Method, apparatus, gateway device and storage medium for processing network monitoring data
By mirroring data packets to CPU components in the gateway device for analysis and generation of filtering rules, the problem that traditional gateway devices are difficult to adapt to complex network attacks is solved, and the generation of dynamic filtering rules and efficient data processing is realized.
Patent Information
- Application Number
- CN202210987625.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-17
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2042-08-17
AI Technical Summary
Traditional gateway devices are difficult to adapt to the complexity of modern cyber attack technologies, and filtering rules are complex, and dynamically adjustable.
The FPGA component mirrors the data packets to the CPU component, and uses the CPU component to generate access control list filtering rules, and sends them to the FPGA component for filtering processing, realizing dynamic generation and automatic learning of filtering rules.
It improves the processing speed of FPGA components and the accuracy of data packet filtering, reduces the burden on CPU components, and enhances the processing capability of network monitoring data.
Smart Images

Figure CN116527523B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data processing, and in particular, to a method, apparatus, gateway device, and storage medium for processing network monitoring data. Background Art
[0002] With the development of Internet technology, there is an increasing amount of network monitoring data, and the requirements for processing network monitoring data are also getting higher and higher.
[0003] Currently, the processing of network monitoring data generally involves data screening and filtering through a gateway device. Traditional gateway devices filter the data flow in the network according to pre-defined filtering rules, which is difficult to adapt to the complexity of modern network attack technologies. Moreover, as the number of filtering rules continues to increase, the management of filtering rules becomes increasingly complex. Summary of the Invention
[0004] Based on this, in view of the above technical problems, it is necessary to provide a method, apparatus, gateway device, and storage medium for processing network monitoring data that can dynamically generate filtering rules and can automatically learn filtering rules.
[0005] A method for processing network monitoring data, which is applied to a gateway device, and the method includes:
[0006] Receiving a data packet stream of network monitoring data obtained through a service port of a switching component; the data packet stream includes a plurality of data packets in chronological order;
[0007] Determining a processing mode corresponding to the current data packet through an FPGA component;
[0008] When the processing mode of the current data packet is the learning mode, mirroring the current data packet to a CPU component through the FPGA component to obtain a corresponding mirrored data packet;
[0009] Generating an access control list filtering rule corresponding to the current data packet based on the data analysis of the mirrored data packet by the CPU component;
[0010] Sending the generated access control list filtering rule to a user for rule parameter configuration;
[0011] When it is determined according to the rule parameters configured by the user that the access control list filtering rule needs to be sent to the FPGA component, sending the access control list filtering rule to the FPGA component.
[0012] In one embodiment, the generating an access control list filtering rule corresponding to the current data packet based on the data analysis of the mirrored data packet by the CPU component includes:
[0013] The CPU component calls a data packet parsing tool to perform data analysis on the mirror data packet, and obtains a session table entry corresponding to the current data packet;
[0014] Write the session table entry into a database to obtain an updated session table corresponding to the data packet stream where the current data packet is located; the session table includes session table entries corresponding to multiple data packets in the data packet stream;
[0015] Based on the IP address parameter of the session table, perform data processing on the session table entry to obtain a target session table entry;
[0016] According to the five-tuple parameter in the target session table entry, generate an access control list filtering rule corresponding to the data packet.
[0017] In one embodiment, the performing data processing on the session table entry based on the IP address parameter of the session table to obtain a target session table entry includes:
[0018] Call the application program interface of the database, and count the number of session table entries corresponding to each IP address in the session table according to the IP address parameter of the session table;
[0019] Determine the target session table entry according to the number of session table entries corresponding to each IP address.
[0020] In one embodiment, the determining the target session table entry according to the number of session table entries corresponding to each IP address includes:
[0021] Sort the session table entries in descending order according to the number of session table entries corresponding to each IP address to obtain a session table entry sequence;
[0022] Based on the sorting position in the session table entry sequence, filter out the session table entries corresponding to the sorting positions before a preset threshold as the target session table entries.
[0023] In one embodiment, the five-tuple parameter includes a source IP address parameter, a destination IP address parameter, a source port number parameter, a destination port number parameter, and a protocol number parameter.
[0024] In one embodiment, the method further includes:
[0025] When the processing mode corresponding to the current data packet is a forwarding mode, directly forward the current data packet to the switching component through the FPGA component; or
[0026] When the processing mode corresponding to the current data packet is the filtering mode, the FPGA component is used to call the ACL filtering rules stored locally to perform filtering processing on the current data packet.
