Message processing method and device, electronic equipment and storage medium

By predicting the upper limit of the kernel state flow table of the virtual switch in advance and intercepting target packets, the network bottleneck problem of the cloud computing management platform is solved, the packet processing efficiency is improved, and network stability is ensured.

CN119945921AActive Publication Date: 2025-05-06JINAN INSPUR DATA TECH CO LTD

Patent Information

Application Number
CN202510103787.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-05-06
Estimated Expiration
2045-01-22

Smart Images

  • Figure CN119945921A_ABST
    Figure CN119945921A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of cloud computing, and discloses a message processing method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining the current environment information of a host machine; determining a kernel mode flow table upper limit value of a virtual switch according to the current environment information of the host machine; determining a kernel mode message interception condition of the virtual switch according to the kernel mode flow table upper limit value of the virtual switch; and under the condition that the kernel mode flow table number of the virtual switch meets the kernel mode message interception condition, intercepting a target message in to-be-processed messages to be transmitted to the kernel mode of the virtual switch. The upper limit value of the kernel mode flow table of the virtual switch is predicted in advance, and the number of the kernel mode flow tables of the virtual switch is accurately controlled, so that the network bottleneck caused by excessive kernel mode flow tables is effectively avoided, the message processing efficiency is improved, and the network stability and the operation efficiency of a cloud computing management platform are further guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of cloud computing, and in particular to a message processing method, device, electronic device and storage medium. Background Art

[0002] With the development of cloud computing technology, cloud computing management platforms have been widely used. Open Virtual Switch (OVS), as an open source virtual switch software, is often used in cloud computing management platforms. OVS implements software switches with similar functions to most switches. As the number of users increases, cloud computing management platforms are facing increased network traffic. In the process of applying OVS, network bottlenecks may occur, and even data loss may occur.

[0003] In the related art, when OVS reaches a network bottleneck, the flow table of all pending messages in the kernel state is usually analyzed, and the flow table entries of the pending messages with common characteristics are merged to merge and process these pending messages.

[0004] However, the above method can only be used for merging and processing after the OVS network bottleneck problem occurs, and the merging and processing process is relatively cumbersome. It not only cannot fundamentally solve the network bottleneck problem of the cloud computing management platform, but also reduces the processing efficiency of the messages to be processed. Summary of the invention

[0005] The present application provides a message processing method, device, electronic device and storage medium to solve the defects that related technologies cannot fundamentally solve the network bottleneck problem of cloud computing management platform, reduce the message processing efficiency, etc.

[0006] The first aspect of the present application provides a message processing method, including:

[0007] Acquire current environment information of a host machine; wherein the host machine is deployed with a virtual switch;

[0008] Determine the upper limit value of the kernel state flow table of the virtual switch according to the current environment information of the host machine;

[0009] Determining a kernel state message interception condition of the virtual switch according to an upper limit value of a kernel state flow table of the virtual switch;

[0010] When the number of kernel state flow tables of the virtual switch meets the kernel state message interception condition, the target message in the to-be-processed messages to be transmitted to the kernel state of the virtual switch is intercepted.

[0011] In an optional implementation, determining the upper limit of the kernel state flow table of the virtual switch according to the current environment information of the host machine includes:

[0012] Under a preset experimental environment, the host machine is subjected to a stress test to obtain test environment information of the host machine when receiving different numbers and types of to-be-processed messages; wherein the test environment information includes at least processor usage, memory occupancy, disk performance index, and network performance index;

[0013] Constructing a plurality of feature vectors according to the test environment information; wherein the feature vectors include a plurality of host machine performance indicators and the number of kernel state flow tables;

[0014] Dividing the multiple feature vectors into a model training sample set and a model testing sample set;

[0015] Based on the model training sample set and the model test sample set, a kernel state flow table upper limit value prediction model is constructed;

[0016] The current environment information of the host machine is input into the kernel state flow table upper limit value prediction model to determine the kernel state flow table upper limit value of the virtual switch based on the kernel state flow table upper limit value prediction model and according to the current environment information.

[0017] In an optional implementation, when the number of kernel state flow tables of the virtual switch meets the kernel state message interception condition, intercepting the target message in the to-be-processed messages to be transmitted to the kernel state of the virtual switch includes:

[0018] When the number of kernel state flow tables of the virtual switch meets the kernel state message interception condition, classification feature extraction is performed on the kernel state flow tables of the virtual switch to obtain classification feature information of each kernel state flow table of the virtual switch; wherein the classification feature information at least includes a destination address, a source address, a protocol type, and a data packet type;

[0019] According to the classification feature information of each kernel state flow table, kernel state flow table classification is performed to obtain corresponding kernel state flow table classification results;

[0020] Determining, according to the kernel state flow table classification result, the type of abnormal kernel state flow table that causes the surge in the number of kernel state flow tables of the virtual switch;

[0021] According to the abnormal kernel state flow table type, target messages are screened from the pending messages to be transmitted to the kernel state of the virtual switch, and the target messages are intercepted.

