Traffic arrangement method and device, electronic equipment and storage medium
By inserting internal header identifiers into the processing request for business traffic, the session identification failure and orchestration failure caused by the modification of five-tuple information by the seven-layer web application firewall component is solved, and the consistency and continuity of business traffic between multiple security resource pools is achieved.
Patent Information
- Application Number
- CN202411993549.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-06
AI Technical Summary
After the seven-layer web application firewall component modifies the five-tuple information of traffic, the SSLO device fails to recognize the original session, resulting in complex traffic management tracking and failure of orchestration.
By inserting an internal header identifier in the processing request for traffic traffic, it is ensured that even if the five-tuple information is modified, the electronic device can still identify and restore the original session information through the internal header identifier.
It realizes consistency and continuity when passing service traffic between multiple secure resource pools, avoiding session recognition failure and orchestration failure.
Smart Images

Figure CN119945748A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a traffic orchestration method, device, electronic device and storage medium. Background Art
[0002] In the related art, the business traffic sent by the terminal device on the user side needs to be orchestrated by the SSLO device (SSL Orchestrator) to the security function component to process the traffic before being received by the application server. The security function component may include a FW device (Firewall), WAF (Web Application Firewall), IPS (Intrusion Prevention System), Internet behavior control system, and bastion host, etc. In the traditional network security architecture, WAF (Web Application Firewall) devices usually have two deployment modes: two-layer deployment and seven-layer reverse proxy deployment. However, when the WAF device (i.e., the seven-layer Web Application Firewall component) deployed with a seven-layer reverse proxy processes the traffic, the five-tuple information of the traffic will be changed. For example, the client's request IP address will be replaced with the IP address of the WAF device, resulting in the SSLO device being unable to identify the original session through the five-tuple information, which in turn complicates the management and tracking of the traffic, thereby causing the orchestration to fail. Summary of the invention
[0003] In view of the above problems, the present application provides a traffic orchestration method, device, electronic device and storage medium, which ensures that even when the seven-layer Web application firewall component changes the five-tuple information of the business traffic, the electronic device (such as an SSLO device) can still identify and restore the original session information through the internal header identifier by inserting an internal header identifier in the processing request of the business traffic, thereby ensuring the consistency and continuity of the business traffic when it is transmitted between multiple security resource pools, thereby solving the problem of session identification failure caused by the seven-layer Web application firewall component modifying the five-tuple information in the related art, thereby causing orchestration failure.
[0004] The embodiment of the present application is implemented by adopting the following technical solutions:
[0005] In a first aspect, an embodiment of the present application provides a traffic orchestration method, which obtains business traffic, an initial session corresponding to the business traffic, and a security service chain corresponding to the initial session, wherein the security service chain is used to indicate that the business traffic passes through at least one security resource pool in a preset order, and each of the security resource pools includes at least one security function component with the same security function; if it is determined that the security service chain corresponding to the business traffic carries information indicating that the security function component is the security resource pool where the seven-layer Web application firewall component is located, an internal header identifier is inserted into the processing request of the business traffic to obtain the first business traffic, and the security resource pool ranked first in the preset order is determined as the first security resource pool, and the internal header identifier carries the information of the initial session; The first business traffic is directed to the first security resource pool, so that the first security resource pool is used to process the first business traffic to obtain the second business traffic; if the security function component in the first security resource pool is a seven-layer Web application firewall component, the second business traffic is obtained based on the business traffic obtained after the first seven-layer Web application firewall component modifies the five-tuple information of the first business traffic according to the address information configured therein, then the first virtual service is called to parse the second business traffic to obtain the internal header identifier, and the first virtual service is associated with the address information configured by the first seven-layer Web application firewall component; based on the initial session information restored by the internal header identifier, a new session is generated as the first session, and the first session is marked as a subsession of the initial session.
[0006] In a second aspect, an embodiment of the present application provides a traffic orchestration device, a data acquisition module, used to acquire business traffic, an initial session corresponding to the business traffic, and a security service chain corresponding to the initial session, the security service chain is used to indicate that the business traffic passes through at least one security resource pool in a preset order, and each of the security resource pools includes at least one security function component with the same security function; an identification insertion module, used to determine that the security service chain corresponding to the business traffic carries information indicating that the security function component is the security resource pool where the seven-layer Web application firewall component is located, insert an internal header identification into the processing request of the business traffic to obtain the first business traffic, and determine the security resource pool ranked first in the preset order as the first security resource pool, and the internal header identification carries the information of the initial session; a traffic introduction module, Used to guide the first business traffic to the first security resource pool so as to use the first security resource pool to process the first business traffic to obtain the second business traffic; a traffic parsing module, used to call the first virtual service to parse the second business traffic when the security function component in the first security resource pool is a seven-layer Web application firewall component, and the second business traffic is obtained based on the business traffic obtained by modifying the five-tuple information of the first business traffic according to the address information configured by the first seven-layer Web application firewall component, and obtain the internal header identifier, and the first virtual service is associated with the address information configured by the first seven-layer Web application firewall component; a session generation module, used to generate a new session as the first session based on the initial session information restored by the internal header identifier, and mark the first session as a subsession of the initial session.
[0007] In a third aspect, an embodiment of the present application provides an electronic device, comprising: one or more processors; a memory; and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the above-mentioned traffic orchestration method.
[0008] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a program code, and the program code can be called by a processor to execute the above-mentioned traffic orchestration method.
