A traffic data processing method, device and equipment, and a storage medium
By generating backup traffic data packets and modifying the source address in the traffic orchestration device, the problem that secure traffic orchestration cannot support the access of traffic mirroring devices is solved, and the continuity of orchestration is realized.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHENZHEN SHENXIN INFORMATION SECURITY CO LTD
- Filing Date
- 2023-06-27
- Publication Date
- 2026-05-29
AI Technical Summary
In existing technologies, Secure Traffic Orchestration (SSLO) cannot support the access of traffic mirroring devices, resulting in data loss at the traffic mirroring device and the inability to continue orchestration.
By generating backup traffic data packets for the target traffic data packets in the traffic orchestration device and modifying the source address of the data packets during forwarding, it simulates receiving packets from the traffic mirroring device, thereby enabling access support for the traffic mirroring device.
It enables secure traffic orchestration to support traffic mirroring devices, ensuring the continuity of orchestration.
Smart Images

Figure CN116582556B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and in particular to a method, apparatus, device, and storage medium for processing traffic data. Background Technology
[0002] Secure Traffic Orchestrator (SSLO) pools user security devices into pools of security resources with different functionalities. It then intelligently orchestrates secure traffic by defining service chains, providing different security capabilities for different traffic types. In related technologies, security devices in the service chain forward received data packets back to the traffic orchestration device; these responses ensure the continuity of orchestration. However, since traffic mirroring devices only receive data packets and do not forward them back to the traffic orchestration device, data is lost at the traffic mirroring device when a mirroring device exists in the service chain, causing traffic orchestration to fail. In other words, Secure Traffic Orchestrator does not support the access of traffic mirroring devices.
[0003] Therefore, the aforementioned technical problems urgently need to be solved by those skilled in the art. Summary of the Invention
[0004] In view of this, the purpose of this invention is to provide a traffic data processing method, apparatus, device, and storage medium that can support secure traffic orchestration for traffic mirroring device access, ensuring the continuity of orchestration. The specific solution is as follows:
[0005] A traffic data processing method, applied to a traffic orchestration device, includes:
[0006] Receive the target traffic data packets from the client;
[0007] For the traffic mirroring device in the service chain, a backup traffic data packet is generated for the target traffic data packet; the content of the target traffic data packet and the backup traffic data packet is the same.
[0008] Choose either the target traffic data packet or the backup traffic data packet and forward it to the traffic mirroring device;
[0009] The source address of the remaining data packet is modified so that the modified data packet is characterized as a data packet sent by the traffic mirroring device to the traffic orchestration device.
[0010] Preferably, selecting any one of the target traffic data packets and the backup traffic data packets to forward to the traffic mirroring device includes:
[0011] Select either the target traffic data packet or the backup traffic data packet as the data packet to be forwarded to the traffic mirroring device;
[0012] Modify the source address of the selected data packet to the physical address of the traffic orchestration device, and modify the destination address to the physical address of the traffic mirroring device;
[0013] The modified data packet is sent to the traffic mirroring device.
[0014] Preferably, modifying the source address of the remaining data packet includes:
[0015] The source address of the remaining data packet is modified to the physical address of the traffic mirroring device to obtain the modified data packet.
[0016] Preferably, before selecting any data packet from the target traffic data packet and the backup traffic data packet to forward to the traffic mirroring device, the method further includes:
[0017] When the traffic mirroring device does not have a real IP address, the traffic orchestration device obtains the physical address of the traffic mirroring device through a pre-configured static ARP policy.
[0018] Preferably, the pre-configuration process of the static ARP policy includes:
[0019] In the case where the traffic mirroring device does not have a real IP address, the traffic orchestration device pre-assigns a physical address and a virtual IP address to the traffic mirroring device and generates link information to connect the traffic mirroring device to the service chain.
[0020] A fixed address mapping relationship is constructed between the virtual IP address of the traffic mirroring device, the link information, and the physical address, thereby obtaining the static ARP policy containing the fixed address mapping relationship.
