Data transmission method, system, device, storage medium and computer program product
By generating long connection rules when the statistics of the five-tuple information data packets of the network security device meet the conditions, the problem of frequent addition and deletion of sessions in RBM dual-machine networking is solved, CPU resources are saved, and the accuracy of traffic matching and device performance are improved.
Patent Information
- Application Number
- CN202411731026.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-28
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2044-11-28
AI Technical Summary
In a dual-node RBM network with session traffic diversion, multiple data packets of the same flow arrive at the network security device one by one due to latency and other factors. This results in frequent addition and deletion of platform and logical sessions, increasing CPU usage. Frequent operations are complex and prone to errors, affecting the accuracy of traffic matching sessions.
By counting the data packets of the same five-tuple information received by the network security device within the time period of the sum of the aging time of the logical session and the platform session, when the number of data packets is greater than or equal to the preset threshold and the statistical duration is less than or equal to the first preset duration, a long connection rule is generated to maintain a long connection between the source address and the destination address to reduce frequent session addition and deletion operations.
This reduces CPU resource consumption on network security devices, lowers the probability of traffic failing to correctly match sessions, and improves device processing efficiency and stability.
Smart Images

Figure CN119544766B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing technology, and more specifically, to a data transmission method, system, device, storage medium, and computer program product. Background Art
[0002] To ensure that messages on the Internet can be transmitted normally at all times, network security equipment generally uses Remote Backup Management (RBM) technology. This technology provides a backup plan when a communication line or device fails. When one network node fails, another network node can take over and continue working.
[0003] Generally, a flow consists of multiple data packets with the same five-tuple. In the current RBM dual-device network session diversion scenario, when the forward and reverse sessions are asymmetric, due to factors such as latency, multiple data packets of the same flow will arrive at the RBM device one by one. Because each data packet corresponds to a reverse message, in general, by the time the reverse message reaches the RBM device, the platform session or logical session on the RBM device has been deleted. The network security device will then re-add the platform session and logical session to ensure normal session operation.
[0004] Therefore, to ensure the normal progress of a flow session, it is necessary to frequently add and delete platform sessions and logical sessions, resulting in high CPU usage and a heavy burden on the performance of network security devices. The more frequent the platform and logical refresh and deletion process, and the more complex the process, the higher the probability of error. For example, refresh anomalies or deletion anomalies, network delays, maintenance message loss, etc., will cause the traffic to be unable to correctly match the session. Summary of the Invention
[0005] Based on the above-mentioned technical defects, the present application proposes a data transmission method, system, device, storage medium and computer program product, which establishes corresponding long connections for data packets with qualified five-tuple information to reduce the addition and deletion of platform sessions and logical sessions, thereby saving CPU resources and reducing the probability that traffic cannot correctly match sessions.
[0006] The first aspect of the present application provides a data transmission method, comprising:
[0007] Obtaining target five-tuple information sent by the network security device and statistical data obtained by counting data packets including the target five-tuple information;
[0008] If it is determined that the statistical data meets a preset condition, a long connection rule is generated for the target quintuple information, where the preset condition is that the number of data packets in the statistical data is greater than or equal to a preset threshold and the statistical duration of the statistical data is equal to a first preset duration, or that the number of data packets is equal to the preset threshold and the statistical duration is less than or equal to the first preset duration, where the first preset duration is determined based on the aging duration of the logical session and the platform session of the network security device, and the statistical duration is the cumulative duration of receiving data packets of the number of data packets;
[0009] The long connection rule is sent to the network security device, where the long connection rule is used to enable the network security device to maintain a long connection between the source address and the destination address in the target quintuple information.
[0010] A second aspect of the present application provides a data transmission method, comprising:
[0011] Send the received target five-tuple information to the business management platform;
[0012] Receive a long connection rule for the target quintuple information sent by the business management platform, where the long connection rule is generated and sent by the business management platform after determining that statistical data of received data packets including the target quintuple information meets a preset condition, and the preset condition is that the number of data packets in the statistical data is greater than or equal to a preset number threshold and the statistical duration of the statistical data is equal to a first preset duration, or that the number of data packets is equal to the preset threshold and the statistical duration is less than or equal to the first preset duration, the duration of the first preset time period is determined based on the aging duration of the logical session and the platform session of the security device, and the statistical duration is the cumulative duration of receiving data packets of the number of data packets;
[0013] Based on the long connection rule, a long connection is established between the source address and the destination address in the target quintuple information.
[0014] A third aspect of the present application provides a data transmission device, including:
[0015] An acquisition module, configured to acquire target five-tuple information sent by a network security device and statistical data obtained by counting data packets including the target five-tuple information;
[0016] a generation module, configured to generate a long connection rule for the target quintuple information if it is determined that the statistical data meets a preset condition, wherein the preset condition is that the number of data packets in the statistical data is greater than or equal to a preset threshold and the statistical duration of the statistical data is equal to a first preset duration, or that the number of data packets is equal to the preset threshold and the statistical duration is less than or equal to the first preset duration, the first preset duration is determined based on the aging duration of the logical session and the platform session of the network security device, and the statistical duration is the cumulative duration of receiving data packets of the number of data packets;
[0017] The sending module is used to send the long connection rule to the network security device, where the long connection rule is used to enable the network security device to maintain a long connection between the source address and the destination address in the target quintuple information.
