Interference flow injection method, device, equipment, storage medium and test system
By obtaining and filtering traffic data from external real networks and using LSTM network model to classify and injecting into virtual scene networks, the problem of low simulation degree of virtual scene networks in the existing technology is solved, and interference traffic injection with high simulation and timeliness is achieved, which improves the testing difficulty and simulation accuracy.
Patent Information
- Application Number
- CN202410368303.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-28
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-03-28
AI Technical Summary
The existing virtual scene network has low simulation degree and is difficult to simulate the real network environment. The simulation traffic is easy to detect, which cannot effectively improve the testing difficulty and simulation accuracy.
By obtaining the traffic data of the external real network, using the trained LSTM network model for classification, selecting traffic data that meets the injection needs, and injecting it into the virtual scene network to achieve the injection of interfering traffic.
The maximum traffic simulation is achieved, the simulation degree of the virtual network environment is improved, the injected interfering traffic is time-sensitive and random, and the difficulty of cracking traffic information is increased.
Smart Images

Figure CN118316882B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information transmission technology, and in particular to an interference flow injection method, device, equipment, storage medium and test system. Background Art
[0002] Virtual scene networks built based on the openstack virtual machine network structure are often used to form test systems. They are used by contestants or students in competitions, training, or teaching scenarios to test user capabilities. During the test, in order to increase the difficulty of questions and pre-set scenarios, interference traffic is usually added to the virtual scene network.
[0003] At present, artificial editing, rewriting or random generation are usually used to add interference traffic to the virtual scene network, which increases the difficulty of testing. However, such methods are difficult to simulate the real network environment, the simulation degree is low, and the interference traffic is easy to be detected. Summary of the invention
[0004] Based on the problem of low simulation degree of existing virtual scene networks, the present invention provides an interference traffic injection method, device, equipment, storage medium and test system, which can inject interference traffic from an external real network into the virtual scene network to achieve maximum traffic simulation and improve the simulation degree of the virtual network environment.
[0005] In a first aspect, the present invention provides a method for injecting interference traffic, comprising:
[0006] Obtain a virtual scene network and injection requirements for injecting interference traffic; wherein the virtual scene network is built based on the openstack virtual machine network structure; the injection requirements include the target virtual machine terminal to be injected with interference traffic and the interference traffic requirements;
[0007] Based on the virtual scene network and the injection requirement, determining a target virtual machine terminal in the virtual scene network;
[0008] Select an external real network and obtain traffic data in real time;
[0009] Based on the acquired traffic data, the traffic data that meets the injection requirements is classified through the trained LSTM network model, and the traffic data that meets the injection requirements is selected; wherein the LSTM network model is trained for the injection requirements, and is trained with the sample traffic data as input and the corresponding traffic data classification results as output;
[0010] Based on the determined target virtual machine terminal, the selected traffic data is injected into the virtual scene network to achieve interference traffic injection.
[0011] Optionally, determining a target virtual machine terminal in the virtual scene network based on the virtual scene network and the injection requirement includes:
[0012] Based on the virtual scene network and the injection requirement, determining the computing node where the target virtual machine terminal in the virtual scene network is located;
[0013] Based on the virtual scene network and the injection requirement, determining a namespace of a target virtual machine terminal network in the virtual scene network;
[0014] Based on the virtual scene network and the injection requirement, a target virtual machine terminal network card in the virtual scene network is determined.
[0015] Optionally, selecting an external real network and acquiring traffic data in real time includes:
[0016] Determine traffic identification rules based on injection requirements;
[0017] Based on the determined traffic identification rules, identify the external real network that transmits the corresponding traffic data;
[0018] According to the preset time period, the traffic data is intercepted in real time in the determined external real network.
[0019] Optionally, injecting the selected traffic data into the virtual scene network based on the determined target virtual machine terminal includes:
[0020] Temporarily store the selected traffic data in the form of pcap packets, and clear the pcap packets without content;
[0021] Modify the target address of the temporarily stored pcap packet, and send the pcap script and the modified pcap packet to the computing node where the target virtual machine terminal is located; wherein the pcap script is used to parse the modified pcap packet;
[0022] Based on the namespace of the target virtual machine terminal network and the target virtual machine terminal network card in the virtual scene network, the modified pcap package is parsed frame by frame by executing the pcap script, and is sent to the determined network segment where the target virtual machine terminal network card is located.