[0009] The traffic orchestration method, device, electronic device and storage medium provided by the embodiments of the present application include: obtaining business traffic, an initial session corresponding to the business traffic and a security service chain corresponding to the initial session, wherein the security service chain is used to indicate that the business traffic passes through at least one security resource pool in a preset order, and each of the security resource pools includes at least one security function component with the same security function; if it is determined that the security service chain corresponding to the business traffic carries information indicating that the security function component is the security resource pool where the seven-layer Web application firewall component is located, inserting an internal header identifier into the processing request of the business traffic to obtain a first business traffic, wherein the internal header identifier carries the information of the initial session; determining the security resource pool ranked first in the preset order as the first security resource pool, and directing the first business traffic to the first A security resource pool is provided, wherein the first security resource pool is used to process the first business flow to obtain the second business flow; if the security function component in the first security resource pool is a seven-layer Web application firewall component, the second business flow is obtained based on the business flow obtained after the first seven-layer Web application firewall component modifies the five-tuple information of the first business flow according to the address information configured by the first seven-layer Web application firewall component, then the first virtual service is called to parse the second business flow to obtain the internal header identifier, and the first virtual service is associated with the address information configured by the first seven-layer Web application firewall component; based on the initial session information restored by the internal header identifier, a new session is generated as the first session, and the first session is marked as a subsession of the initial session; the internal header identifier is deleted from the processing request of the second business flow to obtain the updated second business flow. By adopting the above method, an internal header identifier is inserted into the processing request to carry the information of the initial session, so that when the first seven-layer Web application firewall component changes the five-tuple information of the first business traffic, the first virtual service corresponding to the first seven-layer Web application firewall component can be called to identify the corresponding initial session according to the internal header identifier and create the first session, thereby ensuring the continuity of the session, so that the business traffic can be correctly transmitted and processed according to the service orchestration order when the session is continuous, thereby realizing traffic orchestration, thereby solving the problem of session identification failure caused by the seven-layer Web application firewall component modifying the five-tuple information in the related art and thus causing orchestration failure.
[0010] These and other aspects of the present application will become more clearly understood in the description of the following embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.
[0012] Figure 1 It is a flow chart of a traffic orchestration method proposed in an embodiment of the present application.
[0013] Figure 2 This is another flow chart of a traffic scheduling method provided in an embodiment of the present application.
[0014] Figure 3 This is another flow chart of a traffic scheduling method provided in an embodiment of the present application.
[0015] Figure 4 This is another flow chart of a traffic scheduling method provided in an embodiment of the present application.
[0016] Figure 5 It is a schematic diagram of an application scenario of a traffic orchestration method provided in an embodiment of the present application.
[0017] Figure 6 This is another flow chart of a traffic scheduling method provided in an embodiment of the present application.
[0018] Figure 7 It is a connection block diagram of a traffic orchestration device provided in an embodiment of the present application.
[0019] Figure 8 It is a schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0020] The embodiments of the present application are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present application, and cannot be understood as limiting the present application.
[0021] In order to enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without making creative work are within the scope of protection of the present application.
[0022] The embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0023] An embodiment of the present application provides a traffic orchestration method, wherein the traffic orchestration method can be specifically used on an application delivery device, wherein one application delivery device can correspond to one server or multiple servers, wherein the application delivery device communicates with an initiator (e.g., a terminal device) and the server through a network respectively.
[0024] The terminal device may be, but is not limited to, various personal computers, laptops, smart phones, tablet computers, and portable wearable devices. The application delivery device may be implemented by an independent server or a server cluster consisting of multiple servers. The server may also be implemented by an independent application server or an application server cluster consisting of multiple application servers. The above network may be an external network or an internal network.
[0025] Among them, the application delivery device communicates with multiple security resource pools at the same time. In the present invention, each security resource pool adopts a bypass deployment (also known as bypass hanging) method. The security resource pool is not directly set in the network between the terminal device and the server device. Multiple security resource pools access the network between the terminal device and the server device through bypass deployment. In an optional application scenario, the application delivery device is set between the terminal device and the server, and each security resource pool accesses the network between the terminal device and the server device by establishing a transmission link with the application delivery device. Different security resource pools correspond to different security functions. Each security resource pool includes at least one security function component with the same security function. The security resource pool is an abstraction of a security capability. Each security device resource pool represents a security capability. Multiple security function components with the same security function can be managed in a unified manner. The security function components in the security resource pool can be physical security function components or virtual security function components. For example, security functional components with FW (Firewall) functions form a FW security resource pool; security functional components with WAF (Web Application Firewall) functions form a WAF security resource pool, where WAF is a system that specifically provides protection for Web applications by executing a series of security policies for HTTP / HTTPS; security functional components with IPS (Intrusion Prevention System) functions form an IPS security resource pool, where IPS is a computer network security device that can monitor the network data transmission behavior of a network or network device, and can promptly interrupt, adjust or isolate some abnormal or harmful network data transmission behaviors.
[0026] Application delivery devices, also known as AD (Application Delivery) devices or load balancing devices, are used to perform end-to-end analysis, scheduling, protection, encryption, and optimization of application data.
[0027] See also Figure 1 The present application embodiment provides a traffic scheduling method, which can be applied to an electronic device, which can be Figure 1 The application delivery device in the method includes:
[0028] Step S110: Acquire business traffic, an initial session corresponding to the business traffic, and a security service chain corresponding to the initial session.
[0029] The security service chain is used to instruct the business traffic to pass through at least one security resource pool in a preset order, and each of the security resource pools includes at least one security function component with the same security function.
[0030] Business traffic refers to the network data flow sent from the user-side terminal device to the application server. It usually includes processing requests, such as HTTP / HTTPS requests (Hypertext Transfer Protocol), which are used to access Web applications or other network services to obtain or operate resources, and can also include five-tuple information; the five-tuple information includes the source IP address, destination IP address, source port, destination port and protocol type.
[0031] The initial session corresponding to the service flow is used to record the basic information of the service flow, wherein the initial session specifically includes the session identifier, the five-tuple information of the service flow and the processing request, etc. The initial session may also include the session creation time and the session status, etc. The initial session and its corresponding subsession also save the scheduling results of each session for the security function component. Exemplarily, if a session, such as session M, schedules the security function component N, then session M saves the scheduling results for the security function component N.
[0032] In one possible implementation, the above step S110 includes:
[0033] Step S111: receiving the service traffic sent by the sending end.
[0034] Among them, the sending end can be a terminal device, such as a mobile phone, computer, smart watch, etc., which can initiate a service request.
[0035] Step S112: creating an initial session of the service traffic according to the five-tuple information of the service traffic.
