A method, device, equipment and medium for URPF check based on QoS traffic priority
By prioritizing traffic based on QoS traffic order and configuring loopback interfaces during URPF checks, the problem of high-priority traffic latency in existing technologies is resolved, achieving efficient traffic processing and security optimization, and improving network performance and user experience.
Patent Information
- Application Number
- CN202510057393.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-14
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2045-01-14
AI Technical Summary
In the existing URPF inspection process, the priority information of QoS traffic is not fully considered, resulting in delays in the processing of high-priority traffic, affecting transmission quality and user experience, and the allocation of system resources is not optimized.
Traffic is divided into multiple priorities based on the QoS mechanism, multiple loopback interfaces are configured and URPF checks are enabled or disabled, high-priority traffic is forwarded directly or fast-checked on the loopback interface, and low-priority traffic is security-checked on the loopback interface. Priorities are dynamically adjusted to optimize resource allocation.
It improves the processing efficiency of high-priority traffic, reduces latency, enhances user experience, optimizes system resource utilization, and strengthens network security and performance.
Smart Images

Figure CN119892468B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of computer technology, and in particular to a method, apparatus, device and medium for URPF inspection based on QoS traffic priority. Background Technology
[0002] URPF (Unicast Reverse Path Forwarding) is a network security technique designed to prevent IP address spoofing attacks. It works by verifying that the source IP address of a data packet matches the interface the packet arrived at on the router. This check ensures that the packet's path is valid, meaning the packet was indeed sent from its claimed source address and has not been maliciously altered. URPF checks are typically implemented in routers or firewalls within a network to enhance network security. During an URPF check, the source IP address of a data packet is compared to the reverse path it reached from that interface (i.e., the path the packet should theoretically return to). If they match, the packet is considered trustworthy and allowed to pass; if they do not match, the packet may be dropped to prevent potential spoofing attacks.
[0003] In the existing URPF inspection process, the priority information of QoS (Quality of Service) traffic is often not fully considered because system resources are allocated to the inspection of all traffic. This may lead to processing delays for high-priority traffic, thereby affecting the transmission quality of these traffic and the user experience. Summary of the Invention
[0004] This specification provides one or more embodiments of a URPF inspection method, apparatus, device, and medium based on QoS traffic priority to solve the technical problems raised in the background art.
[0005] One or more embodiments of this specification employ the following technical solutions:
[0006] This specification provides one or more embodiments of a URPF inspection method based on QoS traffic priority, the method comprising:
[0007] Traffic is divided into multiple priorities based on QoS mechanisms;
[0008] Configure multiple loopback interfaces to redirect traffic to each loopback interface and enable or disable URPF checks in each loopback interface;
[0009] After receiving the specified traffic, the specified traffic is redirected to the specified loopback interface according to the priority corresponding to the specified traffic.
[0010] When the specified loopback interface enables URPF checking, URPF checking is performed through the specified loopback interface and the specified traffic is forwarded.
[0011] When the specified loopback interface disables URPF checks, the specified traffic is forwarded through the specified loopback interface.
[0012] It should be noted that the embodiments in this specification, through the above content, have the following beneficial effects:
[0013] Improving the processing efficiency of high-priority traffic: By dividing traffic into multiple priorities according to QoS mechanisms, the system can prioritize the processing of high-priority traffic. This approach ensures that high-priority traffic (such as voice or video calls) can pass through URPF checks faster, reducing processing latency and thus improving the transmission quality of this traffic.
[0014] Improved user experience: User experience is significantly improved as high-priority traffic is processed faster. For real-time applications, such as video conferencing or online gaming, reduced latency can significantly improve the smoothness of interaction and responsiveness.
[0015] Optimize system resource allocation: By configuring multiple loopback interfaces and enabling or disabling URPF checks, the system can dynamically allocate resources based on traffic priority. This means the system can focus on performing URPF checks on traffic with high security requirements, while skipping or reducing checks on traffic with lower security requirements, thereby improving overall resource utilization.
[0016] Furthermore, the multiple priorities include a first priority and a second priority, with the first priority having a higher priority than the second priority; the first priority corresponds to the loopback interface with URPF checks disabled, and the second priority corresponds to the loopback interface with URPF checks enabled.
[0017] It should be noted that the embodiments in this specification, through the above content, have the following beneficial effects:
[0018] High-priority traffic forwarding: Assigning first-priority (higher priority) traffic to loopback interfaces with URPF checks disabled ensures that this traffic is forwarded quickly without URPF checks, thereby reducing latency and improving the transmission efficiency of critical business traffic.
[0019] Second-priority traffic security checks: Second-priority traffic corresponds to loopback interfaces with URPF checks enabled. This means that this traffic undergoes security checks before being forwarded, which helps prevent IP address spoofing attacks and enhances network security.
