Method and device for obtaining full-path network access relationship
By acquiring and connecting the structured session logs of NAT devices, a view of the full-path network access relationship is generated, which solves the problem that the full-path network access relationship cannot be efficiently obtained in the NAT environment, and accurately obtaining network access relationships.
Patent Information
- Application Number
- CN202310454802.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-24
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2043-04-24
AI Technical Summary
In complex networks with NAT environments, prior art cannot efficiently and accurately obtain full-path network access relationships across security boundaries.
By obtaining the structured session logs of multiple NAT devices, the local network access relationship of network sessions at each NAT device is extracted, and the full path network access relationship is generated, and the access direction is determined using the network boundary topology relationship and log aggregation table to generate a view of the full path network access relationship.
In the case where NAT devices have one-to-many mapping, many-to-one mapping and complex configurations, the full-path network access relationship through NAT devices is accurately and efficiently obtained, solving the problem that cannot be efficiently obtained in the prior art.
Smart Images

Figure CN116455801B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network communication technology, and in particular to a method and device for obtaining a full-path network access relationship. Background Art
[0002] With the development of online business, communication between enterprise intranets and the internet and extranets is becoming increasingly frequent, and the security risks of exposed network security boundaries are also increasing. Rapidly obtaining network access relationships within security boundaries is critical for locating perimeter attacks. Because network access communication sessions pass through security boundaries, information such as the source network address (Internet Protocol, IP), destination IP address, and destination port in the access relationship may undergo one or more translations. Related technologies are unable to efficiently and accurately obtain the full path of network access relationships across the security boundary in environments with complex Network Address Translation (NAT), such as those described above.
[0003] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention
[0004] The embodiments of the present application provide a method and device for obtaining full-path network access relationships, so as to at least solve the technical problem that related technologies cannot efficiently and accurately obtain full-path network access relationships that pass through NAT devices due to the complexity of the NAT environment.
[0005] According to one aspect of an embodiment of the present application, a method for obtaining a full-path network access relationship is provided, including: obtaining a structured session log corresponding to each NAT device among multiple NAT devices; extracting a local network access relationship of a network session at each NAT device based on the structured session log corresponding to each NAT device, wherein the network session is a session between a device within a network boundary to which each NAT device belongs and a device outside the network boundary to which each NAT device belongs; and concatenating the local network access relationship of the network session at each NAT device to obtain a full-path network access relationship of the network boundary to which each NAT device belongs.
[0006] Optionally, based on the structured sessionized log corresponding to each NAT device, the local network access relationship of the network session at each NAT device is extracted, including: obtaining the network boundary topology relationship of the NAT device, and generating an input and output path table of the NAT device based on the network boundary topology relationship, wherein the input and output path table of the NAT device includes: the identification information of the NAT device, the name of the network boundary where the NAT device is located, the cascade level of the NAT device, the access direction of the network session passing through the NAT device, the name of the input interface and the name of the output interface, the input interface is the interface for the network session to enter the NAT device, and the output interface is the interface for the network session to exit the NAT device; a log aggregation table is generated based on the structured session log, and the access direction of the network session passing through the NAT device is determined based on the input and output path table and the log aggregation table of the NAT device; and the local network access relationship of the network session at the NAT device is extracted based on the access direction.
[0007] Optionally, obtaining a structured session log corresponding to each NAT device in a plurality of NAT devices includes: obtaining multiple logs of the plurality of NAT devices, obtaining key element information from the plurality of logs, wherein the key element information includes: timestamp, source network address, destination network address, destination port, source mapping network address, destination mapping network address, destination mapping port, protocol type, source interface, and destination interface; obtaining identification information of each NAT device, wherein the identification information includes at least one of the following: the name of the NAT device and the network address of the NAT device; combining the key element information of each NAT device and the identification information of each NAT device to obtain a structured session log corresponding to each NAT device.
[0008] Optionally, generating a log aggregation table based on the structured session log includes: determining a preset period and collecting multiple structured session logs within the preset period; classifying data in the multiple structured session logs that have completely identical key element information except for timestamps into one group of data to obtain multiple groups of data; generating a log aggregation table based on the multiple groups of data, wherein the log aggregation table includes: identification information of the NAT device, key element information and the number of times each group of data appears.
[0009] Optionally, a log aggregation table is generated based on the structured session log, and the access direction of the network session passing through the NAT device is determined based on the input and output path table of the NAT device and the log aggregation table, including: obtaining the identification information of the NAT device in the log aggregation table, the name of the source interface corresponding to the identification information of the NAT device, and the name of the destination interface corresponding to the identification information of the NAT device; using the identification information of the NAT device, the name of the source interface corresponding to the identification information of the NAT device, and the name of the destination interface corresponding to the identification information of the NAT device to determine the access direction of the network session passing through the NAT device indicated by the identification information of the NAT device through the input and output path table of the NAT device.
[0010] Optionally, extracting the local network access relationship of the network session at the NAT device according to the access direction includes: if the access direction is inbound, determining the source mapping network address corresponding to the identification information of the NAT device as the inner interface source network address, determining the destination network address corresponding to the identification information of the NAT device as the inner interface destination network address, determining the destination port corresponding to the identification information of the NAT device as the inner interface destination port, determining the source network address corresponding to the identification information of the NAT device as the outer interface source network address, determining the destination mapping network address corresponding to the identification information of the NAT device as the outer interface destination network address, and determining the destination mapping port corresponding to the identification information of the NAT device as the outer interface destination port, wherein inbound indicates access from a device outside the network boundary to a device inside the network boundary; determining the network session when the access direction is inbound according to the inner interface source network address, the inner interface destination network address, the inner interface destination port, the outer interface source network address, the outer interface destination network address and the outer interface destination port. Multiple local network access relationships at a NAT device; if the access direction is out-of-bounds, determining the source network address corresponding to the identification information of the NAT device as the inner interface source network address, determining the destination mapping network address corresponding to the identification information of the NAT device as the inner interface destination network address, determining the destination mapping port corresponding to the identification information of the NAT device as the inner interface destination port, determining the source mapping network address corresponding to the identification information of the NAT device as the outer interface source network address, determining the destination network address corresponding to the identification information of the NAT device as the outer interface destination network address, and determining the destination port corresponding to the identification information of the NAT device as the outer interface destination port, wherein out-of-bounds indicates access from a device within the network boundary to a device outside the network boundary; determining multiple local network access relationships of a network session at the NAT device when the access direction is out-of-bounds based on the inner interface source network address, the inner interface destination network address, the inner interface destination port, the outer interface source network address, the outer interface destination network address and the outer interface destination port.
[0011] Optionally, the local network access relationship of each NAT device is concatenated to obtain the full-path network access relationship of the network boundary to which each NAT device belongs, including: determining the number of NAT devices in the network boundary to which the NAT device belongs from the ingress and egress path table of the NAT device; if the number is greater than one, concatenating multiple local network access relationships of multiple NAT devices within the same network boundary according to the concatenation rule to obtain the full-path network access relationship; if the number is equal to one, determining the local network access relationship of the NAT device as the full-path network access relationship.
[0012] Optionally, multiple local network access relationships of multiple NAT devices within the same network boundary are connected in series according to the series connection rules, including: if the internal interface source network address of the first NAT device among the multiple NAT devices is equal to the external interface source network address of the second NAT device among the multiple NAT devices, the internal interface destination network address of the first NAT device is equal to the external interface destination network address of the second NAT device, and the internal interface destination port of the first NAT device is equal to the external interface destination port of the second NAT device, the local network access relationship of the first NAT device and the local network access relationship of the second NAT device are connected in series to form a full path access relationship of the network boundary, wherein the first NAT device and the second NAT device belong to the same network boundary, the first NAT device and the second NAT device are adjacent to each other, and the cascade level of the first NAT device is lower than the cascade level of the second NAT device.
