Network security monitoring method, device and system based on cloud gateway
By parsing and detecting network traffic data of user terminals in the network traffic data of user terminal identifiers at the cloud gateway, and performing risk detection and handling based on pre-configured security monitoring rules, the problem of long network traffic data transmission paths and high bandwidth consumption of user terminals is solved, and efficient risk monitoring and handling is achieved.
Patent Information
- Application Number
- CN202411134533.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-19
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2044-08-19
AI Technical Summary
In existing technologies, network traffic data from user terminals needs to be transmitted to network protection devices through multiple network devices, resulting in long transmission paths, high bandwidth consumption, and large latency, and making it difficult to effectively identify and manage risks to user terminals.
By receiving VXLAN network traffic data from user terminals at the cloud gateway, parsing the user terminal identifier, and performing risk detection and handling based on pre-configured security monitoring rules, NDR devices are used to perform security monitoring before network traffic data enters the communication backbone network.
It enables near-source detection of network traffic data, shortens the transmission path, improves the efficiency of risk detection and handling, and enhances the flexibility and effectiveness of risk monitoring.
Smart Images

Figure CN119094175B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security, and in particular to a network security monitoring method, apparatus and system based on a cloud gateway. Background Technology
[0002] In the field of network security, network protection devices are often configured close to the origin server. User terminal network traffic data reaches these devices through various network devices such as passive optical network devices, cloud gateways, and broadband access servers. These devices perform risk detection on network traffic data to ensure the network security of the origin server.
[0003] The drawback of this network security protection method is that network traffic data needs to pass through multiple network devices to be transmitted from the user terminal to the network protection device, resulting in long transmission paths, high bandwidth consumption, and significant latency. Furthermore, this method makes it difficult to effectively identify and manage risk sources at the user terminal, and it is not convenient to customize security monitoring rules for the user terminal.
[0004] How to improve the effectiveness of network security monitoring of user terminal access gateways is the technical problem that this application aims to solve. Summary of the Invention
[0005] The purpose of this application is to provide a network security monitoring method, apparatus, and system based on a cloud gateway, so as to improve the effectiveness of network security monitoring of user terminal access gateways.
[0006] Firstly, a network security monitoring method based on a cloud gateway is provided, applied to a network detection and response (NDR) device, wherein the NDR device is communicatively connected to the cloud gateway, and the method includes:
[0007] The cloud gateway receives virtual extended local area network (VXLAN) traffic data from user terminals forwarded by the cloud gateway. The VXLAN network traffic data is used to request network access.
[0008] Parse the VXLAN network traffic data to obtain the user terminal identifier encapsulated in the VXLAN network traffic data;
[0009] Risk detection is performed on the VXLAN network traffic data based on the pre-configured security monitoring rules corresponding to the user terminal identifier;
[0010] If a risk is detected in the VXLAN network traffic data, the cloud gateway is instructed to perform risk handling on the user terminal corresponding to the user terminal identifier according to the pre-configured security monitoring rules.
[0011] Secondly, a network security monitoring system based on a cloud gateway is provided, including:
[0012] At least one user terminal is used to send network traffic data to the passive optical network device;
[0013] The passive optical network device, which is communicatively connected to the at least one user terminal, is used to perform VXLAN encapsulation on the network traffic data of the user terminal according to the user terminal identifier to obtain VXLAN network traffic data, and send the VXLAN network traffic data to the cloud gateway.
[0014] The cloud gateway, which is communicatively connected to the passive optical network device, is used to forward the VXLAN network traffic data to the network detection and response (NDR) device.
[0015] The NDR device, which is communicatively connected to the cloud gateway, is used to perform the cloud gateway-based network security monitoring method as described in the first aspect.
[0016] Thirdly, a network security monitoring device based on a cloud gateway is provided, applied to a network detection and response (NDR) device, wherein the NDR device is communicatively connected to the cloud gateway, comprising:
[0017] The receiving module receives the Virtual Extended Local Area Network (VXLAN) network traffic data of the user terminal forwarded by the cloud gateway. The VXLAN network traffic data is used to request network access.
[0018] The parsing module parses the VXLAN network traffic data to obtain the user terminal identifier encapsulated in the VXLAN network traffic data;
[0019] The detection module performs risk detection on the VXLAN network traffic data based on the pre-configured security monitoring rules corresponding to the user terminal identifier;
[0020] If the handling module detects a risk in the VXLAN network traffic data, it instructs the cloud gateway to perform risk handling on the user terminal corresponding to the user terminal identifier according to the pre-configured security monitoring rules.
[0021] Fourthly, an electronic device is provided, comprising a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the steps of the method of the first aspect.
[0022] Fifthly, a computer-readable storage medium is provided on which a computer program is stored, which, when executed by a processor, implements the steps of the method of the first aspect.
[0023] In a sixth aspect, a computer program product is provided, comprising a non-transitory computer-readable storage medium storing a computer program operable to cause a computer to perform some or all of the steps of the method of the first aspect.
[0024] In this embodiment, firstly, the system receives Virtual Extended Local Area Network (VXLAN) network traffic data from a user terminal forwarded by the cloud gateway. This VXLAN network traffic data is used to request network access. Then, the VXLAN network traffic data is parsed to obtain the user terminal identifier encapsulated within it. Next, risk detection is performed on the VXLAN network traffic data based on pre-configured security monitoring rules corresponding to the user terminal identifier. If a risk is detected in the VXLAN network traffic data, the cloud gateway is instructed to perform risk mitigation on the user terminal corresponding to the user terminal identifier according to the pre-configured security monitoring rules. This solution is applied to NDR devices communicating with the cloud gateway and enables security monitoring before network traffic data enters the communication backbone network. On one hand, this solution enables near-source detection of network traffic data, effectively shortening the transmission path of network traffic data before security monitoring, preventing risky network traffic data from occupying bandwidth resources in the network, and improving the efficiency of risk detection and mitigation. On the other hand, this solution enables risk detection and mitigation for specific user terminals based on the user terminal identifier and pre-configured security monitoring rules, effectively improving the flexibility and effectiveness of risk monitoring. Attached Figure Description
[0025] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0026] Figure 1a This is a schematic diagram of a network security protection scenario;
[0027] Figure 1b This is one of the flowcharts illustrating an embodiment of the network security monitoring method based on a cloud gateway in this application;
[0028] Figure 1c This is one of the scenario diagrams illustrating an embodiment of the network security monitoring method based on a cloud gateway in this application;
[0029] Figure 2a This is a second schematic flowchart of a network security monitoring method based on a cloud gateway, as described in one embodiment of this application.
