Network traffic processing method and electronic device
By assigning global labels to situational awareness sensors and performing intelligent encapsulation and decapsulation of network traffic, the problems of hardware resource consumption and complexity in existing technologies are solved, enabling traffic monitoring of multiple network types, improving efficiency and accuracy, and reducing costs.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA TELECOM CLOUD TECH CO LTD
- Filing Date
- 2024-12-02
- Publication Date
- 2026-04-21
AI Technical Summary
Existing network traffic monitoring methods in cloud scenarios require additional hardware resources and are highly complex, cannot support multiple network types, and increase management and maintenance costs.
By assigning global tags to the target situational awareness device, the host machine of the virtual machine performs inner and outer encapsulation, and the situational awareness device host machine performs decapsulation, thus realizing intelligent processing of network traffic and supporting two network types: VLAN and VXLAN.
Without increasing hardware resources, it improves the efficiency and accuracy of traffic monitoring, reduces system complexity and cost, and ensures the real-time nature and integrity of monitoring data.
Smart Images

Figure CN119728496B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of cloud scenario traffic monitoring technology, and in particular to a network traffic processing method and electronic device. Background Technology
[0002] Software Defined Networking (SDN) is an architecture that abstracts a network into a control plane and a forwarding plane, making the network agile and flexible. With the rise of the cloud, SDN provides flexible network support for various cloud services and application workloads. However, the differences in details brought about by various virtualization technologies lead to significant challenges for full-stack network interoperability, including the asymmetry of information stored in different virtualization control planes, how to synchronize and manage information from multiple control planes, and how to implement cross-regional routing. OpenFlow is a network communication protocol belonging to the data link layer that can control the forwarding plane of network switches or routers, and is therefore widely used in SDN architectures. SDN uses OpenFlow to control the forwarding plane of OVS (Open Vswitch), thereby changing the network path taken by network packets.
[0003] Traffic monitoring refers to the monitoring of data flows, including content inspection and traffic analysis of network communication data packets. This provides a comprehensive view of network traffic, enabling rapid detection and location of network faults. Simultaneously, it allows for multi-dimensional analysis of network traffic, ensuring the stable operation of critical applications. Traffic mirroring, on the other hand, involves copying packets that meet filtering criteria and forwarding the copied network traffic to a designated situational awareness unit (SIA) or analyzer. The SIA or analyzer then performs content inspection, threat monitoring, and troubleshooting.
[0004] Currently, most public cloud traffic monitoring methods rely on VXLAN networks for monitoring and analysis. However, this method requires deploying dedicated mirror network elements, increasing hardware resource consumption and potentially introducing additional management and maintenance costs. Furthermore, it places high demands on situational awareness devices, requiring them to not only receive and analyze packets but also possess VXLAN decapsulation capabilities. This increases the complexity and cost of situational awareness devices and may limit their applicability across different scenarios and devices. Summary of the Invention
[0005] To overcome or at least partially solve the above problems, embodiments of the present invention provide a network traffic processing method and electronic device to improve the efficiency and accuracy of traffic monitoring while reducing hardware and maintenance costs.
[0006] The first aspect of this invention provides a network traffic processing method applied to a host machine where a virtual machine resides, the method comprising:
[0007] Receive the first OpenFlow flow table and group table issued by the SDN controller. The first OpenFlow flow table carries the global label of the target situational awareness device.
[0008] Based on the first Openflow flow table, the network traffic to be monitored is mirrored to obtain the target packet, and the target packet is copied to the operation and maintenance group table based on the group table.
[0009] Based on the first Openflow flow table, the target message in the operation and maintenance group table is encapsulated in inner and outer layers according to the global tag of the target situational awareness device to obtain the encapsulated message;
[0010] The encapsulated packet is forwarded to the host machine of the situational awareness corresponding to the target situational awareness, so that the host machine of the situational awareness can decapsulate the encapsulated packet based on the second Openflow flow table issued by the SDN controller to obtain the target packet, and send the target packet to the target situational awareness for traffic monitoring and analysis.
[0011] A second aspect of this invention provides a network traffic processing method applied to a situational awareness host machine, the method comprising:
[0012] Receive the second Openflow flow table issued by the SDN controller. The second Openflow flow table is used to decapsulate the encapsulated packets.
[0013] The system receives encapsulated packets forwarded by the host machine where the virtual machine resides. These encapsulated packets are obtained by the host machine based on the first OpenFlow flow table issued by the SDN controller, and by encapsulating the target packets in the operation and maintenance group table using inner and outer layers according to the global tag of the target situational awareness carried in the first OpenFlow flow table. The target packets are obtained by the host machine based on the first OpenFlow flow table, mirroring the network traffic to be monitored, and copying the target packets to the operation and maintenance group table based on the group table issued by the SDN controller.
[0014] Based on the second OpenFlow flow table, the encapsulated message is decapsulated to obtain the target message, and the target message is sent to the target situational awareness device for traffic monitoring and analysis.
[0015] A third aspect of the present invention provides an electronic device, the electronic device comprising: a memory, a processor, and a computer program stored in the memory and running on the processor, wherein when the computer program is executed by the processor, it implements the network traffic processing method of the first aspect of the present invention, and / or implements the network traffic processing method of the second aspect of the present invention.
[0016] In the network traffic processing method provided in this embodiment of the invention, a global label is pre-assigned to the target situational awareness device. When the host machine of the virtual machine encapsulates the target packets corresponding to the network traffic to be monitored, it performs inner and outer encapsulation processing on the target packets through the global label of the target situational awareness device. This is no longer limited to a single network type, and enables simultaneous monitoring of traffic for multiple network types without consuming additional hardware resources. Furthermore, this embodiment improves the efficiency and accuracy of traffic monitoring by directly encapsulating packets and sending them to the situational awareness device host machine, avoiding intermediate forwarding and processing, reducing possible latency and packet loss, thereby ensuring the real-time performance and integrity of the monitoring data. In addition, this embodiment uses the situational awareness device host machine corresponding to the target situational awareness device to decapsulate the encapsulated packets and send the obtained target packets to the target situational awareness device for traffic monitoring and analysis. Thus, the target situational awareness device does not need to decapsulate; it directly performs traffic monitoring based on the received target packets, avoiding the need for the situational awareness device to have VXLAN parsing capabilities, and reducing the complexity and cost of the system. Attached Figure Description
[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 This is a schematic diagram of traffic monitoring based on a VXLAN network, as shown in related technologies;
[0019] Figure 2 This is a flowchart illustrating a network traffic processing method according to an embodiment of the present invention;
[0020] Figure 3 This is a flowchart illustrating a network traffic processing method according to an embodiment of the present invention;
[0021] Figure 4 This is a schematic diagram of an efficient and cost-reducing method for monitoring, analyzing, and processing network traffic in a cloud environment, as proposed in an embodiment of the present invention.
