User Traffic Screening Method, Device, Electronic Device and Storage Medium
By obtaining the target user's identity and controlling the tunnel bearer identity, creating a database and filtering traffic, the analysis system pressure problem caused by excessive traffic data in the LTE core network is solved, and efficient and accurate traffic screening and analysis are achieved.
Patent Information
- Application Number
- CN202510083327.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-20
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2045-01-20
AI Technical Summary
At this stage, the log retention system of the LTE core network connects to all user traffic, resulting in too large data volume of analysis system, increasing the difficulty of analysis, and how to effectively filter and send it to the matching analysis system.
By obtaining the target user's target user's target user's target user, determining the target control tunnel and its bearer identity associated with it, creating a target database, and forwarding the target user traffic to the target analysis system in the case of matching.
It improves the screening efficiency of traffic data in LTE core network and the accuracy of the analysis system, and reduces the processing pressure of the analysis system.
Smart Images

Figure CN119562306B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of LTE core network, and particularly to a method, device, electronic device and storage medium for screening user traffic. Background Art
[0002] The main interfaces of the LTE (Long Term Evolution) core network are S11, S1-U, S58-C, and S58-U. Among them, S11 and S58-C are control plane interfaces, and S1-U and S58-U are user plane interfaces. At present, the log retention system will simultaneously access the traffic of S11, S1-U, S58-C, and S58-U, parse the traffic of all users and generate logs for retention; at the same time, these data are accessed to the subsequent analysis system (this analysis system is only interested in the traffic data generated by certain users, for example, the Internet traffic of target users), which will cause the analysis system to receive too much data and increase the analysis difficulty of the analysis system.
[0003] How to screen these traffic data and send them to the matching analysis system is the key issue studied in the industry. Summary of the Invention
[0004] The present invention provides a method, device, electronic device and storage medium for screening user traffic to screen the traffic data generated by the LTE core network and provide a basis for improving the efficiency and accuracy of subsequent data analysis work.
[0005] According to one aspect of the present invention, a method for screening user traffic is provided, and the method includes:
[0006] In response to a screening instruction for the user traffic of a target user, obtain the target user identifier of the target user;
[0007] Determine a target control tunnel associated with the target user and each bearer identifier belonging to the target control tunnel; the bearer identifier includes a default bearer identifier and a dedicated bearer identifier;
[0008] Create a target database based on the target control tunnel, the bearer identifiers belonging to the target control tunnel, and a target traffic data five-tuple;
[0009] In response to a screening instruction for target user traffic, when it is determined that the target user traffic matches the target database, forward the target user traffic to a target analysis system.
[0010] According to another aspect of the present invention, a device for screening user traffic is provided, and the device includes:
[0011] A user identification acquisition module, configured to acquire a target user identification of the target user in response to a screening instruction for the user traffic of the target user;
[0012] A determination module, configured to determine a target control tunnel associated with the target user and each bearer identification belonging to the target control tunnel; the bearer identification includes a default bearer identification and a dedicated bearer identification;
[0013] A database creation module, configured to create a target database based on the target control tunnel, the bearer identification belonging to the target control tunnel, and a target traffic data quintuple;
[0014] A user traffic screening module, configured to forward the target user traffic to a target analysis system in response to a screening instruction for the target user traffic when it is determined that the target user traffic matches the target database.
[0015] According to another aspect of the present invention, there is provided an electronic device, where the electronic device includes:
[0016] At least one processor; and
[0017] A memory communicatively connected to the at least one processor; wherein,
[0018] The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the user traffic screening method according to any embodiment of the present invention.
[0019] According to another aspect of the present invention, there is provided a computer-readable storage medium storing computer instructions for causing a processor to execute the user traffic screening method according to any embodiment of the present invention when executed.
[0020] According to another aspect of the present invention, there is provided a computer program product including a computer program that implements the user traffic screening method according to any embodiment of the present invention when executed by a processor.
[0021] The technical solution of the embodiment of the present invention obtains the target user identifier of the target user by responding to the screening instruction of the user traffic of the target user; determines the target control tunnel associated with the target user and each bearer identifier belonging to the target control tunnel; the bearer identifier includes a default bearer identifier and a dedicated bearer identifier; creates a target database based on the target control tunnel, the bearer identifiers belonging to the target control tunnel, and the target traffic data quintuple; and forwards the target user traffic to the target analysis system in response to the screening instruction of the target user traffic. In this way, the traffic data generated by the LTE core network can be screened, providing a basis for improving the efficiency and accuracy of subsequent data analysis work.
[0022] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0024] Figure 1 is a flowchart of a method for screening user traffic according to Embodiment 1 of the present invention;
[0025] Figure 2 is a schematic diagram of the relationship between a control tunnel, a default bearer, and a dedicated bearer according to Embodiment 1 of the present invention;
[0026] Figure 3 is a flowchart of a method for screening user traffic according to Embodiment 2 of the present invention;
[0027] Figure 4 is a schematic structural diagram of a device for screening user traffic according to Embodiment 3 of the present invention;
[0028] Figure 5 is a schematic structural diagram of an electronic device for implementing the method for screening user traffic in the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0029] To enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative work shall fall within the scope of protection of the present invention.
