A Size Rule Tree Method for Enabling New Flow Table Rules to Take Effect Quickly in a Massive Flow Table
By splitting the rule tree in the massive flow table into a large rule tree and a small rule tree, and using dynamic adjustment and rule merging methods, the problem of too long taking effect in the massive flow table is solved, and the rule effectiveness speed and cost reduction are achieved.
Patent Information
- Application Number
- CN202411277599.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-12
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2044-09-12
AI Technical Summary
In massive flow tables, when the number of rules is much larger than the equipment flow table space capacity, the effective time of the new flow table rules will be extended infinitely, resulting in network administrators clearly feeling the problem that the rules cannot take effect for a long time.
By splitting the original single rule tree into a large rule tree and a small rule tree, dynamically adjusting the location of rules added, and through rule merging and high-performance tree class search algorithms, ensure that the rules in both rule trees are in an effective state.
When the number of rules is much larger than the device flow table space capacity, this method significantly speeds up the entry rate of rules, reduces the investment cost of network equipment, and avoids resource occupation problems caused by rule overflow.
Smart Images

Figure CN119071225B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of rule trees, and in particular to a large and small rule tree method for enabling newly added flow table rules to take effect quickly in a massive flow table. Background Art
[0002] Current network devices use multi-group rule flow table functions for network access control. In order to ensure high-performance packet processing capabilities, they mainly use dictionary trees or other tree algorithms to implement flow table rule searches. Tree algorithms have a very high search speed when matching rules.
[0003] When the number of rules in a rule tree is small, the tree-based algorithm takes a short time to recompile and build, allowing the rules to take effect without the network administrator noticing. However, when the number of rules in a rule tree exceeds several million or tens of millions, the time required to build the rule tree based on the current CPU hardware main frequency speed will allow the administrator to clearly notice that the newly added rules are taking a long time to take effect. The more rules there are, the longer it will take for the new flow table rules to take effect. Therefore, when faced with massive flow tables, the flow table space capacity is usually limited, forcing network administrators to merge address segments of similar network segments to compress the number of flow table rules and reduce the time it takes for the rules to take effect.
[0004] However, the method of limiting the capacity of the flow table space and forcing network administrators to merge similar address segments and compress the number of flow table rules is only a temporary solution and does not address the root cause. It will not only increase the cost of personnel investment, but also become ineffective in scenarios where the number of rules is far greater than the capacity of the device flow table space. Summary of the invention
[0005] The purpose of the present invention is to provide a large and small rule tree method for quickly taking effect on newly added flow table rules in a massive flow table, and to solve the following technical problems:
[0006] How to reduce the rule effectiveness time when the number of rules is much larger than the device flow table space capacity.
[0007] The purpose of the present invention can be achieved through the following technical solutions:
[0008] A large and small rule tree method for quickly taking effect on newly added flow table rules in a massive flow table, the algorithm comprising:
[0009] S1: Add rules. According to the upper limit of the rule entries in the rule tree, determine whether the time for rebuilding the tree exceeds the maximum tolerance time for the rule to take effect, and decide to which rule tree the rule will be added.
[0010] S2: rule merging, the timer loop checks the current number of rule entries in the small rule tree, and automatically merges the rule entries in the small rule tree into the large rule tree when the current number of rule entries in the small rule tree exceeds the lower limit of rule merging;
[0011] S3: Rule matching. According to the fields in the input network traffic packet, perform a serial search in the size rule tree through a tree - type search algorithm to make all the rules in the size rule tree effective.
