Traffic mirroring method and apparatus, electronic device, and storage medium
By generating and encrypting LAN mirroring instructions on the server side, and configuring the source port to mirror mode using the command-line tool on the target terminal, the problem of complex existing traffic mirroring configuration is solved, configuration efficiency and accuracy are improved, and the professional requirements for network administrators are reduced.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SAIAN TECH (GUANGDONG) CO LTD
- Filing Date
- 2025-02-07
- Publication Date
- 2026-07-31
AI Technical Summary
Existing traffic mirroring configuration methods are complex, require a high level of professional knowledge, and place high demands on network administrators, resulting in low configuration efficiency and susceptibility to human error.
By enabling the local area network (LAN) mirroring function of the target terminal through the network port control editing page on the server side, generating and encrypting LAN mirroring commands, configuring the source port to mirroring mode using the command-line tool on the target terminal, and performing network analysis through the maintenance equipment.
It simplifies the traffic mirroring configuration process, improves the accuracy and efficiency of configuration, reduces the professional requirements for network administrators, and reduces the risk of human error.
Smart Images

Figure CN120110900B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to a traffic mirroring method and apparatus, electronic device and storage medium. Background Technology
[0002] In related technologies, configuring traffic mirroring (also called network traffic mirroring or port mirroring) is commonly used in network devices and plays an important role in network monitoring and troubleshooting. However, existing methods for configuring traffic mirroring are quite complex, require a deep understanding of network devices, and place high demands on the professional skills of network administrators.
[0003] In summary, the technical problems existing in the relevant technologies need to be improved. Summary of the Invention
[0004] The main objective of this application is to provide a traffic mirroring method, apparatus, electronic device, and storage medium, which aims to simplify the configuration process of traffic mirroring.
[0005] To achieve the above objectives, one aspect of this application proposes a traffic mirroring method, which includes the following steps:
[0006] In response to the first instruction, enable the local area network mirroring function of the target terminal on the network port control editing page on the server side;
[0007] The server generates a command to enable LAN mirroring, which includes the source port.
[0008] The source port is configured to mirror mode by applying the enable LAN mirroring command through the command-line tool of the target terminal.
[0009] In some embodiments, generating the LAN mirroring enable command via the server includes:
[0010] The target configuration policy is generated by the server, and the target configuration policy includes the instruction to enable local area network mirroring.
[0011] The server encrypts the target configuration policy using a security and confidentiality protocol and sends the encrypted target configuration policy to the target terminal.
[0012] In some embodiments, the method further includes:
[0013] The target terminal establishes a secure connection with the server using the security and confidentiality protocol.
[0014] The target terminal receives and parses the encrypted target configuration policy to obtain the command to enable local area network mirroring.
[0015] In some embodiments, applying the enable LAN mirroring command via the command-line tool of the target terminal to configure the source port in mirroring mode includes:
[0016] By applying the LAN mirroring enable command through the command-line tool of the target terminal, the integrated switch chip is configured to set the source port of the switch to mirroring mode.
[0017] In some embodiments, the enable LAN mirroring command further includes a mirroring port, and the step of applying the enable LAN mirroring command through the command-line tool of the target terminal to configure the source port in mirroring mode includes:
[0018] By applying the LAN mirroring command through the command-line tool of the target terminal, the network traffic of the source port is copied to the network traffic of the mirror port.
[0019] In some embodiments, the method further includes:
[0020] Connect the mirrored port to the maintenance equipment and perform network analysis using the maintenance equipment's analysis and management tools.
[0021] In some embodiments, the method further includes:
[0022] In response to the second instruction, enable the LAN mirroring function for multiple target terminals on the network port control add page on the server side.
[0023] In some embodiments, the method further includes:
[0024] In response to the third instruction, the local area network mirroring function of the target terminal is disabled on the network port control editing page on the server side;
[0025] The server generates a command to shut down the local area network mirroring, and the command to shut down the local area network mirroring includes the source port.
[0026] The command to disable LAN mirroring is applied using the command-line tool on the target terminal to disable the mirroring mode of the source port.
[0027] In some embodiments, the method further includes:
[0028] In response to the fourth instruction, the LAN mirroring function for multiple target terminals is disabled on the server-side network port control page.
[0029] To achieve the above objectives, another aspect of this application provides a traffic mirroring device, the device comprising:
[0030] The function control module is used to respond to the first command and enable the local area network mirroring function of the target terminal on the network port control editing page on the server side;
[0031] The instruction generation module is used to generate an enable LAN mirroring instruction via the server, wherein the enable LAN mirroring instruction includes a source port;
[0032] The configuration module is used to configure the source port to mirror mode by applying the enable LAN mirroring command through the command line tool of the target terminal.