[0030] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order different from those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0031] Embodiment 1
[0032] Figure 1 is a flowchart of a method for screening user traffic provided according to Embodiment 1 of the present invention. This embodiment is applicable to the situation of screening traffic data generated by the LTE core network. This method can be executed by a user traffic screening device, which can be implemented in the form of hardware and / or software, and can be configured in electronic devices such as computers, servers, or tablets. As Figure 1 shown, the method includes:
[0033] Step 110, in response to a screening instruction for the user traffic of a target user, obtain the target user identifier of the target user.
[0034] Among them, the target user can be any user accessing the LTE core network, and is not limited in this embodiment.
[0035] Among them, the target user identifier of the target user can be the mobile phone number of the target user, or other parameters that can uniquely identify the target user. For example, the user name or registration identifier in the registration information of the target user, etc., is not limited in this embodiment.
[0036] It can be understood that in the LTE core network, the user traffic of the user is transmitted through the user plane interface. Therefore, after receiving the screening instruction for the user traffic of the target user, the user traffic data transmitted by the LTE core network through the user plane interfaces S1-U and S58-U can be obtained, and further, the user traffic data can be screened or shunted.
[0037] In an optional implementation manner of this embodiment, after receiving the screening instruction for the user traffic of the target user, the received screening instruction can be further parsed to obtain the target user identifier of the target user.
[0038] Optionally, in this embodiment, obtaining the target user identifier of the target user may include: obtaining the attachment request and / or PDN (Packet Data Network, creating a specific packet data network) connection request of the target user; determining the target user identifier of the target user based on the attachment request and / or PDN connection request.
[0039] In this embodiment, a user equipment, such as a mobile phone, will trigger the CreatSession process of the S11 and S58-C interfaces in the LTE core network during processes such as attachment and creation of a PDN connection; information such as the mobile phone number, initial location, and default bearer identifier can be carried in the CreatSession process.
[0040] In an optional implementation manner of this embodiment, after receiving the screening instruction for the user traffic of the target user, the CreatSession process in the attachment request and the PDN connection request related to the target user can be further obtained, and the request of the CreatSession process can be parsed to obtain the mobile phone number of the target user; further, the mobile phone number of the target user can be determined as the target user identifier of the target user.
[0041] Step 120: Determine the target control tunnel associated with the target user and each bearer identifier belonging to the target control tunnel.
[0042] Among them, the bearer identifier includes a default bearer identifier and a dedicated bearer identifier.
[0043] Optionally, in an alternative implementation of this embodiment, after receiving a filtering instruction for the Internet traffic of the target user, the target control tunnel associated with the target user and each bearer identifier matching each target control tunnel may be further determined. It can be understood that one control tunnel may be associated with multiple default bearers, and one default bearer may be associated with multiple dedicated bearers. That is, there may be multiple default bearers belonging to the target control tunnel and multiple dedicated bearers belonging to the default bearer at the same time. For example, there may be 2, 3, or 10, etc. This embodiment does not limit it.
[0044] Exemplarily, Figure 2 FIG. 5 is a schematic diagram of the relationship between a control tunnel, a default bearer, and a dedicated bearer according to Embodiment 1 of the present invention; as Figure 2 shown, the target control tunnel may include Control Tunnel 1, Control Tunnel 2, and Control Tunnel 3. Among them, Control Tunnel 1 is associated with two default bearers, namely Default Bearer ID = 5 and Default Bearer ID = 6. Default Bearer ID = 5 is associated with two dedicated bearers, namely Dedicated Bearer ID = 8 and Dedicated Bearer ID = 9. Default Bearer ID = 6 is associated with Dedicated Bearer ID = 11. Control Tunnel 2 is associated with one default bearer, which is Default Bearer ID = 5. Default Bearer ID = 5 is associated with Dedicated Bearer ID = 13. Control Tunnel 3 is associated with one default bearer, which is Default Bearer ID = 5.
[0045] In an alternative implementation of this embodiment, after receiving a filtering instruction for the Internet traffic of the target user, the attachment request related to the target user and the create session process in the PDN connection request may be further obtained, and the response to the create session process may be parsed to obtain the information of the GW-side tunnel of the target user and the default bearer identifier.
[0046] Optionally, in this embodiment, determining the target control tunnel associated with the target user and each bearer identifier belonging to the target control tunnel may include: obtaining a first create session process matching the attachment request, and determining the first uplink and downlink tunnel created in the first create session process and the first bearer identifier; determining the first uplink and downlink tunnel as the target control tunnel and the first bearer identifier as the default bearer identifier belonging to the target control tunnel; or obtaining a second create session process matching the PDN connection request, and determining the second uplink and downlink tunnel created in the second create session process and the second bearer identifier; determining the second uplink and downlink tunnel as the target control tunnel and the second bearer identifier as the default bearer identifier belonging to the target control tunnel; obtaining the dedicated bearer activation process, and obtaining the dedicated bearer identifier associated with the default bearer identifier in the dedicated bearer activation process.
