Message Parsing Method and Apparatus
By using preset offsets to obtain packet field information in the switch, the problem that the switch cannot extract five-tuples is solved, and the switch's shunt function is realized, reducing the cost of the shunt.
Patent Information
- Application Number
- CN202211740581.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-30
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-12-30
AI Technical Summary
Existing switches cannot accurately extract five-tuple information from complex messages, resulting in the inability to use the switch to implement the shunt function to reduce the shunt cost.
By obtaining the field information of the message in sequence according to multiple preset offsets, determining the message type, and determining the starting position of the message according to the position of the last offset when the set threshold is reached, the five-tuple information is accurately extracted.
实现了交换机能够精准提取报文的五元组信息,降低了应用分流器的数据分流成本。
Smart Images

Figure CN116319543B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a method and apparatus for parsing packets. Background Art
[0002] A five-tuple includes a source IP address, a source port, a destination IP address, a destination port, and a transport layer protocol. A network shunt can achieve data traffic shunting for the acquired data traffic through five-tuple information and an output algorithm. However, the production cost of the network shunt is relatively high.
[0003] Existing switches cannot accurately extract the five-tuple information of complex packets, so it is impossible to use a switch to implement the shunt function to reduce the cost of using a shunt. Summary of the Invention
[0004] In view of this, to solve the above technical problems, this application provides a method and apparatus for parsing packets.
[0005] Specifically, this application is implemented through the following technical solutions:
[0006] According to a first aspect of an embodiment of this application, a method for parsing packets is provided. The method includes:
[0007] Perform offsets sequentially according to a plurality of first preset offsets to obtain first field information of a packet to be processed;
[0008] In response to the number of times of obtaining the first field information reaching a set threshold and the obtained first field information not indicating a preset packet type, determine a first packet in the packet to be processed according to the position of the last offset;
[0009] Obtain five-tuple information of the packet to be processed from the first packet.
[0010] Optionally, the step of "in response to the number of times of obtaining the first field information reaching a set threshold and the obtained first field information not indicating a preset packet type, determine a first packet in the packet to be processed according to the position of the last offset" includes:
[0011] Obtain the byte length corresponding to the field where the first field information obtained by the last offset is located;
[0012] Obtain the first packet according to the position of the last offset and the byte length.
[0013] Optionally, the step of "obtain five-tuple information of the packet to be processed from the first packet" includes:
[0014] Determine the message type of the first message according to the field value corresponding to the set byte of the first message, where the set byte corresponds to the message type indicated by the first field information obtained by the last offset;
[0015] According to the message type of the first message, determine the Internet Protocol (IP) header position of the message to be processed;
[0016] Based on the IP header position, obtain the five-tuple information of the message to be processed.
[0017] Optionally, in response to the first field information obtained by the last offset indicating a Multi-Protocol Label Switching (MPLS) label, the determining the message type of the first message according to the field value corresponding to the set byte of the first message includes:
[0018] Obtain the field value corresponding to the byte where the bottom-of-stack identifier is located in the first message;
[0019] According to the field value, determine the first message type.
[0020] Optionally, in response to the first field information obtained by the last offset indicating a Virtual Local Area Network (VLAN) label, the determining the message type of the first message according to the field value corresponding to the set byte of the first message includes:
[0021] Obtain the field value corresponding to the first two bytes before the message header of the first message;
[0022] According to the field value, determine the message type of the first message.
[0023] Optionally, in response to the message type including a message with a VLAN label, the determining the IP header position of the message to be processed according to the message type of the first message includes:
[0024] Obtain the second field information of the first message in sequence according to multiple second preset offsets;
[0025] In the case where the second field information indicates an IP message or an MPLS label, determine the second message in the first message according to the position of the last offset;
[0026] According to the message type of the second message, determine the IP header position of the message to be processed.
[0027] Optionally, the determining the IP header position of the message to be processed according to the message type of the target message, where the target message includes the first message and the second message, includes:
[0028] In response to the message type including an IP message, determine that the end position of the field indicating the message type of the target message is the IP header position;
[0029] In response to the message type including a message with an MPLS label, sequentially obtain third field information of the target message according to a plurality of third preset offsets; when the third field information meets a set condition, determine that the end position of the field where the third field information is located is the IP header position.
[0030] According to a second aspect of the embodiments of the present application, there is provided a message parsing device, and the device includes:
[0031] A field information acquisition module, configured to sequentially perform offsets according to a plurality of first preset offsets to obtain first field information of a message to be processed;
[0032] A response module, in response to the number of times of obtaining the first field information reaching a set threshold and the obtained first field information not indicating a preset message type, determine a first message in the message to be processed according to the position of the last offset;
[0033] A tuple information acquisition module, configured to obtain five-tuple information of the message to be processed from the first message.
[0034] Optionally, the response module is specifically configured to:
[0035] Obtain the byte length corresponding to the field where the first field information obtained by the last offset is located;
[0036] Obtain the first message according to the position of the last offset and the byte length.
