A packet capturing method and device, electronic equipment and storage medium
By acquiring all data packets in the network data stream and determining packet capture rules based on feature information, the problem of decreased packet capture efficiency and accuracy caused by a significant increase in network traffic is solved, achieving efficient and accurate acquisition of traffic analysis data.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING ANBOTONG TECH CO LTD
- Filing Date
- 2023-05-23
- Publication Date
- 2026-04-28
AI Technical Summary
With a significant increase in network traffic, packet capture devices struggle to efficiently acquire the traffic analysis data required by users, leading to a decrease in packet capture efficiency and accuracy.
By acquiring all data packets in the network data stream, at least one target packet capture rule is determined based on feature information and filtering rules to form a packet capture strategy, thereby reducing the packet capture process and improving packet capture efficiency and accuracy.
This ensures the integrity and accuracy of the captured packets, improves packet capture efficiency, and enhances the system's business recognition capabilities.
Smart Images

Figure CN116545878B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computers, and more particularly to a packet capture method and apparatus, electronic device and storage medium. Background Technology
[0002] As network traffic becomes increasingly complex, it surges during peak hours, making enterprise-level network traffic monitoring and analysis increasingly difficult. Enterprises and operations personnel often lack a clear understanding of the actual network traffic conditions at various interfaces, as well as traffic analysis data such as MAC (Media Access Control) and IP (Internet Protocol) addresses, making traffic analysis extremely challenging. Traffic analysis data often requires packet capture to obtain.
[0003] In related technologies, traffic analysis data is typically acquired by capturing packets from all traffic data to determine the traffic analysis data that meets the user's needs. However, due to the increasing volume of network traffic, packet capture devices need to capture even more packets to obtain the traffic analysis data required by the user, resulting in decreasing efficiency in acquiring traffic analysis data. Summary of the Invention
[0004] This application provides a packet capture method that can increase the bandwidth during service processing, making the system's service identification capability more extensive, while ensuring the accuracy of packet capture.
[0005] To achieve the above objectives, the embodiments of this application adopt the following technical solutions:
[0006] Firstly, a packet capture method is provided, comprising: acquiring all data packets in a network data stream; wherein the data packets include messages containing characteristic information, the characteristic information including: source address parameters, destination address parameters, transport layer protocol, application layer protocol, and application name; determining a packet capture strategy consisting of at least one target packet capture rule from multiple packet capture rules based on the characteristic information and filtering rules; wherein the multiple packet capture rules include any one or more of the following: packet capture based on source address parameters, packet capture based on destination address parameters, packet capture based on transport layer protocol, packet capture based on application layer protocol, and packet capture based on application name; the source address parameters include source MAC, source IP, and source port, and the destination address parameters include destination MAC, destination IP, and destination port; and acquiring the target data packet from all data packets according to the packet capture strategy.
[0007] In conjunction with the first aspect, in another possible implementation, the target packet capture rule is determined from multiple packet capture rules based on feature information and filtering rules, including: converting multiple packet capture rules into a first feature vector; converting feature information in multiple data packets into a second feature vector; and determining at least one target packet capture rule from multiple packet capture rules based on the second feature vector and the first feature vector.
[0008] In conjunction with the first aspect, in another possible implementation, the target data packet is obtained from all data packets according to the packet capture strategy, including: when the packet capture mode is the first mode, the data packets that conform to the target packet capture rules are identified as the target data packets, and other data packets are discarded; when the packet capture mode is the second mode, the data packets that do not conform to the target packet capture rules are identified as the target data packets, and other data packets are discarded.
[0009] In conjunction with the first aspect, in another possible implementation, when the packet capture strategy includes at least two target packet capture rules, the target packet is obtained from all packets according to the packet capture strategy, including: if the packet does not conform to any of the target packet capture rules, the packet is discarded; if the packet conforms to all the target packet capture rules, the target packet is obtained from all packets according to the packet capture strategy and a first direction; wherein, the first direction is that the packet is sent from the data source device indicated by the source address parameter to the destination device indicated by the destination address parameter.
[0010] In conjunction with the first aspect, in another possible implementation, if a data packet does not conform to any target packet capture rule, the data packet is discarded, including: if no bidirectional instruction is received, the data packet is discarded if the data packet does not conform to any target packet capture rule; wherein the bidirectional instruction is used to indicate the packet capture direction of the packet capture strategy, including a first direction and a second direction, and the second direction is the opposite direction of the first direction;
[0011] In conjunction with the first aspect, in another possible implementation, if the data packet does not conform to any target packet capture rule, the method further includes: if a bidirectional instruction is received, then the target data packet is obtained from the data packet according to the packet capture strategy and the second direction.
[0012] In conjunction with the first aspect, in another possible implementation, the method further includes: merging data packets with the same 5-tuple information into a stream; obtaining the target stream from all streams according to the target packet capture rules related to the 5-tuple information in the packet capture strategy; and obtaining the target data packets from the target stream according to the target packet capture rules not related to the 5-tuple information in the packet capture strategy.
[0013] In conjunction with the first aspect, in another possible implementation, determining at least one target packet capture rule from multiple packet capture rules based on feature information and filtering rules to obtain a packet capture strategy composed of at least one target packet capture rule includes: determining at least one target packet capture rule from multiple packet capture rules based on feature information and filtering rules; receiving a rule adjustment instruction and adjusting the target packet capture rule in response to the rule adjustment instruction; and obtaining the packet capture strategy based on the target packet capture rule.
[0014] Secondly, a bag-catching device is provided, which has the function of implementing the method of the first aspect described above. This function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-described function.
[0015] Thirdly, a packet capture device is provided, comprising a receiving module for acquiring all data packets in a network data stream; wherein the data packets include messages containing characteristic information, including: source address parameters, destination address parameters, transport layer protocol, application layer protocol, and application name; a policy matching module for determining at least one target packet capture rule from multiple packet capture rules based on the characteristic information contained in the messages in the data packets acquired by the receiving module and filtering rules, to obtain a packet capture strategy composed of at least one target packet capture rule; wherein the multiple packet capture rules include any one or more of the following: packet capture based on source address parameters, packet capture based on destination address parameters, packet capture based on transport layer protocol, packet capture based on application layer protocol, and packet capture based on application name; the source address parameters include source MAC, source IP, and source port, and the destination address parameters include destination MAC, destination IP, and destination port; the packet capture module is used to acquire the target data packet from the data packets acquired by the receiving module according to the packet capture strategy obtained by the policy matching module.
[0016] Fourthly, a packet capture device is provided, comprising: a processor and a memory; the memory is used to store computer execution instructions, and when the first device is running, the processor executes the computer execution instructions stored in the memory to cause the first device to perform the packet capture method provided in any of the first aspects above.
[0017] Fifthly, a computer-readable storage medium is provided that stores instructions which, when executed on a computer, enable the computer to perform the packet capture method provided in any of the first aspects above.
[0018] In a sixth aspect, a computer program product containing instructions is provided, which, when run on a packet capture device, enables the packet capture device to execute the packet capture method provided in any of the first aspects above.
[0019] In a seventh aspect, an apparatus (e.g., a chip system) is provided, comprising a processor for supporting a packet capture device in performing the functions described in the first aspect above. In one possible design, the apparatus further comprises a memory for storing program instructions and data necessary for the packet capture device. When the apparatus is a chip system, it may be composed of chips or may include chips and other discrete devices.
[0020] Based on the technical solution provided in this application embodiment, firstly, the packet capture device acquires all data packets in the network data stream, enabling all data packets to participate in the subsequent packet capture process. That is, all data packets may be captured as packet capture objects in the subsequent packet capture process, ensuring the integrity and accuracy of the captured objects. Secondly, at least one target packet capture rule is determined from multiple packet capture rules according to feature information and filtering rules to obtain a packet capture strategy composed of at least one packet capture rule. This allows for the determination of at least one most suitable target packet capture rule from multiple packet capture rules based on differentiated feature information. Since each packet capture rule corresponds to one packet capture process, determining at least one target packet capture rule from multiple packet capture rules according to feature information and filtering rules can reduce the number of packet capture processes and improve packet capture efficiency. Finally, the target data packet is acquired from all data packets according to the packet capture strategy, completing the packet capture process and ensuring the accuracy of packet capture.
