Traffic analysis method and system of network communication equipment, electronic equipment and storage medium

By acquiring and organizing the transport layer protocol packets of network communication equipment, and combining flag information and multi-group information for traffic analysis, the problem of insufficient traffic analysis in the prior art is solved, and higher analysis accuracy and comprehensiveness are achieved.

CN120017551APending Publication Date: 2025-05-16GUANGZHOU GAOKE COMM TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510176450.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

In the prior art, it is difficult to accurately analyze data packets called by network communication devices in network communication, resulting in insufficient traffic analysis results and difficult to reflect the actual operating status of the network.

Method used

By obtaining the data packets that the network communication device calls the transport layer protocol, combining the flag information and multi-group information in the data packet, the registration information is sorted out, and traffic analysis is performed based on preset traffic analysis rules to obtain more accurate traffic analysis results.

Benefits of technology

It improves the accuracy and comprehensiveness of traffic analysis, can more accurately identify traffic characteristics of different service access, enhances coverage of network activities, and supports flexible traffic analysis requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017551A_ABST
    Figure CN120017551A_ABST
Patent Text Reader

Abstract

The invention discloses a traffic analysis method and system of network communication equipment, electronic equipment and a storage medium. The method comprises the following steps: acquiring a data packet of calling a transport layer protocol by the network communication equipment; an access result and access time are obtained according to mark information in the data packet, and then registration information is obtained by combining multi-element group information of calling a transport layer protocol; the multi-element group information comprises a source ip, a source port, a destination ip and a destination port for calling service access corresponding to the transport layer protocol and a protocol value corresponding to the transport layer protocol; and based on a preset traffic analysis rule, performing traffic analysis according to the registration information corresponding to all service accesses to obtain a traffic analysis result. According to the invention, the detailed registration information is obtained by acquiring the data packet of calling the transport layer protocol by the network communication equipment and arranging the data packet, so that a more comprehensive and accurate data basis is provided for flow analysis, the accuracy and comprehensiveness of flow analysis are improved, and the method can be widely applied to the technical field of data processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and in particular to a traffic analysis method, system, electronic device and storage medium for network communication equipment. Background Art

[0002] In network communications, understanding and analyzing the data packets that network communication devices call transport layer protocols is crucial for monitoring network traffic, optimizing network performance, and ensuring network security. Traditional traffic analysis methods often rely on simple packet capture and statistics, lacking detailed distinction and in-depth analysis of different service accesses. This results in inaccurate traffic analysis results that are difficult to accurately reflect the actual operation status of the network. Summary of the invention

[0003] The present invention aims to solve the problem of related technical limitations at least to a certain extent. To this end, the present invention proposes a traffic analysis method, system, electronic device and storage medium of a network communication device, which can accurately perform traffic analysis of the network communication device.

[0004] On the one hand, an embodiment of the present invention provides a traffic analysis method for a network communication device, comprising the following steps:

[0005] Obtaining data packets of transport layer protocols called by network communication devices;

[0006] The access result and access time are obtained according to the flag information in the data packet, and then the registration information is obtained by combining the multi-tuple information of the calling transport layer protocol; the multi-tuple information includes the source IP, source port, destination IP, destination port of the service access corresponding to the calling transport layer protocol and the protocol value corresponding to the transport layer protocol;

[0007] Based on the preset traffic analysis rules, traffic analysis is performed according to the registration information corresponding to all service accesses to obtain the traffic analysis results.

[0008] Optionally, when the transport layer protocol is the transmission control protocol; obtaining the access result according to the flag information in the data packet includes the following steps:

[0009] Determine whether the corresponding service access completes the three-way handshake mechanism based on the SYN message and ACK message in the data packet;

[0010] When the three-way handshake mechanism is completed, the access result is determined to be a successful access; otherwise, the access result is determined to be a failed access.

[0011] Optionally, when the transport layer protocol is the User Datagram Protocol, and the data packet is a protocol packet to be responded to; obtaining the access result according to the flag information in the data packet includes the following steps:

[0012] According to the port information involved in the response mechanism corresponding to the data packet, query whether the server corresponding to the destination port has a response packet;

[0013] When there is a response packet from the server corresponding to the destination port, the access result is determined to be a successful access; otherwise, the access result is determined to be a failed access.

[0014] Optionally, based on a preset traffic analysis rule, traffic analysis is performed according to registration information corresponding to all service accesses to obtain a traffic analysis result, including the following steps:

[0015] Filter and obtain all registration information corresponding to the target service access according to the multi-group information;

[0016] Determine the number of visits to the target service according to the number of registration information corresponding to the target service visits;

[0017] Based on the access volume and in combination with the access result in each registration information corresponding to the target service access, the access success rate of the target service access is obtained.

[0018] Optionally, based on a preset traffic analysis rule, traffic analysis is performed according to registration information corresponding to all service accesses to obtain a traffic analysis result, including the following steps:

[0019] Filter the access results of all registration information whose destination IP is the target device IP according to the multi-group information;

[0020] Determine the device access availability of the target device based on all access results corresponding to the target device IP as the destination IP;

[0021] When the destination IP is the target device IP and all access results corresponding to the IP are access failures, it is determined that the device access availability of the target device is unavailable.

