Method and device for acquiring real address port information of client

By analyzing TCP SYN messages and hijacking getpeername function calls, obtaining the client's real IP and port information, the problem that the server cannot obtain the real IP address is solved, and a high stability and compatibility client information acquisition method is realized, simplifying the deployment process.

CN120075196APending Publication Date: 2025-05-30HANGZHOU DPTECH TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510231809.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing technology changes the source IP address through SNAT in server load balancing, resulting in the server being unable to directly obtain the client's real IP and port information, and requires the compilation of the kernel TOA module, which is very complex and has a dependency on the kernel version, which affects the system stability and deployment difficulty.

Method used

By obtaining and parsing TCP SYN messages, extracting quadruple information and the client's real IP address and port information, the association is stored in the preset table, and hijacking the application's call to the getpeername function, generating a query request to obtain the real IP and port information, and returning it to the application.

Benefits of technology

It realizes that without compiling the kernel TOA module, obtaining the real IP address and port information of the client, improving system stability and compatibility, simplifying the deployment process, and reducing implementation costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120075196A_ABST
    Figure CN120075196A_ABST
Patent Text Reader

Abstract

The invention relates to a method and a device for acquiring real address port information of a client. The method comprises the following steps: acquiring and analyzing a TCP SYN message to extract tetrad information and a real IP address and port information of a client; associatively storing the tetrad information, the real IP address and the port information in a preset table; calling of the getpeername function by the application program is hijacked, and a query request is generated; analyzing the query request to obtain tetrad information to be queried; querying the preset table according to the tetrad information to obtain a real IP address and port information of the client; and returning the real IP address and port information of the client to the application program to replace the original return value of the getpeername function. According to the method, the real IP address and the port information of the client can be obtained on the server without compiling a kernel TOA module, and higher stability and higher compatibility are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer information processing, and more particularly, to a method and apparatus for obtaining client real address and port information. Background Art

[0002] Server Load Balancing is a technology used to optimize performance, improve reliability, and enhance scalability. It distributes the workload (such as network traffic, data requests, computing tasks, etc.) to multiple computing resources to prevent a single server from being overloaded, thereby improving the overall system performance and availability. In a high-traffic environment, load balancing devices typically use SNAT (Source Network Address Translation) and DNAT (Destination Network Address Translation) technologies. When a user accesses a load balancing IP (such as 115.39.19.22), the load balancing device selects a real server (such as rs1, rs2, rs3) according to an algorithm and performs the following address conversion: the destination IP address is changed to the real server IP; the source IP address is changed to the load balancing device's IP (such as 192.168.0.100).

[0003] Since SNAT changes the source IP address, in the network requests received by the real server, the source address has been modified, and the IP recorded in the server log is not the real client's IP address, resulting in the server being unable to directly obtain the real IP and port information of the client.

[0004] In the existing technical solutions, in order to pass the client IP to the server, the client IP address and source port are inserted into the TCP Option on the load balancing device. On the real server, the TOA module extracts the real IP address and port of the user. The TOA kernel module first calls the original tcp_v4_syn_recv_sock function, and then calls the get_TOA_data function to extract the TOAOPTION from the TCPOPTION and store it in the sk_user_data field. When the user state calls inet_getname to obtain the source address and port, if the source IP address and port exist in the sk_user_data field, the real IP and Port are extracted from it and directly returned; otherwise, the source IP address and port saved by the kernel are returned.

[0005] The existing solutions require compiling the kernel TOA module, installing a compilation environment. Compiling kernel modules is difficult and relatively complex, and is dependent on the kernel version. When the kernel is modified, the TOA module may also need to be modified. If there are bugs in the TOA itself, it may cause the system to crash, having a certain impact on system stability. Additionally, if the kernel versions of servers are different, or even if they are the same but there are numerous Linux distribution versions, all need to be compiled, which also increases the workload for deployment.

[0006] Therefore, a new method and device for obtaining the real address and port information of a client are needed.

[0007] The above information disclosed in the background art section is only used to enhance the understanding of the background of the present application. Therefore, it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0008] In view of this, the present application provides a method and device for obtaining the real IP address and port information of a client, which can obtain the real IP address and port information of the client on the server without compiling the kernel TOA module. Compared with the existing solutions based on the kernel TOA module, the present application does not need to modify the kernel, has higher stability and stronger compatibility. In addition, the solution of the present application does not need to build a compilation environment, can directly distribute and run the program, realizes rapid deployment, and reduces the implementation cost.

