Flow detection system, method, apparatus and storage medium thereof
By adding traffic tags to the aggregation and distribution devices and having the execution unit identify the IP address, the problem of inaccurate IP address detection in Internet data centers and network service providers is solved, and accurate IP address monitoring and alarm information generation are achieved.
Patent Information
- Application Number
- CN202211572525.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-08
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2042-12-08
AI Technical Summary
In existing technologies, Internet Protocol address detection by Internet data centers and network service providers is not effective enough, which makes alarm devices prone to falsely report user-registered addresses.
By adding traffic tags to the aggregation and distribution devices, and having the execution unit identify the traffic tags to determine whether the destination IP address or source IP address of the data traffic is a registered IP address, alarm information is generated to avoid false alarms.
Effectively detect IP addresses to avoid false alarms from alarm devices regarding user-registered addresses and ensure the accuracy of IP address monitoring.
Smart Images

Figure CN116248471B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, and particularly relates to a traffic detection system, method and device and a storage medium thereof. BACKGROUND
[0002] In the related art, the Internet Protocol (IP) address of an Internet Data Center (IDC) or an Internet Service Provider (ISP) cannot be effectively monitored, and the problem of false reporting of the user's registered address by the alarm device is prone to occur. Therefore, how to effectively detect the IP address is a problem to be solved at present. SUMMARY
[0003] The present application provides a traffic detection system, method, device and storage medium, which can effectively detect the IP address.
[0004] To achieve the above object, the present application adopts the following technical scheme:
[0005] In a first aspect, the present application provides a traffic detection system, which comprises a core router (CR), an IDC device, a convergence and distribution device, and an execution unit (EU); the CR and the IDC device are connected through a communication link and forward data to each other through the communication link; the convergence and distribution device accesses the communication link between the CR and the IDC device through an optical splitter; the convergence and distribution device is configured to: acquire first data traffic forwarded between the CR and the IDC device; add a label to the first data traffic according to a preset two-layer message policy to generate second data traffic, and send the second data traffic to the EU; the EU is configured to: receive the second data traffic, determine a traffic label of the second data traffic; the traffic label is any one of an incoming direction traffic label and an outgoing direction traffic label; in the case that the traffic label is the incoming direction traffic label, determine a destination IP address of the data traffic; determine whether the destination IP address is a registered IP address; in the case that the traffic label is the outgoing direction traffic label, determine a source IP address of the data traffic; and determine whether the source IP address is a registered IP address.
[0006] In combination with the first aspect, in a possible implementation manner, the system further comprises an alarm output device; the EU is further configured to: in the case that the destination IP address or the source IP address is not the registered IP address, generate alarm information; and send the alarm information to the alarm output device; and the alarm output device is further configured to: output the alarm information.
[0007] Secondly, this application provides a traffic detection method, the method comprising: identifying a traffic label of data traffic; the traffic label being either an inbound traffic label or an outbound traffic label; if the traffic label is an inbound traffic label, determining the destination IP address of the data traffic; determining whether the destination IP address is a registered IP address; if the traffic label is an outbound traffic label, determining the source IP address of the data traffic; and determining whether the source IP address is a registered IP address.
[0008] In conjunction with the second aspect, in one possible implementation, the traffic label is a label added to the data traffic by the aggregation and distribution device according to a preset Layer 2 packet strategy after the data traffic is acquired.
[0009] In conjunction with the second aspect, in one possible implementation, the method further includes: generating alarm information when the destination IP address or source IP address is not a registered IP address; and sending the alarm information to the alarm output device.
[0010] Thirdly, this application provides a traffic detection device, which includes: a processing unit; the processing unit is used to identify a traffic label of data traffic; the traffic label is either an inbound traffic label or an outbound traffic label; when the traffic label is an inbound traffic label, the processing unit is further used to determine the destination IP address of the data traffic; the processing unit is further used to determine whether the destination IP address is a registered IP address; when the traffic label is an outbound traffic label, the processing unit is further used to determine the source IP address of the data traffic; the processing unit is further used to determine whether the source IP address is a registered IP address.