[0012] Furthermore, the process of rule addition in S1 includes:
[0013] S11: Create two rule trees with different capacities, namely a large rule tree and a small rule tree. The capacity of the small rule tree is set such that the time required to build the tree when the rules are fully configured is less than or equal to the maximum tolerance time for the large rule tree to become effective, and the capacity of the large rule tree is the maximum capacity that the corresponding hardware can bear;
[0014] S12: Set the upper limit of the large rule tree, that is, when exceeding the upper limit value, the tree - building time will be greater than the maximum tolerance time for the rule to become effective;
[0015] S13: Set the upper limit value and the lower limit value for rule merging of the small rule tree. The upper limit value for rule merging indicates that rule merging needs to be immediately executed when exceeded, and the lower limit value for rule merging indicates that rule merging will not be executed when lower than the lower limit value;
[0016] S14: After receiving a new flow table rule, parse out the search fields of the tree - type algorithm. According to the tree - type search algorithm, search for the newly added rule entries in the large and small rule trees. If there are duplicate rules, return that the added rule is duplicate and the rule addition ends. Otherwise, proceed to step S15;
[0017] S15: When there are no duplicate rules, determine whether the current number of rule entries in the large rule tree exceeds the upper limit value.
[0018] Furthermore, the determination process in S15 includes:
[0019] Obtain the capacity occupancy value δ of all current rule entries through the formula
[0020] where i is any rule entry, n is the total number of rule entries in the current large rule tree, dx i is the packet size of the i - th rule entry, dx b is the standard value of dx i jm i is the encryption level of the i - th rule entry, jm y is the preset encryption level, ds i is the packet loss volume impact coefficient of the i - th rule entry, set by empirical fitting, sl is the number of nodes in the current large rule tree, and μ is the rule complexity impact coefficient, set by empirical fitting.
[0021] Furthermore, the determination process in S15 also includes:
[0022] By comparing the capacity occupancy value δ of all current rule entries with the preset capacity occupancy value δ x and comparing the total number of rule entries in the current large rule tree with the upper limit value;
[0023] If the total number of rule entries in the current large rule tree is greater than the upper limit value, directly add the newly added flow table rule to the small rule tree configuration;
[0024] If the total number of rule entries in the current large rule tree is less than the upper limit value and δ≥δ x , it is determined that the capacity occupancy value of all current rule entries is high, and the newly added flow table rule is directly added to the small rule tree configuration;
[0025] If the total number of rule entries in the current large rule tree is less than the upper limit value and δ<δ x , it is determined that the capacity occupancy value of all current rule entries is low, and the newly added flow table rule is added to the large rule tree configuration.
[0026] Furthermore, the judgment process in S15 also includes:
[0027] S151: When the current number of rule entries in the large rule tree does not exceed the upper limit value and the capacity occupancy value of all current rule entries is less than the preset capacity occupancy value, directly add the newly added flow table rule to the large rule tree configuration, update the large rule tree counter, and recompile the large rule tree to make the newly added flow table rule effective, and the rule addition is completed;
[0028] S152: When the current number of rule entries in the large rule tree has exceeded the upper limit value, or although it has not exceeded the upper limit value but the capacity occupancy value of all current rule entries is greater than the preset capacity occupancy value, add the newly added flow table rule to the small rule tree configuration, update the small rule tree counter, and recompile the small rule tree to make the newly added flow table rule effective;
[0029] S153: Judge whether the current number of rule entries in the small rule tree exceeds the rule merging upper limit value. If it exceeds the rule merging upper limit value, trigger the rule merging process and the rule addition is completed. If it does not exceed the rule merging upper limit value, the rule addition is directly completed.
[0030] Furthermore, the process of rule merging in S2 includes:
[0031] S21: Create a rule merging timer and judge whether the current number of rule entries in the small rule tree exceeds the rule merging lower limit value. If not, perform a loop judgment. Otherwise, proceed to step S22;
[0032] S22: Merge all current rule entries in the small rule tree into the large rule tree rule configuration to form a new large rule tree configuration;
[0033] S23: Create a running copy of the large rule tree according to the configuration of the new large rule tree;
[0034] S24: After the compilation of the running copy of the large rule tree is completed, replace the running original of the large rule tree in the original rule matching process with the running copy of the large rule tree, making the running copy of the large rule tree become the running original, and completing the replacement of the running original and copy;
[0035] S25: Delete the replaced copy of the large rule tree to release the memory space, and the rule merging is completed.
