A network traffic filtering method, apparatus and network device

By acquiring and matching the five-tuple information of network traffic, the problem of traditional firewalls being unable to segment network traffic with fine granularity is solved, enabling precise filtering and security management of Web 2.0 applications.

CN116015946BActive Publication Date: 2025-10-17WUHAN SIPU TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211735692.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-31
Publication Date
2025-10-17
Estimated Expiration
2042-12-31

AI Technical Summary

Technical Problem

Traditional firewalls cannot achieve fine-grained network traffic segmentation, resulting in rigid network traffic filtering strategies for Web 2.0 applications, making it impossible to distinguish content and services used for legitimate commercial purposes.

Method used

By obtaining the five-tuple information of network traffic, it is determined whether the network traffic filtering policy configured by the preset five-tuple information of the preset application is matched, and network traffic is allowed or denied.

Benefits of technology

It achieves fine-grained network traffic filtering, which can distinguish and process legitimate and illegitimate network traffic, improving network security and the flexibility of traffic management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116015946B_ABST
    Figure CN116015946B_ABST
Patent Text Reader

Abstract

The application provides a network traffic filtering method, device and network equipment, which is used for network equipment such as a firewall, and can meet the network traffic filtering requirement of fine granularity by processing network traffic of fine granularity. The network traffic filtering method provided by the application comprises the following steps: obtaining target network traffic to be passed through the network equipment; determining five-tuple information of the target network traffic; judging whether the five-tuple information matches a network traffic filtering strategy configured based on preset five-tuple information of a preset application; if yes, passing the target network traffic; and if no, rejecting the target network traffic.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of network security, in particular to a network traffic filtering method and device and network equipment. BACKGROUND

[0002] With the advent of the community network era represented by Web2.0, the Internet has entered the next generation of Internet era represented by forums, blogs, social networking, videos, and P2P sharing applications. Users are no longer one-way information recipients, but content publishers and participants using Web applications as a medium. Under this trend, more and more applications are becoming web-based.

[0003] However, since the basic principle of the traditional firewall is to identify network traffic according to IP address / port number, protocol identifier, and execute related policies, for WebB2.0 applications, all network traffic transmitted based on the browser is the same as seen by the traditional firewall, making it difficult to divide network traffic at a fine granularity. If related traffic or protocols are blocked through these ports, it will prevent all network traffic from Web applications, including legitimate commercial content and services.

[0004] Obviously, the network traffic filtering strategy of the firewall in the prior art has the problem of rigidity and cannot meet the demand for fine-grained network traffic division. SUMMARY

[0005] The present application provides a network traffic filtering method, device and network equipment, which is used for network equipment such as firewalls to process network traffic at a fine granularity, thereby meeting the demand for fine-grained network traffic filtering.

[0006] In a first aspect, the present application provides a network traffic filtering method, the method comprising:

[0007] obtaining target network traffic currently to be passed through a network device;

[0008] determining five-tuple information of the target network traffic;

[0009] judging whether the five-tuple information matches a network traffic filtering strategy configured based on preset five-tuple information of a preset application;

[0010] if matched, passing the target network traffic;

[0011] if not matched, rejecting the target network traffic.

[0012] In combination with the first aspect of the present application, in a first possible implementation manner of the first aspect of the present application, the preset five-tuple information of the preset application specifically includes an application name, a protocol, and a port of the preset application.

[0013] With reference to the first aspect, in a second possible implementation manner of the first aspect, the method further includes:

[0014] determining a baseline application library, wherein the baseline application library includes a plurality of parent applications, and each parent application is arranged with a corresponding child application;

[0015] inducing a to-be-processed application that is currently allowed to pass through network traffic into the baseline application library to form a child application under a corresponding parent application, or adding a to-be-processed application that does not correspond to a parent application to the baseline application library as a new parent application;

[0016] in the baseline application library, obtaining five-tuple information of each application based on an architectural relationship between parent applications and child applications to form preset five-tuple information.

[0017] With reference to the second possible implementation manner of the first aspect, in a third possible implementation manner of the first aspect, the method further includes:

[0018] obtaining a work order five-tuple, wherein the work order five-tuple includes five-tuple information of different applications that are currently to be added to the baseline application library;

[0019] comparing, among the different applications that are currently to be added to the baseline application library, the five-tuple information of the different applications that are currently to be added to the baseline application library with the five-tuple information of each application in the baseline application library, and determining a to-be-processed application that does not have an intersection of five-tuple information.

[0020] With reference to the second possible implementation manner of the first aspect, in a fourth possible implementation manner of the first aspect, an application name of the child application is prefixed with a name of the corresponding parent application.

[0021] With reference to the first aspect, in a fifth possible implementation manner of the first aspect, the method further includes:

[0022] determining different preset applications;

[0023] determining target network devices that network traffic of the different preset applications will pass through in a network architecture;

[0024] deploying network traffic filtering strategies configured based on five-tuple information of the different preset applications on the target network devices that the network traffic of the different preset applications will pass through in the network architecture, respectively.