[0013] Optionally, the method for obtaining a full-path network access relationship also includes: determining the node corresponding to the device that initiates the access request in the full-path network access relationship as the starting node, determining the node corresponding to the device that receives the access request in the full-path network access relationship as the ending node, and determining the NAT device in the full-path network access relationship as the intermediate node; determining the line segment connecting the starting node, the intermediate node and the ending node as an edge, wherein the direction of the edge is determined according to the access direction of the network session across the network boundary, and the direction of the edge is indicated by an arrow; generating a visual graph of the full-path network access relationship based on the starting node, the intermediate node, the ending node and the edge; and displaying the visual graph of the full-path network access relationship.
[0014] According to another aspect of an embodiment of the present application, a system for displaying a full-path network access relationship is also provided, including: a terminal device, a data visualization server, and a data processing server, wherein the terminal device is connected to the data visualization server, and is used to send a query request for requesting access to the full-path network access relationship of the network boundary to the data visualization server, and display the full-path network access relationship; the data visualization server is connected to the data processing server, and is used to respond to the query request and obtain data corresponding to the full-path network access relationship; the data processing server is used to obtain multiple logs of multiple NAT devices, convert the multiple logs into structured session logs corresponding to each NAT device in the multiple NAT devices, extract the local network access relationship of the network session at each NAT device according to the structured session log corresponding to each NAT device, concatenate the local network access relationship at each NAT device, obtain the full-path network access relationship of the network boundary to which each NAT device belongs, store the data corresponding to the full-path network access relationship, and send the data corresponding to the full-path network access relationship to the data visualization server, wherein the network session is a session between a device within the network boundary and a device outside the network boundary.
[0015] According to another aspect of an embodiment of the present application, a device for obtaining a full-path network access relationship is also provided, including: an acquisition module for obtaining a structured session log corresponding to each NAT device among multiple NAT devices; an extraction module for extracting the local network access relationship of the network session at each NAT device based on the structured session log corresponding to each NAT device, wherein the network session is a session between a device within the network boundary to which each NAT device belongs and a device outside the network boundary to which each NAT device belongs; a processing module for concatenating the local network access relationship of the network session at each NAT device to obtain the full-path network access relationship of the network boundary to which each NAT device belongs.
[0016] According to another aspect of an embodiment of the present application, a non-volatile storage medium is provided, in which a computer program is stored. The device where the non-volatile storage medium is located executes the above-mentioned method of full-path network access relationship by running the computer program.
[0017] According to another aspect of an embodiment of the present application, an electronic device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to execute the above-mentioned method of full-path network access relationship through the computer program.
[0018] In an embodiment of the present application, a structured session log corresponding to each NAT device in a plurality of NAT devices is obtained; based on the structured session log corresponding to each NAT device, a local network access relationship of a network session at each NAT device is extracted, wherein a network session is a session between a device within the network boundary to which each NAT device belongs and a device outside the network boundary to which each NAT device belongs; the local network access relationship of the network session at each NAT device is connected in series to obtain a full-path network access relationship of the network boundary to which each NAT device belongs, by collecting the local network access relationships before and after multiple NAT device nodes in the boundary network path, and connecting and matching the local network access relationships collected by multiple nodes in the boundary path, thereby achieving the purpose of obtaining and displaying the full-path network access relationship across the network boundary where the NAT device is located, thereby realizing the existence of one-to-many mapping, many-to-one mapping, and associated policy-based routing in the NAT device. The present invention can accurately and efficiently obtain the full-path network access relationship across NAT devices in application scenarios with complex NAT configurations such as address mapping and port mapping of Pre-NAT Routing (PBR), as well as in complex application scenarios with multiple NAT devices cascaded. This solves the technical problem that related technologies cannot efficiently and accurately obtain the full-path network access relationship across NAT devices due to the complexity of the NAT environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0020] Figure 1 is a flowchart of a method for obtaining a full-path network access relationship according to an embodiment of the present application;
[0021] Figure 2 is a schematic diagram of a log aggregation table according to an embodiment of the present application;
[0022] Figure 3 is a schematic diagram of a network boundary topology diagram according to an embodiment of the present application;
[0023] Figure 4 is a schematic diagram of an inbound and outbound path table of a NAT device according to an embodiment of the present application;
[0024] Figure 5 is a schematic diagram of a full-path network access relationship table according to an embodiment of the present application;
[0025] Figure 6 is a schematic diagram of a visual graph of a full-path network access relationship according to an embodiment of the present application;
[0026] Figure 7 This is a structural diagram of a system for displaying full-path network access relationships according to an embodiment of the present application;
[0027] Figure 8 This is a workflow diagram of a system for displaying full-path network access relationships according to an embodiment of the present application;
[0028] Figure 9 This is a structural diagram of a device for full-path network access relationship according to an embodiment of the present application. DETAILED DESCRIPTION
[0029] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.
[0030] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0031] In order to better understand the embodiments of the present application, the technical terms involved in the embodiments of the present application are explained as follows:
[0032] NAT device: A device that has the function of converting the source IP, destination IP, and destination port in IP packets in network communications; the NAT device in the embodiments of the present application can be a firewall, load balancer, switch, router, NAT gateway, and other devices with NAT function. In terms of device form, it can be a physical device or a virtual server and cloud server.
[0033] Timestamp: Data generated by digital signature technology, used to authenticate the generation time of the signature object. In the embodiment of the present application, the timestamp of each log is used to indicate the generation time of each log.
[0034] Source network address (source IP): indicates the real source IP, that is, the IP value of the source address field in the IP packet message before the data packet initiated by the client side enters the NAT device.
[0035] Source mapped network address (source mapped IP): indicates the IP value of the source address field in the IP packet message after the data packet initiated by the client side passes through the NAT device.
[0036] Destination network address (destination IP): indicates the real destination IP, that is, the IP value of the destination address field in the IP packet message after the data packet initiated by the client side passes through the NAT device.
[0037] Destination mapping network address (destination mapping IP): indicates the IP value of the destination address field in the IP packet message before the data packet initiated by the client side enters the NAT device.
[0038] Destination Port: indicates the real destination port, that is, the port value of the destination port field in the IP packet after the data packet initiated by the client side passes through the NAT device.
[0039] Destination mapping port: indicates the port value of the destination port field in the IP packet sent by the client before entering the NAT device.
[0040] Internal interface: refers to the interface on the side of the NAT device closest to the internal network. When an external network client actively accesses the internal network, it is the outbound interface for data packets. When an internal network client actively accesses the external network, it is the inbound interface for data packets.
[0041] External interface: This interface is the interface on the NAT device that is closest to the external network. It is the inbound interface for packets sent from external network clients to the internal network. It is the outbound interface for packets sent from internal network clients to the external network.
[0042] Internal interface source network address (internal interface source IP): indicates the IP value of the source IP field in the IP packet message on the internal interface side of the NAT device for the data packet initiated by the client side.
[0043] Internal interface destination network address (internal interface destination IP): indicates the IP value of the destination IP field in the IP packet message on the internal interface side of the NAT device for the data packet initiated by the client side.
[0044] Internal interface destination port: indicates the port value of the destination port field in the IP packet of the data packet initiated by the client side on the internal interface side of the NAT device.
[0045] External interface source network address (external interface source IP): indicates the IP value of the source IP field in the IP packet message on the external interface side of the NAT device for the data packet initiated by the client side.
[0046] External interface destination network address (external interface destination IP): indicates the IP value of the destination IP field in the IP packet message on the external interface side of the NAT device for the data packet initiated by the client side.
