Information collection method and device, communication device and readable storage medium
By receiving mirror domain name configuration information and parsing and analyzing the TCP handshake information of IP addresses, the problem of low accuracy of information collection caused by small gateway memory capacity is solved, and efficient information collection and edge computing capabilities are realized.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-25
- Publication Date
- 2026-03-24
AI Technical Summary
In existing technologies, due to the small memory capacity of gateways, storing a large number of IP addresses and packet timestamps results in low accuracy of packet collection information and easy information loss.
By receiving the mirror domain name configuration information, resolving the IP address corresponding to the domain name, and analyzing the TCP handshake information of each IP address, the mapping relationship between the mirror domain name and the IP address and the TCP handshake information are sent directly, avoiding the storage of the original packets and only storing statistical information.
It improves the accuracy of information collection, avoids data loss due to excessive storage, and enhances the precision of collected information and the ability of edge computing.
Smart Images

Figure CN118802837B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of communication technology, specifically relating to an information acquisition method, apparatus, communication equipment, and readable storage medium. Background Technology
[0002] To collect network service transmission quality information, related technologies have proposed using packet mirroring methods to analyze packets in real time, obtaining Transmission Control Protocol (TCP) handshake information, etc. However, existing gateway mirroring structures require storing a large amount of Internet Protocol (IP) addresses and packet timestamps for packet analysis. In this case, since the gateway's memory capacity is generally small, the stored information is prone to loss, resulting in low accuracy of the collected packet information. Summary of the Invention
[0003] The purpose of this application is to provide an information collection method, apparatus, communication device, and readable storage medium to solve the problem of low accuracy of information collected from messages in related technologies.
[0004] To solve the above-mentioned technical problems, this application is implemented as follows:
[0005] Firstly, an information collection method is provided, including:
[0006] The first device receives first information, which is used to configure the mirror domain name;
[0007] The first device parses the message of the mirror domain name to obtain at least one Internet Protocol (IP) address corresponding to the mirror domain name;
[0008] The first device analyzes the mirrored Transmission Control Protocol (TCP) packets for each IP address to obtain the TCP handshake information for each IP address;
[0009] The first device sends the mapping relationship between the mirror domain name and the at least one IP address, as well as the TCP handshake information for each IP address, to the second device.
[0010] Secondly, an information collection method is provided, including:
[0011] The second device sends first information to the first device, the first information being used to configure the mirror domain name;
[0012] The second device receives the mapping relationship between the mirror domain name and at least one IP address, as well as the TCP handshake information for each IP address, sent by the first device; wherein, the at least one IP address is obtained by parsing the packets of the mirror domain name;
[0013] The second device obtains the TCP handshake information of at least one IP address corresponding to the mirror domain name based on the correspondence between the mirror domain name and at least one IP address and the TCP handshake information of each IP address.
[0014] Thirdly, an information collection device is provided, including:
[0015] The first receiving module is used to receive first information, which is used to configure the mirror domain name;
[0016] The parsing module is used to parse the packets of the mirror domain name and obtain at least one IP address corresponding to the mirror domain name;
[0017] The analysis module is used to analyze the mirrored TCP packets of each IP address to obtain the TCP handshake information of each IP address;
[0018] The first sending module is used to send the correspondence between the mirror domain name and the at least one IP address, as well as the TCP handshake information for each IP address, to the second device.
[0019] Fourthly, an information acquisition device is provided, comprising:
[0020] The second sending module is used to send first information to the first device, wherein the first information is used to configure the mirror domain name;
[0021] The second receiving module is configured to receive the mapping relationship between the mirror domain name and at least one IP address, as well as the TCP handshake information for each IP address, sent by the first device; wherein the at least one IP address is obtained by parsing the message of the mirror domain name;
[0022] The processing module is used to obtain the TCP handshake information of at least one IP address corresponding to the mirror domain name based on the correspondence between the mirror domain name and at least one IP address and the TCP handshake information of each IP address.
[0023] Fifthly, a communication device is provided, including a processor, a memory, and a program or instructions stored in the memory and executable on the processor, wherein the program or instructions, when executed by the processor, implement the steps of the method described in the first aspect, or the steps of the method described in the second aspect.