[0021] In summary, the technical solution provided by the embodiments of this application can ensure the integrity and accuracy of the captured object and improve the capture efficiency. Attached Figure Description
[0022] Figure 1 This is a schematic diagram of the software architecture of a packet-catching device provided in an embodiment of this application;
[0023] Figure 2 A flowchart of a packet capture method provided in this application embodiment. Figure 1 ;
[0024] Figure 3 A flowchart of a packet capture method provided in this application embodiment. Figure 2 ;
[0025] Figure 4 A flowchart of a packet capture method provided in this application embodiment. Figure 3 ;
[0026] Figure 5 A flowchart of a packet capture method provided in this application embodiment. Figure 4 ;
[0027] Figure 6 A flowchart of a packet capture method provided in this application embodiment. Figure 5 ;
[0028] Figure 7 A flowchart of a packet capture method provided in this application embodiment. Figure 6 ;
[0029] Figure 8 A flowchart of a packet capture method provided in this application embodiment. Figure 7 ;
[0030] Figure 9 A flowchart of a packet capture method provided in this application embodiment. Figure 8 ;
[0031] Figure 10 A schematic diagram illustrating another packet capture method provided in this application embodiment;
[0032] Figure 11 This is a schematic diagram of a packet capture strategy matching provided in an embodiment of this application;
[0033] Figure 12 This is a schematic diagram illustrating a customized packet capture strategy provided in an embodiment of this application.
[0034] Figure 13 This is a schematic diagram of another bag-catching device provided in an embodiment of this application;
[0035] Figure 14 This is a schematic diagram of another bag-catching device provided in an embodiment of this application. Detailed Implementation
[0036] To make the objectives and implementation methods of this application clearer, exemplary implementation methods of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments.
[0037] It should be noted that the brief descriptions of terms in this application are only for the convenience of understanding the embodiments described below, and are not intended to limit the embodiments of this application. Unless otherwise stated, these terms should be understood in their ordinary and common meaning.
[0038] The terms "first," "second," "third," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar or related objects or entities, and do not necessarily imply a specific order or sequence, unless otherwise specified. It should be understood that such terms are interchangeable where appropriate.
[0039] The terms “comprising” and “having” and any variations thereof in this application are intended to cover but not exclude inclusion, for example, a product or device that includes a series of components is not necessarily limited to all the components that are clearly listed, but may include other components that are not clearly listed or that are inherent to such product or device.
[0040] In this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, in this application, the character " / " generally indicates that the preceding and following related objects have an "or" relationship.
[0041] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0042] Based on the embodiments described in this application, all other embodiments obtained by those skilled in the art without inventive effort are within the scope of protection of the appended claims. Furthermore, although the disclosure in this application is based on one or more exemplary examples, it should be understood that each aspect of these disclosures can constitute a complete implementation on its own. It should be noted that the brief descriptions of terminology in this application are only for the convenience of understanding the embodiments described below, and are not intended to limit the implementation of this application. Unless otherwise stated, these terms should be understood in their ordinary and common meaning.
[0043] First, the terms used in this application are explained as follows:
[0044] DPDK stands for Data Plane Development Kit. It's a collection of libraries and toolkits typically used for packet reception and distribution.
[0045] Flow construction: The process of merging data packets with identical 5-tuple information.
[0046] Application identification: The process of identifying which application's client the data stream originates from.
[0047] Links: These include physical links and logical links. A physical link refers to a physical line formed under the action of physical layer devices (including transmission media, physical interfaces, and transceivers, etc.) and corresponding physical layer communication protocols. It is permanent and cannot be deleted (unless physically dismantled). A logical link, on the other hand, is a logical link established by two communicating parties under the action of data link layer devices and corresponding communication protocols when data communication is required. It can be permanent (such as an Ethernet link in a local area network) or non-permanent (such as a link in a wide area network). Whether it is permanent depends on the specific data link layer service type. Unless otherwise specified, all links mentioned in this application are physical links.
[0048] MAC address: Media Access Control address, also known as a local area network address, Ethernet address, or physical layer address, is an address used to identify the location of a network device. A MAC address uniquely identifies a network interface card (NIC) on a network. If a device has one or more NICs, each NIC needs and will have a unique MAC address.
[0049] IP address: also known as Internet Protocol address or network layer address, it is a logical address assigned to every device on the Internet.
[0050] HTTP stands for Hypertext Transfer Protocol, an application layer protocol.
[0051] The quintuple consists of the source IP address, destination IP address, source port, destination port, and transport layer protocol.
[0052] With the rapid development of network technology and the increasing number of internet users, network traffic monitoring and analysis have become extremely important. When conducting traffic monitoring and analysis, enterprises or operations and maintenance personnel need to understand the actual network traffic situation of each interface, as well as traffic analysis data such as MAC addresses and IP address distribution. This traffic analysis data needs to be obtained through packet capture.
[0053] In related technologies, acquiring traffic analysis data typically involves capturing, intercepting, retransmitting, editing, and saving the data packets corresponding to all traffic data – this process is known as packet capture. Obtaining traffic data from data packets through packet capture helps operations and maintenance personnel monitor network traffic and quickly locate and resolve network traffic faults.
[0054] However, as network traffic increases, packet capture devices need to capture more data packets to obtain the traffic analysis data required by users. The packet capture speed cannot match the packet reception speed, resulting in a decrease in the efficiency and accuracy of obtaining traffic analysis data.
[0055] To address the aforementioned issues, this application proposes a packet capture method. Before packet capture begins, the user can first create a link and connect at least one network interface card to the link for DPDK packet reception. Then, the packet capture rules are determined based on the characteristic information of the packets received by the link. For example, the characteristic information of the packets received by the link may include: different source address parameters, different destination address parameters, different transport layer protocols, different application layer protocols, and different application names. As can be seen from the above characteristic information, there are differences in the various characteristic information of the packets received by the link. Therefore, the packet capture device can determine the packet capture rules based on these characteristic information, such as packet capture based on source address parameters, packet capture based on destination address parameters, packet capture based on transport layer protocols, packet capture based on application layer protocols, and packet capture based on application names.
[0056] After packet capture begins, the packet capture device first acquires all data packets in the network data stream, ensuring that all data packets can participate in the subsequent packet capture process. All data packets are potential targets for capture, guaranteeing the integrity of the captured packets. Second, based on feature information and filtering rules, at least one target packet capture rule is determined from multiple packet capture rules to obtain a packet capture strategy consisting of at least one capture rule. This strategy can determine at least one most suitable target packet capture rule from multiple capture rules based on differing feature information. Since each packet capture rule corresponds to one packet capture process, determining at least one target capture rule from multiple capture rules based on feature information and filtering rules reduces the number of capture processes and improves packet capture efficiency. Finally, the target data packet is acquired from all data packets according to the packet capture strategy, completing the packet capture process and ensuring accuracy. Furthermore, the aforementioned packet capture strategy is link-based, meaning that for multiple links, corresponding packet capture strategies can be configured based on the feature information of the received data packets, improving the flexibility of packet capture.
[0057] Figure 1 A schematic diagram of a system architecture for an exemplary application environment in which a packet capture method and apparatus according to embodiments of this application can be applied is shown.
[0058] like Figure 1 As shown, the system architecture 100 applied in the technical solution provided in this application may include at least one terminal device, the Internet 104, and a server 105. Figure 1The example described uses terminal devices 101, 102, and 103 as examples; in practice, there may be more or fewer terminal devices. The Internet 104 serves as the medium providing a communication link between terminal devices 101, 102, 103, and server 105. The Internet 104 can include various connection types, such as wired, wireless communication links, or fiber optic cables. Terminal devices 101, 102, and 103 can be various electronic devices with displays, including but not limited to desktop computers, laptops, smartphones, and tablets. It should be understood that... Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, there can be any number of terminal devices, networks, and servers. For example, server 105 could be a server cluster composed of multiple servers.
[0059] The packet capture method provided in this embodiment can be executed on server 105. For example, server 105 can acquire all data packets in the network data stream, determine a packet capture strategy consisting of at least one target packet capture rule from multiple packet capture rules based on feature information and filtering rules, and acquire the target data packet from all data packets according to the packet capture strategy. The packet capture method provided in this embodiment can also be executed by a terminal device, or it can be jointly executed by a terminal device and server 105. This embodiment does not impose any special limitations on this.
[0060] The network traffic data involved in this application may be data authorized by the user or fully authorized by all parties.
[0061] The methods described in the following embodiments can be implemented in a packet capture device having the above-described hardware and software structures. The packet capture method provided in the embodiments of this application will be described below.
[0062] Reference Figure 2 As shown, this application embodiment provides a packet capture method applied to a packet capture device. The packet capture device has the function of matching corresponding packet capture rules based on the feature information of data packets. The packet capture device can be the server 105 in the above embodiment or a part thereof. The method may include S210-S230:
[0063] S210. Obtain all data packets in the network data stream.
