Traffic mirroring method and apparatus, electronic device, storage medium, and product

By performing traffic mirroring on the mirror analysis system side, the traffic of Elastic Public Network and Dedicated Resource Instances is directly mirrored, which solves the problem of excessive resource consumption in existing technologies and achieves more efficient resource utilization.

CN116260750BActive Publication Date: 2026-01-09BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310260897.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-13
Publication Date
2026-01-09
Estimated Expiration
2043-03-13

AI Technical Summary

Technical Problem

During traffic mirroring, existing technologies consume a significant amount of host resources such as CPU, memory, and bandwidth, leading to resource waste and performance degradation.

Method used

By performing traffic mirroring on the mirroring analysis system side, traffic from Elastic Public Network and Dedicated Resource Instances can be directly mirrored to a designated device, reducing the consumption of host resources.

Benefits of technology

It effectively reduces the consumption of host CPU, memory and bandwidth resources, and improves the efficiency and resource utilization of traffic mirroring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116260750B_ABST
    Figure CN116260750B_ABST
Patent Text Reader

Abstract

The present disclosure provides a traffic mirroring method and device, electronic equipment, storage medium and product, relates to the technical field of data processing, in particular to the technical field of data traffic mirroring, data traffic collection and the like. The specific implementation scheme is as follows: a mirroring strategy of resource instance traffic to be mirrored is configured for a mirroring analysis system; resource instance traffic is acquired, and based on the mirroring analysis system, first resource instance traffic conforming to the mirroring strategy is mirrored in the resource instance traffic; and the first resource instance traffic is mirrored to a destination. The specified resource instance traffic can be mirrored to the specified device, thereby reducing the consumption of host CPU, memory, bandwidth and other resources.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of data processing, in particular to the technical field of data flow mirroring, data flow collection, and the like, and specifically relates to a flow mirroring method and device, an electronic device, a storage medium, and a product. BACKGROUND

[0002] Flow mirroring can be used in network intrusion detection, security audit, network problem positioning, and the like scenarios of network security. Especially, with the increase of user flow on the cloud and the complication of configuration, the requirement for flow mirroring is also higher and higher.

[0003] In the related art, in the process of flow mirroring, the resources such as central processing unit (CPU), memory, and bandwidth in a host may be consumed in comparison. SUMMARY

[0004] The present disclosure provides a flow mirroring method and device, an electronic device, a storage medium, and a product.

[0005] According to a first aspect of the present disclosure, a flow mirroring method is provided, and the method comprises:

[0006] A mirror analysis system is configured with a mirror policy of resource instance flow to be mirrored; resource instance flow is acquired, and based on the mirror analysis system, first resource instance flow conforming to the mirror policy is mirrored in the resource instance flow; and the first resource instance flow is mirrored to a destination.

[0007] According to a second aspect of the present disclosure, a flow mirroring device is provided, and the device comprises:

[0008] A configuration module is configured to configure a mirror analysis system with a mirror policy of resource instance flow to be mirrored; a mirror module is configured to acquire resource instance flow, and based on the mirror analysis system, mirror first resource instance flow conforming to the mirror policy in the resource instance flow; and the mirror module is further configured to mirror the first resource instance flow to a destination.

[0009] According to a third aspect of the present disclosure, an electronic device is provided, and the device comprises:

[0010] At least one processor; and a memory connected with the at least one processor in communication; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method of the first aspect or the second aspect.

[0011] According to a fourth aspect of the present disclosure, there is provided a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause the computer to perform the method according to the first aspect or the second aspect.

[0012] According to a fifth aspect of the present disclosure, there is provided a computer product comprising a computer program which, when executed by a processor, implements the method according to the first aspect or the second aspect.

[0013] It should be understood that the content described in this section is not intended to identify key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0014] The accompanying drawings are used to better understand the present scheme, and do not constitute a limitation on the present disclosure. Among them:

[0015] Figure 1 A flowchart of a traffic mirroring method provided by an embodiment of the present disclosure is shown;

[0016] Figure 2 A schematic diagram of sending resource instance traffic to a cloud server is shown;

[0017] Figure 3 A flowchart of a mirroring policy configuration method provided by an embodiment of the present disclosure is shown;

[0018] Figure 4 A schematic diagram of controlling flow direction is shown;

[0019] Figure 5 A schematic diagram of traffic mirroring is shown;

[0020] Figure 6 A flowchart of a mirroring policy configuration method provided by an embodiment of the present disclosure is shown;

[0021] Figure 7 A flowchart of an elastic public network resource instance traffic mirroring method provided by an embodiment of the present disclosure is shown;

[0022] Figure 8 A schematic diagram of an elastic public network resource instance traffic mirroring method provided by an embodiment of the present disclosure is shown;

[0023] Figure 9 A flowchart of an elastic public network resource instance traffic mirroring method provided by an embodiment of the present disclosure is shown;

[0024] Figure 10A schematic diagram of a method for mirroring traffic of a special network resource instance is shown.