[0024] In a sixth aspect, a readable storage medium is provided, on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first aspect, or the steps of the method described in the second aspect.
[0025] In a seventh aspect, a computer program product is provided, including computer instructions that, when executed by a processor, implement the steps of the method described in the first aspect, or the steps of the method described in the second aspect.
[0026] In this embodiment, the first device can receive first information, which is used to configure a mirror domain name, parse the packets of the mirror domain name to obtain at least one IP address corresponding to the mirror domain name, analyze the mirror TCP packets of each IP address to obtain the TCP handshake information of each IP address, and send the correspondence between the mirror domain name and the at least one IP address, as well as the TCP handshake information of each IP address, to the second device. Therefore, the first device can directly analyze and statistically analyze the mirror TCP packets, thus only storing the statistical information and not the original packets, avoiding data loss due to excessive storage and improving the accuracy of the collected information. Attached Figure Description
[0027] Figure 1 This is a schematic diagram of the architecture of the information collection system in the embodiments of this application;
[0028] Figure 2 This is a flowchart of an information collection method provided in an embodiment of this application;
[0029] Figure 3 This is a flowchart of another information collection method provided in the embodiments of this application;
[0030] Figure 4 This is a schematic diagram of the structure of an information collection device provided in an embodiment of this application;
[0031] Figure 5 This is a schematic diagram of the structure of an information collection device provided in an embodiment of this application;
[0032] Figure 6 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application. Detailed Implementation
[0033] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0034] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and are not used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and are not limited in number; for example, a first object can be one or more.
[0035] To address the issue of low accuracy in message collection information in related technologies, this application proposes an information collection system, such as... Figure 1 As shown, the system includes at least: gateway hardware 11, gateway software entity 12, and gateway application 13; the functional descriptions of each part are as follows:
[0036] (1) Gateway Hardware 11:
[0037] The gateway hardware 11 includes at least packet forwarding hardware 111. This packet forwarding hardware 111 can receive configured forwarding rules from the gateway software entity 12; and receive packets sent by the Content Delivery Network (CDN), such as video content, game content, and other data packets. Based on the configured forwarding rules, it forwards packets that meet the hard forwarding characteristics to the next node, and forwards packets that do not meet the hard forwarding characteristics to the gateway software entity 12 for processing. The hard forwarding characteristics can be set based on actual needs, and this embodiment does not limit this.
[0038] (2) Gateway software entity 12:
[0039] The gateway software entity 12 includes at least a packet processing module 121, a forwarding rule learning module 122, a packet forwarding control module 123, a packet mirroring interface 124, a Domain Name System (DNS) monitoring module 125, and a packet mirroring module 126; the functions of each part are described below:
[0040] - The message processing module 121 can receive messages that do not conform to the hard forwarding characteristics from the message forwarding hardware 111, process the received messages, and send messages with unknown rules to the forwarding rule learning module 122 for learning.
[0041] - The forwarding rule learning module 122 can learn from received packets (generally control packets), record TCP handshake time, TCP handshake delay (e.g., the delay between the second and first handshakes, the delay between the third and second handshakes), and set packet forwarding rules based on the recorded information. It then sends the set forwarding rules to the packet forwarding control module 123. In addition, the forwarding rule learning module 122 can also timestamp / add timestamps to the mirrored TCP three-way handshake packets based on the configured mirrored IP address, and send the timestamped / added timestamped packets to the packet mirroring module 126 for analysis and statistics.
[0042] - The message forwarding control module 123 can send the configured forwarding rules to the message forwarding hardware 111;
[0043] The DNS monitoring module 125 can receive configuration information from the gateway application 13 via the packet mirroring interface 124. This configuration information can be used to configure at least one mirror domain name and assign an index to each mirror domain name. This index is used to identify the domain name to which the IP address belongs. Furthermore, the DNS monitoring module 125 can also parse the packets of each domain name, monitor the IP addresses of the domain names to be mirrored, and store the correspondence / mapping relationship between mirror domain names and IP addresses. If the same domain name is resolved multiple times during the statistical period, the last resolution will be used. If an IP address resolved by DNS previously generates TCP traffic, that IP address needs to be added to the end of the list of IP addresses resolved by the latest domain name. The index of the IP address in the IP address list can be used for TCP handshake information statistics. For example, the number of IP addresses in the IP address list can exceed 10, with a maximum of 20.