[0064] The network data stream refers to the data stream during network transmission. It consists of multiple data packets, each containing a message with characteristic information. This characteristic information includes: source address parameters, destination address parameters, transport layer protocol, application layer protocol, and application name. Source address parameters may include source MAC address, source IP address, and source port. Destination address parameters may include destination MAC address, destination IP address, and destination port. The source and destination MAC addresses can be obtained through physical layer parsing of the data packets; the source and destination IP addresses can be obtained through network layer parsing; the source and destination ports and transport layer protocol can be obtained through transport layer parsing; the application layer protocol can be obtained through application layer parsing; and the application name can be obtained through application identification module parsing. It is understood that this characteristic information can not only be obtained through parsing the data packets, but it can also be directly written into the data packets during generation so that the packet capture device can read it directly. This application does not impose specific restrictions on the method of obtaining this characteristic information.
[0065] In some examples, users can input multiple packet capture rules into the packet capture device before packet capture begins, based on the characteristic information of the data packets in the network data streams that the network card may output. For example, if the specific sub-parameters of the characteristic information in all possible network data streams output by the network card include: source address parameters A and B, destination address parameters C and D, transport layer protocol E and F, application layer protocol G and H, and application name I and J, the user can input ten packet capture rules into the packet capture device based on the specific content of the above ten characteristic information items, namely, packet capture based on source address parameter A, packet capture based on source address parameter B, packet capture based on destination address parameter C, packet capture based on destination address parameter D, packet capture based on transport layer protocol E, packet capture based on transport layer protocol F, packet capture based on application layer protocol G, packet capture based on application layer protocol H, packet capture based on application name I, and packet capture based on application name J. After subsequent packet capture begins, the packet capture device can create a link and connect at least one network card interface to the link, and obtain all data packets in the network data stream output by the link through DPDK. From the above ten packet capture rules, at least one is determined as the target packet capture rule to form a packet capture strategy.
[0066] In some examples, after obtaining the aforementioned multiple packet capture rules, performing packet capture according to all rules would significantly increase the processing load on the packet capture device. For instance, if the packet capture device determines ten packet capture rules, and in a large-scale, complex network scenario, the number of data packets received per second can reach millions, the packet capture device would need to perform ten packet capture judgments for each data packet according to the ten rules. This would result in tens of millions of packet capture operations performed per second. Therefore, in such a scenario, if the packet capture efficiency of the device cannot match the number of capture operations performed per second, packet loss will occur, causing losses for the user. Thus, after determining multiple packet capture rules, it is necessary to determine a packet capture strategy that includes at least one target packet capture rule based on the characteristics of the data packets. This allows the packet capture device to reduce the number of capture operations performed for each data packet while achieving correct packet capture. Based on this, after step S210, steps S220 and S230 are executed.
[0067] S220. Determine at least one target packet capture rule from multiple packet capture rules based on feature information and filtering rules, so as to obtain a packet capture strategy composed of at least one target packet capture rule.
[0068] Among them, multiple packet capture rules include any one or more of the following: packet capture based on source address parameters, packet capture based on destination address parameters, packet capture based on transport layer protocol, packet capture based on application layer protocol, and packet capture based on application name; the source address parameters include the source physical layer address MAC, the source network layer address IP, and the source port, and the destination address parameters include the destination MAC, the destination IP, and the destination port.
[0069] In some examples, the feature information includes multiple sub-parameters such as source address, destination address, transport layer protocol, application layer protocol, and application name. The filtering rules are those that filter packets corresponding to the same sub-parameter but with different specific content. For example, multiple packet capture rules might include capturing packets based on source address parameter A, source address parameter B, destination address parameter C, destination address parameter D, transport layer protocol E, transport layer protocol F, application layer protocol G, application layer protocol H, application name I, and application name J.
[0070] After determining the characteristic information of multiple data packets, the packet capture device first parses the multiple data packets to obtain the various sub-parameters of the characteristic information, and determines the differences in the specific content of each sub-parameter. For example, if the source address parameters involved in multiple data packets include A and B, then the specific content of the source address parameters involved in multiple data packets is different; if the destination address parameters involved in multiple data packets include C and D, then the specific content of the destination address parameters involved in multiple data packets is different; if the transport layer protocols involved in multiple data packets include E and F, then the specific content of the transport layer protocols involved in multiple data packets is different; if the application layer protocols involved in multiple data packets only include G, then the specific content of the application layer protocols involved in multiple data packets is the same; if the application names involved in multiple data packets only include I, then the specific content of the application names involved in multiple data packets is the same.
[0071] Then, the packet capture device can determine the target packet capture rule from multiple packet capture rules based on feature information and filtering rules. For example, if multiple data packets involve source address parameters including A and B, and the specific content of the source address parameters involved in the multiple data packets is different, then it can be determined that capturing packets based on source address parameter A or capturing packets based on source address parameter B is a target packet capture rule. As another example, if multiple data packets involve application layer protocols that only include G, and the specific content of the application layer protocols involved in the multiple data packets is the same, then it can be determined that capturing packets based on application layer protocols is meaningless, and therefore it can be determined that capturing packets based on application layer protocol G is not a target packet capture rule.
[0072] In some examples, taking the transport layer protocols involved in the packets as TCP (transmission control protocol), UDP (user datagram protocol), RTP (real-time transport protocol), and SCTP (stream control transmission protocol), the packet capture rule for a certain target in the final determined packet capture strategy can be: capturing packets according to the TCP protocol, or capturing packets according to the UDP protocol, or capturing packets according to the RTP protocol, or capturing packets according to the SCTP protocol, or capturing packets according to multiple protocols of TCP, UDP, RTP, and SCTP.
[0073] Furthermore, data packets can be obtained by the user through DPDK packet capture after creating a link and connecting at least one network interface card (NIC) to that link; that is, the data packets obtained through DPDK packet capture originate from the same link. In this case, the packet capture device can respond to the user's operation command and create multiple links before packet capture begins. Then, the user instructs the packet capture device to connect the NIC interface to different links according to actual needs. Afterward, the packet capture device executes S210 and S220 for each link to obtain the packet capture strategy corresponding to different links, rather than all data packets corresponding to a single capture strategy, thus improving the flexibility of packet capture.
[0074] In some examples, at least one target packet capture rule is determined from multiple packet capture rules. Specifically, this can be achieved by determining the correlation between multiple packet capture rules and feature information in the data packet. Based on this, combined with Figure 2 , refer to Figure 3 As shown, S220 may include S310 to S330.
[0075] S310. Transform multiple packet capture rules into a first feature vector to obtain a packet capture strategy consisting of at least one target packet capture rule.
[0076] In some examples, the string used to indicate packet capture rules can be converted into binary code, and a first feature vector can be constructed based on that binary code. For example, a packet capture device can convert the string "capture packets according to TCP protocol" into binary code and construct a first feature vector based on that binary code, which indicates the packet capture rules according to the TCP protocol.
[0077] It is understood that the first feature vector includes not only the packet capture rule "capture according to TCP protocol" mentioned above, but also binary code used to indicate all packet capture rules. The aforementioned "capture according to TCP protocol" is only used as an example of one case in which packet capture rules are converted into the first feature vector. This application does not impose a single limitation on the packet capture rules indicated by the first feature vector.
[0078] It is understood that the packet capture device can construct the first feature vector not only by converting the string used to indicate the packet capture rules into binary code, but also by other methods. This application does not impose specific restrictions on the methods for converting multiple packet capture rules into the first feature vector.
[0079] S320. Convert the feature information in multiple data packets into a second feature vector.
[0080] In some examples, the string used to indicate the characteristics of a message in a data packet can be converted into binary code, and a second feature vector can be constructed based on this binary code. For example, a packet capture device can convert the string "TCP protocol" into binary code and construct a second feature vector based on this binary code. This second feature vector is used to indicate the characteristic information that the transport layer protocol in the data packet is the TCP protocol.
[0081] It is understood that the second feature vector includes not only the "TCP protocol" feature information mentioned above, but also binary code indicating the feature information of the packets in all data packets. The aforementioned "TCP protocol" is only used as an example of one case in which the feature information of the packets in the data packets is converted into the second feature vector. This application does not impose a single limitation on the feature information of the packets in the data packets indicated by the second feature vector.
[0082] It is understood that packet capture devices can construct a second feature vector not only by converting strings used to indicate the characteristic information of messages in data packets into binary code, but also by other methods. This application does not impose specific restrictions on the methods for converting the characteristic information of messages in multiple data packets into a second feature vector.
