DPDK-based firewall CPU load determination method, apparatus and device, and medium

By adopting a DPDK-based method in the firewall, through polling operations and total processing time calculation, the problem of low CPU load accuracy under the top command is solved, and more efficient and accurate CPU load monitoring and resource allocation is achieved.

CN119938306APending Publication Date: 2025-05-06CHINA TELECOM CLOUD TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411785083.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-05
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In the prior art, the top command determines that the firewall CPU has a low load accuracy, especially when the load is high, it will lead to large errors.

Method used

Using a DPDK-based method, by polling each thread within a preset time period, the total processing time of the thread is determined, and the CPU load is calculated based on the time period and the preset time period.

Benefits of technology

It improves the accuracy of the firewall CPU load, can monitor the CPU load in real time, and promptly discover performance bottlenecks and potential overload conditions, thereby allocating resources more reasonably and improving network stability and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119938306A_ABST
    Figure CN119938306A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and discloses a DPDK-based firewall CPU load determination method, apparatus and device, and a medium. The method is applied to a firewall, the firewall comprises at least one thread, and the method comprises the following steps: in a preset time period, aiming at each thread, repeating the following polling operations: determining whether a queue directed at the polling operation of the single thread is empty or not, and when the queue directed at the polling operation of the single thread is not empty, executing the polling operation of the single thread; determining a first processing duration corresponding to the polling operation so as to determine a total processing duration corresponding to each thread; the first processing duration is the duration for the CPU to process the data packet in the queue for the polling operation; the total processing duration is the total duration for the CPU to process the data packet in the preset time period; and determining a CPU load corresponding to each thread according to the total processing duration corresponding to each thread and a preset time period. According to the method and the device, the CPU load can be accurately determined by measuring the total processing duration of each thread in the preset time period.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method, device, equipment and medium for determining a firewall CPU load based on DPDK. Background Art

[0002] With the continuous development of information technology, network security issues have become increasingly prominent. As the first line of defense for network security, the performance and stability of firewalls are directly related to the security of the entire network. However, in actual applications, firewalls often face low hardware configurations such as CPU and memory, which cannot meet the processing requirements of high concurrency and large amounts of data, resulting in performance bottlenecks. In addition, with the continuous development of the Internet, new network applications are emerging in an endless stream. The data packets of these applications are smaller and the traffic is larger, which puts higher requirements on network security equipment: higher throughput and smaller latency. Therefore, calculating the CPU load of the firewall has become a technical problem that technicians in this field need to solve to ensure that the firewall can effectively handle the growing data traffic and complex network attacks while maintaining high performance and stability.

[0003] In the related art, the top command is usually used to observe the CPU load of the firewall. However, when the top command itself occupies more resources, the load will increase. Especially when the load is high, the top command will be affected when obtaining and displaying the CPU load of the firewall, resulting in a large error in the CPU load of the determined firewall.

[0004] Therefore, there is an urgent need for a load determination method that can improve the accuracy of firewall CPU load. Summary of the invention

[0005] Therefore, the technical problem to be solved by the present invention is to overcome the problem of low accuracy in determining the CPU load of the firewall through the top command in the related art.

[0006] In order to solve the above technical problems, the present invention provides a firewall CPU load determination method based on DPDK, which is applied to a firewall, wherein the firewall includes at least one thread, and the firewall CPU load determination method based on DPDK includes:

[0007] Determine the preset time period;

[0008] During the preset time period, for each thread, the following polling operation is repeated:

[0009] Determine whether the queue targeted by the current polling operation of the single thread is empty, and when the queue targeted by the current polling operation is not empty, determine a first processing duration corresponding to the current polling operation to determine a total processing duration corresponding to each of the threads;

[0010] The first processing duration is the duration of the CPU processing the data packets in the queue targeted by the current polling operation; the total processing duration corresponding to a single thread is the total duration of the CPU processing the data packets within the preset time period;

[0011] The CPU load corresponding to each thread is determined according to the total processing time corresponding to each thread and the preset time period.

