A method for realizing distributed traffic mirroring acquisition based on OVS flow table and VXLAN protocol
By adopting a distributed traffic mirror acquisition method based on OVS flow table and VXLAN protocol in a large-scale virtualization environment, combining the adaptive flow table optimization algorithm and in-segment data deduplication algorithm, the problems of complex deployment, high resource occupation and insufficient data quality in the existing technology are solved, and efficient and simple traffic acquisition and transmission are achieved, with strong adaptability and flexible management of complex network traffic.
Patent Information
- Application Number
- CN202411673250.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-21
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2044-11-21
AI Technical Summary
The existing traffic mirror acquisition methods are complex in large-scale virtualization environments, have high resource utilization and insufficient data collection quality, which is difficult to meet the needs of modern cloud computing systems for efficient distributed traffic management.
The distributed traffic mirror acquisition method based on the OVS stream table and VXLAN protocol is adopted. By configuring OVS stream table rules, dynamically adjusting traffic processing rules, and cross-node acquisition of traffic mirrors, combining adaptive stream table optimization algorithm and in-segment data deduplication algorithm, efficient and simple traffic acquisition and transmission are achieved.
It realizes efficient acquisition and cross-node transmission of target virtual machine traffic in a distributed environment, simplifies the deployment process, improves data integrity and collection efficiency, reduces system resource overhead, is highly adaptable, and supports flexible management of complex network traffic.
Smart Images

Figure CN119484554B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of virtualized network communication, and particularly to a method for realizing distributed traffic mirroring acquisition based on OVS flow tables and the VXLAN protocol. Background Art
[0002] With the rapid development of cloud computing technology, the demand for traffic management and data acquisition in large-scale virtualized environments is increasing day by day. In a cloud computing system, network traffic analysis between virtual machines is an important means to ensure service quality and improve network performance. However, existing traffic mirroring acquisition methods have problems such as complex deployment, high resource occupancy, and insufficient data acquisition quality when facing complex virtualized network environments, and it is difficult to meet the requirements of modern cloud computing systems for efficient distributed traffic management.
[0003] Traditional traffic mirroring acquisition methods usually adopt two implementation schemes. One is to collect virtual network card traffic through tools in a virtual machine and perform offline analysis after generating a data file; the other is to install an additional traffic acquisition service program to achieve real-time collection and analysis of traffic data. These methods can play a certain role in small-scale network environments, but they expose the following significant deficiencies in large-scale virtualized environments:
[0004] The first is that the deployment is complex and has a greater impact on the existing environment; traditional traffic acquisition schemes require installing additional tools or services on each virtual machine, which interferes with the operating environment of the cloud computing system and increases the complexity of deployment and maintenance at the same time.
[0005] The second is that the acquisition scope is limited and it is difficult to achieve distributed traffic management; existing methods are usually limited to local acquisition of single-node traffic and lack the global management ability for cross-node traffic. In a large-scale cloud computing environment, virtual machines may be distributed on multiple physical nodes, and their network traffic needs to be acquired and analyzed across nodes. Traditional methods cannot break through the limitations of physical nodes, resulting in incomplete acquired data and making it difficult to meet the requirements of global network traffic analysis.
[0006] The third is that the data acquisition quality is insufficient and there is a lack of dynamic optimization ability; traditional methods usually do not optimize the data when acquiring traffic, and the acquired data may contain a large amount of redundant content, increasing the burden of transmission and storage. When performing traffic mirroring transmission, duplicate data packets are not effectively removed, which not only wastes network bandwidth but also reduces the efficiency of data analysis.
[0007] Therefore, how to provide a method for realizing distributed traffic mirroring acquisition based on OVS flow tables and the VXLAN protocol is an urgent problem to be solved by those skilled in the art. Summary of the Invention
[0008] An object of the present invention is to propose a distributed traffic mirroring acquisition method implemented based on OVS flow tables and the VXLAN protocol. The present invention makes full use of virtualized network technology, SDN technology, and data deduplication optimization algorithms, and details the specific implementation solutions for configuring OVS flow table rules, dynamically adjusting traffic processing rules, and cross-node acquisition of traffic mirrors, with the advantages of simple deployment, high data integrity, and high acquisition efficiency.