[0083] It is understood that S310 and S320 have no logical order. The packet capture device can execute S310 first and then S320, or it can execute S320 first and then S310, or it can execute S310 and S320 simultaneously. This application embodiment does not impose specific restrictions on the execution order of S310 and S320.
[0084] S330. Based on the second feature vector and the first feature vector, determine at least one target packet capture rule among multiple packet capture rules.
[0085] In some examples, at least one target packet capture rule can be determined from multiple packet capture rules based on the correlation between the first feature vector and the second feature vector. The correlation can be that the feature information corresponding to the packet capture rule indicated by the first feature vector exists in the feature information indicated by the second feature vector and is not unique.
[0086] For example, taking the first feature vector as (A, B, C, D, E), the first element A indicates multiple packet capture rules based on the specific content of the source address parameter, the second element B indicates multiple packet capture rules based on the specific content of the destination address parameter, the third element C indicates multiple packet capture rules based on the specific content of the transport layer protocol, the fourth element D indicates multiple packet capture rules based on the specific content of the application layer protocol, and the fifth element E indicates multiple packet capture rules based on the specific content of the application name. Taking the second feature vector as (a1, a2, a3, b1, b2, b3, c1, c2, c3, e) as an example, the first element a1 indicates that the source MAC is 08:00:20:0A:8C:6D, the second element a2 indicates that the source IP is 192.168.1.1, the third base coefficient a3 indicates that the source port is the first port, the fourth element b1 indicates that the destination MAC is 00:01:6C:06:A6:29, the fifth element b2 indicates that the destination IP is 192.168.1.2, the sixth element b3 indicates that the destination port is the second port, the seventh element c1 indicates that the transport layer protocol is TCP, the eighth element indicates that the transport layer protocol is UDP, the ninth element indicates that the transport layer protocol is RTP, and the tenth element indicates that the application name is WeChat.
[0087] In this scenario, c1, c2, and c3 in the second feature vector are correlated with C in the first feature vector. This correlation can include the fact that C, c1, c2, and c3 are all related to transport layer protocols, and the specific transport layer protocols involved are not unique. Therefore, the packet capture device can determine the target packet capture rule based on TCP, UDP, or RTP protocols from among the multiple packet capture rules indicated by element C that capture packets based on specific transport layer protocol content. In some examples, the specific target packet capture rule can be determined based on proportions. For instance, if the number of packets with TCP as the transport layer protocol accounts for 60% of the total number of packets, the number of packets with UDP as the transport layer protocol accounts for 20%, and the number of packets with RTP as the transport layer protocol accounts for 20%, then the target packet capture rule is determined based on TCP, which has the highest proportion.
[0088] Meanwhile, there is no correlation between 'e' in the second feature vector and 'E' in the first feature vector. That is, although both 'E' and 'e' are related to the application name, the specific application name involved is only WeChat. In this case, since the application name is unique, it is meaningless for the packet capture device to capture packets based on the application name (capturing all data packets or discarding all data packets). The packet capture device can determine that none of the multiple packet capture rules indicated by element E in A, B, C, D, and E, which capture packets based on the specific content of the application name, are the target packet capture rules.
[0089] As shown above, the target packet capture rules included in the packet capture strategy determined by the packet capture device are as follows: packet capture based on source address parameters, packet capture based on destination address parameters, and packet capture based on transport layer protocols.
[0090] Furthermore, in some examples, when the network environment is very complex and the number of packets received per second is large, the lengths of the first and second feature vectors will also be long. In this case, to improve the efficiency of determining the packet capture strategy, the lengths of the first and second feature vectors can be reduced. For example, the packet capture device can fold the first and second feature vectors at least once, and determine at least one target packet capture rule from multiple packet capture rules based on the folded first and second feature vectors to obtain the packet capture strategy. This can be specifically implemented using the AFBV (Aggregated and Floaded Bit Vector) matching algorithm. This algorithm divides all packet capture rules into different types and processes them in parallel, thus supporting multiple matching methods such as exact matching, range matching, and arbitrary position mask matching. The AFBV algorithm groups packet capture rules of the same type according to the types of all current packet capture rules and converts them into packet capture rule vectors, then folds the packet capture rule vectors multiple times. When determining the target packet capture rule, it restores the packet capture rule vector before folding, thereby reducing the false matching rate.
[0091] The main idea of the AFBV algorithm is divided into two steps: (1) For example, the original vector O bits (b1, b2...bo), where each bit is 1 or 0, the aggregate vector is m, and the folded vector is z. According to the length of m, the original vector O is divided into O / m bits, and each bit is one bit of the aggregate vector m. It is judged whether the aggregate bit is 1. If the bit is 1, the corresponding position of the m vector is set to 1, otherwise it is set to 0. (2) For example, the number of bits of the folded vector z is k bits and k is much smaller than O. Each bit of the aggregate vector m corresponds to each bit of the folded vector z. The original vector O is folded multiple times with different folding lengths to obtain the correct original vector. This paper uses the AFBV algorithm to fold the vector multiple times. When the number of rules increases, each data packet header is folded and restored multiple times to finally achieve data matching. The AFBV matching algorithm can improve the matching speed.
[0092] In the technical solutions provided in S310 to S330 above, multiple packet capture rules are transformed into a first feature vector, and the feature information in multiple data packets is transformed into a second feature vector. Based on the correlation between the first feature vector and the second feature vector, at least one target packet capture rule is determined among the multiple packet capture rules to obtain a packet capture strategy. It can be seen that this technical solution can reduce the number of packet capture rules in the packet capture strategy, thereby reducing the number of times the packet capture device performs packet capture operations and improving the packet capture speed.
[0093] S230. Obtain the target data packet from all data packets according to the packet capture strategy.
[0094] In some examples, packet capture strategies include seven target packet capture rules: capturing packets based on source MAC address 08:00:20:0A:8C:6D, capturing packets based on source IP address 192.168.1.1, capturing packets based on source port as the first port, capturing packets based on destination MAC address 00:01:6C:06:A6:29, capturing packets based on destination IP address 192.168.1.2, capturing packets based on destination port as the second port, and capturing packets based on transport layer protocol (TCP). According to the packet capture strategy, the packet capture device identifies the target packet from all packets that meets the following criteria: source MAC address 08:00:20:0A:8C:6D, destination MAC address 00:01:6C:06:A6:29, source IP address 192.168.1.1, destination IP address 192.168.1.2, source port is port 1, destination port is port 2, and transport layer protocol is TCP. The device then acquires the target packet.
[0095] In some examples, the packet capture mode typically captures packets that conform to a capture strategy, but this mode lacks flexibility. For instance, if the transport layer protocols for data packets include n protocols such as TCP, UDP, RTP, and SCTP, and the user needs to capture packets other than those using SCTP, the packet capture device's determined capture strategy includes n-1 target capture rules, such as capturing packets according to TCP, UDP, and RTP. The capture device needs to perform n-1 capture operations according to the capture strategy, which obviously affects the capture speed when n is large. Based on this, combined with... Figure 2 , refer to Figure 4 As shown, S230 includes S410 and S420.
[0096] S410. When the packet capture mode is in the first mode, the data packets that conform to the target packet capture rules are identified as target data packets, and other data packets are discarded except for the target data packets.
[0097] The first mode is for capturing data packets that match the packet capture strategy. The packet capture strategy includes the target packet capture rules.
[0098] In some examples, the target packet capture rules in the packet capture strategy are as follows: capture packets based on the source MAC address 08:00:20:0A:8C:6D, capture packets based on the source IP address 192.168.1.1, capture packets based on the source port as the first port, capture packets based on the destination MAC address 00:01:6C:06:A6:29, capture packets based on the destination IP address 192.168.1.2, capture packets based on the destination port as the second port, and capture packets based on the transport layer protocol as TCP. According to the packet capture strategy, the packet capture device identifies packets with the following characteristics as target packets: source MAC address 08:00:20:0A:8C:6D, source IP address 192.168.1.1, source port is port 1, destination MAC address 00:01:6C:06:A6:29, destination IP address 192.168.1.2, destination port is port 2, and transport layer protocol is TCP. Other packets in the target packet are discarded.
[0099] In other examples, taking the packet capture policy based on the application name "WeChat" as an example, the packet capture device identifies the data packet with the application name "WeChat" as the target data packet according to the packet capture policy, and discards other data packets in the data packet except for the target data packet.
[0100] S420. When the packet capture mode is in the second mode, determine the data packets that do not conform to the target packet capture rules as target data packets and discard other data packets except for the target data packets.
