Elephant flow fast forwarding method and device
By stating and identifying the traffic of the stateless gateway, and forwarding the elephant stream using fast paths, the stability and packet loss problems of the gateway when facing the elephant stream are solved, and the system's processing capability and stability are improved.
Patent Information
- Application Number
- CN202510320496.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-06-03
AI Technical Summary
Stateless gateways face elephant flow problems, resulting in excessive single-core usage rate and increased packet loss rate, affecting user experience. Especially when the number of customers on the cloud increases, it is difficult for existing x86 gateways to quickly identify and forward elephant flows.
By obtaining traffic packets to the gateway machine, performing flow frequency statistics, identifying candidate elephant streams whose statistical value exceeds the preset threshold, and forwarding the elephant stream through a fast path.
It realizes rapid identification and forwarding of elephant streams, reduces single-core CPU usage peak, reduces packet loss and jitter, and improves system stability.
Smart Images

Figure CN120090984A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technologies, and in particular, to the field of elephant flow forwarding technologies. Background Art
[0002] The biggest stability challenge currently faced by stateless gateways is the elephant flow problem. The characteristics of this kind of traffic are that there is a sudden increase in packets for a period of time. Too many packets fall on a certain core, resulting in too high a single-core utilization rate. Other packets cannot be processed when they fall on this core, leading to an increase in the single-core packet loss rate, and then an increase in the overall machine packet loss rate and even the packet loss rate of the entire cluster, affecting the user experience. With the increase in cloud customers, the traffic carried by the gateway is getting larger and larger, and the elephant flow problem is becoming increasingly prominent. Moreover, major x86 gateways are all facing the problem of a single core being fully utilized by elephant flows. Therefore, there is an urgent need for a fast and relatively accurate mechanism to identify and quickly forward elephant flow problems.
[0003] Currently, when it is monitored and found that the x86 gateway machine has a sudden large traffic and even starts to lose packets, the corresponding traffic and customer information will be found first, and this traffic will be switched to a programmable hardware gateway that can carry large traffic. Summary of the Invention
[0004] Embodiments of the present disclosure propose an elephant flow fast forwarding method, apparatus, device, storage medium, and program product.
[0005] In a first aspect, embodiments of the present disclosure propose an elephant flow fast forwarding method, including: obtaining packets of traffic arriving at a gateway machine; performing flow frequency statistics on the packets of the traffic to obtain a statistical value; in response to the statistical value exceeding a preset threshold, determining the traffic as a candidate elephant flow; identifying an elephant flow from the candidate elephant flows; and forwarding the elephant flow through a fast path.
[0006] In a second aspect, embodiments of the present disclosure propose an elephant flow fast forwarding apparatus, including: an obtaining module configured to obtain packets of traffic arriving at a gateway machine; a statistical module configured to perform flow frequency statistics on the packets of the traffic to obtain a statistical value; a determining module configured to, in response to the statistical value exceeding a preset threshold, determine the traffic as a candidate elephant flow; an identifying module configured to identify an elephant flow from the candidate elephant flows; and a forwarding module configured to forward the elephant flow through a fast path.
[0007] In a third aspect, embodiments of the present disclosure propose an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method described in the first aspect.
[0008] Fourthly, an embodiment of the present disclosure provides a non-transitory computer-readable storage medium storing computer instructions for causing a computer to execute the method described in the first aspect.
[0009] Fifthly, an embodiment of the present disclosure provides a computer program product including a computer program which, when executed by a processor, implements the method described in the first aspect.
[0010] The key or important features of the embodiments of the present disclosure are not used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understandable through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] Other features, objects, and advantages of the present disclosure will become more apparent by reading the detailed description of non-limiting embodiments with reference to the following drawings. The drawings are used to better understand the solution and do not constitute a limitation to the present disclosure. Among them: Figure 1 is a flowchart of an embodiment of the elephant flow fast forwarding method according to the present disclosure; Figure 2 is a flowchart of another embodiment of the elephant flow fast forwarding method according to the present disclosure; Figure 3 is a flowchart block diagram of elephant flow identification; Figure 4 is a flowchart block diagram of elephant flow forwarding; Figure 5 is a schematic structural diagram of an embodiment of the elephant flow fast forwarding device according to the present disclosure; Figure 6 is a block diagram of an electronic device for implementing the elephant flow fast forwarding method of the embodiments of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0012] The following describes exemplary embodiments of the present disclosure in conjunction with the drawings. Various details of the embodiments of the present disclosure are included to assist understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0013] It should be noted that, without conflict, the embodiments and features in the embodiments of the present disclosure can be combined with each other. The present disclosure will be described in detail below with reference to the drawings and in conjunction with the embodiments.
