Method for processing netflow data, electronic device and medium
By introducing the target segment identifier field into the NetFlow template stream and data stream, the problem of insufficient support for SRv6 in the NetFlow protocol is solved, enabling effective monitoring and planning of SRv6 networks.
Patent Information
- Application Number
- CN202310619771.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-29
- Publication Date
- 2026-01-16
- Estimated Expiration
- 2043-05-29
AI Technical Summary
The existing NetFlow protocol lacks support for Segment Routing IPv6 (SRv6), which makes it impossible to effectively monitor SRv6 packets for security and network planning.
A target segment identifier field is introduced into the NetFlow template stream and data stream to characterize the segment identifier SID associated with the segmented route SRv6 of the IPv6 forwarding plane. The target segment identifier is determined by whether the IPv6 packet contains the target segment identifier and then filled into the NetFlow data stream before being sent to the second device for parsing and analysis.
It enables network and security monitoring, network planning, traffic analysis, and IP statistics for SRv6 networks, solving the problem of SRv6 packets being treated as ordinary IPv6 packets for statistics, and improving the monitoring and planning capabilities of SRv6 networks.
Smart Images

Figure CN119052122B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, and in particular to a NetFlow data processing method, an electronic device and a medium. BACKGROUND
[0002] Currently, NetFlow provides a statistical method about packet flow through a switch / router, based on which, the data provided by NetFlow can support network and security monitoring, network planning, traffic analysis and IP statistics. However, in actual application, the existing NetFlow lacks support for SRv6 (Segment Routing IPv6, Segment Routing based on IPv6 forwarding plane), which results in that the SRv6 message can only be treated as a normal IPv6 (Internet Protocol Version 6, Internet Protocol version 6) message for statistics. Since the destination IPv6 address in the SRv6 message may change with the forwarding path, it will result in that the statistical information cannot perform end-to-end traffic analysis on the SRv6 message, and also cannot realize effective security monitoring and network planning on the SRv6 network. SUMMARY
[0003] The embodiments of the present application provide a NetFlow data processing method, an electronic device and a medium, to solve the problem that the existing NetFlow lacks support for SRv6, which results in that the SRv6 message can only be treated as a normal IPv6 message for statistics, and cannot realize effective security monitoring and network planning on the SRv6 network.
[0004] To solve the above technical problems, the present application is implemented as follows:
[0005] In a first aspect, the embodiments of the present application provide a NetFlow data processing method applied to a first device, comprising: configuring a NetFlow template flow and a NetFlow data flow, wherein the NetFlow template flow and the NetFlow data flow both include a field for representing a target segment identifier, and the target segment identifier is used to represent a segment identifier SID associated with Segment Routing based on IPv6 forwarding plane SRv6; in the case that the first device transmits an IPv6 message, determining whether the target segment identifier is included in the IPv6 message; in the case that the target segment identifier is included in the IPv6 message, filling the target segment identifier into the field in the NetFlow data flow, and sending the NetFlow template flow and the NetFlow data flow after filling the target segment identifier to a second device.
[0006] In a second aspect, an embodiment of the present application provides a method for processing NetFlow data, applied to a second device, the method comprising: parsing a NetFlow template stream sent by a first device and saving a parsing result, wherein the parsing result comprises a template ID and template information; comparing a data ID in a NetFlow data stream sent by the first device with the template ID to determine a NetFlow template stream corresponding to the NetFlow data stream; and parsing the NetFlow data stream based on the template information to obtain a target segment identifier.
[0007] In a third aspect, an embodiment of the present application provides a device, comprising: a configuration module configured to configure a NetFlow template stream and a NetFlow data stream, wherein the NetFlow template stream and the NetFlow data stream each comprise a field for representing a target segment identifier, and the target segment identifier is used to represent a segment identifier SID associated with segment routing SRv6 based on an IPv6 forwarding plane; a first determination module configured to determine whether the target segment identifier is included in an IPv6 packet in a case that the first device transmits the IPv6 packet; and a processing module configured to, in a case that the target segment identifier is included in the IPv6 packet, fill the target segment identifier into the field in the NetFlow data stream, and send the NetFlow template stream and the NetFlow data stream with the target segment identifier filled to a second device.
[0008] In a fourth aspect, an embodiment of the present application provides an electronic device, comprising a transceiver and a processor, wherein the processor is configured to configure a NetFlow template stream and a NetFlow data stream, wherein the NetFlow template stream and the NetFlow data stream each comprise a field for representing a target segment identifier, and the target segment identifier is used to represent a segment identifier SID associated with segment routing SRv6 based on an IPv6 forwarding plane, and determine whether the target segment identifier is included in an IPv6 packet in a case that the first device transmits the IPv6 packet, and fill the target segment identifier into the field in the NetFlow data stream in a case that the target segment identifier is included in the IPv6 packet; and the transceiver is configured to send the NetFlow template stream and the NetFlow data stream with the target segment identifier filled to a second device.
[0009] In a fifth aspect, an embodiment of the present application provides a device, comprising: a first parsing module, configured to parse a NetFlow template stream sent by a first device and save a parsing result, wherein the parsing result comprises a template ID and template information; a comparison module, configured to compare a data ID in a NetFlow data stream sent by the first device with the template ID, so as to determine a NetFlow template stream corresponding to the NetFlow data stream; and a second parsing module, configured to parse the NetFlow data stream based on the template information to obtain a target segment identifier.