[0022] In an optional implementation, determining the abnormal kernel-state flow table type causing a surge in the number of kernel-state flow tables of the virtual switch according to the kernel-state flow table classification result includes:

[0023] Determine multiple kernel state flow table types according to the kernel state flow table classification results, and perform corresponding type grouping to determine the number of kernel state flow tables in each group of the kernel state flow table type;

[0024] According to the number of kernel state flow tables in each group of the kernel state flow table types, the kernel state flow table type with the largest number of kernel state flow tables in the group is taken as the abnormal kernel state flow table type causing a surge in the number of kernel state flow tables of the virtual switch.

[0025] In an optional implementation, the step of screening a target message from the to-be-processed messages to be transmitted to the virtual switch kernel state according to the abnormal kernel state flow table type, and intercepting the target message includes:

[0026] Determine the abnormal kernel state flow table configuration information according to the abnormal kernel state flow table type;

[0027] According to the abnormal kernel state flow table configuration information, the target message is screened from the to-be-processed messages to be transmitted to the kernel state of the virtual switch; wherein the configuration information of the target message matches the abnormal kernel state flow table configuration information;

[0028] According to the abnormal kernel state flow table configuration information, a corresponding abnormal message interception command is constructed to intercept the target message based on the abnormal message interception command.

[0029] In an optional embodiment, the method further includes:

[0030] When the number of kernel state flow tables of the virtual switch meets the kernel state message interception condition, generating abnormal alarm information;

[0031] The abnormal alarm information includes abnormal kernel state flow table configuration information and abnormal message interception command.

[0032] In an optional implementation, determining the kernel state message interception condition of the virtual switch according to the kernel state flow table upper limit value of the virtual switch includes:

[0033] Get the virtual switch flow table threshold issued by the user;

[0034] Determining a kernel state message interception condition of the virtual switch according to the virtual switch flow table threshold and the kernel state flow table upper limit;

[0035] The kernel-state message interception condition at least includes a kernel-state flow table interception value. When the number of kernel-state flow tables of the virtual switch reaches the kernel-state flow table interception value, it is determined that the kernel-state message interception condition is met.

[0036] A second aspect of the present application provides a message processing device, including:

[0037] An acquisition module, used to acquire current environment information of a host machine; wherein the host machine is deployed with a virtual switch;

[0038] A first determination module, configured to determine an upper limit value of a kernel state flow table of a virtual switch according to current environment information of the host machine;

[0039] A second determination module, configured to determine a kernel state message interception condition of the virtual switch according to an upper limit value of a kernel state flow table of the virtual switch;

[0040] The processing module is used to intercept the target message in the to-be-processed messages to be transmitted to the kernel state of the virtual switch when the number of kernel state flow tables of the virtual switch meets the kernel state message interception condition.

[0041] A third aspect of the present application provides an electronic device, comprising: at least one processor and a memory;

[0042] The memory stores computer-executable instructions;

[0043] The at least one processor executes the computer-executable instructions stored in the memory, so that the at least one processor performs the method described in the first aspect and various possible designs of the first aspect.

[0044] A fourth aspect of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions. When a processor executes the computer-executable instructions, the method described in the first aspect and various possible designs of the first aspect are implemented.

[0045] A fifth aspect of the present application provides a computer program product, including computer instructions, which are used to enable a computer to execute the method described in the first aspect and various possible designs of the first aspect.

[0046] The technical solution of this application has the following advantages:

[0047] The present application provides a message processing method, device, electronic device and storage medium, the method comprising: obtaining the current environment information of the host machine; wherein the host machine is deployed with a virtual switch; according to the current environment information of the host machine, determining the upper limit value of the kernel state flow table of the virtual switch; according to the upper limit value of the kernel state flow table of the virtual switch, determining the kernel state message interception condition of the virtual switch; when the number of kernel state flow tables of the virtual switch meets the kernel state message interception condition, intercepting the target message in the to-be-processed message to be transmitted to the kernel state of the virtual switch. The method provided by the above scheme effectively avoids the network bottleneck caused by too many kernel state flow tables by predicting the upper limit value of the kernel state flow table of the virtual switch in advance and accurately controlling the number of kernel state flow tables of the virtual switch, thereby improving the message processing efficiency and thus ensuring the network stability and operation efficiency of the cloud computing management platform. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related technologies, the following is a brief introduction to the drawings required for use in the embodiments or the related technical descriptions. Obviously, the drawings described below are some embodiments of the present application, and a person skilled in the art can also obtain other drawings based on these drawings.

[0049] Figure 1 A schematic diagram of the structure of the message processing system on which the embodiments of the present application are based;

[0050] Figure 2 A flowchart of a message processing method provided in an embodiment of the present application;

[0051] Figure 3 A data packet processing flow chart of a virtual switch provided in an embodiment of the present application;

[0052] Figure 4 A schematic diagram of the training process of an exemplary kernel state flow table upper limit value prediction model provided in an embodiment of the present application;

[0053] Figure 5 A schematic diagram of the structure of a message processing device provided in an embodiment of the present application;

[0054] Figure 6 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application.

[0055] The above drawings have shown clear embodiments of the present application, which will be described in more detail later. These drawings and text descriptions are not intended to limit the scope of the present disclosure in any way, but to illustrate the concepts of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION

[0056] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0057] In addition, the terms "first", "second", etc. are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. In the description of the following embodiments, the meaning of "multiple" is more than two, unless otherwise clearly and specifically defined.