[0014] Figure 1Flow 100 of an embodiment of the elephant flow fast forwarding method according to the present disclosure is shown. The elephant flow fast forwarding method includes the following steps: Step 101, obtain the packets of the traffic arriving at the gateway machine.
[0015] In this embodiment, the execution subject of the elephant flow fast forwarding method may obtain the packets of the traffic arriving at the gateway machine.
[0016] The execution subject of the elephant flow fast forwarding method is usually a server. The server can be hardware or software. When the server is hardware, it can be implemented as a distributed server cluster composed of multiple servers or as a single server. When the server is software, it can be implemented as multiple software or software modules (such as those used to provide distributed services) or as a single software or software module. No specific limitation is made here.
[0017] The gateway machine can receive the packets of the traffic and process the packets. If there is a sudden increase in packets for a continuous period of time, and too many packets fall on a certain core of the gateway machine, resulting in too high a single-core utilization rate, and other packets cannot be processed when they fall on this core, it will lead to an increase in the single-core packet loss rate. Therefore, when the packets of the traffic arrive at the gateway machine, it is necessary to quickly identify the elephant flow and perform fast forwarding.
[0018] Step 102, perform flow frequency statistics on the packets of the traffic to obtain a statistical value.
[0019] In this embodiment, the above execution subject may perform flow frequency statistics on the packets of the traffic to obtain a statistical value. For example, the bandwidth occupied by the packets of the traffic and the transmission time are statistically analyzed. Among them, the traffic that occupies a large amount of bandwidth and transmits data for a long time is the elephant flow.
[0020] In some embodiments, the six-tuple information is parsed from the packets of the traffic; the CBF (Counting BloomFilter) is used to check and statistically analyze the six-tuple information to obtain the occurrence frequency of the traffic. Among them, the six-tuple information (vni, sip, sport, dip, dport, protol) may include the user information vni, the source IP address sip, the destination IP address dip, the source port number sport, the destination port number dport, and the protocol number protol. CBF is an extension of the Bloom filter, which uses a counter instead of a simple bit to represent the state of a certain position. This enables CBF to support deletion operations: when an element is inserted, the counter at the corresponding position is incremented; when an element is deleted, the counter is decremented. Only when the counter is zero does it indicate that there is no element at that position.
[0021] Step 103: In response to the statistical value exceeding a preset threshold, determine the traffic as candidate elephant traffic.
[0022] In this embodiment, the above-mentioned execution entity can determine whether the statistical value exceeds the preset threshold. If the statistical value exceeds the preset threshold, it indicates that the traffic is potential elephant traffic. At this time, the traffic can be determined as candidate elephant traffic.
[0023] In some embodiments, write the EMC (Elephant Match Cache) entry information of the candidate elephant traffic into the EMC, and perform life cycle management on the EMC entry information. Among them, if the candidate elephant traffic is elephant traffic, the life cycle of the EMC entry information of the elephant traffic can be continued in the EMC for keep-alive operations. If the candidate elephant traffic is not elephant traffic, the elephant match cache entry information of the candidate elephant traffic can be deleted from the EMC.
[0024] Step 104: Identify elephant traffic from the candidate elephant traffic.
[0025] In this embodiment, the above-mentioned execution entity can identify elephant traffic from the candidate elephant traffic.
[0026] Generally, for candidate elephant traffic whose statistical value exceeds the preset threshold for a long time, it can be determined as elephant traffic.
[0027] In some embodiments, set aging information for the EMC entry information and insert it into the time wheel. If the candidate elephant traffic appears in the time wheel more than a preset number of rounds, determine it as elephant traffic. Among them, the aging information can be an aging time or an aging function. The aging function can be a function related to the value of the aging time. For example, for the frequency decaying from 4000 bps to 1000 bps, the aging time value is 60 s; for the frequency decaying from 4000 bps to 0, the aging time value is 30 s. For example, set the aging time of the EMC entry information to 30 s and insert it into the time wheel. If the candidate elephant traffic appears with a frequency exceeding 4000 bps twice in 60 s, then determine it as elephant traffic.