[0020] Furthermore, the URPF check includes multiple URPF modes, and the second priority includes multiple sub-priorities, each of which corresponds to a specific URPF mode.
[0021] Performing URPF checks and forwarding the specified traffic through the specified loopback interface includes:
[0022] Determine the specified sub-priority corresponding to the specified traffic, and determine the specified URPF mode corresponding to the specified sub-priority;
[0023] The specified URPF mode is checked through the specified loopback interface, and the specified traffic is forwarded.
[0024] It should be noted that the embodiments in this specification, through the above content, have the following beneficial effects:
[0025] Flexible security policies: By assigning different URPF modes to different sub-priorities, network administrators can implement more granular security policies and select appropriate URPF inspection methods based on the security requirements of different traffic.
[0026] Optimize resource allocation: For traffic with low security risk, a more lenient URPF mode can be used, thereby reducing the computing resources required for inspection. For high-risk traffic, a more stringent mode can be used to ensure security.
[0027] Improved processing efficiency: By assigning a specific URPF mode to each sub-priority, the system can optimize processing for different traffic types, thereby improving overall network processing efficiency.
[0028] Enhance network performance: For high-priority traffic, selecting the fast URPF mode can reduce latency and ensure the performance of critical business applications, such as real-time video calls or transaction data transmission.
[0029] Furthermore, the division of traffic into multiple priorities based on the QoS mechanism includes:
[0030] According to the QoS mechanism, traffic with latency requirements higher than a preset value is set to the first priority, and traffic with latency requirements not higher than a preset value is set to the second priority.
[0031] It should be noted that the embodiments in this specification, through the above content, have the following beneficial effects:
[0032] Prioritize critical applications: Traffic with latency requirements exceeding preset values is set as the highest priority, ensuring that such traffic (such as real-time video conferencing, online gaming, or financial services) is processed first, thereby reducing latency and improving user experience.
[0033] Optimize network resource allocation: By prioritizing traffic through QoS mechanisms, network administrators can allocate network resources more effectively, ensuring that latency-sensitive applications receive sufficient bandwidth and priority.
[0034] Furthermore, before performing the URPF check through the designated loopback interface, the method further includes:
[0035] Obtain the network load ratio;
[0036] A comprehensive URPF check is performed when the network load ratio is lower than a preset ratio.
[0037] When the network load ratio is not lower than a preset ratio, a URPF check is performed on specific traffic.
[0038] It should be noted that the embodiments in this specification, through the above content, have the following beneficial effects:
[0039] Resource optimization: By obtaining the network load ratio, it's possible to determine whether to perform a full URPF check based on the current network load. A full check ensures network security when the network load is low, while reducing the check frequency when the load is high optimizes resource utilization.
[0040] Reduce unnecessary checks: When the network load is below the preset level, a full URPF check can more effectively detect and prevent IP address spoofing attacks, while when the network load is high, checking only specific traffic can reduce unnecessary consumption of network processing capacity.
[0041] Furthermore, the step of forwarding the specified traffic through the specified loopback interface when URPF checks are disabled on the specified loopback interface includes:
[0042] When the specified loopback interface disables URPF checks, obtain the pre-stored list of source IP addresses;
[0043] If the source IP address of the specified traffic is in the list of source IP addresses, the specified traffic is forwarded through the specified loopback interface.
[0044] It should be noted that the embodiments in this specification, through the above content, have the following beneficial effects:
[0045] Enhanced network security: By checking a pre-stored list of source IP addresses, it can be ensured that only known and trusted IP addresses can forward traffic through the designated loopback interface, thereby increasing network security.
[0046] Simplify IP address verification: Since URPF checks typically require verifying whether the source IP address is in the local routing table, disabling URPF and using a list of source IP addresses instead can simplify this verification process and reduce routing table complexity.
[0047] Furthermore, the method also includes:
[0048] Deploy traffic monitoring nodes in the network to collect traffic data in real time, including bandwidth utilization, latency, and packet loss rate;
[0049] Based on the traffic data, a traffic feature database is constructed;
[0050] Based on the traffic data, a traffic prediction model is trained using a supervised learning algorithm. The traffic prediction model predicts future traffic changes based on historical traffic patterns and real-time network conditions.
[0051] Obtain a pre-written dynamic priority adjustment algorithm, which dynamically adjusts the priority based on changes in traffic.
[0052] The future traffic changes predicted by the traffic prediction model are input into the dynamic priority adjustment algorithm to adjust the traffic priority in real time.
[0053] It should be noted that the embodiments in this specification, through the above content, have the following beneficial effects:
[0054] Improve prediction accuracy: By training a traffic prediction model using supervised learning algorithms, future traffic changes can be predicted more accurately based on historical traffic patterns and real-time network conditions, reducing unnecessary network congestion.
[0055] Dynamic resource allocation: By predicting future traffic changes through traffic prediction models, the network can dynamically allocate network resources based on the prediction results, thereby optimizing network performance.
