Data Processing Method, Apparatus, Electronic Device, and Readable Storage Medium

By automatically identifying and defending against DDOS attacks in the data plane of the programmable switch, the problem of poor real-time network security protection is solved and efficient DDOS attack defense is achieved.

CN116192532BActive Publication Date: 2025-07-08PENG CHENG LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310269160.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-08
Publication Date
2025-07-08
Estimated Expiration
2043-03-08

AI Technical Summary

Technical Problem

In the prior art, the real-time performance of network security protection is poor and it is difficult to effectively resist DDOS attacks.

Method used

The data plane of the programmable switch obtains the pending data packet, parses the packet content and classifies the message type to determine whether it is a preset message type. If it is a preset message type, it is stored in the packet register. It judges whether it is an abnormal traffic state based on the number of packets and the storage time, and discards the packet in the event of an abnormality, and uses the data plane to automatically identify and defend against DDOS attacks.

Benefits of technology

It improves the real-time nature of network security protection, reduces dependence on professional personnel configuration, and realizes DDOS attack defense on the data plane.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116192532B_ABST
    Figure CN116192532B_ABST
Patent Text Reader

Abstract

The present application discloses a data processing method, apparatus, electronic device and readable storage medium, which are applied to the field of network security technology and to a programmable switch. The programmable switch includes a data plane. The data processing method includes: the data plane acquires a data packet to be processed, parses the data packet to be processed to obtain the data packet content, and classifies the data packet to be processed into a message type according to the data packet content, so as to obtain the message type corresponding to the data packet to be processed; if the message type is a preset message type, the data plane determines a data packet register corresponding to the data packet to be processed according to the data packet content, and stores the data packet to be processed in the data packet register; the data plane determines whether the data packet to be processed is in an abnormal traffic state according to the number of data packets in each data packet register and the storage time corresponding to each data packet; if so, the data plane discards the data packet to be processed. The present application solves the technical problem of poor real-time performance of network security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technologies, and in particular, to a data processing method, apparatus, electronic device, and readable storage medium. Background Art

[0002] With the rapid development of technology, computer technology has also become increasingly mature. Network attacks usually manifest as DDOS (Distributed Denial of Service) attacks, that is, by controlling multiple machines through a DDOS attacker to simultaneously perform network attacks to increase the CPU resource occupancy of the attack target, thereby affecting the normal operation of the attack target.

[0003] Currently, to resist DDOS attacks, usually professional personnel configure each attack target in the control plane of a programmable switch, and limit the traffic of the to-be-processed data packets matching the attack target through the control plane. However, since the attack targets of the initiated network attacks are not fixed, and the attack targets configured by professional personnel are limited, it is easy to encounter a situation where DDOS attacks cannot be resisted, resulting in poor real-time performance of network security protection. Summary of the Invention

[0004] The main purpose of the present application is to provide a data processing method, apparatus, electronic device, and readable storage medium, aiming to solve the technical problem of poor real-time performance of network security protection in the prior art.

[0005] To achieve the above object, the present application provides a data processing method, which is applied to a programmable switch. The programmable switch includes a data plane, and the data processing method includes:

[0006] Obtain a to-be-processed data packet through the data plane, parse the to-be-processed data packet to obtain the data packet content, and classify the to-be-processed data packet according to the data packet content to obtain the corresponding packet type of the to-be-processed data packet;

[0007] If the packet type is a preset packet type, determine the data packet register corresponding to the to-be-processed data packet through the data plane according to the data packet content, and store the to-be-processed data packet in the data packet register;

[0008] Judge whether the to-be-processed data packet is in an abnormal traffic state through the data plane according to the number of data packets in each data packet register and the storage time corresponding to each data packet;

[0009] If so, discard the to-be-processed data packet through the data plane.

[0010] Optionally, the programmable switch further includes a control plane, the control plane is configured with a blacklist flow table, and after the step of classifying the to-be-processed data packets according to the data packet content to obtain the message type corresponding to the to-be-processed data packets, further includes:

[0011] If the message type is not the preset message type, judging whether the to-be-processed data packet matches the blacklist flow table according to the content of the data packet through the data plane;

[0012] If there is a match, the step of discarding the to-be-processed data packet through the data plane is executed.