[0028] Step 105: Forward the elephant traffic through the fast path.
[0029] In this embodiment, the above-mentioned execution entity can forward the elephant flow through the fast path. Among them, compared with the slow path, the fast path reduces processes such as NAT (Network Address Translation), ACL (Access Control Lists), TTL (Time To Live), ALG (Application Layer Gateway), Dptrace (tracking), Rlimit (resource limit), Sampling (sampling), etc., so as to achieve the fast forwarding of the elephant flow.
[0030] In some embodiments, an EMC identifier is set in the elephant flow packet. When processing the slow path, for the traffic without packet loss, at the output, the action operation install is installed into the Header of the packet (such as eFlow, similar to a snapshot of a packet Header), and the corresponding action is set at the output according to the change of the Header and the information of the skb context, and the elephant flow with the action set is quickly forwarded. Among them, setting an action for the elephant flow facilitates the query of the fast transfer process information.
[0031] In the elephant flow fast transfer process, the integrity of the function needs to be maintained. The information of the processes reduced by the fast path can be recorded in the action. Therefore, for the traffic in the EMC, taking the fast path can maintain the integrity of the function with the original slow path.
[0032] In the elephant flow fast transfer process, the eflow configuration consistency needs to be maintained. Since the fast transfer bypasses the original process, if there is a problem with the fast transfer, the unloaded elephant flow cannot automatically return to the slow path, which is catastrophic for the traffic. Therefore, a fallback mechanism is provided to ensure that the elephant flow has the opportunity to take the slow path again. Based on the configuration consistency check in the fast path, a new timed configuration Version aging mechanism is added to force the traffic to go back to the slow path.
[0033] In the elephant flow fast transfer process, statistical updates are required. When the traffic takes the fast path, to ensure that other functions are not affected, the corresponding statistics and the corresponding rlimit data need to be updated.
[0034] The embodiments of the present disclosure provide a method for a stateless gateway to identify elephant flows and directly perform fast forwarding. First, the traffic on the gateway machine is identified to find potential elephant flows. Based on the identification result, the fast forwarding of elephant flows directly forwards packets through the fast path, while other traffic that does not meet the detection criteria still uses the slow path for forwarding. This reduces the time and manpower consumed by elephant flow problems, improves the single-core elephant flow processing ability, increases the single-core throughput of the X86 gateway machine, reduces the peak CPU usage rate, and reduces the impact on users caused by packet loss and jitter due to elephant flow problems, significantly improving the stability of the system.
[0035] Continue to refer to Figure 2 , which shows the process 200 of another embodiment of the elephant flow fast forwarding method according to the present disclosure. The elephant flow fast forwarding method includes the following steps: Step 201, obtain the packets of the traffic arriving at the gateway machine.
[0036] In this embodiment, the execution entity of the elephant flow fast forwarding method can obtain the packets of the traffic arriving at the gateway machine.
[0037] The execution entity of the elephant flow fast forwarding method is usually a server. The server can be hardware or software. When the server is hardware, it can be implemented as a distributed server cluster composed of multiple servers or as a single server. When the server is software, it can be implemented as multiple software or software modules (such as those used to provide distributed services) or as a single software or software module. No specific limitation is made here.
[0038] The gateway machine can receive the packets of the traffic and process the packets. If there is a sudden increase in packets for a continuous period, and too many packets fall on a certain core of the gateway machine, resulting in too high a single-core usage rate and other packets not being processed in time on this core, it will lead to an increase in the single-core packet loss rate. Therefore, when the packets of the traffic arrive at the gateway machine, it is necessary to promptly identify the elephant flows and perform fast forwarding.
[0039] Step 202, sample the packets of the traffic.
[0040] In this embodiment, the above execution entity can sample the packets of the traffic to relieve the performance pressure on the forwarding core.
[0041] Step 203, perform flow frequency statistics on the packets of the traffic to obtain a statistical value.
[0042] In this embodiment, the above execution entity can perform flow frequency statistics on the packets of the traffic to obtain a statistical value. For example, the bandwidth occupied by the packets of the traffic and the transmission time are statistically analyzed, and among them, the traffic that occupies a large amount of bandwidth and transmits data for a long time is an elephant flow.