[0056] Reduce network congestion: Real-time adjustment of traffic priorities can ensure that critical services or high-priority traffic receive more bandwidth and resources when needed, thereby reducing network congestion.
[0057] Improve network efficiency: The dynamic priority adjustment algorithm can adjust priorities in real time according to changes in traffic, thereby improving the overall efficiency of the network.
[0058] This specification provides one or more embodiments of a URPF inspection device based on QoS traffic priority, comprising:
[0059] Traffic partitioning unit, which divides traffic into multiple priorities according to QoS mechanism;
[0060] The interface configuration unit configures multiple loopback interfaces to redirect traffic to each loopback interface and enable or disable URPF checks in each loopback interface.
[0061] The redirection unit, after receiving the specified traffic, redirects the specified traffic to the specified loopback interface according to the priority corresponding to the specified traffic;
[0062] The first forwarding unit performs URPF checks through the designated loopback interface and forwards the designated traffic when the designated loopback interface enables URPF checks.
[0063] The second forwarding unit forwards the specified traffic through the specified loopback interface when URPF checks are disabled on the specified loopback interface.
[0064] This specification provides one or more embodiments of a URPF inspection device based on QoS traffic priority, comprising:
[0065] At least one processor; and,
[0066] A memory communicatively connected to the at least one processor; wherein,
[0067] The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to:
[0068] Traffic is divided into multiple priorities based on QoS mechanisms;
[0069] Configure multiple loopback interfaces to redirect traffic to each loopback interface and enable or disable URPF checks in each loopback interface;
[0070] After receiving the specified traffic, the specified traffic is redirected to the specified loopback interface according to the priority corresponding to the specified traffic.
[0071] When the specified loopback interface enables URPF checking, URPF checking is performed through the specified loopback interface and the specified traffic is forwarded.
[0072] When the specified loopback interface disables URPF checks, the specified traffic is forwarded through the specified loopback interface.
[0073] This specification provides one or more embodiments of a non-volatile computer storage medium storing computer-executable instructions, which, when executed by a computer, can perform the following:
[0074] Traffic is divided into multiple priorities based on QoS mechanisms;
[0075] Configure multiple loopback interfaces to redirect traffic to each loopback interface and enable or disable URPF checks in each loopback interface;
[0076] After receiving the specified traffic, the specified traffic is redirected to the specified loopback interface according to the priority corresponding to the specified traffic.
[0077] When the specified loopback interface enables URPF checking, URPF checking is performed through the specified loopback interface and the specified traffic is forwarded.
[0078] When the specified loopback interface disables URPF checks, the specified traffic is forwarded through the specified loopback interface.
[0079] The above-described at least one technical solution adopted in the embodiments of this specification can achieve the following beneficial effects:
[0080] Improving the processing efficiency of high-priority traffic: By dividing traffic into multiple priorities according to QoS mechanisms, the system can prioritize the processing of high-priority traffic. This approach ensures that high-priority traffic (such as voice or video calls) can pass through URPF checks faster, reducing processing latency and thus improving the transmission quality of this traffic.
[0081] Improved user experience: User experience is significantly improved as high-priority traffic is processed faster. For real-time applications, such as video conferencing or online gaming, reduced latency can significantly improve the smoothness of interaction and responsiveness.
[0082] Optimize system resource allocation: By configuring multiple loopback interfaces and enabling or disabling URPF checks, the system can dynamically allocate resources based on traffic priority. This means the system can focus on performing URPF checks on traffic with high security requirements, while skipping or reducing checks on traffic with lower security requirements, thereby improving overall resource utilization. Attached Figure Description
[0083] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings:
[0084] Figure 1 A flowchart illustrating a URPF inspection method based on QoS traffic priority provided for one or more embodiments of this specification;
[0085] Figure 2A schematic diagram of a URPF inspection device based on QoS traffic priority provided for one or more embodiments of this specification;
[0086] Figure 3 This is a schematic diagram of a URPF inspection device based on QoS traffic priority, provided for one or more embodiments of this specification. Detailed Implementation
[0087] This specification provides an embodiment of a URPF inspection method, apparatus, device, and medium based on QoS traffic priority.
[0088] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments of this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.
[0089] Figure 1 This diagram illustrates a URPF inspection method based on QoS traffic priority, provided for one or more embodiments of this specification. This process can be executed by a switch. Certain input parameters or intermediate results in the process can be manually adjusted to help improve accuracy.
[0090] The method flow steps of the embodiments in this specification are as follows:
[0091] S101 divides traffic into multiple priorities based on the QoS mechanism.
[0092] In the embodiments described in this specification, the switch can use a QoS mechanism to divide traffic into several priorities (first priority, second priority) according to the priority of traffic. The number of priorities can be set according to the actual situation.