[0012] In an optional implementation, determining the CPU load corresponding to each thread according to the total processing time corresponding to each thread and the preset time period includes:

[0013] The CPU load corresponding to the single thread is determined according to the ratio of the total processing time corresponding to the single thread and the time corresponding to the preset time period, so as to determine the CPU load corresponding to each thread.

[0014] In an optional implementation, determining whether the queue targeted by the current polling operation of the single thread is empty includes:

[0015] Call the preset read function to read the data packets in the queue targeted by the current polling operation of a single thread, and return the read result; wherein the read result includes a first preset value and a second preset value, and returns the first preset value if the queue targeted by the current polling operation is not empty, and returns the second preset value if the queue targeted by the current polling operation is empty.

[0016] In an optional implementation, when the queue targeted by the current polling operation is not empty, determining the first processing duration corresponding to the current polling operation to determine the total processing duration corresponding to each of the threads includes:

[0017] When the queue targeted by the current polling operation is not empty, determine the start time and end time of the preset processing function for processing the data packets in the queue targeted by the current polling operation, and determine the first processing duration corresponding to the current polling operation according to the difference between the end time and the start time;

[0018] When this polling operation is the first polling operation, the first processing duration corresponding to this polling operation is determined as the target duration for this polling operation;

[0019] When the current polling operation is not the first polling operation, the sum of the first processing duration corresponding to the current polling operation and the target duration targeted by the previous polling operation is determined as the target duration targeted by the current polling operation;

[0020] Within the preset time period, the target duration targeted by the last polling operation is determined as the total processing duration corresponding to a single thread, so as to determine the total processing duration corresponding to each thread.

[0021] In an optional implementation, determining the start time and end time of processing the data packets in the queue targeted by the current polling operation by the preset processing function includes:

[0022] When the preset processing function starts to process the data packets in the queue targeted by the current polling operation, the current time is determined as the start time by the preset timer;

[0023] When the preset processing function finishes processing the data packets in the queue targeted by this polling operation, the current time is determined as the end time by the preset timer.

[0024] In an optional implementation, when the preset processing function starts to process the data packets in the queue targeted by the current polling operation, determining the current time as the start time by using the preset timer includes:

[0025] When the preset processing function starts to process the data packets in the queue targeted by the current polling operation, the current tick number is determined as the start time by the preset timer;

[0026] When the preset processing function finishes processing the data packets in the queue targeted by the current polling operation, determining the current time as the end time by using the preset timer, comprises:

[0027] When the preset processing function finishes processing the data packets in the queue targeted by this polling operation, the current tick number is determined as the end time by the preset timer.

[0028] In an optional implementation, the method further includes: when the queue targeted by the current polling operation is empty, performing the next polling operation.

[0029] In a second aspect, the present invention provides a firewall CPU load determination device based on DPDK, which is applied to a firewall, wherein the firewall includes at least one thread, and the firewall CPU load determination device based on DPDK includes:

[0030] A first processing module, used to determine a preset time period;

[0031] The second processing module is used to repeat the following polling operation for each thread within the preset time period:

[0032] Determine whether the queue targeted by the current polling operation of the single thread is empty, and when the queue targeted by the current polling operation is not empty, determine a first processing duration corresponding to the current polling operation to determine a total processing duration corresponding to each of the threads;

[0033] The first processing duration is the duration of the CPU processing the data packets in the queue targeted by the current polling operation; the total processing duration corresponding to a single thread is the total duration of the CPU processing the data packets within the preset time period;

[0034] The third processing module is used to determine the CPU load corresponding to each thread according to the total processing time corresponding to each thread and the preset time period.

[0035] In a third aspect, the present invention provides a computer device, comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the DPDK-based firewall CPU load determination method of the above-mentioned first aspect or any corresponding embodiment thereof by executing the computer instructions.

[0036] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a single computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the DPDK-based firewall CPU load determination method of the above-mentioned first aspect or any corresponding embodiment thereof.

[0037] In a fifth aspect, the present invention provides a computer program product, comprising computer instructions, wherein the computer instructions are used to enable a computer to execute the DPDK-based firewall CPU load determination method of the above-mentioned first aspect or any corresponding embodiment thereof.

