Method and system for acquiring and transmitting mirror data, medium, and computer equipment
Through the combination of mirror data acquisition device, SDN and default routing system, the problems of latency and security risks of existing tools in high-traffic network environments are solved, and the flexible, secure and efficient transmission of mirror data is achieved and the adaptation to complex network environments is achieved.
Patent Information
- Application Number
- CN202510198789.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2045-02-24
AI Technical Summary
Existing mirror data acquisition and transmission tools have problems such as latency, security risks, high operational complexity, and insufficient flexibility in high traffic network environments, especially in complex network environments, which are difficult to achieve flexible data transmission and management.
Through the combination of mirror data acquisition device, SDN and default routing system, one-way transmission and dynamic routing of mirror data are realized, ensuring the security and integrity of data frames, and improving the timeliness and flexibility of data transmission through automated processes.
Without affecting the stability of the original network, flexible acquisition and transmission of mirrored data is achieved, the security, timeliness and efficiency of data resources are improved, and the operation process is simplified.
Smart Images

Figure CN119696929B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of data transmission, and in particular to a method and system, medium, and computer equipment for acquiring and transmitting mirror data. Background Art
[0002] With the rapid development of information technology, the volume of data transmission is experiencing explosive growth, and network applications are becoming increasingly diverse. Against this backdrop, network monitoring, performance optimization, and security auditing have become increasingly important. The acquisition and analysis of mirror data, a copy of data transmitted along a non-primary path, are essential in several key areas. Mirror data is the cornerstone for a deep understanding of network behavior and is crucial for troubleshooting network problems, monitoring bandwidth usage, and evaluating network performance. In network security, the capture and analysis of mirror data is a key means of detecting and defending against network attacks and intrusions. By deeply analyzing network traffic using mirror data, potential security threats can be promptly identified and appropriate measures taken. Furthermore, for sensitive industries such as finance and healthcare, mirror data can help ensure data transmission compliance and meet strict regulatory requirements.
[0003] Currently, the acquisition and transmission of mirrored data primarily relies on specialized network analysis tools such as Wireshark and tcpdump. However, after capturing packets, Wireshark needs to send the data to a local or remote interface for display and analysis. This process can cause delays in high-traffic network environments. When packets are sent locally, they are often temporarily stored locally, significantly increasing the risk of data leakage. Furthermore, this tool primarily focuses on packet analysis and display, lacking sufficient flexibility for data transmission and management in complex network environments. tcpdump, on the other hand, relies on command-line operations, making it difficult for non-technical users to use. Furthermore, this tool primarily focuses on packet capture and filtering, but has limitations in data transmission flexibility and receiver control. Furthermore, both of these tools can easily compromise the security and stability of the data source network. Summary of the Invention
[0004] In view of this, the present application provides a method and system for acquiring and transmitting mirror data, a storage medium, and a computer device. Through the mirror data acquisition device, the one-way transmission of the first data frame of the mirror is guaranteed, reverse attacks or data tampering are prevented, and security is improved; through SDN, real-time transmission of data resources can be achieved, which improves the timeliness and efficiency of data resource transmission; through the default routing system, the original data details can be ensured to be complete and unchanged, thereby ensuring the integrity of data resources. In addition, the embodiment of the present application does not need to store the first data frame of the mirror locally, further ensuring data security; SDN dynamically determines the target default routing system from multiple default routing systems through the first data frame information, which can improve the flexibility of data transmission and management. In addition, the entire process has a high degree of automation and is easy to operate, which is conducive to improving the user experience of non-technical users. The entire process not only protects the security and stability of the original network, but also realizes the flexible acquisition and transmission of data resources, thereby promoting the effective use and monitoring of data resources.
[0005] According to one aspect of the present application, a method for acquiring and transmitting mirrored data is provided, comprising:
[0006] The mirror data acquisition device acquires the first data frame when the first data frame passes through the deployment point of the mirror data acquisition device, and unidirectionally transmits the acquired first data frame to the SDN;
[0007] The SDN determines a target default routing system from a plurality of default routing systems based on the first data frame information, re-encapsulates the target default routing system to obtain a second data frame, and forwards the second data frame to the target default routing system;
[0008] The target default routing system decapsulates the second data frame to obtain a data packet based on the corresponding preset default route, and forwards the data packet to the target device or network, so that the target device or network performs a corresponding task based on the data packet.
[0009] According to another aspect of the present application, a system for acquiring and transmitting mirrored data is provided, comprising:
[0010] A mirror data acquisition device, configured to acquire the first data frame when the first data frame passes through a deployment point of the mirror data acquisition device, and unidirectionally transmit the acquired first data frame to the SDN;
[0011] The SDN is configured to determine a target default routing system from a plurality of default routing systems based on the first data frame information, re-encapsulate the second data frame according to the target default routing system, and forward the second data frame to the target default routing system;
[0012] The target default routing system is used to decapsulate the second data frame to obtain a data packet based on the corresponding preset default route, and forward the data packet to the target device or network, so that the target device or network performs a corresponding task based on the data packet.
[0013] According to another aspect of the present application, a storage medium is provided, on which a computer program is stored. When the program is executed by a processor, the above-mentioned method for acquiring and transmitting mirror data is implemented.
[0014] According to another aspect of the present application, a computer device is provided, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor implements the above-mentioned method for acquiring and transmitting mirror data when executing the program.
