Ip address processing method, system, device and storage medium thereof

By setting up a proxy module on the host machine to collect traffic data, automatically identifying and comparing IP addresses, the problem of difficulty in automatically detecting changes in IP addresses in existing technologies is solved, processing efficiency is improved, and the dynamic expansion needs of business-side systems are adapted.

CN118827623BActive Publication Date: 2025-11-18中国移动通信集团江西有限公司 +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410009427.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-01-03
Publication Date
2025-11-18
Estimated Expiration
2044-01-03

AI Technical Summary

Technical Problem

Existing technologies struggle to automatically detect IP address changes, resulting in low processing efficiency, especially since manual monitoring is required after business-side systems are expanded or scaled down.

Method used

Proxy modules are set up on each host machine of the business-side system. The proxy modules collect traffic data of application services, identify the current IP address of each functional layer, and compare it with the historical IP address in the real-time stream to automatically discover newly added or invalid IP addresses.

Benefits of technology

It enables automatic detection of IP address changes, improves processing efficiency, reduces manual intervention, and adapts to the dynamic changes of containerized deployment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827623B_ABST
    Figure CN118827623B_ABST
Patent Text Reader

Abstract

The application discloses an IP address processing method, system, device and storage medium thereof, and belongs to the technical field of networks. The IP address processing method is applied to an IP address processing system, and the IP address processing system comprises a proxy module. The method comprises the following steps: acquiring traffic data collected by the proxy module arranged on each host computer; identifying current IP addresses corresponding to different function layers of each application service according to each traffic data; comparing the current IP addresses corresponding to the different function layers of each application service with historical IP addresses in real-time flow, and determining new IP addresses according to a comparison result. The application solves the technical problem that a conventional scheme is difficult to automatically find IP address change conditions and IP address processing efficiency is relatively low.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the network technical field, and particularly relates to an IP address processing method, system, device and storage medium thereof. BACKGROUND

[0002] A traditional CRM (Customer Relationship Management) system is deployed on a physical machine or a virtual machine of a business side system, and then a customer perception detection system of an application side collects traffic data based on mirror of a switch, and obtains performance index data of the CRM service through decoding of a probe; meanwhile, an IP (Internet Protocol) address information obtained through prior research is used to configure a path diagram. However, when the business side system is expanded or contracted, the application side system is difficult to automatically find the IP address change, and manual monitoring of the IP address change is needed, which leads to low IP address processing efficiency.

[0003] The above content is only used to assist in understanding the technical solutions of the present application, and does not represent the acknowledgement of the above content as prior art. SUMMARY

[0004] The main purpose of the present application is to provide an IP address processing method, system, device and storage medium, which aims to solve the technical problem that the conventional scheme is difficult to automatically find the IP address change and the IP address processing efficiency is low.

[0005] To achieve the above purpose, the present application provides an IP address processing method, which comprises the following steps:

[0006] The IP address processing method is applied to an IP address processing system, and the IP address processing system comprises a proxy module, and the method comprises the following steps:

[0007] Traffic data collected by the proxy module arranged on each host is obtained;

[0008] According to each traffic data, current IP addresses corresponding to different function layers of each application service are identified;

[0009] The current IP addresses corresponding to different function layers of each application service are compared with historical IP addresses in real-time flow, and a new IP address is determined according to a comparison result.

[0010] Optionally, before the step of identifying the current IP addresses corresponding to different function layers of each application service according to each traffic data, the method further comprises the following steps:

[0011] Identify the target network protocol used by each of the traffic data, and determine the target data cleaning strategy that matches the target network protocol;

[0012] Based on the target data cleaning strategy, data cleaning is performed on each of the traffic data.

[0013] Optionally, the functional layer includes a reverse proxy layer, wherein the step of identifying the target network protocol used by each of the traffic data and determining a target data cleaning strategy matching the target network protocol includes:

[0014] If the target network protocol is a first network protocol, the target data cleaning strategy includes: performing source IP address conversion on traffic data with a source IP address of a first preset IP address, so that the source IP address is converted from the first preset IP address to the container IP address of the reverse proxy layer, wherein the first network protocol is the network protocol used by the reverse proxy layer.