[0021] Preferably, before selecting any data packet from the target traffic data packet and the backup traffic data packet to forward to the traffic mirroring device, the following steps are included:
[0022] When the traffic mirroring device is pre-configured with a real IP address and supports Address Resolution Protocol (ARP), the traffic orchestration device obtains the physical address of the traffic mirroring device through ARP broadcast.
[0023] Preferably, the step of generating a backup traffic data packet for the target traffic data packet before the traffic mirroring device in the service chain includes:
[0024] The real IP address of the traffic mirroring device is used as the access IP address to connect the traffic mirroring device to the service chain.
[0025] A flow data processing device, applied to flow orchestration equipment, comprising:
[0026] The data packet receiving module is used to receive target traffic data packets from the client.
[0027] The data packet replication module is used to generate a backup traffic data packet for the target traffic data packet for the traffic mirroring device in the service chain; the content of the target traffic data packet and the backup traffic data packet is the same.
[0028] The data packet sending module is used to select any one of the target traffic data packets and the backup traffic data packets and forward it to the traffic mirroring device;
[0029] The packet receiving simulation module is used to modify the source address of the remaining packet, so that the modified packet is represented as a packet sent by the traffic mirroring device to the traffic orchestration device.
[0030] An electronic device includes a processor, a communication interface, and a memory; wherein the image interface is used to create a data transmission channel between the electronic device and an external device, and the memory is used to store a computer program, which is loaded and executed by the processor to implement the traffic data processing method described above.
[0031] A computer-readable storage medium is provided for storing computer-executable instructions, which, when loaded and executed by a processor, implement the traffic data processing method described above.
[0032] In this application, the traffic orchestration device receives the target traffic data packet from the client; generates a backup traffic data packet for the target traffic data packet for the traffic mirroring device in the service chain; the target traffic data packet and the backup traffic data packet have the same content; selects either the target traffic data packet or the backup traffic data packet and forwards it to the traffic mirroring device; modifies the source address of the remaining data packet so that the modified data packet is represented as a data packet sent by the traffic mirroring device to the traffic orchestration device, so as to simulate receiving a packet from the traffic mirroring device.
[0033] After receiving the target traffic data packet sent by the client, the traffic orchestration device generates a backup traffic data packet. Then, it selects either the target traffic data packet or the backup traffic data packet to send to the traffic mirroring device and sends it. The source address of the remaining data packet is modified so that the modified data packet representation can represent a data packet sent from the traffic mirroring device to the traffic orchestration device, i.e., simulating receiving a packet from the traffic mirroring device. Therefore, this application addresses the drawback of traffic mirroring devices in a service chain only being able to receive data packets but not return them. When forwarding traffic data packets to traffic mirroring devices in the service chain, the traffic orchestration device generates corresponding backup traffic data packets. By forwarding one of these backup traffic data packets to the traffic mirroring device and modifying the source address of the other, it simulates receiving a packet from the traffic mirroring device, thereby achieving secure traffic orchestration support for traffic mirroring device access and ensuring orchestration continuity. Attached Figure Description
[0034] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0035] Figure 1 A flowchart of a traffic data processing method provided in this application;
[0036] Figure 2 This application provides a specific example diagram of a secure traffic orchestration deployment topology.
[0037] Figure 3 This application provides a flowchart of a specific method for forwarding data packets to a traffic mirroring device;
[0038] Figure 4 A flowchart of a specific traffic data processing method provided in this application;
[0039] Figure 5 A flowchart of another specific traffic data processing method provided in this application;
[0040] Figure 6 A schematic diagram of a traffic data processing device provided in this application;
[0041] Figure 7 This application provides a structural diagram of an electronic device for processing traffic data. Detailed Implementation
[0042] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0043] In existing secure traffic orchestration technologies, security devices in the service chain need to forward received data packets back to the traffic orchestration device, ensuring the continuity of orchestration. However, since traffic mirroring devices only receive data packets and do not forward them back to the traffic orchestration device, data is lost at the traffic mirroring device when a mirroring device exists in the service chain, and traffic orchestration cannot continue. In other words, secure traffic orchestration does not support the access of traffic mirroring devices. Devices with traffic mirroring capabilities are collectively referred to as traffic mirroring devices, such as switches, optical splitters, or other devices. Traffic mirroring refers to the function of completely copying or partially extracting information (such as packet header information) of traffic (such as packets to be processed) flowing through a device (such as a server) based on dimensions such as port and virtual local area network (VLAN), and then sending it to other designated receiving devices (such as heterogeneous firewalls) for traffic processing.