[0043] In some embodiments, six-tuple information is parsed from the traffic packets; the CBF is used to check and count the six-tuple information to obtain the occurrence frequency of the traffic. Among them, the six-tuple information (vni, sip, sport, dip, dport, protol) may include user information vni, source IP address sip, destination IP address dip, source port number sport, destination port number dport, and protocol number protol. CBF is an extension of the Bloom filter, which uses counters instead of simple bit positions to represent the status of a certain position. This enables CBF to support deletion operations: when an element is inserted, the counter at the corresponding position is incremented; when an element is deleted, the counter is decremented. Only when the counter is zero does it indicate that there is no element at that position.
[0044] Step 204: In response to the statistical value exceeding a preset threshold, the traffic is determined as a candidate elephant flow.
[0045] In this embodiment, the above-mentioned execution entity can determine whether the statistical value exceeds the preset threshold. If the statistical value exceeds the preset threshold, it indicates that the traffic is a potential elephant flow. At this time, the traffic can be determined as a candidate elephant flow.
[0046] In some embodiments, the EMC entry information of the candidate elephant flow is written into the EMC, and the life cycle management of the EMC entry information is performed. Among them, if the candidate elephant flow is an elephant flow, the life cycle of the EMC entry information of the elephant flow can be continued in the EMC for keep-alive operations. If the candidate elephant flow is not an elephant flow, the elephant matching cache entry information of the candidate elephant flow can be deleted from the EMC.
[0047] Step 205: Write the elephant matching cache entry information of the candidate elephant flow into the elephant matching cache.
[0048] In this embodiment, the above-mentioned execution entity can write the EMC entry information of the candidate elephant flow into the EMC for easy life cycle management.
[0049] Step 206: Set aging information for the elephant matching cache entry information and insert it into the time wheel.
[0050] In this embodiment, the above-mentioned execution entity can set aging information for the EMC entry information and insert it into the time wheel. Among them, the aging information can be an aging time or an aging function. The aging function can be a function related to the aging time value. For example, for the frequency decaying from 4000 bps to 1000 bps, the aging time value is 60 s; for the frequency decaying from 4000 bps to 0, the aging time value is 30 s.
[0051] Step 207: Determine whether the candidate elephant flow appears in the time wheel more than the preset number of rounds.
[0052] In this embodiment, the above-mentioned execution entity can determine whether the candidate elephant flow appears in the time wheel more than the preset number of rounds. If it exceeds the preset number of rounds, execute Step 208; if it does not exceed the preset number of rounds, execute Step 212.
[0053] Step 208: Determine the candidate elephant flow as an elephant flow.
[0054] In this embodiment, if the candidate elephant flow appears in the time wheel more than the preset number of rounds, the above-mentioned execution entity can determine the candidate elephant flow as an elephant flow. For example, set the aging time of the EMC entry information to 30s and insert it into the time wheel. If the candidate elephant flow appears twice with a frequency exceeding 4000bps within 60s, then determine it as an elephant flow.
[0055] Step 209: Extend the lifecycle of the elephant matching cache entry information of the elephant flow in the elephant matching cache.
[0056] In this embodiment, the above-mentioned execution entity can extend the lifecycle of the EMC entry information of the elephant flow in the EMC to perform a keep-alive operation.
[0057] Step 210: Forward the elephant flow through the fast path.
[0058] In this embodiment, the above-mentioned execution entity can forward the elephant flow through the fast path. Among them, compared with the slow path, the fast path reduces processes such as NAT, ACL, TTL, ALG, Dptrace, Rlimit, Sampling, etc., so as to achieve fast forwarding of the elephant flow.
[0059] In some embodiments, set an EMC identifier in the elephant flow packet. When processing the slow path, for the traffic without packet loss, install the action operation at the output into the Header of the packet (such as eFlow, similar to a snapshot of a packet Header), set the corresponding action according to the change of the Header and the information of the skb context at the output, and perform fast forwarding on the elephant flow with the action already set. Among them, setting an action for the elephant flow facilitates querying the information in the fast forwarding process.
[0060] In the elephant flow fast forwarding process, it is necessary to maintain the integrity of the function. The information of the processes reduced by the fast path can be recorded in the action. Therefore, for the traffic in the EMC that takes the fast path, it can maintain the integrity of the function with the original slow path.