[0015] Optionally, the functional layer includes an interface layer and a service layer, wherein the step of identifying the target network protocol used by each of the traffic data and determining a target data cleaning strategy matching the target network protocol includes:

[0016] If the target network protocol is a second network protocol, the target data cleaning strategy includes: filtering out traffic data whose source IP address is the host IP address of the interface layer, wherein the second network protocol is the network protocol used by the service layer.

[0017] Optionally, the step of identifying the current IP address corresponding to different functional layers of each application service based on the traffic data includes:

[0018] Based on the preset functional layer call chain and the target network protocol used by each traffic data, determine the target functional layer to which the target IP address of each traffic data belongs;

[0019] Each of the target IP addresses is determined to be the current IP address corresponding to its respective target functional layer.

[0020] Optionally, the functional layer call chain includes: the reverse proxy layer making data calls to the interface layer, and the step of determining the target functional layer to which the target IP address of each traffic data belongs based on the preset functional layer call chain and the target network protocol used by each traffic data includes:

[0021] If the target network protocol is the first network protocol, then the target functional layer to which the target IP address of the first data belongs is determined to be the interface layer, wherein the first data is traffic data with the source IP address being the container IP address of the reverse proxy layer, and the first network protocol is the network protocol used by the reverse proxy layer.

[0022] Optionally, the functional layer call chain includes: a service layer located at the end of the functional layer call chain, and the step of determining the target functional layer to which the target IP address of each traffic data belongs based on the preset functional layer call chain and the target network protocol used by each traffic data includes:

[0023] If the target network protocol is the second network protocol, then the target functional layer to which the target IP address of the traffic data belongs is determined as the service layer, wherein the second network protocol is the network protocol used by the service layer.

[0024] This application also provides an IP address processing system, which includes: a proxy module and a control terminal connected in communication;

[0025] The proxy module is used to collect traffic data generated by the host machine.

[0026] The control terminal is used to acquire traffic data collected by the proxy modules set on each host machine; identify the current IP address corresponding to each functional layer of each application service based on the traffic data; compare the current IP address corresponding to each functional layer of each application service with the historical IP address in the real-time stream, and determine the new IP address based on the comparison result.

[0027] This application also provides an electronic device, the electronic device comprising: a memory, a processor, and an IP address processing program stored on the memory and executable on the processor, the IP address processing program being configured to implement the steps of the above-described IP address processing method.

[0028] This application also provides a storage medium, which is a computer-readable storage medium, on which an IP address processing program is stored, and the IP address processing program is executed by a processor to implement the steps of the above-described IP address processing method.

[0029] This application discloses an IP address processing method applied to an IP address processing system, which includes: a proxy module; acquiring traffic data collected by proxy modules set on each host machine; identifying the current IP address corresponding to different functional layers of each application service based on the traffic data; comparing the current IP address corresponding to different functional layers of each application service with historical IP addresses in the real-time stream, and determining newly added IP addresses based on the comparison results, thereby achieving automatic IP address discovery. Since conventional traffic data is collected through switches, but after the business-side system is cloudified, the traffic data of application services no longer passes through switches, but is transmitted within the cluster of the business-side system; therefore, it is difficult to acquire the traffic data transmitted within the cluster of the business-side system, and thus it is impossible to automatically discover newly added IP addresses after the expansion of the business-side system, requiring manual monitoring of IP address changes. This application sets up proxy modules on each host machine of the business-side system, and then collects traffic data generated by each functional layer of the application service when the host machine provides the application service. Then, based on the comparison between the traffic data and the historical IP addresses stored in the real-time stream, it can automatically discover the new IP addresses generated by the expansion of the functional layer of the application service, realize the automatic discovery of IP address changes, and thus improve the processing efficiency of IP addresses. Attached Figure Description

[0030] Figure 1 This is a schematic diagram of the structure of an electronic device in the hardware operating environment involved in the embodiments of this application;

[0031] Figure 2 This is a flowchart illustrating the IP address processing method according to the first embodiment of this application;

[0032] Figure 3 This is a schematic diagram illustrating a scenario of the IP address processing method according to the first embodiment of this application;

[0033] Figure 4 This is a flowchart illustrating the IP address processing method according to the second embodiment of this application;

[0034] Figure 5 This is a schematic diagram of the IP address processing system involved in the embodiments of this application.