[0047] External interface destination port: indicates the port value of the destination port field in the IP packet of the data packet initiated by the client side on the external interface side of the NAT device.
[0048] Local network access relationship: The access relationship in the network traffic observed at a specific location in the network security boundary topology path. In the embodiment of this application, the "source IP, destination IP, destination port and protocol" in the data packet initiated by the client are used to jointly represent a network access relationship.
[0049] Full-path network access relationships: After passing through a NAT device, local network access relationships are transformed. The full-path network access relationships that traverse the entire network security boundary are derived by sequentially matching the local network access relationships before and after each NAT device in the network security boundary path.
[0050] In the related art, a proxy program is set up on the server, and the network access information of the server is reported to the central monitoring server through the proxy program to obtain the local network access relationship of the server; or, a network traffic probe is deployed, and the traffic data packets are captured by the network traffic probe, and the data packets are parsed by the network traffic analysis device to obtain the network session data, and then the network access relationship across the network boundary is obtained after aggregation processing. However, the network access relationship collected by the proxy program is mixed with the access relationship between the internal visits of the intranet, and it is necessary to combine with another database, such as the Configuration Management Database (CMDB) for screening to identify the network access relationship across the network boundary; and since the data center generates a large amount of cross-border business traffic every day, the method of parsing the traffic data packets captured by the network traffic probe to obtain the network access relationship across the network boundary has high requirements for the storage and configuration of the CPU. Therefore, there are problems such as only being able to obtain the local network access relationship across the network boundary, the method being cumbersome, and the cost being high. In order to solve this problem, a relevant solution is provided in the embodiment of the present application, which is described in detail below.
[0051] According to an embodiment of the present application, a method embodiment for obtaining a full-path network access relationship is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0052] Figure 1 This is a flow chart of a method for obtaining a full-path network access relationship according to an embodiment of the present application. Figure 1 As shown, the method includes the following steps:
[0053] Step S102: Obtain a structured session log corresponding to each NAT device among the multiple NAT devices.
[0054] The method provided in the present application is implemented based on obtaining the session log of the NAT device. Therefore, in step S102, the structured session log of each NAT device in the network boundary is first obtained. Since there are usually multiple NAT devices of different types in the network boundary, the formats of the collected logs are different depending on the device type, and the initially collected logs are usually a large string of irregular characters. Therefore, when obtaining the structured session log of each NAT device, it is first necessary to identify the interface protocol of the log interface provided by each NAT device. Specifically, the interface protocol can be a system log protocol (syslog), file transfer protocol (FTP), secure file transfer protocol (SFTP), hypertext transfer protocol (HTTP), and other types of protocols. The session log of each NAT device is collected according to the interface protocol. For example, if the log interface provided by the NAT device uses the system log protocol (syslog), the session log of the NAT device is obtained through the syslog; and then it is converted into a structured session log in a standard format.
[0055] According to an optional embodiment of the present application, obtaining a structured session log corresponding to each NAT device in a plurality of NAT devices includes the following steps: obtaining multiple logs of the plurality of NAT devices, obtaining key element information from the plurality of logs, wherein the key element information includes at least one of the following: timestamp, source network address, destination network address, destination port, source mapped network address, destination mapped network address, destination mapped port, protocol type, source interface, and destination interface; obtaining identification information of each NAT device, wherein the identification information includes at least one of the following: the name of the NAT device and the network address of the NAT device; combining the key element information of each NAT device and the identification information of each NAT device to obtain a structured session log corresponding to each NAT device.
[0056] In this embodiment, the method for converting the collected logs into a structured session log in a standard form is as follows: the collected logs are parsed, and each log is extracted from a timestamp, an IP value of a source address field in an IP packet message from the client side before the data packet enters the NAT device (i.e., source network address, source IP), an IP value of a destination address field in an IP packet message from the client side after the data packet passes through the NAT device (i.e., destination network address, destination IP), a port value of a destination port field in an IP packet message from the client side after the data packet passes through the NAT device (i.e., destination port), an IP value of a source address field in an IP packet message from the client side after the data packet passes through the NAT device (i.e., source mapped network address, source mapped IP), an IP value of a destination address field in an IP packet message from the client side before the data packet enters the NAT device (i.e., destination mapped IP), The method comprises collecting the key elements of the log, such as the network address, the destination IP address, the port value of the destination port field in the IP packet message before the data packet from the client side enters the NAT device (i.e., the destination mapping port), the protocol used by the network session corresponding to the log, the interface through which the data packet enters the NAT device (i.e., the source interface), and the interface through which the data packet exits the NAT device (i.e., the destination interface); extracting the identification information that can identify the NAT device, such as the name of the NAT device or the IP address of the NAT device, from the collected log; combining the key elements of the NAT device name or the IP address identification with the source IP, destination IP, destination port, source mapping IP, destination IP, destination mapping port, source interface, and destination interface of the NAT device indicated by the name / IP address of the NAT device to generate a structured session log for each NAT device. For example, the structured session log for each NAT device is obtained by combining the first field as the NAT device name, the second field as the source IP, the third field as the destination IP, the fourth field as the destination port, the fifth field as the protocol type, the sixth field as the source mapping IP, the seventh field as the destination mapping IP, the eighth field as the destination mapping port, the ninth field as the source interface, and the tenth field as the destination interface.
[0057] Step S104: extracting the local network access relationship of the network session at each NAT device based on the structured session log corresponding to each NAT device, wherein the network session is a session between a device within the network boundary to which each NAT device belongs and a device outside the network boundary to which each NAT device belongs.
[0058] After obtaining the structured session log of each NAT device through the method provided in step S102, in step S104, the access relationship between the network sessions observed at each NAT device (i.e., the local network access relationship) is extracted based on the information recorded in the structured session log of each NAT device, where the network session is a session between a device within the network boundary to which the NAT device belongs and a device outside the network boundary to which the NAT device belongs.
[0059] According to another optional embodiment of the present application, based on the structured sessionized log corresponding to each NAT device, the local network access relationship of the network session at each NAT device is extracted, including the following steps: obtaining the network boundary topology relationship of the NAT device, and generating an input and output path table of the NAT device based on the network boundary topology relationship, wherein the input and output path table of the NAT device includes: identification information of the NAT device, the name of the network boundary where the NAT device is located, the cascade level of the NAT device, the access direction of the network session passing through the NAT device, the name of the input interface and the name of the output interface, the input interface is the interface through which the network session enters the NAT device, and the output interface is the interface through which the network session exits the NAT device; generating a log aggregation table based on the structured session log, and determining the access direction of the network session passing through the NAT device based on the input and output path table and the log aggregation table of the NAT device; and extracting the local network access relationship of the network session at the NAT device based on the access direction.
[0060] In this embodiment, the local network access relationship at each NAT device is extracted from the information recorded in the structured session log of each NAT device through the following steps: First, a log aggregation table is generated based on the structured session log of each NAT device obtained in step S102; then, a network boundary topology map of the network boundary to which the NAT device belongs is obtained, which records information such as the name / IP address of the NAT device (i.e., identification information of the NAT device), the name of the network boundary where the NAT device is located, the cascade level of the NAT device, the access direction of the network session through the NAT device, the name of the interface through which the network session enters the NAT device (i.e., the inbound interface), and the name of the interface through which the network session exits the NAT device (i.e., the outbound interface); based on the network boundary topology map and the log aggregation table, the direction of network access to the NAT device is determined, i.e., whether the access direction is from the external network → NAT device → the internal network or from the internal network → NAT device → the external network; finally, the local network access relationship of the network session at each NAT device is extracted based on the determined access direction.