[0015] By means of the above-described technical solution, the present application provides a method and system for acquiring and transmitting mirrored data, a storage medium, and a computer device. When a first data frame passes through a mirrored data acquisition device, the mirrored data acquisition device can mirror the first data frame. The mirrored first data frame is then sent to the SDN via the mirrored data acquisition device's unidirectional transmission channel. Furthermore, the SDN selects the most appropriate default routing system from a plurality of preconfigured default routing systems as the target default routing system based on the first data frame information in the first data frame. The SDN can also re-encapsulate the first data frame according to the relevant information in the target default routing system, thereby obtaining a second data frame, and send the second data frame to the target default routing system. After receiving the second data frame, the target default routing system decapsulates the second data frame to restore the original data packet, and then forwards the original data packet to the target device or network according to the preset default route corresponding to the target default routing system. The embodiments of the present application utilize the mirrored data acquisition device, SDN, and default routing system to ensure that data packets on the original transmission link can be acquired and transmitted to the target device or network without affecting the original network traffic. The embodiment of the present application ensures the one-way transmission of the mirrored first data frame through the mirror data acquisition device, prevents reverse attacks or data tampering, and improves security; through SDN, real-time transmission of data resources can be achieved, improving the timeliness and efficiency of data resource transmission; through the default routing system, the original data details can be ensured to be complete and unchanged, thereby ensuring the integrity of data resources. In addition, the embodiment of the present application does not need to store the mirrored first data frame locally, further ensuring data security; SDN dynamically determines the target default routing system from multiple default routing systems through the first data frame information, which can improve the flexibility of data transmission and management. In addition, the entire process has a high degree of automation and is easy to operate, which is conducive to improving the user experience of non-technical users. The entire process not only protects the security and stability of the original network, but also realizes the flexible acquisition and transmission of data resources, thereby promoting the effective use and monitoring of data resources.
[0016] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0018] Figure 1A schematic diagram of a process for acquiring and transmitting mirrored data provided in an embodiment of the present application is shown;
[0019] Figure 2 A schematic diagram showing a flow chart of another method for acquiring and transmitting mirrored data provided in an embodiment of the present application is shown;
[0020] Figure 3 A schematic diagram showing a connection relationship of a data diode provided in an embodiment of the present application is shown;
[0021] Figure 4 A schematic diagram showing a flow chart of another method for acquiring and transmitting mirrored data provided in an embodiment of the present application is shown;
[0022] Figure 5 A schematic diagram of the structure of a preset forwarding mode determination model provided in an embodiment of the present application is shown;
[0023] Figure 6 A schematic diagram of a default routing system provided in an embodiment of the present application is shown;
[0024] Figure 7 A schematic diagram of the structure of a system for acquiring and transmitting mirrored data provided in an embodiment of the present application is shown;
[0025] Figure 8 A schematic diagram of the device structure of a computer device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0026] The present application will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that, unless there is a conflict, the embodiments and features in the embodiments of the present application can be combined with each other.
[0027] In this embodiment, a method for acquiring and transmitting mirrored data is provided. Figure 1 As shown, the method includes:
[0028] Step 101 : When a first data frame passes through a deployment point of the mirror data acquisition device, the mirror data acquisition device acquires the first data frame and unidirectionally transmits the acquired first data frame to the SDN.
[0029] An embodiment of the present application provides a method for acquiring and transmitting mirror data, which is implemented by a mirror data acquisition device, an SDN (Software Defined Networking) and a default routing system. Specifically, the mirror data acquisition device can be deployed in advance in the original transmission link of the data to be monitored. When the first data frame passes through the mirror data acquisition device, the mirror data acquisition device can mirror the first data frame, while the original first data frame passing through the mirror data acquisition device continues to be transmitted normally without affecting the original network traffic. Then, the mirrored first data frame is sent to the SDN through the unidirectional transmission channel of the mirror data acquisition device. Here, the unidirectional transmission can ensure that the acquired first data frame can only flow from the mirror data acquisition device to the SDN, preventing reverse attacks or data tampering, and improving security.
[0030] In step 102, the SDN determines a target default routing system from multiple default routing systems based on the first data frame information, re-encapsulates the target default routing system to obtain a second data frame, and forwards the second data frame to the target default routing system.
[0031] After the SDN receives the first data frame, the SDN further selects the most appropriate default routing system from the pre-configured multiple default routing systems as the target default routing system based on the first data frame information in the first data frame. Specifically, based on the first data frame information, the SDN can know the target device or network corresponding to the mirrored first data frame, and then select the target default routing system whose final target address is the target device or network. Afterwards, the SDN can also re-encapsulate the first data frame according to the relevant information in the target default routing system, and after encapsulation, a second data frame can be obtained, and the second data frame can be sent to the target default routing system. Here, re-encapsulation can include modifying the header information of the first data frame, etc., so that the target address of the second data frame points to the target default routing system.
[0032] In step 103 , the target default routing system decapsulates the second data frame based on the corresponding preset default route to obtain a data packet, and forwards the data packet to the target device or network, so that the target device or network performs a corresponding task based on the data packet.
[0033] After receiving the second data frame, the target default routing system decapsulates the second data frame to restore the original data packet. It then forwards the original data packet to the target device or network according to the default route configured for the target default routing system. Upon receiving the original data packet, the target device or network can then perform tasks based on the data packet. These tasks can include security monitoring tasks (traffic analysis using an intrusion detection system (IDS)) or network diagnostic tasks (communication session reconstruction using a packet capture tool). For example, the target device can be a data monitoring terminal or a data analysis terminal. Upon receiving the data packet, it can perform data monitoring or analysis tasks. The network can be the same network as the device that ultimately performs the task.
