Data acquisition method, device, electronic device and computer program product

By setting hook functions in the kernel network stack of the operating system to obtain kernel information, the problem of difficult to delimit kernel-level network failures in the existing technology is solved, and efficient and convenient troubleshooting is achieved.

CN119254615BActive Publication Date: 2025-05-09ALIBABA CLOUD COMPUTING CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411784770.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-05
Publication Date
2025-05-09
Estimated Expiration
2044-12-05

AI Technical Summary

Technical Problem

In the prior art, data captured using packet capture tools is difficult to delimit kernel-level network failures, and operation and maintenance personnel need to have deep kernel knowledge, with a high threshold, which increases the difficulty of troubleshooting.

Method used

By setting a hook function in the kernel network stack of the operating system, the target data packet and target kernel information are obtained, including information such as time stamps during the analysis and encapsulation of the kernel network stack at different levels, and assembled into the assembly results of the target data packets in order to analyze and locate network failures.

Benefits of technology

It improves the accuracy and efficiency of determining network failures at the delimited kernel level, reduces the technical threshold for operation and maintenance personnel, and makes troubleshooting more efficient and convenient.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119254615B_ABST
    Figure CN119254615B_ABST
Patent Text Reader

Abstract

The present application discloses a data acquisition method, device, electronic device and computer program product. The method comprises: receiving a target data packet acquired by a hook function set by the first layer kernel network stack of an operating system; receiving target kernel information acquired by a hook function set by the kernel network stack of the operating system, wherein the target kernel information comprises different target sub-kernel information, and one target sub-kernel information comprises a timestamp when a kernel network stack parses the target data packet; assembling the target data packet and the target kernel information to obtain an assembly result of the target data packet. The present application solves the technical problem in the related art that it is difficult to delimit kernel-level network faults using data captured by a packet capture tool.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a data acquisition method, device, electronic device, and computer program product. Background Art

[0002] In the operation and maintenance work, various network failures often occur, such as packet loss and network jitter. After the above failures occur, they need to be fed back to the front-line operation and maintenance personnel for troubleshooting. If the failure is more complicated, it will be gradually upgraded and further analyzed and handled by a more professional technical support team.

[0003] In order to improve the efficiency of fault handling, some network fault diagnosis methods have emerged in related technologies. For example, basic packet capture tools are used to capture and analyze data packets to locate the fault point. Since basic packet capture tools capture data packets at fixed packet capture points, it is impossible to fully observe the processing process of data packets in the operating system kernel, and it is difficult to determine whether the operating system kernel is the root cause of the network fault. For another example, more advanced tools are used to capture and analyze data packets to observe the processing process of data packets in the operating system kernel, but this requires operation and maintenance personnel to have deep kernel knowledge and be familiar with various kernel functions. The threshold is high, which increases the difficulty of troubleshooting.

[0004] To address the above-mentioned problems, no effective solution has been proposed yet. Summary of the invention

[0005] The embodiments of the present application provide a data acquisition method, device, electronic device, and computer program product to at least solve the technical problem in the related art that it is difficult to delimit kernel-level network failures using data captured by packet capture tools.

[0006] According to one aspect of an embodiment of the present application, a data acquisition method is provided. The data acquisition method is applied in a process in which an application receives a data packet transmitted by a network device through an operating system, comprising: receiving a target data packet obtained by a hook function set by a first-layer kernel network stack of the operating system; receiving target kernel information obtained by a hook function set by a kernel network stack of the operating system, wherein the target kernel information includes different target sub-kernel information, and a target sub-kernel information includes a timestamp when a kernel network stack parses the target data packet; assembling the target data packet and the target kernel information to obtain an assembly result of the target data packet.

[0007] According to one aspect of an embodiment of the present application, another data acquisition method is provided. The data acquisition method is applied in the process of an application sending a data packet to a network device through an operating system, including: receiving an assembly result of a target data packet transmitted by a first-layer kernel network stack of the kernel of the operating system, wherein the assembly result includes a target data packet and target kernel information, the target kernel information is obtained by a hook function set by the kernel network stack of the operating system, the target kernel information includes different target sub-kernel information, and a target sub-kernel information includes a timestamp when a kernel network stack encapsulates the target data packet.

[0008] According to another aspect of an embodiment of the present application, a data acquisition method is also provided. The data acquisition method is applied in a process in which an application receives a data packet transmitted by a network device through an operating system, and includes: receiving a target data packet; copying the target data packet through a hook function set by a first-layer kernel network stack of the operating system, and sending the copied target data packet to the application; parsing the target data packet layer by layer through the kernel network stack of the operating system, obtaining target kernel information obtained by parsing the target data packet through a hook function set by the kernel network stack, and sending the target kernel information to the application, wherein the target kernel information includes different target sub-kernel information, and a target sub-kernel information includes a timestamp when a kernel network stack parses the target data packet, and the application assembles the target data packet and the target kernel information to obtain an assembly result of the target data packet.

[0009] According to another aspect of an embodiment of the present application, another data acquisition method is provided. The data acquisition method is applied in the process of an application sending a data packet to a network device through an operating system, including: receiving a target data packet; encapsulating the target data packet layer by layer through the kernel network stack of the operating system, obtaining target kernel information obtained by encapsulating the target data packet through a hook function set by the kernel network stack, and sending the target kernel information to the application, wherein the target kernel information includes different target sub-kernel information, and a target sub-kernel information includes a timestamp when a kernel network stack encapsulates the target data packet; the application assembles the encapsulated target data packet and the target kernel information to obtain an assembly result of the target data packet.

[0010] According to another aspect of the embodiments of the present application, an electronic device is further provided, including: a memory storing an executable program; and a processor for running the program, wherein the data acquisition method in each embodiment of the present application is executed when the program is running.

[0011] According to another aspect of the embodiments of the present application, a computer program product is also provided, including a computer program, and when the computer program is executed by a processor, the data acquisition method in each embodiment of the present application is implemented.

[0012] According to another aspect of the embodiments of the present application, a computer storage medium is further provided, and the computer storage medium is used to store a program, wherein when the program is running, the device where the computer storage medium is located is controlled to execute the data acquisition method in each embodiment.

[0013] In an embodiment of the present application, a hook function is set in each kernel network stack, so that in the process of data packets being transmitted between an application and a network device through an operating system, the target kernel information obtained by the hook functions set in different kernel network stacks can be obtained, and the target data packet and the target kernel information can be assembled and stored, so that it can be determined whether an abnormality occurs in the target data packet during transmission according to the target kernel information corresponding to the target data packet. In this way, when an abnormality occurs in the transmission of the target data packet, the abnormal location and the abnormal cause can be determined according to the target kernel information corresponding to the target data packet, thereby improving the accuracy and efficiency of determining and delimiting kernel-level network failures, and further solving the technical problem in the related technology that it is difficult to delimit kernel-level network failures using data captured by packet capture tools.

[0014] It is easy to notice that the above general description and the following detailed description are only for the purpose of exemplifying and explaining the present application, and do not constitute a limitation of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0016] Figure 1 A hardware structure block diagram of a computer terminal (or mobile device) for implementing a data acquisition method is shown;

[0017] Figure 2 is a schematic diagram of a data acquisition method according to an embodiment of the present application;

[0018] Figure 3 This is a schematic diagram of an optional data acquisition process according to an embodiment of the present application. Figure 1 ;

[0019] Figure 4 This is a schematic diagram of an optional data acquisition process according to an embodiment of the present application. Figure 2 ;

[0020] Figure 5 is a schematic diagram of another data acquisition method according to an embodiment of the present application;

[0021] Figure 6 This is a schematic diagram of an optional data acquisition process according to an embodiment of the present application. Figure 3 ;

[0022] Figure 7 is a schematic diagram of another data acquisition method according to an embodiment of the present application;

[0023] Figure 8 is a schematic diagram of another data acquisition method according to an embodiment of the present application;

[0024] Fig. 9 is a schematic diagram of a data acquisition device according to an embodiment of the present application;

[0025] Fig.10 is a schematic diagram of another data acquisition device according to an embodiment of the present application;

[0026] Fig.11 is a schematic diagram of another data acquisition device according to an embodiment of the present application;

[0027] Fig.12 is a schematic diagram of another data acquisition device according to an embodiment of the present application;

[0028] Fig.13 It is a structural block diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0029] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.

[0030] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0031] First of all, some nouns or terms that appear in the process of describing the embodiments of the present application are subject to the following explanations: eBPF (Extended Berkeley Packet Filter): is a kernel technology that allows dynamic addition and execution of custom program code snippets to intercept, modify and observe the behavior of the kernel and applications.

[0032] Stubbing: refers to inserting additional code at specific locations in a program to monitor or modify the behavior of the program.

[0033] Hook Function: A function that is automatically executed when a specific event occurs. It is used to capture and process specific events. When a specific event occurs, the hook function will be automatically called to process these events.

