Communication protocol management method and apparatus, computer device, and storage medium
By monitoring changes in IP association documents, obtaining the target IP address and performing network connection tests, a firewall activation request is automatically generated, solving the problem of firewall rule failure caused by changes in the enterprise network IP and improving the efficiency of firewall rule troubleshooting and operation and maintenance.
Patent Information
- Application Number
- CN202411447036.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-16
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-10-16
AI Technical Summary
The dynamic changes in corporate network IP addresses make it impossible for firewalls to correctly identify legitimate access requests. Existing technologies require time-consuming and complex manual troubleshooting and modification of firewall rules, which is difficult to handle efficiently, especially in large-scale application and service environments.
By monitoring changes in IP association documents, obtaining the changed target IP address, generating test data packets and sending them to the corresponding port for network connection testing, it automatically generates firewall activation requests to resolve rule failure issues caused by IP changes.
It achieves instant perception and response to IP address changes, reduces manual troubleshooting delays, quickly identifies firewall rule failures, and improves firewall rule troubleshooting and operation and maintenance efficiency.
Smart Images

Figure CN119299193B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of artificial intelligence and management technology, and in particular to a communication protocol management method, apparatus, computer equipment, and storage medium. Background Art
[0002] When an enterprise faces frequent changes in office areas and floors for different teams, these changes often lead to corresponding changes in wired and wireless IP addresses within the office network. This dynamic nature of IP addresses poses challenges to network security management, particularly for firewall policies that rely on specific IP addresses to access work-related applications or services. Because the original IP addresses are no longer valid, firewalls may not be able to correctly identify and allow legitimate access requests, resulting in these requests being mistakenly blocked or ignored.
[0003] Traditional solutions to address network IP address changes caused by office area and floor changes often require internal teams to conduct a one-by-one investigation and submit a request to the operations department to modify firewall rules for any service applications that are inaccessible due to IP address changes. This is a time-consuming and complex process. Because IT teams frequently use a variety of applications and services (such as log access, REDIS, ES, DSP, databases, etc.), these applications and services are associated with a large number of IP addresses, potentially up to hundreds. Therefore, when these IP addresses change, troubleshooting becomes particularly difficult. Summary of the Invention
[0004] The purpose of the embodiments of the present application is to propose a communication protocol management method, apparatus, computer equipment and storage medium, which can quickly check firewall rules that have become invalid due to changes in network IP.
[0005] In order to solve the above technical problems, the embodiment of the present application provides a communication protocol management method, which adopts the following technical solutions:
[0006] In response to a change signal of an Internet Protocol (IP) association document, obtaining a changed first target IP address according to the change signal;
[0007] matching a second target IP address from the IP association document according to the first target IP address, wherein the IP association document is a document recording associations between each network endpoint IP address in the network and the IP address of a service application running on the network endpoint IP address;
[0008] Generate a test data packet according to the first target IP address and the second target IP address;
[0009] send the test data packet to the port corresponding to the second target IP address to test a network connection state between the port corresponding to the first target IP address and the port corresponding to the second target IP address;
[0010] If the network connection state is that the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is not connected, a firewall opening request is generated according to the first target IP address and the second target IP address, and the firewall opening request is sent to an operation and maintenance terminal corresponding to a firewall management.
[0011] To solve the above technical problems, the embodiment of the application further provides a communication protocol management device, which adopts the technical scheme as follows:
[0012] The acquisition module is configured to acquire a first target IP address which has changed according to a change signal of an Internet Protocol (IP) association document in response to the change signal.
[0013] The matching module is configured to match a second target IP address from the IP association document according to the first target IP address, the IP association document being a document recording the association between each network endpoint IP address in a network and a service application IP address running on the network endpoint IP address.
[0014] The generation module is configured to generate a test data packet according to the first target IP address and the second target IP address.
[0015] The test module is configured to send the test data packet to the port corresponding to the second target IP address to test a network connection state between the port corresponding to the first target IP address and the port corresponding to the second target IP address.
[0016] The request module is configured to generate a firewall opening request according to the first target IP address and the second target IP address if the network connection state is that the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is not connected, and send the firewall opening request to an operation and maintenance terminal corresponding to a firewall management.
[0017] To solve the above technical problems, the embodiment of the application further provides a computer device, which adopts the technical scheme as follows: the computer device comprises a memory and a processor, the memory stores computer readable instructions, and the processor executes the computer readable instructions to realize the steps of the communication protocol management method according to any one of the above.
[0018] In order to solve the above technical problems, an embodiment of the present application also provides a computer-readable storage medium, which adopts the following technical solution: the computer-readable storage medium stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps of the communication protocol management method as described in any one of the above items are implemented.
