Data stream processing method and apparatus, computer device, and storage medium

By performing attribute identification and information acquisition on the data streams accessed by the splitter, the problem of encrypted traffic being repeatedly processed in multiple systems is solved, achieving efficient data stream information transmission and resource optimization.

CN119766562BActive Publication Date: 2025-12-12CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411973600.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-12-12
Estimated Expiration
2044-12-30

AI Technical Summary

Technical Problem

In existing technologies, after network device interfaces introduce network traffic into the splitter through optical splitting or mirroring, they cannot effectively distinguish encrypted traffic, resulting in resource waste and duplicate processing problems. In particular, encrypted traffic is repeatedly extracted from handshake message information and flow feature statistics in multiple systems.

Method used

By identifying the attributes of the data stream accessing the splitter and determining that it is an encrypted data stream, the data stream information is only obtained and sent to the backend system with the subscription relationship, thus avoiding repeated processing in multiple systems.

Benefits of technology

This enables data stream information to be acquired only once, reducing the processing difficulty and resource requirements of the backend system and avoiding resource waste.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119766562B_ABST
    Figure CN119766562B_ABST
Patent Text Reader

Abstract

The application relates to the fields of network technology and security technology, in particular to a data flow processing method and device, computer equipment and a storage medium. The method comprises the following steps: performing data flow attribute identification on a to-be-processed data flow accessed to a flow distributor; if the attribute identification result is that the to-be-processed data flow is an encrypted data flow, obtaining data flow information corresponding to the to-be-processed data flow; and sending the data flow information to a backend system having a subscription relationship with the to-be-processed data. According to the application, each backend system can obtain the data flow information corresponding to the to-be-processed data flow, and each backend system does not need to perform a data flow information obtaining process for the to-be-processed data flow, so that the difficulty of obtaining the data flow information by the backend system is reduced, and the required resource amount in the data flow processing process is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network technology and security technology, and in particular to a data flow processing method and device, computer equipment and a storage medium. BACKGROUND

[0002] The data flow of the interface between a plurality of network devices (such as gateways, switches, routers, etc.) can be accessed to a flow distributor through mirroring, light splitting, etc. The flow distributor can perform operations such as aggregation and distribution on these data flows and output them to a plurality of application systems (such as monitoring systems, business analysis systems, etc.) for subsequent processing. The flow distributor can perform aggregation and distribution according to different requirements of the application systems for the data flow.

[0003] However, in the prior art, network traffic is introduced into a flow distributor through light splitting or mirroring at the interface of a key network device, and then the flow distributor copies and distributes multiple copies to the back-end analysis system (such as a network security detection system, a malicious software detection system, etc.) for processing. There are problems such as being unable to copy and process only the encryption traffic category of interest (such as a malicious software detection system not needing to detect mainstream video application traffic) and the same encrypted original traffic being repeatedly processed for handshake message information extraction and flow feature statistics in multiple systems at the back end, thereby causing resource waste. SUMMARY

[0004] Therefore, it is necessary to provide a data flow processing method and device, computer equipment and a storage medium capable of preventing repeated processing of data flow messages in order to solve the above technical problems.

[0005] In a first aspect, the present application provides a data flow processing method. The method comprises:

[0006] performing data flow attribute identification on a to-be-processed data flow accessed to a flow distributor;

[0007] if the attribute identification result is that the to-be-processed data flow is an encrypted data flow, obtaining data flow information corresponding to the to-be-processed data flow;

[0008] sending the data flow information to a back-end system having a subscription relationship with the to-be-processed data.

[0009] In one embodiment, the data flow information comprises target handshake information and target feature information; obtaining the data flow information corresponding to the to-be-processed data flow comprises:

[0010] performing target handshake information extraction on the to-be-processed data flow to obtain the target handshake information in the data flow information;

[0011] performing feature information collection in the process of the to-be-processed data accessing the flow distributor to obtain the target feature information in the data flow information.

[0012] In one of the embodiments, the target feature information comprises at least one of a packet quantity, a rate, a flow duration, an average packet size, an average packet interval, a packet quantity in a specific packet length interval, and an average packet size / rate in a specific time period interval.

[0013] In one of the embodiments, the target handshake information comprises at least one of a server name indication (SNI), a resource directory indicator (RDI), and certification information.