[0036] It is worth mentioning that the electronic device is provided with a session list. Before executing the above step S112, the five-tuple information of the business traffic can be obtained, and the obtained five-tuple information can be matched with the stored session; if the match fails, it means that the connection corresponding to the five-tuple information is a new connection, and at this time, the connection needs to be established to establish a session, that is, the above S112 is executed. If the match is successful, it means that the connection corresponding to the five-tuple information is an existing connection, and the above business traffic may be a subsequent request of the same session, or a continuous traffic of the same session, so there is no need to establish a new initial session, and the initial session of the business traffic can be directly found according to the five-tuple information of the business traffic.
[0037] Step S113: Acquire a security service chain corresponding to the business traffic from a plurality of predefined service chains, where the security service chain is a security service chain corresponding to the initial session.
[0038] In some possible implementations, considering that the business traffic received by the electronic device is usually encrypted, especially HTTPS requests, encrypted using the SSL / TLS protocol. Therefore, the electronic device needs to have SSL / TLS decryption capabilities, which are usually achieved by integrating an SSL / TLS decryption module. The decryption module needs to be configured with an SSL / TLS certificate and a private key so that it can decrypt the encrypted communication between the client request end and the server end. That is, the electronic device can decrypt the business traffic and obtain the security service chain corresponding to the business traffic from a variety of predefined service chains based on the decrypted business traffic.
[0039] Specifically, traffic characteristics may be extracted from the business traffic; and a security service chain corresponding to the traffic characteristics may be obtained based on the corresponding relationship between the traffic characteristics and preset traffic characteristics and predefined service chains.
[0040] In some implementations, the traffic characteristics of the service traffic may include, but are not limited to, one or more of the switch inlet port, source MAC address, destination MAC address, Ethernet type, Ethernet tag, virtual local area network VLAN priority, source IP, destination IP, IP protocol field, IP service type, TCP / UDP source port number, TCP / UDP destination port number, domain name, and URL path, etc. The correspondence relationship stores predefined traffic characteristics consisting of the above one or more types of traffic information, and the security resource pools that need to be passed through in sequence for each traffic characteristic.
[0041] Exemplarily, the correspondence between the above-mentioned preset traffic characteristics and the predefined service chains may include: the first preset traffic characteristic (protocol type is TCP, source address is 192.168.1.0, and destination address is 10.0.0.0), the corresponding predefined security service chain is: FW security resource pool → seven-layer WAF security resource pool → IPS security resource pool; the second preset traffic characteristic (protocol type is TCP, source address is 192.168.2.0, and destination address is 10.0.0.0), the corresponding predefined security service chain is: FW security resource pool → IPS security resource pool.
[0042] It is worth mentioning that if the security service chain corresponding to the business traffic is not obtained from the corresponding relationship, it can be determined that there is no need to perform security protection on the business traffic. At this time, the business traffic can be sent to the server.
[0043] The above step S113 may also be replaced by the following method: obtaining the security service chain of the business traffic based on a preset service chain generation strategy.
[0044] In some embodiments, the characteristic types of the traffic characteristics of the service traffic may include, but are not limited to, switch inlet port, source MAC address, destination MAC address, Ethernet type, Ethernet tag, virtual local area network VLAN priority, source IP, destination IP, IP protocol field, IP service type, TCP / UDP source port number, TCP / UDP destination port number, domain name or URL path. For example, for the traffic characteristic of the source port number, when the traffic characteristic is that the source port number is 80, the corresponding security resource pool is the WAF security resource pool; when the traffic characteristic is that the source port number is 21, the corresponding security resource pool is the IPS security resource pool. The service chain matching strategy is used to record the matching relationship between different traffic characteristics and different security resource pools. Specifically, when determining whether it is necessary to perform security protection on the service traffic based on the preset service chain matching strategy, one or more traffic characteristics to be matched of the received service traffic are obtained, and each traffic characteristic to be matched is matched with the traffic characteristics recorded in the service chain matching strategy. If at least one traffic characteristic to be matched is matched successfully, it is determined that the service traffic needs to be protected; if all traffic characteristics to be matched fail to match, it is determined that it is not necessary to perform security protection on the service traffic. When there is at least one traffic feature to be matched that is successfully matched, the security resource pool corresponding to the at least one traffic feature to be matched is arranged according to a predetermined rule to obtain a security service chain.
[0045] Exemplarily, the security service chain can be obtained by arranging the corresponding security resource pools in sequence according to the source port number, source IP, destination IP, and destination port number of the traffic features to be matched.
[0046] Step S120: If it is determined that the security service chain corresponding to the business traffic carries information indicating that the security function component is the security resource pool where the seven-layer Web application firewall component is located, an internal header identifier is inserted into the processing request of the business traffic to obtain the first business traffic, and the security resource pool ranked first in the preset order is determined as the first security resource pool.
[0047] The internal header identifier carries the information of the initial session.
[0048] Exemplarily, if the security service chain is FW security resource pool→layer-7 WAF security resource pool→IPS security resource pool, then the layer-7 WAF security resource pool in the security service chain indicates that the security service chain carries information indicating that the security function component is the security resource pool where the layer-7 Web application firewall component is located.
[0049] Exemplarily, if the security service chain is: FW security resource pool → seven-layer WAF security resource pool → IPS security resource pool, the security resource pool ranked first in the preset order is the FW security resource pool. If the security service chain is: seven-layer WAF security resource pool → FW security resource pool, the security resource pool ranked first in the preset order is the seven-layer WAF security resource pool.
[0050] It is worth mentioning that transmission links are respectively provided between the electronic device and different security resource pools. The electronic device sends the first service traffic to the security resource pool and receives the first service traffic returned from the security resource pool through the transmission link between the electronic device and the security resource pool. When the first service traffic flows in from the transmission link, the electronic device determines that the first service traffic comes from the security resource pool corresponding to the transmission link. Exemplarily, a first transmission link is provided between the electronic device and the FW security resource pool, and a second transmission link is provided between the electronic device and the IPS security resource pool. If the first service traffic flows in from the first transmission link, the electronic device determines that the sender of the first service traffic is the FW security resource pool; if the first service traffic flows in from the second transmission link, the electronic device determines that the sender of the first service traffic is the IPS security resource pool.
[0051] In one possible implementation, the internal header identifier includes a session ID.