[0009] A method for distributed traffic mirroring acquisition implemented based on OVS flow tables and the VXLAN protocol according to an embodiment of the present invention includes the following steps:
[0010] S1. Initialize the OVS working environment, including installing and configuring the OVS service on the host machine;
[0011] S2. Create a target virtual machine and obtain the name of the OVS bridge bound to the actual network interface of the target virtual machine;
[0012] S3. Create a VXLAN tunnel interface and bind it to the OVS bridge where the target virtual machine is located;
[0013] S4. Add flow table rules to the OVS bridge to which the target virtual machine belongs, including configuring traffic matching conditions and traffic forwarding actions, and copying and outputting the traffic of the target virtual machine to the VXLAN tunnel interface through the flow table rules;
[0014] S5. Introduce an adaptive flow table optimization algorithm to dynamically adjust the flow table rules in real time according to the dynamic changes of network traffic, and optimize the traffic processing efficiency and resource utilization rate;
[0015] S6. Use an in-segment data deduplication algorithm to detect and remove duplicate data packets within the same data segment before traffic mirroring transmission;
[0016] S7. Receive the traffic mirror data transmitted through the VXLAN tunnel on the OVS bridge of the traffic processing node, and summarize the traffic according to preset rules;
[0017] S8. Complete the distributed traffic mirroring acquisition, obtain the full volume of traffic data of the target virtual machine for traffic analysis and processing.
[0018] Optionally, the S4 includes:
[0019] S41. In the OVS bridge to which the target virtual machine belongs, define a set of traffic matching conditions , where is a traffic matching condition, including source IP address, destination IP address, source port, destination port, and protocol type;
[0020] S42. Issue flow table rules to the OVS bridge through the OpenFlow protocol. The flow table rules include a set of traffic matching conditions and a set of traffic forwarding actions , where is a traffic forwarding action, indicating that the traffic meeting the specified traffic matching conditions is copied and output to the VXLAN tunnel interface;
[0021] S43. Set priority parameters in the flow table rules . The value of the priority determines the rule execution order when traffic meets multiple traffic matching conditions simultaneously. The definition of the priority is: , where represents the weight coefficient of the traffic matching condition, represents the matching intensity when the condition is met, is the set of all traffic conditions;
[0022] S44. Deploy the configured flow table rules to the OVS bridge in a real-time update manner, so that the traffic of the target virtual machine is matched, copied according to the flow table rules, and transmitted to the specified traffic processing node through the VXLAN tunnel interface;
[0023] S45. Dynamically monitor the execution result of traffic forwarding, record the hit statistical data of the set of traffic matching conditions and the set of traffic forwarding actions , and optimize the flow table rules in combination with the hit statistical data.
[0024] Optionally, the S5 includes:
[0025] S51. Collect the current network traffic status parameter set of the target virtual machine , where represents specific traffic characteristic parameters, including traffic size, transmission rate, and network latency;
[0026] S52. Establish a traffic status evaluation function to evaluate the dynamic change of the network traffic of the target virtual machine at time :
[0027] ;
[0028] where represents the actual value of the traffic characteristic parameter at time , is the traffic characteristic weight, indicating the importance of a specific characteristic to the system performance and the traffic mirroring acquisition strategy, and is dynamically adjusted according to the network environment;
[0029] S53. Dynamically adjust the flow table rules according to the evaluation results, including optimizing the set of traffic matching conditions and the set of traffic forwarding actions . The adjustment coefficient is defined as:
[0030] ;
[0031] where represents the relative contribution ratio of specific traffic characteristic parameters to the optimization strategy, which is used to dynamically allocate resources. is a minimum value used to avoid calculation errors when the characteristic parameter is zero;
[0032] S54. Define a dynamic adjustment strategy for the priority of the flow table rules. The priority parameter :
[0033] ;
[0034] where represents the priority of the flow table rule entry, is the adjustment ratio coefficient used to control the range of priority changes, is the preset maximum priority value used to limit the priority range to avoid unreasonable allocation;
[0035] S55. Through the optimized flow table rules, send the rules to the OVS bridge to implement the processing and dynamic optimization of the target virtual machine traffic;
[0036] S56. Monitor the adjusted traffic processing performance, record the performance parameters before and after optimization and , and calculate the performance improvement rate :
[0037] ;
[0038] where represents the performance improvement ratio after the flow table optimization, which is used to quantify the impact of the flow table rule adjustment on the traffic mirroring acquisition efficiency.