[0035] The realization of the purpose, functional features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0036] It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit this application.

[0037] Furthermore, the use of terms such as "first" and "second" in this application is for descriptive purposes only and should not be construed as indicating or implying their relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined with "first" or "second" may explicitly or implicitly include at least one of those features. Additionally, the term "and / or" throughout the text includes three solutions; taking A and / or B as an example, it includes technical solution A, technical solution B, and a technical solution that simultaneously satisfies A and B. Furthermore, the technical solutions of various embodiments can be combined with each other, but this must be based on the ability of a person skilled in the art to implement them. When the combination of technical solutions is contradictory or impossible to implement, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection claimed in this application.

[0038] Reference Figure 1 , Figure 1 This is a schematic diagram of the electronic device structure of the hardware operating environment involved in the embodiments of this application.

[0039] like Figure 1 As shown, the electronic device may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to enable communication between these components. The user interface 1003 may include a display screen or an input unit such as a keyboard; optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The memory 1005 may be a high-speed random access memory (RAM) or a stable non-volatile memory (NVM), such as a disk drive. The memory 1005 may also optionally be a storage device independent of the aforementioned processor 1001.

[0040] Those skilled in the art will understand that Figure 1 The structure shown does not constitute a limitation on the electronic device and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0041] like Figure 1 As shown, the memory 1005, which serves as a storage medium, may include an operating system, a data storage module, a network communication module, a user interface module, and an IP address processing program.

[0042] existFigure 1 In the illustrated electronic device, the network interface 1004 is mainly used for data communication with other devices; the user interface 1003 is mainly used for data interaction with the user; the processor 1001 and memory 1005 in the electronic device of this application can be disposed in the electronic device, and the electronic device calls the IP address processing program stored in the memory 1005 through the processor 1001 and performs the following operations:

[0043] The IP address processing method is applied to an IP address processing system, which includes a proxy module. The method includes the following operations:

[0044] Obtain traffic data collected by the proxy modules set up on each host machine;

[0045] Based on the traffic data, identify the current IP address corresponding to each functional layer of each application service;

[0046] The current IP address corresponding to each functional layer of the application service is compared with the historical IP address in the real-time stream, and the new IP address is determined based on the comparison result.

[0047] Furthermore, the processor 1001 can call the IP address processing program stored in the memory 1005 and also perform the following operations:

[0048] Before the operation of identifying the current IP address corresponding to each functional layer of each application service based on the traffic data, the method further includes:

[0049] Identify the target network protocol used by each of the traffic data, and determine the target data cleaning strategy that matches the target network protocol;

[0050] Based on the target data cleaning strategy, data cleaning is performed on each of the traffic data.

[0051] Furthermore, the functional layer includes a reverse proxy layer, wherein the operation of identifying the target network protocol used by each of the traffic data and determining a target data scrubbing strategy matching the target network protocol includes:

[0052] If the target network protocol is a first network protocol, the target data cleaning strategy includes: performing source IP address conversion on traffic data with a source IP address of a first preset IP address, so that the source IP address is converted from the first preset IP address to the container IP address of the reverse proxy layer, wherein the first network protocol is the network protocol used by the reverse proxy layer.

[0053] Furthermore, the functional layer includes an interface layer and a service layer, wherein the operation of identifying the target network protocol used by each of the traffic data and determining a target data cleaning strategy matching the target network protocol includes:

[0054] If the target network protocol is a second network protocol, the target data cleaning strategy includes: filtering out traffic data whose source IP address is the host IP address of the interface layer, wherein the second network protocol is the network protocol used by the service layer.

[0055] Furthermore, the operation of identifying the current IP address corresponding to different functional layers of each application service based on the traffic data includes:

[0056] Based on the preset functional layer call chain and the target network protocol used by each traffic data, determine the target functional layer to which the target IP address of each traffic data belongs;

[0057] Each of the target IP addresses is determined to be the current IP address corresponding to its respective target functional layer.

[0058] Furthermore, the functional layer call chain includes: the reverse proxy layer making data calls to the interface layer; the operation of determining the target functional layer to which the target IP address of each traffic data belongs based on the preset functional layer call chain and the target network protocol used by each traffic data includes:

[0059] If the target network protocol is the first network protocol, then the target functional layer to which the target IP address of the first data belongs is determined to be the interface layer, wherein the first data is traffic data with the source IP address being the container IP address of the reverse proxy layer, and the first network protocol is the network protocol used by the reverse proxy layer.