[0030] Figure 2b This is a network topology diagram of a network security monitoring method based on a cloud gateway, as described in one embodiment of this application.
[0031] Figure 3a This is the third flowchart of an embodiment of the network security monitoring method based on a cloud gateway in this application;
[0032] Figure 3b This is a second scenario illustration of a network security monitoring method based on a cloud gateway, as described in one embodiment of this application.
[0033] Figure 3c This is a third scenario illustration of a network security monitoring method based on a cloud gateway, as described in one embodiment of this application.
[0034] Figure 4 This is a schematic diagram of the structure of a cloud gateway-based network security monitoring system according to an embodiment of this application;
[0035] Figure 5 This is a partial structural diagram of a cloud gateway-based network security monitoring system according to an embodiment of this application;
[0036] Figure 6 This is a schematic diagram of the structure of a network security monitoring device based on a cloud gateway, according to one embodiment of this application. Detailed Implementation
[0037] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application. The drawing numbers in this application are only used to distinguish the various steps in the solution and are not used to limit the execution order of the various steps. The specific execution order is subject to the description in the specification.
[0038] In the field of cybersecurity, network security protection can be used to intervene and control network risks, ensuring the security of data transmission. Due to the complexity of network attacks, network security protection can specifically involve various security services and mechanisms, including physical security analysis techniques, network structure security analysis techniques, system security analysis techniques, and management security analysis techniques.
[0039] In terms of network security protection, risk monitoring can be achieved through a secure access gateway. A secure access gateway can meet various security needs of customers, including identity security, transmission encryption, access authorization, and log traceability. It provides a unified secure office access point, portal-style single sign-on, application (APP) security hardening, and mobile application data security for various mobile office scenarios, thus offering communication users a "one-stop" secure mobile office solution.
[0040] In practical applications, network security protection devices can be deployed at the origin server. See also Figure 1a If a user terminal requests network access, network traffic data can pass through the Optical Network Unit (ONU), Optical Line Terminal (OLT), cloud gateway connected to the cloud gateway controller, Broadband Remote Access Server (BRAS), and acceleration server to reach the protection device. The protection device performs security monitoring and, after confirming security, then enters the origin server.
[0041] In this approach, user terminals can initiate specific service access via network traffic data. This network traffic data then passes through multiple network devices before reaching the protection device, which can then identify and handle potentially risky network traffic data. This method not only requires consuming network resources to transmit potentially risky network traffic data, but also takes time, resulting in low efficiency in risk detection and handling.
[0042] To address the problems existing in related technologies, this application provides a network security monitoring method based on a cloud gateway, applied to a Network Detection and Response (NDR) device, wherein the NDR device is communicatively connected to the cloud gateway, such as... Figure 1b As shown, the method includes:
[0043] S11: Receive the Virtual Extended Local Area Network (VXLAN) network traffic data of the user terminal forwarded by the cloud gateway. The VXLAN network traffic data is used to request network access.
[0044] The aforementioned cloud gateway is a white-box gateway deployed in the cloud, capable of providing Layer 2 network capabilities, Layer 3 network capabilities, and security protection capabilities. It can also provide various functions such as PPPoE (Point-to-Point Protocol over Ethernet) dialing and tunnel initiation.
[0045] In this solution, after the network traffic data of the user terminal reaches the white box device, the cloud gateway can obtain the VXLAN network traffic data through traffic redirection and forward it to the NDR device, so that the NDR device can receive the aforementioned VXLAN network traffic data.
[0046] The VXLAN network traffic data is used to request network access for the user terminal. Optionally, the white-box device can perform VXLAN encapsulation on the network traffic data sent by the user terminal once. After the cloud gateway obtains the VXLAN network traffic data after the first encapsulation, it can perform a second VXLAN encapsulation, thereby forwarding the second encapsulated VXLAN network traffic data to the NDR device.
[0047] The aforementioned secondary encapsulation of VXLAN can be implemented using QinQ technology, also known as Stacked VLAN or Double VLAN. This can be based on the IEEE 802.1ad standard. Specifically, the user's private network VLAN tag is encapsulated within a public network VLAN tag, allowing packets to carry both layers of VLAN tags as they traverse the backbone network, i.e., the public network.
[0048] The aforementioned white-box device enables bidirectional data flow routing between user terminals via broadband network connections. This white-box device can include various network devices, such as OLTs, ONUs, and optical splitters.
[0049] An OLT (Optical Line Terminal) is a terminal device that can connect to an optical fiber trunk. An ONU (Optical Network Unit) can be further divided into active optical network units (PONs) and passive optical network units (ONUs). A passive optical network (PON) can use a single optical fiber to connect to the OLT, and then the OLT connects to the ONU. The ONU can provide data, IPTV (Internet Protocol Television), and voice services. Voice services can be implemented using an IAD (Integrated Access Device).
[0050] Optionally, in this step, the VXLAN network traffic data can be mirrored and forwarded to the NDR device by the cloud gateway.
[0051] S12: Parse the VXLAN network traffic data to obtain the user terminal identifier encapsulated in the VXLAN network traffic data.
