Network packet processing method and device, electronic equipment and storage medium
By performing packet judgment processing and data change processing of preset judgment groups on network packet data, combined with the transmission of receiving information, the problem of network packet processing delay in the prior art is solved, and efficient and low-latency network packet processing is achieved.
Patent Information
- Application Number
- CN202510121456.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-24
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-24
AI Technical Summary
The existing network packet processing methods have a large delay in network packet processing due to the time when data is stored and processed in memory, as well as the possible queueing delays during network transmission, resulting in a large delay in network packet processing, which in turn reduces processing performance.
By performing packet judgment processing of the acquired multiple network packet data in the preset judgment group, data change processing is performed based on the judgment results and preset change rules, and finally, the target packet data is transmitted to the corresponding receiving end based on the receiving end information.
Real-time processing of network packet data is realized without cached entire packet data, reducing latency, avoiding a large amount of cache space requirements, and being able to process multiple network packet data at the same time, avoiding congestion and improving processing speed.
Smart Images

Figure CN119946094A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of network technology, and in particular to a method and device for processing network packets, an electronic device, and a storage medium. Background Art
[0002] With the increasing speed and number of connections in networks, network packet processing has become a crucial issue, encompassing functions such as packet filtering, load balancing, and network firewalls. Currently, the mainstream network packet processing methods are the Data Plane Development Kit (DPDK) and eXpressData Path (XDP), which achieve high-speed network packet processing.
[0003] Conventional network packet processing methods typically store the network packet in memory first and then use pointers to move it, for example, grabbing the packet data from a specific location in memory, performing the necessary comparison or processing, or modifying the packet data before writing it back to memory. Once the entire process is complete, the packet data is read from memory and transmitted to the network port or host computer.
[0004] Therefore, the existing network packet processing method will cause a large delay in network packet processing due to the time it takes to store and process data in memory, as well as queuing delays that may occur during network transmission, further leading to a decrease in network packet processing performance. Summary of the Invention
[0005] The present disclosure provides a network packet processing method and apparatus, electronic device, and storage medium. Its primary purpose is to address the problem of significant delays in network packet processing, which can be caused by the time required to store and process data in memory, as well as queuing delays that may occur during network transmission, leading to decreased network packet processing performance.
[0006] According to a first aspect of the present disclosure, a method for processing a network packet is provided, comprising:
[0007] Performing packet determination processing on the acquired plurality of network packet data through the corresponding preset determination groups to obtain first determination results corresponding to the plurality of network packet data; wherein the first determination results are used to at least determine whether the corresponding network packet data passes the determination;
[0008] Performing data modification processing on the plurality of network packet data according to the first judgment result and the preset modification rule corresponding to each data segment to obtain a plurality of target packet data; wherein each network packet data includes a plurality of the data segments;
[0009] The target packet data is transmitted to the corresponding packet receiving end according to the first judgment result and the receiving end information, wherein the receiving end information is at least used to determine the packet receiving end corresponding to the target packet data.
[0010] Optionally, performing packet judgment processing on the acquired plurality of network packet data through respective corresponding preset judgment groups to obtain first judgment results corresponding to the plurality of network packet data includes:
[0011] determining first data in the first network packet data based on location data of a first judgment condition in a first preset judgment group; wherein the first preset judgment group includes at least a plurality of judgment conditions, each judgment condition including at least location data, a judgment length, comparison data, a comparison rule, and marking data, the plurality of judgment conditions including the first judgment condition, the first network packet data being any one of the plurality of network packet data, and the first preset judgment group being a preset judgment group corresponding to the first network packet data;
[0012] Determining a data segment to be determined in the first network packet data according to the first data and the determination length of the first determination condition; wherein the plurality of data segments includes the data segment to be determined;
[0013] Comparing the comparison data of the first judgment condition with the data segment to be judged according to the comparison rule of the first judgment condition to obtain a first result corresponding to the first judgment condition;
[0014] The first network packet data is subjected to packet judgment processing one by one according to the multiple judgment conditions until the judgment is completed according to the identification data of the target judgment condition, thereby obtaining the first judgment result, wherein the target judgment condition is any judgment condition among the multiple judgment conditions that is after the first judgment condition.
[0015] Optionally, performing data change processing on the plurality of network packet data according to the first judgment result and a preset change rule corresponding to each data segment to obtain a plurality of target packet data includes:
[0016] Determining, from the plurality of network packet data, network packet data corresponding to each of the preset change rules according to the first preset corresponding information; wherein each of the preset change rules corresponds to one or more of the network packet data;
[0017] Determining the first judgment result of the network packet data corresponding to each of the preset change rules as a reference result corresponding to each of the preset change rules;
[0018] In the case where it is determined according to the reference result that the corresponding network packet data fails the judgment, canceling the data change processing of the network packet data corresponding to the reference result;
[0019] When it is determined that the corresponding network packet data passes the judgment according to the reference result, data change processing is performed on the network packet data corresponding to the reference result according to the preset change rule corresponding to the reference result to obtain the multiple target packet data.
[0020] Optionally, when it is determined that the corresponding network packet data passes the judgment according to the reference result, data change processing is performed on the network packet data corresponding to the reference result according to the preset change rule corresponding to the reference result, and the plurality of target packet data obtained include:
[0021] Determining a change action in the preset change rule; wherein the change action includes at least deletion, replacement, addition, and no action;
[0022] When it is determined that the change action is deletion, deleting the data segment corresponding to the preset change rule in the network packet data corresponding to the reference result;
[0023] When the change action is determined to be add / replace, determining add / replace data in the preset change rule, and performing add / replace processing on the data segment corresponding to the preset change rule in the network packet data corresponding to the reference result according to the add / replace data;
[0024] When it is determined that the change action is no action, no data change processing is performed on the network packet data corresponding to the reference result.
[0025] Optionally, transmitting the target packet data to a corresponding packet receiving end according to the first judgment result and receiving end information includes:
[0026] Determining the first judgment result corresponding to each of the packet receiving ends according to the receiving end information; wherein each of the packet receiving ends corresponds to one or more of the first judgment results;
[0027] If it is determined according to the first judgment result that the corresponding network packet data fails to pass the judgment, canceling the data transmission of the packet receiving end corresponding to the first judgment result;
[0028] When it is determined according to the first judgment result that the corresponding network packet data passes the judgment, the target packet data corresponding to the first judgment result is transmitted to the packet receiving end corresponding to the first judgment result.
[0029] Optionally, before performing packet judgment processing on the acquired plurality of network packet data through the respective corresponding preset judgment groups to obtain the first judgment results respectively corresponding to the plurality of network packet data, the method further includes:
[0030] Performing judgment group setting processing by a preset host computer to obtain a plurality of preset judgment groups;
[0031] The preset host computer performs the judgment group setting process to obtain a plurality of preset judgment groups including:
[0032] The judgment condition setting process is performed by the preset host computer to obtain a plurality of the judgment conditions; wherein the judgment condition setting process performed by the preset host computer at least includes setting position data, setting judgment length, setting comparison data, setting comparison rules, and setting mark data;
[0033] The plurality of judgment conditions are classified and processed according to the network packet data to obtain the plurality of preset judgment groups.