[0010] In a sixth aspect, an embodiment of the present application provides an electronic device, comprising a transceiver and a processor, wherein the transceiver is configured to receive a NetFlow template stream and a NetFlow data stream sent by a first device; the processor is configured to parse the NetFlow template stream sent by the first device and save a parsing result, compare a data ID in the NetFlow data stream sent by the first device with a template ID, so as to determine a NetFlow template stream corresponding to the NetFlow data stream, and parse the NetFlow data stream based on the template information to obtain a target segment identifier; wherein the parsing result comprises the template ID and the template information.
[0011] In a seventh aspect, an embodiment of the present application provides an electronic device, comprising a processor, a memory, and a program stored in the memory and executable in the processor, wherein the program is executed by the processor to implement the steps of the NetFlow data processing method according to the first aspect or the steps of the NetFlow data processing method according to the second aspect.
[0012] In an eighth aspect, an embodiment of the present application provides a computer readable storage medium, wherein a computer program is stored in the computer readable storage medium, and the computer program is executed by a processor to implement the steps of the NetFlow data processing method according to the first aspect or the steps of the NetFlow data processing method according to the second aspect.
[0013] In the embodiment of the present application, when the first device configures the NetFlow template flow and the NetFlow data flow, the target segment identifier (such as SRv6 SID or SRv6 VPN SID) is contained in the NetFlow template flow and the NetFlow data flow, so that the second device can obtain the target segment identifier after receiving the NetFlow template flow and the NetFlow data flow, so that the second device can subsequently complete network and security monitoring, network planning, traffic analysis, IP statistics and the like of the SRv6 network, and can perform statistical analysis on the message according to the VPN, thereby solving the problem that the existing technology lacks support for SRv6 in NetFlow, so that the message of SRv6 can only be treated as a normal IPv6 message for statistics, and effective security monitoring and network planning of the SRv6 network cannot be achieved. BRIEF DESCRIPTION OF DRAWINGS
[0014] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the description of the embodiments of the present application will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0015] Figure 1 is a flow chart of a NetFlow data processing method provided by the embodiment of the present application;
[0016] Figure 2 is a message format diagram corresponding to the NetFlow template flow when the target segment identifier is SRv6 SID provided by the embodiment of the present application;
[0017] Figure 3 is a message format diagram corresponding to the NetFlow template flow when the target segment identifier is SRv6 VPN SID provided by the embodiment of the present application;
[0018] Figure 4 is a message format diagram corresponding to the NetFlow data flow when the target segment identifier is SRv6 SID provided by the embodiment of the present application;
[0019] Figure 5 is a message format diagram corresponding to the NetFlow data flow when the target segment identifier is SRv6 VPN SID provided by the embodiment of the present application;
[0020] Figure 6 is a flow chart of another NetFlow data processing method provided by the embodiment of the present application;
[0021] Figure 7is a network networking structure schematic diagram provided by an embodiment of the present application;
[0022] Figure 8 is a schematic diagram of a template flow and a data flow sent by PE1 when the target segment identifier is SRv6 SID, provided by an embodiment of the present application;
[0023] Figure 9 is a schematic diagram of a template flow and a data flow sent by PE1 when the target segment identifier is SRv6 VPN SID, provided by an embodiment of the present application;
[0024] Figure 10 is a schematic diagram of a device provided by an embodiment of the present application;
[0025] Figure 11 is a schematic diagram of an electronic device provided by an embodiment of the present application;
[0026] Figure 12 is a schematic diagram of another device provided by an embodiment of the present application;
[0027] Figure 13 is a schematic diagram of another electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0028] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some but not all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of the present application.
[0029] First, the NetFlow is explained. The NetFlow [RFC3954][RFC7011] technology is a statistical and publishing technology based on network flow information, which can statistically and publish the traffic and resource usage in the network, and provide a means for network managers to access detailed traffic information.
[0030] A NetFlow system mainly includes three parts: a detector (NetFlow Monitor), a collector (NetFlow collector) and a reporting system (Flow Records). The detector is used to listen to network data. The collector is used to collect data from the detector. The reporting system is used to generate readable reports from the data collected by the collector.
[0031] The collector will send a template flow carrying a template ID to the detector before outputting the NetFlow data flow, and the detector will record the received template ID and template information.
[0032] The NetFlow data record output by the collector consists of data streams and detailed traffic statistics. The data streams can include information such as source and destination related information, protocols and ports used by end-to-end sessions, MPLS labels, and the like. After receiving the data record, the probe matches the template ID carried in the data stream with the corresponding template information to analyze the data stream.
[0033] Referring to Figure 1 , Figure 1 is a flowchart of a method for processing NetFlow data provided by an embodiment of the present application, for a first device, such as a probe of a NetFlow system, as shown in Figure 1 The method comprises the following steps:
[0034] Step 101, configuring a NetFlow template stream and a NetFlow data stream, wherein the NetFlow template stream and the NetFlow data stream each include a field for representing a target segment identifier, the target segment identifier being used to represent a SID (Segment Identifier) associated with SRv6 (Segment Routing over IPv6);
[0035] In specific examples of the present application, the SID associated with SRv6 can refer to an SRv6 SID, or a G-SRv6 SID, and further can refer to an SRv6 VPN (Virtual Private Network) SID or a G-SRv6 VPN SID. In addition, the first device in the embodiment of the present application can be a probe of a NetFlow system, and the second device can be a collector in the NetFlow system. In addition, in some special application scenarios in specific examples, the first device can also be a collector, and the second device can also be a probe. Further, the first device can be a router in specific examples.