[0061] According to some preferred embodiments of the present application, a log aggregation table is generated based on structured session logs, including: determining a preset period and collecting multiple structured session logs within the preset period; classifying data in the multiple structured session logs that have exactly the same key element information except for timestamps into one group of data to obtain multiple groups of data; generating a log aggregation table based on the multiple groups of data, wherein the log aggregation table includes: identification information of the NAT device, key element information, and the number of times each group of data appears.
[0062] In some preferred embodiments, a method for generating a log aggregation table based on structured session logs is as follows: Since a NAT device generates a log each time a session is established, a large amount of data is obtained when the logs of the NAT device are collected in real time in the embodiments of the present application. This large amount of data includes multiple pieces of data that are completely identical except for the timestamp. Therefore, in some preferred embodiments, a processing period (i.e., a preset period) is pre-set, such as one hour, one day, or one month. Structured session logs are collected within the processing period, and the logs within the processing period are aggregated. Specifically, structured session logs with completely identical key elements such as the NAT device name / IP address, source IP, destination IP, destination port, and protocol type are aggregated into a group of data. The multiple groups of data aggregated by the above method are saved to generate a log aggregation table. Figure 2 This is a schematic diagram of the log aggregation table, such as Figure 2 As shown, the row identifiers of the log aggregation table are date, NAT device, source IP, destination IP, destination port, protocol, source mapping IP, destination mapping IP, destination mapping port, source interface, destination interface and connection count (i.e., the number of times each set of data appears). Among them, date is used to indicate the date when the log is generated, NAT device is used to indicate the name / IP address of the NAT device, and connection count is used to indicate the number of times this set of data appears in a processing cycle. Figure 2As shown, in the data collected during a processing cycle on January 1, 2022, there are 100 logs for device 2-1 with a source IP of 211.0.0.2, a destination IP of 172.16.0.2, a destination port of 8080, a protocol type of Transmission Control Protocol (TCP), a source mapping IP of 211.0.0.2, a destination mapping IP of 112.0.0.2, a destination mapping port of 80, a source interface of extranet, and a destination interface of inside. The above-mentioned logs are recorded once in the log table, and the number of times they appear is marked after the log. In addition, the log aggregation table records several groups of data according to how many different logs appear in a processing cycle. That is, the number of groups is the same as the type of logs. Among them, if any of the data in the name / IP address, source IP, destination IP, destination port and protocol type of the NAT device is different, the type of log is different.
[0063] It should be noted that if the source IP and the source mapped IP are the same, it means that the NAT device has not converted the source IP field; if the destination IP and the destination mapped IP are the same, it means that the NAT device has not converted the destination IP field; if the destination port and the destination mapped port are the same, it means that the NAT device has not converted the destination port field.
[0064] According to an optional embodiment of the present application, a log aggregation table is generated based on a structured session log, and an access direction of a network session passing through a NAT device is determined based on an ingress / egress path table and the log aggregation table of the NAT device, including: obtaining identification information of the NAT device in the log aggregation table, a name of a source interface corresponding to the identification information of the NAT device, and a name of a destination interface corresponding to the identification information of the NAT device; and using the identification information of the NAT device, the name of the source interface corresponding to the identification information of the NAT device, and the name of the destination interface corresponding to the identification information of the NAT device to determine, through the ingress / egress path table of the NAT device, the access direction of the network session passing through the NAT device indicated by the identification information of the NAT device.
[0065] Figure 3 It is a schematic diagram of the network boundary topology, such as Figure 3 As shown in FIG, the path of the network session through the NAT device is recorded in the form of a topology diagram. The network boundary topology diagram includes: the name of the network boundary where the NAT device is located, the name of each NAT device in the network boundary where the NAT device is located, the cascade level of each NAT device, the name of the input interface and the name of the output interface of each NAT device, the name of the network that accesses the network boundary where the NAT device is located, and the name of the network that is reached after passing through the network boundary where the NAT device is located, such as Figure 3, the name of the network boundary is network boundary 1, and network boundary 1 includes device 2-1 and device 2-2, wherein the "-1" in device 2-1 indicates that the cascade level of the NAT device is 1, and similarly, the "-2" in device 2-2 indicates that the cascade level of the NAT device is 2; when accessing internal network 2 and / or internal network 3 from external network 1, the input interface of device 2-1 is extranet and the output interface is inside, while the input interface of device 2-2 is outside and the output interface is dmz and intranet. When determining the access direction, the access direction of the network session corresponding to the group of logs is comprehensively queried based on the values of the three fields of NAT device, source interface, and destination interface of each group of logs recorded in the log aggregation table. For example, in a group of logs recorded in the log aggregation table, the value of the NAT device field is device 2-1, the value of the source interface field is extranet, and the value of the destination interface field is inside. If Figure 3 In the network boundary topology diagram shown, it can be found that there is a NAT device named device 2-1 in network boundary 1, with the value of the entry field being extranet and the value of the output interface field being inside. Therefore, it can be determined that the NAT device recorded in this set of logs is the same NAT device as the NAT device in the network topology diagram, and from the network boundary topology diagram, it can be determined that the access from interface extranet to interface inside is from the external network to the internal network, which means that the access direction of the network session in NAT device 2-1 is inbound. On the contrary, if the value of the NAT device field in another set of logs recorded in the log aggregation table is device 2-2, the value of the source interface field is intranet, and the value of the destination interface field is outside, then if Figure 3 The network boundary topology diagram shown shows that a NAT device named Device 2-2 exists in Network Boundary 1, with the value of the Incoming Interface field being Intranet and the value of the Outgoing Interface field being Outside. Therefore, it can be determined that the NAT device recorded in this set of logs is the same NAT device as the device in the network topology diagram. Furthermore, the network boundary topology diagram shows that the connection from Interface Intranet to Interface Outside represents access from the internal network to the external network. This means that the access direction of the network session on NAT device 2-2 is out-of-bounds.
[0066] It should be noted that the server that processes data obtains the network boundary topology relationship in Figure 4 The table is stored as shown. Figure 4 It is the inbound and outbound path table of the NAT device. The contents recorded in this table are the same as Figure 3The information recorded in the NAT device is exactly the same, such as the name of the network boundary where the NAT device is located, the cascade level of the network boundary, the name of each NAT device in the network boundary where the NAT device is located, the cascade level of each NAT device, the access direction of the network session through the NAT device, the interface through which the network session enters the NAT device (i.e., the inbound interface), and the interface through which the network session exits the NAT device (i.e., the outbound interface). Figure 4 As shown, when Figure 3 If the above information is recorded in Figure 4 It also records that in network boundary 1 containing two NAT devices, when accessing internal network 2 from external network 1 through network boundary 1, the access direction is inbound, the inbound interface of device 2-1 with cascade level 1 is extranet, and the outbound interface is inside, and the inbound interface of device 2-2 with cascade level 2 is outside, and the outbound interface is DMZ; when accessing external network 1 from internal network 2 through network boundary 1, the access direction is outbound, the inbound interface of device 2-1 with cascade level 1 is inside, and the outbound interface is extranet, and the inbound interface of device 2-2 with cascade level 2 is DMZ, and the outbound interface is outside; when accessing external network 1 from internal network 3 through network boundary 1, the access direction is outbound, the inbound interface of device 2-1 with cascade level 1 is inside, and the outbound interface is extranet, and the inbound interface of device 2-2 with cascade level 2 is intranet, and the outbound interface is outside. The network boundary topology relationship only needs to be initialized once and can be saved for repeated use. It is only updated when a change in the topology of the NAT device in the network boundary is detected.