[0047] In an optional implementation manner of this embodiment, a first create session procedure matching the attachment request of the target user's mobile device can be obtained; specifically, when receiving the request and response of the first create session procedure, the user identifier can be extracted from the Create Session Request; the default bearer identifier (EBI (EPC Bearer Identify, user plane bearer identifier)) can be extracted from the Create Session Response; one EBI can correspond to one user plane uplink and downlink tunnel. Exemplarily,
[0048] Ip1 + teid1 ip2 + teid2; where, ip2 + teid2 is called the uplink tunnel identifier); in this embodiment, this default bearer identifier is called the first bearer identifier; and GW side tunnel information (such as TEID or creation time), in this embodiment, this GW side tunnel is called the first uplink tunnel. Further, the obtained first uplink tunnel can be determined as the target control tunnel, and the first bearer identifier can be determined as the default bearer identifier belonging to the target control tunnel.
[0049] It should be noted that in this embodiment, the user name interfaces S1U and S58-U are not distinguished. The eNB of S1U and the SGW-U of S58-U are replaced by the AC side, and the SGW-U of S1U and the PGW-U of S58-U are replaced by the GW side; in this embodiment, only the GW side tunnel is taken as an example for illustration, which is not a limitation to this embodiment.
[0050] In another optional implementation manner of this embodiment, a second create session procedure matching the PDN connection request of the target user's mobile device can be obtained; specifically, when receiving the request and response of the second create session procedure, the user identifier can be extracted from the Create Session Request; the default bearer identifier (EBI) can be extracted from the Create Session Response, and in this embodiment, this default bearer identifier is called the second bearer identifier; and GW side tunnel information (such as TEID or creation time), in this embodiment, this GW side tunnel is called the second uplink and downlink tunnel. Further, the obtained second uplink and downlink tunnel can be determined as the target control tunnel, and the second bearer identifier can be determined as the default bearer identifier belonging to the target control tunnel.
[0051] Optionally, in this embodiment, after determining the first bearer identifier and the second bearer identifier as the default bearer identifier based on the above steps, the dedicated bearer activation process can be further obtained; specifically, the default bearer identifier can be found in the Create BearerRequest message (for example, EBI = 5); further, the newly created dedicated bearer identifier can be extracted from the Create BearerResponse message (for example, EBI = 7); further, the default bearer identifier can be associated with the dedicated bearer identifier to form a mapping relationship, that is: the default bearer EBI = 5 corresponds to the dedicated bearer EBI = 7.
[0052] Step 130: Create a target database based on the target control tunnel, the bearer identifier belonging to the target control tunnel, and the target traffic data quintuple.
[0053] The target traffic data quintuple may include: source IP (Internet Protocol) address, which is the IP address of the data packet sender; destination IP address, which is the IP address of the data packet receiver; source port, which is the port number used by the sender application; destination port, which is the port number used by the receiver application; transport layer protocol, such as TCP (Transmission Control Protocol) or UDP (User Datagram Protocol), etc.
[0054] Optionally, in this embodiment, after determining the target control tunnel, each default bearer identifier belonging to the target control tunnel, the dedicated bearer identifier associated with each default bearer identifier, and the quintuple of the target traffic data, a target database can be further created according to the target control tunnel, each default bearer identifier belonging to the target control tunnel, the dedicated bearer identifier associated with each default bearer identifier, and the quintuple of the target traffic data.
[0055] Exemplarily, the identifier of the target control tunnel, each default bearer identifier belonging to the target control tunnel, and the dedicated bearer identifier associated with each default bearer identifier can be stored in the first data table; the tunnel identifier of the GW-side username tunnel created based on the default bearer identifier or the dedicated bearer identifier in the first data table can be stored in the second data table; the Internet access process initiated by the target user under the user plane tunnel recorded in the second data table (represented by the quintuple) can be added to the third data table; further, the first data table, the second data table, and the third data table are combined together to obtain the target database.
[0056] Step 140: In response to a screening instruction for target user traffic, when it is determined that the target user traffic matches the target database, forward the target user traffic to the target analysis system.
[0057] Optionally, in this embodiment, after receiving the target user traffic through the user plane interfaces S1U and S58-U of the LTE core network, the target user traffic can be parsed to determine the five-tuple of the target user traffic or the target user plane tunnel identifier; further, the five-tuple of the target user traffic can be compared with the five-tuples of the target traffic data stored in the target database, or the target user plane tunnel identifier can be compared with the default bearer identifier or dedicated bearer identifier stored in the target database, so as to determine whether to forward the target user traffic to the target analysis system according to the comparison result.
[0058] The technical solution of this embodiment obtains the target user identifier of the target user by responding to a screening instruction for the user traffic of the target user; determines the target control tunnel associated with the target user and each bearer identifier belonging to the target control tunnel; the bearer identifier includes a default bearer identifier and a dedicated bearer identifier; creates a target database based on the target control tunnel, the bearer identifiers belonging to the target control tunnel, and the five-tuple of the target traffic data; and in response to a screening instruction for target user traffic, when it is determined that the target user traffic matches the target database, forwards the target user traffic to the target analysis system, which can screen the traffic data generated by the LTE core network and provide a basis for improving the efficiency and accuracy of subsequent data analysis work.