[0033] To achieve the above objectives, another aspect of this application provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the method described above.
[0034] To achieve the above objectives, another aspect of the embodiments of this application proposes a computer-readable storage medium storing a computer program that, when executed by a processor, implements the methods described above.
[0035] To achieve the above objectives, another aspect of this application provides a computer program product comprising a computer program stored in a computer-readable storage medium. A processor of a computer device reads the computer program from the computer-readable storage medium and executes the computer program, causing the computer device to perform the method described above.
[0036] The embodiments of this application include at least the following beneficial effects: This application provides a traffic mirroring method and apparatus, electronic device and storage medium. This solution improves configuration efficiency and user experience by enabling the local area network mirroring function of the target terminal on the network port control editing page of the server in response to a first instruction; it improves configuration consistency by generating a local area network mirroring enable instruction on the server side, reduces the professional requirements of network administrators, reduces manual operation, and reduces the risk of human error; and it simplifies the traffic mirroring process by enabling the local area network mirroring instruction through the command line tool application of the target terminal, configuring the source port to mirroring mode, improving the accuracy of mirroring configuration, reducing operational complexity, and improving work efficiency. Attached Figure Description
[0037] Figure 1 This is a flowchart of the traffic mirroring method provided in the embodiments of this application;
[0038] Figure 2 This is a flowchart of the steps involved in generating and parsing the traffic mirroring method provided in this application embodiment;
[0039] Figure 3 yes Figure 1 The flowchart of step S103 in the process;
[0040] Figure 4 This is a flowchart illustrating a specific implementation of the traffic mirroring method provided in this application when the terminal is a traffic mirroring device without an IP execution unit.
[0041] Figure 5 This is a schematic diagram of the network port control list page provided in an embodiment of this application;
[0042] Figure 6 This is a schematic diagram of the network port control editing page provided in an embodiment of this application;
[0043] Figure 7 This is a schematic diagram of the network port control list page of the display terminal strategy control provided in this application embodiment;
[0044] Figure 8 This is a schematic diagram of the strategy data page provided in an embodiment of this application;
[0045] Figure 9 This is a schematic diagram of the network port control addition page provided in the embodiments of this application;
[0046] Figure 10 This is a schematic diagram of the flow mirroring device provided in the embodiments of this application;
[0047] Figure 11 This is a schematic diagram of the hardware structure of the electronic device provided in the embodiments of this application. Detailed Implementation
[0048] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit it. In the following description, when referring to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those of this application; they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of this application as detailed in the appended claims.
[0049] It is understood that the terms “first,” “second,” etc., used in this application may be used herein to describe various concepts, but unless otherwise stated, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of the embodiments of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the words “if,” “when,” or “in response to a determination” as used herein may be interpreted as “when…” or “when…” or “in response to a determination.”
[0050] As used in this application, the terms "at least one", "multiple", "each", "any", etc., "at least one" includes one, two or more, "multiple" includes two or more, "each" refers to each of the corresponding multiples, and "any" refers to any one of the multiples.
[0051] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.
[0052] Before providing a detailed description of the embodiments of this application, some of the nouns and terms involved in the embodiments of this application will be explained first. The nouns and terms involved in the embodiments of this application are subject to the following interpretations.
[0053] 1) Local Area Network (LAN): A network of computers and their peripherals connected via a transmission medium within a relatively small geographical area. LANs offer relatively high transmission speeds, typically ranging from hundreds of Mbps to several Gbps, and low latency. LANs facilitate resource sharing, such as printers, file services, and other applications, and enable rapid exchange of data and information.
[0054] 2) USBNET: A technology or device that enables network connectivity via the USB (Universal Serial Bus) interface. USBNET allows a computer to connect to a network via a USB port.
[0055] 3) Secure Socket Layer (SSL), a network security protocol. SSL is a security protocol implemented on top of the TCP / IP transport protocol, employing public-key cryptography. SSL widely supports various types of networks and provides three basic security services.
[0056] 4) A command-line interface (CLI) is a user interface that allows users to interact with computer programs, operating systems, or services by entering a series of commands.
[0057] In related technologies, configuring traffic mirroring (also called network traffic mirroring or port mirroring) is commonly used in network devices and plays an important role in network monitoring and troubleshooting. However, existing methods for configuring traffic mirroring are quite complex, require a deep understanding of network devices, and place high demands on the professional skills of network administrators.
[0058] In summary, the technical problems existing in the relevant technologies need to be improved.