[0044] Optionally, for packet mirroring interface 124, packets from the downstream device can be mirrored based on the remote address. For mirroring rules with a domain name as the destination address, the DNS monitoring module 125 needs to establish a mapping between the domain name and IP address, which may be a one-to-many relationship, meaning one domain name corresponds to multiple IP addresses. For mirroring rules with a domain name as the destination address or an empty destination address, it can support mirroring both IPv4 and IPv6 packets from the downstream device at the destination IP address simultaneously.
[0045] In one alternative embodiment, such as Figure 1 The DNS monitoring module 125 can report DNS information and the correspondence / mapping relationship between mirror domain names and at least one IP address to the message processing function module 132 in the gateway application 13 through the message domain name query interface. For example, the DNS monitoring module 125 can perform the reporting operation based on the query request of the message processing function module 132.
[0046] - The message mirroring module 126 can analyze and statistically analyze TCP three-way handshake messages that conform to the mirroring rules and are timestamped, obtain and store the TCP handshake information for each IP address; this TCP handshake information includes, but is not limited to, the time offset value of the first handshake, the delay between the second and first handshakes, and the delay between the third and second handshakes; wherein, the time offset value of the first handshake is the difference between the monitored first TCP handshake time and the time of the first message of the corresponding domain name; the delay between the second and first handshakes is the difference between the time point of the second handshake and the time point of the first handshake in the TCP three-way handshake; the delay between the third and second handshakes is the difference between the time point of the third handshake and the time point of the second handshake in the TCP three-way handshake. The TCP handshake information can be statistically analyzed based on the IP address index (which can be abbreviated as: IP index).
[0047] In one alternative embodiment, such as Figure 1 The packet mirroring module 126 can report the TCP handshake information it has obtained to the packet processing function module 132 in the gateway application 13 through the packet mirroring query interface.
[0048] (3) Gateway Application 13:
[0049] The gateway application 13 can use deep packet inspection (DPI) technology and includes at least a packet capture control module 131 and a packet processing function module 132; the functions of each part are described below:
[0050] - The packet capture control module 131 can set up mirrored packets and corresponding mirroring rules, where each mirroring rule corresponds to a mirroring task, for example, up to 255 mirroring tasks can be set up; a corresponding mirroring domain name can be configured for each mirroring task; the packet capture control module 131 can configure mirroring tasks and corresponding mirroring domain names to the DNS monitoring module 125 through the packet mirroring interface 124.
[0051] - The message processing module 132 can obtain DNS information and the correspondence between mirrored domain names and IP addresses from the DNS monitoring module 125 through the message domain name query interface, and perform at least one of the following: restore DNS resolution time, resolve the address of the DNS server (such as IP address), and determine the DNS resolution latency; at the same time, the message processing module 132 can also obtain TCP handshake information from the message mirroring module 126 through the message mirroring query interface. The TCP handshake information is statistically analyzed based on the IP address index; then, based on the DNS domain name index and the TCP handshake information, the subdomain TCP handshake information can be obtained and reported to the collection platform, etc.
[0052] Optionally, the solution in this application is applicable to low-consumption gateway services, etc.
[0053] The information collection method, apparatus, communication device, and readable storage medium provided in this application will be described in detail below with reference to the accompanying drawings and through specific embodiments and application scenarios.
[0054] Please see Figure 2 , Figure 2 This is a flowchart of an information collection method provided in an embodiment of this application. The method is applied to a first device, such as the one described above. Figure 1 Gateway software entities or other embedded devices, edge devices, etc., that can achieve similar functions. For example... Figure 2 As shown, the method includes the following steps:
[0055] Step 21: The first device receives the first information, which is used to configure the mirror domain name;
[0056] Step 22: The first device parses the message of the mirror domain name to obtain at least one IP address corresponding to the mirror domain name;
[0057] Step 23: The first device analyzes the mirrored TCP packets for each IP address to obtain the TCP handshake information for each IP address;
[0058] Step 24: The first device sends the mapping relationship between the mirror domain name and the at least one IP address, as well as the TCP handshake information for each IP address, to the second device.
