Chassis device attack packet collection method, query method and computer device

By centrally storing and managing attack packets and logs in a chassis-based firewall, the problems of slow response speed and low efficiency caused by decentralized storage are solved, enabling fast querying and efficient analysis, and ensuring system reliability and user experience.

CN119996048BActive Publication Date: 2025-10-24BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510292342.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-10-24
Estimated Expiration
2045-03-12

AI Technical Summary

Technical Problem

Chassis-based firewalls are slow to respond and have low processing efficiency when dealing with large-scale network attacks. In existing technologies, the scattered storage of attack packets makes information retrieval time-consuming and laborious, affecting the efficiency of log information acquisition and display latency.

Method used

After detecting data plane attack information on the business board, the attack packets and attack logs are obtained, index relationships are configured, and the data is sent to the main control board and backup control board for centralized storage through the inter-board channel. A backup mechanism for the main and backup control boards is established to ensure data reliability and availability, and fast querying is achieved through index relationships.

Benefits of technology

It enables centralized management of attack packets and logs, improves data processing efficiency and query speed, ensures system reliability and availability, reduces information display delay, and supports security analysis and tracing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996048B_ABST
    Figure CN119996048B_ABST
Patent Text Reader

Abstract

The application discloses a machine frame type device attack packet collection method, a query method and a computer device. The collection method comprises the following steps: after detecting data plane attack information, attack packets and attack logs are acquired, an index association relationship between an attack packet name and a packet source slot is configured, and the index association relationship is stored in an index association table; the attack packets and the attack logs are respectively sent to an attack packet receiving main process and a log receiving main process of a main control board and an attack packet receiving backup process and a log receiving backup process of a backup control board through an interboard channel; the attack packets are respectively stored in a main control board packet data table and a backup control board packet data table, and the attack logs are respectively stored in a main control board log data table and a backup control board log data table. The method can realize centralized storage, quick query and summary when subsequent information is called, and ensures that the machine frame type firewall has fast response speed and high processing efficiency when processing large-scale network attacks.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of data communication, and particularly relates to a collection method and a query method of attack packets of a chassis device, and a computer device. BACKGROUND

[0002] As a high-performance network device, the core of the chassis firewall is composed of a control service board and a service board. The control board, as the management unit of the device, is usually configured as two main and standby boards to ensure high stability and reliability of the system. The control board is mainly responsible for system management, configuration maintenance and network service processing. The service board, as a service processing unit, focuses on network forwarding, security service processing and log data recording.

[0003] When detecting attack behaviors in network traffic, the chassis device can record attack logs and display these log information to users through a visual interface. In addition, the service board can detect and record attack packets and store them in a local database for subsequent query and analysis.

[0004] However, in actual application, the main control board needs to connect the databases of each service board for repeated query when collecting log information, which is time-consuming and affects the efficiency of log information acquisition. In addition, when attack information is stored in different service boards, the main control board needs to aggregate and display these information, which not only increases the complexity of packet aggregation, but also causes delay in information display, resulting in slow response and low processing efficiency of the chassis firewall when processing large-scale network attacks. SUMMARY

[0005] Therefore, the embodiments of the present disclosure provide a collection method and a query method of attack packets of a chassis device, and a computer device, which can solve the problem of dispersed storage of attack packets of the chassis device in the prior art, causing slow response and low processing efficiency of the chassis firewall when processing large-scale network attacks, and wasting time and effort when information query is needed.

[0006] In a first aspect, the embodiments of the present disclosure provide a collection method of attack packets of a chassis device, the chassis device comprising a main control board, a standby control board and a plurality of service boards, comprising:

[0007] In response to data plane attack information detected by the service board, obtaining attack packets and attack logs;

[0008] Based on the attack packets and the attack logs, configuring an index association relationship between the attack packet name and the packet source slot, and storing the index association relationship in an index association table;

[0009] The attack message and the attack log are sent to the attack message receiving master process and the log receiving master process of the main control board through the inter-board channel by the attack detection process;

[0010] The attack message and the attack log are sent to the attack message receiving standby process and the log receiving standby process of the standby control board through the inter-board channel by the attack detection process;

[0011] The attack message is stored in the main control board message data table and the standby control board message data table in response to the message receiving messages of the attack message receiving master process and the attack message receiving standby process;

[0012] The attack log is stored in the main control board log data table and the standby control board log data table in response to the log receiving messages of the log receiving master process and the log receiving standby process.

[0013] Optionally, the attack message and the attack log are obtained in response to the data plane attack information detected by the service board, including: attack information is monitored in real time by a data plane attack detection process of a service board of a chassis type security device, and the attack message and the attack log are generated in response to the attack information.

[0014] Optionally, the attack message is stored in the main control board message data table and the standby control board message data table in response to the message receiving messages of the attack message receiving master process and the attack message receiving standby process, including:

[0015] The attack message is stored in the first message cache area in response to the message receiving message of the attack message receiving master process, and the data in the first message cache area is stored in the main control board message data table by the attack message storage process of the main control board;

[0016] The attack message is stored in the second message cache area in response to the message receiving message of the attack message receiving standby process, and the data in the second message cache area is stored in the standby control board message data table by the attack message storage process of the standby control board.

[0017] Optionally, the attack log is stored in the main control board log data table and the standby control board log data table in response to the log receiving messages of the log receiving master process and the log receiving standby process, including:

[0018] The attack log is stored in the first log cache area in response to the log receiving message of the log receiving master process, and the data in the first log cache area is stored in the main control board log data table by the log storage process of the main control board;

[0019] In response to the log receiving message of the log receiving standby process, the attack log is stored into a second log buffer, and data in the second log buffer is stored into the attack log data table of the standby control board by the log storing process of the standby control board.

[0020] Optionally, when the data plane attack information is the set attack information, the set attack information is collected according to the maximum packet record quantity of the chassis device configuration.

[0021] In a second aspect, the application discloses a query method of attack packets of a chassis device, which is based on the collection method of attack packets of the chassis device and stores attack packets, and the query method comprises the following steps:

[0022] Receiving an attack packet data query requirement;

[0023] According to the attack packet data query requirement, a target attack packet name and a target packet source slot are obtained, and the target attack packet name and the target packet source slot are taken as a target index;

[0024] When the target index exists in the index association table, an actual attack log corresponding to the attack packet data query requirement is obtained from the main control board log data table;

[0025] According to the actual attack log, an actual attack packet corresponding to the actual attack log is obtained from the main control board packet data table, and the actual attack log and the actual attack packet are fed back to a client corresponding to the attack packet data query instruction.

