A network detection method and system based on a data development flat kit
Patent Information
- Application Number
- CN202310712897.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-15
- Publication Date
- 2026-09-15
- Estimated Expiration
- 2043-06-15
AI Technical Summary
[0006]本申请实施例提供了一种基于数据开发平面套件的网络检测方法和系统,以至少解决在采用DPDK时数据库客户端有时会认为到审计设备的链路不畅通所导致的无法正常审计的问题
[0017]In this embodiment, an auditing device's data plane development kit receives data packets from a database client. These data packets are sent via a predetermined network protocol and are used to probe the connectivity of the network link between the database client and the auditing device. The data plane development kit parses the data packets to obtain the type of network protocol used by the packets. If the network protocol type is a predetermined type, the data plane development kit determines whether the data packet is a data packet used to probe the connectivity of the network link. After confirming that the data packet is a data packet used to probe the connectivity of the network link, the data plane development kit constructs a response data packet for the data packet and sends the constructed response data packet to the database client. The response data packet indicates that the network link between the database client and the auditing device is active, and the network protocol type used in the response data packet is the same as the network protocol type of the data packet. This application solves the problem that sometimes, when using DPDK, the database client may perceive a disconnected link to the auditing device, leading to the inability to perform normal auditing, thus enabling normal database auditing.
Smart Images

Figure CN116980333B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of databases, and more specifically, to a network detection method and system based on data-driven planar suite development. Background Technology
[0002] Database auditing (DBAudit) centers on security incidents and is based on comprehensive and precise auditing. It records database activities on the network in real time, performs granular auditing of database operations for compliance management, and provides real-time alerts for risky behaviors affecting the database. By recording, analyzing, and reporting user access to the database, it helps users generate compliance reports and trace the root causes of incidents. Simultaneously, it uses big data search technology to provide efficient querying of audit reports, pinpointing the causes of incidents for future querying, analysis, and filtering. This strengthens the monitoring and auditing of internal and external database network behavior, improving data asset security.
[0003] When auditing a database, the typical approach is to capture and audit the traffic accessing the database. This traffic is often mirrored before auditing the mirrored traffic. This traffic is then sent to the server hosting the auditing service. When the audited traffic is high, it can put significant pressure on the network interface card (NIC) of the server hosting the auditing service, leading to reduced auditing efficiency.
[0004] To address this issue, DPDK technology is typically used to improve the efficiency of database traffic reception. The Data Plane Development Kit (DPDK) is a collection of function libraries and drivers developed by multiple companies, primarily running on Linux systems. It's used for fast packet processing, significantly improving data processing performance and throughput, and enhancing the efficiency of data plane applications.
[0005] When using DPDK technology for sending and receiving, DPDK takes over the current network interface card (NIC), making it impossible to use the kernel's protocol stack. Data packets are processed entirely by the user program's business layer. Due to these issues, in some scenarios, the client may not perceive the link as working and therefore will not send data packets to the auditing device, ultimately preventing proper auditing. Summary of the Invention
[0006] This application provides a network detection method and system based on a data development plane suite, which at least solves the problem that database clients sometimes perceive the link to the auditing device as unobstructed when using DPDK, resulting in the inability to perform normal auditing.
[0007] According to one aspect of this application, a network detection method based on a data plane development kit is provided, comprising: the data plane development kit of an auditing device receiving a data packet from a database client, wherein the data packet is sent via a predetermined network protocol, and the data packet is used to probe whether the network link between the database client and the auditing device is functioning; the data plane development kit parsing the data packet to obtain the type of network protocol used by the data packet; if the type of the network protocol is a predetermined type, the data plane development kit determining whether the data packet is a data packet for probing whether the network link is functioning; after the data packet is determined to be a data packet for probing whether the network link is functioning, the data plane development kit constructing a response data packet for the data packet and sending the constructed response data packet to the database client; wherein the response data packet is used to indicate that the network link between the database client and the auditing device is functioning, and the network protocol type used by the response data packet is the same as the network protocol type of the data packet.
[0008] Furthermore, it also includes: the data plane development kit receiving auditable database traffic from the database client; wherein, after receiving the response data packet, the database client sends the database traffic to the data plane development kit; and the data plane development kit sends the database traffic to an auditing service running on the auditing device for auditing.
[0009] Furthermore, the data plane development kit constructs the response data packet of the data packet by: the data plane development kit obtaining data for constructing the response data packet from the data packet; and the data plane development kit using the obtained data and constructing the response data packet according to the network protocol used by the data packet.