[0018] A fourth aspect of the present application provides a data transmission method, including:
[0019] A sending module is used to send the received target five-tuple information to the business management platform;
[0020] a receiving module, configured to receive a long connection rule for the target quintuple information sent by the business management platform, the long connection rule being generated and sent by the business management platform after determining that statistical data of received data packets including the target quintuple information meet a preset condition, the preset condition being that the number of data packets in the statistical data is greater than or equal to a preset number threshold and the statistical duration of the statistical data is equal to a first preset duration, or that the number of data packets is equal to the preset threshold and the statistical duration is less than or equal to the first preset duration, the duration of the first preset time period being determined based on the aging duration of the logical session and the platform session of the security device, and the statistical duration being the cumulative duration of receiving data packets of the number of data packets;
[0021] An establishing module is used to establish a long connection between the source address and the destination address in the target quintuple information based on the long connection rule.
[0022] A fifth aspect of the present application provides a data transmission system, including a service management platform and a network security device;
[0023] The business management platform is used to obtain the target five-tuple information sent by the network security device and the statistical data obtained by counting the data packets including the target five-tuple information; if it is determined that the statistical data meets the preset conditions, a long connection rule is generated for the target five-tuple information, and the preset conditions are that the number of data packets in the statistical data is greater than or equal to a preset threshold and the statistical duration of the statistical data is equal to a first preset duration, or that the number of data packets is equal to the preset threshold and the statistical duration is less than or equal to the first preset duration, and the first preset duration is determined based on the aging duration of the logical session and the platform session of the network security device; the long connection rule is sent to the network security device, and the statistical duration is the cumulative duration of receiving data packets of the number of data packets;
[0024] The network security device is used to send the received target five-tuple information to the business management platform; receive the long connection rules for the target five-tuple information sent by the business management platform; and establish a long connection between the source address and the destination address in the target five-tuple information based on the long connection rules.
[0025] In a sixth aspect, the present application provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement a method as described in any one of the first and second aspects above.
[0026] In a seventh aspect, the present application provides an electronic device having a computer program stored thereon, wherein the program is executed by a processor to implement the method described in any one of the first aspect or the second aspect.
[0027] In an eighth aspect, the present application provides an electronic device, comprising a computer program, wherein when the computer program is executed by a processor, the method described in any one of the first aspect or the second aspect is implemented.
[0028] The beneficial effects of this application include at least:
[0029] In an embodiment of the present application, by counting the data packets of the same five-tuple information received by the network security device within the time period of the sum of the aging time of the logical session and the platform session, a long connection rule for the five-tuple information is generated when the number of data packets in the statistical data is greater than or equal to a preset number threshold and the statistical duration of the statistical data is less than or equal to a first preset duration, or the number of data packets is equal to the preset threshold and the statistical duration is less than or equal to the first preset duration. The long connection rule is used to enable the network security device to maintain a long connection between the source address and the destination address in the target five-tuple information, so as to ensure that the network security device does not frequently add or delete platform sessions and logical sessions when transmitting the data stream corresponding to the five-tuple information, so as to save CPU resources and reduce the probability that the traffic cannot correctly match the session. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate embodiments of the present application and, together with the description, serve to explain the principles of the present application.
[0031] The present application can be more clearly understood from the following detailed description with reference to the accompanying drawings, in which:
[0032] Figure 1 A schematic diagram of a data transmission scenario provided by an exemplary embodiment of the present application is shown;
[0033] Figure 2 A schematic diagram of a data transmission method according to an exemplary embodiment of the present application is shown;
[0034] Figure 3 Another flowchart of a data transmission method provided by an exemplary embodiment of the present application is shown;
[0035] Figure 4 A schematic structural diagram of a data transmission device provided by an exemplary embodiment of the present application is shown;
[0036] Figure 5 Another structural diagram of a data transmission device provided by an exemplary embodiment of the present application is shown;
[0037] Figure 6 A schematic structural diagram of an electronic device provided by an exemplary embodiment of the present application is shown;
[0038] Figure 7 A schematic diagram of a storage medium provided by an exemplary embodiment of the present application is shown. DETAILED DESCRIPTION
[0039] Hereinafter, embodiments of the present application will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present application. In addition, in the following description, descriptions of known structures and technologies are omitted to avoid unnecessary confusion of the concepts of the present application. It is obvious to those skilled in the art that the present application can be implemented without one or more of these details. In other examples, in order to avoid confusion with the present application, some technical features known in the art are not described.
[0040] It should be noted that the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit the exemplary embodiments according to the present application. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should also be understood that when the terms "comprise" and / or "include" are used in this specification, they indicate the presence of the features, wholes, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or combinations thereof.
[0041] Now, exemplary embodiments according to the present application will be described in more detail with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in a variety of different forms and should not be construed as being limited to the embodiments described herein. The accompanying drawings are not drawn to scale, and certain details may be magnified and omitted for the purpose of clarity. The shapes of the various regions and layers shown in the figures and the relative sizes and positional relationships therebetween are merely exemplary and may deviate in practice due to manufacturing tolerances or technical limitations, and those skilled in the art may further design regions / layers with different shapes, sizes, and relative positions according to actual needs.
[0042] The following describes exemplary embodiments of the present application. It should be noted that the following embodiments are merely provided to facilitate understanding of the spirit and principles of the present application, and the embodiments of the present application are not limited in this respect. On the contrary, the embodiments of the present application can be applied to any applicable scenario.