[0025] With reference to the first aspect, in a sixth possible implementation manner of the first aspect, the method further includes:

[0026] The original network traffic filtering policy on the network device is converted into a network traffic filtering policy configured based on preset five-tuple information of preset applications.

[0027] In a second aspect, the present application provides a network traffic filtering device, the device comprising:

[0028] An acquisition unit configured to acquire target network traffic currently to pass through the network device;

[0029] A determination unit configured to determine five-tuple information of the target network traffic;

[0030] A matching unit configured to judge whether the five-tuple information matches a network traffic filtering policy configured based on preset five-tuple information of preset applications, and if so, trigger a passing unit, and if not, trigger a rejecting unit;

[0031] The passing unit configured to pass the target network traffic;

[0032] The rejecting unit configured to reject the target network traffic.

[0033] In a first possible implementation manner of the second aspect of the present application, the preset five-tuple information of the preset applications specifically comprises application name, protocol and port of the preset applications.

[0034] In a second possible implementation manner of the second aspect of the present application, the device further comprises a configuration unit configured to:

[0035] Determine a baseline application library, wherein the baseline application library comprises a plurality of parent applications, and each parent application is provided with corresponding child applications thereunder;

[0036] Induce the to-be-processed applications currently allowed to pass through the network traffic into the baseline application library to form the child applications under the corresponding parent applications, or add the to-be-processed applications not corresponding to the parent applications as new parent applications into the baseline application library;

[0037] In the baseline application library, acquire the five-tuple information of each application based on the architectural relationship between the parent applications and the child applications to form the preset five-tuple information.

[0038] In the second possible implementation manner of the second aspect of the present application, in a third possible implementation manner, the configuration unit is further configured to:

[0039] Acquire work order five-tuple, wherein the work order five-tuple comprises five-tuple information of different applications currently to be added into the baseline application library;

[0040] In the different applications to be added to the baseline application library, the quintuple information of the different applications to be added to the baseline application library is compared with the quintuple information of each application in the baseline application library, and the to-be-processed application without the intersection of the quintuple information is determined.

[0041] In combination with the second possible implementation manner of the second aspect of the present application, in a fourth possible implementation manner of the second aspect of the present application, the application name of the sub-application is prefixed with the name of the corresponding parent application.

[0042] In combination with the second aspect of the present application, in a fifth possible implementation manner of the second aspect of the present application, the apparatus further includes a configuration unit configured to:

[0043] determine different preset applications;

[0044] determine the target network device through which the network traffic of each of the different preset applications will pass in the network architecture;

[0045] deploy the network traffic filtering strategy configured based on the quintuple information of the different preset applications on the target network device through which the network traffic of each of the different preset applications will pass in the network architecture, respectively.

[0046] In combination with the second aspect of the present application, in a sixth possible implementation manner of the second aspect of the present application, the apparatus further includes a configuration unit configured to:

[0047] convert the original network traffic filtering strategy on the network device into the network traffic filtering strategy configured based on the quintuple information of the preset application.

[0048] In a third aspect, the present application provides a network device including a processor and a memory, the memory storing a computer program, and the processor invoking the computer program in the memory to execute the method provided in the first aspect of the present application or any possible implementation manner of the first aspect of the present application.

[0049] In a fourth aspect, the present application provides a computer readable storage medium storing a plurality of instructions, and the instructions are suitable for being loaded by a processor to execute the method provided in the first aspect of the present application or any possible implementation manner of the first aspect of the present application.

[0050] From the above, the present application has the following beneficial effects:

[0051] The application matches the five-tuple information of the target network traffic with the network traffic filtering policy configured in advance by the application based on the preset five-tuple information of the preset application, so that it can be determined whether the network traffic is from the preset application, and the expected solution target of the network traffic division processing with fine granularity is achieved, thereby meeting the network traffic filtering requirement with fine granularity. BRIEF DESCRIPTION OF DRAWINGS

[0052] In order to more clearly illustrate the technical solutions in the embodiments of the application, the drawings needed to be used in the embodiments will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative effort.

[0053] Figure 1 A flowchart of the network traffic filtering method of the application;

[0054] Figure 2 An interface diagram of the baseline application library of the application;

[0055] Figure 3 An application relationship diagram of the parent application and the child application of the application;

[0056] Figure 4 A structural diagram of the network traffic filtering device of the application;

[0057] Figure 5 A structural diagram of the network device of the application. DETAILED DESCRIPTION

[0058] The technical solutions in the embodiments of the application will be described clearly and completely with reference to the drawings of the embodiments of the application. Obviously, the described embodiments are only some of the embodiments of the application, not all the embodiments. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the application.