[0019] Compared with the prior art, the embodiments of the present application have the following beneficial effects:
[0020] The embodiment of the present application monitors changes in IP-related documents. When a change in the IP address in the document is detected, it can immediately respond and obtain the changed first target IP address, thereby realizing instant perception and response to IP address changes and greatly reducing the delay in manual investigation. By matching the second target IP address associated with the first target IP address from the IP-related document, an accurate association between the network port and the service application can be established. By generating a test data packet based on the first target IP address and the second target IP address, and sending the data packet to the port corresponding to the second target IP address for network connection testing, it can accurately determine whether the network connection between the first target IP address and the second target IP address is connected, and quickly identify the problem of firewall rule failure caused by the original IP change. By automatically generating a firewall activation request and sending the request to the operation and maintenance end corresponding to the firewall management when the test shows that the network connection is not connected, the efficiency of firewall rule investigation and operation and maintenance is further improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the solutions in this application, a brief introduction will be given below to the drawings required for use in the description of the embodiments of this application. Obviously, the drawings described below are some embodiments of this application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0022] Figure 1 is an exemplary system architecture diagram to which the present application may be applied;
[0023] Figure 2 This is a flow chart of an embodiment of the communication protocol management method of the present application;
[0024] Figure 3 yes Figure 2 A flowchart of a specific implementation method before step S201;
[0025] Figure 4 yes Figure 2 A flowchart of a specific implementation of step S204;
[0026] Figure 5It is a structural diagram of an embodiment of the communication protocol management device of the present application;
[0027] Figure 6 It is a structural diagram of an embodiment of a computer device of the present application. DETAILED DESCRIPTION
[0028] Unless otherwise defined, all technical and scientific terms used herein have the same meanings as commonly understood by those skilled in the art to which this application belongs. The terms used in the specification of the application are for the purpose of describing specific embodiments only and are not intended to limit this application. The terms "including" and "having" and any variations thereof in the specification and claims of this application and the above-mentioned drawings are intended to cover non-exclusive inclusions. The terms "first", "second", etc. in the specification and claims of this application or the above-mentioned drawings are used to distinguish different objects, not to describe a specific order.
[0029] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0030] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings.
[0031] like Figure 1 As shown, system architecture 100 may include a terminal device 101, a network 102, and a server 103. Terminal device 101 may be a laptop computer 1011, a tablet computer 1012, or a mobile phone 1013. Network 102 is a medium for providing a communication link between terminal device 101 and server 103. Network 102 may include various connection types, such as wired or wireless communication links or fiber optic cables.
[0032] The user can use the terminal device 101 to interact with the server 103 via the network 102 to receive or send messages, etc. Various communication client applications can be installed on the terminal device 101, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social platform software, etc.
[0033] The terminal device 101 can be various electronic devices with a display screen and supporting web browsing. In addition to the laptop computer 1011, tablet computer 1012 or mobile phone 1013, the terminal device 101 can also be an e-book reader, an MP3 player (Moving Picture Experts Group Audio Layer III), an MP4 (Moving Picture Experts Group Audio Layer IV) player, a laptop computer and a desktop computer, etc.
[0034] The server 103 may be a server that provides various services, such as a background server that provides support for web pages displayed on the terminal device 101 .
[0035] It should be noted that the communication protocol management method provided in the embodiment of the present application is generally executed by a server / terminal device, and accordingly, the communication protocol management device is generally set in the server / terminal device.
[0036] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.
[0037] Continue to refer Figure 2 , shows a flow chart of an embodiment of a method for managing a communication protocol according to the present application. The communication protocol management method comprises the following steps:
[0038] Step S201, in response to a change signal of an Internet Protocol (IP) associated document, obtaining a changed first target IP address according to the change signal;
[0039] In this embodiment, the electronic device (eg Figure 1 The server / terminal device shown in the figure can obtain the change signal of the Internet Protocol (IP) associated document through a wired connection or a wireless connection. It should be noted that the above-mentioned wireless connection method may include but is not limited to 2G / 3G / 4G / 5G connection, WiFi connection, Bluetooth connection, WiMAX connection, Zigbee connection, UWB (ultra wideband) connection, and other wireless connection methods currently known or to be developed in the future.
[0040] In this embodiment, IP (Internet Protocol) changes refer to situations where IP addresses change when data is transmitted between devices connected to the Internet (such as computers, mobile phones, servers, etc.). A network endpoint IP address refers to a unique identifier used to locate and identify network devices (such as routers, switches, servers, personal computers, etc.) in a network. A service application IP address refers to the IP address of a device that provides a specific service or application (such as a distributed computing platform Hadoop, big data log access, MYSQL / Oracle database, REDIS development environment, DSP test environment, ES test environment, customer relationship management CRM test environment, security platform, etc.). An IP association document is a document that records the association between each network endpoint IP address in the network and the service or application (i.e., service application IP address) running on the network endpoint IP address. The IP association document may include at least one network endpoint IP address and the service application IP address corresponding to the network endpoint IP address.
[0041] Specifically, a change signal for an IP association document is received and responded to. For example, when an IP address changes, the IP address in the IP association document is modified accordingly. In this case, a change signal is generated corresponding to the IP address change in the IP association document. The change signal includes the changed IP address. In response to the change signal, the changed IP address is obtained as a first target IP address based on the change signal. The first target IP address can be a network endpoint IP address or a service application IP address.
[0042] In some optional implementations, reference Figure 3 The above-mentioned method of responding to the change signal of the Internet Protocol IP association document and obtaining the changed first target IP address according to the change signal may further include the following steps:
[0043] Step S101, monitoring whether there is any change in the IP list in the IP association document, wherein the IP list includes a list of network endpoint IP addresses and a list of service application IP addresses corresponding to each network endpoint IP address;
[0044] In this embodiment, after setting up monitoring of a specific IP list in an IP association document, the IP list in the IP association document is monitored for changes based on a set signal collection period, wherein the IP list includes a list of network endpoint IP addresses and a list of service application IP addresses corresponding to each network endpoint IP address list. Monitoring whether the IP list in the IP association document has changed may, for example, involve collecting the IP list in the current IP association document as baseline data, and after a set signal collection period, recollecting the IP list in the IP association document, comparing the baseline data with the recollected IP list to identify IP addresses that have changed; if there are IP addresses that have changed, then it is determined that the IP list in the IP association document has changed.
[0045] Step S102: If the IP list changes, the IP address that has changed is determined as the first target IP address, and a change signal is generated according to the first target IP address.
[0046] In this embodiment, when a change occurs in the IP list in an IP association document, the identified IP address with the change is determined as the first target IP address, and a change signal for the IP association document is generated based on the first target IP address. The change signal may include the first target IP address, the type of change, the time of the change, and detailed information before and after the change.