[0037] Optionally, the tuple information acquisition module includes:
[0038] A first type determination module, configured to determine the message type of the first message according to the field value of the set byte of the first message, and the set byte corresponds to the message type indicated by the first field information obtained by the last offset;
[0039] A first position determination module, configured to determine the Internet Protocol IP header position of the message to be processed according to the message type of the first message;
[0040] An information acquisition module, configured to obtain five-tuple information of the message to be processed based on the IP header position.
[0041] Optionally, in response to the first field information obtained by the last offset indicating a Multiprotocol Label Switching MPLS label, the first type determination module is specifically configured to:
[0042] Obtain the field value corresponding to the byte where the stack bottom identifier in the first message is located;
[0043] Determine the type of the first message according to the field value.
[0044] Optionally, in response to the first field information obtained by the last offset indicating a Virtual Local Area Network (VLAN) tag, the first type determination module is specifically configured to:
[0045] Obtain the field value corresponding to the first two bytes before the message header of the first message;
[0046] Determine the type of the first message according to the field value.
[0047] Optionally, in response to the message type including a message with a VLAN tag, the first position determination module is specifically configured to:
[0048] A second field information acquisition module, configured to sequentially acquire second field information of the first message according to a plurality of second preset offsets;
[0049] A second type determination module, configured to determine a second message in the first message according to the position of the last offset when the second field information indicates an IP message or an MPLS label;
[0050] A second position determination module, configured to determine the IP header position of the message to be processed according to the message type of the second message.
[0051] Optionally, the first position determination module or the second position determination module is specifically configured to:
[0052] In response to the message type including an IP message, determine that the end position of the field indicating the message type of the target message is the IP header position;
[0053] In response to the message type including a message with an MPLS label, sequentially acquire third field information of the target message according to a plurality of third preset offsets; when the third field information meets a set condition, determine that the end position of the field where the third field information is located is the IP header position.
[0054] According to the third aspect of the embodiments of the present application, a switch is provided, and the switch is configured to implement the message parsing method described in any one of the above embodiments.
[0055] The technical solution provided by the embodiments of the present application may include the following beneficial effects:
[0056] By applying the technical solution provided by the present application, the function that the switch can accurately extract the five-tuple information of the packet is realized, so that the switch can realize the function of the shunt device, thereby reducing the cost of using the shunt device for data shunting.
[0057] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. In addition, any embodiment in the present application does not need to achieve all the above effects. Brief Description of the Drawings
[0058] Figure 1 is a flowchart of a packet parsing method shown in an exemplary embodiment of the present application;
[0059] Figure 2 is a flowchart of a packet parsing method with multi-layer VLAN tags shown in an exemplary embodiment of the present application;
[0060] Figure 3 is a schematic diagram of a packet parsing method flow shown in an exemplary embodiment of the present application;
[0061] Figure 4 is a schematic diagram of the structure of a packet parsing device shown in an exemplary embodiment of the present application. Detailed Description of the Embodiments
[0062] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0063] The terms used in the present application are only for the purpose of describing specific embodiments, and are not intended to limit the present application. The singular forms "a", "the" and "said" used in the present application and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more of the associated listed items.
[0064] It should be understood that although the terms first, second, third, etc. may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of this application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to a determination".
[0065] The five-tuple includes a source IP address, a source port, a destination IP address, a destination port, and a transport layer protocol. The network splitter is installed between the production network mirror port and the analysis device cluster, obtains the production network device mirror or the split traffic, and converges, replicates, and distributes it to one or more data analysis devices according to the five-tuple information, and can achieve the output of the traffic with the same source and the same destination and load balancing.
[0066] However, the production cost of the network splitter is relatively high and it is not easy to develop. In the related art, an FPGA (Field Programmable Gate Array) is used to develop the splitter, which has high performance but high development difficulty and cost; using an ASIC (Application Specific Integrated Circuit) chip for development, the performance is relatively high but the expansion operation is inconvenient; directly developing with a CPU (Central Processing Unit), the forwarding performance of the splitter is affected.
[0067] Existing switches cannot accurately extract five-tuple information for complex packets, such as Ethernet data frames with multiple VLAN tags and packets with multiple MPLS tags; specifically, for complex packets, existing switches cannot accurately locate the position of the IP header, and the packet parsing process has been terminated before the IP packet header has been parsed. Therefore, even if existing switches already have mirroring capabilities, it is still impossible to use switches to implement the splitter function.
[0068] To solve the above problems, this application provides a packet parsing method. See Figure 1 shown, the method may include the following steps:
[0069] S101, perform offsets in sequence according to a plurality of first preset offsets to obtain first field information of the packet to be processed;
[0070] The first preset offset can be set according to the field lengths in different types of messages and corresponds to the encapsulation type of the message. For example, the types of the message can include Ethernet data frames and IP datagrams with MPLS labels. Among them, the first preset offset corresponding to the Ethernet data frame can include the number of bytes corresponding to the combination of the destination physical address and the source-destination address fields, the number of bytes corresponding to the VLAN tag field, and the number of bytes corresponding to the protocol type field; the first preset offset corresponding to the IP datagram with an MPLS label can be the number of bytes corresponding to the bottom-of-stack identifier of the MPLS label and the number of bytes corresponding to the MPLS label field.