[0052] In this step, the NDR device parses the VXLAN network traffic data to obtain the user terminal identifier.
[0053] Optionally, the user terminal identifier can be a VNI encapsulated in the VXLAN network traffic data header, which can identify the home group to which the user terminal belongs.
[0054] In practical applications, multiple different VXLAN virtual networks can be identified and distinguished by assigning VNIs (VXLAN Network Identifiers). One VNI can identify multiple user devices in, for example, a home environment. However, since only virtual machines on the same VXLAN can communicate with each other, there are certain limitations. A VNI occupies 24 bits in a data packet and can support the simultaneous existence of 16 million VXLANs, far exceeding the 4094 VLANs, thus adapting to large-scale tenant deployments.
[0055] S13: Perform risk detection on the VXLAN network traffic data based on the pre-configured security monitoring rules corresponding to the user terminal identifier.
[0056] In this step, the corresponding pre-configured security monitoring rules are determined based on the user terminal identifier identified in the previous steps, and then risk detection is performed using the adapted security monitoring rules. These security monitoring rules can be set based on the user terminal identifier; different user terminal identifiers can be pre-configured with different security monitoring rules, improving the flexibility of risk detection. Specifically, these security monitoring rules may include information such as security detection items for VXLAN network traffic data, the detection standards for each security detection item, and risk handling methods. If the user terminal identifier is a VNI, then the corresponding security monitoring rules can perform risk detection for the user group of that household unit.
[0057] S14: If a risk is detected in the VXLAN network traffic data, the cloud gateway is instructed to perform risk handling on the user terminal corresponding to the user terminal identifier according to the pre-configured security monitoring rules.
[0058] If a risk is detected in VXLAN network traffic data, this step executes risk mitigation based on the security monitoring rules corresponding to the user terminal identifier. Specifically, the NDR device can send relevant information required for risk mitigation to the cloud gateway, instructing the cloud gateway to perform mitigation actions on the user terminal corresponding to the aforementioned user terminal identifier. Mitigation methods may include, for example, service function access control and communication function restrictions, which can be implemented using information such as VNI, IP (Internet Protocol Address), and PORT.
[0059] If monitoring results indicate that VXLAN network traffic is secure, the cloud gateway can inject this VXLAN network traffic back into the access network to provide the necessary communication services to user terminals. For example, secure VXLAN network traffic can be injected back into the BRAS (Broadband Access Controller). The BRAS is a new type of access gateway for broadband network applications. Located at the edge layer of the backbone network, it enables data access to IP / ATM networks for user bandwidth. In practical applications, it can provide broadband internet access for commercial buildings and residential communities, IP VPN services based on IPSec (IP Security Protocol), build enterprise intranets, and facilitate wholesale services from ISPs to users.
[0060] The solution provided in this application is implemented using an NDR device, which can be used to monitor network traffic and network events in real time, and quickly detect and handle security threats. On one hand, this solution enables near-source detection of network traffic data, effectively shortening the transmission path of network traffic data before security monitoring, avoiding the occupation of bandwidth resources by risky network traffic data, and improving the efficiency of risk detection and handling. On the other hand, this solution can perform risk detection and handling for specific user terminals based on user terminal identifiers and pre-configured security monitoring rules, effectively improving the flexibility and effectiveness of risk monitoring.
[0061] The following is combined Figure 1c The scenario shown further illustrates this solution.
[0062] In this embodiment, user terminals such as mobile phones, tablets, and smart TVs can initiate network access requests through white-box devices. These white-box devices then transmit VXLAN network traffic data to the cloud gateway via traffic redirection. The cloud gateway forwards the VXLAN network traffic data to an NDR device for user security monitoring, identifying the user terminal by parsing the VNI. If security detection determines that the VXLAN network traffic data poses a risk, the cloud gateway executes the corresponding risk handling according to security monitoring rules on the identified user terminal, thereby achieving efficient risk control close to the risk source. If security detection determines that the VXLAN network traffic data is secure, the cloud gateway performs traffic reinjection into the access network, for example, into the BRAS, thereby providing the necessary communication functions to the user terminal through the backbone network.
[0063] The solution provided in this application utilizes a cloud gateway deployed behind the BRAS (Branded Access System) near the user terminal to obtain the VNI (Virtual Individual Name) identifier for user identification. This decentralizes the perception and scheduling of computing power to the cloud gateway side. In practical applications, it can access specific service networks based on the user's access to services and needs, while simultaneously mirroring user traffic to the NDR (Network Receiver) device. This allows the NDR device to fully utilize computing resources to identify attack sources and then synchronize the identified attack data to the cloud gateway for blocking malicious users. This solution ensures the security of users accessing the network while providing necessary network service functions to users who are deemed safe, guaranteeing a positive user experience. Furthermore, this solution reduces the impact on the cloud gateway's forwarding performance and effectively protects the user access network and the target origin server.
[0064] Based on the solutions provided in the above embodiments, optionally, such as Figure 2a As shown, in step S11 above, receiving the Virtual Extended Local Area Network (VXLAN) network traffic data of the user terminal forwarded by the cloud gateway includes:
[0065] S21: Receive the VXLAN network traffic data of the user terminal forwarded by the repeater of the cloud gateway to the traffic probe of the NDR device based on the traffic forwarding policy, wherein the traffic forwarding policy includes a forwarding mapping relationship between at least one repeater of the cloud gateway and at least one traffic probe of the NDR device.
[0066] In this embodiment of the application, the NDR device may specifically include at least one traffic probe. The traffic probe can be used to perform L4 (fourth layer) to L7 (seventh layer) deep analysis on the network data flow flowing through the critical path, detect network attacks such as hackers, Trojans, worms, viruses, spyware, protocol anomalies, DoS / DDoS in real time, and discover risks such as abnormal user traffic behavior.
