Illegal node determination method and apparatus, and storage medium

By adding flow-following and hop-by-hop detection identifiers to the network, real-time data flow information between ingress and egress gateway devices is obtained, solving the problem of illegal node identification with poor real-time performance in existing technologies and achieving real-time and accurate location of illegal nodes.

CN118764265BActive Publication Date: 2025-11-18CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410924025.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-10
Publication Date
2025-11-18
Estimated Expiration
2044-07-10

AI Technical Summary

Technical Problem

In existing technologies, attack path reconstruction based on traffic characteristics requires the controller to collect data stream information over a certain period of time, resulting in poor real-time performance and difficulty in accurately identifying illegal nodes in the network.

Method used

By sending a flow detection command to the ingress gateway device and adding a flow detection identifier, the routing path data between the ingress and egress gateway devices is obtained. The location of illegal nodes is determined based on latency information. When a network anomaly is detected, a hop-by-hop detection identifier is added to obtain real-time detection data of intermediate nodes.

Benefits of technology

It enables real-time and accurate location of illegal nodes, improves the real-time performance and accuracy of network monitoring, and solves the problem of poor real-time performance in existing technologies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118764265B_ABST
    Figure CN118764265B_ABST
Patent Text Reader

Abstract

The disclosure provides a non-legal node determination method and device and a storage medium, relates to the technical field of communication, and solves the technical problem that in the related art, real-time performance of attack path reconstruction based on traffic characteristics is poor, and it is difficult to accurately determine non-legal nodes in a network, because data stream information in a certain time needs to be collected by a controller to perform path backtracking. The method comprises the following steps: sending a flow detection instruction to an entry gateway device; obtaining flow detection data from an exit gateway; in the case that it is determined that a routing path has network abnormities, instructing the entry gateway device to add hop-by-hop detection identification to the data stream; and determining the position of the non-legal node based on time delay information reported by multiple intermediate nodes in the target flow detection data. The disclosure is used in a non-legal node detection scene.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to a method, apparatus and storage medium for determining illegal nodes. Background Technology

[0002] Currently, a trusted and secure data flow network needs to have the ability to monitor and trace attacks and illegal traffic paths in real time. Common network path tracing methods reconstruct the attack path based on the differences between attacked traffic and normal traffic characteristics, thereby determining the location of illegal nodes. However, attack path reconstruction based on traffic characteristics requires the controller to collect data flow information over a certain period of time, resulting in poor real-time performance for path backtracking and making it difficult to accurately identify illegal nodes in the network. Summary of the Invention

[0003] This disclosure provides a method, apparatus, and storage medium for determining illegal nodes, which solves the technical problem in related technologies where attack path reconstruction based on traffic characteristics requires the controller to collect data flow information over a certain period of time for path backtracking, resulting in poor real-time performance and difficulty in accurately determining illegal nodes in the network.

[0004] To achieve the above objectives, the present disclosure adopts the following technical solution:

[0005] Firstly, a method for determining illegal nodes is provided. This method includes: sending a flow-following detection command to an ingress gateway device; the flow-following detection command instructing the ingress gateway device to add a flow-following detection identifier to the data flow; the flow-following detection identifier being used to obtain flow-following detection data from the ingress gateway device and the egress gateway device; obtaining flow-following detection data from the egress gateway; the flow-following detection data being used to characterize whether there is a network anomaly in the routing path between the ingress gateway device and the egress gateway device; if a network anomaly is determined in the routing path, instructing the ingress gateway device to add a hop-by-hop detection identifier to the data flow; the hop-by-hop detection identifier being used to instruct multiple intermediate nodes between the ingress gateway device and the egress gateway device to send target flow-following detection data; the target flow-following detection data being the flow-following detection data measured by each of the multiple intermediate nodes; and determining the location of the illegal node based on the latency information reported by the multiple intermediate nodes in the target flow-following detection data.

[0006] In conjunction with the first aspect mentioned above, in one possible implementation, the flow detection data includes: delay information of multiple intermediate nodes; the method specifically includes: determining the delay between each pair of adjacent intermediate nodes in the routing path based on the delay information of multiple intermediate nodes; and determining the location of the illegal node based on the delay between each pair of adjacent intermediate nodes.

[0007] In conjunction with the first aspect above, in one possible implementation, the method specifically includes: determining, in each pair of adjacent intermediate nodes, the adjacent intermediate node whose time delay between adjacent intermediate nodes is greater than a first preset threshold as the target intermediate node; and determining that the illegal node is located between the target intermediate nodes.

[0008] In conjunction with the first aspect above, in one possible implementation, the method specifically includes: determining the packet loss rate and latency between the ingress gateway device and the egress gateway device based on the flow detection data; determining that there is a network anomaly in the routing path when the packet loss rate is greater than a second preset threshold and / or the latency is greater than a third preset threshold; and instructing the ingress gateway device to add a hop-by-hop detection flag to the data flow.

[0009] In conjunction with the first aspect above, in one possible implementation, after instructing the ingress gateway device to add a hop-by-hop detection identifier to the data flow when a network anomaly is determined to exist in the routing path, the method further includes: determining whether all the multiple intermediate nodes for sending target flow detection data between the ingress gateway device and the egress gateway device are preset intermediate nodes; and determining that the network anomaly in the routing path is caused by path optimization when it is determined that there are non-preset intermediate nodes among the multiple intermediate nodes.

[0010] In conjunction with the first aspect mentioned above, in one possible implementation, the target flow detection data further includes: the packet loss rate of each intermediate node. The method further includes: determining the packet loss rate of each intermediate node; and determining that among the packet loss rates of each intermediate node, intermediate nodes with packet loss rates greater than a fourth preset threshold are subject to network attacks.