[0026] In a third aspect, the application discloses a query method of attack packets of a chassis device, which is based on the collection method of attack packets of the chassis device and stores attack packets, and the query method comprises the following steps:

[0027] Receiving an attack packet data query instruction;

[0028] According to the attack packet data query requirement, a target attack packet name and a target packet source slot are obtained, and the target attack packet name and the target packet source slot are taken as a target index;

[0029] When the target index exists in the index association table, a first actual attack log corresponding to the attack packet data query requirement is obtained from the main control board log data table;

[0030] According to the first actual attack log, a first actual attack packet corresponding to the first actual attack log is obtained from the main control board packet data table;

[0031] The first actual attack packet and the first actual attack log are taken as first information.

[0032] obtain a second actual attack log corresponding to the attack packet data query requirement from the backup control board log data table;

[0033] obtain a second actual attack packet corresponding to the second actual attack log from the backup control board packet data table;

[0034] record the second actual attack packet and the second actual attack log as second information;

[0035] when the first information and the second information are consistent, generate target attack packet display information, and feed back the target attack packet display information to a client corresponding to the attack packet data query instruction.

[0036] In a fourth aspect, the embodiments of the present disclosure further provide a computer device, which adopts the following technical scheme:

[0037] The computer device comprises:

[0038] at least one processor; and

[0039] a memory connected with the at least one processor in communication; wherein

[0040] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the collecting method of the attack packet of the chassis device or the querying method of the attack packet of the chassis device.

[0041] In a fifth aspect, the embodiments of the present disclosure further provide a computer readable storage medium, which stores computer instructions for causing a computer to execute the collecting method of the attack packet of the chassis device or the querying method of the attack packet of the chassis device.

[0042] In a sixth aspect, the embodiments of the present disclosure further provide a computer program product, which comprises computer program / instructions, and the computer program / instructions are executed by a processor to implement the steps of the method according to any one of the preceding aspects.

[0043] The application discloses a method for collecting attack packets of a chassis type device, and the method comprises the following steps: in response to data plane attack information detected by a service board, obtaining attack packets and attack logs; based on the packet information and the attack logs, configuring an index association relationship between an attack packet name and a packet source slot; sending the attack packets and the attack logs to an attack packet receiving main process and a log receiving main process of a main control board through an inter-board channel by an attack detection process; sending the attack packets and the attack logs to an attack packet receiving backup process and a log receiving backup process of a backup control board through the inter-board channel by the attack detection process; in response to a packet receiving message of the attack packet receiving main process and the attack packet receiving backup process, storing the attack packets into a main control board packet data table and a backup control board packet data table respectively; and in response to a log receiving message of the log receiving main process and the log receiving backup process, storing the attack logs into a main control board log data table and a backup control board log data table respectively. By the method, the attack packets and the attack logs scattered on various service boards are collected to the main control board and the backup control board for management, which facilitates unified analysis and processing by a security management personnel; by the backup mechanism of the main control board and the backup control board, the reliability and availability of the attack packets and the attack logs are ensured, even if the main control board fails, the backup control board can continue to process data, and the risk of data loss is avoided; by establishing the index association relationship between the attack packet name and the packet source slot and storing the data in the data table, data analysis and mining by a security expert are facilitated, so that the attack means and intention of an attacker are better understood, and corresponding preventive measures are taken; detailed attack logs record the time, type and related information of attack occurrence, and provide strong support for subsequent security audit and tracing.

[0044] The above description is only a summary of the technical solutions of the present disclosure, in order to more clearly understand the technical means of the present disclosure, the content of the specification can be implemented, and in order to make the above and other purposes, characteristics and advantages of the present disclosure more obvious and easy to understand, the following preferred embodiments are described in detail below, and the accompanying drawings are described as follows. BRIEF DESCRIPTION OF DRAWINGS

[0045] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following will briefly introduce the drawings needed to be used in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and those skilled in the art can obtain other drawings according to these drawings without creating any creative labor.

[0046] Figure 1 The flowchart of the method for collecting attack packets of a chassis type device provided by the embodiments of the present disclosure.

[0047] Figure 2A flowchart of a first embodiment of a method for querying attack packets of a chassis device provided by an embodiment of the present disclosure.

[0048] Figure 3 A flowchart of a second embodiment of a method for querying attack packets of a chassis device provided by an embodiment of the present disclosure.

[0049] Figure 4 A structural diagram of a computer device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION

[0050] The embodiments of the present disclosure will be described in detail below with reference to the drawings.

[0051] It should be apparent that the following describes embodiments of this disclosure by way of specific examples, and that one skilled in the art can readily derive other advantages and effects from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of this disclosure, rather than all the embodiments. This disclosure can also be implemented or applied by other different specific embodiments, and various modifications or changes can be made to the details in this specification without departing from the spirit of this disclosure. It should be noted that the following embodiments and features in the embodiments can be combined with each other without conflict. Based on the embodiments in this disclosure, all other embodiments obtained by one of ordinary skill in the art without creative labor fall within the scope of protection of this disclosure.

[0052] It should be noted that the various aspects of the embodiments described below are within the scope of the appended claims. It should be apparent that the aspects described herein can be embodied in a wide variety of forms and that any specific structure and / or function described herein is merely illustrative. Based on the teachings provided herein one skilled in the art will appreciate that one aspect can be implemented independently of any other aspect and that an aspect can be implemented both in isolation and in combination with any other aspect or aspects. For example, an apparatus can be implemented using any number of the aspects described herein. Additionally, an apparatus can be implemented using other structure and / or functionality not expressly described herein. It should also be understood that one aspect described herein can be implemented using software running on a processor that functions to carry out the various processes described herein, and that as such, is non-transitory. It should be noted that the aspects described herein are not limited to any particular software format.

[0053] It should also be noted that the drawings provided herein are merely schematic and that the actual implementation of the present disclosure can differ from the schematic illustrations of the drawings. It should be understood that the presented drawings are not to scale and that a size of certain elements can have been exaggerated for the purpose of clarity. Further, it should be understood that the layout of the components can be more complex than as shown in the drawings.

[0054] Also in the following description, specific details are provided to thoroughly understand examples. However, one of ordinary skill in the art will understand that the described aspects can be practiced without these specific details.

[0055] Referring to Figure 1 The application discloses a method for collecting attack packets of a chassis device, the chassis device comprising a main control board, a backup control board and a plurality of service boards, comprising:

[0056] S100, in response to data plane attack information detected by the service board, obtaining attack packets and attack logs.

