Detection method, device, terminal device and computer readable storage medium

By employing a dual-layer storm identification strategy combining FPGA and driver layer, the problem of low network storm detection accuracy is solved, enabling accurate detection and effective suppression of network storms and improving the safe and stable operation of smart substations.

CN116418712BActive Publication Date: 2026-07-24CYG SUNRI CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CYG SUNRI CO LTD
Filing Date
2022-12-26
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

Existing methods for detecting network storms suffer from inaccurate packet statistics due to untimely reception of storm packets or overly cumbersome processing procedures, which affects the accuracy of network storm detection and consequently impacts the safe operation of smart substations.

Method used

A two-layer storm identification strategy combining field-programmable gate array (FPGA) circuits and driver layer is adopted. The network packet statistics are obtained through FPGA and combined with the packet statistics of driver layer for two-layer detection, which improves detection accuracy and avoids missed statistics and missed reports.

Benefits of technology

It enables accurate detection of network storms, reduces the impact of system lag and normal business functions, and improves the operational reliability and storm resistance of network equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116418712B_ABST
    Figure CN116418712B_ABST
Patent Text Reader

Abstract

The application is suitable for the field of data detection, and provides a detection method, device, terminal equipment and computer readable storage medium method, which comprises the following steps: obtaining first data, wherein the first data represents the packet statistical number of a target network in a statistical period obtained through a first circuit, the first circuit is a field programmable logic gate array circuit; obtaining second data, wherein the second data represents the packet statistical number of the target network in the statistical period obtained through a drive layer of the target network; detecting network storm of the target network according to the first data and the second data, and obtaining a detection result. Through the above method, the ability of each group of network equipment to resist network storm can be improved, the network equipment can be ensured to suppress the storm, and the equipment can be ensured to operate normally.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of data detection, and in particular relates to a detection method, apparatus, terminal equipment and computer-readable storage medium. Background Technology

[0002] With the rapid development of network technology, all industries are gradually entering the era of networking and intelligence. The network has provided great convenience to our lives and work, but it has also brought certain impacts. For example, network storms in smart substations can cause network congestion, large-scale system outages, and other serious problems that affect the safe operation of smart substations.

[0003] Current methods for suppressing network storms suffer from inaccurate packet counts due to untimely reception of storm packets or overly cumbersome processing procedures, thus affecting the accuracy of network storm detection. Summary of the Invention

[0004] This application provides a detection method, apparatus, terminal device, and computer-readable storage medium, which can improve the detection accuracy of network storms, thereby ensuring that network devices can operate normally.

[0005] In a first aspect, embodiments of this application provide a detection method, including:

[0006] First data is obtained, which represents the number of messages in the target network within a statistical period obtained by the first circuit, and the first circuit is a field-programmable gate array circuit.

[0007] Obtain second data, which represents the number of packets counted by the target network within the statistical period obtained through the driver layer of the target network;

[0008] Based on the first data and the second data, network storms in the target network are detected, and detection results are obtained.

[0009] In this embodiment, by utilizing the packet statistics of the target network within a statistical period obtained through a programmable gate array circuit and the packet statistics of the target network within a statistical period obtained through the driver layer, it is equivalent to comprehensively considering the packet statistics actually processed by the driver and the packet statistics obtained by the programmable circuit to detect network storms. Through the above method, this invention combines hardware and software, enabling accurate packet statistics, avoiding missed statistics during storms, and significantly reducing the probability of missed reports during storms.

[0010] In one possible implementation of the first aspect, detecting network storms in the target network based on the first data and the second data, and obtaining detection results, includes:

[0011] A first detection is performed based on the first data to obtain a first result;

[0012] If the first result indicates that no network storm was detected and the first data is greater than the first preset value, then a second detection is performed based on the first data and the second data to obtain a second result. The first preset value represents the minimum number of received packets for the target network to enable storm suppression within the statistical period.