[0058] With the development of cloud computing technology, cloud computing management platforms are favored by more and more users. However, as the audience of cloud computing management platforms increases, the network traffic generated is also increasing. Excessive network traffic may cause network performance bottlenecks of cloud computing management platforms. At the least, it will cause network jams in the user environment and unstable data transmission. At the worst, it will cause user data loss and system crashes, causing inestimable losses. Although the network module in cloud computing has been maturely developed, in the case of some special abnormal situations such as traffic surges and broadcast flooding, the virtualized network in the cloud platform will still reach performance bottlenecks, causing interruptions to normal business and bringing certain risks to users.

[0059] The virtual switch Openvswitch (OVS) is a high-quality, multi-layered virtual switching software. Its purpose is to support large-scale network automation through programming extensions, while also supporting standard management interfaces and protocols. As the current open source virtual switch software, OVS implements software switches with functions similar to most commercial closed-source switches and is widely used in production environments. At present, the network bottleneck problem of OVS is mainly due to the excessive number of kernel-state flow tables being sent to user-state processing, and the packet loss caused by untimely user-state processing. In response to the above network bottleneck problems, the current cloud computing platform based on OVS mostly solves the problem by merging flow table entries, increasing system resources or modifying kernel parameters. Merging flow table entries is an adjustment that is made only after the problem occurs, and it is necessary to compare the flow tables one by one and merge the flow table items with common characteristics. The operation is cumbersome and cannot prevent the occurrence of problems; increasing system resources may lead to cost increases or resource waste; modifying kernel parameters may lead to system instability, performance degradation, resource waste, maintenance complexity, upgrades and compatibility.

[0060] In response to the above problems, the embodiments of the present application provide a message processing method, device, electronic device and storage medium, the method comprising: obtaining the current environment information of the host machine; wherein the host machine is deployed with a virtual switch; according to the current environment information of the host machine, determining the upper limit value of the kernel state flow table of the virtual switch; according to the upper limit value of the kernel state flow table of the virtual switch, determining the kernel state message interception condition of the virtual switch; when the number of kernel state flow tables of the virtual switch meets the kernel state message interception condition, intercepting the target message in the to-be-processed message to be transmitted to the kernel state of the virtual switch. The method provided by the above scheme effectively avoids the network bottleneck caused by too many kernel state flow tables by predicting the upper limit value of the kernel state flow table of the virtual switch in advance and accurately controlling the number of kernel state flow tables of the virtual switch, thereby improving the message processing efficiency and thus ensuring the network stability and operation efficiency of the cloud computing management platform.

[0061] The following specific embodiments may be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments. The embodiments of the present invention will be described below in conjunction with the accompanying drawings.

[0062] First, the structure of the message processing system on which this application is based is described:

[0063] The message processing method, device, electronic device and storage medium provided in the embodiments of the present application are suitable for processing data messages sent to a virtual switch. Figure 1 As shown, it is a structural schematic diagram of the message processing system based on the embodiment of the present application, which mainly includes a data acquisition device, a virtual switch and a message processing device. The message processing system is configured on a host machine, and the cloud computing management platform is composed of multiple host machines. Among them, the data acquisition device is used to collect the current environment information of the host machine, and send the collected current environment information to the message processing device. The message processing device predicts the upper limit value of the kernel state flow table of the virtual switch according to the information obtained, and intercepts the target message according to the prediction result to prevent the target message from entering the virtual switch.

[0064] The embodiment of the present application provides a message processing method for processing a data message sent to a virtual switch. The execution subject of the embodiment of the present application is an electronic device, such as a server, a desktop computer, a laptop computer, a tablet computer, and other electronic devices that can be used as a host to deploy a virtual switch.

[0065] like Figure 2 FIG. 1 is a flow chart of a message processing method provided in an embodiment of the present application, the method comprising:

[0066] Step 201, obtaining the current environment information of the host machine.

[0067] Among them, the host machine is deployed with a virtual switch. The current environmental information of the host machine includes the current processor CPU usage, the current memory occupancy, the current disk performance indicators (disk I / O) and the network performance indicators (network I / O). The current environmental information reflects the real-time operating status of the host machine and provides a basic basis for subsequent decision-making.

[0068] Step 202: Determine the upper limit of the kernel flow table of the virtual switch according to the current environment information of the host machine.

[0069] Specifically, a specific algorithm or model may be used to determine the upper limit of the kernel state flow table of the virtual switch in the current running state of the host machine according to the current environment information of the host machine.

[0070] Step 203: Determine the kernel state message interception condition of the virtual switch according to the kernel state flow table upper limit value of the virtual switch.

[0071] Specifically, the corresponding kernel state message interception condition can be set according to the determined kernel state flow table upper limit value. The kernel state message interception condition is used to determine whether to start the message interception operation at each moment to ensure the stable operation of the virtual switch.

[0072] Specifically, in one embodiment, a virtual switch flow table threshold value issued by a user may be obtained; and a kernel state message interception condition of the virtual switch may be determined according to the virtual switch flow table threshold value and a kernel state flow table upper limit value.

[0073] The kernel-state message interception condition at least includes a kernel-state flow table interception value. When the number of kernel-state flow tables of the virtual switch reaches the kernel-state flow table interception value, it is determined that the kernel-state message interception condition is met.

