Public network ip address traffic verification method based on cloud computing network and related device

By monitoring the ingress and egress traffic of public IP addresses in a cloud computing network, and using cloud servers to analyze and verify the validity of the traffic, the problem of insufficient accuracy in traffic monitoring is solved, and the accuracy of ingress and egress traffic of public IP addresses is verified, thereby improving the accuracy of network traffic monitoring.

CN118590420BActive Publication Date: 2026-08-25CHINA UNITED NETWORK COMM GRP CO LTD +2
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202410977441.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-19
Publication Date
2026-08-25
Estimated Expiration
2044-07-19

AI Technical Summary

Technical Problem

In existing technologies, traffic monitoring of public IP addresses lacks verification methods, which makes it impossible to guarantee the accuracy of traffic monitoring.

Method used

By monitoring the ingress and egress traffic of public IP addresses, analyzing and verifying the validity of the traffic using cloud servers, identifying valid access traffic using preset routing rules and packet capture programs, and forwarding noisy traffic to the default gateway, the accuracy of the monitoring results is ensured.

Benefits of technology

It enables accurate verification of inbound and outbound traffic monitoring of public IP addresses, thereby improving the accuracy of network traffic monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118590420B_ABST
    Figure CN118590420B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a public network IP address flow verification method based on a cloud computing network and related devices. The cloud computing network comprises a cloud server, a public network IP address and an Internet client. The method comprises the following steps: based on a monitoring device corresponding to the public network IP address, monitoring entry access flow of the public network IP address in a preset time period; based on the cloud server receiving the entry access flow from the public network IP address, feeding back valid access flow in the entry access flow to an Internet client corresponding to the valid access flow through the public network IP address; based on the monitoring device corresponding to the public network IP address, monitoring exit feedback flow of the public network IP address in the preset time period; and based on the exit feedback flow, the valid access flow and the entry access flow, verifying whether an entry and exit flow monitoring result of the public network IP address is accurate. The method is used to improve the accuracy of network flow monitoring.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cloud computing, and in particular to a method and related apparatus for verifying public IP address traffic based on cloud computing networks. Background Technology

[0002] With the development of the Internet and the continuous expansion of cloud computing applications, the network, as a core component of cloud computing, can reflect its behavioral characteristics through the dynamic characteristics of the traffic it carries. By monitoring the parameters of network traffic and analyzing the network's operational status, we can obtain the characteristics of the traffic carried on the network and further deepen our understanding of the network's operating mechanisms.

[0003] In existing technologies, the monitoring of traffic entering and leaving public IP addresses is achieved through monitoring devices, which monitor the traffic of public IP addresses by monitoring the incoming and outgoing traffic within a unit of time.

[0004] Since the amount of traffic received by a public IP address per unit of time is an uncertain value, although the incoming and outgoing traffic can be obtained through monitoring, the lack of verification of traffic monitoring makes it impossible to guarantee the accuracy of incoming and outgoing traffic monitoring. Summary of the Invention

[0005] This application provides a method and related apparatus for verifying public IP address traffic based on cloud computing networks, in order to improve the technical effect of improving the accuracy of network traffic monitoring.

[0006] In a first aspect, embodiments of this application provide a method for verifying public IP address traffic based on a cloud computing network. The cloud computing network includes: a cloud server, a public IP address, and an internet client. The method includes:

[0007] Based on the monitoring device corresponding to the public IP address, monitor the inbound access traffic of the public IP address within a preset time period;

[0008] The cloud server receives inbound access traffic from public IP addresses and then feeds back the valid access traffic from the inbound access traffic to the corresponding Internet client via the public IP address.

[0009] Based on the monitoring device corresponding to the public IP address, monitor the outbound feedback traffic of the public IP address within a preset time period;

[0010] Based on outbound feedback traffic, effective access traffic, and inbound access traffic, verify whether the monitoring results of inbound and outbound traffic of public IP addresses are accurate.

[0011] In this process, the cloud server is bound to the public IP address, so that the access traffic received by the public IP address is forwarded to the cloud server.

[0012] In one possible implementation, valid access traffic from the ingress access traffic is fed back to the corresponding internet client via a public IP address, including:

[0013] The system analyzes inbound traffic based on preset routing rules of the cloud server and obtains the client IP address corresponding to the inbound traffic.

[0014] Based on preset routing rules, client IP addresses, and cloud servers, inbound access traffic is fed back to the Internet client via public IP addresses;

[0015] The system retrieves the incoming traffic from the cloud server and identifies it as valid traffic.