[0034] TCP (Transmission Control Protocol) is a connection-oriented, reliable, byte-stream-based transport layer protocol that is responsible for establishing connections between communicating parties, transmitting data, ensuring data reliability and sequence, and releasing the connection at the end of the connection.

[0035] Example 1

[0036] According to an embodiment of the present application, a data acquisition method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0037] The method embodiment provided in Embodiment 1 of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 1 FIG. 1 shows a hardware structure block diagram of a computer terminal (or mobile device) for implementing a data acquisition method. Figure 1 As shown, the computer terminal 10 (or mobile device) may include one or more ( Figure 1 102a, 102b, ..., 102n are used to illustrate) processor 102 (processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission module 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. Those skilled in the art can understand that Figure 1 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations are shown.

[0038] It should be noted that the one or more processors 102 and / or other data processing circuits described above may generally be referred to herein as "data processing circuits". The data processing circuits may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. In addition, the data processing circuit may be a single independent processing module, or may be incorporated in whole or in part into any of the other components in the computer terminal 10 (or mobile device). As involved in the embodiments of the present application, the data processing circuit acts as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).

[0039] The memory 104 can be used to store software programs and modules of application software, such as program instructions / data storage devices corresponding to the methods in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implementing the methods in the above embodiments. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0040] The transmission device 106 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0041] The display may be, for example, a touch screen liquid crystal display (LCD), which may enable a user to interact with a user interface of the computer terminal 10 (or mobile device).

[0042] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0043] In this embodiment, the application is set in the user state, and the data packet can be transmitted between the application and the network device (for example, the network card) through the operating system. For example, when the network device receives the target data packet, the operating system can be notified through the interrupt mechanism, the kernel state of the operating system responds to the interrupt, receives the target data packet from the network device, and the kernel state network protocol stack processes the target data packet, and then transmits the target data packet to the user state application. In the event of network failures such as packet loss and network jitter, it is necessary to analyze the network failure, determine the fault point where the network failure occurs, and then perform maintenance on the fault point to ensure the stable transmission of subsequent data packets.

[0044] The data acquisition method provided in this embodiment can be applied to the scenario of determining the fault point of a network failure during data packet transmission. By setting a hook function in the key functions of each kernel network stack in the kernel state, the target kernel information can be obtained to accurately analyze the fault point of the abnormal network failure based on the target kernel information.

[0045] Under the above operating environment, this application provides Figure 2 The data acquisition method shown. Figure 2 1 is a schematic diagram of a data acquisition method according to an embodiment of the present application. The data acquisition method is applied in a process in which an application receives a data packet transmitted by a network device through an operating system, and includes:

[0046] Step S201, receiving a target data packet obtained by a hook function set by a first layer kernel network stack of an operating system.

[0047] It should be noted that the hook function is a preset code in the key function under each kernel network stack in the kernel state of the operating system. The key function refers to the function that the data packet passes through when the network device transmits the data packet to the application through the operating system. The key function is called when the kernel network stack processes the data packet. At this time, the hook function set in the key function will be triggered, thereby obtaining the parsing information and timestamp information obtained when the data packet is parsed.

[0048] Exemplarily, when the operating system receives the target data packet, the target data packet enters the kernel network stack in the kernel state, wherein the kernel network stack includes at least a driver layer, a TC layer (Traffic Control Layer) and a system call layer. When the data packet is transmitted through the TCP protocol, the kernel network stack may also include a network layer and a transport layer. Among them, the first layer of the kernel network stack may be a driver layer, which first receives the target data packet sent by the network device, and then each kernel network stack will parse the target data packet in turn to obtain the information carried in the packet header of the data packet. As the target data packet is parsed by the kernel network stack, the information in the packet header of the target data packet will gradually decrease. Therefore, the hook function set in the driver layer may first store the target data packet in the storage space of the user state, thereby ensuring the data integrity of the captured target data packet.

[0049] Step S202, receiving target kernel information acquired by a hook function set by a kernel network stack of the operating system, wherein the target kernel information includes different target sub-kernel information, and one target sub-kernel information includes a timestamp when a kernel network stack parses a target data packet.

[0050] It should be noted that the target kernel information can be a collection of target sub-kernel information obtained from each layer in the kernel network stack. The target sub-kernel information is the information obtained after the hook function set in the key function of each layer is triggered, such as timestamp, parsing information and other information. By setting different hook functions in different key functions in different kernel network stacks through eBPF technology, stubbing is performed, thereby tracking and monitoring the network data packet processing process at the operating system kernel level.

[0051] Table 1 is a schematic table of key functions for optionally setting a hook function. As shown in Table 1, when a data packet is transmitted through the TCP protocol, the key function for setting the hook function at the driver layer may be: netif_receive_skb, so that when the function is triggered, the hook function located in the function can be triggered, so that the hook function can obtain the target data packet and the driver layer information; the key function for setting the hook function at the TC layer may be: tc, so that when the function is triggered, the hook function can be triggered to obtain TC information; the key function for setting the hook function at the network layer may be: ip_rcv, so that when the function is triggered, the hook function can be triggered to obtain network information; the key function for setting the hook function at the transport layer may be: tcp_v4_rcv, so that when the function is triggered, the hook function can be triggered to obtain transmission information; the key function for setting the hook function at the system call layer may be: tcp_recvmsg, so that when the function is triggered, the hook function can be triggered to obtain system call information (for example, process information).

[0052] Table 1

[0053]

[0054] Exemplarily, after the driver layer sends the target data packet to the user-state storage space, each layer in the kernel network stack will parse the target data packet in turn, and in the process of parsing the target data packet, the hook function preset in the key function of each layer will be triggered. After being triggered, the hook function will record the timestamp of the parsing of the target data packet in the layer, and record the parsing information obtained after the target data packet is parsed in the layer. For example, after parsing at the driver layer, the parsing information obtained may be the driver layer information of the target data packet, after parsing at the TC layer, the parsing information obtained may be the TC layer information of the target data packet, and after parsing at the system call layer, the parsing information obtained may be the system call layer information of the target data packet, and then the obtained parsing information and timestamp are combined into the target sub-kernel information, and the target sub-kernel information in each layer is combined into the complete target kernel information.

[0055] By setting hook functions in key functions in the kernel network stack, it is possible to capture in real time the processing information of each processing step of the data packet from entering the kernel to leaving the kernel, including but not limited to the processing information of the driver layer, TC layer and system call layer, thereby overcoming the limitations of packet capture tools in related technologies that cannot obtain kernel information, and overcoming the problem that obtaining kernel information requires operation and maintenance personnel to have deep kernel knowledge, thereby realizing kernel-level monitoring of traffic, which helps to quickly demarcate network faults with a low threshold.

[0056] Step S203, assembling the target data packet and the target kernel information to obtain an assembly result of the target data packet.

[0057] Exemplarily, after both the target kernel information and the target data packet are stored in the user-state storage space, the target data packet corresponding to the target kernel information can be determined based on the data packet identifier carried by the target kernel information, and the target data packet and the target kernel information can be combined to obtain complete information obtained by performing processing operations on the target data packet in the kernel state. Furthermore, it is possible to determine whether a network failure occurs during the processing of the target data packet in the kernel state based on the target kernel information in the assembly result, and locate the fault point in the event of a network failure, thereby improving the efficiency of determining the network fault point.

[0058] In an embodiment of the present application, a hook function is set in each core network stack of the first-layer kernel network stack of the operating system, so that in the process of data packets being transmitted between the application and the network device through the operating system, the target data packet obtained by the hook function set by the first-layer kernel network stack can be obtained, and when the target data packet is processed by the kernel network stack, the target kernel information obtained by the hook functions set in different kernel network stacks can be obtained, and the target data packet and the target kernel information are assembled and stored, so that it can be determined whether an abnormality occurs in the target data packet during the transmission process according to the target kernel information corresponding to the target data packet, so that when an abnormality occurs in the transmission process of the target data packet, the abnormal location and the abnormal cause can be determined according to the target kernel information corresponding to the target data packet, thereby improving the accuracy and efficiency of determining and delimiting kernel-level network faults, and further solving the technical problem in the related technology that it is difficult to delimit kernel-level network faults using data captured by packet capture tools.

[0059] In order to reduce the storage pressure of the data cache area in the kernel state, optionally, in the data acquisition method of the embodiment of the present application, receiving the target kernel information obtained by the hook function set by the kernel network stack of the operating system includes: receiving the target sub-kernel information obtained by the hook functions set by different kernel network stacks respectively, and receiving the data packet identifiers carried by different target sub-kernel information; assembling the target data packet and the target kernel information includes: calculating the target data packet identifier of the target data packet, and determining the target sub-kernel information carrying the target data packet identifier, and assembling the target data packet and all target sub-kernel information.