[0022] Optionally, based on a preset traffic analysis rule, traffic analysis is performed according to registration information corresponding to all service accesses to obtain a traffic analysis result, including the following steps:

[0023] According to the preset time interval range, the registration information of each time interval range is obtained by access time statistics;

[0024] Determine the number of visits within the corresponding time interval according to the number of all registration information within each time interval;

[0025] When the number of visits in the time interval is greater than a first threshold, the corresponding time interval is determined to be a busy time period;

[0026] Based on the number of visits during the busy time period, the access success rate during the busy time period is obtained by combining the access results in each registration information during the busy time period.

[0027] When the access success rate during the busy time period is less than the second threshold, a reminder to expand the equipment service capacity is sent to the management personnel.

[0028] Optionally, based on a preset traffic analysis rule, traffic analysis is performed according to registration information corresponding to all service accesses to obtain a traffic analysis result, including the following steps:

[0029] According to the multi-group information and the access time, all the registration information whose source IP is the first device IP and whose destination IP is the second device IP within a preset time range is obtained by filtering;

[0030] For all registration information whose source IP is the first device IP and whose destination IP is the second device IP within a preset time range, statistics are performed on the number of destination ports and the percentage of access failures;

[0031] When the result of quantity statistics is greater than the third threshold and the result of proportion statistics is greater than the fourth threshold, it is determined that a port scanning attack occurs on the first device corresponding to the first device IP.

[0032] On the other hand, an embodiment of the present invention provides a traffic analysis system for a network communication device, including:

[0033] The first module is used to obtain the data packet of the transport layer protocol called by the network communication device;

[0034] The second module is used to obtain the access result and access time according to the flag information in the data packet, and then to obtain the registration information in combination with the multi-tuple information of the calling transport layer protocol; the multi-tuple information includes the source IP, source port, destination IP, destination port of the service access corresponding to the calling transport layer protocol and the protocol value corresponding to the transport layer protocol;

[0035] The third module is used to perform traffic analysis based on preset traffic analysis rules and registration information corresponding to all service accesses to obtain traffic analysis results.

[0036] On the other hand, an embodiment of the present invention provides an electronic device, including: a processor and a memory; the memory is used to store programs; the processor executes the program to implement the traffic analysis method of the above-mentioned network communication device.

[0037] On the other hand, an embodiment of the present invention provides a computer storage medium, in which a program executable by a processor is stored. When the program executable by the processor is executed by the processor, it is used to implement the traffic analysis method of the above-mentioned network communication device.

[0038] The embodiment of the present invention obtains a data packet of a network communication device calling a transport layer protocol; obtains the access result and access time according to the flag information in the data packet, and then obtains the registration information in combination with the multi-tuple information of calling the transport layer protocol; the multi-tuple information includes the source IP, source port, destination IP, destination port of the service access corresponding to the calling transport layer protocol, and the protocol value corresponding to the transport layer protocol; based on the preset traffic analysis rules, traffic analysis is performed according to the registration information corresponding to all service accesses to obtain the traffic analysis result. The embodiment of the present invention includes the following beneficial effects:

[0039] 1. Improve the accuracy of traffic analysis: By combining the flag information in the data packet and the multi-tuple information of the transport layer protocol call, the traffic characteristics of different service accesses can be more accurately identified, thereby improving the accuracy of traffic analysis.

[0040] 2. Enhance the comprehensiveness of traffic analysis: Registration information includes multiple dimensions such as the source IP, source port, destination IP, destination port, and transport layer protocol of service access, so that traffic analysis can cover a wider range of network activities and enhance the comprehensiveness of the analysis.

[0041] 3. Flexibility in supporting traffic analysis: Based on preset traffic analysis rules, registration information can be flexibly processed and analyzed according to actual needs to meet traffic analysis needs in different scenarios.

[0042] In summary, the present invention obtains data packets of transport layer protocols called by network communication devices and organizes them to obtain detailed registration information, thereby providing a more comprehensive and accurate data basis for traffic analysis, thereby improving the accuracy and comprehensiveness of traffic analysis. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] The accompanying drawings are used to provide a further understanding of the technical solution of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the technical solution of the present invention and do not constitute a limitation on the technical solution of the present invention.

[0044] Figure 1 It is a schematic diagram of an implementation environment for performing traffic analysis of a network communication device provided by an embodiment of the present invention;

[0045] Figure 2 It is a flow chart of a method for analyzing traffic of a network communication device provided by an embodiment of the present invention;

[0046] Figure 3 A flow chart of a flow collection example provided in an embodiment of the present invention;

[0047] Figure 4 A schematic diagram of an example of registration information provided by an embodiment of the present invention;

[0048] Figure 5 A schematic diagram of a flow analysis example provided by an embodiment of the present invention;

[0049] Figure 6 A schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0050] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0051] It should be noted that, although the functional modules are divided in the system schematic diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the system or the order in the flowchart. The terms "first / S100", "second / S200", etc. in the specification, claims and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0052] Reference to "embodiments" herein means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present invention. The appearance of the phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0053] It is understandable that the traffic analysis method of the network communication device provided in the embodiment of the present invention can be applied to any computer device with data processing and computing capabilities, and this computer device can be various types of terminals or servers. When the computer device in the embodiment is a server, the server is an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. Optionally, the terminal is a smart phone, a tablet computer, a laptop computer, a desktop computer, etc., but is not limited to this.