[0016] In one possible implementation, based on preset routing rules, client IP addresses, and cloud servers, inbound access traffic is routed back to the internet client via a public IP address, including:

[0017] Based on the cloud server, determine the subnet network to which the cloud server belongs, and determine the first gateway address corresponding to the cloud server;

[0018] The system executes preset routing rules based on the cloud server and generates feedback instructions based on the client's IP address and the first gateway address.

[0019] The cloud server executes the feedback command and sends the ingress access traffic back to the corresponding Internet client via the public IP address.

[0020] In one possible implementation, the process involves obtaining the returned inbound access traffic from the cloud server and identifying it as valid access traffic, including:

[0021] The preset packet capture program configured in the cloud server is determined based on the cloud server.

[0022] When the cloud server sends the ingress access traffic back to the Internet client, the ingress access traffic that has been sent back from the cloud server is captured by a preset packet capture program and identified as valid access traffic.

[0023] In one possible implementation, verifying the accuracy of inbound and outbound traffic monitoring results for public IP addresses includes:

[0024] Determine whether the outbound feedback traffic and the effective access traffic are consistent;

[0025] If they match, then the monitoring of the outbound traffic of the public IP address is accurate;

[0026] Determine whether the inbound traffic is greater than the effective traffic, and calculate the difference between the inbound traffic and the effective traffic;

[0027] If the difference is within the preset range, it is determined that the monitoring of the ingress traffic of the public IP address is accurate.

[0028] In one possible implementation, the cloud computing network further includes a default gateway; after feeding back valid access traffic from the inbound access traffic to the corresponding internet client, it also includes:

[0029] Based on cloud server data, noise traffic other than valid access traffic is identified in the ingress access traffic.

[0030] Based on the cloud server, the second gateway address of the default gateway, and preset routing rules, noisy traffic is forwarded to the default gateway;

[0031] The second gateway address of the default gateway is an IP address that belongs to the same network segment as the cloud server and has not been assigned or used.

[0032] Secondly, embodiments of this application provide a public IP address traffic verification device based on a cloud computing network. The cloud computing network includes: a cloud server, a public IP address, and an internet client. The device includes:

[0033] The first acquisition module is used to monitor the inbound access traffic of the public IP address within a preset time period based on the monitoring device corresponding to the public IP address.

[0034] The first processing module receives inbound access traffic from public IP addresses via a cloud server, and feeds back the valid access traffic in the inbound access traffic to the corresponding Internet client through the public IP address.

[0035] The second acquisition module monitors the outbound feedback traffic of the public IP address within a preset time period based on the monitoring device corresponding to the public IP address.

[0036] The second processing module verifies the accuracy of the monitoring results of the inbound and outbound traffic of public IP addresses based on the outbound feedback traffic, effective access traffic, and inbound access traffic.

[0037] In this process, the cloud server is bound to the public IP address, so that the access traffic received by the public IP address is forwarded to the cloud server.

[0038] In one possible implementation, the first processing module is further configured to:

[0039] The system analyzes inbound traffic based on preset routing rules of the cloud server and obtains the client IP address corresponding to the inbound traffic.

[0040] Based on preset routing rules, client IP addresses, and cloud servers, inbound access traffic is fed back to the Internet client via public IP addresses;

[0041] The system retrieves the incoming traffic from the cloud server and identifies it as valid traffic.

[0042] In one possible implementation, the first processing module is further configured to:

[0043] Based on the cloud server, determine the subnet network to which the cloud server belongs, and determine the first gateway address corresponding to the cloud server;

[0044] The system executes preset routing rules based on the cloud server and generates feedback instructions based on the client's IP address and the first gateway address.

[0045] The cloud server executes the feedback command and sends the ingress access traffic back to the corresponding Internet client via the public IP address.

[0046] In one possible implementation, the first processing module is further configured to:

[0047] The preset packet capture program configured in the cloud server is determined based on the cloud server.

[0048] When the cloud server sends the ingress access traffic back to the Internet client, the ingress access traffic that has been sent back from the cloud server is captured by a preset packet capture program and identified as valid access traffic.

[0049] In one possible implementation, the second processing module is further configured to:

[0050] Determine whether the outbound feedback traffic and the effective access traffic are consistent;

[0051] If they match, then the monitoring of the outbound traffic of the public IP address is accurate;

[0052] Determine whether the inbound traffic is greater than the effective traffic, and calculate the difference between the inbound traffic and the effective traffic;

[0053] If the difference is within the preset range, it is determined that the monitoring of the ingress traffic of the public IP address is accurate.

[0054] In one possible implementation, the first processing module is further configured to:

[0055] Based on cloud server data, noise traffic other than valid access traffic is identified in the ingress access traffic.