[0060] It should be noted that when the target sub-kernel information of each kernel network stack is obtained through the hook function, the target sub-kernel information can be directly sent to the storage space of the user state without being stored in the cache area of ​​the kernel state. Therefore, after receiving the target sub-kernel information sent by the hook functions of different layers, in order to determine the target data packet corresponding to each target sub-kernel information, it is necessary to calculate the unique data packet identifier on the target data packet while the hook function obtains the target sub-kernel information of each layer (for example, the ID, name and other information can be hashed to obtain a unique data packet identifier), and add the unique data packet identifier to the target sub-kernel information, so that when the user state receives the target sub-kernel information sent by the hook function, it can determine the target data packet corresponding to the target sub-kernel information according to the data packet identifier, thereby ensuring the accuracy of assembling the target data packet and the target sub-kernel information.

[0061] Exemplarily, when the target sub-kernel information is obtained by the hook functions of each layer, the target sub-kernel information can be grouped according to the data packet identifier, the identifier of the target sub-kernel information in each group is the same, and the corresponding target data packet is obtained according to the identifier, thereby completing the operation of assembling the target data packet with the corresponding multiple target sub-kernel information and obtaining the assembly result.

[0062] Figure 3 This is a schematic diagram of an optional data acquisition process according to an embodiment of the present application. Figure 1 ,like Figure 3As shown, the network device can be a network card. In the case where the data packet is transmitted through the TCP protocol, after the network card receives the data packet, the operating system can be notified through the interrupt mechanism. The operating system kernel state responds to the interrupt and receives the target data packet from the network card. At this time, the target data packet is processed by the driver layer, and the hook function set in the driver layer is called to copy the target data packet, and the copied target data packet is stored in the storage space of the user state. The parsing information and timestamp of the target data packet in the driver layer are obtained through the hook function to obtain the driver layer information. After the driver layer completes the processing of the target data packet, the TC layer obtains the target data packet, and the hook function in the TC layer obtains the parsing information and timestamp of the target data packet in the TC layer. Timestamp, get TC layer information, further, the hook function in the network layer obtains the parsing information and timestamp of the target data packet in the network layer, and obtains the network layer information, the hook function in the transport layer obtains the parsing information and timestamp of the target data packet in the transport layer, and obtains the transport layer information, the hook function in the system call layer obtains the parsing information and timestamp of the target data packet in the transport layer, and obtains the system call layer information, and transmits the target sub-kernel information obtained in each layer to the user state storage space respectively, and then in the user state storage space, according to the target data packet identifier carried on the target sub-kernel information, assemble the target data packet and all corresponding target sub-kernel information to obtain the assembly result of the target data packet.

[0063] This embodiment obtains the target sub-kernel information sent by the hook functions of different kernel network stacks in the user state, and combines the target sub-kernel information with the corresponding data packet according to the data packet identifier in the user state, thereby avoiding caching the target data packet and the target sub-kernel information of each kernel network stack in the data cache area of ​​the kernel state, and reducing the storage pressure of the data cache area of ​​the kernel state.

[0064] In order to reduce the data processing load in the user state, optionally, in the data acquisition method of the embodiment of the present application, the target kernel information obtained by the hook function set by the kernel network stack of the receiving operating system includes: receiving the target sub-kernel information set sent by the last layer of the kernel network stack of the operating system, wherein the hook functions set by different kernel network stacks sequentially cache the obtained target sub-kernel information to the first cache area of ​​the kernel, and merge the target sub-kernel information associated with the data packet identifier of the target data packet into a target sub-kernel information set in the last layer of the kernel network stack; assembling the target data packet and the target kernel information includes: calculating the target data packet identifier of the target data packet, and determining the target sub-kernel information set carrying the target data packet identifier, and assembling the target data packet and the target sub-kernel information set.

[0065] Exemplarily, after receiving the target data packet, the kernel network stack of each layer parses the target data packet respectively to obtain parsing information and a timestamp, and combines the parsing information and the timestamp into target sub-kernel information, and then stores the target sub-kernel information in the first cache area of ​​the kernel state according to the data packet identifier. Exemplarily, when the hook function in the first layer of the kernel network stack (for example, the driver layer) obtains the target sub-kernel information, the target sub-kernel information and its data packet identifier are stored in the first cache area, and when the hook function in the next layer of the kernel network stack obtains the target sub-kernel information, the data packet identifier is obtained from the first cache area. The method obtains all target sub-kernel information under the target packet identifier, and after splicing the target sub-kernel information obtained by itself and all target sub-kernel information under the same data packet identifier in the first cache area, stores it in the first cache area until the hook function in the last first-layer kernel network stack (for example, the system call layer) obtains the target sub-kernel information and all target sub-kernel information under the same data packet identifier in the first cache area, splicing them, and obtaining a set of target sub-kernel information carrying the target data packet identifier (that is, the target kernel information), thereby eliminating the need to group and integrate the target sub-kernel information in the user state, thereby reducing the amount of resources and computing power consumed in the user state.

[0066] Furthermore, after obtaining the target sub-kernel information set, the system call layer sends the target sub-kernel information set to the user-state storage space, determines the data packet identifier of the target sub-kernel information set in the user-state storage space, and determines the target data packet associated with the target sub-kernel information set based on the data packet identifier, and then combines the target sub-kernel information set with the target data packet in the user state to obtain an assembly result.

[0067] Figure 4 This is a schematic diagram of an optional data acquisition process according to an embodiment of the present application. Figure 2 ,like Figure 4As shown, the network device can be a network card. In the case where the data packet is transmitted through the TCP protocol, after the network card receives the data packet, the operating system can be notified through the interrupt mechanism. The operating system kernel state responds to the interrupt and receives the target data packet from the network card. At this time, the target data packet is processed by the driver layer, and the hook function set in the driver layer is called to copy the target data packet, store the copied target data packet in the storage space of the user state, and obtain the parsing information and timestamp of the target data packet at the driver layer through the hook function to obtain the driver layer information, calculate the data packet identifier, and store the data packet identifier and the driver layer information in the first cache area. After the driver layer completes the processing of the target data packet, the TC layer obtains the target data packet, and the hook function in the TC layer obtains the parsing information and timestamp of the target data packet at the TC layer to obtain the TC layer information, and obtains the driver layer information from the first cache area according to the data packet identifier, splices the driver layer information and the TC layer information, and stores the spliced ​​information in the first cache area. Further, the network layer obtains the target data packet, and the hook function in the network layer obtains the parsing information and timestamp of the target data packet at the network layer Timestamp, get network layer information, and get splicing information from the first buffer area according to the data packet identifier, splice the splicing information and the network layer information again, and store the spliced ​​information in the first buffer area. Further, the transport layer gets the target data packet, and the hook function in the transport layer gets the parsing information and timestamp of the target data packet in the transport layer to get the transport layer information, and get the splicing information from the first buffer area according to the data packet identifier, splice the splicing information and the transport layer information again, and store the spliced ​​information in the first buffer area. Finally, the system call layer processes the target data packet to get the system call layer information. The system call layer gets the splicing information of the driver layer information, the TC layer information, the network layer information and the transport layer information from the first buffer area according to the data packet identifier, and combines the driver layer information, the TC layer information, the network layer information and the transport layer information with the system call layer information into a target sub-kernel information set, and sends it to the storage space in the user state. In the user state, according to the target data packet identifier carried by the target sub-kernel information set, the target data packet and the corresponding target sub-kernel information set are assembled to get the assembly result of the target data packet.

[0068] In addition, it should be noted that when the target data packet is lost at the transport layer, the kernel information that has been obtained is placed in the cache, and the kernel information of the target data packet will be sent to the user state together when the next data packet is transmitted. For example, if 5 data packets are transmitted and the 4th data packet is lost at the transport layer, the kernel information that has been obtained for the 4th data packet is placed in the cache, and when the 5th packet reaches the system call layer, the kernel information of the 4th packet and the kernel information of the 5th packet itself will be sent to the user state together, so that the user state can obtain the kernel information of the lost data packet.

[0069] This embodiment obtains the target sub-kernel information sent by the hook functions of different kernel network stacks in the user state, stores the target sub-kernel information of each layer in the first cache area of ​​the kernel state by appending writes, and the last layer of the kernel network stack combines the target sub-kernel information of each layer into a target sub-kernel information set, and sends the target sub-kernel information set to the user state, and combines the target sub-kernel information set with the data packet in the user state, thereby achieving the technical effect of reducing the data processing load of the user state.

[0070] In order to improve the storage efficiency of data packets, optionally, in the data acquisition method of the embodiment of the present application, before receiving the target data packet obtained by the hook function set by the first layer kernel network stack of the operating system, the method also includes: receiving a first instruction message sent by a user, wherein the first instruction message instructs the hook function set by the first layer kernel network stack to obtain a packet header and a packet body of the target data packet; receiving the target data packet obtained by the hook function set by the first layer kernel network stack of the operating system includes: receiving the packet header and a packet body of the target data packet obtained by the hook function set by the first layer kernel network stack; or, before receiving the target data packet obtained by the hook function set by the first layer kernel network stack of the operating system, the method also includes: receiving a second instruction message sent by a user, wherein the second instruction message instructs the hook function set by the first layer kernel network stack to obtain a packet header of the target data packet; receiving the target data packet obtained by the hook function set by the first layer kernel network stack of the operating system includes: receiving the packet header of the target data packet obtained by the hook function set by the first layer kernel network stack.