[0027] In one embodiment, the rule parameters include rule distribution parameters and rule usage parameters; determining whether to distribute the access control list filtering rules to the FPGA component according to the rule parameters includes:
[0028] When the rule distribution parameter is "can distribute" and the rule usage parameter is "can use", the CPU component distributes the access control list filtering rules to the FPGA component;
[0029] The FPGA component performs filtering processing on the current data packet according to the access control list filtering rules, and prohibits mirroring the data packet identical to the current data packet to the CPU component again.
[0030] A processing device for network monitoring data, characterized in that the device includes:
[0031] A data packet receiving module, configured to receive the data packet of the network monitoring data obtained through the service port of the switching component;
[0032] A packet mirroring processing module, configured to determine the processing mode corresponding to the data packet through the FPGA component; and when the processing mode of the data packet is the learning mode, mirror the data packet to the CPU component through the FPGA component to obtain a corresponding mirrored data packet;
[0033] A filtering rule generation module, configured to generate an access control list filtering rule corresponding to the data packet based on the data analysis of the mirrored data packet by the CPU component;
[0034] A rule parameter configuration module, configured to send the generated access control list filtering rule to the user for rule parameter configuration;
[0035] A filtering rule distribution module, configured to determine whether to distribute the access control list filtering rule to the FPGA component according to the rule parameters, so that the FPGA component performs filtering processing on the data packet according to the access control list filtering rule.
[0036] A gateway device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the steps in the above-mentioned method for processing network monitoring data are implemented.
[0037] A computer-readable storage medium stores a computer program thereon, and when the computer program is executed by a processor, the steps in the above-mentioned method for processing network monitoring data are implemented.
[0038] In the above-mentioned method, apparatus, gateway device and storage medium for processing network monitoring data, a data packet stream of network monitoring data is received through a service port of a switching component and reported to an FPGA. The FPGA mirrors the data packets to a CPU in chronological order, and further analyzes the mirrored data packets of the current data packet to generate corresponding access control list filtering rules. Here, in the form of mirrored data packets, the data packets are directly transmitted to the CPU component without copy, and the CPU component directly calls a data packet parsing tool to analyze the mirrored data packets, thereby generating a control list filtering rule corresponding to the data packet, increasing the packet receiving ability of the CPU, being able to automatically learn from the data packets, and dynamically generating filtering rules according to the data packets. By transferring the step of generating filtering rules to the CPU component for execution, the processing speed of the FPGA component is improved. Further, the generated access control list filtering rules are sent to a user for rule parameter configuration. When the user agrees to issue and use the access control list filtering rules, the FPGA component filters the data packets according to the received access control list filtering rules, thereby implementing the processing of network monitoring data. Description of the Drawings
[0039] Figure 1 It is an application scenario diagram of the method for processing network monitoring data in an embodiment;
[0040] Figure 2 It is a schematic flowchart of the method for processing network monitoring data in an embodiment;
[0041] Figure 3 It is a schematic flowchart of the processing steps of network monitoring data in an embodiment;
[0042] Figure 4 It is a schematic flowchart of the method for processing network monitoring data in another embodiment;
[0043] Figure 5 It is a structural block diagram of the apparatus for processing network monitoring data in an embodiment;
[0044] Figure 6 It is an internal structure diagram of a gateway device in an embodiment;
[0045] Figure 7 It is an internal structure diagram of a computer device in an embodiment. Detailed Embodiments
[0046] In order to make the objectives, technical solutions and advantages of the present application more clear and understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0047] The method for processing network monitoring data provided by the present application can be applied to an application environment as Figure 1 shown. The method for processing network monitoring data is applied to a system for processing network monitoring data. The system for processing network monitoring data includes a switching component 102, an FPGA component 104, and a CPU component 106. The switching component 102 includes service ports; the switching component 102 is connected to the FPGA component 104, and the FPGA component 104 is connected to the CPU component 106; the connection method can be a network connection or a wired connection. The switching component is mainly used to obtain data packets of network monitoring data and implement the two-layer and three-layer forwarding functions of data packets; the FPGA component includes an FPGA chip, a ternary content addressable memory (TCAM), and a DDR memory. The TCAM is mainly used to quickly search access control list (ACL) filtering rules; the CPU component is responsible for the software and hardware initialization of the entire system, implements control management, switching, and security function management. The CPU component provides a PCIE bus to connect to the FPGA chip to implement the management function of the module. The CPU component also provides a user configuration interface, which can be in the form of a web browser. Users can configure various access control list filtering rule parameters for the FPGA component through this interface, so as to implement functions such as filtering, monitoring, and forwarding of data packets specified by users.
[0048] In one embodiment, as Figure 2 shown, a method for processing network monitoring data is provided. Taking the application of this method to a gateway device as an example, the method includes the following steps:
[0049] Step 202, receiving a data packet stream of network monitoring data obtained through the service port of the switching component; the data packet stream includes multiple data packets in chronological order.
