Network traffic-based operation and maintenance method and device, electronic equipment and storage medium

By conducting multi-dimensional and detailed monitoring and in-depth analysis of network traffic, the system addresses issues such as insufficient encrypted traffic analysis capabilities, ineffective traffic policy monitoring, inadequate TCP connection analysis, and cross-regional integrated analysis in the financial industry's network traffic monitoring, thereby improving the stability and reliability of network services.

CN119788542BActive Publication Date: 2026-01-23中国邮政储蓄银行股份有限公司
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411871188.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-18
Publication Date
2026-01-23
Estimated Expiration
2044-12-18

AI Technical Summary

Technical Problem

Existing technologies for network traffic monitoring in the financial industry suffer from insufficient encrypted traffic analysis capabilities, lack of effective monitoring of traffic strategies, insufficient TCP connection analysis capabilities, inadequate traffic content mining capabilities, and a lack of means to comprehensively analyze cross-carrier lines and cross-regional network traffic, leading to increased network risks and operational difficulties.

Method used

By collecting and analyzing network traffic data, and combining cross-regional, sensitive traffic, cross-carrier lines, and HTTP protocol decoding, we conduct in-depth analysis, establish a hardware SSL resource pool for HTTPS traffic, deploy traffic collection devices for real-time monitoring and anomaly detection, and use TCP connection health analysis indicators for network operation and maintenance.

Benefits of technology

It enables in-depth analysis of encrypted traffic, identification and location of packet loss issues, assessment of TCP connection stability, optimization of cross-carrier lines and cross-center traffic, improvement of network service stability and reliability, and ensures data center security and network performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788542B_ABST
    Figure CN119788542B_ABST
Patent Text Reader

Abstract

The application discloses an operation and maintenance method and device based on network traffic, electronic equipment and a storage medium. The method comprises the following steps: collecting network traffic data in a first mode; analyzing the network traffic data in a second mode; and obtaining index monitoring data of the network traffic according to the analysis result of the network traffic data, so as to realize network operation and maintenance of a data center. The application realizes fine monitoring and in-depth analysis of network traffic. The application provides a network traffic monitoring and analysis scheme based on multi-dimensional fine analysis, which can ensure the stability and reliability of network services. The application also provides a network operation scheme of the data center, which provides strong technical support for business innovation and customer service.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data center network operation and maintenance technology, and in particular to an operation and maintenance method, device, electronic equipment, and storage medium based on network traffic. Background Technology

[0002] As the financial industry moves towards digital transformation, the rapid development of business has led to a surge in application systems, which in turn has resulted in an expansion of network scale and increased complexity, significantly increasing network risks and operational difficulties.

[0003] In related technologies, network traffic monitoring of data centers is limited to rough monitoring and simple analysis, and systematic operation and maintenance solutions are lacking. Summary of the Invention

[0004] This application provides a network traffic-based operation and maintenance method, device, electronic device, and storage medium to comprehensively monitor and analyze network traffic in detail by integrating multiple key dimensions.

[0005] The embodiments of this application adopt the following technical solutions:

[0006] In a first aspect, embodiments of this application provide an operation and maintenance method based on network traffic, wherein the operation and maintenance method includes:

[0007] Network traffic data was collected using the first method;

[0008] The network traffic data is analyzed based on the second method; and

[0009] Based on the analysis results of the network traffic data, network traffic indicator monitoring data is obtained to realize network operation and maintenance of the data center.

[0010] In some embodiments, the collection of network traffic data according to the first method includes:

[0011] The corresponding network traffic data was collected using a cross-regional approach;

[0012] Encrypted traffic data was collected from network traffic data according to the sensitive traffic method.

[0013] in,

[0014] The cross-regional nature of the data center includes different security zones within the data center, and the sensitive traffic includes HTTP traffic.

[0015] In some embodiments, the analysis of the network traffic data based on the second method includes:

[0016] Based on the traffic on different network device interfaces and network operator lines, analyze network traffic data across operator lines and across centers;

[0017] Network traffic data based on HTTP protocol decoding and analysis of HTTP traffic content;

[0018] Based on network packet loss, we analyze the network traffic data corresponding to the adoption of traffic strategies.

[0019] In some embodiments, the step of collecting the corresponding network traffic data in a cross-regional manner includes:

[0020] Based on the division relationship and location information of different security zones in the data center, the boundary of the area to be monitored is determined;

[0021] Determine the data flow access rules between different security zones;

[0022] Based on the boundaries of the area to be monitored and the data flow access rules between the various security areas, determine the traffic collection points on the boundaries of each security area.

[0023] Based on the traffic acquisition points at the boundaries of each security zone, deploy traffic acquisition devices and capture sensitive traffic data transmitted across zones in real time;

[0024] Based on the sensitive traffic data, abnormal behavior or potential security threats in cross-regional data transmission can be identified through real-time monitoring and anomaly detection strategies.