[0071] It should be noted that the first layer of the kernel network stack can be a driver layer. When the target data packet is obtained through the hook function of the driver layer, since the data packet consists of a packet header and a packet body, and in some scenarios, the user state has no need to store the packet body data, the composition of the target data packet sent by the driver layer to the user state can be determined according to the user's instruction information, so that the data packet can be transmitted according to the different needs of the user, and the amount of data stored in the user state storage space can be further reduced.

[0072] Exemplarily, when the first instruction information sent by the user is received, it indicates that the user needs to capture the entire content of the target data packet, that is, both the packet header and the packet body need to be stored in the user state. At this time, the hook function set in the driver layer for obtaining the target data packet will respond to the first instruction information sent by the user, and store all the data in the target data packet in the user state, thereby ensuring the integrity of the data.

[0073] Exemplarily, when receiving the second instruction sent by the user, it indicates that the user only needs to capture the header of the target data packet, and does not need to capture the specific data content (i.e., payload) in the target data packet. At this time, the hook function set in the driver layer for obtaining only the header of the target data packet will respond to the second instruction information sent by the user, parse the target data packet, and store the header in the target data packet in the user state, thereby reducing the amount of data storage in the user state.

[0074] This embodiment stores different data packet contents (packet header, or packet header and packet body) in user state according to different user instruction information. While ensuring the integrity of diagnostic information, it not only reduces the data storage volume in the user state, but also significantly reduces the size of the generated file, improves the processing speed and storage efficiency, thereby achieving the technical effect of effectively reducing the burden on the system.

[0075] In order to improve the efficiency of fault analysis of target data packets, optionally, in the data acquisition method of the embodiment of the present application, before receiving the target data packet obtained by the hook function set by the first layer kernel network stack of the operating system, the method also includes: receiving third instruction information sent by the user, wherein the third instruction information instructs the hook function set by the first layer kernel network stack to obtain data packets that meet preset filtering conditions, and the preset filtering conditions include at least one of the following: source address, destination address, source port number and destination port number; receiving the target data packet obtained by the hook function set by the first layer kernel network stack of the operating system includes: receiving the data packet that meets the preset filtering conditions obtained by the hook function set by the first layer kernel network stack to obtain the target data packet.

[0076] Exemplarily, when a third instruction message is received from a user, the data packets that the user wants to obtain can be determined based on the third instruction message. That is, instead of storing all data packets in the user state, only data packets that meet the preset filtering conditions in the third instruction message sent by the user are stored in the user state, thereby ensuring that only the most critical data packets are obtained.

[0077] For example, the third instruction information may be: obtain data packets with a target address of A. At this time, the hook function set in the first layer of the kernel network stack (for example, the driver layer) will filter the data packets according to the preset filtering conditions in the third instruction information, and only obtain data packets with a target address of A, thereby improving the targeted acquisition and analysis of data packets and avoiding interference of irrelevant data packets with the analysis process.

[0078] This embodiment sets filtering conditions. When acquiring data packets, the data packets are filtered according to the filtering conditions, and the data packets that meet the filtering conditions are stored in the user state storage space. This not only greatly reduces the number of captured data packets, but also avoids the interference of irrelevant data packets on the analysis process, thereby improving the accuracy and efficiency of data packet analysis.

[0079] In the event of a network failure resulting in packet loss, in order to accurately determine the packet loss location, optionally, in the data acquisition method of an embodiment of the present application, after assembling the target data packet and the target kernel information to obtain the assembly result of the target data packet, the method also includes: writing the assembly result to a storage device; in the event that the target data packet is lost during transmission, obtaining the assembly result of the target data packet from the storage device; obtaining the target kernel network stack associated with the last timestamp from the kernel information of the assembly result, and determining the next kernel network stack adjacent to the target kernel network stack in the transmission path as the packet loss location.

[0080] It should be noted that most data acquired by kernel tools have their own data formats, and format identification and conversion are required during data transmission. After obtaining the assembly result, in order to ensure that other devices can read the assembly result data and reduce the cost of format identification and conversion, this embodiment can output the assembly result in the standard data format pcapng and store it in the user-state pcapng file.

[0081] Furthermore, after the assembly result is written to the storage device, in the case that the target data packet is lost during the transmission process, the cause of the packet loss can be determined according to the assembly result of the target data packet in the storage device. First, the assembly result of the target data packet is obtained from the storage device, and the target kernel network stack associated with the last timestamp is obtained from the target kernel information of the assembly result. Since the timestamp obtained by the target kernel network stack in the kernel information is the last timestamp, it indicates that when the target data packet is processed in the target kernel network stack, a network failure occurs when the next kernel network stack of the target kernel network stack is processed, resulting in the absence of the timestamp corresponding to the next kernel network stack in the kernel information. Therefore, it can be determined that a network failure occurs when the target data packet is processed in the next kernel network stack adjacent to the target kernel network stack in the transmission path, resulting in packet loss, and then the next kernel network stack adjacent to the target kernel network stack in the transmission path can be determined as the failure point where the network failure occurs.

[0082] After determining the fault point of packet loss, the type of packet loss can be further determined by the content of the target data packet in the assembly result. For example, the type of packet loss can be a handshake data packet, an authentication data packet, or a business information data packet. The cause of packet loss can also be determined by the kernel information of the target data packet. For example, the cause of packet loss can be a security group reason. If an IP whitelist and a port whitelist are set, the packet loss may be caused by a mismatch in the security group. It is also possible that when the kernel calculates the checksum of the kernel group of the data packet, the checksum does not match and causes packet loss. Exemplarily, in addition to the timestamp, each layer of kernel information also contains call stack information (for example, function A calls function B calls function C, which is a call stack), locates the packet loss at the transport layer, and captures the call stack at the transport layer. It can be determined which function called the last packet loss function, find the process where the function is located, the task where the process is located, and analyze the corresponding process and task, so as to determine the cause of packet loss.

[0083] When packet loss occurs, this embodiment determines the target kernel network stack associated with the last timestamp based on the target kernel information, and determines the next kernel network stack as the fault point of the packet loss failure, thereby achieving the technical effect of accurately determining the fault point based on the target kernel information and improving the efficiency of finding the fault point.

[0084] In the case of network jitter, there is a deviation between the time interval for the data packet to arrive at the receiving end and the expected time interval. In order to determine whether the transmission timeout is caused by a certain kernel network stack or the overall kernel delay is too high, optionally, in the data acquisition method of the embodiment of the present application, after assembling the target data packet and the target kernel information to obtain the assembly result of the target data packet, the method also includes: obtaining the first timestamp and the last timestamp from the kernel information of the assembly result to obtain the first timestamp and the second timestamp; comparing the difference between the first timestamp and the second timestamp with the preset duration, and judging whether the transmission duration of the target data packet has timed out according to the comparison result; in the case of a transmission duration timeout, determining the timed out kernel network stack based on the difference between every two adjacent timestamps.

[0085] It should be noted that according to the assembly results, the time taken for each data packet to pass through the kernel network stacks in the kernel state can be accurately tracked, so as to identify whether the overall kernel delay is too high or a specific kernel network stack becomes a bottleneck for data packet processing, thereby promptly discovering the fault point of the network failure and processing it in time to avoid network failures when the data packet is processed later.

[0086] Exemplarily, after obtaining the assembly result, since the kernel information includes the timestamps of each layer, the first timestamp and the last timestamp in the kernel information can be obtained, so as to calculate the time taken to process the data packet in the kernel based on the first timestamp and the last timestamp, and compare the time taken with the preset duration to determine whether the process of processing the data packet has timed out, and then determine whether there is an abnormal kernel network stack at a certain layer in the kernel.

[0087] Furthermore, when the transmission duration times out, it indicates that there is network jitter in the kernel. At this time, it is impossible to determine whether there is delay in each layer of the kernel network stack or whether there is a more serious delay processing phenomenon in a certain layer of the kernel network stack. Therefore, the time difference between each adjacent timestamp can be calculated to determine the time taken by each layer of the kernel network stack to process the data packet, and the time taken by each layer can be compared with the longest processing time of each layer to determine the kernel network stack with delayed processing, thereby achieving the technical effect of accurately locating the kernel network stack with delay, and the kernel network stack with delay can be further processed in time, ensuring the accuracy and stability of subsequent data packet processing.