[0047] More specifically, if the IP list changes, the changed IP address is determined as the first target IP address. For example, after comparing the baseline data with the re-collected IP list, a changed IP address is identified. The type of change may include, but is not limited to, adding an IP address, deleting an IP address, or modifying an IP address. The type of changed IP address may be a network endpoint IP address or a service application IP address. The identified changed IP address is marked to obtain the first target IP address.
[0048] By continuously monitoring the IP list in the IP association document, the embodiment of the present application can instantly detect any changes in IP addresses. This monitoring mechanism ensures that changes in network configuration can be quickly responded to. When an IP address in the IP list changes, the changed IP address can be accurately identified and a corresponding change signal can be quickly generated based on the changed IP address, ensuring the accuracy and timeliness of the signal.
[0049] Step S202: matching a second target IP address from the IP association document according to the first target IP address, wherein the IP association document is a document recording the association between each network endpoint IP address in the network and the IP address of the service application running on the network endpoint IP address;
[0050] In this embodiment, the definition of the IP association document is as described in step S201 above and will not be repeated here. Based on the obtained first target IP address, a second target IP address is obtained by matching the IP association document. For example, when the first target IP address is a network endpoint IP address that has changed, at least one service application IP address running on the network endpoint IP address is obtained from the IP association document as the second target IP address. When the first target IP address is a service application IP address that has changed, the network endpoint IP address that supports the service application IP address is obtained from the IP association document as the second target IP address.
[0051] In some optional implementations, matching the second target IP address from the IP association document according to the first target IP address may include the following steps:
[0052] If the first target IP address is a network endpoint IP address, matching the service application IP address corresponding to the network endpoint IP address from the IP association document as the second target IP address;
[0053] In this embodiment, if the first target IP address is a network endpoint IP address, that is, the IP address that changes in the IP association document is a network endpoint IP address, then at least one service application IP address running on the network endpoint IP address is matched from the IP association document as the second target IP address.
[0054] If the first target IP address is a service application IP address, the network endpoint IP address corresponding to the service application IP address is matched from the IP association document as the second target IP address.
[0055] In this embodiment, if the first target IP address is a service application IP address, that is, the IP address that changes in the IP association document is a service application IP address, then the network endpoint IP address that supports the operation of the service application IP address is matched from the IP association document as the second target IP address.
[0056] By implementing bidirectional association queries in IP association documents, the embodiments of the present application can achieve flexible matching, whether querying the corresponding service application IP address from a network endpoint IP address or querying the corresponding network endpoint IP address from a service application IP address. In particular, when the first target IP address is a network endpoint IP address, at least one service application IP address running on the network endpoint is matched from the IP association document. This allows for handling multiple service application IP addresses corresponding to a network endpoint IP address, supports multi-service application association in complex network architectures, and is suitable for processing scenarios in various large-scale networks or cloud environments.
[0057] Step S203: Generate a test data packet according to the first target IP address and the second target IP address;
[0058] In this embodiment, a test data packet is generated based on the matched first target IP address and second target IP address, wherein the test data packet may include content such as source IP address, destination IP address, source port, and destination port.
[0059] More specifically, a test data packet is generated based on the first target IP address and the second target IP address. For example, the first target IP address is set as the source IP address of the test data packet, and the second target IP address is set as the destination IP address of the test data packet. The source port for sending the test data packet is determined based on the port corresponding to the first target IP address, and the destination port for receiving the test data packet is determined based on the port corresponding to the second target IP address. The test data packet is constructed based on the determined source IP address, destination IP address, source port, and destination port.
[0060] Step S204: Send the test data packet to the port corresponding to the second target IP address to test the network connection status between the port corresponding to the first target IP address and the port corresponding to the second target IP address;
[0061] In this embodiment, the port corresponding to the second target IP address is determined, and a constructed test data packet is sent to the port corresponding to the second target IP address, thereby simulating sending the test data packet from the port corresponding to the first target IP address to the port corresponding to the second target IP address, thereby testing the network connection status between the port corresponding to the first target IP address and the port corresponding to the second target IP address. The network connection status can be that the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is connected, or that the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is disconnected.
[0062] It should be noted that if the electronic device sending the test data packet is the device corresponding to the first target IP address, the test data packet is directly constructed and sent to the port corresponding to the second target IP address through the device corresponding to the first target IP address. If the electronic device sending the test data packet is a third-party device other than the device corresponding to the first target IP address, it is necessary to obtain the IP address of the third-party device and add the IP address of the third-party device to the test data packet. The IP address of the third-party device is used by the third-party device to identify its own device identity in the network; then, continue to set the source IP address to the first target IP address and the destination IP address to the second target IP address in the test data packet, and simulate the test data packet from the device corresponding to the first target IP address through the third-party device to the port corresponding to the second target IP address.
[0063] In some optional implementations, reference Figure 4 The step of sending the test data packet to the port corresponding to the second target IP address to test the network connection status between the port corresponding to the first target IP address and the port corresponding to the second target IP address may include the following steps:
[0064] Step S2041: Send the test data packet to the port corresponding to the second target IP address, and monitor the response signal returned from the second target IP address;
[0065] In this embodiment, after determining the port corresponding to the second target IP address, the constructed test data packet is sent to the port corresponding to the second target IP address, and at the same time, a specific network packet capture tool is used to monitor the response signal returned from the second target IP address.
[0066] Step S2042: If a response signal returned by the second target IP address is received within a preset time, the network connection status is determined to be that the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is connected;
[0067] In this embodiment, a response receiving time range (referred to as the preset time) is set in advance. If a response signal returned from the second target IP address is received within the preset time, it indicates that the port corresponding to the first target IP address and the port corresponding to the second target IP address can communicate normally. At this time, the network connection status is determined as the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is connected.