[0036] Further, the process of rule matching in S3 includes:
[0037] S31: Analyze the input network traffic packet, and parse out the tree class algorithm search fields required by the tree class search algorithm from the network traffic packet;
[0038] S32: Use the tree class algorithm search fields parsed out from the network traffic packet, and perform rule matching in the large rule tree using the tree class search algorithm to determine whether the rule is hit. If so, proceed to step S33; otherwise, proceed to step S34;
[0039] S33: Dispose of the network traffic packet according to the action field corresponding to the rule;
[0040] S34: Search for the small rule tree, use the tree class algorithm search fields parsed out from the network traffic packet, and perform rule matching in the small rule tree using the tree class search algorithm to determine whether the rule is hit. If so, proceed to step S35; otherwise, proceed to step S36;
[0041] S35: Dispose of the network traffic packet according to the action field corresponding to the rule;
[0042] S36: Dispose of the network traffic packet according to the system default rule action field.
[0043] Further, the tree class algorithm search fields include the source address, destination address, protocol number, source port number, and destination port number, and the tree class algorithm search fields of the large and small rule trees are different.
[0044] The beneficial effects of the present invention:
[0045] (1) The present invention splits the original single regular tree into a large regular tree that does not care about the tree building compilation time but has a huge regular capacity and a small regular tree that focuses on the tree building compilation time but has a limited regular capacity. By dynamically adjusting the position of rule addition and adjusting the rule matching mode of network traffic packets, the two regular trees are serially matched to ensure that the rules in the two regular trees are effective at the same time, so as to ensure that when the number of rules is much larger than the device flow table space capacity, by using a high-performance tree-based search algorithm, the problem that the large number of flow table rules affects the effective time of newly added flow table rules for too long is solved.
[0046] (2) The present invention splits the original single regular tree into a large regular tree that does not care about the tree building compilation time but has a huge regular capacity and a small regular tree that focuses on the tree building compilation time but has a limited regular capacity, which can effectively reduce the network device investment cost in the scenario of high-performance and large number of flow table rules. By setting the upper limit value and lower limit value of regular merging for the small regular tree, not only the risk that the tree building time is greater than the maximum tolerable time for rule effectiveness can be avoided, but also the resource occupation caused by frequent tree building of the large regular tree can be reduced, and the work efficiency is improved.
[0047] (3) The present invention compares the capacity occupancy value δ of all current rule entries with the preset upper limit value δ x and compares the total number of rule entries in the current large regular tree with the upper limit value. By combining the analysis of two different categories of data, an accurate judgment can be made on whether the current number of rule entries exceeds the upper limit value, and according to the judgment result, it is decided which regular tree the subsequent newly added rule entries will be added to, so as to ensure that the effective duration of the subsequent newly added rule entries will not be greatly affected, and the effect of accelerating the rule effectiveness speed is achieved when the number of rules is much larger than the device flow table space capacity.
[0048] (4) The present invention can make an accurate judgment on whether the current number of rule entries exceeds the upper limit value by combining the analysis of two different categories of data. By setting like this, when there is a risk that the tree building compilation time of the rules in the network device exceeds the maximum tolerable time for rule effectiveness, by judging whether the current number of rule entries in the large regular tree exceeds the upper limit value, it can be judged whether the effectiveness speed of the current large regular tree is normal. When it is judged that the effectiveness speed of the current large regular tree is slow, each newly added rule in the subsequent will fall into the small regular tree, so that the newly added flow table rules can take effect quickly, and the problem that the large number of flow table rules affects the effective time of newly added flow table rules for too long when using a high-performance tree-based search algorithm is solved.
[0049] (5) When it is determined that the current number of rule entries in the small rule tree exceeds the lower limit value of rule merging, all the current rule entries in the small rule tree are merged into the rule configuration of the large rule tree, the original main copy of the large rule tree in the original rule matching process is replaced with a copy of the large rule tree for operation, and finally the replaced copy of the large rule tree is deleted. By such settings, it can be ensured that the small rule tree will not have the problem of rule overflow affecting the effective time of newly added flow table rules, so as to ensure that when the number of rules is much larger than the capacity of the device flow table space, the effective time of the rules can still be in a relatively fast state. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] The present invention will be further described below with reference to the accompanying drawings.