[0101] The second mode is for capturing packets that do not conform to the packet capture policy. The packet capture policy includes the target packet capture rules.
[0102] In some examples, the target packet capture rules in the packet capture strategy are as follows: capture packets based on the source MAC address 08:00:20:0A:8C:6D, capture packets based on the source IP address 192.168.1.1, capture packets based on the source port as the first port, capture packets based on the destination MAC address 00:01:6C:06:A6:29, capture packets based on the destination IP address 192.168.1.2, capture packets based on the destination port as the second port, and capture packets based on the transport layer protocol as TCP. According to its packet capture strategy, the packet capture device identifies packets that do not conform to the following criteria: source MAC address 08:00:20:0A:8C:6D, source IP address 192.168.1.1, source port 1, destination MAC address 00:01:6C:06:A6:29, destination IP address 192.168.1.2, destination port 2, and transport layer protocol TCP. It then discards all other packets in the packet capture list. In other words, the packet capture device discards packets that conform to the following criteria and captures the remaining packets.
[0103] In other examples, the packet capture policy is used to capture packets with source IPs ranging from 192.168.1.1 to 192.168.1.254, where the source IP range is 192.168.1.1 to 192.168.1.255. The packet capture device, according to the policy, determines packets with source IPs other than 192.168.1.1 to 192.168.1.254 (i.e., packets with source IP 192.168.1.255) as target packets and discards all other packets in the packet collection.
[0104] In some examples, the packet capture device may receive data packets from multiple links and capture packets according to the packet capture strategies corresponding to different links. In this case, the packet capture modes corresponding to each link may be different. For example, taking the packet capture mode of the first link as the first mode and the packet capture mode of the second link as the second mode, the packet capture device can execute S410 and S420 above simultaneously.
[0105] In the technical solutions provided by S410 to S420 above, when the packet capture mode is the first mode, data packets that conform to the target packet capture rules are acquired and data packets that do not conform to the target packet capture rules are discarded. When the packet capture mode is the second mode, data packets that conform to the target packet capture rules are discarded and data packets that do not conform to the target packet capture rules are acquired. It can be seen that when the number of target packet capture rules is large, this technical solution can choose to discard data packets that do not conform to the target packet capture rules instead of directly acquiring data packets that conform to the target packet capture rules. This can reduce the number of packet captures by the packet capture device and improve the packet capture speed and flexibility.
[0106] In some examples, when the packet capture strategy includes at least two target packet capture rules, after determining that a packet does not conform to the first target packet capture rule (the first target packet capture rule in the packet capture strategy), the packet capture device still needs to determine whether the packet conforms to the second target packet capture rule (other target packet capture rules in the packet capture strategy besides the first target packet capture rule) and discard it. Clearly, after determining that a packet does not conform to the first target packet capture rule, it can be determined that the packet does not conform to the packet capture strategy and can be discarded. Continuing to determine whether the packet conforms to the second target packet capture rule would waste resources and slow down the packet capture speed of the packet capture device. Based on this, combined with... Figure 2 , reference Figure 5 As shown, S230 includes S510 and S520.
[0107] S510. If the packet capture strategy includes at least two target packet capture rules and the packet does not conform to any of the target packet capture rules, discard the packet.
[0108] Among them, the target packet capture rules are related by AND. If a data packet does not meet any of the target packet capture rules, it will be directly discarded. Only when a data packet meets all the target packet capture rules will it be identified as a target data packet by the packet capture device.
[0109] In some examples, the target packet capture rules are as follows: capturing packets based on source MAC address 08:00:20:0A:8C:6D; capturing packets based on source IP address 192.168.1.1; capturing packets based on source port 1; capturing packets based on destination MAC address 00:01:6C:06:A6:29; capturing packets based on destination IP address 192.168.1.2; capturing packets based on destination port 2; and capturing packets based on TCP transport protocol. If the packet capture device determines that the source MAC address of a data packet is not 08:00:20:0A:8C:6D, it will directly discard the data packet. If the packet capture device determines that the source MAC address of a data packet is 08:00:20:0A:8C:6D but the transport protocol is not TCP, it will directly discard the data packet. The same logic applies to other cases where the packet is discarded based on the target packet capture rules; these will not be elaborated further here.
[0110] S520. If the packet capture strategy includes at least two target packet capture rules and the data packet conforms to all target packet capture rules, the target data packet is obtained from all data packets according to the packet capture strategy and the first direction.
[0111] In the first direction, the data packet is sent from the data source device indicated by the source address parameter to the destination device indicated by the destination address parameter.
[0112] In some examples, the target packet capture rules are as follows: capture packets based on the source MAC address 08:00:20:0A:8C:6D, capture packets based on the source IP address 192.168.1.1, capture packets based on the source port (first port), capture packets based on the destination MAC address 00:01:6C:06:A6:29, capture packets based on the destination IP address 192.168.1.2, capture packets based on the destination port (second port), and capture packets based on the transport layer protocol (TCP). According to the packet capture strategy, the packet capture device identifies the target packet from all packets that meets the following criteria: source MAC address 08:00:20:0A:8C:6D, destination MAC address 00:01:6C:06:A6:29, source IP address 192.168.1.1, destination IP address 192.168.1.2, source port is the first port, destination port is the second port (the aforementioned source MAC address, destination MAC address, source IP address, destination IP address, source port, and destination port together determine the first direction), and transport layer protocol is TCP. The device then acquires the target packet.
[0113] In other examples, taking the target packet capture rule as follows: capture packets based on the transport layer protocol of UDP, capture packets based on the application name of WeChat, the source IP of the data packet is 192.168.1.1, and the destination IP of the data packet is 192.168.1.2 as an example, the packet capture device will capture data packets with the transport layer protocol of UDP and the application name of WeChat in the direction from 192.168.1.1 to 192.168.1.2.
[0114] In the technical solutions provided in S510 to S520 above, the target packet capture rules are related by AND. A data packet that does not meet any of the target packet capture rules will be directly discarded. Only when a data packet meets all the target packet capture rules will it be identified as a target data packet by the packet capture device. Therefore, this technical solution can reduce the number of packet capture attempts by the packet capture device, avoid the phenomenon of data packets continuing to occupy the packet capture device's resources for meaningless judgment even when they meet the packet loss conditions, and improve the packet capture speed of the packet capture device.
[0115] In some examples, a data packet that does not conform to the packet capture policy in the first direction may conform to the policy in the second direction. In this case, directly discarding the data packet might result in the loss of packet capture, as the data packet conforming to the policy in the second direction is also discarded. Based on this, combined with... Figure 5 ,refer to Figure 6 As shown, S510 includes S610.
[0116] S610. If a data packet does not conform to any target packet capture rule and no bidirectional instruction is received, the data packet is discarded.
[0117] The bidirectional command indicates the packet capture direction of the packet capture strategy, including a first direction and a second direction, where the second direction is the opposite of the first direction. The default packet capture direction is the first direction.
[0118] In some examples, the target packet capture rules are as follows: capturing packets based on the source MAC address 08:00:20:0A:8C:6D; capturing packets based on the source IP address 192.168.1.1; capturing packets based on the source port (port 1); capturing packets based on the destination MAC address 00:01:6C:06:A6:29; capturing packets based on the destination IP address 192.168.1.2; capturing packets based on the destination port (port 2); and capturing packets based on the TCP transport protocol. If the packet capture device does not receive a two-way command and determines that the source MAC address of the data packet is not 08:00:20:0A:8C:6D, the packet is directly discarded. Similarly, if the packet capture device does not receive a two-way command and determines that the source MAC address of the data packet is 08:00:20:0A:8C:6D but the transport protocol is not TCP, the packet is also directly discarded. The same logic applies to other cases where packet discarding is determined based on the target packet capture rules, and will not be elaborated further here.
[0119] Combination Figure 6 , reference Figure 7 As shown, if the data packet does not conform to the arbitrary target packet capture rule and the packet capture device receives a two-way command, S710 is executed.
[0120] S710. If a data packet does not conform to any target packet capture rule, and a bidirectional instruction is received, the target data packet is obtained from the data packet according to the packet capture strategy and the second direction.