[0059] The terms "first", "second", and the like in the description and in the claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data thus used can be interchanged, where appropriate, so that the embodiments described herein can be carried out in sequences other than those illustrated or described herein. Furthermore, the terms "comprise" and "have", and any variations thereof, are intended to cover non-exclusive inclusion, for example, processes, methods, systems, products, or devices that include a series of steps or modules are not necessarily limited to those steps or modules that are clearly listed, but can include other steps or modules that are not clearly listed or inherent to these processes, methods, products, or devices. The naming or numbering of the steps appearing in the present application does not mean that the steps in the method flow must be performed in the order / time sequence indicated by the naming or numbering, and the flow steps that have been named or numbered can change the order of execution according to the technical purpose to be achieved, as long as the same or similar technical effects can be achieved.

[0060] The division of modules appearing in the present application is a logical division, and in actual application, there can be another division manner, for example, a plurality of modules can be combined or integrated in another system, or some features can be ignored or not executed, in addition, the coupling or direct coupling or communication connection between the displayed or discussed each other can be through some interface, the indirect coupling or communication connection between the modules can be electrical or other similar forms, which are not limited in the present application. Moreover, the modules or sub-modules described as separate components can or can not be physically separated, can or can not be physical modules, or can be distributed to a plurality of circuit modules, and part or all of the modules can be selected according to actual needs to achieve the purpose of the present application.

[0061] Before introducing the network traffic filtering method provided by the present application, the background content involved in the present application is first introduced.

[0062] The network traffic filtering method, device and computer readable storage medium provided by the present application can be applied to network equipment, and is used for network equipment such as firewall, etc. Through the fine granularity network traffic division processing, the fine granularity network traffic filtering demand can be met.

[0063] The network traffic filtering method mentioned in the present application can be the network traffic filtering device, or the firewall, switch, router and other different types of network equipment integrated with the network traffic filtering device. The network traffic filtering device can be realized by hardware or software, and the network equipment can also be set by device cluster.

[0064] It can be understood that the network traffic filtering method provided in the application is network architecture-oriented, and can be specifically applied to different types of network devices in the network architecture. The specific execution subject can be adjusted according to actual conditions. When the network traffic filtering method provided in the application is applied, the network device can also be configured in the form of a network device cluster, and a processing device (included in the category of network devices, specially used to serve the original network device) for centralized control / processing can also be configured to provide unified data processing services between network devices.

[0065] Next, the network traffic filtering method provided in the application will be introduced.

[0066] First, referring to Figure 1 , Figure 1 a flowchart of the network traffic filtering method of the application is shown. The network traffic filtering method provided in the application can specifically include the following steps S101 to S105:

[0067] Step S101, obtaining target network traffic currently passing through the network device;

[0068] It can be understood that the application is proposed from the perspective of network traffic filtering whether the network traffic passing through the network device, so it can start from obtaining the target network traffic currently passing through the network device.

[0069] Among them, the target network traffic currently passing through the network device is the network traffic related to Web service, that is, Web network traffic, so as to effectively solve the above-mentioned prior art problems, that is, the existing Web network traffic filtering strategy has the problem of rigidity. Of course, in addition to Web network traffic, other types of network traffic can also be processed by the network device through the application.

[0070] Among them, the network device related in the application can be specifically a firewall, a switch, a router and other different types of network devices, which can be adjusted according to the specific network device deployment requirements in the network architecture.

[0071] Step S102, determining the five-tuple information of the target network traffic;

[0072] In the application, the division of network traffic is based on five-tuple information, the specific content of which is described in the subsequent steps.

[0073] Correspondingly, after determining the current target network traffic, the five-tuple information thereof can be determined to provide processing basis for subsequent data processing.

[0074] The quintuple information is generally directly carried in the target network flow. Specifically, the network flow is embodied / configured in the form of a data packet, and the quintuple information can be carried in a header and extracted from a preset field position in the header.

[0075] In step S103, it is determined whether the quintuple information matches a network flow filtering policy configured based on preset quintuple information of a preset application. If yes, step S104 is triggered; if no, step S105 is triggered.

[0076] Specifically, the application concept is introduced in the present application, so that only network flow from part of the applications can pass through the network device. Thus, the preset quintuple information of the network flow of these applications can be determined in advance, and the network flow filtering policy is configured based on the preset quintuple information.

[0077] Thus, after the quintuple information of the target network flow to be passed through the network device is determined, the quintuple information can be matched with the network flow filtering policy configured based on the preset quintuple information of the preset application. If the match is successful, it is determined that the target network flow is network flow from the preset application allowed to pass through, and step S104 is triggered. Otherwise, step S105 is triggered.

[0078] In the present application, after the quintuple information of the network flow to be identified is managed by the application unit, the specific quintuple information can be located by the application when the network flow of the specific application is allowed to pass through the network device in sequence. Thus, the network flow filtering policy configured based on the quintuple information is more conveniently managed, and the application is more convenient.

[0079] In step S104, the target network flow is passed through.

[0080] It can be understood that after the target network flow is determined to belong to the network flow of the specific application allowed to pass through in step S103, the target network flow is released and allowed to pass through the network device and continue to be sent to the next network node.