[0050] The service port is an interface provided to the service end connected to the gateway device. Through the service port, data packets of network monitoring data monitored by the gateway device can be obtained.
[0051] The data packet stream includes multiple data packets in chronological order. The data packets are sequentially transmitted to the switching component through the service port in chronological order, and the switching component reports them to the FPAG component in sequence.
[0052] Step 204, determining the processing mode corresponding to the current data packet through the FPGA component.
[0053] In one embodiment, the FPGA can obtain the rule parameters configured by the user through the interface of the CPU component to determine the processing mode corresponding to the current data packet, or directly determine the processing mode of the current data packet according to the correspondence between the data packets and the processing modes stored in itself.
[0054] Step 206: When the processing mode of the current data packet is the learning mode, mirror the current data packet to the CPU component through the FPGA component to obtain a corresponding mirrored data packet.
[0055] The processing modes include a forwarding mode, a filtering mode, and a learning mode.
[0056] The mirrored data packet refers to copying a data packet in the FPGA component to the CPU component for data packet parsing and processing.
[0057] Specifically, the FPGA component sequentially receives the data packets reported by the switching component and determines the processing mode corresponding to the data packets. When the processing mode corresponding to the current data packet is the learning mode, mirror the current data packet to the CPU component to obtain a corresponding mirrored data packet.
[0058] In one embodiment, when the processing mode corresponding to the current data packet is the forwarding mode, directly forward the current data packet to the switching component through the FPGA component.
[0059] In one embodiment, when the processing mode corresponding to the current data packet is the filtering mode, call the ACL filtering rules stored locally by the FPGA component to filter the current data packet. For example, if the ACL rule matched by the current data packet is to discard, the FPAG discards the data packet.
[0060] Step 208: Generate an access control list filtering rule corresponding to the current data packet based on the data analysis of the mirrored data packet by the CPU component.
[0061] The access control list filtering rule, that is, the ACL filtering rule, refers to the matching rule for processing data packets. When the matched ACL filtering rule is to save the data packet, save the current data packet.
[0062] In one embodiment, generating an access control list filtering rule corresponding to the current data packet based on the data analysis of the mirror data packet by the CPU component includes: invoking a data packet parsing tool by the CPU component to perform data analysis on the mirror data packet to obtain a session table entry corresponding to the current data packet; writing the session table entry into a database to obtain an updated session table corresponding to the data packet stream where the current data packet is located; the session table includes session table entries corresponding to multiple data packets in the data packet stream; performing data processing on the session table entries based on the IP address parameters of the session table to obtain target session table entries; and generating an access control list filtering rule corresponding to the data packet according to the five-tuple parameters in the target session table entry.
[0063] The data packet parsing tool can be a DPI tool, a DPI tool developed by the Network Research Group of the University of Waikato in New Zealand. The biggest feature is that it can perform traffic classification using only 4 bytes of payload data, saving storage space and reducing the infringement of personal privacy by DPI technology to a certain extent.
[0064] A session table entry refers to the identifying content in a session data. For example, the protocol for accessing a website is the http protocol. Then the identifying content of this session data is the source IP, destination IP, protocol number TCP, source port number, destination port number, etc. The session table entry contains a hash value, source IP address parameter, destination IP address parameter, source port number parameter, destination port number parameter, and protocol number parameter.
[0065] The session table includes session table entries corresponding to multiple data packets in the same data packet stream, and each data packet stream has a corresponding session table.
[0066] Specifically, the CPU component receives the mirror data packet mirrored from the FPGA, invokes the DPI tool to analyze and process the current mirror data packet, and parses out the identifying content that can characterize the data packet to obtain a session table entry corresponding to the current data packet. The CPU continuously receives the mirror data packet mirrored from the FPGA and invokes the DPI to parse and generate corresponding session table entries. To better manage the data and facilitate the maintenance of the rules, the currently generated session table entries are written into the session table of the sqlite database corresponding to the data packet stream to obtain an updated session table corresponding to the data packet stream. Furthermore, the CPU component performs data statistics on the session table entries in the entire session table according to the IP address parameters, and determines the target session table entry corresponding to the session table according to the statistical results.
[0067] In one embodiment, the ACL filtering rules generated in the CPU component are stored in a database to obtain an ACL filtering rule table. According to the five-tuple parameters in the target session entry, generating the access control list filtering rule corresponding to the current data packet may be that the CPU component extracts the five-tuple parameters of the target session entry from the session table and copies them to the ACL filtering rule table, thereby generating the ACL filtering rule corresponding to the current data packet.