[0061] In the fast - turn process of elephant flows, it is necessary to maintain the consistency of eflow configuration. Since fast - turn bypasses the original process, if there is a problem with fast - turn, the unloaded elephant flows cannot automatically return to the slow path, which is catastrophic for traffic. Therefore, a fallback mechanism is provided to ensure that elephant flows have the opportunity to take the slow path again. Based on the configuration consistency check in the fast path, a timed configuration Version aging mechanism is added to force traffic to go back to the slow path.
[0062] In the fast - turn process of elephant flows, statistical updates are required. When traffic is taking the fast path, to ensure that other functions are not affected, corresponding statistics and the corresponding rlimit data need to be updated.
[0063] Step 211: Delete the elephant matching cache table entry information of the elephant flow.
[0064] In this embodiment, after the elephant flow is forwarded through the fast path, the execution entity can delete the EMC table entry information of the elephant flow.
[0065] Step 212: Delete the elephant matching cache table entry information of the candidate elephant flow.
[0066] In this embodiment, if the candidate elephant flow appears in the time wheel no more than the preset number of rounds, the execution entity can delete the EMC table entry information of the candidate elephant flow.
[0067] The embodiments of the present disclosure provide a method for a stateless gateway to identify elephant flows and directly perform fast - turn. First, the traffic on the gateway machine is identified to find potential elephant flows. The fast - turn of elephant flows will directly forward the packets on the fast path based on the identification result, and other traffic that does not meet the detection standard still takes the slow path for forwarding. This reduces the time and manpower consumed by elephant - flow problems, improves the single - core elephant - flow processing ability, increases the single - core throughput of the X86 gateway machine, reduces the peak value of CPU usage, reduces the impact on users caused by packet loss and jitter due to elephant - flow problems, and greatly improves the stability of the system.
[0068] Figure 3 The flowchart of elephant - flow identification is shown. As Figure 3 shown, the elephant - flow identification logic is as follows: Step 301: Pre - processing: Obtain the packet of the traffic arriving at the gateway machine and parse the six - tuple information (vni, sip, sport, dip, dport, protol) in the packet.
[0069] Step 302: Flow sampling: Sample the packet to relieve the performance pressure on the forwarding core.
[0070] Step 303, Elephant flow recognition: Periodically recognize elephant flows, check and count the six-tuple information of each flow using CBF. If the statistical value exceeds the set threshold, it is considered a potential elephant flow and stored in the EMC.
[0071] Step 304, EMC module: Includes operations for adding, updating, and deleting EMC. When adding an EMC table entry, the aging time and aging function of the entry are set simultaneously and inserted into the time wheel.
[0072] Step 305, Elephant flow keep-alive: For traffic that appears in two or more elephant flow recognition phases, directly extend the life cycle of the table entry information in the EMC for keep-alive operations.
[0073] Step 306, Elephant flow aging: For elephant flows with stored actions, when the traffic arrives, it will be directly fast-forwarded. At the same time, the corresponding EMC table entry information needs to be cleared according to certain rules to avoid residues.
[0074] Figure 4 Shows the flow block diagram of elephant flow forwarding. As Figure 4 shown, the elephant flow fast-forwarding process is as follows: 1. Function integrity: For traffic in the EMC, take the fast path. The fast path needs to maintain functional integrity with the original path.
[0075] After identifying the elephant flow, set the EMC flag in the packet. When processing the slow path, for traffic that is not dropped, install the Action operation into the eFlow at the output (similar to a snapshot of a packet Header). At the Output, set the corresponding action according to the changes in the Header and the information on the skb context to facilitate querying of information during the fast-forwarding process.
[0076] 2. eflow configuration consistency: Since the fast-forwarding bypasses the original process, if there is a problem with the fast-forwarding and the unloaded elephant flow cannot automatically return to the slow path, it is catastrophic for the traffic. Therefore, a fallback mechanism needs to be considered here to ensure that the elephant flow has the opportunity to re-take the slow path. Based on the configuration consistency check in the fast path, a new timed configuration Version aging mechanism is added to force the traffic to return to the slow path.
[0077] 3. Statistical update: When the traffic takes the FastPath, in order to ensure that other functions are not affected, the corresponding statistics and the corresponding rlimit data need to be updated.
