A method, apparatus, electronic device, and storage medium for updating a feature library.
By automatically generating unknown application identification features and updating the feature library of network devices through the SDN controller, the problem of complex and lagging manual operation for feature library updates in the existing technology is solved, thereby improving application identification capabilities and the timeliness of updates.
Patent Information
- Application Number
- CN202411244385.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-05
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2044-09-05
AI Technical Summary
Existing feature library update schemes rely on manual operation, which is complex and slow, resulting in insufficient application recognition capabilities.
Traffic analysis is performed through the SDN controller to generate unknown application identification features and automatically update the feature library of network devices. The feature library is automatically updated by using a global feature library and a set of device feature libraries.
It enables automated updates to the feature database, improves the application recognition capabilities of network devices, reduces administrator operations, ensures timely and flexible updates, and lowers system network requirements.
Smart Images

Figure CN119172264B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a feature library update method, apparatus, electronic device, and storage medium. Background Technology
[0002] Some application-based services need to know the application layer protocol to which the message belongs when processing messages, such as Quality of Service (QoS) and Application Specific Packet Filter (ASPF). Application Recognition (APR) can provide application identification services for such services and can perform quantity and rate statistics on messages of a certain application layer protocol received or sent on the interface.
[0003] Generally, the application identification and processing flow is as follows: Configure the device feature library, and the application detection engine will load the feature library when the device is running; when traffic passes through the device, the engine will detect the packets according to the loaded application identification features; if the detection result is a failure to match, the packet will be allowed to pass directly; if the detection result is a successful match, the device will send the detection result to the application business module for processing; the application business will process the packet accordingly based on the detection result, such as dropping, source blocking, redirection, logging, etc.
[0004] Application detection is crucial, as it performs feature matching on all traffic passing through network devices. To significantly improve application identification capabilities, the application identification features in the device feature database must be sufficiently rich and updated in a timely manner. However, current solutions that update device feature databases based on network management systems suffer from drawbacks such as relatively complex update processes, reliance on manual operation, and update delays. Summary of the Invention
[0005] To overcome the problems existing in related technologies, this application provides a feature library updating method, apparatus, electronic device, and storage medium.
[0006] According to a first aspect of the embodiments of this application, a feature library update method is provided, the method being applied to an SDN controller, the method comprising:
[0007] Perform traffic analysis on each network device connected to the SDN controller to identify target network devices whose unknown application traffic reaches the preset update conditions;
[0008] Unknown application identification features are generated based on a global feature library and a device feature library set. The global feature library is synchronized with an external public feature library, and the device feature library set is used to record the feature libraries of all network devices connected to the SDN controller.
[0009] The feature library of the target network device is updated using the unknown application identification features.
[0010] According to a second aspect of the embodiments of this application, a feature library updating apparatus is provided, the apparatus being applied to an SDN controller, the apparatus comprising:
[0011] The traffic analysis module is used to perform traffic analysis on each network device connected to the SDN controller and identify the target network devices whose unknown application traffic reaches the preset update conditions.
[0012] The feature generation module is used to generate unknown application identification features based on the global feature library and the device feature library set. The global feature library is synchronized with the external public feature library, and the device feature library set is used to record the feature libraries of all network devices connected to the SDN controller.
[0013] The update module is used to update the feature library of the target network device using the unknown application identification features.
[0014] According to a third aspect of the present application, an electronic device is provided, including a processor and a machine-readable storage medium storing machine-executable instructions executable by the processor, the processor being prompted by the machine-executable instructions to implement the steps of the feature library update method as described above.
[0015] According to a fourth aspect of the embodiments of this application, a computer-readable storage medium is provided, wherein a computer program is stored therein, and when the computer program is executed by a processor, it implements the steps of the feature library update method described above.
[0016] The technical solutions provided by the embodiments of this application may include the following beneficial effects:
[0017] This application embodiment utilizes an SDN controller to monitor network device traffic in real time. When unknown application traffic reaches certain conditions, it automatically generates identification features for the unknown application and updates the network device's feature database accordingly. In other words, this application embodiment achieves fully automated updates to the network device feature database based on the SDN controller, ensuring the network device's ability to identify applications. Furthermore, the feature database update process requires no administrator intervention, and real-time monitoring of device traffic and updating of the feature database avoids problems such as untimely feature database updates and lagging application identification features.
