Flow identification method and device and related product

By determining and sending application identifiers with high frequency in the operator network equipment, the traffic identification problem caused by different memory capacity of different forwarding nodes is solved, and precise control of application application traffic is achieved.

CN119945984APending Publication Date: 2025-05-06RUIJIE NETWORKS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311463668.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-06
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The operator's network equipment cannot accurately control the application traffic of the application, mainly due to the different memory storage capacity of different forwarding nodes, the number of traffic characteristic information read is inconsistent, and some forwarding nodes cannot recognize the application traffic.

Method used

The first network device receives the information sent by the second network device, determines M applications, and selects Q applications from them as identifications, and sends these application identifiers to the second network device. These Q applications are sorted from high to low according to frequency of use, ensuring that they are small in number and have wide coverage, and can be read into memory by the second network device for identification.

Benefits of technology

By reducing the amount of traffic characteristic information that the second network device needs to process, avoiding excessive memory burden, improving the accuracy and efficiency of traffic identification, thereby achieving accurate control of application application traffic.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945984A_ABST
    Figure CN119945984A_ABST
Patent Text Reader

Abstract

The invention discloses a traffic identification method and device and a related product, belongs to the technical field of communication, and solves the problem that an operator network device cannot accurately control the application traffic of an application program. The specific solution is: receiving first information sent by a second network device, the first information comprising at least one of the following items: a first identifier corresponding to an identified first application traffic and an unidentified second application traffic; m application programs are determined according to the first information, the M application programs are application programs corresponding to the application traffic received by the second network equipment, and M is a positive integer; q application programs are determined from the M application programs, the Q application programs are the first Q application programs with the use frequencies from high to low, and Q is a positive integer; and sending Q application identifiers corresponding to the Q application programs to the second network equipment. The embodiment of the invention is used in a scene for managing and controlling the application traffic of the application program.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of communication technology, and specifically relates to a flow identification method, device and related products. Background Art

[0002] Typically, multiple traffic characteristic information is configured in the hard disk of each forwarding node of the operator network device, so that each forwarding node can read the multiple traffic characteristic information in the hard disk into the memory respectively, and use the traffic characteristic information in the memory to perform traffic identification on the received application traffic to determine the application to which the application traffic belongs, and accurately control the application traffic according to the traffic control policy corresponding to the application, so that the operator network device can achieve accurate control of the application traffic of the application.

[0003] However, since the storage capacity of the memory of different forwarding nodes may be different, the amount of traffic characteristic information read into the memory of different forwarding nodes may be different, which in turn leads to different amounts of traffic characteristic information that different forwarding nodes can use when performing traffic identification. Therefore, some forwarding nodes may fail to identify the received application traffic because they fail to read certain traffic characteristic information into the memory, which results in the inability of these forwarding nodes to accurately control the application traffic of the application, thus causing the operator's network equipment to be unable to accurately control the application traffic of the application. Summary of the invention

[0004] The purpose of the embodiments of the present application is to provide a traffic identification method, device and related products, which can solve the problem that the operator's network equipment is unable to accurately control the application traffic of the application.

[0005] In a first aspect, an embodiment of the present application provides a traffic identification method, which is applied to a first network device, and the method includes: receiving first information sent by a second network device, the first information including at least one of the following: a first identifier corresponding to an identified first application traffic, and an unidentified second application traffic; determining M applications based on the first information, the M applications are applications corresponding to the application traffic received by the second network device, and M is a positive integer; determining Q applications from the M applications, the Q applications are: the first Q applications in descending order of usage frequency, and Q is a positive integer; and sending Q application identifiers corresponding to the Q applications to the second network device.

[0006] The embodiment of the present application provides a traffic identification method. Since the number of second network devices can be at least one, and the application corresponding to the application traffic received by the at least one second network device may not be completely the same, after the at least one second network device sends the first information to the first network device, the number of M applications determined by the first network device according to the first information is greater than the number of applications corresponding to the application traffic received by the at least one second network device. And the first network device can also determine Q applications from the M applications, and the Q applications are a small number of applications with a high traffic transmission frequency. And the Q applications may be at least partially different from the application corresponding to the application traffic received by the at least one second network device. Therefore, after the first network device indicates the Q applications to at least one second network device through Q application identifiers, on the one hand, because the number of Q applications is small, each second network device can read the Q traffic feature information into the memory without bringing too much burden to the memory, and use the Q traffic feature information in the memory to perform traffic identification on the received application traffic. On the other hand, because there may be an application among the Q applications that is different from the application corresponding to the application traffic received by at least one second network device, the at least one second network device can read the traffic characteristic information corresponding to the different application into the memory. Thus, while ensuring that at least one second network device can use the Q traffic characteristic information for traffic identification, the probability that at least one second network device cannot identify the received application traffic due to failure to read certain traffic characteristic information into the memory is reduced. In this way, the operator network device can accurately control the application traffic of the application.

[0007] In combination with the first aspect and the above-mentioned possible implementation methods, in another possible implementation method, the above-mentioned determining M applications based on the first information includes: when the first information includes a first identifier corresponding to the first application traffic and does not include the second application traffic, determining the M applications based on the first identifiers sent by multiple second network devices; or, when the first information includes the second application traffic, determining the second identifier corresponding to the second application traffic, and determining the M applications based on the second identifier.

[0008] In combination with the first aspect and the above-mentioned possible implementation methods, in another possible implementation method, the above-mentioned determining M applications based on the second identifier includes: when the first information also includes the first identifier corresponding to the first application traffic, determining the M applications based on the first identifier and the second identifier.

[0009] In combination with the first aspect and the above-mentioned possible implementation methods, in another possible implementation method, the above-mentioned determining Q applications from M applications includes: determining T applications whose corresponding first identifier matches at least one third identifier from the M applications, T is a positive integer; determining the first Q applications with the highest to lowest traffic transmission frequency among the T applications as Q applications; wherein the above-mentioned at least one third identifier is used to indicate the first at least one application with the highest to lowest usage frequency in the operator network.

[0010] In combination with the first aspect and the above-mentioned possible implementation methods, in another possible implementation method, before determining Q applications from the M applications, the method also includes: receiving second information sent by a second network device, the second information being used to indicate the maximum number of traffic characteristic information stored in the memory of the second network device; determining Q applications based on the maximum number indicated by the second information.

[0011] In a second aspect, an embodiment of the present application provides a traffic identification method, which is applied to a second network device, and the method includes: sending first information to a first network device, the first information including at least one of the following: a first identifier corresponding to an identified first application traffic and an unidentified second application traffic, the first information being used to determine M applications, where M is a positive integer; receiving Q application identifiers corresponding to Q applications sent by the first network device, the Q applications being: the first Q applications with the highest to lowest usage frequency among the M applications, where Q is a positive integer; and performing traffic identification on the application traffic received by the second network device based on the Q traffic feature information corresponding to the Q application identifiers.