[0022] Figure 5 This is a schematic diagram of an electronic device according to an embodiment of the present invention. Detailed Implementation
[0023] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0024] like Figure 1 As shown, Figure 1 This is a schematic diagram illustrating traffic monitoring based on a VXLAN network, as shown in related technologies. Figure 1 In order to deliver mirrored packets to the situational awareness unit deployed in the cloud based on the destination IP, the original packets need to be encapsulated with a double-layer VXLAN (Virtual Extensible Local Area Network) layer. The destination IP of the inner VXLAN layer is the IP address of the situational awareness unit, and the destination IP of the outer VXLAN layer is the IP address of the host machine where the situational awareness unit resides. Since native OVS does not support direct double-layer VXLAN encapsulation via OpenFlow flow tables, traffic monitoring in this method is performed by sending packets to a dedicated mirror network element. This mirror network element is responsible for performing double-layer VXLAN encapsulation on the packets, where the destination IP address of the inner VXLAN layer is set to the IP address of the situational awareness unit, and the outer VXLAN header corresponds to the IP address of the host machine where the situational awareness unit resides.
[0025] The packet, encapsulated by the mirrored network element, is then transmitted to the situational awareness unit's host machine. On the host machine, the VXLAN encapsulation is first removed, i.e., the outer VXLAN header is removed. Then, based on the inner destination IP (i.e., the situational awareness unit's IP), the packet is directed to the situational awareness unit. Since native OVS can only parse one layer of VXLAN, the inner VXLAN packet is transparently passed to the situational awareness unit. After receiving the packet, the situational awareness unit needs to further parse the inner VXLAN before analyzing the packet content.
[0026] However, the aforementioned technologies have several significant drawbacks and limitations. First, these technologies are only applicable to VXLAN networks and cannot directly support traditional VLAN (Virtual Local Area Network) networks. This limits their application scope, especially in network environments that use a hybrid approach of VXLAN and VLAN.
[0027] Secondly, this technology requires the deployment of dedicated mirror network elements in the network environment. This not only increases the consumption of hardware resources but may also introduce additional management and maintenance costs. More importantly, since the mirror network element is a centralized network element, it may become a bottleneck for network traffic forwarding, especially under high traffic loads, potentially leading to performance degradation or increased latency.
[0028] Finally, this technology places high demands on situational awareness devices. A situational awareness device (SAP) is a device installed in a network, primarily used to monitor and collect information such as network traffic, device status, and security events. It is a crucial component of a situational awareness system, capable of sensing the network's security posture in real time. By collecting and analyzing this information, it can identify and respond promptly to various security threats and risk events. SAPs not only need to be able to receive and analyze packets but also require VXLAN decapsulation capabilities. This increases the complexity and cost of the SAP and may also limit its applicability across different scenarios and devices.
[0029] In summary, although this traffic monitoring method of related technologies has achieved network traffic monitoring and analysis to a certain extent, it cannot fully meet the needs of efficient, flexible and low-cost traffic monitoring in cloud scenarios due to its inherent limitations and shortcomings.
[0030] Therefore, to at least partially solve one or more of the above-mentioned problems and other potential problems, this invention proposes a network traffic processing method. This method assigns a global tag to the target packets corresponding to the network traffic to be monitored, and intelligently encapsulates and forwards the target packets based on the global tag. This process requires no additional hardware resources and supports both VLAN and VXLAN network types, thus achieving cost reduction and efficiency improvement. Specifically, it enables traffic monitoring of both VLAN and VXLAN networks without consuming additional hardware resources. This overcomes the limitation of related technologies that can only support a single network type (such as VXLAN), improving the system's flexibility and versatility. Furthermore, by directly encapsulating packets and sending them to the situational awareness host, this method improves the efficiency and accuracy of traffic monitoring, avoids intermediate forwarding and processing, reduces potential latency and packet loss, and thus ensures the real-time performance and integrity of the monitoring data. Furthermore, this method decapsulates the encapsulated packets through the host machine of the target situational awareness device, and sends the obtained target packets to the target situational awareness device for traffic monitoring and analysis. In this way, the target situational awareness device does not need to decapsulate, but directly performs traffic monitoring based on the received target packets. This avoids the need for the situational awareness device to have the ability to parse VXLAN, reduces the complexity and cost of the system, and allows more devices to be used as situational awareness devices, expanding the range of options and simplifying the system deployment and maintenance process.
[0031] In the following sections, specific examples of this solution will be described in more detail with reference to the accompanying drawings.
[0032] refer to Figure 2 , Figure 2 This is a flowchart illustrating a network traffic processing method according to an embodiment of the present invention. Figure 2 As shown, the network traffic processing method proposed in the first aspect of this invention is applied to the host machine where the virtual machine is located. The method may include the following steps:
[0033] Step S11: Receive the first Openflow flow table and group table issued by the SDN controller. The first Openflow flow table carries the global tag of the target situational awareness device.
[0034] In this embodiment, the SDN controller issues a first OpenFlow flow table and a group table to the host machine where the virtual machine resides. The first OpenFlow flow table is used to determine the network traffic to be monitored and the target situational awareness device, and to perform inner and outer encapsulation processing on the target packets obtained from the mirroring. The group table is used to instruct the target packets obtained from the mirroring to be copied to the corresponding operation and maintenance group table.
[0035] The first OpenFlow flow table carries a global label for the target situational awareness, which is used to identify the target situational awareness. The global label of the target situational awareness is a unique global label assigned to the target situational awareness by the SDN controller. In this embodiment, the target situational awareness is a situational awareness that performs traffic monitoring and analysis on target packets.
[0036] OpenFlow is a network communication protocol used in SDN architectures for communication between controllers and repeaters. A core principle of Software-Defined Networking (SDN) is the separation of forwarding and control. To achieve this separation, a standard communication interface needs to be established between the controller and repeaters, allowing the controller to directly access and control the repeater's forwarding plane. OpenFlow introduces the concept of "flow tables," which repeaters use to guide packet forwarding. The SDN controller deploys corresponding OpenFlow flow tables on the repeaters through the interface provided by OpenFlow, thereby controlling the forwarding plane.
[0037] Step S12: Based on the first Openflow flow table, mirror the network traffic to be monitored to obtain the target packet, and copy the target packet to the operation and maintenance group table based on the group table.
[0038] In this embodiment, the host machine where the virtual machine resides, which is also the host machine where the image source virtual machine resides, can determine the network traffic to be monitored based on the first OpenFlow flow table, and mirror the network traffic to be monitored to obtain the target packets corresponding to the network traffic to be monitored. After obtaining the target packets, the target packets can be copied to the corresponding operation and maintenance group table based on the group table.
[0039] In this embodiment, for the matched traffic, i.e. the network traffic to be monitored, the host machine where the virtual machine is located can record the global tag of the target situational awareness in the Openflow register, which is used to uniquely identify the target situational awareness that needs to be sent, guide the target packet encapsulation and forwarding process, and at the same time copy the target packet to the operation and maintenance group table used for operation and maintenance.