[0025] Figure 11 A flowchart of a method for mirroring traffic of an elastic public network resource instance is shown.

[0026] Figure 12 A flowchart of a method for transmitting traffic across regions is shown.

[0027] Figure 13 A flowchart of a method for processing a mirroring policy is shown.

[0028] Figure 14 A structural diagram of a traffic mirroring device is shown.

[0029] Figure 15 A schematic block diagram of an example electronic device that can be used to implement embodiments of the present disclosure is shown. DETAILED DESCRIPTION

[0030] Exemplary embodiments of the present disclosure are described below with reference to the accompanying drawings, which include various details of the embodiments of the present disclosure to assist in understanding them. These should be considered as merely exemplary. Therefore, those of ordinary skill in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Also, descriptions of well-known functions and structures are omitted in the following description for clarity and conciseness.

[0031] Traffic mirroring can be used in network security, network intrusion detection, security audit, network problem positioning, and the like. In particular, as user traffic on the cloud increases and configuration becomes more complex, the requirements for traffic mirroring are also increasing.

[0032] In related technologies, traffic mirroring is performed on a virtual machine network card to obtain packets that pass through an elastic network card and meet filtering conditions. Through a traffic mirroring function, network traffic is copied and content inspection, threat monitoring, and problem troubleshooting are performed. However, in the process of traffic mirroring, resources such as host CPU, memory, bandwidth, and the like can be consumed in the same proportion.

[0033] Based on this, the present disclosure provides a traffic mirroring method and device. By performing traffic mirroring on the mirroring analysis system side, elastic public network resource instance traffic and special resource instance traffic can be directly mirrored, and specified resource instance traffic can be mirrored to a specified device, thereby reducing the consumption of resources such as host CPU, memory, bandwidth, and the like.

[0034] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-described drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present disclosure described herein can be implemented in an order other than that illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the present disclosure as detailed in the appended claims.

[0035] Figure 1 A flowchart of a traffic mirroring method provided by an embodiment of the present disclosure is shown, as shown in Figure 1 The method can include the following steps:

[0036] In step S110, a mirroring policy of resource instance traffic to be mirrored is configured for a mirror and analysis system.

[0037] In an embodiment of the present disclosure, a user can set the mirroring policy as needed, and thus configure the set mirroring policy in the mirror and analysis system.

[0038] For example, the user can specify mirroring of resource instance traffic to a specified device, where the specified resource can be elastic public network resource instance traffic and private network resource instance traffic, and the specified device can be a user cloud server, etc. Resource instance traffic filtering can also be supported, for example, mirroring of traffic protocol.

[0039] Performance indicators can also be set, for example, data describing Queries Per Second (QPS), latency, etc., with constraints such as 99.9%. Stress test data indicators can also be set, for example, the number of rules supported by a single mirror and analysis system (MAS) (e.g., 1000000), supported protocols (TCP, UDP, ICMP), and mirroring filtering conditions supported by each mirroring policy.

[0040] The mirroring policy can be set by a five-tuple, where the five-tuple can be understood as a set of five quantities consisting of a source network segment, a source port, a destination network segment, a destination port, and a protocol type.

[0041] For example, in the mirror strategy, the ingress direction rule is set as: source network segment 192.168.0.0 / 16, source port 10000, destination network segment 10.0.0.0 / 8, destination port 80, and protocol type TCP. When the network traffic flows into the ECS instance, the mirror session will mirror the network traffic that meets the following conditions at the same time: the source network segment is 192.168.0.0 / 16, the source port is 10000, the destination network segment is 10.0.0.0 / 8, the destination port is 80, and the protocol type is TCP.

[0042] In step S120, the resource instance traffic is acquired, and based on the mirror analysis system, the first resource instance traffic that meets the mirror strategy is acquired from the resource instance traffic.