[0039] Optionally, the S53 includes:
[0040] S531. According to the dynamic changes in the network traffic of the target virtual machine, collect the set of current network traffic status parameters of the target virtual machine ;
[0041] S532. Construct the adjustment coefficient ;
[0042] S533. Use the adjustment coefficient The set of traffic matching conditions in the convection table rules is optimized, and the updated rule of the optimized set of traffic matching conditions is as follows:
[0043] ;
[0044] Among them, is the optimized traffic matching condition, is the traffic matching condition;
[0045] S534. Optimize the set of traffic forwarding actions The updated rule of the optimized set of traffic forwarding actions is as follows:
[0046] ;
[0047] Among them, is the optimized traffic forwarding action, is the traffic forwarding action, is the action adjustment factor, which is used to control the upper limit of action adjustment;
[0048] S535. Deploy the optimized set of traffic matching conditions and the set of traffic forwarding actions to the OVS flow table of the target virtual machine, and dynamically update the flow table rules;
[0049] S536. Based on real-time monitoring of the running status of the optimized flow table rules, evaluate the execution effects of traffic matching conditions and traffic forwarding actions, and adjust the flow table update frequency in combination with the traffic dynamic change trend.
[0050] Optionally, the S6 includes:
[0051] S61. Extract the set of traffic mirror data packets of the target virtual machine , where represents the th data packet in the traffic mirror, and record the transmission timestamp, source address, destination address, and data content hash value of each data packet;
[0052] S62. Apply the in-segment data deduplication algorithm to the extracted set of data packets , and identify the duplicate relationship between data packets by constructing an improved duplicate detection function :
[0053] ;
[0054] Among them, is the data packet The content hash value, represents the bitwise exclusive OR operation of the hash values, which is used to measure the similarity of the data packet content, is the threshold for the hash value difference, is the data packet 's timestamp, is the detection time window. When occurs, the data packet is identified as a duplicate packet;
[0055] S63. Based on the result of the duplicate detection function, divide the data packet set into a unique data packet set and a duplicate data packet set , where, , the unique data packet set is reserved for traffic analysis and transmission, and the duplicate data packet set is marked as redundant data;
[0056] S64. Define the optimized traffic transmission ratio :
[0057] ;
[0058] Among them, and respectively represent the sizes of the unique data packet set and the original data packet set, and respectively represent the importance weights of the data packets in the corresponding sets. The weights are calculated based on the frequency and priority of the data packets appearing in the network;
[0059] S65. Output the deduplicated unique data packet set to the traffic processing node, transmit it through the VXLAN tunnel interface, and record the optimized data packet transmission performance metrics, including the transmission efficiency and bandwidth occupancy ratio before and after optimization.
[0060] Optionally, the S62 includes:
[0061] S621. Define a method for generating the data packet content hash value for the traffic mirror data packet set of the target virtual machine and generate the hash value through the following formula :
[0062] ;
[0063] Among them, represents the payload of the data packet, represents the metadata of the data packet, including source address, destination address, and port number information, represents the concatenation operation, represents a hash function used to generate a unique hash identifier;
[0064] S622, constructing a duplicate detection function , combining the hash value and timestamp of the data packet to determine whether two data packets are duplicates.
[0065] Optionally, the S7 includes:
[0066] S71, on the OVS bridge of the traffic processing node, receiving the traffic mirror data packet set transmitted through the VXLAN tunnel, processing the received data packets, and importing them into the traffic aggregation interface;
[0067] S72, classifying the received data packets according to the source address, destination address, and protocol type to generate a classification index set, where each classification index is used to identify an independent traffic group;
[0068] S73, according to the classification index set, grouping the data packets according to the classification index to form multiple groups of traffic grouping data, where each group of traffic data packets contains all data packets with the same classification index;
[0069] S74, storing the grouped traffic data and recording the statistical information of each group of data, including the number of data packets, the total traffic size, and the proportion in the overall traffic;
[0070] S75, further analyzing the grouped traffic data, forwarding the traffic that meets the analysis conditions to the specified analysis module or storage node, and discarding or archiving the traffic data that does not meet the analysis conditions according to the preset rules;
[0071] S76, dynamically adjusting the classification rules and storage policies based on the real-time changes of the traffic to optimize the resource allocation and operation efficiency of the traffic processing node.