[0067] According to another optional embodiment of the present application, the local network access relationship of the network session at the NAT device is extracted according to the access direction, including: if the access direction is inbound, the source mapping network address corresponding to the identification information of the NAT device is determined as the inner interface source network address, the destination network address corresponding to the identification information of the NAT device is determined as the inner interface destination network address, the destination port corresponding to the identification information of the NAT device is determined as the inner interface destination port, the source network address corresponding to the identification information of the NAT device is determined as the outer interface source network address, the destination mapping network address corresponding to the identification information of the NAT device is determined as the outer interface destination network address, and the destination mapping port corresponding to the identification information of the NAT device is determined as the outer interface destination port, wherein inbound indicates access from a device outside the network boundary to a device inside the network boundary; and determining that the access direction of the NAT device is inbound according to the inner interface source network address, the inner interface destination network address, the inner interface port, the outer interface source network address, the outer interface destination network address and the outer interface destination port. The invention discloses a method for determining multiple local network access relationships of a network session at a NAT device when the access direction is out-of-bounds; if the access direction is out-of-bounds, determining the source network address corresponding to the identification information of the NAT device as the inner interface source network address, determining the destination mapping network address corresponding to the identification information of the NAT device as the inner interface destination network address, determining the destination mapping port corresponding to the identification information of the NAT device as the inner interface destination port, determining the source mapping network address corresponding to the identification information of the NAT device as the outer interface source network address, determining the destination network address corresponding to the identification information of the NAT device as the outer interface destination network address, and determining the destination port corresponding to the identification information of the NAT device as the outer interface destination port, wherein out-of-bounds indicates access from a device within the network boundary to a device outside the network boundary; determining multiple local network access relationships of the network session at the NAT device when the access direction is out-of-bounds according to the inner interface source network address, the inner interface destination network address, the inner interface destination port, the outer interface source network address, the outer interface destination network address and the outer interface destination port.
[0068] In this embodiment, after the access direction of the NAT device is determined through the above embodiment, the method for extracting the local network access relationship of the NAT device according to the access direction is as follows: when the access direction is inbound, the value of the source mapping IP field recorded in the log of the NAT device is determined as the network address of the interface of the NAT device close to the internal network side (i.e., the internal interface) (i.e., the internal interface source network address), the value of the destination IP field recorded in the log of the NAT device is determined as the internal interface destination network address of the NAT device, the value of the destination port field recorded in the log of the NAT device is determined as the internal interface destination port of the NAT device, the value of the source IP field recorded in the log of the NAT device is determined as the network address of the interface of the NAT device close to the external network side (i.e., the external interface source network address), the value of the destination mapping IP field recorded in the log of the NAT device is determined as the external interface destination network address of the NAT device, and the destination mapping port recorded in the log of the NAT device is determined as the external interface destination port of the NAT device. When the access direction is out-of-bounds, the value of the source IP field recorded in the log of the NAT device is determined as the network address of the interface (i.e., the inner interface) of the NAT device close to the inner network side (i.e., the inner interface) (i.e., the inner interface source network address), the value of the destination mapping IP field recorded in the log of the NAT device is determined as the inner interface destination network address of the NAT device, the value of the destination mapping port field recorded in the log of the NAT device is determined as the inner interface destination port of the NAT device, the value of the source mapping IP field recorded in the log of the NAT device is determined as the network address of the interface (i.e., the outer interface) of the NAT device close to the outer network side (i.e., the outer interface source network address), the value of the destination IP field recorded in the log of the NAT device is determined as the outer interface destination network address of the NAT device, and the destination port recorded in the log of the NAT device is determined as the outer interface destination port of the NAT device. Therefore, the internal interface source network address, internal interface destination network address, internal interface destination port, external interface source network address, external interface destination network address, and external interface destination port of the NAT device can be determined according to whether the access direction is inbound or outbound, and the local network access relationship of the network session composed of the internal interface source network address, internal interface destination network address, internal interface destination port, external interface source network address, external interface destination network address, and external interface destination port at the NAT device can be further determined. If there is only one NAT device in the network boundary, two local network access relationships of one NAT device should be obtained through this method, one is the local network access relationship from the external network to the external interface of the NAT device, and the other is the local network access relationship from the internal interface of the NAT device to the internal network; if there are multiple NAT devices in the network boundary, two local network access relationships should be obtained for each NAT device. For example, Figure 2The source IP of device 2-1 is 211.0.0.2, the destination IP is 172.16.0.2, the destination port is 8080, the source mapping IP is 211.0.0.2, the destination mapping IP is 112.0.0.2, and the destination mapping port is 80. Figure 3 It can be determined that when accessing internal network 2 from external network 1, the access direction is inbound. When the access direction is inbound, the network session has the following two local network access relationships at device 2-1: one is a local network access relationship from external network 1 to the external interface of NAT device 2-1, consisting of an external interface source network address of 211.0.0.2, an external interface destination network address of 112.0.0.2, and an external interface destination port of 80; the other is a local network access relationship from the internal interface of NAT device 2-1 to the internal interface of NAT device 2-2, consisting of an internal interface source network address of 211.0.0.2, an internal interface destination network address of 172.16.0.2, and an internal interface destination port of 8080.
[0069] Step S106 : Concatenate the local network access relationships of the network sessions at each NAT device to obtain the full-path network access relationship of the network boundary to which each NAT device belongs.
[0070] In step S106, after determining the local network access relationship of the NAT device by the above method, multiple local network access relationships of the network session at each NAT device are connected in series to obtain the full path network access relationship of the network boundary to which the NAT device belongs.
[0071] According to an optional embodiment of the present application, the local network access relationship of each NAT device is concatenated to obtain the full-path network access relationship of the network boundary to which each NAT device belongs, including: determining the number of NAT devices in the network boundary to which the NAT device belongs from the ingress and egress path table of the NAT device; if the number is greater than one, concatenating multiple local network access relationships of multiple NAT devices within the same network boundary according to the concatenation rule to obtain the full-path network access relationship; if the number is equal to one, determining the local network access relationship of the NAT device as the full-path network access relationship.
[0072] In this embodiment, when connecting the local network access relationship of each NAT device in series, first Figure 4The ingress and egress path table of the NAT device shown determines the network boundary to which the NAT device belongs and the number of NAT devices in the network boundary. If there is only one NAT device in the network boundary, then the local network access relationship of this NAT device is the full-path network access relationship of the network boundary; if the network boundary includes two or more NAT devices, at this time, the multiple local network access relationships of multiple NAT devices in the network boundary are connected in series to obtain the full-path network access relationship of the network boundary.
[0073] According to some other preferred embodiments of the present application, multiple local network access relationships of multiple NAT devices within the same network boundary are connected in series according to the series connection rules, including: if the internal interface source network address of the first NAT device among the multiple NAT devices is equal to the external interface source network address of the second NAT device among the multiple NAT devices, the internal interface destination network address of the first NAT device is equal to the external interface destination network address of the second NAT device, and the internal interface destination port of the first NAT device is equal to the external interface destination port of the second NAT device, the local network access relationship of the first NAT device and the local network access relationship of the second NAT device are connected in series to form a full path access relationship of the network boundary, wherein the first NAT device and the second NAT device belong to the same network boundary, the first NAT device and the second NAT device are adjacent to each other, and the cascade level of the first NAT device is lower than the cascade level of the second NAT device.