[0023] Optionally, modifying the target address of the temporarily stored pcap packet includes:
[0024] Change the destination address of the pcap packet to the IP address of the network segment where the target virtual machine terminal network card is located, or
[0025] Randomly generate new destination address for pcap packets.
[0026] Optionally, the pcap script includes a scapy program based on the python language;
[0027] The method of executing the pcap script, parsing the modified pcap package frame by frame, and sending the package to the network segment where the target virtual machine terminal network card is located comprises:
[0028] Call the scapy program to parse the modified pcap packet frame by frame and send it to the network segment where the target virtual machine terminal network card is located.
[0029] In a second aspect, the present invention further provides an interference flow injection device, comprising:
[0030] An environment acquisition module is used to acquire a virtual scene network and injection requirements for injecting interference traffic; wherein the virtual scene network is built based on the openstack virtual machine network structure; the injection requirements include a target virtual machine terminal and interference traffic requirements to be injected into the interference traffic;
[0031] A target orientation module, used to determine a target virtual machine terminal in the virtual scene network based on the virtual scene network and the injection requirement;
[0032] Traffic interception module, used to select external real network and obtain traffic data in real time;
[0033] A data extraction module is used to classify the acquired traffic data through a trained LSTM network model to select traffic data that meets the injection requirements; wherein the LSTM network model is trained for the injection requirements, with sample traffic data as input and corresponding traffic data classification results as output;
[0034] The interference injection module is used to inject selected traffic data into the virtual scene network based on the determined target virtual machine terminal to achieve interference traffic injection.
[0035] In a third aspect, the present invention also provides a test system, which includes a virtual scene network for injecting interference traffic; wherein the virtual scene network is built based on an openstack virtual machine network structure; the test system adopts an interference traffic injection method as described in any one of the above items to inject interference traffic into the virtual scene network.
[0036] In a fourth aspect, the present invention further provides an electronic device, comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, any of the above-mentioned interference traffic injection methods is implemented.
[0037] In a fifth aspect, the present invention further provides a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, enables the computer to execute any one of the above-mentioned interference traffic injection methods.
[0038] The present invention provides an interference traffic injection method, device, electronic device and storage medium. The present invention obtains and screens traffic from an external real network in real time, obtains required traffic and injects it into a virtual scene network. The injected interference traffic is timely and random, and can achieve maximum traffic simulation, thereby improving the simulation degree of the virtual network environment.
[0039] The present invention also provides a test system, which uses the above-mentioned interference traffic injection method to inject interference traffic into the virtual scene network, which can add highly simulated interference traffic in the virtual scene network, improve the test difficulty of the test system, and broaden the test scope. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0041] Figure 1 This is a flow chart of an interference flow injection method provided by an embodiment of the present invention;
[0042] Figure 2 is a hardware architecture diagram of an electronic device provided by an embodiment of the present invention;
[0043] Figure 3 It is a structural diagram of an interference flow injection device provided by one embodiment of the present invention. DETAILED DESCRIPTION
[0044] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0045] As mentioned above, virtual scene networks built based on the openstack virtual machine network structure are often used to form test systems for contestants or students to use in competitions, training, or teaching scenarios to test user capabilities. Injecting interference traffic into the normal traffic of the virtual scene network increases the difficulty of cracking and distinguishing normal traffic, which can enrich the content of competitions or teaching. For example, from the terminal in the network scene, through the packet capture tool, data packets (Packet) outside the current network scene can be captured, and students or contestants can distinguish them through technical means to improve the students and contestants' ability to distinguish.
[0046] At present, it is common to add interference traffic to the virtual scene network by artificial writing, rewriting or random generation, which increases the difficulty of testing. However, this method is difficult to simulate the real network environment, the simulation degree is low, and the interference traffic is easy to be detected, which is not conducive to testing. In view of this, in order to solve the problem of low simulation degree of existing virtual scene networks, increase the test difficulty of the test system, and broaden the test scope, the present invention provides an interference traffic injection method, device, equipment, storage medium and test system.
[0047] The specific implementation of the above concept is described below.