[0060] Furthermore, the functional layer call chain includes: a service layer located at the end of the functional layer call chain; the operation of determining the target functional layer to which the target IP address of each traffic data belongs based on the preset functional layer call chain and the target network protocol used by each traffic data includes:

[0061] If the target network protocol is the second network protocol, then the target functional layer to which the target IP address of the traffic data belongs is determined as the service layer, wherein the second network protocol is the network protocol used by the service layer.

[0062] Based on the above structure, various embodiments of the IP address processing method are proposed.

[0063] Reference Figure 2 , Figure 2 This is a flowchart illustrating the first embodiment of the IP address processing method of this application.

[0064] In this embodiment, the IP address processing method is applied to an IP address processing system. The executing entity of the IP address processing method can be an electronic device, which can be a control terminal in the IP address processing system. The control terminal can be a local device or a network device, and there is no limitation in this embodiment. For ease of description, the executing entity is omitted from the description of each embodiment below. In this embodiment, the IP address processing system includes: a proxy module, and the IP address processing method includes the following steps:

[0065] Step S10: Obtain traffic data collected by the proxy modules set on each host machine;

[0066] The IP address processing system can be a PaaS (Platform as a Service) platform system, which includes multiple servers (i.e., host machines) and provides application services over the network, belonging to a cloud computing service model. The IP address processing system monitors the traffic data generated when each host machine provides application services, and based on the functional layer call chain of the application service, reconstructs the actual call process from the monitored traffic data to identify the initiator and responder in each call. To improve the flexibility, scalability, and deployment efficiency of application services, at least some functional layers of each application service are containerized, i.e., containerized deployment of application services. However, containerized functional layers may dynamically expand and / or shrink, i.e., IP address drift, resulting in corresponding new and / or invalid IP addresses. Since conventional systems can only collect traffic data passing through switches, it is difficult to obtain traffic data transmitted within the cluster without passing through switches; furthermore, the IP addresses of each host machine and functional layer need to be manually recorded and pre-configured through a configuration module before data processing and database operations can be performed based on the configured IP addresses. Therefore, this conventional IP address handling method is difficult to automatically detect IP address changes, and thus is no longer suitable for containerized deployment application services with dynamically changing IP addresses.

[0067] Containerization refers to packaging an application and its dependencies into a separate runtime environment, which is called a container.

[0068] In one feasible embodiment, in order to monitor the IP address changes of different functional layers of the application service when each host provides application services, a proxy module is set up inside each host, and then the traffic data generated by each host when providing application services is collected through the proxy module.

[0069] The proxy module can be an agent, capable of compressing the collected traffic data before transmitting it to the control terminal. The host machine can be a virtual machine or a physical machine.

[0070] For example, refer to Figure 3 The proxy module (AG) is deployed on a host machine, which includes virtual machines and physical machines. The control terminal includes a probe application server and an analysis platform. The proxy module transmits the collected traffic data to the probe application server in the IP address processing system for packet parsing and analysis, and then further transmits it to the analysis platform for comprehensive analysis before front-end display.

[0071] Step S20: Based on the traffic data, identify the current IP address corresponding to each functional layer of each application service;

[0072] In one feasible embodiment, traffic data is collected through a proxy module, and then the traffic data is analyzed to identify the source IP address and destination IP address in the traffic data; and based on the functional layer call chain of the application service, the functional layer to which each source IP address and destination IP address belongs is analyzed, so that the current IP address corresponding to each functional layer of each application service can be identified.

[0073] The source IP address is the IP address of the data sender, while the destination IP address is the IP address of the data receiver.

[0074] The functional layers include: the UI layer, the API layer, the reverse proxy layer, and the service layer, which are different functional levels of the same application service. Among them, the UI layer is the web layer, which is the front-end interface layer; the API layer is the SOA layer, which is used to provide API services; the reverse proxy layer is the Nginx layer, which is used to distribute services within the container; and the service layer is the APP layer, which is used for the actual code implementation and provides backend services.