[0043] In the embodiments of the present disclosure, the resource instance traffic can be acquired when the resource instance traffic passes through a virtual router (Tofino Baidu Virtual Router, TBVR) or a gateway (Baidu Gate Way, BGW), and the resource instance traffic is mirrored to the mirror analysis system.

[0044] Further, the mirror analysis system matches and filters the first resource instance traffic that meets the mirror strategy from the acquired resource instance traffic according to the information carried by the mirror packet and the mirror strategy.

[0045] In step S130, the first resource instance traffic is mirrored to a destination.

[0046] In the embodiments of the present disclosure, the mirror analysis system encapsulates the first resource instance traffic with Vxlan and sends it to the destination.

[0047] The destination can be a user load (Load Balancing, LB) device, and the virtual router needs to be used for website conversion in the mirroring process.

[0048] The user load can send the acquired first resource instance traffic to a required cloud server (Cloud Compute, BCC) or Taihang Elastic Baremetal server (Baremetal Compute, BCC).

[0049] Through the present disclosure, the elastic public network resource instance traffic and the private network resource instance traffic can be directly mirrored to the mirror analysis system, thereby reducing the consumption of host CPU, memory, bandwidth, and other resources.

[0050] Figure 2 A schematic diagram of sending resource instance traffic to a cloud server provided by the embodiments of the present disclosure is shown in FIG. 1. Figure 2As shown in FIG. 1, the B area includes a virtual router, a gateway, and a mirror analysis system, and the A area includes a user load and a cloud server. The B area can be understood as a service area that provides resource instance traffic, and the A area can be understood as a service area that faces customers.

[0051] Further, after the B area mirror analysis system mirrors the online traffic (i.e., resource instance traffic), the mirror analysis system performs transit of all websites through the virtual router, thereby mirroring the mirrored resource instance traffic to the user load, and the user load distributes the mirrored resource instance traffic to the required cloud server.

[0052] It should be noted that the resource instance traffic involved in the present disclosure can also be referred to as traffic.

[0053] The following embodiments of the present disclosure will be described with respect to configuring a mirror policy for the mirror analysis system to mirror resource instance traffic.

[0054] Figure 3 FIG. 2 shows a flowchart of a mirror policy configuration method according to an embodiment of the present disclosure. Figure 3 As shown in FIG. 2, the method can include the following steps.

[0055] In step S310, a mirror metadata interface is invoked, and a control plane interface is invoked based on the mirror metadata interface.

[0056] In step S320, the mirror policy is configured to each network element of the mirror analysis system based on the control plane interface.

[0057] In the embodiments of the present disclosure, after the user sets the mirror policy as needed, the mirror metadata interface can be invoked to configure the mirror policy for the mirror analysis system. Further, the mirror metadata interface can invoke the control plane interface to configure the mirror policy for the mirror analysis system. The present disclosure more centrally configures the mirror policy for the analysis system through the mirror metadata interface.

[0058] Figure 4 FIG. 3 shows a schematic diagram of a control flow direction according to an embodiment of the present disclosure. Figure 4 As shown in FIG. 3, the user invokes the mirror metadata module through the console, thereby controlling the mirror analysis system server and the elastic public network metadata / network service component (Neutron Server), and further controlling the mirror analysis system, the gateway, and the virtual router.

[0059] For example, FIG. 4 shows a schematic diagram of traffic mirroring according to an embodiment of the present disclosure. Figure 5 The mirror analysis system mirrors the resource instance traffic, and the user load distributes the mirrored resource instance traffic to the required cloud server. Figure 5 FIG. 4 shows a schematic diagram of traffic mirroring according to an embodiment of the present disclosure. Figure 5As shown, the user can invoke the mirror metadata interface through the console to configure the mirror policy for the analysis system. Thus, through the configured mirror policy, the intranet online traffic is mirrored in the virtual router, and the public online traffic is mirrored at the gateway. Further, the intranet mirror traffic and the public mirror traffic are transferred through the virtual router, and are mirrored to the user load and then sent to the required cloud server by the user load.

[0060] The following embodiments will illustrate how to configure the mirror policy to each network element of the mirror analysis system based on the control plane interface.

[0061] Figure 6 A flowchart of a mirror policy configuration method provided by an embodiment of the present disclosure is shown in FIG. 6. Figure 6 As shown in FIG. 6, the method can include the following steps.

[0062] In step S610, the virtual private cloud address and the load intranet address are obtained based on the pre-configured load address.