[0052] In some implementations, the internal header identifier may include, in addition to the session ID, information such as the source IP address, destination IP address, source port, destination port, protocol type, request URL, and request method.
[0053] Step S130: directing the first service traffic to the first security resource pool, so as to utilize the first security resource pool to process the first service traffic to obtain second service traffic.
[0054] In some embodiments, the electronic device includes at least one first network port, the security function component includes at least one second network port, the first network port can be a physical network interface or a virtual network interface, the second network port can be a physical network interface or a virtual network interface, and the communication channel formed between one of the first network ports of the electronic device and one of the second network ports of the security function component is a transmission link. In addition to the electronic device and the security function component, each transmission link can also include a switch disposed between the electronic device and the security function component so as to send the first service traffic sent by the electronic device to a certain security function component for corresponding processing according to one or more of the load and computing resources of each security function component, thereby realizing load balancing capability, wherein the transmission link of each security function component in the security resource pool corresponds to the security resource pool, and the transmission link between any security function component in the security resource pool and the electronic device can point to the security resource pool.
[0055] It is worth mentioning that if the security function component in the first security resource pool is a seven-layer Web application firewall component, the seven-layer Web application firewall component can parse the HTTP request and obtain a detection result based on the HTTP request traffic anomaly detection analysis. If the detection result indicates that the first business traffic is normal, a security header is added to the first business request, and the five-tuple information of the first business request is modified to obtain the second business traffic. If the detection result indicates that the first business traffic is abnormal, the seven-layer Web application firewall component blocks the first business request, treats the first business request as malicious traffic, records the detailed information of the malicious traffic, triggers an alarm, and returns an error response to the client.
[0056] Step S140: If the security function component in the first security resource pool is a seven-layer Web application firewall component, the second business traffic is obtained based on the business traffic obtained by modifying the five-tuple information of the first business traffic according to the address information configured by the first seven-layer Web application firewall component, then the first virtual service is called to parse the second business traffic to obtain the internal header identifier.
[0057] The first virtual service is associated with address information configured by a first layer-7 Web application firewall component.
[0058] The electronic device can determine the type of security resource pool that transmits the second business traffic through the receiving network port of the second business traffic, and determine the first virtual service for parsing the second business traffic based on the received five-tuple information of the second business traffic and the address information of the firewall components associated with each of the pre-set multiple virtual services, and call the first virtual service to parse the second business traffic.
[0059] Among them, virtual services corresponding to each seven-layer Web application firewall component in the security resource pool where the seven-layer Web application firewall component is located are pre-created in the electronic device. The virtual service is used to parse the second business traffic processed by the corresponding seven-layer Web application firewall component to extract the internal header identifier therein, and each virtual service usually runs in an independent virtualization environment and works closely with the seven-layer Web application firewall component to ensure the accuracy and reliability of the parsing process.
[0060] Step S150: Based on the initial session information restored by the internal header identifier, a new session is generated as a first session, and the first session is marked as a subsession of the initial session.
[0061] The internal header identifier includes information of the initial session (session identifier of the initial session). The session information restored based on the internal header identifier may include, in addition to the session identifier of the initial session, a source IP address, a destination IP address, a source port, a destination port, a protocol type, and a request. When a new session is generated based on the above-mentioned initialization information, the information in the parsed internal header identifier and the traffic state processed by the seven-layer Web application firewall component (such as at least one of the result of the security detection and the modified five-tuple information) are filled into the new session to obtain a first session. When marking the first session as a child session of the initial session, a field may be added to the first session to identify the parent session ID. The session ID of the initial session may be the same as or different from the session ID of the first session.
[0062] By adopting the above method, when it is determined that the security service chain corresponding to the business traffic carries information indicating that the security function component is the security resource pool where the seven-layer Web application firewall component is located, an internal header identifier is inserted into the processing request of the business traffic to obtain the first business traffic, so that the security function component in the first security resource pool is the seven-layer Web application firewall component, and after the first seven-layer Web application firewall component modifies the five-tuple information of the first business traffic when processing the first business traffic to obtain the second business traffic, the electronic device can call the first virtual service corresponding to the first seven-layer Web application firewall component to identify the corresponding initial session and create the first session through the inserted internal header identifier, thereby ensuring the continuity of the session, so that when the session is continuous, the business traffic can be correctly transmitted and processed according to the service orchestration order to realize traffic orchestration, thereby solving the problem of session identification failure caused by the seven-layer Web application firewall component modifying the five-tuple information in the related art, thereby causing orchestration failure.
[0063] In addition, it should be noted that by setting up a security resource pool, dynamic expansion or contraction can be achieved according to the specific amount of business traffic to ensure full utilization of resources.
[0064] See also Figure 2 In one possible implementation, after executing the above step S150, the method further includes:
[0065] Step S160: Determine whether there is a next security resource pool adjacent to the first security resource pool according to the security service chain and the first session.
[0066] Specifically, it can be determined based on the first session and the security service chain whether there is a next security resource pool adjacent to the first security resource pool, wherein the session information of the first session carries the current processing stage of the session, processed security function components, etc. The processed security function components and the security service chain can be used to determine whether there is a next security resource pool adjacent to the first security resource pool.
[0067] Exemplarily, if the security service chain is: seven-layer WAF security resource pool→FW security resource pool, and the first session indicates that the processed security function component is a seven-layer WAF security function component, it can be determined that there is a next security resource pool, and the next security resource pool is the FW security resource pool.
[0068] If so, execute step S760: use the next security resource pool as a new first security resource pool, use the second service flow as a new first service flow, and use the first session as a new initial session, and return to execute step S130.
[0069] By adopting the above steps 160-S170, it is possible to automatically arrange the business traffic in a predetermined order to various security resource pools for processing, and because each security resource pool can be optimized for a specific security function, the security of the business traffic is improved.
[0070] If there is no next security resource pool adjacent to the first security resource pool, step S180 is executed: the second service traffic obtained after being processed in sequence by each security resource pool in the security service chain is sent to the server.
[0071] See also Figure 3 In one possible implementation, after executing step S130, the method further includes:
[0072] Step S190: If the five-tuple information of the second business traffic matches the initial session, it is determined that the security function component in the first security resource pool is not a seven-layer Web application firewall component, a third session is created based on the initial session and the second business traffic, and the third session is marked as a subsession of the initial session.