[0074] Exemplarily, when the virtual switch flow table threshold value issued by the user is 80% and the kernel state flow table upper limit value is 1000, the kernel state flow table interception value of the virtual switch is determined to be 1000×80%, that is, the kernel state flow table interception value of the virtual switch is 800. When the kernel state flow table number of the virtual switch reaches 800, it is determined that the kernel state message interception condition is met.

[0075] Step 204 , when the number of kernel state flow tables of the virtual switch meets the kernel state message interception condition, intercept the target message in the to-be-processed messages to be transmitted to the kernel state of the virtual switch.

[0076] Specifically, when the number of kernel-state flow tables in the virtual switch meets the preset interception conditions, the target message is identified and intercepted from the pending messages to be transmitted to the kernel state, preventing the virtual switch from uploading the kernel-state flow tables to the user state for processing due to too many kernel-state flow tables, thereby fundamentally solving the network bottleneck problem of the cloud computing management platform.

[0077] Among them, Figure 3 As shown, it is a data packet processing flow chart of the virtual switch provided by an embodiment of the present application. When a data packet (data message) arrives at the system, the datapath kernel module intercepts the data packet for processing; the datapath kernel module is responsible for performing data processing; the datapath kernel module matches the data packets one by one in the flow table, checks the header information of the data packet, such as the source MAC address, the destination MAC address, the VLAN tag, the IP address, etc., to determine the applicable flow table rules; since the first match cannot be made, the data packet is uploaded to the user state vswitchd (virtual switch daemon) through an upcall call (upward call mechanism); wherein vswitchd is the management and control service of OVS, which can interact with the kernel module; vswitchd communicates with the controller through the OpenFlow protocol provided by the management layer to obtain the flow table; the flow table queried in the user state is cached in the flow-table (flow table) in the kernel state, and the flow table is a table for storing network traffic processing rules; vswitchd uses the netlink network connection between the kernel state and the user state through the reinject (re-injection mechanism) to send the data packet back to the kernel module; the datapath then queries the corresponding action according to the data packet and processes it according to the action. The method provided in the embodiment of the present application is used to intercept a target message during the process of sending it to a kernel module through a network card to prevent it from entering a virtual switch.

[0078] Among them, the processing method of the data packet is cached in the kernel state. This processing method of the data packet also exists in the form of a flow table in the kernel state. When a data packet with the same characteristics arrives again, it can go directly to the kernel state. When the kernel state has not received a data packet with the same characteristics for a certain period of time, the kernel state flow table will be aged. The forwarding path that the kernel state upcalls to the user state after the flow table cannot be found is called slow-path, and the path that is directly forwarded through the kernel state datapath is called fast-flow. When the kernel state flow table is too much and exceeds the upper limit, new data packets will be upalled to the user state after they arrive. When the processing upper limit of the user state is exceeded, it will cause network abnormalities such as communication disconnection or jamming. The method provided in the embodiment of the present application can avoid the kernel state from frequently initiating upall to the user state, thereby avoiding the user state processing reaching the upper limit.

[0079] On the basis of the above embodiments, since the upper limit value of the kernel state flow table directly affects the judgment of the kernel state message interception condition, therefore, in order to further improve the accuracy of the result of determining the upper limit value of the kernel state flow table, as an implementable method, on the basis of the above embodiments, in one embodiment, according to the current environment information of the host machine, the upper limit value of the kernel state flow table of the virtual switch is determined, including:

[0080] Step 2021, in a preset experimental environment, a stress test is performed on the host machine to obtain test environment information of the host machine when receiving different numbers and types of to-be-processed messages; wherein the test environment information at least includes a processor usage rate, a memory occupancy rate, a disk performance index, and a network performance index;

[0081] Step 2022: construct multiple feature vectors based on the test environment information; wherein the feature vectors include multiple host machine performance indicators and the number of kernel state flow tables;

[0082] Step 2023, dividing the multiple feature vectors into a model training sample set and a model testing sample set;

[0083] Step 2024, constructing a kernel state flow table upper limit value prediction model based on the model training sample set and the model test sample set;

[0084] Step 2025, input the current environment information of the host machine into the kernel state flow table upper limit value prediction model to determine the kernel state flow table upper limit value of the virtual switch based on the kernel state flow table upper limit value prediction model and the current environment information.

[0085] Specifically, in a preset experimental environment, by sending different numbers and types of pending messages to the host machine, the load conditions in various actual network scenarios are simulated. In this process, relevant information of the host machine is collected, including processor usage, memory occupancy, disk performance indicators (such as disk I / O) and network performance indicators (such as network I / O), etc. This information constitutes the test environment information and provides basic data for subsequent model construction. Based on the obtained test environment information, a variety of host machine performance indicators (such as processor usage, memory occupancy, disk performance indicators, network performance indicators, etc.) are combined with the number of kernel-state flow tables to construct multiple feature vectors. Each feature vector contains the performance of the host machine under a specific load condition and the corresponding number of kernel-state flow tables. These vectors can fully reflect the relationship between the host machine performance and the number of flow tables.