[0054] like Figure 1 FIG. 1 is a schematic diagram of an implementation environment provided by an embodiment of the present invention. Figure 1The implementation environment includes at least one terminal 102 and a server 101. The terminal 102 and the server 101 can be connected to a network wirelessly or wired to complete data transmission and exchange.

[0055] Server 101 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), as well as big data and artificial intelligence platforms.

[0056] In addition, the server 101 can also be a node server in the blockchain network. Blockchain is a new application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithm.

[0057] The terminal 102 may be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, etc., but is not limited thereto. The terminal 102 and the server 101 may be directly or indirectly connected via wired or wireless communication, which is not limited in the embodiment of the present invention.

[0058] Based on the example Figure 1 In the implementation environment shown, an embodiment of the present invention provides a traffic analysis method for a network communication device. The following is explained using the example of the traffic analysis method of the network communication device being applied in the server 101. It can be understood that the traffic analysis method of the network communication device can also be applied in the terminal 102.

[0059] Reference Figure 2 , Figure 2 The flow chart of the method for analyzing the traffic of a network communication device applied to a server provided in an embodiment of the present invention, the execution subject of the method for analyzing the traffic of the network communication device can be any of the aforementioned computer devices (including a server or a terminal). Figure 2 , the method comprises the following steps:

[0060] S100, obtaining a data packet of a network communication device calling a transport layer protocol;

[0061] S200, obtaining access results and access time according to the flag information in the data packet, and then combining the multi-tuple information of the calling transport layer protocol to obtain registration information;

[0062] The tuple information includes the source IP, source port, destination IP, destination port and protocol value corresponding to the transport layer protocol for accessing the service corresponding to the transport layer protocol;

[0063] It should be noted that, in some embodiments, when the transport layer protocol is the Transmission Control Protocol; obtaining the access result based on the flag information in the data packet may include the following steps: determining whether the corresponding service access completes the three-way handshake mechanism based on the SYN message and ACK message in the data packet; when the three-way handshake mechanism is completed, determining that the access result is a successful access, otherwise, determining that the access result is an access failure.

[0064] Exemplarily, in some specific implementations, for the TCP protocol (protocol value 6), by analyzing the SYN and ACK messages in the TCP packet, it is confirmed whether the TCP three-way handshake mechanism is completed normally. If normal, the quintuple (quintuple: source IP, source port, destination IP, destination port, protocol value) at that time point is recorded as +1 for normal access, otherwise the quintuple access is recorded as -1, and the registration information includes the quintuple and the access time.

[0065] Specifically, the three-way handshake process of the TCP message is as follows:

[0066] First handshake: The client sends a SYN segment to the server, indicating that it wants to establish a connection. This segment contains a randomly selected initial sequence number (ISN)

[0067] Second handshake: After receiving the SYN segment from the client, the server sends a SYN-ACK segment as a response. In this segment, the server's SYN and ACK flags are both set to 1, and the confirmation number is the client's initial sequence number plus 1. The server selects an initial sequence number.

[0068] The third handshake: After the client receives the SYN-ACK segment from the server, it sends an ACK segment as confirmation. In this segment, the confirmation number is the server's initial sequence number plus 1, and the client enters the ESTABLISHED state. After the server receives this ACK segment, it also enters the ESTABLISHED state. At this time, the TCP connection is successfully established and both parties can start data transmission.

[0069] According to the three-way handshake process, by analyzing the correspondence between the sequence number and the SYN and ACK of the flags, it can be determined whether it is completed normally, as follows:

[0070] We will record the initial sequence number of the SYN message sent by the client to initiate the connection. We need to confirm whether the confirmation number of the SYN-ACK message sent by the server in response to the connection is +1 on the original SYN message. If it is, it is a normal ACK message, and then record the sequence number of the connection.

[0071] When we receive the ACK message from the client, we confirm whether the confirmation number is the sequence number of the above server + 1. If so, we consider that the three-way handshake has been completed normally.

[0072] Access that does not go through the three-way handshake process is considered not a normal three-way handshake access. After the three-way handshake is completed, even if other signs such as FIN messages are received, it is considered that a normal TCP connection has been completed.

[0073] The three-way handshake needs to consider the timeout. In the network, even if the network delay is long, it is still in the millisecond level. Here, it is considered that if the SYN message is initiated from the client and the three-way handshake connection is not completed within 3 seconds, it is considered an abnormal access situation. Even if the handshake mechanism is actually completed after 3 seconds, it is too slow for the communication network, and this situation is also considered an abnormal situation. Therefore, it is reasonable to set a time of 3 seconds to detect whether the handshake mechanism is completed normally.