[0018] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description
[0019] The accompanying drawings, which are incorporated in and form part of this application, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0020] Figure 1 This is a schematic diagram of a first flowchart of a feature library update method provided in an embodiment of this application;
[0021] Figure 2 This is a schematic diagram illustrating the process of a feature library update method provided in an embodiment of this application;
[0022] Figure 3 This is a second flowchart illustrating a feature library update method provided in an embodiment of this application.
[0023] Figure 4 This is a schematic diagram of a third process for a feature library update method provided in an embodiment of this application;
[0024] Figure 5 This is a schematic diagram of the structure of a feature library updating device provided in an embodiment of this application;
[0025] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0026] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0027] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.
[0028] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the words “if” or “suppose” as used herein may be interpreted as “when…” or “when…”.
[0029] The embodiments of this application will now be described in detail.
[0030] This application provides a feature library update method, which is applied to an SDN controller, such as... Figure 1 As shown, the method may include the following steps:
[0031] Step 110: Perform traffic analysis on each network device connected to the SDN controller to identify the target network devices whose unknown application traffic reaches the preset update conditions;
[0032] Step 120: Generate unknown application identification features based on the global feature library and the device feature library set. The global feature library is synchronized with the external public feature library, and the device feature library set is used to record the feature libraries of all network devices connected to the SDN controller.
[0033] Step 130: Update the feature library of the target network device using the features identified by the unknown application.
[0034] Software-defined networking (SDN) technology is widely used in various fields and user networks. The SDN controller, acting as the network brain, is responsible for controlling and orchestrating the distribution of various network operation and maintenance services. This application implements a feature library update method based on an SDN controller. The feature library refers to a resource library in a network device used to identify application-layer traffic passing through the network device. The feature library includes a series of application identification features. Different network devices may run different applications; therefore, the application identification features contained in the feature libraries of different network devices may differ.
[0035] like Figure 2As shown, this embodiment of the application establishes a global feature library and a device feature library set in the SDN controller. The global feature library is synchronized with an external public feature library, which refers to a series of application identification features officially published on a website. This embodiment of the application periodically obtains the latest application identification features from the website's public feature library via HTTP and synchronizes them to the global feature library. The device feature library set is the feature library of all network devices queried by the SDN controller. The SDN controller can obtain the feature library of each network device through subscription or active query.
[0036] like Figure 2 As shown, this embodiment of the application also adds a traffic analysis module to the SDN controller. The traffic analysis module uses Net Stream technology to monitor and statistically analyze the traffic of various network devices connected to the SDN device. Taking IPv4 packets as an example, the traffic analysis module defines the flow based on the destination IP address, source IP address, destination port number, source port number, protocol number, type of service (ToS), and input or output interface of the packet. Packets with the same five-tuple (destination IP address, source IP address, destination port number, source port number, protocol number) are considered to belong to the same application's data flow.
[0037] In this embodiment, the traffic analysis module performs traffic analysis on each network device connected to the SDN controller. Specifically, the traffic analysis module collects the traffic of each network device and matches the five-tuple of the collected traffic with the application identification features in the feature library of the network device. The content of the application identification features includes, but is not limited to, the five-tuple. If the five-tuple contained in any application identification feature in the feature library is the same as the five-tuple of the traffic, it indicates that it is known application traffic, and the match is considered successful. The known application traffic information <device ID, application number, time, five-tuple, traffic value> is recorded. Otherwise, the match is considered unsuccessful, and the unknown application traffic information <device ID, time, five-tuple, traffic value> is recorded.
[0038] As a specific implementation method, the application identification features include a quintuple, and may also include feature description information, feature encoding, application number, etc.
[0039] In this embodiment, the SDN controller supports configuring preset update conditions, specifically a preset duration T (minutes) and a preset value N (%). That is, within the most recent time period T, if the traffic of an unknown application reaches N% or more of the total known application traffic of the device, the preset update condition is considered met, and the feature database of the network device needs to be updated. Therefore, this embodiment specifically determines the target network device whose unknown application traffic meets the preset update condition by: identifying the target network device whose ratio of unknown application traffic to all known application traffic exceeds a preset value within the preset duration.