[0059] Embodiment 2
[0060] Figure 3 FIG. is a flowchart of a method for screening user traffic according to Embodiment 2 of the present invention. This embodiment further refines the above technical solution, and the technical solution in this embodiment can be combined with each optional solution in one or more of the above embodiments. As Figure 3 shown, the method includes:
[0061] Step 310: In response to a screening instruction for the user traffic of the target user, obtain the target user identifier of the target user.
[0062] Step 320: Determine the target control tunnel associated with the target user and each bearer identifier belonging to the target control tunnel.
[0063] Optionally, in this embodiment, while obtaining the first creation session process that matches the attachment request and determining the first uplink and downlink tunnels and the first bearer identifier created in the first creation session process, and obtaining the second creation session process that matches the PDN connection request and determining the second uplink and downlink tunnels and the second bearer identifier created in the second creation session process, or after obtaining the first creation session process that matches the attachment request and determining the first uplink and downlink tunnels and the first bearer identifier created in the first creation session process, and obtaining the second creation session process that matches the PDN connection request and determining the second uplink and downlink tunnels and the second bearer identifier created in the second creation session process, it is also possible to obtain the first deletion session process that matches the attachment request, or obtain the second deletion session process that matches the PDN connection request; obtain attribute information of the first creation session process, the first deletion session process, the second creation session process and the first deletion session process respectively; and determine the creation time and deletion time of each target control tunnel based on each attribute information.
[0064] Among them, the attribute information may include the user identifier, tunnel identifier, default bearer identifier, creation time or deletion time of each session, etc. of each session process; exemplarily, the first session creation process may include: user identifier, tunnel identifier, at least one default bearer identifier and the creation time of the first session creation process; the first session deletion process may include: user identifier, tunnel identifier, at least one default bearer identifier and the deletion time of the first session deletion process.
[0065] In an optional implementation of this embodiment, in the process of determining the target control tunnel associated with the target user and the default bearer identifiers matching the target control tunnel, attribute information of each creation session or deletion session can also be obtained. Furthermore, the creation time and deletion time of the target control tunnel can be determined based on the obtained attribute information.
[0066] It should be noted that during the session creation process, when the target user's phone requests an attachment, the LTE core network creates uplink and downlink tunnels for the phone on the control plane interfaces S11 and S58-C, and assigns a default bearer and ID; for example, id = 5. When the target user's phone creates a PDN connection request, uplink and downlink tunnels S11 and S58-C are created for the phone (in this process, the attachment process may be reused) and a default bearer ID is assigned; for example, id = 6. It is understandable that the same target user's phone may create multiple PDN connections; therefore, a single S11 / S58-C control tunnel may have multiple default bearers attached to it.
[0067] It should also be noted that in the deletion session process, if the default bearer identifier is not carried, it means deleting all default bearers under the control tunnel and deleting the control tunnel; if the default bearer identifier is carried, it means deleting the default bearer corresponding to the default bearer identifier. When the deletion sessions with the default bearer identifier carried multiple times result in the deletion of all default bearers, the control tunnel needs to be automatically deleted.
[0068] It can be understood that the mobile phone's phone number carries and allocates a control plane tunnel in CreatSession. The target user can be filtered, and the control plane tunnel of the target user can be learned; at the same time, a default bearer is allocated in CreateSession; the default bearer of the target user can be learned; in the control tunnel, a dedicated bearer is created through CreateBear; the dedicated bearer of the target user can be learned; the user's Internet traffic is transmitted in the default bearer or the dedicated bearer. Therefore, the Internet traffic of the target user can be finally filtered out.
[0069] Step 330, create a target database based on the target control tunnel, the bearer identifier belonging to the target control tunnel, and the target traffic data quintuple.
[0070] Optionally, in this embodiment, creating a target database based on the target control tunnel, the bearer identifier belonging to the target control tunnel, and the target traffic data quintuple may include: storing the target control tunnel, the default bearer identifier belonging to the target control tunnel, the dedicated bearer identifier of the dedicated bearer corresponding to the default bearer identifier, the creation time and deletion time of the target control tunnel, and the target traffic data quintuple to be filtered in a target area to obtain a target database; wherein, the target traffic data quintuple includes: source address, destination address, source port, destination port, and transport protocol.
[0071] In an optional implementation manner of this embodiment, after obtaining the target control tunnel, the default bearer identifier belonging to the target control tunnel, the dedicated bearer identifier of the dedicated bearer corresponding to the default bearer identifier, the creation time and deletion time of the target control tunnel, and the target traffic data quintuple to be filtered, the target control tunnel, the default bearer identifier belonging to the target control tunnel, the dedicated bearer identifier of the dedicated bearer corresponding to the default bearer identifier, the creation time and deletion time of the target control tunnel, and the target traffic data quintuple to be filtered can be further added to the database to obtain a target database.