[0093] S102, Configure multiple loopback interfaces to redirect traffic to each loopback interface and enable or disable URPF checks in each loopback interface.
[0094] In the embodiments described in this specification, the switch can be configured with several loopback interfaces for traffic redirection and enabling or disabling URPF-related functions, i.e., enabling or disabling URPF checks. For example, traffic corresponding to the first priority can be redirected to a loopback interface with URPF checks disabled, and traffic corresponding to the second priority can be redirected to a loopback interface with URPF checks enabled.
[0095] S103: After receiving the specified traffic, the specified traffic is redirected to the specified loopback interface according to the priority corresponding to the specified traffic.
[0096] In the embodiments described in this specification, after the switch obtains the specified traffic from the port, it first determines the priority of the specified traffic and redirects the specified traffic to the loopback interface specified by the device according to the priority.
[0097] S104, when the designated loopback interface enables URPF checking, URPF checking is performed through the designated loopback interface and the designated traffic is forwarded.
[0098] S105, when the specified loopback interface disables URPF checks, the specified traffic is forwarded through the specified loopback interface.
[0099] In the embodiments of this specification, multiple priorities include a first priority and a second priority, with the first priority having a higher priority than the second priority; the first priority corresponds to a loopback interface with URPF checks disabled, and the second priority corresponds to a loopback interface with URPF checks enabled. That is, according to the QoS mechanism, traffic with latency requirements higher than a preset value is set to the first priority, and traffic with latency requirements not higher than the preset value is set to the second priority.
[0100] It should be noted that the embodiments in this specification, through the above content, have the following beneficial effects:
[0101] High-priority traffic forwarding: Assigning first-priority (higher priority) traffic to loopback interfaces with URPF checks disabled ensures that this traffic is forwarded quickly without URPF checks, thereby reducing latency and improving the transmission efficiency of critical business traffic.
[0102] Second-priority traffic security checks: Second-priority traffic corresponds to loopback interfaces with URPF checks enabled. This means that this traffic undergoes security checks before being forwarded, which helps prevent IP address spoofing attacks and enhances network security.
[0103] Furthermore, the URPF check includes multiple URPF modes, and the second priority includes multiple sub-priorities, each of which corresponds to a specific URPF mode. When performing the URPF check and forwarding the specified traffic through the specified loopback interface, the specified sub-priority corresponding to the specified traffic can be determined, and the specified URPF mode corresponding to the specified sub-priority can be determined. The specified URPF mode is checked through the specified loopback interface, and the specified traffic is forwarded.
[0104] It should be noted that the embodiments in this specification, through the above content, have the following beneficial effects:
[0105] Flexible security policies: By assigning different URPF modes to different sub-priorities, network administrators can implement more granular security policies and select appropriate URPF inspection methods based on the security requirements of different traffic.
[0106] Optimize resource allocation: For traffic with low security risk, a more lenient URPF mode can be used, thereby reducing the computing resources required for inspection. For high-risk traffic, a more stringent mode can be used to ensure security.
[0107] Improved processing efficiency: By assigning a specific URPF mode to each sub-priority, the system can optimize processing for different traffic types, thereby improving overall network processing efficiency.
[0108] Enhance network performance: For high-priority traffic, selecting the fast URPF mode can reduce latency and ensure the performance of critical business applications, such as real-time video calls or transaction data transmission.
[0109] Furthermore, before performing the URPF check through the designated loopback interface, the network load ratio can be obtained first; when the network load ratio is lower than a preset ratio, a comprehensive URPF check can be performed; when the network load ratio is not lower than the preset ratio, a URPF check can be performed on specific traffic.
[0110] Network load balancing can be monitored using traffic analysis tools such as Wireshark and PRTG. A preset load balancing threshold can be set based on network requirements and business criticality. For example, if the preset load balancing is 70%, a full URPF check will be performed when the network load falls below this threshold. When the network load balancing is below the preset threshold, a full URPF check will be performed on all traffic entering and leaving the network. When the network load balancing is not below the preset threshold, URPF checks will only be performed on specific traffic. Traffic requiring special protection, such as sensitive data transmissions or critical business traffic, can be identified and flagged. URPF checks will only be performed on this flagged traffic.
[0111] It should be noted that the embodiments in this specification, through the above content, have the following beneficial effects:
[0112] Resource optimization: By obtaining the network load ratio, it's possible to determine whether to perform a full URPF check based on the current network load. A full check ensures network security when the network load is low, while reducing the check frequency when the load is high optimizes resource utilization.
[0113] Reduce unnecessary checks: When the network load is below the preset level, a full URPF check can more effectively detect and prevent IP address spoofing attacks, while when the network load is high, checking only specific traffic can reduce unnecessary consumption of network processing capacity.
