Message traffic management method, service cloud gateway and computer-readable storage medium

By managing message traffic at the service cloud gateway level and connecting with external traffic analysis equipment, the pressure problem caused by secure traffic penetration at the intermediate forwarding equipment level is solved, and efficient and accurate traffic forwarding and Internet security are achieved.

CN116112455BActive Publication Date: 2025-06-06WUHAN GREENET INFORMATION SERVICE
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211714775.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-29
Publication Date
2025-06-06
Estimated Expiration
2042-12-29

AI Technical Summary

Technical Problem

The prior art performs secure traffic penetration at the intermediate forwarding equipment level, resulting in high pressure on secure service processing and low accuracy and speed of traffic forwarding.

Method used

By implementing message traffic management at the service cloud gateway level, using bypass link mode or serial mode to connect with external traffic analysis equipment, perform security analysis and conversion and restoration processing at the gateway level.

Benefits of technology

It alleviates the pressure on security service processing of intermediate forwarding equipment, improves the accuracy and speed of traffic forwarding, ensures network security and intelligently analyzes user traffic.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116112455B_ABST
    Figure CN116112455B_ABST
Patent Text Reader

Abstract

The present application provides a message traffic management method, a service cloud gateway and a computer-readable storage medium. The method is applied to the service cloud gateway. After receiving the initial message traffic from the user terminal, the initial message traffic is processed according to the docking mode between the external traffic analysis device and the service cloud gateway to obtain the processed message traffic, and then the processed message traffic is introduced into the external traffic analysis device so that the external traffic analysis device performs security analysis on the processed message traffic, receives the security message traffic sent by the external traffic analysis device and converts and restores the security message traffic, and finally forwards the restored security message traffic to the Internet. The method realizes security traffic penetration at the gateway level, relieves the security business processing pressure of the intermediate forwarding device without affecting the normal operation of the original business, and improves the accuracy and speed of traffic forwarding.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of message transmission technology, and in particular to a message traffic management method, a service cloud gateway, and a computer-readable storage medium. Background Art

[0002] Currently, most physical gateway devices are used in the market, which cannot perform security traffic penetration at the gateway level. Security traffic penetration can only be performed at the level of intermediate forwarding devices (such as optical line terminals OLT). However, due to the large number of users carried on the intermediate forwarding devices, it causes great pressure when processing security services, which seriously affects the performance of traffic forwarding and cannot accurately and quickly penetrate the traffic to the external traffic analysis equipment.

[0003] Therefore, the current technology has technical problems such as high pressure on security business processing and low accuracy and speed of traffic forwarding, which need to be improved. Summary of the invention

[0004] The present application provides a message traffic management method, a service cloud gateway and a computer-readable storage medium, which are used to reduce the pressure of security service processing and improve the accuracy and speed of traffic forwarding.

[0005] In order to solve the above technical problems, this application provides the following technical solutions:

[0006] The present application provides a message traffic management method, which is applied to a service cloud gateway, and the method includes:

[0007] Receiving initial message traffic from a user terminal;

[0008] According to the docking mode between the external traffic analysis device and the service cloud gateway, the initial message traffic is processed to obtain the processed message traffic; wherein the docking mode includes a bypass link mode or a serial connection mode;

[0009] Introducing the processed message traffic into the external traffic analysis device so that the external traffic analysis device performs security analysis on the processed message traffic;

[0010] Receiving the security message traffic sent by the external traffic analysis device;

[0011] The secure message traffic is converted and restored, and the restored secure message traffic is forwarded to the Internet.

[0012] Accordingly, the present application also provides a service cloud gateway, including:

[0013] A first receiving module, used for receiving initial message traffic from a user terminal;

[0014] A first processing module, used to process the initial message traffic according to the docking mode between the external traffic analysis device and the service cloud gateway to obtain processed message traffic; wherein the docking mode includes a bypass link mode or a serial connection mode;

[0015] A security analysis module, used for introducing the processed message traffic into the external traffic analysis device, so that the external traffic analysis device performs security analysis on the processed message traffic;

[0016] A second receiving module, used to receive the security message traffic sent by the external traffic analysis device;

[0017] The conversion and restoration module is used to convert and restore the secure message traffic and forward the restored secure message traffic to the Internet.

[0018] In addition, the present application also provides a computer-readable storage medium, which stores multiple instructions, and the instructions are suitable for a processor to load to execute the steps in the above-mentioned message traffic management method.