[0056] Based on the cloud server, the second gateway address of the default gateway, and preset routing rules, noisy traffic is forwarded to the default gateway;

[0057] The second gateway address of the default gateway is an IP address that belongs to the same network segment as the cloud server and has not been assigned or used.

[0058] Thirdly, embodiments of this application provide a public IP address traffic verification device based on a cloud computing network, comprising: a memory and a processor;

[0059] The memory stores the instructions that the computer executes;

[0060] The processor executes computer execution instructions stored in memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.

[0061] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the first aspect and / or various possible implementations of the first aspect.

[0062] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the first aspect and / or various possible implementations of the first aspect.

[0063] This application provides a method and related apparatus for verifying public IP address traffic based on a cloud computing network. The cloud computing network includes public IP addresses, a cloud server, and an internet client. The method utilizes a public IP address monitoring device to monitor inbound access traffic and uses the cloud server to determine the valid access traffic within the inbound access traffic. Based on the cloud server, the valid access traffic is fed back to the internet client via the public IP address, and the outbound feedback traffic is monitored by the public IP address monitoring device. This ensures that the traffic monitored at the public IP address inbound is all valid access traffic fed back by the cloud server. By comparing the outbound feedback traffic and the valid access traffic, the accuracy of outbound traffic monitoring can be determined; by comparing the valid access traffic and the inbound access traffic, the accuracy of inbound traffic monitoring can be determined; thus, the accuracy of monitoring inbound and outbound traffic of public IP addresses is verified, achieving the technical effect of improving the accuracy of network traffic monitoring. Attached Figure Description

[0064] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0065] Figure 1 A schematic diagram illustrating the scenario of an Internet user accessing a public IP address as provided in this application;

[0066] Figure 2A schematic diagram illustrating the process of public IP address traffic verification based on a cloud computing network, provided as an embodiment of this application;

[0067] Figure 3 A schematic diagram illustrating the process of public IP address traffic verification based on a cloud computing network, provided as another embodiment of this application;

[0068] Figure 4 A schematic diagram illustrating public IPv4 address traffic verification based on a cloud computing network, provided for an embodiment of this application.

[0069] Figure 5 A schematic diagram of the structure of the public IP address traffic verification device based on cloud computing network provided in this application;

[0070] Figure 6 The hardware structure diagram of the public IP address traffic verification device based on cloud computing network provided in this application.

[0071] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0072] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0073] First, let me explain the terms used in this application:

[0074] An IP address (Internet Protocol Address) is an identifier for a device on the Internet, used to uniquely determine the device's location within the network. Every device connected to the Internet, such as a computer, mobile phone, or router, is assigned a unique IP address under the TCP / IP protocol to enable communication and data exchange.

[0075] Private IP address: refers to an IP address used within a local area network (LAN) that is not directly exposed to the Internet and is used for communication within the LAN.

[0076] IPv4 (Internet Protocol Version 4) address: One of the most widely used network protocols on the Internet, it is represented by a 32-bit binary number, usually expressed in dotted decimal notation, such as 192.168.1.1. This format contains four 8-bit groups, each separated by a dot, and each group can represent a number between 0 and 255.

[0077] Virtual Private Cloud (VPC): This refers to a virtual network created in a cloud computing environment, allowing users to partition and manage their own private network space within the infrastructure of a cloud service provider. It allows users to build logically isolated networks in the cloud, similar to local area networks (LANs) in traditional networks, but operating in the cloud and enjoying the elasticity and scalability advantages of the cloud.

[0078] Figure 1 This application provides a schematic diagram illustrating a scenario where an internet user accesses a public IP address. Figure 1 As shown, the specific application scenarios of this application include: Virtual Private Cloud (VPN), the Internet, and public IP addresses; wherein the VPN includes: a cloud server, which is bound to a public IP address through Network Address Translation (NAT) technology. Traffic from users accessing public IP addresses on the Internet reaches the corresponding cloud server via the public IP address. The traffic monitoring device corresponding to the public IP address determines the inbound and outbound traffic information corresponding to the public IP address by monitoring the inbound and outbound traffic per unit time.

[0079] In the context of the above scenarios, relevant technologies primarily obtain public IP address traffic information by monitoring the inbound and outbound traffic of public IP addresses within a unit of time. However, since the traffic received by a public IP address within a unit of time is an uncertain value, although monitoring methods can capture the incoming and outbound traffic, the lack of verification of this monitoring leads to an inability to guarantee the accuracy of the monitoring, resulting in a technical problem of low accuracy in network traffic monitoring.