[0071] Before offsetting according to the first preset offset, the encapsulation type of the message to be processed can be determined according to the field value corresponding to the preset byte in the message header of the message to be processed. For example, in response to the field value corresponding to the set byte indicating the protocol type or the VLAN tag, it can be determined that the message to be processed is an Ethernet data frame. According to the encapsulation type of the message to be processed, the corresponding first preset offset is selected.
[0072] The first field information can be the field information corresponding to the set byte length obtained after offsetting the message to be processed according to the first preset offset. For example, the first preset offset can be 12 bytes, and the set byte length is 2 bytes. After obtaining the message, the position corresponding to 12 bytes backward from the message header is determined, and the field information corresponding to the 2 bytes backward from the position is obtained as the first field information.
[0073] After obtaining the message to be processed, according to each first preset offset, it can be offset to the specified position of the message to be processed to obtain the first field information, and the first field information is matched with the field information corresponding to the preset message type. When any of the following conditions is met, the message to be processed is no longer offset according to the first preset offset: the first field information matches the field information corresponding to the preset message type and the number of times of obtaining the first field information does not exceed the set threshold; the first field information does not match the field information corresponding to the preset message type and the number of times of obtaining the first field information reaches the set threshold.
[0074] In one example, after obtaining the message to be processed and determining that the encapsulation type of the message is an Ethernet data frame message, the first preset offset can include the first preset offset corresponding to the Ethernet data frame.
[0075] After obtaining an Ethernet data frame message, offset backward according to the number of bytes indicating the message header offset in the first preset offset, and take the field information corresponding to the two bytes after this position as the first field information. When the first field information fails to match the field information corresponding to the preset message type, based on the number of offset bytes corresponding to the field indicated by the first field information in the first preset offset, offset backward according to the position of the first offset, and re-obtain the first field information. In the case of a failed field information match, repeat the operations of offsetting according to the first preset offset, obtaining the first field information, and matching the field information.
[0076] When the number of times of obtaining the first field information is less than or equal to the set threshold and the first field information matches the field information corresponding to the preset message type, or when the number of times of obtaining the first field information is equal to the set threshold and the first field information fails to match the field information corresponding to the preset message type, no more offset operations are performed.
[0077] S102, in response to the number of times of obtaining the first field information reaching the set threshold and the obtained first field information not indicating the preset message type, determine the first message in the to-be-processed message according to the position of the last offset.
[0078] The first field information not indicating the preset message type may be that the first field information fails to match the field information corresponding to the preset message type. Taking the preset message type as an IP message as an example, the field information corresponding to the IP message is 0800. In the case where the first field information is 8100, then the first field information does not indicate the preset message type.
[0079] The position of the last offset may include the starting position of the field where the first field information is located when the number of times of obtaining the first field information is equal to the set threshold. For example, the set threshold may be 3, then the position of the last offset may be the position corresponding to the third offset on the to-be-processed message.
[0080] When the number of times of obtaining the first field information is equal to the set threshold and the first field information does not indicate the preset message type, the first message may be determined according to the position of the last offset. Still taking the above set threshold of 3 as an example, when the number of times of obtaining the first field information is equal to 3 and each obtained first field information fails to match the field information corresponding to the preset message type, the first message may be determined according to the position corresponding to the third offset on the to-be-processed message.
[0081] In some embodiments, the determining the first message in the to-be-processed message according to the position of the last offset may include: obtaining the byte length corresponding to the field where the first field information obtained by the last offset is located; obtaining the first message according to the position of the last offset and the byte length.
[0082] Among them, obtaining the first message according to the position of the last offset and the byte length may be to determine the position after adding the byte length to the position of the last offset as the starting position of the first message, and determine the data message after the starting position in the message to be processed as the first message.
[0083] For example, the position of the last offset may be the position corresponding to the 20th byte from the header of the message to be processed. If the first field information obtained is in the VLAN tag field, the corresponding byte length of this field is 4 bytes; therefore, after adding 4 bytes to the end position of the second VLAN tag, the corresponding position is the position corresponding to the 24th byte from the header of the message to be processed, and the data message after the 24th byte position is determined as the first message.
[0084] S103, obtain the five-tuple information of the message to be processed from the first message.
[0085] The five-tuple information includes the source IP address, source port, destination IP address, destination port, and transport layer protocol, which are stored in the IP datagram. After determining the position of the message header of the IP datagram, the five-tuple information can be obtained based on the message header.
[0086] The first message includes the content of the IP datagram in the message to be processed. Therefore, the first message can be parsed, and the five-tuple information of the message to be processed can be obtained from the first message.
[0087] Applying the technical solution provided by the present application realizes the function that the switch can accurately extract the five-tuple information of the message, so that the switch can realize the function of the splitter, thereby reducing the cost of using the splitter for data splitting.
[0088] In some embodiments, obtaining the five-tuple information of the message to be processed from the first message includes: determining the message type of the first message according to the field value corresponding to the set byte of the first message, where the set byte corresponds to the message type indicated by the first field information obtained by the last offset; determining the IP header position of the message to be processed according to the message type of the first message; and obtaining the five-tuple information of the message to be processed based on the IP header position.