[0034] By applying the technical solution of this embodiment, when the first data frame passes through the mirror data acquisition device, the mirror data acquisition device can mirror the first data frame, and then the mirrored first data frame is sent to the SDN through the unidirectional transmission channel of the mirror data acquisition device. Furthermore, the SDN selects the most suitable default routing system from the pre-configured multiple default routing systems as the target default routing system based on the first data frame information in the first data frame. The SDN can also re-encapsulate the first data frame according to the relevant information in the target default routing system, and obtain the second data frame after encapsulation, and send the second data frame to the target default routing system. After receiving the second data frame, the target default routing system decapsulates the second data frame to restore the original data packet, and then forwards the original data packet to the target device or network according to the preset default route corresponding to the target default routing system. Under the premise of not affecting the original network traffic, the embodiment of the present application utilizes the mirror data acquisition device, SDN and the default routing system to ensure that the data packet on the original transmission link can be acquired and transmitted to the target device or network. The embodiment of the present application ensures the one-way transmission of the mirrored first data frame through the mirror data acquisition device, prevents reverse attacks or data tampering, and improves security; through SDN, real-time transmission of data resources can be achieved, improving the timeliness and efficiency of data resource transmission; through the default routing system, the original data details can be ensured to be complete and unchanged, thereby ensuring the integrity of data resources. In addition, the embodiment of the present application does not need to store the mirrored first data frame locally, further ensuring data security; SDN dynamically determines the target default routing system from multiple default routing systems through the first data frame information, which can improve the flexibility of data transmission and management. In addition, the entire process has a high degree of automation and is easy to operate, which is conducive to improving the user experience of non-technical users. The entire process not only protects the security and stability of the original network, but also realizes the flexible acquisition and transmission of data resources, thereby promoting the effective use and monitoring of data resources.
[0035] Furthermore, as a refinement and extension of the specific implementation of the above embodiment, in order to fully illustrate the specific implementation process of this embodiment, another method for obtaining and transmitting mirror data is provided, such as Figure 2 As shown, the method includes:
[0036] Step 201 : When a first data frame passes through a deployment point of the mirrored data acquisition device, the mirrored data acquisition device acquires the first data frame and unidirectionally transmits the acquired first data frame to the SDN.
[0037] In this embodiment, the mirror data acquisition device can be a data diode. The data input end of the data diode is connected to the original transmission link of the first data frame, and the data output end of the data diode is connected to the SDN. Figure 3 As shown, the connection relationship of a data diode in an embodiment of the present application is shown.
[0038] In step 202, the SDN determines the MAC address of the data receiver of the first data frame according to the first data frame information, and determines a first routing device having the same MAC address as the data receiver from a plurality of routing devices with defined MAC addresses included in the SDN.
[0039] In this embodiment, the SDN may include multiple routing devices (e.g., routers, Ethernet switches that also function as routers, virtual routing devices, etc.). These routing devices have defined MAC addresses. The MAC addresses of these routing devices can be pre-determined based on statistics. For example, statistics can be pre-determined on the data to be monitored and acquired. The data recipients corresponding to these data can then be determined. The MAC addresses of these data recipients can then be used to define the MAC addresses of the routing devices in the SDN. Furthermore, a corresponding default routing hierarchy can be pre-configured for each routing device with a defined MAC address. Each default routing hierarchy contains pre-defined data forwarding paths and rules. Each default routing hierarchy can correspond to a final destination device or network.
[0040] After receiving the first data frame, the SDN can search for a matching routing device in its internally maintained MAC address-to-routing device mapping table based on the destination MAC address (i.e., the data receiver's MAC address) in the first data frame. This mapping table is created during the SDN initialization or configuration process and records the routing device information corresponding to each MAC address.
[0041] Step 203: When there is a first routing device with the same MAC address as the data recipient among the multiple routing devices with defined MAC addresses, the default routing system corresponding to the first routing device is used as the target default routing system, and the first data frame is re-encapsulated according to the address of the target default routing system to obtain a second data frame, and the second data frame is forwarded to the target default routing system through the first routing device.
[0042] In this embodiment, if a first routing device matching the destination MAC address is found, the SDN may determine the default routing hierarchy to which this first routing device belongs as the target default routing hierarchy. After determining the target default routing hierarchy, the SDN re-encapsulates the first data frame according to the address of this target default routing hierarchy to generate a second data frame. This re-encapsulation process may include operations such as modifying existing header information to indicate the forwarding destination of the re-encapsulated second data frame to the first routing device. After re-encapsulation is complete, the SDN forwards the second data frame to the target default routing hierarchy via the previously determined first routing device.
[0043] Step 204: When there is no first routing device with the same MAC address as the data receiver among the multiple routing devices with defined MAC addresses, determine a second routing device in an idle state from the multiple routing devices with defined MAC addresses included in the SDN; when there is a second routing device in an idle state among the multiple routing devices with defined MAC addresses, change the defined MAC address corresponding to the second routing device to the MAC address of the data receiver, and configure the default routing system corresponding to the first data frame according to the second routing device and the MAC address and IP address corresponding to the target device or network, use the newly configured default routing system as the target default routing system corresponding to the second routing device, and according to the address of the target default routing system The first data frame is re-encapsulated to obtain a second data frame, and the second data frame is forwarded to the corresponding target default routing system through the second routing device; when there is no second routing device in an idle state among the multiple routing devices with defined MAC addresses, a third routing device is created based on the MAC address of the data recipient, and the default routing system corresponding to the first data frame is configured according to the third routing device and the MAC address and IP address corresponding to the target device or network, the newly configured default routing system is used as the target default routing system corresponding to the third routing device, and the first data frame is re-encapsulated to obtain a second data frame according to the address of the target default routing system, and the second data frame is forwarded to the corresponding target default routing system through the third routing device.
