Traffic Processing Method, Device, Equipment and Medium Based on Deep Packet Inspection

By receiving plug-in registration in the gateway device, extracting session information for in-depth packet detection and processing data packets, the problem that traditional traffic management cannot identify complex protocols is solved, and efficient and intelligent network traffic management is achieved.

CN120017541BActive Publication Date: 2025-07-04SICHUAN TIANYI COMHEART TELECOM
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510476074.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-16
Publication Date
2025-07-04
Estimated Expiration
2045-04-16

AI Technical Summary

Technical Problem

Traditional traffic management methods cannot accurately identify complex application layer protocols and cannot meet the needs of refined traffic control.

Method used

By receiving the plug-in registration request, the plug-in is saved to the target chain array, the session information is extracted for in-depth packet detection and analysis, and the plug-in is called to process data packets based on the analysis results, including malicious traffic detection and traffic optimization.

Benefits of technology

It realizes accurate identification and dynamic processing of complex protocols, improves the intelligence and efficiency of network traffic management, and ensures network security and reasonable allocation of resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017541B_ABST
    Figure CN120017541B_ABST
Patent Text Reader

Abstract

The present application provides a traffic processing method, device, equipment and medium based on deep packet inspection, which relates to the technical field of network management and is used to solve the problem that traditional traffic management methods cannot accurately identify complex protocols. The method includes: receiving registration requests of at least one plugin and saving the at least one plugin into an array corresponding to a target chain; when a target data packet enters the PREROUTING chain, extracting session information from the target data packet; performing deep packet inspection analysis according to the session information to obtain an analysis result; when the target data packet enters the target chain, calling at least one plugin in sequence according to a preset priority; and the at least one plugin processes the target data packet according to the analysis result. Through the deep packet inspection technology, the method can accurately identify complex application layer protocols, and the plugin dynamically processes the traffic according to the deep packet inspection result, so as to achieve efficient, intelligent and refined network traffic management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network management technologies, and provides a traffic processing method, device, equipment, and medium based on deep packet inspection. Background Art

[0002] Traditional traffic management methods mainly rely on basic means such as firewalls, packet filtering, and network address translation to control traffic at the gateway. Although these methods are effective in some scenarios, with the increasing complexity of the network, especially when dealing with encrypted traffic, multiple protocols, and dynamic network environments, traditional traffic management methods cannot accurately identify complex application layer protocols and can no longer meet the refined traffic control requirements. Summary of the Invention

[0003] This application provides a traffic processing method, device, equipment, and medium based on deep packet inspection, which is used to solve the problem that traditional traffic management methods cannot accurately identify complex protocols.

[0004] In a first aspect, this application provides a traffic processing method based on deep packet inspection, including:

[0005] Receiving registration requests of at least one plugin, and saving the at least one plugin into an array corresponding to a target chain; wherein, the registration request includes the target chain; the target chain is a PREROUTING chain or a FORWARD chain;

[0006] When a target data packet enters the PREROUTING chain, extracting session information from the target data packet;

[0007] Performing deep packet inspection analysis according to the session information to obtain an analysis result;

[0008] When the target data packet enters the target chain, calling the at least one plugin in sequence according to a preset priority;

[0009] The at least one plugin processes the target data packet according to the analysis result.

[0010] Optionally, the session information includes an IP address, port information, and protocol information; the performing deep packet inspection analysis according to the session information to obtain an analysis result includes:

[0011] Obtaining the protocol type of the target data packet according to the port information and the protocol information;

[0012] Obtaining the traffic type of the target data packet according to the port information and the protocol information;

[0013] Perform malicious traffic analysis based on the IP address to obtain the security detection result of whether the target data packet is malicious traffic.

[0014] Optionally, the at least one plugin includes a malicious traffic detection plugin and a traffic optimization plugin; the at least one plugin processes the target data packet according to the analysis result, including:

[0015] If the malicious traffic detection plugin determines that the target data packet is malicious traffic, discard the target data packet and trigger a security alarm;

[0016] If the malicious traffic detection plugin determines that the target data packet is not malicious traffic, the traffic optimization plugin optimizes the target data packet according to the traffic type.