[0072] The beneficial effects of the present invention are:
[0073] (1) The present invention combines virtualized network technology and SDN technology to achieve efficient collection and cross-node transmission of the traffic of the target virtual machine in a distributed environment. By configuring the OVS flow table rules and using the VXLAN protocol, the present invention can complete the traffic mirror collection task without installing additional services, simplifies the deployment process, reduces the interference to the existing virtualized network environment, and significantly improves the deployment flexibility and adaptability of the system.
[0074] (2) The present invention adopts an adaptive flow table optimization algorithm and an in-segment data deduplication algorithm, which can adjust the traffic processing rules in real time during the traffic collection process and remove redundant data packets during transmission, effectively improving the efficiency of traffic collection and the transmission quality. By dynamically optimizing the flow table rules, this method realizes the flexible management of complex network traffic, improves the resource utilization rate of traffic processing nodes, and provides a complete and high-quality data basis for subsequent traffic analysis.
[0075] (3) The present invention realizes the efficient summarization and hierarchical management of traffic by classifying and grouping mirror data at traffic processing nodes. The classified data supports the further analysis of key traffic and the archiving of non-key traffic. Combined with the dynamic adjustment strategy, it optimizes the operation efficiency and resource allocation of traffic processing nodes, effectively meeting the traffic analysis requirements in a large-scale cloud computing environment. Brief Description of the Drawings
[0076] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. They are used together with the embodiments of the present invention to explain the present invention, but do not constitute a limitation to the present invention. In the drawings:
[0077] Figure 1 is a flowchart of a method for realizing distributed traffic mirroring collection based on OVS flow table and VXLAN protocol proposed by the present invention;
[0078] Figure 2 is a flowchart of flow table rule and traffic classification processing in a method for realizing distributed traffic mirroring collection based on OVS flow table and VXLAN protocol proposed by the present invention. Detailed Embodiments
[0079] Now, the present invention will be further described in detail with reference to the drawings. These drawings are all simplified schematic diagrams, only showing the basic structure of the present invention in a schematic manner, so they only show the components related to the present invention.
[0080] Refer to Figure 1-2 , a method for realizing distributed traffic mirroring collection based on OVS flow table and VXLAN protocol, includes the following steps:
[0081] S1. Initialize the OVS working environment, including installing and configuring the OVS service on the host machine;
[0082] S2. Create a target virtual machine and obtain the OVS bridge name bound to the actual network interface of the target virtual machine;
[0083] S3. Create a VXLAN tunnel interface and bind it to the OVS bridge where the target virtual machine is located;
[0084] S4. Add a flow table rule to the OVS bridge to which the target virtual machine belongs, including configuring traffic matching conditions and traffic forwarding actions, and copy and output the traffic of the target virtual machine to the VXLAN tunnel interface through the flow table rule;
[0085] S5. Introduce an adaptive flow table optimization algorithm to dynamically adjust the flow table rule in real time according to the dynamic change of network traffic, and optimize the traffic processing efficiency and resource utilization rate;
[0086] S6. Use the in-segment data deduplication algorithm to detect and remove duplicate data packets within the same data segment before traffic mirroring transmission;
[0087] S7. Receive the traffic mirror data transmitted through the VXLAN tunnel on the OVS bridge of the traffic processing node, and summarize the traffic according to the preset rules;
[0088] S8. Complete the distributed traffic mirroring collection, obtain the full volume of traffic data of the target virtual machine, and use it for traffic analysis and processing.
[0089] In this embodiment, the S4 includes:
[0090] S41. Define a traffic matching condition set in the OVS bridge to which the target virtual machine belongs , where is the traffic matching condition, including source IP address, destination IP address, source port, destination port, and protocol type;
[0091] S42. Send the flow table rule to the OVS bridge through the OpenFlow protocol. The flow table rule includes the traffic matching condition set and the traffic forwarding action set , where is the traffic forwarding action, indicating that the traffic that specifies the traffic matching condition is copied and output to the VXLAN tunnel interface;
[0092] S43. Set the priority parameter in the flow table rule. The value of the priority determines the rule execution order when the traffic satisfies multiple traffic matching conditions at the same time. The definition of the priority is: , where, represents the weight coefficient of the traffic matching condition, represents the matching intensity when the condition is satisfied, is the set of all traffic conditions;
[0093] S44. Deploy the configured flow table rules to the OVS bridge in a real-time update manner, so that the traffic of the target virtual machine is matched, copied according to the flow table rules, and transmitted to the specified traffic processing node through the VXLAN tunnel interface;
[0094] S45. Dynamically monitor the execution result of traffic forwarding and record the hit statistical data of the traffic matching condition set and the traffic forwarding action set and optimize the flow table rules in combination with the hit statistical data.