[0034] Optionally, before performing packet judgment processing on the acquired plurality of network packet data through the respective corresponding preset judgment groups to obtain the first judgment results respectively corresponding to the plurality of network packet data, the method further includes:
[0035] Performing preset change rule setting processing by a preset host computer to obtain the preset change rule;
[0036] The preset change rule setting process is performed by the preset host computer to obtain the preset change rule, which includes:
[0037] The preset host computer sets the network packet data corresponding to each of the preset change rules respectively to obtain the first preset corresponding information;
[0038] Setting a change action for each of the preset change rules respectively by the preset host computer to obtain the change action;
[0039] Adding / replacing data is set for each of the preset change rules by the preset host computer to obtain the added / replaced data;
[0040] Data merging processing is performed according to the first preset corresponding information, the change action, and the added / replaced data to obtain the preset change rule.
[0041] According to a second aspect of the present disclosure, a network packet processing device is provided, comprising:
[0042] a judgment unit configured to perform packet judgment processing on the acquired plurality of network packet data through the corresponding preset judgment groups to obtain a first judgment result corresponding to each of the plurality of network packet data; wherein the first judgment result is used to at least determine whether the corresponding network packet data passes the judgment;
[0043] a changing unit, configured to perform data changing processing on the plurality of network packet data according to the first judgment result and a preset changing rule corresponding to each data segment, to obtain a plurality of target packet data; wherein each network packet data includes a plurality of the data segments;
[0044] A transmission unit is used to transmit the target packet data to a corresponding packet receiving end according to the first judgment result and receiving end information, wherein the receiving end information is at least used to determine the packet receiving end corresponding to the target packet data.
[0045] Optionally, the judging unit includes:
[0046] a determination module, configured to determine first data in the first network packet data based on location data of a first judgment condition in a first preset judgment group; wherein the first preset judgment group includes at least a plurality of judgment conditions, each judgment condition including at least location data, a judgment length, comparison data, a comparison rule, and marking data; the plurality of judgment conditions includes the first judgment condition; the first network packet data is any one of the plurality of network packet data; and the first preset judgment group is a preset judgment group corresponding to the first network packet data;
[0047] The determining module is further configured to determine a data segment to be determined in the first network packet data according to the first data and the determination length of the first determination condition; wherein the plurality of data segments includes the data segment to be determined;
[0048] a comparison module, configured to compare the comparison data of the first judgment condition with the data segment to be judged according to the comparison rule of the first judgment condition, to obtain a first result corresponding to the first judgment condition;
[0049] A judgment module is used to perform packet judgment processing on the first network packet data one by one according to the multiple judgment conditions until the judgment is completed according to the identification data of the target judgment condition, thereby obtaining the first judgment result, wherein the target judgment condition is any judgment condition among the multiple judgment conditions that is after the first judgment condition.
[0050] Optionally, the changing unit includes:
[0051] a determination module, configured to determine, from the plurality of network packet data, network packet data corresponding to each of the preset change rules according to the first preset corresponding information; wherein each of the preset change rules corresponds to one or more of the network packet data;
[0052] The determining module is further configured to determine the first judgment result of the network packet data corresponding to each of the preset change rules as a reference result corresponding to each of the preset change rules;
[0053] a cancelling module, configured to cancel data change processing on the network packet data corresponding to the reference result if it is determined that the corresponding network packet data fails to pass the judgment according to the reference result;
[0054] The changing module is used to perform data changing processing on the network packet data corresponding to the reference result according to the preset changing rule corresponding to the reference result when it is determined that the corresponding network packet data passes the judgment according to the reference result, so as to obtain the multiple target packet data.
[0055] Optionally, the changing module is further configured to:
[0056] When it is determined that the corresponding network packet data passes the judgment according to the reference result, data modification processing is performed on the network packet data corresponding to the reference result according to the preset modification rule corresponding to the reference result, and the plurality of target packet data obtained include:
[0057] Determining a change action in the preset change rule; wherein the change action includes at least deletion, replacement, addition, and no action;
[0058] When it is determined that the change action is deletion, deleting the data segment corresponding to the preset change rule in the network packet data corresponding to the reference result;
[0059] When the change action is determined to be add / replace, determining add / replace data in the preset change rule, and performing add / replace processing on the data segment corresponding to the preset change rule in the network packet data corresponding to the reference result according to the add / replace data;
[0060] When it is determined that the change action is no action, no data change processing is performed on the network packet data corresponding to the reference result.
[0061] Optionally, the transmission unit includes:
[0062] a determination module, configured to determine the first judgment result corresponding to each of the packet receiving ends according to the receiving end information; wherein each of the packet receiving ends corresponds to one or more of the first judgment results;
[0063] a cancelling module, configured to cancel the data transmission of the packet receiving end corresponding to the first judgment result when it is determined that the corresponding network packet data fails to pass the judgment according to the first judgment result;
[0064] The transmission module is used to transmit the target packet data corresponding to the first judgment result to the packet receiving end corresponding to the first judgment result when it is determined that the corresponding network packet data passes the judgment according to the first judgment result.
[0065] Optionally, the device further includes:
[0066] A setting unit, configured to perform a judgment group setting process through a preset host computer to obtain a plurality of preset judgment groups;
[0067] The setting unit is further configured to:
[0068] The judgment condition setting process is performed by the preset host computer to obtain a plurality of the judgment conditions; wherein the judgment condition setting process performed by the preset host computer at least includes setting position data, setting judgment length, setting comparison data, setting comparison rules, and setting mark data;
[0069] The plurality of judgment conditions are classified and processed according to the network packet data to obtain the plurality of preset judgment groups.
[0070] Optionally, the setting unit is further configured to:
[0071] Performing preset change rule setting processing by a preset host computer to obtain the preset change rule;
[0072] The setting unit is further configured to:
[0073] The preset host computer sets the network packet data corresponding to each of the preset change rules respectively to obtain the first preset corresponding information;
[0074] Setting a change action for each of the preset change rules respectively by the preset host computer to obtain the change action;
[0075] Adding / replacing data is set for each of the preset change rules by the preset host computer to obtain the added / replaced data;
[0076] Data merging processing is performed according to the first preset corresponding information, the change action, and the added / replaced data to obtain the preset change rule.
[0077] According to a third aspect of the present disclosure, there is provided an electronic device, including:
[0078] at least one processor; and
[0079] a memory communicatively connected to the at least one processor; wherein,
[0080] The memory stores instructions that can be executed by the at least one processor. The instructions are executed by the at least one processor to enable the at least one processor to perform the method described in the first aspect.
[0081] According to a fourth aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to enable the computer to execute the method described in the first aspect.
[0082] According to a fifth aspect of the present disclosure, a computer program product is provided, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the method as described in the first aspect above.