[0086] Furthermore, the constructed multiple feature vectors are divided into two parts, one as a model training sample set and the other as a model test sample set. The model training sample set is used to train the kernel state flow table upper limit prediction model so that it can learn the inherent laws and mapping relationship between the host performance indicators and the kernel state flow table upper limit; the model test sample set is used to evaluate the accuracy and generalization ability of the model after the model training is completed, to ensure that the model can reliably predict the kernel state flow table upper limit in practical applications. Based on the divided model training sample set and model test sample set, a kernel state flow table upper limit prediction model is constructed using appropriate machine learning algorithms or statistical methods. The model can predict the corresponding kernel state flow table upper limit based on the input host performance indicators and other information. During the construction process, the model parameters and structure are continuously adjusted, and the model training sample set is used for training to make the model prediction results as close to the actual situation as possible, and the model test sample set is used for verification and optimization to improve the accuracy and stability of the model.

[0087] Specifically, after obtaining the current environment information of the host machine, this information is input into the kernel state flow table upper limit prediction model that has been built. The model will calculate and output the kernel state flow table upper limit of the virtual switch based on the input current environment information and the rules and relationships learned during the training process. This upper limit will be used to determine the subsequent kernel state message interception conditions, thereby achieving effective control and management of the number of kernel state flow tables of the virtual switch, avoiding network performance problems caused by too many flow tables, and improving message processing efficiency and system stability.

[0088] It should be noted that the data set preparation of the model training sample set and the model test sample set is mainly through the process of collecting the configuration information of the host machine such as the processor usage, memory occupancy, disk performance indicators (disk read and write rate), network performance indicators, and the number of OVS kernel state flow tables and the delay when querying the flow table, and processing them into a standard data set. The processor usage, memory occupancy, disk performance indicators, and network performance indicators in the host machine have an important impact on the speed of user state processing flow tables, so this information is collected; and the number of OVS kernel state flow tables reflects the busyness of the current kernel state data processing. The delay information of command execution when querying the kernel flow table can also reflect the number of kernel flow tables, and it is also strongly related to the host node system information.

[0089] It should be further explained that the information collection can be realized by writing a script, and the "mpstat" command is used to obtain the system CPU usage. The main purpose is to obtain the current CPU usage, including the user state CPU usage and system CPU usage; use the "free-m" command to obtain the memory usage in MB; use the "iostat" command to obtain disk I / O information; use the "ifstat" command to obtain network I / O information; use the "ovs-ofctl dump-flows|wc-l" command to view the number of kernel state flow tables, and use the "time ovs-ofctl dump-flows" command to obtain the latency information of querying the kernel flow table. The above information can be collected at different intervals and can be adjusted according to the subsequent training model situation. The collected features are not limited to the above features. For the construction of the preset experimental environment, the stress test of the system can be performed using the stress, fio or iperf tools. Set the stress index and collect the time series data of the processor usage, memory occupancy, disk performance indicators (disk read and write rate), and network performance indicators over time under different pressures.

[0090] Finally, the collected time series data is processed. Construct the feature vector X = [L 1t ,L 2t …L nt ,M t ], where L 1t ,L 2t …L nt They represent the data collected at time t for information such as processor usage, memory occupancy, disk performance indicators (disk read and write rates), network performance indicators, and kernel flow table query latency. t Represents the number of kernel flow tables; this vector, time, and sample number form a three-dimensional feature, where samples refer to virtualization platforms with different configurations. After building the standard neural network three-dimensional data, the data is filtered, standardized, and normalized. The processed data is divided into a training set and a test set in a ratio of 3:1.

[0091] For example, Figure 4As shown, a training flow diagram of an exemplary kernel state flow table upper limit prediction model provided by an embodiment of the present application is provided. The network state model (kernel state flow table upper limit prediction model) is trained using a neural network algorithm. Taking LSTM (long short-term memory) as an example, it is a special RNN that is commonly used in time series prediction problems. Compared with ordinary RNN, LSTM can perform better in longer sequences. First, the obtained data set is divided, 70% as a training set and 30% as a test set. Then, an LSTM neural network is constructed, and training parameters (initialization model parameters) are set, including the number of hidden layers and hidden layer neurons of the network, batch_size size, activation function, loss function, gradient descent algorithm, maximum number of iterations, optimization algorithm and learning rate, etc., and parameter tuning is performed according to the later training results. Then, the training set is sent to LSTM training to iteratively optimize the model parameters of the LSTM model until the number of iterative optimization reaches the preset maximum number of iterations. Finally, the trained LSTM model is predicted with a test set, and the model with the best performance is used as a flow table prediction model (kernel state flow table upper limit prediction model).

[0092] Among them, in the process of model training sample set and model test sample set, data preprocessing such as filtering, normalization and standardization can be performed on the data to improve the data quality of the final model training sample set and model test sample set.

[0093] Specifically, in one embodiment, in order to ensure that the kernel state flow table upper limit value of the virtual switch output by the kernel state flow table upper limit value prediction model is consistent with the actual situation, that is, to ensure the reliability of the prediction result of the kernel state flow table upper limit value prediction model for the kernel state flow table upper limit value, a real-time monitoring mechanism can be created to monitor the frequency and amplitude of changes in the host machine environment information in real time. When a significant change in the environment is detected, such as the CPU usage fluctuates by more than 20% (preset fluctuation threshold) in a short period of time (preset period), the network traffic suddenly increases by more than 30% (exceeding the preset growth threshold), etc., the update process of the kernel state flow table upper limit value prediction model is triggered, so as to use the online learning algorithm to incrementally incorporate the newly generated environmental information and flow table data into the model training, so that the model can quickly adapt to the dynamic changes in the network environment, so as to ensure that it can continue to provide accurate kernel state flow table upper limit value prediction.