[0051] Figure 1 is a flowchart of a method of a large and small rule tree for quickly making newly added flow table rules effective in a large number of flow tables in the present invention;
[0052] Figure 2 is a conceptual diagram of the rule addition process in the present invention;
[0053] Figure 3 is a flowchart of the rule addition process in the present invention;
[0054] Figure 4 is a flowchart of the judgment process in S15 in the present invention;
[0055] Figure 5 is a conceptual diagram of the rule merging process in the present invention;
[0056] Figure 6 is a flowchart of the rule merging process in the present invention;
[0057] Figure 7 is a conceptual diagram of the rule matching process in the present invention;
[0058] Figure 8 is a flowchart of the rule matching process in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0059] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0060] Please refer to Figure 1 - Figure 8 As shown, in one embodiment, the present application provides a method of a large and small rule tree for quickly making newly added flow table rules effective in a large number of flow tables. The algorithm includes:
[0061] S1: Add rules. According to the upper limit of the rule entries in the rule tree, determine whether the time for rebuilding the tree exceeds the maximum tolerance time for the rule to take effect, and decide to which rule tree the rule will be added.
[0062] S2: rule merging, the timer loop checks the current number of rule entries in the small rule tree, and automatically merges the rule entries in the small rule tree into the large rule tree when the current number of rule entries in the small rule tree exceeds the lower limit of rule merging;
[0063] S3: rule matching, based on the fields in the input network traffic message, serially search in the large and small rule trees through the tree search algorithm, so that all the rules in the large and small rule trees are in effect;
[0064] Through the above technical solution, when this embodiment is used, firstly, according to the upper limit value of the rule entries in the large and small rule trees, it is confirmed whether the tree reconstruction time exceeds the maximum tolerance time for the rule to take effect, and it is decided to which rule tree the rule is added to, so as to ensure that the tree reconstruction time required for the newly added flow table rule is less than the maximum tolerance time for the rule to take effect, and then the current number of rule entries in the small rule tree is checked through a timer loop, and when the current number of rule entries in the small rule tree exceeds the lower limit value of the rule merger, the rule entries in the small rule tree are automatically merged into the large rule tree, so as to ensure that the small rule tree will not have rule overflows that affect the effective time of the newly added flow table rules, and finally, according to the fields in the input network traffic message, the large and small rule trees are serially searched through the tree class search algorithm, so that the rules in the large and small rule trees are all in effect;
[0065] Through such settings, it can split the original single rule tree into a large rule tree that does not care about the tree compilation time but has a large rule capacity, and a small rule tree that focuses on the tree compilation time but has a limited rule capacity. It can also dynamically adjust the position where the rules are added, and adjust the network traffic message rule matching mode to match the two rule trees in series to ensure that the rules in the two rule trees are valid at the same time. This ensures that when the number of rules is much larger than the device flow table space capacity, the problem of the long time it takes for new flow table rules to take effect due to the large number of flow table rules can be solved by using a high-performance tree search algorithm.
[0066] See also Figure 2 and Figure 3 As shown, the process of adding rules in S1 includes:
[0067] S11: Create two rule trees with different capacities, a large rule tree and a small rule tree. The capacity of the small rule tree is set to a value that the tree building time required when the rules are fully configured is less than or equal to the maximum tolerance time for the large rule tree to take effect. The capacity of the large rule tree is the maximum capacity that the corresponding hardware can bear.
