A multi-segment comparison analysis method and system based on full-flow backtracking

Through the multi-segment analysis method of full traffic backtracking, the mirror traffic flowing through multiple network nodes of the same session is obtained and parsed, which solves the problem of low network fault location efficiency and achieves rapid and accurate fault point positioning and operation and maintenance efficiency improvement.

CN115987766BActive Publication Date: 2025-07-18WUHAN SIPU TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211525748.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-30
Publication Date
2025-07-18
Estimated Expiration
2042-11-30

AI Technical Summary

Technical Problem

When multiple physical nodes simultaneously capture network traffic, the prior art cannot ensure uniformity in the time dimension, resulting in low network fault positioning efficiency and unable to meet the needs of rapid positioning and handling.

Method used

Through the multi-segment and analysis method of full traffic backtracking, the mirror traffic flowing through multiple network nodes of the same session is obtained, the traffic parameters of each network node are analyzed, including network performance indicators and application response indicators, and multi-segment and analysis are performed to generate the traffic analysis results of the session.

Benefits of technology

It realizes a unified comparison and analysis of the traffic of multiple different physical nodes in time and physical dimensions, quickly and accurately locates network failure points, and improves operation and maintenance efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115987766B_ABST
    Figure CN115987766B_ABST
Patent Text Reader

Abstract

The present application provides a multi-segment comparison analysis method and system based on full-flow traceback. The method can obtain mirror traffic of the same session flowing through multiple network nodes, parse the mirror traffic of each network node, and obtain the metric parameters generated by the session flowing through the network nodes. Among them, the metric parameters include network performance metric parameters and application response metric parameters. Perform multi-segment comparison analysis on the traffic parameters of multiple network nodes to generate a traffic analysis result of the session. By obtaining the mirror traffic of the same session flowing through multiple network nodes, the method can simultaneously compare and analyze the traffic of multiple different physical nodes, complete unification in terms of time and physical dimensions, and at the same time, quickly and accurately locate network fault points through the traffic analysis result of the session, improving the operation and maintenance efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network technologies, and in particular, to a multi-segment comparison analysis method and system based on full-traffic traceback. Background Art

[0002] The essence of a network is communication, which provides a channel to ensure that information is accurately sent from the source end to the destination end. A network consists of several nodes and links connecting these nodes. The nodes in the network can be computers, switches, routers, mobile terminals, etc. During the operation of the network, each level of nodes can automatically switch paths to establish a data exchange channel. However, during this process, network failures such as packet loss or delay may occur. To ensure the normal operation of the network, it is necessary to locate network failures in a timely manner.

[0003] Currently, for fault location in a complex network environment, session correlation analysis can be used to identify network fault points. By capturing network traffic at different physical nodes and then manually using network packet analysis software (wireshark) to compare and analyze the packet storage files (pcap) of different physical nodes multiple times, an analysis conclusion can be obtained.

[0004] However, the method relying on manual analysis is inefficient, and when capturing traffic at multiple physical nodes simultaneously, the unity in the time dimension cannot be guaranteed, thus affecting the analysis conclusion. For example, when the number of gateway server clusters is large and a fault occurs when a certain session is forwarded through this gateway cluster, it is impossible to locate which gateway server in the gateway cluster has a problem in a short time. And when a specific gateway server is located, it is also necessary to manually execute the corresponding packet capture command to obtain the data packet for further fault analysis, with low timeliness and unable to meet the requirements of quickly locating and handling network faults. Summary of the Invention

[0005] The present application provides a multi-segment comparison analysis method and system based on full-traffic traceback to solve the problem of inability to ensure consistency in time and physical dimensions when analyzing the same session at multiple physical nodes.

[0006] On the one hand, the present application provides a multi-segment comparison analysis method based on full-traffic traceback, including:

[0007] Obtaining mirror traffic of a target session flowing through multiple target network nodes;

[0008] Analyzing the mirror traffic of the target network node to obtain traffic parameters of the target network node, where the traffic parameters are index parameters generated when the target session flows through the target network node, and the index parameters include network performance index parameters and application response index parameters;

[0009] Generate the traffic analysis result of the target session by comparing the traffic parameters of multiple target network nodes.