[0068] In one embodiment, based on the IP address parameters of the session table, performing data processing on the session entries to obtain target session entries includes: calling the application program interface of the database, and counting the number of session entries corresponding to each IP address in the session table according to the IP address parameters of the session table; determining the target session entries according to the number of session entries corresponding to each IP address.
[0069] Specifically, the CPU component calls the application program interface in the sqlite database, and counts each session entry in the session table according to the IP address parameters in the session table to obtain the number of session entries corresponding to each IP address parameter, and then determines the target session entry corresponding to the session table. The CPU component uses the database to store session entries; it is convenient for quick retrieval, statistics, and query. Calling the database interface function realizes functions such as creating a session entry database file, adding session entries, deleting session entries, clearing session entries, and ranking according to IP addresses.
[0070] In one embodiment, determining the target session entries according to the number of session entries corresponding to each IP address includes: sorting the session entries in descending order according to the number of session entries corresponding to each IP address to obtain a session entry sequence; based on the sorting positions in the session entry sequence, screening the session entries corresponding to the sorting positions before the preset threshold as the target session entries.
[0071] In one embodiment, determining the target session entries according to the number of session entries corresponding to each IP address includes: sorting the session entries in ascending order according to the number of session entries corresponding to each IP address to obtain a session entry sequence; based on the sorting positions in the session entry sequence, screening the session entries corresponding to the sorting positions after the preset threshold as the target session entries.
[0072] The preset threshold is set based on historical experience or can also be set by the user. The preset threshold can take 21.
[0073] In one embodiment, the five-tuple parameters include a source IP address parameter, a destination IP address parameter, a source port number parameter, a destination port number parameter, and a protocol number parameter.
[0074] Step 210: Send the generated access control list filtering rules to the user for rule parameter configuration.
[0075] The CPU component transmits the generated ACL filtering rules to the user through the user configuration interface for rule parameter configuration. For example, the user configuration interface can be a WEB browser. The CPU component displays the ACL filtering rules on the user interface of the WEB browser for the user to view, set, and view the learned ACL filtering rules, etc.
[0076] As Figure 3 shown, a schematic diagram of rule parameter configuration is shown. The figure shows the automatic learning mode of the ACL filtering rules; among them, this mode corresponds to the enable / disable function and the setting function; enabling means using the automatic learning mode, and disabling means not using the automatic learning mode. The figure also shows the parameters of the ACL filtering rules, such as the sequence number (rule id), source IP address parameter (sip), destination IP address parameter (dip), source port number parameter (sport), destination port number parameter (dport), protocol number parameter (protocol), distribution parameter (action), and usage parameter (enabled). When the automatic learning mode parameter of the ACL filtering rule is disabled, that is, when the user wants to close the learning mode, it is necessary to clear the ACL rules in the FPGA that were previously used to prevent duplicate data packets from being mirrored to the CPU component.
[0077] Step 212: When it is determined according to the rule parameters configured by the user that the access control list filtering rules need to be sent to the FPGA component, send the access control list filtering rules to the FPGA component.
[0078] In one embodiment, the rule parameters include rule distribution parameters and rule usage parameters; determining whether to send the access control list filtering rules to the FPGA component according to the rule parameters includes: when the rule distribution parameter is "can be distributed" and the rule usage parameter is "can be used", the CPU component sends the access control list filtering rules to the FPGA component; the FPGA component filters the current data packet according to the access control list filtering rules and prohibits the same data packet as the current data packet from being mirrored to the CPU component again.
[0079] In this way, when the CPU component calls the data packet parsing tool and learns a valid packet, it generates the corresponding ACL filtering rule and sends the ACL filtering rule to the FPGA component, so that the FPGA component filters the current data packet according to the ACL filtering rule learned in real time, improving the processing accuracy of the data report; furthermore, the FPGA does not mirror the data packets received after the current data packet in the data packet stream to the CPU component, reducing the packet receiving burden of the CPU component, and then improving the parsing speed of the CPU component for the mirrored data packets, thus accelerating the processing speed of the network monitoring data.
[0080] In the above method for processing network monitoring data, the data packet stream of the network monitoring data is received through the service port of the switching component and reported to the FPGA. The FPGA mirrors the data packets to the CPU in chronological order, and further analyzes the mirrored data packets of the current data packet to generate the corresponding access control list filtering rules; here, in the form of mirroring the data packets, the data packets are directly transmitted to the CPU component without copy. The CPU component directly calls the data packet parsing tool to analyze the mirrored data packets, so as to generate the control list filtering rules corresponding to the data packets, increasing the packet receiving ability of the CPU, which can automatically learn from the data packets and dynamically generate filtering rules according to the data packets. By transferring the step of generating the filtering rules to the CPU component for execution, the processing speed of the FPGA component is improved. Further, the generated access control list filtering rules are sent to the user for rule parameter configuration. When the user agrees to send down and use the access control list filtering rules, the FPGA component filters the data packets according to the received access control list filtering rules, so as to realize the processing of the network monitoring data.