[0011] In conjunction with the first aspect above, in one possible implementation, the method further includes: determining the amount of data transmitted by each of the multiple intermediate nodes based on the target flow detection data; and determining that the network anomaly is caused by routing path congestion when there is a case where the amount of data transmitted by any of the multiple intermediate nodes exceeds the data transmission threshold of the intermediate node.

[0012] Secondly, an illegal node determination device is provided, comprising: a communication unit and a processing unit; the communication unit sends a flow-following detection instruction to an ingress gateway device; the flow-following detection instruction instructs the ingress gateway device to add a flow-following detection identifier to the data flow; the flow-following detection identifier is used to acquire flow-following detection data between the ingress gateway device and the egress gateway device; the communication unit acquires flow-following detection data from the egress gateway; the flow-following detection data is used to characterize whether there is a network anomaly in the routing path between the ingress gateway device and the egress gateway device; the processing unit, when determining that there is a network anomaly in the routing path, instructs the ingress gateway device to add a hop-by-hop detection identifier to the data flow; the hop-by-hop detection identifier instructs multiple intermediate nodes between the ingress gateway device and the egress gateway device to send target flow-following detection data; the target flow-following detection data is the flow-following detection data measured by each of the multiple intermediate nodes; the processing unit determines the location of the illegal node based on the delay information reported by the multiple intermediate nodes in the target flow-following detection data.

[0013] In conjunction with the second aspect above, in one possible implementation, the flow detection data includes: delay information of multiple intermediate nodes; and a processing unit specifically used for: determining the delay between each pair of adjacent intermediate nodes in the routing path based on the delay information of multiple intermediate nodes; and determining the location of illegal nodes based on the delay between each pair of adjacent intermediate nodes.

[0014] In conjunction with the second aspect above, in one possible implementation, the processing unit is specifically used to: determine, in each pair of adjacent intermediate nodes, the adjacent intermediate node whose time delay between adjacent intermediate nodes is greater than a first preset threshold is the target intermediate node; and determine that the illegal node is located between the target intermediate nodes.

[0015] In conjunction with the second aspect above, in one possible implementation, the processing unit is specifically used to: determine the packet loss rate and latency between the ingress gateway device and the egress gateway device based on the flow detection data; determine that there is a network anomaly in the routing path when the packet loss rate is greater than a second preset threshold and / or the latency is greater than a third preset threshold; and instruct the ingress gateway device to add a hop-by-hop detection flag to the data flow.

[0016] In conjunction with the second aspect above, in one possible implementation, after instructing the ingress gateway device to add a hop-by-hop detection identifier to the data flow when a network anomaly is determined to exist in the routing path, the processing unit is further configured to: determine whether all the multiple intermediate nodes for sending target flow detection data between the ingress gateway device and the egress gateway device are preset intermediate nodes; and determine that the network anomaly in the routing path is caused by path optimization when it is determined that there are non-preset intermediate nodes among the multiple intermediate nodes.

[0017] In conjunction with the second aspect above, in one possible implementation, the target flow detection data further includes: the packet loss rate of each intermediate node; the processing unit is also used to determine the packet loss rate of each intermediate node; in determining the packet loss rate of each intermediate node, intermediate nodes with packet loss rates greater than a fourth preset threshold are considered to be under network attack.

[0018] In conjunction with the second aspect above, in one possible implementation, the processing unit is further configured to: determine the amount of data transmitted by each of the multiple intermediate nodes based on the target flow detection data; and determine that the network anomaly is caused by routing path congestion if, among the multiple intermediate nodes, there is a case where the amount of data transmitted exceeds the data transmission threshold of the intermediate node.

[0019] Thirdly, an illegal node determination apparatus is provided, comprising: a processor and a memory; wherein the memory is used to store computer execution instructions, and when the illegal node determination apparatus is running, the processor executes the computer execution instructions stored in the memory to cause the illegal node determination apparatus to perform the illegal node determination method as described in the first aspect above and any possible implementation thereof.

[0020] Fourthly, a computer-readable storage medium is provided, which stores instructions that, when executed by a processor of an illegal node determination device, cause the illegal node determination device to perform the illegal node determination method as described in the first aspect above and any possible implementation thereof.

[0021] Fifthly, a chip is provided, the chip including a processor and a communication interface, the communication interface and the processor being coupled, the processor being used to run computer programs or instructions to implement the illegal node determination method as described in the first aspect above and any possible implementation thereof.

[0022] In this disclosure, the name of the aforementioned illegal node determination device does not limit the device or functional module itself. In actual implementation, these devices or functional modules may appear under other names. As long as the function of each device or functional module is similar to that of this disclosure, it falls within the scope of this disclosure and its equivalents.

[0023] The technical solution provided in this disclosure offers at least the following advantages: The illegal node determination device first sends a flow-following detection command to the ingress gateway device, instructing it to add a flow-following detection identifier to the data flow. Then, it obtains flow-following detection data from the egress gateway device, characterizing whether there is a network anomaly in the routing path between the ingress and egress gateway devices. If a network anomaly is detected in the routing path, the device instructs the ingress gateway device to add a hop-by-hop detection identifier to the data flow. This enables multiple intermediate nodes between the ingress and egress gateway devices to send target flow-following detection data to the illegal node determination device based on the hop-by-hop detection identifier. Finally, based on the real-time latency information reported by multiple intermediate nodes in the target flow-following detection data, the location of the illegal node is determined. When the illegal node determination device determines that there is a network anomaly in the routing path between the ingress and egress gateway devices, it obtains the real-time latency information of all intermediate nodes between the ingress and egress gateway devices based on the hop-by-hop detection identifier, thus determining the location of the illegal node. This solves the technical problem in related technologies where attack path reconstruction based on traffic characteristics requires the controller to collect data flow information over a certain period for path backtracking, resulting in poor real-time performance and difficulty in accurately determining illegal nodes in the network. Attached Figure Description

[0024] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below.

