A blacklist-based traffic message forwarding method, device, and network equipment

By introducing a hash array into the network device to determine the update of the IP address blacklist, the performance consumption problem caused by dynamic IP addresses in the network protection drill scenario is solved, and efficient traffic processing is achieved.

CN118869318BActive Publication Date: 2025-09-02WUHAN SIPU TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411060642.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-05
Publication Date
2025-09-02
Estimated Expiration
2044-08-05

AI Technical Summary

Technical Problem

In the protection network drill scenario, when the protective equipment faces a dynamically changing IP address blacklist, the existing fast transfer mode may cause the malicious IP address to be unable to immediately block, and matching the blacklist by packet will lead to excessive performance consumption, making it difficult to effectively process traffic in large traffic scenarios.

Method used

Introduce a hash array to represent whether the IP address is updated with the blacklist, and determine whether it is forwarded directly or blacklist matching is performed through the hash value, avoid packet-by-packet matching and improve device resource utilization efficiency.

Benefits of technology

With fixed equipment resources, the traffic processing performance of network equipment is significantly improved, the equipment quantity demands are reduced, and the cost is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118869318B_ABST
    Figure CN118869318B_ABST
Patent Text Reader

Abstract

The present application provides a blacklist-based traffic message forwarding method, apparatus, and network device, which are used to introduce a hash array between traffic messages and IP address blacklists to represent whether a specific IP address has been updated as the IP address blacklist is updated. In this way, in fast-forward mode, it can accurately provide a basis for judging whether to directly forward or initiate an IP address blacklist match. In this way, when faced with a dynamically updated IP address blacklist in a network protection drill scenario, when the device resources are relatively fixed, there is no need to increase the number of devices as in the prior art, and the traffic processing performance of the network device can be significantly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication networks, and specifically to a blacklist-based traffic message forwarding method, apparatus, and network equipment. Background Art

[0002] With the rapid development of network technology, security attacks and threats are increasing. With the increasing emphasis on network security, organizations at all levels conduct network protection drills annually. In this context, the processing performance of protective equipment determines whether it can quickly and effectively block network attacks. In network protection drills, protective equipment primarily blocks malicious IP addresses issued by higher-level organizations (threat intelligence and situational awareness centers). These malicious IP addresses (i.e., IP address blacklists) are very large, and current mainstream manufacturers' protective equipment specifications are in the tens of millions.

[0003] Mainstream network security devices generally forward traffic in two modes: slow forwarding and fast forwarding. Slow forwarding follows the forwarding process, matching rules, policies, and searching for routes. Fast forwarding allows for session-based forwarding of packets with the same five-tuple, after the previous packets have already undergone slow forwarding and established a session. This means that packets with the same five-tuple have already matched the relevant policy and have been marked in the session. Subsequent packets are forwarded directly based on the session marking, bypassing the rule and policy matching process. This significantly improves the device's forwarding capabilities.

[0004] However, network protection drills are unique. Unlike the typical practice of IP address attributes, which generally remain static, the IP address blacklist issued in real-world scenarios changes dynamically based on attack and defense drill requirements. This means that the malicious nature of an IP address is dynamically adjusted based on the drill's needs. Therefore, if fast-forward mode and session-based forwarding are used, a situation may arise where an IP address that was not previously on the blacklist, a long link, has already matched the blacklist, and is subsequently forwarded directly based on the session. Therefore, if this IP address is subsequently added to the blacklist, it will not be immediately blocked. Furthermore, because the IP address blacklist matching mechanism operates on a packet-by-packet basis (both fast-forward and slow-forward modes can involve blacklist matching), packet-by-packet matching ensures that the blacklist takes effect quickly. However, this approach incurs significant performance overhead, as every packet must be matched, resulting in lower traffic processing performance. In high-traffic scenarios, the only solution is to add more devices, which is a temporary solution and increases equipment procurement, deployment, and maintenance costs. Summary of the Invention

[0005] The present application provides a blacklist-based traffic message forwarding method, apparatus, and network device, which are used to introduce a hash array between traffic messages and IP address blacklists to represent whether a specific IP address has been updated as the IP address blacklist is updated. In this way, in fast-forward mode, it can accurately provide a basis for judging whether to directly forward or initiate an IP address blacklist match. In this way, when faced with a dynamically updated IP address blacklist in a network protection drill scenario, when the device resources are relatively fixed, there is no need to increase the number of devices as in the prior art, and the traffic processing performance of the network device can be significantly improved.

[0006] In a first aspect, the present application provides a blacklist-based traffic message forwarding method, the method comprising:

[0007] The network device obtains the traffic packets to be forwarded in the network architecture;

[0008] The network device determines whether a corresponding historical session has been created for the traffic message to be forwarded based on the five-tuple information of the traffic message to be forwarded;

[0009] If a corresponding historical session has been created, the fast-forward mode is entered. The network device locates the corresponding two hash nodes in the hash array based on the key values ​​of the source IP address and the destination IP address pre-written in the session structure of the historical session, and extracts the two stored hash values ​​from the two hash nodes. The hash array pre-stores corresponding hash values ​​in different hash nodes corresponding to the key values ​​of different IP addresses. The hash value is used to identify whether the IP address corresponding to the key value has been updated as the IP address blacklist is updated through the change of the value.