[0013] In one possible implementation of the first aspect, the step of performing the first detection based on the first data to obtain the first result includes:

[0014] If the first data is greater than the second preset value, then the first result indicates that a network storm has been detected;

[0015] If the first data is less than or equal to the second preset value, the first result indicates that no network storm was detected, and the second preset value indicates the maximum number of packets that the target network can transmit within the statistical period.

[0016] In one possible implementation of the first aspect, the step of performing a second detection based on the first data and the second data to obtain a second result includes:

[0017] If the difference between the first data and the second data is greater than a third preset value, then the second result indicates that a network storm has been detected.

[0018] If the difference between the first data and the second data is less than or equal to a third preset value, the detection result indicates that no network storm was detected.

[0019] In one possible implementation of the first aspect, the method further includes:

[0020] When a network storm is detected, the first circuit is controlled to perform storm suppression.

[0021] In one possible implementation of the first aspect, controlling the first circuit to perform storm suppression includes:

[0022] Update the fourth preset value, which is the maximum number of packets that the target network can receive when the storm suppression is lifted during the storm suppression process. The updated fourth preset value is compared with the previous fourth preset value.

[0023] The first circuit is controlled to perform storm suppression according to the updated fourth preset value.

[0024] In one possible implementation of the first aspect, the method further includes:

[0025] When the target network is in a storm suppression state, third data is obtained, which represents the number of packets of the target network within the statistical period obtained by the first circuit;

[0026] If the third data is less than the fourth preset value, then the first circuit is controlled to release storm suppression.

[0027] Secondly, embodiments of this application provide a detection device, including:

[0028] The acquisition unit is used to acquire first data, which represents the number of messages of the target network within a period obtained by the first circuit. The first circuit is a field-programmable gate array circuit.

[0029] A generation unit is used to acquire second data, which represents the number of packets counted by the target network within the statistical period obtained through the driver layer of the target network.

[0030] The detection unit is used to detect network storms in the target network based on the first data and the second data, and obtain detection results.

[0031] Thirdly, embodiments of this application provide a terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the detection method as described in any one of the first aspects above.

[0032] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the detection method as described in any one of the first aspects above.

[0033] Fifthly, embodiments of this application provide a computer program product that, when run on a terminal device, causes the terminal device to execute the detection method described in any one of the first aspects.

[0034] It is understood that the beneficial effects of the second to fifth aspects mentioned above can be found in the relevant descriptions in the first aspect mentioned above, and will not be repeated here. Attached Figure Description

[0035] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0036] Figure 1 This is a schematic flowchart of a detection system provided in an embodiment of this application;

[0037] Figure 2 This is a schematic diagram of the process for two-layer storm identification provided in an embodiment of this application;

[0038] Figure 3 This is a schematic diagram of the detection result determination process provided in one embodiment of this application;

[0039] Figure 4 This is a normal interactive message feature map provided in an embodiment of this application;

[0040] Figure 5 This is a storm message feature map provided in an embodiment of this application;

[0041] Figure 6 This is a structural diagram of a detection device provided in an embodiment of this application;

[0042] Figure 7 This is a schematic diagram of the structure of the terminal device provided in the embodiments of this application. Detailed Implementation

[0043] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0044] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0045] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0046] As used in this application specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determined" or "if detected [the described condition or event]" may be interpreted, depending on the context, as meaning "once determined," "in response to determination," "once detected [the described condition or event]," or "in response to detection [the described condition or event]."

[0047] Furthermore, in the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0048] References to "one embodiment" or "some embodiments" in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized.

[0049] With the rapid development of network intelligence, networks have had a significant impact on the development of smart substations. While networks bring conveniences such as data sharing, they also pose certain challenges to the safe and reliable operation of smart substations. Among these challenges, network storms pose a particularly serious threat. On one hand, network storms can cause network congestion and large-scale system outages. On the other hand, network storms can also impact all network devices in the process and bay layers, causing their network card receive buffers to overflow, consuming excessive CPU resources, and leading to software crashes or restarts in various network devices. This severely affects the safe and stable operation of the smart substation.