[0040] In one optional specific example, the first OpenFlow flow table includes at least:
[0041] table = 10, priority = 10000, in_port = 10, quintuple action:load:0x2f->NXM_NX_R EG10[],group:12345,goto_table:11
[0042] Where in_port=10 is the port number of the mirror source virtual machine (i.e., virtual machine) on Openflow, load:0x2f->NXM_NX_REG10[] indicates that the global tag information of the target situational awareness to be mirrored is recorded in register 10, group:12345 indicates that a copy of the target packet is sent to group table 12345 (here it is assumed that 12345 is the operation and maintenance group table used for operation and maintenance), goto_table:11 indicates that the target packet continues to be forwarded normally and sent to the next level table.
[0043] Step S13: Based on the first Openflow flow table, according to the global tag of the target situational awareness device, the target message in the operation and maintenance group table is encapsulated in the inner and outer layers to obtain the encapsulated message.
[0044] In this embodiment, the host machine where the virtual machine is located can encapsulate the target packets in the operation and maintenance group table into inner and outer layers based on the first Openflow flow table and the global label of the target situational awareness device, thereby obtaining the encapsulated packets and realizing the two-layer encapsulation of network traffic packets.
[0045] Step S14: Forward the encapsulated packet to the host machine of the situational awareness corresponding to the target situational awareness, so that the host machine of the situational awareness can decapsulate the encapsulated packet based on the second Openflow flow table issued by the SDN controller to obtain the target packet, and send the target packet to the target situational awareness for traffic monitoring and analysis.
[0046] In this embodiment, after receiving the encapsulated packet, the host machine of the virtual machine determines the host machine corresponding to the target situational awareness based on the global tag of the target situational awareness. This host machine is the host machine where the target situational awareness resides. Then, the encapsulated packet is forwarded to the host machine corresponding to the target situational awareness.
[0047] After receiving the encapsulated packet, the host machine of the target situational awareness can decapsulate the encapsulated packet based on the second Openflow flow table issued by the SDN controller, obtain the parsed target packet, and send the parsed target packet to the target situational awareness, so that the target situational awareness can directly monitor and analyze the traffic of the received target packet.
[0048] In this embodiment, when the host machine of the virtual machine encapsulates the target packets corresponding to the network traffic to be monitored, it performs inner and outer encapsulation processing on the target packets using the global tag of the target situational awareness device. This is no longer limited to a single network type, enabling simultaneous monitoring of traffic from multiple network types without consuming additional hardware resources. Furthermore, by directly encapsulating packets and sending them to the situational awareness device host machine, this embodiment improves the efficiency and accuracy of traffic monitoring, avoids intermediate forwarding and processing, reduces potential latency and packet loss, and thus ensures the real-time performance and integrity of the monitoring data. In addition, this embodiment uses the situational awareness device host machine corresponding to the target situational awareness device to decapsulate the encapsulated packets before sending the resulting target packets to the target situational awareness device for traffic monitoring and analysis. Thus, the target situational awareness device does not need to decapsulate; it directly monitors traffic based on the received target packets, avoiding the need for the situational awareness device to have VXLAN parsing capabilities, and reducing system complexity and cost.
[0049] In conjunction with the above embodiments, in one implementation, the first aspect of the present invention further provides a network traffic processing method. Specifically, in this embodiment, step S13 above, "encapsulating the target packets in the operation and maintenance group table with inner and outer layers according to the global tag of the target situational awareness device to obtain the encapsulated packets," may specifically include steps S21 to S23:
[0050] Step S21: Based on the global tag of the target situational awareness device, encapsulate the target packet with an inner VLAN ID to obtain the inner encapsulation result.
[0051] In this embodiment, the host machine of the virtual machine, based on the first OpenFlow flow table, can encapsulate the target packet with an inner VLAN ID based on the global tag of the target situational awareness, thus obtaining the inner encapsulation result. Here, the global tag in this embodiment is the VLAN ID; that is, the SDN controller assigns a unique VLAN ID to the target situational awareness, and this VLAN ID is the global tag. For example, the inner layer of the target packet can be tagged with a global tag of the target situational awareness, i.e., the VLAN ID of the target situational awareness, to obtain the inner encapsulation result.
[0052] Step S23: Based on the network type of the network where the target situational awareness device is located, perform outer encapsulation on the inner encapsulation result to obtain the encapsulated message.
[0053] This embodiment supports traffic monitoring for both VLAN and VXLAN networks, rather than just a single network type (such as VXLAN), thus improving the system's flexibility and versatility. Based on this, after obtaining the inner encapsulation result, the host machine of the virtual machine, based on the first OpenFlow flow table, performs different outer encapsulation processes on the inner encapsulation result according to the network type of the target situational awareness network, to obtain the encapsulated packet.
[0054] In an optional specific example, this embodiment adds a new situational awareness inner TABLE (let's call it table100) and a situational awareness outer encapsulation TABLE (let's call it table101) during inner encapsulation. In the operations and maintenance group table, the action is to send the packet to the situational awareness inner TABLE, i.e., resubmit(,100). In the situational awareness inner TABLE, based on the global tag of the target situational sensor, the target packet is first tagged with the VLAN ID of the target situational sensor (the VLAN ID assigned to the target situational sensor by the SDN controller, let's call it 2), and then sent to the situational awareness outer TABLE. Specifically, the first OpenFlow flow table includes at least:
[0055] table=100,priority=1000,reg10=0x2f action:push_vlan:0x8100,set_field:0x1002->vlan_vid,goto_table:101
[0056] In this context, push_vlan:0x8100,set_field:0x1002->vlan_vid indicates that a VLAN header is added and marked with VLAN ID 2.
[0057] In the outer TABLE of the situational awareness layer, the global label of the target situational awareness device is also matched, and the target packet is further encapsulated according to the network type of the network where the target situational awareness device is located.
[0058] In conjunction with the above embodiments, in one implementation, the first aspect of the present invention further provides a network traffic processing method. Specifically, in this method, step S23 may specifically include steps S31 and S32:
[0059] Step S31: If the network type of the target situational awareness device is a VXLAN network, encapsulate the outer layer of the inner encapsulation result with the VXLAN ID corresponding to the network where the target situational awareness device is located, and encapsulate the destination IP as the VTEP IP of the situational awareness device host machine corresponding to the target situational awareness device, to obtain the encapsulated packet.
[0060] In this embodiment, when the host machine of the virtual machine determines that the network type of the target situational awareness device is a VXLAN network, it can encapsulate the outer layer of the inner encapsulation result with the VXLAN ID corresponding to the network where the target situational awareness device is located, and encapsulate the destination IP as the VTEP IP of the situational awareness device's host machine corresponding to the target situational awareness device, thus obtaining the encapsulated packet. After obtaining the encapsulated packet, it can be directly sent to the situational awareness device's host machine corresponding to the target situational awareness device based on the address information (i.e., the VTEP IP) of the situational awareness device's host machine.