[0012] The embodiment of the present application provides a traffic identification method. Since the number of second network devices can be at least one, and the application corresponding to the application traffic received by the at least one second network device may not be completely the same, after the at least one second network device sends the first information to the first network device, the number of M applications determined by the first network device according to the first information is greater than the number of applications corresponding to the application traffic received by the at least one second network device. And the first network device can also determine Q applications from the M applications, and the Q applications are a small number of applications with a high traffic transmission frequency. And the Q applications may be at least partially different from the application corresponding to the application traffic received by the at least one second network device. Therefore, after the first network device indicates the Q applications to at least one second network device through Q application identifiers, on the one hand, because the number of Q applications is small, each second network device can read the Q traffic feature information into the memory without bringing too much burden to the memory, and use the Q traffic feature information in the memory to perform traffic identification on the received application traffic. On the other hand, because there may be an application among the Q applications that is different from the application corresponding to the application traffic received by at least one second network device, the at least one second network device can read the traffic characteristic information corresponding to the different application into the memory. Thus, while ensuring that at least one second network device can use the Q traffic characteristic information for traffic identification, the probability that at least one second network device cannot identify the received application traffic due to failure to read certain traffic characteristic information into the memory is reduced. In this way, the operator network device can accurately control the application traffic of the application.

[0013] In combination with the second aspect and the above-mentioned possible implementation methods, in another possible implementation method, before sending the first information to the first network device, the method also includes: performing traffic identification on the application traffic received by the second network device to obtain first information, and the first information includes at least one of the following: a first identifier corresponding to the first application traffic and the second application traffic.

[0014] In combination with the second aspect and the above-mentioned possible implementation methods, in another possible implementation method, before performing traffic identification on the application traffic received by the second network device based on the Q traffic characteristic information corresponding to the Q application identifiers, the method also includes: determining R traffic characteristic information from the Q traffic characteristic information, the R traffic characteristic information being the traffic characteristic information not stored in the memory of the second network device, and R being a positive integer less than or equal to Q; determining the R traffic characteristic information from the hard disk of the second network device; and storing the R traffic characteristic information in the memory.

[0015] In combination with the second aspect and the above-mentioned possible implementation methods, in another possible implementation method, before the above-mentioned receiving of Q application identifiers corresponding to Q applications sent by the first network device, the method also includes: sending second information to the first network device, the second information being used to indicate the maximum amount of traffic characteristic information stored in the memory of the second network device; wherein the above-mentioned second information is used by the first network device to determine the Q applications.

[0016] In a third aspect, an embodiment of the present application provides a flow identification device, which is a first flow identification device, and the first flow identification device includes: a receiving module, a determining module, and a sending module. Among them, the receiving module is used to receive first information from the second flow identification device, and the first information includes at least one of the following: a first identifier corresponding to the identified first application flow, and an unidentified second application flow. The determining module is used to determine M applications according to the first information received by the receiving module, and the M applications are the applications corresponding to the application flow received by the second flow identification device, and M is a positive integer; and determine Q applications from the M applications, and the Q applications are: the first Q applications in descending order of usage frequency, and Q is a positive integer. The sending module is used to send Q application identifiers corresponding to the Q applications determined by the determining module to the second flow identification device.

[0017] In combination with the third aspect and the above-mentioned possible implementation methods, in another possible implementation method, the above-mentioned determination module is specifically used to determine M applications based on the first identifiers sent by multiple second traffic identification devices when the first information includes a first identifier corresponding to the first application traffic and does not include the second application traffic; or, when the first information includes the second application traffic, determine the second identifier corresponding to the second application traffic, and determine the M applications based on the second identifier.

[0018] In combination with the third aspect and the above-mentioned possible implementation methods, in another possible implementation method, the above-mentioned determination module is specifically used to determine M applications based on the first identifier and the second identifier when the first information also includes the first identifier corresponding to the first application traffic.

[0019] In combination with the third aspect and the above possible implementation, in another possible implementation, the above determination module is specifically used to determine T applications whose corresponding first identifier matches at least one third identifier from M applications, where T is a positive integer; and determine the first Q applications with the highest to lowest traffic transmission frequency among the T applications as Q applications. The at least one third identifier is used to indicate the first at least one application with the highest to lowest usage frequency in the operator network.

[0020] In combination with the third aspect and the above-mentioned possible implementation methods, in another possible implementation method, the above-mentioned receiving module is also used to receive second information sent by a second traffic identification device before the determination module determines Q applications from M applications, and the second information is used to indicate the maximum number of traffic characteristic information stored in the memory of the second traffic identification device; and determine Q applications from the M applications based on the maximum number indicated by the second information.

[0021] In a fourth aspect, an embodiment of the present application provides a flow identification device, which is a second flow identification device, and the second flow identification device includes: a sending module, a receiving module, and an execution module. Among them, the sending module is used to send first information to the first flow identification device, and the first information includes at least one of the following: a first identifier corresponding to the identified first application flow, and an unidentified second application flow, and the first information is used by the first flow identification device to determine M applications, where M is a positive integer. The receiving module is used to receive Q application identifiers corresponding to Q applications sent by the first flow identification device, and the Q applications are: among the M applications, the first Q applications with the highest to lowest usage frequency, and Q is a positive integer. The execution module is used to perform flow identification on the application flow received by the second flow identification device based on the Q flow feature information corresponding to the Q application identifiers received by the receiving module.

[0022] In combination with the fourth aspect and the above-mentioned possible implementation methods, in another possible implementation method, the above-mentioned execution module is also used to perform traffic identification on the application traffic received by the second traffic identification device before the sending module sends the first information to the first traffic identification device, so as to obtain the first information, and the first information includes at least one of the following: a first identifier corresponding to the first application traffic and the second application traffic.

[0023] In combination with the fourth aspect and the above-mentioned possible implementation methods, in another possible implementation method, the above-mentioned execution module is also used to determine R traffic characteristic information from the Q traffic characteristic information before performing traffic identification on the application traffic received by the second traffic identification device based on the Q traffic characteristic information corresponding to the Q application identifiers, where the R traffic characteristic information is the traffic characteristic information not stored in the memory of the second traffic identification device, and R is a positive integer less than or equal to Q; and determine the R traffic characteristic information from the hard disk of the second network device; and store the R traffic characteristic information in the memory.

[0024] In combination with the fourth aspect and the above possible implementations, in another possible implementation, the sending module is further used to send second information to the first traffic identification device before the receiving module receives the Q application identifiers corresponding to the Q applications sent by the first traffic identification device, where the second information is used to indicate the maximum amount of traffic feature information stored in the memory of the second traffic identification device. The second information is used by the first traffic identification device to determine the Q applications.

[0025] In a fifth aspect, an embodiment of the present application provides a traffic identification system, which includes a first network device and a second network device; the first network device executes the traffic identification method as described in the first aspect and its possible implementation method; the second network device executes the traffic identification method as described in the second aspect and its possible implementation method.

[0026] In a sixth aspect, an embodiment of the present application provides an electronic device, comprising a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the traffic identification method as described in the first aspect and the possible implementation manner of the first aspect is implemented, or the traffic identification method as described in the second aspect and the possible implementation manner of the second aspect is implemented.