[0010] Furthermore, the network protocol used by the data packet includes at least one of the following: Internet Control Message Protocol (ICMP), Virtual LAN Protocol (VLAN), Virtual Extensible LAN Protocol (VXLAN), 8021.d, and Routing Encapsulation Protocol (GRE).
[0011] According to another aspect of this application, a network detection system based on a data plane development kit is also provided, located within the data plane development kit. The system includes: a receiving module for receiving data packets from a database client, wherein the data packets are sent via a predetermined network protocol, and the data packets are used to probe whether the network link between the database client and an auditing device is functioning correctly; a parsing module for parsing the data packets to obtain the type of network protocol used by the data packets; a determining module for determining whether the data packets are data packets used to probe whether the network link is functioning correctly, if the type of the network protocol is a predetermined type; and a constructing module for constructing a response data packet after the data packets are determined to be data packets used to probe whether the network link is functioning correctly, and sending the constructed response data packet to the database client; wherein the response data packet is used to indicate that the network link between the database client and the auditing device is functioning correctly, and the network protocol type used by the response data packet is the same as the network protocol type of the data packets.
[0012] Furthermore, it also includes: a sending module, used for the data plane development kit to receive auditable database traffic from the database client; wherein, after receiving the response data packet, the database client sends the database traffic to the data plane development kit; and sends the database traffic to an auditing service running on the auditing device for auditing.
[0013] Furthermore, the construction module is configured to: obtain data for constructing the response data packet from the data packet; and construct the response data packet using the obtained data and according to the network protocol used by the data packet.
[0014] Furthermore, the network protocol used by the data packet includes at least one of the following: Internet Control Message Protocol (ICMP), Virtual LAN Protocol (VLAN), Virtual Extensible LAN Protocol (VXLAN), 8021.d, and Routing Encapsulation Protocol (GRE).
[0015] According to another aspect of this application, an electronic device is also provided, including a memory and a processor; wherein the memory is used to store one or more computer instructions, wherein the one or more computer instructions are executed by the processor to implement the above-described method steps.
[0016] According to another aspect of this application, a readable storage medium is also provided, on which computer instructions are stored, wherein the computer instructions, when executed by a processor, implement the above-described method steps.
[0017] In this embodiment, an auditing device's data plane development kit receives data packets from a database client. These data packets are sent via a predetermined network protocol and are used to probe the connectivity of the network link between the database client and the auditing device. The data plane development kit parses the data packets to obtain the type of network protocol used by the packets. If the network protocol type is a predetermined type, the data plane development kit determines whether the data packet is a data packet used to probe the connectivity of the network link. After confirming that the data packet is a data packet used to probe the connectivity of the network link, the data plane development kit constructs a response data packet for the data packet and sends the constructed response data packet to the database client. The response data packet indicates that the network link between the database client and the auditing device is active, and the network protocol type used in the response data packet is the same as the network protocol type of the data packet. This application solves the problem that sometimes, when using DPDK, the database client may perceive a disconnected link to the auditing device, leading to the inability to perform normal auditing, thus enabling normal database auditing. Attached Figure Description
[0018] The accompanying drawings, which form part of this application, are used to provide a further understanding of this application. The illustrative embodiments and descriptions of this application are used to explain this application and do not constitute an undue limitation of this application. In the drawings:
[0019] Figure 1 This is a flowchart of a network detection method based on data-driven planar suite development according to an embodiment of this application. Detailed Implementation
[0020] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. This application will now be described in detail with reference to the accompanying drawings and embodiments.
[0021] It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases the steps shown or described may be executed in a different order than that shown here.
[0022] DPDK is used in the following implementation. DPDK will be explained first.
[0023] The DataPlane Development Kit (DPDK) is a collection of function libraries and drivers developed by multiple companies and primarily run on Linux systems. It is used for fast packet processing and can greatly improve data processing performance and throughput, thereby increasing the efficiency of data plane applications.