[0061] Step S32: If the network type of the target situational awareness device is a VLAN network, encapsulate the VLAN ID corresponding to the network where the target situational awareness device is located in the outer layer of the inner encapsulation result to obtain the encapsulated packet.
[0062] In this embodiment, when the host machine of the virtual machine determines that the network type of the target situational awareness device is a VLAN network, it can encapsulate the inner encapsulation result with the VLAN ID corresponding to the target situational awareness device's network, thus obtaining the encapsulated packet. After obtaining the encapsulated packet, it can be forwarded through the VLAN network and finally delivered to the host machine of the situational awareness device corresponding to the target situational awareness device.
[0063] In an optional specific example, this embodiment also matches global tags in the outer TABLE of the situational awareness layer, and performs an outer encapsulation on the packet based on the network to which the situational awareness device belongs, including:
[0064] 1) If the target situational awareness sensor's network type is VXLAN, then the outer encapsulation layer contains the VXLAN ID (assumed to be 9) corresponding to the target situational awareness sensor's network. The destination IP is encapsulated as the VTEP IP of the situational awareness sensor's host machine (assumed to be 1.2.3.4). After encapsulation, based on the address information of the situational awareness sensor's host machine, the encapsulated packet is directly sent to the corresponding host machine. Specifically, the first OpenFlow flow table includes at least:
[0065] table=101,priority=1000,reg10=0x2f action:set_field:0x9->tun_id,set_field:1.2.3.4->tun_dst,output:vxlan1
[0066] In this context, `set_field:0x9->tun_id` indicates that the VXLAN ID of the subsequent encapsulated VXLAN header is 9, and `set_field:1.2.3.4->tun_dst` indicates that the destination IP of the VXLAN packet is encapsulated with the VTEP IP 1.2.3.4 of the host machine where the situational awareness device is located.
[0067] 2) If the network type of the target situational awareness device is a VLAN network, then the outer layer encapsulates the VLAN ID (assumed to be 9) corresponding to the network where the target situational awareness device is located. The encapsulated packet is forwarded through the VLAN network and finally delivered to the situational awareness device host machine corresponding to the target situational awareness device. Specifically, the first OpenFlow flow table includes at least:
[0068] table=101, priority=1000, reg10=0x2f action: push_vlan:0x8100, set_field:0x1009->vlan_vid, output: bond1.
[0069] During the packet encapsulation process, this embodiment fully leverages the flexibility of OpenFlow flow tables, enabling intelligent processing of target packets through the configuration of corresponding rules, thus adapting to different types of network requirements. Furthermore, since the encapsulation process is completed at the software level, no additional hardware resources or network elements are required, thereby reducing costs.
[0070] In conjunction with the above embodiments, in another implementation, the first aspect of the present invention also provides a network traffic processing method. Specifically, in this embodiment, the global label is a unique global label assigned by the SDN controller to each situational awareness unit within the same VPC based on the characteristics and requirements of each VPC in the cloud network, and the global label can be reused between different VPCs.
[0071] In this embodiment, analyzers and situational awareness devices are deployed in the cloud network. The SDN controller assigns a unique global label to each situational awareness device to uniquely identify and distinguish them. For example, the assigned global label could be 0x2f. Specifically, the SDN controller assigns a unique global label to each situational awareness device within the same VPC (Virtual Private Cloud) based on its characteristics and requirements. However, this global label can be reused across different VPCs. This allows for the assignment of a repeatable global label across different VPCs to conserve resources. In an optional example, the global label assigned by the SDN controller to the situational awareness device is a VLAN ID.
[0072] Based on the same inventive concept, a second aspect of the present invention provides a network traffic processing method. (See reference...) Figure 3 , Figure 3 This is a flowchart illustrating a network traffic processing method according to an embodiment of the present invention. Figure 3 As shown, the network traffic processing method proposed in the second aspect of this invention is applied to a situational awareness host machine, and the method may include the following steps:
[0073] Step S41: Receive the second Openflow flow table issued by the SDN controller. The second Openflow flow table is used to decapsulate the encapsulated packets.
[0074] In this embodiment, the SDN controller sends a second OpenFlow flow table to the situational awareness host. The situational awareness host can receive the second OpenFlow flow table sent by the SDN controller. The second OpenFlow flow table is used to decapsulate the encapsulated packets.
[0075] In one optional embodiment, the SDN controller can issue different second OpenFlow flow tables to the situational awareness host based on the network type of the network where the target situational awareness is located. For example, if the network type of the target situational awareness is a VXLAN network, the SDN controller issues the second OpenFlow flow table corresponding to the VXLAN network to the situational awareness host; if the network type of the target situational awareness is a VLAN network, the SDN controller issues the second OpenFlow flow table corresponding to the VLAN network to the situational awareness host.
[0076] Step S42: Receive the encapsulated packet forwarded by the host machine where the virtual machine is located. The encapsulated packet is obtained by the host machine where the virtual machine is located based on the first Openflow flow table issued by the SDN controller, and by encapsulating the target packet in the operation and maintenance group table with inner and outer layers according to the global tag of the target situational awareness carried in the first Openflow flow table. The target packet is obtained by the host machine where the virtual machine is located based on the first Openflow flow table, by mirroring the network traffic to be monitored, and by copying the target packet to the operation and maintenance group table based on the group table issued by the SDN controller.
[0077] In this embodiment, the SDN controller issues a first OpenFlow flow table and a group table to the host machine where the virtual machine resides. The first OpenFlow flow table is used to determine the network traffic to be monitored and the target situational awareness, and to perform inner and outer encapsulation processing on the target packets obtained from the mirroring process. The group table is used to instruct the mirrored target packets to be copied to the corresponding operations and maintenance group table. The first OpenFlow flow table carries a global label for the target situational awareness. This global label is a unique global label assigned to the target situational awareness by the SDN controller. In this embodiment, the target situational awareness is a situational awareness that monitors and analyzes the traffic of the target packets.
[0078] The host machine where the virtual machine resides, which is also the host machine of the image source virtual machine, can determine the network traffic to be monitored based on the first OpenFlow flow table, and mirror the network traffic to obtain the target packets corresponding to the network traffic to be monitored. After obtaining the target packets, the host machine can copy the target packets to the corresponding operation and maintenance group table based on the group table.
[0079] In this embodiment, for the matched traffic, i.e. the network traffic to be monitored, the host machine where the virtual machine is located can record the global tag of the target situational awareness in the Openflow register, which is used to uniquely identify the target situational awareness that needs to be sent, guide the target packet encapsulation and forwarding process, and at the same time copy the target packet to the operation and maintenance group table used for operation and maintenance.
[0080] Subsequently, the host machine where the virtual machine is located can encapsulate the target packets in the operation and maintenance group table into inner and outer layers based on the first Openflow flow table and the global label of the target situational awareness device, thereby obtaining the encapsulated packets and realizing the two-layer encapsulation of network traffic packets.