[0009] Other features and advantages of the present application will become apparent through the following detailed description, or will be partially learned through the practice of the present application.

[0010] According to one aspect of the present application, a method for obtaining the real address and port information of a client is proposed. The method includes: obtaining and parsing a TCP SYN packet to extract quadruple information and the real IP address and port information of the client; associating and storing the quadruple information and the real IP address and port information in a preset table; hijacking the call of the getpeername function by an application program to generate a query request; parsing the query request to obtain the quadruple information to be queried; querying the preset table according to the quadruple information to obtain the real IP address and port information of the client; and returning the real IP address and port information of the client to the application program to replace the original return value of the getpeername function.

[0011] In an exemplary embodiment of the present application, obtaining and parsing a TCP SYN packet to extract quadruple information and the real IP address and port information of the client includes: creating a packet capture program and setting a filter to obtain a TCP SYN packet; parsing the TCP SYN packet to obtain quadruple information and TOA options; and extracting the real IP address and port information of the client through the TOA options.

[0012] In an exemplary embodiment of the present application, associating and storing the quadruple information with the real IP address and port information in a preset table includes: using the quadruple information as a key; using the real IP address and port information as a value; and associating and storing the quadruple information with the real IP address and port information in a preset hash table in the form of a key-value pair.

[0013] In an exemplary embodiment of the present application, hijacking the call of the getpeername function by an application program to generate a query request includes: hijacking the call of the getpeername function by the application program; obtaining the remote IP address, port, local IP address, and port; and generating the query request through the remote IP address, port, local IP address, and port.

[0014] In an exemplary embodiment of the present application, obtaining the remote IP address, port, local IP address, and port includes: obtaining the remote IP address and port through the original getpeername of libc; and calling getsockname to obtain the local IP address and port.

[0015] In an exemplary embodiment of the present application, parsing the query request to obtain the quadruple information to be queried includes: parsing the query request to obtain the remote IP address, port, local IP address, and port to be queried to form the quadruple information.

[0016] In an exemplary embodiment of the present application, querying the preset table according to the quadruple information to obtain the real IP address and port information of the client further includes: when the real IP address and port information of the client are not found, returning a preset invalid value.

[0017] In an exemplary embodiment of the present application, returning the real IP address and port information of the client to the application program to replace the original return value of the getpeername function includes: constructing a return value through the real IP address and port information of the client; and sending the return value to the application program through the getpeername function.

[0018] In an exemplary embodiment of the present application, returning the real IP address and port information of the client to the application program to replace the original return value of the getpeername function further includes: when a timeout occurs or a preset invalid value is received, sending the original return value of the getpeername of libc to the application program.

[0019] According to one aspect of the present application, a device for obtaining client real address and port information is provided. The device includes: a packet module, configured to obtain and parse TCP SYN packets to extract quadruple information and the real IP address and port information of the client; a storage module, configured to store the quadruple information and the real IP address and port information in association in a preset table; a hijacking module, configured to hijack the call of the getpeername function by the application program to generate a query request; a parsing module, configured to parse the query request to obtain the quadruple information to be queried; a query module, configured to query the preset table according to the quadruple information to obtain the real IP address and port information of the client; and a return module, configured to return the real IP address and port information of the client to the application program to replace the original return value of the getpeername function.

[0020] According to one aspect of the present application, an electronic device is provided. The electronic device includes: one or more processors; a storage device, configured to store one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the method as described above.

[0021] According to one aspect of the present application, a computer-readable medium is provided, on which a computer program is stored. When the program is executed by a processor, the method as described above is implemented.

[0022] According to the method and device for obtaining client real address and port information of the present application, by obtaining and parsing TCP SYN packets to extract quadruple information and the real IP address and port information of the client; storing the quadruple information and the real IP address and port information in association in a preset table; hijacking the call of the getpeername function by the application program to generate a query request; parsing the query request to obtain the quadruple information to be queried; querying the preset table according to the quadruple information to obtain the real IP address and port information of the client; and returning the real IP address and port information of the client to the application program to replace the original return value of the getpeername function, it is possible to obtain the real IP address and port information of the client on the server without compiling the kernel TOA module. Compared with the existing solution based on the kernel TOA module, the present application does not need to modify the kernel, has higher stability and stronger compatibility. In addition, the solution of the present application does not need to build a compilation environment, can directly distribute and run the program, realizes rapid deployment, and reduces the implementation cost.