[0043] Currently, in a network security device session diversion scenario, two network security devices are generally set up: a master network security device and a slave network security device, so that when one network security device fails, the other network security device can take over and continue working.
[0044] Generally, a data flow includes multiple data packets, and these multiple data packets arrive at the network security device at random.
[0045] The network security device's data transmission process for each data packet includes the following steps:
[0046] First, the data packet reaches a network security device, such as the master network security device. The master network security device then establishes a secure session for the data packet and drives the logical session to be flushed. This establishes both a secure session and a logical session for the data packet. Simultaneously, the platform session is backed up to the slave network security device without establishing a logical session.
[0047] Furthermore, if the main network security device does not receive other data packets of the data stream to which the data packet belongs within the aging time of the logical session, the logical session will be deleted. After deleting the logical session, if no other data packets of the data stream to which the data packet belongs are received within the aging time of the platform session, and it is determined that no other data packets are received from the network security device, the platform session will be deleted.
[0048] Generally, the return time of the response message corresponding to the data packet is uncontrollable. If the response message returns to the master network security device or the slave network security device after deleting the logical session, the CPU needs to re-download the logic. If the response message returns to the master network security device or the slave network security device after deleting the platform session, the CPU needs to re-download the logic and re-establish the platform session.
[0049] If there are many data packets in the same data stream and they are transmitted frequently in a short period of time, the network security device will frequently add and delete platform sessions and logical sessions, resulting in session state machine switching and maintenance, etc., leading to high CPU usage and a heavy burden on the performance of the network security device. In addition, the more frequent the platform and logical refresh and deletion process is, and the more complex the process is, the higher the probability of error will be. For example, refresh anomalies or deletion anomalies, network delays, maintenance message loss, etc. will cause the traffic to be unable to correctly match the session.
[0050] In response to the above technical problems, the present application proposes a data transmission method, system, device, storage medium and computer program product. The embodiment of the present application counts the data packets of the same five-tuple information received by the network security device within the time period of the sum of the aging time of the logical session and the platform session, so as to generate a long connection rule for the five-tuple information when the number of data packets in the statistical data is greater than or equal to the preset number threshold and the statistical duration of the statistical data is less than or equal to the first preset duration, or when the number of data packets is equal to the preset threshold and the statistical duration is less than or equal to the first preset duration. The long connection rule is used to enable the network security device to maintain a long connection between the source address and the destination address in the target five-tuple information, so as to ensure that the network security device will not frequently add or delete platform sessions and logical sessions when transmitting the data stream corresponding to the five-tuple information, so as to save CPU resources and reduce the probability that the traffic cannot correctly match the session.
[0051] Before introducing the data transmission method according to the embodiment of the present application, the data transmission scenario according to the embodiment of the present application is first introduced.
[0052] like Figure 1 As shown, the scenario includes a client, a server, and a data transmission system. The system includes a business management platform and network security equipment;
[0053] The client is used to send the request data to the network security device in the data transmission system, the network security device is used to send the request data to the server, the server is used to generate corresponding response data based on the request data, and further send the response data to the network security device, and the network security device is also used to send the response data to the client to complete the data request.
[0054] The service management platform is used to obtain the target five-tuple information sent by the network security device and the statistical data obtained by counting the data packets including the target five-tuple information; if it is determined that the statistical data meets the preset conditions, a long connection rule is generated for the target five-tuple information, and the preset conditions are that the number of data packets in the statistical data is greater than or equal to the preset threshold and the statistical duration of the statistical data is less than or equal to the first preset duration, or that the number of data packets is equal to the preset threshold and the statistical duration is less than or equal to the first preset duration, and the first preset duration is determined based on the aging duration of the logical session and the platform session of the network security device; the long connection rule is sent to the network security device, and the statistical duration is the cumulative duration of the data packets of the number of received data packets;
[0055] The network security device is used to send the received target five-tuple information to the business management platform; receive the long connection rules for the target five-tuple information sent by the business management platform; and establish a long connection between the source address and the destination address in the target five-tuple information based on the long connection rules.
[0056] The embodiment of the present application first describes the data transmission method with the management platform as the execution entity.
[0057] See also Figure 2 , the method includes the following steps.
[0058] S201: Acquire target five-tuple information sent by a network security device and statistical data obtained by counting data packets including the target five-tuple information.
[0059] Among them, network security equipment is used to protect network and information security. Generally, during the interaction between the client and the server, the interaction data will first be sent to the network security equipment for detection to determine whether the interaction data is abnormal data.
[0060] Network security devices can include firewalls, virtual private network devices, network packet control devices, and load balancers, among others. As mentioned above, two network security devices are typically deployed: a master and a slave. This allows the other to take over if one fails. Remote Backup Management (RBM) can be used to configure these two devices, with each acting as the RBM master and slave.
[0061] The target five-tuple information may include: source address, destination address, source port, destination port and transmission protocol.
[0062] In some embodiments, the network security device may send the target quintuple information of the received data packet to the service management platform, so that the service management platform may perform statistics on the data packet including the target quintuple information through the target quintuple information sent by the network security device to obtain statistical data.
[0063] In some other embodiments, the service management platform may implement a network detection function on the inbound interface devices of the two network security devices to collect information about data packets arriving at the two network security devices.
[0064] S202: If it is determined that the statistical data meets the preset conditions, a long connection rule for the target quintuple information is generated.