[0088] Exemplarily, each layer of the kernel network stack is respectively provided with a corresponding data processing time threshold. For example, the time difference between the timestamp of the network layer and the timestamp of the transport layer is the data processing time of the network layer. When the data processing time of the network layer is greater than the data processing time threshold of the network layer, and the processing times of other layers are normal, it indicates that there is a serious delay in processing at the network layer, and the network layer needs to be diagnosed. For another example, the data processing time of each layer of the kernel network stack is calculated based on the difference between every two adjacent timestamps. When the data processing time of each layer of the kernel network stack is greater than the corresponding data processing time threshold, it can be determined that there is a delay in each layer of the kernel network stack. At this time, the kernel needs to be processed to achieve the technical effect of determining the fault location.

[0089] This embodiment determines whether a transmission timeout occurs through the first timestamp and the last timestamp in the kernel information, and in the case of a transmission timeout, determines the processing time of the data packet by each layer of the kernel network stack based on the difference between every two adjacent timestamps, and determines whether the overall kernel delay is too high or a certain kernel network stack causes the transmission timeout based on the processing time of the data packet by each layer of the kernel network stack, thereby achieving the technical effect of accurately locating the kernel network stack with delay in a network jitter scenario, thereby ensuring the accuracy and stability of subsequent processing of the data packet.

[0090] Example 2

[0091] According to an embodiment of the present application, a data acquisition method is also provided. Figure 5is a schematic diagram of another data acquisition method according to an embodiment of the present application, such as Figure 5 As shown, the data acquisition method is applied in the process of an application sending a data packet to a network device through an operating system, and includes:

[0092] Step S501, receiving the assembly result of the target data packet transmitted by the first layer kernel network stack of the kernel of the operating system, wherein the assembly result includes the target data packet and target kernel information, the target kernel information is obtained by the hook function set by the kernel network stack of the operating system, the target kernel information includes different target sub-kernel information, and a target sub-kernel information includes a timestamp when the kernel network stack encapsulates the target data packet.

[0093] It should be noted that the target kernel information can be a collection of target sub-kernel information obtained from each layer in the kernel network stack. The target sub-kernel information is the information obtained after the hook function set in the key function of each layer is triggered, such as timestamp, encapsulation information and other information. By setting different hook functions in different key functions in different kernel network stacks through eBPF technology, stubbing is performed, thereby tracking and monitoring the network data packet encapsulation process at the operating system kernel level.

[0094] The hook function is a preset code in the key function of each kernel network stack in the kernel state of the operating system. The key function refers to the function that the data packet passes through when the application transmits the data packet to the network device through the operating system. The key function is called when the kernel network stack processes the data packet. At this time, the hook function set in the key function will be triggered to obtain the encapsulation information and timestamp information obtained when the data packet is encapsulated. Among them, the kernel network stack includes at least the driver layer, the TC layer (Traffic Control Layer) and the system call layer. When the data packet is transmitted through the TCP protocol, the kernel network stack can also include the network layer and the transport layer.

[0095] Table 2 is an optional configuration table of key functions. As shown in Table 2, when the data packet is transmitted through the TCP protocol, the key function of setting the hook function at the system call layer may be: tcp_sendmsg, so that when the function is triggered, the hook function can be triggered to obtain the system call information; the key function of setting the hook function at the transport layer may be: tcp_transmit_skb, so that when the function is triggered, the hook function can be triggered to obtain the transmission information; the key function of setting the hook function at the network layer may be: ip_output, so that when the function is triggered, the hook function can be triggered to obtain the network information; the key function of setting the hook function at the TC layer may be: tc, so that when the function is triggered, the hook function can be triggered to obtain the TC information; the key function of setting the hook function at the driver layer may be: dev_queue_xmit, so that when the function is triggered, the hook function located in the function can be triggered, so that the hook function can obtain the target data packet and the driver layer information.

[0096] It should be noted that in the scenario of sending data packets, the key functions set in each kernel network stack can be different from the key functions under receiving data packets, ensuring that in the process of receiving and sending data packets, the hook functions can be performed accurately and will not affect each other.

[0097] Table 2

[0098]

[0099] Exemplarily, in the process of an application sending a target data packet to a network device through an operating system, the target data packet needs to be encapsulated through each kernel network stack, and in the process of encapsulating the target data packet, a hook function preset in a key function of each layer will be triggered. After the hook function is triggered, it will record the timestamp of encapsulating the target data packet in the layer, and record the encapsulation information obtained after the target data packet is encapsulated in the layer, and obtain the corresponding target sub-kernel information. For example, after encapsulation at the system call layer, the encapsulation information obtained can be the system call layer information of the target data packet, after encapsulation at the TC layer, the encapsulation information obtained can be the TC layer information of the target data packet, and after encapsulation at the driver layer, the encapsulation information obtained can be the driver layer information of the target data packet.

[0100] After obtaining the target sub-kernel information of the target data packet encapsulated by each kernel network stack, the target sub-kernel information of the target data packet processed by each kernel network stack is combined into target kernel information, the target kernel information is combined with the data packet, and the combined result is sent to the user state through the driver layer for storage, ensuring that in the event of a network failure during the sending of the data packet, the fault point can be determined based on the information in the target kernel information, thereby improving the efficiency of fault handling.

[0101] In an embodiment of the present application, a hook function is set in each kernel network stack, so that in the process of data packets being transmitted between an application and a network device through an operating system, the target kernel information obtained by the hook functions set in different kernel network stacks can be obtained, and the target data packet and the target kernel information can be assembled and stored, so that it can be determined whether an abnormality occurs in the target data packet during transmission according to the target kernel information corresponding to the target data packet. In this way, when an abnormality occurs in the transmission of the target data packet, the abnormal location and the abnormal cause can be determined according to the target kernel information corresponding to the target data packet, thereby improving the accuracy and efficiency of determining and delimiting kernel-level network failures, and further solving the technical problem in the related technology that it is difficult to delimit kernel-level network failures using data captured by packet capture tools.

[0102] In order to ensure the accurate splicing of the target sub-kernel data and the data packet and reduce the storage pressure of the kernel's second cache area, optionally, in the data acquisition method of the embodiment of the present application, different target sub-kernel information all carry data packet identifiers, and the hook functions set by different kernel network stacks cache the acquired target sub-kernel information to the kernel's second cache area in turn, and assemble the target data packet and the target sub-kernel information associated with the data packet identifier of the target data packet in the first-layer kernel network stack.

[0103] Figure 6 This is a schematic diagram of an optional data acquisition process according to an embodiment of the present application. Figure 3 ,like Figure 6 As shown, the network device can be a network card. When the data packet is transmitted through the TCP protocol, in the process of the application sending the target data packet to the network card through the operating system, the package body of the target data packet is first sent from the user state to the kernel state, and the hook function in the system call layer in the kernel state encapsulates the package body of the target data packet, and obtains the system call layer information according to the encapsulation information and the timestamp. Since the subsequent multiple kernel network stacks also need to encapsulate the target data packet, it is necessary to send the target data packet to the next layer, and store the target data packet identifier and the system call layer information in association with each other in the second cache area, wherein the second cache area and the first cache area are two cache areas, respectively storing the target sub-kernel information corresponding to the received data packet and the sent data packet.

[0104] Furthermore, when the transport layer receives the target data packet, the hook function in the transport layer encapsulates the target data packet to obtain transport layer information, and obtains system call layer information from the second cache area according to the target data packet identifier, splices the system call layer information and the transport layer information to obtain splicing information, and sends the splicing information to the second cache area.

[0105] When the network layer receives the target data packet, the hook function in the network layer encapsulates the target data packet to obtain network layer information, and obtains splicing information of system call layer information and transport layer information from the second cache area according to the target data packet identifier, splices the network layer information, the system call layer information and the transport layer information to obtain splicing information, and sends the splicing information to the second cache area.

[0106] When the TC layer receives the target data packet, the hook function in the TC layer encapsulates the target data packet to obtain TC layer information, and obtains the splicing information of the system call layer information, the transport layer information and the network layer information from the second cache area according to the target data packet identifier, splices the TC layer information, the system call layer information, the transport layer information and the network layer information to obtain the splicing information, and sends the splicing information to the second cache area.

[0107] Until the data packet is sent to the driver layer, the hook function in the driver layer processes the data packet to obtain the driver layer information. At this time, the driver layer obtains the splicing information composed of the system call layer information, the transport layer information, the network layer information and the TC layer information from the second buffer area according to the data packet identifier, and combines the driver layer information and the target data packet with the splicing information to obtain the assembly result. The assembly result is sent to the user state, so that the user state can store the assembly result of the target data packet, or determine whether there is a network failure in the sending process according to the assembly result.

[0108] This embodiment obtains the target sub-kernel information sent by the hook functions of different kernel network stacks in user mode, writes the target sub-kernel information of each layer to the second cache area by appending, and assembles the target data packet and the target sub-kernel information of the data packet identifier associated with the target data packet in the driver layer. There is no need to store the packet body of the target data packet in the second cache area, which reduces the amount of data stored in the second cache area during the packet capture process, thereby achieving the technical effect of improving the encapsulation efficiency and packet capture efficiency of the data packet.