[0010] Optionally, the step of obtaining the mirror traffic of the target session flowing through multiple target network nodes further includes:

[0011] Add multiple mirror traffic collection interfaces to multiple interface links respectively, where the mirror traffic collection interface is connected to the target network node;

[0012] Copy the traffic of the target session flowing through multiple target network nodes to the corresponding interface link through multiple mirror traffic collection interfaces;

[0013] Divide the mirror traffic of different target network nodes according to the interface link.

[0014] Optionally, the method further includes:

[0015] Receive multiple packets sent by the mirror traffic collection interface;

[0016] Extract the five-tuple information of the packet, where the five-tuple information includes IP address, source port, destination IP address, destination port, and transport layer protocol;

[0017] Build a flow for the multiple packets according to the interface link to which the packet belongs and the five-tuple information to obtain mirror traffic.

[0018] Optionally, before the step of building a flow for the multiple packets according to the interface link to which the packet belongs and the five-tuple information of the packet, it further includes:

[0019] Distribute the packets with the same five-tuple information to the same thread through a hash algorithm.

[0020] Optionally, the step of parsing the mirror traffic of the target network node to obtain the metric parameters of the target network node further includes:

[0021] Identify the packet protocol of each packet in the mirror traffic;

[0022] Perform packet parsing on the packet protocol to obtain feature fields;

[0023] Determine the traffic parameters of each target network node according to the feature fields, where the traffic parameters are the mirror traffic containing the feature fields.

[0024] Optionally, the step of identifying the packet protocol of each packet in the mirror traffic further includes:

[0025] Obtain the payload and five-tuple information of each packet in the mirror traffic;

[0026] Traverse the protocol features in the preset protocol feature library according to the payload of the message and the five-tuple information of the message;

[0027] Determine the message protocol of each message in the mirrored traffic, where the message protocol is the protocol type corresponding to the protocol feature that matches the payload of the message and the five-tuple information of the message.

[0028] Optionally, the method further includes:

[0029] Store the feature fields and the traffic parameters into the flow table of the mirrored traffic.

[0030] Optionally, the step of comparing the traffic parameters of multiple target network nodes and generating the traffic analysis result of the target session further includes:

[0031] Obtain the historical traffic parameters of each target network node within a target time period;

[0032] Determine the target traffic parameters, where the target traffic parameters are the historical traffic parameters belonging to the target session;

[0033] Compare multiple target traffic parameters and generate the traffic analysis result of the target session.

[0034] Optionally, the step of determining the target traffic parameters further includes:

[0035] Obtain the five-tuple information of the historical traffic parameters;

[0036] Determine the target traffic parameters according to the five-tuple information of the historical traffic parameters, where the target traffic parameters are the historical traffic parameters with the same five-tuple information as the target session.

[0037] On the other hand, the present application further provides a multi-segment comparison analysis system based on full-traffic backtracking, including: a full-traffic forensics device and a data processing device connected to the full-traffic forensics device; the full-traffic forensics device includes a mirrored traffic acquisition interface, and the mirrored traffic acquisition interface is connected to the target network node to obtain mirrored traffic from the target network node; the data processing device is further configured to execute the following program steps:

[0038] Obtain the mirrored traffic of the target session flowing through multiple target network nodes;

[0039] Parse the mirrored traffic of the target network node to obtain the traffic parameters of the target network node, where the traffic parameters are the metric parameters generated by the target session flowing through the target network node, and the metric parameters include network performance metric parameters and application response metric parameters;

[0040] Generate the traffic analysis result of the target session by comparing the traffic parameters of multiple target network nodes.