[0063] In the embodiment of the present disclosure, the user configures in the console, invokes the mirror metadata interface, and the mirror metadata interface obtains the virtual private cloud ID, LB intranet IP and other information based on the pre-configured load address.

[0064] In step S620, the network service interface is invoked to create the terminal node rule based on the virtual private cloud address and the load intranet address.

[0065] In the embodiment of the present disclosure, the mirror metadata interface creates the terminal node rule based on the invocation of the network service component (Neutron Server) interface.

[0066] In the process of creating the terminal node rule, the service number of the elastic public network needs to be used for authentication. The terminal node rule can be understood as the regional domain name of the object storage service (OBS) in different regions, which is used to process access requests in the respective regions. In other words, in the process of mirroring, the access request needs to be sent first, and then the resource instance traffic is mirrored to the specified device (i.e., the destination) after authorization.

[0067] In step S630, the state of the terminal node rule is updated to available, and the terminal node rule is stored in the database.

[0068] In the embodiment of the present disclosure, the Meta updates the terminal node rule, and updates the state (status) to available (available). The created terminal node rule can also be stored in the database. The mirror policy can also be stored in the database as needed.

[0069] In step S640, based on the terminal node rule, the mirror strategy is configured to each network element of the mirror analysis system.

[0070] In the embodiment of the present disclosure, according to the created terminal node rule, the configured mirror strategy is sent to each network element of the mirror analysis system.

[0071] In the embodiment of the present disclosure, after the mirror strategy is issued, the specified resource instance traffic can be mirrored to the destination according to the regular strategy. The resource instance traffic of the present disclosure can be one or two of the elastic public network resource instance traffic and the private resource instance traffic. The following embodiments will respectively illustrate the elastic public network resource instance (EIP) traffic and the private resource instance (VPC) traffic mirroring.

[0072] In an embodiment, the resource instance traffic is the elastic public network resource instance traffic.

[0073] Figure 7 A flowchart of a method for mirroring the elastic public network resource instance traffic according to an embodiment of the present disclosure is shown in FIG. 7. As shown in FIG. 7, the method can include: Figure 7

[0074] In step S710, the elastic public network resource instance traffic is normally mirrored to the mirror analysis system by the boundary gateway.

[0075] In step S720, based on the mirror analysis system, the first elastic public network resource instance traffic that meets the mirror strategy is mirrored in the elastic public network resource instance traffic.

[0076] In the embodiment of the present disclosure, for the EIP traffic, the boundary gateway (EGW) normally mirrors the traffic to the MAS, and the MAS filters the EIP instance traffic according to the IP in the data packet, and then performs rule filtering to obtain the EIP traffic (i.e., the first elastic public network resource instance traffic) that needs to be mirrored.

[0077] For example, Figure 8 A flowchart of a method for mirroring the elastic public network resource instance traffic according to an embodiment of the present disclosure is shown in FIG. 7. As shown in FIG. 7, the method can include: Figure 8

[0078] In an embodiment, the resource instance traffic is the private resource instance traffic. ​​

[0079] Figure 9 A flowchart of a method for mirroring traffic of a public network resource instance is shown in FIG. 9, which can include the following steps. Figure 9

[0080] In step S910, the specified private network resource instance traffic is mirrored to the mirror analysis system through a virtual router.

[0081] In step S920, a network identifier corresponding to the private network resource instance traffic is obtained.

[0082] In step S930, according to the network identifier, the first private network resource instance traffic that meets the mirror policy is mirrored.

[0083] In the embodiment of the present disclosure, for private line gateway traffic mirroring, the virtual router needs to mirror the traffic of a certain VPC to the MAS 1:1, and the MAS filters the traffic of the specified private line gateway according to the mirror policy in the MAS according to the network identifier (VNI) in the data packet, and then filters the traffic that needs to be mirrored according to the rules.

[0084] For example, Figure 10 A flowchart of a method for mirroring traffic of a private network resource instance is shown in FIG. 10, which can include the following steps. Figure 10 In step S1010, the network identifier and the mirror analysis system of the source and the network identifier and the mirror analysis system of the destination are obtained. According to the configured mirror policy, the resource instance traffic that meets the conditions is mirrored to the destination, and the traffic mirroring process is ended.

[0085] It should be noted that the EGW and the TBVR normally mirror traffic to the MAS, and in the present disclosure, the mirrored resource instance traffic and the normally mirrored resource instance traffic use the same implementation.