[0017] Optionally, the traffic optimization plugin optimizes the target data packet according to the traffic type, including:

[0018] If the traffic optimization plugin determines that the traffic type is voice traffic or video traffic, increase the priority of the target data packet by modifying the DSCP value;

[0019] If the traffic optimization plugin determines that the traffic type is P2P traffic, reduce the priority of the target data packet by modifying the DSCP value and limit the bandwidth of the target data packet.

[0020] Optionally, the IP address includes a target IP address; after the traffic optimization plugin optimizes the target data packet according to the traffic type, the method further includes:

[0021] If the traffic optimization plugin determines that the target data packet does not need to be redirected, forward the target data packet according to the target IP address;

[0022] If the traffic optimization plugin determines that the target data packet needs to be redirected, modify the target IP address and forward the target data packet according to the modified target IP address.

[0023] Optionally, before if the traffic optimization plugin determines that the target data packet does not need to be redirected and forwards the target data packet according to the target IP address, the method further includes:

[0024] The traffic optimization plugin determines whether the target data packet needs to be redirected according to the protocol type and the target IP address.

[0025] Optionally, the at least one plugin includes a traffic statistics plugin. Before the malicious traffic detection plugin determines that the target data packet is malicious traffic, discards the target data packet, and triggers a security alert, the method further includes:

[0026] The traffic statistics plugin calculates the proportion of traffic of different protocol types in historical traffic according to the protocol type of the target data packet; the historical traffic includes the target data packet.

[0027] In a second aspect, the present application provides a traffic processing device based on deep packet inspection, including:

[0028] A plugin registration module, configured to receive registration requests of at least one plugin, and save the at least one plugin into an array corresponding to a target chain; wherein, the registration request includes the target chain; the target chain is a PREROUTING chain or a FORWARD chain;

[0029] A deep packet inspection analysis module, configured to extract session information from the target data packet when the target data packet enters the PREROUTING chain; perform deep packet inspection analysis according to the session information to obtain an analysis result;

[0030] A plugin invocation module, configured to sequentially invoke the at least one plugin according to a preset priority when the target data packet enters the target chain;

[0031] A plugin processing module, configured to process the target data packet by the at least one plugin according to the analysis result.

[0032] In a third aspect, the present application provides a gateway device, which includes a memory and a processor. A computer program is stored in the memory, and the processor executes the computer program to implement the traffic processing method based on deep packet inspection described in the first aspect.

[0033] In a fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored, and the processor executes the computer program to implement the traffic processing method based on deep packet inspection described in the first aspect.

[0034] Compared with the prior art, the beneficial effects of the present application are as follows:

[0035] The present application provides a traffic processing method based on deep packet inspection. The method includes: receiving registration requests of at least one plugin, and saving the at least one plugin into an array corresponding to a target chain; wherein, the registration request includes the target chain; the target chain is the PREROUTING chain or the FORWARD chain; when a target data packet enters the PREROUTING chain, extracting session information from the target data packet; performing deep packet inspection analysis according to the session information to obtain an analysis result; when the target data packet enters the target chain, calling the at least one plugin in sequence according to a preset priority; and the at least one plugin processes the target data packet according to the analysis result.

[0036] Through the deep packet inspection technology, the present application deeply analyzes the content of the target data packet, can identify complex application layer protocols and traffic types, and external plugins can be flexibly registered and called back according to traffic characteristics. At different stages of the gateway device (PREROUTING chain and FORWARD chain), the target data packet is dynamically processed (such as optimized, discarded, forwarded, etc.) based on the deep packet inspection analysis result, so as to achieve efficient, intelligent and refined network traffic management. Description of the Drawings

[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0038] Figure 1 It is a schematic diagram of the gateway device structure of the hardware operating environment related to the solution of the embodiment of the present application;

[0039] Figure 2 It is a schematic flowchart of the traffic processing method based on deep packet inspection provided by the embodiment of the present application;

[0040] Figure 3 It is a schematic diagram of some code provided by the embodiment of the present application Figure 1 ;

[0041] Figure 4 It is a schematic diagram of some code provided by the embodiment of the present application Figure 2 ;

[0042] Figure 5 It is a schematic diagram of some code provided by the embodiment of the present application Figure 3 ;

[0043] Figure 6 It is a schematic diagram of some code provided by the embodiment of the present application Figure 4 ;

[0044] Figure 7 Schematic diagram of the processing flow of the plug-in provided by the embodiment of the present application;

[0045] Figure 8 Schematic diagram of the structure of the traffic processing device based on deep packet inspection provided by the embodiment of the present application.