[0059] In this embodiment, the second device is, for example, the one described above. Figure 1 Gateway applications or other software probe plugins that can achieve similar functions.
[0060] Optionally, the first device (e.g., a gateway software entity) can receive first information for configuring the mirror domain name from the second device (e.g., a gateway application) via an application programming interface (API).
[0061] Optionally, the correspondence between the mirror domain name and the IP address can be a one-to-one relationship, that is, one domain name corresponds to one IP address; or it can be a one-to-many relationship, that is, one domain name corresponds to multiple IP addresses.
[0062] Optionally, the mirrored TCP packet is specifically a mirrored TCP three-way handshake packet. Existing technologies can be used to identify the TCP three-way handshake packet, and this embodiment does not limit this approach.
[0063] Optionally, the TCP handshake information may include, but is not limited to, at least one of the following: the time offset value of the first handshake, the delay between the second and first handshakes, and the delay between the third and second handshakes. Specifically, the time offset value of the first handshake is the difference between the monitored first TCP handshake time and the time of the first packet of the corresponding domain name. This allows the storage of the complete timestamp of the first packet for each domain name, while subsequent packets only need to store the offset value, thus reducing the time information by more than half. After the stored data is read, all information is reset. The delay between the second and first handshakes is the difference between the time point of the second handshake and the time point of the first handshake in the TCP three-way handshake. The delay between the third and second handshakes is the difference between the time point of the third handshake and the time point of the second handshake in the TCP three-way handshake. If multiple TCP handshake messages exist for the same IP address, the average of the delays of the first and second handshakes (i.e., the delay between the second and first handshakes) and the delays of the second and third handshakes (i.e., the delay between the third and second handshakes) is taken.
[0064] Optionally, analyzing the mirrored TCP packets for each IP address to obtain the TCP handshake information for each IP address may include: analyzing the mirrored TCP packets for each IP address and using the index of each IP address to statistically analyze the obtained TCP handshake information to obtain the TCP handshake information for each IP address. This allows for statistical analysis of packet information using the index of IP addresses, thereby improving statistical efficiency.
[0065] Optionally, when sending TCP handshake information for each IP address, the TCP handshake information can be statistically analyzed based on the IP address index (which can be abbreviated as: IP index), and the corresponding format is, for example: "IP index 1: [{time offset value of the first handshake, delay of the first and second handshakes, delay of the second and third handshakes}, {time offset value of the first handshake, delay of the first and second handshakes, delay of the second and third handshakes}...]"; for example, up to 50 arrays can be supported.
[0066] In this embodiment, the first device can receive first information, which is used to configure a mirror domain name, parse the packets of the mirror domain name to obtain at least one IP address corresponding to the mirror domain name, analyze the mirror TCP packets of each IP address to obtain the TCP handshake information of each IP address, and send the correspondence between the mirror domain name and the at least one IP address, as well as the TCP handshake information of each IP address, to the second device. Therefore, the first device can directly analyze and statistically analyze the mirror TCP packets, thus only storing the statistical information and not the original packets, avoiding data loss due to excessive storage and improving the accuracy of the collected information.
[0067] Furthermore, by adopting the scheme in this application, parsing information / statistical information can be sent directly to the second device without forwarding a large number of TCP packets, thereby avoiding excessive CPU load on the central processing unit caused by forwarding a large number of TCP packets.
[0068] Furthermore, by adopting the scheme in this application, the edge computing capabilities of the first device (such as a gateway) can be leveraged to perform information statistics without affecting the accuracy of DNS information and TCP handshake delay data, or without losing critical data. This transforms the original packets into extremely concise, high-value data, thereby reducing the amount of data storage and forwarding.