[0080] To address the aforementioned issues, this application provides a public IP address traffic verification method based on cloud computing networks. This method utilizes a public IP address monitoring device to monitor inbound access traffic and a cloud server to determine the valid access traffic within the inbound access traffic. The cloud server then feeds back the valid access traffic to the internet client via the public IP address, and the monitoring device monitors outbound feedback traffic using the public IP address. This ensures that all traffic monitored at the public IP address inbound is valid access traffic fed back by the cloud server. By comparing outbound feedback traffic with valid access traffic, the accuracy of outbound traffic monitoring can be determined; by comparing valid access traffic with inbound access traffic, the accuracy of inbound traffic monitoring can be determined; thus, the accuracy of public IP address inbound and outbound traffic monitoring is verified, achieving the technical effect of improving the accuracy of network traffic monitoring.

[0081] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0082] Figure 2 This is a schematic diagram illustrating a process for verifying public IP address traffic based on a cloud computing network, as provided in an embodiment of this application. The cloud computing network includes public IP addresses, cloud servers, and internet clients. This method can use the public IP addresses, cloud servers, and internet clients within the cloud computing network as the execution entities. Figure 2 As shown, the method includes:

[0083] S201. A monitoring device based on a public IP address monitors the inbound access traffic of the public IP address within a preset time period.

[0084] In this embodiment, the monitoring devices corresponding to public IP addresses include, but are not limited to: network monitoring software and monitoring tools provided by cloud service providers corresponding to cloud computing networks.

[0085] The preset time period can be a time interval within the dates on which the public IP address is put into use; for example, if the public IP address is put into use on July 18, 2024, then the preset time period can be set to a time interval between that date and subsequent dates. For example, the preset time period can be set to 12:00 to 12:30 noon on July 19, 2024.

[0086] For example, using network monitoring software to obtain the ingress traffic of a public IP address within a preset time period can be implemented as follows:

[0087] Based on the monitoring software settings, the specific public IP address that needs to be monitored for traffic is set, and the preset time period for monitoring is set;

[0088] Network packets are captured by monitoring software. The network packets include: source IP address, destination IP address, protocol type, and packet size. The source IP address is the network address that sends the network packet, the destination IP address is the network address that receives the network packet, the protocol type is the network communication protocol used for communication between the source IP address and the destination IP address, and the packet size is the size of the network packet sent from the source IP address to the destination IP address.

[0089] For example, the IP address of the internet client is the first IP address, and the public IP address is the second IP address. The first IP address sends a 30KB network data packet to the second IP address to access the second IP address, and the communication protocol used by the network data packet is the Transmission Control Protocol (TCP). Therefore, the source IP address of the network data packet is the first IP address, the destination IP address is the second IP address, the protocol type is TCP, and the data packet size is 30KB.

[0090] By using monitoring software to calculate network data packet information for a preset time period, the ingress access traffic within that preset time period can be obtained.

[0091] S202. Based on the cloud server, receive inbound access traffic from public IP addresses, and through the public IP addresses, feed back the valid access traffic in the inbound access traffic to the Internet client corresponding to the valid access traffic.

[0092] In this embodiment, the cloud server and the public IP address are bound together, so that the ingress access traffic received by the public IP address is forwarded to the cloud server.

[0093] Ingress traffic includes valid access traffic from internet clients and noise traffic received from public IP addresses. Sources of noise traffic include, but are not limited to: invalid scans and connection attempts, data transmitted by malicious software or botnets, malicious data packets, and harmless network background noise.

[0094] S203. A monitoring device based on a public IP address monitors the outbound feedback traffic of the public IP address within a preset time period.

[0095] In this embodiment, the monitoring device for monitoring outbound feedback traffic is the same as the monitoring device in step S201. For example, when using traffic monitoring software to monitor outbound feedback traffic, the preset time period is set to 12:00 to 12:15 noon on a certain day; the traffic type is TCP, and the size of the currently detected outbound feedback traffic is 256MB, which indicates that the outbound feedback traffic of the public IP address within the preset time period is 256MB.

[0096] S204. Based on outbound feedback traffic, effective access traffic, and inbound access traffic, verify whether the monitoring results of the inbound and outbound traffic of public IP addresses are accurate.

[0097] Alternatively, a specific implementation method for verifying the accuracy of inbound and outbound traffic monitoring results for public IP addresses can be:

[0098] Determine whether the outbound feedback traffic and the effective access traffic are consistent;

[0099] If they match, then the monitoring of the outbound traffic of the public IP address is accurate;

[0100] Determine whether the inbound traffic is greater than the effective traffic, and calculate the difference between the inbound traffic and the effective traffic;

[0101] If the difference is within the preset range, it is determined that the monitoring of the ingress traffic of the public IP address is accurate.