[0046] Markings in the figure: 101 - Processor, 102 - Communication bus, 103 - Network interface, 104 - User interface, 105 - Memory. Detailed implementation manners

[0047] To make the objectives, technical solutions and advantages of the present application clearer and more understandable, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts belong to the scope of protection of the present application. Without conflict, the embodiments in the present application and the features in the embodiments may be arbitrarily combined with each other. And although the logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than here.

[0048] To solve the problem that traditional traffic management methods cannot accurately identify complex protocols, the embodiment of the present application provides a traffic processing method based on deep packet inspection, which can be executed by a gateway device, such as a PON gateway, an FTTR gateway, a convergence gateway, a government and enterprise gateway, etc.

[0049] 1. PON gateway: A gateway device based on Passive Optical Network (PON) technology that converts the optical signal from the optical fiber network into an Ethernet signal for use by home or office network devices.

[0050] 2. FTTR gateway: A gateway device that connects optical fibers to rooms, converts optical fiber signals into electrical signals, and provides network connections through home wiring (such as Ethernet or Wi-Fi).

[0051] 3. Convergence gateway: A gateway device integrating multiple functions, usually capable of supporting different types of access technologies simultaneously, such as ADSL, PON, LTE, Wi-Fi, etc., aiming to provide users with one-stop network connection services.

[0052] 4. Government and enterprise gateway: A high-performance and highly secure gateway device designed for government and enterprise networks, mainly used to connect internal enterprise or government local area networks (LANs) to external Internet or wide area networks (WANs).

[0053] Please refer to Figure 1 , which is a schematic structural diagram of a gateway device for the hardware operating environment involved in the solution of the embodiment of the present application.

[0054] As shown in Figure 1 , the gateway device may include: a processor 101, such as a central processing unit (CPU), a communication bus 102, a user interface 104, a network interface 103, and a memory 105. Among them, the communication bus 102 is used to realize the connection and communication between these components. The user interface 104 may include a display screen (Display) and an input unit such as a keyboard (Keyboard). The user interface 104 may include a standard wired interface and a wireless interface. The network interface 103 may include a standard wired interface and a wireless interface (such as a wireless fidelity (WI-FI) interface). The memory 105 may be a high-speed random access memory (Random Access Memory, RAM) or a stable non-volatile memory (Non-Volatile Memory, NVM), such as a disk memory. Optionally, the memory 105 may also be a storage device independent of the aforementioned processor 101.

[0055] Those skilled in the art can understand that Figure 1 the structure shown in

[0056] does not constitute a limitation on the device, and may include more or fewer components than shown in the figure, or combine some components, or have different component arrangements. Figure 1 As shown in

[0057] In Figure 1 the gateway device shown, the network interface 103 is mainly used for data communication with a network server; the user interface 104 is mainly used for data interaction with a user; the processor 101 and the memory 105 in the gateway device of the present invention may be arranged in the gateway device. The gateway device calls the traffic processing device based on deep packet inspection stored in the memory 105 through the processor 101 and executes the traffic processing method based on deep packet inspection provided by the embodiment of the present application.

[0058] Based on Figure 1 the gateway device shown, the following introduces Figure 2 a traffic processing method based on deep packet inspection shown in

[0059] S201. Receive the registration requests of at least one plugin, and save the at least one plugin into the array corresponding to the target chain.

[0060] In a specific implementation process, any plugin can initiate a registration request to the gateway device through the ctSgw_appRegisterFunc() function, so that the gateway device knows that this plugin can process the traffic after Deep Packet Inspection (DPI) analysis.

[0061] Among them, the registration request contains the target chain, and the target chain is the PREROUTING chain or the FORWARD chain. If the target chain is the PREROUTING chain, the gateway device saves this plugin into the g_preProcInfo[] array, so that this plugin is registered on the PREROUTING chain. When traffic enters the PREROUTING chain, this plugin can be called. If the target chain is the FORWARD chain, the gateway device saves this plugin into the g_forwardProcInfo[] array, so that this plugin is registered on the FORWARD chain. When traffic enters the FORWARD chain, this plugin can be called.