[0067] Optional, see Figure 2b The topology diagram shown illustrates that the NDR device includes a security capability resource pool, which specifically comprises multiple traffic probes and an analysis platform communicatively connected to each traffic probe. The traffic probes can perform risk detection through the analysis platform. These traffic probes can perform necessary parsing on received VXLAN network traffic data and send relevant information for risk detection to the analysis platform, thereby utilizing the platform's reliable computing resources for efficient risk detection.
[0068] Optional, see Figure 2bThe topology diagram shown illustrates that the cloud gateway can specifically include multiple repeaters, each of which communicates with a white-box device on the user terminal side. The cloud gateway also includes a controller for policy control of the forwarding mapping relationships among the various repeaters. Specifically, the repeaters can be controlled to forward VXLAN network traffic data to the corresponding traffic probes by either pre-setting or adjusting the forwarding mapping relationships in real time.
[0069] Based on the solutions provided in the above embodiments, optionally, such as Figure 3a As shown, before step S21 above, that is, before receiving the VXLAN network traffic data of the user terminal forwarded by the cloud gateway's repeater to the NDR device's traffic probe based on the traffic forwarding policy, the method further includes:
[0070] S31: Send functional information of at least one traffic probe contained in the NDR device to the controller of the cloud gateway to instruct the controller of the cloud gateway to send traffic forwarding policies to each forwarder of the cloud gateway. The functional information includes the forwarding address and traffic processing capability information of the traffic probe. The traffic forwarding policy includes a forwarding mapping relationship constructed by the controller of the cloud gateway based on the functional information. The forwarding mapping relationship includes a mapping relationship between the VXLAN network identifier corresponding to at least one forwarder of the cloud gateway and the at least one traffic probe.
[0071] In the solution provided in this application embodiment, the functional information of each traffic probe is sent to the controller of the cloud gateway in advance to instruct the controller to configure the traffic forwarding strategy according to the actual function of each traffic probe, thereby improving the rationality of the forwarder's forwarding of VXLAN network traffic data and further improving the overall efficiency of risk detection.
[0072] The functional information includes the forwarding address and traffic processing capacity of the traffic probe. The controller can configure forwarding mapping relationships for the forwarding addresses of each traffic probe based on its traffic processing capacity. For example, for a traffic probe with strong traffic processing capabilities, multiple forwarders can be designated to forward all VXLAN network traffic data flowing through it to this single traffic probe, so as to make full use of the traffic probe's processing performance resources.
[0073] Optionally, if the functionality information of the traffic probe changes, the latest functionality information of the traffic probe can be sent to the controller of the cloud gateway in real time or at certain intervals to immediately instruct the controller to update the traffic forwarding policy.
[0074] The solution provided in this application embodiment can instruct the controller of the cloud gateway to configure a reasonable traffic forwarding policy, thereby controlling each forwarder of the cloud gateway to reasonably forward VXLAN network traffic data, so as to improve the overall efficiency of risk detection.
[0075] Optionally, the VXLAN network traffic is obtained by performing a first VXLAN encapsulation on the raw traffic sent by the passive optical network device to the user terminal and a second VXLAN encapsulation on the cloud gateway;
[0076] Specifically, parsing the VXLAN network traffic to obtain the user terminal identifier encapsulated in the VXLAN network traffic includes:
[0077] The second VXLAN encapsulation and the first VXLAN encapsulation of the VXLAN network traffic are parsed sequentially to obtain the VXLAN network identifier in the first VXLAN encapsulation.
[0078] Below, in conjunction with Figure 3b The scenario shown further illustrates this solution.
[0079] Step 1: The NDR device's traffic probes report functional information, including its own VXLAN remote IP address, to the cloud gateway's controller, providing a data basis for the controller to configure traffic forwarding policies.
[0080] Step 2: The cloud gateway controller can act as the cloud gateway management platform. This controller performs unified resource orchestration on each forwarder of the cloud gateway, configures traffic forwarding policies, and distributes the corresponding configurations to each forwarder. This enables VXLAN configuration for each forwarder and defines the VNI for the user group corresponding to each forwarder. Once the cloud gateway's forwarder receives VXLAN network traffic data from the white-box device, it mirrors and forwards the VXLAN network traffic data to the traffic probe of the NDR device according to the configured traffic forwarding policy. Specifically, the white-box device performs Layer 1 VXLAN encapsulation on the network traffic data, and the cloud gateway performs Layer 2 VXLAN encapsulation on the encapsulated VXLAN network traffic data.
[0081] Step 3: Perform VXLAN traffic mirroring and parsing. The traffic probe kernel performs VXLAN parsing on the outer layer encapsulated by the cloud gateway, and the traffic probe performs VXLAN parsing on the inner layer encapsulated by the white-box device through the application, to obtain the VNI in the header as the user terminal identifier. Various data information that needs to be detected can be extracted according to specific detection rules, and this information is sent to the NDR device's analysis platform.
[0082] Step 4: The NDR analysis platform can perform targeted risk detection based on the security monitoring rules corresponding to different user representations. The mapping between security monitoring rules and user terminal identifiers can be stored in the NDR analysis platform.
[0083] Step 5: If a risk is detected, the risky VNI and its handling policy are sent to the cloud gateway, instructing the cloud gateway to perform appropriate risk handling for the VNI. For example, risk handling can be achieved through blacklisting VNIs, IPs, and ports to effectively control the source of the risk. If the risk level is high, in practical applications, the VNI that initiated the attack can be directly blocked.
[0084] In addition, if the VXLAN network traffic data is determined to be secure after risk detection, the cloud gateway can be instructed to perform traffic back injection to the BRAS, thereby providing the user terminal with the required communication service functions through the backbone network CMNET.