[0114] Furthermore, when the specified loopback interface disables URPF checks, during the forwarding of the specified traffic through the specified loopback interface, a pre-stored list of source IP addresses is obtained; if the source IP address of the specified traffic is in the list of source IP addresses, the specified traffic is forwarded through the specified loopback interface.
[0115] It should be noted that the embodiments in this specification, through the above content, have the following beneficial effects:
[0116] Enhanced network security: By checking a pre-stored list of source IP addresses, it can be ensured that only known and trusted IP addresses can forward traffic through the designated loopback interface, thereby increasing network security.
[0117] Simplify IP address verification: Since URPF checks typically require verifying whether the source IP address is in the local routing table, disabling URPF and using a list of source IP addresses instead can simplify this verification process and reduce routing table complexity.
[0118] Furthermore, embodiments of this specification can also deploy traffic monitoring nodes in the network to collect traffic data in real time, including bandwidth utilization, latency, and packet loss rate; construct a traffic feature database based on the traffic data; train a traffic prediction model using a supervised learning algorithm based on the traffic data, the traffic prediction model predicting future traffic changes based on historical traffic patterns and real-time network conditions; obtain a pre-written dynamic priority adjustment algorithm, the dynamic priority adjustment algorithm dynamically adjusting priorities based on traffic changes; input the future traffic changes predicted by the traffic prediction model into the dynamic priority adjustment algorithm to adjust traffic priorities in real time.
[0119] It should be noted that the above content can be implemented through the following specific implementation plan:
[0120] 1. Deploy traffic monitoring nodes
[0121] Select monitoring nodes: Choose appropriate network devices or servers as traffic monitoring nodes.
[0122] Deployment tools: Deploy traffic monitoring tools, such as Wireshark, PRTG, or OpenVPN, on the monitoring nodes.
[0123] Configure data collection: Configure monitoring tools to collect network traffic data in real time, including bandwidth utilization, latency, and packet loss rate.
[0124] 2. Construct a traffic feature database
[0125] Data storage: Create a traffic characteristic database in the monitoring node or central database.
[0126] Data collection: Regularly collect traffic data from monitoring nodes and extract key features such as protocol type, source IP, destination IP, port number, and traffic volume.
[0127] Data insertion: Insert the collected traffic characteristic data into the traffic characteristic database.
[0128] 3. Training the traffic prediction model
[0129] Algorithm selection: Choose a suitable supervised learning algorithm, such as linear regression, decision tree, random forest or neural network.
[0130] Data preprocessing: Cleaning and preprocessing the data in the traffic feature database, including handling missing values, outlier handling, and feature scaling.
[0131] Feature selection: Select the features that have the greatest impact on traffic prediction.
[0132] Model training: Use historical traffic data to train a traffic prediction model so that it can predict future traffic changes based on historical traffic patterns and real-time network conditions.
[0133] 4. Pre-write dynamic priority adjustment algorithm
[0134] Algorithm Design: Design a dynamic priority adjustment algorithm that can adjust traffic priority according to real-time traffic changes.
[0135] Algorithm implementation: Convert the algorithm into executable code and deploy it on network devices.
[0136] 5. Adjust traffic priority in real time
[0137] Real-time forecasting: Input the future traffic change data predicted by the traffic forecasting model into the dynamic priority adjustment algorithm.
[0138] Priority Adjustment: The algorithm dynamically adjusts traffic priority based on prediction results to ensure that critical traffic receives higher bandwidth and lower latency.
[0139] Implement the adjustment: Apply the adjusted priority settings to the network devices through the network management interface or script.
[0140] It should be noted that the embodiments in this specification, through the above content, have the following beneficial effects:
[0141] Improve prediction accuracy: By training a traffic prediction model using supervised learning algorithms, future traffic changes can be predicted more accurately based on historical traffic patterns and real-time network conditions, reducing unnecessary network congestion.
[0142] Dynamic resource allocation: By predicting future traffic changes through traffic prediction models, the network can dynamically allocate network resources based on the prediction results, thereby optimizing network performance.
[0143] Reduce network congestion: Real-time adjustment of traffic priorities can ensure that critical services or high-priority traffic receive more bandwidth and resources when needed, thereby reducing network congestion.
[0144] Improve network efficiency: The dynamic priority adjustment algorithm can adjust priorities in real time according to changes in traffic, thereby improving the overall efficiency of the network.
[0145] URPF (Reverse Path Filtering) is a commonly used network security technique. Its purpose is to check whether the source IP address of a data packet matches the path the packet has traversed, thereby preventing source address spoofing and reflection attacks. URPF is primarily used on routers or switches, where it verifies the legitimacy of data packets by checking their reverse path.
[0146] QoS (Quality of Service) technology is used to manage the priority of different traffic in a network. QoS is a network security mechanism and a technology used to solve problems such as network latency and congestion. By classifying, labeling, and scheduling data traffic, QoS can ensure that high-priority traffic (such as real-time video and voice communication) receives higher bandwidth and lower latency, while less important traffic (such as file transfers) is scheduled to low-priority channels.