[0074] It should be noted that, in some embodiments, when the transport layer protocol is the User Datagram Protocol, the data packet is a protocol packet to be responded to; obtaining the access result according to the flag information in the data packet may include the following steps: querying whether there is a response packet from the server corresponding to the destination port according to the port information involved in the response mechanism corresponding to the data packet; when there is a response packet from the server corresponding to the destination port, determining that the access result is a successful access, otherwise, determining that the access result is a failed access.

[0075] For example, in some specific implementations, there is a request and response mechanism for UDP protocol (protocol value 17) and DNS protocol. This requires parsing the message according to the specific protocol, registering the quintuple with +1 for normal access and -1 for abnormal access. There are also protocols such as syslog log remote reporting that do not require a response, and no abnormal statistics are made for this.

[0076] For example, the parsing of the request and response of the DNS protocol message: if the parsing is sent to UDP port 53 (the service port of the DNS protocol), that is, the destination port is 53 and the query bit of the flags field in the message is set to 1, then it is considered that a DNS query has been initiated. This is a DNS query message. If there is a response message UDP message from the DNS server within 3 seconds, the source port is the service port 53, the destination port is the same as the port number of the original query message, and the response field in the flags message is set to 1, we believe it is a DNS response message, and it is a response to the above DNS query message. Here, this access is considered a normal access.

[0077] In addition, TFTP also requires a UDP message to respond, and you can determine whether it is a response message by analyzing the port number.

[0078] S300: Based on preset traffic analysis rules, traffic analysis is performed according to registration information corresponding to all service accesses to obtain traffic analysis results.

[0079] It should be noted that, in some embodiments, step S300 may include the following steps: filtering all registration information corresponding to the target service access based on the multi-group information; determining the number of visits to the target service access based on the number of registration information corresponding to the target service access; based on the number of visits, combining the access results in each registration information corresponding to the target service access to obtain the access success rate of the target service access.

[0080] For example, in some specific implementations, the access volume and success rate of service access are analyzed. For each specific service, there is a specific port number, such as telnet uses port 23 and uses the TCP protocol (protocol value 6). According to the number of normal accesses and the number of failed accesses in the 5-tuple record of the retrieval record with the port number 23, the protocol value 6, and the destination IP as the device IP, the access volume and the access success rate can be obtained. If the access success rate is relatively low, it is necessary to find the reason for the low success rate and deal with it.

[0081] It should be noted that, in some embodiments, step S300 may include the following steps: obtaining access results of all registration information whose destination IP is the target device IP based on multi-group information screening; determining the device access availability of the target device based on all access results corresponding to the destination IP being the target device IP; wherein, when all access results corresponding to the destination IP being the target device IP are access failures, determining the device access availability of the target device is unavailable.

[0082] For example, in some specific implementations, the availability of device access is analyzed. For a certain device IP, if all accesses to it with the destination IP being the IP in the quintuple of accesses fail, it is likely that the device is unavailable, and the specific reason needs to be found based on the device IP.

[0083] It should be noted that, in some embodiments, step S300 may include the following steps: according to a preset time interval range, obtaining registration information for each time interval range through access time statistics; determining the number of visits for the corresponding time interval range according to the number of all registration information within each time interval range; when the number of visits for the time interval range is greater than a first threshold, determining that the corresponding time interval range is a busy time period; based on the number of visits for the busy time period, combining the access result statistics in each registration information within the busy time period, obtaining the access success rate for the busy time period; wherein, when the access success rate for the busy time period is less than the second threshold, issuing a device service expansion reminder to the management personnel.

[0084] For example, in some specific implementations, the access success rate during busy time periods is analyzed. According to the generation time of each statistic, the number of visits and the number of successful and failed visits every 10 minutes in a day can be counted, and it can be seen whether the access success rate is relatively low during busy time points (i.e., points with more visits). If the success rate is low at points with more visits, it is necessary to improve the overall performance of the device, or expand the capacity of the device service to improve the success rate.

[0085] It should be noted that, in some embodiments, step S300 may include the following steps: filtering according to the multi-tuple information and the access time to obtain all registration information whose source IP is the first device IP and whose destination IP is the second device IP within a preset time range; performing statistics on the number of destination ports and the proportion of access results of failed access for all registration information whose source IP is the first device IP and whose destination IP is the second device IP within the preset time range; when the result of the quantity statistics is greater than the third threshold and the result of the proportion statistics is greater than the fourth threshold, it is determined that a port scanning attack exists on the first device corresponding to the first device IP.

[0086] For example, in some specific implementations, it is analyzed whether there is a port scanning attack. Within each 10-minute time range, the number of port numbers corresponding to each access source IP accessing the same device is counted. If the port number exceeds 50 and the failure rate exceeds 20%, it is considered that hackers are scanning which port numbers of this device are available and may use the open ports to attack. The source IP needs to be added to the blacklist.

[0087] In order to explain the principle of the technical solution of the present invention in detail, the overall process of the present invention is described below in combination with some specific embodiments. It is easy to understand that the following is an explanation of the technical principle of the present invention and cannot be regarded as a limitation of the present invention.