[0019] Beneficial effects: The present application provides a message traffic management method, a service cloud gateway, and a computer-readable storage medium. Specifically, the method is applied to a service cloud gateway. After receiving the initial message traffic from the user terminal, the service cloud gateway processes the initial message traffic according to the docking mode between the external traffic analysis device and the service cloud gateway, which includes a bypass link mode or a serial connection mode, to obtain processed message traffic, and then introduces the processed message traffic into the external traffic analysis device so that the external traffic analysis device performs security analysis on the processed message traffic, and then after receiving the secure message traffic sent by the external traffic analysis device, converts and restores the secure message traffic, and forwards the restored secure message traffic to the Internet. This method relieves the pressure of security business processing on the intermediate forwarding device by changing the processing of security traffic penetration from the original processing at the intermediate conversion device level to the processing at the gateway level. At the same time, the initial message traffic is processed through the docking mode of the external traffic analysis device and the business cloud gateway, and the processed message traffic is introduced into the external traffic analysis device, so that the external traffic analysis device can perform security analysis and processing on the message traffic. Without affecting the original business, it not only ensures Internet access efficiency and improves the accuracy and speed of traffic forwarding, but also ensures Internet security by intelligently analyzing the user's Internet traffic and filtering potential network attack risks. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The technical solution and other beneficial effects of the present application will be made apparent by describing in detail the specific implementation methods of the present application in conjunction with the accompanying drawings.

[0021] Figure 1 It is a system architecture diagram of the message traffic management system provided in an embodiment of the present application.

[0022] Figure 2 It is a flow chart of the message traffic management method provided in the embodiment of the present application.

[0023] Figure 3 It is a data flow diagram of the bypass link mode provided in an embodiment of the present application.

[0024] Figure 4 It is a schematic diagram of data flow in the serial mode provided in an embodiment of the present application.

[0025] Figure 5 It is a structural diagram of the business cloud gateway provided in an embodiment of the present application. DETAILED DESCRIPTION

[0026] The technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present application.

[0027] The terms "including" and "having" and any variations thereof in the specification and claims of this application are intended to cover non-exclusive inclusions; the division of modules appearing in this application is merely a logical division, and there may be other division methods when implemented in actual applications, for example, multiple modules may be combined or integrated into another system, or some features may be ignored or not executed.

[0028] The present application provides a message traffic management method, a service cloud gateway, and a computer-readable storage medium.

[0029] See also Figure 1 , Figure 1 is a system architecture diagram of the message traffic management system provided in the embodiment of the present application, such as Figure 1 As shown, the message traffic management system may include terminals and servers, and the terminals, servers, and terminals and servers are connected and communicated through the Internet composed of various gateways, etc., wherein the system at least includes a user terminal 101, an access cloud gateway 102, a service cloud gateway 103, an external traffic analysis device 104, and the Internet 105:

[0030] The user terminal 101 refers to a device used to connect to the edge device of the PTN network, including a terminal device used to connect to the optical fiber trunk line, such as an optical line terminal (OLT). It should be noted that multiple optical modem devices can be connected to one optical line terminal through a splitter.

[0031] The access cloud gateway 102 refers to the edge access layer located in the soft switch architecture, and provides a cloud gateway that simulates a user line interface. In a three-layer IP network, the access cloud gateway generally refers to various IP gateway devices that connect to user hosts at the edge of the network, where the cloud gateway simulates a disk array, a block-based device or a file server. The access cloud gateway can provide scenario-based network access services for users to quickly access the cloud and flexibly build a hybrid cloud.

[0032] The service cloud gateway 103 refers to the cloud gateway device that connects the service network and the bearer network, completes the function of the service access layer in the architecture, and mainly provides necessary protocol conversion for mobile terminals when using data services. Different service gateways are set for services with different protocol conversion types.

[0033] The external traffic analysis device 104 refers to a device (such as a security pool) used for data cleaning, network analysis, and other servers. The external traffic analysis device contains a global security IP library provided by the operator. It should be noted that the business cloud gateway can be connected to the external traffic analysis device through a bypass link mode or a serial module.

[0034] The Internet 105 refers to a huge network of networks connected in series. These networks are connected by a set of common protocols to form a logically single huge international network.