[0038] The technical solution provided by the present invention has the following technical effects:

[0039] The technical solution of the embodiment of the present invention can accurately determine the CPU load by accurately measuring the processing time of each thread within a preset time period, which is crucial for subsequent performance tuning and resource allocation. The technical solution based on the embodiment of the present invention can monitor the CPU load of the firewall in real time, which helps to promptly discover performance bottlenecks and potential overloads. By understanding the load of each thread, resources can be allocated more reasonably, for example, more CPU cores can be allocated to threads with higher loads. Complex performance can be easily expanded to more threads or more complex firewall architectures. The technical solution of the embodiment of the present invention provides an efficient and accurate way to determine the firewall CPU load, which helps to improve the stability and security of the network. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0041] Figure 1 It is a flowchart of a method for determining a firewall CPU load based on DPDK according to an embodiment of the present invention;

[0042] Figure 2 It is a schematic diagram of the architecture of a typical firewall in an embodiment of the present invention;

[0043] Figure 3 This is a flow chart of counting total processing time by a timer according to an embodiment of the present invention;

[0044] Figure 4 is a schematic diagram of a flow chart of a single polling operation according to an embodiment of the present invention;

[0045] Figure 5 This is a schematic diagram of the distribution of packets received by each network port of the firewall under 100% new construction pressure in an embodiment of the present invention;

[0046] Figure 6 This is a schematic diagram of the distribution of packets received by each network port of the firewall under 80% new construction pressure in an embodiment of the present invention;

[0047] Figure 7 It is a structural schematic diagram of a firewall CPU load determination device based on DPDK according to an embodiment of the present invention;

[0048] Figure 8 It is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0049] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.

[0050] The embodiment of the present invention provides a firewall CPU load determination method, apparatus, device and medium based on a data plane development kit (DPDK) to solve the problem of low accuracy in firewall CPU load determination in related technologies.

[0051] According to an embodiment of the present invention, an embodiment of a method for determining a firewall CPU load based on DPDK is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer device such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0052] Figure 1 It is a flowchart of a method for determining a firewall CPU load based on DPDK according to an embodiment of the present invention.

[0053] like Figure 1 As shown, an embodiment of the present invention provides a firewall CPU load determination method based on DPDK. The firewall CPU load determination method based on DPDK is applied to a firewall, and the firewall includes at least one thread.

[0054] The firewall is a multi-threaded process. Each thread has different tasks. For example, the forwarding thread is used to send and receive packets and query routes. The security thread performs further security processing on the packets sent from the forwarding thread: such as access control, deep packet inspection, etc. The log thread is used to send logs. Figure 2 As shown, as an example, a typical firewall architecture includes a network card, a forwarding thread, a security thread, and a log thread. The forwarding thread receives packets from the network card, and then divides the packets equally among several security threads through a hash algorithm. The security thread processes the packets, and if a log is generated, a log message is sent to the log thread.

[0055] Whether it is the forwarding thread receiving packets from the network card, or the packet transfer between the forwarding thread and the security thread, or the log message from the security thread to the log thread, these inter-thread communications all rely on queues. The queue includes data packets, which are used as a thread-safe data structure to store and transfer data packets, so that different threads can effectively exchange information and data. Considering that the time for processing data packets accounts for the vast majority of the program workload, the deviation of the CPU time occupied by other tasks is within an acceptable range. Therefore, the inventive concept of the present invention is proposed, and the proportion of time that the CPU is in a load state is approximated by the proportion of time that the CPU processes data packets. The following is a specific technical solution.

[0056] In this field, DPDK is a high-performance packet processing acceleration tool set provided by Intel. The application of this tool set can remove the kernel bypass, and the user-mode process directly receives and processes the data packets received by the network card. Therefore, the CPU occupied by the process is not subject to kernel scheduling. Therefore, programs based on DPDK often use polling working mode. At this time, using top to observe that the CPU load is 100%, it is impossible to clearly know the actual load of the current CPU, that is, whether it is idling or processing data packets. This has caused great trouble for the monitoring and alarm of such programs. Therefore, the present invention proposes a technical solution for determining the CPU load of a firewall based on DPDK to solve the problem of low accuracy in determining the CPU load in the scenario of applying DPDK.