[0048] Please refer to Figure 1 , an embodiment of the present invention provides a method for injecting interference traffic, the method comprising:
[0049] Step 100, obtaining a virtual scenario network and injection requirements for injecting interference traffic;
[0050] The virtual scene network is built based on the openstack virtual machine network structure; the injection requirements include the target virtual machine terminal and the interference traffic requirements to be injected with the interference traffic;
[0051] The virtual scene network can be built by the user based on the openstack virtual machine network structure, or the corresponding file can be directly imported; the interference flow requirement may include information such as flow type;
[0052] Step 102, based on the virtual scene network and the injection requirement, determining a target virtual machine terminal in the virtual scene network;
[0053] Step 104, selecting an external real network and obtaining traffic data in real time;
[0054] External real network, that is, the area where traffic occurs over a wide area, such as the Internet;
[0055] Step 106, based on the acquired traffic data, the traffic data that meets the injection requirements is classified through the trained LSTM network model;
[0056] The LSTM network model is trained for injection requirements, with sample traffic data as input and corresponding traffic data classification results as output; if the interference traffic requirement is a traffic type, such as mp4, then the traffic data classification result is the corresponding traffic type, and the LSTM network model can classify the input traffic data into different types, such as mp4, avi, etc., to avoid manual screening and judgment;
[0057] According to the flow data classification result, the flow data that meets the injection requirement can be selected; if the interference flow requirement is the flow type, such as mp4, then according to the flow data classification result, it can be determined which data in the acquired flow data is mp4 data;
[0058] Step 108, based on the determined target virtual machine terminal, inject the selected traffic data into the virtual scene network to achieve interference traffic injection.
[0059] The above-mentioned embodiment obtains the virtual scene network and injection requirements for injecting interference traffic according to actual needs, selects an external real network, and obtains traffic data in real time, and injects it into the virtual scene network. The injected interference traffic has a high degree of simulation, timeliness and randomness, and can effectively simulate the real network environment, increasing the difficulty of cracking traffic information.
[0060] Optionally, step 102 further includes:
[0061] Step 102-0, based on the virtual scene network and the injection requirement, determining the computing node where the target virtual machine terminal in the virtual scene network is located;
[0062] Compute nodes refer to nodes at the openstack platform level;
[0063] Step 102-2, based on the virtual scene network and the injection requirement, determining the namespace of the target virtual machine terminal network in the virtual scene network;
[0064] Step 102-4: Based on the virtual scene network and the injection requirement, determine the target virtual machine terminal network card in the virtual scene network.
[0065] Commonly used traffic injection tools, such as tcpreplay program, scapy program, etc., when used, generally act on the virtual network device (ie, tap) of the physical host network card. When the openstack virtual machine is created, each network card will also have a corresponding virtual network device on the host machine, but due to network isolation, the injection tool cannot directly act on the virtual network device. Considering the basic principle of the openstack virtual machine network structure, since each time a network is created, a namespace with the same name (ie, namespace) will be created on the host machine, when the virtual machine is created, the network (network) mounting will also mount the virtual machine under the corresponding namespace, therefore, interference traffic can be sent by entering the corresponding namespace. The above embodiment determines the computing node where the target virtual machine terminal is located in the virtual scene network, the namespace of the target virtual machine terminal network, and the target virtual machine terminal network card, so as to determine the virtual machine terminal to be injected with traffic in the virtual scene network; the present invention bypasses the limitations of the openstack virtual machine network itself, acts on the target terminal network card in a directional manner, and the implementation scheme is more flexible.
[0066] Optionally, step 104 further includes:
[0067] Step 104-0, determining a flow identification rule according to the injection requirement;
[0068] Specific traffic identification rules can be set as needed, such as traffic type, traffic name, etc.
[0069] Step 104-2, based on the determined traffic identification rule, identifying the external real network that transmits the corresponding traffic data;
[0070] Identify the external real network that transmits traffic that meets the traffic identification rules, and refer to the traffic identification method in the prior art, which will not be further limited here;
[0071] Step 104-4, intercepting traffic data in real time in the determined external real network according to a preset time period;
[0072] The duration and frequency of intercepting traffic in the determined external real network can be set according to actual needs. The above embodiment dynamically intercepts traffic data that meets the traffic identification rules from the external real network, meets the injection requirements, and has randomness, which can effectively increase the difficulty of cracking whether the traffic data is normal traffic.
[0073] Optionally, for step 106, the LSTM network model is trained in the following manner:
[0074] Build LSTM network model;
[0075] Obtain sample traffic data and corresponding traffic data classification results to form a sample set; the sample set includes multiple samples;
[0076] Divide the sample set into a training set and a test set;
[0077] Based on the obtained training set and test set, the constructed LSTM network model is trained.
