A high-performance flow collector based on XDP

By using an XDP-based traffic collector, combined with a user-space management module and a kernel EBPF module, dynamically compiling tcpdump filter statements and processing data packets in the network card driver, the contradiction between performance and versatility in traffic sampling technology is resolved, achieving high-performance, easy-to-use, and highly compatible traffic sampling.

CN118869261BActive Publication Date: 2026-01-09CHINA TELECOM CLOUD TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410854160.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-28
Publication Date
2026-01-09
Estimated Expiration
2044-06-28

AI Technical Summary

Technical Problem

Existing traffic sampling technologies struggle to balance performance and versatility. The libpcap-based approach is prone to performance bottlenecks and high system loads in high-traffic scenarios, while the DPDK-based approach suffers from poor versatility and complex deployment, requiring dedicated network cards and incurring high learning costs.

Method used

It adopts a high-performance traffic collector based on XDP, combined with a user-space management module and a kernel EBPF module. It generates EBPF programs by dynamically compiling tcpdump filter statements and directly processes data packets in the network card driver, avoiding the kernel protocol stack. It supports tcpdump filtering syntax and has the high performance of DPDK.

Benefits of technology

It achieves high-performance sampling in high-traffic scenarios, combining versatility and ease of use. It supports tcpdump filtering syntax, requires no dedicated network card, has fine-grained configuration and high controllability, and its performance far exceeds that of tcpdump, with strong compatibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118869261B_ABST
    Figure CN118869261B_ABST
Patent Text Reader

Abstract

The application relates to an XDP-based high-performance flow collector, and belongs to the network technology and security field.The collector comprises a user state management module and a kernel EBPF module, wherein a sampling management program is arranged on the user state management module, the sampling management program is used for dynamically compiling an input tcpdump capture filter statement, generating an EBPF program, and then sending the EBPF program to the kernel EBPF module; a high-performance data path XDP program is arranged on the kernel EBPF module, the kernel EBPF module is used for receiving the EBPF program from the user state management module, and mounting the EBPF program on the XDP program. The collector provided by the application has the consistent capture filter syntax of tcpdump and the high-performance general flow sampling program of DPDK, and solves the problem that the performance and the general performance cannot be compatible.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the field of network technology and security, and particularly relates to a high-performance traffic collector based on XDP. BACKGROUND

[0002] With the popularity of the Internet and the development of applications, network traffic is growing rapidly, and network security problems are becoming increasingly prominent. Sampling and analyzing the traffic transmitted in the network can detect and respond to security events such as network attacks, intrusion behaviors, malicious codes in a timely manner, reduce potential risks, and protect the integrity, availability and confidentiality of the network.

[0003] Currently, there are two kinds of mainstream traffic packet sampling tools:

[0004] (1) libpcap-based sampling tools such as tcpdump: simple syntax, powerful functions, supports rich filters, strong universality, suitable for all Linux distributions, but relatively weak performance, not suitable for large traffic scenarios.

[0005] (2) DPDK-based sampling tools: high performance and low latency, bypassing the kernel protocol stack, very high throughput, but very complex to use, high deployment and learning cost, poor universality, and needs specific intel network cards to work, and cannot coexist with kernel firewall modules, which is prone to conflict.

[0006] The existing sampling technology has the problem that performance and universality cannot be compatible. The biggest problem of using libpcap-based sampling is performance bottleneck. Long-term continuous sampling can easily interfere with normal business, and the sampling rate and maximum sampling rate cannot be directly set. In large traffic scenarios, sampling will directly increase the system load and cause packet loss. Using DPDK to collect traffic can obtain high performance and low latency, but the biggest problem is poor universality, which requires special intel network cards, high learning threshold, special development and debugging skills for fine-tuning, and high maintenance cost. SUMMARY

[0007] In view of the above shortcomings of the prior art, the purpose of the application is to provide a high-performance traffic collector based on XDP, which can provide consistent capture filter syntax with tcpdump and has a DPDK high-performance universal traffic sampler solution, solving the problem that performance and universality cannot be compatible.