[0057] The DPDK-based firewall CPU load determination method includes:

[0058] S101: Determine a preset time period.

[0059] S102: Within a preset time period, for each thread, repeat the following polling operation: determine whether the queue targeted by this polling operation of a single thread is empty; when the queue targeted by this polling operation is not empty, determine the first processing duration corresponding to this polling operation to determine the total processing duration corresponding to each thread.

[0060] S103: Determine the CPU load corresponding to each thread according to the total processing time corresponding to each thread and a preset time period.

[0061] S101 in the DPDK-based firewall CPU load determination method: determining a preset time period.

[0062] In this embodiment, the preset time period is a natural time period, which can be manually set and modified according to actual needs. In addition, the preset time period can also be a time interval corresponding to a time period determined when periodically determining the CPU load of the firewall.

[0063] S102 in the DPDK-based firewall CPU load determination method: within a preset time period, for each thread, repeat the following polling operation: determine whether the queue targeted by this polling operation of a single thread is empty, and when the queue targeted by this polling operation is not empty, determine the first processing duration corresponding to this polling operation to determine the total processing duration corresponding to each thread.

[0064] In this embodiment, the first processing duration is the duration for the CPU to process the data packets in the queue targeted by the current polling operation. The total processing duration corresponding to a single thread is the total duration for the CPU to process the data packets within a preset time period.

[0065] In this embodiment, determining whether the queue targeted by the current polling operation of the single thread is empty in S102 specifically includes: calling a preset read function to read the data packet in the queue targeted by the current polling operation of the single thread, and returning the read result.

[0066] In this embodiment, the read result includes a first preset value and a second preset value. The first preset value is returned when the queue targeted by the current polling operation is not empty, and the second preset value is returned when the queue targeted by the current polling operation is empty. As an example, the preset read function may be a read_fifo() function, the first preset value may be 1, and the second preset value may be 0.

[0067] In this embodiment, when the queue targeted by the current polling operation is not empty, determining the first processing duration corresponding to the current polling operation in S102 to determine the total processing duration corresponding to each thread specifically includes:

[0068] S1021: When the queue targeted by this polling operation is not empty, determine the start time and end time of the preset processing function for processing the data packets in the queue targeted by this polling operation, and determine the first processing duration tsc corresponding to this polling operation according to the difference between the end time and the start time.

[0069] In this embodiment, the preset processing function may be a process_packet(packets) function, which is used to execute a data packet processing flow.

[0070] In this embodiment, the process_packet(packets) function is a function for processing network packets, and its main tasks depend on the specific requirements of the application and the processing logic of the network protocol. The following are some common processing steps and operations that the function may perform: Parse the packet: parse the packet from the raw byte stream into a structured format, extract the header information, payload, etc. Verify the integrity of the packet: check the checksum or cyclic redundancy check of the packet to ensure that the data has not been tampered with during transmission. Security check: perform security scans on the packet to detect potential malware, viruses, or attacks. Filtering decision: decide whether to allow the packet to pass based on firewall rules or access control lists. Routing selection: determine the destination of the packet and select the best routing path. Load processing: process the payload of the packet, such as decompressing data, performing protocol-specific operations, etc. Protocol processing: process the packet according to the network protocol stack, such as TCP, UDP, ICMP, etc. Session management: manage session status and connections for protocols that require connections (such as TCP). Traffic statistics: record traffic information, such as packet counts, byte counts, etc., for monitoring and billing. Logging: record relevant information about the packet for debugging, auditing, or security analysis. Error handling: For damaged or invalid packets, execute error handling logic. Response generation: If necessary, generate a response packet and send it back to the sender. Data forwarding: Forward the processed data packet to the next processing link or send it directly to the destination. Quality of service: Apply different quality of service rules based on the type and priority of the data packet. Interface processing: Process data packets on the sending or receiving interface, such as VLAN tag processing. The specific implementation of the process_packet(packets) function will vary depending on the combination of the above steps and the specific logic of the application. In high-performance network processing, this function is often optimized to handle a large number of data packets while maintaining low latency and high throughput.