[0073] By matching the five-tuple information, the newly created third session is ensured to be consistent with the initial session, ensuring the continuity and integrity of the session. By marking the third session as a subsession of the initial session, the processing process of each session can be recorded and tracked in more detail, which is convenient for subsequent auditing and troubleshooting. For example, according to the security service chain configuration, it is determined that the current session needs to pass through the seven-layer WAF security resource pool, FW security resource pool, IPS security resource pool and AV security resource pool in sequence. If the third session indicates that the business traffic has been processed by the seven-layer WAF security function component, it can be determined whether there is a next security resource pool based on the security service chain and the third session, and the next security resource pool is the FW security resource pool.
[0074] After executing step S190, the method further includes:
[0075] Step S2000: Determine whether there is a next security resource pool adjacent to the first security resource pool based on the security service chain and the third session.
[0076] If so, execute step S210: use the next security resource pool as a new first security resource pool, use the second service flow as a new first service flow, and use the third session as a new initial session, and return to execute step S120.
[0077] For the specific implementation principles of the above steps S190-S210, please refer to the specific description of the above steps S160-S170, which will not be repeated here.
[0078] If not, execute the aforementioned step S180: send the second service traffic obtained after being processed in sequence by each security resource pool in the security service chain to the server.
[0079] In one possible implementation, before executing step S180, the method further includes: deleting the internal header identifier from the processing request of the second service flow to obtain an updated second service flow.
[0080] Since the internal header identifier contains sensitive information, such as the source IP address, request URL, etc., deleting the internal header identifier can protect user privacy and prevent sensitive information leakage. In addition, deleting the internal header identifier can make the updated second service traffic more standardized, ensuring that the updated second service traffic will not be affected by additional internal header information during subsequent processing.
[0081] It is worth mentioning that the above-mentioned second business traffic can be the second business traffic obtained by the first seven-layer Web application firewall component based on the first business traffic, or it can be the second business traffic obtained by the last security resource pool in the security service chain, which is not specifically limited here.
[0082] See also Figure 4 In one possible implementation, after executing the aforementioned step S170, the method further includes:
[0083] Step S220: receiving feedback traffic generated by the server based on the received second service traffic.
[0084] Step S230: Determine the last security resource pool in the security service chain as the second security resource pool.
[0085] Specifically, the initial session of the feedback traffic can be found based on the five-tuple information of the feedback traffic. Once the corresponding initial session is found, the processing service chain that the feedback traffic needs to follow can be determined. This processing service chain includes the same security resource pool as the security service chain corresponding to the initial session, but the sorting order of these resource pools is opposite to the preset order. This means that if the business traffic first passes through a certain security function component (seven-layer Web application firewall component), then the feedback traffic of the business traffic will finally pass through the security function component (that is, the seven-layer Web application firewall component).
[0086] Step S240: directing the feedback traffic to the second security resource pool, so as to utilize the second security resource pool to process the feedback traffic to obtain the first feedback traffic.
[0087] It is worth mentioning that, for example, if the security service chain of business traffic is: FW security resource pool → seven-layer WAF security resource pool → IPS security resource pool, the resource pools that the feedback traffic corresponding to the business traffic passes through in sequence are: IPS security resource pool → seven-layer WAF security resource pool → FW security resource pool. If the security service chain of business traffic is: seven-layer WAF security resource pool → FW security resource pool: the processing service chain of the feedback traffic corresponding to the business traffic is: FW security resource pool → seven-layer WAF security resource pool.
[0088] In addition, it should be noted that during the entire feedback traffic processing process, since the feedback traffic is a direct response to the business traffic, it is always associated with the same initial session. Therefore, the processing logic of the feedback traffic can be based on the initial session information of the corresponding business traffic, and the processing of the feedback traffic is only through a series of pre-defined security resource pools, and the role of these resource pools is to perform necessary security processing on the traffic, rather than to establish or change the session state. When processing the feedback traffic, there is no need to create a session.
[0089] Exemplarily, in one implementable embodiment, the method also includes determining whether there is an upper security resource pool adjacent to the second security resource pool in the security service chain; if so, using the upper security resource pool as the new second security resource pool, using the processed first feedback traffic as the new feedback traffic and returning to execute the step of directing the feedback traffic to the second security resource pool, so as to use the second security resource pool to process the first feedback traffic to obtain the first feedback traffic; if not, sending the first feedback traffic obtained after being processed in sequence by each security resource pool in the security service chain to the sending end of the business traffic.
[0090] For example, assuming that the security service chain of the business traffic is: FW security resource pool → seven-layer WAF security resource pool → IPS security resource pool, then the feedback traffic first selects the IPS security resource pool as the second security resource pool to process the feedback traffic. After the IPS security resource pool completes processing of the feedback traffic, it then checks whether there is an upper security resource pool (seven-layer WAF security resource pool) adjacent to the IPS security resource pool in the security service chain. If so, it sets it as the new second security resource pool and continues to process the processed feedback traffic as the new input; next, it checks again whether there is an upper security resource pool (FW security resource pool) adjacent to the seven-layer WAF security resource pool. If so, repeat the above steps. Finally, when there are no more security resource pools, the feedback traffic processed by all security resource pools (that is, the feedback traffic processed by the IPS security resource pool → the seven-layer WAF security resource pool → the FW security resource pool in sequence) is sent back to the sender.
[0091] The present invention provides a method for traffic scheduling, which includes the following stages:
[0092] 1. Security device resource pool and virtual service creation phase:
[0093] Create multiple security device resource pools (such as FW resource pool, IPS resource pool and WAF security resource pool). Since the seven-layer Web application firewall component in the WAF security resource pool will modify the destination IP or port of the data packet, in order to correctly identify the traffic returned from the WAF security resource pool to the single device, it is necessary to specify the rewritten destination IP and port of the seven-layer Web application firewall component in the WAF security resource pool when configuring the seven-layer anti-generation security device. An internal virtual service can be created based on the IP and port of each seven-layer Web application firewall component in the WAF security resource pool, so that each virtual service is associated with the address information configured by a seven-layer Web application firewall component.