[0086] In the embodiment of the present disclosure, for EIP traffic mirroring, the current EGW full traffic can be mirrored to the MAS; for private line traffic mirroring, the current TBVR mirrored to the MAS is sampled. For the private line gateway that has been sampled and mirrored, the mirror configuration of the private line gateway needs to be changed to 1:1. Thus, the present disclosure can reuse the current public network traffic mirroring and private line traffic sampling capabilities to make traffic mirroring simpler and does not require additional development for the EGW and the TBVR.

[0087] The mirror traffic of the present disclosure is mirrored from the upstream (TBVR or EGW) to the MAS, and the MAS is mirrored to the user's cloud server, i.e., the resource instance traffic to the destination needs to be transmitted across zones, and the implementation is as follows.

[0088] Figure 11 ​A flowchart of a method for mirroring public network resource instance traffic according to an embodiment of the present disclosure is shown in FIG. 1. Figure 11 As shown in FIG. 1, the method can include the following steps.

[0089] In step S1110, the mirror analysis system sends an access request to the device corresponding to the destination.

[0090] In step S1120, the destination address is obtained.

[0091] In step S1130, in response to receiving the authorization information of the access request, the first resource instance traffic is mirrored to the destination corresponding to the destination address.

[0092] In the present embodiment, since the traffic needs to be transmitted across zones, the mirror analysis system needs to actively send an access request to the device corresponding to the destination. After determining that it is authorized, the resource instance traffic is transmitted.

[0093] Further, a terminal node rule can be created for each accessed destination resource, and the traffic address is converted in the transit virtual router, i.e., underlay to overlay conversion.

[0094] Figure 12 A flowchart of a method for transmitting traffic across zones according to an embodiment of the present disclosure is shown in FIG. 2. Figure 12 As shown in FIG. 2, the control console transmits the resource instance traffic mirror to the virtual router, thereby mirroring to the user's individual cloud server and the like.

[0095] In the present disclosure, access control can be achieved in two dimensions. Specifically, whether the transit address virtual router can be accessed is determined by the state of the terminal node; and which mirror analysis system can access the transit address virtual router is determined by the virtual router security group.

[0096] For a service provider-controlled virtual machine, the state can be specified as available when applying for a terminal node, and no additional authorization is required, so the virtual machine can be accessed by the corresponding mirror analysis system.

[0097] For a user's individual virtual machine, the user's authorization is usually required, and the state of the terminal node is updated to available after the user's authorization.

[0098] The service provider (traffic provider) needs to add its banatIP to the security group, and non-banatIP segments will be directly intercepted by the firewall.

[0099] In the present disclosure, when the MAS encapsulates Vxlan, the destination port needs to use the specified terminal node rule, and whether the non-standard message will be intercepted needs to be considered. If it is confirmed that it can pass, the traffic can be transmitted.

[0100] In the embodiments of the present disclosure, the configured mirror strategy can also be deleted, modified, added, etc.

[0101] In an embodiment, in response to determining to delete the mirror strategy, a terminal node rule corresponding to the first resource instance traffic is searched; if the terminal node rule exists, the terminal node rule is deleted; and if the terminal node rule does not exist, an error report is fed back.

[0102] In other words, it can be queried whether the instance has a corresponding terminal node, and if so, the terminal node is deleted, and if not, an error is reported.

[0103] In another embodiment, in response to determining to modify the mirror strategy, a terminal node rule corresponding to the first resource instance traffic is deleted, and a terminal node rule is recreated based on the modified mirror strategy.

[0104] That is, the backend LB is changed, and the original LB corresponding terminal node rule needs to be deleted first, and then the new LB corresponding terminal node rule is added.

[0105] In another embodiment, in response to determining that the load is deleted and / or determining that the elastic public network is released, the mirror strategy of the mirror analysis system is updated, and the mirror resource instance traffic of the mirror analysis system is stopped.

[0106] The present disclosure can periodically check the LB state, or subscribe to the LB event, if the LB has been deleted, the mirror rule on the MAS is updated, and the MAS is stopped mirroring. The EIP state can also be periodically checked, and if the EIP is released, the mirror rule on the MAS is updated, and the MAS is stopped mirroring.