[0014] In one of the embodiments, the data stream attribute identification of the to-be-processed data stream accessing the access splitter comprises:

[0015] determining whether a traffic protocol of the to-be-processed data stream is an encrypted protocol;

[0016] if yes, determining that the attribute identification result is that the to-be-processed data stream is an encrypted data stream; and if no, determining that the attribute identification result is that the to-be-processed data stream is a non-encrypted data stream.

[0017] In one of the embodiments, the method further comprises:

[0018] verifying whether the target handshake information matches a traffic replication rule;

[0019] if yes, sending a replicated data stream of the to-be-processed data stream to the backend system.

[0020] In a second aspect, the present application further provides a data stream processing apparatus. The apparatus comprises:

[0021] an identification module configured to perform data stream attribute identification on a to-be-processed data stream accessing an access splitter;

[0022] an acquisition module configured to, if the attribute identification result is that the to-be-processed data stream is an encrypted data stream, acquire data stream information corresponding to the to-be-processed data stream;

[0023] a sending module configured to send the data stream information to a backend system having a subscription relationship with the to-be-processed data.

[0024] In a third aspect, the present application further provides a computer device. The computer device comprises a memory and a processor, the memory stores a computer program, and the processor implements the following steps when executing the computer program:

[0025] performing data stream attribute identification on a to-be-processed data stream accessing an access splitter;

[0026] if the attribute identification result is that the to-be-processed data stream is an encrypted data stream, acquiring data stream information corresponding to the to-be-processed data stream.

[0027] sending the data stream information to a backend system having a subscription relationship with the to-be-processed data.

[0028] In a fourth aspect, the present application provides a computer readable storage medium. The computer readable storage medium has a computer program stored thereon, and the computer program, when executed by a processor, implements the following steps:

[0029] performing data stream attribute identification on a to-be-processed data stream accessing the access splitter;

[0030] if the attribute identification result is that the to-be-processed data stream is an encrypted data stream, obtaining data stream information corresponding to the to-be-processed data stream;

[0031] sending the data stream information to a backend system having a subscription relationship with the to-be-processed data.

[0032] In a fifth aspect, the present application provides a computer program product. The computer program product comprises a computer program, and the computer program, when executed by a processor, implements the following steps:

[0033] performing data stream attribute identification on a to-be-processed data stream accessing the access splitter;

[0034] if the attribute identification result is that the to-be-processed data stream is an encrypted data stream, obtaining data stream information corresponding to the to-be-processed data stream;

[0035] sending the data stream information to a backend system having a subscription relationship with the to-be-processed data.

[0036] The data stream processing method, device, computer device and storage medium described above perform data stream attribute identification on a to-be-processed data stream, obtain data stream information corresponding to the to-be-processed data stream in the case that the attribute identification result is that the to-be-processed data stream is an encrypted data stream, and then send the data stream information to a backend system having a subscription relationship with the to-be-processed data. According to the above content, it can be known that, in the process of processing the data stream, the present application does not use the method of sending the data stream to multiple backend systems and then extracting data stream information in the multiple backend systems in the prior art; instead, after determining that the to-be-processed data is an encrypted data stream, the data stream information corresponding to the to-be-processed data stream is obtained, and then the obtained data stream information is sent to a backend system having a subscription relationship with the to-be-processed data; so that only one step of data stream information acquisition is performed, each backend system can obtain the data stream information corresponding to the to-be-processed data stream, and each backend system does not need to perform a data stream information acquisition process for the to-be-processed data stream, thereby reducing the difficulty of the backend system in obtaining the data stream information and reducing the amount of resources required in the data stream processing process. Attached Figure Description

[0037] Figure 1 An application environment diagram of a data stream processing method provided in this application embodiment;

[0038] Figure 2 A flowchart illustrating the first data stream processing method provided in this application embodiment;

[0039] Figure 3 A flowchart illustrating the second data stream processing method provided in this application embodiment;

[0040] Figure 4 A flowchart illustrating the third data stream processing method provided in this application embodiment;

[0041] Figure 5 A flowchart illustrating the fourth data stream processing method provided in this application embodiment;

[0042] Figure 6 A schematic diagram illustrating a data stream processing method performed by a splitter, provided in an embodiment of this application;

[0043] Figure 7 A structural block diagram of a data stream processing device provided in an embodiment of this application;