[0027] In the seventh aspect, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the traffic identification method as described in the first aspect and its possible implementation method of the first aspect is implemented, or the traffic identification method as described in the second aspect and its possible implementation method of the second aspect is implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 This is one of the flow charts of the traffic identification method provided in the embodiment of the present application;

[0029] Figure 2 This is the second flow chart of the traffic identification method provided in the embodiment of the present application;

[0030] Figure 3 is a schematic diagram of the structure of a second network device provided in an embodiment of the present application;

[0031] Figure 4 is a schematic diagram of the structure of a first network device and a second network device provided in an embodiment of the present application;

[0032] Figure 5 This is the third flow chart of the traffic identification method provided in the embodiment of the present application;

[0033] Figure 6This is the fourth flow chart of the traffic identification method provided in the embodiment of the present application;

[0034] Figure 7 This is the fifth flow chart of the traffic identification method provided in the embodiment of the present application;

[0035] Figure 8 A schematic diagram of the composition of a first flow identification device provided in an embodiment of the present application;

[0036] Fig. 9 A schematic diagram of the composition of a second flow identification device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0037] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0038] The terms "first", "second", etc. in the specification and claims of this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way can be interchangeable under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are generally of the same type, and the number of objects is not limited. For example, the first object can be one or more.

[0039] In addition, the term "and / or" in this article is only a description of the association relationship between the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.

[0040] The terms "at least one (item)", "at least one of" and the like in the specification and claims of the present application refer to any one, any two or a combination of more than two of the objects included therein. For example, at least one (item) of a, b, and c can be represented by: "a", "b", "c", "a and b", "a and c", "b and c" and "a, b and c", where a, b, and c can be single or multiple. Similarly, "at least two (items)" refers to two or more, and its meaning is similar to that of "at least one (item)".

[0041] The implementation of the embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0042] At present, with the rapid progress of enterprise digital transformation, enterprise applications have undergone earth-shaking changes. Faced with an endless stream of applications, how to accurately control, count and visualize application traffic is the biggest problem facing network administrators. The premise of control is to accurately identify various applications in the network. Therefore, application identification is a widely used technology.

[0043] In the related art, multiple traffic characteristic information is configured in the hard disk of each forwarding node (such as a router) of the operator network device, so that each router can read the multiple traffic characteristic information in the hard disk into the memory respectively, and use the traffic characteristic information in the memory to perform traffic identification on the received application traffic to determine the application to which the application traffic belongs, and accurately control the application traffic according to the traffic control policy corresponding to the application, so that the operator network device can realize accurate control of the application traffic of the application.

[0044] However, since the storage capacity of the memory of different routers may be different, this may cause different forwarding nodes to read different amounts of traffic characteristic information into the memory, resulting in different amounts of traffic characteristic information that different forwarding nodes can use when performing traffic identification. Multiple routers managed by the same Software Defined Network (SDN) controller need to first read the multiple traffic characteristic information configured by the SDN controller from the hard disk into the memory before using the traffic characteristic information in the memory for traffic identification. Therefore, different routers use different amounts of traffic characteristic information when performing traffic identification, which in turn causes different routers to use different traffic characteristic information when performing traffic identification. As a result, some routers may fail to identify the received application traffic because they fail to read certain traffic characteristic information into the memory, which in turn causes these routers to be unable to accurately control the application traffic of the application, thus causing the operator's network equipment to be unable to accurately control the application traffic of the application.

[0045] In order to solve the above technical problems, an embodiment of the present application provides a traffic identification method. Figure 1 A flow chart of a flow identification method provided in an embodiment of the present application. Figure 1 As shown, the traffic identification method may include the following steps 101 to 107.

[0046] Step 101: A second network device sends first information to a first network device.

[0047] In some embodiments of the present application, the first network device may be a network element device in the operator network device, for example, the first network device may be an SDN controller in the operator network device. The second network device may be a network element device in the operator network device, for example, the second network device may be a router in the operator network device.

[0048] In some embodiments of the present application, the number of the second network device may be at least one.

[0049] In some embodiments of the present application, when a first network device is communicatively connected with a second network device, the first network device can send first indication information to the second network device, and the first indication information is used to instruct the second network device to report the first information, so that the second network device can obtain the application traffic received by the second network device within a preset time period according to the first indication information, and perform traffic identification on the received application traffic, and determine the first information according to the identification result obtained by performing the traffic identification, and then the second network device can send the first information to the first network device.

[0050] In a possible implementation, the above identification result may include at least one of the following: an identifier corresponding to the identified traffic, and unidentified application traffic. The identifier may include at least one of the following: an application identifier, and an application type identifier. The application identifier may include at least one of the following: an application name, and an application identity (ID), and the application type identifier may include at least one of the following: an application type name, and an application type ID.

[0051] Exemplarily, assuming that the above-mentioned identifier includes an application identifier, the second network device performs traffic identification on the received application traffic and can obtain at least one of the application name "Micro X" of the application corresponding to the application traffic and the application ID 1 of the "Micro X" application.

[0052] Exemplarily, assuming that the above-mentioned identifier includes an application type identifier, the second network device performs traffic identification on the received application traffic and can obtain at least one of the application type name "chat application type" of the application corresponding to the application traffic and the application type ID 2 of the "chat application type".

[0053] In a possible implementation, the second network device may directly determine at least one of all identified identifiers and all unidentified application traffic as the first information.

[0054] In some embodiments of the present application, the number of the first information may be at least one. Wherein, when the number of the second network device is one, the number of the first information may be one, and when the number of the second network device is multiple (i.e., at least two), the number of the first information may be at least two.

[0055] In the embodiment of the present application, the first information includes at least one of the following: a first identifier corresponding to the identified first application flow, and an unidentified second application flow. It can be understood that when the number of first information is at least two, each first information includes at least one item: a first identifier corresponding to the identified first application flow, and an unidentified second application flow.

[0056] In some embodiments of the present application, the number of first identifiers corresponding to the first application traffic may be at least one, and the first identifier corresponding to the first application traffic may include at least one of the following: application identifier, application type identifier. It should be noted that for the description of the application identifier and the application type identifier, reference can be made to the specific description in the above embodiments, and the embodiments of the present application will not be repeated here.

[0057] In some embodiments of the present application, the number of the second application traffic may be at least one.

[0058] In one scenario, the first information only includes a first identifier corresponding to the first application traffic.

[0059] In this scenario, there are multiple (i.e., at least two) second network devices, and each second network device can fully identify the received application traffic to obtain the first identifier corresponding to the first application traffic. Therefore, the first information sent by each second network device to the first network device only includes the first identifier corresponding to the first application traffic, and does not include the unidentified second application traffic.

[0060] However, since the application programs to which the application traffic received by each second network device belongs may not be completely the same, the identifier (i.e., the first identifier) ​​obtained by traffic identification of the received application traffic by a certain second network device (e.g., device A) may be different from the identifier (i.e., the first identifier) ​​obtained by traffic identification of the received application traffic by another second network device (e.g., device B).

[0061] Therefore, the type of first identifier included in the first information jointly sent by multiple second network devices (including device A and device B) to the first network device must be more than the type of first identifier obtained by at least one second network device (such as device A or device B) for traffic identification.

[0062] In the embodiment of the present application, the first network device determines M applications according to the first information, where M is a positive integer. A second network device (for example, device A) determines N applications according to the first identification obtained by the device, where N is a positive integer. M is greater than N.

[0063] In another scenario, the first information only includes the second application traffic.

[0064] In this scenario, the number of the second network devices is one or more, and each second network device is completely unable to identify the received application traffic. Therefore, the first information sent by each second network device to the first network device only includes the second application traffic.

[0065] In the embodiment of the present application, the first network device determines M applications according to the first information, where M is a positive integer. A second network device (eg, device A) determines N applications according to the first identification obtained by the device, where N is 0. M is greater than N.

[0066] In another scenario, the first information includes a first identifier corresponding to the first application traffic and a second application traffic.