[0109] Example 3

[0110] According to an embodiment of the present application, a data acquisition method is also provided. Figure 7 is a schematic diagram of another data acquisition method according to an embodiment of the present application, such as Figure 7As shown, the data acquisition method is applied in the process of an application receiving a data packet transmitted by a network device through an operating system, and includes:

[0111] Step S701, receiving a target data packet.

[0112] The execution subject of this embodiment is the kernel state of the operating system, and the kernel state receives the target data packet transmitted by the network device.

[0113] Step S702, copying the target data packet through the hook function set by the first layer kernel network stack of the operating system, and sending the copied target data packet to the application.

[0114] Exemplarily, when the operating system receives the target data packet, the target data packet enters the kernel network stack in the kernel state. Among them, the first layer of the kernel network stack can be a driver layer. The driver layer first receives the target data packet sent by the network device, and then each kernel network stack will parse the target data packet in turn to obtain the information carried in the packet header of the data packet. As the target data packet is parsed by the kernel network stack, the information in the packet header of the target data packet will gradually decrease. Therefore, the target data packet can be copied by the hook function set in the driver layer first, and the target data packet is stored in the storage space of the user state, thereby ensuring the data integrity of the captured target data packet. The hook function set in the driver layer is a preset code in the key function that the data packet under the driver layer passes through, which is called when the driver layer processes the data packet to copy the target data packet.

[0115] Step S703, parse the target data packet layer by layer through the kernel network stack of the operating system, obtain the target kernel information obtained by parsing the target data packet through the hook function set by the kernel network stack, and send the target kernel information to the application, wherein the target kernel information includes different target sub-kernel information, and a target sub-kernel information includes a timestamp when the kernel network stack parses the target data packet. The application assembles the target data packet and the target kernel information to obtain the assembly result of the target data packet.

[0116] Among them, the kernel network stack at least includes a driver layer, a TC layer and a system call layer. When the data packet is transmitted through the TCP protocol, the kernel network stack can also include a network layer and a transport layer. The driver layer parses the target data packet to obtain driver information, the TC layer parses the target data packet to obtain TC information, the network layer parses the target data packet to obtain network information, and the transport layer parses the target data packet to obtain transmission information.

[0117] It should be noted that the hook function is a preset code in the key function under each kernel network stack in the kernel state of the operating system. The key function refers to the function that the data packet passes through when the network device transmits the data packet to the application through the operating system. The key function is called when the kernel network stack processes the data packet. At this time, the hook function set in the key function will be triggered, thereby obtaining the parsing information and timestamp information obtained when the data packet is parsed.

[0118] The target kernel information can be a collection of target sub-kernel information obtained for each layer in the kernel network stack. The target sub-kernel information is information obtained after the hook function set in the key function of each layer is triggered, such as timestamp, parsing information and other information. By setting different hook functions in different key functions in different kernel network stacks through eBPF technology, stubbing is performed, thereby tracking and monitoring the network data packet processing process at the operating system kernel level.

[0119] After storing both the target kernel information and the target data packet in the user-state storage space, the target data packet corresponding to the target kernel information can be determined based on the data packet identifier carried by the target kernel information, and the target data packet and the target kernel information can be combined to obtain complete information obtained by executing processing operations on the target data packet in the kernel state. Furthermore, it is possible to determine whether a network failure occurs during the processing of the target data packet in the kernel state based on the target kernel information in the assembly result, and locate the fault point in the event of a network failure, thereby improving the efficiency of determining the network fault point.

[0120] In an embodiment of the present application, a hook function is set in each kernel network stack of the first-layer kernel network stack of the operating system, so that in the process of data packets being transmitted between the application and the network device through the operating system, the hook function set in the first-layer kernel network stack of the kernel state of the operating system copies the target data packet and sends the target data packet to the user state of the application. When the target data packet is processed by the kernel network stack, the hook functions set in different kernel network stacks obtain the target kernel information and send the target kernel information to the user state. The user state further assembles and stores the target data packet and the target kernel information, so that it is possible to determine whether an exception occurs in the transmission of the target data packet according to the target kernel information corresponding to the target data packet. In this way, when an exception occurs in the transmission of the target data packet, the exception location and the exception cause can be determined according to the target kernel information corresponding to the target data packet, thereby improving the accuracy and efficiency of determining and delimiting kernel-level network failures, and further solving the technical problem in the related art that it is difficult to delimit kernel-level network failures using data captured by packet capture tools.

[0121] Example 4

[0122] According to an embodiment of the present application, a data acquisition method is also provided. Figure 8 is a schematic diagram of another data acquisition method according to an embodiment of the present application, such as Figure 8 As shown, the data acquisition method is applied in the process of an application sending a data packet to a network device through an operating system, and includes:

[0123] Step S801, receiving a target data packet.

[0124] The execution subject of this embodiment is the kernel state of the operating system, and the kernel state receives the target data packet transmitted by the network device.

[0125] Step S802, encapsulate the target data packet layer by layer through the kernel network stack of the operating system, obtain the target kernel information obtained by encapsulating the target data packet through the hook function set by the kernel network stack, and send the target kernel information to the application, wherein the target kernel information includes different target sub-kernel information, and a target sub-kernel information includes a timestamp when the kernel network stack encapsulates the target data packet. The application assembles the encapsulated target data packet and the target kernel information to obtain the assembly result of the target data packet.

[0126] It should be noted that the target kernel information can be a collection of target sub-kernel information obtained from each layer in the kernel network stack. The target sub-kernel information is the information obtained after the hook function set in the key function of each layer is triggered, such as timestamp, encapsulation information and other information. By setting different hook functions in different key functions in different kernel network stacks through eBPF technology, stubbing is performed, thereby tracking and monitoring the network data packet encapsulation process at the operating system kernel level.

[0127] The hook function is a preset code in the key function of each kernel network stack in the kernel state of the operating system. The key function refers to the function that the data packet passes through when the application transmits the data packet to the network device through the operating system. The key function is called when the kernel network stack processes the data packet. At this time, the hook function set in the key function will be triggered to obtain the encapsulation information and timestamp information obtained when the data packet is encapsulated. Among them, the kernel network stack includes at least the driver layer, the TC layer (Traffic Control Layer) and the system call layer. When the data packet is transmitted through the TCP protocol, the kernel network stack can also include the network layer and the transport layer.

[0128] After obtaining the target sub-kernel information of the target data packet encapsulated by each kernel network stack, the target sub-kernel information of the target data packet processed by each kernel network stack is combined into target kernel information, the target kernel information is combined with the data packet, and the combined result is sent to the user state through the driver layer for storage, ensuring that in the event of a network failure during the sending of the data packet, the fault point can be determined based on the information in the target kernel information, thereby improving the efficiency of fault handling.

[0129] In an embodiment of the present application, a hook function is set in each kernel network stack of the first layer kernel network stack of the operating system, so that when the data packet is transmitted between the application and the network device through the operating system, when the target data packet is processed by the kernel network stack, the hook functions set in different kernel network stacks obtain the target kernel information and send the target kernel information to the user state. After the encapsulated target data packet is sent to the user state, the user state further assembles and stores the target data packet and the target kernel information, so that it can be determined whether an abnormality occurs in the target data packet during the transmission process according to the target kernel information corresponding to the target data packet. In the event that an abnormality occurs during the transmission of the target data packet, the abnormal location and the abnormal cause can be determined according to the target kernel information corresponding to the target data packet, thereby improving the accuracy and efficiency of determining the delimitation of kernel-level network faults, and further solving the technical problem in the related technology that it is difficult to delimit kernel-level network faults using data captured by packet capture tools.

[0130] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the described order of actions, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present application.

[0131] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, disk, CD), and includes a number of instructions for a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0132] Example 5

[0133] According to an embodiment of the present application, a data acquisition device for implementing the above data acquisition method is also provided. Fig. 9 is a schematic diagram of a data acquisition device according to an embodiment of the present application, such as Fig. 9 As shown, the data acquisition device is applied in the process of receiving data packets transmitted by network devices through an application program through an operating system, and includes:

[0134] The first receiving unit 91 is used to receive a target data packet obtained by a hook function set by a first layer kernel network stack of the operating system.

[0135] The second receiving unit 92 is used to receive target kernel information obtained by a hook function set by a kernel network stack of the operating system, wherein the target kernel information includes different target sub-kernel information, and one target sub-kernel information includes a timestamp when the kernel network stack parses the target data packet.

[0136] The first assembling unit 93 is used to assemble the target data packet and the target kernel information to obtain an assembly result of the target data packet.

[0137] Optionally, in the data acquisition device of the embodiment of the present application, the second receiving unit 92 includes: a first receiving module, used to respectively receive target sub-kernel information obtained by hook functions set by different kernel network stacks, and receive data packet identifiers carried by different target sub-kernel information; the first assembling unit 93 includes: a first assembling module, used to calculate the target data packet identifier of the target data packet, and determine the target sub-kernel information carrying the target data packet identifier, and assemble the target data packet and all target sub-kernel information.