[0008] The application provides a high-performance traffic collector based on XDP, which comprises a user state management module and a kernel EBPF module, wherein,

[0009] The user state management module is located in the user space, and a sampling management program is deployed on the user state management module, the sampling management program is used for dynamically compiling an input tcpdump capture filter statement, generating an EBPF program, and then sending the EBPF program to the kernel EBPF module;

[0010] The kernel EBPF module is located in the kernel space, and a high-performance data path XDP program is deployed on the kernel EBPF module, the kernel EBPF module is used for receiving the EBPF program from the user state management module, and mounting the EBPF program to an XDP program, the XDP program directly sends a data packet to the sampling management program through a ring buffer, without passing through a kernel protocol stack.

[0011] Further, the sampling management program loads and parses a configuration file after starting, compiles a filter field of the configuration file into EBPF bytecode, inserts the EBPF bytecode into a pre-developed EBPF template, and compiles the EBPF template into an obj file, loads the compiled obj file to a network card driver XDP mounting point, writes ratio and max_rate in the configuration file to an EBPF-MAP data structure, and the XDP program reads the EBPF-MAP data structure to sample according to the ratio and the maximum rate, and the sampling management program obtains the sampled data from a ring buffer and provides the data for subsequent analysis.

[0012] Further, the configuration file includes:

[0013] The nic file is used for describing sampling on the network card.

[0014] The ratio file is used for describing the sampling ratio.

[0015] The max_rate file is used for describing the maximum sampling rate.

[0016] The filter file is used for describing the data packet of interest.

[0017] Further, the sampling management program loads the compiled obj file to the XDP mounting point of the network card specified by the nic field of the configuration file.

[0018] Further, the compiling of the filter field of the configuration file into EBPF bytecode and the inserting of the EBPF bytecode into the pre-developed EBPF template include:

[0019] When the tcpdump filter statement of the filter field is compiled into an EBPF instruction, it is first compiled into a CBPF instruction, and then the CBPF instruction is converted into an EBPF program, and the compiled EBPF program is loaded into the kernel

[0020] Further, the EBPF template is developed, including: the EBPF template program is responsible for packet filtering according to the configured ratio and max_rate, and then jumps to the EBPF program compiled by the filter through the bpf_tail_call instruction, and hits the ring buffer first. The management process sends data.

[0021] Further, the sampling management program performs real-time security analysis or serialization of the collected data packet after analyzing the sampled data obtained from the ring buffer.

[0022] Further, the user state management module is further configured with a business program, wherein the sk_buff data is allocated after the data packet enters the protocol stack, and is used to maintain the socket buffer state and description information, and is sent to the business program by the protocol stack through the socket.

[0023] Further, the XDP-based high-performance traffic collector is deployed on the load balancer at the traffic entrance to collect all the traffic arriving at the load balancer, including all the data packets constructed by the scanner.

[0024] Further, the XDP-based high-performance traffic collector is deployed on each server to collect the traffic arriving at each server.

[0025] The present application has the following advantages:

[0026] The XDP-based high-performance traffic collector has the following advantages:

[0027] 1. High performance: The performance is much higher than that of tcpdump and is more suitable for large flow sampling scenarios. The main reason for high performance is that the XDP program can be called in the network card driver and can not pass through the kernel protocol stack, and the sampled data has a shorter path in the kernel.

[0028] 2. High universality: completely supports the capture filter syntax of tcpdump, without additional learning cost. The capture filter syntax is completely consistent with tcpdump, without additional learning cost similar to DPDK. The main reason for supporting the tcpdump filter syntax is that the parsed CBPF program can be easily converted into an EBPF program.

[0029] 3. Fine configuration: configure the sampling ratio and maximum sampling rate through the configuration file, and the EBPF program can obtain the configuration from the user mode through EBPF-MAP, and the existing tcpdump only supports full collection of traffic passing through the filter.

[0030] 4. Strong compatibility: no need to adapt to the dedicated intel network card like DPDK, XDP supports from linux4.8.