[0036] Step 102, in the case of transmitting an IPv6 packet by the first device, determining whether the target segment identifier is included in the IPv6 packet;
[0037] Step 103, in the case where the target segment identifier is included in the IPv6 packet, filling the target segment identifier into the field in the NetFlow data stream, and sending the NetFlow template stream and the NetFlow data stream with the filled target segment identifier to the second device.
[0038] As can be known from steps 101 to 103 of the embodiment of the application, when the first device configures the NetFlow template flow and the NetFlow data flow, the target segment identifier (such as the SRv6 SID or the SRv6 VPN SID, and the G-SRv6 SID or the G-SRv6 VPN SID) is contained in the NetFlow template flow and the NetFlow data flow, so that the second device can obtain the target segment identifier after receiving the NetFlow template flow and the NetFlow data flow, so as to complete subsequent network and security monitoring, network planning, traffic analysis, IP statistics and the like of the SRv6 network by the second device, and can perform statistical analysis on the message according to the VPN, thereby solving the problem that the NetFlow in the prior art lacks support for the SRv6, the message of the SRv6 can only be treated as a normal IPv6 message for statistics, and effective security monitoring and network planning of the SRv6 network cannot be implemented.
[0039] It should be noted that in the embodiment of the application, when the first device is a probe, the second device is a collector; in other scenarios, the first device can also be a collector, and the second device is a probe. Specific settings can be made according to actual needs.
[0040] In an optional implementation of the embodiment of the application, the message format corresponding to the NetFlow template flow in the embodiment of the application at least includes a first field for representing whether it is a template flow, a second field for representing the length of the NetFlow template flow, a third field for representing the template ID, a fourth field for representing the number of fields in the NetFlow template flow, a fifth field for representing the field type, and a sixth field for representing the length of the field type.
[0041] It can be seen that the existing NetFlow protocol is extended in the embodiment of the application. In a specific example, if the current target segment identifier is the SRv6 SID, the SRv6 related value definition such as SRv6_SID_1, SRv6_SID_2,..., and SRv6_SID_M can be newly added in the Field Type (field type), as shown in Table 1. It should be noted that in the embodiment of the application, the G-SRv6 (Generalized Segment Routing IPv6, SRv6 header compression technology) related value definition can also be newly added in the Field Type (field type) of the NetFlow protocol according to needs, and the newly added G-SRv6 related value is similar to the newly added SRv6 related value, that is, it can be G-SRv6_SID_M.
[0042]
[0043]
[0044] Table 1
[0045] Based on Table 1, in a specific example, the format of the template message corresponding to the NetFlow template flow is as shown in Table 2. Figure 2 FlowSet ID (corresponding to the first field) = 0 indicates that it is a template flow. Length (corresponding to the second field) is used to indicate the length of the entire FlowSet, specifically the length of the FlowSet ID, Length and all Template fields. Template ID (corresponding to the third field) is used to identify the template, wherein a unique Template ID is generated for each newly generated template, and the optional value of Template ID is 256-65535. Field Count (corresponding to the fourth field) is used to indicate the number of fields in this template. Field Type (corresponding to the fifth field) is used to identify the type of the field. Field Length (corresponding to the sixth field) is used to indicate the length of the field corresponding to the Field Type.
[0046] In a specific example, if the current target segment identifier is SRv6 VPN SID, a Field Type field SRv6_VPN_SID related value definition is added, and the specific definition is as shown in Table 2.
[0047]
[0048]
[0049] Table 2
[0050] Based on Table 2, in a specific example, the format of the template message corresponding to the NetFlow template flow is as shown in Table 2. Figure 3 FlowSet ID (corresponding to the first field) = 0 indicates that it is a template flow. Length (corresponding to the second field) is used to indicate the length of the entire FlowSet, specifically the length of the FlowSet ID, Length and all Template fields. Template ID (corresponding to the third field) is used to identify the template, wherein a unique Template ID is generated for each newly generated template, and the optional value of Template ID is 256-65535. Field Count (corresponding to the fourth field) is used to indicate the number of fields in this template. Field Type (corresponding to the fifth field) is used to indicate that the type of the field is SRv6_VPN_SID. Field Length (corresponding to the sixth field) is used to indicate the length of the field corresponding to the type SRv6_VPN_SID.
[0051] In the case that the target segment identifier is SRv6 SID or SRv6 VPN SID as introduced above, the format of the template message corresponding to the NetFlow template flow is introduced as follows. The message format corresponding to the NetFlow data flow at least includes a seventh field for representing data ID, an eighth field for representing NetFlow data flow length, and a ninth field for representing field content.