[0068] S12: Set the upper limit of the large rule tree, that is, when exceeding the upper limit value, the tree building time will be greater than the maximum tolerable time for the rule to take effect;
[0069] S13: Set the upper limit value and the lower limit value for rule merging of the small rule tree. The upper limit value for rule merging indicates that rule merging needs to be immediately executed when exceeded, and the lower limit value for rule merging indicates that rule merging will not be executed when lower than the lower limit value;
[0070] S14: After receiving a new flow table rule, parse out the tree - type algorithm search fields. According to the tree - type search algorithm, search for the newly added rule entries in the large and small rule trees. If there are duplicate rules, return that the added rule is duplicate and the rule addition ends. Otherwise, proceed to step S15;
[0071] S15: When there are no duplicate rules, determine whether the current number of rule entries in the large rule tree exceeds the upper limit value;
[0072] Through the above - mentioned technical solution, this embodiment provides a process for adding rules. First, create two rule trees with different capacities, namely a large rule tree and a small rule tree, and set the capacity of the small rule tree so that the tree building time when the rules are fully configured is less than or equal to the maximum tolerable time for the large rule tree to take effect. The capacity of the large rule tree is the maximum capacity that the corresponding hardware can bear. Subsequently, set the upper limit of the large rule tree, that is, when exceeding the upper limit value, the tree building time will be greater than the maximum tolerable time for the rule to take effect;
[0073] After that, set the upper limit value and the lower limit value for rule merging of the small rule tree. The upper limit value for rule merging indicates that rule merging needs to be immediately executed when exceeded, otherwise there is a risk that the tree building time will be greater than the maximum tolerable time for the rule to take effect. The lower limit value for rule merging indicates that rule merging will not be executed when lower than the lower limit value, reducing the resource occupation caused by frequent tree building of the large rule tree. Finally, after receiving a new flow table rule, parse out the tree - type algorithm search fields. According to the tree - type search algorithm, search for the newly added rule entries in the large and small rule trees. If there are duplicate rules, return that the added rule is duplicate and the rule addition ends. When there are no duplicate rules, determine whether the current number of rule entries in the large rule tree exceeds the upper limit value;
[0074] By setting like this, by splitting the original single rule tree into a large rule tree that does not care about the tree building compilation time but has a large rule capacity and a small rule tree that focuses on the tree building compilation time but has a limited rule capacity, the network device investment cost in high - performance and massive flow table rule scenarios can be effectively reduced. And by setting the upper limit value and the lower limit value for rule merging of the small rule tree, not only can the risk that the tree building time is greater than the maximum tolerable time for the rule to take effect be avoided, but also the resource occupation caused by frequent tree building of the large rule tree can be reduced, improving the work efficiency.
[0075] The judgment process in S15 includes:
[0076] Obtained by the formula Calculate the capacity occupancy value δ of all current rule entries;
[0077] Among them, i is any rule entry, n is the total number of rule entries in the current large rule tree, dx i is the data packet size of the i-th rule entry, dx b is for dx i The standard value of, the above standard value can be selected and set according to the allowable error in the empirical data, jm i is the encryption level of the i-th rule entry, jm y is the preset encryption level, ds i is the data packet loss volume influence coefficient of the i-th rule entry, set by empirical fitting, sl is the number of nodes in the current large rule tree, μ is the rule complexity influence coefficient, set by empirical fitting;
[0078] Through the above technical solution, this embodiment provides the capacity occupancy value δ of all current rule entries. Obviously, the larger the data packet size and encryption level of the i-th rule entry, and the fewer the number of nodes in the current large rule tree, the larger the capacity occupancy value of all current rule entries. On the contrary, when the data packet size and encryption level of the i-th rule entry are lower, and the number of nodes in the current large rule tree is more, the capacity occupancy value of all current rule entries is smaller. Through this calculation method, the usage ratio of all rule entries in the current large rule tree can be reflected, so as to provide accurate data for subsequent judgment on whether the current number of rule entries in the large rule tree exceeds the upper limit value.