[0057] Specifically, the attack information is monitored in real time by a data plane attack detection process of the service board of the chassis security device, and attack packets and attack logs are generated in response to the attack information.

[0058] In this embodiment, the attack packets comprise attack packet information, an attack packet name and a packet source slot, and the attack logs comprise the attack packet name and the packet source slot.

[0059] Specifically, the data traffic flowing through the service board can be monitored in real time by an intrusion detection system (IDS) or an intrusion prevention system (IPS) deployed on the service board. For example, when an abnormally high frequency of TCP connection requests is detected, or a malicious port scanning behavior is found, it is determined that data plane attack information is detected, or information with attack characteristics is detected.

[0060] Once the attack information is detected, the service board will immediately capture the relevant packets being transmitted. Specifically, the attack packets can be captured from the network interface by a network packet capture tool, such as the tcpdump tool under the Linux system, and stored in a temporary buffer of the service board. At the same time when the attack is detected, the service board will record detailed attack logs, and the log content comprises the time of attack occurrence, the type of attack (such as DDoS attack, SQL injection attack, etc.), the source IP address and the destination IP address of the attack, and other information. These logs will be stored in a log file of the service board.

[0061] Taking a port scanning attack as an example, when monitoring network traffic, the attack detection process finds that a certain IP address frequently attempts to connect multiple ports in a short period of time, which meets the characteristics of port scanning. At this time, the system will capture the packets sent by the IP address as attack packets, and record the time of attack occurrence, the source IP address and other information as attack logs.

[0062] In this step, timely capturing attack packets and logs can provide original data for subsequent analysis and processing; attack packets can help security experts analyze the attack means and intentions of attackers, while attack logs can record the time and related information of attack occurrence, facilitating subsequent tracing and auditing.

[0063] S200, based on the attack packets and the attack logs, configuring an index association relationship between the attack packet name and the packet source slot, and storing the index association relationship into an index association table.

[0064] The packet source slot refers to the board card number of the service board.

[0065] In this embodiment, the obtained attack packet name can be directly associated with the packet source slot to establish the index association relationship.

[0066] In another embodiment, key information such as source IP address, destination IP address, protocol type can also be extracted from the attack packet, and at the same time, the timestamp of attack occurrence can be obtained from the attack log. According to the extracted information, a unique name is generated for the attack packet. For example, the naming method of "source IP-destination IP-timestamp" can be used, such as "192.168.1.1-10.0.0.1-20250306100000".

[0067] The attack packet name is associated with the slot number of the packet source and stored in the index table of the service board. For example, if the attack packet comes from slot 3 of the service board, the corresponding relationship between "192.168.1.1-10.0.0.1-20250306100000" and "slot 3" is recorded in the index table.

[0068] Through the index association relationship, the source slot of the attack packet can be quickly located, improving the efficiency of data processing; at the same time, the unique attack packet name also avoids the problem of packet naming conflict.

[0069] S300, through the attack detection process, the attack packets and the attack logs are respectively sent to the attack packet receiving master process and the log receiving master process of the main control board through the inter-board channel.

[0070] S400, through the attack detection process, the attack packets and the attack logs are respectively sent to the attack packet receiving backup process and the log receiving backup process of the backup control board through the inter-board channel.

[0071] Specifically, for inter-board channel establishment: the service board, the main control board and the backup control board in the chassis device establish an inter-board channel through a high-speed inter-board communication interface (such as PCIe, Ethernet, etc.); when the device starts, the inter-board channel is initialized and configured to ensure stable transmission of data between different board cards.

[0072] For data sending: the attack detection process on the service board encapsulates the attack packets and attack logs into a specific packet format and sends them to the main control board and the backup control board through the inter-board channel. For example, the UDP protocol can be used for data transmission to improve transmission efficiency. The attack packet receiving master process and the log receiving master process on the main control board and the attack packet receiving backup process and the log receiving backup process on the backup control board listen to the corresponding ports to receive data from the service board.

[0073] Through this step, centralized management of attack packets and attack logs can be achieved; data is uniformly sent to the main control board and the backup control board, which facilitates subsequent data analysis and processing; at the same time, through the backup mechanism of the backup control board, the reliability and availability of data are improved, and even if the main control board fails, the backup control board can continue to process attack packets and logs.

[0074] S500, in response to the message receiving of the attack packet receiving master process and the attack packet receiving backup process, the attack packets are respectively stored into the main control board packet data table and the backup control board packet data table.

[0075] Specifically, in response to the message receiving of the attack packet receiving master process, the attack packets are stored into the first packet buffer area, and the data in the first packet buffer area is stored into the main control board packet data table by the main control board attack packet storage process one by one.

[0076] In response to the message receiving of the attack packet receiving backup process, the attack packets are stored into the second packet buffer area, and the data in the second packet buffer area is stored into the backup control board packet data table by the backup control board attack packet storage process one by one.

[0077] S600, in response to the log receiving of the log receiving master process and the log receiving backup process, the attack logs are respectively stored into the main control board log data table and the backup control board log data table.

[0078] Specifically, in response to the log receiving of the log receiving master process, the attack logs are stored into the first log buffer area, and the data in the first log buffer area is stored into the main control board log data table by the main control board log storage process one by one.

[0079] In response to the log receiving of the log receiving backup process, the attack logs are stored into the second log buffer area, and the data in the second log buffer area is stored into the backup control board log data table by the backup control board log storage process one by one.

[0080] In this embodiment, the attack message receiving main process and the attack message receiving backup process on the main control board and the backup control board can send a message receiving message to the service board after receiving the attack message, and the service board confirms that the attack message has been successfully sent after receiving the message; the main control board and the backup control board store the received attack message in the respective message data table (i.e. the main control board message data table and the backup control board message data table), and further can use a database (such as MySQL, SQLite, etc.) to store the attack message for subsequent query and analysis; when storing, the attack message name and related index information are stored together to facilitate subsequent association query.

[0081] The log receiving main process and the log receiving backup process on the main control board and the backup control board can send a log receiving message to the service board after receiving the attack log, and the service board confirms that the attack log has been successfully sent after receiving the message; the main control board and the backup control board store the received attack log in the respective log data table (i.e. the main control board log data table and the backup control board log data table), and also can use a database to store the attack log, and the storage content includes the detailed information of the attack log and the related index information.