[0023] It should be understood that the above general description and the following detailed description are only exemplary and do not limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] These and other objectives, features, and advantages of the present application will become more apparent by describing its exemplary embodiments in detail with reference to the accompanying drawings. The following described drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0025] Figure 1 is a flowchart of a method for obtaining client real address and port information according to an exemplary embodiment.

[0026] Figure 2 is a flowchart of a method for obtaining client real address and port information according to an exemplary embodiment.

[0027] Figure 3 is a flowchart of a method for obtaining client real address and port information according to another exemplary embodiment.

[0028] Figure 4 is a flowchart of a method for obtaining client real address and port information according to another exemplary embodiment.

[0029] Figure 5 is a block diagram of a device for obtaining client real address and port information according to an exemplary embodiment.

[0030] Figure 6 is a block diagram of an electronic device according to an exemplary embodiment.

[0031] Figure 7 is a block diagram of a computer-readable medium according to an exemplary embodiment. Detailed Embodiments

[0032] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided so that this application will be thorough and complete, and will fully convey the concept of the example embodiments to those skilled in the art. Identical reference numerals in the figures denote identical or similar parts, and thus their repeated description will be omitted.

[0033] In addition, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present application. However, those skilled in the art will realize that the technical solutions of the present application can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. can be adopted. In other cases, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of the present application.

[0034] The block diagrams shown in the drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor devices and / or microcontroller devices.

[0035] The flowcharts shown in the drawings are only illustrative and not necessarily include all the content and operations / steps, nor are they necessarily executed in the described order. For example, some operations / steps can be decomposed, while some operations / steps can be combined or partially combined, so the actual execution order may change according to the actual situation.

[0036] It should be understood that although terms such as first, second, and third may be used herein to describe various components, these components should not be limited by these terms. These terms are used to distinguish one component from another. Therefore, the first component discussed below can be referred to as the second component without departing from the teachings of the concept of the present application. As used herein, the term "and / or" includes any one of the associated listed items and all combinations of one or more of them.

[0037] Those skilled in the art can understand that the drawings are only schematic diagrams of exemplary embodiments, and the modules or processes in the drawings are not necessarily essential for implementing the present application, so they cannot be used to limit the protection scope of the present application.

[0038] The technical abbreviations related to the present application are explained as follows:

[0039] TCP Option: In addition to the fixed 20 bytes of the TCP header, an OPTION field is also set to store custom data. The maximum length of the Option field is 40 bytes. The content format of Option is in the format of (identification field - length - data). Generally, it is stored in 4-byte alignment.

[0040] Load balancing: That is, the access traffic or tasks are evenly guided to multiple servers or network devices for processing, so as to achieve the purpose of improving the bandwidth of devices and servers, increasing throughput, enhancing data processing capabilities, and improving the availability and stability of services.

[0041] NAT technology: NAT (Network Address Translation) was proposed in 1994. When some hosts inside a private network have already been assigned local IP addresses (i.e., private addresses only used within this private network), but now they want to communicate with hosts on the Internet, the NAT method can be used.

[0042] Figure 1It is a flowchart of a method for obtaining client real address and port information shown according to an exemplary embodiment. The method 10 for obtaining client real address and port information at least includes steps S102 to S112.

[0043] As Figure 1 shown, in S102, obtain and parse a TCP SYN packet to extract quadruple information and the real IP address and port information of the client. For example, create a packet capture program and set a filter to obtain the TCP SYN packet; parse the TCP SYN packet to obtain quadruple information and TOA options; extract the real IP address and port information of the client through the TOA options.

[0044] In S104, associate and store the quadruple information and the real IP address and port information in a preset table. For example, use the quadruple information as the key; use the real IP address and port information as the value; associate and store the quadruple information and the real IP address and port information in a preset hash table in the form of a key-value pair.

[0045] In S106, hijack the application's call to the getpeername function to generate a query request. For example, hijack the application's call to the getpeername function; obtain the remote IP address, port and local IP address, port; generate the query request through the remote IP address, port and local IP address, port.

[0046] More specifically, the remote IP address and port can be obtained through the original getpeername of libc; the local IP address and port can be obtained by calling getsockname.

[0047] In S108, parse the query request to obtain the quadruple information to be queried. The query request can be parsed to obtain the remote IP address, port and local IP address, port to be queried to form quadruple information.