[0081] In step S105, the target network flow is rejected.

[0082] It can be understood that after the target network flow is determined not to belong to the network flow of the specific application allowed to pass through in step S103, the target network flow is rejected and cannot pass through the network device. At this time, the target network flow can be ignored or deleted, so that the target network flow cannot pass through the network device and cannot continue to be sent to the next network node.

[0083] For the convenience of understanding the above content, the following example can also be used for illustration. For the convenience of understanding the above content, the following example can also be used for illustration.

[0084] For a certain platform, the portal of the platform can be accessed by various Web services in the prior art, however, among the users accessing the platform through various channels, there can be bad users, whose access purpose is to prepare for or is already initiating a network attack, and such security problems are difficult to prevent.

[0085] However, after the application is applied, the channels that can be effectively accessed can be restricted, i.e., the user needs to initiate access through a preset application allowed by the application to pass network traffic, obviously, this setting can meet the access needs of normal users (if normal access, the access is initiated through the preset application that is allowed by the application to pass, obviously, this setting can meet the access needs of normal users), and can effectively and significantly restrict the initiation channel of a network attack. For a preset application, it is usually an application with a large user scale or a high security level, and therefore the application itself has a high security policy, and the users of the application are basically normal users, and therefore the network security of the portal platform can be significantly improved.

[0086] From Figure 1 As can be seen from the embodiments shown in the drawings, the application matches the five-tuple information of the target network traffic with the network traffic filtering strategy configured in advance by the application based on the preset five-tuple information of the preset application, so that it can be determined whether the network traffic is from the preset application, and the expected scheme target of fine-grained network traffic division processing is achieved, and therefore the fine-grained network traffic filtering requirement can be met.

[0087] The steps of the above-mentioned embodiments and the possible implementation manners thereof in actual application are described in detail. Figure 1

[0088] Specifically, the preset five-tuple information of the preset application involved in the above content can specifically include the application name, protocol and port of the preset application as a practical implementation manner.

[0089] It can be understood that when determining whether the network traffic belongs to the network traffic of a specific application, the application name in the five-tuple information can be directly compared, or the related protocol or related port of the specific application can be compared.

[0090] ​Specifically, in actual application, the network traffic allowed to pass through the specific application can be matched with the preset five-tuple information of the preset application in one of the application name, the protocol and the port, or can be matched with the preset five-tuple information of the preset application in all of the three, obviously, it will be affected by the specific content of the preset five-tuple information of the preset application, and will be affected by the preset application, therefore, it can be set to match only one to be considered to match the network traffic matching strategy configured based on the preset five-tuple information, so as to be more flexible and convenient in application while meeting the purpose of accurately identifying the network traffic belonging to the preset application.

[0091] In addition, as another practical implementation manner, the preset five-tuple information of the preset application can also be configured in the process of the preset application, and the corresponding optimization setting can also be provided, and the method of the application can also include:

[0092] determining a baseline application library, wherein the baseline application library includes a plurality of parent applications, and the parent applications are provided with corresponding child applications thereunder;

[0093] inducing the to-be-processed application allowed to pass through the network traffic into the baseline application library to form the child application under the corresponding parent application, or adding the to-be-processed application not corresponding to the parent application as a new parent application to the baseline application library;

[0094] obtaining the five-tuple information of each application based on the architectural relationship of the parent application and the child application in the baseline application library to form the preset five-tuple information.

[0095] It can be seen that the preset five-tuple information of the preset application is deployed / updated in the embodiment, and the concept of the baseline application library is introduced, and the architectural setting of the parent application and the child application also exists in the baseline application library, so that the preset application allowed to pass through the network traffic is more intelligently divided.

[0096] Therefore, in actual application, on the one hand, the child application can reuse the related five-tuple information of the parent application, which is beneficial to simplify the data processing amount, and is also beneficial to the convenience, accuracy of subsequent matching processing, and on the other hand, it is also beneficial to the actual business processing, and it is convenient to divide the application related to the specific manufacturer / platform to configure the corresponding network traffic filtering strategy.

[0097] For example, taking a large company as an example, the company involves N applications, one of which X application involves the basic application service of other applications, at this time, the X application can be configured as a parent application, and the other applications can be configured as child applications of the X application; or, the company involves N applications, one of which Y application is the main application of the company, at this time, the Y application can be configured as a parent application, and the other applications can be configured as child applications of the Y application.

[0098] Obviously, the so-called parent application-child application architecture relationship does not have an absolute fixed superior-inferior relationship, and the superior-inferior relationship can be adjusted as needed, and the application is convenient.

[0099] In this case, the application can be updated in the baseline application library for the current application allowed by the network traffic, thereby continuing to update the network traffic filtering policy based on the preset quintuple information of the preset application involved in the subsequent matching processing.