[0044] In this embodiment, due to statistical omissions or the temporary addition of new data recipients when pre-defining MAC addresses for routing devices, the currently defined MAC addresses may not fully cover all situations. Therefore, it is possible that the currently defined MAC addresses do not include the MAC address of the data recipient corresponding to the first data frame. In this case, the SDN can check its internally maintained routing device status information to determine whether a second routing device is in an idle state. In this context, the idle state generally refers to the routing device not currently processing any data forwarding tasks or its processing capacity has not yet reached saturation. This can be determined through indicators such as traffic monitoring and CPU / memory utilization.
[0045] If the SDN discovers that there is an idle second routing device after inspection, the SDN can change the defined MAC address corresponding to the second routing device to the MAC address of the data recipient of the first data frame. After the modification, the routing device will be responsible for processing all data frames sent to the MAC address of the data recipient corresponding to the first data frame. Next, the SDN configures the default routing system corresponding to the first data frame based on the MAC address and IP address of the target device or network, as well as the information of the second routing device, so that the configured default routing system can successfully forward data resources from the second routing device to the target device or network. After configuring the new default routing system, the SDN re-encapsulates the first data frame according to the address of the newly configured default routing system, generates a second data frame, and forwards the second data frame to the corresponding target default routing system (that is, the new default routing system configured for the second routing device) through the second routing device.
[0046] If the SDN finds that there is no idle second routing device after checking, the SDN can create a new third routing device based on the MAC address of the data recipient of the first data frame. This new device can be a physical device or a virtual device, depending on the implementation and configuration of the SDN. Subsequently, the SDN configures the default routing system corresponding to the first data frame based on the MAC address and IP address of the target device or network, as well as the information of the third routing device. After configuring the new default routing system, the SDN re-encapsulates the first data frame according to the address of the newly configured default routing system, generates a second data frame, and forwards the second data frame to the corresponding target default routing system (that is, the new default routing system configured for the third routing device) through the third routing device.
[0047] When the defined MAC address does not contain the MAC address of the data recipient of the first data frame, the embodiment of the present application automatically determines a new routing device and a default routing system corresponding to the new routing device. This can adapt well to dynamic network environments, does not require manual intervention, and has good automation performance. When determining a new routing device, it prioritizes the reuse of idle devices, which can improve the utilization rate of existing routing devices. When no idle devices exist, it supports the creation of new routing devices, further improving the scalability of SDN. Through the centralized control capabilities of SDN, the embodiment of the present application realizes the dynamic allocation and intelligent management of routing resources, solving the problems of resource waste and lack of flexibility caused by fixed routing configurations in traditional networks.
[0048] In step 205 , the target default routing system decapsulates the second data frame based on the corresponding preset default route to obtain a data packet, and forwards the data packet to the target device or network, so that the target device or network performs a corresponding task based on the data packet.
[0049] Furthermore, as a refinement and extension of the specific implementation of the above embodiment, in order to fully illustrate the specific implementation process of this embodiment, another method for obtaining and transmitting mirror data is provided, such as Figure 4 As shown, the method includes:
[0050] Step 301 : When a first data frame passes through a deployment point of the mirrored data acquisition device, the mirrored data acquisition device acquires the first data frame and unidirectionally transmits the acquired first data frame to the SDN.
[0051] In step 302 , the SDN parses the received first data frame, determines header information corresponding to the first data frame, and inputs the header information into a preset forwarding mode determination model.
[0052] In step 303, the preset forwarding mode determination model extracts the target features corresponding to the header information through the feature extraction layer, and outputs the probability value corresponding to each preset forwarding mode based on the target features through the result output layer, and uses the preset forwarding mode with the largest probability value as the target forwarding mode for the SDN to forward the second data frame to the target default routing system, wherein the preset forwarding mode includes a routing forwarding mode and a flow table forwarding mode.
[0053] In this embodiment, in the SDN architecture, the control plane of the network is separated from the data forwarding plane. This separation makes the control and management of the network more flexible and programmable. However, faced with complex network environments and changing traffic demands, how to efficiently select the data forwarding path becomes a challenge. The embodiment of the present application can quickly determine the forwarding method suitable for each first data frame by setting a preset forwarding method determination model in the SDN. The preset forwarding method determination model can be constructed based on machine learning and is used to predict the optimal forwarding method based on the header information of the data frame. Specifically, it can include a feature extraction layer and a result output layer.
[0054] Specifically, after receiving the first data frame, the SDN can parse it to extract its header information. The data frame header typically contains important information such as the source address, destination address, and protocol type, which is crucial for subsequently determining the forwarding path. After extracting the header information, the SDN inputs it into a pre-set forwarding mode determination model. The pre-set forwarding mode determination model first uses its feature extraction layer to extract features related to the target forwarding mode from the header information. These features may include specific patterns in the source and destination addresses, protocol type, packet size, and traffic type (such as video or text). The extracted target features are then input into the result output layer, which calculates the probability corresponding to each pre-set forwarding mode based on the target features extracted by the feature extraction layer. Pre-set forwarding modes include routing forwarding and flow table forwarding. Routing forwarding refers to forwarding data frames according to the default routing hierarchy, while flow table forwarding refers to forwarding data frames according to the SDN's internal flow table (a table of match-action rules). Different forwarding methods have different advantages in different situations. By presetting the forwarding method to determine the model, the optimal forwarding method can be selected according to the real-time situation.