[0083] The network packet processing method and device, electronic device and storage medium provided by the present disclosure perform packet judgment processing on multiple acquired network packet data through their respective corresponding preset judgment groups to obtain first judgment results corresponding to each of the multiple network packet data; wherein the first judgment result is at least used to determine whether the corresponding network packet data passes the judgment; data change processing is performed on the multiple network packet data according to the first judgment result and the preset change rule corresponding to each data segment to obtain multiple target packet data; wherein each network packet data includes multiple data segments; the target packet data is transmitted to the corresponding packet receiving end according to the first judgment result and the receiving end information, wherein the receiving end information is at least used to determine the packet receiving end corresponding to the target packet data. Compared with related technologies, the embodiments of the present disclosure can process network packet data in real time through pre-set preset judgment groups, preset change rules, and receiving end information. There is no need to cache the entire network packet data before processing the packet data. It can promptly judge and process network packet data, reduce latency, and avoid the need for a large amount of cache space. Furthermore, it can also process multiple network packet data simultaneously, avoid congestion, and improve the processing speed of packet data.
[0084] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present application, nor is it intended to limit the scope of the present application. Other features of the present application will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0085] The accompanying drawings are provided to facilitate a better understanding of the present invention and do not constitute a limitation of the present disclosure.
[0086] Figure 1 A flowchart of a method for processing network packets provided by an embodiment of the present disclosure;
[0087] Figure 2 A diagram of a network packet processing architecture provided by an embodiment of the present disclosure;
[0088] Figure 3 A schematic diagram of the structure of a packet determination module provided by an embodiment of the present disclosure;
[0089] Figure 4 A schematic diagram of the structure of a packet modification module provided in an embodiment of the present disclosure;
[0090] Figure 5 A schematic diagram of the structure of a packet path switching module provided by an embodiment of the present disclosure;
[0091] Figure 6 A schematic diagram of a packet determination process provided by an embodiment of the present disclosure;
[0092] Figure 7 A schematic diagram of network packet data provided by an embodiment of the present disclosure;
[0093] Figure 8 An example diagram of a packet determination module provided by an embodiment of the present disclosure;
[0094] Figure 9 An example diagram of a packet modification module provided in an embodiment of the present disclosure;
[0095] Figure 10 An example diagram of a packet path switching module provided by an embodiment of the present disclosure;
[0096] Figure 11 A schematic diagram of the structure of a network packet processing device provided by an embodiment of the present disclosure;
[0097] Figure 12 A schematic structural diagram of another network packet processing device provided by an embodiment of the present disclosure;
[0098] Figure 13 A schematic block diagram of an exemplary electronic device provided for an embodiment of the present disclosure. DETAILED DESCRIPTION
[0099] The following description of exemplary embodiments of the present disclosure is made in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding. These details should be considered as merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0100] The following describes a method and apparatus for processing network packets, an electronic device, and a storage medium according to embodiments of the present disclosure with reference to the accompanying drawings.
[0101] Figure 1 A flowchart of a method for processing network packets provided by an embodiment of the present disclosure is provided.
[0102] like Figure 1 As shown, the method is applied to the server and includes the following steps:
[0103] In step 101, the obtained plurality of network packet data are subjected to packet judgment processing by corresponding preset judgment groups to obtain first judgment results corresponding to the plurality of network packet data; wherein the first judgment results are at least used to determine whether the corresponding network packet data passes the judgment.
[0104] In the embodiment of the present disclosure, network packet data can be processed through a hardware pipeline architecture combined with parallel processing capabilities. That is, when executing the network packet processing method of the embodiment of the present disclosure, accelerated processing can be performed through custom-selected hardware devices. The hardware devices include but are not limited to: application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), etc. Specifically, the embodiment of the present disclosure does not limit the selection of the hardware devices.
[0105] Furthermore, for the sake of convenience, in the subsequent real-time examples, the hardware device is described using FPGA as an example. When executing the network packet processing method, the network packet data can be processed and judged by three modules in the FPGA. Specifically, Figure 2 As shown, Figure 2A diagram of a network packet processing architecture provided in an embodiment of the present disclosure includes a packet judgment module, a packet change module, and a packet path switching module. Network packet data enters the FPGA via a network channel port, first passing through the packet judgment module, then the packet change module, and finally the packet path switching module.
[0106] It should be noted that Figure 2 The packet judgment module is the module including the preset judgment group, the packet change module is the module including the preset change rule, and the packet path switching module is the module including the receiving end information.
[0107] For the above-mentioned preset judgment group and packet judgment processing of network packet data, please refer to Figure 3 To explain, Figure 3 This is a schematic diagram of the structure of a packet judgment module provided in an embodiment of the present disclosure. The packet judgment module includes multiple preset judgment groups (e.g., Group 1, Group 2, etc.). Each preset judgment group contains a random access memory (RAM) space. The RAM space includes multiple judgment conditions, such as the three judgment conditions included in Group 1. The contents of the RAM space, i.e., the judgment conditions, can be determined by, but not limited to, a preset host computer setting the judgment conditions in the RAM. The judgment conditions of the preset judgment groups can be used to perform packet judgment on the contents of different regions of a single network packet data, for example, to determine whether the contents of the network packet data are equal to comparison data, or whether the contents of the network packet data are less than the comparison data. The comparison data is pre-set data used to judge the contents of the network packet data.
[0108] The first judgment result is the judgment result of the network packet data obtained after the network packet data passes the judgment of the corresponding preset judgment group, for example: result1, result2, etc. It should be noted that if all the judgment conditions in a preset judgment group are met, the judgment result of the network packet data corresponding to this preset judgment group is passed. If any judgment condition in a preset judgment group is not met, the judgment result of the network packet data corresponding to this preset judgment group is failed.
[0109] Step 102 , performing data modification processing on the plurality of network packet data according to the first judgment result and the preset modification rule corresponding to each data segment, to obtain a plurality of target packet data; wherein each network packet data includes a plurality of the data segments.
[0110] In the embodiment of the present disclosure, the corresponding data segment in the network packet data can be changed by presetting the change rule to obtain the target packet data. For details, see Figure 4 In the description, Figure 4 A schematic diagram of the structure of a packet change module provided in an embodiment of the present disclosure is provided, wherein the packet change module includes multiple groups of registers, each group of registers representing the content of each packet data segment that needs to be changed, namely the preset change rule.
[0111] like Figure 4 As shown, after the packet judgment module completes the comparison of network packet data, the network packet data is modified according to the action of the register. Each register group (preset modification rule) includes action (indicating the modification action, for example: 0 = delete, 1 = replace, 2 = add, 3 = do nothing); content is the content replaced or added to the network packet data when performing the replacement or addition action; en_mask indicates which groups of the packet judgment module's results are to be referenced, with each bit representing each judgment group. For example, if the network packet data corresponds to three preset judgment groups and en_mask indicates that reference is needed for result1, then only result1 (the first judgment result corresponding to the first preset judgment group (group 1)) needs to be considered. If result1 is a pass, the network packet data can be modified according to the preset modification rule even if the first judgment results corresponding to other groups are a fail. If result1 is a fail, the network packet data cannot be modified even if the first judgment results corresponding to other groups are a pass.
[0112] It should be noted that each network packet data corresponds to one or more preset judgment groups. Furthermore, each network packet data corresponds to one or more first judgment results.
[0113] Step 103: Transmit the target packet data to the corresponding packet receiving end according to the first judgment result and receiving end information, wherein the receiving end information is at least used to determine the packet receiving end corresponding to the target packet data.