[0147] In existing technologies, URPF and QoS are typically used independently. QoS helps optimize network bandwidth allocation and ensures the real-time performance of high-priority traffic, while URPF is primarily used to prevent traffic from illegal source addresses. However, existing implementations often fail to effectively combine these two, resulting in the underutilization of QoS traffic priority information during URPF checks, thus affecting the efficiency and accuracy of URPF checks.
[0148] Currently, there are patented technologies that combine ACL (Access Control List) and URPF. First, traffic packets are acquired, and the ACL is used to determine if they are designated traffic packets. If they are designated traffic packets, the traffic is redirected to a pre-configured first target loopback interface in the switch; otherwise, it is redirected to a pre-configured second target loopback interface in the switch. The first target loopback interface does not have URPF enabled, while the second target loopback interface has URPF enabled.
[0149] The existing solutions described above have the following drawbacks:
[0150] 1. Schemes combining ACLs and URPF are often based on static traffic filtering rules, which may not fully consider the priority differences of traffic when processing different types of traffic. URPF (Reverse Path Filtering) usually checks all traffic, which may cause unnecessary latency or additional computational burden for high-priority traffic (such as real-time video and voice traffic), affecting the real-time performance of the network.
[0151] 2. The combined ACL and URPF approach typically has a relatively fixed approach to traffic classification and processing, relying on manually configured ACL rules to identify which traffic requires URPF checks. This method has poor responsiveness to dynamic demands from different traffic types and lacks flexibility.
[0152] 3. In traditional schemes combining ACL and URPF, URPF checks treat all traffic (regardless of priority) the same way, which may lead to some security vulnerabilities. For example, low-priority traffic may not undergo sufficient path checks, posing a risk of source address spoofing. Moreover, URPF checks themselves increase the network's computational burden, affecting the real-time performance of high-priority traffic.
[0153] 4. Solutions combining ACLs and URPF typically require manually configuring complex ACL rules to identify traffic and determine how to handle it based on these rules. As the network grows, the management and maintenance of ACL rules become increasingly complex, especially when dynamic adjustments are needed based on different business requirements, significantly increasing the workload of manual management.
[0154] 5. In a dynamically changing network environment, the nature and load of traffic often fluctuate. Traditional ACL+URPF solutions rely on static rule configurations, which are difficult to respond to changes in network load in real time. This may lead to performance bottlenecks when the network load is high, or affect network security when the traffic type changes.
[0155] To address these shortcomings, the embodiments in this specification aim to:
[0156] By utilizing QoS mechanisms to prioritize traffic and then performing URPF checks, network performance and security can be optimized. Specifically, the embodiments in this specification aim to:
[0157] 1. Improve the efficiency of URPF checks and reduce delays caused by checks, especially for high-priority traffic (such as voice and video);
[0158] 2. While ensuring network security, ensure that high-priority traffic is better protected and avoid high-priority data being affected by URPF checks.
[0159] This specification provides an embodiment of a URPF inspection method based on QoS traffic priority, which is implemented through the following steps:
[0160] 1. The switch uses QoS mechanism to divide traffic into several priority levels (such as high priority, medium priority, and low priority) according to the priority of traffic; it is configured with several loopback interfaces for traffic redirection and enabling or disabling URPF related functions;
[0161] 2. After obtaining traffic from the port, the switch first determines the priority of the traffic and redirects the traffic to the loopback interface specified by the device according to the priority;
[0162] 3. Finally, if the redirection is to a loopback interface configured with URPF, the loopback interface will perform URPF-related checks and then forward the relevant traffic; if the redirection is to a loopback interface without URPF, the traffic will be forwarded directly.
[0163] Higher-priority traffic will be prioritized for reverse path verification checks, reducing latency caused by URPF checks. For lower-priority traffic, a strategy with higher latency tolerance can be adopted, allowing for stricter URPF checks.
[0164] For example, switch A sends traffic to switch B. Internally, the switches categorize the traffic into several priorities based on QoS mechanisms (this is just a simplified example, dividing traffic into high and low priorities; in practice, QoS can classify traffic into up to eight priorities). High-priority traffic is forwarded to loopback interface 1 within the switch, and loopback interface 1 is not configured with URPF, meaning the source address of the traffic is not checked. Low-priority traffic is forwarded to loopback interface 2 within the switch, and loopback interface 2 is configured with URPF, meaning the source address of the traffic is checked. Finally, the high-priority and low-priority traffic is forwarded to other devices according to the corresponding loopback interface.
[0165] The embodiments described in this specification have the following beneficial effects:
[0166] 1. Improve network performance: The embodiments in this specification combine QoS traffic priority with the URPF inspection mechanism, which enables effective URPF inspection without affecting high-priority traffic, thereby improving network performance and the real-time performance of data transmission.