[0024] The volume of communication that the Internet and other internet networks must carry is constantly growing and changing. Today, the widespread use of the real-time responsive World Wide Web and the increasing use of audio, images, and video are driving the growth in Quality of Service (QoS) requirements. To address this growth, the TCP / IP architecture has evolved to support various types of communication with diverse QoS requirements. The Data Plane, one of the three planes of the QoS framework, is responsible for mechanisms that operate directly on the data stream, such as packet queue management, queuing scheduling, and congestion avoidance, playing a crucial role in improving network communication efficiency. Building on this, there is a desire to provide diverse network units and rich functionality, such as application processing, control processing, packet processing, and signal processing, at a lower cost and with shorter product development cycles. To adapt to this new industry trend, DPDK (Data Processing Device) has emerged.
[0025] DPDK enables the processing of network packets and allows the implementation of a TCP / IP protocol stack, operating in user space. There are various ways to implement a TCP / IP protocol stack using DPDK. For example, a DPDK implementation of a TCP / IP protocol stack can provide the following interfaces for application layer calls: a socket creation method, which calls the TCP / IP protocol stack's socket interface to create a socket; a socket connection method, which calls the TCP / IP protocol stack's connect interface; a socket binding method, which calls the TCP / IP protocol stack's bind interface to bind the socket to a specified address and port; and a socket listening method, which calls the TCP / IP protocol stack's listen interface to perform listening operations. The DPDK environment's TCP / IP stack includes several methods for receiving socket connections: receiving data via the `accept` interface and reading data from the socket's circular receive queue. Sending data via the `write` interface adds data to the socket's circular send queue. Closing the connection and releasing resources via the `close` interface. Setting socket properties via the `setsockopt` interface and retrieving properties via the `getsockopt` interface. Other methods for implementing TCP / IP using DPDK are not detailed here.
[0026] During database auditing, the database client sends the traffic to be audited (also known as the data packets to be audited) to the auditing device. In the following implementation, the computing device with the database auditing service installed is referred to as the auditing device. This auditing device can be a standalone server or an auditing service provided by cloud computing. Before sending the traffic to be audited to the auditing device, the client first probes the network link between itself and the auditing device to check its connectivity. It sends network probe packets to the auditing device using a network probe protocol. If the auditing device does not use DPDK technology, the kernel in the operating system where the auditing service resides will respond to the network probe packets by sending a response packet to the client. After receiving the response packet, the client confirms that the network link between itself and the auditing device is connected and then sends the traffic to be audited to the auditing device. If the client does not receive a response packet from the auditing device within a predetermined time, it assumes that the link between itself and the auditing device is not working and will not send the database traffic to be audited to the auditing device.
[0027] If the auditing device uses DPDK technology, but DPDK does not support network probe protocols, DPDK will discard the received network probe packets and will not send response packets to the client. As a result, the client will not send the database traffic to be audited to the auditing device, which will lead to the failure of database auditing.
[0028] To address the aforementioned issues, the following implementation provides a network detection method based on data-driven planar suite development. Figure 1 This is a flowchart of a network detection method based on data development of planar suites according to an embodiment of this application. The following describes... Figure 1 The steps involved in the method described are explained.
[0029] In step S102, the data plane development kit of the auditing device receives a data packet from the database client, wherein the data packet is sent via a predetermined network protocol and is used to detect whether the network link between the database client and the auditing device is working properly.
[0030] In step S104, the data plane development kit parses the data packet to obtain the type of network protocol used by the data packet.
[0031] Step S106: The data plane development kit determines whether the data packet is a data packet for probing whether the network link is working properly, provided that the network protocol type is a predetermined type.
[0032] In one optional implementation, the network protocol type and the values of predetermined fields in the data packets supported by that network protocol are pre-configured. When a predetermined field has a pre-defined value, it indicates that the data packet containing that pre-defined field is a data packet used to probe the network link's connectivity. During configuration, an input interface can be provided, allowing the user to input the network protocol type and the values of the predetermined fields.
[0033] Step S108: After the data packet is a data packet probing whether the network link is working, the data plane development kit constructs a response data packet for the data packet and sends the constructed response data packet to the database client; wherein, the response data packet is used to indicate that the network link between the database client and the auditing device is working, and the network protocol type used by the response data packet is the same as the network protocol type of the data packet.
[0034] As another optional implementation, a predetermined duration can be configured in the audit service. If the audit service does not receive any database traffic for auditing from the data development plane suite within the predetermined duration, the audit service sends an alarm message to a pre-configured administrator account. The alarm message indicates that the audit service has not received any database traffic within the predetermined duration. Optionally, the predetermined duration may vary for different time periods each day. The predetermined duration for each time period is calculated based on statistics of historically received audit data traffic.