[0067] In this scenario, the number of second network devices is one or more. When the number of second network devices is one, the second network device can only partially identify the application traffic it receives. When the number of second network devices is multiple, at least one second network device (for example, device A) can only partially identify the application traffic it receives, or at least one second network device (for example, device B) cannot identify the application traffic it receives at all, but there is another second network device (for example, device C) that can fully or partially identify the application traffic it receives. Therefore, the first information sent by one or more second network devices to the first network device includes not only the second application traffic, but also the first identifier corresponding to the first application traffic.

[0068] In the embodiment of the present application, the first network device determines M applications according to the first information, where M is a positive integer. A second network device (for example, device A) determines N applications according to the first identification obtained by the device, where N is a positive integer. M is greater than N.

[0069] In some embodiments of the present application, the above-mentioned M applications may include at least one of the following: a chat application, a video application, a music application, a short video interaction application, etc.

[0070] In some embodiments of the present application, when the first information includes the first identifier corresponding to the first application traffic, and the first identifier is at least one of the application ID and the application type ID, the second network device can send the first information to the first network device through the Google Remote Procedure Call (GRPC) channel. Of course, the second network device can also send the first information to the first network device through other channels, which is not limited in the embodiments of the present application.

[0071] It should be noted that since the application ID and / or application type ID corresponding to the above-mentioned first application traffic is specific digital data, and the GRPC can upload digital data, in this example the second network device can send the identified identifier to the first network device through the GRPC channel.

[0072] In some embodiments of the present application, when the first information includes the second application traffic, the second network device may send the first information to the first network device through an Internet Protocol Flow Information Export (IPFIX) channel. Of course, the second network device may also send the first information to the first network device through other channels, which is not limited in the embodiments of the present application.

[0073] It should be noted that, since the application traffic is an IP forwarding message, and the IPFIX channel can upload IP forwarding messages, in this example, the second network device can send the second application traffic to the first network device via the IP forwarding message.

[0074] In some embodiments of the present application, the first information may further include at least one of the following: a site ID of a site to which the second network device belongs, and a device ID of the second network device. Thus, the first network device may determine the second network device corresponding to the first information based on the first information.

[0075] The following is an example of a specific scheme in which the second network device determines the first information.

[0076] In some embodiments of the present application, Figure 1 ,like Figure 2 As shown, before the above step 101, the traffic identification method provided in the embodiment of the present application may also include the following step 201.

[0077] Step 201: The second network device performs traffic identification on the application traffic received by the second network device to obtain first information.

[0078] In an embodiment of the present application, the above-mentioned first information includes at least one of the following: a first identifier corresponding to the first application traffic and the second application traffic.

[0079] It is understandable that since the second network device may not be able to identify each application flow in the received application flow, for the first application flow that the second network device can identify, the second network device can identify the identifier corresponding to the application program to which the first application flow belongs, thereby obtaining the first identifier corresponding to the first application flow; and / or, for the application flow that the second network device cannot identify, the second network device will copy the application flow, thereby obtaining the second application flow.

[0080] In some embodiments of the present application, Figure 3 As shown, the second network device is provided with an application identification detection device 11, so that the second network device can control the application identification detection device 11 to perform traffic identification on the application traffic received by the second network device through the operating system.

[0081] In some embodiments of the present application, the second network device can control the application identification detection device 11 through the operating system to read at least one flow characteristic information from the memory of the second network device, each flow characteristic information is characteristic information of the application flow of an application program, and each flow characteristic information can be regarded as a matching feature set. Based on the at least one flow characteristic information, the application flow received by the second network device is subjected to flow identification to obtain the first identifier corresponding to the first application flow and at least one of the second application flows.

[0082] The at least one flow characteristic information may satisfy at least one of the following: pre-configured flow characteristic information, flow characteristic information agreed upon by the protocol, or flow characteristic information determined by the second network device. The at least one flow characteristic information is pre-written into the memory of the second network device, and the at least one flow characteristic information may include at least one of the following: application protocol unique ID, application protocol description, header information of application flow packets, etc.

[0083] In one possible implementation, combining Figure 3For each application flow in the application flow received by the second network device, the second network device can first determine the flow characteristic information of any application flow through the application identification detection device 11, and then compare the flow characteristic information of any application flow with the flow characteristic information pre-stored in the memory. In the case that any flow characteristic information matches any flow characteristic information, the identifier of the application corresponding to any flow characteristic information is determined as a first identifier through the application identification detection device 11. Alternatively, in the case that the one flow characteristic information does not match any flow characteristic information, the one application flow (i.e., unidentified application flow) is copied through the copy module 12 in the second network device to obtain a second application flow. And so on, to obtain at least one of the first identifier and the second application flow corresponding to the first application flow.

[0084] It should be noted that the above “matching” can be understood as: being identical, or the similarity between the two being greater than or equal to a preset threshold.

[0085] In some embodiments of the present application, after the second network device performs traffic identification on the application traffic received by the second network device, the second network device can determine at least part of the first identifier corresponding to the first application traffic as the first information; and / or, the second network device can determine at least part of the first application traffic in the second application traffic copied by the copy module 12 as the first information.

[0086] It can be understood that the first information may include at least one of the following: at least part of the first identifier in the first identifier corresponding to the first application traffic, and at least part of the second application traffic in the second application traffic.

[0087] In some embodiments of the present application, the second network device is also provided with an identified application sending module 13, so that when the first information is determined by at least part of the first identifier, the second network device can send the first information to the first network device through the application sending module 13, and / or, when the first information is determined by at least part of the second application traffic, the second network device can send the first information to the first network device through the copy module 12.

[0088] As can be seen, since the second network device can perform traffic identification on the application traffic received by the second network device, and indicate to the first network device at least one of the first identifier and the second application traffic corresponding to the identified first application traffic. In this way, the first network device can obtain the various application traffic received by the second network device based on the first information, and determine the M applications that transmit traffic through the second network device based on the various application traffic received by the second network device, and the first network device can determine the number of traffic transmissions for each application based on the number of application traffic received by the second network device corresponding to each application. Therefore, the first network device can accurately determine the Q applications that transmit traffic more frequently from the M applications based on the number of traffic transmissions for each application, that is, accurately determine a small number of applications that may transmit traffic again through the second network device.

[0089] Therefore, in the subsequent steps, after the first network device indicates the Q applications to the second network device. Since the number of applications M determined by the first network device is greater than the number of applications N determined by at least one second network device (for example, device A) based on the first identifier obtained by its identification. Therefore, the Q applications determined by the first network device from the M applications may include applications that are different from the applications corresponding to the application traffic received by device A, and therefore, there may be applications that device A cannot recognize. Therefore, device A can read the traffic feature information corresponding to the applications that it cannot recognize into the memory, reducing the probability of being unable to recognize the received application traffic.

[0090] Step 102: The first network device receives first information sent by the second network device.

[0091] In some embodiments of the present application, when a first network device is communicatively connected with multiple second network devices, the first network device can send first indication information to each of the multiple second network devices, and the first indication information is used to instruct each second network device to report the first information. Thus, each second network device can obtain the application traffic received by each second network device within a preset time period according to the first indication information, and perform traffic identification on the received application traffic, and determine the first information according to the identification result obtained after the traffic identification. Furthermore, each second network device can send the first information to the first network device, so that the first network device can receive multiple first information from the multiple second network devices.