[0074] In other preferred embodiments, multiple local network access relationships of multiple NAT devices in the same network boundary are connected in series by the following method to determine the cascade level of multiple NAT devices in the same network boundary. If the internal interface source network address recorded in the local network access relationship of the NAT device of the lower cascade level is the same as the external interface source network address recorded in the local network access relationship of the NAT device of the higher cascade level adjacent to it, and the internal interface destination network address recorded in the local network access relationship of the NAT device of the lower cascade level is the same as the external interface destination network address recorded in the local network access relationship of the NAT device of the higher cascade level adjacent to it, and the internal interface destination port recorded in the local network access relationship of the NAT device of the lower cascade level is the same as the external interface destination port recorded in the local network access relationship of the NAT device of the higher cascade level adjacent to it, then starting from the lowest level, the local network access relationships of the NAT devices of the lower cascade level are connected in series with the local network access relationships of the NAT devices of the higher cascade level in sequence according to the cascade level until they are connected in series to the NAT device with the highest cascade level in the network boundary, and the result of the series connection is used as the full path network access relationship of the network boundary. For example, network boundary 1 includes a level 1 NAT device 2-1 and a level 2 NAT device 2-2. The internal interface source network address of NAT device 2-1 is 211.0.0.2, the internal interface destination network address is 172.16.0.2, and the internal interface destination port is 8080. The external interface source network address of NAT device 2-2 is 211.0.0.2, the external interface destination network address is 172.16.0.2, and the external interface destination port is 8080. Then, the local network access relationship of NAT device 2-1 and the local network access relationship of NAT device 2-2 are concatenated into the full path network access relationship of network boundary 1.
[0075] Figure 5 This is a schematic diagram of the full-path network access relationship table. It should be noted that after obtaining the full-path network access relationship of the network boundary, it can also be used as Figure 5 The records are saved in the form of the table shown. The full-path network access relationship table records the name of the network boundary, the access direction of the network session to the network boundary, the local network access relationship of the external interface of the lowest cascade level, the local network access relationship of the internal interface of the highest cascade level, and the local network access relationship between adjacent NAT devices, the protocol used by the network session, and the number of times the same full-path network access relationship appears (i.e., the number of connections). Among them, the local network access relationship of the external interface of the lowest cascade level, the local network access relationship of the internal interface of the highest cascade level, and the local network access relationship between adjacent NAT devices are composed of the source IP field, the destination IP field, and the destination port field. Figure 3The network boundary 1 shown includes a NAT device 2-1 at the lowest cascade level and a NAT device 2-2 at the highest cascade level. When accessing the internal network 2 or the internal network 3 through the external network 1, the access direction is recorded as inbound in the full-path network access relationship table of the network boundary 1. The local network access relationship of the external interface of the device 2-1 consists of the source IP 211.0.0.2, the destination IP 112.0.0.2, and the destination port 80. The local network access relationship of the internal interface of the device 2-2 consists of the source IP 211.0.0.2, the destination IP 172.16.0.2, and the destination port 8080. The local network access relationship between the devices 2-1 and 2-2 consists of the source IP 211.0.0.2, the destination IP 172.16.0.2, and the destination port 8080. At the same time, the number of times this full-path access relationship appears (for example, 100 times) is recorded in the full-path network access relationship table of the network boundary 1. When accessing external network 1 through internal network 2 or internal network 3, in the full-path network access relationship table of network boundary 1, the access direction is recorded as out-of-bounds, the local network access relationship of the external interface of device 2-1 is composed of source IP 112.0.10.3, destination IP 211.0.0.3, and destination port 443, the local network access relationship of the internal interface of device 2-2 is composed of source IP 172.16.0.3, destination IP 192.168.0.3, and destination port 443, and the local network access relationship between device 2-1 and device 2-2 is composed of source IP 172.16.0.3, destination IP 211.0.0.3, and destination port 443. At the same time, the number of times this full-path access relationship appears (for example, 200 times) is recorded in the full-path network access relationship table of network boundary 1.
[0076] Through the above steps, it is possible to extract the local network access relationship before and after passing through the NAT device through the NAT session log, and combine the NAT device topology diagram of the network boundary to connect multiple local network access relationships into the full-path network access relationship of the network boundary where the NAT device is located; because the full-path network access relationship of the network session passing through the network boundary is extracted from the session log, and there is no need to obtain the full-path network access relationship of the network session passing through the network boundary based on the mapping configuration data of the NAT device, it is suitable for application scenarios with complex NAT configurations such as one-to-many mapping, many-to-one mapping, and mapping associated with policy routing in the NAT device, and is also suitable for application scenarios with multiple NAT devices cascaded. Without the need to deploy agent programs or capture and parse massive business traffic data packets, the full-path network access relationship of the network boundary can be accurately and efficiently obtained while reducing operation and maintenance costs.
[0077] According to an optional embodiment of the present application, the method for obtaining a full-path network access relationship also includes: determining the node corresponding to the device that initiates the access request in the full-path network access relationship as the starting node, determining the node corresponding to the device that receives the access request in the full-path network access relationship as the ending node, and determining the NAT device in the full-path network access relationship as the intermediate node; determining the line segment connecting the starting node, the intermediate node and the ending node as an edge, wherein the direction of the edge is determined according to the access direction of the network session crossing the network boundary, and the direction of the edge is indicated by an arrow; generating a visual graph of the full-path network access relationship based on the starting node, the intermediate node, the ending node and the edge; and displaying the visual graph of the full-path network access relationship.
[0078] The method provided by the embodiment of the present application can also display the full path network access relationship. Figure 6 It is a schematic diagram of the visual graph of the full path network access relationship, such as Figure 6As shown, the full-path network access relationship visualization diagram includes the external network area, the network boundary area, and the internal network area. Among them, the network session is initiated by the internal network. The internal network area displays the name of the device in the internal network (i.e., client) and the network address of the device (e.g., 172.16.0.3) and the local network access relationship of the network session entering the network boundary from the internal network; the network boundary area displays the name of each NAT device in the network boundary (e.g., NAT device 1, NAT device 2), the source interface (e.g., inside, intranet), and the destination interface (e.g., extranet, outside), as well as the local network access relationship between the NAT devices in the network boundary of the network session; the external network area displays the name of the device in the external network (e.g., server) and the network address of the device (e.g., 112.16.0.3). 0.10.3:443) and the local network access relationship of the network session accessing the external network through the network boundary; the local network access relationship of the external network accessing the network boundary is displayed in the form of a label, including the source network address (such as 112.00.10.3), the destination network address (such as 211.0.10.3) and the destination port (such as 443); the local network access relationship of the internal network accessing the network boundary is displayed in the form of a label, including the source network address (such as 172.16.0.3), the destination network address (such as 192.168.0.3) and the destination port (such as 443); the local network access relationship of the network session between NAT devices is displayed in the form of a label, including the source network address (such as 172.16.0.3), the destination network address (such as 211.0.0.3) and the destination port (such as 443). When displaying the access path, the node corresponding to the accessed device is used as the end node, the multiple nodes corresponding to multiple NAT devices are used as multiple intermediate nodes, and the node corresponding to the device that initiates the access request in the entire path is used as the start node. The nodes corresponding to the devices in the access path are connected by line segments as edges, and the access direction is indicated by arrows.
[0079] Figure 7This is a structural diagram of a system for displaying full-path network access relationships provided according to an embodiment of the present application, including: a terminal device 70, a data visualization server 72, and a data processing server 74, wherein the terminal device 70 is connected to the data visualization server 72 and is used to send a query request for requesting access to the full-path network access relationship of the network boundary to the data visualization server 72 and display the full-path network access relationship; the data visualization server 72 is connected to the data processing server 74 and is used to respond to the query request and obtain data corresponding to the full-path network access relationship; the data processing server 74 is used to obtain multiple logs of multiple NAT devices, convert the multiple logs into structured session logs corresponding to each of the multiple NAT devices, extract the local network access relationship of the network session at each NAT device based on the structured session log corresponding to each NAT device, concatenate the local network access relationship at each NAT device to obtain the full-path network access relationship of the network boundary to which each NAT device belongs, store the data corresponding to the full-path network access relationship, and send the data corresponding to the full-path network access relationship to the data visualization server 72, wherein the network session is a session between a device within the network boundary and a device outside the network boundary.