[0031] 5. Strong controllability: the EBPF program of XDP can realize more fine matching when filtering traffic. BRIEF DESCRIPTION OF DRAWINGS

[0032] The accompanying drawings are included to provide a further understanding of the application and are incorporated in and constitute a part of this specification, illustrate embodiments of the application and together with the description serve to explain the principles of the application. In the drawings:

[0033] Figure 1 A structure diagram of a high-performance flow collector based on XDP according to an embodiment of the application;

[0034] Figure 2 An XDP flow capture architecture diagram according to an embodiment of the application;

[0035] Figure 3 A sampling management program processing flowchart according to an embodiment of the application;

[0036] Figure 4 A flowchart of the deployment of the sampling management program according to an embodiment of the application. DETAILED DESCRIPTION

[0037] In order to enable those skilled in the art to better understand the technical solutions in the embodiments of the application, the technical solutions of the application will be described clearly and completely below with reference to the drawings. Obviously, the described embodiments are only some of the embodiments of the application, rather than all the embodiments. It should be understood that these descriptions are only exemplary, and are not intended to limit the scope of the application. Based on the embodiments of the application, all other embodiments obtained by those skilled in the art without creative labor should fall within the scope of protection of the application.

[0038] In addition, in the following description, the description of well-known structures and techniques is omitted to avoid unnecessary confusion of the concepts disclosed in the application.

[0039] In the description of the present application, it should be noted that, unless otherwise explicitly specified and limited, the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the devices or elements referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the present application. In addition, the terms "first", "second", "third" are only for descriptive purposes and cannot be understood as indicating or implying relative importance. The terms "mounting", "connection", "connection" should be broadly understood, for example, it can be fixed connection, or detachable connection, or integral connection; it can be mechanical connection, or electrical connection; it can be directly connected, or indirectly connected through an intermediate medium, or the internal communication of two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.

[0040] The exemplary embodiments will be described in detail herein, with examples shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application. Rather, they are merely examples of methods and systems consistent with some aspects of the present application as detailed in the appended claims.

[0041] The technical terms related to the present application are described as follows:

[0042] CBPF(Classic Berkeley Packet Filter) is a simple and effective packet filtering language and execution engine based on instruction set.

[0043] EBPF(Extended Berkeley Packet Filter, Extended Berkeley Packet Filter): It is a powerful virtual machine technology in the Linux kernel, which provides a set of safe runtime constraints and verification mechanisms, while extending the functionality of the kernel and ensuring the stability of the system.

[0044] XDP(eXpress Data Path, high-performance data path): a high-performance packet processing technology, which is a subsystem in the Linux kernel, used for raw packet processing on the hardware interface of network devices.

[0045] Libpcap(Packet Capture Library): a library for network packet capture and analysis;

[0046] DPDK (Data Plane Development Kit): an open-source software development kit for building high-performance data plane applications.

[0047] EBPF-MAP (extended Berkeley Packet Filter) Map is a data structure used to store and share data within eBPF programs. It is similar to a dictionary or hash table in regular programming languages, allowing key-value pairs to be associated for reading and modifying in different parts of eBPF programs.

[0048] The present application provides a high-performance flow collector based on XDP, which provides consistent capture filter syntax with tcpdump and has a DPDK high-performance general flow sampler solution, solving the problem that performance and universality cannot be achieved simultaneously.

[0049] As shown in Figure 1 , the high-performance flow collector based on XDP of the embodiment of the present application comprises: a user state management module 100 and a kernel EBPF module 200.

[0050] As shown in Figure 2 , the user state management module 100 is located in the user space, and a sampling management program is deployed on the user state management module 100. The kernel EBPF module 200 is located in the kernel space, and a high-performance data path XDP program is deployed on the kernel EBPF module 200. The XDP program can send the data packets of interest directly to the sampling management program through the ring buffer without passing through the kernel protocol stack, thus providing very excellent performance. At the same time, since linux 4.8 and above versions support XDP, the present application is more universal than DPDK.

[0051] Specifically, the sampling management program is used to dynamically compile the input tcpdump capture filter statement and generate an EBPF program, and then send the EBPF program to the kernel EBPF module.

[0052] As shown in Figure 3 , first, the sampling management program loads and parses the configuration file after starting.

[0053] In the embodiment of the present application, the configuration file comprises:

[0054] nic file: used to describe sampling on that network card;

[0055] ratio file: used to describe the sampling ratio;

[0056] max_rate file: used to describe the maximum sampling rate;

[0057] filter file: used to describe the data packets of interest.

[0058] The present application adopts the same syntax as tcpdump, so it is basically the same as tcpdump in use, and is easy to use.