[0035] In another alternative implementation, a second predetermined duration can be configured in the data development plane suite. If the data development plane suite does not receive database traffic for auditing within the second predetermined duration, the data development plane suite will no longer be responsible for receiving network data packets, and will hand over the reception of network data packets to the kernel of the operating system in which the data development plane suite resides for processing.
[0036] The above steps resolve the issue where database clients sometimes perceive a disconnected link to the auditing device when using DPDK, thus enabling normal database auditing.
[0037] Optionally, for normal auditing, the above method may further include the following steps: the data plane development kit receives the database traffic to be audited from the database client; wherein, after receiving the response data packet, the database client sends the database traffic to the data plane development kit; the data plane development kit sends the database traffic to the auditing service running on the auditing device for auditing.
[0038] There are many methods for constructing response packets. For example, the data plane development kit constructs the response packet by: the data plane development kit obtaining data for constructing the response packet from the packet; and the data plane development kit using the obtained data and constructing the response packet according to the network protocol used by the packet.
[0039] The above steps support various network protocols. For example, the network protocol used by the data packet includes at least one of the following: Internet Control Message Protocol (ICMP), Virtual LAN Protocol (VLAN), Virtual Extensible LAN Protocol (VXLAN), 802.d, and GRE Routing Encapsulation Protocol. The following examples illustrate the above implementation. In the following examples, when using DPDK technology for sending and receiving, because DPDK takes over the current network card, the kernel's protocol stack cannot be used, and the data packet is entirely processed by the user program's service layer. Due to this problem, in some scenarios, the client may not consider the link to be open and therefore will not send the data packet to the auditing device, ultimately resulting in the inability to perform normal auditing.
[0040] In the following example, DPDK may not support configuring IP addresses. Instead, it captures specific packets and constructs specific response packets (i.e., response data packets), thus eliminating the need to implement the complete protocol stack. In this example, by sending response packets to the link detection protocol, the client is made to believe the link is open, achieving the purpose of normal data redirection. This example uses the ICMP protocol as the network probe protocol for illustration. The example may include the following steps:
[0041] a. The auditing device uses DPDK technology to take over the device's network card and begins receiving data packets from the network card.
[0042] b. The client uses the ICMP protocol to check whether the network status of the link is normal.
[0043] c. Upon receiving and parsing the data packet, the auditing equipment discovered that it was an ICMP protocol packet.
[0044] This step adds ICMP protocol packet detection: 1) Obtain the 12-byte destination MAC and source MAC. 2) Obtain the current packet's 2-byte protocol type, 0x0800, indicating IPv4. 3) Obtain the header version and header length from the 1-byte IP header. 4) Use the header length to obtain packet data information. 5) The 10th byte of the packet data contains a value of 01, indicating that the data carries the ICMP protocol. 6) Skip the IP header to obtain the ICMP protocol data and inspect it. 7) If the first byte is 08, it indicates a Request for Auth (RFA) packet.
[0045] d. The auditing device returns a standard ICMP response packet to the client according to the ICMP protocol.
[0046] This step adds an ICMP protocol packet return packet (i.e., a response packet, also called an echo packet). The construction of this response packet can be achieved through the following steps: 1) Construct the MAC layer by writing the source and destination MAC addresses of the received ICMP packet. 2) Write 0x0800 to indicate that the IP layer is IPv4. 3) Write the IPv4 layer protocol content, where the source and destination IP addresses use the destination and source IP addresses of the received packet, and the next layer protocol is 01 to indicate the ICMP protocol, updating checksums and other flag bits. 4) Construct the ICMP packet, where ICMP uses type 0 to indicate a normal link, and updates other timestamps and other flags. 5) Send the packet from the network interface card (NIC) to the client device's NIC.
[0047] e. When the client receives the ICMP response packet, it considers the link to be normal and sends subsequent packets to the auditing device.
[0048] Through the above steps, the protocol content of the data packets is detected. Protocol analysis reveals that a ping packet link detection is currently underway, prompting the creation of a response packet to be returned to the client. Although the above network detection protocol (also known as a link detection protocol) is illustrated using ICMP as an example, it is not limited to this. For instance, link detection protocols can also include, but are not limited to, the following protocols: vlan / vxlan / 8021.d / GRE, etc.
[0049] In this embodiment, an electronic device is provided, including a memory and a processor. The memory stores a computer program, and the processor is configured to run the computer program to perform the methods described in the above embodiments.