[0095] In this embodiment, the S5 includes:
[0096] S51. Collect the current network traffic status parameter set of the target virtual machine, where represents specific traffic characteristic parameters, including traffic size, transmission rate, and network latency;
[0097] S52. Establish a traffic status evaluation function to evaluate the dynamic change of the network traffic of the target virtual machine at time :
[0098] ;
[0099] Among them, represents the actual value of the traffic characteristic parameter at time , is the traffic characteristic weight, indicating the importance of a specific characteristic to the system performance and traffic mirroring acquisition strategy, and is dynamically adjusted according to the network environment;
[0100] S53. Dynamically adjust the flow table rules according to the evaluation result, including optimizing the traffic matching condition set and the traffic forwarding action set , and the adjustment coefficient is defined as:
[0101] ;
[0102] Among them, represents the relative contribution ratio of the specific traffic characteristic parameter to the optimization strategy, which is used for dynamic resource allocation, is a minimum value used to avoid calculation errors when the characteristic parameter is zero;
[0103] S54. Define a dynamic adjustment strategy for the priority of the flow table rules, and the priority parameter :
[0104] ;
[0105] Among them, represents the priority of the flow table rule entry, is the adjustment ratio coefficient, which is used to control the range of priority change, is the preset maximum priority value, which is used to limit the priority range to avoid unreasonable allocation;
[0106] S55. Through the optimized flow table rules, the rules are sent to the OVS bridge to implement the processing and dynamic optimization of the target virtual machine traffic;
[0107] S56. Monitor the traffic processing performance after adjustment, and record the performance parameters before and after optimization and , and calculate the performance improvement rate :
[0108] ;
[0109] Among them, represents the performance improvement ratio after the flow table optimization, which is used to quantify the impact of the flow table rule adjustment on the traffic mirroring acquisition efficiency.
[0110] In this embodiment, the S53 includes:
[0111] S531. According to the dynamic change of the network traffic of the target virtual machine, collect the current network traffic status parameter set of the target virtual machine ;
[0112] S532. Construct the adjustment coefficient ;
[0113] S533. Use the adjustment coefficient to optimize the traffic matching condition set in the flow table rule. The update rule of the optimized traffic matching condition set is:
[0114] ;
[0115] Among them, is the optimized traffic matching condition, is the traffic matching condition;
[0116] S534. Optimize the traffic forwarding action set The update rule of the optimized traffic forwarding action set is:
[0117] ;
[0118] Among them, is the optimized traffic forwarding action, is a traffic forwarding action, is an action adjustment factor used to control the upper limit of action adjustment;
[0119] S535. Deploy the optimized traffic matching condition set and the traffic forwarding action set to the OVS flow table where the target virtual machine belongs, and dynamically update the flow table rules;
[0120] S536. Based on the real-time monitoring of the running status of the optimized flow table rules, evaluate the execution effects of the traffic matching conditions and traffic forwarding actions, and adjust the flow table update frequency in combination with the traffic dynamic change trend.
[0121] In this embodiment, the S6 includes:
[0122] S61. Extract the traffic mirror data packet set of the target virtual machine, where represents the th data packet in the traffic mirror, and record the transmission timestamp, source address, destination address, and data content hash value of each data packet;
[0123] S62. Apply the in-segment data deduplication algorithm to the extracted data packet set to identify the duplicate relationship between data packets by constructing an improved duplicate detection function :
[0124] ;
[0125] Among them, is the content hash value of the data packet , represents the bitwise exclusive OR operation of the hash values, which is used to measure the similarity of the data packet content, is the threshold of the hash value difference, is the timestamp of the data packet , is the detection time window. When , the data packet is identified as a duplicate packet;
[0126] S63. Based on the results of the duplicate detection function, divide the data packet set into a unique data packet set and a duplicate data packet set , where, , the unique data packet set is reserved for traffic analysis and transmission, and the duplicate data packet set is marked as redundant data;
[0127] S64. Define the optimized traffic transmission ratio :
[0128] ;
[0129] wherein, and respectively represent the sizes of the unique packet set and the original packet set, and respectively represent the importance weights of the packets in the corresponding sets, and the weights are calculated based on the packet appearance frequency and priority in the network;
[0130] S65. Output the deduplicated unique packet set to the traffic processing node, transmit it through the VXLAN tunnel interface, and record the optimized packet transmission performance metrics, including the transmission efficiency and bandwidth occupancy ratio before and after optimization.