[0068] Step S2043: If no response signal returned by the second target IP address is received within the preset time, the network connection status is determined as the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is disconnected.
[0069] In this embodiment, if no response signal is received from the second target IP address within the preset time, it indicates that the port corresponding to the first target IP address and the port corresponding to the second target IP address cannot communicate normally. At this time, the network connection status is determined as the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is not connected.
[0070] The embodiment of the present application can quickly and accurately reflect the network connection status between the first target IP address and the second target IP address by sending a test data packet to the port corresponding to the second target IP address and monitoring the response signal from the second target IP address based on a set preset time.
[0071] In some optional implementations, after the step of determining that the network connection state is connected between the port corresponding to the first target IP address and the port corresponding to the second target IP address, the following steps may be further included:
[0072] The first target IP address and the second target IP address are marked with a connection success identifier, and the connection success identifier is stored in the IP association document.
[0073] In this embodiment, when the test result shows that the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is connected, the first target IP address and the second target IP address are marked with a connection success identifier to indicate that the network connection between the first target IP and the second target IP has been successfully established. At this time, the connection success identifier between the first target IP address and the second target IP address is stored in the IP association document.
[0074] In the embodiment of the present application, the successfully connected IP address pairs are marked with a connection success identifier and stored in the IP association document, so that the network connections between which IP address pairs are connected can be quickly understood by querying the IP association document later.
[0075] In some optional implementations, after the step of determining that the network connection status is disconnected between the port corresponding to the first target IP address and the port corresponding to the second target IP address, the following steps may be further included:
[0076] The first target IP address and the second target IP address are marked with a connection failure identifier, and the connection failure identifier is stored in the IP association document.
[0077] In this embodiment, when the test result is that the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is not connected, the first target IP address and the second target IP address are marked with a connection failure identifier, indicating that the network connection between the first target IP and the second target IP has failed to be successfully established, and there may be a firewall blockage. At this time, the connection failure identifier between the first target IP address and the second target IP address is stored in the IP association document.
[0078] The embodiment of the present application marks the IP address pairs that failed to connect with a connection failure identifier and stores it in the IP association document, so that it is possible to quickly find out which network connections between the IP address pairs are disconnected by querying the IP association document, thereby quickly determining the firewall rules that have become invalid due to changes in the network IP.
[0079] Step S205: If the network connection status is that the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is not connected, a firewall activation request is generated based on the first target IP address and the second target IP address, and the firewall activation request is sent to the operation and maintenance end corresponding to the firewall management.
[0080] In this embodiment, if the network connection status obtained from the test indicates that the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is disconnected, this indicates that the connection between the first target IP address and the second target IP address does not comply with the preset firewall rules and is blocked by the firewall. In this case, a firewall activation request is generated based on the first target IP address and the second target IP address. The firewall activation request may include, but is not limited to, the first target IP address and its corresponding port, the second target IP address and its corresponding port, the test disconnection status, and the expected network communication requirements. The firewall activation request is sent to the operation and maintenance end corresponding to the set firewall management. The operation and maintenance end may be an IT service management system.
[0081] In some optional implementations, generating a firewall activation request according to the first target IP address and the second target IP address may include the following steps:
[0082] Extracting a plurality of first target IP addresses and second target IP addresses marked with connection failure identifiers from the IP association document;
[0083] A firewall activation request is generated according to the plurality of first target IP addresses and second target IP addresses.
[0084] In this embodiment, based on the connection failure identifier in the IP association document, several first target IP addresses and second target IP addresses marked with the connection failure identifier are extracted from the IP association document, and the several first target IP addresses and second target IP addresses that have failed to connect to each other are matched one by one, and firewall activation requests are generated in batches based on the corresponding several first target IP addresses and second target IP addresses.
[0085] The embodiments of the present application can generate firewall activation requests in batches, so that multiple IP address pairs with failed connections can be processed at once without manual operation one by one, significantly improving processing efficiency and being particularly suitable for large-scale network environments. By activating firewalls for IP address pairs with failed connections, the allocation of network resources can be optimized. The activation of the firewall ensures that network communications between these IP address pairs are properly protected and filtered, thereby improving the overall security and performance of the network.
[0086] The embodiment of the present application adopts the above-mentioned scheme, specifically by monitoring the changes of IP-related documents. When the IP address in the document is monitored to have changed, it can immediately respond and obtain the changed first target IP address, thereby realizing instant perception and response to the IP address change and greatly reducing the delay of manual investigation. By matching the second target IP address associated with the first target IP address from the IP-related document, it is possible to establish an accurate association between the network port and the service application. By generating a test data packet based on the first target IP address and the second target IP address, and sending the data packet to the port corresponding to the second target IP address for network connection testing, it is possible to accurately determine whether the network connection between the first target IP address and the second target IP address is connected, and quickly identify the problem of firewall rule failure caused by the original IP change. By automatically generating a firewall activation request and sending the request to the operation and maintenance end corresponding to the firewall management when the network connection is not connected, the efficiency of firewall rule investigation and operation and maintenance is further improved.
[0087] It should be emphasized that in order to further ensure the privacy and security of the above-mentioned IP association documents, the first target IP address, the second target IP address and other related data, the above-mentioned IP association documents, the first target IP address, the second target IP address and other related data can also be stored in a blockchain node.
[0088] The blockchain referred to in this application is a new application model for computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms. Blockchain is essentially a decentralized database, a series of data blocks generated using cryptographic methods. Each data block contains information about a batch of network transactions, which is used to verify the validity of this information (to prevent counterfeiting) and generate the next block. Blockchain can include the underlying blockchain platform, the platform product service layer, and the application service layer.