[0075] The functional layer call chain includes: UI layer load balancer → UI layer → API layer load balancer → reverse proxy layer → API layer → service layer → database. The arrows indicate the direction of service request transmission. The UI layer load balancer and API layer load balancer are used for load balancing within the UI and API layers, respectively. To improve application flexibility, scalability, and deployment efficiency, each host machine containers the reverse proxy layer, API layer, and service layer; therefore, a reverse proxy layer is added to distribute service requests from the API layer load balancer to the containers.

[0076] Step S30: Compare the current IP address corresponding to each functional layer of each application service with the historical IP address in the real-time stream, and determine the new IP address based on the comparison result.

[0077] In one feasible embodiment, after identifying the current IP address corresponding to each functional layer of each application service, the current IP address is compared with the historical IP address stored in the real-time stream; and the new IP address can be discovered through the comparison result, thus realizing automatic IP address discovery.

[0078] Optionally, upon discovering a new IP address, the real-time stream is updated based on the new IP address; the real-time stream includes real-time streams of different application services.

[0079] Optionally, the current IP address corresponding to each functional layer of each application service is compared with the historical IP address in the real-time stream, and the invalid IP address is determined according to the comparison result. The invalid IP address is the IP address whose corresponding business volume is less than a preset business volume threshold within a preset monitoring period; and then the invalid IP address is deleted from the real-time stream.

[0080] In this embodiment, traffic data collected by proxy modules set up on each host machine is acquired; then, based on the traffic data, the current IP address corresponding to each functional layer of each application service is identified; then, the current IP address corresponding to each functional layer of each application service is compared with the historical IP address in the real-time stream, and the newly added IP address is determined based on the comparison result, thus achieving automatic IP address discovery. Since conventional traffic data is collected through switches, after the business-side system is cloudified, the traffic data of application services no longer passes through switches but is transmitted within the cluster of the business-side system; therefore, it is difficult to acquire the traffic data transmitted within the cluster of the business-side system, and thus it is impossible to automatically discover the newly added IP addresses after the expansion of the business-side system, requiring manual monitoring of IP address changes. This application, by setting up proxy modules on each host machine of the business-side system, collects traffic data generated by each functional layer of the application service when the host machine provides the application service; then, based on the comparison between the traffic data and the historical IP addresses stored in the real-time stream, the newly added IP addresses resulting from the expansion of the functional layers of the application service can be automatically discovered, achieving automatic discovery of IP address changes, thereby improving IP address processing efficiency.

[0081] Furthermore, based on the first embodiment described above, a second embodiment of the IP address processing method of this application is proposed. In this embodiment, reference is made to... Figure 4 Before step S20, which identifies the current IP address corresponding to different functional layers of each application service based on the traffic data, the method further includes:

[0082] Step S11: Identify the target network protocol used by each of the traffic data, and determine the target data cleaning strategy that matches the target network protocol;

[0083] In one feasible embodiment, in order to improve the accuracy and efficiency of current IP address identification, the acquired traffic data can be pre-cleaned; then the network protocol used by each traffic data (hereinafter referred to as the target network protocol for distinction) can be identified; a data cleaning strategy can be matched based on the target network protocol to obtain a target data cleaning strategy; wherein, the data cleaning strategy includes: filtering duplicate data in the traffic data and selecting target data; and / or, mapping and converting the source IP address in the traffic data of the reverse proxy layer access interface layer.

[0084] In one feasible implementation, the functional layer includes: a reverse proxy layer. Step S11, identifying the target network protocol used by each of the traffic data and determining a target data scrubbing strategy matching the target network protocol, includes:

[0085] Step S111: If the target network protocol is a first network protocol, the target data cleaning strategy includes: performing source IP address conversion on traffic data with a source IP address of a first preset IP address, so that the source IP address is converted from the first preset IP address to the container IP address of the reverse proxy layer, wherein the first network protocol is the network protocol used by the reverse proxy layer.

[0086] In one feasible embodiment, since the network protocols used by each functional layer are different, the reverse proxy layer and the interface layer use the first network protocol; then if the target network protocol of the traffic data is the first network protocol, the data in the traffic data whose source IP address is the first preset IP address is further filtered out, and its source IP address is converted to the container IP address of the reverse proxy layer.