[0069] In this embodiment of the application, to improve the accuracy of information statistics, a timestamp can be introduced into the mirrored TCP packets. The timestamp is the point in time when the packet receiver receives the packet. Before analyzing the mirrored TCP packets for each IP address, the information collection method may further include:
[0070] The first device adds a timestamp to the TCP three-way handshake message mirrored for each IP address; this adding of a timestamp can also be called stamping a timestamp.
[0071] The analysis of mirrored TCP packets for each IP address to obtain TCP handshake information for each IP address may include: the first device analyzing the TCP three-way handshake packets with timestamps added to obtain TCP handshake information for each IP address. Since packet forwarding / mirroring often experiences delays or even loss when there are a large number of packets, adding timestamps can greatly improve the accuracy of the received packet time, thereby enhancing the accuracy of the obtained TCP handshake information.
[0072] In this embodiment, multiple domain names can be resolved. Specifically, the first information can be used to configure multiple mirror domain names and a domain name index for each mirror domain name. Correspondingly, step 22 above may include: the first device resolving the message of each mirror domain name to obtain at least one IP address corresponding to each mirror domain name. This improves the efficiency of collecting TCP handshake information compared to related technologies that only support a single domain name.
[0073] Please see Figure 3 , Figure 3 This is a flowchart of an information collection method provided in an embodiment of this application. The method is applied to a second device, such as the one described above. Figure 1 Gateway applications or other software probe plugins that can achieve similar functionality. For example... Figure 3 As shown, the method includes the following steps:
[0074] Step 31: The second device sends first information to the first device, the first information being used to configure the mirror domain name;
[0075] Step 32: The second device receives the mapping relationship between the mirror domain name and at least one IP address, as well as the TCP handshake information for each IP address, sent by the first device; the at least one IP address is obtained by parsing the packets of the mirror domain name;
[0076] Step 33: The second device obtains the TCP handshake information of at least one IP address corresponding to the mirror domain name based on the correspondence between the mirror domain name and at least one IP address and the TCP handshake information of each IP address.
[0077] In this embodiment, the first device is, for example, the one described above. Figure 1 Gateway software entities or other embedded devices, edge devices, etc. that can achieve similar functions.
[0078] Optionally, the second device (e.g., a gateway application) can send first information for configuring the mirror domain name to the first device (e.g., a gateway software entity) via an API.
[0079] Optionally, the correspondence between the mirror domain name and the IP address can be a one-to-one relationship, that is, one domain name corresponds to one IP address; or it can be a one-to-many relationship, that is, one domain name corresponds to multiple IP addresses.
[0080] Optionally, the TCP handshake information may include, but is not limited to, at least one of the following: the time offset value of the first handshake, the delay between the second and first handshakes, and the delay between the third and second handshakes. Specifically, the time offset value of the first handshake is the difference between the monitored first TCP handshake time and the time of the first packet of the corresponding domain name. This allows the storage of the complete timestamp of the first packet for each domain name, while subsequent packets only need to store the offset value, thus reducing the time information by more than half. After the stored data is read, all information is reset. The delay between the second and first handshakes is the difference between the time point of the second handshake and the time point of the first handshake in the TCP three-way handshake. The delay between the third and second handshakes is the difference between the time point of the third handshake and the time point of the second handshake in the TCP three-way handshake. If multiple TCP handshake messages exist for the same IP address, the average of the delays of the first and second handshakes (i.e., the delay between the second and first handshakes) and the delays of the second and third handshakes (i.e., the delay between the third and second handshakes) is taken.
[0081] Optionally, the TCP handshake information can be statistically analyzed based on IP address indexes (which can be abbreviated as: IP index), and the corresponding format is, for example: "IP index 1: [{time offset value of the first handshake, delay of the first and second handshakes, delay of the second and third handshakes}, {time offset value of the first handshake, delay of the first and second handshakes, delay of the second and third handshakes}...]"; for example, up to 50 arrays can be supported.
[0082] In this embodiment, the first device can directly analyze and statistically analyze the mirrored TCP packets, thus storing only the statistical information instead of the original packets, avoiding data loss due to excessive storage and improving the accuracy of the collected information; while the second device can obtain the TCP handshake information of the domain name based on the obtained parsing information and statistical information.