[0089] Among them, the message type indicated by the first field information may include indicating a VLAN tag and an MPLS tag. In one example, when the first field information includes 8100, it corresponds to indicating a VLAN tag; when the first field information includes 8847, it corresponds to indicating an MPLS tag.
[0090] Determine the set byte according to the information indicated by the first field information, and determine the message type of the first message based on the field value corresponding to the set byte.
[0091] In some embodiments, in response to the first field information obtained by the last offset according to the first preset offset indicating an MPLS label, obtain the field value corresponding to the byte where the bottom-of-stack identifier in the first message is located; determine the message type of the first message according to the field value.
[0092] Among them, the bottom-of-stack identifier of the MPLS label corresponds to the field value of the 23rd bit of the MPLS label field, and the field value of the bottom-of-stack identifier takes a value of 0 or 1. When the field value is 0, the MPLS label where the current field value is located is not the bottom-of-stack label, that is, the field after the end position of the MPLS label field is still an MPLS label; when the field value is 1, the MPLS label where the current field value is located is the bottom-of-stack label, that is, the data message after the end position of the MPLS label field is an IP data message.
[0093] The determining the message type of the first message according to the field value may include: in response to the field value being 0, determining that the message type of the first message is a message with an MPLS label; in response to the field value being 1, determining that the message type of the first message is an IP message.
[0094] In some embodiments, in response to the first field information obtained by the last offset according to the first preset offset indicating a VLAN label, obtain the field value corresponding to the first two bytes before the message header of the first message; determine the message type of the first message according to the field value.
[0095] Among them, if the first field information obtained by the last offset indicates a VLAN label message, the first two bytes before the message header of the first message may include a VLAN label field and an Ethernet data frame protocol type field.
[0096] The determining the message type of the first message according to the field value may include: in response to the field value including 8100, determining that the message type of the first message is a message with a VLAN label; in response to the field value including 8847, determining that the message type of the first message is a message with a VLAN label; in response to the field value including 0800, determining that the message type of the first message is an IP message.
[0097] In some embodiments, after determining the packet type of the first packet, in response to the packet type of the first packet including a packet with a VLAN tag; determining the IP header position of the packet to be processed according to the packet type of the first packet includes: sequentially obtaining second field information of the first packet according to a plurality of second preset offsets; in the case where the second field information indicates an IP packet or an MPLS label, determining a second packet in the first packet according to the position of the last offset; and determining the IP header position of the packet to be processed according to the packet type of the second packet.
[0098] In the case where the packet type of the first packet is a packet with a VLAN tag, offsets can be made according to a plurality of second preset offsets to sequentially obtain second field information. After making an offset according to each second preset offset, obtain the field information corresponding to the set number of bytes, and determine whether the field information indicates an MPLS label or an IP packet. In the case where the determination result is negative, make an offset according to the next second offset and re-obtain the second field information.
[0099] Taking the first packet as a packet with a two-layer VLAN tag as an example, assume that the fields of the first packet are <VLAN tag 1><VLAN tag 2><protocol type><data field><frame check sequence> in sequence. For the first time, make an offset of 4 bytes according to the second preset offset. The current offset position is at the end position of the VLAN1 tag field, and obtain the field information corresponding to the first two bytes after this end position. The field information indicates a VLAN tag; then for the second time, make an offset of 4 bytes according to the second preset offset. The current offset position is at the end position of the VLAN2 tag field, and obtain the field information corresponding to the first two bytes after this end position. The field information includes the field information corresponding to the protocol type. When the field information indicates an IP packet type or an MPLS label, no further offset is made according to the second preset offset. For example, if the field information corresponding to the protocol type is 0800, then the field information indicates an IP packet type.
[0100] In the case where the second field information indicates an IP packet or an MPLS label, determine a second packet in the first packet according to the position of the last offset.
[0101] Still taking the above packet with a two-layer VLAN tag as an example, when the field information indicates an IP packet type, the position of the last offset includes the end position of the VLAN2 tag field. It can be determined that the data packet after the end position of the VLAN2 tag field is the second packet, that is, it can be determined that <protocol type><data field><frame check sequence> is the second packet.
[0102] In some embodiments, determining the IP header position of the to-be-processed packet according to the packet type of the first packet or the second packet includes:
[0103] In response to the packet type including an IP packet, determining the end position of the field indicating the packet type of the target packet as the IP header position;
[0104] In response to the packet type including a packet with an MPLS label, sequentially obtaining third field information of the target packet according to a plurality of third preset offsets; in the case where the third field information meets a set condition, determining the end position of the field where the third field information is located as the IP header position.
[0105] Wherein, the packet type of the first packet is determined according to the field value corresponding to the set byte in the packet header, the second packet type is determined according to the second field information, and the second field information is obtained after being offset according to the second preset offset for the last time. The determined second packet may include the field where the second field information is located.