[0065] The preset conditions are that the number of data packets in the statistical data is greater than or equal to the preset threshold and the statistical duration of the statistical data is less than or equal to the first preset duration, or the number of data packets is equal to the preset threshold and the statistical duration is less than or equal to the first preset duration, and the first preset duration is determined based on the aging duration of the logical session and platform session of the network security device.
[0066] Among them, the statistical data may include the number of data packets and the statistical duration. The number of data packets may be the number of data packets received by the network security device including the target five-tuple information, and the statistical duration may be the total reception duration corresponding to the number of data packets.
[0067] As can be seen from the above, if the same data flow contains many packets and the packets are transmitted frequently in a short period of time, it will cause the network security device to frequently add and delete platform sessions and logical sessions. Therefore, the data flow can be limited by the number of packets received in a fixed time.
[0068] The first preset duration may be the sum of the aging durations of the logical session and the platform session of the network security device. Of course, the first preset duration may also be other durations, which may be determined according to the CPU capability of the network security device.
[0069] Based on the same principle, the preset threshold value can also be any number and can also be determined according to the CPU capability of the network security device.
[0070] It can be understood that if it is determined that the statistical data meets the preset conditions, it means that the data packets of the data flow corresponding to the target quintuple information arrive at the network security device too frequently, and the addition and deletion of platform sessions and logical sessions exceed the CPU processing capacity of the network security device. Therefore, a long connection rule for the target quintuple information can be generated, that is, to remind the network security device to establish a long connection session for the target quintuple information.
[0071] In some embodiments, the process of obtaining statistical data by counting data packets of target quintuple information may be implemented as follows:
[0072] When the statistical time is the first preset duration, the number of data packets in the statistical data is determined, or the number of accumulated data packets is determined, and when the number of data packets reaches a preset threshold, the statistical duration in the statistical data is determined.
[0073] Correspondingly, the process of determining whether the statistical data meets the preset conditions can be implemented as follows:
[0074] When the statistical time is a first preset duration, the number of data packets in the statistical data is determined. If the number of data packets is greater than or equal to a preset threshold, the statistical data is determined to meet the preset condition. Alternatively, when the number of data packets reaches a preset threshold, the statistical duration in the statistical data is determined. If the statistical duration is less than or equal to the first preset duration, the statistical data is determined to meet the preset condition.
[0075] S203: Send the long connection rule to the network security device, where the long connection rule is used to enable the network security device to maintain a long connection between the source address and the destination address in the target five-tuple information.
[0076] Among them, after receiving the long connection rule, the network security device can configure the corresponding long connection session, that is, establish a long connection session with a higher priority in addition to the platform session and the logical session. When receiving a data packet including the target five-tuple information, the data packet is transmitted through the long connection session, and the response message corresponding to the data packet is transmitted through the long connection session, thereby avoiding frequent addition and deletion of logical sessions and platform sessions, and saving CPU resources.
[0077] The present application proposes a data transmission method. An embodiment of the present application counts data packets of the same five-tuple information received by a network security device within a time period that is the sum of the aging times of the logical session and the platform session, so as to generate a long connection rule for the five-tuple information when the number of data packets in the statistical data is greater than or equal to a preset number threshold and the statistical duration of the statistical data is less than or equal to a first preset duration, or when the number of data packets is equal to the preset threshold and the statistical duration is less than or equal to the first preset duration. The long connection rule is used to enable the network security device to maintain a long connection between the source address and the destination address in the target five-tuple information, so as to ensure that the network security device does not frequently add or delete platform sessions and logical sessions when transmitting the data stream corresponding to the five-tuple information, so as to save CPU resources and reduce the probability that the traffic cannot correctly match the session.
[0078] In some embodiments, after sending the persistent connection rule to the network security device, the method further includes:
[0079] It is determined within a second preset time period that the network security device has not received a data packet including the target quintuple information, and a prompt message is sent to the network security device.
[0080] The prompt message is used to prompt the network security device to delete the persistent connection rule.
[0081] The time period of the second preset duration is later than the time period of the first preset duration.
[0082] If it is determined that the network security device has not received the data packet including the target quintuple information within the second preset time period, it means that the multiple data packets belonging to the data flow corresponding to the target quintuple information have been transmitted. The network security device can be prompted to delete the long connection rule and the corresponding long connection session to release the session resources and save the resources of the network security device.
[0083] In some embodiments, the network security device includes: a master network security device and a slave network security device, and obtaining target five-tuple information sent by the network security device includes:
[0084] Monitoring a first input interface of a master network security device and a second input interface of a slave network security device;
[0085] When monitoring that the first input interface or the second input interface receives a data packet, the target five-tuple information of the data packet is obtained.
[0086] As can be seen from the above, the data packets arrive at the master network security device and the slave network security device randomly, and each data packet including the target five-tuple information will be used as the basis for whether to generate a long connection rule for the target five-tuple information. Therefore, the network monitoring function can be set on the first input interface of the master network security device and the second input interface of the slave network security device respectively to obtain the target five-tuple information of the data packets received by the first input interface and the second input interface respectively.
[0087] Of course, after receiving the data packet, the master network security device and the slave network security device may also send the target five-tuple information of the data packet to the service management platform respectively.
[0088] In some embodiments, statistical data obtained by counting data packets including target quintuple information includes: obtaining quintuple information corresponding to each of multiple data packets received by the first input interface and the second input interface within a first preset time period; determining the number of data packets in the multiple data packets whose quintuple information is consistent with the target quintuple information; and determining statistical data of the data packets based on the first preset time period and the number of data packets.