[0011] In conjunction with the third aspect, in one possible implementation, the traffic label is a label added to the data traffic by the aggregation and distribution device according to a preset Layer 2 message policy after the data traffic is acquired.
[0012] In conjunction with the third aspect, in one possible implementation, the device further includes: a communication unit; and, in the case that the destination IP address or the source IP address is not a registered IP address, the processing unit is also used to generate alarm information; and the communication unit is used to send the alarm information to the alarm output device.
[0013] Fourthly, this application provides a flow detection device, which includes: a processor and a communication interface; the communication interface and the processor are coupled, and the processor is used to run computer programs or instructions to implement the flow detection method as described in the second aspect and any possible implementation of the second aspect.
[0014] Fifthly, this application provides a computer-readable storage medium storing instructions that, when executed on a terminal, cause the terminal to perform the traffic detection method as described in the second aspect and any possible implementation thereof.
[0015] In this application, the name of the aforementioned flow detection device does not limit the device or functional module itself. In actual implementation, these devices or functional modules may appear under other names. As long as the function of each device or functional module is similar to that of this application, it falls within the scope of the claims of this application and its equivalents.
[0016] These or other aspects of this application will become more readily apparent in the following description.
[0017] Based on the above technical solution, the traffic detection method provided in this application identifies the traffic label of data traffic through a traffic detection device. If the traffic label is an inbound traffic label, the destination IP address of the data traffic is determined, and the traffic detection device then determines whether the destination IP address belongs to the registered IP address. If the traffic label is an outbound traffic label, the source IP address of the data traffic is determined, and the traffic detection device then determines whether the source IP address belongs to the registered IP address. This method can effectively detect IP addresses and avoid the problem of alarm devices misreporting user registered addresses. Attached Figure Description
[0018] Figure 1 A schematic diagram of the structure of a flow detection device provided in this application;
[0019] Figure 2 A schematic diagram of a flow detection system provided in this application;
[0020] Figure 3 A flowchart of a traffic detection method provided in this application;
[0021] Figure 4 A flowchart of another traffic detection method provided in this application;
[0022] Figure 5 A schematic diagram of the structure of a flow detection device provided in this application;
[0023] Figure 6 A schematic diagram of another flow detection device provided in this application. Detailed Implementation
[0024] The following description, in conjunction with the accompanying drawings, details a flow detection system, method, apparatus, and storage medium provided in the embodiments of this application.
[0025] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.
[0026] The terms "first" and "second," etc., used in the specification and drawings of this application are used to distinguish different objects or to distinguish different treatments of the same object, rather than to describe a specific order of objects.
[0027] Furthermore, the terms "comprising" and "having," and any variations thereof, used in the description of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.
[0028] It should be noted that in the embodiments of this application, the words "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.
[0029] Figure 1 This is a schematic diagram of the structure of a flow detection device provided in an embodiment of this application, as shown below. Figure 1 As shown, the flow detection device 100 includes at least one processor 101, a communication line 102, and at least one communication interface 104, and may also include a memory 103. The processor 101, memory 103, and communication interface 104 are connected via the communication line 102.
[0030] The processor 101 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application, such as one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs).
[0031] Communication line 102 may include a path for transmitting information between the aforementioned components.
[0032] The communication interface 104 is used to communicate with other devices or communication networks. It can use any transceiver-like device, such as Ethernet, radio access network (RAN), wireless local area network (WLAN), etc.
[0033] The memory 103 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of including or storing desired program code having the form of instructions or data structures and accessible by a computer, but not limited thereto.