[0044] Figure 8 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0045] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0046] The data stream processing method provided in this application embodiment can be applied to, for example, Figure 1The application environment shown. Among them, the terminal 102 communicates with the server 104 through the network. The data storage system can store the data required by the server 104 to process. The data storage system can be integrated on the server 104, or placed on the cloud or other network servers. According to the data stream attribute identification of the to-be-processed data stream, in the case that the attribute identification result is that the to-be-processed data stream is an encrypted data stream, the data stream information corresponding to the to-be-processed data stream is obtained, and then the data stream information is sent to the backend system which has a subscription relationship with the to-be-processed data. Among them, the terminal 102 can be, but not limited to, various personal computers, notebook computers, smart phones, tablet computers, Internet of Things devices and portable wearable devices, Internet of Things devices can be smart speakers, smart televisions, smart air conditioners, smart vehicle devices, etc. Portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The server 104 can be realized by an independent server or a server cluster composed of multiple servers.

[0047] In one embodiment, as shown in Figure 2 , a data stream processing method is provided, and the method is applied to the server 104 in Figure 1 for example, including the following steps:

[0048] S201, the data stream attribute identification of the to-be-processed data stream accessed to the access splitter is performed.

[0049] It should be noted that the data stream data can include but is not limited to encrypted data stream and non-encrypted data; therefore, when the data stream attribute identification of the to-be-processed data stream accessed to the access splitter is performed, it can be determined whether the to-be-processed data stream is encrypted, and then according to the encryption condition of the to-be-processed data stream, the data stream attribute of the to-be-processed data stream is determined.

[0050] Further, whether the to-be-processed data stream is encrypted can be determined by judging whether the flow protocol of the to-be-processed data stream is an encrypted flow protocol.

[0051] In an embodiment of the present application, when the data stream attribute identification of the to-be-processed data stream accessed to the access splitter is needed, the flow protocol of the to-be-processed data stream can be obtained, in the case that the flow protocol of the to-be-processed data stream is an encrypted flow protocol, it is determined that the attribute identification result is that the to-be-processed data stream is an encrypted data stream; in the case that the flow protocol of the to-be-processed data stream is a non-encrypted flow protocol, it is determined that the attribute identification result is that the to-be-processed data stream is a non-encrypted data stream.

[0052] S202, if the attribute identification result is that the to-be-processed data stream is an encrypted data stream, the data stream information corresponding to the to-be-processed data stream is obtained.

[0053] It should be noted that in the case of determining that the to-be-processed data is an encrypted data stream, a process of acquiring data stream information corresponding to the to-be-processed data stream is triggered, wherein the data stream information includes target handshake information and target feature information.

[0054] In an embodiment of the present application, if the attribute recognition result is that the to-be-processed data stream is an encrypted data stream, target handshake information extraction is performed on the to-be-processed data stream, and at the same time, statistics of target feature information are started.

[0055] S203, the data stream information is sent to the backend system having a subscription relationship with the to-be-processed data.

[0056] It should be noted that before the data stream information is sent to the backend system having a subscription relationship with the to-be-processed data, the subscription relationship between at least one backend system and the to-be-processed data stream can be verified; and then, according to the subscription relationship, the data stream information is sent to the backend system having a subscription relationship with the to-be-processed data.

[0057] In an embodiment of the present application, for each backend system, if there is a subscription relationship between a certain backend system and the to-be-processed data stream, and the subscription relationship indicates that the data stream information of the to-be-processed data stream needs to be acquired, the data stream information is sent to the backend system having a subscription relationship with the to-be-processed data.

[0058] Further description, it is also necessary to verify whether the target handshake information matches the traffic replication rule; if it matches, the replicated data stream of the to-be-processed data stream is sent to the backend system.

[0059] Among them, at least one handshake information is recorded in the traffic replication rule, if the handshake information of a certain data stream is the same as the handshake information recorded in the traffic replication rule, it is determined that the data stream needs to be replicated, and the replicated data stream after traffic replication is sent to the backend system having a subscription relationship with the data stream.

[0060] According to the above data stream processing method, data stream attribute identification is performed on the to-be-processed data stream, in a case where the attribute identification result is that the to-be-processed data stream is an encrypted data stream, data stream information corresponding to the to-be-processed data stream is acquired, and then the data stream information is sent to a backend system that has a subscription relationship with the to-be-processed data. According to the above content, it can be known that, in the process of processing the data stream, the method of sending the data stream to multiple backend systems in the prior art and then performing data stream information extraction in the multiple backend systems is not used; rather, after it is determined that the to-be-processed data is an encrypted data stream, the data stream information corresponding to the to-be-processed data stream is acquired, and then the acquired data stream information is sent to a backend system that has a subscription relationship with the to-be-processed data; so that only one step of data stream information acquisition is performed, each backend system can acquire the data stream information corresponding to the to-be-processed data stream, and each backend system does not need to perform a data stream information acquisition process for the to-be-processed data stream, thereby reducing the difficulty of the backend system in acquiring the data stream information and reducing the amount of resources required in the data stream processing process.