[0052] In a specific example, in the case that the target segment identifier is SRv6 SID, based on the above Table 1, the message format of the NetFlow publishing data flow in the embodiment of the present application is as shown in Figure 4 FlowSet ID (corresponding to the seventh field) is used to correspond to a Template ID in a template flow to indicate the template flow corresponding to the data flow. Length (corresponding to the eighth field) is used to indicate the length of the entire FlowSet, specifically the length of FlowSet ID, Length and all flow record contents. SRv6_SID_1 (corresponding to the ninth field) is used to identify the specific carried field content.
[0053] In a specific example, in the case that the target segment identifier is SRv6 VPN SID, based on the above Table 2, the message format of the NetFlow publishing data flow in the embodiment of the present application is as shown in Figure 5 FlowSet ID (corresponding to the seventh field) is used to correspond to a Template ID to identify the template flow corresponding to the data flow. Length (corresponding to the eighth field) is used to indicate the length of the entire FlowSet, specifically the length of FlowSet ID, Length and all flow record contents. SRv6_VPN_SID (corresponding to the ninth field) is used to indicate the value of End.DT4 SID, End.DT6 SID or End.DT6 SID extracted from the SRv6 message by the collector.
[0054] In an optional implementation of the embodiment of the present application, for the manner of determining whether the target segment identifier is included in the IPv6 message in the above step 102, further includes:
[0055] Step 11, judging whether the next header type in the IPv6 message is SRH;
[0056] Step 12, in the case that the next header (Next Header) type is SRH, analyzing the SRH to determine whether the target segment identifier is included in the SRH.
[0057] Based on the above steps 11 and 12, further, in the case that the target segment identifier is SRv6 SID and the N-layer SRv6 SID is included in the NetFlow template flow, the way of filling the target segment identifier into the field in the NetFlow data flow involved in the above step 103 can further include:
[0058] Step 21, in the case that the number of parsed SRv6 SIDs is greater than or equal to N, the first N parsed SRv6 SIDs are filled into the N fields in the NetFlow data flow;
[0059] Step 22, in the case that the number of parsed SRv6 SIDs is less than N, the parsed SRv6 SIDs are filled into the NetFlow data flow, and then the unfilled fields are supplemented with 0; wherein N is a positive integer.
[0060] It can be seen that in the embodiments of the present application, the SID list of the SRv6 packet is defined to be included in the NetFlow packet template and the NetFlow data flow, so that the second device can obtain the SRv6 SID list and analyze it to complete network and security monitoring, network planning, traffic analysis, IP statistics, etc. of the SRv6 network.
[0061] In combination with the above steps 11 and 12, and steps 21 and 22, for the method of the above steps 101 to 103 in the specific example, it can further include:
[0062] Step 201, when the first device (equivalent to the probe) is configured with the NetFlow to publish N-layer SRv6 SID, the first device will publish a template flow containing N-layer SRv6 SID information.
[0063] Step 202, when the first device receives / sends an IPv6 packet, it judges whether the Next Header (lower layer header type) is the SRH extension header, if yes, it parses the SRH header to obtain the SID list and fills the NetFlow data flow. If the number of parsed SIDs in the packet is greater than N, only the first N SIDs are filled according to the definition. If the number of parsed SIDs in the packet is less than N, after filling the SIDs, the excess is supplemented with 0 according to the definition.
[0064] Step 203, when the second device (equivalent to the collector) receives the NetFlow template flow, it parses the template flow and stores the template information.
[0065] Step 204, when the second device receives the NetFlow data stream, the template information corresponding to the data stream is determined by comparing the FlowSet ID in the data stream with the Template ID in the template stream, and the data stream is parsed according to the template information.
[0066] From the above steps 201 to 204, the SID list of the SRv6 packet is defined to be included in the NetFlow packet template and the data stream. Since each SRv6 SID is a complete IPv6 address, if the SRv6 SID is added to the statistical information at the same time, not only can the forwarding path of the packet be drawn through the SRv6 SID, but also the different SID types contained in the SRv6 SID can be analyzed to analyze its meaning to monitor the network security, that is, the second device receives the NetFlow template stream and the NetFlow data stream, can obtain the SRv6 SID list and analyze it, to complete the network and security monitoring, network planning, traffic analysis and IP statistics of the SRv6 network.
[0067] Based on the above steps 11 and 12, further, in the case of the target segment identifier being an SRv6 VPN SID, the method of filling the target segment identifier into the field in the NetFlow data stream involved in step 103 in the embodiments of the present application can further include:
[0068] Step 31, filling the SRv6 VPN SID into the field in the NetFlow data stream.
[0069] It can be seen that in the embodiments of the present application, the VPN SID in the SID list of the SRv6 packet is defined to be included in the NetFlow packet template and the data stream, so that the second device can obtain the SRv6 SID list and analyze it in the future, to complete the network and security monitoring, network planning, traffic analysis and IP statistics of the SRv6 network.
[0070] In combination with the above steps 11 and 12, and step 31, for the method of the above steps 101 to 103 in the specific example, it can further include:
[0071] Step 301, the first device sends a template stream containing SRv6_VPN_SID to the probe.
[0072] Step 302, when the first device receives / sends an IPv6 packet, the packet is processed.
[0073] Specifically, it is first judged whether the Next Header (lower layer header type) of the IPv6 message is the SRH extension header, if yes, the SRH header is parsed. Then it is judged whether the SRH header contains a VPN SID, if yes, the VPN SID value is obtained and filled in the NetFlow data stream SRv6_VPN_SID field.