[0050] To address the challenges brought about by networking, key measures include improving the quality of networking equipment such as switches, or reducing the probability of network storms caused by equipment failures. Taking effective measures can enhance the ability of each networking device to withstand network storms, ensuring that the devices can suppress storms, operate normally, and retain core functions.

[0051] Currently, the main method for suppressing network storms is to use driver-level packet statistics. The driver layer needs to determine whether a packet is a storm packet before processing it, which is usually not timely and can cause device lag. As the CPU usage increases, the operation of the system and even normal business functions will be affected.

[0052] Currently, there are many types of storm messages, such as commonly used messages like TCP, ICMP, GOOSE, and ARP. However, the process of using the driver layer to count network messages requires separate processing for different messages, making the process increasingly cumbersome.

[0053] To address the shortcomings of the existing technology, this application proposes a detection method. In this embodiment, by combining hardware and software and introducing a two-layer storm identification strategy, storms can be suppressed after detection, and the operational reliability of network devices can be improved.

[0054] First, the detection system involved in the embodiments of this application is introduced, see [link to relevant documentation]. Figure 1 This is a schematic flowchart of the detection system provided in an embodiment of this application. As an example and not a limitation, the method includes the following steps:

[0055] Step S101: Obtain first data, which represents the number of messages in the target network within a statistical period obtained by the first circuit, where the first circuit is a field-programmable gate array circuit.

[0056] In this embodiment, the Field Programmable Gate Array (FPGA) is a further development based on programmable devices. As a semi-custom circuit in the field of application-specific integrated circuits (ASICs), it has a high degree of integration and can perform extremely complex sequential and combinational logic circuits. An FPGA can be simply understood as a hardware circuit. Because FPGAs, as hardware circuits, support dynamic configuration, this application uses FPGAs to acquire data from the network. Furthermore, using hardware to acquire data reduces the impact on the system and normal business functions.

[0057] The FPGA is used to acquire data (i.e., the first data) from the target network, which mainly consists of network packets within a statistical period. A network packet refers to a data unit exchanged and transmitted in the network, that is, a data block that a station sends at one time. A packet contains complete data information to be sent, and its length varies, is unlimited, and is variable.

[0058] The hardware FPGA is used to obtain the packet count of the target network within a statistical period. The FPGA can enable functions such as packet deduplication, MAC flow control, and IP filtering according to actual needs. The hardware FPGA first identifies and filters duplicate packets through packet deduplication processing logic; secondly, it performs MAC flow control based on configured flow control enablement, network interface total traffic limit, and MAC whitelist; finally, it performs IP filtering using the configured IP whitelist, processing only packets sent by IPs in the whitelist. After executing the configurable functions, the FPGA initializes the FPGA packet count and reads the current FPGA packet count after the sampling time arrives, thus obtaining the packet count within the statistical period, which can be set to Cf.

[0059] Step S102: Obtain second data, which represents the number of packets counted by the target network within the statistical period obtained through the driver layer of the target network.

[0060] In this embodiment, the driver layer consists of a hardware abstraction layer, a board support package, and a driver program. It is an indispensable and important part of the embedded system. Its function is to provide the upper-layer program with an operation interface for external devices and to implement the device driver program. The upper-layer program can call the driver's interface to implement the driver.

[0061] The driver layer contains the drivers generated during the operation of network devices. By reading the programs in the driver layer, the number of packets within the target network statistical period can be obtained, i.e., the second data, which can be denoted as Cd. The aforementioned statistical period represents the data collection period set for counting network packets. Because packet data is updated in real time, it is necessary to set a collection period to collect and analyze the data. The statistical data collection period can be set based on experience.

[0062] Step S103: Detect network storms in the target network based on the first data and the second data, and obtain detection results.

[0063] In this embodiment, the software algorithm employs a two-layer network storm detection strategy. Therefore, under both normal packet exchange and storm conditions, network storm detection results are obtained by comparing the number of packets obtained from the FPGA and the number obtained from the driver layer. The detection results show two outcomes: network storm detected and no network storm detected. Further analysis is performed on the detected results, and corresponding measures are implemented. This method enables more accurate counting of packets within a given period, avoiding omissions in storm conditions.