[0010] The network device determines whether the two hash values ​​are the historical hash values ​​stored in the hash array of the key value of the source IP address and the historical hash values ​​stored in the hash array of the key value of the destination IP address that are pre-written in the session structure;

[0011] If the two hash values ​​are the historical hash value of the source IP address key value stored in the hash array and the historical hash value of the destination IP address key value stored in the hash array pre-written in the session structure, the network device forwards the traffic message to be forwarded.

[0012] In a second aspect, the present application provides a blacklist-based traffic message forwarding device, the device comprising:

[0013] An acquisition unit, configured to acquire traffic packets to be forwarded in the network architecture;

[0014] A judgment unit, configured to judge whether a corresponding historical session has been created for the traffic message to be forwarded based on the five-tuple information of the traffic message to be forwarded;

[0015] An extraction unit is configured to enter a fast-forward mode if a corresponding historical session is created, locate two corresponding hash nodes in a hash array based on the key values ​​of the source IP address and the destination IP address pre-written in the session structure of the historical session, and extract two stored hash values ​​from the two hash nodes, wherein the hash array pre-stores corresponding hash values ​​in different hash nodes corresponding to the key values ​​of different IP addresses, and the hash values ​​are used to identify, by numerical changes, whether the IP address corresponding to the key value has been updated as the IP address blacklist is updated;

[0016] The judging unit is further used to judge whether the two hash values ​​are the historical hash values ​​of the key value of the source IP address and the historical hash values ​​of the key value of the destination IP address stored in the hash array that are pre-written in the session structure;

[0017] The forwarding unit is used to forward the traffic message to be forwarded if the two hash values ​​are the historical hash value of the key value of the source IP address stored in the hash array and the historical hash value of the key value of the destination IP address stored in the hash array pre-written in the session structure.

[0018] In a third aspect, the present application provides a network device comprising a processor and a memory, wherein a computer program is stored in the memory, and when the processor calls the computer program in the memory, the method provided in the first aspect of the present application or any possible implementation of the first aspect of the present application is executed.

[0019] In a fourth aspect, the present application provides a computer-readable storage medium, which stores multiple instructions, and the instructions are suitable for a processor to load to execute the method provided in the first aspect of the present application or any possible implementation of the first aspect of the present application.

[0020] From the above content, it can be concluded that this application has the following beneficial effects:

[0021] Aiming at the traffic processing goal of the network protection drill scenario, this application introduces a hash array between traffic messages and IP address blacklists to represent whether a specific IP address has been updated as the IP address blacklist is updated. In this way, in the fast-forward mode, it can accurately provide a judgment basis for whether to directly forward or initiate an IP address blacklist match. In this way, when faced with a dynamically updated IP address blacklist in the network protection drill scenario, when the device resources are relatively fixed, there is no need to increase the number of devices like the existing technology, and the traffic processing performance of the network device can be significantly improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.

[0023] Figure 1 A flow chart of a blacklist-based traffic message forwarding method of this application;

[0024] Figure 2 This is a structural diagram of a blacklist-based traffic message forwarding device of this application;

[0025] Figure 3 This is a structural diagram of the network device of this application. DETAILED DESCRIPTION

[0026] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making creative efforts are within the scope of protection of this application.

[0027] The terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate so that the embodiments described herein can be implemented in a sequence other than that illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or modules is not necessarily limited to those steps or modules clearly listed, but may include other steps or modules that are not clearly listed or that are inherent to these processes, methods, products or devices. The naming or numbering of steps in this application does not mean that the steps in the method flow must be executed in the time / logical sequence indicated by the naming or numbering. The process steps that have been named or numbered can be changed in the execution order according to the technical purpose to be achieved, as long as the same or similar technical effects can be achieved.

[0028] The division of modules in this application is a logical division. In actual application, there may be other division methods. For example, multiple modules can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, and the indirect coupling or communication connection between modules can be electrical or other similar forms, which are not limited in this application. Moreover, the modules or submodules described as separate components may or may not be physically separated, may or may not be physical modules, or may be distributed into multiple circuit modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this application.

[0029] Before introducing the blacklist-based traffic message forwarding method provided by this application, the background content involved in this application is first introduced.

[0030] The blacklist-based traffic message forwarding method, device and computer-readable storage medium provided in the present application can be applied to network equipment and used to introduce a hash array between traffic messages and IP address blacklists to represent whether a specific IP address has been updated as the IP address blacklist is updated. In this way, in the fast-forward mode, it can accurately provide a judgment basis for whether to directly forward or initiate an IP address blacklist match. In this way, when faced with a dynamically updated IP address blacklist in a network protection drill scenario, when the device resources are relatively fixed, there is no need to increase the number of devices like in the existing technology, and the traffic processing performance of the network device can be significantly improved.

[0031] Among them, it can be understood that the present application is faced with the traffic message forwarding processing in the network architecture. Correspondingly, the device that executes the blacklist-based traffic message forwarding method provided by the present application or is equipped with the corresponding application service of the blacklist-based traffic message forwarding provided by the present application is specifically a network device in the network architecture. The network device is usually a network node in the network architecture that specializes in forwarding traffic messages. Of course, it is not ruled out that some network devices are devices that temporarily undertake the work of forwarding traffic messages (that is, devices that were not originally dedicated to forwarding traffic messages). This may also happen in actual situations. Moreover, these network devices may also be configured in the form of a device cluster under actual circumstances rather than a single device.