[0025] In some embodiments, the step of collecting encrypted traffic data from network traffic data according to a sensitive traffic method includes:

[0026] Establish a hardware SSL resource pool for HTTPS traffic;

[0027] Based on the hardware SSL resource pool, HTTPS traffic is centrally decrypted and processed.

[0028] Collect the decrypted data traffic and distribute the decrypted data traffic mirrored to security tools;

[0029] The security tools described herein are used to analyze and monitor network attack traffic data, and to issue alerts regarding the network attack traffic data.

[0030] In some embodiments, based on the analysis results of the network traffic data, network traffic indicator monitoring data is obtained to achieve network operation and maintenance of the data center, including:

[0031] Based on the analysis results of the network traffic data, the TCP connection health analysis index of the network traffic is obtained;

[0032] Based on any one or more of the TCP connection health analysis metrics, such as the number of connection establishment failures, retransmission rate, and combinations thereof, network operation and maintenance of the data center can be achieved by issuing alarms for abnormal results of the TCP connection health analysis metrics.

[0033] In some embodiments, the method further includes:

[0034] Network traffic data is collected from the hardware SSL offloading device of the data center in accordance with the first method;

[0035] Based on the static resources in the network traffic data of the data center, network traffic indicator monitoring data is obtained.

[0036] Secondly, embodiments of this application also provide a network traffic-based operation and maintenance (O&M) system, wherein the O&M device includes:

[0037] The first module is used to collect network traffic data according to the first method;

[0038] The second module is used to analyze the network traffic data based on the second method; and

[0039] The operation and maintenance module is used to obtain network traffic indicator monitoring data based on the analysis results of the network traffic data, so as to realize the network operation and maintenance of the data center.

[0040] Thirdly, embodiments of this application also provide an electronic device, including: a processor; and a memory arranged to store computer-executable instructions, which, when executed, cause the processor to perform the above-described method.

[0041] Fourthly, embodiments of this application also provide a computer-readable storage medium that stores one or more programs, which, when executed by an electronic device including multiple applications, cause the electronic device to perform the above-described method.

[0042] The above-mentioned at least one technical solution adopted in the embodiments of this application can achieve the following beneficial effects: network traffic data is collected in a first manner and analyzed in a second manner. Then, based on the analysis results of the network traffic data, network traffic indicator monitoring data is obtained to realize network operation and maintenance of the data center. Through refined processing of traffic data collection, traffic data analysis and traffic data indicators in multiple dimensions, operation and maintenance in the data center is realized to ensure the stability and reliability of network services. Attached Figure Description

[0043] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0044] Figure 1 This is a schematic diagram of the data center architecture in the network traffic-based operation and maintenance method in the embodiments of this application;

[0045] Figure 2 This is a flowchart illustrating the network traffic-based operation and maintenance method in the embodiments of this application;

[0046] Figure 3 This is a schematic diagram of the network traffic-based operation and maintenance device in the embodiments of this application;

[0047] Figure 4 This is a schematic diagram of the structure of an electronic device according to an embodiment of this application. Detailed Implementation

[0048] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0049] Network traffic monitoring and analysis methods in related technologies are mainly used to accurately monitor network traffic, analyze network traffic trends and abnormal behaviors, thereby ensuring the optimal allocation of network resources and the timely detection and identification of risks.

[0050] With the rapid development and increasing complexity of financial services, the network risks and operational difficulties have risen significantly. Traditional network traffic monitoring and analysis methods have shown their limitations, proving inadequate in handling encrypted traffic analysis, traffic content analysis, traffic policy packet loss detection, TCP connection stability assessment, and effective multi-line and multi-center traffic management. To meet current network operation and maintenance needs, it is necessary to improve and innovate network traffic monitoring and analysis methods. Existing network traffic monitoring has the following drawbacks:

[0051] (1) Insufficient encrypted traffic analysis capabilities: With the continuous development of cloud era and mobile Internet technology, the banking industry has fully entered the digital age, and business scenarios are becoming more and more complex, especially Internet business scenarios, which have led to an increasing number of network traffic transmitted through HTTPS protocol encryption. HTTPS protocol protects the integrity and privacy of data through encryption technology, but this encryption also brings challenges to security analysis, which requires improving the ability to analyze secure traffic.

[0052] (2) Lack of effective monitoring of traffic policies: Rate limiting policies are a common traffic management tool used to control the use of network resources and prevent certain traffic from consuming excessive bandwidth. If rate limiting policies are set improperly or monitored inadequately, it may lead to packet loss and other network problems. Effective monitoring and detection of packet loss caused by rate limiting policies are necessary, and traffic policies should be adjusted in a timely manner to ensure the stability of services.