[0100] In practical applications, the application library of a certain manufacturer can be connected as a baseline application library, and the baseline application library can support addition, deletion, modification and query. When the baseline application library cannot meet the applications of other manufacturers, applications can be added to the baseline application library to maintain a large and complete baseline application library.

[0101] For the maintenance of the mapping relationship between the applications of each manufacturer and the baseline application library, in general, the applications accessed by the internal personnel of the enterprise are usually common applications, so for this case, the applications of each manufacturer can be automatically / manually mapped to the baseline application library. The parent application is mapped to the parent application, and the child application is mapped to the child application. Please refer to Figure 2 The interface diagram of the baseline application library of the present application is shown, and the background database can be mapped by the application name. Please refer to Figure 3 The application relationship diagram of the parent application-child application of the present application is shown.

[0102] In this way, even if there are various situations of each manufacturer, it can be conveniently normalized to the baseline application library for standardized, standardized and unified management.

[0103] In the baseline application library, the description of the related application can be combined with the preset quintuple information involved in the previous embodiment, which specifically includes the setting of the application name, protocol and port of the preset application. Specifically, it can include:

[0104] Application name (full name / abbreviation in Chinese and English), application ID (specific identifier), protocol, port, description,

[0105] Among them, the application name and the application ID can be considered as the application name mentioned above, which is the application name in different forms.

[0106] Among them, in order to further facilitate the identification effect of the parent application-child application relationship, and also to make the presentation more intuitive, it can also be configured with:

[0107] The application name of the child application is prefixed with the name of the corresponding parent application.

[0108] For example, the application ID of the sub-application in the baseline application library can be "parent application ID_self ID".

[0109] Obviously, under this setting, the application relationship between the parent application and its sub-application can be intuitively seen, which is convenient for the specific processing of the business, and the standardization of the application name also ensures the convenience and orderliness of data processing.

[0110] In addition, corresponding to the business processing of the to-be-processed application currently allowed to pass through the network traffic in the actual situation in the above embodiment, as another practical implementation manner, the method of the present application can further include:

[0111] Obtaining a work order five tuple, wherein the work order five tuple includes five tuple information of different applications currently to be added to the baseline application library;

[0112] Among the different applications currently to be added to the baseline application library, the five tuple information of the different applications currently to be added to the baseline application library is compared with the five tuple information of each application in the baseline application library, and a to-be-processed application with no intersecting five tuple information is determined.

[0113] It can be understood that in the business processing, the baseline application library can be updated in the form of a work order to achieve the purpose of automatic operation and maintenance.

[0114] Specifically, the staff / system can input the content of the work order five tuple, which itself also describes the corresponding situation of the different applications currently to be added to the baseline application library. At this time, the content can be compared with the five tuple information of each application in the baseline application library to determine whether there is an intersection, i.e., a duplication. If there is an intersection / duplication, obviously, the application does not need to be added again. Conversely, if there is no intersection / duplication, it can be determined as a to-be-processed application, which needs to be updated and processed by the baseline application library.

[0115] An example is shown below to assist in explaining the work order processing content in the actual application of the embodiment.

[0116] The overall idea is to obtain the five tuple information of the network traffic currently rejected by the network traffic filtering policy by comparing the work order five tuple and the network traffic filtering policy, and then generate a network traffic filtering policy that allows the network traffic to pass according to the five tuple information of the rejected network traffic.

[0117] The specific logic is as follows:

[0118] Case 1. The processing object in the work order five tuple and the network traffic filtering policy is an application

[0119] The work order five tuple and the network traffic filtering policy are intersected, the intersection of the application IDs is obtained, if the action of the network traffic filtering policy is deny, the intersection content is placed into the deny set, if it is permit, the matching continues.

[0120] Case 2. The processing object of the work order five tuple is a protocol and a port, and the processing object of the network traffic filtering policy is an application

[0121] The work order five tuple information is compared from top to bottom with the network traffic filtering policy, then the matching is skipped and is regarded as a miss.

[0122] Case 3. The processing object of the work order five tuple is an application, and the processing object of the network traffic filtering policy is a protocol and a port

[0123] According to the work order five tuple, the protocol and the port of the corresponding application are determined, so as to compare with the protocol and the port of the network traffic filtering policy.

[0124] Case 3.1 If the work order five tuple is completely contained by the network traffic filtering policy, the intersection is obtained, and then the action of the network traffic filtering policy is judged, if it is deny, the intersection is placed into the deny set, if it is permit, the matching continues.

[0125] Case 3.2 If the work order five tuple is not completely contained by the network traffic filtering policy, the rule is skipped and is regarded as a miss.

[0126] Case 4. The processing object of the work order five tuple and the network traffic filtering policy is a protocol and a port at the same time

[0127] The work order five tuple and the network traffic filtering policy are intersected, if the action of the network traffic filtering policy is deny, the intersection content is placed into the deny set, if it is permit, the matching continues.

[0128] Up to now, the work order five tuple is divided into deny and permit two parts of data flow.