[0032] Next, we will introduce the blacklist-based traffic message forwarding method provided by this application.

[0033] First, see Figure 1 , Figure 1A flow chart of a blacklist-based traffic message forwarding method of the present application is shown. The blacklist-based traffic message forwarding method provided by the present application may specifically include the following steps S101 to S105:

[0034] Step S101: The network device obtains a traffic message to be forwarded in the network architecture;

[0035] It can be understood that, corresponding to the forwarding target of the traffic message, the present application solution can start from obtaining the traffic message that needs to be forwarded in the current network architecture from the network device. For the current targeted traffic message, the present application can record it as the traffic message to be forwarded.

[0036] The traffic packets to be forwarded may also be referred to as network traffic to be forwarded.

[0037] Step S102: The network device determines whether a corresponding historical session has been created for the traffic message to be forwarded based on the five-tuple information of the traffic message to be forwarded;

[0038] It should be understood that the main purpose of this application solution is to address the problem of traffic packet forwarding processing in fast-forward mode and its inability to adapt to the dynamic and changing IP address blacklist in the network protection drill scenario (also known as the HW scenario). Therefore, the main processing of this application solution involves traffic packet forwarding processing in fast-forward mode.

[0039] During the traffic message forwarding process, the fast-forward mode corresponds to the situation where a session with traffic messages is created in advance. In this way, fast forwarding can be performed according to the session tag and the previous forwarding method. This application can modify it to adapt to the dynamic and changeable characteristics of the IP address blacklist.

[0040] In this regard, after determining the traffic message to be forwarded that needs to be processed, it can be judged based on its five-tuple information whether a corresponding historical session has been created. If a historical session exists, it can obviously trigger the subsequent step S103 and enter the traffic message forwarding processing in the fast-forward mode that this application focuses on.

[0041] Among them, considering the quintuple information itself (including source IP address, destination IP address, source port, destination port and protocol) and how to determine the session based on the quintuple information, it belongs to the scope of existing technology and is not the focus of this application solution, so it will not be explained in detail here.

[0042] Step S103: If a corresponding historical session has been created, the fast-forward mode is entered. The network device locates two corresponding hash nodes in the hash array based on the key values ​​of the source IP address and the destination IP address pre-written in the session structure of the historical session, and extracts two stored hash values ​​from the two hash nodes. The hash array pre-stores corresponding hash values ​​in different hash nodes corresponding to the key values ​​of different IP addresses. The hash value is used to identify whether the IP address corresponding to the key value has been updated as the IP address blacklist is updated through the change in the value.

[0043] It can be seen that the present application introduces a hash array, which can also be understood as a hash table or hash table. It defines a suitable hash bucket (the total number of elements contained in the array) and calculates the key value (index) corresponding to the IP address through the selected hash algorithm (hash algorithm). This key value is the subscript of the hash array and can be understood as a position identifier. Different key values ​​map different hash nodes recorded by the hash array, and the hash nodes record the corresponding hash values. The hash value is calculated from the relevant information of the corresponding IP address. Since the information for calculating the hash value contains whether the corresponding IP address is with the IP address, the hash value is calculated from the relevant information of the corresponding IP address. The information is updated with the update of the address blacklist. Therefore, when the IP address itself remains relatively unchanged, resulting in the key value calculated based on the IP address remaining unchanged, if the IP address itself is updated due to the update of the IP address blacklist, the hash value will inevitably change. In this way, the numerical change of the hash value can be used to identify the update of the corresponding IP address as the IP address blacklist is updated. It may be that the IP address attribute is changed from non-malicious to malicious, or from malicious to non-malicious. This corresponds to the dynamic and changeable characteristics of the IP address blacklist in the network protection drill scenario.

[0044] In this way, based on the additional configuration of a hash array to indirectly represent whether the IP address attributes have been updated, the present application can record the hash values ​​(i.e., historical hash values) of the source and destination IP addresses previously recorded in the hash array in the session control body. After the message belonging to the session appears in real time, the key values ​​of the two IP addresses can be calculated in fast-forward mode, and the corresponding hash nodes can be located in the hash array to extract the corresponding hash values ​​recorded in the current hash array (the latest hash values ​​updated in real time with the IP address blacklist).

[0045] Obviously, if the two are the same, it means that from the hash value of the source and destination IP addresses recorded in the hash array in the session control body (that is, the historical hash value) to the current time range, the IP address attributes of the source and destination IP addresses have not been updated with the update of the IP address blacklist, so that the previous forwarding strategy can be maintained and the corresponding forwarding processing can be performed (this does not mean forwarding, the forwarding processing may be forwarding messages or discarding messages, including these two types of specific forwarding methods).

[0046] The hash value involved in this application can be, as an example, an MD5 value. Correspondingly, the hash algorithm involved is the MD5 algorithm. The MD5 algorithm is a message digest algorithm and a widely used cryptographic hash function that can generate a 128-bit (16-byte) hash value. Of course, in actual situations, a hash value generated by a SHA series hash algorithm or other types of hash algorithms can also be used.