[0114] In the embodiment of the present disclosure, for ease of understanding, the embodiment of the present disclosure provides a structural diagram of a packet path switching module, such as Figure 5As shown, the packet path switching module includes receiving end information to determine whether the target packet data flows to the network port or to the host computer through the Peripheral Component Interconnect Express (PCIe). The packet path switching module contains two en_masks, which respectively indicate whether the packet is to flow to the network port or the host computer, and each bit represents each judgment group.
[0115] Regarding en_mask, for example, when the target packet data corresponds to three first judgment results, and the en_mask of the network port indicates that result1 needs to be referenced, then when transmitting the target packet data to the network port, it is only necessary to pay attention to whether result1 (the first judgment result corresponding to the first preset judgment group (group 1)) is a pass judgment. When result1 is a pass judgment, the target packet data can be transmitted to the network port even if the first judgment results corresponding to other groups are a fail judgment. When result1 is a fail judgment, the target packet data cannot be transmitted to the network port even if the first judgment results corresponding to other groups are a pass judgment.
[0116] The present disclosure provides a method for processing network packets, wherein a plurality of acquired network packet data are subjected to packet judgment processing according to respective corresponding preset judgment groups, thereby obtaining first judgment results corresponding to the plurality of network packet data. The first judgment results are used to at least determine whether the corresponding network packet data passes the judgment. The plurality of network packet data are subjected to data modification processing according to the first judgment results and preset modification rules corresponding to each data segment, thereby obtaining a plurality of target packet data. Each network packet data includes a plurality of data segments. The target packet data are transmitted to a corresponding packet receiving end according to the first judgment results and receiving end information, wherein the receiving end information is used to at least determine the packet receiving end corresponding to the target packet data. Compared with the related art, the present disclosure, through the use of pre-set preset judgment groups, preset modification rules, and receiving end information, can process network packet data in real time, eliminating the need to cache the entire network packet data before processing the packet data. This allows for timely judgment and processing of network packet data, reduces latency, and avoids the need for large amounts of cache space. Furthermore, multiple network packet data can be processed simultaneously, avoiding congestion and increasing packet data processing speed.
[0117] In one possible implementation of the embodiment of the present disclosure, as a refinement of the above step 101, when performing packet judgment processing on multiple network packet data, the embodiment of the present disclosure provides a flow chart of packet judgment processing, such as Figure 6 Shown, including:
[0118] Step 601, determining first data in first network packet data based on location data of a first judgment condition in a first preset judgment group; wherein the first preset judgment group includes at least a plurality of judgment conditions, each judgment condition includes at least location data, a judgment length, comparison data, a comparison rule, and marking data, the plurality of judgment conditions includes the first judgment condition, the first network packet data is any network packet data among the plurality of network packet data, and the first preset judgment group is a preset judgment group corresponding to the first network packet data.
[0119] In the embodiment of the present disclosure, refer to 3, wherein the pkt_ptr position in the RAM indicates the content that needs to be judged for the packet, and its position in the network packet data (i.e., position data), in bytes. For example, the position of pkt_ptr = 0 Byte represents the first bit of data in the network packet data, and the position of pkt_ptr = 6 Byte represents the seventh bit of data in the network packet data; the length in the RAM indicates the length of the content that needs to be judged for the packet (i.e., judgment length), in bytes. For example, length = 6 Byte indicates that 6 bytes of data need to be judged continuously; R The value in AM indicates the value to be compared; the compare in RAM indicates the comparison to be performed (i.e., comparison rules, such as: 0 = greater than, 1 = less than, 2 = equal to, 3 = not equal to); and the end in RAM is used to identify the last condition of the judgment group (i.e., marking data, for example: 0 = this judgment condition is not the last, 1 = this judgment condition is the last). When the last judgment condition is completed, each group in the packet judgment module will output its own judgment result. If all judgment conditions within a group are met, the judgment result of the group is passed; otherwise, it is failed.
[0120] Specifically, the first data in the first network packet data is determined, that is, according to the pkt_ptr of the first judgment condition, and the data to be judged in the first network packet data, that is, the first data, is determined.
[0121] Step 602: Determine a data segment to be determined in the first network packet data according to the first data and the determination length of the first determination condition; wherein the plurality of data segments includes the data segment to be determined.
[0122] In the embodiment of the present disclosure, the data segment to be judged is determined based on the judgment length. For example, when the judgment length is length = 6Byte, it means that 6 data starting from the first data need to be judged (the 6 data include the first data). At this time, the 6 data starting from the first data are the data segment to be judged.
[0123] Step 603 : Compare the comparison data of the first judgment condition with the data segment to be judged according to the comparison rule of the first judgment condition to obtain a first result corresponding to the first judgment condition.
[0124] In the embodiment of the present disclosure, the comparison data is data used for comparison. For example, the comparison rule of the first judgment condition is equal to, and the comparison data is 01 02 03 04 05 06. At this time, when the data segment to be judged is also 01 02 03 04 05 06, the first result is passed judgment. When there is a difference between the data segment to be judged and 01 02 03 04 05 06, the first result is failed judgment.
[0125] Step 604: perform packet judgment processing on the first network packet data one by one according to the multiple judgment conditions until the judgment is completed according to the identification data of the target judgment condition, and obtain the first judgment result, wherein the target judgment condition is any judgment condition among the multiple judgment conditions that is after the first judgment condition.
[0126] In the embodiment of the present disclosure, since each preset judgment group includes multiple judgment conditions, the first judgment result can be determined only after all the judgment conditions in the preset judgment group are judged.
[0127] The disclosed embodiment judges and processes network packet data through multiple judgment conditions set by user-defined settings and preset judgment groups. By filling in RAM and register, any network packet data can be flexibly filtered and decisions can be made on how to process the network packet data.
[0128] Furthermore, the process of determining the end of judgment based on the identification data of the target judgment condition and obtaining the first judgment result can be implemented in but not limited to the following manner: when determining the end of judgment based on the identification data of the target judgment condition, obtaining the initial judgment result corresponding to each of the judgment conditions; when all of the initial judgment results are passed, the first judgment result is passed; when there is any initial judgment result that fails to pass among all the initial judgment results, the first judgment result is failed.
[0129] The embodiment of the present disclosure determines the final first judgment result through the judgment results of multiple judgment conditions set by user-defined settings, which can accurately filter network packet data and improve the accuracy of network packet data judgment.
[0130] In one implementable manner of the embodiment of the present disclosure, as a refinement of the above-mentioned step 102, when performing data change processing, it can also be implemented in the following manner but not limited to: determine the network packet data corresponding to each of the preset change rules from the multiple network packet data according to the first preset corresponding information; wherein each of the preset change rules corresponds to one or more of the network packet data; determine the first judgment result of the network packet data corresponding to each of the preset change rules as the reference result corresponding to each of the preset change rules; if it is determined according to the reference result that the corresponding network packet data fails to pass the judgment, cancel the data change processing of the network packet data corresponding to the reference result; if it is determined according to the reference result that the corresponding network packet data passes the judgment, perform data change processing on the network packet data corresponding to the reference result according to the preset change rule corresponding to the reference result to obtain the multiple target packet data.
[0131] In the embodiment of the present disclosure, the preset change rule indicates which groups of packet judgment module results are to be referenced, and the first judgment result corresponding to the packet judgment module to be referenced is used as the reference result. At this time, only when the reference result passes the judgment, the network packet data corresponding to the reference result will be processed for data change.