[0102] In this embodiment, the outbound feedback traffic refers to the outbound traffic of the monitored public IP address, the effective access traffic refers to the traffic forwarded to the client through the public IP address, and the inbound access traffic refers to the inbound traffic of the monitored public IP address. According to the traffic feedback method, the effective access traffic and the outbound feedback traffic should be consistent, and the inbound access traffic should be greater than the effective access traffic, with the difference remaining within a preset range. If both conditions are met simultaneously, it indicates that the monitoring of the inbound and outbound traffic of the public IP address is accurate.

[0103] For example, the preset range is 0~10M. Within the preset time period, the monitoring device detects 100M of inbound access traffic to the public IP address, 80M of effective access traffic obtained by the cloud server, and 70M of outbound feedback traffic detected by the monitoring device. If the effective access traffic and the outbound feedback traffic are inconsistent, it is determined that the outbound traffic monitoring of the public IP address is inaccurate. If the difference between the effective access traffic and the inbound access traffic is not within the preset range, it is determined that the inbound traffic monitoring of the public IP address is inaccurate.

[0104] This application embodiment utilizes a public IP address monitoring device to monitor inbound access traffic and a cloud server to determine the valid access traffic within the inbound access traffic. Based on this, the cloud server feeds back the valid access traffic to the internet client via the public IP address, and the monitoring device also monitors the outbound feedback traffic. This ensures that all traffic monitored at the public IP address inbound is valid access traffic fed back by the cloud server. By comparing the outbound feedback traffic and the valid access traffic, the accuracy of outbound traffic monitoring can be determined; by comparing the valid access traffic and the inbound access traffic, the accuracy of inbound traffic monitoring can be determined; thus, the accuracy of monitoring inbound and outbound traffic from the public IP address is verified, achieving the technical effect of improving the accuracy of network traffic monitoring.

[0105] Figure 3 This is a schematic diagram illustrating a public IP address traffic verification process based on a cloud computing network, as provided in another embodiment of this application. This embodiment... Figure 2 Based on the above embodiments shown, a detailed explanation is provided on how to feed back effective traffic to the Internet client based on the cloud server, such as... Figure 3 As shown, this method uses a cloud server as the execution entity, and the method includes:

[0106] S301. Analyze the ingress access traffic based on the preset routing rules of the cloud server, and obtain the client IP address corresponding to the ingress access traffic.

[0107] In this embodiment, the preset routing rules are used to return the traffic to the Internet client corresponding to the client's IP address after the cloud server receives the traffic from the client's IP address.

[0108] In this embodiment, the ingress access traffic carries the source IP address and the destination IP address. If the destination IP address is the public IP address in this application, then the source IP address corresponding to the destination IP address is the client IP address that needs to be obtained.

[0109] For example, in this application, the public IP address is 192.168.1.100. The destination IP address corresponding to the traffic with a source IP address of 192.168.2.102 in the inbound access traffic is 192.168.1.100, which is consistent with the public IP address. Therefore, the source IP address 192.168.2.102 can be determined as the client IP address. If the corresponding destination IP address is inconsistent with the public IP address, the source IP address cannot be determined as the client IP address.

[0110] S302. Determine the subnet to which the cloud server belongs based on the cloud server, and determine the first gateway address corresponding to the cloud server.

[0111] In this embodiment, the subnet where the cloud server resides is the subnet where the private IP address assigned to the cloud server is located; this subnet network depends on the cloud service provider offering the cloud server. For example, when deploying a cloud server, it needs to select a virtual private cloud (VPN), and each VPN contains multiple subnets. The cloud server will be assigned an IP address to one of these subnets.

[0112] In this embodiment, the first gateway address corresponding to the cloud server is the actual gateway address of the subnet network to which the cloud server belongs. The first gateway address corresponding to the cloud server can be obtained by querying the platform to which the cloud server belongs and the specific network configuration within that platform. For example, if the cloud server is deployed in a virtual private cloud (VPN), each VPN contains a master routing table, which includes local routes and user-defined routes, and each subnet is associated with a master routing table; then the first gateway address corresponding to the cloud server can be obtained by querying the master routing table of the subnet network to which the cloud server belongs.

[0113] S303: Execute preset routing rules based on the cloud server, and generate feedback instructions according to the client IP address and the first gateway address.

[0114] For example, the default routing rule is: `router add <client IP address> mask255.255.255.255 <first gateway address corresponding to the cloud server>`; the client address is 192.168.1.123, and the first gateway address corresponding to the cloud server is 10.0.0.1. Then the feedback command is: `router add 192.168.1.123 mask255.255.255.255 10.0.0.1`.

[0115] S304. Execute feedback instructions based on the cloud server and send the ingress access traffic back to the corresponding Internet client via the public IP address.