[0061] In an embodiment, the backend system subscribes to encrypted traffic based on handshake information filtered raw traffic, handshake message information, and flow feature statistical data through a shunt northbound interface. Specifically, (1) duplicate raw traffic: taking the subscription of raw traffic excluding mainstream video application as an example, the raw traffic with SNI not equal to list1 is subscribed. The content of list1 is the SNI set of mainstream video application; the handshake information includes but is not limited to SNI, RDI, and Certification; (2) flow feature statistical data includes but is not limited to packet quantity, rate, flow duration, average packet size, average packet interval, packet quantity statistics in a certain packet length interval, average packet size / rate statistics in a certain time interval, etc.

[0062] In an embodiment, as shown in Figure 3 The data stream information includes target handshake information and target feature information, so when the data stream information corresponding to the to-be-processed data stream needs to be acquired, the following content can be included:

[0063] S301, target handshake information extraction is performed on the to-be-processed data stream to obtain the target handshake information in the data stream information.

[0064] The target handshake information includes at least one of a server name indication SNI, a resource directory indicator RDI, and authentication information Certification.

[0065] S302, feature information collection is performed in the process of accessing the shunt by the to-be-processed data to obtain the target feature information in the data stream information.

[0066] The target feature information includes at least one of a packet quantity, a rate, a flow duration, an average packet size, an average packet interval, a packet quantity in a specific packet length interval, and an average packet size / rate in a specific time period interval.

[0067] In an embodiment of the present application, when the attribute identification result is that the to-be-processed data stream is an encrypted data stream, target handshake information extraction is performed on the to-be-processed data stream to obtain target handshake information in the data stream information, the collected target handshake information is sent to an XDR generation module, and at the same time, feature information collection is performed until the end of the flow in the process of the to-be-processed data accessing the flow distributor to obtain target feature information in the data stream information, the collected target feature information is sent to the XDR generation module, and the XDR generation module sends various corresponding XDR data in the data stream information to a backend system having a subscription relationship with the to-be-processed data.

[0068] The above data stream processing method can obtain target handshake information and target feature information by performing target handshake information extraction on the to-be-processed data stream and performing feature information collection in the process of the to-be-processed data accessing the flow distributor, so as to realize the step of obtaining data stream information only once, realize that each backend system obtains the data stream information corresponding to the to-be-processed data stream, and reduce the difficulty of the backend system obtaining the data stream information and the amount of resources required in the data stream processing process.

[0069] In an embodiment, as shown in Figure 4 When it is necessary to identify the data stream attribute of the to-be-processed data stream accessing the flow distributor, the following content can be included.

[0070] S401, determining whether the traffic protocol of the to-be-processed data stream is an encrypted protocol.

[0071] It should be noted that when it is necessary to determine whether the traffic protocol of the to-be-processed data stream is an encrypted protocol, it can be detected whether the traffic protocol is an encrypted protocol. Specifically, if it is determined that the traffic protocol is a known encrypted protocol such as HTTPS, SSL / TLS, VPN, SSH, etc., it is determined that the traffic protocol of the to-be-processed data stream is an encrypted protocol.

[0072] In an embodiment of the present application, at least an encrypted protocol white list can be preset, after determining the traffic protocol of the to-be-processed data stream, it is verified whether the traffic protocol belongs to the encrypted protocol white list, if it belongs, it is determined that the traffic protocol of the to-be-processed data stream is an encrypted protocol. The encrypted protocol white list records at least one encrypted protocol.

[0073] S402, if yes, determining that the attribute recognition result is that the to-be-processed data stream is an encrypted data stream; if no, determining that the attribute recognition result is that the to-be-processed data stream is a non-encrypted data stream.

[0074] In an embodiment of the present application, if it is determined that the attribute recognition result is that the to-be-processed data stream is an encrypted data stream, a subsequent step of acquiring data stream information corresponding to the to-be-processed data stream is performed; if it is determined that the attribute recognition result is that the to-be-processed data stream is a non-encrypted data stream, the to-be-processed data stream is processed by a non-encrypted traffic processing module.