[0082] Through the above steps, the persistent storage of the attack message and the attack log can be ensured; the data is stored in the data table to facilitate subsequent data analysis, statistics and query; at the same time, the dual storage mechanism of the main control board and the backup control board further improves the reliability and security of the data.

[0083] The application discloses a machine frame device attack packet collection method, which comprises the following steps: in response to data plane attack information detected by a service board, attack packets and attack logs are acquired; based on the packet information and the attack logs, an index association relationship between an attack packet name and a packet source slot is configured; through an attack detection process, the attack packets and the attack logs are respectively sent to an attack packet receiving main process and a log receiving main process of a main control board through an inter-board channel; through the attack detection process, the attack packets and the attack logs are respectively sent to an attack packet receiving backup process and a log receiving backup process of a backup control board through the inter-board channel; in response to a packet receiving message of the attack packet receiving main process and the attack packet receiving backup process, the attack packets are respectively stored into a main control board packet data table and a backup control board packet data table; and in response to a log receiving message of the log receiving main process and the log receiving backup process, the attack logs are respectively stored into a main control board log data table and a backup control board log data table. Through the method, the attack packets and the attack logs scattered on various service boards are collected and managed on the main control board and the backup control board, so that unified analysis and processing of the security management personnel are facilitated; through the backup mechanism of the main control board and the backup control board, the reliability and availability of the attack packets and the attack logs are ensured, even if the main control board fails, the backup control board can continue to process data, and the risk of data loss is avoided; through the establishment of the index association relationship between the attack packet name and the packet source slot and the storage of the data in the data table, data analysis and mining of the security experts are facilitated, so that the attack means and intention of the attacker are better understood, and corresponding preventive measures are taken; and detailed attack logs record the time, type and related information of the attack, thereby providing strong support for subsequent security audit and tracing.

[0084] In the embodiment, the main control board log data table and the backup control board log data table are externally displayed, and the main control board packet data table and the backup control board packet data table are not externally displayed.

[0085] The machine frame device attack packet collection method disclosed by the application further comprises the following steps: before the attack packets and the attack logs are acquired, it is judged whether the data plane attack information has been marked, if not, the data plane attack information is marked and recorded as attack information that has been set, that is, attack information in a set state; and if yes, the data plane attack information is not marked, and the attack packets and the attack logs are acquired.

[0086] If yes, the data plane attack information is not marked, and the attack packets and the attack logs are acquired.

[0087] The collecting method of the attack packet of the chassis-type device disclosed in the application further comprises: when the data plane attack information is in the set state, collecting the set attack information according to the maximum packet record quantity configured by the chassis-type device. Specifically, when the same data plane attack information (referring to the same packet name and packet source slot) in the set state appears twice continuously, only the set attack information is collected for the subsequent information collection, and other attack information is no longer collected.

[0088] Specifically, the chassis-type device can be pre-configured with a maximum packet record quantity, which is an upper limit value. When collecting the attack information in the set state, the system collects the relevant attack information packets according to the pre-configured maximum quantity. For example, if the maximum packet record quantity is set to 5, the system will only collect at most 5 attack information in the set state.

[0089] When the system monitors that the same set attack information appears twice continuously, a special collection mode is entered; in the subsequent information collection process, the system focuses on collecting the set attack information that has appeared twice continuously, which means that the system continues to pay attention to and collect the packets related to the specific attack information, and further analyzes the characteristics and rules of the attack. Once the above-mentioned special collection mode is entered, the system will temporarily ignore other types of attack information, that is, for other attack information that is not the set attack information appearing twice continuously, the system will not perform the collection operation until certain specific conditions (such as the maximum packet record quantity is reached, the attack information no longer appears, etc.) are met, and the collection of other attack information can be restored.

[0090] Suppose that the maximum packet record quantity configured by the chassis-type device is 50, and the system monitors that the set attack information of “SYN flood attack” appears twice continuously, then in the subsequent collection process, the system will only collect the packets related to “SYN flood attack”, and will not collect other types of attack information such as “ICMP flood attack” and “SQL injection attack”, until 50 packets of “SYN flood attack” are collected.

[0091] In this embodiment, the attack message and attack log are stored in the data table of the main control board and the backup control board respectively. Storing in the backup control board has important intentions in many aspects, mainly reflected in improving the reliability, availability, data integrity and coping with special situations of the system. The following is a detailed description: The main control board may be damaged due to hardware aging, overheating, power failure and other reasons, for example, the hard disk on the main control board has bad tracks, which may cause the data stored in the message data table and log data table of the main control board to be lost. The data storage of the backup control board can be used as a backup, even if the main control board hardware fails, the attack message and log can still be obtained from the data table of the backup control board, ensuring that the data is not lost and ensuring the continuous analysis and processing capability of the system to attack events.

[0092] The operating system, database management system and other software of the main control board may crash, abnormally and other situations, such as database software deadlock, which causes the data table of the main control board to be inaccessible. At this time, the data storage of the backup control board is not affected and can continue to provide data support for security management personnel to ensure the normal operation of the system.

[0093] In addition, when the main control board is upgraded or maintained, the main control board may need to be temporarily stopped, for example, the database of the main control board is upgraded, which may take several hours or even longer. During this period, the data storage of the backup control board can continue to provide query and analysis services for attack messages and logs, ensuring that the system can still maintain the monitoring and response capability to attack events during maintenance and upgrade, and improving the availability of the system.

[0094] When a large number of security management personnel access the data table of the main control board for data analysis at the same time, it may cause the load of the main control board to be too high, causing access delay or even failure to respond. The data storage of the backup control board can share part of the access pressure, allowing some personnel to obtain the required data from the data table of the backup control board, thereby ensuring the availability of the system under high concurrency.

[0095] During the transmission of attack messages and logs from the service board to the main control board through the inter-board channel, data transmission errors may occur due to network interference, signal attenuation and other reasons. The backup control board as another independent receiving and storage node can verify and store the transmitted data again. If the data received by the main control board is incorrect, but the data received by the backup control board is complete, the data of the backup control board can be used as the standard to ensure the integrity of the data. The main control board may cause data damage due to program logic errors, data conflicts and other reasons when storing and processing attack messages and logs. The data storage of the backup control board can be used as an independent data source to restore and verify the data of the main control board, ensuring the integrity of the data.