[0041] As can be seen from the above technical solutions, the present application provides a multi-segment comparison analysis method based on full traffic backtracking. The method can obtain the mirror traffic of the same session flowing through multiple network nodes, parse the mirror traffic of each network node, and obtain the metric parameters generated when the session flows through the network nodes. Among them, the metric parameters include network performance metric parameters and application response metric parameters. Perform multi-segment comparison analysis on the traffic parameters of multiple network nodes to generate the traffic analysis result of the session. By obtaining the mirror traffic of the same session flowing through multiple network nodes, the method can compare and analyze the traffic of multiple different physical nodes simultaneously, unify in terms of time and physical dimensions, and at the same time, the traffic analysis result of the session can quickly and accurately locate the network fault point, improving the operation and maintenance efficiency. Brief Description of the Drawings

[0042] To more clearly illustrate the technical solutions of the present application, the following will briefly introduce the drawings required in the embodiments. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0043] Figure 1 It is a schematic flow chart of a multi-segment comparison analysis method based on full traffic backtracking provided by an embodiment of the present application;

[0044] Figure 2 It is a schematic diagram of the interface link provided by an embodiment of the present application;

[0045] Figure 3 It is a schematic flow chart of obtaining mirror traffic provided by an embodiment of the present application;

[0046] Figure 4 It is a schematic flow chart of parsing mirror traffic provided by an embodiment of the present application;

[0047] Figure 5 It is a schematic flow chart of matching message protocols provided by an embodiment of the present application;

[0048] Figure 6 It is a schematic flow chart of comparing the traffic parameters of multiple target nodes provided by an embodiment of the present application;

[0049] Figure 7 It is a schematic diagram of the traffic analysis result provided by an embodiment of the present application;

[0050] Figure 8 It is a schematic structural diagram of a multi-segment comparison analysis system based on full traffic backtracking provided by an embodiment of the present application. Detailed Embodiments

[0051] Embodiments will be described in detail below, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following embodiments do not represent all embodiments consistent with the present application. They are merely examples of systems and methods consistent with some aspects of the present application detailed in the claims.

[0052] The multi-segment contrast analysis method based on full-flow backtracking provided by the present application can be applied to network fault analysis to quickly locate network faults. For the fault location in a complex network environment, session correlation analysis can be used to identify network fault points. By capturing network traffic at different physical nodes and then manually using network packet analysis software (Wireshark) to compare and analyze the packet storage files (pcap) of different physical nodes multiple times, an analysis conclusion can be obtained.

[0053] A session refers to the process of communication between a user terminal and a specified network server (or terminal). For example, the process from entering the operating system by inputting an account password to exiting the operating system is a session process. Multiple network traffic data will be exchanged during the communication process, that is, a session includes multiple network traffic data flowing through multiple network terminals. By comparing and analyzing the network traffic data of multiple network terminals, it can be determined whether there are network anomalies such as packet loss or delay. However, the method of manual analysis is less efficient, and when capturing traffic at multiple physical nodes simultaneously, the unity in the time dimension cannot be guaranteed, thus affecting the analysis conclusion and unable to meet the requirement of quickly locating and handling network faults.

[0054] See Figure 1 , which is a schematic flow chart of a multi-segment contrast analysis method based on full-flow backtracking according to the present application. As can be seen from Figure 1 , in order to be able to compare and analyze the traffic of multiple different network nodes simultaneously, the multi-segment contrast analysis method based on full-flow backtracking provided by the present application is applied to a multi-segment contrast analysis system based on full-flow backtracking. The system includes a full-flow forensics device and a data processing device connected to the full-flow forensics device. Among them, the full-flow forensics device includes a mirror traffic collection interface, and the mirror traffic collection interface is connected to the target network node to obtain mirror traffic from the target network node. The method includes the following steps:

[0055] S100: Obtain the mirror traffic of the target session flowing through multiple target network nodes.

[0056] Among them, mirroring means copying the traffic passing through a specified port to another specified port. To facilitate the comparative analysis of the traffic of multiple different physical nodes, it is necessary to obtain the traffic of different physical nodes. Mirroring can copy the traffic of a session passing through a network node through a mirror traffic collection interface without affecting the normal processing of the session by the device of the network node, and obtain mirror traffic.