[0131] In this embodiment, the S62 includes:
[0132] S621. Define a method for generating the hash value of the packet content for the traffic mirror packet set of the target virtual machine and generate the hash value through the following formula :
[0133] ;
[0134] wherein, represents the payload of the packet, represents the metadata of the packet, including source address, destination address, and port number information, represents the concatenation operation, represents the hash function, which is used to generate a unique hash identifier;
[0135] S622. Construct a duplicate detection function , and combine the hash value and timestamp of the packet to determine whether two packets are duplicates.
[0136] In this embodiment, the S7 includes:
[0137] S71. On the OVS bridge of the traffic processing node, receive the traffic mirror packet set transmitted through the VXLAN tunnel, process the received packets, and import them into the traffic aggregation interface;
[0138] S72. Classify the received packets according to the source address, destination address, and protocol type, generate a classification index set, and each classification index is used to identify an independent traffic group;
[0139] S73. Group the data packets according to the classification index set to form multiple groups of traffic packet data. Each group of traffic data packets contains all the data packets with the same classification index;
[0140] S74. Store the grouped traffic data and record the statistical information of each group of data, including the number of data packets, the total traffic size, and the proportion in the overall traffic;
[0141] S75. Further analyze the grouped traffic data, forward the traffic that meets the analysis conditions to the specified analysis module or storage node, and discard or archive the traffic data that does not meet the analysis conditions according to the preset rules;
[0142] S76. Dynamically adjust the classification rules and storage policies based on the real-time changes of the traffic, and optimize the resource allocation and operation efficiency of the traffic processing nodes.
[0143] Example 1:
[0144] In the data center of a large Internet enterprise in China, the enterprise is mainly responsible for providing cloud computing services for global users, covering fields such as distributed deployment of virtual machines, network traffic monitoring, and efficient data management. With the continuous expansion of the scale of the data center, the enterprise faces the following main challenges: how to accurately collect the network traffic of large-scale virtual machines without affecting the existing virtualized network environment; how to achieve efficient management and transmission of distributed traffic; and how to ensure the integrity and quality of the collected data. For this reason, the enterprise decided to introduce the distributed traffic mirroring and collection method proposed in the present invention to optimize its traffic management system.
[0145] In actual application, the enterprise deployed the method of the present invention in a large data center with 500 servers and more than 3000 virtual machines. The deployment process first installs and configures the OVS service in each host to initialize the network environment; then creates a VXLAN tunnel interface on the target virtual machine and realizes real-time mirroring and transmission of virtual machine traffic through the configuration of flow table rules. By introducing an adaptive flow table optimization algorithm, the flow table rules are dynamically adjusted to cope with the dynamic changes of network traffic, ensuring the priority processing of key traffic. In addition, the in-segment data deduplication algorithm effectively removes duplicate data packets in the mirroring transmission, significantly improving the transmission efficiency.
[0146] In a test of the data center, the network traffic of 100 virtual machines was selected for mirroring and collection. The test results show that compared with traditional traffic collection methods (such as tcpdump or by installing third-party traffic analysis tools), the method of the present invention has obvious advantages in deployment efficiency and data quality. The specific performance is as follows:
[0147] Table 1 Performance Comparison Table before and after the Implementation of Distributed Traffic Mirroring Acquisition
[0148]
[0149] As shown in Table 1 above, in the actual scenario application, the intra-segment data deduplication algorithm of the present invention efficiently identifies and removes redundant data packets in mirror transmission. Taking a traffic peak period as an example (the peak traffic of a virtual machine is 500 Mbps), among the data packets generated by the traditional method, about 15% are duplicate packets, while the present invention reduces the duplication rate to 2% through dynamic hash detection and time window filtering, effectively reducing the bandwidth occupancy. And the adaptive flow table optimization algorithm dynamically adjusts the matching rules according to the real-time changes of the traffic, realizing the priority processing of key traffic. In a sudden traffic event (the traffic of the target virtual machine instantaneously increases to 800 Mbps), the packet loss rate of the traditional method is as high as 5%, while the present invention reduces the packet loss rate to 0.5% through real-time rule adjustment.