[0121] In some examples, the target packet capture rules are set to UDP packet capture based on the transport layer protocol and WeChat packet capture based on the application name. For instance, the data packets might meet the following criteria: source MAC address 08:00:20:0A:8C:6D, destination MAC address 00:01:6C:06:A6:29, source IP address 192.168.1.1, destination IP address 192.168.1.2, source port is port 1, and destination port is port 2. First, the packet capture device determines that the transport layer protocol of the data packet in the first direction (from 08:00:20:0A:8C:6D to 00:01:6C:06:A6:29, from 192.168.1.1 to 192.168.1.2, and from the first port to the second port) is TCP, and the application name is not WeChat. At this time, the data packet does not meet any of the target packet capture rules. Second, the packet capture device receives bidirectional instructions from the user and determines that the transport layer protocol of the data packet in the second direction (the opposite direction of the first direction) (from 00:01:6C:06:A6:29 to 08:00:20:0A:8C:6D, from 192.168.1.2 to 192.168.1.1, and from the second port to the first port) is UDP, and the application name is WeChat. That is, the data packet satisfies all the target packet capture rules in the second direction. Finally, the packet capture device determines the data packet that conforms to the target packet capture rules in the second direction as the target data packet and acquires the target data packet.
[0122] In other examples, if a data packet does not meet either target capture rule in the first direction and also does not meet either target capture rule in the second direction, the device will discard the data packet.
[0123] In the technical solutions provided by S610 and S710 above, when the packet capture device receives a bidirectional command, it determines whether a data packet that does not conform to any target packet capture rule in the first direction conforms to all target packet capture rules in the second direction. If the data packet conforms to all target packet capture rules in the second direction, it is identified as a target data packet; if the data packet does not conform to any target packet capture rule in the second direction, it is discarded. Therefore, this technical solution can avoid packet loss and ensure the accuracy of packet capture.
[0124] In some examples, packet capture devices need to parse each packet to determine if it conforms to the capture strategy. However, in large-scale, complex network scenarios, the number of packets received by a packet capture device can reach millions per second. This means the device needs to parse millions of packets per second and determine if they meet the target capture rules. In such scenarios, if the packet capture device's receiving speed cannot match the number of packets it needs to parse per second, packet loss will occur, causing losses for users. Based on this, combined with... Figure 2 , reference Figure 8As shown, S230 includes S810 to S830.
[0125] S810: Merge data packets with identical quintuple information into a stream.
[0126] The five-tuple information consists of the source IP, destination IP, source port, destination port, and transport layer protocol.
[0127] In some examples, packets with identical 5-tuple information are defined as a single stream. For instance, all packets with source IP 192.168.1.1, destination IP 192.168.1.2, source port 1, destination port 2, and transport protocol TCP constitute one stream, while all packets with source IP 192.168.1.1, destination IP 192.168.1.2, source port 1, destination port 2, and transport protocol UDP constitute another stream, distinct from the aforementioned stream.
[0128] In some examples, the packet capture device can treat the stream as a whole and determine the target stream based on the target packet capture rules associated with the five-tuple information in the packet capture strategy. Based on this, S820 is executed after S810.
[0129] S820. Obtain the target stream from all streams according to the target packet capture rules related to the quintuple information in the packet capture strategy.
[0130] In some examples, the packet capture device determines the target packet capture rule related to the five-tuple information in the target packet capture rule of the packet capture strategy. For example, taking the target packet capture rule related to the five-tuple information as a source IP of 192.168.1.1, a destination IP of 192.168.1.2, a source port of port 1, a destination port of port 2, and a transport layer protocol of TCP as an example, the packet capture device determines the target stream in all streams that matches the source IP of 192.168.1.1, a destination IP of 192.168.1.2, a source port of port 1, a destination port of port 2, and a transport layer protocol of TCP, and then acquires all data packets of the target stream.
[0131] S830. Obtain the target data packet from the target stream according to the target packet capture rule in the packet capture strategy that is not related to the 5-tuple information.
[0132] In some examples, the target packet capture rule, which is irrelevant to the five-tuple information, is used to capture packets based on the source MAC address 08:00:20:0A:8C:6D, the destination MAC address 08:00:20:0A:8C:6D, and the application name "WeChat". For instance, the packet capture device, based on the target packet capture rule in the packet capture strategy that is irrelevant to the five-tuple information, identifies packets with source MAC address 08:00:20:0A:8C:6D, destination MAC address 08:00:20:0A:8C:6D, and application name "WeChat" from packets in a stream that meet the following criteria: source IP address 192.168.1.1, destination IP address 192.168.1.2, source port 1, destination port 2, and transport layer protocol TCP. The target packet is then retrieved from the packets in that stream.
[0133] In the technical solutions provided by S810 to S830 above, firstly, the packet capture device can merge data packets with the same five-tuple information into multiple streams. Compared to parsing a single data packet, parsing the stream as a whole reduces the parsing workload of the packet capture device. Secondly, the target stream is obtained from all streams according to the target packet capture rules related to the five-tuple information in the packet capture strategy. Finally, the target data packet is obtained from the target stream according to the target packet capture rules unrelated to the five-tuple information in the packet capture strategy. Therefore, this technical solution can reduce the number of packet capture attempts by the packet capture device and improve the packet capture speed.
[0134] In some examples, users can customize and modify the target packet capture rules before forming the packet capture strategy. Based on this, combined with Figure 2 , reference Figure 9 As shown, S220 also includes S10 to S930.
[0135] S910. Determine at least one target packet capture rule from multiple packet capture rules based on feature information and filtering rules.
[0136] S920: Receives rule adjustment instructions and adjusts the target packet capture rules in response to the rule adjustment instructions.
[0137] In some examples, before determining at least one target packet capture rule from multiple packet capture rules based on feature information and filtering rules to obtain a packet capture strategy consisting of at least one target packet capture rule, a rule adjustment instruction is received, and the target packet capture rule is adjusted in response to the rule adjustment instruction. For example, if the rule adjustment instruction is an address input instruction, the packet capture device can determine the target packet capture rule based on the MAC or IP address entered by the user; if the rule adjustment instruction is a protocol input instruction, the packet capture device can determine the packet capture rule based on the protocol name entered by the user; if the rule adjustment instruction is an application name input instruction, the packet capture device can determine the packet capture rule based on the application name entered by the user.
[0138] In some examples, rule adjustment instructions may also include two-way instructions.
[0139] S930. Obtain the packet capture strategy based on the target packet capture rules.
[0140] In the technical solutions provided by S910 to S930 above, users can customize and modify the target packet capture rules before the packet capture device forms a packet capture strategy. It is evident that this technical solution can improve the flexibility of the packet capture rules, enabling the packet capture device to capture packets according to the user's actual needs, thereby improving the user experience.
[0141] In the technical solutions provided in S210 to S230 above, firstly, the packet capture device acquires all data packets in the network data stream, enabling all data packets to participate in the subsequent packet capture process. That is, all data packets may be captured as packet capture objects in the subsequent packet capture process, ensuring the integrity and accuracy of the captured objects. Secondly, at least one target packet capture rule is determined from multiple packet capture rules based on feature information and filtering rules to obtain a packet capture strategy composed of at least one packet capture rule. This allows for the determination of at least one most suitable target packet capture rule from multiple packet capture rules based on differentiated feature information. Since each packet capture rule corresponds to one packet capture process, determining at least one target packet capture rule from multiple packet capture rules based on feature information and filtering rules can reduce the number of packet capture processes and improve packet capture efficiency. Finally, the target data packet is acquired from all data packets according to the packet capture strategy, completing the packet capture process and ensuring the accuracy of packet capture.
[0142] To more clearly illustrate the technical solutions provided in the embodiments of this application, taking an example with a source MAC address of 08:00:20:0A:8C:6D, a source IP address of 192.168.1.1, a source port of the first port, a destination MAC address of 00:01:6C:06:A6:29, a destination IP address of 192.168.1.2, a destination port of the second port, a transport layer protocol of TCP, an application layer protocol of HTTP, and an application name of WeChat, the packet capture method provided in this application may include, as follows: Figure 10 The process shown may specifically include:
[0143] 1. Create a link.
[0144] For example, a user creates different links and connects at least one interface of the network card to the link.
[0145] 2. DPDK receives packets.
[0146] For example, a packet capture device uses DPDK to receive data packets from a network data stream on a certain link.
[0147] 3. Physical layer analysis.
[0148] For example, the packet capture device determines the source MAC address of the data packet through physical layer parsing, including 08:00:20:0A:8C:6D and other physical addresses, and the destination MAC address includes 00:01:6C:06:A6:29 and other physical addresses.
[0149] 4. Network layer analysis.
[0150] For example, the packet capture device determines the source IP of the data packet, including 192.168.1.1 and other network addresses, and the destination IP, including 192.168.1.2 and other network addresses, through network layer resolution.
[0151] 5. Transport layer analysis.
[0152] For example, packet capture devices determine the transport layer protocol of data packets, including TCP and other transport layer protocols, the source port, including the first port and other ports, and the destination port, including the second port and other ports, through transport layer parsing.