[0013] Optionally, the step of judging whether the to-be-processed data packet is in an abnormal traffic state according to the number of data packets of each data packet in the data packet register and the storage time corresponding to each data packet through the data plane includes:

[0014] Determining, by the data plane, whether the number of data packets exceeds a preset number threshold;

[0015] If it exceeds, the time interval between the storage time corresponding to the first data packet in the data packet register and the storage time corresponding to the data packet to be processed is calculated by the data plane according to each storage time, and it is determined whether the time interval is less than the preset time interval;

[0016] If it is less than, it is determined that the data packet to be processed is in an abnormal traffic state.

[0017] Optionally, the programmable switch further includes a control plane, the control plane is configured with a blacklist flow table, and after the step of discarding the to-be-processed data packet through the data plane, further includes:

[0018] Sending the data packet content of the to-be-processed data packet to the control plane via the data plane;

[0019] The blacklist flow table is updated according to the data packet content through the control plane.

[0020] Optionally, after the step of discarding the to-be-processed data packet through the data plane, the method further includes:

[0021] Controlling the data plane to start a current limiting state;

[0022] After the step of updating the blacklist flow table according to the data packet content through the control plane, the method further includes:

[0023] Control the data plane to release the current limiting state.

[0024] Optionally, the step of determining, by the data plane, the packet register corresponding to the packet to be processed according to the packet content includes:

[0025] Calculating, by the data plane, a hash value of the packet to be processed according to the packet content;

[0026] Querying, by the data plane, the packet register corresponding to the packet to be processed according to the hash value.

[0027] Optionally, the data processing method further includes:

[0028] Emptying, by the control plane, the flow table content in the blacklist flow table configured by the control plane every preset time.

[0029] To achieve the above object, the present application further provides a data processing apparatus, which is applied to a programmable switch. The programmable switch includes a data plane. The data processing apparatus includes:

[0030] A classification module, configured to obtain, by the data plane, a packet to be processed and parse the packet to be processed to obtain packet content, and classify the packet to be processed according to the packet content to obtain a message type corresponding to the packet to be processed;

[0031] A storage module, configured to, if the message type is a preset message type, determine, by the data plane, a packet register corresponding to the packet to be processed according to the packet content, and store the packet to be processed in the packet register;

[0032] A judgment module, configured to judge, by the data plane, whether the packet to be processed is in an abnormal traffic state according to the number of packets in each packet register and the storage time corresponding to each packet;

[0033] A discard module, configured to, if so, discard the packet to be processed by the data plane.

[0034] Optionally, the programmable switch further includes a control plane, and the control plane is configured with a blacklist flow table. After the step of classifying the packet to be processed according to the packet content to obtain the message type corresponding to the packet to be processed, the data processing apparatus is further configured to:

[0035] If the message type is not the preset message type, determine, by the data plane, whether the packet to be processed matches the blacklist flow table according to the packet content;

[0036] If there is a match, the step of discarding the to-be-processed data packet through the data plane is executed.

[0037] Optionally, the judging module is further used for:

[0038] Determining, by the data plane, whether the number of data packets exceeds a preset number threshold;

[0039] If it exceeds, the time interval between the storage time corresponding to the first data packet in the data packet register and the storage time corresponding to the data packet to be processed is calculated by the data plane according to each storage time, and it is determined whether the time interval is less than the preset time interval;

[0040] If it is less than, it is determined that the data packet to be processed is in an abnormal traffic state.

[0041] Optionally, the programmable switch further includes a control plane, the control plane is configured with a blacklist flow table, and after the step of discarding the to-be-processed data packet through the data plane, the data processing device is further used to:

[0042] Sending the data packet content of the to-be-processed data packet to the control plane via the data plane;

[0043] The blacklist flow table is updated according to the data packet content through the control plane.

[0044] Optionally, after the step of discarding the to-be-processed data packet through the data plane, the data processing device is further used to:

[0045] Controlling the data plane to start a current limiting state;

[0046] After the step of updating the blacklist flow table according to the data packet content through the control plane, the data processing device is further used for:

[0047] Control the data plane to release the current limiting state.

[0048] Optionally, the storage module is further used for:

[0049] Calculating a hash value of the data packet to be processed according to the content of the data packet through the data plane;

[0050] The data packet register corresponding to the data packet to be processed is obtained by querying the data plane according to the hash value.