[0047] In addition, as an example, the session structure involved in this application can be specifically nf_conn under the Linux kernel, which is a control structure for session configuration. Similarly, the message structure involved in the subsequent application can be specifically skb under the Linux kernel, which is a control structure for message configuration (or sending and receiving data packets). The main difference between the two in the present application scheme lies in the different objects they target. The former targets the traffic message itself, and the latter targets the session to which the traffic message belongs.

[0048] Step S104: The network device determines whether the two hash values ​​are the historical hash values ​​of the source IP address key value and the destination IP address key value stored in the hash array that are pre-written in the session structure;

[0049] It is easy to see from the description of the previous step S103 that after the two key values ​​calculated by the source and destination IP addresses of the current traffic message to be forwarded are located in the corresponding two hash nodes in the hash array and the two stored hash values ​​are extracted from the two hash nodes, they can be compared (or matched) with the historical hash values ​​of the key value of the source IP address stored in the hash array and the historical hash values ​​of the key value of the destination IP address stored in the hash array that are recorded and pre-written in the session structure.

[0050] It is easy to understand that the comparison here does not have any difference in order and can be understood in terms of a set, that is, to determine whether the set of two latest hash values ​​obtained in real time is the set of two pre-recorded historical hash values.

[0051] In step S105, if the two hash values ​​are the historical hash value of the source IP address key value stored in the hash array and the historical hash value of the destination IP address key value stored in the hash array pre-written in the session structure, the network device forwards the traffic message to be forwarded.

[0052] It can be understood that the present application can be specifically set or defaulted to: the session structure only records the historical hash value of the key value of the source IP address stored in the hash array and the historical hash value of the key value of the destination IP address stored in the hash array when the IP address is not malicious, or, in other words, the historical hash value of the key value of the IP address stored in the hash array and the historical hash value of the key value of the destination IP address stored in the hash array recorded by the session structure only updates the corresponding hash value when the IP address is not malicious.

[0053] In this way, when the judgment result is yes, that is, two hash values ​​are obtained in real time, which are the historical hash value of the key value of the source IP address pre-written in the session structure and the historical hash value of the key value of the destination IP address stored in the hash array, it is obvious that it means that the source and destination IP addresses of the traffic message to be forwarded are still non-malicious IP address attributes when facing the latest IP address blacklist.

[0054] In this way, there is no need to match the source and destination IP addresses with the IP address blacklist, and there is no time-consuming traversal processing involved. The traffic packets to be forwarded that can be forwarded directly and normally can be quickly screened out in the fast forwarding mode, and the traffic packets to be forwarded can be forwarded according to their original forwarding path.

[0055] For the above Figure 1 In brief, the embodiment shown is aimed at the traffic processing goal of the network protection drill scenario. This application introduces a hash array between traffic packets and the IP address blacklist to represent whether a specific IP address has been updated as the IP address blacklist is updated. In this way, in the fast-forward mode, it can accurately provide a judgment basis for whether to directly forward or initiate an IP address blacklist match. In this way, when faced with the dynamically updated IP address blacklist in the network protection drill scenario, when the device resources are relatively fixed, there is no need to increase the number of devices like the existing technology, and the traffic processing performance of the network device can be significantly improved.

[0056] Continue to the above Figure 1 Each step of the illustrated embodiment and its possible implementation in practical applications are described in detail.

[0057] As mentioned above, the hash array configured in this application realizes the mapping relationship between the hash node and the IP address through the key value calculated by the relevant algorithm based on the IP address. For the key value calculation algorithm, a hash algorithm or other types of algorithms can be used. It should be noted that the hash algorithm involved in calculating the key value here is not the same as the hash algorithm involved in the hash value stored in the hash node. That is, the same hash algorithm can be used or different hash algorithms can be used, which can be adjusted according to actual conditions.

[0058] In addition, based on the needs of lightweight applications, in addition to being configured so that one IP address can correspond to one key value, this application can also be configured so that multiple IP addresses correspond to one key value. That is, multiple IP addresses share the same key value (the input of the key value calculation algorithm and / or the algorithm processing logic need to be configured accordingly). The hash value stored in the hash node mapped by the same key value is used to characterize whether the IP address attributes of multiple IP addresses have changed from an overall level. For example, if one or more of the multiple IP addresses change their IP address attributes due to the IP address blacklist, the hash value will change numerically. Conversely, if none of the multiple IP addresses change their IP address attributes due to the IP address blacklist, the hash value will not change numerically, that is, the value remains unchanged.

[0059] Correspondingly, as an exemplary embodiment, the hash value involved in this application is used to identify, through numerical changes, whether at least one of multiple IP addresses corresponding to a key value has been updated as the IP address blacklist is updated.

[0060] In this way, a good balance can be achieved between the update and maintenance cost of the hash array and the convenience of traffic message forwarding processing in the fast-forward mode based on the hash array, meeting the lightweight application needs in actual situations.

[0061] At the same time, corresponding to the application of the hash array, the method of the present application may also involve the update processing of the hash array. In this regard, as another exemplary embodiment, the blacklist-based traffic message forwarding method of the present application may also include:

[0062] The network device obtains the latest IP address blacklist;

[0063] The network device updates the target hash value stored in the corresponding target hash node in the hash array based on the target key value of the target IP address updated by the latest IP address blacklist.