[0106] In the case where the packet type of the first packet or the second packet is an IP packet, the end position of the field indicating that the packet type is an IP packet can be determined as the IP header position. For example, if the field value corresponding to the first two bytes in the packet header of the first packet indicates that the packet type is an IP packet, the end position of the first two bytes in the packet header is determined as the IP header position; taking the above-mentioned second packet <protocol type><data field><frame check sequence> as an example, when the field value corresponding to the protocol type is 0800, the end position of the protocol type field is determined as the IP header position.
[0107] In the case where the packet type of the first packet or the second packet includes a packet with an MPLS label, the third field information of the target packet is sequentially obtained according to a plurality of third preset offsets, and the steps of obtaining the field information are similar to the foregoing steps and will not be elaborated herein.
[0108] In one example, the third field information may be the field value indicating the bottom of the MPLS label stack, and the corresponding set condition may be that the field value is 1. In the case where the third field information meets the condition that the field value is 1, the MPLS label where the third field information is located is the bottom label, and the data packet after the bottom label is an IP packet. Therefore, the end position of the MPLS label field where the third field information is located can be determined as the IP header position.
[0109] Taking the case where the target message type is a message with MPLS labels as an example, the format of the target message may include <MPLS label 1><MPLS label 2><IP datagram>, and the third preset offset may include an offset of 18 bits for the message header and an offset of 4 bytes for the MPLS label. The field information obtained according to the third preset offset includes the field value corresponding to the bottom-of-stack identifier of the MPLS label. The determining of the IP header position may include the following operations:
[0110] After offsetting 18 bits for the message header, determine the first offset position, and obtain the field value corresponding to one byte after the offset position. The field value corresponding to the bottom-of-stack identifier of MPLS label 1 is 0;
[0111] Offset 4 bytes backward from the first offset position to determine the second offset position, and obtain the field value corresponding to one byte after the offset position. The field value corresponding to the bottom-of-stack identifier of MPLS label 2 is 1;
[0112] In response to the field value being 1, determine the end position of the MPLS label 2 field as the IP header position.
[0113] Next, the solution of the present application will be described in conjunction with a specific application example of the message parsing method.
[0114] In the embodiment of the present application, a message with multiple VLAN labels is taken as an example to exemplarily elaborate on the solution of the present application. The VLAN label is a field inserted after the destination physical address and source physical address fields and before the protocol type field of the Ethernet data frame, and the field length is four bytes. The field values corresponding to the first two bytes of the VLAN label are 8100, which are used to identify that the field where the current field value is located is the VLAN label. In the embodiment of the present application, a message with four VLAN labels is taken as an example, and the preset message type is an IP message or a message with MPLS labels. Those skilled in the art should understand that the number of layers of the VLAN label and the preset message type depend on the actual message to be processed, and the present application does not limit this.
[0115] The format of the message may include <destination physical address><source physical address><VLAN label 1><VLAN label 2><VLAN label 3><VLAN label 4><protocol type><data field><frame check sequence>.
[0116] Next, each step of parsing a message with four VLAN labels will be described in detail. Refer to Figure 2 as shown, this step may include:
[0117] S201, perform offset according to multiple first preset offsets to obtain the first field information of the message to be processed.
[0118] The first preset offset may include an offset of 12 bytes for the packet header, an offset of 4 bytes for the VLAN tag field, and an offset of 2 bytes for the protocol type field.
[0119] After obtaining the packet, perform the following operations:
[0120] After offsetting the packet header by 12 bytes, the corresponding first offset position is the end position of the source physical address field. Obtain the field value corresponding to the first two bytes after this end position;
[0121] The field value indicates VLAN tag 1 and does not meet the preset packet type. After offsetting by 4 bytes corresponding to VLAN tag 1, the corresponding second offset position is the end position of the VLAN tag 1 field. Obtain the field value corresponding to the first two bytes after this end position;
[0122] Repeat the previous step. The corresponding third offset position is the end position of the VLAN tag 2 field. The obtained field value indicates VLAN tag 3; Based on the number of times of obtaining the field value corresponding to the first two bytes reaching the set threshold 3, and at this time the field value does not meet the preset packet type, so no further backward offset is continued according to the first preset offset.
[0123] S202, in response to the number of times of obtaining the first field information reaching the set threshold and the obtained first field information not indicating the preset packet type, determine the first packet in the to-be-processed packet according to the position of the last offset;
[0124] Based on the number of times of obtaining the field value corresponding to the first two bytes being equal to the set threshold and the field value obtained for the third time indicating the MPLS label, determine the first packet in the to-be-processed packet according to the position of the third offset above.
[0125] In this embodiment, the field where the field value obtained for the third time is located is the VLAN tag 3 field, and the corresponding byte length is 4 bytes. The determining the first packet in the to-be-processed packet according to the position of the third offset above may include: The position of the third offset is the end position of the VLAN tag 2 field. Determine the position after adding four bytes to this end position as the start position of the first packet. That is, determine the data packet after the end position of the VLAN tag 3 field as the first packet. The first packet may include <VLAN tag 4><protocol type><data field><frame check sequence>.