[0072] Exemplarily, in this embodiment, after the above data is determined, the tunnel identifier, creation time, deletion time of the target control tunnel, the default bearer identifier belonging to the target control tunnel, and the dedicated bearer identifier corresponding to the default bearer identifier can be further added to the first data table; the tunnel identifier of the user plane tunnel created based on the default bearer identifier or dedicated bearer identifier in the first data table is added to the second data table; the Internet access process initiated by the target user (represented by a five-tuple) under the user plane tunnel recorded in the second data table is added to the third data table; the first data table, the second data table, and the third data table are jointly stored in the target area to obtain the target database. Step 340: Analyze the target user traffic to obtain a target five-tuple that matches the target user traffic; compare the target five-tuple with the target traffic data five-tuple stored in the target database to obtain a comparison result; when it is determined according to the comparison result that the target five-tuple is consistent with the target traffic data five-tuple stored in the target database, forward the target user traffic to the target analysis system.
[0073] In an optional implementation manner of this embodiment, after the target database associated with the target user is constructed, if the user plane interface receives a target user traffic packet, the target user traffic packet can be further analyzed to obtain the target five-tuple in the target user traffic packet, that is, the source address, destination address, source port, destination port, and transport protocol of the target user traffic data; further, it can be determined whether the target five-tuple matches the target traffic data five-tuple recorded in the third data table in the target database; if it is determined that the target five-tuple is consistent with the target traffic data five-tuple recorded in the third data table in the target database, it can be determined that the target five-tuple matches the target traffic data five-tuple recorded in the third data table in the target database, and further, the target user traffic can be forwarded to the target analysis system.
[0074] Further, the target analysis system can perform subsequent analysis and processing on each received target user traffic packet; exemplarily, if each target user traffic packet contains the Internet access information of the target user, then the target analysis system can determine the Internet access habits of the target user by analyzing this Internet access information.
[0075] Step 350: When it is determined according to the comparison result that the target five-tuple is inconsistent with the target traffic data five-tuple stored in the target database, determine the target user plane tunnel identifier of the target user traffic; determine whether the target user plane tunnel identifier is consistent with the user plane tunnel identifier stored in the target database. When it is determined that the target user plane tunnel identifier is consistent with the user plane tunnel identifier stored in the target database, forward the target user traffic to the target analysis system, and add the target five-tuple to the target database.
[0076] The target user plane tunnel identifier includes: the access side (AC side) user plane tunnel identifier and the gateway side (GW side) user plane tunnel identifier.
[0077] It can be understood that in this embodiment, the target control tunnel stored in the target database is an upstream tunnel; however, during the process of screening the target user traffic, the upstream and downstream tunnels of the target user traffic are respectively matched with the tunnel identifiers stored in the database.
[0078] In an optional implementation manner of this embodiment, when it is determined according to the comparison result that the target five-tuple is inconsistent with the target traffic data five-tuple stored in the target database, that is, it is determined that the target five-tuple is inconsistent with the target traffic data five-tuple recorded in the third data table of the target database, then the target user plane tunnel identifier can be continuously determined according to the parsing result of the target user traffic; further, it can be determined whether the target user plane tunnel identifier is consistent with the user plane tunnel identifier stored in the second data table of the target database; if it is determined that the target user plane tunnel identifier is consistent with the user plane tunnel identifier stored in the second data table of the target database, then the target user traffic can be further forwarded to the target analysis system; at the same time, the target five-tuple can also be added to the third data table of the target database, thereby updating the target database; in this way, when subsequent user traffic consistent with the target five-tuple is obtained, the user traffic can be directly forwarded to the target analysis system, improving the efficiency of traffic screening.
[0079] In the solution of this embodiment, after constructing the target database associated with the target user, if the target user traffic is received, the target user traffic can be parsed to obtain a target five-tuple that matches the target user traffic; the target five-tuple is compared with the target traffic data five-tuple stored in the target database to obtain a comparison result; when it is determined according to the comparison result that the target five-tuple is consistent with the target traffic data five-tuple stored in the target database, the target user traffic is forwarded to the target analysis system; when it is determined according to the comparison result that the target five-tuple is inconsistent with the target traffic data five-tuple stored in the target database, the target user plane tunnel identifier of the target user traffic is determined; it is determined whether the target user plane tunnel identifier is consistent with the user plane tunnel identifier stored in the target database. When it is determined that the target user plane tunnel identifier is consistent with the user plane tunnel identifier stored in the target database, the target user traffic is forwarded to the target analysis system, and the target five-tuple is added to the target database. The target database can be used to screen each target user traffic, and target data for the target analysis system to analyze can be obtained, providing a basis for quickly and accurately obtaining an analysis result subsequently.
[0080] To better understand the method for screening user traffic involved in this embodiment, the following uses a specific example to describe the implementation manner of this solution:
[0081] 1) Database:
[0082] The database may include: Uplink control tunnel: at least one default bearer EBI; Uplink data tunnel: default bearer, with dedicated bearers under the default bearer; Internet access traffic five-tuple:
[0083] The database contains different data tables, an uplink control tunnel table, which stores the GW-side control tunnel of the target user (the control tunnel needs to record the default bearer id and its dedicated bearer id); an uplink data tunnel table, which creates a GW-side user plane tunnel under the control tunnel of the uplink control tunnel table; an Internet access traffic five-tuple table, which represents each Internet access process initiated by the target user under the user plane tunnel of the uplink data tunnel table with a five-tuple.