[0089] In some embodiments, if it is determined that the statistical data meets the preset conditions, a long connection rule for the target quintuple information is generated, including:
[0090] If it is determined that the number of data packets in the statistical data is greater than or equal to a preset number threshold, a long connection rule for the target five-tuple information is generated.
[0091] In some embodiments, the CPU capacity of the network security device can be used continuously within a period of time, that is, frequently adding and deleting platform sessions and logical sessions within a certain time period will not put pressure on the CPU. Therefore, the five-tuple information corresponding to the multiple data packets received by the first input interface and the second input interface within the time period can be determined.
[0092] The time period may be a first preset time period.
[0093] The number of data packets whose quintuple information is consistent with the target quintuple information is determined among the multiple data packets.
[0094] The number of data packets and the first preset duration are used as statistical data of the data packets and as a basis for determining whether to generate a long connection rule.
[0095] If the number of data packets exceeds the preset threshold, it means that the data packets of the data flow corresponding to the target five-tuple information arrive at the network security device too frequently. If the platform session and logical session are still used to transmit the data packet after this time period, it will exceed the CPU processing capacity of the network security device. Therefore, after determining that the number of data packets in the statistical data is greater than or equal to the preset number threshold, a long connection rule is generated for the target five-tuple information.
[0096] In some embodiments, determining the statistical data of the data packets corresponding to the target five-tuple information received by the network security device also includes: counting the cumulative number of data packets consistent with the target five-tuple information; determining the statistical duration of the cumulative number of data packets; and determining the statistical data of the data packets based on the cumulative number and the total reception duration.
[0097] In some embodiments, if it is determined that the statistical data meets the preset conditions, a long connection rule is generated for the target five-tuple information, and it also includes: if it is determined that the cumulative number reaches a preset number threshold and the statistical duration is less than or equal to the first preset duration, a long connection rule is generated for the target five-tuple information.
[0098] In some embodiments, the CPU of certain network security devices will exceed its processing capacity after refreshing the logical session and platform session several times within a period of time. Therefore, the business management platform will count the cumulative number of data packets that are consistent with the target five-tuple information, and at the same time count the statistical duration of the cumulative number of data packets, that is, the total receiving time of the cumulative number of data packets, and use the cumulative number and statistical duration as the statistical data of the data packet.
[0099] Furthermore, if it is detected that the cumulative number reaches a preset threshold, and it is further detected that the statistical duration is less than or equal to the first preset duration, it means that the CPU processing capacity limit has been reached at this time. If another data packet is received, the network security device may not forward the data packet. Therefore, it is necessary to generate a long connection rule for the target five-tuple information and send it to the network security device to establish a corresponding long connection session to relieve CPU pressure.
[0100] In some embodiments, if it is determined that the statistical data does not meet the preset conditions, it means that the data stream corresponding to the data packet can be transmitted normally through the logical session and the platform session, then the five-tuple information sent by the network security device is continued to be obtained to perform statistics on other data streams.
[0101] In addition, data packets may be abnormal. For example, the source address in the five-tuple information of a data packet frequently appears in other data packets, that is, a source address frequently sends data packets to different destination addresses, and the source address is considered abnormal.
[0102] If an abnormal data packet is detected, an alarm message is sent to the network security device, thereby reminding the network security device to prohibit the transmission of the data packet.
[0103] In addition, the embodiment of the present application also provides a flowchart of a data transmission method, such as Figure 3 The embodiment of the present application takes the execution subject as a network security device as an example to illustrate the data transmission method.
[0104] S301. Send the received target quintuple information to the service management platform.
[0105] As can be seen from the above, generally two network security devices are provided: a master network security device and a slave network security device. The target five-tuple information can be sent by the master network security device or the slave network security device.
[0106] S302: Receive a long connection rule for the target five-tuple information sent by the service management platform.
[0107] The long connection rule is generated and sent by the business management platform after determining that the statistical data of the received data packets including the target five-tuple information meets the preset conditions. The preset conditions are that the number of data packets in the statistical data is greater than or equal to the preset number threshold and the statistical duration of the statistical data is less than or equal to the first preset duration, or the number of data packets is equal to the preset threshold and the statistical duration is less than or equal to the first preset duration. The duration of the first preset time period is determined based on the aging duration of the logical session and the platform session of the security device.
[0108] As can be seen from the above, if the same data flow contains many packets and the packets are transmitted frequently in a short period of time, it will cause the network security device to frequently add and delete platform sessions and logical sessions. Therefore, the data flow can be limited by the number of packets received in a fixed time.
[0109] The first preset duration may be the sum of the aging durations of the logical session and the platform session of the network security device. Of course, the first preset duration may also be other durations, which may be determined according to the CPU capability of the network security device.
[0110] Based on the same principle, the preset threshold value can also be any number and can also be determined according to the CPU capability of the network security device.
[0111] It can be understood that if it is determined that the statistical data meets the preset conditions, it means that the data packets of the data flow corresponding to the target quintuple information arrive at the network security device too frequently, and the addition and deletion of platform sessions and logical sessions exceed the CPU processing capacity of the network security device. Therefore, a long connection rule for the target quintuple information can be generated, that is, to remind the network security device to establish a long connection session for the target quintuple information.
[0112] S303: Based on the long connection rule, establish a long connection between the source address and the destination address in the target five-tuple information.