[0035] A communication link is provided between the user terminal 101, the access cloud gateway 102, the service cloud gateway 103, the external traffic analysis device 104 and the Internet 105 to realize information interaction; the type of the communication link may include a wired or wireless communication link or an optical fiber cable, etc., which is not limited in this application, wherein:

[0036] The user terminal 101 sends an initial message traffic to the access cloud gateway 102, and the access cloud gateway 102 forwards the initial message traffic to the service cloud gateway 103. After receiving the initial message traffic from the user terminal, the service cloud gateway 103 processes the initial message traffic according to the docking mode between the external traffic analysis device 104 and the service cloud gateway 103, wherein the docking mode includes a bypass link mode or a serial connection mode, to obtain processed message traffic, and then introduces the processed message traffic to the external traffic analysis device 104. The external traffic analysis device 104 performs security analysis on the processed message traffic to obtain secure message traffic, and then sends the secure message traffic to the service cloud gateway 103. After receiving the secure message traffic sent by the external traffic analysis device, the service cloud gateway 103 converts and restores the secure message traffic to obtain restored secure message traffic, and sends the restored secure message traffic to the access cloud gateway 102. The access cloud gateway 102 sends the restored secure message traffic to the Internet 105, completing the secure Internet access of the user terminal.

[0037] In the above process, the original security traffic penetration at the intermediate conversion device level is changed to security traffic penetration at the gateway level, which alleviates the security business processing pressure of the intermediate forwarding device. At the same time, the initial message traffic is processed through the docking mode of the external traffic analysis device and the business cloud gateway, and the processed message traffic is introduced into the external traffic analysis device, so that the external traffic analysis device can perform security analysis and processing on the message traffic. Without affecting the original business, it not only ensures Internet access efficiency and improves the accuracy and speed of traffic forwarding, but also filters potential network attack risks through intelligent analysis of users' Internet traffic, thereby ensuring Internet security.

[0038] It should be noted that Figure 1 The system architecture diagram shown is only an example. The terminals, devices, and scenarios described in the embodiments of this application are intended to more clearly illustrate the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. It is known to those skilled in the art that with the evolution of the system and the emergence of new business scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems. The following are described in detail. It should be noted that the order of description of the following embodiments is not intended to limit the preferred order of the embodiments.

[0039] In the embodiments of this application, please refer to Figure 2 As shown, Figure 2 1 is a flow chart of a message traffic management method provided in an embodiment of the present application, and the message traffic management method is applied to a service cloud gateway. The method comprises at least the following steps:

[0040] S201: receiving initial message traffic from a user terminal.

[0041] Edge cloud gateway devices have gradually developed into a new network deployment solution due to their low cost, easy deployment and easy scalability. More and more telecom operators have begun to deploy cloud network services. Therefore, the embodiment of the present application is based on the cloud network deployment of the new metropolitan area network, introduces cloud security services for traffic penetration, and uses a service cloud gateway to process the access message traffic.

[0042] Specifically, when a user uses a user terminal to request to access the Internet, the user terminal packages the user's Internet access request data (such as the page you want to visit, the video you want to watch, the network file you want to download, etc.) into an initial message flow and sends it to the access cloud gateway, so that the access cloud gateway can connect the user terminal and the Internet based on the received initial message flow, so that the user terminal can successfully access the Internet. However, in order to ensure the security of the initial message flow, after receiving the initial message flow, the access cloud gateway needs to forward the initial message flow to the business cloud gateway. At this time, the business cloud gateway has received the initial message flow from the user terminal, and the business cloud gateway processes the initial message flow (such as necessary protocol conversion, etc.) and then transfers it back to the access cloud gateway, so as to achieve Internet access.

[0043] In one embodiment, the initial message traffic includes a network address translation IP, and the initial message traffic of different user terminals includes different network address translation IPs. Specifically, different user terminal accounts (such as optical modem device accounts) need to be distinguished by sending different network address translation IPs (i.e., NAT IPs), and the user terminal needs to encapsulate and process the data in the process of sending data to the access cloud gateway to form message traffic. The message traffic contains the complete data information that the user terminal will send to the access cloud gateway. Therefore, the initial message traffic includes a network address translation IP (i.e., NAT IP), and the initial message traffic of different user terminals includes different network address translation IPs (i.e., NAT IPs).

[0044] S202: Process the initial message traffic according to the docking mode between the external traffic analysis device and the service cloud gateway to obtain processed message traffic; wherein the docking mode includes a bypass link mode or a serial connection mode.

[0045] In one embodiment, before step S202, it also includes: establishing a connection with an external traffic analysis device according to a preset connection method, the preset connection method includes a VxLAN connection method; configuring a three-layer sub-interface in the inner layer of the business cloud gateway so that different virtual local area networks can be interconnected. Among them, the preset connection method refers to a preset connection method between an external traffic analysis device and a business cloud gateway; a three-layer sub-interface refers to a three-layer logical interface, and multiple sub-interfaces are configured on a physical interface. These sub-interfaces correspond to different virtual local area networks (VLANs), so that only one physical interface needs to be connected to achieve intercommunication between different virtual local area networks (VLANs). Intercommunication between virtual local area networks (VLANs) can be achieved through a three-layer sub-interface. This is only applicable to scenarios where hosts in each virtual local area network (VLAN) are in different network segments.