[0055] After the output layer calculates the probability of each forwarding method, the SDN selects the forwarding method with the highest probability as the target forwarding method. This means the model believes this forwarding method is most likely to meet current network conditions and traffic requirements. Once the target forwarding method is determined, the SDN applies it to the forwarding decision for the second data frame. This enables SDN to manage network traffic in a dynamic and intelligent manner.
[0056] The embodiment of the present application introduces a machine learning model to enable the SDN to intelligently select a forwarding method based on the header information of the first data frame. This method not only improves the efficiency of network forwarding, but also enhances the flexibility and adaptability of the network.
[0057] In addition, the preset forwarding mode determination model may also include a feature acquisition layer, such as Figure 5 As shown in the figure, the feature acquisition layer is triggered by the feature extraction layer. When the feature extraction layer receives the header information, it begins to acquire contextual features. Contextual features can include current link utilization, historical flow table hit rates, controller load status, and other features. After the feature extraction layer extracts features from the header information, the result output layer concatenates the features from the feature extraction and acquisition layers and then calculates the probability value corresponding to each preset forwarding method based on the concatenated results.
[0058] In step 304, the SDN determines a target default routing system from multiple default routing systems based on the first data frame information, re-encapsulates the target default routing system to obtain a second data frame, and forwards the second data frame to the target default routing system.
[0059] In step 305 , the target default routing system decapsulates the second data frame to obtain a data packet based on the corresponding preset default route, and forwards the data packet to the target device or network, so that the target device or network performs a corresponding task based on the data packet.
[0060] In an embodiment of the present application, optionally, when the target forwarding mode is a flow table forwarding mode, step 304 includes: the network device in the SDN searches for a target flow table corresponding to the header information from the flow table pre-issued by the SDN controller based on the header information of the first data frame, modifies the address in the header information according to the matching item in the target flow table, and re-encapsulates it to obtain a second data frame, and forwards the second data frame to the target default routing system corresponding to the forwarding strategy according to the forwarding strategy indicated by the target flow table matching item.
[0061] In this embodiment, the SDN may include network devices, an SDN controller, and flow tables pre-delivered by the SDN controller. Flow tables are a key component of the SDN, defining how data flows passing through the network devices are processed. When a first data frame enters a pre-configured network device (such as a switch or router) in the SDN, the network device processes the first data frame. Specifically, the network device first parses the header information of the first data frame. The data frame header contains various metadata, such as the source address, destination address, and protocol type. Then, based on the header information of the first data frame, the network device searches the flow tables pre-delivered by the SDN controller for a target flow table that matches the header information. Target flow tables are flow table entries whose matching entries match the data frame header information. Once the target flow table is found, the network device modifies the address in the data frame header information based on the matching entries in the target flow table, resulting in a second data frame. This re-encapsulation process ensures that the data frame is correctly forwarded according to the new routing policy.
[0062] The target flow table not only contains items for matching data frames, but also contains policies indicating how to forward the matched data streams. Next, the network device determines the target default routing system for the second data frame based on the forwarding policy indicated by the target flow table matching item, and forwards the second data frame to the specified target default routing system based on the forwarding policy. The embodiment of the present application utilizes the centralized control and dynamic routing selection capabilities of SDN, and achieves flexible forwarding of data frames through flow table matching and header information modification, which not only improves the flexibility and programmability of the network, but also enhances the performance and security of the network.
[0063] In addition, when the target forwarding mode is a routing forwarding mode, step 304 includes: the SDN determines the MAC address of the data recipient of the first data frame based on the first data frame information, determines a first routing device with the same MAC address as the data recipient from multiple routing devices with defined MAC addresses contained in the SDN, uses the default routing system corresponding to the first routing device as the target default routing system, and re-encapsulates the first data frame according to the address of the target default routing system to obtain a second data frame, and forwards the second data frame to the target default routing system through the first routing device.
[0064] In an embodiment of the present application, optionally, before the step of "obtaining the first data frame" in step 301, the method further includes: if the MAC address of the data recipient of the first data frame obtained by the mirrored data acquisition device is known, creating a fourth routing device based on the known MAC address, and configuring a default routing system corresponding to the first data frame according to the fourth routing device and the MAC address and IP address corresponding to the target device or network, and using the configured default routing system as the target default routing system corresponding to the fourth routing device; accordingly, after the step of "obtaining the first data frame" in step 301, the method further includes: the mirrored data acquisition device unidirectionally transmitting the acquired first data frame to the fourth routing device; the fourth routing device re-encapsulating the first data frame according to the address of the target default routing system to obtain a second data frame, and sending the second data frame to the corresponding target default routing system; the target default routing system decapsulating the second data frame based on the corresponding preset default route to obtain a data packet, and forwarding the data packet to the target device or network, so that the target device or network performs a corresponding task based on the data packet.
[0065] In this embodiment, if the MAC address of the data recipient of the first data frame obtained by the mirror data acquisition device on the deployed link is known and fixed, then a routing device can be directly constructed in advance based on the known and fixed MAC address, which can be referred to as the fourth routing device. Subsequently, based on the MAC address and IP address of the target device or network, as well as the information of the fourth routing device, the default routing system corresponding to the first data frame is configured, and the newly configured default routing system can be used as the target default routing system corresponding to the fourth routing device. In this way, after the mirror data acquisition device obtains the first data frame, the data frame can be forwarded directly through the fourth routing device without setting up an SDN for it, further reducing the complexity of forwarding the data frame and reducing deployment costs.