[0034] In one possible design, the memory 103 can exist independently of the processor 101, meaning the memory 103 can be an external memory of the processor 101. In this case, the memory 103 can be connected to the processor 101 via the communication line 102 to store execution instructions or application code, and its execution is controlled by the processor 101 to implement the network quality determination method provided in the following embodiments of this application. In another possible design, the memory 103 can also be integrated with the processor 101, meaning the memory 103 can be an internal memory of the processor 101. For example, the memory 103 can be a cache, which can be used to temporarily store some data and instruction information.
[0035] As one possible implementation, processor 101 may include one or more CPUs, for example Figure 1 CPU0 and CPU1 in the example. Alternatively, the flow detection device 100 may include multiple processors, such as CPU0 and CPU1. Figure 1 The processors 101 and 107 are included. Alternatively, the flow detection device 100 may also include an output device 105 and an input device 106.
[0036] Through the above description of the implementation methods, those skilled in the art will clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the network node can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, modules, and network nodes described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0037] The following is an explanation of the terms used in this application.
[0038] 1. Aggregation and distribution equipment is located at the forefront of the network visualization system. Its main functions include data collection from different network access points, protocol parsing (link layer and network layer), simple filtering, traffic distribution, same-source / sinking, and load balancing. Also known as primary distribution equipment or coarse-screening equipment, it is deployed in the backbone network, typically in the operator's data center. The filtered data is then connected to the user's data center via a dedicated line. After preprocessing (parsing and filtering) by the aggregation and distribution equipment, the required data is output to different backend business systems according to business needs.
[0039] 2. A beam splitter is a passive device, also known as an optical splitter. It requires no external energy, only input light. A beam splitter consists of entrance and exit slits, a mirror, and a dispersive element. Its function is to separate the desired resonant absorption lines. The key component of a beam splitter is the dispersive element; modern commercial instruments typically use gratings.
[0040] 3. An Internet Data Center (IDC) refers to a facility with complete equipment (including high-speed internet access bandwidth, high-performance local area networks, and a secure and reliable data center environment), professional management, and a comprehensive application service platform. Based on this platform, IDC service providers offer customers basic internet platform services (server hosting, virtual hosting, email caching, virtual mail, etc.) as well as various value-added services (site rental services, domain name system services, load balancing systems, database systems, data backup services, etc.).
[0041] 4. Internet Service Provider (ISP): An Internet service provider is a telecommunications operator that provides comprehensive Internet access, information services, and value-added services to a wide range of users. In the Internet application service industry chain of "equipment supplier – basic network operator – content collector and producer – service provider – user," the ISP occupies the positions of content collector, producer, and service provider.
[0042] 5. Core Router (CR): In the Internet, it is located in the network core and is mainly used for data packet routing and forwarding. It is generally a router with a large throughput.
[0043] 6. The quintuple is a communications term. It typically refers to the source IP address, source port, destination IP address, destination port, and transport layer protocol.
[0044] 7. Inbound traffic can be understood as data traffic entering the Internet Data Center (IDC) equipment from the core router (CR).
[0045] 8. Outbound traffic can be understood as data traffic sent from Internet Data Center (IDC) devices to the core router (CR).
[0046] 9. The execution component is also known as the execution unit (EU).
[0047] In related technologies, when collecting device data to detect traffic, a DNS data source is typically used to extract data with attributes matching those within the data center from the total data, and then simulated requests are made. First, an HTTP (GET / POST) request is made. If the simulated request result is outside the reasonable range, an HTTPS (GET / POST) request is made, thereby detecting missed detections of active IP and domain data. Because this method primarily detects missed data by comparing the return values of HTTP and HTTPS requests, it places certain demands on device performance and has a significant resource consumption.
[0048] Currently, there is no better method for detecting Internet Protocol (IP) addresses of Internet Data Centers (IDCs) or Internet Service Providers (ISPs), making it impossible to effectively detect IP addresses and leading to the problem of alarm devices misreporting user-registered addresses.
[0049] To address the problem that existing technologies cannot effectively detect IP addresses, this application provides a method such as... Figure 2 The flow detection system 20 shown.