[0085] Optionally, for VXLAN network traffic data identified as posing a risk, further risk information can be displayed on the page. Below, in conjunction with... Figure 3c The scenario shown is relevant to this solution.
[0086] For multiple different home users, raw traffic can be sent from the user terminal to the white-box device in their respective home. The white-box device performs VXLAN encapsulation on the raw traffic once to obtain VXLAN network traffic data. Then, the white-box device sends the VXLAN network traffic data to the cloud gateway, where a second VXLAN encapsulation is performed. The cloud gateway's repeater then forwards the double-encapsulated VXLAN network traffic data to the corresponding traffic probe of the NDR product according to the traffic forwarding policy. Subsequently, the traffic probe performs parsing and sends alarm logs and other information required for risk detection to the analysis platform. If the analysis platform detects that specific VXLAN network traffic data poses a risk, it can display a risk page based on the VNI corresponding to the risky VXLAN network traffic data. This risk page can display risk information and optional risk handling methods.
[0087] To address the problems existing in related technologies, embodiments of this application provide a network security monitoring system based on a cloud gateway, such as... Figure 4 As shown, it includes:
[0088] At least one user terminal is used to send network traffic data to the passive optical network device;
[0089] The passive optical network device, which is communicatively connected to the at least one user terminal, is used to perform VXLAN encapsulation on the network traffic data of the user terminal according to the user terminal identifier to obtain VXLAN network traffic data, and send the VXLAN network traffic data to the cloud gateway.
[0090] The cloud gateway, which is communicatively connected to the passive optical network device, is used to forward the VXLAN network traffic data to the network detection and response (NDR) device.
[0091] The NDR device, which is communicatively connected to the cloud gateway, is used to execute the cloud gateway-based network security monitoring method described in any of the above embodiments.
[0092] The system provided in this application embodiment allows a user terminal to send network traffic data to a passive optical network (PON) device connected to the communication network. The PON device then performs a VXLAN encapsulation to obtain VXLAN network traffic data and forwards it to a cloud gateway. The cloud gateway then forwards the VXLAN network traffic data to an NDR device. Before forwarding, the cloud gateway can perform a second VXLAN encapsulation on the already encapsulated VXLAN network traffic. The NDR device then receives the VXLAN network traffic data from the user terminal forwarded by the cloud gateway. This VXLAN network traffic data is used to request network access. The NDR device then parses the VXLAN network traffic data to obtain the user terminal identifier encapsulated within it. Next, it performs risk detection on the VXLAN network traffic data based on pre-configured security monitoring rules corresponding to the user terminal identifier. If a risk is detected in the VXLAN network traffic data, the cloud gateway is instructed to perform risk management on the user terminal corresponding to the user terminal identifier according to the pre-configured security monitoring rules. This solution is applied to an NDR device connected to a cloud gateway and enables security monitoring before network traffic data enters the communication backbone network. On the one hand, this solution enables near-source detection of network traffic data, effectively shortening the transmission path of network traffic data before security monitoring is performed, preventing potentially risky network traffic data from consuming bandwidth resources in the network, and improving the efficiency of risk detection and handling. On the other hand, this solution can perform risk detection and handling for specific user terminals based on user terminal identifiers and pre-configured security monitoring rules, effectively improving the flexibility and effectiveness of risk monitoring.
[0093] The system provided in this application embodiment can be deployed on the edge of the backbone network BRAS (Branch Area Service) closer to the user terminal, thereby achieving risk monitoring near the source of risk. This solution can accurately obtain information about the user terminal identifier in the access network, thus achieving user-level network security protection. By sinking security protection to the BRAS and performing near-source cleaning, and realizing orchestration policy capabilities based on cloud gateways and NDR (Network Detection and Reduction) devices, the system ultimately achieves high availability, high utilization, and high security protection of the network, improving user access efficiency and enhancing the security protection capabilities of the cloud gateway.
[0094] In the system provided in this application embodiment, the NDR device applies network detection and response technology to monitor network traffic and network events in real time, and quickly detect and respond to security threats. Optionally, the NDR device may include a traffic probe and an analysis platform. The aforementioned cloud gateway is used to orchestrate network traffic and security capabilities, forward traffic, and inject traffic back. The controller in the cloud gateway can flexibly and intelligently orchestrate forwarding policies based on the processing capabilities of the traffic probe in the NDR device and the processing capabilities of the cloud gateway. The NDR device may include a security capability resource pool for parsing and detecting risks in user-level network traffic data, thereby enabling the monitoring and protection against network threat attacks.
[0095] Based on the solutions provided in the above embodiments, optionally, such as Figure 5 As shown, the cloud gateway includes multiple repeaters and at least one controller. The number of NDR devices is multiple, and each NDR device includes at least one traffic probe. The controller is used for:
[0096] Obtain information on risk events that occurred within the first historical time period, including information on the type of risk event and the location of the risk source;
[0097] Based on the risk event information, a risk level index for each risk event type relative to the location of the target risk source is determined;
[0098] Based on the functional information of multiple NDR devices and the risk level index of each risk event type relative to the target risk source location, a target NDR device matching the target risk source location is determined from the multiple NDR devices.
[0099] Construct a forwarding mapping relationship between the repeater at the target risk source location and at least one traffic probe in the target NDR device.
[0100] In the system provided in this application embodiment, the cloud gateway includes multiple repeaters and at least one controller. There are multiple NDR devices, and each NDR device includes at least one traffic probe. The controller is used to orchestrate the forwarding mapping relationships between the multiple repeaters and the multiple traffic probes.
[0101] The controller can periodically acquire information on risk events that occurred within a historical time period based on a preset time T. The controller then uses this risk event information to determine which flow probes are suitable for the target risk source location.