[0075] The data stream processing method described above realizes different processing modes for processing the to-be-processed data stream according to the data stream attribute recognition result by determining whether the traffic protocol of the to-be-processed data stream is an encrypted protocol, thereby reducing the difficulty of the backend system in acquiring data stream information and reducing the amount of resources required in the data stream processing process.

[0076] In an embodiment, as shown in Figure 5 When the data stream information needs to be sent to a backend system having a subscription relationship with the to-be-processed data, the following content can be included:

[0077] S501, determining whether the traffic protocol of the to-be-processed data stream is an encrypted protocol.

[0078] S502, if yes, determining that the attribute recognition result is that the to-be-processed data stream is an encrypted data stream; if no, determining that the attribute recognition result is that the to-be-processed data stream is a non-encrypted data stream.

[0079] S503, if the attribute recognition result is that the to-be-processed data stream is an encrypted data stream, target handshake information of the to-be-processed data stream is extracted to obtain target handshake information in the data stream information.

[0080] S504, verifying whether the target handshake information matches a traffic replication rule.

[0081] S505, if yes, sending a replicated data stream of the to-be-processed data stream to the backend system.

[0082] S506, acquiring feature information in the data stream information in a process in which the to-be-processed data accesses a flow distributor.

[0083] S507, sending the data stream information to a backend system having a subscription relationship with the to-be-processed data.

[0084] Specifically, as shown in Figure 6As shown, when the encrypted traffic data stream enters the splitter, the splitter identifies that the data stream is an encrypted protocol such as HTTPS, QUIC, etc., extracts the information related to the service provider (including but not limited to SNI, RDN, and Certification, etc.) from the data stream handshake packet, and compares it with the rule configuration to determine whether to copy to the backend system according to the rule matching condition; at the same time, the splitter starts the flow feature statistics process in the memory, and the flow feature statistics can include but are not limited to the number of packets, the rate, the flow duration, the average packet size, the average packet interval, the packet number statistics in a certain packet length interval, the average packet size / rate statistics in a certain time interval, etc. When the splitter identifies that the flow is ended, according to the subscription content of the backend system, various xDRs containing the flow quintuple, the start and end time of the flow, the handshake packet information, various flow feature values, etc. are formed and output to the corresponding backend system.

[0085] According to the above data stream processing method, the data stream attribute of the to-be-processed data stream is identified, in a case where the attribute identification result is that the to-be-processed data stream is an encrypted data stream, the data stream information corresponding to the to-be-processed data stream is acquired, and then the data stream information is sent to a backend system having a subscription relationship with the to-be-processed data. According to the above content, it can be known that, in the process of processing the data stream, the method of sending the data stream to multiple backend systems in the prior art and then respectively extracting the data stream information in the multiple backend systems is not adopted; rather, after it is determined that the to-be-processed data is an encrypted data stream, the data stream information corresponding to the to-be-processed data stream is acquired, and then the acquired data stream information is sent to a backend system having a subscription relationship with the to-be-processed data; so that only one step of acquiring the data stream information is implemented, each backend system can acquire the data stream information corresponding to the to-be-processed data stream, and each backend system does not need to implement the data stream information acquisition process for the to-be-processed data stream, thereby reducing the difficulty of the backend system in acquiring the data stream information and reducing the amount of resources required in the data stream processing process.

[0086] It should be understood that, although each step in the flowchart involved in each of the above embodiments is displayed in sequence according to the arrow, these steps are not necessarily executed in sequence according to the order indicated by the arrow. Unless otherwise specified herein, the execution of these steps is not strictly limited in sequence, and these steps can be executed in other orders. Moreover, at least part of the steps in the flowchart involved in each of the above embodiments can include multiple steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily sequential, but can be executed in rotation or alternation with at least part of other steps or steps or stages in other steps.

[0087] Based on the same inventive concept, the embodiments of the present application further provide a data flow processing apparatus for implementing the data flow processing method described above. The implementation scheme of the apparatus for solving the problem is similar to the implementation scheme described in the above method, so the specific limitations in one or more data flow processing apparatus embodiments provided below can refer to the limitations of the data flow processing method described above, which will not be repeated here.