[0046] Specifically, the business cloud gateway is connected to the external traffic analysis device using a preset connection method. Since the VxLAN connection method can penetrate the third-layer network to extend the second-layer network, it can solve the portability limitation of VMS (virtual memory system) by encapsulating traffic and extending it to the third-layer gateway, so that it can access the server on the external IP subnet. Therefore, the preset connection method can be packaged into a VxLAN connection method, wherein VxLAN is essentially a tunnel technology. On the IP network between the source network device and the destination network device, a logical tunnel is established, and the user-side message is forwarded through this tunnel after being specifically encapsulated; at the same time, since different virtual local area networks (VLANs) need to communicate with each other, the most direct way is to connect different virtual local area networks (VLANs) to different interfaces of the third-layer device, and realize data communication between different virtual local area networks (VLANs) through routing, but this will waste the limited physical interfaces on the device. To solve this problem, a third-layer sub-interface can be used. Therefore, a third-layer sub-interface needs to be configured in the inner layer of the business cloud gateway to realize the interconnection between different virtual local area networks (VLANs).

[0047] It should be noted that before configuring a Layer 3 sub-interface to achieve intercommunication between different virtual local area networks (VLANs), it is necessary to ensure that the virtual local area network (VLAN) has been created and the interface has been switched from Layer 2 mode to Layer 3 mode.

[0048] In the embodiment of the present application, the connection mode between the external traffic analysis device and the service cloud gateway includes a bypass connection mode or a serial connection mode. Figure 3 and Figure 4 As shown, Figure 3 is a schematic diagram of data flow in the bypass link mode provided in an embodiment of the present application, Figure 4 It is a schematic diagram of data flow in the serial mode provided in an embodiment of the present application.

[0049] In one embodiment, step S202 includes: determining the docking mode between the external traffic analysis device and the service cloud gateway; when the docking mode is a bypass link mode, transferring the initial message traffic back to the access cloud gateway, and mirroring the initial message traffic to obtain mirrored message traffic; performing data processing on the mirrored message traffic to obtain processed message traffic. Among them, the bypass link mode refers to the link mode in which the external traffic analysis device is in a bypass state in the network link. Specifically, the bypass link mode can be divided into a bypass monitoring link mode and a bypass proxy link mode. Among them, the bypass monitoring link mode refers to the external traffic analysis device deployed in the bypass of the business cloud gateway. By configuring the mirroring function of the business cloud gateway, the import and export message traffic is exactly mirrored to the external traffic analysis device, and the original message traffic direction remains unchanged. The external traffic analysis device monitors, detects and analyzes the network and application system status through the mirrored message traffic; the bypass proxy link mode refers to the external traffic analysis device working in the bypass proxy link mode, which is equivalent to a proxy gateway. At this time, it is necessary to change the network configuration to point all network data and access traffic to the bypass external traffic analysis device, and then return to the business cloud gateway after cleaning and filtering by the external traffic analysis device. It should be noted that since the mirroring function is required, the bypass link mode adopted in this application is the bypass monitoring link mode.

[0050] Specifically, the service cloud gateway first determines whether the connection mode between the service cloud gateway and the external traffic analysis device is the bypass connection mode or the serial connection mode. When the connection mode between the service cloud gateway and the external traffic analysis device is determined to be the bypass connection mode, such as Figure 3 As shown, after the initial message traffic reaches the business cloud gateway, the business cloud gateway directly transfers the initial message traffic back to the access cloud gateway, and at the same time mirrors the initial message traffic to obtain mirrored message traffic, and then performs data processing on the mirrored message traffic (including encapsulation and network address translation, etc.) to obtain processed message traffic.

[0051] It should be noted that when the connection mode between the external traffic analysis device and the business cloud gateway is the bypass link mode, the business cloud gateway will not process the initial message traffic received, but directly forward it to the access cloud gateway, and then obtain the mirror message traffic through mirror processing, and then process the mirror message traffic, such as Figure 3As shown, the initial message traffic in and out of the business cloud gateway remains unchanged compared to when no external traffic analysis device is added. Only the mirroring function of the business cloud gateway is used to mirror the initial message traffic in and out to the external traffic analysis device. This bypass link mode is simple to deploy, low cost, and can be implemented without too much adjustment to the networking. It supports both VxLAN and VLAN modes, and the device going online and offline has no effect on the network. However, since it is mirrored traffic, the external traffic analysis device can only perform security analysis and processing on the mirrored message traffic, and it is difficult to intercept, filter, and other operations on the network. The function is slightly simple. In summary, this bypass link mode not only ensures the normal forwarding of the original initial message traffic and the normal operation of the business, but also can quickly and accurately penetrate the initial message traffic through mirroring processing to external traffic analysis devices such as security pools for security analysis and processing.