[0096] In the prior art, when collecting log information, the main control board needs to connect the databases of each service board for repeated queries, which is time-consuming. The disclosed method for collecting attack packets of a chassis-type device actively sends attack packets and attack logs to the main control board and the backup control board through the inter-board channel after the service board detects data plane attack information. Specifically, after the service board detects attack information, it acquires attack packets and attack logs. The attack packets and attack logs are sent through the inter-board channel to the attack packet receiving main process and the log receiving main process of the main control board and the attack packet receiving backup process and the log receiving backup process of the backup control board through the attack detection process. In this way, the main control board and the backup control board do not need to actively connect the databases of each service board for repeated queries, reducing the query link and thus shortening the time for collecting log information and improving the efficiency of log information acquisition.

[0097] In the prior art, when attack information is stored on different service boards, the main control board needs to aggregate and display these information, increasing the complexity of packet aggregation and causing delay in information display. The present application solves this problem by configuring an index association relationship between the attack packet name and the packet source slot based on packet information and attack logs. This association relationship enables the main control board and the backup control board to clearly know the source of the packets and logs when receiving attack packets and attack logs, facilitating subsequent aggregation and processing. The main control board and the backup control board store the received attack packets and attack logs in corresponding data tables, i.e., the main control board packet data table, the backup control board packet data table, the main control board log data table, and the backup control board log data table. In this way, attack packets and attack logs are stored centrally on the control board, avoiding the dispersion of information on different service boards and reducing the complexity of packet aggregation. At the same time, since the data is already centrally stored, there is no need for complex aggregation operations when displaying information, thereby reducing the delay in information display.

[0098] The present application avoids the process of the main control board actively querying the databases of each service board, with the service board actively pushing attack packets and attack logs, reducing the query time and enabling log information to be acquired by the main control board and the backup control board more quickly, improving the timeliness of the system in acquiring key information and providing faster data support for subsequent analysis and processing. By configuring an index association relationship between the attack packet name and the packet source slot and centrally storing attack packets and attack logs in the data tables of the control board, the packet aggregation process is more clear and simple. The main control board and the backup control board can accurately process packets and logs according to the index association relationship, reducing errors and confusion in the aggregation process and improving the reliability and stability of the system.

[0099] Reference Figure 2In a second aspect, the application discloses a method for querying attack packets of a chassis-type device, which is based on the method for collecting attack packets of the chassis-type device and stores the attack packets. The method for querying comprises the following steps:

[0100] A100, receiving a query requirement for attack packet data.

[0101] For example, a client (such as a management terminal used by a network administrator) sends a query request to a query service interface of the chassis-type device through a network. The request can be a POST request based on an HTTP protocol, and the request body contains key information required for the query, such as a time range for the query and an attack type. After receiving the request, the query service module of the chassis-type device analyzes the request and extracts the key query conditions.

[0102] By receiving the query requirement of the client, it can be known that the user wants to query what kind of attack packet data, thereby providing a clear direction for subsequent query operations. The client is allowed to actively initiate the query, thereby meeting diversified query requirements of different users in different scenarios.

[0103] A200, obtaining a target attack packet name and a target packet source slot according to the query requirement for attack packet data, and taking the target attack packet name and the target packet source slot as a target index.

[0104] After receiving the query requirement, the chassis-type device first searches the internal metadata storage area for information matching the query conditions. It is assumed that according to the attack type and the time range for the query, the system determines that the target attack packet name is “PortScan_20250305” and the target packet source slot is “Slot5” from the metadata.

[0105] Then, the two pieces of information are combined into the target index, for example, they are connected by using a specific separator (such as “@”), to form “PortScan_20250305@Slot5” as a key identifier for subsequent queries.

[0106] In this step, the target attack packet name and the target packet source slot are obtained, which lays a foundation for subsequent accurate searching for related attack packets and logs, so that the query can be focused on a specific attack event and device location. The two key pieces of information are combined into the target index, which simplifies the process of searching in the data table, improves the query efficiency, and reduces the complexity of data processing.

[0107] A300, when the target index exists in the index association table, obtaining actual attack logs corresponding to the query requirement for attack packet data from a mainboard log data table.

[0108] The chassis-type device maintains an index association table that records the correspondence between target indexes and records in the main control board log data table. The system first searches the index association table for the target index generated in step A200 (for example, "PortScan_20250305@Slot5"). If the target index exists, the system locates the corresponding record in the main control board log data table based on the mapping relationship recorded in the index association table. The main control board log data table may store basic attack information, such as the attack start time, end time, and attack source IP address.

[0109] In this step, through the screening mechanism of the index association table, subsequent log data acquisition operations are performed only when the target index exists, avoiding unnecessary data queries and saving system resources; the index association table is used to associate the target index with the records in the main control board log data table, ensuring that the actual attack logs that match the query requirements can be accurately obtained, thereby improving the accuracy and relevance of the data.

[0110] A400 obtains the corresponding actual attack message from the message data table of the main control board based on the actual attack log, and feeds back the actual attack log and the actual attack message to the client corresponding to the attack message data query instruction.

[0111] Based on key information (such as the attack name and time) from the actual attack log obtained in step A300, a search is performed in the main control board message data table. The main control board message data table stores detailed attack message content. For example, based on the attack name "PortScan_20250305" and the attack time range, the corresponding actual attack message is located, which may contain a series of network data packet information. The system then integrates the actual attack log and the actual attack message and sends them back to the client via the network interface in an appropriate format (such as JSON or XML).

[0112] In this step, complete attack information can be provided to the client, including attack logs and detailed attack message content, so that the user can fully understand the situation of the attack event and facilitate in-depth analysis and processing; the query results are fed back to the client in a timely manner, which improves the efficiency of users in obtaining information, enhances the user experience, and helps users make decisions quickly.

[0113] In this embodiment, by a series of steps, the target index and the index association table are used to quickly and accurately locate and obtain the required attack log and message information from a large amount of data, greatly improving the query efficiency and reducing the query time; ensure that the attack information obtained by the client is complete and accurate, from the basic log of the attack to the detailed message content, which can provide comprehensive analysis and judgment for network security management personnel, and take corresponding protection measures in time; allow users to obtain the required information through a simple query request, and the entire query process is transparent to the user, improving the usability and user satisfaction of the system, and facilitating the use of users with different technical levels.

[0114] Referring to Figure 3 In a third aspect, the application discloses a query method for attack message of machine frame equipment, based on the collection method for attack message of machine frame equipment, the storage of attack message, the query method comprises:

[0115] B100, receiving an attack message data query instruction.

[0116] Through this step, the specific range and characteristics of the attack message data that the user wants to query can be clearly understood, providing accurate direction for subsequent query operation; allowing users to actively initiate queries to meet the diversified needs of different users for attack message data in different scenarios, improving the practicality of the system.