[0113] After receiving the long connection rule, the network security device can configure the corresponding long connection session, that is, establish a long connection session with a higher priority in addition to the platform session and logical session. When receiving a data packet including the target five-tuple information, the data packet is transmitted through the long connection session, and the response message corresponding to the data packet is transmitted through the long connection session, thereby avoiding frequent addition and deletion of logical sessions and platform sessions, saving CPU resources.
[0114] The present application proposes a data transmission method. An embodiment of the present application counts data packets of the same five-tuple information received by a network security device within a time period that is the sum of the aging times of logical sessions and platform sessions, so as to generate a long connection rule for the five-tuple information when the number of data packets in the statistical data is greater than or equal to a preset number threshold and the statistical duration of the statistical data is less than or equal to a first preset duration, or when the number of data packets is equal to the preset threshold and the statistical duration is less than or equal to the first preset duration, and sends the long connection rule to the network security device. The long connection rule is used to enable the network security device to maintain a long connection between the source address and the destination address in the target five-tuple information, so as to ensure that the network security device does not frequently add or delete platform sessions and logical sessions when transmitting the data stream corresponding to the five-tuple information, so as to save CPU resources and reduce the probability that the traffic cannot correctly match the session.
[0115] In some embodiments, the network security device includes: a master network security device and a slave network security device, and establishes a persistent connection between a source address and a destination address in target quintuple information based on a persistent connection rule, including:
[0116] A long connection between the source address and the destination address in the target five-tuple information is established in the master network security device and the slave network security device respectively.
[0117] It is understandable that the purpose of setting up two network security devices is that when one of the network security devices fails, the other network security device can take over and continue working. Therefore, it is necessary to establish a long connection between the source address and the destination address in the target five-tuple information in the master network security device and the slave network security device respectively.
[0118] In some embodiments, after establishing a long connection between the source address and the destination address in the target quintuple information based on the long connection rule, the method also includes: receiving a prompt message from the network security device, the prompt message is sent by the business management platform when it determines that the network security device has not received a data packet including the target quintuple information within a second preset time period; and deleting the long connections established in the master network security device and the slave network security device respectively based on the prompt message.
[0119] The time period of the second preset duration is later than the time period of the first preset duration.
[0120] If it is determined that the network security device has not received the data packet including the target quintuple information within the second preset time period, it means that the multiple data packets belonging to the data flow corresponding to the target quintuple information have been transmitted. The network security device can be prompted to delete the long connection rule and the corresponding long connection session to release the session resources and save the resources of the network security device.
[0121] The present application also provides a data transmission device for performing the above Figure 2 The data transmission method in the embodiment, such as Figure 4 As shown, the device includes:
[0122] An acquisition module 401 is configured to acquire target five-tuple information sent by a network security device and statistical data obtained by counting data packets including the target five-tuple information;
[0123] a generation module 402, configured to generate a long connection rule for the target quintuple information if it is determined that the statistical data satisfies a preset condition, wherein the preset condition is that the number of data packets in the statistical data is greater than or equal to a preset threshold and the statistical duration of the statistical data is equal to a first preset duration, or that the number of data packets is equal to the preset threshold and the statistical duration is less than or equal to the first preset duration, wherein the first preset duration is determined based on the aging duration of the logical session and the platform session of the network security device, and the statistical duration is the cumulative duration of receiving data packets of the number of data packets;
[0124] The sending module 403 is configured to send the long connection rule to the network security device, where the long connection rule is configured to enable the network security device to maintain a long connection between the source address and the destination address in the target quintuple information.
[0125] In some embodiments, the sending module 403 is further configured to:
[0126] If it is determined within a second preset time period that the network security device has not received the data packet including the target five-tuple information, a prompt message is sent to the network security device, where the prompt message is used to prompt the network security device to delete the long connection rule.
[0127] In some embodiments, the network security device includes: a master network security device and a slave network security device, and the acquisition module 401 is specifically configured to:
[0128] Monitoring a first input interface of the master network security device and a second input interface of the slave network security device;
[0129] When monitoring that the first input interface or the second input interface receives a data packet, obtain target quintuple information of the data packet.
[0130] In some embodiments, the acquisition module 401 is further specifically configured to:
[0131] Obtaining quintuple information corresponding to each of a plurality of data packets received by the first input interface and the second input interface within a first preset time period;
[0132] Determining the number of data packets whose quintuple information is consistent with the target quintuple information in the multiple data packets;
[0133] Statistical data of the data packets is determined based on the first preset time period and the number of the data packets.
[0134] In some embodiments, the acquisition module 401 is further specifically configured to:
[0135] Count the cumulative number of data packets that are consistent with the target five-tuple information;
[0136] Determining a statistical duration of the cumulative number of data packets;
[0137] The statistical data of the data packet is determined based on the accumulated number and the total reception time.
[0138] In some embodiments, the generating module 402 is specifically configured to:
[0139] If it is determined that the number of data packets in the statistical data is greater than or equal to a preset number threshold, a long connection rule for the target quintuple information is generated.
[0140] In some embodiments, the generating module 402 is further configured to:
[0141] If it is determined that the accumulated number reaches a preset number threshold, and the statistical duration is less than or equal to a first preset duration, a long connection rule for the target quintuple information is generated.
[0142] The data transmission device provided in the embodiment of the present application and the data transmission method provided in the embodiment of the present application are based on the same application concept and have the same beneficial effects as the methods adopted, operated or implemented by them.