[0052] In one embodiment, step S202 includes: determining the docking mode between the external traffic analysis device and the service cloud gateway; when the docking mode is the serial mode, directly processing the initial message traffic to obtain the processed message traffic. The serial mode refers to the working mode of connecting the external traffic analysis device in series in the network link. At this time, all message traffic will be cleaned and filtered by the external traffic analysis device and then forwarded. Specifically, the serial mode is divided into two types, one is the routing mode and the other is the transparent mode. The routing mode is also called the gateway mode, which means that the external traffic analysis device is used as a routing device or a gateway. The outgoing traffic in the local area network is first directed to the internal network port IP address of the external traffic analysis device. The external traffic analysis device sends the data through static or dynamic reason configuration or NAT address conversion; the transparent mode is also called the bridge mode or the bridge mode. When working in this mode, the original network device does not need to change any configuration and is completely transparent on the network link. For the external traffic analysis device, there is no need to configure the IP address interconnected with the gateway, and only a pair of IP addresses for internal bridging need to be configured. It should be noted that, considering the network deployment cost, the serial connection mode adopted in this application is the transparent mode.

[0053] Specifically, the service cloud gateway first determines whether the connection mode between the service cloud gateway and the external traffic analysis device is the bypass connection mode or the serial connection mode. When the connection mode between the service cloud gateway and the external traffic analysis device is determined to be the serial connection mode, Figure 4 As shown, after the initial message traffic arrives at the business cloud gateway, the business cloud gateway performs data processing (including encapsulation and network address translation, etc.) on the initial message traffic to obtain processed message traffic.

[0054] It should be noted that in the serial mode, the deployment method of the routing mode is more complicated, requiring major changes to the network and re-planning of the interconnected IP addresses. Once a problem occurs with the device, the fault recovery time will be very long. However, in the routing mode, many functions above the third layer can be used, such as NAT address translation, VPN channels, load balancing, etc.; while the transparent mode is simple to deploy and does not require any changes to the network configuration. It only requires connecting an external traffic analysis device in series in the network link. If the external traffic analysis device fails, the external traffic analysis device can be directly skipped or replaced. The fault recovery time is short, but functions above the third layer such as NAT and load balancing cannot be used. However, NAT and load balancing are performed by dedicated equipment, and the external traffic analysis device only needs to perform security protection functions. Therefore, the embodiment of the present application adopts a simple transparent mode to connect the external traffic analysis device to the business cloud gateway.

[0055] In one embodiment, when the docking mode is the serial mode, the initial message traffic is directly processed, and the steps of obtaining the processed message traffic include: encapsulating the layer 2 data of the initial message traffic according to the layer 3 sub-interface to obtain the layer 2 encapsulated traffic; according to the network address conversion IP of the initial message traffic, respectively performing address conversion on the layer 3 data and layer 4 data in the initial message traffic to obtain layer 3 conversion traffic and layer 4 conversion traffic; determining the processed message traffic according to the layer 2 encapsulated traffic, the layer 3 conversion traffic and the layer 4 conversion traffic.

[0056] According to the above steps, the business cloud gateway is connected to the external traffic analysis device using a VxLAN connection method, wherein VxLAN is used to connect non-VxLAN traffic to the VxLAN virtual network, and can also be used for Layer 2 communication of the same VxLAN virtual network, and can also be used for Layer 3 communication across subnets of the VxLAN virtual network. At the same time, the inner layer of the business cloud gateway is configured with a Layer 3 sub-interface for interconnection between different virtual LANs. Therefore, after the business cloud gateway receives the initial message traffic, it is necessary to encapsulate the Layer 2 data (such as network number VLAN and host number MAC) of the initial traffic according to the Layer 3 sub-interface, so as to obtain the Layer 2 encapsulated traffic. The purpose of encapsulation is to match the Layer 2 network data and sub-interface in the initial message traffic to facilitate subsequent transmission. At the same time, the Layer 3 data and Layer 4 data in the initial message traffic are converted to the network address according to the network address conversion IP in the message, so as to obtain the Layer 3 conversion traffic and the Layer 4 conversion traffic. Finally, combining the Layer 2 encapsulated traffic, the Layer 3 conversion traffic and the Layer 4 conversion traffic, the message is encapsulated and converted in the above manner to obtain the processed message traffic.