[0117] B200, according to the attack message data query requirement, obtaining the target attack message name and the target message source slot, and taking the target attack message name and the target message source slot as the target index.

[0118] The two key information is combined into a target index, which simplifies the process of searching in the data table, improves the query efficiency, and reduces the complexity of data processing.

[0119] B300, when the target index exists in the index association table, obtaining the first actual attack log corresponding to the attack message data query requirement from the main control board log data table.

[0120] Through the screening mechanism of the index association table, only when the target index exists, the subsequent log data acquisition operation is performed, unnecessary data query is avoided, and system resources are saved; the target index is associated with the record in the main control board log data table by using the index association table, so that the actual attack log matched with the query requirement can be accurately obtained, and the accuracy and relevance of the data are improved.

[0121] B400, based on the first actual attack log, obtaining the corresponding first actual attack message from the main control board message data table.

[0122] According to the key information (such as attack name, time range, source IP and destination IP, etc.) in the first actual attack log obtained in step B300, a search is performed in the main control panel message data table. The main control panel message data table stores detailed attack message content, which can be a series of network packet information. For example, through the attack name "SQL_Injection_20250308" and the attack time range, the corresponding first actual attack message is located, and its content can contain detailed information such as specific SQL injection statements.

[0123] The detailed attack message content obtained from the main control panel message data table, combined with the first actual attack log, can provide users with more comprehensive attack event information, which helps to deeply analyze the principles and processes of attacks; based on the key information in the first actual attack log, the attack message obtained is ensured to accurately match the query requirements and log information.

[0124] B500, the first actual attack message and the first actual attack log are recorded as the first information.

[0125] Combining attack logs and attack messages together facilitates subsequent processing and comparison operations, improving the efficiency of data management; expressing the first information in a unified format ensures the completeness and consistency of the data, which is convenient for subsequent analysis and display.

[0126] B600, obtaining the second actual attack log corresponding to the attack message data query requirement from the backup control panel log data table.

[0127] Similar to the main control panel, the backup control panel also has its own log data table. The system directly searches in the backup control panel log data table according to the attack message data query requirement received in step B100. For example, according to the query attack type, time range and other conditions, the corresponding second actual attack log is located, and its content can be similar to the first actual attack log, containing basic attack information.

[0128] The data in the backup control panel log data table can be used as a backup and verification of the main control panel data. By obtaining the second actual attack log, the consistency of the main control panel and backup control panel data can be checked, improving the reliability of the data; in the case of main control panel failure or data loss, the log data of the backup control panel can be used as a backup data source, ensuring that the system can still provide effective query services.

[0129] B700, obtaining the corresponding second actual attack message from the backup control panel message data table based on the second actual attack log.

[0130] According to the key information (such as attack name, time range, etc.) in the second actual attack log obtained in step B600, a search is performed in the backup control board message data table. The backup control board message data table stores detailed attack message contents corresponding to the backup control board log. For example, through the attack name and time range, the corresponding second actual attack message is located, and its content should correspond to the first actual attack message.

[0131] Similar to step B400, obtaining the second actual attack message can ensure that the data of the backup control board is complete and matches the log information. At the same time, by comparing with the first actual attack message, the accuracy of the data can be further verified; the data in the backup control board message data table serves as a backup of the main control board message data, and can provide alternative data when the main control board has a problem, ensuring the normal operation of the system.

[0132] B800, the second actual attack message and the second actual attack log are recorded as second information.

[0133] The system integrates the second actual attack log obtained in step B600 and the second actual attack message obtained in step B700 to form a unified data structure, which is recorded as second information. Similarly, they are combined together using the JSON format, and the format is similar to the first information.

[0134] Similar to step B500, the attack log and the attack message of the backup control board are combined together, which facilitates subsequent comparison operations and improves the management efficiency of the data. The second information is expressed in a unified format, ensuring the completeness and consistency of the backup control board data, and facilitating comparison with the first information.

[0135] B900, when the first information and the second information are consistent, the target attack message display information is generated, and the target attack message display information is fed back to the client corresponding to the attack message data query instruction.

[0136] The system compares the first information and the second information in detail, including each item of information in the attack log (such as attack name, time, source IP, destination IP, etc.) and the content of the attack message. A special comparison algorithm can be written to compare each field in the JSON data structure one by one. If the first information and the second information are consistent, the system will generate target attack message display information according to these information, and the display information can be further formatted and arranged to present to the user in a more friendly way, such as adding some descriptive text, charts, etc. Then the target attack message display information is sent back to the client through a network interface (such as HTTP response).

[0137] By comparing the consistency of the first information and the second information, the accuracy and reliability of the query result can be ensured. If the two are inconsistent, it means that there may be data errors or system failures, which need to be further investigated. The target attack message display information is generated and fed back to the client in a friendly way, improving the efficiency and experience of users obtaining information, and enabling users to more intuitively understand the situation of the attack event.

[0138] In this embodiment, by simultaneously obtaining data from the master control board and the backup control board and performing consistency verification, the accuracy and reliability of the query result are ensured. In the case of failure or data anomaly of the master control board, the data of the backup control board can be used as backup to ensure the normal operation of the system. At the same time, complete attack information is provided, including attack logs and detailed attack message content, which helps network security management personnel to fully understand the situation of the attack event and conduct in-depth analysis and processing. The entire query process is transparent to the user, and the user only needs to send a simple query instruction to obtain the verified and formatted target attack message display information, improving the ease of use and user satisfaction of the system.

[0139] Further, when the first information is consistent with the second information and there are multiple groups of first information, the multiple groups of first information can be combined in chronological order, and a fusion attack message information is outputted, which is used as the target attack message display information.

[0140] In this embodiment, the target attack message display information can be a pcap format file.

[0141] Further, when the first information is inconsistent with the second information, the union information of the first information and the second information can be obtained, and the union information is used as the target attack message display information.

[0142] In a fourth aspect, the present application discloses a machine frame device attack message collection system for executing a machine frame device attack message collection method, the machine frame device including a master control board, a backup control board, and a plurality of service boards, comprising:

[0143] The acquisition module is configured to acquire attack messages and attack logs in response to data plane attack information detected by the service boards.

[0144] The configuration module is configured to configure an index association relationship between attack message names and message source slots based on message information and attack logs.

[0145] The first sending module is configured to send attack messages and attack logs to attack message receiving master processes and log receiving master processes of the master control board through inter-board channels through attack detection processes.