[0025] Figure 1 This is a schematic diagram of the structure of an illegal node determination system provided in an embodiment of the present disclosure;

[0026] Figure 2 This is a schematic diagram of the hardware structure of an illegal node determination device provided in an embodiment of the present disclosure;

[0027] Figure 3 A flowchart illustrating an illegal node determination method provided in this embodiment of the disclosure;

[0028] Figure 4 A flowchart illustrating yet another method for determining illegal nodes provided in this disclosure embodiment;

[0029] Figure 5 A flowchart illustrating yet another method for determining illegal nodes provided in this disclosure embodiment;

[0030] Figure 6 A flowchart illustrating yet another method for determining illegal nodes provided in this disclosure embodiment;

[0031] Figure 7 A flowchart illustrating yet another method for determining illegal nodes provided in this disclosure embodiment;

[0032] Figure 8 A flowchart illustrating yet another method for determining illegal nodes provided in this disclosure embodiment;

[0033] Figure 9 A flowchart illustrating yet another method for determining illegal nodes provided in this disclosure embodiment;

[0034] Figure 10 This is a schematic diagram of an illegal node determination device provided in an embodiment of the present disclosure. Detailed Implementation

[0035] The following describes in detail, with reference to the accompanying drawings, an illegal node determination method, apparatus, and storage medium provided in the embodiments of this disclosure.

[0036] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.

[0037] The terms “first” and “second” in this disclosure and its accompanying drawings are used to distinguish different objects or to distinguish different treatments of the same object, rather than to describe a particular order of objects.

[0038] Furthermore, the terms "comprising" and "having," and any variations thereof, used in the description of this disclosure are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to such processes, methods, products, or apparatus. It should be noted that in the embodiments of this disclosure, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this disclosure should not be construed as preferred or advantageous over other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0039] In the description of this disclosure, unless otherwise stated, "multiple" means two or more.

[0040] The following explanations of the terms used in the embodiments of this disclosure are provided to facilitate the reader's understanding.

[0041] 1. In-flow detection technology

[0042] Flow-based detection technology is a detection technique that directly detects network performance indicators by marking network traffic with features. It can significantly improve the timeliness and effectiveness of network operations and maintenance, promoting the development of intelligent operations and maintenance. Compared with traditional network operations and maintenance technologies, flow-based detection technology has the advantages of high accuracy, real-time performance, and visualization. It can flexibly adapt to various business scenarios and further lay a solid foundation for the development of intelligent operations and maintenance through its integration with big data platforms and intelligent algorithms.

[0043] Currently, a trusted and secure data flow network needs to have the ability to monitor and trace attacks and illegal traffic paths in real time. Common network path tracing methods reconstruct the attack path based on the differences between attacked traffic and normal traffic characteristics, thereby determining the location of illegal nodes. However, attack path reconstruction based on traffic characteristics requires the controller to collect data flow information over a certain period of time, resulting in poor real-time performance for path backtracking and making it difficult to accurately identify illegal nodes in the network.

[0044] To address the aforementioned technical problems, this disclosure provides a method, apparatus, and storage medium for determining illegitimate nodes. This addresses the issue that attack path reconstruction based on traffic characteristics requires the controller to collect data flow information over a certain period for path backtracking, resulting in poor real-time performance and difficulty in accurately identifying illegitimate nodes in the network. The method includes: the illegitimate node determination apparatus first sends a flow-following detection instruction to the ingress gateway device, instructing it to add a flow-following detection identifier to the data flow; then, it obtains flow-following detection data from the egress gateway device, characterizing whether there is a network anomaly in the routing path between the ingress and egress gateway devices; if a network anomaly is determined in the routing path, it instructs the ingress gateway device to add a hop-by-hop detection identifier to the data flow; this causes multiple intermediate nodes between the ingress and egress gateway devices to send target flow-following detection data to the illegitimate node determination apparatus based on the hop-by-hop detection identifier; finally, based on the real-time latency information reported by multiple intermediate nodes in the target flow-following detection data, the location of the illegitimate node is determined. When an illegal node identification device determines that there is a network anomaly in the routing path between the ingress gateway device and the egress gateway device, it obtains the real-time latency information of all intermediate nodes between the ingress gateway device and the egress gateway device based on hop-by-hop detection identifiers, thereby determining the location of the illegal node. This solves the technical problem in related technologies where attack path reconstruction based on traffic characteristics requires the controller to collect data flow information within a certain period of time for path backtracking, resulting in poor real-time performance and difficulty in accurately identifying illegal nodes in the network.

[0045] In one possible implementation, the above-mentioned illegal node determination method can be applied to the illegal node determination system 100. The following, in conjunction with... Figure 1 This application provides a detailed description of an illegal node determination system 100 according to an embodiment. For example... Figure 1 As shown, Figure 1 An illegal node determination system 100 provided in this embodiment of the disclosure includes: an ingress gateway device 101, multiple intermediate node devices 102, an egress gateway device 103, and an illegal node determination device 104.