[0116] In this embodiment, the cloud server executes the feedback instruction, and the inbound access traffic is sent to the Internet client via the public IP address. The inbound access traffic that can be fed back to the Internet client carries the corresponding client IP address and public IP address.

[0117] S305. Determine the preset packet capture program configured in the cloud server based on the cloud server.

[0118] In this embodiment, the preset packet capture program in the cloud server can be: a graphical tool, a command-line tool, or a network traffic monitoring tool.

[0119] S306. When the cloud server sends the ingress access traffic back to the Internet client, the ingress access traffic that has been sent back in the cloud server is captured based on the preset packet capture program and identified as valid access traffic.

[0120] In this embodiment, when the cloud server sends the ingress access traffic back to the internet client, a preset packet capture program is started to capture the ingress access traffic sent out by the cloud server and identify the captured ingress access traffic as valid access traffic. Preset routing rules can be used to achieve accurate feedback of valid access traffic, thus confirming that the valid access traffic obtained from the packet capture is the traffic generated by the accurate internet client access received from the public IP address.

[0121] Optionally, the cloud computing network also includes a default gateway. After feeding back valid access traffic to the Internet client, it also includes feeding back noisy traffic to the default gateway. A specific implementation of feeding back noisy traffic to the default gateway can be:

[0122] Based on cloud server data, noise traffic other than valid access traffic is identified in the ingress access traffic.

[0123] Based on the cloud server, the second gateway address of the default gateway, and preset routing rules, noisy traffic is forwarded to the default gateway;

[0124] The second gateway address of the default gateway is an IP address that belongs to the same network segment as the cloud server and has not been assigned or used.

[0125] In this embodiment, the preset routing rules are also used to forward the noisy traffic to the default gateway after the cloud server receives the noisy traffic, thereby eliminating the noisy traffic.

[0126] In this embodiment, the default gateway and the cloud server belong to the same network segment and both are private IP addresses. The cloud server forwards noisy traffic to the default gateway, so the noisy traffic will not be forwarded to the Internet through the public IP address. Therefore, the outbound traffic monitoring of the public IP address will not detect the noisy traffic, thus limiting the outbound traffic monitored by the public IP address to valid access traffic. The accuracy of the outbound traffic monitoring of the public IP address can be determined by comparing the monitored outbound feedback traffic with the valid access traffic.

[0127] For example, a command line that forwards noisy traffic to the default gateway based on preset routing rules can be designed as: router add 0.0.0.0 mask 0.0.0.0 <second gateway address corresponding to the default gateway>.

[0128] Figure 4This diagram illustrates public IPv4 address traffic verification based on a cloud computing network, as provided in an embodiment of this application. For example,... Figure 4 As shown, the cloud computing network includes: the Internet, public IPv4 addresses, cloud servers, and the default gateway corresponding to each cloud server. A cloud server is a virtual machine deployed in a virtual private cloud, and the default gateway is an unassigned network address on the same network segment as the cloud server. The cloud server establishes a mapping and binding relationship with the public IPv4 address through Network Address Translation (NAT) technology.

[0129] The cloud server can be configured with a Windows image, an 8-core processor, and up to 16GB of memory. It is bound to a public IPv4 address, allowing internet users to access it directly via the ping command.

[0130] Traffic from internet users accessing public IPv4 networks, and noise traffic received by public IPv4 networks, are both categorized according to... Figure 4 The solid arrows in the image indicate traffic entering the cloud server; this traffic is collectively referred to as public IPv4 ingress traffic. The cloud server, according to preset routing rules, routes the valid access traffic corresponding to internet users through... Figure 4 The direction of the straight line / dashed arrow in the image is fed back to the internet, and the noisy traffic is transmitted through... Figure 4 The dashed arrow on the curve forwards the data to the default gateway.

[0131] In this embodiment, using a cloud server, preset routing rules, and a packet capture program, the inbound access traffic received by the cloud server from public IP addresses is divided into valid access traffic and noise traffic. Specifically, the preset routing rules are used to feed the inbound access traffic back to the internet client via the public IP address, and the packet capture program is used to obtain the valid access traffic that can be fed back. The preset routing rules are used to forward the noise traffic to the default gateway, thus discarding the noise traffic and avoiding its impact on outbound traffic monitoring. By comparing the outbound feedback traffic and valid access traffic from outbound monitoring, the accuracy of outbound traffic monitoring is verified. Similarly, by comparing the inbound access traffic and valid access traffic, the accuracy of inbound traffic monitoring from public IP addresses is verified, thereby improving the accuracy of network traffic monitoring.