[0044] To address the aforementioned technical deficiencies, this application provides a traffic data processing solution. Addressing the limitation that traffic mirroring devices in a service chain can only receive data packets but cannot return them, the traffic orchestration device generates corresponding backup traffic data packets when forwarding them to the traffic mirroring devices in the service chain. By forwarding one backup packet to the traffic mirroring device and modifying the source address of the other, it simulates receiving packets from the traffic mirroring device, thereby enabling secure traffic orchestration to support access to traffic mirroring devices and ensuring the continuity of orchestration.
[0045] Figure 1 A flowchart illustrating a traffic data processing method provided in an embodiment of this application. See also... Figure 1 As shown, this traffic data processing method is applied to a traffic orchestration device, including:
[0046] S10: Receive the target traffic data packet from the client.
[0047] In this embodiment of the application, the content of the target traffic data packet itself is not limited.
[0048] S11: For traffic mirroring devices in the service chain, generate backup traffic data packets for the target traffic data packets.
[0049] The target traffic data packet and the backup traffic data packet have the same content.
[0050] In this embodiment, the traffic orchestration device (SSLO device) generates a backup traffic data packet for the target traffic data packet for the traffic mirroring device in the service chain. The traffic orchestration device forwards the target traffic data packet according to the order of the devices in the service chain. If the device to be forwarded is a traffic mirroring device, a backup traffic data packet for the target traffic data packet will be generated. The content of the target traffic data packet and its backup traffic data packet are the same. Specifically, the backup traffic data packet can be generated by copying the target traffic data packet, or by other backup methods. This embodiment does not limit this.
[0051] Figure 2 The diagram illustrates a secure traffic orchestration deployment topology example, including a service chain example. Most traffic sent from clients to the traffic orchestration device is SSL encrypted. Therefore, upon receiving traffic from a client, the traffic orchestration device first performs SSL offloading, i.e., decryption. Once the traffic becomes plaintext, the traffic orchestration device begins forwarding the target traffic data packets according to the device order in the service chain, until it reaches the traffic mirroring device, at which point it copies the data packets. This is because the traffic mirroring device itself only receives data packets and does not forward user traffic back to the traffic orchestration device. Therefore, when sending packets to the traffic mirroring device, the traffic orchestration device needs to save a copy of the data packet first and then modify the source address of this packet to facilitate subsequent simulation of receiving packets from the traffic mirroring device.
[0052] As we understand it, SSL (Secure Sockets Layer) is a security protocol that provides security and data integrity for network communication. SSL encrypts network connections between the transport layer and the application layer. Correspondingly, SSL offloading is achieved by transferring the SSL encryption and decryption process during application access to a device that provides encryption and decryption capabilities. This reduces server performance pressure and improves website access speed while meeting the demands of high-concurrency access.
[0053] S12: Select either the target traffic data packet or the backup traffic data packet and forward it to the traffic mirroring device.
[0054] In this embodiment, after the traffic orchestration device generates a backup traffic data packet for the target traffic data packet, it needs to forward either the target traffic data packet or the backup traffic data packet to the traffic mirroring device. Since the target traffic data packet is sent from the client to the traffic orchestration device, the destination address of both the target traffic data packet and its corresponding backup traffic data packet is the physical address of the traffic orchestration device, i.e., the MAC address (Media Access Control Address).
[0055] In this embodiment, any one of the target traffic data packets and the backup traffic data packets is selected as the data packet to be forwarded to the traffic mirroring device. The specific process includes the following steps: Figure 3 ):
[0056] S121: Modify the source address of the selected data packet to the physical address of the traffic orchestration device, and modify the destination address to the physical address of the traffic mirroring device.
[0057] S122: Send the modified data packet to the traffic mirroring device.