[0057] When the same session passes through multiple network nodes, the traffic of multiple network nodes is mirrored by the above-mentioned traffic mirroring method. Since a session will pass through multiple network nodes. Therefore, to compare and analyze the traffic of multiple different network nodes, it is necessary to determine which target node the mirror traffic belongs to. Therefore, in some embodiments, the step of obtaining the mirror traffic of a target session passing through multiple target network nodes further includes:

[0058] Add multiple mirror traffic collection interfaces to multiple interface links respectively, and the mirror traffic collection interface is connected to the target network node.

[0059] Copy the traffic of the target session passing through multiple target network nodes to the corresponding interface link through multiple mirror traffic collection interfaces.

[0060] Divide the mirror traffic of different target network nodes according to the interface link.

[0061] In this embodiment, by setting multiple interface links, such as Figure 2 As shown, each mirror traffic interface is correspondingly connected to an interface link, and the traffic of multiple network nodes is mirrored to multiple interface links simultaneously by the traffic mirroring method, that is, the mirror traffic of different network nodes flows into different interface links, and the mirror traffic of different network nodes is distinguished by the interface link.

[0062] Among them, traffic is a set of packets with the same attributes sent sequentially through the same network within a period of time. During the process of mirroring traffic, the sequentially sent packets are copied through a mirror traffic collection interface, and a flow is established for the copied packets to obtain mirror traffic. As Figure 3 Shown, the method for obtaining mirror traffic further includes:

[0063] S110: Receive multiple packets sent by the mirror traffic collection interface.

[0064] Copy the sequentially sent packets through the mirror traffic collection interface, as Figure 2 Shown, and send the copied packets to the packet receiving modules of different interface links. The packet receiving module can receive packets through the Data Plane Development Kit (DPDK).

[0065] S120: Extract the five-tuple information of the said packet.

[0066] Among them, the five-tuple information includes the IP address, source port, destination IP address, destination port, and transport layer protocol. When the packet receiving module receives a packet, it determines the session to which the packet belongs by extracting the five-tuple information in the packet. The five-tuple can distinguish different sessions, and the corresponding session is unique. And to ensure that the same flow can be processed in the same thread, when the packet receiving module receives a packet, it can distribute the packets with the same five-tuple information to the same thread for processing, which is beneficial to improving the processing performance of the system for data packets.

[0067] To avoid the packet being tampered with during the distribution process and improve the reliability of packet distribution, the packet distribution can be implemented through a hash algorithm, and the packets with the same five-tuple information are distributed to the same thread through the hash algorithm. Thus, the accuracy of traffic statistics can be improved. Specifically, the packets with the same five-tuple can be distributed to the same service processing thread through the Data Plane Development Kit (DPDK) by using the hash algorithm.

[0068] S130: Build a flow for the multiple packets according to the interface link to which the packet belongs and the five-tuple information, and obtain the mirrored traffic.

[0069] After the packet receiving module distributes the received packets to the service processing threads, the flow building module builds a flow according to the interface link to which the packet belongs and the five-tuple of the packet, and obtains the mirrored traffic.

[0070] S200: Analyze the mirrored traffic of the target network node to obtain the traffic parameters of the target network node.

[0071] Among them, the traffic parameter is the metric parameter generated when the target session flows through the target network node, and the metric parameter includes the network performance metric parameter and the application response metric parameter. After obtaining the mirrored traffic of each target network node, analyze the mirrored traffic to obtain the traffic parameters. The traffic parameter is a metric parameter that can characterize the characteristics of the current network traffic data. Through the metric parameter, the operation status of the network can be reflected. The metric parameter includes the network performance metric parameter and the application response metric parameter. For example, rate, bandwidth, throughput, delay, delay-bandwidth product, round-trip time RTT, utilization channel, etc. By analyzing the mirrored traffic of the target network node, the metric parameter of the target network node is obtained, which provides data support for the comparative analysis of multiple network nodes in the follow-up.