[0138] Optionally, in the data acquisition device of the embodiment of the present application, the second receiving unit 92 includes: a second receiving module, used to receive a target sub-kernel information set sent by the last layer of the kernel network stack of the operating system, wherein the hook functions set by different kernel network stacks cache the acquired target sub-kernel information to the first cache area of ​​the kernel in turn, and merge the target sub-kernel information associated with the data packet identifier of the target data packet into a target sub-kernel information set at the last layer of the kernel network stack; the first assembling unit 93 includes: a second assembling module, used to calculate the target data packet identifier of the target data packet, and determine the target sub-kernel information set carrying the target data packet identifier, and assemble the target data packet and the target sub-kernel information set.

[0139] Optionally, in the data acquisition device of the embodiment of the present application, before receiving the target data packet obtained by the hook function set by the first layer kernel network stack of the operating system, the device also includes: a third receiving unit, used to receive the first instruction information sent by the user, wherein the first instruction information indicates that the hook function set by the first layer kernel network stack obtains the header and body of the target data packet; the first receiving unit 91 includes: a first receiving module, used to receive the header and body of the target data packet obtained by the hook function set by the first layer kernel network stack; or, before receiving the target data packet obtained by the hook function set by the first layer kernel network stack of the operating system, the device also includes: a fourth receiving unit, used to receive the second instruction information sent by the user, wherein the second instruction information indicates that the hook function set by the first layer kernel network stack obtains the header of the target data packet; the first receiving unit 91 includes: a second receiving module, used to receive the header of the target data packet obtained by the hook function set by the first layer kernel network stack.

[0140] Optionally, in the data acquisition device of the embodiment of the present application, before receiving the target data packet obtained by the hook function set by the first layer kernel network stack of the operating system, the device also includes: a fifth receiving unit, used to receive third instruction information sent by a user, wherein the third instruction information instructs the hook function set by the first layer kernel network stack to obtain data packets that meet preset filtering conditions, and the preset filtering conditions include at least one of the following: source address, destination address, source port number and destination port number; the first receiving unit 91 includes: a third receiving module, used to receive the data packet that meets the preset filtering conditions obtained by the hook function set by the first layer kernel network stack, and obtain the target data packet.

[0141] Optionally, in the data acquisition device of the embodiment of the present application, after assembling the target data packet and the target kernel information to obtain the assembly result of the target data packet, the device also includes: a writing unit, used to write the assembly result to a storage device; a first acquisition unit, used to obtain the assembly result of the target data packet from the storage device when the target data packet is lost during transmission; a second acquisition unit, used to obtain the target kernel network stack associated with the last timestamp from the kernel information of the assembly result, and determine the next kernel network stack adjacent to the target kernel network stack in the transmission path as the packet loss location.

[0142] Optionally, in the data acquisition device of the embodiment of the present application, after assembling the target data packet and the target kernel information to obtain the assembly result of the target data packet, the device also includes: a third acquisition unit, used to obtain the first timestamp and the last timestamp from the kernel information of the assembly result to obtain the first timestamp and the second timestamp; a comparison unit, used to compare the difference between the first timestamp and the second timestamp with a preset duration, and determine whether the transmission duration of the target data packet has timed out based on the comparison result; a determination unit, used to determine the timed out kernel network stack based on the difference between every two adjacent timestamps when the transmission duration times out.

[0143] It should be noted that the preferred implementation scheme involved in the above embodiments of the present application is the same as the scheme provided in Example 1, as well as the application scenario and implementation process, but is not limited to the scheme provided in Example 1.

[0144] Example 6

[0145] According to an embodiment of the present application, a data acquisition device for implementing the above data acquisition method is also provided. Fig.10 is a schematic diagram of another data acquisition device according to an embodiment of the present application, such as Fig.10 As shown, the data acquisition device is applied in the process of an application sending a data packet to a network device through an operating system, and includes:

[0146] The sixth receiving unit 1001 is used to receive the assembly result of the target data packet transmitted by the first layer kernel network stack of the kernel of the operating system, wherein the assembly result includes the target data packet and target kernel information, the target kernel information is obtained by the hook function set by the kernel network stack of the operating system, the target kernel information includes different target sub-kernel information, and a target sub-kernel information includes a timestamp when the kernel network stack encapsulates the target data packet.

[0147] Optionally, in the data acquisition device of the embodiment of the present application, different target sub-kernel information all carries a data packet identifier, and the hook functions set by different kernel network stacks cache the acquired target sub-kernel information to the second cache area of ​​the kernel in turn, and assemble the target data packet and the target sub-kernel information associated with the data packet identifier of the target data packet in the first layer of the kernel network stack.

[0148] It should be noted that the preferred implementation scheme involved in the above embodiments of the present application is the same as the scheme provided in Example 2 as well as the application scenario and implementation process, but is not limited to the scheme provided in Example 2.

[0149] Example 7

[0150] According to an embodiment of the present application, a data acquisition device for implementing the above data acquisition method is also provided. Fig.11is a schematic diagram of another data acquisition device according to an embodiment of the present application, such as Fig.11 As shown, the data acquisition device is applied in the process of receiving data packets transmitted by network devices through an application program through an operating system, and includes:

[0151] The seventh receiving unit 1101 is used to receive a target data packet.

[0152] The first sending unit 1102 is used to copy the target data packet through the hook function set by the first layer kernel network stack of the operating system, and send the copied target data packet to the application.

[0153] The second sending unit 1103 is used to parse the target data packet layer by layer through the kernel network stack of the operating system, obtain the target kernel information obtained by parsing the target data packet through the hook function set by the kernel network stack, and send the target kernel information to the application, wherein the target kernel information includes different target sub-kernel information, and a target sub-kernel information includes a timestamp when the kernel network stack parses the target data packet. The application assembles the target data packet and the target kernel information to obtain the assembly result of the target data packet.

[0154] It should be noted that the preferred implementation scheme involved in the above embodiments of the present application is the same as the scheme provided in Example 3, as well as the application scenario and implementation process, but is not limited to the scheme provided in Example 3.

[0155] Example 8

[0156] According to an embodiment of the present application, a data acquisition device for implementing the above data acquisition method is also provided. Fig.12 is a schematic diagram of another data acquisition device according to an embodiment of the present application, such as Fig.12 As shown, the data acquisition device is applied in the process of an application sending a data packet to a network device through an operating system, and includes:

[0157] The eighth receiving unit 1201 is configured to receive a target data packet.

[0158] The third sending unit 1202 is used to encapsulate the target data packet layer by layer through the kernel network stack of the operating system, obtain the target kernel information obtained by encapsulating the target data packet through the hook function set by the kernel network stack, and send the target kernel information to the application, wherein the target kernel information includes different target sub-kernel information, and a target sub-kernel information includes a timestamp when the kernel network stack encapsulates the target data packet. The application assembles the encapsulated target data packet and the target kernel information to obtain the assembly result of the target data packet.

[0159] It should be noted that the preferred implementation scheme involved in the above embodiments of the present application is the same as the scheme provided in Example 4, as well as the application scenario and implementation process, but is not limited to the scheme provided in Example 4.

[0160] Example 9

[0161] The embodiment of the present application may provide an electronic device, which may be any electronic device in a group of electronic devices. Optionally, in this embodiment, the electronic device may also be replaced by a terminal device such as a mobile terminal.

[0162] Optionally, in this embodiment, the electronic device may be located in at least one network device among a plurality of network devices of a computer network.

[0163] In this embodiment, the computer terminal can execute the program code in the data acquisition method.

[0164] Optionally, Fig.13 is a structural block diagram of an electronic device according to an embodiment of the present application. As shown in the figure, the electronic device A may include: one or more ( Fig.13 (only one is shown) processor 102, memory 104, storage controller, and peripheral interface, wherein the peripheral interface is connected to the radio frequency module, audio module and display.

[0165] Among them, the memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the data acquisition method and device in the embodiment of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, the data acquisition method in the above embodiment is realized. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely arranged relative to the processor, and these remote memories may be connected to the terminal A via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0166] The processor can call the information and application programs stored in the memory through the transmission device to execute the steps of the data acquisition method provided in the above embodiment.

[0167] Those skilled in the art will understand that Fig.13The structure shown is for illustration only. The electronic device may also be a smart phone, a tablet computer, a PDA, a mobile Internet device (MID), a PAD, or other terminal devices. This figure does not limit the structure of the above electronic devices. For example, the electronic device A may also include Fig.13 The present invention may include more or fewer components (such as a network interface, a display device, etc.) shown in the figure, or may have a different configuration than that shown in the figure.

[0168] A person of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a computer-readable storage medium, and the storage medium may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.