[0088] First of all, it should be noted that the traffic of the device is usually not analyzed or utilized comprehensively, and is only used to observe the service traffic and monitor whether the service is normal. In view of this, an embodiment of the present invention provides a traffic analysis method for a network communication device, which can be implemented as follows:

[0089] 1. Traffic collection:

[0090] (1) Figure 3 and Figure 4 As shown, for the TCP protocol (protocol value 6), by analyzing the SYN and ACK messages in the TCP packet, confirm whether the TCP three-way handshake mechanism is completed normally. If normal, record the normal access +1 of the quintuple (quintuple: source IP, source port, destination IP, destination port, protocol value) at this time point, otherwise record the quintuple access -1, and the registration information includes the quintuple and access time.

[0091] The three-way handshake process of TCP message is as follows:

[0092] First handshake: The client sends a SYN segment to the server, indicating that it wants to establish a connection. This segment contains a randomly selected initial sequence number (ISN)

[0093] Second handshake: After receiving the SYN segment from the client, the server sends a SYN-ACK segment as a response. In this segment, the server's SYN and ACK flags are both set to 1, and the confirmation number is the client's initial sequence number plus 1. The server selects an initial sequence number.

[0094] The third handshake: After the client receives the SYN-ACK segment from the server, it sends an ACK segment as confirmation. In this segment, the confirmation number is the server's initial sequence number plus 1, and the client enters the ESTABLISHED state. After the server receives this ACK segment, it also enters the ESTABLISHED state. At this time, the TCP connection is successfully established and both parties can start data transmission.

[0095] According to the three-way handshake process, by analyzing the correspondence between the sequence number and the SYN and ACK of the flags, it can be determined whether it is completed normally, as follows:

[0096] We will record the initial sequence number of the SYN message sent by the client to initiate the connection. We need to confirm whether the confirmation number of the SYN-ACK message sent by the server in response to the connection is +1 on the original SYN message. If it is, it is a normal ACK message, and then record the sequence number of the connection.

[0097] When we receive the ACK message from the client, we confirm whether the confirmation number is the sequence number of the above server + 1. If so, we consider that the three-way handshake has been completed normally.

[0098] Access that does not go through the three-way handshake process is considered not a normal three-way handshake access. After the three-way handshake is completed, even if other signs such as FIN messages are received, it is considered that a normal TCP connection has been completed.

[0099] The three-way handshake needs to consider the timeout. In the network, even if the network delay is long, it is still in the millisecond level. Here, it is considered that if the SYN message is initiated from the client and the three-way handshake connection is not completed within 3 seconds, it is considered an abnormal access situation. Even if the handshake mechanism is actually completed after 3 seconds, it is too slow for the communication network, and this situation is also considered an abnormal situation. Therefore, it is reasonable to set a time of 3 seconds to detect whether the handshake mechanism is completed normally.

[0100] (2) Figure 3 and Figure 4As shown, for the UDP protocol (protocol value 17), there is a request and response mechanism for protocols such as DNS. This requires parsing the message according to the specific protocol, registering the quintuple normal access +1, abnormal access -1. There are also protocols such as syslog log remote reporting that do not require a response, and no abnormal statistics are made for this.

[0101] For example, the parsing of the request and response of the DNS protocol message: if the parsing is sent to UDP port 53 (the service port of the DNS protocol), that is, the destination port is 53 and the query bit of the flags field in the message is set to 1, then it is considered that a DNS query has been initiated. This is a DNS query message. If there is a response message UDP message from the DNS server within 3 seconds, the source port is the service port 53, the destination port is the same as the port number of the original query message, and the response field in the flags message is set to 1, we believe it is a DNS response message, and it is a response to the above DNS query message. Here, this access is considered a normal access.

[0102] In addition, TFTP also requires a UDP message to respond, and you can determine whether it is a response message by analyzing the port number.

[0103] 2. Traffic analysis (such as Figure 5 shown):

[0104] (1) Analyze the number of visits and the success rate of service access. Each specific service has a specific port number. For example, telnet uses port 23 and the TCP protocol (protocol value 6). Based on the number of normal visits and the number of failed visits in the 5-tuple record of the retrieval record with the port number 23, the protocol value 6, and the destination IP as the device IP, the number of visits and the success rate of the visits can be obtained. If the access success rate is relatively low, it is necessary to find the cause of the low success rate and deal with it.

[0105] In the above traffic collection stage, the three-way handshake mechanism has been used to distinguish normal access and access failure messages, and the five-tuple and access quantity are registered. We traverse the five-tuple records in the registration records, and find the five-tuple records that meet the destination IP as the statistical device IP, the destination port number as the port number 23, and the protocol as TCP, and accumulate the access records of successful access and the accumulated access failures. The total access records that meet the retrieval conditions are: accumulated successful access records + accumulated access failure records.

[0106] Success rate calculation: accumulated successful records / total retrieved records.

[0107] During the traffic analysis phase, there is no need to consider time windows, concurrent access, and other situations. The service itself should support concurrent access, and failures caused by concurrent access are also considered to be insufficiently robust services, so there is no need to consider these special situations.

[0108] (2) Analyze the availability of device access. For a certain device IP, if all accesses to it with the destination IP in the five-tuple of accesses to the device fail, it is likely that the device is unavailable, and the specific reason needs to be found based on the device IP.