[0081] After receiving the encapsulated packet, the host machine hosting the virtual machine determines the corresponding situational awareness host based on the global tag of the target situational awareness. This target situational awareness host is the host machine where the target situational awareness resides. The host machine hosting the virtual machine then forwards the encapsulated packet to the target situational awareness host machine. The target situational awareness host machine receives the encapsulated packet forwarded by the host machine hosting the virtual machine.
[0082] Step S43: Based on the second Openflow flow table, decapsulate the encapsulated message to obtain the target message, and send the target message to the target situational awareness device for traffic monitoring and analysis.
[0083] In this embodiment, after receiving the encapsulated packet, the host machine of the situational awareness device can decapsulate the encapsulated packet based on the second Openflow flow table to obtain the parsed target packet, and send the parsed target packet to the target situational awareness device, so that the target situational awareness device can directly monitor and analyze the traffic of the received target packet.
[0084] In this embodiment, when the host machine of the virtual machine encapsulates the target packets corresponding to the network traffic to be monitored, it performs inner and outer encapsulation processing on the target packets using the global tag of the target situational awareness device. This is no longer limited to a single network type, enabling simultaneous monitoring of traffic from multiple network types without consuming additional hardware resources. Furthermore, by directly encapsulating packets and sending them to the situational awareness device host machine, this embodiment improves the efficiency and accuracy of traffic monitoring, avoids intermediate forwarding and processing, reduces potential latency and packet loss, and thus ensures the real-time performance and integrity of the monitoring data. In addition, this embodiment uses the situational awareness device host machine corresponding to the target situational awareness device to decapsulate the encapsulated packets before sending the resulting target packets to the target situational awareness device for traffic monitoring and analysis. Thus, the target situational awareness device does not need to decapsulate; it directly monitors traffic based on the received target packets, avoiding the need for the situational awareness device to have VXLAN parsing capabilities, and reducing system complexity and cost.
[0085] In conjunction with the above embodiments, in one implementation, the second aspect of the present invention further provides a network traffic processing method. Specifically, in this embodiment, the step S43 above, "decapsulating the encapsulated packet to obtain the target packet, and sending the target packet to the target situational awareness device," may specifically include steps S51 and S52:
[0086] Step S51: If the network type of the target situational awareness device is a VXLAN network, the encapsulated message is parsed through the OS protocol stack to obtain the parsed message and the corresponding VXLAN ID and VLAN ID.
[0087] In this embodiment, when the host machine of the situational awareness device determines that the network type of the network where the target situational awareness device is located is a VXLAN network, it can parse the received encapsulated message through the OS protocol stack to obtain the parsed message and the corresponding VXLAN ID and VLAN ID.
[0088] Step S52: Based on the VXLAN port corresponding to the VXLAN ID, match the VLAN ID corresponding to the parsed packet with the VLAN ID stored in the Openflow register. If the match is successful, determine the parsed packet as the target packet, match the corresponding target situational awareness device based on the VLAN ID corresponding to the parsed packet, and send the target packet to the target situational awareness device.
[0089] In this embodiment, after obtaining the parsed packet and the corresponding VXLAN ID and VLAN ID, the VLAN ID corresponding to the parsed packet can be matched with the VLAN ID stored in the Openflow register based on the VXLAN port corresponding to the VXLAN ID of the parsed packet.
[0090] If the VLAN ID corresponding to the parsed packet successfully matches the VLAN ID stored in the Openflow register, the parsed packet is identified as the target packet. Based on the VLAN ID corresponding to the parsed packet, the corresponding target situational awareness device is matched, and the target packet is sent to the target situational awareness device so that the target situational awareness device can perform traffic monitoring based on the target packet.
[0091] In this embodiment, the global tag is the VLAN ID, and the Openflow register stores the unique VLAN ID assigned to each situational awareness device by the SDN controller. If the VLAN ID corresponding to the parsed packet successfully matches the VLAN ID stored in the Openflow register (i.e., the VLAN ID corresponding to the parsed packet is the same as a VLAN ID stored in the Openflow register), it can be determined that the VLAN ID corresponding to the parsed packet is the global tag corresponding to the target situational awareness device. At this point, it can be determined that the parsed packet is the target packet, and the corresponding target situational awareness device can be determined based on the VLAN ID corresponding to the parsed packet.
[0092] In an optional specific example, this embodiment decapsulates packets for VXLAN networks where the target situational awareness device resides by matching the outer VXLAN ID and the inner VLAN ID to ensure that the packet can be correctly delivered to the situational awareness virtual machine (i.e., the target situational awareness device). Specifically, the second OpenFlow flow table includes at least:
[0093] table = 0, priority = 50000, tun_id = 0x9, dl_vlan = 2, action: pop_vlan, output: situational awareness virtual machine.
[0094] In conjunction with the above embodiments, in one implementation, the second aspect of the present invention further provides a network traffic processing method. Specifically, in this method, step S43 above, "decapsulating the encapsulated packet to obtain the target packet, and sending the target packet to the target situational awareness device," may specifically include step S61:
[0095] Step S61: If the network type of the network where the target situational awareness device is located is a VLAN network, the outer VLAN of the encapsulated packet is parsed through multi-level table processing, and the target situational awareness device is matched according to the inner VLAN ID of the encapsulated packet to obtain the target packet, and the target packet is sent to the target situational awareness device.
[0096] In this embodiment, when the host machine of the situational awareness device determines that the network type of the target situational awareness device is a VXLAN network, since Openflow can only parse VLANs layer by layer, the host machine of the situational awareness device can parse the outer VLAN of the encapsulated packet through multi-level table processing, match the corresponding target situational awareness device according to the inner VLAN ID of the encapsulated packet, obtain the target packet, and send the target packet to the target situational awareness device.
[0097] In conjunction with the above embodiments, in one implementation, the second aspect of the present invention further provides a network traffic processing method. Specifically, in this method, the step S61 above, "parse the outer VLAN of the encapsulated packet through multi-level table processing, match the target situational awareness device according to the inner VLAN ID of the encapsulated packet, obtain the target packet, and send the target packet to the target situational awareness device," may specifically include steps S71 to S73:
[0098] Step S71: Parse the encapsulated packet through the first-level table, strip the outer VLAN of the encapsulated packet to obtain an intermediate result, record the first VLAN ID of the outer VLAN in the Openflow register, and send the intermediate result to the second-level sub-table of the first priority in the second-level table.
[0099] In this embodiment, the second OpenFlow flow table includes a multi-level table, comprising a first-level table and a second-level table. The situational awareness host can parse the encapsulated packet using the first-level table, stripping the outer VLAN of the encapsulated packet to obtain an intermediate result. The first VLAN ID from the stripped outer VLAN is recorded in the OpenFlow register, and the intermediate result is sent to a second-level sub-table of the second-level table with a first priority. The second-level table includes at least: a second-level sub-table with a first priority and a second-level sub-table with a second priority, where the first priority is different from the second priority.