[0040] As a specific implementation method, the traffic analysis module periodically checks applications in the unknown traffic list that meet the conditions based on the configured preset duration T (minutes) and preset value N (%). The process is as follows: First, the traffic size S of all known applications on the network device within the most recent T time period is calculated according to the first formula. Then, the traffic size P of each unknown application on the network device within the most recent T time period is calculated sequentially according to the second formula. Finally, the unknown application traffic threshold is checked. If (P / S)*100>=N, the traffic is considered to have reached the threshold, and the unknown application traffic is large and needs to be identified, requiring an update to the device dynamic feature database list. The first formula is shown below:
[0041]
[0042] Where S is the total traffic of n known applications within time T, i is the application number, j represents each application at different time points, and V(i,j) represents the traffic of application number i at time j.
[0043] The second formula is shown below:
[0044]
[0045] Where P represents the traffic of each unknown application within time T, j represents the time points of the unknown application, and V(j) represents the traffic of the unknown application at time j.
[0046] After the above process, the target network device whose unknown application traffic meets the preset update conditions can be identified. Then, unknown application identification features are generated based on the global feature library and the device feature library. To improve efficiency in generating unknown application identification features, this application embodiment classifies the types of application identification features as follows:
[0047] Predefined features: Predefined application identification features that cannot be modified or deleted;
[0048] Custom features: Application identification features manually created by the administrator, who can add or delete them.
[0049] Dynamic Features: The dynamic feature list function provided by network devices supports the SDN controller to dynamically issue features based on traffic conditions.
[0050] Based on the above classification, when generating features to identify unknown applications, the matching is performed in the following order: Figure 3 As shown:
[0051] Step 310: Match the five-tuple of the unknown application with the application identification features of the device feature library set whose feature type is a predefined feature; if the match is successful, proceed to step 350, otherwise proceed to step 320.
[0052] Step 320: Match the five-tuple of the unknown application with the application identification features of the device feature library set whose feature type is custom feature; if the match is successful, proceed to step 350, otherwise proceed to step 330.
[0053] Step 330: Match the five-tuple of the unknown application with the application identification features of the feature type dynamic feature in the device feature library set; if the match is successful, proceed to step 350, otherwise proceed to step 340.
[0054] Step 340: Match the quintuple of the unknown application with the application identification features in the global feature library; if the match is successful, proceed to step 350.
[0055] Step 350: Use the matching results as identification features for unknown applications.
[0056] After the above process, the unknown application identification features can be obtained. When updating the feature library of the target network device using the unknown application identification features, this embodiment of the application considers that different devices have different resource limitations, and therefore support different upper limits on the number of features. Therefore, it first queries the number of features and the upper limit of the number of features from the target network device, and then updates the feature library according to the following process: Figure 4 As shown:
[0057] Step 410: When the number of features of the target network device is less than the upper limit of the number of features of the target network device, the unknown application identification features are sent to the feature library of the target network device.
[0058] Step 420: When the number of features of the target network device is equal to the upper limit of the number of features of the target network device, determine the known application with the smallest traffic in the target network device, and replace the application identification feature of the known application with the smallest traffic in the feature library of the target network device with the unknown application identification feature.
[0059] As can be seen from the above technical solutions, the embodiments of this application provide a feature library update method. This method is implemented based on an SDN controller and can monitor the traffic of network devices. When it is detected that the feature library version of a network device is outdated or the application recognition rate is low, the feature library of the network device is automatically updated through the SDN controller, thereby improving the application recognition capability of the network device. This method has at least the following advantages:
[0060] First, in this method, the SDN controller can ensure that the local global feature library is synchronized with the external public feature library. Therefore, during the process of updating the device feature library, the network device does not need to access the official feature library service, which reduces the network requirements of the entire system.
[0061] Secondly, the feature database update process is fully automated, requiring no manual intervention, which reduces the operational difficulty for administrators and saves management costs;
[0062] Third, this method identifies unknown applications and generates updated content based on the network device's recent business traffic. The update method is very flexible and the update speed is very timely.