[0057] It should be noted that the fourth layer generally transmits data messages, mainly in protocol format. The third layer, namely the network layer, transmits data packets, including data messages, and adds third-layer information such as the IP address used for transmission. The second layer, namely the data link layer, transmits data frames, including data packets, and adds corresponding MAC addresses and second-layer information.

[0058] In one embodiment, the address conversion method includes conversion according to the account or conversion according to the terminal. The function of address conversion is to convert private IP addresses into public IP addresses, and public IP addresses into private IP addresses. Specifically, for the address conversion of three-layer data and four-layer data, its essence is to make a fuss on the IP data packet header. The IP header contains two fields, the source IP address and the destination IP address. As long as the data packet passes through the service cloud gateway, the content of these two fields can be modified to complete the address conversion. It can choose to convert according to the account or according to the terminal. The account refers to the optical modem device account. Each account has an IP segment. The network address conversion can be completed according to this IP segment. For conversion according to the terminal, you only need to replace the network number in the three-layer data, and the host number can use the original terminal.

[0059] S203: Introducing the processed message traffic into an external traffic analysis device, so that the external traffic analysis device performs security analysis on the processed message traffic.

[0060] After obtaining the processed message traffic according to the above method, the service cloud gateway introduces the processed message traffic into the external traffic analysis device, and performs data cleaning and filtering, network analysis and other services through the external traffic analysis device. Specifically, the external traffic analysis device contains the global security IP library provided by the operator. The external traffic analysis device compares the received processed message traffic with the global security IP library to determine whether the message traffic sent by the user is safe.

[0061] S204: Receive the security message traffic sent by the external traffic analysis device.

[0062] After the external traffic analysis device performs security analysis on the received processed message traffic according to step S203, it forwards the cleaned and filtered secure message traffic to the business cloud gateway. It should be noted that when the external traffic analysis device and the business cloud gateway are in bypass link mode, the external traffic analysis device is only responsible for security analysis on the processed message traffic, and cannot intercept, filter, etc. the received message traffic, nor can it send the secure message traffic processed by security analysis to the business cloud gateway; however, when the external traffic analysis device and the business cloud gateway are in serial mode, the external traffic analysis device can intercept, filter, etc. the received message traffic, and send the secure message traffic processed by security analysis to the business cloud gateway.

[0063] S205: convert and restore the secure message traffic, and forward the restored secure message traffic to the Internet.

[0064] In one embodiment, step S205 includes: performing conversion and restoration processing on the secure message traffic according to the network address translation IP in the secure message traffic to obtain the restored secure message traffic; forwarding the restored secure message traffic to the access cloud gateway so that the access cloud gateway distributes the restored secure message traffic to the Internet. The conversion and restoration processing includes network address translation.

[0065] Specifically, because the business cloud gateway performs network address translation when sending the processed message traffic to the external traffic analysis device, its network number VLAN and host number MAC have been replaced. Therefore, when the external traffic analysis device forwards the secure message traffic after security analysis back to the business cloud gateway, it is necessary to perform network address translation and restore the modified message traffic to obtain the restored secure message traffic. The external traffic analysis device sends the restored secure message traffic to the business cloud gateway, and the business cloud gateway sends the restored secure message traffic to the access cloud gateway. Finally, the access cloud gateway distributes the restored secure message traffic to the Internet to achieve secure Internet access for user terminals.

[0066] It can be seen from the above embodiments that the message traffic management method of the present application realizes secure traffic penetration at the gateway level. Compared with the prior art that realizes secure traffic penetration at the intermediate forwarding device level, it saves the processing capacity of the intermediate forwarding device. At the same time, it can realize that without affecting the network traffic forwarding, it can quickly and accurately penetrate the message traffic to the external traffic analysis device and other external traffic analysis devices, and the deployment cost is low. It can be achieved without too much adjustment to the networking. By means of network address translation and the establishment of three-layer sub-interfaces, the docking of external traffic analysis equipment with the business cloud gateway becomes easier, and traffic penetration accurate to the terminal level can be achieved. In addition, in the bypass link mode, the initial message traffic is mirrored through the mirroring function of the business cloud gateway, which ensures the normal forwarding of the original message traffic and the normal operation of the business, and can also quickly and accurately penetrate the message traffic to the external traffic analysis device for cleaning and filtering and other security analysis processing.