[0050] like Figure 2 As shown, the traffic detection system 20 provided in this application includes a core router CR201, an Internet Data Center (IDC) device 202, an aggregation and distribution device 203, and an execution unit EU204.
[0051] The core router CR201 and the Internet Data Center (IDC) device 202 are connected via a communication link and forward data to each other through the communication link. The aggregation and splitting device 203 is connected to the communication link between the core router CR201 and the IDC device 202 via an optical splitter. The aggregation and splitting device 203 is configured to: acquire the first data traffic forwarded between the core router CR201 and the IDC device 202; add tags to the first traffic data according to a preset Layer 2 packet policy to generate a second data traffic, and send the second data traffic to the execution unit EU204.
[0052] The execution unit EU204 is configured to: receive a second data traffic, determine the traffic label of the second data traffic; the traffic label is either an inbound traffic label or an outbound traffic label; if the traffic label is an inbound traffic label, determine the destination IP address of the data traffic; determine whether the destination IP address is a registered IP address; if the traffic label is an outbound traffic label, determine the source IP address of the data traffic; determine whether the source IP address is a registered IP address.
[0053] In one possible implementation, during the data traffic exchange between the core router CR201 and the Internet Data Center (IDC) device 202, if a certain data traffic enters the IDC device 202, then the data traffic is inbound data traffic; if a certain data traffic leaves the IDC device 202, then the data traffic is outbound data traffic.
[0054] Optionally, the aggregation and distribution device 203 includes multiple ports, which are used to acquire traffic from different directions or to acquire traffic between different IDC devices and CR devices.
[0055] In one example, the aggregation and distribution device 203 includes two ports, namely port A31 and port B32. Port A31 is used to acquire inbound traffic between CR201 and IDC202; port B32 is used to acquire outbound traffic between CR201 and IDC202.
[0056] The following example illustrates the process by which the aggregation and distribution device 203 acquires traffic.
[0057] The aggregation and splitting device 203 obtains the first data traffic during the data traffic exchange between the core router CR201 and the Internet Data Center (IDC) device 202 via an optical splitter. If the first data traffic is inbound data traffic, the optical splitter sends the first data traffic to the aggregation and splitting device 203. A preset Layer 2 packet policy is configured on port A31, and an inbound traffic label is added to the first data traffic according to the preset Layer 2 packet policy to generate the second data traffic. For example, the inbound traffic label can be VLAN 10.
[0058] In another example, the aggregation and splitting device 203 obtains the first data traffic during the data traffic exchange between the core router CR201 and the Internet Data Center (IDC) device 202 via an optical splitter. If the first data traffic is outbound data traffic, the optical splitter sends this first data traffic to the aggregation and splitting device 203. A preset Layer 2 packet policy is configured on port B32, and an outbound traffic label is added to the first data traffic according to the preset Layer 2 packet policy to generate the second data traffic. For example, the outbound traffic label can be VLAN 20.
[0059] The following section explains the process of traffic detection performed by the execution unit EU204, using examples.
[0060] In another example, the aggregation and distribution device 203 sends the generated second data traffic to the execution unit EU204. The execution unit EU204 identifies the traffic label of the second data traffic. If the traffic label of the second data traffic is VLAN 10, the execution unit EU204 determines that the second data traffic is inbound traffic. The execution unit EU204 then determines the destination IP address of the second data traffic through 5-tuple analysis. Finally, the execution unit EU204 compares the destination IP address of the second data traffic with the registered IP addresses in the storage unit DU206 to determine whether the destination IP address exceeds the range of registered IP addresses.
[0061] In another example, the aggregation and distribution device 203 sends the generated second data traffic to the execution unit EU204. The execution unit EU204 identifies the traffic label of the second data traffic. If the traffic label of the second data traffic is VLAN 20, the execution unit EU204 determines that the second data traffic is outbound traffic. The execution unit EU204 then determines the source IP address of the second data traffic through 5-tuple analysis. Finally, the execution unit EU204 compares the source IP address of the second data traffic with the registered IP addresses in the storage unit DU206 to determine whether the source IP address exceeds the range of registered IP addresses.