[0109] All access to a certain IP address fails when the three-way handshake is not completed normally in the TCP packets collected from the traffic (see the above description on how to consider the three-way handshake to be completed normally), and the UDP packets that require a response (such as the DNS packets mentioned above) do not receive a normal response.

[0110] (3) Analyze the access success rate during busy time periods. Based on the generation time of each statistic, the number of visits and the number of successful and failed visits every 10 minutes of the day can be counted. This allows us to see whether the access success rate is relatively low during busy time points (i.e. points with a large number of visits). If the success rate is low at points with a large number of visits, we need to improve the overall performance of the device or expand the capacity of the device service to increase the success rate.

[0111] (4) Analyze whether there is a port scanning attack. In every 10-minute time range, count the number of port numbers corresponding to each source IP accessing the same device. If the port number exceeds 50 and the failure rate exceeds 20%, it is considered that hackers are scanning which port numbers are available on this device and may use the open ports to attack. The source IP needs to be added to the blacklist.

[0112] In the above traffic collection stage, there is already a three-way handshake mechanism to distinguish between normal access and access failure messages, and there is also a method of judging success and failure by analyzing the message content according to a specific UDP protocol such as the DNS protocol. In the five-tuple registered in the traffic analysis stage, by registering the access time and the five-tuple, we can analyze which ports are successfully accessed and which ports are failed when a source IP accesses the destination port number of the destination IP (i.e. the device IP) within every 10 minutes, and see if the total port number exceeds 50 and the failed port number exceeds 10 (50*20%). If so, it is considered a scanning attack. The difference between the UDP protocol and the TCP protocol needs to be considered, because the port is bound to the protocol, and the same port of different protocols is a different listener. Normal business access will not access many ports in a short period of time, nor should it fail to access many ports. Therefore, when these factors are superimposed, the source IP is not performing normal business access to the device. We believe that this situation should be a hacker scanning which ports the device has opened. Of course, the statistical duration, the number of ports counted, and the failure rate can be adjusted according to different device application scenarios.

[0113] In summary, whether network services are available, whether network devices are available, whether network service loads are overloaded, whether network failures are discovered in time, and whether attacks exist are all issues that require attention. The present invention aims to discover and resolve the above issues as early as possible by analyzing network traffic. By conducting statistics and analysis on the traffic of the device, it can be concluded that:

[0114] (1) Service access volume: distinguish which businesses or services are frequently used and need special attention, and which are less frequently used and have less traffic. Rationally adjust the capacity of the business to fully utilize the network bandwidth and improve network availability.

[0115] (2) The success rate of the service. If there are many failures, the cause needs to be found. If there are few visits but many failures, it is necessary to identify whether the failure is caused by network port scanning or normal access. In the latter case, it is necessary to find the implementation problems of the service and improve the service.

[0116] (3) Equipment availability. If access to a certain IP address fails, it means that the IP address is unavailable. You need to find the cause and replace the device.

[0117] (4) Equipment performance: If the access success rate is low during peak hours when the number of visits is high, the equipment needs to be expanded or its performance improved.

[0118] (5) The system can detect service unavailability and device unavailability through traffic analysis, and can detect faults in a timely manner, improve fault response efficiency, and reduce maintenance costs.

[0119] (6) Identify scanning port traffic and add it to the blacklist to prevent hacker attacks.

[0120] Compared with the prior art, the present invention has at least the following beneficial effects:

[0121] 1. By analyzing the network traffic passing through the device, we can understand the abnormal access to the service ports of each IP, such as consistent access failures, and determine service abnormalities.

[0122] 2. Count the access traffic and access success rate of each service as the basis for the network service load, confirm whether the service can handle the access volume and whether capacity expansion is needed.

[0123] 3. Identify abnormal attacks or scan traffic.

[0124] 4. Identify business usage and provide a basis for adjusting business network resource bandwidth.

[0125] 5. Identify equipment unavailability, detect faults early, and reduce fault response time and maintenance costs.

[0126] On the other hand, an embodiment of the present invention provides a traffic analysis system for a network communication device, which may include:

[0127] The first module is used to obtain the data packet of the transport layer protocol called by the network communication device;

[0128] The second module is used to obtain the access result and access time according to the flag information in the data packet, and then to obtain the registration information in combination with the multi-tuple information of the calling transport layer protocol; the multi-tuple information includes the source IP, source port, destination IP, destination port of the service access corresponding to the calling transport layer protocol and the protocol value corresponding to the transport layer protocol;

[0129] The third module is used to perform traffic analysis based on preset traffic analysis rules and registration information corresponding to all service accesses to obtain traffic analysis results.

[0130] The contents of the method embodiments of the present invention are all applicable to the device embodiments. The functions specifically implemented by the device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0131] On the other hand, an embodiment of the present invention further provides an electronic device, the electronic device comprising a memory and a processor, the memory storing a computer program, and the processor implementing the above-mentioned traffic analysis method of the network communication device when executing the computer program. The electronic device can be any intelligent terminal including a tablet computer, a car computer, etc.