[0053] (3) Insufficient TCP connection analysis capabilities: Traditional network traffic monitoring often focuses on macro indicators such as bandwidth usage and packet transmission rate, while the assessment of the health status of TCP connections is not in-depth enough. In order to more effectively identify and locate network faults, more detailed monitoring and analysis of TCP connections are needed.

[0054] (4) Insufficient traffic content mining capabilities: With the rapid development of business and frequent version iterations, the updating and adjustment of static resources have become increasingly frequent. In this situation, if there is a lack of effective analysis of network traffic content, a large number of static resources may fail to be accessed through optimized technologies such as Content Delivery Networks (CDNs). This will cause non-real-time transaction file transfer traffic to consume valuable Internet bandwidth resources, negatively impacting the operating efficiency of business systems and user experience.

[0055] (5) Lack of comprehensive analysis methods for cross-carrier lines and cross-regional network traffic: In modern network environments, to ensure high availability and performance of services, a multi-line load balancing strategy is typically adopted. However, the peak traffic times for each line may differ, requiring comprehensive analysis to accurately assess the actual traffic of a specific system at a specific moment. Given the complexity of internet applications, especially scenarios involving multiple carrier lines and multiple data center exits, accurate monitoring of overall system traffic across lines and data centers becomes particularly important. This is not only related to the accuracy of capacity planning and assessment but also crucial for ensuring service quality and user experience.

[0056] To address the aforementioned shortcomings, this application provides a network traffic-based operation and maintenance method in its embodiments. This method achieves fine-grained monitoring and in-depth analysis of network traffic by integrating multiple key dimensions. It not only significantly enhances the ability to analyze encrypted traffic but also deeply analyzes traffic content, accurately identifies and locates packet loss issues, measures the stability of TCP connections, and effectively monitors complex network traffic across carrier lines and data centers.

[0057] The technical solutions provided by the various embodiments of this application are described in detail below with reference to the accompanying drawings.

[0058] This application provides an operation and maintenance method based on network traffic, such as... Figure 2 The diagram illustrates a network traffic-based operation and maintenance method in this embodiment of the application. The method includes at least the following steps S210 to S230:

[0059] Step S210: Collect network traffic data according to the first method.

[0060] like Figure 1 The diagram shown is a schematic of a data center architecture. A data center can include multiple data centers 1, data center 2, etc., corresponding to data centers deployed in different regions or remotely.

[0061] "Network traffic data" refers to the traffic data in network devices and connected devices in a data center.

[0062] The network traffic data that needs to be monitored can be collected using the first method. The first method includes, but is not limited to, any traffic collection method or any optimization method of traffic collection.

[0063] For example, cross-regional traffic and encrypted traffic are collected according to the first method. It can be understood that cross-regional traffic mainly refers to traffic data between different data centers, and encrypted traffic mainly refers to encrypted traffic data within a data center or between different data centers.

[0064] Step S220: Analyze the network traffic data based on the second method.

[0065] The second approach to analyzing network traffic data allows for the monitoring and analysis of data flow through the network, providing insights into the traffic patterns on different lines. This second approach includes, but is not limited to, any traffic analysis method or any optimized version of traffic analysis.

[0066] It is understood that "first method" or "first approach" is used only to refer to a certain collection or analysis method and is not used to limit the specific implementation method in the embodiments of this application.

[0067] For example, analyzing network traffic data based on the second method includes comprehensive analysis of cross-carrier lines and cross-center network traffic, HTTP traffic content analysis, and traffic strategy analysis.

[0068] Step S230: Based on the analysis results of the network traffic data, obtain network traffic indicator monitoring data to realize network operation and maintenance of the data center.

[0069] The network traffic data is analyzed to obtain corresponding analysis results, including the detection and analysis results of the traffic data. Based on these results, network traffic indicator monitoring data can be obtained, and network operation and maintenance of the data center can be implemented based on whether the indicator monitoring data is abnormal. The network traffic indicator monitoring data includes at least TCP connection stability indicators.

[0070] The above method first collects network traffic data using the first approach, then analyzes the network traffic data using the second approach, and finally obtains network traffic indicator monitoring data based on the analysis results, thereby achieving network operation and maintenance of the data center. Through refined optimization of network traffic data collection, analysis, and indicator monitoring, collection efficiency is improved, unified monitoring and analysis of traffic across multiple lines and data centers is achieved, in-depth analysis of HTTP static resource content is conducted, and early warning and judgment of key indicators are provided.

[0071] By comprehensively considering multiple key dimensions of traffic, the above methods enable refined monitoring and in-depth analysis of network traffic. This not only enhances the ability to analyze encrypted traffic but also delves deeper into traffic content, accurately detects and diagnoses packet loss issues, assesses TCP connection stability, and effectively manages and optimizes complex network traffic across carrier lines and data centers. Furthermore, it strengthens the understanding and control of network traffic, providing more powerful and flexible tools for network operations and maintenance, thereby improving the overall efficiency and reliability of network operations and providing technical support for business innovation and customer service.