[0062] It should be noted that the gateway device supports the registration of multiple plugins. Each plugin can provide different functions, such as malicious traffic detection plugins, traffic optimization plugins, traffic statistics plugins, etc., and allows these plugins to perform in-depth detection on traffic on the PREROUTING chain or the FORWARD chain. The core code is as Figure 3 shown. ctSgw_appRegisterFunc() is used to register plugins.

[0063] In a possible embodiment, the gateway device includes a plugin information management module, and the plugin information management module is used to provide functions of plugin information registration and query. The gateway device performs dynamic loading according to the description provided by the plugin.

[0064] S202. When the target data packet enters the PREROUTING chain, extract the session information from the target data packet.

[0065] In the specific implementation process, the PREROUTING hook is triggered when a data packet first enters the gateway device (before the routing decision), and the FORWARD hook is triggered when the data packet is forwarded by the routing decision. Therefore, after the target data packet enters the gateway device, it will first enter the PREROUTING chain and then enter the FORWARD chain. The nf_conntrack module is a connection tracking module in the Linux kernel, which is used to track network connections passing through the firewall or router. When the target data packet enters the PREROUTING chain, the gateway device can capture the target data packet in real time through the nf_conntrack module, extract the session information from the target data packet, and finally encapsulate the session information into the CtSgwTupleInfo structure.

[0066] Among them, the session information is the key feature of the target data packet, including the IP address, port information, protocol information, and session status. The IP address includes the source IP address and the target IP address. The port information includes the source port and the target port. The protocol information includes the transport layer protocol. The session status is used to indicate whether it is a new session. The CtSgwTupleInfo structure is shown in Table 1.

[0067] Table 1

[0068]

[0069] S203. Perform deep packet inspection and analysis based on the session information to obtain the analysis result.

[0070] In a possible embodiment, according to the port information and the protocol information, obtain the protocol type of the target data packet; according to the port information and the protocol information, obtain the traffic type of the target data packet; perform malicious traffic analysis based on the IP address to obtain the security detection result of the target data packet.

[0071] In the specific implementation process, the gateway device can perform DPI analysis based on the CtSgwTupleInfo structure. First, according to the port information and the protocol information, use DPI rule matching to determine the protocol type of the target data packet (such as HTTP, HTTPS, DNS, FTP, etc.).

[0072] For example: If the target port is 80 and the transport layer protocol is TCP, then determine that the protocol type of the target data packet is HTTP. If the target port is 443 and the transport layer protocol is TCP, then determine that the protocol type of the target data packet is HTTPS. If the target port is 53 and the transport layer protocol is UDP, then determine that the protocol type of the target data packet is DNS. If the target port is 21 and the transport layer protocol is TCP, then determine that the protocol type of the target data packet is FTP.

[0073] Then, the gateway device can obtain the traffic type of the target data packet according to the port information and protocol information. The traffic types include, for example, video traffic (YouTube, Netflix), P2P traffic (BitTorrent), voice traffic (VoIP), etc.

[0074] The common port information and protocols for video traffic are as follows:

[0075] 1. Real-Time Messaging Protocol (RTMP): The default port is 1935 and the transport layer protocol is TCP.

[0076] 2. Microsoft Media Services (MMS): The default port is 1755 and the transport layer protocol is TCP.

[0077] 3. Real-Time Streaming Protocol (RTSP): The default port is 554 and the transport layer protocol is TCP.

[0078] The common port information and protocols for P2P traffic are as follows:

[0079] 1. BitTorrent: The default ports are 6881 - 6889 and the transport layer protocol is TCP.

[0080] 2. eMule: The default port is 4662 and the transport layer protocol is TCP.

[0081] 3. eDonkey: The default port is 4242 and the transport layer protocol is TCP.

[0082] The common port information and protocols for voice traffic are as follows:

[0083] 1. Session Initiation Protocol (SIP): The common port is 5060 and the transport layer is TCP or UDP.

[0084] 2. Real-Time Protocol (RTP): The common port range is [16384, 32767] and the transport protocol is UDP.

[0085] 3. H.323: The common port is 1720 and the transport protocol is TCP.

[0086] Finally, there are multiple ways for the gateway device to perform malicious traffic analysis, which will be introduced separately below.

[0087] The first way: Matching malicious IP addresses.

[0088] The gateway device pre-stores a blacklist, which contains some malicious IP addresses. Malicious IP addresses are usually associated with known attack sources, botnets, or malicious actors. The gateway device can match the destination IP address of the target data packet with the malicious IP addresses in the blacklist. If the match is successful, it indicates that the target data packet is malicious traffic.