[0048] In S110, query the preset table according to the quadruple information to obtain the real IP address and port information of the client. For example, when the real IP address and port information of the client are not found, return a preset invalid value.

[0049] In S112, return the real IP address and port information of the client to the application to replace the original return value of the getpeername function. For example, construct a return value through the real IP address and port information of the client; send the return value to the application through the getpeername function.

[0050] In one embodiment, for example, when a timeout occurs or a preset invalid value is received, the original return value of the libc's getpeername is sent to the application program.

[0051] According to the method for obtaining client real address and port information of the present application, by obtaining and parsing TCP SYN packets to extract quadruple information and the real IP address and port information of the client; associating and storing the quadruple information and the real IP address and port information in a preset table; hijacking the application program's call to the getpeername function to generate a query request; parsing the query request to obtain the quadruple information to be queried; querying the preset table according to the quadruple information to obtain the real IP address and port information of the client; and returning the real IP address and port information of the client to the application program in a manner that replaces the original return value of the getpeername function, it is possible to obtain the real IP address and port information of the client on the server without compiling the kernel TOA module. Compared with the existing kernel TOA module-based solution, the present application does not require modifying the kernel, has higher stability and stronger compatibility. In addition, the solution of the present application does not require setting up a compilation environment, can directly distribute and run the program, realizes rapid deployment, and reduces the implementation cost.

[0052] It should be clearly understood that the present application describes how to form and use specific examples, but the principles of the present application are not limited to any details of these examples. On the contrary, based on the teachings of the content disclosed in the present application, these principles can be applied to many other embodiments.

[0053] In actual applications, to implement the technology in the present application, it can be achieved by starting a TOA management process and creating two threads in this process. More specifically, one thread is used to capture and parse the TOA option in the TCP SYN packet to extract the real source IP address and source port of the client; the other thread is used to process the TOA query request. At the same time, by using the LD_PRELOAD environment variable of the Linux system, the getpeername function in the libc library in the program is hijacked and replaced with a custom function. This custom function will initiate a TOA query request to the TOA management process, thereby obtaining the real IP address and port information of the client.

[0054] LD_PRELOAD is an environment variable in the Linux system, which can affect the loading order of dynamic link libraries when a program runs. Through LD_PRELOAD, a specified dynamic link library can be preferentially loaded, even overriding the system's default function library. This function is mainly used to selectively replace functions in the dynamic link library. In this application, using the LD_PRELOAD mechanism, the custom getpeername function is preloaded into the program to achieve the replacement of the original getpeername function.

[0055] In practical applications, the content of this application can be specifically implemented through the following three modules:

[0056] Packet capture and parsing TOA module: Responsible for capturing TCP SYN packets and parsing the TOA options therein, and extracting the real IP address and port information of the client.

[0057] TOA query request processing module: Responsible for receiving and processing TOA query requests, and returning the real IP address and port according to the quadruple information in the requests.

[0058] Hook the getpeername function module of the libc library: Hijack the getpeername function through the LD_PRELOAD mechanism, replace it with a custom function, and initiate a query request to the TOA management process.

[0059] Among them, the packet capture and parsing TOA module and the TOA query request processing module run in the same TOA management process, corresponding to two threads of the TOA management process respectively.

[0060] Figure 2 It is a flowchart of a method for obtaining the real address and port information of a client shown according to an exemplary embodiment. Figure 2 The shown process 20 is a detailed description of the packet capture and parsing TOA module.

[0061] As Figure 2 shown, in S202, a packet capture program is created. An AF_PACKET type socket can be created in the packet capture thread to capture TCP SYN packets.

[0062] In S204, a filter is set to obtain TCP SYN packets. A TCP SYN packet type filter is set on the socket to ensure that only SYN packets during the establishment of TCP connections are captured.

[0063] In S206, the TCP SYN packet is parsed to obtain the remote IP address, local IP address from the network layer, and the remote port and local port from the transport layer.

[0064] In S208, the TCP layer option part is parsed to determine whether there is a TOA option.

[0065] In S210, the original IP address and source port address are extracted from the TOA.

[0066] In S212, using the quadruple information as the key and the real IP address and port information as the value. The extracted remote IP address and port are added to the hash table. The hash table key is the quadruple <remote IP address, port, local IP address, port>. The IP address is the IP address extracted at the network layer, and the value is the real client IP address and port carried in the TOA. Then, the hash table is searched according to the key.