[0067] Based on the content of the above embodiment, the embodiment of the present application provides a service cloud gateway. Figure 5 , the business cloud gateway includes:

[0068] The first receiving module 501 is used to receive initial message traffic from a user terminal;

[0069] The first processing module 502 is used to process the initial message traffic according to the docking mode between the external traffic analysis device and the service cloud gateway; wherein the docking mode includes a bypass link mode or a serial connection mode;

[0070] The security analysis module 503 is used to introduce the processed message traffic into the external traffic analysis device so that the external traffic analysis device performs security analysis on the processed message traffic;

[0071] The second receiving module 504 is used to receive the security message traffic sent by the external traffic analysis device;

[0072] The conversion and restoration module 505 is used to convert and restore the secure message traffic and forward the restored secure message traffic to the Internet.

[0073] The initial message traffic includes a network address translation IP, and the initial message traffic of different user terminals includes different network address translation IPs.

[0074] In one embodiment, the service cloud gateway further includes:

[0075] A connection establishment module, used to establish a connection with an external traffic analysis device according to a preset connection mode, wherein the preset connection mode includes a VxLAN connection mode;

[0076] The interface configuration module is used to configure a three-layer sub-interface in the inner layer of the service cloud gateway so that different virtual local area networks can be interconnected.

[0077] In one embodiment, the first processing module 502 includes:

[0078] A mode determination module, used to determine the connection mode between the external traffic analysis device and the service cloud gateway;

[0079] A second processing module, configured to transfer the initial message traffic back to the access cloud gateway and perform mirroring processing on the initial message traffic to obtain mirrored message traffic when the docking mode is a bypass link mode;

[0080] The third processing module is used to perform data processing on the mirrored message traffic to obtain processed message traffic.

[0081] In one embodiment, the first processing module 502 further includes:

[0082] A mode determination module, used to determine the connection mode between the external traffic analysis device and the service cloud gateway;

[0083] The fourth processing module is used to directly perform data processing on the initial message traffic to obtain processed message traffic when the docking mode is the serial mode.

[0084] In one embodiment, the fourth processing module includes:

[0085] A traffic encapsulation module, used for encapsulating the layer 2 data of the initial message traffic according to the layer 3 sub-interface to obtain layer 2 encapsulated traffic;

[0086] An address translation module, configured to translate the IP address of the initial message flow, and to perform address translation on the layer 3 data and layer 4 data in the initial message flow respectively, to obtain layer 3 translation flow and layer 4 translation flow;

[0087] The first determination module is used to determine the processed message flow according to the layer 2 encapsulation flow, the layer 3 conversion flow and the layer 4 conversion flow.

[0088] The address conversion method includes conversion based on account or conversion based on terminal.

[0089] In one embodiment, the conversion and restoration module includes:

[0090] The conversion and restoration submodule is used to convert the IP address in the secure message flow, convert and restore the secure message flow, and obtain the restored secure message flow;

[0091] A traffic forwarding module is used to forward the restored secure message traffic to the access cloud gateway, so that the access cloud gateway distributes the restored secure message traffic to the Internet.

[0092] In addition, the service cloud gateway may also include a processor and a memory, wherein:

[0093] The processor is the control center of the service cloud gateway. It uses various interfaces and lines to connect the various parts of the entire service cloud gateway. By running or executing software programs and / or modules stored in the memory and calling data stored in the memory, it executes various functions and processes data of the above-mentioned units of the service cloud gateway, thereby monitoring the service cloud gateway as a whole. In one embodiment, the processor may include one or more processing cores; preferably, the processor may integrate an application processor and a modem processor, wherein the application processor mainly processes the operating system, user interface, and application programs, and the modem processor mainly processes wireless communications. It is understandable that the above-mentioned modem processor may not be integrated into the processor.

[0094] The memory can be used to store software programs and modules. The processor executes various functional applications and data processing by running computer programs and modules stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, an application required for at least one function, etc.; the data storage area can store data created according to the use of the terminal, etc. In addition, the memory can include a high-speed random access memory and can also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other volatile solid-state storage devices. Accordingly, the memory can also include a memory controller to provide the processor and the input unit with access to the memory.

[0095] Different from the current technology, the business cloud gateway provided by the present application is provided with a first processing module and a security analysis module. Through the first processing module, the security traffic penetration is changed from the original processing at the intermediate conversion device level to processing at the gateway level, which alleviates the security business processing pressure of the intermediate forwarding device. At the same time, the initial message traffic is processed by the first processing module according to the docking mode between the external traffic analysis device and the business cloud gateway, ensuring the normal operation of the original business. The processed message traffic is introduced into the external traffic analysis device through the security analysis module, so that the external traffic analysis device performs security analysis and processing on the message traffic, which not only ensures the Internet access efficiency and improves the accuracy and speed of traffic forwarding, but also filters potential network attack risks by intelligently analyzing the user's Internet traffic, thereby ensuring Internet security.