[0100] Step S72: By stripping the inner layer of the intermediate result through the second-level sub-table of the first priority, determine whether the inner layer of the intermediate result has a second VLAN ID.
[0101] In this embodiment, the situational awareness host machine uses a second-level sub-table with a first priority to strip the inner layer of the intermediate result. Specifically, it uses this second-level sub-table with a first priority to strip the inner layer of the intermediate result and determine whether a second VLAN ID exists within the inner layer. Here, the first VLAN ID is the VLAN ID of the outer layer of the encapsulated packet, and the second VLAN ID is the VLAN ID of the inner layer of the encapsulated packet.
[0102] Step S73: If a second VLAN ID exists in the inner layer of the intermediate result, the intermediate result is parsed to obtain the target packet. The target situational awareness device is determined based on the second VLAN ID, and the target packet is sent to the target situational awareness device.
[0103] In this embodiment, when the host machine of the situational awareness device determines that there is a second VLAN ID in the inner layer of the intermediate result, it parses the intermediate result through the second-level sub-table of the first priority to obtain the target packet. That is, it parses the intermediate result to obtain the parsed target packet, and determines the corresponding target situational awareness device based on the second VLAN ID, and then sends the target packet to the target situational awareness device so that the target situational awareness device can perform traffic monitoring based on the target packet.
[0104] In conjunction with the above embodiments, in one implementation, the second aspect of the present invention further provides a network traffic processing method. Specifically, in addition to the steps described above, the method may also include steps S81 and S82:
[0105] Step S81: If there is no second VLAN ID in the inner layer of the intermediate result, send the intermediate result to the second-level sub-table of the second priority in the second-level table.
[0106] In this embodiment, the first priority is higher than the second priority. If the situational awareness host determines that there is no second VLAN ID in the inner layer of the intermediate result, it can send the intermediate result to the second-level sub-table of the second priority in the second-level table.
[0107] Step S82: Parse the intermediate result through the second-level sub-table of the second priority to obtain a normal forwarding packet, read the first VLAN ID from the Openflow register, re-label the normal forwarding packet with the first VLAN ID, and then forward the packet.
[0108] In this embodiment, the situational awareness host obtains a normal forwarding packet by parsing the intermediate result through the second-level sub-table of the second priority, rather than a target packet. That is, the situational awareness host can parse the intermediate result through the second-level sub-table of the second priority to obtain the parsed normal forwarding packet. At this time, the first VLAN ID is read from the Openflow register, and the parsed normal forwarding packet is re-labeled with the first VLAN ID before normal forwarding of the packet.
[0109] The decapsulation process proposed in this embodiment ensures that the target message can be delivered accurately and efficiently to the target situational awareness virtual machine (i.e., the target situational awareness virtual machine). Since the message sent to the situational awareness device is the original target message without any additional encapsulation, the situational awareness virtual machine is not required to have any decapsulation capability, thus reducing the complexity and cost of the situational awareness device.
[0110] In an optional specific example, this embodiment decapsulates a VLAN network where the target situational awareness device resides. Since OpenFlow can only parse VLANs layer by layer, multi-level table processing is required to parse the outer VLAN and match the situational awareness virtual machine based on the inner VLAN ID. Specifically, the second OpenFlow flow table includes at least:
[0111] table = 0, priority = 50000, dl_vlan = 0x9 action:pop_vlan,load:0x9->NXM_NX_REG11[],goto_table:1 (This means that the packet with VLAN ID 9 will first be stripped of one VLAN layer, and its VLAN value will be recorded in register 11 and sent to table1 for further processing);
[0112] table=1,priority=50000,reg11=0x9,dl_vlan=2action:pop_vlan,output:situational awareness virtual machine (meaning that after stripping the outer VLAN, if there is still an inner VLAN and the VLAN is 2, then it is a mirror packet (i.e., the target packet), and the inner VLAN is stripped and sent to the target situational awareness device).
[0113] table = 1, priority = 0, action: push_vlan: 0x8100, move: NXM_NX_REG11[]->vlan_vid, goto_table: 2 (This means that after stripping the outer VLAN, if there is no inner VLAN, it will be a normal forwarding packet. The original VLAN 9 will be re-applied and the packet will be forwarded normally).
[0114] Among them, priority=50000 has a higher priority than priority=0. The table=1,priority=50000 is executed first. If the condition is not met (i.e., if there is no VLAN in the inner layer), then the table=1,priority=0 is executed.
[0115] like Figure 4 As shown, Figure 4 This is a schematic diagram illustrating a highly efficient and cost-effective cloud-based network traffic monitoring, analysis, and processing method proposed in an embodiment of the present invention. Figure 4 In a typical cloud scenario, users create multiple Virtual Private Clouds (VPCs) through a cloud platform, each containing a large number of virtual machines (VMs) and VXLAN networks. To ensure the security and performance of these cloud networks, real-time monitoring and analysis of network traffic is necessary. For example... Figure 4As shown, this embodiment no longer requires the configuration of additional mirror network elements, reducing the complexity and cost of the system.
[0116] First, deploy situational awareness agents: Deploy a cloud-native situational awareness agent service in each VPC of the cloud platform. These services run in the cloud environment as containers or Pods, offering high scalability and flexibility. Simultaneously, the SDN controller assigns a globally unique tag to each situational awareness agent for differentiation during traffic processing. Additionally, each situational awareness agent is assigned a unique VLAN ID within the VPC to ensure correct traffic identification and forwarding within the VLAN network.
[0117] After the situational awareness device is put into service, the SDN controller issues a second OpenFlow flow table to the host machine where the situational awareness virtual machine is located (i.e., the situational awareness device host machine) via OpenFlow, so that the situational awareness device host machine can match the outer VXLANID and the inner VLAN ID to ensure that the packets can be correctly delivered to the situational awareness virtual machine.
[0118] In one example, the second OpenFlow flow table includes at least: table=0, priority=50000, tun_id=0x9, dl_vlan=2, action:pop_vlan, output: situational awareness virtual machine.
[0119] Secondly, traffic mirroring rule configuration: On the cloud platform, configure traffic mirroring rules through the first OpenFlow flow table: select the virtual machine traffic to be monitored and configure the traffic to be sent to the designated situational awareness. After the rule configuration is complete, the SDN controller, through OpenFlow, issues the first OpenFlow flow table and group table to the host machine where the virtual machine to be monitored resides, mirroring the network traffic to be monitored. For matched traffic, the global tag of the target situational awareness to be sent is recorded in the OpenFlow register for subsequent unique identification of the situational awareness to be sent, guiding the packet encapsulation and forwarding process, and simultaneously copying the packet to the group table used for operation and maintenance. In the operation and maintenance group table, the action is to send it to the inner TABLE of the situational awareness, i.e., resubmit(,100). In the inner TABLE of the situational awareness, based on the global tag of the situational awareness, the inner layer of the packet is first tagged with the VLAN ID of the situational awareness (and the global tag assigned by the SDN controller: VLAN ID, assumed to be 2), and then sent to the outer TABLE of the situational awareness. In the outer TABLE of the situational awareness layer, the global label is also matched, and the VXLAN ID (assumed to be 9) corresponding to the network where the situational awareness is located is encapsulated. The destination IP is encapsulated as the VTEP IP of the host machine where the situational awareness is located (assumed to be 1.2.3.4). After encapsulation, the packet is sent directly to the corresponding host machine according to the address information of the situational awareness host machine.