[0080] Figure 8 It is a workflow diagram of the display system that shows the full path network access relationship of the network boundary where the NAT device is located, such as Figure 8 The terminal device 70 shown first initiates a query request to the data visualization server 72 to query the full-path network access relationship of the network boundary where the NAT is located. After receiving the query request, the data visualization server 72 obtains the full-path network access relationship from the data processing server 74; the data processing server 74 sends the stored data for identifying the full-path network access relationship to the data visualization server 72, wherein the data processing server 74 collects the session logs of each NAT device in the network boundary in a predetermined period and converts each session log into a standard structured session log, and then extracts the local network access relationship of each NAT device through the structured session log of each NAT device, and concatenates the local network access relationship of each NAT device into the full-path network access relationship of the network boundary where these multiple NAT devices are located according to the above method and stores it; the data visualization server 72 sends the processed visualized full-path network access relationship to the terminal device 70, and the terminal device 70 generates a visual diagram representing the full-path network access relationship and displays the visual diagram.
[0081] Figure 9This is a structural diagram of a device for obtaining a full-path network access relationship provided according to an embodiment of the present application, including: an acquisition module 90, used to obtain a structured session log corresponding to each NAT device in a plurality of NAT devices; an extraction module 92, used to extract the local network access relationship of a network session at each NAT device based on the structured session log corresponding to each NAT device, wherein the network session is a session between a device within a network boundary to which each NAT device belongs and a device outside the network boundary to which each NAT device belongs; a processing module 94, used to concatenate the local network access relationship of the network session at each NAT device to obtain the full-path network access relationship of the network boundary to which each NAT device belongs.
[0082] When the device for obtaining the full-path network access relationship is working, the acquisition module 90 collects and analyzes the session logs of each NAT device in the network boundary in real time, and converts the collected original session logs into standard structured session logs; the extraction module 92 obtains and stores the structured session logs obtained by the acquisition module 90, and aggregates and classifies the data within an hour, a day, or a month according to a preset period such as one hour, one day, or one month, and extracts the local network access relationship before and after the NAT device; the processing module 94 connects the local network access relationship before and after the NAT device obtained by the extraction module 92 into a full-path network access relationship of the network device where the NAT device is located.
[0083] It should be noted that Figure 9 The preferred implementation of the embodiment shown can be found in Figure 1 The relevant description of the illustrated embodiment will not be repeated here.
[0084] The method provided in this embodiment can be applied to any network boundary where a NAT device is deployed, for example, it can be applied to the boundary between the intranet of a data center and the Internet, the boundary between different business isolation zones within a data center, the boundary between the public cloud and the Internet, etc. The method provided in the embodiment of the present application collects the NAT session logs of the NAT device at the network security boundary, extracts the local network access relationship before and after the NAT device, and performs serial matching on the local network access relationship before and after multiple NAT device nodes on the boundary network path, thereby accurately obtaining the full-path access relationship of the security boundary. In a complex multi-NAT device cascade environment, and in a complex NAT device configuration environment, such as an application environment in which there are one-to-many mappings, many-to-one mappings, address mappings associated with policy-based routing (PBR), port mappings, and other complex NAT configurations in the NAT device, the full-path network access relationship of the network boundary can be accurately and efficiently obtained without deploying agent programs on a large number of business servers, nor capturing and parsing massive business traffic data packets, thereby reducing operation and maintenance costs.
[0085] An embodiment of the present application further provides a non-volatile storage medium, in which a computer program is stored. The device where the non-volatile storage medium is located executes the above method of establishing a full-path network access relationship by running the computer program.
[0086] The non-volatile storage medium is used to store a program that performs the following functions: obtaining a structured session log corresponding to each NAT device among multiple NAT devices; extracting a local network access relationship of a network session at each NAT device based on the structured session log corresponding to each NAT device, wherein the network session is a session between a device within a network boundary to which each NAT device belongs and a device outside the network boundary to which each NAT device belongs; and concatenating the local network access relationship of the network session at each NAT device to obtain a full-path network access relationship of the network boundary to which each NAT device belongs.
[0087] An embodiment of the present application further provides an electronic device including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to execute the above method of full-path network access relationship through the computer program.
[0088] The processor in the above-mentioned electronic device is used to run a program that performs the following functions: obtaining a structured session log corresponding to each NAT device among multiple NAT devices; extracting the local network access relationship of the network session at each NAT device based on the structured session log corresponding to each NAT device, wherein the network session is a session between a device within the network boundary to which each NAT device belongs and a device outside the network boundary to which each NAT device belongs; and concatenating the local network access relationship of the network session at each NAT device to obtain the full-path network access relationship of the network boundary to which each NAT device belongs.
[0089] It should be noted that the various modules in the above-mentioned device for obtaining full-path network access relationships can be program modules (for example, a set of program instructions that implement a certain specific function) or hardware modules. For the latter, it can be expressed in the following forms, but is not limited to this: the expression form of each of the above-mentioned modules is a processor, or the functions of each of the above-mentioned modules are implemented by a processor.
[0090] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0091] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0092] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0093] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0094] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0095] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the relevant technology or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.
[0096] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A method for obtaining full-path network access relations, characterized in that: include: Obtaining a structured session log corresponding to each of the multiple NAT devices; Extracting, based on the structured session log corresponding to each NAT device, a local network access relationship of the network session at each NAT device, including: generating a log aggregation table based on the structured session log, and determining an access direction of the network session passing through the NAT device based on an ingress / egress path table of the NAT device and the log aggregation table; extracting, based on the access direction, the local network access relationship of the network session at the NAT device, wherein the ingress / egress path table is used to store a path of the network session passing through the NAT device, and wherein the network session is a session between a device within a network boundary to which each NAT device belongs and a device outside the network boundary to which each NAT device belongs; The local network access relationships of the network session at each NAT device are concatenated to obtain the full-path network access relationship of the network boundary to which each NAT device belongs, including: determining the number of NAT devices in the network boundary to which the NAT device belongs from the ingress and egress path table of the NAT device; if the number is greater than one, concatenating multiple local network access relationships of multiple NAT devices within the same network boundary according to the concatenation rule to obtain the full-path network access relationship; if the number is equal to one, determining the local network access relationship of the NAT device as the full-path network access relationship.
2. The method according to claim 1, characterized in that Extracting the local network access relationship of the network session at each NAT device according to the structured session log corresponding to each NAT device, further comprising: Obtain a network boundary topology relationship of the NAT device, and generate an input and output path table of the NAT device based on the network boundary topology relationship, wherein the input and output path table of the NAT device includes: identification information of the NAT device, the name of the network boundary where the NAT device is located, the cascade level of the NAT device, the access direction of the network session passing through the NAT device, the name of the input interface, and the name of the output interface, where the input interface is the interface where the network session enters the NAT device, and the output interface is the interface where the network session exits the NAT device.
3. The method according to claim 1, characterized in that Obtain structured session logs corresponding to each of multiple NAT devices, including: Obtain multiple logs of multiple NAT devices, and obtain key element information from the multiple logs, wherein the key element information includes: timestamp, source network address, destination network address, destination port, source mapping network address, destination mapping network address, destination mapping port, protocol type, source interface, and destination interface; Acquire identification information of each NAT device, wherein the identification information includes at least one of the following: a name of the NAT device and a network address of the NAT device; The key element information of each NAT device and the identification information of each NAT device are combined to obtain a structured session log corresponding to each NAT device.