[0063] Fourth, the method also considers the upper limit of the number of feature libraries for different network devices during the update process to ensure the reliability of the update process.
[0064] Based on the same inventive concept, this application also provides a feature library updating device, which is applied to an SDN controller, such as... Figure 5 As shown, the device includes:
[0065] The traffic analysis module 510 is used to perform traffic analysis on each network device connected to the SDN controller and identify the target network device whose unknown application traffic reaches the preset update conditions.
[0066] The feature generation module 520 is used to generate unknown application identification features based on the global feature library and the device feature library set. The global feature library is synchronized with the external public feature library, and the device feature library set is used to record the feature libraries of all network devices connected to the SDN controller.
[0067] The update module 530 is used to update the feature library of the target network device using the unknown application identification features.
[0068] In one specific implementation, the device further includes:
[0069] The feature database synchronization module 540 is used to periodically obtain external public feature databases via HTTP and update the global feature database based on the public feature databases.
[0070] In one specific implementation, the device further includes:
[0071] The device feature acquisition module 550 is used to obtain the feature library of all network devices connected to the SDN controller through subscription or active query, and update the device feature library set according to the feature library of all network devices.
[0072] As a specific implementation method, the traffic analysis module 510 specifically determines the target network device whose unknown application traffic reaches the preset update conditions through the following method:
[0073] Identify target network devices where the ratio of unknown application traffic to all known application traffic exceeds a preset value within a preset time period.
[0074] As one specific implementation, the feature generation module 520 specifically includes:
[0075] The first matching unit is used to match the five-tuple of unknown applications with the application identification features of the device feature library set whose feature type is a predefined feature;
[0076] The first output unit is used to use the matching result as an unknown application identification feature if the match is successful.
[0077] The second matching unit is used to match the five-tuple of the unknown application with the application identification features of the feature type of the device feature library set if the matching fails.
[0078] The second output unit is used to use the matching result as an unknown application identification feature if the match is successful.
[0079] The third matching unit is used to match the five-tuple of the unknown application with the application identification features of the feature type dynamic feature in the device feature library set if the matching fails.
[0080] The third output unit is used to use the matching result as an unknown application identification feature if the match is successful.
[0081] The fourth matching unit is used to match the five-tuple of the unknown application with the application identification features in the global feature library if the matching fails.
[0082] The fourth output unit is used to use the matching result as an unknown application identification feature if a match is successful.
[0083] As one specific implementation, the update module 530 specifically includes:
[0084] The first update unit is used to send the unknown application identification feature to the feature library of the target network device when the number of features of the target network device is less than the upper limit of the number of features of the target network device.
[0085] The second updating unit is used to replace the application identification feature with the lowest traffic in the feature library of the target network device with the unknown application identification feature when the number of features of the target network device is equal to the upper limit of the number of features of the target network device.
[0086] This application also provides an electronic device, such as... Figure 6 As shown, it includes a processor 601 and a machine-readable storage medium 602, the machine-readable storage medium 602 storing machine-executable instructions that can be executed by the processor 601, the processor 601 being prompted by the machine-executable instructions to implement the steps of any of the above-described feature library update methods.
[0087] The aforementioned machine-readable storage medium may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the machine-readable storage medium may also be at least one storage device located remotely from the aforementioned processor.
[0088] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0089] In another embodiment provided in this application, a computer-readable storage medium is also provided, which stores a computer program that, when executed by a processor, implements the steps of any of the above-described feature library update methods.
[0090] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A feature library update method, characterized in that, The method is applied to an SDN controller, and the method includes: Perform traffic analysis on each network device connected to the SDN controller to identify target network devices whose unknown application traffic reaches the preset update conditions; Unknown application identification features are generated based on a global feature library and a device feature library set. The global feature library is synchronized with an external public feature library, and the device feature library set is used to record the feature libraries of all network devices connected to the SDN controller. The feature library of the target network device is updated using the unknown application identification features; Unknown application identification features are generated based on the global feature library and the device feature library, specifically including: Match the five-tuple of unknown applications with application identification features of predefined feature types in the device feature library set; If a match is successful, the matching result will be used as an identification feature for unknown applications. If the match fails, the five-tuple of the unknown application will be matched with the application identification features of the device feature library set whose feature type is custom feature. If a match is successful, the matching result will be used as an identification feature for unknown applications. If the match fails, the five-tuple of the unknown application will be matched with the application identification features of the dynamic feature type in the device feature library set; the dynamic feature is the dynamic feature list function provided by the network device, which supports the SDN controller to dynamically issue features according to traffic conditions. If a match is successful, the matching result will be used as an identification feature for unknown applications. If the match fails, the five-tuple of the unknown application will be matched with the application identification features in the global feature library. If a match is successful, the matching result will be used as an identification feature for unknown applications.