[0078] Different LSTM network models can be selected for different injection requirements to obtain more accurate classification results. The LSTM network model can be used to automatically identify and classify traffic data.
[0079] Optionally, step 108 further includes:
[0080] Step 108-0, temporarily storing the selected traffic data in the form of pcap packets, and clearing the pcap packets without content;
[0081] Step 108-2, modifying the target address of the temporarily stored pcap packet, and sending the pcap script and the modified pcap packet to the computing node where the target virtual machine terminal is located; wherein the pcap script is used to parse the modified pcap packet;
[0082] Step 108-4, based on the namespace of the target virtual machine terminal network in the virtual scene network and the target virtual machine terminal network card, by executing the pcap script, the modified pcap package is parsed frame by frame, and sent to the determined network segment where the target virtual machine terminal network card is located.
[0083] The above embodiment uses the LSTM network model to filter out the required traffic, temporarily stores it in the form of pcap packets, and then removes the data packets without content to achieve the maximum degree of traffic simulation.
[0084] Further, with respect to step 108-2, the modification of the target address of the temporarily stored pcap packet includes:
[0085] Change the destination address of the pcap packet to the IP address of the network segment where the target virtual machine terminal network card is located, or
[0086] Randomly generate new destination address for pcap packets.
[0087] The target address of the pcap packet can be set as needed. The target address of the pcap packet affects the destination of the interference traffic data, but does not affect the injection of interference traffic. By modifying the target address of the pcap packet to the IP of the network segment where the target virtual machine terminal network card is located, or randomly generating a new target address for the pcap packet, the simulation degree of the virtual network environment is improved.
[0088] Optionally, the pcap script includes a scapy program based on the python language;
[0089] With respect to step 108-4, the pcap script is executed to parse the modified pcap packet frame by frame, and the packet is sent to the network segment where the target virtual machine terminal network card is located, including:
[0090] Call the scapy program to parse the modified pcap packet frame by frame and send it to the network segment where the target virtual machine terminal network card is located.
[0091] The Scapy program is a powerful interactive data packet processing program that can forge or decode data packets of various protocols, and realize functions such as online sending, capturing, matching requests and responses. In other embodiments, the target address of the temporarily stored pcap packet can also be modified by the Scapy program.
[0092] In other embodiments, other methods may be used to implement step 108-4, for example:
[0093] The pcap script includes a tcpreplay program based on the python language;
[0094] With respect to step 108-4, the pcap script is executed to parse the modified pcap packet frame by frame, and the packet is sent to the network segment where the target virtual machine terminal network card is located, including:
[0095] Call the tcpreplay program to parse the modified pcap packet frame by frame and send it to the network segment where the target virtual machine terminal network card is located.
[0096] An embodiment of the present invention also provides a test system, which includes a virtual scene network for injecting interference traffic; wherein the virtual scene network is built based on an openstack virtual machine network structure; the test system adopts an interference traffic injection method as described in any embodiment of the present invention to inject interference traffic into the virtual scene network.
[0097] The above-mentioned embodiment adopts the aforementioned interference traffic injection method to inject interference traffic into the virtual scene network, which can add highly simulated interference traffic in the virtual scene network, increase the test difficulty of the test system, broaden the test scope, and can be applied to scenarios such as competitions, training or teaching.
[0098] like Figure 2 , Figure 3 As shown, an embodiment of the present invention provides a device for injecting interference traffic. The device embodiment can be implemented by software, or by hardware or a combination of software and hardware. From the hardware level, Figure 2As shown, it is a hardware architecture diagram of an electronic device where an interference flow injection device provided by an embodiment of the present invention is located, except Figure 2 In addition to the processor, memory, network interface, and non-volatile memory shown, the electronic device in the embodiment may also include other hardware, such as a forwarding chip responsible for processing messages, etc. Taking software implementation as an example, Figure 3 As shown, as a device in a logical sense, the CPU of the electronic device in which it is located reads the corresponding computer program in the non-volatile memory into the memory and runs it. This embodiment provides an interference flow injection device, including:
[0099] The environment acquisition module 301 is used to obtain a virtual scene network and injection requirements for injecting interference traffic; wherein the virtual scene network is built based on the openstack virtual machine network structure; the injection requirements include the target virtual machine terminal to be injected with interference traffic and the interference traffic requirements;
[0100] A target orientation module 302 is used to determine a target virtual machine terminal in the virtual scene network based on the virtual scene network and the injection requirement;
[0101] The traffic interception module 303 is used to select an external real network and obtain traffic data in real time;
[0102] The data extraction module 304 is used to classify the acquired traffic data through the trained LSTM network model to select the traffic data that meets the injection requirements; wherein the LSTM network model is trained for the injection requirements, and is trained with the sample traffic data as input and the corresponding traffic data classification result as output;
[0103] The interference injection module 305 is used to inject the selected traffic data into the virtual scene network based on the determined target virtual machine terminal to achieve interference traffic injection.