[0167] 2. Reduce latency: By prioritizing high-priority traffic and reducing the complexity of checking low-priority traffic, the embodiments in this specification can effectively reduce network latency, especially in real-time data transmission scenarios such as video and voice.
[0168] 3. Enhanced security: Despite the optimization of traffic prioritization and URPF inspection processes, the embodiments in this specification still maintain a high degree of emphasis on network security, avoiding security vulnerabilities caused by traffic scheduling.
[0169] Figure 2 This specification provides a schematic diagram of a URPF inspection device based on QoS traffic priority, which includes one or more embodiments of the present specification. The device comprises: a traffic partitioning unit 201, an interface configuration unit 202, a redirection unit 203, a first forwarding unit 204, and a second forwarding unit 205.
[0170] Traffic partitioning unit 201 divides traffic into multiple priorities according to the QoS mechanism;
[0171] Interface configuration unit 202 configures multiple loopback interfaces to redirect traffic to each loopback interface and enable or disable URPF checks in each loopback interface;
[0172] After receiving the specified traffic, the redirection unit 203 redirects the specified traffic to the specified loopback interface according to the priority corresponding to the specified traffic.
[0173] The first forwarding unit 204 performs URPF checks and forwards the specified traffic through the designated loopback interface when the designated loopback interface enables URPF checks.
[0174] The second forwarding unit 205 forwards the specified traffic through the specified loopback interface when the specified loopback interface disables URPF checks.
[0175] Figure 3 A schematic diagram of a URPF inspection device based on QoS traffic priority, provided for one or more embodiments of this specification, includes:
[0176] At least one processor; and,
[0177] A memory communicatively connected to the at least one processor; wherein,
[0178] The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to:
[0179] Traffic is divided into multiple priorities based on QoS mechanisms;
[0180] Configure multiple loopback interfaces to redirect traffic to each loopback interface and enable or disable URPF checks in each loopback interface;
[0181] After receiving the specified traffic, the specified traffic is redirected to the specified loopback interface according to the priority corresponding to the specified traffic.
[0182] When the specified loopback interface enables URPF checking, URPF checking is performed through the specified loopback interface and the specified traffic is forwarded.
[0183] When the specified loopback interface disables URPF checks, the specified traffic is forwarded through the specified loopback interface.
[0184] This specification provides one or more embodiments of a non-volatile computer storage medium storing computer-executable instructions, which, when executed by a computer, can perform the following:
[0185] Traffic is divided into multiple priorities based on QoS mechanisms;
[0186] Configure multiple loopback interfaces to redirect traffic to each loopback interface and enable or disable URPF checks in each loopback interface;
[0187] After receiving the specified traffic, the specified traffic is redirected to the specified loopback interface according to the priority corresponding to the specified traffic.
[0188] When the specified loopback interface enables URPF checking, URPF checking is performed through the specified loopback interface and the specified traffic is forwarded.
[0189] When the specified loopback interface disables URPF checks, the specified traffic is forwarded through the specified loopback interface.
[0190] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the embodiments of apparatus, devices, and non-volatile computer storage media are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0191] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the apparatus embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0192] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0193] In the embodiments provided in this application, it should be understood that the disclosed apparatus / network devices and methods can be implemented in other ways. For example, the apparatus / network device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0194] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0195] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The aforementioned units can be implemented in hardware or software.
[0196] If the integrated module / unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium can be appropriately added or removed according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electrical carrier signals and telecommunication signals.
[0197] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.
Claims
1. A URPF inspection method based on QoS traffic priority, characterized in that, include: Traffic is divided into multiple priorities based on QoS mechanisms; Configure multiple loopback interfaces to redirect traffic to each loopback interface and enable or disable URPF checks in each loopback interface; After receiving the specified traffic, the specified traffic is redirected to the specified loopback interface according to the priority corresponding to the specified traffic. When the specified loopback interface enables URPF checking, URPF checking is performed through the specified loopback interface and the specified traffic is forwarded. When the specified loopback interface disables URPF checks, the specified traffic is forwarded through the specified loopback interface. The multiple priorities include a first priority and a second priority, with the first priority having a higher priority than the second priority; the first priority corresponds to a loopback interface with URPF checks disabled, and the second priority corresponds to a loopback interface with URPF checks enabled. The process of dividing traffic into multiple priorities based on the QoS mechanism includes: According to the QoS mechanism, traffic with latency requirements higher than a preset value is set to the first priority, and traffic with latency requirements not higher than a preset value is set to the second priority.
2. The method according to claim 1, characterized in that, The URPF check includes multiple URPF modes, and the second priority includes multiple sub-priorities, each of which corresponds to a specific URPF mode. Performing URPF checks and forwarding the specified traffic through the specified loopback interface includes: Determine the specified sub-priority corresponding to the specified traffic, and determine the specified URPF mode corresponding to the specified sub-priority; The specified URPF mode is checked through the specified loopback interface, and the specified traffic is forwarded.