[0051] Optionally, the data processing device is further used for:

[0052] The flow table content in the blacklist flow table configured by the control plane is cleared at preset time intervals through the control plane.

[0053] The present application also provides an electronic device, which includes: a memory, a processor, and a program of the data processing method stored on the memory and executable on the processor. When the program of the data processing method is executed by the processor, the steps of the data processing method as described above can be implemented.

[0054] The present application also provides a computer-readable storage medium, on which a program for implementing the data processing method is stored. When the program of the data processing method is executed by the processor, the steps of the data processing method as described above are implemented.

[0055] The present application also provides a computer program product, including a computer program. When the computer program is executed by the processor, the steps of the data processing method as described above are implemented.

[0056] The present application provides a data processing method, apparatus, electronic device and readable storage medium. Compared with the method of configuring each attack object through a professional in the control plane of a programmable switch and restricting the traffic of the to-be-processed data packet matching the attack object through the control plane, the present application is applied to a programmable switch, which includes a data plane. The to-be-processed data packet is obtained through the data plane and the content of the to-be-processed data packet is parsed. According to the content of the data packet, the to-be-processed data packet is classified into a message type, and the message type corresponding to the to-be-processed data packet is obtained; if the message type corresponding to the to-be-processed data packet is a preset message type, the data packet register corresponding to the to-be-processed data packet is determined through the data plane according to the content of the data packet, and the to-be-processed data packet is stored in the data packet register; it is judged whether the to-be-processed data packet is in an abnormal traffic state through the data plane according to the number of data packets in each data packet register and the storage time corresponding to each data packet; if so, the to-be-processed data packet is discarded through the data plane. Since the DDOS attack feature is a high-traffic network attack, by judging the number of data packets and the data packet storage time of the data packet register corresponding to the to-be-processed data packet, the traffic state of the to-be-processed data packet is judged. Thus, when it is in an abnormal traffic state, that is, when there is a high-traffic network attack threat, the to-be-processed data packet is discarded, realizing the automatic identification of data packets in the data plane, that is, realizing the DDOS attack defense through the data plane, without relying on manual configuration of attack objects through the control plane, thereby improving the real-time performance of network security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] The drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with the present application and used together with the specification to explain the principles of the present application.

[0058] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0059] Figure 1 It is a schematic flowchart of the first embodiment of the data processing method of the present application;

[0060] Figure 2 It is another schematic flowchart of the first embodiment of the data processing method of the present application;

[0061] Figure 3 It is a schematic structural diagram of the device involved in the data processing method in the embodiments of the present application;

[0062] Figure 4 It is a schematic structural diagram of the device of the hardware operating environment involved in the data processing method in the embodiments of the present application.

[0063] The realization of the purpose, functional features and advantages of the present application will be further described in conjunction with the embodiments with reference to the accompanying drawings. Detailed implementation manners

[0064] To make the above objects, features and advantages of the present application more obvious and understandable, the following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts belong to the scope of protection of the present application.

[0065] Embodiment 1

[0066] The embodiments of the present application provide a data processing method. In the first embodiment of the data processing method of the present application, referring to Figure 1 and Figure 2 , it is applied to a programmable switch. The programmable switch includes a data plane. The data processing method includes:

[0067] Step S10, obtaining a data packet to be processed through the data plane, parsing the data packet to be processed to obtain the packet content, and classifying the data packet to be processed according to the packet content to obtain the packet type corresponding to the data packet to be processed;

[0068] In this embodiment, it should be noted that the data packet to be processed is a data packet waiting to be processed.

[0069] Exemplarily, the data plane is used to obtain the data packet to be processed and the protocol type of the data packet to be processed. The data plane parses the header of the data packet to be processed according to the protocol type to obtain the data packet content. According to the data packet content, the data packet to be processed is classified into message types, and the corresponding message type of the data packet to be processed is generated.

[0070] As a feasible embodiment, if the protocol type is an IP (Internet Protocol) layer protocol, the IP content of the data packet to be processed is parsed to obtain the parsed IP (hereinafter referred to as the first IP for distinction), the port of the data packet to be processed is initialized to 0, and the initialized port (hereinafter referred to as the first port for distinction) and the first IP are used as the data packet content of the data packet to be processed.