2. The method according to claim 1, characterized in that, The method further includes: The system periodically retrieves external public feature databases via HTTP and updates the global feature database based on these databases.
3. The method according to claim 1, characterized in that, The method further includes: The feature library of all network devices connected to the SDN controller is obtained through subscription or active query, and the device feature library set is updated based on the feature library of all network devices.
4. The method according to claim 1, characterized in that, Identify target network devices whose unknown application traffic meets preset update conditions, specifically including: Identify target network devices where the ratio of unknown application traffic to all known application traffic exceeds a preset value within a preset time period.
5. The method according to any one of claims 1 to 4, characterized in that, Updating the feature library of the target network device using the unknown application identification features specifically includes: When the number of features of the target network device is less than the upper limit of the number of features of the target network device, the unknown application identification features are sent to the feature library of the target network device. When the number of features of the target network device is equal to the upper limit of the number of features of the target network device, the application identification feature with the lowest traffic in the feature library of the target network device is replaced by the unknown application identification feature.
6. A feature library updating device, characterized in that, The device is used in an SDN controller, and the device includes: The traffic analysis module is used to perform traffic analysis on each network device connected to the SDN controller and identify the target network devices whose unknown application traffic reaches the preset update conditions. The feature generation module is used to generate unknown application identification features based on the global feature library and the device feature library set. The global feature library is synchronized with the external public feature library, and the device feature library set is used to record the feature libraries of all network devices connected to the SDN controller. The update module is used to update the feature library of the target network device using the unknown application identification features; The feature generation module specifically includes: The first matching unit is used to match the five-tuple of unknown applications with the application identification features of the device feature library set whose feature type is a predefined feature; The first output unit is used to use the matching result as an unknown application identification feature if the match is successful. The second matching unit is used to match the five-tuple of the unknown application with the application identification features of the feature type of the device feature library set if the matching fails. The second output unit is used to use the matching result as an unknown application identification feature if the match is successful. The third matching unit is used to match the five-tuple of the unknown application with the application identification features of the feature type in the device feature library set if the matching fails; the dynamic features are the dynamic feature list function provided by the network device, which supports the SDN controller to dynamically issue features according to traffic conditions. The third output unit is used to use the matching result as an unknown application identification feature if the match is successful. The fourth matching unit is used to match the five-tuple of the unknown application with the application identification features in the global feature library if the matching fails. The fourth output unit is used to use the matching result as an unknown application identification feature if a match is successful.
7. The apparatus according to claim 6, characterized in that, The traffic analysis module specifically identifies target network devices whose unknown application traffic meets preset update conditions through the following methods: Identify target network devices where the ratio of unknown application traffic to all known application traffic exceeds a preset value within a preset time period.
8. The apparatus according to claim 6 or 7, characterized in that, The update module specifically includes: The first update unit is used to send the unknown application identification feature to the feature library of the target network device when the number of features of the target network device is less than the upper limit of the number of features of the target network device. The second updating unit is used to replace the application identification feature with the lowest traffic in the feature library of the target network device with the unknown application identification feature when the number of features of the target network device is equal to the upper limit of the number of features of the target network device.
9. An electronic device, characterized in that, The method includes a processor and a machine-readable storage medium storing machine-executable instructions that can be executed by the processor, the processor being prompted by the machine-executable instructions to perform the method steps of any one of claims 1-5.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the method steps of any one of claims 1-5.
Citation Information
Patent Citations
Network traffic analysis method and device, and processing equipment
CN116366568A
Flow monitoring method and system based on SDN architecture, and electronic equipment
CN116827859A