[0058] In this embodiment, when forwarding data packets to the traffic mirroring device, one data packet is first arbitrarily selected from the target traffic data packet and the backup traffic data packet as the data packet to be forwarded to the traffic mirroring device. Here, either the target traffic data packet itself or the corresponding backup traffic data packet can be forwarded to the traffic mirroring device. Then, the source address of the data packet to be forwarded to the traffic mirroring device is modified to the physical address of the traffic orchestration device.
[0059] It is understood that the data packets to be forwarded to the traffic mirroring device are either target traffic data packets or corresponding backup traffic data packets. The source address to be forwarded to the traffic mirroring device is either the client's physical address or the physical address of the previous security device in the service chain. To send these packets from the traffic orchestration device to the traffic mirroring device, their physical addresses need to be modified to the physical address of the traffic orchestration device. Next, the destination address of the data packets to be forwarded to the traffic mirroring device is modified to the physical address of the traffic mirroring device. Based on this, the modified data packets are forwarded to the traffic mirroring device.
[0060] S13: Modify the source address of the remaining data packet so that the modified data packet is represented as a data packet sent from the traffic mirroring device to the traffic orchestration device.
[0061] In this embodiment, to simulate receiving packets from the traffic mirroring device, the traffic orchestration device needs to modify the source address of another data packet so that the modified data packet represents a data packet sent from the traffic mirroring device to the traffic orchestration device. Similarly, the source address of the other data packet is either the client's physical address or the physical address of the previous security device in the service chain.
[0062] Specifically, the source address of the remaining data packet is modified, including changing the source address of the remaining data packet to the physical address of the traffic mirroring device. That is, the source address of the remaining data packet is modified to the physical address of the traffic mirroring device, resulting in the modified data packet.
[0063] In this embodiment, the traffic orchestration device identifies the modified data packet as a data packet returned by the traffic mirroring device. It can be understood that the modified data packet is stored in the traffic orchestration device's local storage space, and treating it as a data packet received from the traffic mirroring device simulates the process of the traffic mirroring device forwarding data packets to the traffic orchestration device.
[0064] As can be seen, in this application, the traffic orchestration device receives the target traffic data packet from the client; generates a backup traffic data packet for the traffic mirroring device in the service chain; the target traffic data packet and the backup traffic data packet have the same content; selects either the target traffic data packet or the backup traffic data packet and forwards it to the traffic mirroring device; modifies the source address of the remaining data packet so that the modified data packet is represented as a data packet sent from the traffic mirroring device to the traffic orchestration device, so as to simulate receiving packets from the traffic mirroring device.
[0065] After receiving the target traffic data packet sent by the client, the traffic orchestration device generates a backup traffic data packet. Then, it selects either the target traffic data packet or the backup traffic data packet to send to the traffic mirroring device and sends it. The source address of the remaining data packet is modified so that the modified data packet representation can represent a data packet sent from the traffic mirroring device to the traffic orchestration device, i.e., simulating receiving a packet from the traffic mirroring device. Therefore, this application addresses the drawback of traffic mirroring devices in a service chain only being able to receive data packets but not return them. When forwarding traffic data packets to traffic mirroring devices in the service chain, the traffic orchestration device generates corresponding backup traffic data packets. By forwarding one of these backup traffic data packets to the traffic mirroring device and modifying the source address of the other, it simulates receiving a packet from the traffic mirroring device, thereby achieving secure traffic orchestration support for traffic mirroring device access and ensuring orchestration continuity.
[0066] Figure 4 A flowchart illustrating a specific traffic data processing method provided in this application embodiment. See also... Figure 4 As shown, this traffic data processing method is applied to a traffic orchestration device, including:
[0067] S21: When the traffic mirroring device does not have a real IP address, the traffic orchestration device pre-assigns a physical address and a virtual IP address to the traffic mirroring device and generates link information to connect the traffic mirroring device to the service chain.
[0068] The real IP address is the IP address configured by the network operator.