[0071] As another feasible embodiment, if the protocol type is a TCP (Transmission Control Protocol) protocol or a UDP (User Datagram Protocol) protocol, the IP content, port content, and protocol content of the data packet to be processed are respectively parsed to obtain the parsed IP (hereinafter referred to as the second IP for distinction), the parsed port (hereinafter referred to as the second port for distinction), and the parsed protocol content. The second IP, the second port, and the parsed protocol content are used as the data packet content of the data packet to be processed.

[0072] Exemplarily, according to the IP content in the data packet content, the data packet to be processed is classified into message types, and the corresponding message type of the data packet to be processed is generated.

[0073] As a feasible embodiment, if the value of the IP content is 1, the message type is an ICMP (Internet Control Message Protocol) message type; if the value of the IP content is -2, the message type is an IGMP (Internet Group Management Protocol); if the value of the IP content is -6, the message type is a TCP message type.

[0074] Step D10, determine whether the message type is a preset message type;

[0075] In this embodiment, it should be noted that the preset packet type is a pre-set packet type, and the preset packet type includes at least one of ICMP packet type, IP packet type, TCP packet type, SYN (Synchronize Sequence Numbers) packet type, UDP packet type, IPV6 (where V6 represents the V6 version of the IP packet) packet type, IPSec packet type, IGMP packet type, etc.

[0076] It can be understood that DDOS attacks often focus on specific packet types. If the abnormal traffic status is judged for all packet type data packets, it will cause unnecessary resource occupation. Therefore, in the embodiment of the present application, by judging the abnormal traffic status of the to-be-processed data packets belonging to the preset packet type, the resource occupation of the programmable switch is saved.

[0077] If the packet type is the preset packet type, step S20 is executed. The data plane determines the packet register corresponding to the to-be-processed data packet according to the packet content, and stores the to-be-processed data packet in the packet register.

[0078] Step S30, the data plane judges whether the to-be-processed data packet is in an abnormal traffic status according to the number of data packets in each data packet register and the storage time corresponding to each data packet.

[0079] In this embodiment, it should be noted that the abnormal traffic status is a state of sudden increase in the traffic of the data packet.

[0080] If so, step S40 is to discard the to-be-processed data packet through the data plane.

[0081] Exemplarily, if the to-be-processed data packet is in an abnormal traffic status, it is determined that the to-be-processed data packet has a network attack threat, and the to-be-processed data packet is discarded through the data plane. If the to-be-processed data packet is not in an abnormal traffic status, it is determined that the to-be-processed data packet does not have a network attack threat, and the to-be-processed data packet is forwarded through the data plane.

[0082] It can be understood that the data plane in the programmable switch can perform nanosecond-level parsing and identification of data packets, and its throughput is much larger than that of other software firewalls, and its programmable flexibility is also much larger than that of hardware firewalls. Therefore, by parsing and judging the to-be-processed data packets through the data plane in the programmable switch, the real-time performance of network security protection is improved.

[0083] Wherein, the programmable switch further includes a control plane, and the control plane is configured with a blacklist flow table. After the step of classifying the packet type of the to-be-processed packet according to the packet content to obtain the packet type corresponding to the to-be-processed packet, if the packet type is not the preset packet type, step D20 is executed, and it is determined whether the to-be-processed packet matches the blacklist flow table through the data plane according to the packet content;

[0084] If it matches, step S40 is executed.

[0085] It can be understood that the blacklist flow table can be a preset flow table, which can be set by the user or received from the cloud.

[0086] Wherein, in step S30, the step of determining whether the to-be-processed packet is in an abnormal traffic state through the data plane according to the number of packets in each packet in the packet register and the storage time corresponding to each packet includes:

[0087] Step S31, determining through the data plane whether the number of packets exceeds a preset number threshold;

[0088] In this embodiment, it should be noted that the preset number threshold is a packet number critical value preset for determining that there are more packets in the packet register.

[0089] Step S32, if it exceeds, calculating, through the data plane, the time interval between the storage time corresponding to the first packet in the packet register and the storage time corresponding to the to-be-processed packet according to each storage time, and determining whether the time interval is less than a preset time interval;

[0090] In this embodiment, it should be noted that the preset time interval is a storage time interval critical value preset for determining the sudden increase of data in the packet register between the first packet and the last packet.