[0143] The present application also provides a data transmission device for performing the above Figure 3 The data transmission method in the embodiment, such as Figure 5 As shown, the device includes:
[0144] The sending module 501 is used to send the received target quintuple information to the service management platform;
[0145] A receiving module 502 is configured to receive a long connection rule for the target five-tuple information sent by the business management platform, where the long connection rule is generated and sent by the business management platform after determining that statistical data of received data packets including the target five-tuple information meet a preset condition, where the preset condition is that the number of data packets in the statistical data is greater than or equal to a preset threshold and the statistical duration of the statistical data is equal to a first preset duration, or that the number of data packets is equal to the preset threshold and the statistical duration is less than or equal to the first preset duration, where the duration of the first preset time period is determined based on the aging duration of the logical session and the platform session of the security device, and the statistical duration is the cumulative duration of receiving data packets of the number of data packets;
[0146] The establishing module 503 is configured to establish a persistent connection between the source address and the destination address in the target quintuple information based on the persistent connection rule.
[0147] In some embodiments, the network security device includes: a master network security device and a slave network security device, and the apparatus further includes: an establishment module for
[0148] A long connection between the source address and the destination address in the target quintuple information is established in the master network security device and the slave network security device respectively.
[0149] In some embodiments, the receiving module 502 is further configured to:
[0150] receiving a prompt message from a network security device, wherein the prompt message is sent when the service management platform determines that the network security device has not received a data packet including the target quintuple information within a second preset time period;
[0151] The long connections established in the master network security device and the slave network security device are deleted respectively based on the prompt information.
[0152] Please refer to the following Figure 6 , which shows a schematic diagram of an electronic device provided by some embodiments of the present application. Figure 6 As shown, the electronic device 7 includes: a processor 700, a memory 701, a bus 707 and a communication interface 703, and the processor 700, the communication interface 703 and the memory 701 are connected via the bus 707; the memory 701 stores a computer program that can be run on the processor 700, and when the processor 700 runs the computer program, it executes the data transmission method provided in any of the aforementioned embodiments of the present application.
[0153] Memory 701 may include high-speed random access memory (RAM) and may also include non-volatile memory, such as at least one disk storage. Communication between the system network element and at least one other network element is achieved through at least one communication interface 703 (which may be wired or wireless), and may use the Internet, a wide area network, a local area network, a metropolitan area network, etc.
[0154] The bus 707 may be an ISA bus, a PCI bus, or an EISA bus. The bus may be divided into an address bus, a data bus, a control bus, and the like. The memory 701 is used to store programs, and the processor 700 executes the programs upon receiving execution instructions. The data transmission method disclosed in any of the aforementioned embodiments of the present application may be applied to the processor 700 or implemented by the processor 700.
[0155] The processor 700 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by hardware integrated logic circuits in the processor 700 or by software instructions. The processor 700 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in conjunction with the embodiments of this application can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium mature in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory 701 , and the processor 700 reads the information in the memory 701 and completes the steps of the above method in combination with its hardware.
[0156] The electronic device provided in the embodiment of the present application and the data transmission method provided in the embodiment of the present application are based on the same application concept and have the same beneficial effects as the methods adopted, operated or implemented by them.
[0157] The present application also provides a computer-readable storage medium corresponding to the data transmission method provided in the above embodiment. Figure 7, Figure 7 The computer-readable storage medium shown is an optical disc 30 on which a computer program (ie, a program product) is stored. When the computer program is executed by a processor, the data transmission method provided by any of the aforementioned embodiments is executed.
[0158] In addition, examples of the computer-readable storage medium may also include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other optical or magnetic storage media, which are not listed here one by one.
[0159] The computer-readable storage medium provided in the above-mentioned embodiments of the present application and the data transmission method provided in the embodiments of the present application are based on the same application concept and have the same beneficial effects as the methods adopted, run or implemented by the application programs stored therein.
[0160] It should be noted that the algorithms and displays provided herein are not inherently related to any particular computer, virtual device, or other device. Various general-purpose devices may also be used in conjunction with the teachings herein. The structures required to construct such devices are readily apparent from the above description. Furthermore, this application is not directed to any particular programming language. It should be understood that the content of this application described herein may be implemented using a variety of programming languages, and the above description of specific languages is intended to disclose the best mode of implementation of this application.
[0161] Similarly, it should be understood that in order to streamline the present application and aid understanding of one or more of the various application aspects, in the above description of the exemplary embodiments of the present application, various features of the present application are sometimes grouped together into a single embodiment, figure, or description thereof. However, this disclosed method should not be interpreted as reflecting an intention that the claimed application requires more features than are expressly recited in each claim. Rather, as reflected in the claims below, aspects of the application lie in less than all the features of the individual embodiments disclosed above. Accordingly, the claims following the detailed description are hereby expressly incorporated into this detailed description, with each claim standing on its own as a separate embodiment of the present application.
[0162] The various component embodiments of the present application can be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. Those skilled in the art will appreciate that a microprocessor or digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components in the creation device of the virtual machine according to the embodiment of the present application. The application can also be implemented as a device or device program for executing part or all of the methods described herein. The program implementing the application can be stored on a computer-readable medium, or can have the form of one or more signals. Such a signal can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.