[0072] In some embodiments, as Figure 4 shown, the step of analyzing the mirrored traffic of the target network node to obtain the metric parameter of the target network node further includes:

[0073] S210: Identify the message protocol of each message in the mirror traffic.

[0074] S220: Perform message parsing on the message protocol to obtain characteristic fields.

[0075] S230: Determine the traffic parameters of each target network node according to the characteristic fields, where the traffic parameters are the mirror traffic containing the characteristic fields.

[0076] In this embodiment, when parsing the mirror traffic of the target network node, the messages in the mirror traffic can be analyzed. The protocol identification module is used to identify the message protocol of each message in the mirror traffic to determine the message protocol to which each message belongs. Then, the protocol parsing module performs message parsing on the message protocol to obtain characteristic fields, and the characteristic fields include message fields and audit fields. For the convenience of subsequent calling of the characteristic fields, the characteristic fields can be stored in the flow table of the mirror traffic. The flow table is a set of policy entries for a specific flow and is responsible for packet lookup and forwarding. Each flow table corresponds to a flow of network transmission, that is, each mirror traffic corresponds to a flow table. By storing the parsed characteristic fields in the flow table corresponding to the mirror traffic, it is convenient for subsequent calling and improves the system processing performance.

[0077] Based on the above-parsed characteristic fields, the traffic parameters of each target network node can be determined. By statistically analyzing the characteristic fields, the traffic parameters of each target network node can be determined. For example, uplink packet loss analysis, downlink packet loss analysis, uplink retransmission packet analysis, downlink retransmission packet analysis, uplink reset packet analysis, downlink reset packet analysis, client handshake RTT, server handshake RTT, number of connection requests reset, number of connection unanswered, number of TCP SYN packets, number of TCP SYN-ACK packets, client retransmission delay, server retransmission delay, number of normal three-way handshakes, number of TCP out-of-order packets, etc. Similarly, the obtained traffic parameters can be saved to the flow table corresponding to the mirror traffic respectively to provide data support for multi-node comparison of a specified session.

[0078] In some embodiments, as Figure 5 shown, the steps of identifying the message protocol of each message in the mirror traffic further include:

[0079] S211: Obtain the payload and five-tuple information of each message in the mirror traffic.

[0080] S212: Traverse the protocol characteristics in the preset protocol characteristic library according to the payload of the message and the five-tuple information of the message.

[0081] S213: Determine the message protocol of each message in the mirror traffic, where the message protocol is the protocol type corresponding to the protocol feature that matches the payload of the message and the five-tuple information of the message.

[0082] In this embodiment, when identifying the message protocol of each message in the mirror traffic, the protocol identification module can extract the payload and five-tuple information (source IP address, source port, destination IP address, destination port, transport layer protocol) of each message in the mirror traffic, so as to match the protocol feature. That is, the payload of the message and the five-tuple information are matched with the protocol feature library. When the protocol feature of a specific protocol is hit, it is protocol identification. After the message is identified by the protocol identification module, the protocol parsing module can parse the message protocols of multiple messages respectively according to the identified protocol type.

[0083] S300: Generate a traffic analysis result for the target session by comparing the traffic parameters of multiple target network nodes.

[0084] After obtaining the traffic parameters of the target session flowing through multiple target network nodes, the traffic parameters of multiple target network nodes can be compared and analyzed, that is, the network performance index parameters and application response index parameters of the target session flowing through multiple target network nodes are compared and analyzed to generate a traffic analysis result.

[0085] In some embodiments, as Figure 6 shown, the steps of comparing the traffic parameters of multiple target network nodes and generating a traffic analysis result for the target session further include:

[0086] S310: Obtain the historical traffic parameters of each target network node within a target time period.

[0087] S320: Determine the target traffic parameters, where the target traffic parameters are the historical traffic parameters belonging to the target session.

[0088] S330: Compare multiple target traffic parameters and generate a traffic analysis result for the target session.