[0062] One possible implementation is, such as Figure 2As shown, the traffic detection system 20 also includes: an alarm output device 205; and an execution unit EU204, which is configured to: generate alarm information when the destination IP address or source IP address is not a registered IP address; and send alarm information to the alarm output device 205.
[0063] The alarm output device 205 is also configured to output alarm information.
[0064] For example, if the destination IP address or the source IP address exceeds the registered IP address, the execution unit EU4 generates an alarm message, which is then output by the alarm output device.
[0065] Based on the above technical solution, the traffic detection system provided in this application adds a traffic tag to the first data traffic through the aggregation and distribution device and sends it to the execution unit EU. The execution unit EU identifies the traffic tag according to the Layer 2 packet policy, and then determines whether the first data traffic is inbound or outbound traffic. If the first data traffic is inbound traffic, the execution unit EU determines its destination IP address and finally compares the destination IP address with the registered IP address to determine whether the destination IP address exceeds the registered IP address. Similarly, if the second data traffic is outbound traffic, the execution unit EU determines its source IP address and finally compares the source IP address with the registered IP address to determine whether the source IP address exceeds the registered IP address. This effectively detects IP addresses and avoids the problem of alarm devices misreporting user registered addresses.
[0066] The above describes the traffic detection system provided in the embodiments of this application.
[0067] The traffic detection method provided in the embodiments of this application will be described below.
[0068] like Figure 3 The diagram shown is a flowchart of a traffic detection method provided in this application. The traffic detection method provided in this application can be applied to, for example... Figure 2 In the traffic detection system shown, the execution unit EU identifies the traffic label of the data traffic. If the traffic label is an inbound traffic label, the execution unit EU determines the destination IP address of the data traffic and compares it with the registered IP address in the registration table to determine whether the destination IP address is a registered IP address, ensuring effective monitoring of the destination IP address. If the traffic label is an outbound traffic label, the execution unit EU determines the source IP address of the data traffic and compares it with the registered IP address in the registration table to determine whether the source IP address is a registered IP address, effectively monitoring the source IP address and avoiding the problem of alarm devices misreporting the user's registered address.
[0069] The following provides a detailed description of the traffic detection method provided in the embodiments of this application, such as... Figure 3 As shown, the flow detection method can be implemented through the following S301-S305.
[0070] S301, The flow detection device identifies the flow tag of the data flow.
[0071] The flow label can be either the inbound flow label or the outbound flow label.
[0072] In one possible implementation, the traffic detection device can be understood as an execution unit (EU). The traffic tag is a tag added to the data traffic by the aggregation and distribution device according to a preset Layer 2 message policy after the data traffic is acquired.
[0073] In one example, the flow detection device identifies the flow label of the data flow. If the flow label is an inbound flow label, which can be represented as VLAN 10, then the data flow is inbound data flow. If the flow label is an outbound flow label, which can be represented as VLAN 20, then the data flow is outbound data flow.
[0074] S302. When the traffic label is an inbound traffic label, the traffic detection device determines the destination IP address of the data traffic.
[0075] For example, if the data traffic is inbound, the traffic detection device analyzes the five-tuple of the inbound data traffic to determine that the destination IP address of the data traffic is 120.80.100.200. At this time, the destination IP address is the IP address of the IDC device.
[0076] S303. The traffic detection device determines whether the destination IP address is a registered IP address.
[0077] Referring to the example in S302, if the registered IP address stored in storage unit DU is 120.80.100.0 / 25, the traffic detection device determines that the destination IP address of the data traffic, 120.80.100.200, is not the registered IP address 120.80.100.0 / 25. If the registered IP address stored in storage unit DU is 120.80.100.200, then the traffic detection device determines that the destination IP address of the data traffic, 120.80.100.200, is the registered IP address 120.80.100.200.