[0074] Step 303, when the second device receives the NetFlow template stream, the template stream is parsed, and the TemplateID in the template is stored.
[0075] Step 304, when the second device receives the NetFlow data stream, the template information corresponding to the data stream is determined by comparing the FlowSet ID in the data stream with the Template ID in the template stream, and the SRv6_VPN_SID field in the data stream is parsed according to the template information.
[0076] By the above steps 301 to 304, the VPN SID of the SRv6 message is defined to be contained in the NetFlow message template and data stream, so that after the second device receives the NetFlow template stream and the NetFlow data stream, the SRv6 VPN SID list can be obtained and analyzed, and the message can be statistically analyzed according to the VPN.
[0077] Corresponding to the above Figure 1 The embodiment of the application also provides a NetFlow data processing method applied to a second device, as shown in the figure, the steps of the method include: Figure 6
[0078] Step 601, the NetFlow template stream sent by the first device is parsed, and the parsing result is saved, wherein the parsing result includes the template ID and the template information;
[0079] Step 602, the data ID in the NetFlow data stream sent by the first device is compared with the template ID to determine the NetFlow template stream corresponding to the NetFlow data stream;
[0080] Step 603, the NetFlow data stream is parsed based on the template information to obtain the target segment identifier.
[0081] It can be seen that in the embodiment of the present application, the NetFlow template stream and the NetFlow data stream received by the second device include the target segment identifier, if the target segment identifier is an SRv6 SID or an SRv6 VPN SID, the second device can obtain the SRv6 SID or the SRv6 VPN SID after receiving the NetFlow template stream and the NetFlow data stream, and can complete network and security monitoring, network planning, traffic analysis, IP statistics and the like of the SRv6 network, and can perform statistical analysis on the message according to the VPN.
[0082] The present application will be explained and described below in combination with specific embodiments of the present application.
[0083] Embodiment 1
[0084] In this embodiment, the NetFlow related configuration information can be issued to the collector according to the service requirement through the network control plane or the centralized SDN controller, the network management system and the like, such as Figure 7 As shown in the figure, the PE1 and P2 devices in the network are used as the collector, the controller is the detector and the reporting system, and based on this, the locators of the nodes are as follows:
[0085] PE1 A:1::
[0086] P1 A:2::
[0087] P2 A:3::
[0088] PE2 A:4::
[0089] The path information arrangement of the SRv6 Policy between the CE1->CE2 nodes of the user is Segment list:<A:1::11End.X,A:2::11End.X,A:3::11End.X,A:4::100End.DT4 VPN SID>.
[0090] It should be noted that PE represents a high-end router, P represents an edge router, and CE represents a user.
[0091] The NetFlow reporting is configured on the PE1 and P2, and then the template stream and the data stream sent by the PE1 and P2 are as shown in Figure 8 Based on this, taking the PE1 as an example, the specific process steps include:
[0092] In step 701, the PE1 publishes a template stream according to the NetFlow configuration, and the template includes five SRv6 SID information.
[0093] Step 702: PE1 carries the traffic of CE1 into the SRv6 Policy tunnel and performs statistical sampling. According to the SRH header information of the packet, PE1 encapsulates the SRv6 SID information in the NetFlow data stream. Since there are only 4 SRv6 SIDs in the packet, the fifth SRv6 SID information is encapsulated as 0 and sent to the controller.
[0094] Step 703: The controller receives the NetFlow template stream published by PE1 and records the template format and Template ID.
[0095] Step 704: The controller receives the NetFlow data stream published by PE1, compares the FlowSet with the Template ID to determine the template format corresponding to the data stream, and parses and analyzes the message.
[0096] As can be seen, this embodiment defines the inclusion of the SID list of SRv6 packets in the NetFlow packet template and data stream. This allows the controller to obtain and analyze the SRv6 SID list, and complete network and security monitoring, network planning, traffic analysis, and IP statistics for the SRv6 network.
[0097] Example 2
[0098] like Figure 7 The network physical topology shown is illustrated below, with the following locators for each node:
[0099] PE1 A:1::
[0100] P1 A:2::
[0101] P2 A:3::
[0102] PE2 A:4::
[0103] The path information for the SRv6 Policy between the user's CE1 and CE2 nodes is organized into a segment list:<A:1::11End.X,A:2::11End.X,A:3::11End.X,A:4::100End.DT4 VPN SID> .
[0104] Configure NetFlow reporting on PE1 and P2, then the template stream and data stream sent by PE1 and P2 will be as follows: Figure 9 The NetFlow template stream and data stream shown are illustrated. Taking PE1 as an example, the specific steps of the process include:
[0105] Step 801: PE1 publishes a template stream according to the NetFlow configuration, and the template contains SRv6_VPN_SID information.
[0106] Step 802, PE1 directs the traffic of CE1 into the SRv6 Policy tunnel according to the VPN, and statistics sampling, finds A:4::100End.DT4 VPN SID in the SRH header information of the message, and encapsulates A:4::100 in the SRv6_VPN_SID field of the NetFlow data stream, and sends to the controller.
[0107] Step 803, the controller receives the NetFlow template stream published by PE1, and records the template format and Template ID.