[0096] A person of ordinary skill in the art will appreciate that all or part of the steps in the various methods of the above embodiments may be completed by instructions, or by controlling related hardware through instructions. The instructions may be stored in a computer-readable storage medium and loaded and executed by a processor.

[0097] To this end, an embodiment of the present application provides a computer-readable storage medium, in which multiple instructions are stored, and the instructions can be loaded by a processor to implement the functions of the above-mentioned message traffic management method.

[0098] The computer-readable storage medium may include: a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.

[0099] The above is a detailed introduction to the message traffic management method, service cloud gateway and computer-readable storage medium provided in the embodiments of the present application. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea; at the same time, for technical personnel in this field, according to the ideas of the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. A message traffic management method, It is characterized in that Applied to a business cloud gateway, the method includes: Receiving initial message traffic from a user terminal; Determine the docking mode between the external traffic analysis device and the service cloud gateway, the docking mode includes a bypass connection mode or a serial connection mode, and when the docking mode is the serial connection mode, directly perform network address translation processing on the initial message traffic to obtain processed message traffic; Introducing the processed message traffic into the external traffic analysis device so that the external traffic analysis device performs security analysis on the processed message traffic; Receiving the security message traffic sent by the external traffic analysis device; According to the network address translation IP in the secure message traffic, the secure message traffic is converted and restored to obtain the restored secure message traffic, and the restored secure message traffic is forwarded to the Internet.

2. The message traffic management method according to claim 1, It is characterized in that The initial message traffic includes a network address translation IP, and the initial message traffic of different user terminals includes different network address translation IPs.

3. The message traffic management method according to claim 1, It is characterized in that In the step of determining the docking mode between the external traffic analysis device and the service cloud gateway, the docking mode includes a bypass link mode or a serial connection mode. When the docking mode is the serial connection mode, directly performing network address translation processing on the initial message traffic to obtain the processed message traffic, the method further includes: Establishing a connection with an external traffic analysis device according to a preset connection mode, wherein the preset connection mode includes a VxLAN connection mode; A three-layer sub-interface is configured in the inner layer of the service cloud gateway to enable interconnection between different virtual LANs.

4. The message traffic management method according to claim 3, It is characterized in that The method further comprises: When the docking mode is the bypass link mode, the initial message traffic is transferred back to the access cloud gateway, and the initial message traffic is mirrored to obtain mirrored message traffic; Data processing is performed on the mirrored message traffic to obtain processed message traffic.

5. The message traffic management method according to claim 3, It is characterized in that When the connection mode is the serial connection mode, the step of directly performing network address translation processing on the initial message flow to obtain the processed message flow includes: Encapsulating the layer 2 data of the initial message flow according to the layer 3 sub-interface to obtain layer 2 encapsulated flow; According to the network address translation IP of the initial message flow, respectively perform address translation on the layer 3 data and layer 4 data in the initial message flow to obtain layer 3 translation flow and layer 4 translation flow; The processed message flow is determined according to the layer 2 encapsulation flow, the layer 3 conversion flow and the layer 4 conversion flow.

6. The message traffic management method according to claim 5, It is characterized in that The address conversion method includes conversion based on account number or conversion based on terminal.

7. The message traffic management method according to claim 1, It is characterized in that The step of forwarding the restored secure message traffic to the Internet includes: The restored secure message traffic is forwarded to an access cloud gateway so that the access cloud gateway distributes the restored secure message traffic to the Internet.

8. A business cloud gateway, It is characterized in that include: A first receiving module, used for receiving initial message traffic from a user terminal; A first processing module is used to determine a docking mode between an external traffic analysis device and the service cloud gateway, wherein the docking mode includes a bypass connection mode or a serial connection mode. When the docking mode is the serial connection mode, the initial message traffic is directly subjected to network address translation processing to obtain processed message traffic; A security analysis module, used for introducing the processed message traffic into the external traffic analysis device, so that the external traffic analysis device performs security analysis on the processed message traffic; A second receiving module, used to receive the security message traffic sent by the external traffic analysis device; The conversion and restoration module is used to convert the IP address in the secure message traffic, convert and restore the secure message traffic to obtain the restored secure message traffic, and forward the restored secure message traffic to the Internet.

9. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor to execute the steps in the message traffic management method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Internet of Things security defense system for intelligent terminal

    CN106713301A

  • Anti-virus gateway processing acceleration strategy based on user traffic characteristics

    CN112751839A