[0064] It is understandable that in the network protection drill scenario, the IP address blacklist is issued by a dedicated threat intelligence and situational awareness center.

[0065] In addition, it can also be seen that the present application can actually be applied to application scenarios other than network protection drill scenarios, involving traffic message forwarding processing based on blacklists. In this case, the acquisition and processing of the IP address blacklist can be more flexible. It can be manually configured, or it can be autonomously generated according to a preset autonomous generation strategy during network security work or traffic message forwarding work, or it can be forwarded by other devices. These are all possible situations.

[0066] In addition, as mentioned in the description of the previous step S105, the present application can specifically set or default to: the session structure only records the historical hash value of the key value of the source IP address stored in the hash array and the historical hash value of the key value of the destination IP address stored in the hash array when the IP address is not malicious, or in other words, the historical hash value of the key value of the IP address stored in the hash array and the historical hash value of the key value of the destination IP address stored in the hash array recorded by the session structure only updates the corresponding hash value when the IP address is not malicious.

[0067] This can also be reflected in the data processing carried out according to another judgment result of step S104. Specifically, as another exemplary embodiment, the blacklist-based traffic message forwarding method of the present application may further include:

[0068] If the two hash values ​​are not the historical hash values ​​of the source IP address key value stored in the hash array and the historical hash values ​​of the destination IP address key value stored in the hash array pre-written in the session structure, then the corresponding source IP address and / or destination IP address has been updated with the update of the IP address blacklist. Based on this, the network device matches the IP address carried in the traffic message to be forwarded with the IP address blacklist;

[0069] If there is a match, the network device discards the traffic message to be forwarded;

[0070] If there is no match, the network device forwards the traffic message to be forwarded, and updates the two hash values ​​as the new hash values ​​stored in the hash array with the key value of the source IP address and the new hash value stored in the hash array with the key value of the destination IP address to the session structure.

[0071] It can be seen that if the hash value does not match, the matching process of the original IP address blacklist can be triggered. If the IP address blacklist does not match, the two hash values ​​calculated by the source and destination IP addresses of the current traffic message to be forwarded can be extracted from the hash array and used as new hash values ​​and recorded in the session structure. Subsequently, if the IP address attributes of the two IP addresses do not change with the changes in the IP address blacklist, then in the next fast-forward mode, the traffic message can be directly forwarded if the hash value matches.

[0072] In addition, the solution of the present application may also involve a situation where no historical session is pre-created / recorded for the current traffic message to be forwarded, that is, it involves processing in a slow-forward mode.

[0073] In this regard, as another exemplary embodiment, the blacklist-based traffic message forwarding method of the present application may further include:

[0074] If no corresponding historical session is created, the system enters slow forwarding mode, and the network device matches the source and destination IP addresses carried in the traffic packets to be forwarded with the IP address blacklist.

[0075] If there is a match, the network device discards the traffic message to be forwarded;

[0076] If there is no match, the network device forwards the traffic message to be forwarded, creates a session for the traffic message to be forwarded, and writes the key values ​​of the source and destination IP addresses in the session structure of the traffic message to be forwarded, and locates the corresponding two hash nodes in the hash array with the key values ​​of the source and destination IP addresses and extracts the two stored hash values ​​from them.

[0077] In this way, if no match is found on the IP address blacklist in the slow-forward mode, the calculated key value and the hash value extracted from the hash array based on the key value can be recorded in the created session structure, laying the foundation for the subsequent fast-forward mode. That is, when a traffic message belonging to the same session appears later and the IP address has not been updated to the IP address blacklist, it can be forwarded quickly.

[0078] It is easy to understand that, before performing a write operation on the session structure, the embodiment here may also involve locating the key values ​​of the source and destination IP addresses to the corresponding two hash nodes in the hash array and extracting the two stored hash values ​​therefrom.

[0079] In this regard, this application can also clarify the specific acquisition node / timing from the business process aspect, and set it to be executed before the IP address blacklist matching, that is, first obtain the hash value, configure the message structure of the message, and then perform the IP address blacklist matching.

[0080] Correspondingly, as another exemplary embodiment, before the network device matches the source and destination IP addresses carried by the traffic message to be forwarded with the IP address blacklist, the blacklist-based traffic message forwarding method of the present application may further include:

[0081] The network device calculates the key values ​​of the source and destination IP addresses and writes the key values ​​of the source and destination IP addresses into the message structure of the traffic message to be forwarded;

[0082] The network device locates the corresponding two hash nodes in the hash array according to the key values ​​of the source and destination IP addresses, extracts the two stored hash values ​​from them, and writes the two hash values ​​into the message structure.

[0083] In addition, this application also provides a more convenient operation method for how to write the hash value into the session structure of the traffic message to be forwarded.

[0084] Specifically, as another exemplary embodiment, in the session structure of the traffic message to be forwarded, the key values ​​of the source and destination IP addresses are located in the corresponding two hash nodes in the hash array and the two stored hash values ​​are extracted therefrom, which may specifically include:

[0085] Copy the two hash values ​​written in the message structure to the session structure.