[0078] Further refer to Figure 5 , as an implementation of the methods shown in the above figures, the present disclosure provides an embodiment of an elephant flow fast-forwarding device. This device embodiment is related toFigure 1 corresponds to the method embodiment shown, and this device can be specifically applied to various electronic devices.
[0079] Such as Figure 5 As shown, the elephant flow fast forwarding device 500 in this embodiment may include: an obtaining module 501, a statistics module 502, a determination module 503, an identification module 504, and a forwarding module 505. Among them, the obtaining module 501 is configured to obtain packets of the traffic arriving at the gateway machine; the statistics module 502 is configured to perform flow frequency statistics on the packets of the traffic to obtain a statistical value; the determination module 503 is configured to determine the traffic as a candidate elephant flow in response to the statistical value exceeding a preset threshold; the identification module 504 is configured to identify an elephant flow from the candidate elephant flows; the forwarding module 505 is configured to forward the elephant flow through a fast path.
[0080] In this embodiment, in the elephant flow fast forwarding device 500: the specific processing of the obtaining module 501, the statistics module 502, the determination module 503, the identification module 504, and the forwarding module 505 and the technical effects brought by them can respectively refer to Figure 1 the relevant descriptions of steps 101-105 in the corresponding embodiment, which will not be elaborated here.
[0081] In some optional implementation manners of this embodiment, the statistics module 502 is further configured to: parse six-tuple information from the packets of the traffic; use a counting Bloom filter to check and count the six-tuple information to obtain the occurrence frequency of the traffic.
[0082] In some optional implementation manners of this embodiment, the six-tuple information includes user information, source IP address, destination IP address, source port number, destination port number, and protocol number.
[0083] In some optional implementation manners of this embodiment, the elephant flow fast forwarding device 500 further includes: a sampling module, which is configured to sample the packets of the traffic.
[0084] In some optional implementation manners of this embodiment, the elephant flow fast forwarding device 500 further includes: a writing module, which is configured to write the elephant matching cache table entry information of the candidate elephant flow into the elephant matching cache; a management module, which is configured to perform life cycle management on the elephant matching cache table entry information.
[0085] In some optional implementation manners of this embodiment, the management module is further configured to: set aging information for the elephant matching cache table entry information and insert it into the time wheel; and the identification module 504 is further configured to: determine the candidate elephant flow as an elephant flow in response to the candidate elephant flow appearing in the time wheel exceeding a preset number of rounds.
[0086] In some alternative implementation manners of this embodiment, the elephant flow fast forwarding device 500 further includes: a continuation module configured to continue the lifecycle of the elephant matching cache entry information of the elephant flow in the elephant matching cache.
[0087] In some alternative implementation manners of this embodiment, the elephant flow fast forwarding device 500 further includes: a first deletion module configured to delete the elephant matching cache entry information of the elephant flow after the elephant flow is forwarded through the fast path.
[0088] In some alternative implementation manners of this embodiment, the elephant flow fast forwarding device 500 further includes: a second deletion module configured to delete the elephant matching cache entry information of the candidate elephant flow in response to the candidate elephant flow appearing in the time wheel not exceeding a preset number of rounds.
[0089] In some alternative implementation manners of this embodiment, the forwarding module 505 is further configured to: set an elephant matching cache identifier in the packet of the elephant flow, install an action operation at the output into the header of the packet, set a corresponding action according to the change of the header and the information of the socket cache context, and perform fast forwarding on the elephant flow with the action already set.
[0090] In the technical solution of the present disclosure, the acquisition, storage, application, etc. of the user's personal information involved all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0091] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0092] Figure 6 FIG. shows a schematic block diagram of an exemplary electronic device 600 that can be used to implement the embodiments of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely exemplary and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0093] As Figure 6As shown, device 600 includes a computing unit 601, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 602 or a computer program loaded from a storage unit 608 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the device 600 can also be stored. The computing unit 601, the ROM 602, and the RAM 603 are connected to each other via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0094] Multiple components in the device 600 are connected to the I / O interface 605, including: an input unit 606, such as a keyboard, a mouse, etc.; an output unit 607, such as various types of displays, speakers, etc.; a storage unit 608, such as a magnetic disk, an optical disc, etc.; and a communication unit 609, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 609 allows the device 600 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0095] The computing unit 601 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 601 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The computing unit 601 executes the various methods and processes described above, such as the elephant flow fast forwarding method. For example, in some embodiments, the elephant flow fast forwarding method can be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as the storage unit 608. In some embodiments, part or all of the computer program can be loaded and / or installed onto the device 600 via the ROM 602 and / or the communication unit 609. When the computer program is loaded into the RAM 603 and executed by the computing unit 601, one or more steps of the elephant flow fast forwarding method described above can be executed. Alternatively, in other embodiments, the computing unit 601 can be configured to execute the elephant flow fast forwarding method in any other appropriate way (e.g., by means of firmware).