[0153] 6. Application layer parsing.
[0154] For example, packet capture devices determine the application layer protocol of data packets through application layer parsing, including HTTP and other application layer protocols.
[0155] 7. Application recognition.
[0156] For example, the packet capture device identifies the application for each data packet, determining that the application name includes WeChat and other application names.
[0157] 8. Generate packet capture strategy.
[0158] For example, refer to Figure 11 As shown, the packet capture device generates 11 packet capture policies, with the default initial packet capture mode being receive. These policies include those based on TCP, UDP, and TCP protocols for specific ports, as well as those based on ARP, ICMP, and ICMPv6 protocols. The final, 11th policy is ANY, meaning it can capture any current protocol. Finally, in response to a button press in the application, the packet capture policy is sent to the background program to take effect.
[0159] 9. User-defined packet capture strategy.
[0160] For example, refer to Figure 12 As shown, users can customize packet capture policies in the custom interface. Customization options include: policy name, matching method selection (bidirectional command), source MAC address input, destination MAC address input, source IP address input, destination IP address input, source port input, destination port input, protocol selection, application name selection, and packet capture mode (accept or discard).
[0161] 10. Two-way bag capture.
[0162] For example, when bidirectional matching is selected in matching mode 9, the packet capture device captures packets according to the destination address parameter in the direction of the source address parameter and then according to the packet capture strategy.
[0163] 11. Packet loss.
[0164] For example, a packet capture device may discard a packet if it does not conform to the target packet capture rule in any packet capture strategy.
[0165] 12. Business processing.
[0166] For example, packet capture equipment performs deep parsing of packets to obtain business-related information from them.
[0167] 13. Release memory.
[0168] For example, packet capture devices release memory promptly after packet processing is complete.
[0169] The foregoing mainly describes the solutions provided by the embodiments of this application from a methodological perspective. To achieve the above functions, it includes corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, based on the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0170] This application embodiment can divide the packet capture device into functional modules according to the above method example. For example, each function can be divided into its own functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods.
[0171] Reference Figure 13 As shown in the figure, this application provides a packet capture device, which may include a packet receiving module 131, a strategy matching module 132, and a packet capture module 133.
[0172] Specifically, the packet receiving module 131 is used to acquire all data packets in the network data stream; wherein, the data packets include messages, and the messages contain characteristic information, including: source address parameters, destination address parameters, transport layer protocol, application layer protocol, and application name; the policy matching module 132 is used to determine at least one target packet capture rule from multiple packet capture rules based on the characteristic information contained in the messages in the data packets acquired by the packet receiving module and the filtering rules, so as to obtain a packet capture strategy composed of at least one target packet capture rule; wherein, the multiple packet capture rules include any one or more of the following: packet capture based on source address parameters, packet capture based on destination address parameters, packet capture based on transport layer protocol, packet capture based on application layer protocol, and packet capture based on application name; the source address parameters include source MAC, source IP, and source port, and the destination address parameters include destination MAC, destination IP, and destination port; the packet capture module 133 is used to acquire target data packets from the data packets acquired by the packet receiving module according to the packet capture strategy obtained by the policy matching module.
[0173] In one possible implementation, a target packet capture rule is determined from multiple packet capture rules based on feature information and filtering rules. The policy matching module 132 is specifically used to: convert multiple packet capture rules into a first feature vector; convert feature information in multiple data packets into a second feature vector; and determine at least one target packet capture rule from multiple packet capture rules based on the second feature vector and the first feature vector.
[0174] In one possible implementation, the target data packet is obtained from all data packets according to the packet capture strategy. Specifically, the packet capture module 133 is used to: determine the data packets that conform to the target packet capture rules as the target data packets when the packet capture mode is the first mode, and discard other data packets except the target data packets; and determine the data packets that do not conform to the target packet capture rules as the target data packets when the packet capture mode is the second mode, and discard other data packets except the target data packets.
[0175] In one possible implementation, when the packet capture strategy includes at least two target packet capture rules, the target packet is obtained from all packets according to the packet capture strategy. Specifically, the packet capture module 133 is used to: discard the packet if it does not conform to any of the target packet capture rules; and obtain the target packet from all packets according to the packet capture strategy and a first direction if it conforms to all the target packet capture rules. The first direction is that the packet is sent from the data source device indicated by the source address parameter to the destination device indicated by the destination address parameter.
[0176] In one possible implementation, if a data packet does not conform to any target packet capture rule, the data packet is discarded. Specifically, the packet capture module 133 is used to: discard the data packet if no bidirectional instruction is received when the data packet does not conform to any target packet capture rule; wherein, the bidirectional instruction is used to indicate the packet capture direction of the packet capture strategy, including a first direction and a second direction, and the second direction is the opposite direction of the first direction.
[0177] In one possible implementation, the packet capture module 133 is specifically used to: if a bidirectional instruction is received, and the packet does not conform to any target packet capture rule, then the target packet is obtained from the packet according to the packet capture strategy and the second direction.
[0178] In one possible implementation, the packet capture device further includes: merging data packets with the same 5-tuple information into a stream; obtaining a target stream from all streams according to a target packet capture rule in the packet capture strategy that is related to the 5-tuple information; and obtaining target data packets from the target stream according to a target packet capture rule in the packet capture strategy that is not related to the 5-tuple information.
[0179] In one possible implementation, the strategy matching module 132 is specifically used for: before determining at least one target packet capture rule from multiple packet capture rules based on feature information and filtering rules to obtain a packet capture strategy composed of at least one target packet capture rule, the packet capture device further includes: determining at least one target packet capture rule from multiple packet capture rules based on feature information and filtering rules; receiving a rule adjustment instruction and adjusting the target packet capture rule in response to the rule adjustment instruction; and obtaining a packet capture strategy based on the target packet capture rule.
[0180] It should be understood that the division of units or modules (hereinafter referred to as units) in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, all units in the device can be implemented in software through processing element calls; all units can be implemented in hardware; or some units can be implemented in software through processing element calls, and some units can be implemented in hardware.
[0181] For example, each unit can be a separate processing element, or it can be integrated into a chip within the device. Alternatively, it can be stored in memory as a program, and its function can be called and executed by a processing element within the device. Furthermore, these units can be integrated together in whole or in part, or they can be implemented independently. The processing element here can also be called a processor, which can be an integrated circuit with signal processing capabilities. In implementation, each step of the above method or each of the above units can be implemented through integrated logic circuits in the processor element or through software calls by the processing element.
[0182] In one example, the unit in the above device may be one or more integrated circuits configured to implement the above methods, such as one or more ASICs, or one or more DSPs, or one or more FPGAs, or a combination of at least two of these integrated circuit forms.
[0183] For example, when the units in the device can be implemented through a processing element scheduler, the processing element can be a general-purpose processor, such as a CPU or other processor capable of calling programs. Alternatively, these units can be integrated together to form a system-on-a-chip (SoC).
[0184] In one implementation, the units that implement the corresponding steps in the above method can be implemented in the form of a processing element scheduler. For example, the device may include a processing element and a storage element, wherein the processing element calls a program stored in the storage element to execute the packet capture method of the above method embodiment. The storage element may be a storage element located on the same chip as the processing element, i.e., an on-chip storage element.
[0185] In another implementation, the program used to perform the above method can be located on a storage element on a different chip than the processing element, i.e., an off-chip storage element. In this case, the processing element calls or loads the program from the off-chip storage element onto the on-chip storage element to call and execute the packet capture method of the above method embodiment.
[0186] Reference Figure 14 As shown in the illustration, this application embodiment also provides a packet capture device, including a communicator 141 configured to acquire all data packets in a network data stream; wherein, the data packets include messages containing feature information, the feature information including: source address parameters, destination address parameters, transport layer protocol, application layer protocol, and application name; a processor 142, coupled to the communicator, configured to determine a packet capture strategy consisting of at least one target packet capture rule from multiple packet capture rules based on the feature information and filtering rules; wherein, the multiple packet capture rules include any one or more of the following: packet capture based on source address parameters, packet capture based on destination address parameters, packet capture based on transport layer protocol, packet capture based on application layer protocol, and packet capture based on application name; the source address parameters include source MAC, source IP, and source port, and the destination address parameters include destination MAC, destination IP, and destination port; the target data packet is acquired from all data packets according to the packet capture strategy.