[0146] The second sending module is configured to send the attack message and the attack log to the attack message receiving backup process and the log receiving backup process of the backup control board through the inter-board channel through the attack detection process.

[0147] The first storage module is configured to store the attack message into the main control board message data table and the backup control board message data table in response to the message receiving messages of the attack message receiving main process and the attack message receiving backup process.

[0148] The second storage module is configured to store the attack log into the main control board log data table and the backup control board log data table in response to the log receiving messages of the log receiving main process and the log receiving backup process.

[0149] In a fifth aspect, the present application discloses a machine frame device attack message query system for executing the machine frame device attack message query method, and the query system comprises:

[0150] The receiving module is configured to receive an attack message data query requirement.

[0151] The query module is configured to acquire an actual attack message name and an actual message source slot corresponding to the attack message data query requirement from the main control board log data table according to the attack message data query requirement and the index association relationship.

[0152] The determination module is configured to take the actual attack message name and the actual message source slot as target indexes.

[0153] The analysis and feedback module is configured to acquire attack message information corresponding to the target indexes from the main control board message data table and feed back the attack message information to a client corresponding to the attack message data query instruction.

[0154] In a sixth aspect, the present application discloses a machine frame device attack message query system for executing the machine frame device attack message query method, and the query system comprises:

[0155] The instruction receiving module is configured to receive an attack message data query instruction.

[0156] The first information query module is configured to acquire an actual attack message name and an actual message source slot corresponding to the attack message data query requirement from the main control board log data table according to the attack message data query instruction and the index association relationship, and record the actual attack message name and the actual message source slot as a first name and a first slot respectively.

[0157] The first target index determination module is configured to take the first name and the first slot as first target indexes.

[0158] The first information acquisition module is configured to acquire attack message information corresponding to the first target indexes from the main control board message data table, and record the attack message information as first information.

[0159] The second information query module is configured to obtain, according to the attack packet data query instruction and the index association relationship, the actual attack packet name and the actual packet source slot corresponding to the attack packet data query requirement from the backup control board log data table, and record the actual attack packet name and the actual packet source slot as a second name and a second slot respectively.

[0160] The third target index determination module is configured to take the second name and the second slot as a second target index.

[0161] The second information acquisition module is configured to obtain, from the backup control board packet data table, attack packet information corresponding to the second target index, and record the attack packet information as second information.

[0162] The display module is configured to determine whether the first information and the second information are consistent, and if so, generate target attack packet display information and feed back the target attack packet display information to a client corresponding to the attack packet data query instruction.

[0163] The computer device according to the embodiments of the present disclosure includes a memory and a processor. The memory is configured to store non-transitory computer readable instructions. Specifically, the memory can include one or more computer program products, which can include various forms of computer readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM), cache memory, and / or the like. The non-volatile memory may, for example, include read-only memory (ROM), hard disk, flash memory, and / or the like.

[0164] The processor can be a central processing unit (CPU) or other forms of processing units having data processing and / or instruction execution capabilities, and can control other components in the computer device to perform desired functions. In an embodiment of the present disclosure, the processor is configured to run the computer readable instructions stored in the memory, so that the computer device performs all or part of the steps of the collecting method of attack packets of a chassis device or the querying method of attack packets of a chassis device according to the embodiments of the present disclosure.

[0165] Those skilled in the art should understand that, in order to solve the technical problem of how to obtain a good user experience effect, the embodiments of the present disclosure can also include well-known structures such as a communication bus, an interface, and the like, which should also be included in the protection scope of the present disclosure.

[0166] As Figure 4 A structural schematic diagram of a computer device according to an embodiment of the present disclosure is provided. The structural schematic diagram shows the structure of a computer device suitable for use in the embodiments of the present disclosure. Figure 4 The computer device shown is merely an example, and should not impose any limitation on the functions and use range of the embodiments of the present disclosure.

[0167] like Figure 4 As shown, the computer device may include a processor (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) or a program loaded from a storage device into a random access memory (RAM). Various programs and data required for the operation of the computer device are also stored in the RAM. The processor, ROM, and RAM are connected to each other via a bus. An input / output (I / O) interface is also connected to the bus.

[0168] Typically, the following devices can be connected to the I / O interface: input devices such as sensors or visual information acquisition devices; output devices such as display screens; storage devices such as tapes and hard disks; and communication devices. The communication device can allow the computer device to communicate with other devices (such as edge computing devices) wirelessly or by wire to exchange data. Figure 4 A computer device having various devices is shown, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead.

[0169] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processor, all or part of the steps of the method for collecting attack messages of a frame device or the method for querying attack messages of a frame device of the embodiment of the present disclosure are executed.

[0170] For detailed description of this embodiment, please refer to the corresponding description in the aforementioned embodiments, which will not be repeated here.

[0171] According to an embodiment of the present disclosure, a computer-readable storage medium stores non-transitory computer-readable instructions. When the non-transitory computer-readable instructions are executed by a processor, all or part of the steps of the aforementioned methods for collecting attack messages for chassis-type devices or querying attack messages for chassis-type devices are performed.

[0172] The computer-readable storage medium described above includes, but is not limited to, an optical storage medium (for example, a CD-ROM and a DVD), a magneto-optical storage medium (for example, an MO), a magnetic storage medium (for example, a magnetic tape or a magnetic hard disk), a medium having a built-in rewritable nonvolatile memory (for example, a memory card), and a medium having a built-in ROM (for example, a ROM cartridge).

[0173] For detailed description of the present embodiment, reference can be made to the corresponding description in the foregoing embodiments, which will not be repeated here.

[0174] The above describes the basic principles of the present disclosure in combination with specific embodiments, but it should be noted that the advantages, benefits, effects and the like mentioned in the present disclosure are only examples and are not limiting, and these advantages, benefits, effects and the like cannot be considered as necessary for each embodiment of the present disclosure. In addition, the above specific details of the disclosure are only for the purpose of example and for the purpose of understanding, and are not limiting, and the above details do not limit the present disclosure to be necessarily implemented with the above specific details.

[0175] In the present disclosure, the relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between the entities or operations. The block diagrams of devices, apparatuses, equipment, systems involved in the present disclosure are only illustrative examples and are not intended to require or imply the connection, arrangement, configuration shown in the block diagram. As those skilled in the art will recognize, these devices, apparatuses, equipment, systems can be connected, arranged, configured in any manner. Words such as "include", "contain", "have" and the like are open-ended words, which mean "including but not limited to", and can be used interchangeably. The words "or" and "and" used herein mean the word "and / or", and can be used interchangeably unless the context clearly indicates otherwise. The word "such as" used herein means the phrase "such as but not limited to", and can be used interchangeably.