[0132] By determining the reference result and determining whether data change is required based on the reference result, the network packet data can be accurately changed, thereby improving the accuracy of network packet processing.
[0133] Furthermore, in an implementable manner of the embodiment of the present disclosure, when data change processing is performed on the network packet data corresponding to the reference result to obtain the multiple target packet data, it can also be implemented in but not limited to the following manner: when it is determined according to the reference result that the corresponding network packet data passes the judgment, data change processing is performed on the network packet data corresponding to the reference result according to the preset change rule corresponding to the reference result to obtain the multiple target packet data, which includes: determining a change action in the preset change rule; wherein the change action at least includes deletion, replacement, addition and no action; when it is determined that the change action is deletion, deleting the data segment corresponding to the preset change rule in the network packet data corresponding to the reference result; when it is determined that the change action is addition / replacement, determining the addition / replacement data in the preset change rule, and adding / replacing the data segment corresponding to the preset change rule in the network packet data corresponding to the reference result according to the addition / replacement data; when it is determined that the change action is no action, not performing data change processing on the network packet data corresponding to the reference result.
[0134] In the disclosed embodiment, accurate data change processing can be performed on network packet data according to the change action in the preset change rule. In the network packet data, the data that needs to be changed is the data segment corresponding to the preset change rule. For example, the data segment corresponding to the preset change rule is the destination MAC address (DA) data segment, and the change action of the preset change rule is replacement. In the network packet data, the original destination MAC address is replaced with the replacement data in the preset change rule to obtain the target network packet data.
[0135] By replacing the data of network packet data, we can adapt to different network environments, ensure security, optimize transmission efficiency, and improve service availability to ensure the correct transmission, security, efficiency and reliability of network packet data.
[0136] In one implementable manner of the embodiment of the present disclosure, when transmitting target packet data, it can also be implemented in but not limited to the following manner: determine the first judgment result corresponding to each packet receiving end according to the receiving end information; wherein, each packet receiving end corresponds to one or more first judgment results; when it is determined according to the first judgment result that the corresponding network packet data fails to pass the judgment, cancel the data transmission of the packet receiving end corresponding to the first judgment result; when it is determined according to the first judgment result that the corresponding network packet data passes the judgment, transmit the target packet data corresponding to the first judgment result to the packet receiving end corresponding to the first judgment result.
[0137] In the embodiment of the present disclosure, when the first judgment result is a passing judgment, the target packet data can be transmitted to the corresponding data receiving end, and the data receiving end includes but is not limited to: a network port, a host computer, etc.
[0138] By transmitting the target packet data to the corresponding data receiving end according to the judgment result, the target data packet can be determined according to the first judgment result during the processing of the network packet, ensuring that only the data that passes the judgment can be transmitted to the destination, thereby maintaining the efficiency and security of network communication.
[0139] In one implementable manner of the embodiment of the present disclosure, in order to smoothly complete the processing of network packets, the following method may also be adopted but is not limited to: performing judgment group setting processing through a preset host computer to obtain a plurality of the preset judgment groups; wherein, performing judgment group setting processing through a preset host computer to obtain a plurality of the preset judgment groups includes: performing judgment condition setting processing through the preset host computer to obtain a plurality of the judgment conditions; wherein, performing judgment condition setting processing through the preset host computer at least includes setting position data, setting judgment length, setting comparison data, setting comparison rules and setting tag data; classifying the plurality of judgment conditions according to the network packet data to obtain the plurality of preset judgment groups.
[0140] In the disclosed embodiment, by customizing the preset judgment group on the host computer, any network packet can be flexibly filtered and a decision can be made on how to process the packet.
[0141] In one implementable manner of the embodiment of the present disclosure, in order to smoothly complete the processing of network packets, the following method may also be adopted but is not limited to: performing preset change rule setting processing through a preset host computer to obtain the preset change rule; wherein, performing preset change rule setting processing through a preset host computer to obtain the preset change rule includes: setting the network packet data corresponding to each of the preset change rules respectively through the preset host computer to obtain the first preset corresponding information; performing change action setting for each of the preset change rules respectively through the preset host computer to obtain the change action; performing add / replace data setting for each of the preset change rules respectively through the preset host computer to obtain the add / replace data; performing data merging processing according to the first preset corresponding information, the change action and the add / replace data to obtain the preset change rule.
[0142] In the disclosed embodiment, by customizing the preset change rules set by the host computer, any network packet can be flexibly changed and decisions can be made on how to process the packet.
[0143] Furthermore, in order to facilitate understanding of the implementation process of the embodiment of the present disclosure, the embodiment of the present disclosure provides an example for illustration: Figure 7 As shown, Figure 7A schematic diagram of network packet data provided by an embodiment of the present disclosure, wherein the network packet data is a TCP message, and the message is used to illustrate the starting position and data length of several important data items. In the TCP message: Destination MAC Address (C8:09:a8:c9:7b:a6): located at Byte 0, with a length of 6 bytes; Source MAC Address (00:f8:2c:e8:12:5c): located at Byte 6, with a length of 6 bytes; Type (0x0800, IPv4): located at Byte 12, with a length of 2 bytes; Protocol (0x6, TCP): located at Byte 23, with a length of 1 byte; Source IP Address (0xac.0x10.0x7a.0x52): located at Byte 26, with a length of 4 bytes; Destination IP Address (0xac.0x10.0xa2.0x36): located at Byte 30, with a length of 4 bytes; Source Port (0x9967): located at Byte 34, with a length of 2 bytes; Destination Port (0x04d2): located at Byte 36, with a length of 2 bytes.
[0144] The requirements for processing network packet data are as follows: 1. For packets from IP 192.168.1.10, only its TCP packets are received and transmitted to the host computer, and other packets are directly discarded; 2. For packets from IP 192.168.1.x, its UDP packets are forwarded to MAC_ADR = 11:22:33:44:55:66, IP_ADR = 192.168.11.123.
[0145] At this point, the process of the network packet processing method described in this disclosure is as follows:
[0146] 1. The host computer fills in the RAM content of the packet judgment module (i.e. fills in the judgment conditions), such as Figure 8 As shown, Figure 8 An example diagram of a packet determination module provided by an embodiment of the present disclosure, wherein Group 1: compares Protocol (starting position pkt_ptr=23) to TCP (6), and source IP Address (starting position pkt_ptr=26) to 192.168.1.10; Group 2: compares Protocol (starting position pkt_ptr=23) to UDP (17), and source IP Address (starting position pkt_ptr=26) to 192.168.1.x;
[0147] 2. The host computer fills in the register of the packet change module (that is, fills in the preset change rules), such as Figure 9 As shown, Figure 9 This is an example diagram of a packet modification module provided by an embodiment of the present disclosure, in which the Destination MAC is changed to 11:22:33:44:55:66 and the Destination IP is changed to 192.168.11.123;
[0148] 3. The host computer fills in the register of the packet path switching module (i.e. fills in the receiving end information), such as Figure 10 As shown, Figure 10 This is an example diagram of a packet path switching module provided by an embodiment of the present disclosure, wherein, if the result of judgment group 1 = 1 (PASS), the target packet data is transmitted to the host computer via PCIe; if the result of judgment group 2 = 1 (PASS), the target packet data is transmitted to the network port.