[0107] In the present disclosure, if the user configures the mirror rule to reference the resource instance, and then actively deletes the resource, the network service component will subscribe to the deletion event of the resource after creating the terminal node rule, and will delete the terminal node rule in association; the MAS-Server can subscribe to the LB deletion event, or periodically check whether the LB exists, and if not, update the mirror rule on the MAS to stop mirroring.

[0108] If the user configures the mirror rule to reference the resource instance, and then changes the intranet IP of the resource instance, in the case that the network service component does not perform associated processing after changing the intranet IP, the console has an interface for changing the intranet IP, and the LB does not, then it can be executed according to the interface without stopping mirroring.

[0109] If a user configures mirroring rules, references an EIP instance, and then releases the EIP resource, the mirroring analysis system can periodically check if the EIP exists. If it does not exist, the system updates the mirroring rules on MAS, causing MAS to stop mirroring.

[0110] Figure 13 A schematic flowchart of a mirror strategy processing method provided in an embodiment of this disclosure is shown, as follows: Figure 13 As shown,

[0111] Users configure image policies to the image analytics system server by calling the image metadata interface through the console, thereby configuring image policies in various image analytics systems. The image analytics system server can also inspect the configured image policies and adjust them in real time.

[0112] Based on and Figure 1 The method shown follows the same principle. Figure 14 A schematic diagram of a flow mirroring device provided in an embodiment of this disclosure is shown, as follows: Figure 14 As shown, the flow mirroring device 1400 may include:

[0113] Configuration module 1401 is used to configure the mirroring strategy for the traffic of the resource instances to be mirrored in the mirroring analysis system;

[0114] The mirroring module 1402 is used to acquire resource instance traffic and, based on the mirroring analysis system, mirror the first resource instance traffic that conforms to the mirroring strategy from the resource instance traffic.

[0115] The mirroring module is also used to mirror the traffic of the first resource instance to the destination.

[0116] In this embodiment of the disclosure, the configuration module 1401 is used to call the image metadata interface and, based on the image metadata interface, call the control plane interface; and, based on the control plane interface, configure the image policy to each network element of the image analysis system.

[0117] In this embodiment of the disclosure, the configuration module 1401 is used to obtain a virtual private cloud address and a load intranet address based on a pre-configured load address; to call a network service interface to create terminal node rules based on the virtual private cloud address and the load intranet address; to update the status of the terminal node rules to available and store the terminal node rules in a database; and to configure the mirroring policy to each network element of the mirroring analysis system based on the terminal node rules.

[0118] In the embodiments of the present disclosure, the resource instance traffic is elastic public network resource instance traffic; the mirroring module 1402 is configured to mirror the elastic public network resource instance traffic to the mirror analysis system through a border gateway; based on the mirror analysis system, the first elastic public network resource instance traffic that mirrors the mirror policy is obtained from the elastic public network resource instance traffic.

[0119] In the embodiments of the present disclosure, the resource instance traffic is private network resource instance traffic; the mirroring module 1402 is configured to mirror the specified private network resource instance traffic to the mirror analysis system through a virtual router; a network identifier corresponding to the private network resource instance traffic is obtained; and the first private network resource instance traffic that mirrors the mirror policy is obtained according to the network identifier.

[0120] In the embodiments of the present disclosure, the mirroring module 1402 is configured to send an access request to a device corresponding to a destination through the mirror analysis system; a destination address is obtained; and the first resource instance traffic is mirrored to a destination corresponding to the destination address in response to receiving authorization information of the access request.

[0121] In the embodiments of the present disclosure, the configuration module 1401 is further configured to, in response to determining to delete the mirror policy, search for a terminal node rule corresponding to the first resource instance traffic; if the terminal node rule exists, delete the terminal node rule; and if the terminal node rule does not exist, feed back an error report.

[0122] In the embodiments of the present disclosure, the configuration module 1401 is further configured to, in response to determining to modify the mirror policy, delete a terminal node rule corresponding to the first resource instance traffic, and re-create a terminal node rule based on the modified mirror policy.

[0123] In the embodiments of the present disclosure, the configuration module 1401 is further configured to, in response to determining that the load is deleted and / or determining that the elastic public network is released, update a mirror policy of the mirror analysis system, and stop the mirror risk policy from mirroring resource instance traffic.

[0124] According to the embodiments of the present disclosure, the present disclosure further provides an electronic device, a readable storage medium, and a computer program product.

[0125] In an example embodiment, an electronic device includes at least one processor and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method as described in the above embodiments. The electronic device can be the above-mentioned computer or server.