[0094] 2. Security service chain creation stage:
[0095] Create service chains corresponding to various traffic characteristics. A service chain is an abstraction of a set of security capabilities. It is responsible for orchestrating which resource pools the traffic needs to pass through, the order in which it passes through the resource pools, and whether the traffic can bypass a resource pool when a resource pool is unavailable. Figure 5 As shown in the service chain topology, it indicates that when business traffic is orchestrated according to the service chain, it needs to pass through the FW security resource pool first, then the WAF security resource pool, and finally the IPS security resource pool.
[0096] 3. Traffic Orchestration Phase
[0097] Taking the security service chain of business traffic as Figure 5 The service chain in the example: FW security resource pool → WAF security resource pool → IPS security resource pool is used for explanation. The service traffic transmitted between the sender and the electronic device is transmitted in the form of ciphertext, and the service traffic transmitted between the electronic device and the server can be transmitted in the form of plaintext / ciphertext.
[0098] See also Figure 6 After the electronic device receives the business traffic sent by the sender, it can first decode the business traffic into plain text, and then create an initial session (session 1) of the business traffic based on the decoded quintuple information of the business traffic; obtain the security service chain corresponding to the business traffic from a variety of predefined service chains, and the security service chain is the security service chain corresponding to the initial session.
[0099] Since the security service chain corresponding to the business traffic carries information indicating that the security function component is the security resource pool where the seven-layer Web application firewall component is located, an internal header identifier (HTTP header identifier) is inserted into the processing request of the business traffic to obtain the first business traffic, and the security resource pool (FW security resource pool) ranked first in the preset order is determined as the first security resource pool, and the internal header identifier carries the information of the initial session.
[0100] The electronic device forwards the first service traffic to the FW security resource pool, so that the security function component in the FW security resource pool processes the first service traffic to obtain the second service traffic and feeds it back to the electronic device.
[0101] Since the quintuple of the second service data has not changed after passing through the FW security device, after the second service traffic returns to the electronic device, the electronic device can directly identify that the second service traffic is the service traffic corresponding to the initial session. At this time, a first session (session 2) can be generated based on the second service traffic and the initial session, and the first session is marked as a subsession of the initial session. That is, session 2 is a subsession of session 1.
[0102] According to the first session and the security service chain, it can be determined that there is a next security resource pool (WAF security resource pool) adjacent to the first security resource pool (FW security resource pool). At this time, the next security resource pool (WAF security resource pool) can be used as a new first security resource pool, the second business traffic can be used as a new first business traffic, and the first session can be used as a new initial session, and the first business traffic can be sent to the first security resource pool (WAF security resource pool).
[0103] Among them, the security function component of the WAF security resource pool is a seven-layer Web application firewall component. Therefore, when the first seven-layer Web application firewall component in the WAF security resource pool receives the first business traffic, it will process the first business traffic and modify the five-tuple information of the first business traffic according to the address information configured by the first seven-layer Web application firewall component itself to obtain the second business traffic.
[0104] When the electronic device receives the second service flow returned by the WAF security resource pool, it can call the first virtual service to parse the second service flow, obtain the internal header identifier (HTTP header identifier), and generate a first session (session 3) based on the internal header identifier and the second service flow. The first virtual service is associated with the address information configured by the first seven-layer Web application firewall component. Among them, session 3 is a subsession of session 2 and includes relevant information of session 2.
[0105] After obtaining the second service flow, the internal header identifier (HTTP header identifier) may be deleted from the processing request of the second service flow to obtain an updated second service flow.
[0106] The electronic device can also determine the existence of a next security resource pool (IPS security resource pool) adjacent to the first security resource pool (WAF security resource pool) based on the first session (session 3) and the security service chain. The next security resource pool (IPS security resource pool) is used as a new first security resource pool (IPS security resource pool), the first session (session 3) is used as a new initial session, the second service traffic is used as a new first service traffic, and then the first service traffic is sent to the first security resource pool (IPS security resource pool).
[0107] The electronic device can also receive the second service traffic returned by the first security resource pool (IPS security resource pool), and generate a first session (session 4) based on the second service traffic and the initial session (session 3), and mark session 4 as a subsession of session 3. Afterwards, according to session 4 and the security service chain, it can be determined that all security resource pools corresponding to the security service chain have been arranged, that is, there is no next security resource pool adjacent to the first security resource pool (IPS security resource pool). At this time, the second service traffic obtained after being processed in sequence by each security resource pool in the security service chain can be sent to the service end.
[0108] It is worth mentioning that, since multiple sessions corresponding to business traffic have been established above (i.e., session 1, session 2, session 3, and session 4), when the electronic device receives the feedback traffic returned by the server based on the business traffic, it can determine that the initial session of the feedback traffic is session 1 based on the five-tuple information of the feedback traffic. Thereafter, it can be determined based on session 1 and its corresponding sub-sessions that the feedback traffic needs to pass through the following security resource pools once: IPS security resource pool → WAF security resource pool → FW security resource pool. At this time, the electronic device can input the business traffic into the IPS security resource pool, WAF security resource pool, and FW security resource pool in turn for business processing, and finally send the second feedback traffic obtained after being processed in turn by each security resource pool in the processing service chain to the sending end.
[0109] like Figure 7 , Figure 7A traffic orchestration device 300 provided in an embodiment of the present application is applied to an electronic device. The device 300 includes: a data acquisition module 310, an identification insertion module 320, a traffic introduction module 330, a traffic parsing module 350, and a session generation module 350. The data acquisition module 310 is used to obtain business traffic, an initial session corresponding to the business traffic, and a security service chain corresponding to the initial session. The security service chain is used to indicate that the business traffic passes through at least one security resource pool in a preset order, and each of the security resource pools includes at least one security function component with the same security function; the identification insertion module 320 is used to determine that the security service chain corresponding to the business traffic carries information indicating that the security function component is the security resource pool where the seven-layer Web application firewall component is located, insert an internal header identification into the processing request of the business traffic to obtain a first business traffic, and determine the security resource pool ranked first in the preset order as the first security resource pool, and the internal header identification carries the information of the initial session; the traffic introduction module 330 is used to insert the first business flow The first service flow is directed to the first security resource pool so as to use the first security resource pool to process the first service flow to obtain the second service flow; a traffic parsing module 340 is used for, when the security function component in the first security resource pool is a seven-layer Web application firewall component, and the second service flow is obtained by modifying the five-tuple information of the first service flow according to the address information configured by the first seven-layer Web application firewall component, calling the first virtual service to parse the second service flow to obtain the internal header identifier, and the first virtual service is associated with the address information configured by the first seven-layer Web application firewall component; a session generation module 350 is used to generate a new session as the first session based on the initial session information restored by the internal header identifier, and mark the first session as a subsession of the initial session.