[0088] In one embodiment, as shown in Figure 7 a data flow processing apparatus is provided, comprising an identification module 10, an acquisition module 20 and a sending module 30, wherein:

[0089] The identification module 10 is configured to perform data flow attribute identification on the to-be-processed data flow accessing the flow distributor.

[0090] The acquisition module 20 is configured to acquire data flow information corresponding to the to-be-processed data flow if the attribute identification result is that the to-be-processed data flow is an encrypted data flow.

[0091] The sending module 30 is configured to send the data flow information to a backend system having a subscription relationship with the to-be-processed data.

[0092] In one embodiment, target handshake information is extracted from the to-be-processed data flow to obtain target handshake information in the data flow information.

[0093] In one embodiment, feature information is collected during the process of the to-be-processed data accessing the flow distributor to obtain target feature information in the data flow information.

[0094] In one embodiment, the target feature information includes at least one of the following: packet quantity, rate, flow duration, average packet size, average packet interval, packet quantity in a specific packet length interval, and average packet size / rate in a specific time period interval.

[0095] In one embodiment, the target handshake information includes at least one of the following: server name indication (SNI), resource directory indicator (RDI), and certification information (Certification).

[0096] In one embodiment, it is determined whether the traffic protocol of the to-be-processed data flow is an encrypted protocol.

[0097] If yes, it is determined that the attribute identification result is that the to-be-processed data flow is an encrypted data flow; if no, it is determined that the attribute identification result is that the to-be-processed data flow is a non-encrypted data flow.

[0098] In one embodiment, it is verified whether the target handshake information matches a traffic replication rule.

[0099] If yes, the replicated data flow of the to-be-processed data flow is sent to the backend system.

[0100] The data stream processing apparatus according to the above, according to the data stream to be processed, carries out data stream attribute identification, in the case of the attribute identification result that the data stream to be processed is an encrypted data stream, obtains the data stream information corresponding to the data stream to be processed, and then sends the data stream information to the back-end system which has a subscription relationship with the data to be processed. According to the above content, it can be known that in the process of processing the data stream, the method of sending the data stream to the back-end multiple systems and then extracting the data stream information in the back-end multiple systems is not adopted in the prior art; but after determining that the data to be processed is an encrypted data stream, the data stream information corresponding to the data to be processed is obtained, and then the obtained data stream information is sent to the back-end system which has a subscription relationship with the data to be processed; so as to realize that only one data stream information obtaining step is carried out, that is, each back-end system can obtain the data stream information corresponding to the data stream to be processed, and each back-end system does not need to carry out the data stream information obtaining process for the data stream to be processed, which reduces the difficulty of the back-end system obtaining the data stream information, and reduces the amount of resources required in the data stream processing process.

[0101] Each module in the data stream processing apparatus according to the above can be realized by software, hardware and a combination thereof in whole or in part. The above modules can be embedded in or independent of the processor in the computer device in hardware form, or can be stored in the memory in the computer device in software form, so as to be called and executed by the processor to execute the operations corresponding to the above modules.

[0102] In one embodiment, a computer device is provided, which can be a terminal, and the internal structure diagram thereof can be as shown in Figure 8The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. The processor, the memory, and the input / output interface are connected through a system bus. The communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. The processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for running the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is configured to exchange information between the processor and external devices. The communication interface of the computer device is configured to perform wired or wireless communication with external terminals. The wireless communication can be achieved through WIFI, mobile cellular network, NFC (Near Field Communication), or other technologies. The computer program is executed by the processor to implement a data stream processing method. The display unit of the computer device is configured to form a visually visible picture, which can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer overlaid on the display screen, or a key, trackball, or touchpad arranged on the shell of the computer device. The input device can also be an external keyboard, touchpad, or mouse, etc.

[0103] Those skilled in the art can understand that Figure 8 The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. A specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0104] In one embodiment, a computer device is provided, including a memory and a processor, the memory storing a computer program, and the processor implementing the following steps when executing the computer program:

[0105] Performing data stream attribute identification on the to-be-processed data stream accessed by the access shunt.

[0106] If the attribute identification result is that the to-be-processed data stream is an encrypted data stream, obtaining data stream information corresponding to the to-be-processed data stream.

[0107] Sending the data stream information to a backend system having a subscription relationship with the to-be-processed data.

[0108] In one embodiment, the processor further implements the following steps when executing the computer program:

[0109] Performing target handshake information extraction on the to-be-processed data stream to obtain target handshake information in the data stream information.