[0089] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing related hardware via computer-readable instructions. The computer-readable instructions can be stored in a computer-readable storage medium, and when the program is executed, it can include the processes in the above-described method embodiments. The aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).
[0090] It should be understood that although the steps in the flowcharts of the accompanying drawings are shown in sequence as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in the flowcharts of the accompanying drawings may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.
[0091] Further references Figure 5 , as a response to the above Figure 2 The present application provides an embodiment of a communication protocol management device. Figure 2 Corresponding to the method embodiment shown, the device can be specifically applied to various electronic devices.
[0092] like Figure 5 As shown, the communication protocol management device 400 of this embodiment includes: an acquisition module 401, a matching module 402, a generation module 403, a testing module 404 and a request module 405.
[0093] An acquisition module 401 is configured to respond to a change signal of an Internet Protocol (IP) associated document and acquire a changed first target IP address according to the change signal;
[0094] a matching module 402 configured to match a second target IP address from the IP association document according to the first target IP address, the IP association document being a document recording associations between each network endpoint IP address in a network and an IP address of a service application running on the network endpoint IP address;
[0095] A generating module 403 is configured to generate a test data packet according to the first target IP address and the second target IP address;
[0096] A testing module 404 is configured to send the test data packet to the port corresponding to the second target IP address to test the network connection status between the port corresponding to the first target IP address and the port corresponding to the second target IP address;
[0097] The request module 405 is used to generate a firewall activation request based on the first target IP address and the second target IP address if the network connection status is that the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is not connected, and send the firewall activation request to the operation and maintenance end corresponding to the firewall management.
[0098] In this embodiment, IP (Internet Protocol) changes refer to situations where IP addresses change when data is transmitted between devices connected to the Internet (such as computers, mobile phones, servers, etc.). A network endpoint IP address refers to a unique identifier used to locate and identify network devices (such as routers, switches, servers, personal computers, etc.) in a network. A service application IP address refers to the IP address of a device that provides a specific service or application (such as a distributed computing platform Hadoop, big data log access, MYSQL / Oracle database, REDIS development environment, DSP test environment, ES test environment, customer relationship management CRM test environment, security platform, etc.). An IP association document is a document that records the association between each network endpoint IP address in the network and the service or application (i.e., service application IP address) running on the network endpoint IP address. The IP association document may include at least one network endpoint IP address and the service application IP address corresponding to the network endpoint IP address.
[0099] Specifically, the acquisition module 401 is configured to receive and respond to a change signal for the IP association document, such as when an IP address changes, the corresponding IP address in the IP association document is modified, at this time, a change signal is generated in response to the change of the IP address in the IP association document, and the change signal contains the IP address that has changed. The acquisition module 401 is also configured to acquire the IP address that has changed as a first target IP address according to the change signal in response to the change signal. The first target IP address can be a network endpoint IP address or a service application IP address.
[0100] Specifically, the matching module 402 is configured to match a second target IP address from the IP association document according to the acquired first target IP address, such as when the first target IP address is a changed network endpoint IP address, at least one service application IP address running on the network endpoint IP address is acquired from the IP association document as the second target IP address. When the first target IP address is a changed service application IP address, the network endpoint IP address supporting the running of the service application IP address is acquired from the IP association document as the second target IP address.
[0101] Specifically, the generation module 403 is configured to generate a test data packet from the matched first target IP address and second target IP address, wherein the test data packet can include source IP address, destination IP address, source port, destination port, and the like.
[0102] More specifically, the generation module 403 is configured to generate a test data packet according to the first target IP address and the second target IP address, specifically configured to set the first target IP address as the source IP address of the test data packet, set the second target IP address as the destination IP address of the test data packet, determine the source port of the test data packet according to the port corresponding to the first target IP address, determine the destination port of the test data packet according to the port corresponding to the second target IP address, and construct the test data packet according to the determined source IP address, destination IP address, source port, and destination port.
[0103] Specifically, the testing module 404 is configured to determine the port corresponding to the second target IP address and send a constructed test data packet to the port corresponding to the second target IP address, thereby simulating sending the test data packet from the port corresponding to the first target IP address to the port corresponding to the second target IP address, thereby testing the network connection status between the port corresponding to the first target IP address and the port corresponding to the second target IP address. The network connection status can be that the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is connected, or that the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is disconnected.
[0104] It should be noted that if the electronic device sending the test data packet is the device corresponding to the first target IP address, the test data packet is directly constructed and sent to the port corresponding to the second target IP address through the device corresponding to the first target IP address. If the electronic device sending the test data packet is a third-party device other than the device corresponding to the first target IP address, it is necessary to obtain the IP address of the third-party device and add the IP address of the third-party device to the test data packet. The IP address of the third-party device is used by the third-party device to identify its own device identity in the network; then, continue to set the source IP address to the first target IP address and the destination IP address to the second target IP address in the test data packet, and simulate the test data packet from the device corresponding to the first target IP address through the third-party device to the port corresponding to the second target IP address.
[0105] Specifically, if the network connection status obtained by the test is that the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is not connected, it indicates that the connection between the first target IP address and the second target IP address does not comply with the preset firewall rules and there is a firewall blockage. At this time, a firewall activation request is generated based on the first target IP address and the second target IP address. The firewall activation request may include but is not limited to the first target IP address and its corresponding port, the second target IP address and its corresponding port, the test disconnection situation, the expected network communication requirements, etc. The firewall activation request is sent to the operation and maintenance end corresponding to the set firewall management. The operation and maintenance end can be an IT service management system.