[0078] It should be noted that the destination IP address of inbound data traffic is the IP address of the IDC device. Each IDC device has a pre-stored registered IP address in its storage unit DU. The registered IP address is used to compare with the destination IP address determined by the traffic detection device. If the destination IP address is not a registered IP address, it means that the system has missed reporting IP addresses. The missed IP addresses need to be added to the registered IP address list to avoid such omissions.
[0079] S304. When the traffic label is an outbound traffic label, the traffic detection device determines the source IP address of the data traffic.
[0080] For example, if the data traffic is outbound, the traffic detection device analyzes the outbound data traffic 5-tuple to determine that the source IP address of the data traffic is 120.80.100.200. In this case, the source IP address is the IP address of the IDC device.
[0081] In another example, when the data traffic is outbound, the traffic detection device analyzes the five-tuple of the outbound data traffic to determine that the destination IP address of the data traffic is 120.80.100.200. In this case, the destination IP address is the user's IP address. In the existing system, 120.80.100.200 may be an external service address or a service address that the user failed to report, making it impossible to determine. Therefore, this application uses the execution unit EU to identify the traffic label and determine whether the traffic label is an inbound or outbound traffic label. If it is an outbound traffic label, and the destination IP address is determined after analyzing the five-tuple, then the destination IP address 120.80.100.200 is an external network service address and does not belong to the case of user failure to report.
[0082] S305. The traffic detection device determines whether the source IP address is a registered IP address.
[0083] Referring to the example in S304, if the registered IP address stored in storage unit DU is 120.80.100.0 / 25, the traffic detection device determines that the source IP address of the data traffic, 120.80.100.200, is not the registered IP address 120.80.100.0 / 25. However, if the registered IP address stored in storage unit DU is 120.80.100.200, then the traffic detection device determines that the source IP address of the data traffic, 120.80.100.200, is the registered IP address 120.80.100.200.
[0084] It should be noted that the source IP address of outbound data traffic is the IP address of the IDC device; the destination IP address of outbound data traffic is the IP address of the user terminal. Each IDC device pre-stores registered IP addresses in its storage unit (DU). These registered IP addresses are used to compare with the source IP addresses determined by the traffic detection device. If a source IP address is not a registered IP address, it indicates that the system has missed reporting IP addresses, and the missed IP addresses need to be added to the registered IP address list.
[0085] The technical solutions provided by the above embodiments bring at least the following beneficial effects. Compared with the prior art, the traffic detection method provided by the embodiments of this application identifies the traffic label of the data traffic through the traffic detection device. If the traffic label is an inbound traffic label, the destination IP address of the data traffic is determined. The traffic detection device then determines whether the destination IP address belongs to the registered IP address. If the traffic label is an outbound traffic label, the source IP address of the data traffic is determined. The traffic detection device then determines whether the source IP address belongs to the registered IP address. This can effectively detect IP addresses and avoid the problem of alarm devices misreporting user registered addresses.
[0086] In one possible implementation, combining Figure 2 and Figure 3 ,like Figure 4 As shown, before the flow detection device identifies the flow tag of the data flow in S301 above, the aggregation and splitting device needs to add a tag to the data flow. This can be achieved through the following S401-S402, which are explained in detail below:
[0087] S401, Data traffic is acquired by aggregation and distribution equipment.
[0088] In one example, during the data traffic exchange between the core router (CR) and the Internet Data Center (IDC) equipment, the aggregation and splitting equipment obtains the exchanged data traffic through an optical splitter.
[0089] S402. The aggregation and distribution equipment adds tags to the data traffic according to the preset Layer 2 message policy.