[0069] In this embodiment, the traffic orchestration device assigns an IP address as the access IP address to the traffic mirroring device and generates link information to connect the traffic mirroring device to the service chain. Traffic mirroring devices need to be connected to the service chain; some traffic mirroring devices are configured with real IP addresses, while others are not. Different traffic mirroring devices connect to the service chain in different ways. For traffic mirroring devices without real IP addresses, when the device connects, the traffic orchestration device needs to assign an IP address as the access IP address and generate corresponding link information, which is the outgoing interface information of the traffic.
[0070] S22: Construct a fixed address mapping relationship between the virtual IP address and link information of the traffic mirroring device and the physical address, thereby obtaining a static ARP policy containing the fixed address mapping relationship.
[0071] In this embodiment, traffic mirroring devices without configured IP addresses cannot send ARP responses, and traffic orchestration devices cannot request physical addresses via ARP broadcasts. ARP (Address Resolution Protocol) is a TCP / IP protocol that obtains a physical address from an IP address. ARP's function is to obtain the destination MAC address given a known destination IP address, providing a dynamic mapping between IP addresses and their corresponding physical addresses. Since the traffic mirroring device does not have a real IP address, it is naturally impossible to obtain its physical address via ARP responses.
[0072] In this embodiment, when the traffic mirroring device does not have a real IP address, the physical address is obtained by issuing a static address resolution protocol policy. Specifically, a fixed address mapping relationship is established between the access IP address, link information, and physical address to obtain a static address resolution protocol policy containing this fixed mapping relationship. This static address resolution protocol policy is used to obtain the physical address when the packet address is modified.
[0073] S23: For traffic mirroring devices in the service chain, generate backup traffic data packets for the target traffic data packets.
[0074] In this embodiment, the specific process of step S23 can be referred to the corresponding content disclosed in the previous embodiments, and will not be repeated here.
[0075] S24: When the traffic mirroring device does not have a real IP address, the traffic orchestration device obtains the physical address of the traffic mirroring device through a pre-configured static ARP policy.
[0076] In this embodiment, if the traffic mirroring device is pre-configured with a static address resolution protocol policy, the physical address is obtained based on the fixed address mapping relationship configured in the static address resolution protocol policy. That is, if a static address resolution protocol policy containing fixed address mapping relationships is pre-built, the physical address is directly obtained based on the fixed address mapping relationships configured in the static address resolution protocol policy. The static address resolution protocol policy includes IP addresses, MAC addresses, and link information. When the traffic orchestration device looks up routes, it hits this static address resolution protocol policy, and then takes the MAC address from the policy to modify the source or destination address of the data packet; that is, it takes the MAC address from the static address resolution protocol policy to fill the data packet.
[0077] S25: Forward either the target traffic data packet or the backup traffic data packet to the traffic mirroring device.
[0078] S26: Modify the source address of another data packet to the physical address of the traffic mirroring device to obtain the modified data packet.
[0079] S27: Identify the modified data packet as a data packet returned by the traffic mirroring device.
[0080] In this embodiment, the specific process of steps S25 to S27 can be referred to the corresponding content disclosed in the previous embodiments, and will not be repeated here.
[0081] As can be seen, this embodiment first assigns an IP address as the access IP address to the traffic mirroring device and generates link information to connect the traffic mirroring device to the service chain; wherein, the traffic mirroring device does not have a real IP address. Then, a fixed address mapping relationship between the access IP address, link information, and physical address is constructed to obtain a static address resolution protocol strategy containing the fixed address mapping relationship. For the traffic mirroring device in the service chain, a backup traffic data packet of the target traffic data packet is generated. If the traffic mirroring device is pre-configured with a static address resolution protocol strategy, the physical address is obtained based on the fixed address mapping relationship configured in the static address resolution protocol strategy. On this basis, any one of the target traffic data packet and the backup traffic data packet is forwarded to the traffic mirroring device, and the source address of the other data packet is modified to the physical address of the traffic mirroring device to obtain the modified data packet. Finally, the modified data packet is determined as the data packet returned by the traffic mirroring device. This embodiment uses a static address resolution protocol strategy to obtain the physical address of the traffic mirroring device for traffic mirroring devices that do not have a real IP address, thereby realizing the forwarding of traffic to the traffic mirroring device.