[0106] The communication protocol management device of the embodiment of the present application monitors changes in IP-related documents. When a change in the IP address in the document is detected, the device can immediately respond and obtain the changed first target IP address, thereby realizing instant perception and response to IP address changes and greatly reducing the delay of manual investigation. By matching the second target IP address associated with the first target IP address from the IP-related document, an accurate association between the network port and the service application can be established. By generating a test data packet based on the first target IP address and the second target IP address and sending the data packet to the port corresponding to the second target IP address for network connection testing, it is possible to accurately determine whether the network connection between the first target IP address and the second target IP address is connected, and quickly identify the problem of firewall rule failure caused by the original IP change. By automatically generating a firewall activation request and sending the request to the operation and maintenance end corresponding to the firewall management when the network connection is not connected, the efficiency of firewall rule investigation and operation and maintenance is further improved.
[0107] In some optional implementations of this embodiment, the communication protocol management device 400 may further include: a monitoring module and a determination module.
[0108] A monitoring module, configured to monitor whether there are any changes in the IP list in the IP association document, wherein the IP list includes a list of network endpoint IP addresses and a list of service application IP addresses corresponding to each network endpoint IP address;
[0109] The determination module is used to determine the changed IP address as the first target IP address if the IP list changes, and generate a change signal according to the first target IP address.
[0110] Specifically, the monitoring module is used to monitor whether the IP list in the IP association document has changed based on a set signal collection period after setting the monitoring of a specific IP list in the IP association document, wherein the IP list includes a network endpoint IP address list and a service application IP address list corresponding to each network endpoint IP address list. The method of monitoring whether the IP list in the IP association document has changed can be, for example, collecting the IP list in the current IP association document as baseline data, and after a set signal collection period, collecting the IP list in the IP association document again, comparing the baseline data with the recollected IP list to identify IP addresses that have changed; if there is an IP address that has changed, it is determined that the IP list in the IP association document has changed.
[0111] Specifically, the determining module is configured to determine the identified changed IP address as a first target IP address when the IP list in the IP association document changes, and generate a change signal for the IP association document according to the first target IP address. The change signal can include the first target IP address, the type of change, the time of change, and detailed information before and after the change.
[0112] More specifically, when the determining module determines the changed IP address as the first target IP address if the IP list changes, the determining module is configured to identify the changed IP address after comparing the baseline data with the IP list collected again. The type of change can include, but is not limited to, adding an IP, deleting an IP, or modifying an IP. The type of changed IP address can be a network endpoint IP address or a service application IP address. The identified changed IP address is marked to obtain the first target IP address.
[0113] The communication protocol management device according to the embodiments of the present application can instantly perceive any change of IP address by continuously monitoring the IP list in the IP association document. The real-time monitoring mechanism ensures that the network configuration change can be responded quickly. When the IP address in the IP list changes, the changed IP address can be accurately identified, and the corresponding change signal can be quickly generated according to the changed IP address, ensuring the accuracy and timeliness of the signal.
[0114] In some optional implementations of the embodiments, the matching module 402 can include a first matching sub-module and a second matching sub-module. Wherein:
[0115] The first matching sub-module is configured to, if the first target IP address is a network endpoint IP address, match a service application IP address corresponding to the network endpoint IP address from the IP association document as a second target IP address.
[0116] The second matching sub-module is configured to, if the first target IP address is a service application IP address, match a network endpoint IP address corresponding to the service application IP address from the IP association document as a second target IP address.
[0117] Specifically, the first matching sub-module is configured to, if the first target IP address is a network endpoint IP address, i.e., the changed IP address in the IP association document is a network endpoint IP address, match at least one service application IP address running on the network endpoint IP address from the IP association document as a second target IP address.
[0118] Specifically, the second matching submodule is used to match the network endpoint IP address that supports the operation of the service application IP address from the IP association document as the second target IP address if the first target IP address is a service application IP address, that is, the IP address that changes in the IP association document is a service application IP address.
[0119] The matching module of the embodiment of the present application, by implementing bidirectional association queries in IP association documents, can achieve flexible matching, whether querying the corresponding service application IP address from a network endpoint IP address, or querying the corresponding network endpoint IP address from a service application IP address. In particular, when the first target IP address is a network endpoint IP address, at least one service application IP address running on the network endpoint is matched from the IP association document. This can handle the situation where multiple service application IP addresses correspond to a network endpoint IP address, supporting multi-service application association in complex network architectures and meeting the processing scenarios of various large-scale networks or cloud environments.
[0120] In some optional implementations of this embodiment, the test module 404 may include a sending submodule, a first state determination submodule, and a second state determination submodule. The sending submodule is configured to send the test data packet to the port corresponding to the second target IP address and monitor a response signal returned from the second target IP address;
[0121] a first state determination submodule configured to determine, if a response signal returned by the second target IP address is received within a preset time, that the network connection state is established between the port corresponding to the first target IP address and the port corresponding to the second target IP address;
[0122] The second status determination submodule is used to determine the network connection status as the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is not connected if no response signal returned by the second target IP address is received within a preset time.
[0123] Specifically, the sending submodule is used to send the constructed test data packet to the port corresponding to the second target IP address after determining the port corresponding to the second target IP address, and at the same time, use a specific network packet capture tool to monitor the response signal returned from the second target IP address.
[0124] Specifically, the first status determination submodule is used to pre-set a response reception time range (referred to as the preset time). If a response signal returned from the second target IP address is received within the preset time, it indicates that the port corresponding to the first target IP address and the port corresponding to the second target IP address can communicate normally. At this time, the network connection status is determined as the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is connected.