[0090] In one example, the aggregation and distribution device has two ports, designated Port A and Port B. If the data traffic is inbound, the aggregation and distribution device adds a label to the inbound data traffic using the Layer 2 packet policy on Port A. The traffic label for inbound data traffic can be VLAN 10. If the data traffic is outbound, the aggregation and distribution device adds a label to the outbound data traffic using the Layer 2 packet policy on Port B. The traffic label for outbound data traffic can be VLAN 20.
[0091] One possible implementation is, such as Figure 3As shown, this application also includes the following alarm steps, which can be implemented through S306-S307, and are described in detail below:
[0092] S306. If the destination IP address or source IP address is not a registered IP address, the traffic detection device generates an alarm message.
[0093] Referring to the example in S303, the destination IP address 120.80.100.200 is not the registered IP address 120.80.100.0 / 25, and the traffic detection device determines the alarm information.
[0094] Referring to the example in S305, the source IP address 120.80.100.200 is not the registered IP address 120.80.100.0 / 25, and the traffic detection device determines the alarm information.
[0095] S307. The flow detection device sends alarm information to the alarm output device.
[0096] This application embodiment can divide the flow detection device into functional modules or functional units according to the above method example. For example, each function can be divided into a separate functional module or functional unit, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or in software functional modules or functional units. The module or unit division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.
[0097] like Figure 5 The diagram shown is a structural schematic of a flow detection device 50 provided in an embodiment of this application. The flow detection device 50 includes a processing unit 501.
[0098] Processing unit 501 is used to identify the traffic label of data traffic; the traffic label is either an inbound traffic label or an outbound traffic label; when the traffic label is an inbound traffic label, processing unit 501 is also used to determine the destination IP address of the data traffic; processing unit 501 is also used to determine whether the destination IP address is a registered IP address; when the traffic label is an outbound traffic label, processing unit 501 is also used to determine the source IP address of the data traffic; processing unit 501 is also used to determine whether the source IP address is a registered IP address.
[0099] Optionally, traffic tags are tags added to the data traffic by the aggregation and distribution device after it acquires the data traffic, according to a preset Layer 2 packet policy.
[0100] Optionally, the traffic detection device 50 further includes: a communication unit 502; if the destination IP address or source IP address is not a registered IP address, the processing unit 501 is also used to generate alarm information; the communication unit 502 is used to send alarm information to the alarm output device.
[0101] When implemented in hardware, the communication unit 502 in this embodiment can be integrated onto the communication interface, and the processing unit 501 can be integrated onto the processor. Specific implementation methods are as follows: Figure 6 As shown.
[0102] Figure 6 A schematic diagram of another possible structure of the traffic detection device involved in the above embodiments is shown. The traffic detection device includes a processor 602 and a communication interface 603. The processor 602 is used to control and manage the operation of the traffic detection device, for example, executing the steps performed by the processing unit 501, and / or performing other processes of the technology described herein. The communication interface 603 is used to support communication between the traffic detection device and other network entities, for example, executing the steps performed by the communication unit 502. The traffic detection device may also include a memory 601 and a bus 604, the memory 601 being used to store the program code and data of the traffic detection device.
[0103] The memory 601 may be a memory in a flow detection device, and the memory may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as read-only memory, flash memory, hard disk or solid-state drive; the memory may also include a combination of the above types of memory.
[0104] The processor 602 described above can implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor can be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor can also be a combination that implements computing functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.
[0105] Bus 604 can be an Extended Industry Standard Architecture (EISA) bus, etc. Bus 604 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 6 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0106] Through the above description of the embodiments, those skilled in the art will clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device, and unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0107] This application provides a computer program product containing instructions that, when run on a computer, cause the computer to execute the traffic detection method in the above method embodiments.
[0108] This application also provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the traffic detection method in the method flow shown in the above method embodiments.