[0064] In one embodiment, see Figure 2 This is a schematic diagram of a two-layer network storm detection process provided in an embodiment of this application, as shown below. Figure 2As shown, one implementation of step S103 includes:

[0065] Step S201: Perform a first detection based on the first data to obtain a first result.

[0066] Step S202: If the first result indicates that no network storm was detected and the first data is greater than the first preset value, then a second detection is performed based on the first data and the second data to obtain a second result. The first preset value represents the minimum number of received packets for the target network to enable storm suppression within the statistical period.

[0067] In this embodiment of the application, after the software algorithm obtains the packet statistics data in the hardware FPGA, it will perform the first storm detection. During this process, a first preset value is set. The first preset value represents the minimum number of packets Cmin in the target network within the statistical period. Its value is obtained through experimental testing and empirical analysis.

[0068] If the first network storm detection shows that no network storm was detected, and the number of packets within the period obtained through the hardware FPGA is greater than Cmin obtained through experimental testing or empirical analysis, then a second network storm detection will be performed, and the results of the second detection will be analyzed.

[0069] The above method, employing a two-layer network storm detection approach, can accurately extract the characteristics of network storms, identify storms, and provide accurate data for network storm suppression, thereby improving the reliability of network equipment operation.

[0070] In one embodiment, one implementation of step S201 includes:

[0071] If the first data is greater than the second preset value, then the first result indicates that a network storm has been detected;

[0072] If the first data is less than or equal to the second preset value, the first result indicates that no network storm was detected, and the second preset value indicates the maximum number of packets that the target network can transmit within the statistical period.

[0073] In this embodiment, after performing a first detection on the number of packets counted within a period obtained through the FPGA, the obtained detection results are analyzed. During this process, a second preset value is set. The second preset value represents the maximum number of packets Cmax that the target network can transmit within the statistical period. This value is also obtained through experimental testing or empirical analysis. In the first detection result, if the periodic packet count Cf, i.e., the first data, is greater than the maximum number of packets Cmax, then the detection result is determined to be a network storm, and the network storm needs to be suppressed. Similarly, if the first data is less than or equal to the maximum number of packets, it means that no network storm has been detected, and the above-mentioned step S202 needs to be implemented.

[0074] The above method can accurately represent the detection results during the first-layer network storm detection process and accurately determine whether a second detection is needed.

[0075] In one embodiment, see Figure 3 This is a flowchart illustrating the process of determining the detection result according to an embodiment of this application, as shown below. Figure 3 As shown, one implementation of step S203 further includes:

[0076] Step S301: If the difference between the first data and the second data is greater than a third preset value, then the second result indicates that a network storm has been detected.

[0077] Step S302: If the difference between the first data and the second data is less than or equal to a third preset value, then the second result indicates that no network storm was detected.

[0078] In this embodiment, if the first layer does not detect a network storm, and the number of packets Cf (the first data) within the statistical period is greater than Cmin, a second network storm detection is performed. At this time, the number of packets Cd (the second data) from the driver is read. If the difference between Cf and Cd is greater than a set value Δd, it is considered a storm packet. During this process, a third preset value Δd needs to be set, which can be based on the difference between the first and second data.

[0079] Layer 2 network storm detection does not require processing a specific type of packet; see [link / reference] Figure 4 This is a message feature map of normal message interaction provided in an embodiment of this application, such as... Figure 4 As shown. Normal interactive messages are discussed in the following three cases:

[0080] (1) Due to the existence of a sliding window, the TCP message cannot be sent indefinitely. Therefore, the FPGA message statistics and the message statistics processed in the driver are basically consistent.

[0081] (2) UDP messages are mainly used in daily business communication. Their mechanism is a question and answer, so the FPGA message statistics and the message statistics processed in the driver are basically consistent.