[0091] Exemplarily, if the number of packets exceeds the preset number threshold, the data plane filters the storage time corresponding to the first packet in the packet register and the storage time corresponding to the to-be-processed packet according to each storage time, and uses the time difference between the storage time corresponding to the to-be-processed packet and the storage time corresponding to the first packet as the time interval between the storage time corresponding to the first packet and the storage time corresponding to the to-be-processed packet, and determines whether the time interval is less than the preset time interval.

[0092] Step S33, if it is less, determining that the to-be-processed packet is in an abnormal traffic state.

[0093] Exemplarily, if the time interval is less than a preset time interval, it is determined that the data packet to be processed is in an abnormal traffic state.

[0094] Wherein, in step S40, the programmable switch further includes a control plane, and the control plane is configured with a blacklist flow table. After the step of discarding the data packet to be processed by the data plane, the following steps are further included:

[0095] Step A10, sending the data packet content of the data packet to be processed to the control plane through the data plane;

[0096] Step A20, updating the blacklist flow table according to the data packet content through the control plane.

[0097] Exemplarily, the data packet content is added to the blacklist flow table through the control plane to update the blacklist flow table.

[0098] The embodiment of the present application provides a data processing method. Compared with the method of configuring each attack object through a professional in the control plane of a programmable switch and restricting the traffic of the data packet to be processed that matches the attack object through the control plane, the embodiment of the present application is applied to a programmable switch. The programmable switch includes a data plane, obtains the data packet to be processed through the data plane and parses the data packet to be processed to obtain the data packet content, and classifies the data packet to be processed according to the data packet content to obtain the message type corresponding to the data packet to be processed; if the message type corresponding to the data packet to be processed is a preset message type, determine the data packet register corresponding to the data packet to be processed according to the data packet content through the data plane, and store the data packet to be processed in the data packet register; judge whether the data packet to be processed is in an abnormal traffic state according to the number of data packets in the data packet register and the storage time corresponding to each data packet; if so, discard the data packet to be processed through the data plane. Since the DDOS attack feature is a high-traffic network attack, by judging the number of data packets in the data packet register corresponding to the data packet to be processed and the data packet storage time, the traffic state of the data packet to be processed is judged, so that when it is in an abnormal traffic state, that is, when there is a high-traffic network attack threat, the data packet to be processed is discarded, realizing the automatic identification of data packets on the data plane, that is, realizing the DDOS attack defense through the data plane, without relying on manual configuration of attack objects through the control plane, thereby improving the real-time performance of network security protection.

[0099] Embodiment Two

[0100] Further, based on the first embodiment of the present application, in another embodiment of the present application, the same or similar contents as those in the above-mentioned embodiment 1 can be referred to the above introduction, and will not be repeated later. On this basis, in step S40, after the step of discarding the data packet to be processed by the data plane, it also includes:

[0101] Step B10, controlling the data plane to start a current limiting state;

[0102] Exemplarily, the data plane is controlled to start a flow limiting state to limit the flow of the data packets to be processed, thereby defending against DDOS attacks.

[0103] After the step of updating the blacklist flow table according to the data packet content through the control plane, the method further includes:

[0104] Step A30: Control the data plane to release the current limiting state.

[0105] Exemplarily, the data plane is controlled to release the current limiting state so that the next round of data packets to be processed can flow normally, thereby enabling network security threat judgment for the next round of data packets to be processed.

[0106] Wherein, in step S20, the step of determining the data packet register corresponding to the data packet to be processed according to the data packet content through the data plane includes:

[0107] Step S21, calculating the hash value of the data packet to be processed according to the content of the data packet through the data plane;

[0108] Exemplarily, according to the content of the data packet, a quintuple corresponding to the data packet to be processed is determined, and the quintuple is converted into a hash value of the data packet to be processed according to a preset algorithm, wherein the preset algorithm may be a CRC (Cyclic Redundancy Check) algorithm,

[0109] Step S22, obtaining a data packet register corresponding to the data packet to be processed through the data plane according to the hash value query.

[0110] Exemplarily, the data packet register corresponding to the data packet to be processed is obtained by querying each data packet register according to the hash value.