[0132] It can be understood that the contents of the above method embodiments are all applicable to the present device embodiments, the functions specifically implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0133] like Figure 6 As shown, Figure 6 The hardware structure of an electronic device 1000 of another embodiment is illustrated. The electronic device 1000 includes:

[0134] The processor 1001 may be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (application-specific integrated circuit, aSIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present invention;

[0135] The memory 1002 may be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1002 may store an operating system and other application programs. When the technical solution provided in the embodiment of this specification is implemented by software or firmware, the relevant program code is stored in the memory 1002, and the processor 1001 calls and executes the network node population optimization method of the embodiment of the present invention;

[0136] Input / output interface 1003, used to implement information input and output;

[0137] The communication interface 1004 is used to realize the communication interaction between the device and other devices. The communication can be realized through a wired manner (such as USB, network cable, etc.) or a wireless manner (such as mobile network, WIFI, Bluetooth, etc.);

[0138] A bus 1005 , which transmits information between various components of the device (e.g., the processor 1001 , the memory 1002 , the input / output interface 1003 , and the communication interface 1004 );

[0139] The processor 1001 , the memory 1002 , the input / output interface 1003 and the communication interface 1004 are connected to each other in communication within the device via the bus 1005 .

[0140] The electronic device embodiments described above are merely illustrative, and the units described as separate components may or may not be physically separated, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0141] The contents of the method embodiments of the present invention are all applicable to the electronic device embodiments. The functions specifically implemented by the electronic device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0142] Another aspect of an embodiment of the present invention further provides a computer-readable storage medium, wherein the storage medium stores a program, and the program is executed by a processor to implement the above method.

[0143] It should be noted that the computer-readable medium shown in the embodiment of the present invention may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disk read-only memory (Compact Disc Read to Only Memory, CD to ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, a computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system, device or device. In the present invention, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer readable signal media may also be any computer readable medium other than computer readable storage media, which may send, propagate, or transmit programs for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer readable medium may be transmitted using any suitable medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0144] The contents of the method embodiments of the present invention are all applicable to the computer-readable storage medium embodiments. The functions specifically implemented by the computer-readable storage medium embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0145] The embodiment of the present invention also discloses a computer program product or a computer program, which includes a computer instruction stored in a computer-readable storage medium. A processor of a computer device can read the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes the above method.

[0146] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present invention. In this regard, each box in the flow chart or block diagram can represent a module, a program segment, or a part of a code, and the above-mentioned module, program segment, or a part of a code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flow chart, and the combination of the boxes in the block diagram or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0147] It should be noted that, although several modules of the device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to an embodiment of the present invention, the features and functions of two or more modules or units described above can be embodied in one module or unit. On the contrary, the features and functions of one module or unit described above can be further divided into being embodied by multiple modules or units.

[0148] Through the description of the above implementation, it is easy for those skilled in the art to understand that the example implementation described here can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the implementation of the present invention can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD to ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a touch terminal, or a network device, etc.) to execute the method according to the implementation of the present invention.

[0149] In some selectable embodiments, the function / operation mentioned in the block diagram may not occur in the order mentioned in the operation diagram. For example, depending on the function / operation involved, the two boxes shown in succession can actually be executed substantially simultaneously or the boxes can sometimes be executed in reverse order. In addition, the embodiment presented and described in the flow chart of the present invention is provided by way of example, for the purpose of providing a more comprehensive understanding of technology. The disclosed method is not limited to the operation and logic flow presented herein. Selectable embodiments are expected, wherein the order of various operations is changed and the sub-operation of a part for which is described as a larger operation is performed independently.

[0150] In addition, although the present invention is described in the context of functional modules, it should be understood that, unless otherwise specified, one or more of the functions and / or features can be integrated into a single physical device and / or software module, or one or more functions and / or features can be implemented in a separate physical device or software module. It is also understood that a detailed discussion of the actual implementation of each module is unnecessary for understanding the present invention. More specifically, in view of the properties, functions and internal relationships of the various functional modules in the device disclosed herein, the actual implementation of the module will be understood within the conventional skills of the engineer. Therefore, those skilled in the art can implement the present invention set forth in the claims without excessive experimentation using ordinary techniques. It is also understood that the specific concepts disclosed are merely illustrative and are not intended to limit the scope of the present invention, which is determined by the full scope of the appended claims and their equivalents.

[0151] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.

[0152] The logic and / or steps represented in the flowchart or otherwise described herein, for example, may be considered as an ordered list of executable instructions for implementing logical functions, and may be embodied in any computer-readable medium for use by an instruction execution device, apparatus or device (such as a computer-based device, a device including a processor, or other device that can fetch instructions from an instruction execution device, apparatus or device and execute the instructions), or in conjunction with such instruction execution device, apparatus or device. For purposes of this specification, "computer-readable medium" may be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution device, apparatus or device, or in conjunction with such instruction execution device, apparatus or device.

[0153] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering or, if necessary, processing in another suitable manner, and then stored in a computer memory.

[0154] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, a plurality of steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution device. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0155] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "examples", "specific examples", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.

[0156] Although the embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the claims and their equivalents.