4. The method according to claim 3, characterized in that Generating a log aggregation table according to the structured session log includes: Determining a preset period, and collecting a plurality of the structured session logs within the preset period; Classifying data in the structured conversation logs that have identical key element information except the timestamp into one group of data to obtain multiple groups of data; A log aggregation table is generated according to the multiple groups of data, wherein the log aggregation table includes: identification information of the NAT device, the key element information, and the number of times each group of data appears.
5. The method according to claim 2, characterized in that Generating a log aggregation table according to the structured session log, and determining an access direction of the network session passing through the NAT device according to the inbound and outbound path table of the NAT device and the log aggregation table, including: Obtaining identification information of the NAT device in the log aggregation table, a name of a source interface corresponding to the identification information of the NAT device, and a name of a destination interface corresponding to the identification information of the NAT device; The access direction of the network session of the NAT device indicated by the identification information of the NAT device is determined through the ingress and egress path table of the NAT device using the identification information of the NAT device, the name of the source interface corresponding to the identification information of the NAT device, and the name of the destination interface corresponding to the identification information of the NAT device.
6. The method according to claim 2, characterized in that Extracting a local network access relationship of the network session at the NAT device according to the access direction includes: If the access direction is inbound, determining the source mapping network address corresponding to the identification information of the NAT device as the inner interface source network address, determining the destination network address corresponding to the identification information of the NAT device as the inner interface destination network address, determining the destination port corresponding to the identification information of the NAT device as the inner interface destination port, determining the source network address corresponding to the identification information of the NAT device as the outer interface source network address, determining the destination mapping network address corresponding to the identification information of the NAT device as the outer interface destination network address, and determining the destination mapping port corresponding to the identification information of the NAT device as the outer interface destination port, wherein the inbound indication is accessing a device within the network boundary from a device outside the network boundary; Determine, based on the inner interface source network address, the inner interface destination network address, the inner interface destination port, the outer interface source network address, the outer interface destination network address, and the outer interface destination port, a plurality of local network access relationships of the network session at the NAT device when the access direction is inbound; If the access direction is out-of-bounds, determining the source network address corresponding to the identification information of the NAT device as the inner interface source network address, determining the destination mapped network address corresponding to the identification information of the NAT device as the inner interface destination network address, determining the destination mapped port corresponding to the identification information of the NAT device as the inner interface destination port, determining the source mapped network address corresponding to the identification information of the NAT device as the outer interface source network address, determining the destination network address corresponding to the identification information of the NAT device as the outer interface destination network address, and determining the destination port corresponding to the identification information of the NAT device as the outer interface destination port, wherein the out-of-bounds indication is accessing a device outside the network boundary from a device inside the network boundary; Determine multiple local network access relationships of the network session at the NAT device when the access direction is out of bounds based on the internal interface source network address, the internal interface destination network address, the internal interface destination port, the external interface source network address, the external interface destination network address and the external interface destination port.
7. The method according to claim 1, characterized in that Connecting multiple local network access relationships of multiple NAT devices within the same network boundary in series according to a series connection rule includes: If the internal interface source network address of a first NAT device among the multiple NAT devices is equal to the external interface source network address of a second NAT device among the multiple NAT devices, the internal interface destination network address of the first NAT device is equal to the external interface destination network address of the second NAT device, and the internal interface destination port of the first NAT device is equal to the external interface destination port of the second NAT device, the local network access relationship of the first NAT device and the local network access relationship of the second NAT device are concatenated into a full path access relationship of the network boundary, wherein the first NAT device and the second NAT device belong to the same network boundary, the first NAT device and the second NAT device are adjacent to each other, and the cascade level of the first NAT device is lower than the cascade level of the second NAT device.
8. The method according to claim 1, characterized in that The method further comprises: Determine the node corresponding to the device that initiates the access request in the full-path network access relationship as the starting node, determine the node corresponding to the device that receives the access request in the full-path network access relationship as the ending node, and determine the NAT device in the full-path network access relationship as the intermediate node; Determine a line segment connecting the start node, the intermediate node, and the end node as an edge, wherein a direction of the edge is determined according to an access direction of the network session crossing the network boundary, and the direction of the edge is indicated by an arrow; Generate a visual graph of the full-path network access relationship according to the starting node, the intermediate node, the ending node, and the edge; A visual diagram showing the full-path network access relationship.
9. A system for displaying full-path network access relationships, characterized in that: include: Terminal equipment, data visualization server and data processing server, wherein, The terminal device is connected to the data visualization server and is used to send a query request for requesting access to the full-path network access relationship of the network boundary to the data visualization server, and display the full-path network access relationship; The data visualization server is connected to the data processing server and is used to respond to the query request and obtain data corresponding to the full-path network access relationship; The data processing server is used to obtain multiple logs of multiple NAT devices, convert the multiple logs into structured session logs corresponding to each NAT device in the multiple NAT devices, extract the local network access relationship of the network session at each NAT device according to the structured session log corresponding to each NAT device, concatenate the local network access relationship at each NAT device to obtain the full-path network access relationship of the network boundary to which each NAT device belongs, store data corresponding to the full-path network access relationship, and send the data corresponding to the full-path network access relationship to the data visualization server, wherein the network session is a session between a device within the network boundary and a device outside the network boundary, and the extraction of the local network access relationship of the network session at each NAT device includes: generating a log aggregation table according to the structured session log, and according to the N The in / out path table of the AT device and the log aggregation table determine the access direction of the network session passing through the NAT device; extract the local network access relationship of the network session at the NAT device according to the access direction, and the in / out path table is used to store the path of the network session passing through the NAT device; the local network access relationship at each NAT device is connected in series to obtain the full-path network access relationship of the network boundary to which each NAT device belongs, including: determining the number of NAT devices in the network boundary to which the NAT device belongs from the in / out path table of the NAT device; if the number is greater than one, connecting multiple local network access relationships of multiple NAT devices within the same network boundary in series according to a connection rule to obtain the full-path network access relationship; if the number is equal to one, determining the local network access relationship of the NAT device as the full-path network access relationship.
10. A device for obtaining full-path network access relations, characterized in that: include: An acquisition module, configured to acquire a structured session log corresponding to each of the plurality of NAT devices; An extraction module is configured to extract, based on the structured session log corresponding to each NAT device, a local network access relationship of a network session at each NAT device, including: generating a log aggregation table based on the structured session log, and determining an access direction of the network session passing through the NAT device based on an ingress / egress path table of the NAT device and the log aggregation table; extracting the local network access relationship of the network session at the NAT device based on the access direction, wherein the ingress / egress path table is used to store a path of the network session passing through the NAT device, wherein the network session is a session conducted between a device within a network boundary to which each NAT device belongs and a device outside the network boundary to which each NAT device belongs; A processing module, configured to concatenate the local network access relationships of the network sessions at each NAT device to obtain a full-path network access relationship of the network boundary to which each NAT device belongs, comprising: Determine the number of NAT devices in the network boundary to which the NAT device belongs from the ingress and egress path table of the NAT device; if the number is greater than one, concatenate multiple local network access relationships of multiple NAT devices within the same network boundary according to the concatenation rule to obtain the full-path network access relationship; if the number is equal to one, determine the local network access relationship of the NAT device as the full-path network access relationship.
11. A non-volatile storage medium, characterized in that: The non-volatile storage medium stores a computer program, wherein the device where the non-volatile storage medium is located executes the method for establishing a full-path network access relationship according to any one of claims 1 to 8 by running the computer program.
12. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to execute the method for establishing a full-path network access relationship according to any one of claims 1 to 8 through the computer program.
Citation Information
Patent Citations
Method for IPv4 internal private network to visit IPv6 network and router thereof
CN101227408A
Data access full-path association auditing method
CN110062046A