[0072] Unlike related technologies that uniformly collect decrypted network traffic data for monitoring, traditional network traffic monitoring suffers from this problem. The method described above, with its refined traffic collection dimensions, allows for more effective monitoring and analysis of HTTPS traffic. Refined traffic analysis dimensions can identify frequently accessed static resources. Refined traffic metrics dimensions not only accelerate problem localization but also improve the monitoring and optimization of TCP connection quality.

[0073] In one embodiment of this application, the step of collecting network traffic data in a first manner includes: collecting corresponding network traffic data in a cross-regional manner; and collecting encrypted traffic data in the network traffic data in a sensitive traffic manner; wherein, the cross-regional manner includes different security zones in the data center, and the sensitive traffic includes HTTP traffic.

[0074] For data centers that may span multiple centers or regions, considering that cross-firewall traffic involves data exchange between network zones with different security levels, strict security monitoring and filtering mechanisms are required to prevent potential network attacks and data breaches. Collecting network traffic data in a cross-regional manner enables effective monitoring of traffic between these critical security zones. Current regional technologies can only analyze traffic data from a single center or line, lacking the ability for comprehensive multi-center analysis. A cross-regional approach allows for real-time monitoring of traffic between network zones and enables comprehensive traffic analysis using security tools, quickly identifying and responding to security threats. This helps ensure data center security, optimize cross-regional network traffic management, and enhance the overall network's defense capabilities.

[0075] By collecting encrypted traffic data from network traffic data using the sensitive traffic method, it is possible to effectively process HTTP traffic and perform in-depth security analysis. The entire process design based on the sensitive traffic method fully considers the balance between efficiency and security, ensuring both high-efficiency data collection and data security and privacy. It solves the problem of insufficient encrypted traffic analysis capabilities in related technologies. It also addresses the lack of means in related technologies to comprehensively analyze cross-carrier lines and cross-regional network traffic.

[0076] By refining the traffic collection dimensions described above, sensitive cross-regional network traffic can be collected to promptly detect security threats. HTTPS traffic undergoes centralized decryption, and the decrypted data is then collected uniformly, ensuring both high efficiency and data security and privacy. This approach allows for more effective monitoring and analysis of HTTPS traffic, enabling timely detection and response to various cybersecurity challenges.

[0077] In one embodiment of this application, the analysis of network traffic data based on the second method includes: analyzing cross-carrier lines and cross-center network traffic data based on traffic on different network device interfaces and network operator lines; analyzing network traffic data of HTTP traffic content based on HTTP protocol decoding; and analyzing network traffic data corresponding to the adoption of traffic strategies based on network packet loss.

[0078] Cross-carrier line and cross-data center network traffic coordination analysis refers to the use of a global traffic definition method based on IP and port information to integrate traffic on different network device interfaces and carrier lines when multiple network devices, multiple carrier lines, and multiple data centers are involved. This achieves unified monitoring and analysis of traffic across multiple lines and multiple data centers.

[0079] HTTP traffic content analysis refers to the in-depth analysis of HTTP traffic content through decoding the HTTP protocol and analyzing other key information. The analysis can yield information such as URI type, the number of requests / responses for different URIs, and page size. By analyzing the number of requests / responses for different URIs, frequently accessed static resources, such as images, videos, stylesheets, and scripts, can be identified.

[0080] Preferably, for the static resources, Content Delivery Network (CDN) technology can be used to cache the website's static content (such as images, videos, style sheets, and scripts) on a distributed server. This reduces the pressure on the intranet's bandwidth, shortens access latency, and improves the reliability of content delivery. This solves the problem of insufficient traffic content mining capabilities in related technologies.

[0081] Traffic strategy analysis refers to the traffic strategies implemented at critical network locations such as backbone networks and the Internet to ensure the rational allocation of network resources and the stable operation of systems. In the embodiments of this application, daily monitoring of network packet loss is performed. Specifically, automated methods are used to periodically inspect devices, automatically comparing packet loss data from the current time with the same period of the previous day. If an increase in packet loss is detected, it usually indicates that a system has experienced a traffic peak and may have reached its rate limit. Comparative analysis of network packet loss helps to promptly identify potential traffic management and network performance issues, and allows for timely adjustments to rate limiting strategies based on the analysis results, ensuring stable business operation. This solves the problem of the lack of effective monitoring of traffic strategies in related technologies.

[0082] By refining the traffic analysis dimensions described above, and comprehensively analyzing traffic across operator lines and data centers, a more holistic perspective can be provided for network management decisions. This allows for a clearer view of the overall traffic situation across lines and data centers, optimizing overall network performance. Analyzing HTTP traffic content identifies frequently accessed static resources, enabling the use of CDN technology to cache these resources, reducing pressure on intra-industry internet bandwidth, shortening access latency, and improving the reliability of content delivery. Furthermore, automated inspection methods monitor and analyze packet loss in traffic strategies, promptly identifying potential traffic management and network performance issues.