[0083] In this embodiment, multiple domain names can be resolved. Specifically, the first information can be used to configure multiple mirror domain names and a domain name index for each mirror domain name. Correspondingly, step 32 may include: the second device receiving the correspondence between each mirror domain name and at least one IP address sent by the first device, as well as the TCP handshake information for each IP address.
[0084] Step 33 may include: the second device obtaining the TCP handshake information of at least one IP address corresponding to each mirror domain name based on the correspondence between each mirror domain name and at least one IP address and the TCP handshake information of each IP address. This improves the efficiency of TCP handshake information collection compared to related technologies that only support a single domain name.
[0085] Optionally, the information collection method in this application embodiment may further include:
[0086] The second device receives DNS information sent by the first device; this DNS information can be understood as information related to resolving domain names.
[0087] Based on the DNS information, the second device performs at least one of the following: determining the DNS resolution time, resolving the address of the DNS server (e.g., IP address), and determining the DNS resolution latency. This allows for direct access to information related to DNS resolution.
[0088] In one optional embodiment, the DNS information may include DNS resolution time, DNS server address, and / or DNS resolution latency, etc.
[0089] It should be noted that the information collection method provided in this application embodiment can be executed by an information collection device or a control module within that information collection device for executing the information collection method. This application embodiment uses an information collection device executing the information collection method as an example to illustrate the information collection device provided in this application embodiment.
[0090] Please see Figure 4 , Figure 4 This is a schematic diagram of the structure of an information collection device provided in an embodiment of this application. The device is applied to a first device, such as the one described above. Figure 1 Gateway software entities or other embedded devices, edge devices, etc. that can achieve similar functions; such as Figure 4 As shown, the information acquisition device 40 includes:
[0091] The first receiving module 41 is used to receive first information, which is used to configure the mirror domain name;
[0092] The parsing module 42 is used to parse the message of the mirror domain name and obtain at least one IP address corresponding to the mirror domain name;
[0093] Analysis module 43 is used to analyze the mirrored TCP packets of each IP address to obtain the TCP handshake information of each IP address;
[0094] The first sending module 44 is used to send the correspondence between the mirror domain name and the at least one IP address, as well as the TCP handshake information of each IP address, to the second device.
[0095] Optionally, the information collection device 40 includes:
[0096] An additional module is added to add a timestamp to the TCP three-way handshake packets of each IP address before analyzing the mirrored TCP packets of each IP address.
[0097] The analysis module 43 is specifically used to: analyze the TCP three-way handshake messages after adding timestamps to obtain the TCP handshake information for each IP address.
[0098] Optionally, the TCP handshake information includes at least one of the following:
[0099] The time offset of the first handshake;
[0100] The time delay between the first and second handshakes;
[0101] The time delay between the third handshake and the second handshake.
[0102] Optionally, the first information is specifically used to configure multiple mirror domain names and the domain name index of each mirror domain name; the parsing module 42 is specifically used to: parse the message of each mirror domain name to obtain at least one IP address corresponding to each mirror domain name.
[0103] Optionally, the analysis module 43 is specifically used to: analyze the mirrored TCP packets of each IP address, and use the index of each IP address to perform statistics on the analyzed TCP handshake information to obtain the TCP handshake information of each IP address.
[0104] The information acquisition device 40 of this application embodiment can achieve the above-mentioned... Figure 2 The various processes of the method embodiments shown can achieve the same technical effect, and will not be described again here to avoid repetition.
[0105] Please see Figure 5 , Figure 5 This is a schematic diagram of the structure of an information collection device provided in an embodiment of this application. The device is applied to a second device, such as the one described above. Figure 1 Gateway applications or other software probe plugins that can achieve similar functionality; such as Figure 5 As shown, the information acquisition device 50 includes:
[0106] The second sending module 51 is used to send first information to the first device, the first information being used to configure the mirror domain name;
[0107] The second receiving module 52 is used to receive the correspondence between the mirror domain name and at least one IP address and the TCP handshake information of each IP address sent by the first device; the at least one IP address is obtained by parsing the message of the mirror domain name;
[0108] Processing module 53 is used to obtain the TCP handshake information of at least one IP address corresponding to the mirror domain name based on the correspondence between the mirror domain name and at least one IP address and the TCP handshake information of each IP address.