[0109] The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: electrical connections having one or more wires; portable computer disks; hard disks; random access memory (RAM); read-only memory (ROM); erasable programmable read-only memory (EPROM); registers; hard disks; optical fibers; portable compact disc read-only memory (CD-ROM); optical storage devices; magnetic storage devices; or any suitable combination thereof; or any other form of computer-readable storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may reside in an application-specific integrated circuit (ASIC). In the embodiments of this application, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0110] Since the flow detection device, computer-readable storage medium, and computer program product in the embodiments of the present invention can be applied to the above method, the technical effects obtained can also be referred to the above method embodiments. The embodiments of the present invention will not be described again here.
[0111] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0112] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0113] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0114] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A flow detection system, characterized in that, The system includes: The system includes a core router (CR), an internet data center (IDC) device, an aggregation and distribution device, and an execution unit (EU); the CR and the IDC device are connected via a communication link and forward data to each other through the communication link; the aggregation and distribution device is connected to the communication link between the CR and the IDC device via an optical splitter. The aggregation and distribution device is configured to: acquire the first data traffic forwarded between the CR and the IDC device; add a Virtual Local Area Network (VLAN) tag to the first data traffic according to a preset Layer 2 packet policy, generate a second data traffic, and send the second data traffic to the execution unit EU; The execution unit EU is configured to: receive the second data traffic; determine the traffic label of the second data traffic; the traffic label is either an inbound traffic label or an outbound traffic label; if the traffic label is an inbound traffic label, determine the destination IP address of the data traffic; determine whether the destination IP address is a registered IP address; if the traffic label is an outbound traffic label, determine the source IP address of the data traffic; and determine whether the source IP address is a registered IP address.
2. The system according to claim 1, characterized in that, The system also includes: an alarm output device; The EU is also configured to: generate alarm information when the destination IP address or source IP address is not a registered IP address; and send the alarm information to the alarm output device. The alarm output device is also configured to output the alarm information.
3. A flow rate detection method, characterized in that, The method includes: Identify the traffic label of the data traffic; the traffic label is either an inbound traffic label or an outbound traffic label; the traffic label is a VLAN label added to the data traffic by the aggregation and distribution device after it obtains the data traffic, according to a preset Layer 2 packet policy; If the traffic label is an inbound traffic label, determine the destination IP address of the data traffic; Determine whether the destination IP address is a registered IP address; If the traffic label is an outbound traffic label, determine the source IP address of the data traffic; Determine whether the source IP address is a registered IP address.
4. The method according to claim 3, characterized in that, The method further includes: If the destination IP address or the source IP address is not a registered IP address, an alarm message is generated. Send the alarm information to the alarm output device.
5. A flow detection device, characterized in that, The device includes: a processing unit; The processing unit is used to identify the traffic label of the data traffic; the traffic label is either an inbound traffic label or an outbound traffic label; the traffic label is a VLAN label added to the data traffic by the aggregation and distribution device after it obtains the data traffic, according to a preset Layer 2 packet policy; When the traffic label is an inbound traffic label, the processing unit is further configured to determine the destination IP address of the data traffic; The processing unit is further configured to determine whether the destination IP address is a registered IP address; When the traffic label is an outbound traffic label, the processing unit is further configured to determine the source IP address of the data traffic; The processing unit is also used to determine whether the source IP address is a registered IP address.
6. The apparatus according to claim 5, characterized in that, The device further includes: a communication unit; If the destination IP address or the source IP address is not a registered IP address, the processing unit is also used to generate alarm information; The communication unit is used to send the alarm information to the alarm output device.
7. A flow detection device, characterized in that, include: A processor and a communication interface; the communication interface is coupled to the processor, the processor being used to run computer programs or instructions to implement the traffic detection method as described in any one of claims 3-4.
8. A computer-readable storage medium storing instructions, characterized in that, When the computer executes the instruction, the computer performs the flow detection method as described in any one of claims 3-4.
Citation Information
Patent Citations
Intranet NAT traffic positioning method and system
CN110505248A
IP address filing information checking method and device based on data flow
CN113923189A