[0089] In this embodiment, a certain period of time can be selected for the comparative analysis of the target session. The target time period is the time selected by the user. The comparative analysis of the target session can be performed by selecting a certain period of time through the backtracking module on a certain interface link, and the traffic of the target session on other interface links is judged to determine the target traffic parameters belonging to the target session. Multiple target traffic parameters are compared to generate a traffic analysis result for the target session.

[0090] Determine whether there is traffic of the target session on other links. It can be determined whether other interface links are associated with the target session through the five-tuple information. Obtain the five-tuple information of the historical traffic parameters, and determine whether the historical traffic parameters belong to the target session according to the five-tuple information. Therefore, the steps for determining the target traffic parameters further include:

[0091] Obtain the five-tuple information of the historical traffic parameters. Determine the target traffic parameters according to the five-tuple information of the historical traffic parameters, where the target traffic parameters are the historical traffic parameters with the same five-tuple information as the target session.

[0092] As Figure 7 shown, it is a schematic diagram of an exemplary traffic analysis result, which is the traffic analysis result between the network nodes corresponding to Interface Link 1 and Interface Link 2. The interval range is the target time period selected by the user, and the traffic parameters are not limited to Figure 7 the parameters shown in, and also include client bit rate, server bit rate, uplink data packets, downlink data packets, total number of created sessions, etc. In some embodiments, in order to improve the user experience, the traffic analysis result can be further plotted into forms such as line charts and pie charts and presented to the user more intuitively.

[0093] It can be seen from the above technical solutions that the present application obtains the mirror traffic of the same session flowing through multiple network nodes through the traffic mirroring method, obtains the index parameters generated by the session flowing through the network nodes by parsing the mirror traffic, and obtains the traffic analysis result of the session by performing multi-segment comparison analysis on the index parameters between multiple network nodes. It can realize the simultaneous comparison analysis of the traffic of multiple different physical nodes, complete the unification in the time and physical dimensions, and at the same time quickly and accurately locate the network fault points through the traffic analysis result of the session, improving the operation and maintenance efficiency.

[0094] The following uses an exemplary embodiment to elaborate on the multi-segment comparison analysis method based on full traffic backtracking provided by the present application.

[0095] The network card of Company A's office network is stuck. The user suspects that there is a problem with the network between the "core switch" and the "firewall" and needs to perform network fault analysis on the network between the "core switch" and the "firewall". The network fault analysis can be performed through the multi-segment comparison analysis method based on full traffic backtracking provided by the present application to determine whether there is a problem with the network quality between the two physical nodes of the "core switch" and the "firewall".

[0096] Among them, the traffic interaction between the "core switch" and the "firewall" is the traffic generated in the office local area network. The traffic is forwarded from the "core switch" to the "firewall" and then forwarded by the "firewall" to the Internet.

[0097] First, as Figure 8As shown in the figure, the two mirror traffic collection interfaces of the full-flow forensics device are respectively connected to two network nodes, namely the "core switch" and the "firewall", and the mirror traffic collection interfaces corresponding to the "core switch" and the "firewall" are respectively added to different interface links. The traffic of the two network nodes, namely the "core switch" and the "firewall", is copied to the corresponding interface links through the mirror traffic collection interfaces.

[0098] The data processing device can receive the mirror traffic of the two network nodes, namely the "core switch" and the "firewall". The user can perform multi-segment comparison analysis by selecting a session and a time period. For example, the user selects a TCP session for multi-segment comparison analysis, and the selected time period is from 16:16 on February 8, 2022 to 16:21 on February 8, 2022.

[0099] By obtaining the traffic parameters of the two network nodes, namely the "core switch" and the "firewall", for this TCP session within the selected time period, that is, the metric parameters generated when this TCP session flows through the two network nodes of the "core switch" and the "firewall", the metric parameters include network performance metric parameters and application response metric parameters. By comparing the metric parameters of the two network nodes of the "core switch" and the "firewall", a traffic analysis result of this TCP session is generated.