[0071] S1022: When the current polling operation is the first polling operation, a first processing duration corresponding to the current polling operation is determined as a target duration work_tsc for the current polling operation.

[0072] S1023: When the current polling operation is not the first polling operation, a sum of the first processing duration corresponding to the current polling operation and the target duration targeted by the previous polling operation is determined as the target duration targeted by the current polling operation.

[0073] S1024: Within a preset time period, the target duration targeted by the last polling operation is determined as the total processing duration corresponding to a single thread, so as to determine the total processing duration corresponding to each thread.

[0074] In this embodiment, determining the start time and end time of the preset processing function processing the data packets in the queue targeted by the current polling operation in S1021 specifically includes:

[0075] When the preset processing function starts to process the data packets in the queue targeted by the current polling operation, the current time is determined as the start time last by the preset timer. Specifically, when the preset processing function starts to process the data packets in the queue targeted by the current polling operation, the current tick number is determined as the start time now by the preset timer.

[0076] When the preset processing function finishes processing the data packets in the queue targeted by the current polling operation, the current time is determined as the end time by the preset timer. Specifically, when the preset processing function finishes processing the data packets in the queue targeted by the current polling operation, the current tick number is determined as the end time by the preset timer.

[0077] In this embodiment, the preset timer may be a DPDK high-precision timer.

[0078] In this embodiment, for each thread, each polling operation will first determine whether the queue targeted by the current polling operation is empty. If there are data packets in the queue, they will be taken out and processed by a preset processing function such as process_packet(packets). The polling operation of each thread is abstractly summarized as follows:

[0079]

[0080]

[0081] By counting the time it takes to call the process_packet(packets) function within a preset time period, we can roughly estimate the CPU load. The pseudo code is as follows:

[0082]

[0083] In the above pseudo code, when packets is greater than 0, it means that the queue is not empty and there are packets in the queue that need to be processed. At this time, it is necessary to count the actual time taken to process the packets. The tick count generated by the DPDK high-precision timer can be used to count the time taken by the process_packet(packets) function. The specific process is as follows: Figure 3 shown.

[0084] In this embodiment, when the queue targeted by the current polling operation is empty, the next polling operation is performed.

[0085] S103 in the DPDK-based firewall CPU load determination method: determining the CPU load corresponding to each thread according to the total processing time corresponding to each thread and a preset time period.

[0086] In this embodiment, determining the CPU load corresponding to each thread according to the total processing time corresponding to each thread and the preset time period in S103 specifically includes:

[0087] The CPU load corresponding to the single thread is determined according to the ratio of the total processing time corresponding to the single thread to the time corresponding to the preset time period, so as to determine the CPU load corresponding to each thread.

[0088] As an example, within a preset time period, the CPU load corresponding to the thread=the total processing time corresponding to the thread / the time corresponding to the preset time period.

[0089] The total processing time work_tsc corresponding to the thread finally obtained is divided by the corresponding time of the preset time period, and the CPU load in the preset time period can be obtained: cpuload = work_tsc / total_tsc. The flowchart of a single polling operation is as follows Figure 4 As shown:

[0090] If there are multiple threads, it is necessary to apply the technical solution of the present invention to each thread separately to obtain the CPU load corresponding to each thread, and then take the average value as the CPU load of the firewall.

[0091] The technical solution algorithm of the present invention is simple and practical, and has a wide range of applications. The technical solution of the present invention is easy to integrate into various network programs based on DPDK, and has strong compatibility. Both accuracy and performance consumption are acceptable. The performance of the algorithm depends on the high-precision timer provided by DPDK, which has relatively small accuracy and resource consumption. It can be applied to cloud firewalls and other products based on DPDK network programs that need to monitor the real CPU load.