[0126] S203, determine the first packet type according to the field value corresponding to the first four bytes of the header of the first packet;
[0127] In response to the field value including 8100, determine that the message type of the first message is a message with a VLAN tag; in response to the field value including 0800, determine that the message type of the first message is an IP message; in response to the field value including 8847, determine that the message type of the first message is a message with an MPLS tag.
[0128] In this embodiment, if the field value corresponding to the first two bytes of the header of the first message is 8100, then determine that the message type of the first message is a message with a VLAN tag.
[0129] S204, determine the IP header position of the message to be processed according to the message type of the first message;
[0130] In response to the message type of the first message being a message with a VLAN tag, sequentially obtain the field information of the first message according to multiple preset offsets, and determine whether the field information indicates an IP message or an MPLS tag; in the case where the field information indicates an IP message or an MPLS tag, determine the second message in the first message according to the position of the last offset; in response to the message type of the second message, determine the IP header position of the message to be processed.
[0131] In this embodiment, the preset offset may include a 4-byte offset for the VLAN tag field. After offsetting 4 bytes from the first message header, the position of the first offset is the end position of VLAN tag 4. Obtain the field value corresponding to the two bytes after this end position, and the field value indicates the message type. Assume that the field value corresponding to the protocol type is 0800, then the field value indicates an IP message, and it can be determined that the data message after the end position of VLAN tag 4 is the second message, that is, the second message may include <protocol type><data field><frame check sequence>, and the message type of the second message is an IP message.
[0132] In response to the message type of the second message, determine the IP header position of the message to be processed.
[0133] When the message type of the second message is an IP message, determine that the end position of the field indicating the message type of the target message is the IP header position;
[0134] When the message type of the second message is a message with an MPLS tag, sequentially obtain the field value corresponding to the bottom-of-stack identifier in the MPLS tag of the second message according to multiple preset offsets. The preset offset may include an 18-bit offset from the message header and a 4-byte offset for the MPLS tag field; in the case where the field value indicating the bottom of the MPLS tag stack satisfies the field value of 1, determine that the end position of the MPLS tag field where the last obtained field information is located is the IP header position.
[0135] In this embodiment, the packet type of the second packet is an IP packet. The second packet includes <protocol type><data field><frame check sequence>. Therefore, it is determined that the end position of the protocol type field is the IP header position.
[0136] S205. Based on the IP header position, determine the five-tuple information of the packet to be processed.
[0137] After determining the IP header position, the five-tuple information can be obtained through the following offset methods: After the IP header position is offset backward by 9 bytes, the value of the next byte field corresponds to the transport protocol; after the IP header position is offset backward by 12 bytes, the values of the next 4 byte fields correspond to the source IP address; after the IP header position is offset backward by 16 bytes, the values of the next 4 byte fields correspond to the destination IP address; after the IP header position is offset backward by 20 bytes, the values of the next 2 byte fields correspond to the source port; after the IP header position is offset backward by 22 bytes, the values of the next 2 byte fields correspond to the destination port.
[0138] The embodiment of the present application elaborates a method for parsing packets with multiple-layer VLAN tags. Through the technical solution provided by the present application, the function that the switch can accurately extract the five-tuple information of complex packets with multiple-layer tags is realized, so that the switch can realize the function of a shunt device, thereby reducing the cost of using a shunt device for data shunting.
[0139] The embodiment of the present application provides a packet parsing method, as Figure 3 shown, to make an exemplary elaboration on the solution of the present application. After receiving the packet to be processed, the type of the packet to be processed can be determined by obtaining the field information corresponding to the set bytes of the packet header of the packet to be processed. The set bytes include the first to fourth bytes and the thirteenth to sixteenth bytes. In response to the field value corresponding to the first to fourth bytes indicating the MPLS label field, it is determined that the packet to be processed is a packet with an MPLS label; in response to the field value corresponding to the thirteenth to sixteenth bytes indicating the VLAN label field or the protocol type, it is determined that the packet to be processed is a packet with a VLAN label.