[0082] (3) The ICMP message mechanism is also a question-and-answer process. The next frame can only continue after the answer or timeout. The timeout time is generally in the second range and is not considered. Only the question-and-answer case is considered. Therefore, the FPGA message statistics and the message statistics processed in the driver are basically consistent.

[0083] From the above scenarios and Figure 4 As shown, under the three normal interaction message scenarios, the statistics of FPGA messages and the statistics of messages already processed in the driver are basically consistent, thus determining the characteristics of normal interaction messages. Furthermore, it eliminates the need to distinguish specific messages and process certain messages separately, significantly simplifying the processing code. In storm scenarios, network storm messages are generally sent to the device periodically at certain intervals. The characteristic of these messages is that they are continuously sent regardless of the device's response.

[0084] In one embodiment, see Figure 5 This is a feature map of a storm message provided in an embodiment of this application, such as... Figure 5 As shown. In storm conditions, there is a significant difference between the packet statistics count of the FPGA and the packet statistics processed in the driver. Therefore, the difference between normal interactive packets and storm packets lies in the difference between the packet statistics count of the FPGA and the packet statistics processed in the driver. If the difference is too large, it is identified as a network storm.

[0085] By using the above method and leveraging hardware FPGA to implement a second storm identification, the possibility of storms being missed can be effectively avoided.

[0086] In one embodiment, a detection method further includes:

[0087] When a network storm is detected, the first circuit is controlled to perform storm suppression.

[0088] Update the fourth preset value, which is the maximum number of packets that the target network can receive when the storm suppression is lifted during the storm suppression process. The updated fourth preset value is compared with the previous fourth preset value.

[0089] The first circuit is controlled to perform storm suppression according to the updated fourth preset value.

[0090] In this embodiment of the application, when the result of the first or second storm detection indicates a network storm, it is necessary to control the first circuit, i.e., the FPGA, to suppress the storm. Before suppressing the storm, it is necessary to set a fourth preset value, which represents the maximum number of packets Cs allowed to be transmitted by the target network within the statistical period.

[0091] Optionally, during storm suppression, the fourth preset value can be set to half of its original value; that is, the updated fourth preset value is half of the original fourth preset value. This extends the time it takes for the FPGA to release storm suppression, preventing premature release and subsequent receipt of storm messages. Finally, the relevant counters are cleared, and the statistical cycle restarts.

[0092] Understandably, the ratio between the updated fourth preset value and the original fourth preset value can be set according to actual needs, and no specific limitation is made here. The smaller the updated fourth preset value, the longer the storm suppression time; the larger the updated fourth preset value, the shorter the storm suppression time.

[0093] Using the above method, the suppression status of the network storm can be observed in real time during the process of suppressing the network storm, and the suppression status can be lifted when the storm suppression ends.

[0094] In one embodiment, a detection method further includes:

[0095] When the target network is in a storm suppression state, third data is obtained, which represents the number of packets of the target network within the statistical period obtained by the first circuit;

[0096] If the third data is less than the fourth preset value, then the first circuit is controlled to release storm suppression.

[0097] In this embodiment of the application, after the FPGA suppresses a network storm, it needs to release the suppression state to ensure the normal operation of the communication function. First, it will determine whether the network port is in a suppressed state. If so, the number of packets of the target network within the statistical period is the third data. If the third data is less than the above-mentioned fourth preset value, it indicates that the storm has ended, and the FPGA can release the storm suppression.

[0098] This application provides a network storm suppression method based on a combination of hardware and software. It consists of two parts: a hardware FPGA and a software algorithm. By detecting the number of packets within a statistical period obtained using the hardware FPGA and the number of packets obtained through the driver layer, if the first detection result indicates a network storm, the FPGA is used to suppress the storm. If no network storm is detected, the data obtained from the storm characteristics is used to perform a second network storm detection and further processing.

[0099] In the above method, this application no longer relies solely on the number of driver-generated statistical packets. Instead, it employs a packet counter on a hardware FPGA for packet counting. This not only alleviates device lag caused by driver-layer packet counting but also reduces the impact on system and normal business operations, providing data for software algorithms to identify and suppress storms. This method also effectively reduces the occurrence of missed packet counts and missed storm reports, improving the equipment's storm resilience and significantly enhancing the reliability of network equipment.