[0092] In the embodiment of the present application, the above-mentioned first information includes at least one of the following: a first identifier corresponding to the identified first application traffic and an unidentified second application traffic.

[0093] Step 103: The first network device determines M applications according to the first information.

[0094] In the embodiment of the present application, the above-mentioned M applications are applications corresponding to the application traffic received by the second network device, and M is a positive integer.

[0095] It can be understood that the M applications are applications corresponding to all application traffic received by the second network device.

[0096] In some embodiments of the present application, the above step 103 can be specifically implemented by the following step 103a or step 103b.

[0097] Step 103a: When the first information includes a first identifier corresponding to the first application traffic but does not include the second application traffic, the first network device determines M applications according to the first identifiers sent by the plurality of second network devices.

[0098] It can be understood that, in the case where each first information includes a first identifier corresponding to the first application traffic, the number of the second network devices is multiple (ie, at least two).

[0099] In some embodiments of the present application, the first network device may determine the corresponding M applications according to the first identifiers sent by the plurality of second network devices.

[0100] It can be seen that, in the case where multiple second network devices send the first identifier corresponding to the first application traffic to the first network device, the first network device can accurately determine the application corresponding to the application traffic already received by the second network device based on the first identifier sent by the multiple second network devices, and accurately determine a small number of applications (i.e., Q applications) that may transmit traffic again through the second network device based on the usage frequency of the application corresponding to the application traffic already received by the second network device.

[0101] Step 103b: When the first information includes the second application traffic, the first network device determines a second identifier corresponding to the second application traffic, and determines M application programs according to the second identifier.

[0102] In some embodiments of the present application, the number of the second identifiers may be at least one. The first network device may perform flow identification on the second application flow, and determine each identifier obtained by flow identification as a second identifier, and then determine M application programs corresponding to the at least one second identifier.

[0103] In some embodiments of the present application, Figure 4As shown, an application identification detection device is provided in the first network device, and the application identification detection device 14 can be communicatively connected with the replication module 12 of the second network device, so that the first network device can control the application identification detection device 14 through the operating system to perform traffic identification on the second application traffic to obtain at least one second identifier.

[0104] It should be noted that, for the description of the first network device controlling the application identification detection device to perform traffic identification on the first application traffic through the operating system, reference can be made to the specific description of the second network device controlling the application identification detection device to perform traffic identification on the application traffic received by the second network device through the operating system in the above embodiment, and the embodiments of the present application will not be repeated here.

[0105] In an embodiment of the present application, since the storage capacity of the memory of the first network device may be greater than the storage capacity of the memory of the second network device, the amount of traffic characteristic information used by the first network device when performing traffic identification is greater than the amount of traffic characteristic information used by the second network device when performing traffic identification. Therefore, the first network device can perform traffic identification on the unidentified second application traffic and obtain at least one second identifier.

[0106] As can be seen, since the first information may include the second application traffic that is not recognized by the second network device, the first network device can directly perform traffic recognition on the unrecognized second application traffic to accurately determine the application to which the unrecognized second application traffic belongs. Therefore, the first network device can accurately determine the application that transmits traffic through the second network device, and based on the usage frequency of the application that transmits traffic through the second network device, accurately determine a small number of applications (i.e., Q applications) that may transmit traffic again through the second network device.

[0107] In some embodiments of the present application, the above step 103b can be specifically implemented through the following step 103b1.

[0108] Step 103b1: When the first information further includes a first identifier corresponding to the first application traffic, the first network device determines M application programs according to the first identifier and the second identifier.

[0109] In some embodiments of the present application, the first network device can determine a corresponding part of the applications based on the first identifier, and determine a corresponding other part of the applications based on the second identifier, so that the first network device can determine the one part of the applications and the other part of the applications as M applications.

[0110] It can be seen that since the first information can also include the first identifier corresponding to the first application traffic, the first network device can determine a part of the applications based on the first identifier, and determine another part of the applications based on the second identifier, so as to accurately determine the applications corresponding to the application traffic received by the second network device. Therefore, the first network device can accurately determine a small number of applications (i.e., Q applications) that may transmit traffic again through the second network device based on the usage frequency of the applications corresponding to the application traffic received by the second network device.

[0111] In some embodiments of the present application, Figure 4 An application frequency statistics device 15 and an identified application sending module 16 are also provided in the first network device, so that the first network device can send the first identifier corresponding to the first application traffic sent by the identified application sending module 13 of the second network device to the application frequency statistics device 15; and / or, the first network device can identify the second application traffic sent by the copy module 12 of the second network device through the application identification detection device 14, and send at least one second identifier obtained by identification to the application frequency statistics device 15 through the identified application sending module 16; further, the first network device can determine Q applications from M applications through the application frequency statistics device 15.

[0112] The function of the identified application sending module 16 is to forward at least one second identifier to the application frequency counting device 15 .

[0113] In a possible implementation of the present application, the first network device may obtain the historical activity of each of the M applications from other network devices through the application frequency statistics device 15, so as to determine the usage frequency of each application according to the historical activity of each application.

[0114] In another possible implementation of the present application, the first network device can determine the frequency of traffic transmission of each application program, and further determine the frequency of use of each application program, by using the application frequency statistics device 15, according to the number of identifiers (i.e., the first identifier or the second identifier) ​​corresponding to each application program. The larger the number of identifiers corresponding to an application program, the higher the frequency of traffic transmission of the application program, and the higher the frequency of use; the smaller the number of identifiers corresponding to an application program, the lower the frequency of traffic transmission of the application program, and the lower the frequency of use.

[0115] It can be understood that if the number of identifiers corresponding to an application (i.e., the first identifier or the second identifier) ​​is larger, it can be considered that the number of application traffic (i.e., the first application traffic or the second application traffic) belonging to the application in the application traffic received by the second network device is larger, and therefore, it can be determined that the traffic transmission frequency of the application is higher. If the number of identifiers corresponding to an application is smaller, it can be considered that the number of application traffic belonging to the application in the application traffic received by the second network device is smaller, and therefore, it can be determined that the traffic transmission frequency of the application is lower.

[0116] Step 104: The first network device determines Q applications from the M applications.

[0117] In the embodiment of the present application, the above Q applications are: the first Q applications in descending order of usage frequency, where Q is a positive integer.

[0118] In some embodiments of the present application, the first network device may first obtain the historical activity of each application in M ​​applications from other network devices, and then sort the M applications in order of historical activity from high to low, and determine Q applications from the sorted M applications.

[0119] It can be understood that the higher the historical activity of an application is, the more frequently the application is used; and the lower the historical activity of an application is, the less frequently the application is used.

[0120] In some embodiments of the present application, the first network device may first determine the number of identifiers corresponding to each application in M ​​applications, and then sort the M applications in descending order of the number of identifiers, and determine Q applications from the sorted M applications.

[0121] It can be understood that the larger the number of identifiers corresponding to an application, that is, the higher the traffic transmission frequency of an application, the higher the usage frequency of the application can be considered; the smaller the number of identifiers corresponding to an application, that is, the lower the traffic transmission frequency of an application, the lower the usage frequency of the application can be considered.

[0122] The following is an example of a specific solution for the first network device to determine Q application programs.

[0123] In some embodiments of the present application, Figure 1 ,like Figure 5 As shown, the above step 104 can be specifically implemented through the following steps 104a and 104b.