[0140] As Figure 3 shown, the packet to be processed is a packet with a VLAN label. The corresponding multiple first preset offsets include an offset of 12 bytes from the packet header, an offset of 4 bytes from the VLAN label field, and an offset of 2 bytes from the protocol type field. The preset packet types include packets with MPLS labels and IP packets. The set threshold corresponding to the number of times of obtaining the first field information is 3. Then, the parsing process of the packet to be processed is as follows:
[0141] After offsetting 12 bytes from the packet header, obtain the information of the first field corresponding to the last 4 bytes at the offset position, and execute M = M + 1, where M represents the number of times of obtaining the first field information. At this time, the offset position is the end position of the field corresponding to the 12th byte of the packet header;
[0142] Further, determine whether the first field information indicates a protocol type field. If it indicates a protocol type field, enter the processing flow for packets with MPLS labels or IP packets; if it indicates a VLAN tag field, determine whether the number of times M of obtaining the first field information is greater than a set threshold, and perform the following operations according to the result:
[0143] If not, offset 4 bytes backward from the current offset position according to the offset corresponding to the VLAN tag field in the first preset offset, and obtain the information of the first field corresponding to the set number of bytes. At this time, the offset position is the end position of the field corresponding to the Nth byte of the packet header, where N = 12 + 4 * (M - 1), and M;
[0144] If so, determine the first packet in the to-be-processed packet according to the last offset position and the byte length corresponding to the first field information obtained last time;
[0145] Further, obtain the field value corresponding to the first 4 bytes of the first packet header. Further, according to the field value, judge the first packet type and perform the following operations respectively:
[0146] The field value includes 8100, determine that the packet type of the first packet is a packet with a VLAN tag; according to multiple preset offsets corresponding to the packet with a VLAN tag, offset backward from the current offset position of the first packet in turn and obtain the field information of the first packet, and judge whether the field information indicates an IP packet or an MPLS label;
[0147] When the field information indicates an IP packet or an MPLS label field, enter the processing flow for packets with MPLS labels or IP packets;
[0148] Further, when the field information indicates an IP packet, determine that the end position of the field information indicating the IP packet is the IP header position;
[0149] Further, when the field information indicates an MPLS label, determine that the end position of the field information indicating the IP packet is the start position of the packet header of the second packet;
[0150] Obtain the field value corresponding to the bottom-of-stack identifier in the MPLS label of the second packet in sequence according to multiple preset offsets corresponding to the packet with the MPLS label. The preset offsets may include an offset of 18 bits from the packet header and an offset of 4 bytes from the MPLS label field. Further, determine whether the field value corresponding to the bottom-of-stack identifier is 1. If so, determine that the end position of the MPLS label field where the last obtained field information is located is the IP header position.
[0151] Further, the five-tuple information can be determined according to the IP header position.
[0152] Corresponding to the embodiment of the foregoing packet parsing method, see Figure 4 As shown, the present application also provides an embodiment of a packet parsing device, and the device may include:
[0153] A field information acquisition module 401, configured to perform offsets in sequence according to multiple first preset offsets, and acquire first field information of a packet to be processed;
[0154] A packet acquisition module 402, in response to the number of times of acquiring the first field information reaching a set threshold and the obtained first field information not indicating a preset packet type, determine a first packet in the packet to be processed according to the position of the last offset;
[0155] A tuple information acquisition module 403, configured to acquire five-tuple information of the packet to be processed from the first packet.
[0156] In some embodiments, the packet acquisition module is specifically configured to:
[0157] Acquire the byte length corresponding to the field where the first field information obtained by the last offset is located;
[0158] Acquire the first packet according to the position of the last offset and the byte length.
[0159] In some embodiments, the tuple information acquisition module includes:
[0160] A first type determination module, configured to determine the packet type of the first packet according to the field value of the set byte of the first packet, and the set byte corresponds to the packet type indicated by the first field information obtained by the last offset;
[0161] A first position determination module, configured to determine the Internet Protocol (IP) header position of the packet to be processed according to the packet type of the first packet;
[0162] An information acquisition module, configured to acquire five-tuple information of the packet to be processed based on the IP header position.
[0163] In some embodiments, in response to the first field information obtained from the last offset indicating an MPLS label, the first type determination module is specifically configured to:
[0164] Obtain the field value corresponding to the byte where the bottom-of-stack identifier in the first packet is located;
[0165] Determine the type of the first packet according to the field value.
[0166] In some embodiments, in response to the first field information obtained from the last offset indicating a VLAN label, the first type determination module is specifically configured to:
[0167] Obtain the field value corresponding to the first two bytes before the packet header of the first packet;
[0168] Determine the type of the first packet according to the field value.
[0169] In some embodiments, in response to the packet type including a packet with a VLAN label, the first position determination module is specifically configured to:
[0170] A second field information acquisition module, configured to sequentially acquire the second field information of the first packet according to a plurality of second preset offsets;
[0171] A second type determination module, configured to determine the second packet in the first packet according to the position of the last offset when the second field information indicates an IP packet or an MPLS label;
[0172] A second position determination module, configured to determine the IP header position of the packet to be processed according to the type of the second packet.
[0173] In some embodiments, the first position determination module or the second position determination module is specifically configured to:
[0174] In response to the packet type including an IP packet, determine that the end position of the field indicating the packet type of the target packet is the IP header position;
[0175] In response to the packet type including a packet with an MPLS label, sequentially acquire the third field information of the target packet according to a plurality of third preset offsets; when the third field information meets the set conditions, determine that the end position of the field where the third field information is located is the IP header position.
[0176] The implementation processes of the functions and roles of each unit in the above device are specifically described in detail in the implementation processes of the corresponding steps in the above method, and will not be elaborated here.
[0177] For the apparatus embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the descriptions of the method embodiments. The apparatus embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this application. A person of ordinary skill in the art can understand and implement it without creative work.
[0178] The embodiments of the present application also provide a switch, which can implement the steps of any packet parsing method provided in any one embodiment or any optional implementation manner of the present application.
[0179] Through the technical solution provided by the present application, the function that the switch can accurately extract the five-tuple information of complex packets with multiple-layer tags is realized, so that the switch can implement the function of a shunt device, thereby reducing the cost of using a shunt device for data shunting.