[0132] The following are embodiments of the apparatus described in this application, which can be used to execute the embodiments of the method described in this application. For details not disclosed in the apparatus embodiments of this application, please refer to the embodiments of the method described in this application. Figure 5 This is a schematic diagram of the structure of the public IP address traffic verification device based on a cloud computing network provided in this application. The cloud computing network includes: a cloud server, a public IP address, and an internet client, such as... Figure 5As shown, the public IP address traffic verification device 50 based on cloud computing network provided in this embodiment includes:

[0133] The first acquisition module 501 is used to monitor the ingress access traffic of the public IP address within a preset time period based on the monitoring device corresponding to the public IP address.

[0134] The first processing module 502 receives inbound access traffic from a public IP address based on the cloud server, and feeds back the valid access traffic in the inbound access traffic to the Internet client corresponding to the valid access traffic through the public IP address.

[0135] The second acquisition module 503 monitors the outbound feedback traffic of the public IP address within a preset time period based on the monitoring device corresponding to the public IP address.

[0136] The second processing module 504 verifies the accuracy of the monitoring results of the inbound and outbound traffic of the public IP address based on the outbound feedback traffic, effective access traffic, and inbound access traffic.

[0137] In this process, the cloud server is bound to the public IP address, so that the access traffic received by the public IP address is forwarded to the cloud server.

[0138] In one possible implementation, the first processing module 502 is further configured to:

[0139] The system analyzes inbound traffic based on preset routing rules of the cloud server and obtains the client IP address corresponding to the inbound traffic.

[0140] Based on preset routing rules, client IP addresses, and cloud servers, inbound access traffic is fed back to the Internet client via public IP addresses;

[0141] The system retrieves the incoming traffic from the cloud server and identifies it as valid traffic.

[0142] In one possible implementation, the first processing module 502 is further configured to:

[0143] Based on the cloud server, determine the subnet network to which the cloud server belongs, and determine the first gateway address corresponding to the cloud server;

[0144] The system executes preset routing rules based on the cloud server and generates feedback instructions based on the client's IP address and the first gateway address.

[0145] The cloud server executes the feedback command and sends the ingress access traffic back to the corresponding Internet client via the public IP address.

[0146] In one possible implementation, the first processing module 502 is further configured to:

[0147] The preset packet capture program configured in the cloud server is determined based on the cloud server.

[0148] When the cloud server sends the ingress access traffic back to the Internet client, the ingress access traffic that has been sent back from the cloud server is captured by a preset packet capture program and identified as valid access traffic.

[0149] In one possible implementation, the second processing module 504 is further configured to:

[0150] Determine whether the outbound feedback traffic and the effective access traffic are consistent;

[0151] If they match, then the monitoring of the outbound traffic of the public IP address is accurate;

[0152] Determine whether the inbound traffic is greater than the effective traffic, and calculate the difference between the inbound traffic and the effective traffic;

[0153] If the difference is within the preset range, it is determined that the monitoring of the ingress traffic of the public IP address is accurate.

[0154] In one possible implementation, the first processing module 502 is further configured to:

[0155] Based on cloud server data, noise traffic other than valid access traffic is identified in the ingress access traffic.

[0156] Based on the cloud server, the second gateway address of the default gateway, and preset routing rules, noisy traffic is forwarded to the default gateway;

[0157] The second gateway address of the default gateway is an IP address that belongs to the same network segment as the cloud server and has not been assigned or used.

[0158] The public IP address traffic verification device based on cloud computing network provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.

[0159] Figure 6 The hardware structure diagram of the public IP address traffic verification device based on cloud computing network provided in this application is shown. Figure 6 As shown, the public IP address traffic verification device 60 based on cloud computing network provided in this embodiment includes at least one processor 601 and a memory 602. Optionally, the device 60 also includes a communication component 603. The processor 601, memory 602, and communication component 603 are connected via a bus 604.

[0160] In a specific implementation, at least one processor 601 executes computer execution instructions stored in memory 602, causing at least one processor 601 to perform the above-described method.

[0161] The specific implementation process of processor 601 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.

[0162] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0163] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.

[0164] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0165] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.

[0166] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.

[0167] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0168] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.

[0169] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.

[0170] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0171] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0172] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0173] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0174] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.