[0086] It can be understood that the copy operation in the embodiment herein links the message structure and the session structure, which has a more convenient operation effect in actual situations.

[0087] Furthermore, in order to facilitate understanding of the effects of the solutions achieved in the above exemplary embodiments, a more vivid explanation can be provided with the help of the following set of comparative examples with the prior art.

[0088] In network protection drill scenarios, the proportion of actual traffic that needs to be blocked is relatively low. That is, most of the traffic is normal traffic. Matching the blacklist packet by packet will cause significant performance loss and greatly affect the device's processing and forwarding performance.

[0089] Taking the lab test as an example, the following comparative test is conducted with the same equipment and background traffic:

[0090] Without a blacklist, the device can forward a maximum of 12G of traffic.

[0091] If a 1000w blacklist is configured and 10% of the traffic matches the blacklist, the device can only process 1G of traffic.

[0092] After using this application plan, the situation is as follows:

[0093] If a 10 million blacklist is configured and 10% of the traffic matches the blacklist, the device can handle 11G of traffic.

[0094] Obviously, in the network protection test scenario, this application solution can significantly improve the equipment processing and forwarding performance, and under limited equipment conditions, it can exert significantly enhanced equipment forwarding capabilities.

[0095] At the same time, this application also provides a set of examples of the application scheme from a practical perspective, specifically:

[0096]

[0097]

[0098]

[0099] The above is an introduction to the blacklist-based traffic message forwarding method provided by this application. In order to facilitate better implementation of the blacklist-based traffic message forwarding method provided by this application, this application also provides a blacklist-based traffic message forwarding device from the perspective of functional modules.

[0100] See Figure 2 , Figure 2 This is a schematic diagram of the structure of a blacklist-based traffic message forwarding device of the present application. In the present application, the blacklist-based traffic message forwarding device 200 may specifically include the following structure:

[0101] The acquisition unit 201 is used to acquire the traffic message to be forwarded in the network architecture;

[0102] The judging unit 202 is configured to judge whether a corresponding historical session has been created for the traffic message to be forwarded based on the five-tuple information of the traffic message to be forwarded;

[0103] The extraction unit 203 is configured to enter a fast-forward mode if a corresponding historical session has been created, locate two corresponding hash nodes in the hash array based on the key values ​​of the source IP address and the destination IP address pre-written in the session structure of the historical session, and extract two stored hash values ​​from the two hash nodes. The hash array pre-stores corresponding hash values ​​in different hash nodes corresponding to the key values ​​of different IP addresses. The hash values ​​are used to identify, by numerical changes, whether the IP address corresponding to the key value has been updated as the IP address blacklist has been updated.

[0104] The judging unit 202 is further configured to judge whether the two hash values ​​are the historical hash values ​​of the source IP address key value stored in the hash array and the historical hash values ​​of the destination IP address key value stored in the hash array that are pre-written in the session structure;

[0105] The forwarding unit 204 is configured to forward the traffic message to be forwarded if the two hash values ​​are the historical hash value of the source IP address key value stored in the hash array and the historical hash value of the destination IP address key value stored in the hash array pre-written in the session structure.

[0106] In an exemplary embodiment, the hash value is used to identify, through a numerical change, whether at least one of a plurality of IP addresses corresponding to a key value has been updated as the IP address blacklist is updated.

[0107] In another exemplary embodiment, the apparatus further includes an updating unit 205, configured to:

[0108] Get the latest IP address blacklist;

[0109] Based on the target key value of the target IP address updated by the latest IP address blacklist, the target hash value stored in the corresponding target hash node is updated in the hash array.

[0110] In yet another exemplary embodiment, the apparatus further comprises:

[0111] The matching unit 206 is configured to match the IP address carried by the traffic message to be forwarded with the IP address blacklist if the two hash values ​​are not the historical hash values ​​of the source IP address key value stored in the hash array and the historical hash values ​​of the destination IP address key value stored in the hash array pre-written in the session structure;

[0112] A discarding unit 207 is configured to discard the traffic message to be forwarded if a match is found;

[0113] The forwarding unit 204 is further configured to forward the traffic message to be forwarded if there is no match;

[0114] The updating unit 205 is configured to update the session structure with the two hash values ​​as the new hash values ​​stored in the hash array for the key value of the source IP address and the new hash values ​​stored in the hash array for the key value of the destination IP address if there is no match.

[0115] In yet another exemplary embodiment, the apparatus further comprises:

[0116] Matching unit 206, for entering slow forwarding mode if no corresponding historical session is created, and matching the source and destination IP addresses carried by the traffic message to be forwarded with the IP address blacklist;

[0117] A discarding unit 207 is configured to discard the traffic message to be forwarded if a match is found;

[0118] The forwarding unit 204 is further configured to forward the traffic message to be forwarded if there is no match;

[0119] A creating unit 208, configured to create a session for the traffic message to be forwarded if there is no match;

[0120] The writing unit 209 is used to write the key values ​​of the source and destination IP addresses in the session structure if there is no match, and locate the key values ​​of the source and destination IP addresses in the hash array to the corresponding two hash nodes and extract the two stored hash values ​​therefrom.