[0046] The ingress gateway device 101 is configured to receive a flow detection instruction from the illegal node determination device 104, add a flow detection identifier to the data flow based on the flow detection instruction, and, when the illegal node determination device 104 determines that there is a network anomaly in the routing path between the ingress gateway device 101 and the egress gateway device 103, receive an indication from the illegal node determination device 104, add a hop-by-hop detection identifier to the data flow, so that multiple intermediate node devices 102 between the ingress gateway device 101 and the egress gateway device 103 send their own flow detection data to the illegal node determination device 104.

[0047] Intermediate node device 102 is used to send target flow detection data to illegal node determination device 104 based on hop-by-hop detection identifiers in the data stream. The target flow detection data is the flow detection data measured by each intermediate node device 102 among multiple intermediate nodes.

[0048] The egress gateway device 103 is used to send flow detection data to the illegal node determination device 104 based on the flow detection identifier in the data flow.

[0049] The illegal node identification device 104 is used to send a flow-following detection command to the ingress gateway device 101; the flow-following detection command is used to instruct the ingress gateway device 101 to add a flow-following detection identifier to the data flow; the flow-following detection identifier is used to obtain flow-following detection data between the ingress gateway device 101 and the egress gateway device 103; obtain flow-following detection data from the egress gateway 103; the flow-following detection data is used to characterize whether there is a network anomaly in the routing path between the ingress gateway device 101 and the egress gateway device 103; if it is determined that there is a network anomaly in the routing path, instruct the ingress gateway device 101 to add a hop-by-hop detection identifier to the data flow; the hop-by-hop detection identifier is used to instruct multiple intermediate node devices 102 between the ingress gateway device 101 and the egress gateway device 103 to send target flow-following detection data; finally, based on the latency information reported by multiple intermediate node devices 102 in the target flow-following detection data, the location of the illegal node is determined.

[0050] In one possible implementation, the hardware structure of the illegal node determination device includes: Figure 2 The illegal node determination device 200 shown below includes the following components: Figure 2 The hardware structure of the illegal node determination device is described using the illegal node determination device 200 shown as an example. Figure 2As shown, the illegal node determination device 200 includes at least one processor 201, a communication line 202, and at least one communication interface 204, and may also include a memory 203. The processor 201, memory 203, and communication interface 204 are connected via the communication line 202.

[0051] The processor 201 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement embodiments of the present disclosure, such as one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs).

[0052] Communication line 202 may include a path for transmitting information between the aforementioned components.

[0053] The communication interface 204 is used to communicate with other devices or communication networks. It can use any transceiver-like device, such as Ethernet, radio access network (RAN), wireless local area network (WLAN), etc.

[0054] The memory 203 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of including or storing desired program code having the form of instructions or data structures and accessible by a computer, but not limited thereto.

[0055] In one possible design, the memory 203 can exist independently of the processor 201, meaning the memory 203 can be an external memory of the processor 201. In this case, the memory 203 can be connected to the processor 201 via the communication line 202 to store execution instructions or application code, and its execution is controlled by the processor 201 to implement the illegal node determination method provided in the following embodiments of this disclosure. In another possible design, the memory 203 can also be integrated with the processor 201, meaning the memory 203 can be an internal memory of the processor 201. For example, the memory 203 can be a cache, which can be used to temporarily store some data and instruction information.

[0056] As one possible implementation, processor 201 may include one or more CPUs, for example Figure 2 CPU0 and CPU1 in the example. Alternatively, the illegal node determination device 200 may include multiple processors, such as... Figure 2 The processors 201 and 207 are included. Alternatively, the illegal node determination device 200 may also include an output device 205 and an input device 206.

[0057] The following provides a detailed description of an illegal node determination method provided by an embodiment of this disclosure.

[0058] like Figure 3 As shown, Figure 3 This disclosure provides a method for determining illegal nodes, which can be applied to, for example... Figure 2 The illegal node determination device shown includes the following steps S301-S304, which will be described in detail below.

[0059] S301, The illegal node identification device sends a flow detection command to the ingress gateway device.

[0060] In one possible implementation, the flow detection command is used to instruct the ingress gateway device to add a flow detection identifier to the data flow.

[0061] Among them, the flow detection identifier is used to obtain flow detection data of the ingress gateway device and the egress gateway device.

[0062] S302, The illegal node identification device obtains flow detection data from the egress gateway.

[0063] Among them, the flow detection data is used to characterize whether there are network anomalies in the routing path between the ingress gateway device and the egress gateway device.

[0064] In one possible implementation, the flow detection data includes performance indicators such as latency, packet loss, and jitter of the network between the ingress gateway device and the egress gateway device.

[0065] S303. When the illegal node identification device determines that there is a network anomaly in the routing path, it instructs the ingress gateway device to add a hop-by-hop detection flag to the data flow.

[0066] Among them, the hop-by-hop detection identifier is used to instruct multiple intermediate nodes between the ingress gateway device and the egress gateway device to send target flow detection data; the target flow detection data is the flow detection data measured by each of the multiple intermediate nodes.

[0067] In one possible implementation, when the illegal node identification device determines that there is a network anomaly in the routing path, in order to determine the specific cause of the network anomaly, it instructs the ingress gateway device to add a hop-by-hop detection identifier to the data flow, obtains the flow detection data measured by each of the multiple intermediate nodes, and thus determines the cause of the network anomaly based on the flow detection data measured by each of the multiple intermediate nodes.

[0068] S304. The illegal node determination device determines the location of the illegal node based on the time delay information reported by multiple intermediate nodes in the target flow detection data.

[0069] In one possible implementation, the illegal node determination device acquires the flow detection data reported by all intermediate nodes between the ingress gateway device and the egress gateway device, determines the latency of the data flow between each intermediate node, and determines the location of the illegal node based on the latency of the data flow between each intermediate node.