[0100] For example, the uplink traffic, downlink traffic, total traffic, bytes per second, bit rate, client bit rate, server bit rate, uplink packets, etc. of the two network nodes of the "core switch" and the "firewall" can be compared. Detailed analysis can also be performed on this TCP session. For example, analyze the TCP three-way handshake of this TCP session, including uplink packet loss analysis, downlink packet loss analysis, uplink retransmission packet analysis, downlink retransmission packet analysis, uplink reset packet analysis, downlink reset packet analysis, client handshake RTT, etc., and perform statistical analysis on the number of lost packets, retransmission packets, reset packets, and handshake RTT.

[0101] According to the traffic analysis result, if there are no abnormalities in the metrics such as the number of lost packets, retransmission packets, handshake RTT, and retransmission delay between the two network nodes of the "core switch" and the "firewall", it can be further determined that there is no network quality problem between the two network nodes of the "core switch" and the "firewall", and the troubleshooting scope can be narrowed down within the core switch.

[0102] Based on the above multi-segment comparison analysis method based on full-flow backtracking, as Figure 8As shown in the figure, the present application also provides a multi-segment comparison analysis system based on full-flow traceback, including: a full-flow forensics device and a data processing device connected to the full-flow forensics device; the full-flow forensics device includes a mirrored traffic collection interface, and the mirrored traffic collection interface is connected to the target network node to obtain mirrored traffic from the target network node; the data processing device is further configured to execute the following program steps:

[0103] S100: Obtain the mirrored traffic of the target session flowing through multiple target network nodes.

[0104] S200: Analyze the mirrored traffic of the target network node to obtain the traffic parameters of the target network node. The traffic parameters are the metric parameters generated when the target session flows through the target network node, and the metric parameters include network performance metric parameters and application response metric parameters.

[0105] S300: Generate a traffic analysis result of the target session by comparing the traffic parameters of multiple target network nodes.

[0106] It can be seen from the above technical solutions that the present application provides a multi-segment comparison analysis method based on full-flow traceback. The method can obtain the mirrored traffic of the same session flowing through multiple network nodes, analyze the mirrored traffic of each network node, and obtain the metric parameters generated when the session flows through the network node. Among them, the metric parameters include network performance metric parameters and application response metric parameters. Perform multi-segment comparison analysis on the traffic parameters of multiple network nodes to generate a traffic analysis result of the session. By obtaining the mirrored traffic of the same session flowing through multiple network nodes, the method can compare and analyze the traffic of multiple different physical nodes at the same time, complete unification in terms of time and physical dimensions, and at the same time, quickly and accurately locate network fault points through the traffic analysis result of the session, improving the operation and maintenance efficiency.

[0107] For the similarity parts between the embodiments provided in the present application, reference can be made to each other. The specific embodiments provided above are only several examples under the general concept of the present application, and do not constitute a limitation on the protection scope of the present application. For those skilled in the art, any other implementation manner extended based on the solution of the present application without creative efforts belongs to the protection scope of the present application.

Claims

1. A multi-segment comparative analysis method based on full-flow backtracking, characterized in that, The method includes: Obtaining the mirror traffic of a target session flowing through multiple target network nodes; the step of obtaining the mirror traffic of a target session flowing through multiple target network nodes further includes: adding multiple mirror traffic collection interfaces to multiple interface links respectively, where the mirror traffic collection interfaces are connected to the target network nodes; copying the traffic of the target session flowing through the multiple target network nodes to the corresponding interface links through the multiple mirror traffic collection interfaces; dividing the mirror traffic of different target network nodes according to the interface links; Parsing the mirror traffic of the target network node to obtain the traffic parameters of the target network node, where the traffic parameters are index parameters representing the characteristics of the current network traffic data generated by the target session flowing through the target network node, and the index parameters include network performance index parameters and application response index parameters, which are used to reflect the network operation situation; Generating a traffic analysis result of the target session by comparing the traffic parameters of multiple target network nodes; the step of comparing the traffic parameters of multiple target network nodes and generating a traffic analysis result of the target session further includes: obtaining the historical traffic parameters of each target network node within a target time period; determining the target traffic parameters, where the target traffic parameters are the historical traffic parameters belonging to the target session; comparing the multiple target traffic parameters to generate a traffic analysis result of the target session.