[0083] In one embodiment of this application, the step of collecting corresponding network traffic data in a cross-regional manner includes: determining the boundaries of the areas to be monitored based on the division relationship and location information of different security zones in the data center; determining the data flow access rules between each security zone; determining traffic collection points on the boundaries of each security zone based on the boundaries of the areas to be monitored and the data flow access rules between each security zone; deploying traffic collection devices and capturing sensitive traffic data transmitted across regions in real time based on the traffic collection points on the boundaries of each security zone; and obtaining abnormal behavior or potential security threats in cross-regional data transmission based on the sensitive traffic data through real-time monitoring and anomaly detection strategies.

[0084] Data centers are typically divided into multiple virtual security zones, such as a production core zone, a production external zone, and an internet zone. These zones are segmented using firewalls or physical isolation to protect data security in high-security areas. Cross-firewall traffic involves data exchange between network zones of different security levels, such as communication between the production external zone and the core production zone. Therefore, strict security monitoring and filtering mechanisms are required to prevent potential network attacks and data breaches.

[0085] To achieve effective monitoring of traffic between these critical security zones, in the embodiments of this application, S1, network segmentation and analysis: First, the division and location of different security zones in the data center are clarified to identify the boundaries of the areas that need to be monitored. S2, mutual access rule confirmation: The data flow access rules between each security zone are determined, clarifying which traffic is legitimate cross-zone access and which is potential abnormal behavior. S3, traffic collection point confirmation: Based on the information from the first two steps, traffic collection points on the boundaries of each security zone are determined. These points are usually set on critical network nodes to ensure comprehensive collection of cross-zone traffic. S4, sensitive traffic collection: At the determined collection points, traffic collection devices are deployed to capture sensitive traffic data transmitted across zones in real time. This data will be sent to security tools for in-depth analysis. S5, real-time monitoring and anomaly detection: Based on the collected traffic data, abnormal behavior or potential security threats in cross-zone data transmission are detected in a timely manner through real-time monitoring and anomaly detection technologies to prevent data leakage and network attacks.

[0086] It is understood that the security tools mentioned include, but are not limited to, intrusion detection systems and data loss prevention systems. It should be noted that the critical network nodes include, but are not limited to, firewalls and routers.

[0087] This method enables real-time monitoring of traffic between network areas and allows for comprehensive traffic analysis using security tools. It enables rapid identification and response to security threats, helping to ensure data center security, optimize cross-regional network traffic management, and enhance the overall network's defense capabilities.

[0088] In one embodiment of this application, the step of collecting encrypted traffic data from network traffic data according to the sensitive traffic method includes: establishing a hardware SSL resource pool for HTTPS traffic; centrally decrypting HTTPS traffic according to the hardware SSL resource pool; collecting the decrypted data traffic and distributing the decrypted data traffic mirror to security tools; analyzing and monitoring network attack traffic data through the security tools, and issuing alarms for the network attack traffic data.

[0089] The encrypted traffic collection process mainly includes: S1, building a dedicated hardware SSL resource pool for centralized management and decryption of HTTPS traffic; S2, centrally decrypting HTTPS traffic through the hardware SSL resource pool, which not only optimizes resource utilization but also ensures the efficiency of data collection; S3, uniformly collecting decrypted data traffic and distributing the decrypted traffic image to various security tools; S4, using security tools to conduct targeted network attack traffic monitoring and analysis; and S5, transmitting alarm logs to the situational awareness platform for unified analysis and handling.

[0090] The aforementioned encrypted traffic collection method strikes a balance between efficiency and security, ensuring both high-efficiency data collection and data security and privacy. This approach allows for more effective monitoring and analysis of HTTPS traffic, enabling timely detection and response to various potential cybersecurity risks.

[0091] In one embodiment of this application, network traffic indicator monitoring data is obtained based on the analysis results of the network traffic data to realize network operation and maintenance of the data center. This includes: obtaining TCP connection health analysis indicators of network traffic based on the analysis results of the network traffic data; and using any one or more indicators from the TCP connection health analysis indicators, such as the number of connection establishment failures, retransmission rate, and combinations of the number of connection establishment failures and retransmission rate, to issue alarms for abnormal results of the TCP connection health analysis indicators, thereby realizing network operation and maintenance of the data center.

[0092] Health analysis indicators include, but are not limited to, the number of connection failures, the retransmission rate, and a combination of the number of connection failures and the retransmission rate. Specifically, the number of connection failures refers to the number of times all SYN packets are retransmitted and SYN packets fail to respond within the current time. In the TCP three-way handshake process, if a SYN packet does not receive a SYN+ACK response packet in a timely manner within a specific time, it will be marked as a connection failure. This includes two possible phenomena: (1) The SYN packet is retransmitted multiple times, and if the interval between each retransmission exceeds a specific time, it is marked as a connection failure. (2) The SYN packet is not retransmitted, and the connection is forcibly broken directly by RST, which is also marked as a connection failure. In the embodiments of this application, by monitoring the number of connection failures, the quality of TCP connections can be quickly identified and diagnosed, which helps to discover potential network problems, such as network congestion, configuration errors, or hardware failures, which may lead to connection establishment failure or delay.