[0067] In S214, when the current key-value pair does not exist in the hash table, the current key-value pair is stored in the hash table.

[0068] In S216, when the current key-value pair exists in the hash table, the hash table entry is updated.

[0069] Figure 3 It is a flowchart of a method for obtaining client real address and port information according to another exemplary embodiment. Figure 3 The shown process 30 is a detailed description of the TOA query request processing module.

[0070] As Figure 3 shown, in S302, a thread for processing the TOA query request is started. A TOA query request processing thread is created. A unix-type socket can be created as a server to receive the TOA query request.

[0071] In S304, the query request is accepted.

[0072] In S306, the query request is parsed to obtain the quadruple.

[0073] In S308, the hash table is searched according to the quadruple.

[0074] In S310, if found, the query result is returned. If found, the real client IP address and port carried in the TOA are returned.

[0075] In S312, if not found, a preset invalid value is returned. If not found, an IP address and port of all 0s can be immediately returned, indicating that it has not been found.

[0076] Figure 4 It is a flowchart of a method for obtaining client real address and port information according to another exemplary embodiment. Figure 4 The shown process 40 is a detailed description of the getpeername function module.

[0077] As shown Figure 4 in the figure, in S402, the hijacking application calls the getpeername function. When the getpeername function is called to obtain the source IP address, the getpeername function is intercepted.

[0078] The getpeername function is used to obtain the remote address information (peer address) of the connected socket, that is, to obtain the source address and port information. Its prototype is as follows: int getpeername(int sockfd, struct sockaddr* addr, socklen_t* addrlen);

[0079] sockfd: The socket file descriptor for which to obtain the remote address information.

[0080] addr: A pointer to a sockaddr structure, used to store the obtained remote address information.

[0081] addrlen: A pointer to a socklen_t type, specifying the size of the addr structure. After the function is called, this parameter will be modified to the size of the address structure actually filled into addr.

[0082] If the call is successful, getpeername will return 0 and fill the peer address information into the provided addr structure.

[0083] In S404, a query request is generated and sent to the TOA request processing process. The original getpeername function of libc is called to obtain the remote IP address and port, and getsockname is called to obtain the local IP address and port, and then a TOA query request is constructed.

[0084] In S406, a timer is set. The select can be used to set a timeout timer, and the time can be configured, for example, configured to 1 s.

[0085] In S408, if there is no timeout and a return result is obtained, a return value is constructed and sent to the application side.

[0086] In S410, if it times out, the return value of the original getpeername function of libc is sent to the application.

[0087] More specifically, the intercepted getpeername function code above can be compiled into a dynamic library so file, and the LD_PRELOAD environment variable can be set. This environment variable can specify one or more dynamic link libraries, which will be pre-loaded into memory when the program starts and overwrite the system's default library functions. In this way, the behavior of the program can be changed without modifying the source code. For example, if the compiled so file is named get_real_IPport.so, it can be run like this:

[0088] LD_PRELOAD= / path / get_real_IPport.so. / your_program

[0089] Where / your_program is the program to be run. It can also be run by exporting the LD_PRELOAD environment variable. Or write it into the / etc / ld.so.preload or / etc / ld.so.cache file.

[0090] Those skilled in the art can understand that all or part of the steps for implementing the above embodiments are implemented as a computer program executed by the CPU. When this computer program is executed by the CPU, the above functions defined by the above method provided in this application are executed. The program can be stored in a computer-readable storage medium, which can be a read-only memory, a disk, an optical disc, etc.

[0091] In addition, it should be noted that the above drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present application, rather than for limiting purposes. It is easy to understand that the processes shown in the above drawings do not indicate or limit the time sequence of these processes. Additionally, it is also easy to understand that these processes can be executed synchronously or asynchronously in, for example, multiple modules.

[0092] The following is an embodiment of the device of the present application, which can be used to execute the method embodiment of the present application. For details not disclosed in the embodiment of the device of the present application, please refer to the method embodiment of the present application.

[0093] Figure 5 is a block diagram of a device for obtaining client real address and port information shown according to an exemplary embodiment. As Figure 5 shown, the device 50 for obtaining client real address and port information includes: a message module 502, a storage module 504, a hijacking module 506, an analysis module 508, a query module 510, and a return module 512.