[0111] Wherein, the data processing method further includes:

[0112] Step C10: clearing the flow table content in the blacklist flow table configured by the control plane at preset time intervals through the control plane.

[0113] It can be understood that, due to the large and variable number of data packets to be processed, and the fact that a DDOS attack will frequently switch IP addresses to update the attack target, if a unified blacklist flow table is always used, it is likely to take a long time to look up the table.

[0114] In the embodiment of the present application, the control plane clears the content of the flow table in the blacklist flow table configured by the control plane every preset time, and regularly clears the blacklist flow table configured by the control plane, so that the blacklist flow table obtained by the control plane configuration is the flow table within the real-time time period, thereby avoiding the technical defect of long table lookup time, and further improving the real-time performance of network security protection.

[0115] Embodiment III

[0116] The embodiment of the present application also provides a data processing device, which is applied to a programmable switch. The programmable switch includes a data plane. Refer to Figure 3 , and the data processing device includes:

[0117] A classification module, configured to obtain data packets to be processed through the data plane, parse the data packets to be processed to obtain packet content, and classify the data packets to be processed according to the packet content to obtain the corresponding packet type of the data packets to be processed;

[0118] A storage module, configured to, if the packet type is a preset packet type, determine a packet register corresponding to the data packet to be processed through the data plane according to the packet content, and store the data packet to be processed in the packet register;

[0119] A judgment module, configured to judge whether the data packet to be processed is in an abnormal traffic state through the data plane according to the number of data packets in each data packet in the packet register and the storage time corresponding to each data packet;

[0120] A discard module, configured to, if so, discard the data packet to be processed through the data plane.

[0121] Optionally, the programmable switch further includes a control plane, and the control plane is configured with a blacklist flow table. After the step of classifying the data packet to be processed according to the packet content to obtain the corresponding packet type of the data packet to be processed, the data processing device is further configured to:

[0122] If the packet type is not the preset packet type, judge whether the data packet to be processed matches the blacklist flow table through the data plane according to the packet content;

[0123] If there is a match, the step of discarding the to-be-processed data packet through the data plane is executed.

[0124] Optionally, the judging module is further used for:

[0125] Determining, by the data plane, whether the number of data packets exceeds a preset number threshold;

[0126] If it exceeds, the time interval between the storage time corresponding to the first data packet in the data packet register and the storage time corresponding to the data packet to be processed is calculated by the data plane according to each storage time, and it is determined whether the time interval is less than the preset time interval;

[0127] If it is less than, it is determined that the data packet to be processed is in an abnormal traffic state.

[0128] Optionally, the programmable switch further includes a control plane, the control plane is configured with a blacklist flow table, and after the step of discarding the to-be-processed data packet through the data plane, the data processing device is further used to:

[0129] Sending the data packet content of the to-be-processed data packet to the control plane via the data plane;

[0130] The blacklist flow table is updated according to the data packet content through the control plane.

[0131] Optionally, after the step of discarding the to-be-processed data packet through the data plane, the data processing device is further used to:

[0132] Controlling the data plane to start a current limiting state;

[0133] After the step of updating the blacklist flow table according to the data packet content through the control plane, the data processing device is further used for:

[0134] Control the data plane to release the current limiting state.

[0135] Optionally, the storage module is further used for:

[0136] Calculating a hash value of the data packet to be processed according to the content of the data packet through the data plane;

[0137] The data packet register corresponding to the data packet to be processed is obtained by querying the data plane according to the hash value.

[0138] Optionally, the data processing device is further used for:

[0139] The flow table content in the blacklist flow table configured by the control plane is cleared at preset time intervals through the control plane.

[0140] The data processing device provided in this application adopts the data processing method in the above embodiment, and solves the technical problem of poor real-time performance of network security protection. Compared with the prior art, the beneficial effects of the data processing device provided in the embodiment of this application are the same as those of the data processing method provided in the above embodiment, and other technical features in this data processing device are the same as those disclosed in the method of the above embodiment, and will not be elaborated here.

[0141] Embodiment 4

[0142] The embodiment of this application provides an electronic device, and the electronic device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the data processing method in the above embodiment.

[0143] Refer to the following Figure 4 , which shows a schematic structural diagram of an electronic device suitable for implementing the embodiments of the present disclosure. The electronic device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (tablet computers), PMPs (Portable Media Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 4 The electronic device shown is only an example, and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.