[0110] The feature information is collected in the process of the data access shunt to be processed, and target feature information in the data stream information is obtained.

[0111] In one embodiment, the processor, when executing the computer program, also implements the following steps:

[0112] The target feature information includes at least one of the following: packet quantity, rate, flow duration, average packet size, average packet interval, packet quantity in a specific packet length interval, and average packet size / rate in a specific time period interval.

[0113] In one embodiment, the processor, when executing the computer program, also implements the following steps:

[0114] The target handshake information includes at least one of the following: server name indication (SNI), resource directory indicator (RDI), and certification information.

[0115] In one embodiment, the processor, when executing the computer program, also implements the following steps:

[0116] Determine whether the traffic protocol of the data stream to be processed is an encrypted protocol.

[0117] If yes, determine that the attribute recognition result is that the data stream to be processed is an encrypted data stream; if no, determine that the attribute recognition result is that the data stream to be processed is a non-encrypted data stream.

[0118] In one embodiment, the processor, when executing the computer program, also implements the following steps:

[0119] Verify whether the target handshake information matches the traffic replication rule.

[0120] If matched, send the replicated data stream of the data stream to be processed to the backend system.

[0121] In one embodiment, a computer-readable storage medium is provided, and the computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the following steps are implemented:

[0122] Perform data stream attribute recognition on the data stream to be processed accessing the shunt.

[0123] If the attribute recognition result is that the data stream to be processed is an encrypted data stream, obtain data stream information corresponding to the data stream to be processed.

[0124] Send the data stream information to a backend system having a subscription relationship with the data to be processed.

[0125] In one embodiment, the computer program, when executed by the processor, also implements the following steps:

[0126] Target handshake information in the data stream information is obtained by performing target handshake information extraction on the to-be-processed data stream.

[0127] Target feature information in the data stream information is obtained by performing feature information collection on the to-be-processed data in the process of accessing the shunt.

[0128] In one embodiment, the computer program, when executed by the processor, further implements the following steps:

[0129] The target feature information includes at least one of the following: packet quantity, rate, flow duration, average packet size, average packet interval, packet quantity in a specific packet length interval, and average packet size / rate in a specific time period interval.

[0130] In one embodiment, the computer program, when executed by the processor, further implements the following steps:

[0131] The target handshake information includes at least one of the following: server name indication (SNI), resource directory indicator (RDI), and certification information.

[0132] In one embodiment, the computer program, when executed by the processor, further implements the following steps:

[0133] Determine whether the traffic protocol of the to-be-processed data stream is an encrypted protocol.

[0134] If yes, determine that the attribute recognition result is that the to-be-processed data stream is an encrypted data stream; if no, determine that the attribute recognition result is that the to-be-processed data stream is a non-encrypted data stream.

[0135] In one embodiment, the computer program, when executed by the processor, further implements the following steps:

[0136] Verify whether the target handshake information matches the traffic replication rule.

[0137] If matched, send the replicated data stream of the to-be-processed data stream to the backend system.

[0138] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the following steps:

[0139] Perform data stream attribute recognition on the to-be-processed data stream accessing the shunt.

[0140] If the attribute recognition result is that the to-be-processed data stream is an encrypted data stream, obtain data stream information corresponding to the to-be-processed data stream.

[0141] Send the data stream information to a backend system that has a subscription relationship with the to-be-processed data.

[0142] In one embodiment, the computer program, when executed by the processor, further implements the following steps:

[0143] Target handshake information is extracted from the to-be-processed data stream to obtain target handshake information in the data stream information.

[0144] Feature information is collected in the process of accessing the data shuffler by the to-be-processed data to obtain target feature information in the data stream information.

[0145] In one embodiment, the computer program, when executed by the processor, further implements the following steps:

[0146] The target feature information includes at least one of the following: packet quantity, rate, flow duration, average packet size, average packet interval, packet quantity in a specific packet length interval, and average packet size / rate in a specific time period interval.

[0147] In one embodiment, the computer program, when executed by the processor, further implements the following steps:

[0148] The target handshake information includes at least one of the following: server name indication (SNI), resource directory indicator (RDI), and certification information.

[0149] In one embodiment, the computer program, when executed by the processor, further implements the following steps:

[0150] It is determined whether the traffic protocol of the to-be-processed data stream is an encrypted protocol.