[0163] The above description is merely a preferred embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A data transmission method, characterized in that: The method comprises: Obtaining target five-tuple information sent by the network security device and statistical data obtained by counting data packets including the target five-tuple information; If it is determined that the statistical data meets a preset condition, a long connection rule is generated for the target quintuple information, where the preset condition is that the number of data packets in the statistical data is greater than or equal to a preset threshold and the statistical duration of the statistical data is equal to a first preset duration, or that the number of data packets is equal to the preset threshold and the statistical duration is less than or equal to the first preset duration, where the first preset duration is determined based on the aging duration of the logical session and the platform session of the network security device, and the statistical duration is the cumulative duration of receiving data packets of the number of data packets; The long connection rule is sent to the network security device, where the long connection rule is used to enable the network security device to maintain a long connection between the source address and the destination address in the target quintuple information.
2. The method according to claim 1, characterized in that After sending the persistent connection rule to the network security device, the method further includes: If it is determined within a second preset time period that the network security device has not received the data packet including the target five-tuple information, a prompt message is sent to the network security device, where the prompt message is used to prompt the network security device to delete the long connection rule.
3. The method according to claim 1, characterized in that The network security device includes: a master network security device and a slave network security device, and obtaining target quintuple information sent by the network security device includes: Monitoring a first input interface of the master network security device and a second input interface of the slave network security device; When it is monitored that the first input interface or the second input interface receives a data packet, target five-tuple information of the data packet received by the first input interface or the second input interface is obtained.
4. The method according to claim 3, characterized in that Obtaining statistical data obtained by counting data packets including the target quintuple information, including: Obtaining quintuple information corresponding to each of a plurality of data packets received by the first input interface and the second input interface within a first preset time period; Determining the number of data packets whose quintuple information is consistent with the target quintuple information in the multiple data packets; Statistical data of the data packets are determined based on the first preset duration and the number of the data packets.
5. The method according to claim 3, characterized in that The determining of statistical data of data packets corresponding to the target five-tuple information received by the network security device further includes: Count the cumulative number of data packets that are consistent with the target five-tuple information; Determining a statistical duration of the cumulative number of data packets; The statistical data of the data packet is determined based on the accumulated number and the total reception time.
6. The method according to claim 4, characterized in that If it is determined that the statistical data meets the preset condition, generating a long connection rule for the target quintuple information includes: If it is determined that the number of data packets in the statistical data is greater than or equal to a preset threshold, a long connection rule for the target quintuple information is generated.
7. The method according to claim 5, characterized in that If it is determined that the statistical data meets the preset condition, generating a long connection rule for the target quintuple information also includes: If it is determined that the accumulated number reaches a preset threshold and the statistical duration is less than or equal to a first preset duration, a long connection rule for the target quintuple information is generated.
8. A data transmission method, characterized in that: The method comprises: Send the received target five-tuple information to the business management platform; Receive a long connection rule for the target quintuple information sent by the business management platform, where the long connection rule is generated and sent by the business management platform after determining that statistical data of received data packets including the target quintuple information meets a preset condition, where the preset condition is that the number of data packets in the statistical data is greater than or equal to a preset threshold and the statistical duration of the statistical data is equal to a first preset duration, or that the number of data packets is equal to the preset threshold and the statistical duration is less than or equal to the first preset duration, where the first preset duration is determined based on the aging duration of the logical session and the platform session of the network security device, and the statistical duration is the cumulative duration of receiving data packets of the number of data packets; Based on the long connection rule, a long connection is established between the source address and the destination address in the target quintuple information.
9. The method according to claim 8, characterized in that The network security device includes: a master network security device and a slave network security device, and establishing a persistent connection between a source address and a destination address in the target quintuple information based on the persistent connection rule includes: A long connection between the source address and the destination address in the target quintuple information is established in the master network security device and the slave network security device respectively.
10. The method according to claim 9, characterized in that After establishing a persistent connection between the source address and the destination address in the target quintuple information based on the persistent connection rule, the method further includes: receiving a prompt message from a network security device, wherein the prompt message is sent when the service management platform determines that the network security device has not received a data packet including the target quintuple information within a second preset time period; The long connections established in the master network security device and the slave network security device are deleted respectively based on the prompt information.
11. A data transmission system, characterized in that: The system includes a business management platform and network security equipment; The business management platform is used to obtain the target five-tuple information sent by the network security device and the statistical data obtained by counting the data packets including the target five-tuple information; if it is determined that the statistical data meets the preset conditions, a long connection rule is generated for the target five-tuple information, and the preset conditions are that the number of data packets in the statistical data is greater than or equal to a preset threshold and the statistical duration of the statistical data is equal to a first preset duration, or that the number of data packets is equal to the preset threshold and the statistical duration is less than or equal to the first preset duration, and the first preset duration is determined based on the aging duration of the logical session and the platform session of the network security device; the long connection rule is sent to the network security device, and the statistical duration is the cumulative duration of receiving data packets of the number of data packets; The network security device is used to send the received target quintuple information to the service management platform; Receive a long connection rule for the target five-tuple information sent by the business management platform; and establish a long connection between the source address and the destination address in the target five-tuple information based on the long connection rule.
12. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: The processor runs the computer program to implement the method according to any one of claims 1 to 10.
13. A computer-readable storage medium having a computer program stored thereon, characterized in that: The program is executed by a processor to implement the method according to any one of claims 1 to 10.
14. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 10 is implemented.
Citation Information
Patent Citations
Method and device for conversation aging
CN101369973A
Firewall session number monitoring method and apparatus
CN107872503A