[0144] As Figure 4 shown, the electronic device may include a processing device (such as a central processing unit, a graphics processing unit, etc.), which may execute various appropriate actions and processes according to a program stored in a ROM (Read-Only Memory) or a program loaded from a storage device into a RAM (Random Access Memory). In the RAM, various programs and data required for the operation of the electronic device are also stored. The processing device, the ROM, and the RAM are connected to each other through a bus. The input / output (I / O) interface is also connected to the bus.

[0145] Generally, the following systems can be connected to the I / O interface: input devices including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; output devices including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; storage devices including, for example, magnetic tape, a hard disk, etc.; and a communication device. The communication device can allow the electronic device to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows an electronic device having various systems, it should be understood that it is not required to implement or have all the systems shown. Instead, more or fewer systems can be implemented or had.

[0146] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product that includes a computer program carried on a computer-readable medium, and the computer program includes program codes for performing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through the communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processing device, the above-mentioned functions defined in the method of the embodiment of the present disclosure are executed.

[0147] The electronic device provided by the present application adopts the data processing method in the above embodiment, and solves the technical problem of poor real-time performance of network security protection. Compared with the prior art, the beneficial effects of the electronic device provided by the embodiment of the present application are the same as those of the data processing method provided by the above embodiment, and other technical features in the electronic device are the same as those disclosed in the method of the above embodiment, and will not be elaborated here.

[0148] It should be understood that each part of the present disclosure can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.

[0149] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present application, and all should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0150] Embodiment Five

[0151] This embodiment provides a computer-readable storage medium having computer-readable program instructions stored thereon for performing the method of the data processing method in the above embodiment.

[0152] The computer-readable storage medium provided by the embodiments of the present application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, RAM, ROM, EPROM (Erasable Programmable Read Only Memory), or flash memory, optical fibers, CD-ROM (Compact Disc Read-Only Memory), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or combined with an instruction execution system, device, or component. The program code contained on the computer-readable storage medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination of the above.

[0153] The above computer-readable storage medium may be included in an electronic device; or it may exist separately and not be assembled into the electronic device.

[0154] The above computer-readable storage medium carries one or more programs. When the above one or more programs are executed by an electronic device, the electronic device is enabled to: obtain a data packet to be processed through the data plane and parse the data packet to be processed to obtain the data packet content, and classify the data packet to be processed according to the data packet content to obtain the message type corresponding to the data packet to be processed; if the message type is a preset message type, determine the data packet register corresponding to the data packet to be processed through the data plane according to the data packet content, and store the data packet to be processed in the data packet register; determine whether the data packet to be processed is in an abnormal traffic state through the data plane according to the number of data packets in each data packet register and the storage time corresponding to each data packet; if so, discard the data packet to be processed through the data plane.

[0155] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a LAN (Local Area Network) or a WAN (Wide Area Network), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0156] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0157] The modules described in the embodiments of the present disclosure may be implemented in software or in hardware. In some cases, the name of the module does not constitute a limitation on the unit itself.

[0158] The computer-readable storage medium provided by the present application stores computer-readable program instructions for performing the above data processing method, solving the technical problem of poor real-time performance of network security protection. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by the embodiments of the present application are the same as those of the data processing method provided by the above embodiments, and will not be elaborated herein.

[0159] Embodiment Six

[0160] The present application also provides a computer program product, including a computer program, which when executed by a processor implements the steps of the data processing method as described above.

[0161] The computer program product provided by the present application solves the technical problem of poor real-time performance of network security protection. Compared with the prior art, the beneficial effects of the computer program product provided by the embodiments of the present application are the same as those of the data processing method provided by the above embodiments, and will not be elaborated here.

[0162] The above are only the preferred embodiments of the present application, and do not limit the patent scope of the present application accordingly. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present application, or directly or indirectly applied to other related technical fields, shall be equally included in the patent scope of the present application.