Claims

1. A public IP address traffic verification method based on cloud computing networks, characterized in that, The cloud computing network includes: cloud servers, public IP addresses, and internet clients; the method includes: Based on the monitoring device corresponding to the public IP address, monitor the inbound access traffic of the public IP address within a preset time period; The cloud server receives inbound access traffic from the public IP address and, through the public IP address, feeds back the valid access traffic in the inbound access traffic to the corresponding Internet client; wherein, the inbound access traffic includes valid access traffic from the Internet client and noise traffic received from the public IP address; Based on the monitoring device corresponding to the public IP address, monitor the outbound feedback traffic of the public IP address within the preset time period; Based on the outbound feedback traffic, the effective access traffic, and the inbound access traffic, verify whether the inbound and outbound traffic monitoring results of the public IP address are accurate; The cloud server and the public IP address are bound together, so that the ingress access traffic received by the public IP address is forwarded to the cloud server; The cloud computing network also includes a default gateway; after feeding back the valid access traffic in the ingress access traffic to the Internet client corresponding to the valid access traffic, it further includes: Based on the cloud server, noise traffic other than the valid access traffic is identified in the ingress access traffic; based on the cloud server, the second gateway address of the default gateway, and the preset routing rules of the cloud server, the noise traffic is forwarded to the default gateway; wherein, the preset routing rules are used to forward the noise traffic to the default gateway after the cloud server receives the noise traffic, thereby eliminating the noise traffic; The second gateway address of the default gateway is an IP address that belongs to the same network segment as the cloud server and has not been assigned or used.

2. The method according to claim 1, characterized in that, The step of feeding back the valid access traffic from the ingress access traffic to the corresponding Internet client via the public IP address includes: The entry traffic is analyzed based on the preset routing rules of the cloud server, and the client IP address corresponding to the entry traffic is obtained. Based on the preset routing rules, the client IP address, and the cloud server, the ingress access traffic is fed back to the Internet client via the public IP address; The cloud server retrieves the incoming traffic that has been reported and identifies it as valid traffic.

3. The method according to claim 2, characterized in that, The step of routing the ingress traffic to the internet client via the public IP address, based on the preset routing rules, the client IP address, and the cloud server, includes: Based on the cloud server, determine the subnet network to which the cloud server belongs, and determine the first gateway address corresponding to the cloud server; The cloud server executes the preset routing rules and generates a feedback instruction based on the client's IP address and the first gateway address. The cloud server executes the feedback instruction and sends the ingress access traffic back to the internet client corresponding to the ingress access traffic via the public IP address.

4. The method according to claim 2, characterized in that, The step of obtaining the returned inbound access traffic based on the cloud server and determining it as valid access traffic includes: Based on the cloud server, determine the preset packet capture program configured in the cloud server; When the cloud server sends the ingress access traffic back to the Internet client, the preset packet capture program captures the ingress access traffic that has been sent back from the cloud server and determines it as valid access traffic.

5. The method according to claim 1, characterized in that, The verification of the accuracy of the inbound and outbound traffic monitoring results of the public IP address includes: Determine whether the outbound feedback traffic and the valid access traffic are consistent; If they match, then the monitoring of the outbound traffic of the public IP address is accurate. Determine whether the inbound access traffic is greater than the effective access traffic, and calculate the difference between the inbound access traffic and the effective access traffic; If the difference is within a preset range, then the ingress traffic monitoring of the public IP address is determined to be accurate.

6. A public IP address traffic verification device based on cloud computing networks, characterized in that, The cloud computing network includes: a cloud server, a public IP address, and an internet client; the device includes: The first acquisition module is used to monitor the ingress access traffic of the public IP address within a preset time period based on the monitoring device corresponding to the public IP address. The first processing module receives inbound access traffic from the public IP address based on the cloud server, and feeds back the valid access traffic in the inbound access traffic to the Internet client corresponding to the valid access traffic through the public IP address; the inbound access traffic includes valid access traffic from the Internet client and noise traffic received from the public IP address; The second acquisition module monitors the outbound feedback traffic of the public IP address within the preset time period based on the monitoring device corresponding to the public IP address. The second processing module verifies the accuracy of the inbound and outbound traffic monitoring results of the public IP address based on the outbound feedback traffic, the effective access traffic, and the inbound access traffic. The cloud server and the public IP address are bound together, so that the ingress access traffic received by the public IP address is forwarded to the cloud server; The cloud computing network also includes a default gateway; the first processing module is further configured to: Based on the cloud server, noise traffic other than the valid access traffic is identified in the ingress access traffic; based on the cloud server, the second gateway address of the default gateway, and the preset routing rules of the cloud server, the noise traffic is forwarded to the default gateway; wherein, the preset routing rules are used to forward the noise traffic to the default gateway after the cloud server receives the noise traffic, thereby eliminating the noise traffic; The second gateway address of the default gateway is an IP address that belongs to the same network segment as the cloud server and has not been assigned or used.

7. A public IP address traffic verification device based on cloud computing networks, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-5.

9. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method described in any one of claims 1-5.

Citation Information

Patent Citations

  • Flow monitoring, flow analyzing and message pushing system based on mobile Internet

    CN104469729A

  • Gateway traffic data monitoring method and system, electronic equipment and storage medium

    CN117955881A

  • Third party gateway

    US20230403345A1