[0087] Because the reverse proxy layer automatically performs IP address translation when accessing the interface layer, converting the container IP address of the reverse proxy layer it uses to the first preset IP address; if the first preset IP address is used directly, the functional layer to which the IP address belongs may be incorrectly determined; therefore, based on the access characteristics of the reverse proxy layer, the source IP in the traffic data of the reverse proxy layer accessing the interface layer is mapped and translated to improve the accuracy of subsequent IP address processing.

[0088] The first network protocol can be HTTP (Hypertext Transfer Protocol); the first preset IP address can be the IP address of flannel.1, the host machine to which the reverse proxy layer belongs, or the IP address of docker0. Since the container IP address of the reverse proxy layer is the same as the IP address of its host machine, the first preset IP address can be converted to the IP address of the host machine to which the reverse proxy layer belongs.

[0089] It should be understood that after the application service containerizes the reverse proxy layer, interface layer, and service layer, the host machine IP address of the containerized functional layer may be inconsistent.

[0090] In one feasible implementation, the functional layer includes: an interface layer and a service layer. Step S11, identifying the target network protocol used by each of the traffic data and determining a target data cleaning strategy matching the target network protocol, includes:

[0091] Step S112: If the target network protocol is the second network protocol, the target data cleaning strategy includes: filtering out traffic data whose source IP address is the host IP address of the interface layer, wherein the second network protocol is the network protocol used by the service layer.

[0092] In one feasible embodiment, since the network protocols used by each functional layer are different, the service layer uses a second network protocol. When the interface layer accesses the service layer, two traffic data points are generated. The IP addresses contained in these two traffic data points are: interface layer container IP address - service layer host IP address, and interface layer host IP address - service layer container IP address, respectively. Therefore, when collecting interface layer traffic data, the IP addresses contained in the traffic data are: interface layer container IP address - service layer host IP address; and when collecting service layer traffic data, the IP addresses contained in the traffic data are: interface layer host IP address - service layer container IP address. IP address processing mainly requires detecting changes in the service layer container IP address. Therefore, if the target network protocol is the second network protocol, traffic data with the source IP address being the interface layer host IP address is filtered out, while traffic data with the target IP address being the service layer host IP address is filtered out. Subsequently, during IP address identification, the functional layer to which the IP address contained in the traffic data belongs can be determined based on the network protocol used, improving the efficiency of IP address processing.

[0093] Optionally, the second network protocol can be the Psocket protocol.

[0094] The host IP address is a fixed IP address and will not drift. Therefore, it can be identified by the host IP addresses of each functional layer that are stored in the real-time stream.

[0095] Step S12: Based on the target data cleaning strategy, perform data cleaning on each of the traffic data.

[0096] In one feasible embodiment, based on the matched target data cleaning strategy, targeted data cleaning is performed on the traffic data; thereby, step S20 is executed on the cleaned traffic data to identify the current IP address corresponding to each functional layer of each application service according to each traffic data.

[0097] In this embodiment, in order to improve the accuracy and efficiency of identifying the current IP address, the acquired traffic data is pre-cleaned; then, the target network protocol used by each traffic data is identified, and a target data cleaning strategy matching the target network protocol is determined; then, a targeted target data cleaning strategy is used to clean each traffic data, thereby improving the accuracy and efficiency of IP address processing.

[0098] Furthermore, based on the first and / or second embodiments described above, a third embodiment of the IP address processing method of this application is proposed. In this embodiment, step S20, which identifies the current IP address corresponding to different functional layers of each application service based on the traffic data, includes:

[0099] Step S21: Based on the preset functional layer call chain and the target network protocol used by each traffic data, determine the target functional layer to which the target IP address of each traffic data belongs;

[0100] In one feasible embodiment, based on the functional layer call chain of the application service, namely: UI layer load → UI layer → interface layer load → reverse proxy layer → interface layer → service layer → database, and the target network protocol used by each traffic data, the functional layer to which the target IP address in each traffic data belongs (hereinafter referred to as the target functional layer for distinction) is determined.

[0101] In one feasible implementation, the functional layer call chain includes: the reverse proxy layer making data calls to the interface layer; step S21, the step of determining the target functional layer to which the target IP address of each traffic data belongs based on the preset functional layer call chain and the target network protocol used by each traffic data includes:

[0102] Step S211: If the target network protocol is the first network protocol, then the target functional layer to which the target IP address of the first data belongs is determined to be the interface layer, wherein the first data is traffic data with the source IP address being the container IP address of the reverse proxy layer, and the first network protocol is the network protocol used by the reverse proxy layer.