Claims

1. A data processing method, characterized in that, Applied to a programmable switch, the programmable switch includes a data plane, and the data processing method includes: Acquire the data packet to be processed through the data plane and parse the data packet to be processed to obtain the data packet content, and classify the data packet to be processed according to the data packet content to obtain the message type corresponding to the data packet to be processed, wherein the protocol type in the data packet content is used to parse the header of the data packet to be processed to obtain the data packet content; If the message type is a preset message type, determining a data packet register corresponding to the to-be-processed data packet according to the data packet content through the data plane, and storing the to-be-processed data packet in the data packet register; Determining whether the data packet to be processed is in an abnormal traffic state according to the number of data packets of each data packet in the data packet register and the storage time corresponding to each data packet through the data plane; If so, the data packet to be processed is discarded through the data plane, wherein the programmable switch further includes a control plane, and the control plane is configured with a blacklist flow table. After the step of classifying the data packet to be processed according to the content of the data packet, and obtaining the message type corresponding to the data packet to be processed, it also includes: If the message type is not the preset message type, the data plane determines whether the data packet to be processed matches the blacklist flow table according to the data packet content; if it matches, the step of discarding the data packet to be processed through the data plane is executed, wherein the data packet content includes the parsed IP and port.

2. The data processing method according to claim 1, wherein The step of judging whether the to-be-processed data packet is in an abnormal traffic state according to the number of data packets of each data packet in the data packet register and the storage time corresponding to each data packet through the data plane comprises: Determining, by the data plane, whether the number of data packets exceeds a preset number threshold; If it exceeds, the time interval between the storage time corresponding to the first data packet in the data packet register and the storage time corresponding to the data packet to be processed is calculated by the data plane according to each storage time, and it is determined whether the time interval is less than the preset time interval; If it is less than, it is determined that the data packet to be processed is in an abnormal traffic state.

3. The data processing method according to claim 1, wherein The programmable switch further includes a control plane, the control plane is configured with a blacklist flow table, and after the step of discarding the to-be-processed data packet through the data plane, further includes: Sending the data packet content of the to-be-processed data packet to the control plane via the data plane; The blacklist flow table is updated according to the data packet content through the control plane.

4. The data processing method according to claim 3, wherein After the step of discarding the to-be-processed data packet through the data plane, the method further includes: Controlling the data plane to start a current limiting state; After the step of updating the blacklist flow table according to the data packet content through the control plane, the method further includes: Control the data plane to release the current limiting state.

5. The data processing method according to claim 1, wherein The step of determining, by the data plane, the packet register corresponding to the packet to be processed according to the packet content includes: Calculating, by the data plane, a hash value of the packet to be processed according to the packet content; Querying, by the data plane, the packet register corresponding to the packet to be processed according to the hash value.

6. The data processing method according to any one of claims 1 to 5, characterized in that The data processing method further includes: Emptying, by the control plane, the flow table content in the blacklist flow table configured by the control plane at preset time intervals.

7. A data processing device, characterized in that, Applied to a programmable switch, the programmable switch includes a data plane, and the data processing device includes: A classification module, configured to obtain, by the data plane, a packet to be processed and parse the packet to be processed to obtain packet content, and classify the packet to be processed into a packet type according to the packet content, to obtain the packet type corresponding to the packet to be processed, where the protocol type in the packet content is used to parse the header of the packet to be processed to obtain the packet content; A storage module, configured to, if the packet type is a preset packet type, determine, by the data plane, the packet register corresponding to the packet to be processed according to the packet content, and store the packet to be processed in the packet register; A judgment module, configured to judge, by the data plane, whether the packet to be processed is in an abnormal traffic state according to the number of packets in each packet register and the storage time corresponding to each packet; A discard module, configured to, if so, discard the packet to be processed by the data plane, where the programmable switch further includes a control plane, the control plane is configured with a blacklist flow table, and after the step of classifying the packet to be processed into a packet type corresponding to the packet to be processed according to the packet content, further includes: If the packet type is not the preset packet type, judging, by the data plane, whether the packet to be processed matches the blacklist flow table according to the packet content; if it matches, executing the step of discarding the packet to be processed by the data plane, where the packet content includes parsed IP and port.

8. An electronic device, characterized in that, The electronic device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the steps of the data processing method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, A program for implementing a data processing method is stored on the computer-readable storage medium, and the program for implementing the data processing method is executed by a processor to implement the steps of the data processing method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Collaborative theory-based DDoS (Distributed Denial of Service Attack) defense system and method

    CN106921666A

  • Flow-based abnormal communication behavior detection method and system

    CN110149343A