[0081] In one embodiment, as Figure 4As shown, a schematic diagram of the processing flow of network monitoring data is presented. As shown in the figure, the data packet stream of network monitoring data is obtained through the service port of the switching component, that is, the data stream in the figure. Furthermore, the obtained data stream is sent to the FPGA component. The FPGA processes the data packets in the received data stream and processes the current data packet according to the processing mode corresponding to the data packet in the data stream. When the processing mode is the forwarding mode, the received data packet is directly forwarded to the switching component. When the processing mode is the filtering mode, the ACL filtering rules stored locally in the FPGA component are called to filter the received data packet. When the processing mode is the learning mode, the received data packet is mirrored to the CPU component, and the data packet parsing tool is called by the CPU component to process the mirrored data packet, generate the corresponding session entry, and write the session entry into the database to obtain the session table. Currently, it supports creating 3000 session entries per second and 10000 concurrent sessions. Further, the application programming interface API in the database is called to perform data statistics on the session entries according to the IP address parameter, thereby obtaining the session entry ranking and displaying it in the WEB browser. At the same time, the CPU component counts the number of session entries according to the protocol number parameter in the session table and displays it in the WEB browser. The CPU component determines the target session entry according to the session entry ranking, and then generates the ACL filtering rule corresponding to the current data packet according to the five-tuple parameter of the target session entry, thereby dynamically generating the corresponding ACL filtering rule and sending the filtering rule to the FPGA to update the ACL filtering rules stored locally in the FPGA.
[0082] In one embodiment, as Figure 5 shown, a schematic diagram of the processing hardware of network monitoring data is presented. As shown in the figure, KD5760 is a switching chip, KD3004 is the physical port of the switching chip, and SGMII is the connection between the switching chip and the physical port. DDR is the memory, LS2K is the CPU, and ETH, PCIE, and XAUI are all communication interfaces, and ETH is the network card interface.
[0083] It should be understood that although Figure 2 the steps in the flowchart of Figure 2 are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover,
[0084] In one embodiment, as Figure 5 shown, a processing device 500 for network monitoring data is provided, including: a data packet receiving module 502, a packet mirroring processing module 504, a filtering rule generation module 506, a rule parameter configuration module 508, and a filtering rule distribution module 510, where:
[0085] The data packet receiving module 502 is configured to receive data packets of network monitoring data obtained through a service port of a switching component.
[0086] The packet mirroring processing module 504 is configured to determine a processing mode corresponding to the data packet through an FPGA component; and when the processing mode of the data packet is a learning mode, mirror the data packet to a CPU component through the FPGA component to obtain a corresponding mirrored data packet.
[0087] The filtering rule generation module 506 is configured to generate an access control list filtering rule corresponding to the data packet based on data analysis of the mirrored data packet by the CPU component.
[0088] The rule parameter configuration module 508 is configured to send the generated access control list filtering rule to a user for rule parameter configuration.
[0089] The filtering rule distribution module 510 is configured to, when it is determined according to rule parameters configured by the user that the access control list filtering rule needs to be distributed to the FPGA component, distribute the access control list filtering rule to the FPGA component.
[0090] In one embodiment, the filtering rule generation module is further configured to call a data packet parsing tool through the CPU component to perform data analysis on the mirrored data packet to obtain a session table entry corresponding to the current data packet; write the session table entry into a database to obtain an updated session table corresponding to the data packet stream where the current data packet is located; the session table includes session table entries corresponding to multiple data packets in the data packet stream; perform data processing on the session table entries based on IP address parameters of the session table to obtain target session table entries; and generate an access control list filtering rule corresponding to the current data packet according to five-tuple parameters in the target session table entries.
[0091] In one embodiment, the filtering rule generation module is further configured to call an application program interface of the database, count the number of session table entries corresponding to each IP address in the session table according to IP address parameters of the session table; and determine target session table entries according to the number of session table entries corresponding to each IP address.
[0092] In one embodiment, the filtering rule generation module is further configured to sort the session table entries in descending order according to the number of session table entries corresponding to each IP address, so as to obtain a session table entry sequence; and based on the sorting positions in the session table entry sequence, filter out the session table entries corresponding to the sorting positions before a preset threshold as target session table entries.
[0093] In one embodiment, the five-tuple parameters include a source IP address parameter, a destination IP address parameter, a source port number parameter, a destination port number parameter, and a protocol number parameter.