[0094] The message module 502 is used to obtain and parse TCP SYN messages to extract the quadruple information, the real IP address of the client, and the port information; the message module 502 is also used to create a packet capture program and set a filter to obtain TCP SYN messages; parse the TCP SYN messages to obtain the quadruple information and TOA options; extract the real IP address and port information of the client through the TOA options.

[0095] The storage module 504 is used to associate and store the quadruple information, the real IP address, and the port information in a preset table; the storage module 504 is also used to use the quadruple information as a key; use the real IP address and port information as values; and associate and store the quadruple information, the real IP address, and the port information in a preset hash table in the form of key-value pairs.

[0096] The hijacking module 506 is used to hijack the application's call to the getpeername function to generate a query request; the hijacking module 506 is also used to hijack the application's call to the getpeername function; obtain the remote IP address, port, local IP address, and port; and generate the query request through the remote IP address, port, local IP address, and port.

[0097] The parsing module 508 is used to parse the query request to obtain the quadruple information to be queried; the parsing module 508 is also used to parse the query request to obtain the remote IP address, port, local IP address, and port to be queried to form quadruple information.

[0098] The query module 510 is used to query the preset table according to the quadruple information to obtain the real IP address and port information of the client; the query module 510 is also used to return a preset invalid value when the real IP address and port information of the client are not queried.

[0099] The return module 512 is used to return the real IP address and port information of the client to the application to replace the original return value of the getpeername function. The return module 512 is also used to construct a return value through the real IP address and port information of the client; and send the return value to the application through the getpeername function.

[0100] The client real address and port information acquisition device according to the present application extracts the quadruple information and the real IP address and port information of the client by acquiring and parsing the TCP SYN packet; associates and stores the quadruple information with the real IP address and port information in a preset table; hijacks the call of the getpeername function by the application program to generate a query request; parses the query request to obtain the quadruple information to be queried; queries the preset table according to the quadruple information to obtain the real IP address and port information of the client; and returns the real IP address and port information of the client to the application program. In the way of replacing the original return value of the getpeername function, it can obtain the real IP address and port information of the client on the server without compiling the kernel TOA module. Compared with the existing kernel TOA module-based scheme, the present application does not need to modify the kernel, has higher stability and stronger compatibility. In addition, the scheme of the present application does not need to build a compilation environment, can directly distribute and run the program, realizes rapid deployment, and reduces the implementation cost.

[0101] Figure 6 It is a block diagram of an electronic device shown according to an exemplary embodiment.

[0102] The following refers to Figure 6 to describe the electronic device 600 according to this embodiment of the present application. Figure 6 The shown electronic device 600 is only an example and should not bring any limitation to the functions and usage scope of the embodiments of the present application.

[0103] As Figure 6 shown, the electronic device 600 is presented in the form of a general-purpose computing device. The components of the electronic device 600 may include but are not limited to: at least one processing unit 610, at least one storage unit 620, a bus 630 connecting different system components (including the storage unit 620 and the processing unit 610), a display unit 640, etc.

[0104] Among them, the storage unit stores program codes, and the program codes can be executed by the processing unit 610, so that the processing unit 610 executes the steps according to various exemplary embodiments of the present application described in this specification. For example, the processing unit 610 can execute the steps as Figures 1 to 4 shown.

[0105] The storage unit 620 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 6201 and / or a cache storage unit 6202, and may further include a read-only storage unit (ROM) 6203.

[0106] The storage unit 620 may further include a program / utility 6204 having a set (at least one) of program modules 6205. Such program modules 6205 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment.

[0107] The bus 630 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus structures.

[0108] The electronic device 600 may also communicate with one or more external devices 600' (such as a keyboard, a pointing device, a Bluetooth device, etc.), enabling communication with a device that allows a user to interact with the electronic device 600, and / or communication with any device (such as a router, a modem, etc.) that enables the electronic device 600 to communicate with one or more other computing devices. Such communication may be through the input / output (I / O) interface 650. Also, the electronic device 600 may communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 660. The network adapter 660 may communicate with other modules of the electronic device 600 through the bus 630. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 600, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0109] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software, or by a combination of software and necessary hardware. Therefore, as Figure 7 shown, the technical solution according to the embodiments of the present application can be embodied in the form of a software product. The software product can be stored in a non-volatile storage medium (which may be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which may be a personal computer, a server, or a network device, etc.) to execute the above method according to the embodiments of the present application.