[0093] The retransmission rate refers to the ratio of the total number of retransmitted packets to the total number of packets. Reasons for retransmission include network layer packet loss, server non-response or dropping of the data packet, and spurious retransmissions. Combining the analysis of connection failures and the retransmission rate allows for the construction of a highly efficient combined alarm system, significantly improving the speed and accuracy of problem localization. This analytical method can quickly distinguish whether the root cause of the problem lies at the network layer or the service layer, thus enabling targeted solutions. If there are a large number of connection failures with a low retransmission rate, this may indicate a network connectivity problem; if connections are successfully established but the number of retransmitted packets is high, this may indicate insufficient server processing capacity.

[0094] Furthermore, considering that TCP connection quality includes not only the efficiency of connection establishment and data transmission, but also the stability and reliability of the connection, monitoring the number of connection failures and retransmission rates can promptly identify and resolve issues affecting TCP connection quality, ensuring efficient and stable network communication. In other words, combining the analysis of connection failures and retransmission rates not only accelerates problem localization but also strengthens the monitoring of TCP connection quality. This helps ensure efficient, stable, and secure network communication, providing users with a better service experience. This addresses the problem of insufficient TCP connection analysis capabilities in related technologies.

[0095] By refining the aforementioned traffic metrics, indicators such as the number of connection failures and retransmission rate were established. Combining these two metrics for analysis overcomes the shortcomings of traditional monitoring methods (which often focus only on network layer connectivity metrics, lacking analysis of TCP connection quality). This not only accelerates problem localization but also improves the monitoring and optimization of TCP connection quality. This helps ensure efficient, stable, and secure network communication, providing users with a better service experience.

[0096] In one embodiment of this application, the method further includes: collecting network traffic data from the hardware SSL offloading device of the data center in a first manner; and obtaining network traffic indicator monitoring data based on the static resources in the network traffic data of the data center.

[0097] In the embodiments of this application, the traffic collection dimension includes the collection of cross-network security zone traffic, the centralized construction of hardware SSL offloading devices, and the centralized collection of encrypted traffic after offloading, thereby improving collection efficiency.

[0098] In the embodiments of this application, emphasis is placed on improving the ability to deeply analyze and process HTTP static resource content, enabling detailed analysis and optimization of static resources on the network, such as images, videos, CSS and JavaScript files.

[0099] This application embodiment also provides an operation and maintenance device 300 based on network traffic, such as... Figure 3 As shown, a schematic diagram of the structure of a network traffic-based operation and maintenance device 300 in this application embodiment is provided. The network traffic-based operation and maintenance device 300 includes at least: a first module 310, a second module 320, and an operation and maintenance module 330, wherein:

[0100] In one embodiment of this application, the first module 310 is specifically used to: collect network traffic data in a first manner.

[0101] like Figure 1 The diagram shown is a schematic of a data center architecture. Data centers can include multiple data centers, which may be deployed in different regions or in different locations.

[0102] "Network traffic data" refers to the traffic data in network devices and connected devices in a data center.

[0103] The network traffic data that needs to be monitored can be collected using the first method. The first method includes, but is not limited to, any traffic collection method or any optimization method of traffic collection.

[0104] For example, cross-regional traffic and encrypted traffic are collected according to the first method. It can be understood that cross-regional traffic mainly refers to traffic data between different data centers, and encrypted traffic mainly refers to encrypted traffic data within a data center or between different data centers.

[0105] In one embodiment of this application, the second module 320 is specifically used to: analyze the network traffic data based on a second method.

[0106] The second approach to analyzing network traffic data allows for the monitoring and analysis of data flow through the network, providing insights into the traffic patterns on different lines. This second approach includes, but is not limited to, any traffic analysis method or any optimized version of traffic analysis.

[0107] It is understood that "first method" or "first approach" is used only to refer to a certain collection or analysis method and is not used to limit the specific implementation method in the embodiments of this application.

[0108] For example, analyzing network traffic data based on the second method includes comprehensive analysis of cross-carrier lines and cross-center network traffic, HTTP traffic content analysis, and traffic strategy analysis.

[0109] In one embodiment of this application, the operation and maintenance module 330 is specifically used to: obtain network traffic indicator monitoring data based on the analysis results of the network traffic data, so as to realize network operation and maintenance of the data center.