[0094] In one embodiment, the apparatus further includes a forwarding and filtering data processing module, configured to, when the processing mode corresponding to the current data packet is the forwarding mode, directly forward the current data packet to the switching component through the FPGA component; or when the processing mode corresponding to the current data packet is the filtering mode, call the ACL filtering rules stored locally by the FPGA component to perform filtering processing on the current data packet.
[0095] In one embodiment, the rule parameters include a rule distribution parameter and a rule usage parameter; the filtering rule distribution module is further configured to, when the rule distribution parameter is "can distribute" and the rule usage parameter is "can use", distribute the access control list filtering rules to the FPGA component through the CPU component; and make the FPGA component perform filtering processing on the current data packet according to the access control list filtering rules, and prohibit mirroring the data packet identical to the current data packet to the CPU component again.
[0096] In the present embodiment, the data packet stream of the network monitoring data is received through the service port of the switching component and reported to the FPGA. The data packets are mirrored to the CPU in chronological order by the FPGA, and further, data analysis is performed on the mirrored data packets of the current data packet to generate corresponding access control list filtering rules. Here, in the form of mirroring the data packets, the data packets are directly transmitted to the CPU component without copy. The CPU component directly calls the data packet parsing tool to perform data analysis on the mirrored data packets, so as to generate the control list filtering rules corresponding to the data packets, which increases the packet receiving capacity of the CPU, can automatically learn from the data packets, and can dynamically generate filtering rules according to the data packets. By transferring the step of generating the filtering rules to the CPU component for execution, the processing speed of the FPGA component is improved. Further, the generated access control list filtering rules are sent to the user for configuring the rule parameters. When the user agrees to distribute and use the access control list filtering rules, the FPGA component performs filtering processing on the data packets according to the received access control list filtering rules, so as to implement the processing of the network monitoring data.
[0097] For the specific limitations of the processing device for network monitoring data, reference can be made to the limitations of the processing method for network monitoring data in the foregoing text, which will not be elaborated herein. Each module in the above-mentioned processing device for network monitoring data can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in the processor in the gateway device in hardware form or be independent of it, or can be stored in the memory in the gateway device in software form, so as to facilitate the processor to call and execute the operations corresponding to each of the above modules.
[0098] In one embodiment, a gateway device is provided. The gateway device can be a terminal, and its internal structural diagram can be as Figure 7 shown. The gateway device includes a processor, a memory, a network interface, a display screen, and an input device connected through a system bus. Among them, the processor of the gateway device is used to provide computing and control capabilities. The memory of the gateway device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the gateway device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a method for processing network monitoring data. The display screen of the gateway device can be a liquid crystal display screen or an electronic ink display screen. The input device of the gateway device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the outer shell of the gateway device, or an external keyboard, a touchpad, or a mouse, etc.
[0099] Those skilled in the art can understand that Figure 7 the structure shown in
[0100] In one embodiment, a gateway device is provided, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented: receiving a data packet stream of network monitoring data obtained through a service port of a switching component; the data packet stream includes multiple data packets in chronological order; determining a processing mode corresponding to the current data packet through an FPGA component; when the processing mode of the current data packet is the learning mode, mirroring the current data packet into a CPU component through the FPGA component to obtain a corresponding mirrored data packet; generating an access control list filtering rule corresponding to the current data packet based on the data analysis of the mirrored data packet by the CPU component; sending the generated access control list filtering rule to a user for rule parameter configuration; and when it is determined according to the rule parameters configured by the user that the access control list filtering rule needs to be sent to the FPGA component, sending the access control list filtering rule to the FPGA component.
[0101] In one embodiment, when the processor executes the computer program, the following steps are further implemented: calling a data packet parsing tool through the CPU component to perform data analysis on the mirrored data packet to obtain a session table entry corresponding to the current data packet; writing the session table entry into a database to obtain an updated session table corresponding to the data packet stream where the current data packet is located; the session table includes session table entries corresponding to multiple data packets in the data packet stream; performing data processing on the session table entries based on the IP address parameters of the session table to obtain target session table entries; and generating an access control list filtering rule corresponding to the current data packet according to the five-tuple parameters in the target session table entry.
[0102] In one embodiment, when the processor executes the computer program, the following steps are further implemented: calling an application program interface of the database, and counting the number of session table entries corresponding to each IP address in the session table according to the IP address parameters of the session table; and determining target session table entries according to the number of session table entries corresponding to each IP address.
[0103] In one embodiment, when the processor executes the computer program, the following steps are further implemented: sorting the session table entries in descending order according to the number of session table entries corresponding to each IP address to obtain a session table entry sequence; and screening the session table entries corresponding to the sorting positions before a preset threshold based on the sorting positions in the session table entry sequence as target session table entries.