[0110] The software product may employ any combination of one or more readable media. The readable media can be a readable signal medium or a readable storage medium. A readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the foregoing. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0111] The computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, in which the readable program code is carried. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The readable storage medium can also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium can be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0112] The program code for performing the operations of the present application can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, executed as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (e.g., by using an Internet service provider to connect through the Internet).

[0113] The above computer-readable medium carries one or more programs, which, when executed by the device, cause the computer-readable medium to implement the following functions: obtaining and parsing TCP SYN packets to extract quadruple information and the real IP address and port information of the client; associatively storing the quadruple information and the real IP address and port information in a preset table; hijacking the call of the getpeername function by the application program to generate a query request; parsing the query request to obtain the quadruple information to be queried; querying the preset table according to the quadruple information to obtain the real IP address and port information of the client; and returning the real IP address and port information of the client to the application program to replace the original return value of the getpeername function.

[0114] Those skilled in the art can understand that the above-mentioned modules can be distributed in the device according to the description of the embodiments, or can be correspondingly changed and distributed in one or more devices that are different from this embodiment only. The modules of the above embodiments can be combined into one module, or can be further split into multiple sub-modules.

[0115] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described here can be implemented by software, or can be implemented by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on the network, including several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present application.

[0116] The above specifically shows and describes the exemplary embodiments of the present application. It should be understood that the present application is not limited to the detailed structures, setting methods or implementation methods described here; on the contrary, the present application intends to cover various modifications and equivalent settings included in the spirit and scope of the appended claims.

Claims

1. A method for obtaining real address port information of a client, which can be applied in a server, characterized in that: include: Obtain and parse TCP SYN packets to extract the four-tuple information and the client's real IP address and port information; The four-tuple information is associated with the real IP address and port information and stored in a preset table; Hijack the application's call to the getpeername function to generate a query request; Parsing the query request to obtain the four-tuple information to be queried; According to the four-tuple information, the preset table is queried to obtain the real IP address and port information of the client; The real IP address and port information of the client are returned to the application to replace the original return value of the getpeername function.

2. The method according to claim 1, characterized in that Obtain and parse the TCP SYN message to extract the four-tuple information and the client's real IP address and port information, including: Create a packet capture program and set filters to capture TCP SYN packets; Parsing the TCP SYN message to obtain four-tuple information and TOA options; The real IP address and port information of the client are extracted through the TOA option.

3. The method according to claim 1, characterized in that The four-tuple information is associated with the real IP address and port information and stored in a preset table, including: Using the four-tuple information as a key; The real IP address and port information are used as values; The four-tuple information is associated with the real IP address and port information in the form of a key-value pair and stored in a preset hash table.

4. The method according to claim 1, characterized in that Hijack the application's call to the getpeername function and generate a query request, including: Hijack the application's call to the getpeername function; Get the remote IP address, port and local IP address, port; The query request is generated through the remote IP address, port and the local IP address, port.

5. The method according to claim 4, characterized in that Get the remote IP address, port and local IP address, port, including: Get the remote IP address and port through libc's original getpeername; Call getsockname to obtain the local IP address and port.

6. The method according to claim 1, characterized in that Parsing the query request to obtain the four-tuple information to be queried includes: The query request is parsed to obtain the remote IP address, port and local IP address, port to be queried to form a four-tuple information.

7. The method according to claim 1, characterized in that The method further includes querying the preset table according to the four-tuple information to obtain the real IP address and port information of the client: When the real IP address and port information of the client are not queried, a preset invalid value is returned.

8. The method according to claim 1, characterized in that Return the client's real IP address and port information to the application to replace the original return value of the getpeername function, including: Construct the return value through the client's real IP address and port information; The return value is sent to the application through the getpeername function.

9. The method according to claim 1, characterized in that Return the client's real IP address and port information to the application to replace the original return value of the getpeername function, and also include: Upon timeout or receipt of a preset invalid value, the original getpeername return value of libc is sent to the application.

10. A device for obtaining real address port information of a client, which can be applied in a server, characterized in that: include: The message module is used to obtain and parse the TCP SYN message to extract the four-tuple information and the client's real IP address and port information; A storage module, used to associate and store the four-tuple information with the real IP address and port information in a preset table; Hijacking module, used to hijack the application's call to the getpeername function to generate a query request; A parsing module, used for parsing the query request to obtain the four-tuple information to be queried; A query module, used to query the preset table according to the four-tuple information to obtain the real IP address and port information of the client; The return module is used to return the real IP address and port information of the client to the application to replace the original return value of the getpeername function.