[0125] Specifically, the second status determination submodule is used to pre-set a response reception time range (referred to as the preset time). If no response signal returned from the second target IP address is received within the preset time, it indicates that the port corresponding to the first target IP address and the port corresponding to the second target IP address cannot communicate normally. At this time, the network connection status is determined as the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is not connected.
[0126] The test module 404 of the embodiment of the present application can quickly and accurately reflect the network connection status between the first target IP address and the second target IP address by sending a test data packet to the port corresponding to the second target IP address and listening to the response signal from the second target IP address based on a set preset time.
[0127] In some optional implementations of this embodiment, the test module 404 may further include a first marking submodule, wherein the first marking submodule is configured to mark the first target IP address and the second target IP address with a connection success flag, and store the connection success flag in the IP association document.
[0128] Specifically, the first marking submodule is used to mark the first target IP address and the second target IP address with a connection success mark when the test result shows that the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is connected, thereby indicating that the network connection between the first target IP and the second target IP has been successfully established. At this time, the connection success mark between the first target IP address and the second target IP address is stored in the IP association document.
[0129] The test module 404 of the embodiment of the present application marks the successfully connected IP address pairs with a connection success identifier and stores it in the IP association document, so that it is possible to quickly find out which network connections between the IP address pairs are connected by querying the IP association document later.
[0130] In some optional implementations of this embodiment, the test module 404 may further include a second marking submodule, wherein the second marking submodule is configured to mark the first target IP address and the second target IP address with a connection failure flag, and store the connection failure flag in the IP association document.
[0131] Specifically, the second marking submodule is used to mark the first target IP address and the second target IP address with a connection failure flag when the test result shows that the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is not connected, thereby indicating that the network connection between the first target IP and the second target IP has failed to be successfully established, and there may be a firewall blockage. At this time, the connection failure flag between the first target IP address and the second target IP address is stored in the IP association document.
[0132] The test module 404 of the embodiment of the present application marks the IP address pairs that failed to connect with a connection failure identifier and stores it in the IP association document, so that it can subsequently quickly understand which IP address pairs have disconnected network connections by querying the IP association document, thereby quickly determining the firewall rules that have become invalid due to changes in the network IP.
[0133] In some optional implementations of this embodiment, the request module 405 may further include an identification extraction submodule and a request generation submodule.
[0134] an identifier extraction submodule, configured to extract a plurality of first target IP addresses and second target IP addresses marked with a connection failure identifier from the IP association document;
[0135] The request generation submodule is used to generate a firewall activation request according to the plurality of first target IP addresses and second target IP addresses.
[0136] Specifically, the identifier extraction submodule is configured to extract, from the IP association document, a plurality of first target IP addresses and second target IP addresses marked with the connection failure identifier based on the connection failure identifier in the IP association document. The request generation submodule is configured to associate the plurality of first target IP addresses and second target IP addresses that have failed to connect to each other one-to-one, and to batch generate firewall activation requests based on the associated plurality of first target IP addresses and second target IP addresses.
[0137] The request module 405 of the embodiment of the present application can generate firewall activation requests in batches. This allows multiple IP address pairs with failed connections to be processed all at once without requiring manual processing one by one, significantly improving processing efficiency and being particularly suitable for large-scale network environments. By activating a firewall for IP address pairs with failed connections, the allocation of network resources can be optimized. The activation of the firewall ensures that network communications between these IP address pairs are properly protected and filtered, thereby improving the overall security and performance of the network.
[0138] To solve the above technical problems, the present application also provides a computer device. Figure 6 , Figure 6 This is a basic structural block diagram of the computer device in this embodiment.
[0139] The computer device 6 includes a memory 61, a processor 62, and a network interface 63 that are interconnected through a system bus. It should be noted that the figure only shows a computer device 6 with a memory 61, a processor 62, and a network interface 63, but it should be understood that it is not required to implement all the components shown, and more or fewer components can be implemented instead. Among them, those skilled in the art can understand that the computer device here is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to a microprocessor, an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a digital signal processor (DSP), an embedded device, etc.
[0140] The computer device may be a desktop computer, notebook computer, PDA, cloud server, etc. The computer device may interact with the user via a keyboard, mouse, remote control, touchpad, or voice control device.
[0141] The memory 61 includes at least one type of readable storage medium, such as a flash memory, a hard disk, a multimedia card, a card-type memory (e.g., an SD or DX memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, an optical disk, etc. In some embodiments, the memory 61 can be an internal storage unit of the computer device 6, such as a hard disk or a memory of the computer device 6. In other embodiments, the memory 61 can also be an external storage device of the computer device 6, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device 6. Of course, the memory 61 can also include both an internal storage unit and an external storage device of the computer device 6. In this embodiment, the memory 61 is generally used to store an operating system and various application software installed on the computer device 6, such as computer readable instructions of the communication protocol management method, etc. In addition, the memory 61 can also be used to temporarily store various data that have been output or will be output.
[0142] The processor 62 can be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip in some embodiments. The processor 62 is generally used to control the overall operation of the computer device 6. In this embodiment, the processor 62 is used to run computer readable instructions or process data stored in the memory 61, such as computer readable instructions of the communication protocol management method.
[0143] The network interface 63 can include a wireless network interface or a wired network interface, and is generally used to establish a communication connection between the computer device 6 and other electronic devices.
[0144] The present application also provides another embodiment, i.e., to provide a computer readable storage medium storing computer readable instructions, which can be executed by at least one processor to make the at least one processor perform the steps of the communication protocol management method as described above.