[0180] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the scope of protection of the present application.
Claims
1. A message parsing method, characterized in that, The method includes: Offsetting the message to be processed in sequence according to a plurality of first preset offsets, and obtaining first field information of the message to be processed after each offset; In response to the number of times of obtaining the first field information reaching a set threshold and the obtained first field information not indicating a preset message type, determining a first message in the message to be processed according to the position of the last offset, including: Obtaining the byte length corresponding to the field where the first field information obtained by the last offset is located; obtaining the first message according to the position of the last offset and the byte length; Obtaining five-tuple information of the message to be processed from the first message, including: Determining the message type of the first message according to the field value corresponding to the set byte of the first message, where the set byte corresponds to the message type indicated by the first field information obtained by the last offset; Determining the Internet Protocol (IP) header position of the message to be processed according to the message type of the first message; Obtaining the five-tuple information of the message to be processed based on the IP header position.
2. The method according to claim 1, wherein In response to the first field information obtained by the last offset indicating a Multi-Protocol Label Switching (MPLS) label, the determining the message type of the first message according to the field value corresponding to the set byte of the first message includes: Obtaining the field value corresponding to the byte where the bottom-of-stack identifier in the first message is located; Determining the message type of the first message according to the field value.
3. The method according to claim 1, wherein In response to the first field information obtained by the last offset indicating a Virtual Local Area Network (VLAN) label, the determining the message type of the first message according to the field value corresponding to the set byte of the first message includes: Obtaining the field value corresponding to the first two bytes before the message header of the first message; Determining the message type of the first message according to the field value.
4. The method according to claim 1, characterized in that, In response to the message type including a message with a VLAN label, the determining the IP header position of the message to be processed according to the message type of the first message includes: Obtaining second field information of the first message in sequence according to a plurality of second preset offsets; In the case where the second field information indicates an IP message or an MPLS label, determining a second message in the first message according to the position of the last offset; Determining the IP header position of the message to be processed according to the message type of the second message.
5. The method according to claim 1 or 4, characterized in that, Determining the IP header position of the message to be processed according to the message type of the target message, where the target message includes the first message and the second message, including: In response to the message type including an IP message, determining the end position of the field indicating the message type of the target message as the IP header position; In response to the message type including a message with an MPLS label, obtaining third field information of the target message in sequence according to a plurality of third preset offsets; in the case where the third field information meets a set condition, determining the end position of the field where the third field information is located as the IP header position.
6. A message parsing device, characterized in that, The apparatus includes: A field information acquisition module, configured to offset the message to be processed in sequence according to a plurality of first preset offsets, and obtain first field information of the message to be processed after each offset; A response module, in response to the number of times of obtaining the first field information reaching a set threshold and the obtained first field information not indicating a preset message type, determines a first message in the to-be-processed message according to the position of the last offset, including: Obtaining the byte length corresponding to the field where the first field information obtained by the last offset is located; obtaining the first message according to the position of the last offset and the byte length; A tuple information obtaining module, obtaining five-tuple information of the to-be-processed message from the first message; Wherein, the tuple information obtaining module includes: A first type determining module, configured to determine the message type of the first message according to the field value of the set byte of the first message, and the set byte corresponds to the message type indicated by the first field information obtained by the last offset; A first position determining module, configured to determine the Internet Protocol (IP) header position of the to-be-processed message according to the message type of the first message; An information obtaining module, configured to obtain five-tuple information of the to-be-processed message based on the IP header position.
7. The device according to claim 6, characterized in that, In response to the first field information obtained by the last offset indicating a Multi-Protocol Label Switching (MPLS) label, the first type determining module is specifically configured to: Obtain the field value corresponding to the byte where the bottom-of-stack identifier in the first message is located; Determine the message type of the first message according to the field value.
8. The device according to claim 6, characterized in that, In response to the first field information obtained by the last offset indicating a Virtual Local Area Network (VLAN) label, the first type determining module is specifically configured to: Obtain the field values corresponding to the first two bytes before the message header of the first message; Determine the message type of the first message according to the field values.
9. The device according to claim 6, characterized in that, In response to the message type including a message with a VLAN label, the first position determining module includes: A second field information obtaining module, configured to sequentially obtain second field information of the first message according to a plurality of second preset offsets; A second type determining module, configured to determine a second message in the first message according to the position of the last offset when the second field information indicates an IP message or an MPLS label; A second position determining module, configured to determine the IP header position of the to-be-processed message according to the message type of the second message.
10. The device according to claim 6 or 9, characterized in that, The first position determining module or the second position determining module is specifically configured to: In response to the message type including an IP message, determine that the end position of the field indicating the message type of the target message is the IP header position, where the target message includes the first message and the second message; In response to the message type including a message with an MPLS label, sequentially obtain third field information of the target message according to a plurality of third preset offsets; when the third field information meets a set condition, determine that the end position of the field where the third field information is located is the IP header position.
Citation Information
Patent Citations
Message filtering method and message filtering chip based on IP message length
CN106549941A
Message processing method and device
CN113489659A