[0110] The network traffic data is analyzed to obtain corresponding analysis results, including the detection and analysis results of the traffic data. Based on these results, network traffic indicator monitoring data can be obtained, and network operation and maintenance of the data center can be implemented based on whether the indicator monitoring data is abnormal. The network traffic indicator monitoring data includes at least TCP connection stability indicators.

[0111] In one embodiment of this application, the first module 310 is further configured to

[0112] The corresponding network traffic data was collected using a cross-regional approach;

[0113] Encrypted traffic data was collected from network traffic data according to the sensitive traffic method.

[0114] in,

[0115] The cross-regional nature of the data center includes different security zones within the data center, and the sensitive traffic includes HTTP traffic.

[0116] In one embodiment of this application, the second module 320 is further used for

[0117] Based on the traffic on different network device interfaces and network operator lines, analyze network traffic data across operator lines and across centers;

[0118] Network traffic data based on HTTP protocol decoding and analysis of HTTP traffic content;

[0119] Based on network packet loss, we analyze the network traffic data corresponding to the adoption of traffic strategies.

[0120] In one embodiment of this application, the first module 310 is further configured to

[0121] Based on the division relationship and location information of different security zones in the data center, the boundary of the area to be monitored is determined;

[0122] Determine the data flow access rules between different security zones;

[0123] Based on the boundaries of the area to be monitored and the data flow access rules between the various security areas, determine the traffic collection points on the boundaries of each security area.

[0124] Based on the traffic acquisition points at the boundaries of each security zone, deploy traffic acquisition devices and capture sensitive traffic data transmitted across zones in real time;

[0125] Based on the sensitive traffic data, abnormal behavior or potential security threats in cross-regional data transmission can be identified through real-time monitoring and anomaly detection strategies.

[0126] In one embodiment of this application, the first module 310 is further configured to establish a hardware SSL resource pool for HTTPS traffic;

[0127] Based on the hardware SSL resource pool, HTTPS traffic is centrally decrypted and processed.

[0128] Collect the decrypted data traffic and distribute the decrypted data traffic mirrored to security tools;

[0129] The security tools described herein are used to analyze and monitor network attack traffic data, and to issue alerts regarding the network attack traffic data.

[0130] In one embodiment of this application, the operation and maintenance module 330 is further used for

[0131] Based on the analysis results of the network traffic data, the TCP connection health analysis index of the network traffic is obtained;

[0132] Based on any one or more of the TCP connection health analysis metrics, such as the number of connection establishment failures, retransmission rate, and combinations thereof, network operation and maintenance of the data center can be achieved by issuing alarms for abnormal results of the TCP connection health analysis metrics.

[0133] It is understood that the above-mentioned network traffic-based operation and maintenance device can implement each step of the network traffic monitoring method provided in the foregoing embodiments. The relevant explanations of the network traffic monitoring method are applicable to the network traffic-based operation and maintenance device, and will not be repeated here.

[0134] Figure 4 This is a schematic diagram of the structure of an electronic device according to an embodiment of this application. Please refer to it. Figure 4 At the hardware level, the electronic device includes a processor, and optionally also includes an internal bus, a network interface, and memory. The memory may include main memory, such as high-speed random-access memory (RAM), or non-volatile memory, such as at least one disk drive. Of course, the electronic device may also include other hardware required for other business operations.

[0135] The processor, network interface, and memory can be interconnected via an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 4 The symbol is represented by a single double-headed arrow, but this does not mean that there is only one bus or one type of bus.

[0136] Memory is used to store programs. Specifically, programs may include program code, which includes computer operation instructions. Memory may include main memory and non-volatile memory, and provides instructions and data to the processor.

[0137] The processor reads the corresponding computer program from non-volatile memory into main memory and then runs it, forming a network traffic-based operations and maintenance device at the logical level. The processor executes the program stored in memory and specifically performs the following operations:

[0138] Network traffic data was collected using the first method;

[0139] The network traffic data is analyzed based on the second method; and

[0140] Based on the analysis results of the network traffic data, network traffic indicator monitoring data is obtained to realize network operation and maintenance of the data center.

[0141] The above is as stated in this application. Figure 2The method for network traffic-based operation and maintenance devices disclosed in the illustrated embodiments can be applied to a processor or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by integrated logic circuits in the processor's hardware or by instructions in software form. The processor can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software module can reside in a mature storage medium in the field, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0142] The electronic device can also perform Figure 2 A method for network traffic-based operation and maintenance devices is described, and the implementation of network traffic-based operation and maintenance devices in this context is described. Figure 2 The functions of the embodiments shown are not described in detail here.

[0143] This application also proposes a computer-readable storage medium that stores one or more programs, the programs including instructions that, when executed by an electronic device including multiple applications, enable the electronic device to perform... Figure 2 The method executed by the network traffic-based operation and maintenance device in the illustrated embodiment is specifically used to perform:

[0144] Network traffic data was collected using the first method;

[0145] The network traffic data is analyzed based on the second method; and

[0146] Based on the analysis results of the network traffic data, network traffic indicator monitoring data is obtained to realize network operation and maintenance of the data center.