[0121] In another exemplary embodiment, before matching the source and destination IP addresses carried by the traffic message to be forwarded with the IP address blacklist, the writing unit 209 is further configured to:

[0122] Calculate the key values ​​of the source and destination IP addresses, and write the key values ​​of the source and destination IP addresses into the message structure of the traffic message to be forwarded;

[0123] According to the key values ​​of the source and destination IP addresses, the corresponding two hash nodes are located in the hash array and the two stored hash values ​​are extracted from them, and the two hash values ​​are written into the message structure.

[0124] In another exemplary embodiment, the writing unit 209 is specifically configured to:

[0125] Copy the two hash values ​​written in the message structure to the session structure.

[0126] This application also provides a network device from the perspective of hardware structure, see Figure 3 , Figure 3 Schematic diagram of a network device of the present invention is shown. Specifically, the network device of the present invention may include a processor 301, a memory 302, and an input / output device 303. The processor 301 is configured to execute a computer program stored in the memory 302 to implement the following Figure 1 Each step of the blacklist-based traffic message forwarding method in the corresponding embodiment; or, when the processor 301 is used to execute the computer program stored in the memory 302, Figure 2 The memory 302 is used to store the functions of each unit in the embodiment corresponding to the processor 301. Figure 1 The computer program required for the blacklist-based traffic message forwarding method in the corresponding embodiment.

[0127] For example, the computer program may be divided into one or more modules / units, one or more of which are stored in the memory 302 and executed by the processor 301 to complete the present application. One or more modules / units may be a series of computer program instruction segments capable of performing specific functions, and the instruction segments are used to describe the execution process of the computer program in a computer device.

[0128] The network device may include, but is not limited to, a processor 301, a memory 302, and an input / output device 303. Those skilled in the art will appreciate that the diagram is merely an example of a network device and does not limit the network device. The network device may include more or fewer components than shown, or a combination of certain components, or different components. For example, the network device may further include a network access device, a bus, etc., and the processor 301, the memory 302, the input / output device 303, etc. are connected via the bus.

[0129] The processor 301 may be a central processing unit (CPU), or other general-purpose processors, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor. The processor is the control center of the network device and connects various parts of the entire device using various interfaces and lines.

[0130] The memory 302 can be used to store computer programs and / or modules. The processor 301 implements various functions of the computer device by running or executing the computer programs and / or modules stored in the memory 302 and accessing the data stored in the memory 302. The memory 302 may mainly include a program storage area and a data storage area. The program storage area may store an operating system, at least one application required for a function, etc.; the data storage area may store data generated based on the use of the network device, etc. In addition, the memory may include high-speed random access memory and non-volatile memory, such as a hard disk, internal memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one disk storage device, a flash memory device, or other volatile solid-state storage device.

[0131] When the processor 301 is used to execute the computer program stored in the memory 302, it can specifically implement the following functions:

[0132] Obtain traffic packets to be forwarded in the network architecture;

[0133] Based on the five-tuple information of the traffic message to be forwarded, determine whether a corresponding historical session has been created for the traffic message to be forwarded;

[0134] If a corresponding historical session has been created, fast forward mode is entered. Based on the key values ​​of the source IP address and the destination IP address pre-written in the session structure of the historical session, the two corresponding hash nodes are located in the hash array, and the two stored hash values ​​are extracted from the two hash nodes. The hash array pre-stores corresponding hash values ​​in different hash nodes corresponding to the key values ​​of different IP addresses. The hash value is used to identify whether the IP address corresponding to the key value has been updated as the IP address blacklist is updated through the change of the value.

[0135] Determine whether the two hash values ​​are the historical hash values ​​stored in the hash array of the key value of the source IP address and the historical hash values ​​stored in the hash array of the key value of the destination IP address pre-written in the session structure;

[0136] If the two hash values ​​are the historical hash value of the source IP address key value stored in the hash array and the historical hash value of the destination IP address key value stored in the hash array pre-written in the session structure, the traffic message to be forwarded is forwarded.

[0137] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working process of the blacklist-based traffic message forwarding device, network device and its corresponding units described above can refer to the following. Figure 1 The description of the blacklist-based traffic message forwarding method in the corresponding embodiment will not be repeated here.

[0138] Those skilled in the art will appreciate that all or part of the steps in the various methods of the above embodiments may be accomplished by instructions, or by controlling related hardware through instructions. The instructions may be stored in a computer-readable storage medium and loaded and executed by a processor.

[0139] To this end, the present application provides a computer-readable storage medium, which stores a plurality of instructions, which can be loaded by a processor to execute the present application as follows: Figure 1 For the steps of the blacklist-based traffic message forwarding method in the corresponding embodiment, the specific operations can be referred to as follows: Figure 1 The description of the blacklist-based traffic message forwarding method in the corresponding embodiment will not be repeated here.

[0140] The computer-readable storage medium may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.

[0141] Due to the instructions stored in the computer readable storage medium, the present application can be executed as follows: Figure 1 The steps of the blacklist-based traffic message forwarding method in the corresponding embodiment, therefore, the present application can be implemented as follows Figure 1 The beneficial effects that can be achieved by the blacklist-based traffic message forwarding method in the corresponding embodiment are detailed in the previous description and will not be repeated here.