[0108] Step 804, the controller receives the NetFlow data stream published by PE1, compares the FlowSet ID and the Template ID, determines the template format corresponding to the data stream, and parses the data stream message to obtain the SRv6_VPN_SID value as A:4::100.
[0109] It can be seen that in the specific embodiment, the VPN SID in the SID list of the SRv6 message is included in the NetFlow message template and the data stream, so that the controller can obtain the VPN SID and analyze it, complete the network and security monitoring, network planning, traffic analysis and IP statistics of the SRv6 network, and perform statistical analysis on the message according to the VPN.
[0110] Referring to Figure 10 , Figure 10 is a structural schematic diagram of a device provided by an embodiment of the application, as Figure 10 shown, the first device comprises:
[0111] The configuration module 1002 is configured to configure a NetFlow template stream and a NetFlow data stream, wherein the NetFlow template stream and the NetFlow data stream each comprise a field for representing a target segment identifier, and the target segment identifier is used to represent a segment identifier SID associated with segment routing SRv6 based on an IPv6 forwarding plane;
[0112] The first determination module 1004 is configured to determine whether the target segment identifier is included in an IPv6 message in the case that the first device transmits the IPv6 message.
[0113] The processing module 1006 is configured to, in the case that the target segment identifier is included in the IPv6 message, fill the target segment identifier into the field in the NetFlow data stream, and send the NetFlow template stream and the NetFlow data stream with the filled target segment identifier to the second device.
[0114] Optionally, the first determining module in this application embodiment may further include: a judging unit, used to judge whether the lower-layer header type in the IPv6 packet is a Segmentation Routing Extension Header (SRH); and a parsing unit, used to parse the SRH when the lower-layer header type is SRH, to determine whether the SRH includes a target segment identifier.
[0115] Optionally, when the target segment identifier is an SRv6 SID and the NetFlow template stream includes N layers of SRv6 SIDs, the processing module 1006 may further include: a first filling unit, used to fill the first N parsed SRv6 SIDs into N fields in the NetFlow data stream when the number of parsed SRv6 SIDs is greater than or equal to N; and a second filling unit, used to fill the unfilled fields with 0 after filling the parsed SRv6 SIDs into the NetFlow data stream when the number of parsed SRv6 SIDs is less than N; wherein N is a positive integer.
[0116] Optionally, if the target segment identifier is an SRv6 VPN SID, the processing module 1006 may further include a third padding unit for padding the SRv6 VPN SID into a field in the NetFlow data stream.
[0117] Optionally, the message format corresponding to the NetFlow template stream includes at least a first field for indicating whether it is a template stream, a second field for indicating the length of the NetFlow template stream, a third field for indicating the template ID, a fourth field for indicating the number of fields in the NetFlow template stream, a fifth field for indicating the field type, and a sixth field for indicating the length of the field type.
[0118] Optionally, the message format corresponding to the NetFlow data stream includes at least a seventh field for representing the data ID, an eighth field for representing the length of the NetFlow data stream, and a ninth field for representing the content of the field.
[0119] It should be noted that the first device provided in this embodiment of the invention is capable of performing the above-described... Figure 1 If the apparatus for processing NetFlow data in the embodiments is applicable to the first device, then all implementations of the NetFlow data processing method in the above embodiments are applicable to the first device and can achieve the same or similar beneficial effects.
[0120] For details, see Figure 11 As shown, this embodiment of the invention also provides an electronic device, including a bus 1101, a transceiver 1102, an antenna 1103, a bus interface 1104, a processor 1105, and a memory 1106.
[0121] The processor 1105 is configured to configure a NetFlow template flow and a NetFlow data flow, wherein the NetFlow template flow and the NetFlow data flow each include a field for representing a target segment identifier, the target segment identifier is used to represent a segment identifier (SID) associated with segment routing (SRv6) based on an IPv6 forwarding plane, and in a case that the first device transmits an IPv6 packet, it is determined whether the target segment identifier is included in the IPv6 packet, and in a case that the target segment identifier is included in the IPv6 packet, the target segment identifier is filled into the field in the NetFlow data flow.
[0122] The transceiver 1102 is configured to send the NetFlow template flow and the NetFlow data flow with the filled target segment identifier to the second device.
[0123] Optionally, the electronic device in the embodiment of the present application Figure 11 may also be configured to perform other method steps in the embodiment of the present application Figure 1 , and the effects are similar, which will not be described here.
[0124] In the embodiment of the present application Figure 11 , the bus architecture (represented by the bus 1101) can include any number of interconnected buses and bridges, which link various circuits including one or more processors represented by the processor 1105 and the memory represented by the memory 1106. The bus 1101 can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, and thus, will not be described further herein. The bus interface 1104 provides an interface between the bus 1101 and the transceiver 1102. The transceiver 1102 can be one element or multiple elements such as multiple receivers and transmitters, which provide a unit for communicating with various other devices on a transmission medium. The data processed by the processor 1105 is transmitted on a wireless medium through the antenna 1103, and further, the antenna 1103 also receives data and transmits the data to the processor 1105.
[0125] The processor 1105 is responsible for managing the bus 1101 and general processing, and can also provide various functions including timing, peripheral interface, voltage regulation, power management, and other control functions. The memory 1106 can be used to store data used by the processor 1105 in performing operations.