[0079] The judgment process in S15 further includes:
[0080] By comparing the capacity occupancy value δ of all current rule entries with the preset capacity occupancy value δ x And compare the total number of rule entries in the current large rule tree with the upper limit value;
[0081] If the total number of rule entries in the current large rule tree is greater than the upper limit value, directly add the new flow table rule to the small rule tree configuration;
[0082] If the total number of rule entries in the current large rule tree is less than the upper limit value, and δ≥δ x , judge that the capacity occupancy value of all current rule entries is high, and directly add the new flow table rule to the small rule tree configuration;
[0083] If the total number of rule entries in the current large rule tree is less than the upper limit value, and δ<δ x , judge that the capacity occupancy value of all current rule entries is low, and add the new flow table rule to the large rule tree configuration;
[0084] Through the above technical solution, in this embodiment, the capacity occupancy value δ of all current rule entries is compared with the preset upper limit value δ x and the total number of rule entries in the current large rule tree is compared with the upper limit value. By analyzing by combining two different categories of data, an accurate judgment can be made on whether the current number of rule entries exceeds the upper limit value, and based on the judgment result, a decision can be made on which rule tree to add the subsequent newly added rule entries to, so as to ensure that the effective duration of the subsequent newly added rule entries will not be greatly affected, and the effect of accelerating the rule effective speed can be achieved when the number of rules is much larger than the device flow table space capacity;
[0085] It should be noted that the above preset capacity occupancy value δ x can be fitted and set based on the maximum capacity borne by the corresponding hardware of the large rule tree.
[0086] Please refer to Figure 2 and Figure 4 as shown, the judgment process in S15 further includes:
[0087] S151: When the current number of rule entries in the large rule tree does not exceed the upper limit value and the capacity occupancy value of all current rule entries is less than the preset capacity occupancy value, directly add the newly added flow table rule to the large rule tree configuration, update the large rule tree counter, and recompile the large rule tree to make the newly added flow table rule effective, and the rule addition is completed;
[0088] S152: When the current number of rule entries in the large rule tree has exceeded the upper limit value, or has not exceeded the upper limit value but the capacity occupancy value of all current rule entries is greater than the preset capacity occupancy value, add the newly added flow table rule to the small rule tree configuration, update the small rule tree counter, and recompile the small rule tree to make the newly added flow table rule effective;
[0089] S153: Judge whether the current number of rule entries in the small rule tree exceeds the rule merging upper limit value. If it exceeds the rule merging upper limit value, trigger the rule merging process and the rule addition is completed. If it does not exceed the rule merging upper limit value, the rule is directly added and completed;
[0090] Through the above technical solution, by combining and analyzing two different categories of data, an accurate judgment can be made on whether the current number of rule entries exceeds the upper limit value. With such a setting, when there is a risk that the rule building and compilation time in the network device exceeds the maximum tolerable time for rule activation, by judging whether the current number of rule entries in the large rule tree exceeds the upper limit value, it can be determined whether the activation speed of the current large rule tree is normal. When it is judged that the activation speed of the current large rule tree is slow, each newly added rule will fall into the small rule tree in the subsequent process, enabling the newly added flow table rules to be activated quickly, and solving the problem that the long activation time of the massive flow table rules affects the newly added flow table rules when using the high-performance tree-based search algorithm.
[0091] Please refer to Figure 5 and Figure 6 As shown, the process of rule merging in S2 includes:
[0092] S21: Create a rule merging timer, and check whether the current number of rule entries in the small rule tree exceeds the lower limit value of rule merging. If not, perform a loop check; otherwise, proceed to step S22.
[0093] S22: Merge all the current rule entries in the small rule tree into the rule configuration of the large rule tree to form a new large rule tree configuration.
[0094] S23: Create a running copy of the large rule tree according to the new large rule tree configuration.
[0095] S24: After the compilation of the running copy of the large rule tree is completed, replace the running original of the large rule tree in the original rule matching process with the running copy of the large rule tree, making the running copy of the large rule tree become the running original, and completing the replacement of the running original and copy.
[0096] S25: Delete the replaced copy of the large rule tree to release the memory space, and the rule merging is completed.