[0082] Figure 5 A flowchart illustrating another specific traffic data processing method provided in this application embodiment. See also... Figure 5As shown, this traffic data processing method is applied to a traffic orchestration device, including:
[0083] S31: Use the real IP address of the traffic mirroring device as the access IP address to connect the traffic mirroring device to the service chain.
[0084] Among them, the traffic mirroring device has an IP address and can respond to Address Resolution Protocol broadcasts.
[0085] In this embodiment, the traffic orchestration device uses the real IP address of the traffic mirroring device as the access IP address to connect the traffic mirroring device to the service chain. Traffic mirroring devices need to be connected to the service chain; some traffic mirroring devices have real IP addresses, while others do not, and the methods for connecting to the service chain differ. For traffic mirroring devices with real IP addresses, the traffic orchestration device directly uses the real IP address of the traffic mirroring device as the access IP address during device connection.
[0086] S32: For traffic mirroring devices in the service chain, generate backup traffic data packets for the target traffic data packets.
[0087] In this embodiment, the specific process of step S32 can be referred to the corresponding content disclosed in the previous embodiments, and will not be repeated here.
[0088] S33: When the traffic mirroring device is pre-configured with a real IP address and supports Address Resolution Protocol (ARP), the traffic orchestration device obtains the physical address of the traffic mirroring device through ARP broadcast.
[0089] In this embodiment, if the traffic mirroring device is not pre-configured with a static address resolution protocol policy, an address resolution protocol broadcast is sent to the traffic mirroring device, and the physical address is obtained based on the broadcast response. A traffic mirroring device without a configured static address resolution protocol policy has an IP address and can respond to ARP requests; the traffic orchestration device can request the physical address via ARP broadcast. That is, when the traffic mirroring device is configured with a real IP address and can respond to ARP requests, the traffic orchestration device first sends an ARP broadcast, then finds the MAC address of the traffic mirroring device based on the ARP response, and finally uses that MAC address to fill data packets.
[0090] S34: Forward either the target traffic data packet or the backup traffic data packet to the traffic mirroring device.
[0091] S35: Modify the source address of another data packet to the physical address of the traffic mirroring device to obtain the modified data packet.
[0092] S36: Identify the modified data packet as a data packet returned by the traffic mirroring device.
[0093] In this embodiment, the specific process of steps S34 to S36 can be referred to the corresponding content disclosed in the previous embodiments, and will not be repeated here.
[0094] As can be seen, this embodiment first uses the real IP address of the traffic mirroring device as the access IP address to connect the traffic mirroring device to the service chain; wherein, the traffic mirroring device has a real IP address and can respond to Address Resolution Protocol (ARP) broadcasts. Then, for the traffic mirroring device in the service chain, a backup traffic data packet for the target traffic data packet is generated. If the traffic mirroring device has not been configured with a static ARP policy in advance, an ARP broadcast is sent to the traffic mirroring device, and the physical address is obtained according to the broadcast response. Based on this, either the target traffic data packet or the backup traffic data packet is forwarded to the traffic mirroring device, and the source address of the other data packet is modified to the physical address of the traffic mirroring device, resulting in a modified data packet. Finally, the modified data packet is identified as the data packet returned by the traffic mirroring device. This embodiment uses ARP broadcasts to obtain the physical address of the traffic mirroring device for traffic mirroring devices with IP addresses, thereby realizing the forwarding of traffic to the traffic mirroring device.
[0095] See Figure 6 As shown in the illustration, this application also discloses a traffic data processing device, applied to a traffic orchestration device, comprising:
[0096] The data packet receiving module 101 is used to receive target traffic data packets from the client;
[0097] The data packet replication module 102 is used to generate a backup traffic data packet for the target traffic data packet for the traffic mirroring device in the service chain; the content of the target traffic data packet and the backup traffic data packet is the same.
[0098] The data packet sending module 103 is used to select any data packet from the target traffic data packet and the backup traffic data packet and forward it to the traffic mirroring device;
[0099] The packet receiving simulation module 104 is used to modify the source address of the remaining packet, so that the modified packet is represented as a packet sent from the traffic mirroring device to the traffic orchestration device.