[0059] In view of this, this application provides a traffic mirroring method, apparatus, device, and medium. This solution, in response to a first instruction, enables the local area network (LAN) mirroring function of the target terminal on the network port control editing page of the server, improving configuration efficiency and user experience. By generating a LAN mirroring enable instruction on the server side, configuration consistency is improved, reducing the professional requirements for network administrators, minimizing manual operations, and reducing the risk of human error. Furthermore, by enabling the LAN mirroring instruction through the command-line tool application on the target terminal, the source port is configured in mirroring mode, simplifying the traffic mirroring process, improving the accuracy of mirroring configuration, reducing operational complexity, and increasing work efficiency.
[0060] The traffic mirroring method provided in this application relates to the field of network security technology. The traffic mirroring method provided in this application can be applied to a terminal, a server, or software running on a terminal or server. In some embodiments, the terminal can be a smartphone, tablet, laptop, desktop computer, smart speaker, smartwatch, or in-vehicle terminal, but is not limited to these. The server can be configured as an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The server can also be a node server in a blockchain network. The software can be an application implementing the traffic mirroring method, but is not limited to the above forms.
[0061] This application can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0062] It should be noted that in all specific embodiments of this application, when processing data related to user identity or characteristics, such as user information, user behavior data, user historical data, and user location information, user permission or consent is obtained first. Furthermore, the collection, use, and processing of this data comply with relevant laws, regulations, and standards. In addition, when embodiments of this application require access to sensitive personal information of users, separate permission or consent from the user is obtained through pop-ups or redirects to confirmation pages. Only after obtaining the user's separate permission or consent is the necessary user-related data required for the proper functioning of these embodiments acquired.
[0063] Figure 1 This is an optional flowchart of the traffic mirroring method provided in the embodiments of this application. Figure 1 The method may include, but is not limited to, steps S101 to S103.
[0064] Step S101: In response to the first instruction, enable the local area network mirroring function of the target terminal on the network port control editing page on the server side.
[0065] Specifically, the first instruction is triggered when the LAN mirroring control is selected and clicked or the save control is selected. The first instruction is used to enable the LAN mirroring function of the target terminal.
[0066] In some embodiments, by checking the "Enable LAN mirroring" checkbox on the server-side network port control editing page and clicking "Save," the LAN mirroring function for the target terminal can be enabled. The network port control editing page displays the target terminal identifier.
[0067] This application does not impose specific limitations on the target terminal, which can be flexibly selected based on actual testing needs. For example, the target terminal can be a single terminal or multiple terminals.
[0068] In one specific embodiment, in response to the second instruction, the local area network mirroring function for multiple target terminals is enabled on the network port control add page on the server side. The second instruction is triggered when the batch settings control is selected, multiple target terminals are selected, the local area network mirroring control is selected, and the save control is clicked or selected. The second instruction is used to enable the local area network mirroring function for multiple target terminals.
[0069] Specifically, on the server-side network port control add page, check the batch settings checkbox, select multiple target terminals, check the enable LAN mirroring function checkbox, and click save to enable the LAN mirroring function for multiple target terminals.
[0070] It is understood that this embodiment can be applied to enabling or disabling LAN mirroring on a target terminal. In some embodiments, in response to a third instruction, the LAN mirroring function of the target terminal is disabled on the network port control editing page on the server side. The third instruction is triggered when the LAN mirroring control is deselected and the save control is clicked or selected; the third instruction is used to disable the LAN mirroring function of the target terminal.
[0071] In this embodiment, in response to the first instruction, the local area network mirroring function of the target terminal is enabled on the network port control editing page on the server side. This simplifies the configuration process, and the visual page allows users to perform mirroring configuration intuitively and clearly, thereby reducing operational complexity and improving configuration efficiency and user experience.
[0072] Step S102: Generate a command to enable local area network mirroring via the server.
[0073] Specifically, the command to enable LAN mirroring includes the source port, which represents the port that needs to be mirrored.
[0074] The source port can be predetermined or dynamically selected according to actual needs.
[0075] In some embodiments, a target configuration policy is generated by the server, the target configuration policy including a local area network mirroring instruction; the target configuration policy is encrypted by the server using a security and confidentiality protocol, and the encrypted target configuration policy is sent to the target terminal.
[0076] In one specific embodiment, in response to a click, check mark, or selection of a policy control command on the policy data page, the target configuration policy is sent to the target terminal.
[0077] This application does not impose specific limitations on the security and confidentiality protocol; it can be flexibly selected based on actual testing needs. For example, the security and confidentiality protocol can be either SSL or TLS.