[0149] 4. Then start receiving the input of network packet data (i.e., obtain multiple network packet data). When the first byte (first data) of the network packet data is received, reset the result of all groups to 1 (PASS);
[0150] 5. If the network packet data received at this time is a UDP packet from IP 192.168.1.22, the UDP packet passes through the packet judgment module and then directly enters the packet modification module. First, after the 23rd byte of the UDP packet enters, if the comparison value of Group 1 is not 6 (UDP = 17), the result of Group 1 is set to 0 (FAIL). At the same time, if the comparison value of Group 2 is equal, the result of Group 2 remains unchanged (PASS).
[0151] 6. When the 26th, 27th, and 28th bytes of the UDP packet enter, if the values of Group 1 and Group 2 are the same, both results remain unchanged.
[0152] 7. When group 2 reaches 28 bytes, the RAM end displays 1, indicating the last judgment condition of the comparison. At this time, the result 2 (1, PASS) is output to the packet change module and the packet path switching module;
[0153] 8. When group 1 reaches 29 bytes, the RAM end display is 1, indicating that the last judgment condition has been compared. At this time, the result 1 (0, FAIL) is output to the packet change module and the packet path switching module;
[0154] 9. After receiving the results of result1 and result2, the UDP packet is output by the packet modification module to the packet routing module. During this output process, the data is modified according to the register in the packet modification module. The DA en_mask is b10, indicating that only the result of result2 is referenced. At this time, the result of result2 is 1. According to the DA action (1 = replace), the DA is replaced with 11:22:33:44:55:66. The destination IP is also replaced with the content value according to the register, 192.168.11.123.
[0155] 10. SA's en_mask is b00, indicating that the results of result1 and result2 are not referenced. Therefore, no changes are made to SA's data, and other data are also unchanged according to the register.
[0156] 11. The UDP packet then enters the packet routing module. The network port's en_mask value is b10, indicating that the packet will be output to the network port only if result2 is true. In this example, result2 = 1, so the packet will be output to the network port.
[0157] 12. The host computer's en_mask value is b01, which means the packet will be transmitted to the host computer only when result1 is true. In this example, result1 = 0, so this packet will not be transmitted to the host computer.
[0158] 13. Finally, in this example, the UDP packet from the IP address 192.168.1.22 will be sent through the network port to the device with MAC_ADR = 11:22:33:44:55:66 and IP_ADR = 192.168.11.123.
[0159] In summary, the embodiments of the present disclosure can achieve the following effects:
[0160] 1. The disclosed embodiments utilize pre-defined judgment groups, pre-defined change rules, and receiver information to process network packet data in real time. This eliminates the need to cache the entire network packet data before processing it. This allows for timely judgment and processing of network packet data, reduces latency, and avoids the need for large amounts of cache space. Furthermore, multiple network packet data can be processed simultaneously, avoiding congestion and increasing packet data processing speed.
[0161] 2. The disclosed embodiment allows users to flexibly filter any network packets and decide how to process the packets by filling in RAM and register.
[0162] 3. The embodiment of the present disclosure can process packets only through RAM and registers. There is no need to place a processor inside the hardware to run the instruction set, nor is there a need for additional memory to store the instruction set.
[0163] 4. The embodiment of the present disclosure does not need to cache the entire packet before processing the packet content. According to the pipeline concept, the packet can be judged and processed in a timely manner, thereby reducing latency and avoiding the need for a large amount of cache space.
[0164] 5. The disclosed embodiment utilizes hardware parallel processing capabilities to process multiple packets simultaneously, thereby avoiding congestion and speeding up packet processing.
[0165] Corresponding to the aforementioned network packet processing method, the present invention further provides a network packet processing device. Since the device embodiment of the present invention corresponds to the aforementioned method embodiment, details not disclosed in the device embodiment can be referred to the aforementioned method embodiment and will not be further described in the present invention.
[0166] Figure 11 This is a schematic diagram of the structure of a network packet processing device provided by an embodiment of the present disclosure, wherein the device is applied to a server, such as Figure 11 Shown, including:
[0167] The judgment unit 1101 is configured to perform packet judgment processing on the obtained plurality of network packet data through the corresponding preset judgment groups to obtain a first judgment result corresponding to each of the plurality of network packet data; wherein the first judgment result is used to at least determine whether the corresponding network packet data passes the judgment;
[0168] a changing unit 1102 configured to perform data change processing on the plurality of network packet data according to the first judgment result and a preset change rule corresponding to each data segment, to obtain a plurality of target packet data; wherein each network packet data includes a plurality of the data segments;
[0169] The transmission unit 1103 is configured to transmit the target packet data to a corresponding packet receiving end according to the first determination result and receiving end information, wherein the receiving end information is at least used to determine the packet receiving end corresponding to the target packet data.
[0170] The present disclosure provides a network packet processing device that processes multiple acquired network packet data using corresponding preset judgment groups to obtain first judgment results corresponding to each of the multiple network packet data. The first judgment results are used to determine whether the corresponding network packet data passes the judgment. The device then performs data modification processing on the multiple network packet data based on the first judgment results and preset modification rules corresponding to each data segment to obtain multiple target packet data. Each network packet data includes multiple data segments. The device then transmits the target packet data to a corresponding packet receiving end based on the first judgment results and receiving end information. The receiving end information is used to determine the packet receiving end corresponding to the target packet data. Compared to related art, the present disclosure utilizes pre-set preset judgment groups, preset modification rules, and receiving end information to process network packet data in real time. This eliminates the need to cache the entire network packet data before processing the packet data. This allows for timely judgment and processing of network packet data, reduces latency, and avoids the need for large amounts of cache space. Furthermore, the device can process multiple network packet data simultaneously, avoiding congestion and increasing packet data processing speed.
[0171] Furthermore, in a possible implementation of the embodiment of the present disclosure, as Figure 12 As shown, the judging unit 1101 includes:
[0172] Determining module 11011, configured to determine first data in first network packet data based on location data of a first judgment condition in a first preset judgment group; wherein the first preset judgment group includes at least a plurality of judgment conditions, each judgment condition including at least location data, a judgment length, comparison data, a comparison rule, and marking data; the plurality of judgment conditions includes the first judgment condition; the first network packet data is any one of the plurality of network packet data; and the first preset judgment group is a preset judgment group corresponding to the first network packet data;
[0173] The determining module 11011 is further configured to determine a data segment to be determined in the first network packet data according to the first data and the determination length of the first determination condition; wherein the plurality of data segments includes the data segment to be determined;
[0174] a comparison module 11012, configured to compare the comparison data of the first judgment condition with the data segment to be judged according to the comparison rule of the first judgment condition, to obtain a first result corresponding to the first judgment condition;
[0175] The judgment module 11013 is used to perform packet judgment processing on the first network packet data one by one according to the multiple judgment conditions until the judgment is completed according to the identification data of the target judgment condition, and the first judgment result is obtained, wherein the target judgment condition is any judgment condition among the multiple judgment conditions that is after the first judgment condition.