[0070] The technical solution provided by the above embodiments can bring at least the following beneficial effects: The illegal node determination device first sends a flow detection command to the ingress gateway device, instructing the ingress gateway device to add a flow detection identifier to the data flow, and then obtains flow detection data from the egress gateway to characterize whether there is a network anomaly in the routing path between the ingress gateway device and the egress gateway device; if a network anomaly is determined in the routing path, the device instructs the ingress gateway device to add a hop-by-hop detection identifier to the data flow; so that multiple intermediate nodes between the ingress gateway device and the egress gateway device send target flow detection data to the illegal node determination device based on the hop-by-hop detection identifier; finally, based on the real-time latency information reported by multiple intermediate nodes in the target flow detection data, the location of the illegal node is determined. When the illegal node determination device determines that there is a network anomaly in the routing path between the ingress gateway device and the egress gateway device, it obtains the real-time latency information of all intermediate nodes between the ingress gateway device and the egress gateway device based on the hop-by-hop detection identifier, and determines the location of the illegal node. This solves the technical problem in related technologies where attack path reconstruction based on traffic characteristics requires the controller to collect data flow information within a certain period of time for path backtracking, resulting in poor real-time performance and difficulty in accurately determining illegal nodes in the network.

[0071] In one possible implementation, the flow detection data includes: latency information from multiple intermediate nodes, combined with... Figure 3 ,like Figure 4 As shown, the process of determining the location of an illegal node based on the time delay information reported by multiple intermediate nodes in the target flow detection data, as described in S304 above, can be specifically implemented through the following S401-S402, which will be explained in detail below.

[0072] S401, The illegal node determination device determines the time delay between each pair of adjacent intermediate nodes in the routing path based on the time delay information of multiple intermediate nodes.

[0073] In one possible implementation, the illegal node determination device acquires the flow detection data of all intermediate nodes between the ingress gateway device and the egress gateway device, and determines the time delay between each adjacent intermediate node based on the flow detection data of all intermediate nodes.

[0074] S402, The illegal node determination device determines the location of the illegal node based on the time delay between each pair of adjacent intermediate nodes.

[0075] In one possible implementation, the illegal node determination device determines the time delay between each adjacent intermediate node based on the flow detection data of all intermediate nodes, and determines that the illegal node is located between the adjacent intermediate nodes with higher time delay.

[0076] The technical solution provided by the above embodiments can bring at least the following beneficial effects: the illegal node determination device obtains the flow detection data of all intermediate nodes between the ingress gateway device and the egress gateway device, determines the latency between each adjacent intermediate node based on the flow detection data of all intermediate nodes, and determines that the illegal node is located between the adjacent intermediate nodes with higher latency. This solves the technical problem in related technologies that attack path reconstruction based on traffic characteristics requires the controller to collect data flow information within a certain period of time, resulting in poor real-time performance for path backtracking and difficulty in accurately determining illegal nodes in the network.

[0077] In one possible implementation, combining Figure 4 ,like Figure 5 As shown, the illegal node determination device determines the position of the illegal node based on the time delay between each pair of adjacent intermediate nodes in S402. Specifically, it can be determined by the following S501-S502, which will be explained in detail below.

[0078] S501, The illegal node determination device determines that in each pair of adjacent intermediate nodes, the adjacent intermediate node whose time delay between adjacent intermediate nodes is greater than a first preset threshold is the target intermediate node.

[0079] In one possible implementation, the illegal node determination device determines the time delay between each adjacent intermediate node based on the flow detection data of all intermediate nodes, and then determines the adjacent intermediate node whose time delay between each adjacent intermediate node is greater than a first preset threshold as the target intermediate node.

[0080] It is understandable that when the latency between adjacent intermediate nodes is greater than the first preset threshold, it can be determined that the data flow has been routed around between the adjacent nodes and the data flow has been routed to an illegal node.

[0081] S502, The illegal node determination device determines that the illegal node is located between the target intermediate nodes.

[0082] In one possible implementation, the illegal node determination device determines that the adjacent intermediate node with a delay greater than a first preset threshold between each adjacent intermediate node is the target intermediate node. That is, it determines that the data flow has undergone routing detour between the target adjacent intermediate nodes and the data flow has detoured to the illegal node. The illegal node determination device determines that the illegal node is located between the target intermediate nodes.

[0083] The technical solution provided by the above embodiments can bring at least the following beneficial effects: the illegal node determination device determines the time delay between each adjacent intermediate node based on the flow detection data of all intermediate nodes, and then determines the adjacent intermediate node whose time delay between each adjacent intermediate node is greater than the first preset threshold as the target intermediate node. When the time delay between adjacent intermediate nodes is greater than the first preset threshold, it can be determined that the data flow has undergone routing line detour between the adjacent nodes, and the data flow has detoured to the illegal node, thereby determining that the illegal node is located between the target intermediate nodes.

[0084] In one possible implementation, combining Figure 5 ,like Figure 6 As shown, the process by which the illegal node determination device instructs the ingress gateway device to add a hop-by-hop detection flag to the data flow when it determines that there is a network anomaly in the routing path can be specifically implemented through the following S601-S603, which will be explained in detail below.

[0085] S601, The illegal node identification device determines the packet loss rate and latency between the ingress gateway device and the egress gateway device based on the flow detection data.

[0086] In one possible implementation, the illegal node determination device determines the overall packet loss rate and latency of the data stream during transmission along the routing path between the ingress and egress gateway devices based on the flow detection data reported by the ingress gateway device and the flow detection data reported by the egress gateway device.

