data request to obtain second control connection information and communication information; the communication information includes server IP, client IP and open data port information; Performing a hash operation based on the communication information to obtain a second hash value; The second Hash value and the second control connection information are stored in association.
4. The FTP-based connection communication method according to claim 3, wherein The second control connection information includes upload operation information or download operation information, and the second control connection information also includes response information replied by the server; the communication information includes server IP, client IP and open data port information.
5. The FTP-based connection communication method according to claim 4, wherein The step of performing a hash operation based on the communication information to obtain a second hash value comprises: splicing the data port information in integer form to obtain a splicing result; Perform an XOR operation based on the splicing result and the random number to obtain an operation result; The remainder between the operation result and a preset maximum hash value is calculated to obtain a second hash value.
6. The FTP-based connection communication method according to claim 1, wherein, Before the step of parsing the acquired FTP data request data to obtain the connect content, the method further includes: predefined control connection data structure and data connection data structure; Initialize the data shared memory and encapsulate the hash algorithm interface; wherein the hash algorithm interface is used to provide hash operation capability.
7. The FTP-based connection communication method according to claim 1, characterized in that The control connection data structure includes at least Nginx's own ngx_connection_t connection information, file operation information, file name information, file size information and a pointer to the data connection data structure; the data connection data structure includes at least ngx_connection_t connection information, file content information and a pointer to the control connection data structure.
8. A connection communication device based on FTP, characterized in that, The FTP-based connection communication device comprises: The parsing unit is used to parse the acquired FTP data request to obtain the connect content; the connect content includes the server IP, the client IP and the open data port information; An operation unit, configured to perform a hash operation based on the connect content to obtain a first hash value; A first detection unit, configured to detect whether there is first control connection information associated with the first hash value; 9. An electronic device, characterized in that, A determination unit, configured to, when there is the first control 10. A readable storage medium, characterized in that, connection information, determine that the ftp data request is a data connection request, control a pointer of a data connection data structure to point to a control connection data structure, and then control a pointer of the control connection data structure to point to the data connection data structure; A receiving unit, configured to receive a transmitted data file through the data connection. The electronic device includes a memory and a processor. The memory is configured to store a computer program. The processor runs the computer program to cause the electronic device to execute the ftp-based connection communication method according to any one of claims 1 to 7. Computer program instructions are stored in the readable storage medium. When the computer program instructions are read and run by a processor, the ftp-based connection communication method according to any one of claims 1 to 7 is executed.
Citation Information
Patent Citations
Flow classification method and device of multi-channel process
CN106341344A
Method for processing father-son connection in full-flow storage backtracking analysis system
CN113630331A