[0110] In one possible implementation, the traffic orchestration device 300 also includes a judgment module and a data update module, the judgment module being used to judge whether there is a next security resource pool adjacent to the first security resource pool based on the security service chain and the first session; the data update module being used to, when there is a next security resource pool adjacent to the first security resource pool, use the next security resource pool as a new first security resource pool, use the second business traffic as a new first business traffic, and use the first session as a new initial session.
[0111] In one possible implementation, the traffic orchestration device 300 also includes a traffic sending module for sending the second business traffic obtained after being processed in sequence by each security resource pool in the security service chain to the server when there is no next security resource pool adjacent to the first security resource pool.
[0112] In one possible implementation, the traffic orchestration device 300 further includes: a traffic receiving module and a service chain determination module. The traffic receiving module is used to receive feedback traffic generated by the server based on the received second service traffic; a resource pool determination module is used to determine the last security resource pool in the security service chain as the second security resource pool; and a feedback traffic processing module is used to direct the feedback traffic to the second security resource pool so as to process the feedback traffic using the second security resource pool to obtain the first feedback traffic.
[0113] In one possible implementation, the judgment module is also used to judge whether there is an upper security resource pool adjacent to the second security resource pool in the security service chain; the data update module is also used to, if so, use the upper security resource pool as the new second security resource pool and the processed first feedback traffic as the new feedback traffic; the traffic sending module is also used to send the first feedback traffic obtained after being processed in sequence by each security resource pool in the security service chain to the sending end of the business traffic when there is no upper security resource pool adjacent to the second security resource pool.
[0114] In one possible implementation, the session generation module is further used to determine that the security function component in the first security resource pool is not a seven-layer Web application firewall component when the five-tuple information of the second business traffic matches the initial session, create a third session based on the initial session and the second business traffic, and mark the third session as a subsession of the initial session.
[0115] In one feasible implementation, the judgment module is used to judge whether there is a next security resource pool adjacent to the first security resource pool based on the security service chain and the third session; the data update module is used to, when there is a next security resource pool adjacent to the first security resource pool, use the next security resource pool as the new first security resource pool, use the second business traffic as the new first business traffic, and use the third session as the new initial session.
[0116] In one possible implementation, the data acquisition module includes a data receiving submodule, a session creation submodule, a decryption submodule, and a service chain acquisition submodule. The data receiving submodule is used to receive the business traffic sent by the sender; the session creation submodule is used to create an initial session of the business traffic according to the five-tuple information of the business traffic; the service chain acquisition submodule is used to acquire a security service chain corresponding to the business traffic from a plurality of predefined service chains, and the security service chain is the security service chain corresponding to the initial session.
[0117] In one possible implementation, the service chain acquisition submodule is further used to extract traffic characteristics from the business traffic; and obtain a security service chain corresponding to the traffic characteristics based on the correspondence between the traffic characteristics and preset traffic characteristics and predefined service chains.
[0118] In one possible implementation, the traffic orchestration device 300 further includes: a traffic update module, configured to delete the internal header identifier from the processing request of the second service traffic to obtain an updated second service traffic.
[0119] Correspondingly, such as Figure 8 The embodiment of the present application also provides an electronic device 400, which may be an electronic device such as a smart phone, a tablet computer, a server, etc. that can run applications. The electronic device 400 may include one or more processors 410, a memory 420, and one or more applications, wherein the one or more applications are stored in the memory 420 and configured to be executed by the one or more processors 410, and the one or more applications are configured to execute the above-mentioned traffic orchestration method.
[0120] It can be understood that the processor 410 and the memory 420 are connected via a communication bus to complete the communication between them, and the processor 420 can call the logic instructions in the memory 420 to execute the speech template generation method in any of the aforementioned embodiments. Exemplarily, the processor 410 can be implemented in the form of a general-purpose CPU, a microprocessor, an application-specific integrated circuit (Application Specific Integrated Circuit.ASIC), or one or more integrated circuits, etc., for executing related programs to implement the technical solution provided in this application. The memory can include ROM (Read Only Memory, read-only memory), RAM (Random Access Memory, random access memory) static storage devices, dynamic storage devices, etc.
[0121] Correspondingly, an embodiment of the present application further provides a computer-readable storage medium, in which a program code is stored, and the program code can be called by a processor to execute the above-mentioned traffic orchestration method.
[0122] It can be understood that the logic instructions in the above-mentioned memory can be implemented in the form of software functional units and can be stored in a computer-readable storage medium when sold or used as an independent product.
[0123] Part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes a number of instructions for enabling a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of various embodiments of the present invention. The aforementioned storage medium includes: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and other media that can store program codes.
[0124] The above are only preferred embodiments of the present application, and are not intended to limit the present application in any form. Although the present application has been disclosed as above with preferred embodiments, it is not intended to limit the present application. Any technical personnel in the field can make some changes or modify the technical contents disclosed above into equivalent embodiments without departing from the scope of the technical solution of the present application. However, any brief modifications, equivalent changes and modifications made to the above embodiments based on the technical essence of the present application without departing from the content of the technical solution of the present application are still within the scope of the technical solution of the present application.