[0097] Through the above technical solution, in this embodiment, a rule merging timer is created, and it is checked whether the current number of rule entries in the small rule tree exceeds the lower limit value of rule merging. If not, a loop check is performed; if so, all the current rule entries in the small rule tree are merged into the rule configuration of the large rule tree to form a new large rule tree configuration, and a running copy of the large rule tree is created according to the new large rule tree configuration. After waiting for the compilation of the running copy of the large rule tree to be completed, the running original of the large rule tree in the original rule matching process is replaced with the running copy of the large rule tree, making the running copy of the large rule tree become the running original, and completing the replacement of the running original and copy. Finally, the replaced copy of the large rule tree is deleted to release the memory space, and the rule merging is completed.
[0098] When it is determined that the current number of rule entries in the small rule tree exceeds the lower limit of rule merging, all current rule entries in the small rule tree are merged into the rule configuration of the large rule tree, and the running original of the large rule tree in the original rule matching process is replaced with the running copy of the large rule tree, and finally the replaced copy of the large rule tree is deleted. Through such settings, it can be ensured that the small rule tree will not have rule overflows that affect the effective time of the newly added flow table rules, thereby ensuring that when the number of rules is much larger than the flow table space capacity of the device, the rule effectiveness time can still be kept at a faster state.
[0099] See also Figure 7 and Figure 8 As shown, the rule matching process in S3 includes:
[0100] S31: parsing the input network traffic message, parsing the tree algorithm search field required by the tree search algorithm from the network traffic message;
[0101] S32: searching the field by the tree algorithm parsed from the network traffic message, and matching the rules in the large rule tree by using the tree search algorithm to determine whether the rule is matched. If yes, proceed to step S33; otherwise, proceed to step S34;
[0102] S33, processing the network traffic message according to the behavior field corresponding to the rule;
[0103] S34: Searching for a small rule tree, searching for fields through a tree algorithm parsed from the network traffic message, and using a tree search algorithm to match rules in the small rule tree to determine whether the rule is matched. If yes, proceed to step S35, otherwise, proceed to step S36;
[0104] S35: Processing network traffic messages according to the behavior field corresponding to the rule;
[0105] S36: Processing network traffic messages according to the system default rule behavior field;
[0106] Through the above technical solution, this embodiment first parses the input network traffic message, parses the tree algorithm search field required by the tree search algorithm from the network traffic message, and then uses the tree algorithm search field parsed from the network traffic message to match the rules in the large rule tree using the tree search algorithm to determine whether the rule is hit. If the rule is hit, the network traffic message is processed according to the behavior field corresponding to the rule. Otherwise, the small rule tree is searched, the tree algorithm search field parsed from the network traffic message is used, and the tree search algorithm is used to match the rules in the small rule tree to determine whether the rule is hit. If the rule is hit, the network traffic message is processed according to the behavior field corresponding to the rule. Otherwise, the network traffic message is processed according to the system default rule behavior field.
[0107] By setting it in this way, serial search in the size rule tree through the tree - type search algorithm can make all the rules in the size rule tree in an effective state, thus ensuring that the size rule tree can be used normally. Furthermore, it can ensure that when used subsequently, even when the number of rules is much larger than the capacity of the device flow table space, the speed of rule effectiveness can still be guaranteed.
[0108] The search fields of the tree - type algorithm include source address, destination address, protocol number, source port number, and destination port number, and the search fields of the tree - type algorithm of the size rule tree are different;
[0109] Through the above - mentioned technical solution, when in use, by determining different search fields of the tree - type algorithm for the size rule tree, which are defined in the header of the data packet, it can ensure that data can be correctly and efficiently transmitted from one node to another node.
[0110] The above has described an embodiment of the present invention in detail, but the content described is only the preferred embodiment of the present invention and cannot be considered as limiting the scope of implementation of the present invention. All equivalent changes and improvements made according to the scope of the application of the present invention should still fall within the scope covered by the patent of the present invention.