[0100] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0101] Corresponding to the detection method described in the above embodiments, Figure 5 This is a structural block diagram of the detection device provided in the embodiments of this application. For ease of explanation, only the parts related to the embodiments of this application are shown.

[0102] Reference Figure 6 The device includes:

[0103] Acquisition unit 61 is used to acquire first data, which represents the number of messages of the target network within a period obtained by the first circuit. The first circuit is a field-programmable gate array circuit.

[0104] The generation unit 62 is used to obtain second data, which represents the number of packets of the target network within the statistical period obtained by the driver layer of the target network.

[0105] The detection unit 63 is used to detect network storms in the target network based on the first data and the second data, and obtain detection results.

[0106] Optionally, the detection unit 63 is also used for:

[0107] A first detection is performed based on the first data to obtain a first result;

[0108] If the first result indicates that no network storm was detected and the first data is greater than the first preset value, then a second detection is performed based on the first data and the second data to obtain a second result. The first preset value represents the minimum number of received packets for the target network to enable storm suppression within the statistical period.

[0109] Optionally, the detection unit 63 is also used for:

[0110] If the first data is greater than the second preset value, then the first result indicates that a network storm has been detected;

[0111] A network storm is detected. The second preset value represents the maximum number of packets that the target network can transmit within the statistical period.

[0112] Optionally, the detection unit 63 is also used for:

[0113] If the difference between the first data and the second data is greater than a third preset value, then the second result indicates that a network storm has been detected.

[0114] If the difference between the first data and the second data is less than or equal to a third preset value, then the second result indicates that no network storm was detected.

[0115] Optionally, the detection unit 63 is also used for:

[0116] When a network storm is detected, the first circuit is controlled to perform storm suppression.

[0117] Optionally, the detection unit 63 is also used for:

[0118] Update the fourth preset value, which is the maximum number of packets that the target network can receive when the storm suppression is lifted during the storm suppression process. The updated fourth preset value is compared with the previous fourth preset value.

[0119] The first circuit is controlled to perform storm suppression according to the updated fourth preset value.

[0120] Optionally, the detection unit 63 is also used for:

[0121] When the target network is in a storm suppression state, third data is obtained, which represents the number of packets of the target network within the statistical period obtained by the first circuit;

[0122] If the third data is less than the fourth preset value, then the first circuit is controlled to release storm suppression.

[0123] It should be noted that the information interaction and execution process between the above-mentioned devices / units are based on the same concept as the method embodiments of this application. For details on their specific functions and technical effects, please refer to the method embodiments section, and they will not be repeated here.

[0124] in addition, Figure 6 The detection device shown can be a software unit, hardware unit, or a combination of software and hardware built into an existing terminal device, or it can be integrated into the terminal device as an independent component, or it can exist as an independent terminal device.

[0125] Figure 7 This is a schematic diagram of the structure of the terminal device provided in the embodiments of this application. For example... Figure 7As shown, the terminal device 7 of this embodiment includes: at least one processor 70 (only one of 70 is shown), a memory 71, and a computer program 72 stored in the memory 71 and executable on the at least one processor 70. When the processor 70 executes the computer program 72, it implements the steps in any of the above control method embodiments.

[0126] The terminal device may be a desktop computer, laptop, handheld computer, or cloud server, etc. This terminal device may include, but is not limited to, a processor and memory. Those skilled in the art will understand that... Figure 7 The example of terminal device 7 is merely an illustration and does not constitute a limitation on terminal device 7. It may include more or fewer components than shown in the figure, or combine certain components, or different components, such as input / output devices, network access devices, etc.

[0127] The processor 70 may be a Central Processing Unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.