2. The multi-segment comparison and analysis method based on full-flow backtracking according to claim 1, wherein The method further includes: Receiving multiple packets sent by the mirror traffic collection interface; Extracting the five-tuple information of the packet, where the five-tuple information includes IP address, source port, destination IP address, destination port, and transport layer protocol; Building a flow for the multiple packets according to the interface link to which the packet belongs and the five-tuple information to obtain the mirror traffic.

3. The multi-segment comparison analysis method based on full-flow traceback according to claim 2, wherein Before the step of building a flow for the multiple packets according to the interface link to which the packet belongs and the five-tuple information of the packet, it further includes: Distributing the packets with the same five-tuple information to the same thread through a hash algorithm.

4. The multi-segment comparison analysis method based on full-flow backtracking according to claim 1, characterized in that The step of parsing the mirror traffic of the target network node to obtain the index parameters of the target network node further includes: Identifying the packet protocol of each packet in the mirror traffic; Performing packet parsing on the packet protocol to obtain the characteristic fields; Determining the traffic parameters of each target network node according to the characteristic fields, where the traffic parameters are the mirror traffic containing the characteristic fields.

5. The multi-segment comparison analysis method based on full-flow backtracking according to claim 4, wherein The step of identifying the packet protocol of each packet in the mirror traffic further includes: Obtaining the payload and five-tuple information of each packet in the mirror traffic; Traversing the protocol characteristics in a preset protocol characteristic library according to the payload of the packet and the five-tuple information of the packet; Determining the packet protocol of each packet in the mirror traffic, where the packet protocol is the protocol type corresponding to the protocol characteristic that matches the payload of the packet and the five-tuple information of the packet.

6. The multi-segment comparison and analysis method based on full-flow backtracking according to claim 4, characterized in that The method further includes: Storing the characteristic fields and the traffic parameters into the flow table of the mirror traffic.

7. The multi-segment comparison analysis method based on full-flow backtracking according to claim 1, wherein The step of determining the target traffic parameters further includes: Obtaining the five-tuple information of the historical traffic parameters; Determine target traffic parameters according to the five-tuple information of the historical traffic parameters, where the target traffic parameters are historical traffic parameters that are the same as the five-tuple information corresponding to the target session.

8. A multi-segment comparative analysis system based on full-flow backtracking, characterized in that, Including: A full-traffic forensics device and a data processing device connected to the full-traffic forensics device; The full-traffic forensics device includes a mirrored traffic collection interface, and the mirrored traffic collection interface is connected to a target network node to obtain mirrored traffic from the target network node; the data processing device is further configured to execute the following program steps: Obtain the mirrored traffic of the target session flowing through multiple target network nodes; The step of obtaining the mirrored traffic of the target session flowing through multiple target network nodes further includes: adding multiple mirrored traffic collection interfaces to multiple interface links respectively; copying the traffic of the target session flowing through multiple target network nodes to the corresponding interface links through the multiple mirrored traffic collection interfaces; dividing the mirrored traffic of different target network nodes according to the interface links; Analyze the mirrored traffic of the target network node to obtain the traffic parameters of the target network node. The traffic parameters are index parameters that characterize the characteristics of the current network traffic data generated by the target session flowing through the target network node. The index parameters include network performance index parameters and application response index parameters, which are used to reflect the network operation conditions; Generate a traffic analysis result of the target session by comparing the traffic parameters of multiple target network nodes; the step of comparing the traffic parameters of multiple target network nodes to generate a traffic analysis result of the target session further includes: obtaining the historical traffic parameters of each target network node within a target time period; determining target traffic parameters, where the target traffic parameters are historical traffic parameters belonging to the target session; comparing multiple target traffic parameters to generate a traffic analysis result of the target session.

Citation Information

Patent Citations

  • Method and system for positioning APT attack source

    CN106549929A