[0087] S602. When the illegal node identification device determines that the packet loss rate is greater than the second preset threshold and / or the delay is greater than the third preset threshold, it determines that there is a network anomaly in the routing path.

[0088] In one possible implementation, the illegal node identification device determines that there is a network attack in the overall routing path when the packet loss rate of the data stream during the transmission of the data stream along the routing path between the ingress gateway device and the egress gateway device is greater than a second preset threshold.

[0089] In one possible implementation, if the illegal node determination device determines that the data flow has undergone route detour during transmission along the routing path between the ingress gateway device and the egress gateway device when the delay is greater than a third preset threshold, the illegal node determination device determines that the data flow has undergone route detour during transmission along the routing path.

[0090] S603, The illegal node identification device instructs the ingress gateway device to add a hop-by-hop detection flag to the data stream.

[0091] In one possible implementation, when the illegal node identification device determines that there is a network attack in the overall routing path and / or that the data flow has been routed around during transmission in the routing path, it instructs the ingress gateway device to add a hop-by-hop detection identifier to the data flow, so that all intermediate nodes between the ingress gateway device and the egress gateway device send target flow detection data based on the hop-by-hop detection identifier.

[0092] The technical solution provided by the above embodiments can bring at least the following beneficial effects: The illegal node determination device first determines the packet loss rate and latency between the ingress gateway device and the egress gateway device. When the packet loss rate of the routing path between the ingress gateway device and the egress gateway device is greater than a second preset threshold and / or the latency is greater than a third preset threshold, it determines that there is a network anomaly in the routing path and instructs the ingress gateway device to add a hop-by-hop detection identifier to the data flow, so that all intermediate nodes between the ingress gateway device and the egress gateway device send target flow detection data based on the hop-by-hop detection identifier, so that the illegal node determination device determines the specific reason for the network anomaly in the routing path based on the target flow detection data.

[0093] One possible implementation is, such as Figure 7 As shown in S303 above, when the illegal node determination device determines that there is a network anomaly in the routing path, it instructs the ingress gateway device to add a hop-by-hop detection flag to the data flow. Then, it needs to determine whether the cause of the network anomaly is path optimization. This process can be implemented through the following S701-S702, which will be explained in detail below.

[0094] S701, The illegal node determination device determines whether all the intermediate nodes that transmit target flow detection data between the ingress gateway device and the egress gateway device are preset intermediate nodes.

[0095] In one possible implementation, the target following detection data includes the identifier of the sending end node. The illegal node determination device determines whether all the multiple intermediate nodes that sent the target following detection data are preset intermediate nodes based on the identifier of the sending end node in the target following detection data and the identifier of the preset intermediate node.

[0096] S702. When the illegal node determination device determines that there is a non-preset intermediate node among multiple intermediate nodes, it determines that the network anomaly of the routing path is caused by path optimization.

[0097] In one possible implementation, when a physical link failure occurs in the routing path between the ingress gateway device and the egress gateway device, routing path optimization is performed to adjust the data flow transmission path. Data transmission is carried out by non-preset intermediate nodes and the flow detection data is reported. If the illegal node determination device determines that there are non-preset intermediate nodes among the multiple intermediate nodes, it determines that the network anomaly of the routing path is caused by path optimization.

[0098] The technical solution provided by the above embodiments can bring at least the following beneficial effects: When the illegal node determination device determines that there is a network anomaly in the routing path, it instructs the ingress gateway device to add a hop-by-hop detection identifier to the data flow. Based on the identifier of the sending end node in the target following flow detection data and the identifier of the preset intermediate node, it determines whether all the multiple intermediate nodes sending the target following flow detection data are preset intermediate nodes. If it is determined that there are non-preset intermediate nodes among the multiple intermediate nodes, it determines that the network anomaly in the routing path is caused by path optimization.

[0099] In one possible implementation, the target flow detection data also includes: the packet loss rate of each intermediate node, such as... Figure 8 As shown, when it is determined that all the intermediate nodes for sending target flow detection data between the ingress gateway device and the egress gateway device are preset intermediate nodes, it is necessary to determine the intermediate node in the routing path where the network attack occurred. This process can be implemented through the following S801-S802, which will be explained in detail below.

[0100] S801, The illegal node identification device determines the packet loss rate of each intermediate node.

[0101] In one possible implementation, the illegal node identification device determines the packet loss rate of the data stream during transmission at each intermediate node between the ingress gateway device and the egress gateway device based on target flow detection data.

[0102] S802, The illegal node determination device determines that among the packet loss rates of each intermediate node, the intermediate node with a packet loss rate greater than the fourth preset threshold is under network attack.

[0103] In one possible implementation, the illegal node determination device determines the packet loss rate of the data stream when it is transmitted between the ingress gateway device and the egress gateway device based on the target flow detection data, and determines that the intermediate nodes with a packet loss rate greater than a fourth preset threshold are under network attack.

[0104] The technical solution provided by the above embodiments can bring at least the following beneficial effects: When the illegal node determination device determines that all the intermediate nodes for sending target flow detection data between the ingress gateway device and the egress gateway device are preset intermediate nodes, it determines the packet loss rate of the data stream when it is transmitted at each intermediate node between the ingress gateway device and the egress gateway device based on the target flow detection data, and determines the intermediate node in the routing path where the network attack occurred based on the packet loss rate.

[0105] One possible implementation is, such as Figure 9 As shown, the illegal node determination device also needs to determine whether the network anomaly is caused by routing path congestion. This process can be implemented through the following S901-S902, which will be explained in detail below.