[0126] In an example embodiment, the computer program product can be a non-transitory computer readable storage medium storing computer instructions, which, when executed by a computer, cause the computer to perform the method according to the above embodiments.

[0127] In an example embodiment, the computer program product comprises a computer program which, when executed by a processor, implements the method according to the above embodiments.

[0128] In the technical solution of the present disclosure, the acquisition, storage and application of user personal information comply with relevant laws and regulations and do not violate public order and good customs.

[0129] According to the embodiments of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium and a computer program product.

[0130] Figure 15 A schematic block diagram of an example electronic device 1500 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular telephones, smartphones, wearable devices, and other similar computing devices. The components shown here, their connections and relationships, and their functions, are meant to be examples only, and are not meant to limit implementations of the present disclosure described and / or claimed in this document.

[0131] As shown in Figure 15 The device 1500 includes a computing unit 1501 that can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 1502 or a computer program loaded from a storage unit 1508 into a random access memory (RAM) 1503. Various programs and data required for the operation of the device 1500 can also be stored in the RAM 1503. The computing unit 1501, the ROM 1502, and the RAM 1503 are connected to each other through a bus 1504. An input / output (I / O) interface 1505 is also connected to the bus 1504.

[0132] Various components in the device 1500 are connected to the I / O interface 1505, including an input unit 1506, such as a keyboard, a mouse, etc., an output unit 1507, such as various types of displays, speakers, etc., a storage unit 1508, such as a magnetic disk, an optical disk, etc., and a communication unit 1509, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 1509 allows the device 1500 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.

[0133] The computing unit 1501 can be various general and / or special purpose processing components with processing and computing capabilities. Some examples of the computing unit 1501 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 1501 performs various methods and processes described above, such as the traffic mirroring method. For example, in some embodiments, the traffic mirroring method can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 1508. In some embodiments, part or all of the computer program can be loaded and / or installed onto the device 1500 via the ROM 1502 and / or the communication unit 1509. When the computer program is loaded onto the RAM 1503 and executed by the computing unit 1501, one or more steps of the traffic mirroring method described above can be performed. Alternatively, in other embodiments, the computing unit 1501 can be configured to perform the traffic mirroring method by any other suitable means, such as by means of firmware.

[0134] Various implementations of the systems and techniques described above can be realized in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a programmable logic device (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.

[0135] Program code for carrying out methods of the present disclosure can be written in any combination of one or more programming languages. The program code can be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the program code, when executed by the processor or controller, produces a means for implementing the functions / acts specified in the flowcharts and / or block diagrams. The program code can be executed entirely on a machine, partially on a machine, partially on a machine and partially on a remote machine or entirely on a remote machine or server.

[0136] In the context of this disclosure, a machine-readable medium can be a tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include but is not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0137] To provide for interaction with a user, the systems and techniques described here can be implemented on a computer having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.

[0138] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.

[0139] The computer system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. The server can be a cloud server, a server of a distributed system, or a server combined with a blockchain.

[0140] It should be understood that the various forms of flow shown above can be used to reorder, add, or delete steps. For example, the steps described in the present disclosure can be performed in parallel, in series, or in a different order, as long as the desired results of the technology disclosed in the present disclosure can be achieved, which is not limited herein.

[0141] The above detailed description does not constitute a limitation on the protection scope of the present disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present disclosure shall be included in the protection scope of the present disclosure.

Claims

1. A traffic mirroring method, the method comprising: configuring a mirroring policy of resource instance traffic to be mirrored for a mirroring analysis system; acquiring resource instance traffic, and mirroring first resource instance traffic conforming to the mirroring policy in the resource instance traffic based on the mirroring analysis system; mirroring the first resource instance traffic to a destination; wherein the configuring the mirroring policy of resource instance traffic to be mirrored for the mirroring analysis system comprises: calling a mirroring metadata interface, and calling a control plane interface based on the mirroring metadata interface; configuring the mirroring policy to each network element of the mirroring analysis system based on the control plane interface; wherein it comprises: acquiring a virtual private cloud address and a load internal network address based on a pre-configured load address; calling a network service interface to create a terminal node rule based on the virtual private cloud address and the load internal network address; updating a state of the terminal node rule to available, and storing the terminal node rule into a database; configuring the mirroring policy to each network element of the mirroring analysis system based on the terminal node rule.