[0169] Example 10

[0170] The embodiment of the present application further provides a computer-readable storage medium. Optionally, in this embodiment, the computer-readable storage medium can be used to store the program code executed by the data acquisition method provided in the above embodiment.

[0171] Optionally, in this embodiment, the above storage medium may be located in any electronic device in a group of electronic devices in a computer network, or in any mobile terminal in a group of mobile terminals.

[0172] Optionally, in this embodiment, a computer-readable storage medium is configured to store program code for executing the following steps: receiving a target data packet obtained by a hook function set by a driver layer of an operating system; receiving target kernel information obtained by a hook function set by a kernel network stack of the operating system, wherein the target kernel information includes different target sub-kernel information, and a target sub-kernel information includes a timestamp when a kernel network stack parses the target data packet; assembling the target data packet and the target kernel information to obtain an assembly result of the target data packet.

[0173] Embodiment 11

[0174] The embodiment of the present application also provides a computer program product. Optionally, the computer program product may include a non-volatile computer-readable storage medium, which may be used to store a computer program, and when the computer program is executed by a processor, the data acquisition method provided in the embodiment is implemented.

[0175] Example 12

[0176] The embodiment of the present application further provides a computer program. Optionally, in this embodiment, when the computer program is executed by a processor, the data acquisition method provided in the above embodiment is implemented.

[0177] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0178] In the above embodiments of the present application, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.

[0179] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0180] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0181] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0182] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, disk or optical disk, etc., which can store program code.

[0183] The above is only a preferred implementation of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. A data acquisition method, characterized in that: The data acquisition method is applied in a process in which an application receives a data packet transmitted by a network device through an operating system, and includes: Receive a target data packet obtained by a hook function set by a first layer kernel network stack of the operating system; Receive target kernel information obtained by a hook function set by a kernel network stack of the operating system, wherein the target kernel information includes different target sub-kernel information, and one target sub-kernel information includes a timestamp when a kernel network stack parses the target data packet; Assembling the target data packet and the target kernel information to obtain an assembly result of the target data packet; Wherein, different target sub-kernel information all carries a data packet identifier, and the target data packet and the target sub-kernel information associated with the data packet identifier of the target data packet are assembled in the user state.

2. The method according to claim 1, characterized in that The target kernel information obtained by the hook function receiving the kernel network stack setting of the operating system includes: Respectively receive target sub-kernel information obtained by hook functions set by different kernel network stacks, and receive data packet identifiers carried by different target sub-kernel information; Assembling the target data packet and the target kernel information comprises: The target data packet identifier of the target data packet is calculated, and the target sub-kernel information carrying the target data packet identifier is determined, and the target data packet and all the target sub-kernel information are assembled.

3. The method according to claim 1, characterized in that The target kernel information obtained by the hook function receiving the kernel network stack setting of the operating system includes: Receive a target sub-kernel information set sent by the last layer kernel network stack of the operating system, wherein the hook functions set by different kernel network stacks sequentially cache the acquired target sub-kernel information into the first cache area of ​​the kernel, and merge the target sub-kernel information associated with the data packet identifier of the target data packet into the target sub-kernel information set at the last layer kernel network stack; Assembling the target data packet and the target kernel information comprises: The target data packet identifier of the target data packet is calculated, and the target sub-kernel information set carrying the target data packet identifier is determined, and the target data packet and the target sub-kernel information set are assembled.

4. The method according to claim 1, characterized in that: Before receiving the target data packet obtained by the hook function set by the first layer kernel network stack of the operating system, the method further includes: receiving first instruction information sent by a user, wherein the first instruction information instructs the hook function set by the first layer kernel network stack to obtain the packet header and packet body of the target data packet; receiving the target data packet obtained by the hook function set by the first layer kernel network stack of the operating system includes: receiving the packet header and packet body of the target data packet obtained by the hook function set by the first layer kernel network stack; or Before receiving the target data packet obtained by the hook function set by the first layer kernel network stack of the operating system, the method also includes: receiving second instruction information sent by the user, wherein the second instruction information instructs the hook function set by the first layer kernel network stack to obtain the packet header of the target data packet; receiving the target data packet obtained by the hook function set by the first layer kernel network stack of the operating system includes: receiving the packet header of the target data packet obtained by the hook function set by the first layer kernel network stack.

5. The method according to claim 1, characterized in that Before receiving the target data packet obtained by the hook function set by the first layer kernel network stack of the operating system, the method further includes: Receive a third instruction message sent by a user, wherein the third instruction message instructs the hook function set by the first layer kernel network stack to obtain a data packet that meets a preset filtering condition, wherein the preset filtering condition includes at least one of the following: a source address, a destination address, a source port number, and a destination port number; Receiving target data obtained by a hook function set by the first layer kernel network stack of the operating system includes: receiving a data packet that meets the preset filtering condition and is obtained by the hook function set by the first layer kernel network stack to obtain the target data packet.

6. The method according to claim 1, characterized in that After assembling the target data packet and the target kernel information to obtain an assembly result of the target data packet, the method further includes: Writing the assembly result into a storage device; In the case where the target data packet is lost during transmission, obtaining the assembly result of the target data packet from the storage device; The target kernel network stack associated with the last timestamp is obtained from the kernel information of the assembly result, and the next kernel network stack adjacent to the target kernel network stack in the transmission path is determined as the packet loss position.

7. The method according to claim 1, characterized in that After assembling the target data packet and the target kernel information to obtain an assembly result of the target data packet, the method further includes: Obtaining a first timestamp and a last timestamp from the kernel information of the assembly result to obtain a first timestamp and a second timestamp; Compare the difference between the first timestamp and the second timestamp with a preset duration, and determine whether the transmission duration of the target data packet has timed out according to the comparison result; When the transmission duration times out, the kernel network stack determines the timeout based on the difference between every two adjacent timestamps.

8. A data acquisition method, characterized in that: The data acquisition method is applied in the process of an application sending a data packet to a network device through an operating system, and includes: Receive an assembly result of a target data packet transmitted by a first-layer kernel network stack of the operating system, wherein the assembly result includes the target data packet and target kernel information, the target kernel information is obtained by a hook function set by the kernel network stack of the operating system, the target kernel information includes different target sub-kernel information, and one target sub-kernel information includes a timestamp when a kernel network stack encapsulates the target data packet; Among them, different target sub-kernel information all carry data packet identifiers, and the assembly result of the target data packet is obtained by assembling the target data packet and the target sub-kernel information associated with the data packet identifier of the target data packet in the first layer kernel network stack.

9. The method according to claim 8, characterized in that The hook functions set in different kernel network stacks sequentially cache the acquired target sub-kernel information into the second cache area of ​​the kernel.

10. A data acquisition method, characterized in that: The data acquisition method is applied in a process in which an application receives a data packet transmitted by a network device through an operating system, and includes: Receive target data packets; Copying the target data packet through a hook function set by the first layer kernel network stack of the operating system, and sending the copied target data packet to the application; The target data packet is parsed layer by layer through the kernel network stack of the operating system, target kernel information obtained by parsing the target data packet is obtained through a hook function set by the kernel network stack, and the target kernel information is sent to the application, wherein the target kernel information includes different target sub-kernel information, and one target sub-kernel information includes a timestamp when the kernel network stack parses the target data packet, and the application assembles the target data packet and the target kernel information to obtain an assembly result of the target data packet; Among them, different target sub-kernel information all carry data packet identifiers, and the assembly result of the target data packet is obtained by assembling the target data packet and the target sub-kernel information associated with the data packet identifier of the target data packet in user mode.

11. A data acquisition method, characterized in that: The data acquisition method is applied in the process of an application sending a data packet to a network device through an operating system, and includes: Receive target data packets; The target data packet is encapsulated layer by layer through the kernel network stack of the operating system, the target kernel information obtained by encapsulating the target data packet is obtained through a hook function set by the kernel network stack, and the target kernel information is sent to the application, wherein the target kernel information includes different target sub-kernel information, and one target sub-kernel information includes a timestamp when the kernel network stack encapsulates the target data packet, and the application assembles the encapsulated target data packet and the target kernel information to obtain an assembly result of the target data packet; Among them, different target sub-kernel information all carry data packet identifiers, and the assembly result of the target data packet is obtained by assembling the target data packet and the target sub-kernel information associated with the data packet identifier of the target data packet in the first layer kernel network stack.

12. An electronic device, characterized in that: include: A memory storing an executable program; A processor, configured to run the program, wherein the program executes the method according to any one of claims 1 to 11 when running.

13. A computer program product, characterized in that The invention comprises a computer program which, when executed by a processor, implements the method according to any one of claims 1 to 11.

14. A computer storage medium, characterized in that: The computer storage medium is used to store a program, wherein when the program is executed, the device where the computer storage medium is located is controlled to execute the method according to any one of claims 1 to 11.

Citation Information

Patent Citations

  • Network detection method and device, and storage medium

    CN115811484A