[0066] Furthermore, after the mirrored data acquisition device acquires the first data frame, it can unidirectionally transmit the first data frame to a fourth routing device. Upon receiving the first data frame, the fourth routing device re-encapsulates the first data frame according to the address of the target default routing system, generating a second data frame, and forwards the second data frame to the corresponding target default routing system (i.e., the new default routing system configured for the fourth routing device). Upon receiving the second data frame, the target default routing system decapsulates the second data frame to restore the original data packet and then forwards the original data packet to the target device or network according to the preset default route corresponding to the target default routing system. Consequently, when the target device or network receives the original data packet, it can execute a corresponding task based on the data packet.
[0067] It should be noted that the mirror data acquisition device deployed on different links can choose whether to configure SDN for it according to whether the mac address of the data recipient of the first data frame acquired by the mirror data acquisition device is known or unknown. When the mac address of the data recipient of the first data frame is unknown, by configuring SDN for it, the SDN can further determine the target default routing system from multiple default routing systems, thereby accurately determining the transmission direction of the first data frame; and when the mac address of the data recipient of the first data frame is known, the SDN is omitted and directly transmitted by the pre-configured fourth routing device, which can save deployment costs and reduce the complexity of data frame forwarding. The embodiment of the present application determines the data frame transmission method according to actual conditions, which greatly improves the flexibility of mirror data transmission.
[0068] In an embodiment of the present application, optionally, each of the default routing systems includes at least one default router, and each default router is configured with a preset default route; when the target default routing system includes multiple default routers, step 305 includes: the first default router in the target default routing system decapsulates the second data frame to obtain a data packet, and forwards the data packet to an adjacent default router based on the corresponding preset default route; each of the remaining default routers in the target default routing system forwards the data packet in sequence according to its corresponding preset default route, so as to forward the data packet to the target device or network.
[0069] In this embodiment, there may be one or more default routers in each default routing system. Each default router is configured with a preset default route, which is used to guide the transmission path of data packets in the network. The schematic diagram of the default routing system can be as follows: Figure 6 When the target default routing system contains multiple default routers, the data packet (here specifically the data packet obtained after decapsulation of the second data frame) is processed as follows:
[0070] a. Processing of the first default router in the target default routing hierarchy:
[0071] After receiving the second data frame, it decapsulates it and restores it to the original data packet. After decapsulation, it forwards the data packet to the adjacent default router according to its pre-configured default route. The "adjacent" here refers to the next-hop router that matches the packet's destination address in the routing table.
[0072] b. Processing of other default routers in the target default routing system:
[0073] Each subsequent default router that receives a data packet determines the next-hop transmission path based on its own configured preset default route and forwards the data packet to the next adjacent default router until the data packet reaches the destination device or network.
[0074] The target default routing system of the embodiment of the present application ensures the integrity of data packets (the details of the original data packets are complete and unchanged) through the collaborative work of multiple default routers and preset default routes, thereby achieving efficient and reliable transmission of data packets in the network.
[0075] Further, as Figure 1 The specific implementation of the method, the embodiment of the present application provides a system for obtaining and transmitting mirror data, such as Figure 7 As shown, the system includes:
[0076] A mirror data acquisition device, configured to acquire the first data frame when the first data frame passes through a deployment point of the mirror data acquisition device, and unidirectionally transmit the acquired first data frame to the SDN;
[0077] The SDN is configured to determine a target default routing system from a plurality of default routing systems based on the first data frame information, re-encapsulate the second data frame according to the target default routing system, and forward the second data frame to the target default routing system;
[0078] The target default routing system is used to decapsulate the second data frame to obtain a data packet based on the corresponding preset default route, and forward the data packet to the target device or network, so that the target device or network performs a corresponding task based on the data packet.
[0079] Optionally, the mirror data acquisition device is a data diode, a data input end of the data diode is connected to the original transmission link of the first data frame, and a data output end of the data diode is connected to the SDN.
[0080] Optionally, the SDN is used to:
[0081] Determine the MAC address of the data recipient of the first data frame based on the first data frame information, determine a first routing device with the same MAC address as the data recipient from multiple routing devices with defined MAC addresses included in the SDN, use the default routing system corresponding to the first routing device as the target default routing system, re-encapsulate the first data frame according to the address of the target default routing system to obtain a second data frame, and forward the second data frame to the target default routing system through the first routing device.
[0082] Optionally, when there is no first routing device having the same MAC address as the data receiver among the multiple routing devices with defined MAC addresses, the SDN is further configured to:
[0083] Determining a second routing device in an idle state from a plurality of routing devices with defined MAC addresses included in the SDN;
[0084] When there is a second routing device in an idle state among the multiple routing devices with defined MAC addresses, the defined MAC address corresponding to the second routing device is changed to the MAC address of the data receiver, and according to the second routing device and the MAC address and IP address corresponding to the target device or network, a default routing system corresponding to the first data frame is configured, the newly configured default routing system is used as the target default routing system corresponding to the second routing device, and the first data frame is re-encapsulated according to the address of the target default routing system to obtain a second data frame, and the second data frame is forwarded to the corresponding target default routing system through the second routing device;
[0085] When there is no idle second routing device among the multiple routing devices with defined MAC addresses, a third routing device is created based on the MAC address of the data recipient, and a default routing system corresponding to the first data frame is configured according to the third routing device and the MAC address and IP address corresponding to the target device or network, and the newly configured default routing system is used as the target default routing system corresponding to the third routing device. The first data frame is re-encapsulated according to the address of the target default routing system to obtain a second data frame, and the second data frame is forwarded to the corresponding target default routing system through the third routing device.