[0124] Step 104a: The first network device determines T applications whose corresponding identifiers match at least one third identifier from among the M applications.

[0125] In the embodiment of the present application, since the M applications can be determined by at least one of the first identifier and the second identifier, the identifiers corresponding to the M applications include at least one of the first identifier and the second identifier.

[0126] In some embodiments of the present application, the first network device may first determine L applications from M applications, where the L applications are: the first L applications whose corresponding identifiers are in descending order, and L is a positive integer; and then determine T applications whose corresponding identifiers match at least one third identifier from the L applications.

[0127] In some embodiments of the present application, the first network device may first sort the M applications in descending order according to the number of corresponding identifiers, and then determine the top L applications from the sorted M applications.

[0128] In the embodiment of the present application, the at least one third identifier is used to indicate the first at least one application program in the operator network with the highest to lowest usage frequency, and T is a positive integer.

[0129] In the embodiment of the present application, the at least one third identifier may include at least one of the following: an application identifier and an application type identifier.

[0130] In some embodiments of the present application, an operator network includes multiple network devices, including a first network device. The multiple network devices can be SDN controllers, and each network device can respectively determine the top at least one application with the highest to lowest traffic transmission frequency to determine the top at least one application with the highest to lowest usage frequency, thereby obtaining at least one third identifier, and then the first network device can send a request message to other network devices among the multiple network devices except the first network device, so that the other network devices can send at least one third identifier to the first network device, so that the first network device can determine at least one third identifier.

[0131] It should be noted that, for the description of determining the first at least one application with the highest to lowest traffic transmission frequency for each network device, reference can be made to the specific description of the first network device determining Q applications from M applications in the above embodiment, and the embodiments of the present application will not be repeated here.

[0132] In some embodiments of the present application, the first network device may first determine L identifiers of L applications, and then select T identifiers from the L identifiers that match (for example, are the same as) any one of at least one third identifier, and determine the applications indicated by the T identifiers as T applications.

[0133] Step 104b: The first network device determines the first Q applications among the T applications whose traffic transmission frequencies are ranked from high to low as Q applications.

[0134] It can be understood that, in the embodiment, T is a positive integer greater than or equal to Q.

[0135] In some embodiments of the present application, the first network device may determine the first Q applications among the T applications ranked from high to low as Q applications according to the ranking of at least one application ranked from high to low in frequency of use in the operator network.

[0136] Thus, it can be known that, since the first network device can determine T applications with high frequency of use in the operator network from a large number of M applications, that is, a small number of applications with high frequency of use, that is, a small number of applications that are more likely to transmit traffic again through the second network device, and further determine Q applications with high traffic transmission frequency from the small number of applications, that is, a smaller number of applications that are more likely to transmit traffic again through the second network device. Therefore, in the subsequent steps, after the first network device indicates the smaller number of applications to the second network device, since the number of the smaller number of applications is small and it is more likely to transmit traffic again through the second network device. And since the smaller amount of traffic feature information may include traffic feature information that the second network device has not read into the memory, that is, the traffic feature information of the second application traffic that the second network device cannot identify. Therefore, the second network device can read the traffic feature information corresponding to the application that it cannot identify into the memory, so as to perform traffic identification based on the smaller amount of traffic feature information, and can identify the application traffic received subsequently with a greater probability, so that the probability of being unable to identify the received application traffic can be reduced.

[0137] Step 105: The first network device sends Q application identifiers corresponding to the Q application programs to the second network device.

[0138] In an embodiment of the present application, the above-mentioned Q application identifiers are used by the second network device to determine the traffic characteristic information used for traffic identification.

[0139] Step 106: The second network device receives Q application identifiers corresponding to the Q application programs sent by the first network device.

[0140] In the embodiment of the present application, the above-mentioned Q applications are: the first Q applications with the highest to lowest usage frequency among the M applications, and Q is a positive integer.

[0141] Step 107: The second network device performs traffic identification on the application traffic received by the second network device based on the Q traffic feature information corresponding to the Q application identifiers.

[0142] In some embodiments of the present application, the Q pieces of traffic feature information correspond to the Q applications one by one, and each piece of traffic feature information is feature information of the application traffic of the corresponding application. The Q pieces of traffic feature information include at least one of the following: application protocol unique ID, application protocol description, header information of the application traffic message, etc.

[0143] In some embodiments of the present application, Figure 1 ,like Figure 6 As shown, before the above step 107, the traffic identification method provided in the embodiment of the present application may also include the following steps 401 to 403.

[0144] Step 401: The second network device determines R pieces of traffic feature information from Q pieces of traffic feature information.

[0145] In the embodiment of the present application, the above-mentioned R traffic characteristic information is the traffic characteristic information not stored in the memory of the second network device, and R is a positive integer less than or equal to Q.

[0146] In a possible implementation of the present application, the second network device may first determine Q pieces of traffic feature information corresponding to the Q application identifiers in the hard disk of the second network device, and then determine R pieces of traffic feature information from the Q pieces of traffic feature information.

[0147] In some embodiments of the present application, the second network device may first obtain at least one corresponding relationship from the hard disk of the second network device, and then determine Q traffic feature information corresponding to the Q application identifiers based on the at least one corresponding relationship.

[0148] Among them, each of the at least one corresponding relationship is a corresponding relationship between an application identifier and traffic feature information.

[0149] Optionally, the second network device may receive the at least one corresponding relationship from the first network device in advance, and store the at least one corresponding relationship in a feature library file in the hard disk of the second network device, so that the second network device may directly obtain at least one corresponding relationship from the feature library file stored in the hard disk.

[0150] Optionally, the corresponding relationship stored in the hard disk of the second network device and the corresponding relationship stored in the hard disk of other network devices may be completely the same.

[0151] Optionally, for each application identifier among the Q application identifiers, the second network device can determine an application identifier that is identical to one of the Q application identifiers from at least one application identifier in at least one corresponding relationship, and determine the traffic characteristic information corresponding to the application identifier to determine a traffic characteristic information, and so on, to determine the Qth traffic characteristic information.

[0152] In another possible implementation of the present application, the second network device may first determine P pieces of traffic feature information stored in the memory of the second network device from the Q pieces of traffic feature information, and then determine R pieces of traffic feature information not stored in the memory of the second network device from the Q pieces of traffic feature information. R=QP.

[0153] Among them, in the embodiment of the present application, the above-mentioned P traffic characteristic information is the traffic characteristic information stored in the memory of the second network device, and P is a positive integer.

[0154] Optionally, the second network device may read the traffic feature information in the memory to determine P traffic feature information. It is understandable that the P traffic feature information is the traffic feature information used by the second network device to perform traffic identification on the application traffic received recently.

[0155] In the embodiment of the present application, since the amount of traffic feature information that can be stored in the hard disk is greater than the amount of traffic feature information that can be stored in the memory of the second network device, a large number of corresponding relationships can be stored in the feature library file in the hard disk of the second network device. In this way, the second network device can determine the corresponding Q traffic feature information based on the Q application identifiers sent by the first network device, so as to perform traffic identification based on the Q traffic feature information.

[0156] Step 402: The second network device determines R traffic feature information from the hard disk of the second network device.

[0157] In some embodiments of the present application, the second network device may directly read R traffic feature information from the audio.

[0158] Step 403: The second network device stores R traffic feature information in the memory.