[0106] S901, the illegal node determination device determines the amount of data transmitted by each of the multiple intermediate nodes based on the target flow detection data.

[0107] In one possible implementation, the illegal node determination device determines the amount of data transmitted by each intermediate node based on the flow detection data reported by each intermediate node in the routing path.

[0108] It is understandable that the amount of data to be transmitted may increase during the data flow through the routing path, and there may also be data loss. Therefore, the amount of data transmitted at each intermediate node may be different.

[0109] S902. When the illegal node identification device determines that the network anomaly is caused by routing path congestion when there is a situation where the amount of data transmitted in multiple intermediate nodes exceeds the data transmission threshold of the intermediate nodes.

[0110] In one possible implementation, the illegal node determination device obtains the data transmission threshold of each intermediate node in the routing path, and determines that the network anomaly is caused by routing path congestion if it determines that there is an intermediate node in the routing path whose data transmission volume is greater than the intermediate node's data transmission threshold.

[0111] The technical solution provided by the above embodiments can bring at least the following beneficial effects: the illegal node determination device determines the amount of data transmitted by each of the multiple intermediate nodes based on the target flow detection data, and in the case where the amount of data transmitted by the multiple intermediate nodes is greater than the data transmission threshold of the intermediate node, it determines that the network anomaly is caused by routing path congestion.

[0112] As can be seen, the above mainly describes the technical solutions provided by the embodiments of this disclosure from a methodological perspective. To achieve the above functions, it includes corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, in conjunction with the modules and algorithm steps of the various examples described in the embodiments disclosed herein, the embodiments of this disclosure can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.

[0113] This disclosure embodiment can divide the illegal node determination device into functional modules according to the above method example. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. Optionally, the module division in this disclosure embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.

[0114] One possible implementation is, such as Figure 10 , Figure 10 This is a schematic diagram of the structure of an illegal node determination device 1000 provided in this disclosure.

[0115] An illegal node identification device 1000 includes: a communication unit 1001 and a processing unit 1002; the communication unit 1001 sends a flow-following detection command to an ingress gateway device; the flow-following detection command instructs the ingress gateway device to add a flow-following detection identifier to the data flow; the flow-following detection identifier is used to acquire flow-following detection data between the ingress gateway device and the egress gateway device; the communication unit 1001 acquires flow-following detection data from the egress gateway; the flow-following detection data is used to characterize whether there is a network anomaly in the routing path between the ingress gateway device and the egress gateway device; the processing unit 1002, when it is determined that there is a network anomaly in the routing path, instructs the ingress gateway device to add a hop-by-hop detection identifier to the data flow; the hop-by-hop detection identifier instructs multiple intermediate nodes between the ingress gateway device and the egress gateway device to send target flow-following detection data; the target flow-following detection data is the flow-following detection data measured by each of the multiple intermediate nodes; the processing unit 1002 determines the location of the illegal node based on the delay information reported by the multiple intermediate nodes in the target flow-following detection data.

[0116] In one possible implementation, the flow detection data includes: delay information of multiple intermediate nodes; the processing unit 1002 is specifically used to: determine the delay between each pair of adjacent intermediate nodes in the routing path based on the delay information of multiple intermediate nodes; and determine the location of illegal nodes based on the delay between each pair of adjacent intermediate nodes.

[0117] In one possible implementation, the processing unit 1002 is specifically used to: determine that in each pair of adjacent intermediate nodes, the adjacent intermediate node whose time delay between adjacent intermediate nodes is greater than a first preset threshold is the target intermediate node; and determine that the illegal node is located between the target intermediate nodes.

[0118] In one possible implementation, the processing unit 1002 is specifically used to: determine the packet loss rate and latency between the ingress gateway device and the egress gateway device based on the flow detection data; determine that there is a network anomaly in the routing path when the packet loss rate is greater than a second preset threshold and / or the latency is greater than a third preset threshold; and instruct the ingress gateway device to add a hop-by-hop detection flag to the data flow.

[0119] In one possible implementation, after instructing the ingress gateway device to add a hop-by-hop detection identifier to the data flow when a network anomaly is determined to exist in the routing path, the processing unit 1002 is further configured to: determine whether all the multiple intermediate nodes for sending target flow detection data between the ingress gateway device and the egress gateway device are preset intermediate nodes; and determine that the network anomaly in the routing path is caused by path optimization when it is determined that there are non-preset intermediate nodes among the multiple intermediate nodes.

[0120] In one possible implementation, the target flow detection data also includes: the packet loss rate of each intermediate node; the processing unit 1002 is further used to determine the packet loss rate of each intermediate node; in determining the packet loss rate of each intermediate node, intermediate nodes with packet loss rates greater than a fourth preset threshold are considered to be under network attack.

[0121] In one possible implementation, the processing unit 1002 is further configured to: determine the amount of data transmitted by each of the multiple intermediate nodes based on the target flow detection data; and determine that the network anomaly is caused by routing path congestion if, among the multiple intermediate nodes, there is a case where the amount of data transmitted is greater than the data transmission threshold of the intermediate node.

[0122] This disclosure also provides an illegal node determination device, which includes a processor and a memory; wherein the memory is used to store computer execution instructions, and when the illegal node determination device is running, the processor executes the computer execution instructions stored in the memory, so that the illegal node determination device performs the illegal node determination method described in this disclosure embodiment.

[0123] Embodiments of this disclosure provide a computer program product containing instructions that, when executed on a computer, cause the computer to perform the illegal node determination method in the above method embodiments.