[0050] The aforementioned program can run on a processor or be stored in memory (or a computer-readable medium). Computer-readable media include both permanent and non-permanent, removable and non-removable media, and information storage can be achieved by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.
[0051] These computer programs may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes can be implemented using different modules, and different steps can be implemented using different modules.
[0052] This embodiment provides such an apparatus or system. The system, called a network detection system based on the data plane development kit, is located within the data plane development kit. The system includes: a receiving module for receiving data packets from a database client, wherein the data packets are sent via a predetermined network protocol and are used to probe the connectivity of the network link between the database client and an auditing device; a parsing module for parsing the data packets to obtain the type of network protocol used by the data packets; a determining module for determining whether the data packets are data packets used to probe the connectivity of the network link if the network protocol type is a predetermined type; and a constructing module for constructing a response data packet after the data packets are determined to be data packets used to probe the connectivity of the network link, and sending the constructed response data packet to the database client; wherein the response data packet indicates that the network link between the database client and the auditing device is accessible, and the network protocol type used by the response data packet is the same as the network protocol type of the data packets.
[0053] The system or apparatus is used to implement the functions of the methods in the above embodiments. Each module in the system or apparatus corresponds to each step in the method, as has been described in the method and will not be repeated here.
[0054] Optionally, it further includes: a sending module, configured to receive auditable database traffic from the database client after the data plane development kit receives the response data packet; wherein the database client sends the database traffic to the data plane development kit after receiving the response data packet; and sends the database traffic to an auditing service running on the auditing device for auditing.
[0055] Optionally, the construction module is configured to: obtain data for constructing the response data packet from the data packet; and construct the response data packet using the obtained data and according to the network protocol used by the data packet.
[0056] Optionally, the network protocol used by the data packet includes at least one of the following: Internet Control Message Protocol (ICMP), Virtual LAN Protocol (VLAN), Virtual Extensible LAN Protocol (VXLAN), 8021.d, and Routing Encapsulation Protocol (GRE).
[0057] The above implementation method solves the problem that database clients sometimes perceive the link to the auditing device as unsustainable when using DPDK, thus enabling normal database auditing.
[0058] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A network detection method based on data development flat kit, characterized in that, include: The audit device's data plane development kit receives data packets from a database client, wherein the data packets are sent via a predetermined network protocol and are used to probe the connectivity of the network link between the database client and the audit device. The data plane development kit parses the data packets to obtain the type of network protocol used by the data packets; The data plane development kit determines whether the data packet is a data packet for probing whether the network link is working properly when the network protocol type is a predetermined type. After the data packet is a data packet that probes whether the network link is working, the data plane development kit constructs a response data packet for the data packet and sends the constructed response data packet to the database client; wherein, the response data packet is used to indicate that the network link between the database client and the auditing device is working, and the network protocol type used by the response data packet is the same as the network protocol type of the data packet; The data plane development kit receives auditable database traffic from the database client; wherein, after receiving the response data packet, the database client sends the database traffic to the data plane development kit; The data plane development kit sends the database traffic to the audit service running on the audit device for auditing; Specifically, a predetermined duration is configured in the audit service. If the audit service does not receive any database traffic for auditing from the data development plane suite within the predetermined duration, the audit service sends an alarm message to a pre-configured administrator account. The alarm message is used to indicate that the audit service has not received any database traffic within the predetermined duration. The predetermined duration is different in different time periods of the day, and the predetermined duration in each time period is obtained by statistically analyzing the audit data traffic received in history.
2. The method according to claim 1, characterized in that, The response data packet constructed by the data plane development kit includes: The data plane development kit obtains the data for constructing the response data packet from the data packet; The data plane development kit uses the acquired data and constructs the response data packet according to the network protocol used by the data packet.
3. The method according to claim 2, characterized in that, The network protocol used by the data packet includes at least one of the following: Internet Control Message Protocol (ICMP), Virtual Local Area Network Protocol (VLAN), Virtual Extensible Local Area Network Protocol (VXLAN), 802.1d, and GRE (Gateway Encapsulation Protocol).
4. An electronic device comprising a memory and a processor; wherein, The memory is used to store one or more computer instructions, wherein the one or more computer instructions are executed by the processor to implement the steps of the method according to any one of claims 1 to 3.
5. A readable storage medium having computer instructions stored thereon, wherein, When executed by a processor, the computer instructions implement the steps of the method described in any one of claims 1 to 3.