[0092] The technical solution of the present invention can also obtain the result by counting the number of packets received and the packet receiving time of each CPU core of the firewall, and comprehensively calculating the time for the CPU to process the data packet. The technical solution of the present invention is simple in principle and is particularly suitable for network programs that need to process a large number of data packets. It has been found through testing that the accuracy and efficiency are within an acceptable range.

[0093] In the present invention, the technical solution of the present invention is conceived in that CPU load=time_used / time_total.

[0094] Among them, time_total represents a natural time, that is, the duration corresponding to the preset time period. time_used represents the time used by the CPU to process data packets within the preset time period. It can be seen from the formula that if there are no data packets to be processed within a period of time, it means that the CPU is idling during this period. If the CPU is used to process data packets during this period, it means that the CPU is in a fully loaded state. The basic idea is to approximate the proportion of time the CPU is in a load state by the proportion of time the CPU spends processing data packets. The basis for this approximation is that the time for processing data packets accounts for the vast majority of the program workload, and the deviation of the CPU time occupied by other tasks is within an acceptable range.

[0095] The present invention subsequently tests the accuracy of the technical solution. The test solution is: for the firewall, if the current CPU is fully loaded at 100%, the tester will have packet loss. Whether the CPU load is at 100% is determined by whether the firewall loses packets. DPDK provides a packet receiving function rte_rx_brust, which works by periodically polling the queue of the network card. If there are data packets in the queue, the data packets are obtained in batches, 32 or 64 at a time.

[0096] The distribution of packets received by each network port of the firewall under 100% new pressure is as follows Figure 5 As shown in the figure, the distribution of packets received by each network port of the firewall under the 80% new pressure is as follows Figure 6 As shown in the figure, the horizontal axis represents the number of packets received by the packet receiving function rte_rx_brust each time, and the vertical axis represents the number of packets received for the specified number of packets. Figure 5 and Figure 6 It can be seen that the distribution of 80% newly created is very different from the distribution of 100% newly created. Since 100% is full load, packet loss has begun to occur, indicating that most of the network card queues have data packets waiting to be collected by the packet receiving function, and the packet receiving function collects them in the form of the largest batch each time. However, in the 80% distribution, the distribution of batch receiving packets of 0 is the most. After fitting, it just occupies about 20% of the overall packet receiving situation, which means that 20% of the polling CPU is indeed idle. According to the above test results, it can be determined that the accuracy of the technical solution of the present invention is acceptable.

[0097] It should be noted that the contents not described in detail in the specification of the present invention belong to the common knowledge of those skilled in the art.

[0098] In this embodiment, a firewall CPU load determination device based on DPDK is also provided. A single device is used to implement the above-mentioned embodiment and optional implementation methods. The descriptions that have been made will not be repeated. As used below, the term "module" can implement a combination of software and / or hardware for a predetermined function. Although the device described in the following embodiments is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.

[0099] Figure 7 It is a structural schematic diagram of a firewall CPU load determination device based on DPDK according to an embodiment of the present invention.

[0100] The present invention provides a firewall CPU load determination device based on DPDK, which is applied to a firewall. The firewall includes at least one thread, such as Figure 7 As shown, the DPDK-based firewall CPU load determination device includes:

[0101] The first processing module 11 is used to determine a preset time period.

[0102] The second processing module 12 is used to repeat the following polling operation for each thread within a preset time period:

[0103] Determine whether the queue targeted by the current polling operation of a single thread is empty. When the queue targeted by the current polling operation is not empty, determine the first processing duration corresponding to the current polling operation to determine the total processing duration corresponding to each thread.

[0104] The first processing duration is the duration for the CPU to process the data packets in the queue targeted by the current polling operation. The total processing duration corresponding to a single thread is the total duration for the CPU to process the data packets within a preset time period.

[0105] The third processing module 13 is used to determine the CPU load corresponding to each thread according to the total processing time corresponding to each thread and a preset time period.

[0106] In an optional implementation, the third processing module 13 is specifically used to determine the CPU load corresponding to a single thread according to the ratio of the total processing time corresponding to the single thread and the time corresponding to the preset time period, so as to determine the CPU load corresponding to each thread.