[0176] Furthermore, in a possible implementation of the embodiment of the present disclosure, as Figure 12 As shown, the changing unit 1102 includes:
[0177] The determining module 11021 is configured to determine, from the plurality of network packet data, network packet data corresponding to each of the preset change rules according to the first preset corresponding information; wherein each of the preset change rules corresponds to one or more of the network packet data;
[0178] The determining module 11021 is further configured to determine the first judgment result of the network packet data corresponding to each of the preset change rules as a reference result corresponding to each of the preset change rules;
[0179] a cancelling module 11022, configured to cancel data modification processing on the network packet data corresponding to the reference result if it is determined according to the reference result that the corresponding network packet data fails to pass the judgment;
[0180] The change module 11023 is used to perform data change processing on the network packet data corresponding to the reference result according to the preset change rule corresponding to the reference result when it is determined that the corresponding network packet data passes the judgment according to the reference result, so as to obtain the multiple target packet data.
[0181] Furthermore, in a possible implementation of the embodiment of the present disclosure, the changing module 11023 is further configured to:
[0182] When it is determined that the corresponding network packet data passes the judgment according to the reference result, data modification processing is performed on the network packet data corresponding to the reference result according to the preset modification rule corresponding to the reference result, and the plurality of target packet data obtained include:
[0183] Determining a change action in the preset change rule; wherein the change action includes at least deletion, replacement, addition, and no action;
[0184] When it is determined that the change action is deletion, deleting the data segment corresponding to the preset change rule in the network packet data corresponding to the reference result;
[0185] When the change action is determined to be add / replace, determining add / replace data in the preset change rule, and performing add / replace processing on the data segment corresponding to the preset change rule in the network packet data corresponding to the reference result according to the add / replace data;
[0186] When it is determined that the change action is no action, no data change processing is performed on the network packet data corresponding to the reference result.
[0187] Furthermore, in a possible implementation of the embodiment of the present disclosure, as Figure 12 As shown, the transmission unit 1103 includes:
[0188] The determining module 11031 is configured to determine the first judgment result corresponding to each of the packet receiving ends according to the receiving end information; wherein each of the packet receiving ends corresponds to one or more of the first judgment results;
[0189] a cancelling module 11032, configured to cancel the data transmission of the packet receiving end corresponding to the first judgment result if it is determined that the corresponding network packet data fails the judgment according to the first judgment result;
[0190] The transmission module 11033 is configured to transmit the target packet data corresponding to the first judgment result to the packet receiving end corresponding to the first judgment result when it is determined that the corresponding network packet data passes the judgment according to the first judgment result.
[0191] Furthermore, in a possible implementation of the embodiment of the present disclosure, as Figure 12 As shown, the device also includes:
[0192] The setting unit 1104 is configured to perform a judgment group setting process through a preset host computer to obtain a plurality of preset judgment groups;
[0193] The setting unit 1104 is further configured to:
[0194] The judgment condition setting process is performed by the preset host computer to obtain a plurality of the judgment conditions; wherein the judgment condition setting process performed by the preset host computer at least includes setting position data, setting judgment length, setting comparison data, setting comparison rules, and setting mark data;
[0195] The plurality of judgment conditions are classified and processed according to the network packet data to obtain the plurality of preset judgment groups.
[0196] Furthermore, in a possible implementation of the embodiment of the present disclosure, the setting unit 1104 is further configured to:
[0197] Performing preset change rule setting processing by a preset host computer to obtain the preset change rule;
[0198] The setting unit 1104 is further configured to:
[0199] The preset host computer sets the network packet data corresponding to each of the preset change rules respectively to obtain the first preset corresponding information;
[0200] Setting a change action for each of the preset change rules respectively by the preset host computer to obtain the change action;
[0201] The preset host computer performs adding / replacing data setting for each of the preset change rules to obtain the adding / replacing data;
[0202] Data merging processing is performed according to the first preset corresponding information, the change action, and the added / replaced data to obtain the preset change rule.
[0203] It should be noted that the above explanation of the method embodiment is also applicable to the device of the embodiment of the present disclosure, and the principles are the same, which is no longer limited in the embodiment of the present disclosure.
[0204] According to an embodiment of the present disclosure, the present disclosure further provides an electronic device and a readable storage medium.
[0205] Figure 13 A schematic block diagram of an example electronic device 1300 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are provided as examples only and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0206] like Figure 13As shown, the device 1300 includes a computing unit 1301, which can perform various appropriate actions and processes according to a computer program stored in a ROM (Read-Only Memory) 1302 or a computer program loaded from a storage unit 1308 into a RAM (Random Access Memory) 1303. Various programs and data required for the operation of the device 1300 can also be stored in the RAM 1303. The computing unit 1301, the ROM 1302, and the RAM 1303 are connected to each other via a bus 1304. An I / O (Input / Output) interface 1305 is also connected to the bus 1304.
[0207] Various components in device 1300 are connected to I / O interface 1305, including an input unit 1306, such as a keyboard and mouse; an output unit 1307, such as various types of displays and speakers; a storage unit 1308, such as a magnetic disk and optical disk; and a communication unit 1309, such as a network card, a modem, a wireless communication transceiver, etc. Communication unit 1309 allows device 1300 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0208] Computing unit 1301 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of computing unit 1301 include, but are not limited to, CPUs (Central Processing Units), GPUs (Graphic Processing Units), various specialized AI (Artificial Intelligence) computing chips, various computing units that run machine learning model algorithms, DSPs (Digital Signal Processors), and any suitable processors, controllers, microcontrollers, etc. Computing unit 1301 performs the various methods and processes described above, such as the network packet processing method. For example, in some embodiments, the network packet processing method can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as storage unit 1308. In some embodiments, part or all of the computer program can be loaded and / or installed onto device 1300 via ROM 1302 and / or communication unit 1309. When the computer program is loaded into RAM 1303 and executed by computing unit 1301, one or more steps of the method described above can be performed. Alternatively, in other embodiments, the computing unit 1301 may be configured to execute the aforementioned network packet processing method in any other appropriate manner (eg, by means of firmware).
[0209] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, FPGAs (Field Programmable Gate Arrays), ASICs (Application-Specific Integrated Circuits), ASSPs (Application Specific Standard Products), SOCs (System on Chips), CPLDs (Complex Programmable Logic Devices), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0210] The program code for implementing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flow chart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0211] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or apparatus. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or apparatus, or any suitable combination of the foregoing. More specific examples of machine-readable storage media may include an electrical connection based on one or more wires, a portable computer disk, a hard disk, RAM, ROM, EPROM (Electrically Programmable Read-Only-Memory) or flash memory, optical fiber, CD-ROM (Compact Disc Read-Only Memory), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0212] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (Cathode-Ray Tube) or LCD (Liquid Crystal Display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0213] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: LAN (Local Area Network), WAN (Wide Area Network), the Internet, and blockchain networks.
[0214] A computer system may include a client and a server. The client and server are generally remote from each other and typically interact via a communication network. This client-server relationship is established by computer programs running on the respective computers, establishing a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host, a host product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosts and VPS services ("Virtual Private Servers" or simply "VPS"). The server may also be a server in a distributed system or a server integrated with blockchain.