[0104] In an embodiment of the present invention, the environment acquisition module 301 can be used to execute step 100 in the above method embodiment, the target orientation module 302 can be used to execute step 102 in the above method embodiment, the traffic interception module 303 can be used to execute step 104 in the above method embodiment, the data extraction module 304 can be used to execute step 106 in the above method embodiment, and the interference injection module 305 can be used to execute step 108 in the above method embodiment.
[0105] It is to be understood that the structure illustrated in the embodiment of the present invention does not constitute a specific limitation on an interference flow injection device. In other embodiments of the present invention, an interference flow injection device may include more or fewer components than those shown in the figure, or combine some components, or split some components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.
[0106] The information interaction, execution process and other contents between the modules in the above-mentioned device are based on the same concept as the embodiment of the method of the present invention. For specific contents, please refer to the description in the embodiment of the method of the present invention, and no further description is given here.
[0107] An embodiment of the present invention further provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, an interference traffic injection method in any embodiment of the present invention is implemented.
[0108] An embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the processor executes an interference traffic injection method in any embodiment of the present invention.
[0109] Specifically, a system or device equipped with a storage medium can be provided, on which software program code that implements the functions of any of the above-mentioned embodiments is stored, and a computer (or CPU or MPU) of the system or device can read and execute the program code stored in the storage medium.
[0110] In this case, the program code itself read from the storage medium can realize the function of any one of the above-mentioned embodiments, and thus the program code and the storage medium storing the program code constitute a part of the present invention.
[0111] The storage medium embodiments for providing the program code include a floppy disk, a hard disk, a magneto-optical disk, an optical disk (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), a magnetic tape, a non-volatile memory card, and a ROM. Alternatively, the program code can be downloaded from a server computer by a communication network.
[0112] In addition, it should be clear that the functions of any of the above embodiments can be implemented not only by executing the program code read by the computer, but also by enabling an operating system operating on the computer to complete part or all of the actual operations based on instructions from the program code.
[0113] In addition, it can be understood that the program code read from the storage medium is written to a memory provided in an expansion board inserted into the computer or to a memory provided in an expansion module connected to the computer, and then based on the instructions of the program code, a CPU installed on the expansion board or expansion module is enabled to perform part or all of the actual operations, thereby realizing the functions of any of the above-mentioned embodiments.
[0114] Each embodiment of the present invention has at least the following beneficial effects:
[0115] 1. The present invention provides a method, device, electronic device and storage medium for injecting interference traffic, which obtains and filters traffic from an external real network in real time, obtains required traffic, and injects it into a virtual scene network to achieve maximum traffic simulation;
[0116] 2. The present invention also provides a test system, which uses the aforementioned interference traffic injection method to inject interference traffic into the virtual scene network, which can add highly simulated interference traffic in the virtual scene network, increase the test difficulty of the test system, and broaden the test scope.
[0117] It should be noted that, in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the statement "comprise a ..." do not exclude the presence of other identical factors in the process, method, article or device including the elements.
[0118] A person of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above method embodiments; and the aforementioned storage medium includes: ROM, RAM, magnetic disk or optical disk, etc., various media that can store program codes.