[0157] The above is a specific description of the preferred implementation of the present invention, but the present invention is not limited to the embodiments. Those skilled in the art can make various equivalent modifications or substitutions without violating the spirit of the present invention. These equivalent modifications or substitutions are all included in the scope defined by the claims of the present invention.

Claims

1. A traffic analysis method for a network communication device, characterized in that: The following steps are involved: Obtaining data packets of transport layer protocols called by network communication devices; The access result and access time are obtained according to the flag information in the data packet, and then the registration information is obtained by combining the multi-tuple information of calling the transport layer protocol; the multi-tuple information includes the source IP, source port, destination IP, destination port of the service access corresponding to the transport layer protocol and the protocol value corresponding to the transport layer protocol; Based on the preset traffic analysis rules, traffic analysis is performed according to the registration information corresponding to all service accesses to obtain traffic analysis results.

2. The method for analyzing traffic of a network communication device according to claim 1, characterized in that: When the transport layer protocol is the transmission control protocol; obtaining the access result according to the flag information in the data packet comprises the following steps: Determine whether the corresponding service access completes the three-way handshake mechanism according to the SYN message and the ACK message in the data packet; When the three-way handshake mechanism is completed, the access result is determined to be an access success, otherwise, the access result is determined to be an access failure.

3. The method for analyzing traffic of a network communication device according to claim 1, characterized in that: When the transport layer protocol is the User Datagram Protocol, and the data packet is a protocol packet to be responded to; obtaining the access result according to the flag information in the data packet includes the following steps: Querying whether a server corresponding to a destination port has a response packet according to the port information involved in the response mechanism corresponding to the data packet; When the response packet exists in the server corresponding to the destination port, it is determined that the access result is a successful access; otherwise, it is determined that the access result is a failed access.

4. The method for analyzing traffic of a network communication device according to claim 1, characterized in that: The method of performing traffic analysis based on the preset traffic analysis rules and the registration information corresponding to all service accesses to obtain traffic analysis results includes the following steps: Filtering according to the multi-tuple information to obtain all the registration information corresponding to the target service access; Determine the number of visits to the target service according to the number of the registration information corresponding to the visit to the target service; Based on the access volume and in combination with the access result in each of the registration information corresponding to the target service access, the access success rate of the target service access is obtained by statistics.

5. The method for analyzing traffic of a network communication device according to claim 1, characterized in that: The method of performing traffic analysis based on the preset traffic analysis rules and the registration information corresponding to all service accesses to obtain traffic analysis results includes the following steps: The access result of all the registration information where the destination IP is the target device IP is obtained by filtering the multi-tuple information; Determine the device access availability of the target device according to all the access results corresponding to the target device IP being the destination IP; When the destination IP is the target device IP and all the access results corresponding to the target device IP are access failures, it is determined that the device access availability of the target device is unavailable.

6. The method for analyzing traffic of a network communication device according to claim 1, characterized in that: The method of performing traffic analysis based on the preset traffic analysis rules and the registration information corresponding to all service accesses to obtain traffic analysis results includes the following steps: According to a preset time interval range, obtaining the registration information of each time interval range through the access time statistics; Determine the number of visits within the corresponding time interval according to the number of all the registration information within each time interval; When the access volume in the time interval is greater than a first threshold, determining that the corresponding time interval is a busy time period; Based on the access volume in the busy time period, and in combination with the access result in each of the registration information in the busy time period, obtain the access success rate of the busy time period; When the access success rate in the busy time period is less than a second threshold, a device service expansion reminder is sent to the management personnel.

7. The method for analyzing traffic of a network communication device according to claim 1, characterized in that: The method of performing traffic analysis based on the preset traffic analysis rules and the registration information corresponding to all service accesses to obtain traffic analysis results includes the following steps: Filtering according to the multi-group information and the access time to obtain all the registration information within a preset time range in which the source IP is the first device IP and the destination IP is the second device IP; For all the registration information in the preset time range where the source IP is the first device IP and the destination IP is the second device IP, statistics are performed on the number of destination ports and the proportion of access results that are access failures; When the result of the quantity statistics is greater than the third threshold and the result of the proportion statistics is greater than the fourth threshold, it is determined that a port scanning attack occurs on the first device corresponding to the first device IP.

8. A traffic analysis system for a network communication device, characterized in that: include: The first module is used to obtain the data packet of the transport layer protocol called by the network communication device; The second module is used to obtain the access result and access time according to the flag information in the data packet, and then to obtain the registration information in combination with the multi-tuple information of calling the transport layer protocol; the multi-tuple information includes the source IP, source port, destination IP, destination port of the service access corresponding to the transport layer protocol and the protocol value corresponding to the transport layer protocol; The third module is used to perform traffic analysis based on the registration information corresponding to all service accesses based on preset traffic analysis rules to obtain traffic analysis results.

9. An electronic device, characterized in that: including a processor and a memory; The memory is used to store programs; The processor executes the program to implement the method according to any one of claims 1 to 7.

10. A computer storage medium storing a program executable by a processor, characterized in that: The program executable by the processor is used to implement the method according to any one of claims 1 to 7 when executed by the processor.