[0145] The computer device, computer-readable storage medium, and computer-readable instructions thereof provided by the embodiments of the present application monitor changes in IP-related documents through processor execution. When a change in the IP address in the document is detected, the computer device can immediately respond and obtain the changed first target IP address, thereby realizing instant perception and response to the IP address change and greatly reducing the delay of manual investigation. By matching the second target IP address associated with the first target IP address from the IP-related document, an accurate association between the network port and the service application can be established. By generating a test data packet based on the first target IP address and the second target IP address and sending it to the port corresponding to the second target IP address for network connection testing, it is possible to accurately determine whether the network connection between the first target IP address and the second target IP address is connected, and quickly identify the problem of firewall rule failure caused by the original IP change. By automatically generating a firewall activation request and sending the request to the operation and maintenance end corresponding to the firewall management when the network connection is tested to be unconnected, the efficiency of firewall rule investigation and operation and maintenance is further improved.
[0146] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.
[0147] Obviously, the embodiments described above are only some of the embodiments of the present application, rather than all of the embodiments. The preferred embodiments of the present application are given in the accompanying drawings, but they do not limit the patent scope of the present application. The present application can be implemented in many different forms. On the contrary, the purpose of providing these embodiments is to make the understanding of the disclosure of the present application more thorough and comprehensive. Although the present application has been described in detail with reference to the aforementioned embodiments, for those skilled in the art, it is still possible to modify the technical solutions described in the aforementioned specific embodiments, or to make equivalent replacements for some of the technical features therein. Any equivalent structure made using the contents of the present application specification and the accompanying drawings, directly or indirectly used in other related technical fields, is also within the scope of patent protection of the present application.
[0148] The non-Company software tools or components appearing in the embodiments of this application are merely examples and do not represent actual use.
Claims
1. A communication protocol management method, characterized in that: The steps include: In response to a change signal of an Internet Protocol (IP) association document, obtaining a changed first target IP address according to the change signal; matching a second target IP address from the IP association document according to the first target IP address, wherein the IP association document is a document recording associations between each network endpoint IP address in the network and the IP address of a service application running on the network endpoint IP address; Generate a test data packet according to the first target IP address and the second target IP address; Sending the test data packet to the port corresponding to the second target IP address to test the network connection status between the port corresponding to the first target IP address and the port corresponding to the second target IP address; If the network connection status is that the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is not connected, a firewall activation request is generated based on the first target IP address and the second target IP address, and the firewall activation request is sent to the operation and maintenance end corresponding to the firewall management.
2. The communication protocol management method according to claim 1, characterized in that: Before the step of responding to the change signal of the Internet Protocol (IP) association document and obtaining the changed first target IP address according to the change signal, the method further includes: Monitor whether there are any changes in the IP list in the IP association document, wherein the IP list includes a list of network endpoint IP addresses and a list of service application IP addresses corresponding to each network endpoint IP address; If the IP list changes, the IP address that has changed is determined as the first target IP address, and a change signal is generated according to the first target IP address.
3. The communication protocol management method according to claim 1, characterized in that: The step of matching the second target IP address from the IP association document according to the first target IP address includes: If the first target IP address is a network endpoint IP address, matching the service application IP address corresponding to the network endpoint IP address from the IP association document as the second target IP address; If the first target IP address is a service application IP address, the network endpoint IP address corresponding to the service application IP address is matched from the IP association document as the second target IP address.
4. The communication protocol management method according to claim 1, wherein: The step of sending the test data packet to the port corresponding to the second target IP address to test the network connection status between the port corresponding to the first target IP address and the port corresponding to the second target IP address includes: Sending the test data packet to the port corresponding to the second target IP address, and monitoring a response signal returned from the second target IP address; If a response signal returned by the second target IP address is received within a preset time, the network connection state is determined as a network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is connected; If no response signal returned by the second target IP address is received within a preset time, the network connection status is determined as the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is disconnected.
5. The communication protocol management method according to claim 4, characterized in that: After the step of determining that the network connection state is that the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is connected, the method further includes: The first target IP address and the second target IP address are marked with a connection success identifier, and the connection success identifier is stored in the IP association document.
6. The communication protocol management method according to claim 4, characterized in that: After the step of determining the network connection status as a disconnected network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address, the method further includes: The first target IP address and the second target IP address are marked with a connection failure identifier, and the connection failure identifier is stored in the IP association document.
7. The communication protocol management method according to claim 6, characterized in that: The step of generating a firewall activation request according to the first target IP address and the second target IP address includes: Extracting a plurality of first target IP addresses and second target IP addresses marked with connection failure identifiers from the IP association document; A firewall activation request is generated according to the plurality of first target IP addresses and second target IP addresses.
8. A communication protocol management device, characterized in that: The device comprises: an acquisition module, configured to respond to a change signal of an Internet Protocol (IP) associated document and acquire a changed first target IP address according to the change signal; a matching module, configured to match a second target IP address from the IP association document according to the first target IP address, the IP association document being a document recording associations between each network endpoint IP address in a network and an IP address of a service application running on the network endpoint IP address; A generating module, configured to generate a test data packet according to the first target IP address and the second target IP address; a testing module, configured to send the test data packet to the port corresponding to the second target IP address to test the network connection status between the port corresponding to the first target IP address and the port corresponding to the second target IP address; A request module is used to generate a firewall activation request based on the first target IP address and the second target IP address if the network connection status is that the network connection between the port corresponding to the first target IP address and the port corresponding to the second target IP address is not connected, and send the firewall activation request to the operation and maintenance end corresponding to the firewall management.
9. A computer device, characterized in that: The method comprises a memory and a processor, wherein the memory stores computer-readable instructions, and the processor implements the steps of the communication protocol management method according to any one of claims 1 to 7 when executing the computer-readable instructions.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the communication protocol management method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Container visit firewall intelligent linkage method and device, equipment and medium
CN113315754A
IP asset management method and device, nonvolatile storage medium and electronic equipment
CN118677871A