[0086] Optionally, the SDN is used to:
[0087] The network device in the SDN searches, based on the header information of the first data frame, a target flow table corresponding to the header information from a flow table pre-issued by the SDN controller, modifies the address in the header information according to a matching item in the target flow table, and re-encapsulates the second data frame, and forwards the second data frame to a target default routing system corresponding to the forwarding strategy according to a forwarding strategy indicated by the matching item in the target flow table.
[0088] Optionally, the SDN is further used to:
[0089] Before determining a target default routing system from a plurality of default routing systems based on the first data frame information, parsing the received first data frame to determine header information corresponding to the first data frame, and inputting the header information into a preset forwarding mode determination model;
[0090] The preset forwarding mode determination model extracts the target features corresponding to the header information through a feature extraction layer, and outputs the probability value corresponding to each preset forwarding mode based on the target features through a result output layer, and uses the preset forwarding mode with the largest probability value as the target forwarding mode for the SDN to forward the second data frame to the target default routing system, wherein the preset forwarding mode includes a routing forwarding mode and a flow table forwarding mode.
[0091] Optionally, the system further includes a routing device configuration device; the routing device configuration device is configured to:
[0092] Before acquiring the first data frame, if the MAC address of the data recipient of the first data frame acquired by the mirrored data acquisition device is known, creating a fourth routing device based on the known MAC address, and configuring a default routing system corresponding to the first data frame according to the fourth routing device and the MAC address and IP address corresponding to the target device or network, and using the configured default routing system as the target default routing system corresponding to the fourth routing device;
[0093] Correspondingly, the mirror data acquisition device is further configured to, after acquiring the first data frame, unidirectionally transmit the acquired first data frame to the fourth routing device;
[0094] the fourth routing device is configured to re-encapsulate the first data frame according to the address of the target default routing system to obtain a second data frame, and send the second data frame to the corresponding target default routing system;
[0095] The target default routing system is used to decapsulate the second data frame to obtain a data packet based on the corresponding preset default route, and forward the data packet to the target device or network, so that the target device or network performs a corresponding task based on the data packet.
[0096] Optionally, each of the default routing systems includes at least one default router, and each default router is configured with a preset default route;
[0097] When the target default routing system includes multiple default routers, the first default router in the target default routing system is used to decapsulate the second data frame to obtain a data packet, and forward the data packet to an adjacent default router based on the corresponding preset default route; each of the remaining default routers in the target default routing system is used to forward the data packet in sequence according to its corresponding preset default route, so as to forward the data packet to the target device or network.
[0098] It should be noted that for other corresponding descriptions of the functional units involved in the system for acquiring and transmitting mirrored data provided in the embodiment of the present application, please refer to Figures 1 to 6 The corresponding description in the method will not be repeated here.
[0099] The present application also provides a computer device, which can be a personal computer, a server, a network device, etc. Figure 8 As shown, the computer device includes a bus, a processor, a memory, and a communication interface, and may also include an input / output interface and a display device. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store location information. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, the steps of each method embodiment are implemented.
[0100] Those skilled in the art will understand that Figure 8 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0101] In one embodiment, a computer-readable storage medium is provided. The computer-readable storage medium may be non-volatile or volatile, and stores a computer program thereon. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.
[0102] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.
[0103] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0104] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned embodiments. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), data processing logic devices based on quantum computing, and the like.
[0105] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0106] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A method for acquiring and transmitting mirror data, characterized in that: include: The mirror data acquisition device acquires the first data frame when the first data frame passes through the deployment point of the mirror data acquisition device, and unidirectionally transmits the acquired first data frame to the SDN; The SDN determines a target default routing system from a plurality of default routing systems based on the first data frame information, re-encapsulates the target default routing system to obtain a second data frame, and forwards the second data frame to the target default routing system; The target default routing system decapsulates the second data frame to obtain a data packet based on the corresponding preset default route, and forwards the data packet to the target device or network, so that the target device or network performs a corresponding task based on the data packet; The SDN includes a plurality of routing devices with defined MAC addresses, each routing device with a defined MAC address corresponds to a default routing system, and the target default routing system is determined based on the default routing system of the routing device with the same MAC address as the data recipient of the first data frame; When there is no routing device with the same MAC address as the data receiver among the multiple routing devices with defined MAC addresses, the method further includes: Determine a second routing device in an idle state from the multiple routing devices with defined MAC addresses; if there is a second routing device in an idle state, change the defined MAC address corresponding to the second routing device to the MAC address of the data receiver, so as to process the first data frame based on the modified routing device; if there is no second routing device in an idle state, create a third routing device based on the MAC address of the data receiver, configure a new default routing system for the third routing device, so as to process the first data frame based on the new default routing system of the third routing device.
2. The method according to claim 1, characterized in that The mirror data acquisition device is a data diode, a data input end of the data diode is connected to the original transmission link of the first data frame, and a data output end of the data diode is connected to the SDN.
3. The method according to claim 1, characterized in that The SDN determines, based on the first data frame information, a target default routing system from a plurality of default routing systems, re-encapsulates the second data frame according to the target default routing system, and forwards the second data frame to the target default routing system, including: The SDN determines the MAC address of the data recipient of the first data frame based on the first data frame information, determines a first routing device with the same MAC address as the data recipient from multiple routing devices with defined MAC addresses included in the SDN, uses the default routing system corresponding to the first routing device as the target default routing system, re-encapsulates the first data frame according to the address of the target default routing system to obtain a second data frame, and forwards the second data frame to the target default routing system through the first routing device.