3. The method according to claim 1, characterized in that, Before performing the URPF check through the designated loopback interface, the method further includes: Obtain the network load ratio; A comprehensive URPF check is performed when the network load ratio is lower than a preset ratio. When the network load ratio is not lower than a preset ratio, a URPF check is performed on specific traffic.
4. The method according to claim 1, characterized in that, When the specified loopback interface disables URPF checks, forwarding the specified traffic through the specified loopback interface includes: When the specified loopback interface disables URPF checks, obtain the pre-stored list of source IP addresses; If the source IP address of the specified traffic is in the list of source IP addresses, the specified traffic is forwarded through the specified loopback interface.
5. The method according to claim 1, characterized in that, The method further includes: Deploy traffic monitoring nodes in the network to collect traffic data in real time, including bandwidth utilization, latency, and packet loss rate; Based on the traffic data, a traffic feature database is constructed; Based on the traffic data, a traffic prediction model is trained using a supervised learning algorithm. The traffic prediction model predicts future traffic changes based on historical traffic patterns and real-time network conditions. Obtain a pre-written dynamic priority adjustment algorithm, which dynamically adjusts the priority based on changes in traffic. The future traffic changes predicted by the traffic prediction model are input into the dynamic priority adjustment algorithm to adjust the traffic priority in real time.
6. A URPF inspection device based on QoS traffic priority, characterized in that, include: Traffic partitioning unit, which divides traffic into multiple priorities according to QoS mechanism; The interface configuration unit configures multiple loopback interfaces to redirect traffic to each loopback interface and enable or disable URPF checks in each loopback interface. The redirection unit, after receiving the specified traffic, redirects the specified traffic to the specified loopback interface according to the priority corresponding to the specified traffic; The first forwarding unit performs URPF checks through the designated loopback interface and forwards the designated traffic when the designated loopback interface enables URPF checks. The second forwarding unit forwards the specified traffic through the specified loopback interface when the specified loopback interface disables URPF checks. The multiple priorities include a first priority and a second priority, with the first priority having a higher priority than the second priority; the first priority corresponds to a loopback interface with URPF checks disabled, and the second priority corresponds to a loopback interface with URPF checks enabled. The process of dividing traffic into multiple priorities based on the QoS mechanism includes: According to the QoS mechanism, traffic with latency requirements higher than a preset value is set to the first priority, and traffic with latency requirements not higher than a preset value is set to the second priority.
7. A URPF inspection device based on QoS traffic priority, characterized in that, include: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to: Traffic is divided into multiple priorities based on QoS mechanisms; Configure multiple loopback interfaces to redirect traffic to each loopback interface and enable or disable URPF checks in each loopback interface; After receiving the specified traffic, the specified traffic is redirected to the specified loopback interface according to the priority corresponding to the specified traffic. When the specified loopback interface enables URPF checking, URPF checking is performed through the specified loopback interface and the specified traffic is forwarded. When the specified loopback interface disables URPF checks, the specified traffic is forwarded through the specified loopback interface. The multiple priorities include a first priority and a second priority, with the first priority having a higher priority than the second priority; the first priority corresponds to a loopback interface with URPF checks disabled, and the second priority corresponds to a loopback interface with URPF checks enabled. The process of dividing traffic into multiple priorities based on the QoS mechanism includes: According to the QoS mechanism, traffic with latency requirements higher than a preset value is set to the first priority, and traffic with latency requirements not higher than a preset value is set to the second priority.
8. A non-volatile computer storage medium, characterized in that, It stores computer-executable instructions, which, when executed by a computer, can achieve the following: Traffic is divided into multiple priorities based on QoS mechanisms; Configure multiple loopback interfaces to redirect traffic to each loopback interface and enable or disable URPF checks in each loopback interface; After receiving the specified traffic, the specified traffic is redirected to the specified loopback interface according to the priority corresponding to the specified traffic. When the specified loopback interface enables URPF checking, URPF checking is performed through the specified loopback interface and the specified traffic is forwarded. When the specified loopback interface disables URPF checks, the specified traffic is forwarded through the specified loopback interface. The multiple priorities include a first priority and a second priority, with the first priority having a higher priority than the second priority; the first priority corresponds to a loopback interface with URPF checks disabled, and the second priority corresponds to a loopback interface with URPF checks enabled. The process of dividing traffic into multiple priorities based on the QoS mechanism includes: According to the QoS mechanism, traffic with latency requirements higher than a preset value is set to the first priority, and traffic with latency requirements not higher than a preset value is set to the second priority.
Citation Information
Patent Citations
Message submitting method and switch chip
CN106789759A
BUM message sending method and device in VXLAN network, and storage medium
CN115567464A