Claims
1. A traffic scheduling method, characterized in that: The method comprises: Acquire business traffic, an initial session corresponding to the business traffic, and a security service chain corresponding to the initial session, wherein the security service chain is used to indicate that the business traffic passes through at least one security resource pool in a preset order, and each of the security resource pools includes at least one security function component having the same security function; If it is determined that the security service chain corresponding to the business flow carries information indicating that the security function component is the security resource pool where the seven-layer Web application firewall component is located, inserting the internal header identifier into the processing request of the business flow to obtain the first business flow, determining the security resource pool ranked first in the preset sequence as the first security resource pool, and the internal header identifier carries the information of the initial session; Directing the first service traffic to the first security resource pool, so as to use the first security resource pool to process the first service traffic to obtain second service traffic; If the security function component in the first security resource pool is a seven-layer Web application firewall component, the second service flow is obtained based on the service flow obtained by modifying the five-tuple information of the first service flow according to the address information configured by the first seven-layer Web application firewall component, then calling the first virtual service to parse the second service flow to obtain the internal header identifier, and the first virtual service is associated with the address information configured by the first seven-layer Web application firewall component; Based on the restored initial session information of the internal header identifier, a new session is generated as a first session, and the first session is marked as a subsession of the initial session.
2. The method according to claim 1, characterized in that The method further comprises: Determining whether there is a next security resource pool adjacent to the first security resource pool according to the security service chain and the first session; If it exists, use the next security resource pool as the new first security resource pool, use the second business traffic as the new first business traffic, and use the first session as the new initial session, and return to execute the step of directing the first business traffic to the first security resource pool, so as to use the first security resource pool to process the first business traffic to obtain the second business traffic.
3. The method according to claim 2, characterized in that The method further comprises: If there is no next security resource pool adjacent to the first security resource pool, the second service traffic obtained after being processed in sequence by the security resource pools in the security service chain is sent to the server.
4. The method according to claim 3, characterized in that The method further comprises: Receiving feedback traffic generated by the server based on the received second service traffic; Determining the last security resource pool in the security service chain as the second security resource pool; The feedback traffic is directed to the second security resource pool, so that the feedback traffic is processed by the second security resource pool to obtain the first feedback traffic.
5. The method according to claim 4, characterized in that The method further comprises: Determining whether there is a previous security resource pool adjacent to the second security resource pool in the security service chain; If so, use the previous security resource pool as a new second security resource pool, use the processed first feedback traffic as new feedback traffic, and return to execute the step of directing the feedback traffic to the second security resource pool, so as to use the second security resource pool to process the first feedback traffic to obtain the first feedback traffic; If not present, the first feedback traffic obtained after being processed in sequence by each security resource pool in the security service chain is sent to the sending end of the business traffic.
6. The method according to claim 1, characterized in that The method further comprises: If the five-tuple information of the second business traffic matches the initial session, it is determined that the security function component in the first security resource pool is not a seven-layer Web application firewall component, a third session is created based on the initial session and the second business traffic, and the third session is marked as a subsession of the initial session.
7. The method according to claim 6, characterized in that The method further comprises: determining whether there is a next security resource pool adjacent to the first security resource pool according to the security service chain and the third session; If it exists, use the next security resource pool as the new first security resource pool, use the second business traffic as the new first business traffic, and use the third session as the new initial session, and return to execute the step of directing the first business traffic to the first security resource pool, so as to use the first security resource pool to process the first business traffic to obtain the second business traffic.
8. The method according to claim 1, characterized in that: The acquiring of the service flow, the initial session corresponding to the service flow, and the security service chain corresponding to the initial session includes: Receive business traffic sent by the sender; Creating an initial session of the service traffic according to the five-tuple information of the service traffic; A security service chain corresponding to the business traffic is obtained from a plurality of predefined service chains, where the security service chain is a security service chain corresponding to the initial session.
9. The method according to claim 8, characterized in that The obtaining of the security service chain corresponding to the business traffic from a plurality of predefined service chains, where the security service chain is a security service chain corresponding to the initial session, includes: Extracting traffic features from the service traffic; A security service chain corresponding to the traffic feature is obtained according to the correspondence between the traffic feature and the preset traffic feature and the predefined service chain.
10. The method according to any one of claims 1 to 9, characterized in that: The method further comprises: The internal header identifier is deleted from the processing request of the second service flow to obtain an updated second service flow.
11. A traffic scheduling device, characterized in that: The device comprises: A data acquisition module, used to acquire business traffic, an initial session corresponding to the business traffic, and a security service chain corresponding to the initial session, wherein the security service chain is used to indicate that the business traffic passes through at least one security resource pool in a preset order, and each of the security resource pools includes at least one security function component having the same security function; an identification insertion module, configured to carry information indicating that the security function component is a security resource pool where the seven-layer Web application firewall component is located in the security service chain corresponding to the business flow, insert an internal header identification into a processing request of the business flow to obtain a first business flow, determine the security resource pool ranked first in the preset sequence as the first security resource pool, and carry information of the initial session in the internal header identification; A traffic introduction module, used to introduce the first service traffic to the first security resource pool, so as to use the first security resource pool to process the first service traffic to obtain a second service traffic; a traffic parsing module, for, when the security function component in the first security resource pool is a seven-layer Web application firewall component, and the second business traffic is obtained based on the business traffic obtained after the first seven-layer Web application firewall component modifies the five-tuple information of the first business traffic according to the address information configured therein, calling the first virtual service to parse the second business traffic and obtain the internal header identifier, and the first virtual service is associated with the address information configured by the first seven-layer Web application firewall component; A session generation module is used to generate a first session based on the internal header identifier, and mark the first session as a subsession of the initial session.
12. An electronic device, characterized in that: include: one or more processors; Memory; One or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the method according to any one of claims 1-10.
13. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores program codes, and the program codes can be called by a processor to execute the method according to any one of claims 1 to 10.
14. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the method described in any one of claims 1 to 10 are implemented.
Citation Information
Patent Citations
Method and device for access of service function node to service link network
CN104283891A
Service flow arrangement method and device, application delivery equipment and medium
CN115296842A
Traffic arrangement method, electronic equipment and device
CN116684289A
Safe traffic arrangement method, device and equipment
CN116846777A
Method and apparatus for traffic orchestration
WO2023245721A1
Cited By
Port multiplexing method and device, electronic equipment, medium and computer program product
CN120614336A
Port multiplexing methods, apparatuses, electronic devices, media and computer program products
CN120614336B