[0126] Optionally, the processor 1105 can be a CPU, an ASIC, an FPGA, or a CPLD.
[0127] It should be noted that the electronic device provided by the embodiment of the present application is capable of executing the above-mentioned Figure 1 The device for processing the NetFlow data in the embodiment is capable of executing all the implementation manners of the above-mentioned
[0128] Referring to Figure 12 , Figure 12 is a structural schematic diagram of a device provided by the embodiment of the present application, as shown in Figure 12 The second device comprises:
[0129] The first analysis module 1202 is configured to analyze the NetFlow template stream sent by the first device and save the analysis result, wherein the analysis result comprises the template ID and the template information.
[0130] The comparison module 1204 is configured to compare the data ID in the NetFlow data stream sent by the first device with the template ID, so as to determine the NetFlow template stream corresponding to the NetFlow data stream.
[0131] The second analysis module 1206 is configured to analyze the NetFlow data stream based on the template information to obtain the target segment identifier.
[0132] It should be noted that the second device provided by the embodiment of the present application is capable of executing the above-mentioned Figure 6 The device for processing the NetFlow data in the embodiment is capable of executing all the implementation manners of the above-mentioned
[0133] Specifically, referring to Figure 13 The present application further provides an electronic device, which comprises a bus 1301, a transceiver 1302, an antenna 1303, a bus interface 1304, a processor 1305 and a memory 1306.
[0134] The transceiver 1302 is configured to receive the NetFlow template stream and the NetFlow data stream sent by the first device.
[0135] The processor 1305 is configured to analyze the NetFlow template stream sent by the first device and save the analysis result, and compare the data ID in the NetFlow data stream sent by the first device with the template ID, so as to determine the NetFlow template stream corresponding to the NetFlow data stream, and analyze the NetFlow data stream based on the template information to obtain the target segment identifier; wherein the analysis result comprises the template ID and the template information.
[0136] In Figure 13 which a bus architecture (represented by bus 1301), the bus 1301 can include any number of interconnecting buses and bridges, the bus 1301 links together various circuits such as the processor 1305 represented by one or more processors and the memory 1306 represented by the memory. The bus 1301 can also link together various other circuits which are well known in the art, therefore, further description of such other circuits is not necessary here. The bus interface 1304 provides an interface between the bus 1301 and the transceiver 1302. The transceiver 1302 can be a single element or multiple elements such as a plurality of receivers and transmitters, which provides a means for communicating with various other apparatus over a transmission medium. Data processed by the processor 1305 is transmitted over a wireless medium via the antenna 1303, further, the antenna 1303 also receives data and transmits the data to the processor 1305.
[0137] The processor 1305 is responsible for managing the bus 1301 and general processing, and can also provide various functions including timing, peripheral interface, voltage regulation, power management, and other control functions. The memory 1306 can be used to store data used by the processor 1305 in performing operations.
[0138] Optionally, the processor 1305 can be a CPU, ASIC, FPGA or CPLD.
[0139] The embodiments of the present application also provide an electronic device, comprising: a processor, a memory and a program stored in the memory and executable in the processor, the program is executed by the processor to implement the above Figure 1 or Figure 6 the processes of the embodiment of the method for processing NetFlow data shown in the above, and the same technical effects can be achieved, to avoid repetition, here will not be described.
[0140] The embodiments of the present application also provide a computer readable storage medium, the computer readable storage medium stores a computer program, the computer program is executed by the processor to implement the above Figure 1 or Figure 6 the processes of the embodiment of the method for processing NetFlow data shown in the above, and the same technical effects can be achieved, to avoid repetition, here will not be described. The computer readable storage medium, such as read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), magnetic disk or optical disk, etc.
[0141] It should be noted that, in this document, the terms "comprises", "comprising", or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can also include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by "comprises... a" does not, without more constraints, exclude the presence of additional identical elements in the process, method, article, or apparatus that comprises the element.
[0142] Those skilled in the art can clearly understand the above-mentioned embodiment method can be realized by means of software and necessary general hardware platform, of course, also can be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of software product, and the computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), including a plurality of instructions to make a terminal (may be a mobile phone, computer, server, air conditioner, or network equipment, etc.) execute the method described in various embodiments of the present application.
[0143] The embodiments of the present application are described above in conjunction with the drawings, but the present application is not limited to the above-mentioned specific embodiments, and the above-mentioned specific embodiments are only illustrative, not restrictive. Those skilled in the art can make many forms under the inspiration of the present application without departing from the purpose of the present application and the scope protected by the claims, which all belong to the protection of the present application.
Claims
1. A method for processing NetFlow data, applied to a first device, comprising: The method comprises: configuring a NetFlow template flow and a NetFlow data flow, wherein the NetFlow template flow and the NetFlow data flow each comprise a field for representing a target segment identifier for representing a segment identifier (SID) associated with segment routing over IPv6 (SRv6); in the case that the first device transmits an IPv6 packet, determining whether the target segment identifier is included in the IPv6 packet; in the case that the target segment identifier is included in the IPv6 packet, filling the target segment identifier into the field in the NetFlow data flow, and sending the NetFlow template flow and the NetFlow data flow with the filled target segment identifier to a second device.