[0120] In one example, the first OpenFlow flow table includes at least the following four parts:
[0121] Part 1: table = 10, priority = 10000, in_port = 10, quintuple action:load:0x2f->NXM_NX_REG10[],group:12345,goto_table:11;
[0122] Part 2: group_id:12345: resubmit(,100);
[0123] Part 3: table=100, priority=1000, reg10=0x2f action:push_vlan:0x8100,set_field:0x1002->vlan_vid,goto_table:101;
[0124] Part 4: table=101, priority=1000, reg10=0x2f action:set_field:0x9->t un_id,set_field:1.2.3.4->tun_dst,output:vxlan1.
[0125] Finally, message processing and storage: After the source virtual machine to be monitored sends the encapsulated message, the host machine matches the first OpenFlow flow table issued by SDN and mirrors it to the host machine where the situational awareness device resides. Upon receiving the message, the host machine of the situational awareness device matches the second OpenFlow flow table issued by the SDN controller and sends it to the situational awareness device. After receiving the message, the situational awareness device performs corresponding security analysis and situational awareness processing, obtaining the analysis results. The analysis results can be stored in the object storage service of the cloud platform or sent in real time to a centralized monitoring and display system for administrators or security teams to view and analyze.
[0126] Thus, this embodiment solves the problems existing in related technologies through innovative message encapsulation and forwarding mechanisms, improves the efficiency and accuracy of network traffic monitoring, reduces system complexity and cost, and provides an efficient, flexible and low-cost solution for network traffic monitoring in cloud scenarios.
[0127] In summary, this invention provides a highly efficient and cost-effective method for monitoring, analyzing, and processing cloud traffic. Specifically, it offers a generalizable and cost-efficient traffic monitoring method: First, analyzers and situational awareness units (SAUs) are deployed in the cloud network. Each SAU is assigned a globally unique tag, and repeatable VLAN IDs are assigned to SAUs based on VPC characteristics and requirements to save resources and achieve efficient VLAN reuse. Then, OpenFlow flow table technology is used to mirror the network traffic to be monitored, achieving accurate traffic capture. The global tag of the SAU is added to the OpenFlow register to uniquely identify the SAU to be delivered, providing guidance for subsequent packet encapsulation and forwarding. In the packet encapsulation and forwarding stage, an intelligent packet encapsulation and forwarding method is provided, designing an inner SAU table and an outer encapsulation table, and encapsulating the packet with the inner VLAN ID based on the global tag. Based on the network type (VXLAN or VLAN) of the situational awareness sensor, intelligent outer encapsulation is performed on the packets. For VXLAN networks, the outer encapsulation includes the VXLAN ID and destination IP address corresponding to the situational awareness sensor's network; for VLAN networks, the corresponding VLAN ID encapsulation is performed. After encapsulation, the packets are directly forwarded to the situational awareness sensor's host machine through the network, reducing intermediate nodes, lowering network latency, and decoupling the mirrored packets from the situational awareness sensor's network, adapting to different network requirements and reducing hardware costs. At the situational awareness sensor's host machine, OpenFlow flow tables are configured to match and process arriving packets. For VXLAN networks, the outer VXLAN ID and inner VLAN ID ensure correct packet delivery. For VLAN networks, multi-level table processing resolves the outer VLAN and matches the situational awareness virtual machine based on the inner VLAN ID, decapsulating the packets before sending them to the situational awareness sensor. Since the packets received by the situational awareness sensor are mirrored original packets, no further packet decapsulation processing is required, reducing the complexity of the situational awareness sensor.
[0128] In terms of cost, this invention reduces the involvement of intermediate nodes, thereby lowering not only the investment cost of hardware equipment but also the expenses for maintaining and managing these intermediate nodes. In related network architectures, each intermediate node requires corresponding hardware equipment support and necessitates regular maintenance and upgrades, all of which represent significant expenses. This solution effectively reduces these costs by minimizing the number of intermediate nodes.
[0129] In terms of efficiency, reducing intermediate nodes in this invention means reducing the data transmission path length in the network, thereby reducing transmission latency. This latency reduction is particularly important for applications requiring real-time responses. Furthermore, by reducing the forwarding process of data between multiple nodes, the risk of data loss and errors is reduced, improving data transmission reliability and enhancing overall network performance.
[0130] In terms of universality and complexity, in related public cloud network monitoring solutions, after packets are sent to the situational awareness unit (SIA), the SIA needs to perform another VXLAN decapsulation process to extract and analyze key information. Since most traditional SIAs lack VXLAN decapsulation capabilities, this process not only increases the processing burden on the SIA but also presents technical challenges. This solution, however, ultimately provides the SIA with a mirrored copy of the original packet, avoiding the complex decapsulation process and simplifying the SIA's processing logic. This enables the SIA to process and analyze packets more quickly and accurately, reducing complexity and improving its efficiency and accuracy.
[0131] As can be seen, the solution of this invention, through key technologies such as global tagging and VLAN allocation, and intelligent packet encapsulation and forwarding strategies, achieves efficient monitoring and analysis of network traffic, reduces costs, and simplifies operation processes, demonstrating significant beneficial effects. Furthermore, this solution is highly adaptable and scalable, capable of flexibly addressing different types of network needs.
[0132] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.
[0133] Based on the same inventive concept, another embodiment of the present invention provides an electronic device, such as... Figure 5 As shown. Figure 5 This is a schematic diagram of an electronic device according to an embodiment of the present invention. The electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When executed by the processor, the program implements the steps of the network traffic processing method as described in the first aspect of the present invention, and / or implements the steps of the network traffic processing method as described in the second aspect of the present invention.
[0134] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0135] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, embodiments of the present invention can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0136] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0137] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0138] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0139] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the present invention.
[0140] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.