[0096] The various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), systems on a chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that receives data and instructions from a storage system, at least one input device, and at least one output device, and transmits the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0097] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowchart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, executed partially on the machine as an independent software package and partially on a remote machine, or executed entirely on a remote machine or server.
[0098] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media would include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0099] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).
[0100] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.
[0101] A computer system can include a client and a server. The client and the server are generally far from each other and usually interact through a communication network. The client - server relationship is created by computer programs running on the respective computers and having a client - server relationship with each other. The server can be a cloud server, a server of a distributed system, or a server incorporating a blockchain.
[0102] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions provided in this disclosure can be achieved, and no limitation is imposed herein.
[0103] The above - mentioned specific implementation manners do not constitute a limitation on the protection scope of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub - combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the protection scope of this disclosure.
Claims
1. A method for fast forwarding of an elephant flow, comprising: Get the traffic packets arriving at the gateway machine; Performing flow frequency statistics on the packets of the flow to obtain a statistical value; In response to the statistical value exceeding a preset threshold, determining the flow as a candidate elephant flow; identifying an elephant flow from the candidate elephant flows; The elephant flow is forwarded via a fast path.
2. The method according to claim 1, wherein: The performing flow frequency statistics on the packets of the flow to obtain a statistical value includes: Parsing six-tuple information from the message of the traffic; The six-tuple information is checked and counted using a counting Bloom filter to obtain the occurrence frequency of the traffic.
3. The method according to claim 2, wherein: The six-tuple information includes user information, source IP address, destination IP address, source port number, destination port number and protocol number.
4. The method according to claim 1, wherein: Before performing flow frequency statistics on the packets of the flow to obtain the statistical value, the method further includes: The packets of the traffic are sampled.
5. The method according to claim 1, wherein: The method further comprises: Writing the elephant matching cache entry information of the candidate elephant flow into the elephant matching cache; The elephant matching cache entry information is managed for its life cycle.
6. The method according to claim 5, wherein: The performing life cycle management on the elephant matching cache entry information includes: Setting aging information for the elephant matching cache entry information and inserting it into the time wheel; and The step of identifying the elephant flow from the candidate elephant flows comprises: In response to the candidate elephant flow appearing for more than a preset number of rounds in a time round, the candidate elephant flow is determined as the elephant flow.
7. The method according to claim 6, wherein: The method further comprises: The life cycle of the elephant matching cache entry information of the elephant flow is continued in the elephant matching cache.
8. The method according to claim 7, wherein: The method further comprises: After the elephant flow is forwarded through the fast path, the elephant matching cache entry information of the elephant flow is deleted.
9. The method according to claim 8, wherein: The method further comprises: In response to the candidate elephant flow appearing no more than a preset round in the time round, the elephant matching cache entry information of the candidate elephant flow is deleted.
10. The method according to claim 1, wherein: The forwarding of the elephant flow through a fast path includes: An elephant matching cache identifier is set in the message of the elephant flow, an action operation is installed in the header of the message at the output, a corresponding action is set according to the change of the header and the information of the socket cache context, and the elephant flow with the set action is quickly forwarded.
11. A fast forwarding device for an elephant flow, comprising: An acquisition module is configured to acquire packets of traffic arriving at the gateway machine; A statistics module is configured to perform flow frequency statistics on the packets of the flow to obtain a statistical value; a determination module, configured to determine the flow as a candidate elephant flow in response to the statistical value exceeding a preset threshold; an identification module, configured to identify an elephant flow from the candidate elephant flows; The forwarding module is configured to forward the elephant flow through a fast path.
12. An electronic device comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 10.
13. A non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause the computer to execute the method of any one of claims 1 to 10.
14. A computer program product comprising a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 10.