[0084] It can be understood that in this embodiment, the uplink control tunnel table stores the uplink control tunnel of the target user, the identifiers of each user plane bearer of the target user, and the uplink tunnels of each user plane bearer identifier; the uplink data tunnel table stores the uplink tunnels of the user plane bearer identifiers of the target user; the Internet access traffic five-tuple table stores the Internet access traffic five-tuples of the target user.
[0085] 2) Addition:
[0086] Specifically, the default bearer can be learned in CreateSession; check whether the mobile phone number in CreateSession is the target user; if so, learn the control tunnel on the GW side and insert it into the uplink control tunnel table (the control tunnel records its default bearer ID); learn the user plane tunnel on the GW side of the default bearer and insert it into the uplink data tunnel table; if not, do not process further; learn the dedicated bearer in Createbear (CreatBear / DeleteBear is initiated by the GW side), and cache the request / response; CreateBearReq goes through the downlink control tunnel from the GW side to the AC side and needs to be cached. Its corresponding CreateBearResp goes through the uplink control tunnel from the AC side to the GW side. Check whether this uplink control tunnel hits the uplink control tunnel table; if it hits, insert the dedicated bearer GW side user plane tunnel carried into the uplink data tunnel table. And update the uplink control tunnel table (the default bearer ID records its dedicated bearer ID); if it does not hit, do not process further.
[0087] 3) Modification:
[0088] Specifically, modify the downlink control / data tunnel in ModifyBear. Therefore, it can be ignored; the AC side tunnel is prone to change, so we record the GW side tunnel. Therefore, the uplink control tunnel table and the uplink data tunnel table only involve addition and deletion, not modification.
[0089] 4) Deletion:
[0090] Specifically, in the DeleteBear process, delete the dedicated bearer; DeleteBearReq goes through the downlink control tunnel from the GW side to the AC side and needs to be cached. Its corresponding DeleteBearResp goes through the uplink control tunnel from the AC side to the GW side. Check whether this uplink control tunnel hits the uplink control tunnel table; if it hits, delete the GW side user plane tunnel corresponding to the dedicated bearer ID carried from the uplink data tunnel table. And update the uplink control tunnel table (delete the dedicated bearer ID from the default bearer ID); if it does not hit, do not process further.
[0091] In the DeleteSession process of deleting the session, delete a single default bearer and its downstream dedicated bearers, and delete all bearers; check whether the control tunnel that DeleteSession goes through hits the uplink control tunnel table; if it hits, if it carries the default bearer ID, delete the default bearer tunnel from the uplink data tunnel table, delete the dedicated bearers hanging under the default bearer, and update the uplink control tunnel table (delete the default bearer ID and its downstream dedicated bearer IDs); if it does not carry the default bearer ID, delete this control tunnel from the uplink control tunnel table and delete all bearers of this control tunnel from the uplink data tunnel table; if it does not hit, do not process further.
[0092] 5) Filter the Internet access traffic:
[0093] Specifically, the five-tuple of the Internet access traffic can be parsed to check whether it is in the Internet access traffic five-tuple table; if so, forward the traffic to the directional analysis system; if not, parse the AC-side and GW-side user plane tunnels of the Internet access traffic. Check whether one of the two tunnels is in the uplink data tunnel table; if so, insert the five-tuple into the Internet access traffic five-tuple table; if not, do not process further.
[0094] The solution of this embodiment can filter the Internet access traffic of some 4G users from the S1U and S58-U user plane interfaces and output it to the directional traffic analysis system, reducing the traffic processing pressure of the directional analysis system.
[0095] Embodiment Three
[0096] Figure 4 It is a schematic structural diagram of a user traffic screening device provided according to Embodiment Three of the present invention. As Figure 4 shown, the device includes: a user identification acquisition module 410, a determination module 420, a database creation module 430, and a user traffic screening module 440.
[0097] Among them, the user identification acquisition module 410 is used to obtain the target user identification of the target user in response to a screening instruction for the user traffic of the target user;
[0098] The determination module 420 is used to determine the target control tunnel associated with the target user and each bearer identification belonging to the target control tunnel; the bearer identification includes a default bearer identification and a dedicated bearer identification;
[0099] The database creation module 430 is used to create a target database based on the target control tunnel, the bearer identification belonging to the target control tunnel, and the target traffic data five-tuple;
[0100] The user traffic screening module 440 is used to forward the target user traffic to the target analysis system in the case of determining that the target user traffic matches the target database in response to a screening instruction for the target user traffic.