[0094] Based on the above embodiment, as an implementable manner, based on the above embodiment, in one embodiment, when the number of kernel state flow tables of the virtual switch meets the kernel state message interception condition, the target message in the to-be-processed message to be transmitted to the kernel state of the virtual switch is intercepted, including:

[0095] Step 2041, when the number of kernel state flow tables of the virtual switch meets the kernel state message interception condition, extract classification features from the kernel state flow tables of the virtual switch to obtain classification feature information of each kernel state flow table of the virtual switch; wherein the classification feature information at least includes a destination address, a source address, a protocol type, and a data packet type;

[0096] Step 2042, classifying the kernel state flow tables according to the classification feature information of each kernel state flow table, and obtaining the corresponding kernel state flow table classification result;

[0097] Step 2043, determining the type of abnormal kernel-state flow table that causes a surge in the number of kernel-state flow tables of the virtual switch according to the kernel-state flow table classification result;

[0098] Step 2044 , according to the abnormal kernel state flow table type, the target message is screened from the pending messages to be transmitted to the kernel state of the virtual switch, and the target message is intercepted.

[0099] The destination address and source address may be the destination IP address, source IP address, target MAC address and source MAC address, the protocol type is also called the network type, such as the ipv4 protocol type, etc., and the data packet type includes HTTP data packets (Hypertext Transfer Protocol data packets), etc. The classification feature information may also include the number of bytes matched by the flow table and other information that can be used for flow table classification. The classification feature information may be obtained by using the "ovs-ofctl dump-flows" command to collect statistics on the detailed information of the flow table.

[0100] Specifically, based on the classification feature information of each kernel-state flow table extracted, the kernel-state flow table is classified using a preset classification algorithm or rule. Flow tables with similar features are grouped together to form different categories. For example, flow tables with the same destination address range and the same protocol type are grouped together, or flow tables of a specific data packet type are grouped together. Through classification, the distribution and internal rules of the flow table can be more clearly seen, providing a basis for finding abnormal flow table types.

[0101] Specifically, in one embodiment, based on the kernel state flow table classification results, multiple kernel state flow table types can be determined, and corresponding type grouping can be performed to determine the number of kernel state flow tables in a group of each kernel state flow table type; based on the number of kernel state flow tables in a group of each kernel state flow table type, the kernel state flow table type with the largest number of kernel state flow tables in the group is taken as the abnormal kernel state flow table type that causes a surge in the number of kernel state flow tables of the virtual switch.

[0102] Specifically, after the classification is completed, statistics and analysis are performed on various types of flow tables to determine the number of kernel-state flow tables in the group of each kernel-state flow table type. The degree of increase of this type of flow table in a short period of time can also be determined, and then the categories that cause the surge in the number of kernel-state flow tables can be found. These categories are abnormal kernel-state flow table types. For example, it may be found that a certain type of flow table has the largest number of kernel-state flow tables in the group, and its destination address points to a specific server, and the number increases sharply in a short period of time, which means that the server has been hit by abnormal traffic. By determining the abnormal kernel-state flow table type, the root cause of the problem can be accurately located, providing a clear direction for subsequent message interception.

[0103] Furthermore, according to the determined abnormal kernel state flow table type, the target message can be screened in the pending messages to be transmitted to the kernel state of the virtual switch to prevent the target message from entering the virtual switch through the network card. The screening is based on the characteristics that match the abnormal kernel state flow table type. For example, if the abnormal kernel state flow table type is a large number of data packets for a specific destination address, the pending messages with the destination address can be screened out as target messages. Then, these target messages are intercepted to prevent them from entering the kernel state, thereby avoiding the performance degradation and resource exhaustion of the kernel state due to processing too many abnormal messages, and ensuring the normal operation of the virtual switch and the stability of the entire network system.

[0104] Specifically, in one embodiment, the abnormal kernel state flow table configuration information can be determined according to the abnormal kernel state flow table type; according to the abnormal kernel state flow table configuration information, the target message is screened from the pending messages to be transmitted to the kernel state of the virtual switch; wherein the configuration information of the target message matches the abnormal kernel state flow table configuration information; according to the abnormal kernel state flow table configuration information, a corresponding abnormal message interception command is constructed to intercept the target message based on the abnormal message interception command.

[0105] Among them, the abnormal kernel state flow table configuration information can be obtained by extracting each field of the kernel state flow table. The abnormal kernel state flow table configuration information includes the abnormal destination address, abnormal source address, abnormal protocol type or abnormal data packet type corresponding to the abnormal kernel state flow table type.