[0103] In one feasible embodiment, the functional layer call chain includes: the reverse proxy layer making a data call to the interface layer, i.e.: reverse proxy layer → interface layer; and the network protocol used by the reverse proxy layer is the first network protocol; therefore, if the target network protocol used by the traffic data is the first network protocol, the target functional layer to which the target IP address of the traffic data (i.e., the first data) whose source IP address is the container IP address of the reverse proxy layer belongs is determined to be the interface layer.

[0104] In one feasible implementation, the functional layer call chain includes: the service layer is located at the end of the functional layer call chain; step S21, the step of determining the target functional layer to which the target IP address of each traffic data belongs based on the preset functional layer call chain and the target network protocol used by each traffic data includes:

[0105] Step S212: If the target network protocol is the second network protocol, then the target functional layer to which the target IP address of the traffic data belongs is determined as the service layer, wherein the second network protocol is the network protocol used by the service layer.

[0106] In one feasible embodiment, since the service layer is located at the end of the functional layer call chain and the network protocol used by the service layer is the second network protocol, the target functional layer to which the target IP address in the traffic data using the second network protocol belongs can be directly determined as the service layer.

[0107] Step S22: Determine the current IP address corresponding to the target functional layer to which each target IP address belongs.

[0108] In one feasible embodiment, after determining the target functional layer to which the target IP address of each traffic data belongs, the target IP address in each traffic data is identified as the current IP address corresponding to its target functional layer, thereby realizing the automatic discovery of the IP address used by each functional layer.

[0109] In this embodiment, based on the preset functional layer call chain and the target network protocol used by each traffic data, the target functional layer to which the target IP address of each traffic data belongs is determined; then each target IP address is determined as the current IP address corresponding to its target functional layer; thus realizing the automatic discovery of the IP address used by each functional layer.

[0110] Furthermore, embodiments of this application also provide an IP address processing system, referring to... Figure 5 The IP address processing system includes: a proxy module and a control terminal connected by communication;

[0111] The proxy module is used to collect traffic data generated by the host machine.

[0112] The control terminal is used to acquire traffic data collected by the proxy modules set on each host machine; identify the current IP address corresponding to each functional layer of each application service based on the traffic data; compare the current IP address corresponding to each functional layer of each application service with the historical IP address in the real-time stream, and determine the new IP address based on the comparison result.

[0113] Optionally, the control terminal is further configured to identify the target network protocol used by each of the traffic data, and determine a target data cleaning strategy that matches the target network protocol; and perform data cleaning on each of the traffic data based on the target data cleaning strategy.

[0114] Optionally, the control terminal is further configured to, if the target network protocol is a first network protocol, then the target data cleaning strategy includes: performing source IP address conversion on traffic data with a source IP address of a first preset IP address, so that the source IP address is converted from the first preset IP address to the container IP address of the reverse proxy layer, wherein the first network protocol is the network protocol used by the reverse proxy layer.

[0115] Optionally, the control terminal is further configured to, if the target network protocol is a second network protocol, then the target data cleaning strategy includes: filtering out traffic data whose source IP address is the host IP address of the interface layer, wherein the second network protocol is the network protocol used by the service layer.

[0116] Optionally, the control terminal is further configured to determine the target functional layer to which the target IP address of each traffic data belongs based on a preset functional layer call chain and the target network protocol used by each traffic data; and to determine each target IP address as the current IP address corresponding to its target functional layer.

[0117] Optionally, the control terminal is further configured to, if the target network protocol is a first network protocol, determine the target functional layer to which the target IP address of the first data belongs as an interface layer, wherein the first data is traffic data with the source IP address being the container IP address of the reverse proxy layer, and the first network protocol is the network protocol used by the reverse proxy layer.

[0118] Optionally, the control terminal is further configured to, if the target network protocol is a second network protocol, determine the target functional layer to which the target IP address of the traffic data belongs as a service layer, wherein the second network protocol is the network protocol used by the service layer.