4. The method according to claim 3, characterized in that When there is no first routing device with the same MAC address as the data receiver among the plurality of routing devices with defined MAC addresses, the method further includes: Determining a second routing device in an idle state from a plurality of routing devices with defined MAC addresses included in the SDN; When there is a second routing device in an idle state among the multiple routing devices with defined MAC addresses, the defined MAC address corresponding to the second routing device is changed to the MAC address of the data receiver, and according to the second routing device and the MAC address and IP address corresponding to the target device or network, a default routing system corresponding to the first data frame is configured, the newly configured default routing system is used as the target default routing system corresponding to the second routing device, and the first data frame is re-encapsulated according to the address of the target default routing system to obtain a second data frame, and the second data frame is forwarded to the corresponding target default routing system through the second routing device; When there is no idle second routing device among the multiple routing devices with defined MAC addresses, a third routing device is created based on the MAC address of the data recipient, and a default routing system corresponding to the first data frame is configured according to the third routing device and the MAC address and IP address corresponding to the target device or network, and the newly configured default routing system is used as the target default routing system corresponding to the third routing device. The first data frame is re-encapsulated according to the address of the target default routing system to obtain a second data frame, and the second data frame is forwarded to the corresponding target default routing system through the third routing device.
5. The method according to claim 1, wherein The SDN determines, based on the first data frame information, a target default routing system from a plurality of default routing systems, re-encapsulates the second data frame according to the target default routing system, and forwards the second data frame to the target default routing system, including: The network device in the SDN searches, based on the header information of the first data frame, a target flow table corresponding to the header information from a flow table pre-issued by the SDN controller, modifies the address in the header information according to a matching item in the target flow table, and re-encapsulates the second data frame, and forwards the second data frame to a target default routing system corresponding to the forwarding strategy according to a forwarding strategy indicated by the matching item in the target flow table.
6. The method according to claim 1, characterized in that Before the SDN determines a target default routing system from a plurality of default routing systems based on the first data frame information, the method further includes: The SDN parses the received first data frame, determines header information corresponding to the first data frame, and inputs the header information into a preset forwarding mode determination model; The preset forwarding mode determination model extracts the target features corresponding to the header information through a feature extraction layer, and outputs the probability value corresponding to each preset forwarding mode based on the target features through a result output layer, and uses the preset forwarding mode with the largest probability value as the target forwarding mode for the SDN to forward the second data frame to the target default routing system, wherein the preset forwarding mode includes a routing forwarding mode and a flow table forwarding mode.
7. The method according to claim 1, characterized in that Before acquiring the first data frame, the method further includes: If the MAC address of the data recipient of the first data frame obtained by the mirrored data obtaining device is known, a fourth routing device is created based on the known MAC address, and a default routing system corresponding to the first data frame is configured according to the fourth routing device and the MAC address and IP address corresponding to the target device or network, and the configured default routing system is used as the target default routing system corresponding to the fourth routing device; Correspondingly, after obtaining the first data frame, the method further includes: The mirror data acquisition device unidirectionally transmits the acquired first data frame to the fourth routing device; The fourth routing device re-encapsulates the first data frame according to the address of the target default routing system to obtain a second data frame, and sends the second data frame to the corresponding target default routing system; The target default routing system decapsulates the second data frame to obtain a data packet based on the corresponding preset default route, and forwards the data packet to the target device or network, so that the target device or network performs a corresponding task based on the data packet.
8. The method according to any one of claims 1 to 7, characterized in that Each of the default routing systems includes at least one default router, and each default router is configured with a preset default route; When the target default routing system includes multiple default routers, the target default routing system decapsulates the second data frame to obtain a data packet based on the corresponding preset default route, and forwards the data packet to the target device or network, including: The first default router in the target default routing system decapsulates the second data frame to obtain a data packet, and forwards the data packet to an adjacent default router based on a corresponding preset default route; Each of the remaining default routers in the target default routing system forwards the data packet in sequence according to its corresponding preset default route, so as to forward the data packet to the target device or network.
9. A system for acquiring and transmitting mirror data, characterized in that: include: A mirror data acquisition device, configured to acquire the first data frame when the first data frame passes through a deployment point of the mirror data acquisition device, and unidirectionally transmit the acquired first data frame to the SDN; The SDN is configured to determine a target default routing system from a plurality of default routing systems based on the first data frame information, re-encapsulate the second data frame according to the target default routing system, and forward the second data frame to the target default routing system; The target default routing system is configured to decapsulate the second data frame to obtain a data packet based on the corresponding preset default route, and forward the data packet to a target device or network, so that the target device or network performs a corresponding task based on the data packet; The SDN includes a plurality of routing devices with defined MAC addresses, each routing device with a defined MAC address corresponds to a default routing system, and the target default routing system is determined based on the default routing system of the routing device with the same MAC address as the data recipient of the first data frame; When there is no first routing device with the same MAC address as the data receiver among the plurality of routing devices with defined MAC addresses, the SDN is further configured to: Determining a second routing device in an idle state from the plurality of routing devices with defined MAC addresses; if a second routing device in an idle state exists, changing the defined MAC address corresponding to the second routing device to the MAC address of the data receiver, so as to process the first data frame based on the modified routing device; If there is no idle second routing device, a third routing device is created based on the MAC address of the data receiver, and a new default routing system is configured for the third routing device to process the first data frame based on the new default routing system of the third routing device.
10. A medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.
11. A computer device comprising a storage medium, a processor, and a computer program stored in the storage medium and executable on the processor, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Traffic mirroring method, device, equipment, system and storage medium
CN117834564A
Data forwarding method, static routing flow table entry generation method and device, computer equipment and storage medium
CN118784548A