[0159] In the embodiment of the present application, if the second network device is to perform traffic identification, the second network device needs to read the traffic feature information used for traffic identification from the memory. Therefore, after the second network device reads Q traffic feature information from the hard disk, it can store R traffic feature information into the memory for subsequent direct use. Among them, each traffic feature information can be regarded as a matching feature set.

[0160] It can be understood that after the second network device stores R traffic feature information in the memory, Q traffic feature information is stored in the memory.

[0161] Thus, it can be known that since the second network device can determine a small amount of traffic characteristic information (i.e., R traffic characteristic information) corresponding to a small number of applications with a higher transmission frequency from the Q traffic characteristic information, and read the small amount of traffic characteristic information (i.e., R traffic characteristic information) corresponding to the small number of applications with a higher transmission frequency from the hard disk, the second network device can directly store the small amount of traffic characteristic information (i.e., R traffic characteristic information) corresponding to the small number of applications with a higher transmission frequency into the memory, instead of storing a large amount of traffic characteristic information into the memory, which can avoid the situation where some traffic characteristic information cannot be written due to insufficient memory storage capacity, and therefore, can reduce the situation where the received application traffic cannot be identified due to the inability to write some traffic characteristic information. In this way, the situation where the received application traffic cannot be identified due to the inability to store some traffic characteristic information can be reduced while reducing the waste of transmission resources.

[0162] The embodiment of the present application provides a traffic identification method. Since the number of second network devices can be at least one, and the application corresponding to the application traffic received by the at least one second network device may not be completely the same, after the at least one second network device sends the first information to the first network device, the number of M applications determined by the first network device according to the first information is greater than the number of applications corresponding to the application traffic received by the at least one second network device. And the first network device can also determine Q applications from the M applications, and the Q applications are a small number of applications with a high traffic transmission frequency. And the Q applications may be at least partially different from the application corresponding to the application traffic received by the at least one second network device. Therefore, after the first network device indicates the Q applications to at least one second network device through Q application identifiers, on the one hand, because the number of Q applications is small, each second network device can read the Q traffic feature information into the memory without bringing too much burden to the memory, and use the Q traffic feature information in the memory to perform traffic identification on the received application traffic. On the other hand, because there may be an application among the Q applications that is different from the application corresponding to the application traffic received by at least one second network device, the at least one second network device can read the traffic characteristic information corresponding to the different application into the memory. Thus, while ensuring that at least one second network device can use the Q traffic characteristic information for traffic identification, the probability that at least one second network device cannot identify the received application traffic due to failure to read certain traffic characteristic information into the memory is reduced. In this way, the operator network device can accurately control the application traffic of the application.

[0163] Of course, in order to ensure that each of the Q traffic feature information indicated by the first network device to the second network device can be used by the second network device for traffic identification, the second network device can also indicate the memory storage capacity of the second network device to the first network device, so that the first network device can determine the Q applications according to the memory storage capacity. The following is an example.

[0164] In some embodiments of the present application, Figure 1 ,like Figure 7 As shown, before the above step 104, the traffic identification method provided in the embodiment of the present application may further include the following step 501, and the above step 104 may be specifically implemented by the following step 104c and step 104d.

[0165] Step 501: The second network device sends second information to the first network device.

[0166] In the embodiment of the present application, the second information is used to indicate the maximum amount of traffic characteristic information stored in the memory of the second network device. The second information is used by the first network device to determine Q applications.

[0167] In some embodiments of the present application, the second network device may carry the second information in the first information to send the second information to the first network device. Alternatively, the second network device may send the second information to the first network device before or after sending the first information to the first network device.

[0168] In the embodiment of the present application, since the memory storage capabilities of different network devices are different, the maximum amount of flow characteristic information stored in the memory of different network devices is also different. Therefore, the second network device can report the maximum amount of flow characteristic information stored in the memory of the second network device to the first network device to avoid the situation where the number of Q application identifiers indicated by the first network device exceeds the maximum amount of flow characteristic information stored in the memory of the second network device, thereby avoiding the situation where the Q flow characteristic information indicated by the first network device cannot be written into the memory of the second network device, resulting in the second network device being unable to use some of the Q flow characteristic information for flow identification.

[0169] Step 104c: The first network device receives the second information sent by the second network device.

[0170] In the embodiment of the present application, the second information is used to indicate the maximum amount of traffic characteristic information stored in the memory of the second network device.

[0171] Step 104d: The first network device determines Q applications from the M applications according to the maximum number indicated by the second information.

[0172] In some embodiments of the present application, the first network device may determine the maximum number indicated by the second information as the number Q of the above-mentioned Q applications.

[0173] In some embodiments of the present application, the first network device may first determine the T applications, and then determine Q applications from the T applications.

[0174] In this way, it can be seen that since the second network device can report the maximum number of traffic characteristic information stored in its own memory to the first network device, so that the first network device can indicate the maximum number of application identifiers to the second network device, that is, the maximum number of application identifiers within the capability range of the second network device can be indicated to the second network device. Therefore, the situation where the Q traffic characteristic information indicated by the first network device cannot be written into the memory of the second network device, resulting in the second network device being unable to use some of the Q traffic characteristic information for traffic identification can be reduced.

[0175] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of the interaction between the first network device and the second network device. It is understandable that, in order to realize the above functions, the first network device or the second network device includes a hardware structure and / or software module corresponding to each function. It should be easily appreciated by those skilled in the art that, in combination with the algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present application.

[0176] The embodiment of the present application can divide the functional modules of the first network device or the second network device according to the above method example. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical function division. There may be other division methods in actual implementation.

[0177] In the case of dividing each functional module into corresponding functional modules, Figure 8 FIG. 2 shows a possible schematic diagram of the flow identification device involved in the above embodiment, and the flow identification device is a first flow identification device. Figure 8As shown, the first traffic identification device 40 may include: a receiving module 41, a determining module 42 and a sending module 43. Among them, the receiving module 41 is used to receive the first information from the second traffic identification device, and the first information includes at least one of the following: a first identifier corresponding to the identified first application traffic, and an unidentified second application traffic. The determining module 42 is used to determine M applications according to the first information received by the receiving module 41, and the M applications are the applications corresponding to the application traffic received by the second traffic identification device, and M is a positive integer; and determine Q applications from the M applications, and the Q applications are: the first Q applications in descending order of usage frequency, and Q is a positive integer. The sending module 43 is used to send Q application identifiers corresponding to the Q applications determined by the determining module 42 to the second traffic identification device.

[0178] In an embodiment of the present application, the above-mentioned determination module 42 is specifically used to determine M applications based on the first identifiers sent by multiple second traffic identification devices when the first information includes a first identifier corresponding to the first application traffic and does not include the second application traffic; or, when the first information includes the second application traffic, determine the second identifier corresponding to the second application traffic, and determine the M applications based on the second identifier.

[0179] In the embodiment of the present application, the above-mentioned determination module 42 is specifically used to determine M application programs according to the first identifier and the second identifier when the first information also includes the first identifier corresponding to the first application traffic.

[0180] In the embodiment of the present application, the determination module 42 is specifically used to determine T applications whose corresponding first identifier matches at least one third identifier from M applications, where T is a positive integer; and determine the first Q applications with the highest to lowest traffic transmission frequency among the T applications as Q applications. The at least one third identifier is used to indicate the first at least one application with the highest to lowest usage frequency in the operator network.