[0129] Among them, the deny data flow corresponds to the related application which does not exist in the baseline application library, that is, the application to be processed involved in the foregoing, at this time, it can be updated to the baseline application library.

[0130] In addition, the present application promotes more detailed network traffic division / filtering effect at the detail level, and different network devices can also be configured with different network traffic filtering policies, correspondingly, as another practical implementation manner, the method of the present application can further include:

[0131] Different preset applications are determined;

[0132] determine the target network devices through which the network traffic of different preset applications will pass in the network architecture;

[0133] deploy the network traffic filtering strategies configured based on the five-tuple information of different preset applications on the target network devices through which the network traffic of different preset applications will pass in the network architecture.

[0134] It can be understood that, for the setting of configuring different network traffic filtering strategies on different network devices, different preset applications can be used, such as in the above process, different preset applications in the baseline application library can be determined first, and then the target network devices through which the corresponding network traffic of these preset applications will pass in the network architecture can be determined, at this time, the network traffic filtering strategies related to each preset application can be configured based on the target network devices corresponding to these preset applications, so as to achieve the deployment effect of fine and subdivided network traffic filtering strategies.

[0135] As an example, after the system / staff inputs the work order five-tuple, the starting device can be located according to the source IP, and then the routing information can be queried one by one from the starting device according to the destination IP, so as to obtain all network devices through which the network traffic corresponding to the work order will pass, all network devices in the path are the target network devices related to the work order five-tuple, after the target network devices related to the work order five-tuple are determined, the passing permission of the network traffic of the application corresponding to the work order five-tuple can be opened only on these target network devices, and the network traffic filtering strategy of the corresponding application can be deployed.

[0136] In addition, for network devices, the present application can also involve the modification of the original network traffic filtering strategy, specifically, in another practical implementation mode, the method of the present application can further include:

[0137] convert the original network traffic filtering strategy on the network device into a network traffic filtering strategy configured based on the five-tuple information of the preset application.

[0138] It can be understood that, for the preset application, the network traffic filtering strategy configured based on the five-tuple information of the preset application is configured, and on the network device, there will also be part of the network traffic filtering measurement different from the configuration form of the strategy.

[0139] In order to promote the form alignment of the strategy and realize unified standardization, and also in order to preserve the filtering target of the original strategy, it can be detected whether there is an original network traffic filtering strategy not configured in the form of the network traffic filtering strategy based on the five-tuple information of the preset application, if there is, it can be converted into a network traffic filtering strategy configured based on the five-tuple information of the preset application.

[0140] The above is an introduction to the network traffic filtering method provided by the present application. In order to better implement the network traffic filtering method provided by the present application, the present application also provides a network traffic filtering device from the perspective of functional modules.

[0141] Reference Figure 4 , Figure 4 Fig. 1 is a structural schematic diagram of the network traffic filtering device of the present application. In the present application, the network traffic filtering device 400 can specifically include the following structures:

[0142] The acquisition unit 401 is configured to acquire target network traffic currently to be passed through the network device;

[0143] The determination unit 402 is configured to determine five-tuple information of the target network traffic;

[0144] The matching unit 403 is configured to judge whether the five-tuple information matches a network traffic filtering policy configured based on preset five-tuple information of a preset application. If the matching is successful, the passing unit 404 is triggered. If the matching is unsuccessful, the rejection unit 405 is triggered.

[0145] The passing unit 404 is configured to pass the target network traffic;

[0146] The rejection unit 405 is configured to reject the target network traffic.

[0147] In an exemplary implementation, the preset five-tuple information of the preset application specifically includes an application name, a protocol, and a port of the preset application.

[0148] In another exemplary implementation, the device further includes a configuration unit 406 configured to:

[0149] determine a baseline application library, wherein the baseline application library includes a plurality of parent applications, and each parent application is provided with a corresponding child application thereunder;

[0150] induce a to-be-processed application currently allowed to pass through the network traffic into the baseline application library to form a child application under the corresponding parent application, or add a to-be-processed application not corresponding to a parent application as a new parent application to the baseline application library;

[0151] In the baseline application library, acquire the five-tuple information of each application based on the architectural relationship between the parent applications and the child applications to form the preset five-tuple information.

[0152] In another exemplary implementation, the configuration unit 406 is further configured to:

[0153] acquire a work order five-tuple, wherein the work order five-tuple includes five-tuple information of different applications currently to be added to the baseline application library;

[0154] In the different applications to be added to the baseline application library, the quintuple information of the different applications to be added to the baseline application library is compared with the quintuple information of the applications in the baseline application library, and the to-be-processed applications with quintuple information not existing intersection are determined.

[0155] In yet another exemplary implementation, the application name of the sub-application is prefixed with the name of the corresponding parent application.