[0215] It's important to note that artificial intelligence (AI) is the study of how computers can simulate certain human thought processes and intelligent behaviors (such as learning, reasoning, thinking, and planning). This encompasses both hardware and software technologies. AI hardware technologies generally include sensors, specialized AI chips, cloud computing, distributed storage, and big data processing. AI software technologies primarily encompass computer vision, speech recognition, natural language processing, machine learning / deep learning, big data processing, and knowledge graphs.
[0216] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved. This is not limited herein.
[0217] The above specific embodiments do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the scope of protection of this disclosure.
Claims
1. A method for processing a network packet, characterized in that: include: Perform packet judgment processing on the acquired multiple network packet data through the corresponding preset judgment groups to obtain the first judgment results corresponding to the multiple network packet data; wherein the first judgment results are at least used to determine whether the corresponding network packet data passes the judgment; According to the first judgment result and the preset change rule corresponding to each data segment, the plurality of network packet data are respectively subjected to data change processing to obtain a plurality of target packet data; wherein each network packet data includes a plurality of the data segments; The target packet data is transmitted to the corresponding packet receiving end according to the first judgment result and the receiving end information, wherein the receiving end information is at least used to determine the packet receiving end corresponding to the target packet data.
2. The method according to claim 1, characterized in that The obtained plurality of network packet data are subjected to packet determination processing through the respective corresponding preset determination groups to obtain the first determination results respectively corresponding to the plurality of network packet data, including: Determine the first data in the first network packet data according to the position data of the first judgment condition in the first preset judgment group; wherein the first preset judgment group includes at least a plurality of judgment conditions, each judgment condition includes at least position data, judgment length, comparison data, comparison rules and marking data, the plurality of judgment conditions include the first judgment condition, the first network packet data is any network packet data in the plurality of network packet data, and the first preset judgment group is a preset judgment group corresponding to the first network packet data; Determine the data segment to be determined in the first network packet data according to the first data and the determination length of the first determination condition; wherein the data segment to be determined is included in the plurality of data segments; Compare the comparison data of the first judgment condition with the data segment to be judged according to the comparison rule of the first judgment condition to obtain a first result corresponding to the first judgment condition; The first network packet data is subjected to packet judgment processing one by one according to the multiple judgment conditions, until the judgment is completed according to the identification data of the target judgment condition, and the first judgment result is obtained, wherein the target judgment condition is any judgment condition among the multiple judgment conditions that is after the first judgment condition.
3. The method according to claim 1, characterized in that: The data change processing is performed on the plurality of network packet data respectively according to the first judgment result and the preset change rule corresponding to each data segment to obtain a plurality of target packet data including: Determine the network packet data corresponding to each of the preset change rules from the plurality of network packet data according to the first preset corresponding information; wherein each of the preset change rules corresponds to one or more of the network packet data; Determine the first judgment result of the network packet data corresponding to each of the preset change rules as the reference result corresponding to each of the preset change rules; In the case where it is determined according to the reference result that the corresponding network packet data fails to pass the judgment, canceling the data change processing of the network packet data corresponding to the reference result; When it is determined that the corresponding network packet data passes the judgment according to the reference result, data change processing is performed on the network packet data corresponding to the reference result according to the preset change rule corresponding to the reference result to obtain the multiple target packet data.
4. The method according to claim 3, characterized in that: In the case where the corresponding network packet data is determined to pass the judgment according to the reference result, data change processing is performed on the network packet data corresponding to the reference result according to the preset change rule corresponding to the reference result, and the plurality of target packet data are obtained, including: Determine the change action in the preset change rule; wherein the change action at least includes deletion, replacement, addition and no action; When it is determined that the change action is deletion, in the network packet data corresponding to the reference result, the data segment corresponding to the preset change rule is deleted; In the case where it is determined that the change action is to add / replace, determining the add / replace data in the preset change rule, and performing an add / replace process on the data segment corresponding to the preset change rule in the network packet data corresponding to the reference result according to the add / replace data; When it is determined that the change action is no action, no data change processing is performed on the network packet data corresponding to the reference result.
5. The method according to claim 1, characterized in that The transmitting the target packet data to the corresponding packet receiving end according to the first judgment result and the receiving end information comprises: Determine the first judgment result corresponding to each of the packet receiving ends according to the receiving end information; wherein each of the packet receiving ends corresponds to one or more of the first judgment results; In the case where it is determined according to the first judgment result that the corresponding network packet data fails to pass the judgment, canceling the data transmission of the packet receiving end corresponding to the first judgment result; When it is determined that the corresponding network packet data passes the judgment according to the first judgment result, the target packet data corresponding to the first judgment result is transmitted to the packet receiving end corresponding to the first judgment result.
6. The method according to claim 2, characterized in that Before performing packet determination processing on the acquired plurality of network packet data through the respective corresponding preset determination groups to obtain the first determination results respectively corresponding to the plurality of network packet data, the method further includes: Performing judgment group setting processing by a preset host computer to obtain a plurality of preset judgment groups; The preset host computer performs the judgment group setting process to obtain a plurality of preset judgment groups, including: The judgment condition setting process is performed by the preset host computer to obtain a plurality of the judgment conditions; wherein the judgment condition setting process performed by the preset host computer at least includes setting position data, setting judgment length, setting comparison data, setting comparison rules and setting marking data; The plurality of judgment conditions are classified and processed according to the network packet data to obtain the plurality of preset judgment groups.
7. The method according to any one of claims 4, characterized in that Before performing packet determination processing on the acquired plurality of network packet data through the respective corresponding preset determination groups to obtain the first determination results respectively corresponding to the plurality of network packet data, the method further includes: Performing preset change rule setting processing by a preset host computer to obtain the preset change rule; The preset change rule setting process is performed by the preset host computer to obtain the preset change rule, which includes: The network packet data corresponding to each of the preset change rules is respectively set by the preset host computer to obtain the first preset corresponding information; Setting a change action for each of the preset change rules respectively through the preset host computer to obtain the change action; By using the preset host computer, each of the preset change rules is respectively set to add / replace data to obtain the added / replaced data; Data merging processing is performed according to the first preset corresponding information, the change action and the added / replaced data to obtain the preset change rule.
8. A network packet processing device, characterized in that: include: A judgment unit, used to perform packet judgment processing on the acquired multiple network packet data through the corresponding preset judgment groups, and obtain the first judgment results corresponding to the multiple network packet data; wherein the first judgment results are at least used to determine whether the corresponding network packet data passes the judgment; a change unit, configured to perform data change processing on the plurality of network packet data respectively according to the first judgment result and a preset change rule corresponding to each data segment, so as to obtain a plurality of target packet data; wherein each network packet data includes a plurality of the data segments; A transmission unit is used to transmit the target packet data to a corresponding packet receiving end according to the first judgment result and receiving end information, wherein the receiving end information is at least used to determine the packet receiving end corresponding to the target packet data.
9. An electronic device, characterized in that: include: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 7.
10. A non-transitory computer-readable storage medium storing computer instructions, characterized in that: The computer instructions are used to cause the computer to execute the method according to any one of claims 1-7.
Citation Information
Patent Citations
Network address translation device and packet processing method thereof
CN101616072A
Media file decapsulation method and device, media file decapsulation method and device, media and electronic equipment
CN117376329A
Packet recombination method and device, storage medium and electronic equipment
CN118353860A
Device, method and program for packet acquisition
JP2019193201A