[0107] In an optional implementation, the second processing module 12 includes a first processing unit, the first processing unit is used to call a preset read function to read the data packets in the queue targeted by the current polling operation of a single thread, and return the read result. The read result includes a first preset value and a second preset value, and the first preset value is returned when the queue targeted by the current polling operation is not empty, and the second preset value is returned when the queue targeted by the current polling operation is empty.

[0108] In an optional embodiment, the second processing module 12 also includes a second processing unit, which is used to determine the start time and end time of the preset processing function for processing the data packets in the queue targeted by this polling operation when the queue targeted by this polling operation is not empty, and determine the first processing duration corresponding to this polling operation according to the difference between the end time and the start time. When this polling operation is the first polling operation, the first processing duration corresponding to this polling operation is determined as the target duration targeted by this polling operation. When this polling operation is not the first polling operation, the sum of the first processing duration corresponding to this polling operation and the target duration targeted by the last polling operation is determined as the target duration targeted by this polling operation. Within the preset time period, the target duration targeted by the last polling operation is determined as the total processing duration corresponding to a single thread to determine the total processing duration corresponding to each thread.

[0109] In an optional embodiment, the second processing unit of the second processing module 12 includes a first processing subunit, and the first processing subunit is used to determine the current time as the start time through a preset timer when the preset processing function starts to process the data packets in the queue targeted by the current polling operation. When the preset processing function finishes processing the data packets in the queue targeted by the current polling operation, the current time is determined as the end time through a preset timer.

[0110] In an optional implementation, the first processing subunit is specifically configured to determine the current tick number as the start time through a preset timer when the preset processing function starts to process the data packets in the queue targeted by the current polling operation. When the preset processing function finishes processing the data packets in the queue targeted by the current polling operation, determine the current tick number as the end time through a preset timer.

[0111] In an optional implementation, the second processing module 12 is further configured to perform the next polling operation when the queue targeted by the current polling operation is empty.

[0112] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.

[0113] The DPDK-based firewall CPU load determination device in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.

[0114] The embodiment of the present invention also provides a computer device having the above Figure 7 The DPDK-based firewall CPU load determination device is shown.

[0115] See also Figure 8 , Figure 8 Schematic diagram of the hardware structure of the computer device according to the embodiment of the present invention. Figure 8 As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components are connected to each other using different buses for communication, and can be installed on a common mainboard or installed in other ways as needed. The processor can process instructions executed in the computer device, including instructions stored in or on the memory to display the graphical information of the GUI on an external input / output device (such as a display device coupled to the interface). In an optional embodiment, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor device). Figure 8 A processor 10 is taken as an example.

[0116] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be a dedicated integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.

[0117] The memory 20 stores instructions executable by at least one processor 10, so that at least one processor 10 executes the method shown in the above embodiment.

[0118] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating device, an application required for at least one function. The data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage devices. In an optional embodiment, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0119] The memory 20 may include a volatile memory, such as a random access memory. The memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive. The memory 20 may also include a combination of the above-mentioned types of memory.

[0120] The computer device further comprises a communication interface 30 for the computer device to communicate with other devices or a communication network.

[0121] The embodiment of the present invention also provides a computer-readable storage medium. The method according to the embodiment of the present invention can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium through a network download, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state hard disk, etc. Further, the storage medium can also include a combination of the above-mentioned types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.

[0122] A part of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the existence of the computer program instruction in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc., and accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium accessible to the computer.

[0123] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations are all within the scope defined by the appended claims.

Claims

1. A method for determining a firewall CPU load based on DPDK, applied to a firewall, wherein the firewall includes at least one thread, characterized in that: include: Determine the preset time period; During the preset time period, for each thread, the following polling operation is repeated: Determine whether the queue targeted by the current polling operation of the single thread is empty, and when the queue targeted by the current polling operation is not empty, determine a first processing duration corresponding to the current polling operation to determine a total processing duration corresponding to each of the threads; The first processing duration is the duration of the CPU processing the data packets in the queue targeted by the current polling operation; the total processing duration corresponding to a single thread is the total duration of the CPU processing the data packets within the preset time period; The CPU load corresponding to each thread is determined according to the total processing time corresponding to each thread and the preset time period.