[0101] In the solution of this embodiment, the user identification acquisition module responds to the screening instruction of the user traffic of the target user to obtain the target user identification of the target user; the determination module 420 is used to determine the target control tunnel associated with the target user and each bearer identification belonging to the target control tunnel; the bearer identification includes a default bearer identification and a dedicated bearer identification; the database creation module creates a target database based on the target control tunnel, the bearer identification belonging to the target control tunnel, and the target traffic data quintuple; the user traffic screening module responds to the screening instruction of the target user traffic, and in the case of determining that the target user traffic matches the target database, forwards the target user traffic to the target analysis system, so as to screen the traffic data generated by the LTE core network and provide a basis for improving the efficiency and accuracy of subsequent data analysis work.
[0102] In an optional implementation manner of this embodiment, the user identification acquisition module 410 is specifically configured to obtain the attachment request of the target user and / or the request for creating a specific packet data network (PDN) connection;
[0103] Based on the attachment request and / or the PDN connection request, determine the target user identification of the target user.
[0104] In an optional implementation manner of this embodiment, the determination module 420 is specifically configured to obtain the first session creation process that matches the attachment request, and determine the first uplink and downlink tunnel created in the first session creation process, and the first bearer identification;
[0105] Determine the first uplink and downlink tunnel as the target control tunnel, and determine the first bearer identification as the default bearer identification belonging to the target control tunnel;
[0106] Or,
[0107] Obtain the second session creation process that matches the PDN connection request, and determine the second uplink and downlink tunnel created in the second session creation process, and the second bearer identification;
[0108] Determine the second uplink and downlink tunnel as the target control tunnel, and determine the second bearer identification as the default bearer identification belonging to the target control tunnel;
[0109] Obtain the dedicated bearer activation process, and obtain the dedicated bearer identification associated with the default bearer identification in the dedicated bearer activation process.
[0110] In an optional implementation manner of this embodiment, the user traffic screening device further includes: an attribute information determination module, which is used for
[0111] Obtain a first deletion session procedure that matches the attachment request, or obtain a second deletion session procedure that matches the PDN connection request, or obtain a bearer deletion procedure;
[0112] Respectively obtain the attribute information of the first session creation procedure, the first deletion session procedure, the second session creation procedure, the first deletion session procedure, and the bearer deletion procedure;
[0113] Determine the creation time and deletion time of each target control tunnel according to the respective attribute information.
[0114] In an optional implementation manner of this embodiment, the database creation module 430 is specifically configured to store the target control tunnel, the default bearer identifier belonging to the target control tunnel, the dedicated bearer identifier corresponding to the default bearer identifier, the creation time and deletion time of the target control tunnel, and the target traffic data quintuple to be screened in a target area to obtain a target database;
[0115] Wherein, the target traffic data quintuple includes: source address, destination address, source port, destination port, and transport protocol.
[0116] In an optional implementation manner of this embodiment, the user traffic screening module 440 is specifically configured to analyze the target user traffic to obtain a target quintuple that matches the target user traffic;
[0117] Compare the target quintuple with the target traffic data quintuple stored in the target database to obtain a comparison result;
[0118] When it is determined according to the comparison result that the target quintuple is consistent with the target traffic data quintuple stored in the target database, forward the target user traffic to the target analysis system.
[0119] In an optional implementation manner of this embodiment, the user traffic screening module 440 is further specifically configured to, when it is determined according to the comparison result that the target quintuple is inconsistent with the target traffic data quintuple stored in the target database, determine the target user plane tunnel identifier of the target user traffic;
[0120] Determine whether the target user plane tunnel identifier is consistent with the user plane tunnel identifier stored in the target database. When it is determined that the target user plane tunnel identifier is consistent with the user plane tunnel identifier stored in the target database, forward the target user traffic to the target analysis system and add the target quintuple to the target database;
[0121] The target user plane tunnel identifier includes: an access side user plane tunnel identifier and a gateway side user plane tunnel identifier.
[0122] The user traffic screening device provided by the embodiments of the present invention can execute the user traffic screening method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.
[0123] Embodiment 4
[0124] Figure 5 FIG. shows a schematic structural diagram of an electronic device 10 that can be used to implement the embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0125] As Figure 5 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. Among them, the memory stores a computer program executable by the at least one processor. The processor 11 can execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.
[0126] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0127] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the method for screening user traffic, which includes: in response to a screening instruction for the user traffic of a target user, obtaining the target user identifier of the target user; determining a target control tunnel associated with the target user, and each bearer identifier belonging to the target control tunnel; the bearer identifier includes a default bearer identifier and a dedicated bearer identifier; creating a target database based on the target control tunnel, the bearer identifiers belonging to the target control tunnel, and a target traffic data quintuple; in response to a screening instruction for the target user traffic, when it is determined that the target user traffic matches the target database, forwarding the target user traffic to a target analysis system.
[0128] In some embodiments, the method for screening user traffic can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the method for screening user traffic described above can be executed. Alternatively, in other embodiments, the processor 11 can be configured to execute the method for screening user traffic by any other suitable means (e.g., by means of firmware).
[0129] The various embodiments of the systems and technologies described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: implemented in one or more computer programs, which can be executed and / or interpreted on a programmable system including at least one programmable processor, the programmable processor can be a dedicated or general-purpose programmable processor, and can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0130] A computer program for implementing the method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer programs are executed by the processor, the functions / operations specified in the flowchart and / or block diagram are implemented. The computer programs can be executed entirely on the machine, partially on the machine, executed partially on the machine and partially on a remote machine as an independent software package, or executed entirely on a remote machine or server.