[0059] Then, the sampling management program compiles the filter field of the configuration file into EBPF bytecode and inserts it into the pre-developed EBPF template and compiles it into an obj file together, and then loads the compiled obj file onto the XDP mounting point of the network card driver, and then writes the ratio and max_rate in the configuration file to the EBPF-MAP data structure.

[0060] The kernel EBPF module receives the EBPF program from the user state management module and mounts the EBPF program on the XDP program, and the XDP program sends the data packet directly to the sampling management program through the ring buffer, without going through the kernel protocol stack.

[0061] Specifically, the XDP program samples by reading the EBPF-MAP data structure according to the ratio and the maximum rate, and the sampling management program obtains the sampled data from the ring buffer and provides it for subsequent analysis.

[0062] In an embodiment of the present application, the sampling management program loads the compiled obj file onto the XDP mounting point of the network card specified by the nic field of the configuration file.

[0063] In an embodiment of the present application, the filter field of the configuration file is compiled into EBPF bytecode and inserted into the pre-developed EBPF template, which includes:

[0064] When compiling the tcpdump filter statement of the filter field into EBPF instructions, first compile it into CBPF instructions, and then convert the CBPF instructions into EBPF programs, and load the compiled EBPF programs into the kernel.

[0065] In an embodiment of the present application, the EBPF template is developed, including: the EBPF template program is responsible for filtering data packets according to the configured ratio and max_rate, and then jumps to the EBPF program compiled by the filter through the bpf_tail_call instruction, and hits the ring buffer first. The management process sends data. Here, when the received number of packets hits the user-configured tcpdump syntax filter, the EBPF program sends the data packet from the kernel to the user state management program through the ring buffer.

[0066] The sampling management program performs real-time security analysis or serialization of the collected data packet after analyzing the sampled data obtained from the ring buffer.

[0067] In addition, referring to Figure 2 , a data packet is described using a data structure sk_buff in the linux kernel. The user state management module is further configured with a service program, and the skb_buff is allocated as soon as the data packet enters the protocol stack, and the skb_buff is used for processing in the entire protocol stack path. The skb_buff is used to maintain the socket buffer state and description information, and the payload of the sk_buff is finally sent to the service program by the protocol stack through the socket.

[0068] Referring to Figure 2 , the data packet first enters the XDP program, performs the work of the XDP program, and then the data packet enters the protocol stack. The skb_buff is allocated as soon as the data packet enters the protocol stack, and the skb_buff is used for processing in the entire protocol stack path.

[0069] As shown in Figure 4 , the high-performance traffic collector based on XDP provided by the application can be deployed on a load balancer at a traffic entrance or on each server.

[0070] (1) The high-performance traffic collector based on XDP provided by the application is deployed on a load balancer at a traffic entrance to collect all traffic arriving at the load balancer, including all data packets constructed by scanners.

[0071] (2) The high-performance traffic collector based on XDP provided by the application is deployed on each server to collect traffic arriving at each server.

[0072] The high-performance traffic collector based on XDP provided by the application can provide consistent capture filter syntax with tcpdump while having the performance of DPDK general traffic sampler solution, solving the problem that performance and generality cannot be compatible. The application mainly consists of a user state management program and a kernel EBPF program. The user state management program dynamically compiles the input tcpdump capture filter statement and generates an EBPF program, and then mounts the EBPF program to XDP. Since the XDP program can be executed by the network card driver and does not pass through the kernel protocol stack, it has the performance of DPDK. In addition, the EBPF program can provide more detailed configurations than tcpdump, such as dynamically adjusting the sampling rate and sampling rate.

[0073] The high-performance traffic collector based on XDP provided by the application has the following beneficial effects:

[0074] 1. High performance: Performance far exceeds tcpdump more suitable for large flow scene sampling. The main reason for high performance is that the XDP program can be called in the network card driver and can not pass through the kernel protocol stack, and the sampled data has a shorter path in the kernel.

[0075] 2. High universality: Fully support the capture filter syntax of tcpdump, no additional learning cost. The capture filter syntax is completely consistent with tcpdump, and there is no additional learning cost similar to DPDK. The main reason for supporting the tcpdump filter syntax is that the parsed CBPF program can be easily converted to EBPF program.