2. The method according to claim 1, characterized in that: The determining the CPU load corresponding to each thread according to the total processing time corresponding to each thread and the preset time period includes: The CPU load corresponding to the single thread is determined according to the ratio of the total processing time corresponding to the single thread and the time corresponding to the preset time period, so as to determine the CPU load corresponding to each thread.

3. The method according to claim 1, characterized in that The determining whether the queue targeted by the current polling operation of the single thread is empty includes: Call the preset read function to read the data packets in the queue targeted by the current polling operation of a single thread, and return the read result; wherein the read result includes a first preset value and a second preset value, and returns the first preset value if the queue targeted by the current polling operation is not empty, and returns the second preset value if the queue targeted by the current polling operation is empty.

4. The method according to claim 1, characterized in that When the queue targeted by the current polling operation is not empty, determining a first processing duration corresponding to the current polling operation to determine a total processing duration corresponding to each of the threads includes: When the queue targeted by the current polling operation is not empty, determine the start time and end time of the preset processing function for processing the data packets in the queue targeted by the current polling operation, and determine the first processing duration corresponding to the current polling operation according to the difference between the end time and the start time; When this polling operation is the first polling operation, the first processing duration corresponding to this polling operation is determined as the target duration for this polling operation; When the current polling operation is not the first polling operation, the sum of the first processing duration corresponding to the current polling operation and the target duration targeted by the previous polling operation is determined as the target duration targeted by the current polling operation; Within the preset time period, the target duration targeted by the last polling operation is determined as the total processing duration corresponding to a single thread, so as to determine the total processing duration corresponding to each thread.

5. The method according to claim 4, characterized in that Determining the start time and end time of the preset processing function processing the data packets in the queue targeted by the current polling operation includes: When the preset processing function starts to process the data packets in the queue targeted by the current polling operation, the current time is determined as the start time by the preset timer; When the preset processing function finishes processing the data packets in the queue targeted by this polling operation, the current time is determined as the end time by the preset timer.

6. The method according to claim 5, characterized in that When the preset processing function starts to process the data packets in the queue targeted by the current polling operation, determining the current time as the start time by using the preset timer includes: When the preset processing function starts to process the data packets in the queue targeted by the current polling operation, the current tick number is determined as the start time by the preset timer; When the preset processing function finishes processing the data packets in the queue targeted by the current polling operation, determining the current time as the end time by using the preset timer, comprises: When the preset processing function finishes processing the data packets in the queue targeted by this polling operation, the current tick number is determined as the end time by the preset timer.

7. The method according to claim 1, characterized in that The method further includes: when the queue targeted by the current polling operation is empty, performing the next polling operation.

8. A firewall CPU load determination device based on DPDK, applied to a firewall, wherein the firewall includes at least one thread, characterized in that: include: A first processing module, used to determine a preset time period; The second processing module is used to repeat the following polling operation for each thread within the preset time period: Determine whether the queue targeted by the current polling operation of the single thread is empty, and when the queue targeted by the current polling operation is not empty, determine a first processing duration corresponding to the current polling operation to determine a total processing duration corresponding to each of the threads; The first processing duration is the duration of the CPU processing the data packets in the queue targeted by the current polling operation; the total processing duration corresponding to a single thread is the total duration of the CPU processing the data packets within the preset time period; The third processing module is used to determine the CPU load corresponding to each thread according to the total processing time corresponding to each thread and the preset time period.

9. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the DPDK-based firewall CPU load determination method according to any one of claims 1 to 7 by executing the computer instructions.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the DPDK-based firewall CPU load determination method according to any one of claims 1 to 7.

Citation Information

Cited By

  • Dynamic compensation-based CPU (Central Processing Unit) load monitoring method for satellite-borne network equipment

    CN120415548A