[0119] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for injecting interference traffic, characterized in that: include: Obtain a virtual scene network and injection requirements for injecting interference traffic; wherein the virtual scene network is built based on the openstack virtual machine network structure; the injection requirements include the target virtual machine terminal to be injected with interference traffic and the interference traffic requirements; Based on the virtual scene network and the injection requirement, determining a target virtual machine terminal in the virtual scene network; Select an external real network and obtain traffic data in real time; Based on the acquired traffic data, the traffic data that meets the injection requirements is classified through the trained LSTM network model, and the traffic data that meets the injection requirements is selected; wherein the LSTM network model is trained for the injection requirements, and is trained with the sample traffic data as input and the corresponding traffic data classification results as output; Based on the determined target virtual machine terminal, the selected traffic data is injected into the virtual scene network to implement interference traffic injection; the target virtual machine terminal in the virtual scene network is determined based on the virtual scene network and the injection requirement, including: Based on the virtual scene network and the injection requirement, determining the computing node where the target virtual machine terminal in the virtual scene network is located; Based on the virtual scene network and the injection requirement, determining a namespace of a target virtual machine terminal network in the virtual scene network; Based on the virtual scene network and the injection requirement, determining a target virtual machine terminal network card in the virtual scene network; The step of injecting the selected traffic data into the virtual scene network based on the determined target virtual machine terminal includes: Temporarily store the selected traffic data in the form of pcap packets, and clear the pcap packets without content; Modify the target address of the temporarily stored pcap package, and send the pcap script and the modified pcap package to the computing node where the target virtual machine terminal is located; wherein the pcap script is used to parse the modified pcap package; Based on the namespace of the target virtual machine terminal network and the target virtual machine terminal network card in the virtual scene network, the modified pcap package is parsed frame by frame by executing the pcap script, and is sent to the determined network segment where the target virtual machine terminal network card is located.
2. The method according to claim 1, characterized in that The selecting of an external real network and obtaining traffic data in real time includes: Determine traffic identification rules based on injection requirements; Based on the determined traffic identification rules, identify the external real network that transmits the corresponding traffic data; According to the preset time period, the traffic data is intercepted in real time in the determined external real network.
3. The method according to claim 1, characterized in that The modification of the target address of the temporarily stored pcap package includes: Change the destination address of the pcap packet to the IP address of the network segment where the target virtual machine terminal network card is located, or Randomly generate new destination address for pcap packets.
4. The method according to claim 1, characterized in that The pcap script includes a scapy program based on the python language; The method of executing the pcap script, parsing the modified pcap package frame by frame, and sending the package to the network segment where the target virtual machine terminal network card is located comprises: Call the scapy program to parse the modified pcap packet frame by frame and send it to the network segment where the target virtual machine terminal network card is located.
5. A disturbance flow injection device, characterized in that: include: An environment acquisition module is used to acquire a virtual scene network and injection requirements for injecting interference traffic; wherein the virtual scene network is built based on the openstack virtual machine network structure; the injection requirements include a target virtual machine terminal and interference traffic requirements to be injected into the interference traffic; A target orientation module, used to determine a target virtual machine terminal in the virtual scene network based on the virtual scene network and the injection requirement; Traffic interception module, used to select external real network and obtain traffic data in real time; A data extraction module is used to classify the acquired traffic data through a trained LSTM network model to select traffic data that meets the injection requirements; wherein the LSTM network model is trained for the injection requirements, with sample traffic data as input and corresponding traffic data classification results as output; An interference injection module, used to inject selected traffic data into the virtual scene network based on a determined target virtual machine terminal to implement interference traffic injection; The step of determining a target virtual machine terminal in the virtual scene network based on the virtual scene network and the injection requirement includes: Based on the virtual scene network and the injection requirement, determining the computing node where the target virtual machine terminal in the virtual scene network is located; Based on the virtual scene network and the injection requirement, determining a namespace of a target virtual machine terminal network in the virtual scene network; Based on the virtual scene network and the injection requirement, determining a target virtual machine terminal network card in the virtual scene network; The step of injecting the selected traffic data into the virtual scene network based on the determined target virtual machine terminal includes: Temporarily store the selected traffic data in the form of pcap packets, and clear the pcap packets without content; Modify the target address of the temporarily stored pcap package, and send the pcap script and the modified pcap package to the computing node where the target virtual machine terminal is located; wherein the pcap script is used to parse the modified pcap package; Based on the namespace of the target virtual machine terminal network and the target virtual machine terminal network card in the virtual scene network, the modified pcap package is parsed frame by frame by executing the pcap script, and is sent to the determined network segment where the target virtual machine terminal network card is located.
6. A testing system, characterized in that: The test system includes a virtual scene network for injecting interference traffic; wherein the virtual scene network is built based on the openstack virtual machine network structure; The test system adopts the interference traffic injection method as described in any one of claims 1-4 to inject interference traffic into the virtual scene network.
7. An electronic device comprising a memory and a processor, wherein a computer program is stored in the memory, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 4 is implemented.
8. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed in a computer, the computer is caused to execute the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Creation method and device for virtual training network
CN108965021A
Simulation method and system for simulating real network environment based on virtualization, electronic equipment and storage medium
CN111555913A