[0089] The second method: Detect abnormal behaviors.

[0090] The gateway device can also perform DPI analysis. By analyzing the packet header, data payload, etc. of the target data packet, potential attack features can be extracted to determine whether there are abnormal behaviors in the target data packet. If so, it indicates that the target data packet is malicious traffic.

[0091] For example, Distributed Denial of Service (DDoS) attacks and port scanning attacks. DDoS attacks are often accompanied by abnormal increases in traffic, especially a surge in traffic targeting specific targets. DDoS attacks can be identified through traffic pattern analysis. An attacker may scan the open ports of a system to find potential vulnerabilities. By detecting unconventional port access patterns, frequent requests, or scanning behaviors for a wide range of ports, port scanning attacks can be identified.

[0092] The third method: Identify signature codes.

[0093] Signature codes refer to specific patterns, strings, or behavioral characteristics in data packets. The gateway device can perform DPI analysis and, by analyzing the data packet content in detail, if a signature code is identified, it indicates that the target data packet is malicious traffic.

[0094] For example: Suppose a Trojan communicates with its command and control server (C2). Its signature code may be that the request contains a specific URL path, such as / update.php?cmd=run, or contains a specific identifier, such as X-Trojan-ID: 1234567.

[0095] In a possible embodiment, the gateway device includes a DPI analysis module. The DPI analysis module is responsible for traffic parsing, session management, and DPI analysis. The DPI session context is created through the dpi_if_call_ctx_create() function, and the DPI analysis results are stored in ct->layer7_id. The nf_conntrack events are listened to, and the session information is updated in real time. The core code is as Figure 4 shown.

[0096] S204. When the target data packet enters the target chain, at least one plugin is called in sequence according to the priority.

[0097] In the specific implementation process, multiple plugins may be registered on the PREROUTING chain and the FORWARD chain. For example, a malicious traffic detection plugin and a traffic statistics plugin are registered on the PREROUTING chain, and a traffic optimization plugin is registered on the FORWARD chain. When the target data packet enters the PREROUTING chain, at least one plugin registered on the PREROUTING chain is called in sequence according to the priority. When the target data packet enters the FORWARD chain, at least one plugin registered on the FORWARD chain is called in sequence according to the priority.

[0098] S205. At least one plugin processes the target data packet according to the analysis result.

[0099] In a possible embodiment, if the malicious traffic detection plugin determines that the target data packet is malicious traffic, the target data packet is discarded and a security alarm is triggered. If the malicious traffic detection plugin determines that the target data packet is not malicious traffic, the traffic optimization plugin optimizes the target data packet according to the traffic type.

[0100] In the specific implementation process, the malicious traffic detection plugin is called first. Based on the security detection result in the DPI analysis result, it is identified whether the target data packet is malicious traffic. If so, the target data packet is discarded through the DPI_DNY operation. Part of the code is as Figure 5 shown. If not, the traffic optimization plugin is called to further optimize the traffic.

[0101] In the embodiment of the present application, by combining the DPI technology and the plugin, malicious traffic is detected and intercepted in real time, various network attacks can be effectively identified and prevented, the network can be protected from malicious traffic intrusion, and the security and stability of the network can be guaranteed.

[0102] In a possible embodiment, the traffic optimization plugin optimizes the target data packet according to the traffic type, including:

[0103] If the traffic optimization plugin determines that the traffic type is voice traffic or video traffic, the priority of the target data packet is increased by modifying the DSCP value;

[0104] If the traffic optimization plugin determines that the traffic type is P2P traffic, the priority of the target data packet is decreased by modifying the DSCP value, and the bandwidth of the target data packet is restricted.

[0105] In the specific implementation process, Differentiated Services Code Point (DSCP) is a technology used for Quality of Service (QoS) management in IP packets, mainly used for priority marking of network traffic. It is embedded in the 6-bit DSCP field of the IP header and is used to identify the priority of traffic between routers and switches, thus supporting different processing methods for different types of traffic.

[0106] By modifying the DSCP value, the priority of video traffic can be increased, reducing lags and ensuring low latency and high-quality video playback. By modifying the DSCP value, the priority of voice traffic can be increased to ensure that voice traffic is processed preferentially to avoid impaired call quality. By modifying the DSCP value, the priority of P2P traffic can be reduced, and the bandwidth of P2P traffic can be restricted (limiting the maximum upload and download rates of P2P traffic) to ensure that it does not occupy too much bandwidth, thus preventing the bandwidth of other applications from being restricted.