[0128] In some embodiments, the memory 51 may be an internal storage unit of the terminal device 7, such as a hard disk or memory of the terminal device 5. In other embodiments, the memory 71 may be an external storage device of the terminal device 5, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the terminal device 7. Furthermore, the memory 51 may include both internal and external storage units of the terminal device 7. The memory 51 is used to store the operating system, applications, boot loader, data, and other programs, such as the program code of the computer program. The memory 71 can also be used to temporarily store data that has been output or will be output.

[0129] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, can implement the steps in the above-described method embodiments.

[0130] This application provides a computer program product that, when run on a terminal device, enables the terminal device to implement the steps described in the various method embodiments.

[0131] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of this application can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include at least: any entity or device capable of carrying computer program code to a device / terminal device, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium. Examples include USB flash drives, portable hard drives, magnetic disks, or optical disks. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electrical carrier signals or telecommunication signals.

[0132] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0133] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0134] In the embodiments provided in this application, it should be understood that the disclosed devices / terminal equipment and methods can be implemented in other ways. For example, the device / terminal equipment embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling or direct coupling or communication connection may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0135] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0136] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A detection method, characterized in that, include: First data is obtained, which represents the number of messages in the target network within a statistical period obtained by the first circuit, and the first circuit is a field-programmable gate array circuit. Obtain second data, which represents the number of packets counted by the target network within the statistical period obtained through the driver layer of the target network; A first detection is performed based on the first data to obtain a first result; If the first data is greater than the second preset value, then the first result indicates that a network storm has been detected; If the first data is less than or equal to the second preset value, the first result indicates that no network storm was detected, and the second preset value indicates the maximum number of packets that the target network can transmit within the statistical period. If the first result indicates that no network storm was detected and the first data is greater than the first preset value, then a second detection is performed based on the first data and the second data to obtain a second result. The first preset value represents the minimum number of received packets for the target network to enable storm suppression within the statistical period. If the difference between the first data and the second data is greater than a third preset value, then the second result indicates that a network storm has been detected. If the difference between the first data and the second data is less than or equal to a third preset value, then the second result indicates that no network storm was detected. The detection results determine whether a network storm exists in the target network.

2. The detection method as described in claim 1, characterized in that, The method further includes: When a network storm is detected, the first circuit is controlled to perform storm suppression.

3. The detection method as described in claim 2, characterized in that, The control of the first circuit to perform storm suppression includes: Update the fourth preset value, which is the maximum number of packets that the target network can receive when the storm suppression is lifted during the storm suppression process. The updated fourth preset value is compared with the previous fourth preset value. The first circuit is controlled to perform storm suppression according to the updated fourth preset value.

4. The detection method as described in claim 3, characterized in that, The method further includes: When the target network is in a storm suppression state, third data is obtained, which represents the number of packets of the target network within the statistical period obtained by the first circuit; If the third data is less than the fourth preset value, then the first circuit is controlled to release storm suppression.

5. A detection device, characterized in that, include: The acquisition unit is used to acquire first data, which represents the number of messages of the target network within a statistical period obtained by the first circuit. The first circuit is a field-programmable gate array circuit. A generation unit is used to acquire second data, which represents the number of packets counted by the target network within the statistical period obtained through the driver layer of the target network. The detection unit is used to perform a first detection based on the first data to obtain a first result; If the first data is greater than the second preset value, then the first result indicates that a network storm has been detected; The detection unit is also used for: If the first data is less than or equal to the second preset value, the first result indicates that no network storm was detected, and the second preset value indicates the maximum number of packets that the target network can transmit within the statistical period. If the first result indicates that no network storm was detected and the first data is greater than the first preset value, then a second detection is performed based on the first data and the second data to obtain a second result. The first preset value represents the minimum number of received packets for the target network to enable storm suppression within the statistical period. If the difference between the first data and the second data is greater than a third preset value, then the second result indicates that a network storm has been detected. If the difference between the first data and the second data is less than or equal to a third preset value, then the second result indicates that no network storm was detected. The detection results determine whether a network storm exists in the target network.

6. A terminal device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method as described in any one of claims 1 to 4.

7. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1 to 4.