2. The method of claim 1, wherein, The determination of whether the target segment identifier is included in the IPv6 packet comprises: determining whether a lower layer header type in the IPv6 packet is a segment routing header (SRH); in the case that the lower layer header type is the SRH, parsing the SRH to determine whether the target segment identifier is included in the SRH.
3. The method of claim 2, wherein, In the case that the target segment identifier is an SRv6 SID and N SRv6 SIDs are included in the NetFlow template flow, the filling of the target segment identifier into the field in the NetFlow data flow comprises: in the case that the number of parsed SRv6 SIDs is greater than or equal to the N, filling the first N parsed SRv6 SIDs into N fields in the NetFlow data flow; in the case that the number of parsed SRv6 SIDs is less than the N, filling the parsed SRv6 SIDs into the NetFlow data flow and then supplementing the unfilled fields with 0s; wherein N is a positive integer.
4. The method of claim 2, wherein, In the case that the target segment identifier is an SRv6 VPN SID, the filling of the target segment identifier into the field in the NetFlow data flow comprises: filling the SRv6 VPN SID into the field in the NetFlow data flow.
5. The method of claim 1, wherein, The message format corresponding to the NetFlow template flow comprises at least a first field for representing whether it is a template flow, a second field for representing the length of the NetFlow template flow, a third field for representing a template ID, a fourth field for representing the number of fields in the NetFlow template flow, a fifth field for representing the type of a field, and a sixth field for representing the length of the type of a field.
6. The method of claim 1, wherein, The message format corresponding to the NetFlow data flow comprises at least a seventh field for representing a data ID, an eighth field for representing the length of the NetFlow data flow, and a ninth field for representing the content of a field.
7. The method of claim 1, wherein, After sending the NetFlow template flow and the NetFlow data flow with the filled target segment identifier to the second device, the method further comprises: The second device parses the NetFlow template stream sent by the first device and saves the parsing result, wherein the parsing result includes a template ID and template information; The second device compares a data ID in the NetFlow data stream sent by the first device with the template ID to determine the NetFlow template stream corresponding to the NetFlow data stream; The second device parses the NetFlow data stream based on the template information to obtain a target segment identifier.
8. A forwarding device, characterized in that, Comprise: The configuration module is configured to configure a NetFlow template stream and a NetFlow data stream, wherein the NetFlow template stream and the NetFlow data stream both include a field for representing a target segment identifier, and the target segment identifier is used to represent a segment identifier SID associated with segment routing SRv6 based on an IPv6 forwarding plane; The first determination module is configured to determine whether the target segment identifier is included in an IPv6 packet in the case that the first device transmits the IPv6 packet; The processing module is configured to fill the target segment identifier into the field in the NetFlow data stream and send the NetFlow template stream and the NetFlow data stream with the filled target segment identifier to a second device in the case that the target segment identifier is included in the IPv6 packet.
9. The forwarding device of claim 8, wherein, The forwarding device comprises a controller, and the controller is configured to: Parse a NetFlow template stream sent by a first device and save a parsing result, wherein the parsing result includes a template ID and template information; Compare a data ID in a NetFlow data stream sent by the first device with the template ID to determine the NetFlow template stream corresponding to the NetFlow data stream; Parse the NetFlow data stream based on the template information to obtain a target segment identifier.
10. An electronic device, comprising: Comprise a transceiver and a processor, The processor is configured to configure a NetFlow template stream and a NetFlow data stream, wherein the NetFlow template stream and the NetFlow data stream both include a field for representing a target segment identifier, and the target segment identifier is used to represent a segment identifier SID associated with segment routing SRv6 based on an IPv6 forwarding plane, and determine whether the target segment identifier is included in an IPv6 packet in the case that a first device transmits the IPv6 packet, and fill the target segment identifier into the field in the NetFlow data stream in the case that the target segment identifier is included in the IPv6 packet; The transceiver is configured to send the NetFlow template stream and the NetFlow data stream with the filled target segment identifier to a second device.
11. The electronic device of claim 10, wherein, Comprise a second transceiver and a second processor, wherein, The second transceiver is configured to receive a NetFlow template stream and a NetFlow data stream sent by a first device; The second processor is configured to parse the NetFlow template stream and the NetFlow data stream, and save a parsing result, wherein the parsing result includes a template ID and template information; The second processor is configured to parse the NetFlow template stream sent by the first device, save the parsing result, compare the data ID and the template ID in the NetFlow data stream sent by the first device, determine the NetFlow template stream corresponding to the NetFlow data stream, and parse the NetFlow data stream based on the template information to obtain the target segment identifier; wherein the parsing result includes the template ID and the template information.
12. An electronic device, comprising: The application further provides a computer readable storage medium having stored thereon a computer program, wherein the computer program is executed by a processor to implement the steps of the processing method of the NetFlow data according to any one of claims 1 to 7. The application further provides a computer readable storage medium having stored thereon a computer program, wherein the computer program is executed by a processor to implement the steps of the processing method of the NetFlow data according to any one of claims 1 to 7.
13. A computer-readable storage medium, characterized in that,
Citation Information
Patent Citations
Message processing method and device, equipment and storage medium
CN113411834A
Message processing method, node and computer readable storage medium
CN114650256A