[0107] The traffic optimization plugin can perform QoS optimization through dpi_set_qos() and dpi_set_dscp(), perform DSCP marking according to the DPI analysis result to control traffic priority, and process the DPI result through dpi_session_handing() to decide whether to perform NAT or QoS optimization. Some code is as Figure 6 shown.

[0108] In the embodiment of this application, based on the DPI analysis result, the DSCP value is dynamically adjusted to increase the priority of critical traffic, optimize the scheduling of network traffic, ensure the preferential transmission of critical traffic, and effectively improve network performance, reducing latency and packet loss. Combining QoS policies and feedback mechanisms can achieve flexible traffic management, ensure the reasonable allocation of network resources, and improve the reliability of critical applications.

[0109] In a possible embodiment, after the traffic optimization plugin optimizes the target data packet according to the traffic type, the method further includes:

[0110] If the traffic optimization plugin determines that the target data packet does not need to be redirected, it forwards the target data packet according to the target IP address; if the traffic optimization plugin determines that the target data packet needs to be redirected, it modifies the target IP address and forwards the target data packet according to the modified target IP address.

[0111] In the specific implementation process, the traffic optimization plugin determines whether the target data packet needs to be redirected according to the protocol type and the target IP address. For example, DNS hijacking: If the protocol type of the target data packet is DNS and the target IP address is 8.8.8.8, then the target data packet may be redirected to the internal network DNS. Or, for example, HTTP proxy: If the protocol type of the target data packet is HTTP, then the target data packet may be redirected to a transparent proxy.

[0112] In a possible embodiment, before the malicious traffic detection plugin determines that the target data packet is malicious traffic, discards the target data packet, and triggers a security alarm, the method further includes:

[0113] The traffic statistics plugin calculates the traffic proportion of different protocol types in the historical traffic according to the protocol type of the target data packet; the historical traffic includes the target data packet.

[0114] In the specific implementation process, the gateway device records the protocol type of each data packet in the historical traffic (including the target data packet) after each DPI analysis. The traffic statistics plugin can calculate the traffic proportion of each protocol type in the historical traffic based on the number of data packets of each protocol type, the data volume (number of bytes), or the traffic duration. The following introduces these several methods respectively.

[0115] Method 1: The ratio between the number of data packets of each protocol type and the number of data packets in the historical traffic can be calculated to obtain the traffic proportion of different protocol types.

[0116] Method 2: The ratio between the data volume (number of bytes) of each protocol type and the data volume (number of bytes) of the historical traffic can be calculated to obtain the traffic proportion of different protocol types.

[0117] Method 3: The ratio between the traffic duration of each protocol type and the traffic duration of the historical traffic can be calculated to obtain the traffic proportion of different protocol types.

[0118] In the embodiments of the present application, by using the plugin to calculate the traffic proportion of different protocol types in the historical traffic for traffic monitoring, it can help the administrator analyze the bandwidth usage situation, and then perform dynamic bandwidth adjustment in the network. If the traffic proportion of a certain protocol suddenly increases, traffic monitoring can help the administrator identify potential risks, so as to make adjustments or expansions in advance.

[0119] Please refer to Figure 7 , which is the schematic diagram of the processing flow of the plugin provided by the embodiments of the present application.

[0120] 1. Plugin registration: The plugin is registered using ctSgw_appRegisterFunc(), enabling the gateway device to know that this plugin can be used to process the traffic after DPI analysis.

[0121] 2. Gateway calls the plugin interface: When traffic arrives at the PREROUTING chain or the FORWARD chain, the gateway device calls the registered plugin.

[0122] 3. Plugin callback interface: The plugin receives traffic information and performs DPI analysis.

[0123] 4. Plugin performs traffic analysis: Based on the analysis results of DPI, the plugin performs corresponding processing, such as QoS optimization, discarding, modifying NAT rules, etc.

[0124] In summary, the present application provides a traffic processing method based on deep packet inspection, which has the following beneficial effects:

[0125] 1. Deep traffic analysis: Combining deep packet inspection technology, it can comprehensively analyze application layer data, identify potential security threats and abnormal traffic, and improve network security.