[0109] Optionally, the first information is specifically used to configure multiple mirror domain names and the domain name index of each mirror domain name;
[0110] The second receiving module 52 is specifically used to: receive the correspondence between each of the mirror domain names and at least one IP address, as well as the TCP handshake information for each IP address, sent by the first device;
[0111] The processing module 53 is specifically used to: obtain the TCP handshake information of at least one IP address corresponding to each mirror domain name based on the correspondence between each mirror domain name and at least one IP address and the TCP handshake information of each IP address.
[0112] Optionally, the TCP handshake information includes at least one of the following:
[0113] The time offset of the first handshake;
[0114] The time delay between the first and second handshakes;
[0115] The time delay between the third handshake and the second handshake.
[0116] Optionally, the information collection device 50 may also include:
[0117] The third receiving module is used to receive Domain Name System (DNS) information sent by the first device;
[0118] The execution module is configured to perform at least one of the following based on the DNS information: determine the DNS resolution time, resolve the address of the DNS server, and determine the DNS resolution latency.
[0119] The information acquisition device 50 of this application embodiment can achieve the above-mentioned... Figure 3 The various processes of the method embodiments shown can achieve the same technical effect, and will not be described again here to avoid repetition.
[0120] Optional, such as Figure 6 As shown, this application embodiment also provides a communication device 60, including a processor 61, a memory 62, and a program or instructions stored in the memory 62 and executable on the processor 61. When the program or instructions are executed by the processor 61, they implement the above-mentioned... Figure 2 or Figure 3 The various processes of the method embodiments shown can achieve the same technical effect, and will not be described again here to avoid repetition.
[0121] This application also provides a computer program product, including computer instructions, which, when executed by a processor, can perform the above-described functions. Figure 2 or Figure 3 The various processes of the method embodiments shown can achieve the same technical effect, and will not be described again here to avoid repetition.
[0122] This application also provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they can implement the various processes of the above-described information acquisition method embodiments and achieve the same technical effects. To avoid repetition, they will not be described again here.
[0123] Computer-readable media include both permanent and non-permanent, removable and non-removable media, which can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0124] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0125] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0126] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a service classification device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0127] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. An information collection method, characterized in that, include: The first device receives first information, which is used to configure the mirror domain name; wherein, the first device receives the first information for configuring the mirror domain name from the second device through an application programming interface; The first device parses the message of the mirror domain name to obtain at least one Internet Protocol (IP) address corresponding to the mirror domain name; The first device analyzes the mirrored Transmission Control Protocol (TCP) packets for each IP address to obtain the TCP handshake information for each IP address; The first device sends the mapping relationship between the mirror domain name and the at least one IP address, as well as the TCP handshake information for each IP address, to the second device.
2. The method according to claim 1, characterized in that, Before analyzing the mirrored TCP packets for each of the IP addresses, the method further includes: The first device adds a timestamp to the TCP three-way handshake message of each IP address's mirror image; The first device analyzes the mirrored TCP packets for each IP address to obtain the TCP handshake information for each IP address, including: The first device analyzes the TCP three-way handshake messages after adding timestamps to obtain the TCP handshake information for each IP address.
3. The method according to claim 1 or 2, characterized in that, The TCP handshake information includes at least one of the following: The time offset of the first handshake; The time delay between the first and second handshakes; The time delay between the third handshake and the second handshake.
4. The method according to claim 1, characterized in that, The first information is specifically used to configure multiple mirror domain names and the domain name index of each mirror domain name; The first device parses the packets of the mirror domain name to obtain at least one Internet Protocol (IP) address corresponding to the mirror domain name, including: The first device parses the packets of each of the mirror domain names to obtain at least one IP address corresponding to each of the mirror domain names.