[0141] The above provides a detailed description of the network traffic processing method and electronic device provided by the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A method for processing network traffic, characterized in that, Applied to the host machine where the virtual machine resides, the method includes: Receive the first OpenFlow flow table and group table issued by the SDN controller. The first OpenFlow flow table carries the global label of the target situational awareness device. Based on the first Openflow flow table, the network traffic to be monitored is mirrored to obtain the target packet, and the target packet is copied to the operation and maintenance group table based on the group table. Based on the first Openflow flow table, the target message in the operation and maintenance group table is encapsulated in inner and outer layers according to the global tag of the target situational awareness device to obtain the encapsulated message; The encapsulated packet is forwarded to the host machine of the situational awareness corresponding to the target situational awareness, so that the host machine of the situational awareness can decapsulate the encapsulated packet based on the second Openflow flow table issued by the SDN controller to obtain the target packet, and send the target packet to the target situational awareness for traffic monitoring and analysis. The step involves encapsulating the target message in the operation and maintenance group table with inner and outer layers based on the global tag of the target situational awareness device, resulting in an encapsulated message, including: Based on the global tag of the target situational awareness device, the target packet is encapsulated with an inner VLAN ID to obtain the inner encapsulation result; Based on the network type of the network where the target situational awareness device is located, the inner encapsulation result is encapsulated by an outer encapsulation to obtain the encapsulated message. When the network type of the target situational awareness device is a VXLAN network, the encapsulated message is parsed through the protocol stack to obtain the parsed message and the corresponding VXLANID and VLANID. Based on the VXLAN port corresponding to the VXLANID, the VLANID corresponding to the parsed packet is matched with the VLANID stored in the Openflow register. If the match is successful, the parsed packet is determined as the target packet.
2. The network traffic processing method according to claim 1, characterized in that, The step of performing outer encapsulation on the inner encapsulation result according to the network type of the network where the target situational awareness device is located, to obtain the encapsulated message, includes: When the network type of the network where the target situational awareness is located is a VXLAN network, the outer layer of the inner encapsulation result is encapsulated with the VXLAN ID corresponding to the network where the target situational awareness is located, and the destination IP is encapsulated as the VTEP IP of the situational awareness host machine corresponding to the target situational awareness, so as to obtain the encapsulated message. If the network type of the target situational awareness device is a VLAN network, the outer layer of the inner encapsulation result is encapsulated with the VLAN ID corresponding to the network where the target situational awareness device is located, to obtain the encapsulated packet.
3. The network traffic processing method according to any one of claims 1 to 2, characterized in that, The global label is a unique global label assigned by the SDN controller to each situational awareness device within the same VPC based on the characteristics and requirements of each VPC in the cloud network. The global label can be reused between different VPCs.
4. A network traffic processing method, characterized in that, The method, applied to a situational awareness host machine, includes: Receive the second Openflow flow table issued by the SDN controller. The second Openflow flow table is used to decapsulate the encapsulated packets. The system receives encapsulated packets forwarded by the host machine where the virtual machine resides. These encapsulated packets are obtained by the host machine based on the first OpenFlow flow table issued by the SDN controller, and by encapsulating the target packets in the operation and maintenance group table using inner and outer layers according to the global tag of the target situational awareness carried in the first OpenFlow flow table. The target packets are obtained by the host machine based on the first OpenFlow flow table, mirroring the network traffic to be monitored, and copying the target packets to the operation and maintenance group table based on the group table issued by the SDN controller. Based on the second Openflow flow table, the encapsulated packet is decapsulated to obtain the target packet, and the target packet is sent to the target situational awareness device for traffic monitoring and analysis; The step involves encapsulating the target message in the operation and maintenance group table with inner and outer layers based on the global tag of the target situational awareness device, resulting in an encapsulated message, including: Based on the global tag of the target situational awareness device, the target packet is encapsulated with an inner VLAN ID to obtain the inner encapsulation result; Based on the network type of the network where the target situational awareness device is located, the inner encapsulation result is encapsulated by an outer encapsulation to obtain the encapsulated message. When the network type of the target situational awareness device is a VXLAN network, the encapsulated message is parsed through the protocol stack to obtain the parsed message and the corresponding VXLANID and VLANID. Based on the VXLAN port corresponding to the VXLANID, the VLANID corresponding to the parsed packet is matched with the VLANID stored in the Openflow register. If the match is successful, the parsed packet is determined as the target packet.
5. The network traffic processing method according to claim 4, characterized in that, The process of decapsulating the encapsulated message to obtain the target message and sending the target message to the target situational awareness unit includes: When the network type of the target situational awareness device is a VXLAN network, the encapsulated message is parsed through the OS protocol stack to obtain the parsed message and the corresponding VXLAN ID and VLAN ID; Based on the VXLAN port corresponding to the VXLAN ID, the VLAN ID corresponding to the parsed packet is matched with the VLAN ID stored in the Openflow register. If the match is successful, the parsed packet is determined as the target packet. Based on the VLAN ID corresponding to the parsed packet, the corresponding target situational awareness is matched, and the target packet is sent to the target situational awareness. The global tag is a VLAN ID, and the Openflow register stores the unique VLAN ID assigned by the SDN controller to each situational awareness unit.
6. The network traffic processing method according to claim 4, characterized in that, The process of decapsulating the encapsulated message to obtain the target message and sending the target message to the target situational awareness unit includes: When the network type of the target situational awareness device is a VLAN network, the outer VLAN of the encapsulated packet is parsed through multi-level table processing, and the target situational awareness device is matched according to the inner VLAN ID of the encapsulated packet to obtain the target packet, and the target packet is sent to the target situational awareness device.
7. The network traffic processing method according to claim 6, characterized in that, The process involves parsing the outer VLAN of the encapsulated packet through multi-level table processing, matching the inner VLAN ID of the encapsulated packet with the target situational awareness device to obtain the target packet, and then sending the target packet to the target situational awareness device. The encapsulated packet is parsed using the first-level table to remove the outer VLAN of the encapsulated packet, and an intermediate result is obtained. The first VLAN ID of the outer VLAN is recorded in the Openflow register, and the intermediate result is sent to the second-level sub-table of the first priority in the second-level table. By stripping the inner layer of the intermediate result from the second-level sub-table of the first priority, it is determined whether the inner layer of the intermediate result has a second VLAN ID; If a second VLAN ID exists within the inner layer of the intermediate result, the intermediate result is parsed to obtain the target packet. The target situational awareness device is determined based on the second VLAN ID, and the target packet is sent to the target situational awareness device.
8. The network traffic processing method according to claim 7, characterized in that, The method further includes: If the inner layer of the intermediate result does not contain a second VLAN ID, the intermediate result is sent to the second-level sub-table of the second-level table with the second priority, where the first priority is higher than the second priority. The intermediate results are parsed using the second-level sub-table of the second priority to obtain a normal forwarding packet. The first VLAN ID is read from the Openflow register, and the normal forwarding packet is re-labeled with the first VLAN ID before being forwarded.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the computer program is executed by the processor, it implements the network traffic processing method as described in any one of claims 1 to 3, and / or implements the network traffic processing method as described in any one of claims 4 to 8.
Citation Information
Patent Citations
Method and system for implementing active-active communication of openflow switch
CN108390821A
Data transmission method and device, flow table configuration method and device, equipment and storage medium
CN114422471A