[0156] In yet another exemplary implementation, the apparatus further comprises a configuration unit 406 configured to:

[0157] determine different preset applications;

[0158] determine the target network device through which the network traffic of the different preset applications will pass in the network architecture;

[0159] deploy the network traffic filtering strategies configured based on the quintuple information of the different preset applications on the target network device through which the network traffic of the different preset applications will pass in the network architecture, respectively.

[0160] In yet another exemplary implementation, the apparatus further comprises a configuration unit 406 configured to:

[0161] convert the original network traffic filtering strategy on the network device into the network traffic filtering strategy configured based on the quintuple information of the preset application.

[0162] The present application also provides a network device from the hardware structure, specifically, for the convenience of description, the network device applying the network traffic filtering method of the present application (including the multiple network devices mentioned above and even including the processing device) is treated as a hardware device, and the network device of the present application is shown in a structural schematic diagram, specifically, the network device of the present application can comprise a processor 501, a memory 502 and an input and output device 503, the processor 501 is used to execute the computer program stored in the memory 502 to realize the steps of the network traffic filtering method in the corresponding embodiments, or the processor 501 is used to execute the computer program stored in the memory 502 to realize the functions of the units in the corresponding embodiments, the memory 502 is used to store the computer program required by the network traffic filtering method in the corresponding embodiments. Figure 5 , Figure 5 The network device of the present application is shown in a structural schematic diagram, specifically, the network device of the present application can comprise a processor 501, a memory 502 and an input and output device 503, the processor 501 is used to execute the computer program stored in the memory 502 to realize the steps of the network traffic filtering method in the corresponding embodiments, or the processor 501 is used to execute the computer program stored in the memory 502 to realize the functions of the units in the corresponding embodiments, the memory 502 is used to store the computer program required by the network traffic filtering method in the corresponding embodiments. Figure 1 The network device of the present application is shown in a structural schematic diagram, specifically, the network device of the present application can comprise a processor 501, a memory 502 and an input and output device 503, the processor 501 is used to execute the computer program stored in the memory 502 to realize the steps of the network traffic filtering method in the corresponding embodiments, or the processor 501 is used to execute the computer program stored in the memory 502 to realize the functions of the units in the corresponding embodiments, the memory 502 is used to store the computer program required by the network traffic filtering method in the corresponding embodiments. Figure 4 The network device of the present application is shown in a structural schematic diagram, specifically, the network device of the present application can comprise a processor 501, a memory 502 and an input and output device 503, the processor 501 is used to execute the computer program stored in the memory 502 to realize the steps of the network traffic filtering method in the corresponding embodiments, or the processor 501 is used to execute the computer program stored in the memory 502 to realize the functions of the units in the corresponding embodiments, the memory 502 is used to store the computer program required by the network traffic filtering method in the corresponding embodiments. Figure 1 The network device of the present application is shown in a structural schematic diagram, specifically, the network device of the present application can comprise a processor 501, a memory 502 and an input and output device 503, the processor 501 is used to execute the computer program stored in the memory 502 to realize the steps of the network traffic filtering method in the corresponding embodiments, or the processor 501 is used to execute the computer program stored in the memory 502 to realize the functions of the units in the corresponding embodiments, the memory 502 is used to store the computer program required by the network traffic filtering method in the corresponding embodiments.

[0163] For example, the computer program can be divided into one or more modules / units, one or more modules / units are stored in the memory 502 and executed by the processor 501 to complete the present application. One or more modules / units can be a series of computer program instruction segments capable of completing a specific function, which are used to describe the execution process of the computer program in the computer device.

[0164] The network device can include, but is not limited to, the processor 501, the memory 502, and the input / output device 503. Those skilled in the art can understand that the schematic diagram is only an example of the network device and does not constitute a limitation on the network device, which can include more or fewer components than the schematic diagram, or combine certain components, or different components, for example, the network device can also include a network access device, a bus, etc., and the processor 501, the memory 502, and the input / output device 503 are connected through the bus.

[0165] The processor 501 can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The processor is the control center of the network device, which connects all parts of the device through various interfaces and lines.

[0166] The memory 502 can be used to store computer programs and / or modules, and the processor 501 realizes various functions of the computer device by running or executing the computer programs and / or modules stored in the memory 502, and calling the data stored in the memory 502. The memory 502 can mainly include a program storage area and a data storage area, wherein the program storage area can store operating systems, at least one application required by a function, etc.; the data storage area can store data created according to the use of the network device, etc. In addition, the memory can include a high-speed random access memory, and can also include a non-volatile memory, for example, a hard disk, a memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state memory devices.

[0167] The processor 501 is configured to execute a computer program stored in the memory 502, and specifically can implement the following functions:

[0168] Obtaining target network traffic currently passing through the network device;

[0169] Determining five-tuple information of the target network traffic;

[0170] Determining whether the five-tuple information matches a network traffic filtering policy configured based on preset five-tuple information of a preset application;

[0171] If the match is found, passing the target network traffic;

[0172] If the match is not found, rejecting the target network traffic.