[0104] In one embodiment, when the processor executes the computer program, the following steps are further implemented: when the processing mode corresponding to the current data packet is the forwarding mode, directly forwarding the current data packet to the switching component through the FPGA component; or when the processing mode corresponding to the current data packet is the filtering mode, calling an ACL filtering rule stored locally by the FPGA component to perform filtering processing on the current data packet.
[0105] In one embodiment, when the processor executes the computer program, the following steps are further implemented: when the rule distribution parameter is capable of distribution and the rule usage parameter is capable of usage, the access control list filtering rule is distributed to the FPGA component through the CPU component; the FPGA component filters the current data packet according to the access control list filtering rule, and prohibits mirroring the data packet identical to the current data packet to the CPU component again.
[0106] In this embodiment, the data packet stream of the network monitoring data is received through the service port of the switching component and reported to the FPGA. The data packets are mirrored to the CPU in chronological order by the FPGA, and further data analysis is performed on the mirrored data packets of the current data packet to generate the corresponding access control list filtering rules; here, in the form of mirroring the data packets, the data packets are directly transmitted to the CPU component without copy. The CPU component directly calls the data packet parsing tool to perform data analysis on the mirrored data packets, thereby generating the control list filtering rules corresponding to the data packets, increasing the packet receiving ability of the CPU, being able to automatically learn from the data packets, and dynamically generating filtering rules according to the data packets. By transferring the step of generating the filtering rules to the CPU component for execution, the processing speed of the FPGA component is improved. Further, the generated access control list filtering rules are sent to the user for configuring the rule parameters. When the user agrees to distribute and use the access control list filtering rule, the FPGA component filters the data packets according to the received access control list filtering rule, thereby implementing the processing of the network monitoring data.
[0107] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented: receiving the data packet stream of the network monitoring data obtained through the service port of the switching component; the data packet stream includes a plurality of data packets in chronological order; determining the processing mode corresponding to the current data packet through the FPGA component; when the processing mode of the current data packet is the learning mode, mirroring the current data packet to the CPU component through the FPGA component to obtain the corresponding mirrored data packet; generating the access control list filtering rule corresponding to the current data packet based on the data analysis of the mirrored data packet by the CPU component; sending the generated access control list filtering rule to the user for configuring the rule parameters; when it is determined according to the rule parameters configured by the user that the access control list filtering rule needs to be distributed to the FPGA component, distributing the access control list filtering rule to the FPGA component.
[0108] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: calling a data packet parsing tool by a CPU component to perform data analysis on the mirrored data packet to obtain a session table entry corresponding to the current data packet; writing the session table entry into a database to obtain an updated session table corresponding to the data packet stream where the current data packet is located; the session table includes session table entries corresponding to multiple data packets in the data packet stream; performing data processing on the session table entries based on the IP address parameter of the session table to obtain target session table entries; generating an access control list filtering rule corresponding to the current data packet according to the five-tuple parameter in the target session table entry.
[0109] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: calling an application program interface of a database, and counting the number of session table entries corresponding to each IP address in the session table according to the IP address parameter of the session table; determining target session table entries according to the number of session table entries corresponding to each IP address.
[0110] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: sorting the session table entries in descending order according to the number of session table entries corresponding to each IP address to obtain a session table entry sequence; screening the session table entries corresponding to the sorting positions before a preset threshold based on the sorting positions in the session table entry sequence as target session table entries.
[0111] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: when the processing mode corresponding to the current data packet is a forwarding mode, directly forwarding the current data packet to a switching component through an FPGA component; or when the processing mode corresponding to the current data packet is a filtering mode, calling an ACL filtering rule stored locally by the FPGA component to perform filtering processing on the current data packet.
[0112] In one embodiment, when the rule distribution parameter is "can distribute" and the rule usage parameter is "can use", the access control list filtering rule is distributed to the FPGA component through the CPU component; the FPGA component performs filtering processing on the current data packet according to the access control list filtering rule and prohibits mirroring the data packet identical to the current data packet to the CPU component again.
[0113] In this embodiment, the data packet stream of network monitoring data is received through the service ports of the switching components and reported to the FPGA. The FPGA mirrors the data packets to the CPU in chronological order, and further analyzes the mirrored data packets of the current data packets to generate corresponding access control list filtering rules. Here, in the form of mirrored data packets, the data packets are directly transmitted to the CPU component without copying, and the CPU component directly calls the data packet parsing tool to analyze the mirrored data packets, so as to generate the control list filtering rules corresponding to the data packets. This increases the packet receiving ability of the CPU, can automatically learn from the data packets, and can dynamically generate filtering rules according to the data packets. By transferring the step of generating filtering rules to the CPU component for execution, the processing speed of the FPGA component is improved. Further, the generated access control list filtering rules are sent to the user for rule parameter configuration. When the user agrees to issue and use the access control list filtering rules, the FPGA component filters the data packets according to the received access control list filtering rules, so as to realize the processing of network monitoring data.