[0126] 2. Dynamic QoS management: Through DSCP settings, it can dynamically adjust the priority of traffic according to different application requirements and network status, effectively ensuring the bandwidth and latency requirements of critical applications.

[0127] 3. Flexible scalability: It supports user-defined plugins, allowing users to expand the packet processing logic according to different requirements to meet the network traffic management needs in different scenarios.

[0128] 4. Efficient connection management: Through the connection tracking mechanism, it can monitor the connection status in real time and perform different processing operations according to the connection type, improving the flexibility and efficiency of network traffic processing.

[0129] Based on the same inventive concept, the present application also provides a traffic processing device based on deep packet inspection, as Figure 8 shown. The device includes:

[0130] A plugin registration module, configured to receive registration requests of at least one plugin, and save the at least one plugin into an array corresponding to the target chain; wherein, the registration request includes the target chain; the target chain is the PREROUTING chain or the FORWARD chain;

[0131] A deep packet inspection analysis module, configured to extract session information from the target packet when the target packet enters the PREROUTING chain; perform deep packet inspection analysis according to the session information to obtain an analysis result;

[0132] The plug-in call module is used to sequentially call at least one plug-in according to a preset priority when a target data packet enters a target chain;

[0133] The plug-in processing module is used for at least one plug-in to process the target data packet according to the analysis result.

[0134] It should be noted that in this embodiment, each module in the traffic processing device based on deep packet inspection corresponds one-to-one to each step in the traffic processing method based on deep packet inspection in the foregoing embodiment. Therefore, the specific implementation manner of this embodiment can refer to the implementation manner of the foregoing traffic processing method based on deep packet inspection, which will not be elaborated here.

[0135] In addition, in one embodiment, the present application further provides a gateway device, which includes a processor, a memory, and a computer program stored in the memory. When the computer program is run by the processor, it implements the foregoing traffic processing method based on deep packet inspection.

[0136] In addition, in one embodiment, the present application further provides a computer storage medium, on which a computer program is stored. When the computer program is run by the processor, it implements the foregoing traffic processing method based on deep packet inspection.

[0137] In some embodiments, the computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, flash memory, magnetic surface memory, optical disc, or CD-ROM; or it may be various devices including one or any combination of the foregoing memories. The computer may be various computing devices including smart terminals and servers.

[0138] In some embodiments, the executable instructions may be in the form of a program, software, software module, script, or code, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including being deployed as an independent program or being deployed as a module, component, subroutine, or other unit suitable for use in a computing environment.

[0139] As an example, the executable instructions may or may not correspond to files in the file system, and may be stored as part of a file that stores other programs or data. For example, they may be stored in one or more scripts in a Hyper Text Markup Language (HTML) document, stored in a single file dedicated to the program being discussed, or stored in multiple cooperating files (for example, files that store one or more modules, subroutines, or code portions).

[0140] As an example, the executable instructions may be deployed to execute on one computing device, or on multiple computing devices located at one location, or on multiple computing devices distributed at multiple locations and interconnected by a communication network.

[0141] It should be noted that in this document, the terms "including", "comprising" or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article or system comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or system. Without further limitation, an element defined by the statement "comprising a..." does not exclude the presence of additional identical elements in the process, method, article or system comprising the element.

[0142] The serial numbers of the embodiments of the present application above are only for description and do not represent the superiority or inferiority of the embodiments.

[0143] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art can be embodied in the form of a software optical communication device. The computer software optical communication device is stored in a storage medium (such as a read-only memory / random access memory, magnetic disk, optical disk) and includes several instructions for causing a multimedia terminal device to execute the methods described in the various embodiments of the present application.

[0144] The above are only the preferred embodiments of the present application and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, is equally included in the patent protection scope of the present application.

Claims

1. A traffic processing method based on deep packet inspection, characterized in that Including: Receiving a registration request for at least one plugin, and saving the at least one plugin into an array corresponding to a target chain; wherein, the registration request includes the target chain; the target chain is a PREROUTING chain or a FORWARD chain; the PREROUTING hook is triggered when a data packet just enters the gateway device, and the FORWARD hook is triggered when the data packet is routed and determined to be forwarded; the gateway device supports the registration of multiple plugins, and each plugin provides different functions; When a target data packet enters the PREROUTING chain, extracting session information from the target data packet; Performing deep packet inspection analysis according to the session information to obtain an analysis result; When the target data packet enters the PREROUTING chain, sequentially calling at least one plugin registered on the PREROUTING chain according to the priority; when the target data packet enters the FORWARD chain, sequentially calling at least one plugin registered on the FORWARD chain according to the priority; The at least one plugin processes the target data packet according to the analysis result.