[0102] In practical applications, for new areas where security monitoring is being performed for the first time, time T can be set as the time for the system's first proactive update, and an execution entity P with relatively balanced capabilities can be selected. j This is the initial executor, used to perform user security monitoring in the newly added region. For the new region, first select P.j Operational monitoring is used to obtain information on risk events that occurred within the first historical time period. After the runtime reaches T, the forwarding mapping relationship in this region is flexibly adjusted.
[0103] For ease of explanation, the embodiments of this application define a set P = {P1, P2, ..., P...} m}, where P n Let P represent the nth NDR device, and m represent the total number of NDR devices in the set, where P is any number of NDR devices. n The programming language, runtime environment, exception matching logic, etc., can be different; hereinafter referred to as P n For NDR devices or NDR executors, set P is a set of heterogeneous NDR executors. Set set L = {L1, L2, ..., L...} k}, where k represents the number of network attack types, L n Let L represent the nth attack type. Using L as the distinguishing dimension, we perform capability rating on the executors in set P, constructing a capability set of k attack types. Among them, Q Ln Let P be the set of results for rating the detection capability of the nth type of attack. Set collection in, Indicates the execution body P n Peak traffic processing capacity.
[0104] After obtaining risk event information, risk level indicators for each risk event type relative to the location of the target risk source are determined based on the risk event information.
[0105] For example, the number of anomalies caused by different attacks is recorded in the risk event information, organized by attack type. For any attack type L... n Set a set in, D represents 1 The most recent L-type event in the region n The number of exceptions caused by this type of attack. D represents 1 The most recent L-type event in the region n The timing of such attacks.
[0106] by L is calculated based on this. n Class attacks in D 1 Unusual regional influence:
[0107]
[0108] in, Let β represent the influence factor of the importance of the nth type of anomaly, and β is the time factor adjustment constant.
[0109] Construct different types of attacks in D 1 Collection of unusual influences in the region
[0110] Specifically, updates can be made whenever an anomaly occurs. Ensure the timeliness of abnormal influence sets.
[0111] Subsequently, Sort the attacks and select the top five attack types with the largest numerical values. Let's assume that the top five attack types with the largest abnormal impact are L1, L2, L3, L5, and L6, in descending order.
[0112] Next, based on the functional information of multiple NDR devices and the risk level indicators of each risk event type relative to the target risk source location, the target NDR device that matches the target risk source location is determined from the multiple NDR devices.
[0113] Specifically, calculate D for all assets in P separately. 1 Regional matching With P n For example:
[0114]
[0115] Where, λ one , λ two , λ three , λ four , λ five These are the anomalous influence factors affecting the top five rankings, forming a matching list set. Sets based on matching degree The system sorts the data and selects the entity with the highest matching degree as the corresponding regulatory entity for that region.
[0116] Furthermore, a forwarding mapping relationship is constructed between the repeaters at the target risk source location and at least one traffic probe in the target NDR device. Whenever the top five attack types with the largest abnormal impact are updated, the regional matching degree is recalculated, and the online execution unit is updated based on the latest calculation result.
[0117] The solution provided in this application can flexibly and dynamically arrange the forwarding mapping relationship between the repeater and the traffic probe, improve the rationality of traffic forwarding, and select appropriate NDR devices to perform risk monitoring for the actual risk of the target risk source location, thereby improving the rationality and effectiveness of risk monitoring.
[0118] Based on the solution provided in the above embodiments, optionally, constructing a forwarding mapping relationship between the repeater at the target risk source location and at least one traffic probe in the target NDR device includes:
[0119] Obtain peak traffic information of the target risk source location during a second historical time period, wherein the peak traffic information includes the peak network traffic data corresponding to each terminal user in the target risk source location;
[0120] If the peak value of the network traffic data of the first user terminal is greater than or equal to the preset traffic processing peak value of the target NDR device, then the forwarding mapping relationship of the first user terminal pointing to a traffic probe in the target NDR device through the corresponding repeater is configured, and the security monitoring rules corresponding to the user terminal identifier of the first user terminal are configured based on the ratio of the peak value of the network traffic data of the first user terminal to the preset traffic processing peak value.
[0121] If the peak network traffic data of the second user terminal is less than the preset traffic processing peak of the target NDR device, then at least one third user terminal is selected from the plurality of terminal users to form a user terminal group with the second user terminal, and the forwarding mapping relationship of the user terminal group is configured to point to a traffic probe in the target NDR device through the corresponding repeater. Furthermore, based on the peak network traffic data of the user terminal group, the security monitoring rules corresponding to the user terminal identifier of the user terminal group are configured, wherein the sum of the peak network traffic data of the second user terminal and the peak network traffic data of the at least one third user terminal is greater than or equal to the preset traffic processing peak of the target NDR device.
[0122] The embodiments of this application provide a solution that addresses the traffic peak on the user side and the traffic processing performance allocation and forwarding mapping relationship of NDR, ensuring that the network traffic data of user terminals can be monitored and processed in a timely and effective manner.
[0123] For example, assuming the second historical period is T, based on the initial regulatory region D... 1 Based on the peak traffic information, the cloud gateway controller uses the peak traffic occurring u times in the peak traffic information at time T as the basis to construct a basic set of control peak traffic information. Where q represents D 1 Number of users in the region D represents 1 Controlled peak traffic for user 1 in region.
[0124] In practical applications, the set H changes in real time as network traffic fluctuates. Optionally, the cloud gateway controller can continuously monitor peak traffic.
[0125] For example, if, within a time interval Y, a situation occurs where the traffic volume exceeds the current peak traffic volume and this situation occurs at least u times, then the user's controlled peak traffic volume value is updated.
[0126] If the maximum peak traffic is the same and the number of occurrences is greater than or equal to u, then the controlled peak traffic will be changed to that maximum peak traffic.
[0127] If the maximum peak traffic occurs more than or equal to u but with different values, then the peak traffic is set to the weighted average of the number of occurrences plus the traffic value.