[0100] In this application, the traffic orchestration device receives the target traffic data packet from the client; generates a backup traffic data packet for the target traffic data packet for the traffic mirroring device in the service chain; the target traffic data packet and the backup traffic data packet have the same content; selects either the target traffic data packet or the backup traffic data packet and forwards it to the traffic mirroring device; modifies the source address of the remaining data packet so that the modified data packet is represented as a data packet sent by the traffic mirroring device to the traffic orchestration device, so as to simulate receiving a packet from the traffic mirroring device.
[0101] After receiving the target traffic data packet sent by the client, the traffic orchestration device generates a backup traffic data packet. Then, it selects either the target traffic data packet or the backup traffic data packet to send to the traffic mirroring device and sends it. The source address of the remaining data packet is modified so that the modified data packet representation can represent a data packet sent from the traffic mirroring device to the traffic orchestration device, i.e., simulating receiving a packet from the traffic mirroring device. Therefore, this application addresses the drawback of traffic mirroring devices in a service chain only being able to receive data packets but not return them. When forwarding traffic data packets to traffic mirroring devices in the service chain, the traffic orchestration device generates corresponding backup traffic data packets. By forwarding one of these backup traffic data packets to the traffic mirroring device and modifying the source address of the other, it simulates receiving a packet from the traffic mirroring device, thereby achieving secure traffic orchestration support for traffic mirroring device access and ensuring orchestration continuity.
[0102] In one specific embodiment of this application, the data packet sending module 103 is specifically used to select any one of the target traffic data packets and the backup traffic data packets as the data packet to be forwarded to the traffic mirroring device;
[0103] Change the source address of the selected data packet to the physical address of the traffic orchestration device, and the destination address to the physical address of the traffic mirroring device;
[0104] Send the modified data packet to the traffic mirroring device.
[0105] In one specific embodiment of this application, the packet receiving simulation module 104 is specifically used to modify the source address of the remaining data packet to the physical address of the traffic mirroring device.
[0106] In one specific embodiment of this application, it further includes:
[0107] The physical address acquisition module is used to select either the target traffic data packet or the backup traffic data packet before forwarding it to the traffic mirroring device. In the case that the traffic mirroring device does not have a real IP address, the traffic orchestration device obtains the physical address of the traffic mirroring device through a pre-configured static ARP policy.
[0108] In one specific embodiment of this application, the policy configuration module is used to implement the pre-configuration process of static ARP policies. Specifically, when the traffic mirroring device does not have a real IP address, the traffic orchestration device pre-assigns a physical address and a virtual IP address to the traffic mirroring device and generates link information to connect the traffic mirroring device to the service chain.
[0109] A fixed address mapping relationship is constructed between the virtual IP address and link information of the traffic mirroring device and the physical address, thereby obtaining a static ARP policy containing the fixed address mapping relationship.
[0110] In one specific embodiment of this application, the physical address acquisition module is specifically used to obtain the physical address of the traffic mirroring device by ARP broadcast before selecting any data packet from the target traffic data packet and the backup traffic data packet to forward to the traffic mirroring device, provided that the traffic mirroring device is pre-configured with a real IP address and supports the Address Resolution Protocol (ARP).
[0111] In one specific embodiment of this application, before generating a backup traffic data packet for the target traffic data packet for a traffic mirroring device in the service chain, the method includes: using the real IP address of the traffic mirroring device as the access IP address to connect the traffic mirroring device to the service chain.
[0112] Furthermore, embodiments of this application also provide an electronic device. Figure 7 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.
[0113] Figure 7 This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the traffic data processing method disclosed in any of the foregoing embodiments.
[0114] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.
[0115] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221, computer program 222 and data 223, etc., and the storage method can be temporary storage or permanent storage.
[0116] The operating system 221 manages and controls the various hardware devices and computer programs 222 on the electronic device 20 to enable the processor 21 to perform calculations and processing on the massive amounts of data 223 in the memory 22. The operating system 221 can be Windows Server, Netware, Unix, Linux, etc. In addition to including computer programs capable of performing the traffic data processing methods executed by the electronic device 20 as disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs capable of performing other specific tasks. The data 223 may include target traffic data packets collected by the electronic device 20.