[0150] After the implementation of the present invention, the overall traffic acquisition efficiency and the system operation stability have been significantly improved. It not only solves the problems of complex deployment and insufficient data quality of the traditional traffic acquisition method, but also greatly reduces the system resource overhead and optimizes the performance of distributed traffic acquisition and management. Compared with the traditional method, the present invention provides a more intelligent and accurate solution in a dynamic network environment, providing strong technical support for traffic management and data analysis in the cloud computing environment.
[0151] The above is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent substitution or change, and should be covered by the protection scope of the present invention.
Claims
1. A method for distributed traffic mirroring collection based on OVS flow table and VXLAN protocol, characterized in that: The following steps are involved: S1. Initialize the OVS working environment, including installing and configuring the OVS service on the host machine; S2. Create a target virtual machine and obtain the OVS bridge name to which the actual network interface of the target virtual machine is bound; S3. Create a VXLAN tunnel interface and bind it to the OVS bridge where the target VM is located. S4. Add flow table rules on the OVS bridge to which the target virtual machine belongs, including configuring traffic matching conditions and traffic forwarding actions, copy the traffic of the target virtual machine through the flow table rules and output it to the VXLAN tunnel interface; S5, introduce adaptive flow table optimization algorithm, adjust flow table rules in real time according to dynamic changes of network traffic, optimize traffic processing efficiency and resource utilization; S6. Use the intra-segment data deduplication algorithm to detect and remove duplicate data packets in the same data segment before traffic mirroring transmission; S7, receiving the traffic mirroring data transmitted through the VXLAN tunnel on the OVS bridge of the traffic processing node, and summarizing the traffic according to the preset rules; S8. Complete the distributed traffic mirroring collection and obtain the full traffic data of the target virtual machine for traffic analysis and processing; The S5 includes: S51. Collect the current network traffic status parameter set of the target virtual machine ,in Indicates specific traffic characteristic parameters, including traffic size, transmission rate, and network delay; S52, establish flow state evaluation function , evaluate the target virtual machine in time Dynamic changes in network traffic at all times: ; in, Indicates time The actual value of the traffic characteristic parameter at the moment, The traffic feature weight indicates the importance of a specific feature to system performance and traffic mirroring collection strategy, and is dynamically adjusted according to the network environment. S53, according to Dynamically adjust flow table rules based on evaluation results, including optimizing the set of traffic matching conditions and traffic forwarding action set , the adjustment factor is defined as: ; in, Indicates specific traffic characteristic parameters The relative contribution ratio to the optimization strategy, used to dynamically allocate resources, is a minimum value, which is used to avoid calculation errors when the characteristic parameter is zero; S54, define the dynamic adjustment strategy of the flow table rule priority, priority parameter : ; in, Indicates the priority of the flow table rule item. To adjust the proportional coefficient, used to control the range of priority changes, It is the preset maximum priority value, which is used to limit the priority range to avoid unreasonable allocation; S55, through the optimized flow table rules, the rules are sent to the OVS bridge to realize the processing and dynamic optimization of the target virtual machine traffic; S56. Monitor the adjusted traffic processing performance and record the performance parameters before and after optimization. and , calculation performance improvement rate : ; in, Indicates the performance improvement ratio after flow table optimization, which is used to quantify the impact of flow table rule adjustment on traffic mirroring collection efficiency. The S53 includes: S531. According to the dynamic changes of the network traffic of the target virtual machine, collect the current network traffic state parameter set of the target virtual machine ; S532, build adjustment coefficient ; S533, use adjustment coefficient Set of traffic matching conditions in flow table rules Optimize and optimize the traffic matching condition set The update rule is: ; in, For the optimized traffic matching conditions, is the traffic matching condition; S534, traffic forwarding action set Optimize and optimize the traffic forwarding action set The update rule is: ; in, For the optimized traffic forwarding action, is the traffic forwarding action, is the action adjustment factor, which is used to control the upper limit of action adjustment; S535: Set the optimized traffic matching conditions and traffic forwarding action set Deploy to the OVS flow table of the target virtual machine and dynamically update the flow table rules; S536. Based on real-time monitoring of the running status of the optimized flow table rules, evaluate the execution effect of the traffic matching conditions and traffic forwarding actions, and adjust the flow table update frequency in combination with the dynamic change trend of the traffic.