[0151] If yes, it is determined that the attribute recognition result is that the to-be-processed data stream is an encrypted data stream; if no, it is determined that the attribute recognition result is that the to-be-processed data stream is a non-encrypted data stream.

[0152] In one embodiment, the computer program, when executed by the processor, further implements the following steps:

[0153] It is verified whether the target handshake information matches the traffic replication rule.

[0154] If matched, the replicated data stream of the to-be-processed data stream is sent to the backend system.

[0155] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use, and processing of related data need to comply with relevant laws, regulations, and standards of relevant countries and regions.

[0156] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when the computer program is executed, the processes of the above-mentioned embodiments of the methods can be included. Any reference to memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. The non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric memory (FRAM), phase change memory (PCM), graphene memory, etc. The volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration but not limitation, the RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., without being limited thereto.

[0157] Any combination of the technical features of the above embodiments can be made. In order to make the description simple, all possible combinations of the technical features in the above embodiments are not described, however, as long as the combination of the technical features does not exist, it should be considered as the scope of the present application.

[0158] The above embodiments only express several implementation manners of the present application, and the description is more specific and detailed, but it should not be understood as a limitation on the scope of the patent of the present application. It should be pointed out that for ordinary skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are all within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A method of data flow processing, the method comprising: The method comprises: performing data stream attribute identification on a to-be-processed data stream accessing a flow distributor; if the attribute identification result is that the to-be-processed data stream is an encrypted data stream, performing target handshake information extraction on the to-be-processed data stream to obtain target handshake information in data stream information; performing feature information collection in the process of the to-be-processed data stream accessing the flow distributor to obtain target feature information in the data stream information; sending the data stream information to a backend system having a subscription relationship with the to-be-processed data, wherein the data stream information comprises the target handshake information and the target feature information; verifying whether the target handshake information matches a traffic replication rule; if the target handshake information matches the traffic replication rule, sending a replicated data stream of the to-be-processed data stream to the backend system.

2. The method of claim 1, wherein, The target feature information comprises at least one of a packet quantity, a rate, a flow duration, an average packet size, an average packet interval, a packet quantity in a specific packet length interval, and an average packet size / rate in a specific time period interval.

3. The method of claim 1, wherein, The target handshake information comprises at least one of a server name indication (SNI), a resource directory indicator (RDI), and certification information.

4. The method according to any one of claims 1-3, characterized in that, The data stream attribute identification on the to-be-processed data stream accessing the flow distributor comprises: determining whether a traffic protocol of the to-be-processed data stream is an encrypted protocol; if yes, determining that the attribute identification result is that the to-be-processed data stream is an encrypted data stream; and if no, determining that the attribute identification result is that the to-be-processed data stream is a non-encrypted data stream.

5. A data flow processing apparatus, characterized by The apparatus comprises: an identification module configured to perform data stream attribute identification on a to-be-processed data stream accessing a flow distributor; an acquisition module configured to, if the attribute identification result is that the to-be-processed data stream is an encrypted data stream, perform target handshake information extraction on the to-be-processed data stream to obtain target handshake information in data stream information, and perform feature information collection in the process of the to-be-processed data stream accessing the flow distributor to obtain target feature information in the data stream information; a sending module configured to send the data stream information to a backend system having a subscription relationship with the to-be-processed data, wherein the data stream information comprises the target handshake information and the target feature information, and verify whether the target handshake information matches a traffic replication rule; if the target handshake information matches the traffic replication rule, send a replicated data stream of the to-be-processed data stream to the backend system.

6. The apparatus of claim 5, wherein, The target feature information comprises at least one of a packet quantity, a rate, a flow duration, an average packet size, an average packet interval, a packet quantity in a specific packet length interval, and an average packet size / rate in a specific time period interval.

7. The apparatus of claim 5, wherein, The target handshake information comprises at least one of a server name indication (SNI), a resource directory indicator (RDI), and certification information.

8. A computer device comprising a memory and a processor, the memory storing a computer program, characterized in that, The processor, when executing the computer program, implements the steps of the method of any one of claims 1 to 4.

9. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program, when executed by the processor, implements the steps of the method of any one of claims 1 to 4.

10. A computer program product comprising a computer program, characterized in that, The computer program, when executed by the processor, implements the steps of the method of any one of claims 1 to 4.

Citation Information

Patent Citations

  • Application identification method, system and equipment for encrypted traffic

    CN112751802A

  • Identification of a protocol of a data stream

    WO2020008159A1