[0142] The above is a detailed introduction to the blacklist-based traffic message forwarding method, device, network device and computer-readable storage medium provided by the present application. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea; at the same time, for technical personnel in this field, based on the ideas of the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. A traffic message forwarding method based on a blacklist, characterized in that: The method comprises: The network device obtains the traffic packets to be forwarded in the network architecture; The network device determines, based on the quintuple information of the traffic message to be forwarded, whether a corresponding historical session has been created for the traffic message to be forwarded; If a corresponding historical session is created, the fast-forward mode is entered. The network device locates two corresponding hash nodes in the hash array based on the key value of the source IP address and the key value of the destination IP address pre-written in the session structure of the historical session, and extracts two stored hash values ​​from the two hash nodes. The hash array pre-stores corresponding hash values ​​in different hash nodes corresponding to the key values ​​of different IP addresses. The hash values ​​are used to identify whether the IP address corresponding to the key value has been updated as the IP address blacklist is updated through value changes. The network device determines whether the two hash values ​​are the historical hash values ​​of the source IP address key value stored in the hash array and the historical hash values ​​of the destination IP address key value stored in the hash array that are pre-written in the session structure; If the two hash values ​​are the historical hash values ​​of the key value of the source IP address pre-written in the session structure and stored in the hash array, and the historical hash values ​​of the key value of the destination IP address stored in the hash array, the network device forwards the traffic message to be forwarded.

2. The method according to claim 1, characterized in that The hash value is used to identify, through a numerical change, whether at least one of the multiple IP addresses corresponding to one of the key values ​​has been updated as the IP address blacklist is updated.

3. The method according to claim 1, characterized in that The method further comprises: The network device obtains the latest IP address blacklist; The network device updates the target hash value stored in the corresponding target hash node in the hash array based on the target key value of the target IP address updated by the latest IP address blacklist.

4. The method according to claim 1, wherein The method further comprises: If the two hash values ​​are not the historical hash values ​​of the source IP address key value stored in the hash array and the historical hash values ​​of the destination IP address key value stored in the hash array that are pre-written in the session structure, the network device matches the IP address carried by the traffic message to be forwarded with the IP address blacklist; If there is a match, the network device discards the traffic message to be forwarded; If there is no match, the network device forwards the traffic message to be forwarded, and updates the two hash values ​​as the new hash values ​​stored in the hash array with the key value of the source IP address and the new hash value stored in the hash array with the key value of the destination IP address to the session structure.

5. The method according to claim 1, wherein The method further comprises: If the corresponding historical session is not created, the slow forwarding mode is entered, and the network device matches the source and destination IP addresses carried by the traffic message to be forwarded with the IP address blacklist; If there is a match, the network device discards the traffic message to be forwarded; If there is no match, the network device forwards the traffic message to be forwarded, creates a session for the traffic message to be forwarded, and writes the key values ​​of the source and destination IP addresses in the session structure, and locates the corresponding two hash nodes in the hash array with the key values ​​written in the source and destination IP addresses and extracts the two stored hash values ​​therefrom.

6. The method according to claim 5, characterized in that Before the network device matches the source and destination IP addresses carried by the to-be-forwarded traffic message with the IP address blacklist, the method further includes: The network device calculates the key values ​​of the source and destination IP addresses, and writes the key values ​​of the source and destination IP addresses into the message structure of the traffic message to be forwarded; The network device locates the two corresponding hash nodes in the hash array according to the key values ​​of the source and destination IP addresses, extracts the two stored hash values ​​therefrom, and writes the two hash values ​​into the message structure.

7. The method according to claim 6, characterized in that The key values ​​written into the source and destination IP addresses are located in the hash array to the corresponding two hash nodes and the two stored hash values ​​are extracted therefrom, including: The two hash values ​​written in the message structure are copied to the session structure.

8. A traffic message forwarding device based on a blacklist, characterized in that: The device comprises: An acquisition unit, configured to acquire traffic packets to be forwarded in the network architecture; A judging unit, configured to judge whether a corresponding historical session has been created for the traffic message to be forwarded based on the five-tuple information of the traffic message to be forwarded; an extraction unit, configured to enter a fast-forward mode if a corresponding historical session is created, locate two corresponding hash nodes in a hash array based on the key value of the source IP address and the key value of the destination IP address pre-written in the session structure of the historical session, and extract two stored hash values ​​from the two hash nodes, wherein the hash array pre-stores corresponding hash values ​​in different hash nodes corresponding to the key values ​​of different IP addresses, and the hash values ​​are used to identify, by numerical changes, whether the IP address corresponding to the key value has been updated as the IP address blacklist is updated; The judging unit is further configured to judge whether the two hash values ​​are historical hash values ​​of the key value of the source IP address and the key value of the destination IP address stored in the hash array, which are pre-written in the session structure; A forwarding unit is used to forward the traffic message to be forwarded if the two hash values ​​are the historical hash value of the key value of the source IP address stored in the hash array and the historical hash value of the key value of the destination IP address stored in the hash array pre-written in the session structure.

9. A network device, characterized in that: The method comprises a processor and a memory, wherein a computer program is stored in the memory, and when the processor calls the computer program in the memory, the method according to any one of claims 1 to 7 is executed.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor to execute the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Access control method, device and system based on black and white lists

    CN109862025A

  • Network attack detection and identification method and related equipment

    CN115801305A