2. The method of claim 1, wherein, The resource instance traffic is elastic public network resource instance traffic; The mirroring, based on the mirroring analysis system, of first resource instance traffic conforming to the mirroring policy in the resource instance traffic comprises: normally mirroring the elastic public network resource instance traffic to the mirroring analysis system through a border gateway; mirroring, based on the mirroring analysis system, first elastic public network resource instance traffic conforming to the mirroring policy in the elastic public network resource instance traffic.

3. The method of claim 1, wherein, The resource instance traffic is private network resource instance traffic; The mirroring, based on the mirroring analysis system, of first resource instance traffic conforming to the mirroring policy in the resource instance traffic comprises: mirroring specified private network resource instance traffic to the mirroring analysis system through a virtual router; acquiring a network identifier corresponding to the private network resource instance traffic; mirroring, according to the network identifier, first private network resource instance traffic conforming to the mirroring policy.

4. The method of claim 1, wherein, The mirroring of the first resource instance traffic to the destination comprises: sending an access request to a device corresponding to the destination through the mirroring analysis system; acquiring a destination address; in response to receiving authorization information of the access request, mirroring the first resource instance traffic to a destination corresponding to the destination address.

5. The method of claim 1, wherein, The configuring the mirroring policy of resource instance traffic to be mirrored for the mirroring analysis system further comprises: in response to determining to delete the mirroring policy, finding a terminal node rule corresponding to the first resource instance traffic; if the terminal node rule exists, deleting the terminal node rule; if the terminal node rule does not exist, feeding back an error report.

6. The method of claim 1, wherein, The configuring the mirroring policy of resource instance traffic to be mirrored for the mirroring analysis system further comprises: in response to determining to modify the mirroring policy, deleting a terminal node rule corresponding to the first resource instance traffic, and re-creating a terminal node rule based on the modified mirroring policy.

7. The method of claim 1, wherein, The method further comprises: In response to determining that the load is deleted and / or determining that the elastic public network is released, updating a mirror policy of the mirror analysis system, and stopping the mirror analysis system from mirroring the resource instance traffic.

8. A traffic mirroring apparatus, the apparatus comprising: a configuration module configured to configure a mirror policy of resource instance traffic to be mirrored for a mirror analysis system; a mirroring module configured to obtain the resource instance traffic and, based on the mirror analysis system, mirror first resource instance traffic that complies with the mirror policy in the resource instance traffic; the mirroring module is further configured to mirror the first resource instance traffic to a destination; wherein the configuration module is configured to: invoke a mirror metadata interface and invoke a control plane interface based on the mirror metadata interface; configure the mirror policy to each network element of the mirror analysis system based on the control plane interface; wherein the configuration module is configured to: obtain a virtual private cloud address and a load intranet address based on a preconfigured load address; invoke a network service interface to create a terminal node rule based on the virtual private cloud address and the load intranet address; update a state of the terminal node rule to available and store the terminal node rule into a database; configure the mirror policy to each network element of the mirror analysis system based on the terminal node rule.

9. The apparatus of claim 8, wherein, the resource instance traffic is elastic public network resource instance traffic; the mirroring module is configured to: mirror the elastic public network resource instance traffic to the mirror analysis system through a border gateway; based on the mirror analysis system, mirror first elastic public network resource instance traffic that complies with the mirror policy in the elastic public network resource instance traffic.

10. The apparatus of claim 8, wherein, the resource instance traffic is private network resource instance traffic; the mirroring module is configured to: mirror specified private network resource instance traffic to the mirror analysis system through a virtual router; obtain a network identifier corresponding to the private network resource instance traffic; mirror first private network resource instance traffic that complies with the mirror policy according to the network identifier.

11. The apparatus of claim 8, wherein, the mirroring module is configured to: send an access request to a device corresponding to the destination through the mirror analysis system; obtain a destination address; in response to receiving authorization information of the access request, mirror the first resource instance traffic to a destination corresponding to the destination address.

12. An electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-7.

13. A non-transitory computer readable storage medium having stored thereon computer instructions, wherein, The computer instructions are used to enable the computer to perform the method of any one of claims 1-7.

14. A computer program product comprising a computer program which, when executed by a processor, implements the method of any one of claims 1-7.

14. A computer program product comprising a computer program which, when executed by a processor, implements the method of any one of claims 1-7.

Citation Information

Patent Citations

  • Business flow-mirroring method and mirroring device

    CN103051497A