[0173] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the network traffic filtering device, the network device and the corresponding units described above can be referred to as Figure 1 the description of the network traffic filtering method in the corresponding embodiments, which will not be repeated here.

[0174] Those skilled in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructions, or by relevant hardware controlled by the instructions, which can be stored in a computer readable storage medium and loaded and executed by a processor.

[0175] To this end, the present application provides a computer readable storage medium, which stores a plurality of instructions capable of being loaded by a processor to execute the steps of the network traffic filtering method of the present application as Figure 1 the corresponding embodiments, and the specific operations can be referred to as Figure 1 the description of the network traffic filtering method in the corresponding embodiments, which will not be repeated here.

[0176] The computer readable storage medium can include a read only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.

[0177] Since the instructions stored in the computer readable storage medium can execute the steps of the network traffic filtering method of the present application as Figure 1 the corresponding embodiments, the beneficial effects of the network traffic filtering method of the present application as Figure 1 the corresponding embodiments can be achieved, and the details are described above and will not be repeated here.

[0178] The network traffic filtering method, device, network equipment and computer readable storage medium provided by the present application are described in detail above, the principles and implementation modes of the present application are described in this paper, and the above examples are only used to help understand the method and core idea of the present application; at the same time, for those skilled in the art, according to the idea of the present application, the specific implementation mode and application range will be changed, and the above description should not be understood as the limitation of the present application.

Claims

1. A network traffic filtering method, characterized in that: The method comprises: Get the target network traffic that is currently passing through the network device; Determining quintuple information of the target network traffic; Determining whether the quintuple information matches a network traffic filtering policy configured based on preset quintuple information of a preset application; If there is a match, the target network traffic is passed; If there is no match, the target network traffic is denied; The method further comprises: Determine a baseline application library, wherein the baseline application library includes a plurality of parent applications, and corresponding child applications are provided under the parent applications; Integrate the pending applications that are currently allowed to pass network traffic into the baseline application library to form the sub-applications corresponding to the parent application, or add the pending applications that do not correspond to the parent application as new parent applications to the baseline application library; In the baseline application library, based on the architectural relationship between the parent application and the child application, quintuple information of each application is obtained to form the preset quintuple information; The method further comprises: Acquire a work order quintuple, wherein the work order quintuple includes quintuple information of different applications currently to be added to the baseline application library; Comparing the five-tuple information of the different applications to be added to the baseline application library with the five-tuple information of each application in the baseline application library among the different applications to be added to the baseline application library, and determining the to-be-processed applications for which the five-tuple information does not intersect; The application name of the sub-application is prefixed with the name of the corresponding parent application.

2. The method according to claim 1, characterized in that The preset five-tuple information of the preset application specifically includes the application name, protocol and port of the preset application.

3. The method according to claim 1, characterized in that The method further comprises: determining different preset applications; Determine target network devices that the network traffic of different preset applications will pass through in the network architecture; The network traffic filtering policies configured based on the quintuple information of different preset applications are respectively deployed on target network devices that the network traffic of the different preset applications will pass through in the network architecture.

4. The method according to claim 1, wherein The method further comprises: The original network traffic filtering policy on the network device is converted into the network traffic filtering policy configured based on the quintuple information of the preset application.

5. A network traffic filtering device, characterized in that: The device comprises: An acquisition unit, used for acquiring target network traffic currently passing through the network device; a determining unit, configured to determine quintuple information of the target network traffic; a matching unit, configured to determine whether the five-tuple information matches a network traffic filtering policy configured based on a preset five-tuple information of a preset application, and trigger a pass unit if the policy matches; and trigger a reject unit if the policy does not match; The passing unit is used to pass the target network traffic; The rejecting unit is used to reject traffic from passing through the target network; The device further comprises a configuration unit, configured to: Determine a baseline application library, wherein the baseline application library includes a plurality of parent applications, and corresponding child applications are provided under the parent applications; Integrate the pending applications that are currently allowed to pass network traffic into the baseline application library to form the sub-applications corresponding to the parent application, or add the pending applications that do not correspond to the parent application as new parent applications to the baseline application library; In the baseline application library, based on the architectural relationship between the parent application and the child application, quintuple information of each application is obtained to form the preset quintuple information; The configuration unit is further configured to: Acquire a work order quintuple, wherein the work order quintuple includes quintuple information of different applications currently to be added to the baseline application library; Comparing the five-tuple information of the different applications to be added to the baseline application library with the five-tuple information of each application in the baseline application library among the different applications to be added to the baseline application library, and determining the to-be-processed applications for which the five-tuple information does not intersect; The application name of the sub-application is prefixed with the name of the corresponding parent application.

6. A network device, characterized in that: The method comprises a processor and a memory, wherein a computer program is stored in the memory, and when the processor calls the computer program in the memory, the method according to any one of claims 1 to 4 is executed.

7. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor to execute the method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Automatic acquisition method, apparatus and system of mobile application program traffic, and medium

    CN108804287A