5. The method according to claim 1, characterized in that, The analysis of the mirrored TCP packets for each IP address to obtain the TCP handshake information for each IP address includes: The mirrored TCP packets for each IP address are analyzed, and the TCP handshake information obtained from the analysis is statistically analyzed using the index of each IP address to obtain the TCP handshake information for each IP address.
6. An information collection method, characterized in that, include: The second device sends first information to the first device, the first information being used to configure the mirror domain name; wherein, the first device receives the first information for configuring the mirror domain name from the second device through an application programming interface; The second device receives the mapping relationship between the mirror domain name and at least one IP address, as well as the TCP handshake information for each IP address, sent by the first device; wherein, the at least one IP address is obtained by parsing the packets of the mirror domain name; The second device obtains the TCP handshake information of at least one IP address corresponding to the mirror domain name based on the correspondence between the mirror domain name and at least one IP address and the TCP handshake information of each IP address.
7. The method according to claim 6, characterized in that, The first information is specifically used to configure multiple mirror domain names and the domain name index of each mirror domain name; The second device receives the mapping relationship between the mirror domain name and at least one IP address, as well as the TCP handshake information for each IP address, sent by the first device, including: The second device receives the correspondence between each of the mirror domain names and at least one IP address, as well as the TCP handshake information for each IP address, sent by the first device; The second device obtains the TCP handshake information of at least one IP address corresponding to the mirror domain name based on the correspondence between the mirror domain name and at least one IP address and the TCP handshake information of each IP address, including: The second device obtains the TCP handshake information of at least one IP address corresponding to each mirror domain name based on the correspondence between each mirror domain name and at least one IP address and the TCP handshake information of each IP address.
8. The method according to claim 6 or 7, characterized in that, The TCP handshake information includes at least one of the following: The time offset of the first handshake; The time delay between the first and second handshakes; The time delay between the third handshake and the second handshake.
9. The method according to claim 6, characterized in that, The method further includes: The second device receives Domain Name System (DNS) information sent by the first device; The second device performs at least one of the following actions based on the DNS information: determining the DNS resolution time, resolving the address of the DNS server, and determining the DNS resolution latency.
10. An information acquisition device, characterized in that, include: A first receiving module is configured to receive first information, which is used to configure a mirror domain name; wherein, the first device receives the first information for configuring the mirror domain name from the second device through an application programming interface. The parsing module is used to parse the packets of the mirror domain name and obtain at least one IP address corresponding to the mirror domain name; The analysis module is used to analyze the mirrored TCP packets of each IP address to obtain the TCP handshake information of each IP address; The first sending module is used to send the correspondence between the mirror domain name and the at least one IP address, as well as the TCP handshake information for each IP address, to the second device.
11. An information acquisition device, characterized in that, include: The second sending module is used to send first information to the first device, the first information being used to configure the mirror domain name; wherein, the first device receives the first information for configuring the mirror domain name from the second device through an application programming interface. The second receiving module is configured to receive the mapping relationship between the mirror domain name and at least one IP address, as well as the TCP handshake information for each IP address, sent by the first device; wherein the at least one IP address is obtained by parsing the message of the mirror domain name; The processing module is used to obtain the TCP handshake information of at least one IP address corresponding to the mirror domain name based on the correspondence between the mirror domain name and at least one IP address and the TCP handshake information of each IP address.
12. A communication device, characterized in that, It includes a processor, a memory, and a program or instructions stored in the memory and executable on the processor, wherein the program or instructions, when executed by the processor, implement the steps of the method as claimed in any one of claims 1 to 5, or the steps of the method as claimed in any one of claims 6 to 9.
13. A readable storage medium, characterized in that, The readable storage medium stores a program or instructions that, when executed by a processor, implement the steps of the method as described in any one of claims 1 to 5, or the steps of the method as described in any one of claims 6 to 9.
14. A computer program product, characterized in that, Includes computer instructions that, when executed by a processor, implement the steps of the method as claimed in any one of claims 1 to 5, or the steps of the method as claimed in any one of claims 6 to 9.
Citation Information
Patent Citations
Message processing method, device and equipment and computer readable storage medium
CN111404765A