[0106] For example, if the target message is a multicast flood message, the abnormal protocol type is ipv4, and the source address is 224.0.0.0 / 4 network segment (i.e., a multicast flood message), the following firewall rule (abnormal message interception command) is constructed to perform a drop operation (interception / discarding operation) on the multicast flood message to prevent normal service interruption caused by invalid flood messages:

[0107] firewall-cmd--permanent--add-rich-rule='rule family="ipv4" sourceaddress="224.0.0.0 / 4"drop'

[0108] Furthermore, in one embodiment, when the number of kernel-state flow tables of the virtual switch meets the kernel-state message interception condition, abnormal alarm information may be generated.

[0109] The abnormal alarm information includes abnormal kernel flow table configuration information (eg, ipv4, source address="224.0.0.0 / 4") and abnormal message interception commands.

[0110] Specifically, by generating and reporting abnormal alarm information, the user can be notified to check the network environment, find out the cause of the environmental performance bottleneck, and after solving the problem, manually delete the firewall rule (abnormal message interception command) to restore the network environment, so as to achieve early prevention of sudden problems and ensure that the user's normal business is not affected by abnormal traffic.

[0111] The embodiment of the present application provides a message processing method, which obtains the current environment information of the host machine; wherein the host machine is deployed with a virtual switch; according to the current environment information of the host machine, the upper limit value of the kernel state flow table of the virtual switch is determined; according to the upper limit value of the kernel state flow table of the virtual switch, the kernel state message interception condition of the virtual switch is determined; when the number of kernel state flow tables of the virtual switch meets the kernel state message interception condition, the target message in the to-be-processed message to be transmitted to the kernel state of the virtual switch is intercepted. The method provided by the above scheme effectively avoids the network bottleneck caused by too many kernel state flow tables by predicting the upper limit value of the kernel state flow table of the virtual switch in advance and accurately controlling the number of kernel state flow tables of the virtual switch, thereby improving the message processing efficiency and ensuring the network stability and operation efficiency of the cloud computing management platform. In addition, combined with the firewall rules, such problems can be avoided before the network packet loss failure caused by abnormal traffic surge occurs in the user environment, thereby ensuring the reliable and stable operation of the network of the cloud computing management platform.

[0112] An embodiment of the present application provides a message processing device, which is used to execute the message processing method provided in the above embodiment.

[0113] like Figure 5 , which is a schematic diagram of the structure of a message processing device provided in an embodiment of the present application. The message processing device 50 comprises: an acquisition module 501 , a first determination module 502 , a second determination module 503 and a processing module 504 .

[0114] Among them, the acquisition module is used to obtain the current environment information of the host machine; wherein the host machine is deployed with a virtual switch; the first determination module is used to determine the upper limit value of the kernel state flow table of the virtual switch according to the current environment information of the host machine; the second determination module is used to determine the kernel state message interception condition of the virtual switch according to the upper limit value of the kernel state flow table of the virtual switch; the processing module is used to intercept the target message in the to-be-processed message to be transmitted to the kernel state of the virtual switch when the number of kernel state flow tables of the virtual switch meets the kernel state message interception condition.

[0115] Regarding the message processing device in this embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.

[0116] The message processing device provided in the embodiment of the present application is used to execute the message processing method provided in the above embodiment. Its implementation method and principle are the same and will not be repeated here.

[0117] An embodiment of the present application provides an electronic device for executing the message processing method provided in the above embodiment.

[0118] like Figure 6 FIG. 6 is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device 60 includes: at least one processor 61 and a memory 62 .

[0119] The memory stores computer-executable instructions; at least one processor executes the computer-executable instructions stored in the memory, so that the at least one processor executes the message processing method provided in the above embodiment.

[0120] The electronic device provided in the embodiment of the present application is used to execute the message processing method provided in the above embodiment. Its implementation method and principle are the same and will not be repeated here.

[0121] An embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the message processing method provided in any of the above embodiments is implemented.

[0122] The storage medium containing computer executable instructions provided in the embodiment of the present application can be used to store computer executable instructions of the message processing method provided in the aforementioned embodiment. Its implementation method and principle are the same and will not be repeated here.

[0123] An embodiment of the present application provides a computer program product, including computer instructions, which are used to enable a computer to execute the message processing method provided in the aforementioned embodiment.

[0124] The embodiments of the present application provide a computer program product that can be used to execute computer instructions of the message processing method provided in the aforementioned embodiments. The implementation method and principle are the same and will not be repeated here.

[0125] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0126] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0127] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of hardware plus software functional units.

[0128] The above-mentioned integrated unit implemented in the form of a software functional unit can be stored in a computer-readable storage medium. The above-mentioned software functional unit is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to perform some steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk and other media that can store program code.

[0129] A part of the present application may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the existence of computer program instructions in computer-readable media includes, but is not limited to, source files, executable files, installation package files, etc., and accordingly, the way in which computer program instructions are executed by a computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to the computer.

[0130] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example for illustration. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. The specific working process of the device described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.

[0131] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A message processing method, characterized in that: include: Acquire current environment information of a host machine; wherein the host machine is deployed with a virtual switch; Determine the upper limit value of the kernel state flow table of the virtual switch according to the current environment information of the host machine; Determining a kernel state message interception condition of the virtual switch according to an upper limit value of a kernel state flow table of the virtual switch; When the number of kernel state flow tables of the virtual switch meets the kernel state message interception condition, the target message in the to-be-processed messages to be transmitted to the kernel state of the virtual switch is intercepted.