2. According to claim 1, a method for distributed traffic mirroring collection based on OVS flow table and VXLAN protocol is characterized in that: The S4 includes: S41. Define a set of traffic matching conditions in the OVS bridge to which the target virtual machine belongs. ,in Traffic matching conditions include source IP address, destination IP address, source port, destination port, and protocol type; S42, send flow table rules to the OVS bridge through the OpenFlow protocol, the flow table rules include a set of traffic matching conditions and traffic forwarding action set ,in Traffic forwarding action, indicating that the traffic matching the specified traffic condition is copied and output to the VXLAN tunnel interface; S43. Set priority parameters in flow table rules , priority The value determines the order in which rules are executed when traffic meets multiple traffic matching conditions at the same time. is defined as: ,in, Indicates the weight coefficient of the traffic matching condition. Indicates the matching strength when the condition is met. is the set of all flow conditions; S44, deploy the configured flow table rules to the OVS bridge in a real-time update manner, so that the traffic of the target virtual machine is matched and copied according to the flow table rules, and transmitted to the designated traffic processing node through the VXLAN tunnel interface; S45. Dynamically monitor the execution results of traffic forwarding and record the traffic matching condition set and traffic forwarding action set The hit statistics are used to optimize the flow table rules.
3. According to claim 1, a method for distributed traffic mirroring collection based on OVS flow table and VXLAN protocol is characterized in that: The S6 includes: S61. Extract the traffic mirror data packet set of the target virtual machine ,in Indicates the first Data packets, record the transmission timestamp, source address, destination address and data content hash value of each data packet; S62: Collect the extracted data packets Apply intra-segment data deduplication algorithms by building improved duplicate detection functions Identify duplicate relationships between packets: ; in, For data packets The content hash value of Represents the bitwise XOR operation of the hash value, which is used to measure the similarity of the data packet content. is the threshold of hash value difference, For data packets timestamp, is the detection time window, when When the data packet Identified as a duplicate package; S63, based on the result of the duplicate detection function, the data packet set Divide into unique sets of packets and duplicate packet collection ,in, , unique data packet set Reserved for traffic analysis and transmission, repeated data packet collection Marked as redundant data; S64. Define the optimized traffic transmission ratio : ; in, and Represents the size of the unique data packet set and the original data packet set, and They represent the importance weights of the data packets in the corresponding set, respectively. The weights are calculated based on the frequency and priority of the data packets in the network. S65: The unique data packet after deduplication is collected The data is output to the traffic processing node and transmitted through the VXLAN tunnel interface. The optimized data packet transmission performance indicators are recorded, including the transmission efficiency and bandwidth occupancy ratio before and after optimization.
4. According to claim 1, a method for distributed traffic mirroring collection based on OVS flow table and VXLAN protocol is characterized in that: The S62 includes: S621, traffic mirroring data packet set for the target virtual machine Define the method for generating the hash value of the data packet content and generate the hash value using the following formula : ; in, Represents the payload of the data packet, Represents the metadata of the data packet, including source address, destination address and port number information, Represents a splicing operation, Represents a hash function, which is used to generate a unique hash identifier; S622. Construct duplicate detection function , combined with the hash value and timestamp of the data packet, it is determined whether two data packets are duplicates.
5. According to claim 1, a method for distributed traffic mirroring collection based on OVS flow table and VXLAN protocol is characterized in that: The S7 comprises: S71. On the OVS bridge of the traffic processing node, receive a set of traffic mirror data packets transmitted through the VXLAN tunnel, process the received data packets, and import them into the traffic aggregation interface; S72, classifying the received data packets according to the source address, the destination address, and the protocol type, and generating a classification index set, where each classification index is used to identify an independent traffic group; S73, according to the classification index set, grouping the data packets according to the classification index to form multiple groups of traffic group data, each group of traffic data packets containing all data packets with the same classification index; S74, storing the grouped traffic data and recording statistical information of each group of data, including the number of data packets, the total traffic size, and the proportion of the total traffic; S75, further analyzing the grouped traffic data, forwarding the traffic that meets the analysis conditions to a designated analysis module or storage node, and discarding or archiving the traffic data that does not meet the analysis conditions according to preset rules; S76. Dynamically adjust classification rules and storage strategies based on real-time changes in traffic to optimize resource allocation and operating efficiency of traffic processing nodes.
Citation Information
Patent Citations
Flow table rapid recovery method and system under Openstack
CN117579464A
Transmission method based on virtual machine network card flow mirror image in cloud network
CN117812088A