[0114] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0115] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as these technical feature combinations do not conflict, they should be considered as the scope recorded in this specification.
[0116] The above embodiments only represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several deformations and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.
Claims
1. A method for processing network monitoring data, which is applied in a gateway device, and the method includes: Receiving a data packet stream of network monitoring data obtained through a service port of a switching component; The data packet stream includes multiple data packets in chronological order; Determining a processing mode corresponding to the current data packet through an FPGA component; When the processing mode of the current data packet is the learning mode, mirroring the current data packet to a CPU component through the FPGA component to obtain a corresponding mirrored data packet; Generating an access control list filtering rule corresponding to the current data packet based on the data analysis of the mirrored data packet by the CPU component; Sending the generated access control list filtering rule to a user for rule parameter configuration; When it is determined according to the rule parameters configured by the user that the access control list filtering rule needs to be sent to the FPGA component, sending the access control list filtering rule to the FPGA component.
2. The method according to claim 1, wherein The generating an access control list filtering rule corresponding to the current data packet based on the data analysis of the mirrored data packet by the CPU component includes: Invoking a data packet parsing tool by the CPU component to perform data analysis on the mirrored data packet to obtain a session table entry corresponding to the current data packet; Writing the session table entry into a database to obtain an updated session table corresponding to the data packet stream where the current data packet is located; the session table includes session table entries corresponding to multiple data packets in the data packet stream; Performing data processing on the session table entries based on the IP address parameters of the session table to obtain target session table entries; Generating an access control list filtering rule corresponding to the current data packet according to the five-tuple parameters in the target session table entry.
3. The method according to claim 2, wherein The performing data processing on the session table entries based on the IP address parameters of the session table to obtain target session table entries includes: Invoking an application program interface of the database, and counting the number of session table entries corresponding to each IP address in the session table according to the IP address parameters of the session table; Determining target session table entries according to the number of session table entries corresponding to each IP address.
4. The method according to claim 3, wherein The determining target session table entries according to the number of session table entries corresponding to each IP address includes: Sorting the session table entries in descending order according to the number of session table entries corresponding to each IP address to obtain a session table entry sequence; Based on the sorting positions in the session table entry sequence, screening the session table entries corresponding to the sorting positions before a preset threshold as target session table entries; or Sorting the session table entries in ascending order according to the number of session table entries corresponding to each IP address to obtain a session table entry sequence; Based on the sorting positions in the session table entry sequence, screening the session table entries corresponding to the sorting positions after a preset threshold as target session table entries.
5. The method according to any one of claims 2 to 4, characterized in that, The five-tuple parameters include a source IP address parameter, a destination IP address parameter, a source port number parameter, a destination port number parameter, and a protocol number parameter.
6. The method according to claim 1, wherein The method further includes: When the processing mode corresponding to the current data packet is the forwarding mode, the current data packet is directly forwarded to the switching component through the FPGA component; or When the processing mode corresponding to the current data packet is the filtering mode, the FPGA component is used to call the ACL filtering rules stored locally to perform filtering processing on the current data packet.
7. The method according to claim 1, wherein The rule parameters include rule distribution parameters and rule usage parameters; determining whether to distribute the access control list filtering rules to the FPGA component according to the rule parameters includes: When the rule distribution parameter is "can distribute" and the rule usage parameter is "can use", the CPU component distributes the access control list filtering rules to the FPGA component; The FPGA component performs filtering processing on the current data packet according to the access control list filtering rules, and prohibits mirroring the data packet identical to the current data packet to the CPU component again.
8. A processing device for network monitoring data, characterized in that, The device includes: A data packet receiving module, configured to receive a data packet of network monitoring data obtained through a service port of the switching component; A packet mirroring processing module, configured to determine the processing mode corresponding to the data packet through the FPGA component; and when the processing mode of the data packet is the learning mode, mirror the data packet to the CPU component through the FPGA component to obtain a corresponding mirrored data packet; A filtering rule generation module, configured to generate an access control list filtering rule corresponding to the data packet based on the data analysis of the mirrored data packet by the CPU component; A rule parameter configuration module, configured to send the generated access control list filtering rule to the user for rule parameter configuration; A filtering rule distribution module, configured to determine whether to distribute the access control list filtering rules to the FPGA component according to the rule parameters, so that the FPGA component performs filtering processing on the data packet according to the access control list filtering rules.
9. A gateway device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Data memory mapping method and device, electronic equipment and storage medium
CN113835831A
Method and device for generating filtering rule of data packet, system, equipment and medium
CN114826775A