[0181] In an embodiment of the present application, the above-mentioned receiving module 41 is also used to receive second information sent by a second traffic identification device before the determination module 42 determines Q applications from M applications, and the second information is used to indicate the maximum number of traffic characteristic information stored in the memory of the second traffic identification device; and determine Q applications from the M applications according to the maximum number indicated by the second information.

[0182] It should be noted that all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.

[0183] In the case of dividing each functional module into corresponding functional modules, Fig. 9 FIG. 2 shows a possible schematic diagram of the flow identification device involved in the above embodiment, which is a second flow identification device. Fig. 9 As shown, the second traffic identification device 50 may include: a sending module 51, a receiving module 52 and an execution module 53. The sending module 51 is used to send first information to the first traffic identification device, and the first information includes at least one of the following: a first identifier corresponding to the identified first application traffic and an unidentified second application traffic. The first information is used by the first traffic identification device to determine M applications, where M is a positive integer. The receiving module 52 is used to receive Q application identifiers corresponding to Q applications sent by the first traffic identification device. The Q applications are: among the M applications, the first Q applications with the highest to lowest usage frequency, where Q is a positive integer. The execution module 53 is used to perform traffic identification on the application traffic received by the second traffic identification device 50 based on the Q traffic feature information corresponding to the Q application identifiers received by the receiving module 52.

[0184] In an embodiment of the present application, the above-mentioned execution module 53 is also used to perform traffic identification on the application traffic received by the second traffic identification device 50 before the sending module 51 sends the first information to the first traffic identification device, so as to obtain the first information, and the first information includes at least one of the following: a first identifier corresponding to the first application traffic and the second application traffic.

[0185] In an embodiment of the present application, the above-mentioned execution module 53 is also used to determine R traffic characteristic information from the Q traffic characteristic information before performing traffic identification on the application traffic received by the second traffic identification device 50 based on the Q traffic characteristic information corresponding to the Q application identifiers, where the R traffic characteristic information is the traffic characteristic information not stored in the memory of the second traffic identification device, and R is a positive integer less than or equal to Q; and determine the R traffic characteristic information from the hard disk of the second traffic identification device 50; and store the R traffic characteristic information in the memory.

[0186] In the embodiment of the present application, the sending module 51 is further used to send second information to the first traffic identification device before the receiving module 52 receives the Q application identifiers corresponding to the Q applications sent by the first traffic identification device, and the second information is used to indicate the maximum amount of traffic feature information stored in the memory of the second traffic identification device 50. The second information is used by the first traffic identification device to determine the Q applications.

[0187] It should be noted that all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.

[0188] The embodiment of the present application further provides a traffic identification system, including: a first network device and a second network device, wherein the first network device executes the traffic identification method as described in the above implementation, and the second network device executes the traffic identification method as described in the above implementation.

[0189] It should be noted that the specific working process of each functional module in the first network device and the second network device provided in the embodiment of the present application can refer to the specific description of the corresponding process in the method embodiment, and the embodiment of the present application will not be repeated in detail here. The first network device and the second network device provided in the embodiment of the present application are used to execute the above-mentioned traffic identification method, so the same effect as the above-mentioned traffic identification method can be achieved.

[0190] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0191] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0192] The units described as separate components may or may not be physically separated, and the components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple different places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0193] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0194] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium, including several instructions to enable a device (which can be a single-chip microcomputer, chip, etc.) or a processor (processor) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory, ROM), random access memory (RandomAccess Memory, RAM), disk or optical disk and other media that can store program code.

[0195] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A traffic identification method, applied to a first network device, characterized in that: The method comprises: Receive first information sent by a second network device, wherein the first information includes at least one of the following: a first identifier corresponding to the identified first application traffic and an unidentified second application traffic; Determine M applications according to the first information, where the M applications are applications corresponding to the application traffic received by the second network device, and M is a positive integer; Determine Q applications from the M applications, where the Q applications are: the first Q applications from high to low usage frequency, where Q is a positive integer; Send Q application identifiers corresponding to the Q application programs to the second network device.

2. The method according to claim 1, characterized in that The determining M applications according to the first information includes: In a case where the first information includes the first identifier corresponding to the first application traffic but does not include the second application traffic, determining the M applications according to the first identifiers sent by a plurality of the second network devices; or, In the case where the first information includes the second application traffic, a second identifier corresponding to the second application traffic is determined, and the M applications are determined according to the second identifier.

3. The method according to claim 2, characterized in that The determining the M applications according to the second identifier includes: In a case where the first information further includes the first identifier corresponding to the first application traffic, the M application programs are determined according to the first identifier and the second identifier.

4. The method according to claim 1, characterized in that: Determining Q applications from the M applications includes: Determine T applications whose corresponding identifiers match at least one third identifier from the M applications, where T is a positive integer; Determine the top Q applications with the highest to lowest traffic transmission frequencies among the T applications as the Q applications; The at least one third identifier is used to indicate the first at least one application program in the operator network with the highest to lowest usage frequency.

5. The method according to claim 1, characterized in that Determining Q applications from the M applications includes: receiving second information sent by the second network device, where the second information is used to indicate a maximum amount of traffic characteristic information stored in a memory of the second network device; The Q applications are determined from the M applications according to the maximum number indicated by the second information.

6. A traffic identification method, applied to a second network device, characterized in that: The method comprises: Sending first information to a first network device, the first information including at least one of the following: a first identifier corresponding to the identified first application traffic and unidentified second application traffic, the first information being used by the first network device to determine M applications, where M is a positive integer; Receiving Q application identifiers corresponding to Q application programs sent by the first network device, where the Q application programs are: first Q application programs in descending order of usage frequency among the M application programs, where Q is a positive integer; Based on the Q traffic feature information corresponding to the Q application identifiers, traffic identification is performed on the application traffic received by the second network device.

7. The method according to claim 6, characterized in that Before sending the first information to the first network device, the method further includes: Perform traffic identification on the application traffic received by the second network device to obtain the first information, where the first information includes at least one of the following: the first identifier corresponding to the first application traffic and the second application traffic.

8. The method according to claim 6, characterized in that Before performing traffic identification on the application traffic received by the second network device based on the Q traffic feature information corresponding to the Q application identifiers, the method further includes: Determine R pieces of traffic feature information from the Q pieces of traffic feature information, where the R pieces of traffic feature information are traffic feature information not stored in the memory of the second network device, and R is a positive integer less than or equal to Q; Determine the R traffic feature information from the hard disk of the second network device; The R flow characteristic information is stored in the memory.

9. The method according to claim 6, characterized in that Before receiving the Q application identifiers corresponding to the Q application programs sent by the first network device, the method further includes: Sending second information to the first network device, where the second information is used to indicate a maximum amount of traffic characteristic information stored in a memory of the second network device; The second information is used by the first network device to determine the Q applications.

10. A flow identification system, characterized in that: The traffic identification system includes a first network device and a second network device; The first network device executes the traffic identification method according to any one of claims 1 to 5; the second network device executes the traffic identification method according to any one of claims 6 to 9.

11. A network device, characterized in that: The method comprises a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the traffic identification method as described in any one of claims 1 to 9 are implemented.

12. A readable storage medium, characterized in that: The readable storage medium stores a program or instruction, and when the program or instruction is executed by a processor, the steps of the traffic identification method according to any one of claims 1 to 9 are implemented.