[0117] Furthermore, this application also discloses a storage medium storing a computer program. When the computer program is loaded and executed by a processor, it implements the traffic data processing method steps disclosed in any of the foregoing embodiments.
[0118] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.
[0119] Finally, it should be noted that in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0120] The above provides a detailed description of the traffic data processing method, apparatus, device, and storage medium provided by the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A method for processing traffic data, characterized in that, Applications in flow orchestration equipment, including: Receive the target traffic data packets from the client; For the traffic mirroring device in the service chain, a backup traffic data packet is generated for the target traffic data packet; the content of the target traffic data packet and the backup traffic data packet is the same. Choose either the target traffic data packet or the backup traffic data packet and forward it to the traffic mirroring device; The source address of the remaining data packet is modified so that the modified data packet is characterized as a data packet sent by the traffic mirroring device to the traffic orchestration device.
2. The traffic data processing method according to claim 1, characterized in that, The step of selecting any one of the target traffic data packets and the backup traffic data packets to forward to the traffic mirroring device includes: Select either the target traffic data packet or the backup traffic data packet as the data packet to be forwarded to the traffic mirroring device; Modify the source address of the selected data packet to the physical address of the traffic orchestration device, and modify the destination address to the physical address of the traffic mirroring device; The modified data packet is sent to the traffic mirroring device.
3. The traffic data processing method according to claim 1, characterized in that, Modifying the source address of the remaining data packet includes: Modify the source address of the remaining packet to the physical address of the traffic mirroring device.
4. The traffic data processing method according to claim 2 or 3, characterized in that, Before selecting any data packet from the target traffic data packet and the backup traffic data packet to forward to the traffic mirroring device, the method further includes: When the traffic mirroring device does not have a real IP address, the traffic orchestration device obtains the physical address of the traffic mirroring device through a pre-configured static ARP policy.
5. The traffic data processing method according to claim 4, characterized in that, The pre-configuration process of the static ARP policy includes: In the case where the traffic mirroring device does not have a real IP address, the traffic orchestration device pre-assigns a physical address and a virtual IP address to the traffic mirroring device and generates link information to connect the traffic mirroring device to the service chain. A fixed address mapping relationship is constructed between the virtual IP address of the traffic mirroring device, the link information, and the physical address, thereby obtaining the static ARP policy containing the fixed address mapping relationship.
6. The traffic data processing method according to claim 2 or 3, characterized in that, Before selecting any data packet from the target traffic data packet and the backup traffic data packet to forward to the traffic mirroring device, the following steps are included: When the traffic mirroring device is pre-configured with a real IP address and supports Address Resolution Protocol (ARP), the traffic orchestration device obtains the physical address of the traffic mirroring device through ARP broadcast.
7. The traffic data processing method according to claim 6, characterized in that, Before generating the backup traffic data packet for the target traffic data packet for the traffic mirroring device in the service chain, the process includes: The real IP address of the traffic mirroring device is used as the access IP address to connect the traffic mirroring device to the service chain.
8. A flow data processing device, characterized in that, Applications in flow orchestration equipment, including: The data packet receiving module is used to receive target traffic data packets from the client. The data packet replication module is used to generate a backup traffic data packet for the target traffic data packet for the traffic mirroring device in the service chain; the content of the target traffic data packet and the backup traffic data packet is the same. The data packet sending module is used to select any one of the target traffic data packets and the backup traffic data packets and forward it to the traffic mirroring device; The packet receiving simulation module is used to modify the source address of the remaining packet, so that the modified packet is represented as a packet sent by the traffic mirroring device to the traffic orchestration device.
9. An electronic device, characterized in that, The electronic device includes a processor, a communication interface, and a memory; wherein the communication interface is used to create a data transmission channel between the electronic device and an external device, and the memory is used to store a computer program, which is loaded and executed by the processor to implement the traffic data processing method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, Used to store computer-executable instructions, which, when loaded and executed by a processor, implement the traffic data processing method as described in any one of claims 1 to 7.