[0076] 3. Fine configuration: Set the sampling ratio and maximum sampling rate through the configuration file, mainly through EBPF program can get configuration from user space through EBPF-MAP, and the existing tcpdump only supports full-quantity collection of traffic through the filter.

[0077] 4. Strong compatibility: No need to adapt to special intel network card like DPDK, XDP is supported natively from linux4.8.

[0078] 5. Strong controllability: EBPF program of XDP can realize more fine matching when filtering traffic.

[0079] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the embodiments of the present application, and not to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application. Any changes or replacements that can be easily thought of by those skilled in the art within the technical scope disclosed by the present application should be covered within the protection scope of the present application.

Claims

1. An XDP-based high-performance flow collector, characterized in that, The application relates to a user state management module and a kernel EBPF module, wherein, The user state management module is located in a user space, a sampling management program is deployed on the user state management module, the sampling management program is used for dynamically compiling an input tcpdump capture filter statement and generating an EBPF program, and then the EBPF program is sent to the kernel EBPF module. The kernel EBPF module is located in a kernel space, a high-performance data path XDP program is deployed on the kernel EBPF module, the kernel EBPF module is used for receiving the EBPF program from the user state management module, and the EBPF program is mounted on an XDP program, the XDP program directly sends a data packet to the sampling management program through a ring buffer, and does not pass through a kernel protocol stack. After the sampling management program is started, a configuration file is loaded, a filter field of the configuration file is compiled into EBPF bytecode and is inserted into a pre-developed EBPF template and is compiled into an obj file, the compiled obj file is loaded onto a network card driver XDP mounting point, ratio and max_rate in the configuration file are written into an EBPF-MAP data structure, the XDP program reads the EBPF-MAP data structure to sample according to the ratio and the maximum rate, and the sampling management program obtains the sampled data from a ring buffer and provides subsequent analysis.

2. The high-performance flow collector based on XDP according to claim 1, wherein, The configuration file comprises:

3. The high-performance flow collector based on XDP according to claim 2, wherein, A nic file used for describing sampling on a network card; A ratio file used for describing a sampling ratio; A max_rate file used for describing a maximum sampling rate; And a filter file used for describing a data packet of interest. The sampling management program loads the compiled obj file onto the XDP mounting point of the network card specified by the nic field of the configuration file.

4. The high-performance flow collector based on XDP according to claim 2, wherein, The filter field of the configuration file is compiled into EBPF bytecode and is inserted into a pre-developed EBPF template, and the process comprises the following steps:

5. The high performance flow collector based on XDP according to claim 2, characterized in that, When the tcpdump filter statement of the filter field is compiled into EBPF instructions, the tcpdump filter statement is first compiled into CBPF instructions, then the CBPF instructions are converted into an EBPF program, and the compiled EBPF program is loaded into a kernel. The EBPF template is developed, and the process comprises the following steps: the EBPF template program is responsible for packet filtering according to the configured ratio and max_rate, then the EBPF program compiled from the filter is jumped to through a bpf_tail_call instruction, and the hit is sent to a data management process through a ring buffer.

6. The high-performance flow collector based on XDP according to claim 2 or 5, characterized in that, After the sampling management program obtains the sampled data from the ring buffer and analyzes the sampled data, the sampling management program performs real-time security analysis or serialization on the collected data packets.

7. The high performance flow collector based on XDP according to claim 2, characterized in that, ​ 8. The high performance flow collector based on XDP according to claim 1, wherein, The user mode management module is further configured with a service program, wherein, after the data packet enters the protocol stack, the sk_buff data is allocated for maintaining the socket buffer state and description information, and the payload of the sk_buff is finally sent to the service program by the protocol stack through the socket.

9. The high performance flow collector based on XDP according to claim 1, wherein, The XDP-based high-performance traffic collector is deployed on a load balancer at a traffic entrance to collect all the traffic arriving at the load balancer, including all the packets constructed by scanners.

10. The high performance flow collector based on XDP according to claim 1, wherein, The XDP-based high-performance traffic collector is deployed on each server to collect the traffic arriving at each server.

Citation Information

Patent Citations

  • Flow collection method and device based on eBPF

    CN114006839A

  • EBPF-based network high-speed forwarding relay method and system

    CN116886422A