[0187] In one possible implementation, a target packet capture rule is determined from multiple packet capture rules based on feature information and filtering rules. The processor 142 converts the multiple packet capture rules into a first feature vector; converts the feature information in the multiple data packets into a second feature vector; and determines at least one target packet capture rule from the multiple packet capture rules based on the second feature vector and the first feature vector.
[0188] In one possible implementation, the processor 142 is configured to obtain the target data packet from all data packets according to the packet capture strategy. When the packet capture mode is in the first mode, the processor 142 determines the data packet that conforms to the target packet capture rule as the target data packet and discards other data packets except the target data packet. When the packet capture mode is in the second mode, the processor 142 determines the data packet that does not conform to the target packet capture rule as the target data packet and discards other data packets except the target data packet.
[0189] In one possible implementation, when the packet capture strategy includes at least two target packet capture rules, the target packet is obtained from all packets according to the packet capture strategy. The processor 142 is configured to discard the packet if it does not conform to any of the target packet capture rules; and to obtain the target packet from all packets according to the packet capture strategy and a first direction if it conforms to all the target packet capture rules. The first direction is that the packet is sent from the data source device indicated by the source address parameter to the destination device indicated by the destination address parameter.
[0190] In one possible implementation, if a data packet does not conform to any target packet capture rule, the data packet is discarded. The processor 142 is configured to discard the data packet if no bidirectional instruction is received if the data packet does not conform to any target packet capture rule. The bidirectional instruction is used to indicate the packet capture direction of the packet capture strategy, which includes a first direction and a second direction, wherein the second direction is the opposite direction of the first direction.
[0191] In one possible implementation, the processor 142 is configured to, if a bidirectional instruction is received, acquire the target data packet from the data packet according to the packet capture strategy and the second direction, if the data packet does not conform to either target packet capture rule.
[0192] In one possible implementation, processor 142 is configured to merge packets with the same 5-tuple information into a stream; obtain a target stream from all streams according to a target packet capture rule in the packet capture strategy that is related to the 5-tuple information; and obtain target packets from the target stream according to a target packet capture rule in the packet capture strategy that is not related to the 5-tuple information.
[0193] In one possible implementation, and in another possible implementation, before determining at least one target packet capture rule from multiple packet capture rules based on feature information and filtering rules to obtain a packet capture strategy consisting of at least one target packet capture rule, processor 142 is configured to: determine at least one target packet capture rule from multiple packet capture rules based on feature information and filtering rules; receive rule adjustment instructions and adjust the target packet capture rule in response to the rule adjustment instructions; and obtain a packet capture strategy based on the target packet capture rule.
[0194] This application also provides a packet capture device, which may include a display screen, a memory, and one or more processors. The display screen, memory, and processors are coupled. The memory stores computer program code, which includes computer instructions. When the processor executes the computer instructions, the packet capture device can perform various functions or steps performed by the packet capture device in the above method embodiments.
[0195] For example, this application also provides a chip that can be applied to the aforementioned packet capture device or server. The chip includes one or more interface circuits and one or more processors; the interface circuits and processors are interconnected via lines; the processor receives and executes computer instructions from the memory of the packet capture device through the interface circuits to implement the methods in the above method embodiments.
[0196] This application also provides a computer-readable storage medium storing computer program instructions (or instructions). When the computer program instructions are executed by a packet capture device, the packet capture device can implement the packet capture method described above.
[0197] This application also provides a computer program product, including computer instructions for running the packet capture device as described above. When the computer program product runs in the packet capture device, the packet capture device can implement the packet capture method as described above.
[0198] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0199] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another apparatus, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0200] The units described as separate components may or may not be physically separate. A component shown as a unit can be one or more physical units; that is, it can be located in one place or distributed in multiple different locations. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0201] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0202] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product, such as a program. This software product is stored in a program product, such as a computer-readable storage medium, and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.
[0203] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for capturing packets, characterized in that, The method includes: Acquire all data packets in the network data stream; wherein, the data packets include messages, and the messages contain characteristic information, including: source address parameters, destination address parameters, transport layer protocol, application layer protocol, and application name; Transform multiple packet capture rules into a first feature vector; The feature information in the multiple data packets is converted into a second feature vector; Based on the correlation between the second feature vector and the first feature vector, at least one target packet capture rule is determined from the plurality of packet capture rules to obtain a packet capture strategy composed of the at least one target packet capture rule; wherein, the correlation is that the feature information corresponding to the packet capture rule indicated by the first feature vector exists in the feature information indicated by the second feature vector and is not unique; the plurality of packet capture rules include any one or more of the following: packet capture based on source address parameters, packet capture based on destination address parameters, packet capture based on transport layer protocol, packet capture based on application layer protocol, and packet capture based on application name; the source address parameters include source physical layer address MAC, source network layer address IP, and source port, and the destination address parameters include destination MAC, destination IP, and destination port; The target data packet is obtained from all the data packets according to the packet capture strategy.
2. The bag-catching method according to claim 1, characterized in that, The step of obtaining the target data packet from all the data packets according to the packet capture strategy includes: When the packet capture mode is in the first mode, the data packets that conform to the target packet capture rules are identified as the target data packets, and other data packets except for the target data packets are discarded; When the packet capture mode is in the second mode, the data packets that do not conform to the target packet capture rules are identified as the target data packets, and the other data packets are discarded except for the target data packets.
3. The bag-catching method according to claim 1, characterized in that, When the packet capture strategy includes at least two target packet capture rules, the step of obtaining the target data packet from all the data packets according to the packet capture strategy includes: If the data packet does not conform to any of the target packet capture rules, the data packet is discarded; If the data packet conforms to all the target packet capture rules, the target data packet is obtained from all the data packets according to the packet capture strategy and the first direction; wherein, the first direction is that the data packet is sent from the data source device indicated by the source address parameter to the destination device indicated by the destination address parameter.
4. The bag-catching method according to claim 3, characterized in that, The step of discarding the data packet if it does not conform to any of the target packet capture rules includes: If the data packet does not conform to any of the target packet capture rules, the data packet is discarded if no bidirectional instruction is received; wherein the bidirectional instruction is used to indicate the packet capture direction of the packet capture strategy, including the first direction and the second direction, and the second direction is the opposite direction of the first direction.
5. The bag-catching method according to claim 4, characterized in that, The method further includes: If the data packet does not conform to any of the target packet capture rules, and the bidirectional instruction is received, the target data packet is obtained from the data packet according to the packet capture strategy and the second direction.
6. The bag-catching method according to claim 1, characterized in that, The method further includes: Data packets with identical quintuple information are merged into a stream; The target stream is obtained from all the streams according to the target packet capture rules related to the quintuple information in the packet capture strategy; The target data packet is obtained from the target stream according to the target packet capture rule in the packet capture strategy that is not related to the 5-tuple information.
7. The bag-catching method according to claim 1, characterized in that, The method further includes determining at least one target packet capture rule from among the plurality of packet capture rules based on the second feature vector and the first feature vector to obtain a packet capture strategy composed of the at least one target packet capture rule. Receive rule adjustment instructions and adjust the target packet capture rules in response to the rule adjustment instructions; The packet capture strategy is obtained based on the target packet capture rules.
8. A bag-catching device, characterized in that, The device includes: The packet receiving module is used to acquire all data packets in the network data stream; wherein, the data packets include messages, and the messages contain characteristic information, including: source address parameters, destination address parameters, transport layer protocol, application layer protocol, and application name; A strategy matching module is used to convert multiple packet capture rules into a first feature vector; convert the feature information in multiple data packets into a second feature vector; and determine at least one target packet capture rule among the multiple packet capture rules based on the association relationship between the second feature vector and the first feature vector, so as to obtain a packet capture strategy composed of the at least one target packet capture rule; wherein, the association relationship is that the feature information corresponding to the packet capture rule indicated by the first feature vector exists in the feature information indicated by the second feature vector and is not unique; the multiple packet capture rules include any one or more of the following: packet capture based on source address parameters, packet capture based on destination address parameters, packet capture based on transport layer protocol, packet capture based on application layer protocol, and packet capture based on application name; the source address parameters include source MAC, source IP, and source port, and the destination address parameters include destination MAC, destination IP, and destination port; The packet capture module is used to obtain the target data packet from the data packet obtained by the packet receiving module according to the packet capture strategy obtained by the strategy matching module.
9. An electronic device, characterized in that, include: processor; Memory for storing the executable instructions of the processor; The processor is configured to execute the packet capture method according to any one of claims 1-7 by executing the executable instructions.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed by a processor of the packet capture device, enable the packet capture device to perform the packet capture method as described in any one of claims 1-7.
Citation Information
Patent Citations
Network traffic refined screening device and method
CN112491901A