[0128] Meanwhile, with X as the time interval, if no value greater than the previous peak flow occurs within a continuous time period X, the controlled peak flow value will automatically revert to the value before the update, and this reversion will continue until it returns to the initial value.
[0129] Assume D 1 The selected executor for the region is P3, and This is the optimal utilization factor for P3 in the execution unit. The preset peak flow rate in this solution is... Processing peak traffic based on preset flow rate Based on this, H is divided into two batches:
[0130]
[0131] against calculate At this time, the cloud gateway and traffic monitoring are configured according to 1: Configuration.
[0132] Considering the balance between matching costs and resource utilization, for H low A combination method from largest to smallest is adopted. First, select H. low maximum value Then select H low The second largest value
[0133] like Then select H low The third largest value And and Compare them.
[0134] like Then select H low The third largest value And and Compare them.
[0135] Until H appears low The minimum value is still greater than Or, the occurrence equals In this case, the previously accumulated traffic is mapped to an execution body, and a forwarding mapping relationship is constructed.
[0136] At the same time, the selected collective assets will be from H low Remove from the list and proceed to the next round of comparison until H is removed. low All available resources in the system have completed the forwarding mapping configuration.
[0137] The solution provided in this application, by combining orchestration algorithms with dynamic traffic redirection and executor selection, effectively ensures the stable and efficient completion of network security monitoring tasks by the information monitoring architecture. It effectively solves problems such as difficulty in tracing risks, high bandwidth consumption, and high latency in the field of network security monitoring. This solution can configure user-level security monitoring rules based on user terminal identifiers and implement risk tracing and handling based on user terminal identifiers, avoiding the use of a single security monitoring rule to monitor all network users. Furthermore, this solution can achieve risk monitoring near the risk source, improving risk monitoring efficiency and preventing potentially risky network traffic data from consuming network resources through long transmission paths.
[0138] When the user terminal identifier is a VNI, this solution can directly identify the downstream devices of a home user based on the home user's VNI and the attacking IP, which is conducive to targeted risk handling. In addition, security monitoring rules configured based on VNI can be personalized for each home user, improving the rationality and efficiency of network security monitoring.
[0139] In practical applications, backbone networks deploy computing network infrastructure, and security protection is fundamental to realizing network functions. Improving user network security and protecting target source stations from attacks is particularly important. The solution provided in this application can reduce the security protection costs of the access network during the construction of computing networks, while improving the efficiency of network security monitoring. It can achieve user-level security prevention and risk handling, and can flexibly allocate forwarding rules and risk monitoring rules, improving the effectiveness of risk monitoring and helping to ensure the overall security and stability of network service functions.
[0140] To address the problems existing in related technologies, embodiments of this application provide a network security monitoring device 60 based on a cloud gateway, such as... Figure 6 As shown, an NDR (Network Detection and Response) device is applied to the network, and the NDR device is communicatively connected to a cloud gateway, including:
[0141] The receiving module 61 receives the Virtual Extended Local Area Network (VXLAN) network traffic data of the user terminal forwarded by the cloud gateway. The VXLAN network traffic data is used to request network access.
[0142] Parsing module 62 parses the VXLAN network traffic data to obtain the user terminal identifier encapsulated in the VXLAN network traffic data;
[0143] The detection module 63 performs risk detection on the VXLAN network traffic data based on the pre-configured security monitoring rules corresponding to the user terminal identifier;
[0144] If the handling module 64 detects a risk in the VXLAN network traffic data, it instructs the cloud gateway to perform risk handling on the user terminal corresponding to the user terminal identifier according to the pre-configured security monitoring rules.
[0145] The apparatus provided in this application first receives Virtual Extended Local Area Network (VXLAN) network traffic data of a user terminal forwarded by a cloud gateway, wherein the VXLAN network traffic data is used to request network access. Then, the VXLAN network traffic data is parsed to obtain the user terminal identifier encapsulated within it. Next, risk detection is performed on the VXLAN network traffic data based on pre-configured security monitoring rules corresponding to the user terminal identifier. If a risk is detected in the VXLAN network traffic data, the cloud gateway is instructed to perform risk handling on the user terminal corresponding to the user terminal identifier according to the pre-configured security monitoring rules. This solution is applied to NDR devices communicating with a cloud gateway and can achieve security monitoring before network traffic data enters the communication backbone network. On the one hand, this solution can achieve near-source detection of network traffic data, effectively shortening the transmission path of network traffic data before security monitoring, avoiding the occupation of bandwidth resources by risky network traffic data in the network, and improving the efficiency of risk detection and risk handling. On the other hand, this solution can perform risk detection and risk handling for specific user terminals based on the user terminal identifier and according to pre-configured security monitoring rules, effectively improving the flexibility and effectiveness of risk monitoring.
[0146] In this application, the modules in the apparatus provided can also implement the method steps provided in the method embodiments. Alternatively, the apparatus provided in this application may include other modules besides those described above to implement the method steps provided in the method embodiments. Furthermore, the apparatus provided in this application can achieve the technical effects achievable by the method embodiments.
[0147] Preferably, this application embodiment also provides an electronic device, including a processor, a memory, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, it implements the various processes of the above-described cloud gateway-based network security monitoring method embodiment and achieves the same technical effect. To avoid repetition, it will not be described again here.
[0148] This application also provides a computer-readable storage medium storing a computer program. When executed by a processor, this computer program implements the various processes of the above-described cloud gateway-based network security monitoring method embodiments and achieves the same technical effects. To avoid repetition, it will not be described again here. The computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0149] This application also provides a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program. The computer program is operable to cause a computer to perform some or all of the steps of the above-described cloud gateway-based network security monitoring method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0150] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0151] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more flowchart illustrations and / or one or more block diagrams.
[0152] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.
[0153] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.