[0131] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0132] In order to provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0133] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
[0134] A computing system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs that run on respective computers and have a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0135] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.
[0136] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for screening user traffic, characterized in that: include: In response to a filter instruction for user traffic of a target user, obtaining a target user identifier of the target user; Determine a target control tunnel associated with the target user and each bearer identifier belonging to the target control tunnel; the bearer identifier includes a default bearer identifier and a dedicated bearer identifier; Creating a target database based on the target control tunnel, a bearer identifier belonging to the target control tunnel, and a target traffic data quintuple; In response to a screening instruction of target user traffic, if it is determined that the target user traffic matches the target database, forwarding the target user traffic to a target analysis system; The target traffic data quintuple includes: source address, destination address, source port, destination port and transmission protocol.
2. The method for screening user traffic according to claim 1, characterized in that: The step of obtaining the target user identifier of the target user includes: Obtaining an attachment request of the target user and / or a request to create a specific packet data network (PDN) connection; A target user identifier of the target user is determined based on the attach request and / or the PDN connection request.
3. The method for screening user traffic according to claim 2, characterized in that: The determining of the target control tunnel associated with the target user and the bearer identifiers belonging to the target control tunnel includes: Obtaining a first session creation process that matches the attach request, and determining a first uplink and downlink tunnel created in the first session creation process, and a first bearer identifier; Determine the first uplink and downlink tunnel as a target control tunnel, and determine the first bearer identifier as a default bearer identifier belonging to the target control tunnel; or, Obtain a second session creation process that matches the PDN connection request, and determine a second uplink and downlink tunnel created in the second session creation process, and a second bearer identifier; Determine the second uplink and downlink tunnel as a target control tunnel, and determine the second bearer identifier as a default bearer identifier belonging to the target control tunnel; A dedicated bearer activation process is obtained, and a dedicated bearer identifier associated with the default bearer identifier in the dedicated bearer activation process is obtained.
4. The method for screening user traffic according to claim 3, characterized in that: The method further comprises: Acquire a first session deletion process that matches the attach request, or acquire a second session deletion process that matches the PDN connection request, or acquire a bearer deletion process; Respectively obtain attribute information of the first create session process, the first delete session process, the second create session process, the first delete session process, and the attribute information of the bearer delete process; The creation time and deletion time of each target control tunnel are determined according to each attribute information.
5. The method for screening user traffic according to claim 4, characterized in that: The creating a target database based on the target control tunnel, the bearer identifier belonging to the target control tunnel, and the target traffic data quintuple includes: The target control tunnel, the default bearer identifier belonging to the target control tunnel, the dedicated bearer identifier corresponding to the default bearer identifier, the creation time and deletion time of the target control tunnel, and the target traffic data quintuple to be filtered are stored in the target area to obtain a target database.
6. The method for screening user traffic according to claim 1, characterized in that: The step of responding to the target user traffic screening instruction and forwarding the target user traffic to a target analysis system when it is determined that the target user traffic matches the target database includes: Parsing the target user traffic to obtain a target five-tuple matching the target user traffic; Comparing the target quintuple with the target traffic data quintuple stored in the target database to obtain a comparison result; When it is determined according to the comparison result that the target quintuple is consistent with the target traffic data quintuple stored in the target database, the target user traffic is forwarded to the target analysis system.
7. The method for screening user traffic according to claim 6, characterized in that: The method further comprises: If it is determined according to the comparison result that the target quintuple is inconsistent with the target traffic data quintuple stored in the target database, determining a target user plane tunnel identifier for the target user traffic; determining whether the target user plane tunnel identifier is consistent with the user plane tunnel identifier stored in the target database; if it is determined that the target user plane tunnel identifier is consistent with the user plane tunnel identifier stored in the target database, forwarding the target user traffic to a target analysis system and adding the target quintuple to the target database; The target user plane tunnel identifier includes: an access side user plane tunnel identifier and a gateway side user plane tunnel identifier.
8. A user traffic screening device, characterized in that: include: A user identification acquisition module, configured to acquire a target user identification of a target user in response to a filter instruction for user traffic of the target user; a determination module, configured to determine a target control tunnel associated with the target user and each bearer identifier belonging to the target control tunnel; the bearer identifiers include a default bearer identifier and a dedicated bearer identifier; A database creation module, configured to create a target database based on the target control tunnel, a bearer identifier belonging to the target control tunnel, and a target traffic data quintuple; A user traffic screening module is configured to respond to a screening instruction of target user traffic and forward the target user traffic to a target analysis system if it is determined that the target user traffic matches the target database; The target traffic data quintuple includes: source address, destination address, source port, destination port and transmission protocol.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor. The computer program is executed by the at least one processor to enable the at least one processor to perform the user traffic screening method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the user traffic screening method according to any one of claims 1 to 7 when executed.
Citation Information
Patent Citations
Core network data collection system, method and apparatus, and terminal device
CN109688633A