2. The traffic processing method based on deep packet inspection according to claim 1, wherein The session information includes an IP address, port information, and protocol information; The performing deep packet inspection analysis according to the session information to obtain an analysis result includes: Obtaining the protocol type of the target data packet according to the port information and the protocol information; Obtaining the traffic type of the target data packet according to the port information and the protocol information; Performing malicious traffic analysis according to the IP address to obtain a security detection result as to whether the target data packet is malicious traffic.

3. The traffic processing method based on deep packet inspection according to claim 2, wherein The at least one plugin includes a malicious traffic detection plugin and a traffic optimization plugin; The at least one plugin processes the target data packet according to the analysis result, including: If the malicious traffic detection plugin determines that the target data packet is malicious traffic, then discarding the target data packet and triggering a security alarm; If the malicious traffic detection plugin determines that the target data packet is not malicious traffic, then the traffic optimization plugin optimizes the traffic of the target data packet according to the traffic type.

4. The traffic processing method based on deep packet inspection according to claim 3, wherein The traffic optimization plugin optimizes the traffic of the target data packet according to the traffic type, including: If the traffic optimization plugin determines that the traffic type is voice traffic or video traffic, then improving the priority of the target data packet by modifying the DSCP value; If the traffic optimization plugin determines that the traffic type is P2P traffic, then reducing the priority of the target data packet by modifying the DSCP value and restricting the bandwidth of the target data packet.

5. The traffic processing method based on deep packet inspection according to claim 3, wherein The IP address includes a target IP address; After the traffic optimization plugin optimizes the traffic of the target data packet according to the traffic type, the method further includes: If the traffic optimization plugin determines that the target data packet does not need to be redirected, then forwarding the target data packet according to the target IP address; If the traffic optimization plugin determines that the target data packet needs to be redirected, then modifying the target IP address and forwarding the target data packet according to the modified target IP address.

6. The traffic processing method based on deep packet inspection according to claim 5, wherein Before the traffic optimization plugin determines that the target data packet does not need to be redirected and forwards the target data packet according to the target IP address, the method further includes: The traffic optimization plugin determines whether the target data packet needs to be redirected according to the protocol type and the target IP address.

7. The traffic processing method based on deep packet inspection according to claim 3, wherein The at least one plugin includes a traffic statistics plugin. Before the malicious traffic detection plugin determines that the target data packet is malicious traffic, discards the target data packet, and triggers a security alarm, the method further includes: The traffic statistics plugin counts the traffic proportion of different protocol types in the historical traffic according to the protocol type of the target data packet; the historical traffic includes the target data packet.

8. A traffic processing device based on deep packet inspection, characterized in that Including: A plugin registration module, configured to receive registration requests of at least one plugin, and save the at least one plugin into an array corresponding to a target chain; wherein the registration request includes the target chain; the target chain is a PREROUTING chain or a FORWARD chain; the PREROUTING hook is triggered when a data packet just enters the gateway device, and the FORWARD hook is triggered when the data packet is routed and determined to be forwarded; the gateway device supports registration of multiple plugins, and each plugin provides different functions; A deep packet detection and analysis module, configured to extract session information from the target data packet when the target data packet enters the PREROUTING chain; perform deep packet detection and analysis according to the session information to obtain an analysis result; A plugin invocation module, configured to sequentially invoke at least one plugin registered on the PREROUTING chain according to the priority when the target data packet enters the PREROUTING chain; and sequentially invoke at least one plugin registered on the FORWARD chain according to the priority when the target data packet enters the FORWARD chain; A plugin processing module, configured to process the target data packet by the at least one plugin according to the analysis result.

9. A gateway device, characterized in that, The gateway device includes a memory and a processor. A computer program is stored in the memory, and the processor executes the computer program to implement the traffic processing method based on deep packet detection according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and the processor executes the computer program to implement the traffic processing method based on deep packet detection according to any one of claims 1-7.

Citation Information

Patent Citations

  • Message processing method and device

    CN118174906A