[0154] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0155] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0156] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0157] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0158] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0159] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A network security monitoring method based on a cloud gateway, characterized in that, The method, applied to a network detection and response (NDR) device communicatively connected to a cloud gateway, includes: The cloud gateway receives virtual extended local area network (VXLAN) traffic data from user terminals forwarded by the cloud gateway. The VXLAN network traffic data is used to request network access. Parse the VXLAN network traffic data to obtain the user terminal identifier encapsulated in the VXLAN network traffic data; Risk detection is performed on the VXLAN network traffic data based on the pre-configured security monitoring rules corresponding to the user terminal identifier; If a risk is detected in the VXLAN network traffic data, the cloud gateway is instructed to perform risk handling on the user terminal corresponding to the user terminal identifier according to the pre-configured security monitoring rules.
2. The method as described in claim 1, characterized in that, Receiving Virtual Extended Local Area Network (VXLAN) network traffic data from user terminals forwarded by the cloud gateway, including: The system receives VXLAN network traffic data of the user terminal forwarded by the repeater of the cloud gateway to the traffic probe of the NDR device based on a traffic forwarding policy. The traffic forwarding policy includes a forwarding mapping relationship between at least one repeater of the cloud gateway and at least one traffic probe of the NDR device.
3. The method as described in claim 2, characterized in that, Before receiving the VXLAN network traffic data of the user terminal forwarded by the repeater of the cloud gateway to the traffic probe of the NDR device based on the traffic forwarding policy, the process also includes: The controller of the cloud gateway sends functional information of at least one traffic probe contained in the NDR device to the controller of the cloud gateway, so as to instruct the controller of the cloud gateway to send traffic forwarding policies to each forwarder of the cloud gateway. The functional information includes the forwarding address and traffic processing capability information of the traffic probe. The traffic forwarding policy includes a forwarding mapping relationship constructed by the controller of the cloud gateway based on the functional information. The forwarding mapping relationship includes a mapping relationship between the VXLAN network identifier corresponding to at least one forwarder of the cloud gateway and the at least one traffic probe.
4. A network security monitoring system based on a cloud gateway, characterized in that, include: At least one user terminal is used to send network traffic data to the passive optical network device; The passive optical network device, which is communicatively connected to the at least one user terminal, is used to perform VXLAN encapsulation on the network traffic data of the user terminal according to the user terminal identifier to obtain VXLAN network traffic data, and send the VXLAN network traffic data to the cloud gateway. The cloud gateway, which is communicatively connected to the passive optical network device, is used to forward the VXLAN network traffic data to the network detection and response (NDR) device. The NDR device, which is communicatively connected to the cloud gateway, is used to execute the network security monitoring method based on the cloud gateway as described in any one of claims 1 to 3.
5. The system as described in claim 4, characterized in that, The cloud gateway includes multiple repeaters and at least one controller. The number of NDR devices is multiple, and each NDR device includes at least one traffic probe. The controller is used for: Obtain information on risk events that occurred within the first historical time period, including information on the type of risk event and the location of the risk source; Based on the risk event information, a risk level index for each risk event type relative to the location of the target risk source is determined; Based on the functional information of multiple NDR devices and the risk level index of each risk event type relative to the target risk source location, a target NDR device matching the target risk source location is determined from the multiple NDR devices. Construct a forwarding mapping relationship between the repeater at the target risk source location and at least one traffic probe in the target NDR device.
6. The system as described in claim 5, characterized in that, Constructing a forwarding mapping relationship between the repeater at the target risk source location and at least one traffic probe in the target NDR device, including: Obtain peak traffic information of the target risk source location during a second historical time period, wherein the peak traffic information includes the peak network traffic data corresponding to each terminal user in the target risk source location; If the peak value of the network traffic data of the first user terminal is greater than or equal to the preset traffic processing peak value of the target NDR device, then the forwarding mapping relationship of the first user terminal pointing to a traffic probe in the target NDR device through the corresponding repeater is configured, and the security monitoring rules corresponding to the user terminal identifier of the first user terminal are configured based on the ratio of the peak value of the network traffic data of the first user terminal to the preset traffic processing peak value. If the peak network traffic data of the second user terminal is less than the preset traffic processing peak of the target NDR device, then at least one third user terminal is selected from the plurality of terminal users to form a user terminal group with the second user terminal, and the forwarding mapping relationship of the user terminal group is configured to point to a traffic probe in the target NDR device through the corresponding repeater. Furthermore, based on the peak network traffic data of the user terminal group, the security monitoring rules corresponding to the user terminal identifier of the user terminal group are configured, wherein the sum of the peak network traffic data of the second user terminal and the peak network traffic data of the at least one third user terminal is greater than or equal to the preset traffic processing peak of the target NDR device.
7. A network security monitoring device based on a cloud gateway, characterized in that, An application for network detection and response (NDR) devices, wherein the NDR device is communicatively connected to a cloud gateway, including: The receiving module receives the Virtual Extended Local Area Network (VXLAN) network traffic data of the user terminal forwarded by the cloud gateway. The VXLAN network traffic data is used to request network access. The parsing module parses the VXLAN network traffic data to obtain the user terminal identifier encapsulated in the VXLAN network traffic data; The detection module performs risk detection on the VXLAN network traffic data based on the pre-configured security monitoring rules corresponding to the user terminal identifier; If the handling module detects a risk in the VXLAN network traffic data, it instructs the cloud gateway to perform risk handling on the user terminal corresponding to the user terminal identifier according to the pre-configured security monitoring rules.
8. An electronic device, characterized in that, include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the steps of the method as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the method as described in any one of claims 1 to 6.
10. A computer program product, characterized in that, The computer program product includes a non-transitory computer-readable storage medium storing a computer program operable to cause a computer to perform some or all of the steps of the method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Traffic monitoring method and device in VXLAN
CN105591834A
Method, device and system for processing vxlan packet
CN108028748A