[0119] The specific implementation of the IP address processing system in this application is basically the same as the embodiments of the above-described IP address processing methods, and will not be repeated here.

[0120] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.

[0121] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0122] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.

Claims

1. A method for processing IP addresses, characterized in that, The IP address processing method is applied to an IP address processing system, which includes a proxy module. The method includes the following steps: Obtain traffic data collected by the proxy modules set up on each host machine; Based on the preset functional layer call chain and the target network protocol used by each traffic data, determine the target functional layer to which the target IP address of each traffic data belongs; Each of the target IP addresses is determined to be the current IP address corresponding to its target functional layer, so as to identify the current IP address corresponding to each functional layer of each application service. The current IP address corresponding to each functional layer of the application service is compared with the historical IP address in the real-time stream, and the new IP address is determined based on the comparison result.

2. The IP address processing method as described in claim 1, characterized in that, Before the step of determining the target functional layer to which the target IP address of each traffic data belongs based on a preset functional layer call chain and the target network protocol used by each traffic data, the method further includes: Identify the target network protocol used by each of the traffic data, and determine the target data cleaning strategy that matches the target network protocol; Based on the target data cleaning strategy, data cleaning is performed on each of the traffic data.

3. The IP address processing method as described in claim 2, characterized in that, The functional layer includes a reverse proxy layer. The step of identifying the target network protocol used by each of the traffic data and determining a target data cleaning strategy that matches the target network protocol includes: If the target network protocol is a first network protocol, the target data cleaning strategy includes: performing source IP address conversion on traffic data with a source IP address of a first preset IP address, so that the source IP address is converted from the first preset IP address to the container IP address of the reverse proxy layer, wherein the first network protocol is the network protocol used by the reverse proxy layer.

4. The IP address processing method as described in claim 2, characterized in that, The functional layer includes an interface layer and a service layer. The step of identifying the target network protocol used by each of the traffic data and determining a target data cleaning strategy that matches the target network protocol includes: If the target network protocol is a second network protocol, the target data cleaning strategy includes: filtering out traffic data whose source IP address is the host IP address of the interface layer, wherein the second network protocol is the network protocol used by the service layer.

5. The IP address processing method as described in claim 1, characterized in that, The functional layer call chain includes: the reverse proxy layer making data calls to the interface layer. The step of determining the target functional layer to which the target IP address of each traffic data belongs based on the preset functional layer call chain and the target network protocol used by each traffic data includes: If the target network protocol is the first network protocol, then the target functional layer to which the target IP address of the first data belongs is determined to be the interface layer, wherein the first data is traffic data with the source IP address being the container IP address of the reverse proxy layer, and the first network protocol is the network protocol used by the reverse proxy layer.

6. The IP address processing method as described in claim 1, characterized in that, The functional layer call chain includes: a service layer located at the end of the functional layer call chain; the step of determining the target functional layer to which the target IP address of each traffic data belongs based on the preset functional layer call chain and the target network protocol used by each traffic data includes: If the target network protocol is the second network protocol, then the target functional layer to which the target IP address of the traffic data belongs is determined as the service layer, wherein the second network protocol is the network protocol used by the service layer.

7. An IP address processing system, characterized in that, The IP address processing system includes: a proxy module and a control terminal with communication connections; The proxy module is used to collect traffic data generated by the host machine. The control terminal is used to acquire traffic data collected by the proxy modules set on each host machine; based on the preset functional layer call chain and the target network protocol used by each traffic data, determine the target functional layer to which the target IP address of each traffic data belongs; determine the current IP address corresponding to the target functional layer to which each target IP address belongs, so as to identify the current IP address corresponding to each functional layer of each application service; compare the current IP address corresponding to each functional layer of each application service with the historical IP address in the real-time stream, and determine the new IP address based on the comparison result.

8. An electronic device, characterized in that, The device includes: a memory, a processor, and an IP address processing program stored in the memory and executable on the processor, the IP address processing program being configured to implement the steps of the IP address processing method as described in any one of claims 1 to 6.

9. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and the storage medium stores an IP address processing program. When the IP address processing program is executed by a processor, it implements the steps of the IP address processing method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Network equipment discovery method and device, electronic equipment and storage medium

    CN115242595A

  • Cloud platform and cloud platform service calling method

    CN116033000A