[0124] Embodiments of this disclosure provide a chip including a processor and a communication interface, the communication interface and the processor being coupled together, the processor being used to run computer programs or instructions to implement the illegal node determination method as described in the above method embodiments.

[0125] The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), registers, hard disks, optical fibers, compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing, or any other form of computer-readable storage medium in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may reside in an application-specific integrated circuit (ASIC). In this embodiment of the disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0126] Since the apparatus, devices, computer-readable storage media, and computer program products in the embodiments of this disclosure can be applied to the above methods, the technical effects they can achieve can also be referred to the above method embodiments. The embodiments of this disclosure will not be repeated here.

[0127] The above descriptions are merely specific embodiments of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any variations or substitutions within the technical scope disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.

Claims

1. A method for determining illegal nodes, characterized in that, include: Send a flow detection command to the ingress gateway device; The following detection instruction is used to instruct the ingress gateway device to add a following detection identifier to the data stream; The following flow detection identifier is used to acquire the following flow detection data of the ingress gateway device and the egress gateway device; The flow detection data is obtained from the egress gateway; The flow detection data is used to characterize whether there are network anomalies in the routing path between the ingress gateway device and the egress gateway device; If a network anomaly is detected in the routing path, the ingress gateway device is instructed to add a hop-by-hop detection flag to the data stream. The hop-by-hop detection identifier is used to instruct multiple intermediate nodes between the ingress gateway device and the egress gateway device to send target flow detection data; The target flow detection data is the flow detection data measured by each of the plurality of intermediate nodes; Based on the delay information reported by multiple intermediate nodes in the target flow detection data, the location of the illegal node is determined.

2. The method according to claim 1, characterized in that, The flow-following detection data includes: the latency information of the multiple intermediate nodes; determining the location of the illegal node based on the latency information reported by the multiple intermediate nodes in the target flow-following detection data includes: The delay between each pair of adjacent intermediate nodes in the routing path is determined based on the delay information of the multiple intermediate nodes. The location of the illegal node is determined based on the time delay between each pair of adjacent intermediate nodes.

3. The method according to claim 2, characterized in that, Determining the location of the illegal node based on the time delay between each pair of adjacent intermediate nodes includes: In each pair of adjacent intermediate nodes, the adjacent intermediate node whose time delay between adjacent intermediate nodes is greater than a first preset threshold is identified as the target intermediate node. The illegal node is determined to be located between the target intermediate nodes.

4. The method according to claim 3, characterized in that, The step of instructing the ingress gateway device to add a hop-by-hop detection flag to the data stream when a network anomaly is determined to exist in the routing path includes: Based on the flow detection data, the packet loss rate and latency between the ingress gateway device and the egress gateway device are determined. If the packet loss rate is greater than a second preset threshold and / or the latency is greater than a third preset threshold, it is determined that there is a network anomaly in the routing path; The ingress gateway device is instructed to add a hop-by-hop detection flag to the data stream.

5. The method according to claim 4, characterized in that, If a network anomaly is determined to exist in the routing path, after instructing the ingress gateway device to add a hop-by-hop detection flag to the data flow, the method further includes: Determine whether all the multiple intermediate nodes between the ingress gateway device and the egress gateway device that send the target flow detection data are preset intermediate nodes; If it is determined that there is a non-preset intermediate node among the plurality of intermediate nodes, the network anomaly of the routing path is determined to be caused by path optimization.

6. The method according to claim 5, characterized in that, The target flow detection data further includes: the packet loss rate of each intermediate node; when it is determined that all intermediate nodes sending the target flow detection data between the ingress gateway device and the egress gateway device are preset intermediate nodes, the method further includes: Determine the packet loss rate of each intermediate node; Among the packet loss rates of each intermediate node, those intermediate nodes with packet loss rates greater than a fourth preset threshold are considered to be under network attack.

7. The method according to any one of claims 1-6, characterized in that, The method further includes: The amount of data transmitted by each of the plurality of intermediate nodes is determined based on the target flow detection data. If, among the multiple intermediate nodes, there exists a data transmission volume exceeding the intermediate node's data transmission threshold, the network anomaly is determined to be caused by congestion in the routing path.

8. An illegal node determination device, characterized in that, include: Communication unit and processing unit; The communication unit sends a flow detection command to the ingress gateway device; The following detection instruction is used to instruct the ingress gateway device to add a following detection identifier to the data stream; the following detection identifier is used to obtain the following detection data of the ingress gateway device and the egress gateway device. The communication unit is used to obtain the flow detection data from the egress gateway; The flow detection data is used to characterize whether there are network anomalies in the routing path between the ingress gateway device and the egress gateway device; The processing unit is configured to instruct the ingress gateway device to add a hop-by-hop detection identifier to the data stream when it is determined that there is a network anomaly in the routing path; The hop-by-hop detection identifier is used to instruct multiple intermediate nodes between the ingress gateway device and the egress gateway device to send target flow detection data; The target flow detection data is the flow detection data measured by each of the plurality of intermediate nodes; The processing unit is used to determine the location of illegal nodes based on the delay information reported by multiple intermediate nodes in the target flow detection data.

9. An illegal node determination device, characterized in that, include: A processor and a memory; wherein the memory is used to store computer execution instructions, and when the illegal node determination device is running, the processor executes the computer execution instructions stored in the memory to cause the illegal node determination device to perform the illegal node determination method according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed by a processor that determines an illegal node, cause the illegal node determination device to perform the illegal node determination method according to any one of claims 1-7.

Citation Information

Patent Citations

  • Routing node quality monitoring method and device and related equipment

    CN116055361A

  • KR20240050072A