[0147] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0148] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0149] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0150] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0151] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0152] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0153] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0154] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0155] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0156] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A network traffic-based operation and maintenance method, wherein, The operation and maintenance methods include: Network traffic data was collected using the first method; The network traffic data collected according to the first method includes: The corresponding network traffic data was collected in a cross-regional manner, wherein the cross-regional refers to different security zones in the data center; The network traffic data collected in a cross-regional manner includes: Based on the division relationship and location information of different security zones in the data center, the boundary of the area to be monitored is determined; Determine the data flow access rules between different security zones; Based on the boundaries of the area to be monitored and the data flow access rules between the various security areas, determine the traffic collection points on the boundaries of each security area. Based on the traffic acquisition points at the boundaries of each security zone, deploy traffic acquisition devices and capture sensitive traffic data transmitted across zones in real time; Based on the sensitive traffic data, abnormal behavior or potential security threats in cross-regional data transmission can be obtained through real-time monitoring and anomaly detection strategies. The network traffic data is analyzed based on the second method; and Based on the analysis results of the network traffic data, network traffic indicator monitoring data is obtained to realize network operation and maintenance of the data center.

2. The method as described in claim 1, wherein, The network traffic data collected according to the first method includes: Encrypted traffic data was collected from network traffic data according to the sensitive traffic method. The sensitive traffic includes HTTP traffic.

3. The method as described in claim 2, wherein, The analysis of the network traffic data based on the second method includes: Based on the traffic on different network device interfaces and network operator lines, analyze network traffic data across operator lines and across centers; Network traffic data based on HTTP protocol decoding and analysis of HTTP traffic content; Based on network packet loss, we analyze the network traffic data corresponding to the adoption of traffic strategies.

4. The method as described in claim 2, wherein, The method of collecting encrypted traffic data from network traffic data according to sensitive traffic methods includes: Establish a hardware SSL resource pool for HTTPS traffic; Based on the hardware SSL resource pool, HTTPS traffic is centrally decrypted and processed. Collect the decrypted data traffic and distribute the decrypted data traffic mirrored to security tools; The security tools described herein are used to analyze and monitor network attack traffic data, and to issue alerts regarding the network attack traffic data.

5. The method as described in claim 1, wherein, Based on the analysis results of the network traffic data, network traffic indicator monitoring data is obtained to achieve network operation and maintenance of the data center, including: Based on the analysis results of the network traffic data, the TCP connection health analysis index of the network traffic is obtained; Based on any one or more of the TCP connection health analysis metrics, such as the number of connection establishment failures, retransmission rate, and combinations of the number of connection establishment failures and retransmission rate, network operation and maintenance of the data center can be achieved by issuing alarms for abnormal results of the TCP connection health analysis metrics.

6. The method according to any one of claims 1 to 5, wherein, The method further includes: Network traffic data is collected from the hardware SSL offloading device of the data center in accordance with the first method; Based on the static resources in the network traffic data of the data center, network traffic indicator monitoring data is obtained.

7. A network traffic-based operation and maintenance device, wherein, The maintenance equipment includes: The first module is used to collect network traffic data according to the first method; The network traffic data collected according to the first method includes: The corresponding network traffic data was collected in a cross-regional manner, wherein the cross-regional refers to different security zones in the data center; The network traffic data collected in a cross-regional manner includes: Based on the division relationship and location information of different security zones in the data center, the boundary of the area to be monitored is determined; Determine the data flow access rules between different security zones; Based on the boundaries of the area to be monitored and the data flow access rules between the various security areas, determine the traffic collection points on the boundaries of each security area. Based on the traffic acquisition points at the boundaries of each security zone, deploy traffic acquisition devices and capture sensitive traffic data transmitted across zones in real time; Based on the sensitive traffic data, abnormal behavior or potential security threats in cross-regional data transmission can be obtained through real-time monitoring and anomaly detection strategies. The second module is used to analyze the network traffic data based on the second method; and The operation and maintenance module is used to obtain network traffic indicator monitoring data based on the analysis results of the network traffic data, so as to realize the network operation and maintenance of the data center.

8. An electronic device, comprising: processor; as well as A memory configured to store computer-executable instructions, which, when executed, cause the processor to perform the method of any one of claims 1 to 6.

9. A computer-readable storage medium storing one or more programs, which, when executed by an electronic device including a plurality of applications, cause the electronic device to perform the method of any one of claims 1 to 6.

Citation Information

Patent Citations

  • Network security perception system and method, and readable storage medium

    CN107995162A

  • Encrypted TCP (Transmission Control Protocol) flow collection method and device

    CN113315678A

  • Abnormal behavior detection method and device for encrypted traffic network

    CN119030802A