[0176] In addition, as used herein, "or" used in the list of items preceded by "at least one of" means a disjunctive list, such that, for example, a list of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the word "example" does not mean that the described example is preferred or better than other examples.

[0177] It should also be noted that in the systems and methods of the present disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be considered as equivalents of the present disclosure.

[0178] Various changes, modifications, and alterations to the techniques described herein can be made without departing from the teachings of the attached claims. Moreover, the scope of the claims of the present disclosure is not limited to the particular aspects described herein. Rather, the scope of the claims of the present disclosure includes all alternatives, modifications, and equivalents falling within the scope of the claims of the present disclosure. Accordingly, the attached claims are incorporated into this Detailed Description by reference.

[0179] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the generic principles defined herein can be applied to other aspects without departing from the scope of the disclosure. Thus, the present disclosure is not intended to be limited to the aspects shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0180] The above description has been presented for the purpose of illustration and description. Furthermore, this description is not intended to limit the embodiments of the present disclosure to the forms disclosed herein. Although various example aspects and embodiments have been discussed above, those of ordinary skill in the art will appreciate a variety of modifications, alternatives, permutations, and equivalents thereof. Accordingly, the disclosure is intended to embrace all such alterations, modifications, and permutations of the aspects described herein, including other aspects falling within the scope of the appended claims.

Claims

1. A method for collecting attack packets of a chassis device, the chassis device comprising a master control board, a backup control board and a plurality of service boards, characterized in that, The method comprises the following steps: In response to the data plane attack information detected by the service board, attack packets and attack logs are obtained, specifically including: real-time monitoring of attack information by a data plane attack detection process of a machine frame type security device service board, in response to the attack information, attack packets and attack logs are generated; the attack packets include attack packet information, attack packet name, and packet source slot, and the attack logs include attack packet name and packet source slot; Based on the attack packets and the attack logs, an index association relationship between the attack packet name and the packet source slot is configured, and the index association relationship is stored in an index association table; Through the attack detection process, the attack packets and the attack logs are respectively sent to an attack packet receiving main process and a log receiving main process of the main control board through an inter-board channel; Through the attack detection process, the attack packets and the attack logs are respectively sent to an attack packet receiving backup process and a log receiving backup process of the backup control board through the inter-board channel; In response to the packet receiving messages of the attack packet receiving main process and the attack packet receiving backup process, the attack packets are respectively stored in a main control board packet data table and a backup control board packet data table; In response to the log receiving messages of the log receiving main process and the log receiving backup process, the attack logs are respectively stored in a main control board log data table and a backup control board log data table.

2. The method of claim 1, wherein the method further comprises: The response to the packet receiving messages of the attack packet receiving main process and the attack packet receiving backup process, and the storage of the attack packets in the main control board packet data table and the backup control board packet data table, comprises: In response to the packet receiving message of the attack packet receiving main process, the attack packets are stored in a first packet buffer area, and the data in the first packet buffer area is stored in the main control board packet data table by the main control board attack packet storage process; In response to the packet receiving message of the attack packet receiving backup process, the attack packets are stored in a second packet buffer area, and the data in the second packet buffer area is stored in the backup control board packet data table by the backup control board attack packet storage process.

3. The method of claim 2, wherein the method further comprises: The response to the log receiving messages of the log receiving main process and the log receiving backup process, and the storage of the attack logs in the main control board log data table and the backup control board log data table, comprises: In response to the log receiving message of the log receiving main process, the attack logs are stored in a first log buffer area, and the data in the first log buffer area is stored in the main control board log data table by the main control board log storage process; In response to the log receiving message of the log receiving backup process, the attack logs are stored in a second log buffer area, and the data in the second log buffer area is stored in the backup control board log data table by the backup control board log storage process.

4. The method of claim 1, wherein the method further comprises: When the data plane attack information is set attack information, the maximum number of packet records configured by the machine frame type device is used for collecting the set attack information.

5. A method for querying a chasis device attack packet, characterized in that, The attack packet storage is performed based on the machine frame type device attack packet collection method in any one of claims 1-4, and the query method comprises: Receiving attack packet data query requirements; According to the attack packet data query requirement, a target attack packet name and a target packet source slot are obtained, and the target attack packet name and the target packet source slot are taken as a target index; When the target index exists in the index association table, an actual attack log corresponding to the attack packet data query requirement is obtained from the main control panel log data table; Based on the actual attack log, an actual attack packet corresponding to the main control panel packet data table is obtained, and the actual attack log and the actual attack packet are fed back to a client corresponding to the attack packet data query instruction.

6. A method for querying a chasis device attack packet, characterized in that, The method for collecting attack packets of the machine frame device according to any one of claims 1-4 is used for storing attack packets, and the query method comprises: receiving an attack packet data query instruction; According to the attack packet data query requirement, a target attack packet name and a target packet source slot are obtained, and the target attack packet name and the target packet source slot are taken as a target index; When the target index exists in the index association table, an actual attack log corresponding to the attack packet data query requirement is obtained from the main control panel log data table; Based on the actual attack log, an actual attack packet corresponding to the main control panel packet data table is obtained, and the actual attack log and the actual attack packet are fed back to a client corresponding to the attack packet data query instruction. The computer device comprises: at least one processor; and a memory connected in communication with the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method for collecting attack packets of the machine frame device according to any one of claims 1-4 or the method for querying attack packets of the machine frame device according to claim 5 or the method for querying attack packets of the machine frame device according to claim 6. The computer readable storage medium stores computer instructions for causing a computer to execute the method for collecting attack packets of the machine frame device according to any one of claims 1-4 or the method for querying attack packets of the machine frame device according to claim 5 or the method for querying attack packets of the machine frame device according to claim 6.

7. A computer apparatus, comprising: The computer instructions, when executed by a processor, implement the steps of the method for collecting attack packets of the machine frame device according to any one of claims 1-4 or the method for querying attack packets of the machine frame device according to claim 5 or the method for querying attack packets of the machine frame device according to claim 6. ​ ​ ​ 8. A computer-readable storage medium, characterized in that, ​ 9. A computer program product comprising computer instructions, characterized in that, ​

Citation Information

Patent Citations

  • APT attack analysis method and system, and server

    CN112165451A

  • Large-scale network attack-oriented tracing system and method

    CN114584401A