Claims
1. A method for quickly taking effect of new flow table rules in a massive flow table, characterized in that: include: S11: Create two rule trees with different capacities: a large rule tree and a small rule tree; The capacity of the small rule tree is set to the time required to build the tree when the rules are fully configured, which is less than or equal to the maximum tolerance time for the rules to take effect. The capacity of the large rule tree is the maximum capacity that the corresponding hardware can carry. S12: Setting an upper limit value of direct addition of a large rule tree, that is, after exceeding the upper limit value of direct addition, the tree building time will be greater than the maximum tolerance time for the rule to take effect; S13: Setting the upper limit value and the lower limit value of rule merging of small rule trees; S14: parse the five-element field of the newly added flow table rule, and search for the rule entry of the newly added flow table rule in the large and small rule trees according to the tree search algorithm. If there is no duplication, proceed to step S15, otherwise end; S15: If the total number of rule entries in the current large rule tree is less than the upper limit of adding directly and δ<δ x , add the new flow table rules to the big rule tree configuration, update the counter of the big rule tree and recompile the big rule tree; If the total number of rule entries in the current large rule tree is less than the upper limit of adding directly and δ≥δ x , or the total number of rule entries in the current large rule tree is greater than the upper limit, the newly added flow table rules are directly added to the small rule tree configuration, the counter of the small rule tree is updated and the small rule tree is recompiled; δ is the capacity occupied by all current rule entries, δ x is the preset capacity occupancy value; Check through a timer loop whether the number of current rule entries in the small rule tree exceeds the lower limit of rule merging. If so, merge the rule entries in the small rule tree into the large rule tree, otherwise perform rule matching; Rule matching: Based on the five-element field in the input network traffic message, a tree search algorithm is used to serially search in the large and small rule trees, so that all the rules in the large and small rule trees are in effect.
2. According to claim 1, a large and small rule tree method for allowing newly added flow table rules to take effect quickly in a massive flow table is characterized in that: By formula Calculate and obtain the capacity occupancy value μ of all current rule entries; Among them, i is any rule entry, n is the total number of rule entries in the current large rule tree, dx i is the packet size of the ith rule entry, dx b dx i The standard value of jm i is the encryption level of the i-th rule entry, jm y is the default encryption level, ds i is the impact coefficient of packet loss of the ith rule entry, which is set according to empirical fitting; sl is the number of nodes in the current large rule tree; μ is the impact coefficient of rule complexity, which is set according to empirical fitting.
3. According to claim 1, a large and small rule tree method for allowing newly added flow table rules to take effect quickly in a massive flow table is characterized in that: After merging the rule entries in the small rule tree into the large rule tree to obtain a new large rule tree, the method further includes: S23: Create a big rule tree running copy according to the new big rule tree configuration; S24: After the big rule tree running copy is compiled, the big rule tree running original in the original rule matching process is replaced with the big rule tree running copy, so that the big rule tree running copy becomes the running original, and the running original and copy replacement is completed; S25: Delete the replaced large rule tree copy, release memory space, and complete the rule merging.
4. According to claim 3, a large and small rule tree method for allowing newly added flow table rules to take effect quickly in a massive flow table is characterized in that: The rule matching process includes: S31: parsing the input network traffic message, parsing the five-element field required by the tree search algorithm from the network traffic message; S32: using the five-element field parsed from the network traffic message, and using the tree search algorithm to match the rule in the large rule tree, to determine whether the rule is hit, if yes, proceed to step S33, otherwise, proceed to step S34; S33, processing the network traffic message according to the behavior field corresponding to the rule; S34: searching the small rule tree, using the five-element field parsed from the network traffic message, and using the tree search algorithm to match the rule in the small rule tree, to determine whether the rule is hit, if yes, proceed to step S35, otherwise, proceed to step S36; S35: Processing network traffic messages according to the behavior field corresponding to the rule; S36: Process the network traffic message according to the system default rule behavior field.
5. According to claim 1, a large and small rule tree method for allowing newly added flow table rules to take effect quickly in a massive flow table is characterized in that: The five-element field includes source address, destination address, protocol number, source port number, and destination port number.
Citation Information
Patent Citations
Data stream classifying method
CN1494278A
Batch incremental update
US20140279850A1