2. The method according to claim 1, characterized in that The step of determining the upper limit of the kernel state flow table of the virtual switch according to the current environment information of the host machine includes: Under a preset experimental environment, the host machine is subjected to a stress test to obtain test environment information of the host machine when receiving different numbers and types of to-be-processed messages; wherein the test environment information includes at least processor usage, memory occupancy, disk performance index, and network performance index; Constructing a plurality of feature vectors according to the test environment information; wherein the feature vectors include a plurality of host machine performance indicators and the number of kernel state flow tables; Dividing the multiple feature vectors into a model training sample set and a model testing sample set; Based on the model training sample set and the model test sample set, a kernel state flow table upper limit value prediction model is constructed; The current environment information of the host machine is input into the kernel state flow table upper limit value prediction model to determine the kernel state flow table upper limit value of the virtual switch based on the kernel state flow table upper limit value prediction model and according to the current environment information.

3. The method according to claim 1, characterized in that When the number of kernel state flow tables of the virtual switch meets the kernel state message interception condition, intercepting the target message in the to-be-processed messages to be transmitted to the kernel state of the virtual switch includes: When the number of kernel state flow tables of the virtual switch meets the kernel state message interception condition, classification feature extraction is performed on the kernel state flow tables of the virtual switch to obtain classification feature information of each kernel state flow table of the virtual switch; wherein the classification feature information at least includes a destination address, a source address, a protocol type, and a data packet type; According to the classification feature information of each kernel state flow table, kernel state flow table classification is performed to obtain corresponding kernel state flow table classification results; Determining, according to the kernel state flow table classification result, the type of abnormal kernel state flow table that causes the surge in the number of kernel state flow tables of the virtual switch; According to the abnormal kernel state flow table type, target messages are screened from the pending messages to be transmitted to the kernel state of the virtual switch, and the target messages are intercepted.

4. The method according to claim 3, characterized in that The determining, according to the kernel state flow table classification result, the abnormal kernel state flow table type causing the surge in the number of kernel state flow tables of the virtual switch comprises: Determine multiple kernel state flow table types according to the kernel state flow table classification results, and perform corresponding type grouping to determine the number of kernel state flow tables in each group of the kernel state flow table type; According to the number of kernel state flow tables in each group of the kernel state flow table types, the kernel state flow table type with the largest number of kernel state flow tables in the group is taken as the abnormal kernel state flow table type causing a surge in the number of kernel state flow tables of the virtual switch.

5. The method according to claim 3, characterized in that: The step of screening target messages from the to-be-processed messages to be transmitted to the virtual switch kernel state according to the abnormal kernel state flow table type, and intercepting the target messages includes: Determine the abnormal kernel state flow table configuration information according to the abnormal kernel state flow table type; According to the abnormal kernel state flow table configuration information, the target message is screened from the to-be-processed messages to be transmitted to the kernel state of the virtual switch; wherein the configuration information of the target message matches the abnormal kernel state flow table configuration information; According to the abnormal kernel state flow table configuration information, a corresponding abnormal message interception command is constructed to intercept the target message based on the abnormal message interception command.

6. The method according to claim 1, characterized in that The method further comprises: When the number of kernel state flow tables of the virtual switch meets the kernel state message interception condition, generating abnormal alarm information; The abnormal alarm information includes abnormal kernel state flow table configuration information and abnormal message interception command.

7. The method according to claim 1, characterized in that The determining, according to the upper limit value of the kernel state flow table of the virtual switch, the kernel state message interception condition of the virtual switch comprises: Get the virtual switch flow table threshold issued by the user; Determining a kernel state message interception condition of the virtual switch according to the virtual switch flow table threshold and the kernel state flow table upper limit; The kernel-state message interception condition at least includes a kernel-state flow table interception value. When the number of kernel-state flow tables of the virtual switch reaches the kernel-state flow table interception value, it is determined that the kernel-state message interception condition is met.

8. A message processing device, characterized in that: include: An acquisition module, used to acquire current environment information of a host machine; wherein the host machine is deployed with a virtual switch; A first determination module, configured to determine an upper limit value of a kernel state flow table of a virtual switch according to current environment information of the host machine; A second determination module, configured to determine a kernel state message interception condition of the virtual switch according to an upper limit value of a kernel state flow table of the virtual switch; The processing module is used to intercept the target message in the to-be-processed messages to be transmitted to the kernel state of the virtual switch when the number of kernel state flow tables of the virtual switch meets the kernel state message interception condition.

9. An electronic device, characterized in that: include: at least one processor and memory; The memory stores computer-executable instructions; The at least one processor executes the computer-executable instructions stored in the memory, so that the at least one processor performs the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, and when a processor executes the computer-executable instructions, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Message processing method and device and medium

    CN115002028A

  • Message forwarding method and device of server, storage medium and electronic equipment

    CN118677872A

  • Method for kernel mode flow control unloading, computer equipment and medium

    CN119324907A

  • Flow table processing method and related device

    US20230269182A1

  • Data packet processing method and device based on open virtual switch (OVS)

    WO2021226948A1

Cited By

  • Two-layer network security defense method and device and electronic equipment

    CN122027372A