[0078] Optionally, the source port can be dynamically selected when the network status changes, and an appropriate LAN mirroring command can be automatically generated for adjustment, enhancing flexibility.
[0079] Furthermore, traffic can be filtered by protocol, traffic type, etc., and only the filtered network image can be copied to the mirror port.
[0080] It is understood that this embodiment can be applied to generating commands to shut down the local area network mirroring via the server side.
[0081] In this embodiment, generating the LAN mirroring enable command on the server side helps improve configuration consistency, reduces the professional requirements for network administrators, reduces manual operation, reduces the risk of human error, and improves the accuracy of operation.
[0082] Step S103: Enable the LAN mirroring command through the command-line tool application on the target terminal and configure the source port to mirroring mode.
[0083] Specifically, the command to enable LAN mirroring also includes a mirror port, where the target port represents the port that receives mirrored traffic.
[0084] In some embodiments, the target terminal establishes a secure connection with the server using a security and confidentiality protocol; the target terminal receives and parses the encrypted target configuration policy to obtain the command to enable local area network mirroring.
[0085] Furthermore, by using the command-line tools of the Linux system on the target terminal to enable the LAN mirroring command, the integrated switch chip is configured to set the source port of the switch to mirroring mode.
[0086] Understandably, when a switch's source port is configured to mirror mode, all traffic passing through the source port will be mirrored to the mirror port.
[0087] In one specific embodiment, port mirroring is configured via the switch's CLI (command line interface).
[0088] Furthermore, the mirrored port is connected to the maintenance equipment, and network analysis is performed using the analysis and management tools of the maintenance equipment.
[0089] It is understood that this embodiment can be applied to disable the local area network mirroring command and disable the mirroring mode of the source port by using the command line tool application on the target terminal.
[0090] In this embodiment, enabling the LAN mirroring command through the command-line tool application on the target terminal and configuring the source port in mirroring mode helps to simplify the traffic mirroring process, improve the accuracy of mirroring configuration, reduce operational complexity, and improve work efficiency.
[0091] Steps S101 to S103 as illustrated in this embodiment of the application, in response to the first instruction, enable the local area network (LAN) mirroring function of the target terminal on the network port control editing page on the server side, thereby improving configuration efficiency and user experience; by generating the LAN mirroring enable instruction on the server side, the consistency of configuration is improved, the professional requirements for network administrators are reduced, manual operation is reduced, and the risk of human error is reduced; by enabling the LAN mirroring instruction through the command-line tool application on the target terminal, the source port is configured to mirroring mode, simplifying the traffic mirroring process, improving the accuracy of mirroring configuration, reducing operational complexity, and improving work efficiency.
[0092] Please see Figure 2 In some embodiments, the traffic mirroring method provided in this application further includes steps for generating and parsing a policy, which include, but are not limited to, steps S201 to S204:
[0093] Step S201: Generate the target configuration policy through the server.
[0094] Specifically, the target configuration policy includes LAN mirroring instructions.
[0095] In step S201 of some embodiments, the server generates a target configuration policy based on the target terminal and local area network mirroring function enabled operation of the first instruction.
[0096] The server-side uses a preset template to input the target terminal and enable the local area network mirroring function, generating the target configuration policy.
[0097] Furthermore, different preset templates can be used on the server side for different types of terminal devices.
[0098] Optionally, the server generates a configuration file for the target configuration policy based on the target terminal and the local area network mirroring function being enabled. The configuration file can be in formats such as JSON or XML.
[0099] In this embodiment, generating the target configuration policy on the server side helps improve the effectiveness and relevance of the configuration and simplifies the configuration process of traffic mirroring.
[0100] Step S202: The target configuration policy is encrypted using a security and confidentiality protocol on the server side, and the encrypted target configuration policy is sent to the target terminal.
[0101] Among them, security encryption protocols include, but are not limited to, SSL security encryption protocol, AES security encryption protocol and RSA security encryption protocol.
[0102] In step S202 of some embodiments, the target configuration policy is encrypted and sent to the target terminal by the server using the SSL security protocol.
[0103] In this embodiment, the target configuration policy is encrypted by the server using a security and confidentiality protocol, and the encrypted target configuration policy is sent to the target terminal, thereby improving the security of communication.
[0104] Step S203: Establish a secure connection between the target terminal and the server using a security and confidentiality protocol.
[0105] In step S203 of some embodiments, when the target terminal receives a request from the server, it establishes an encrypted secure connection with the server using the same security protocol.
[0106] In this embodiment, the target terminal establishes a secure connection with the server using a security and confidentiality protocol, which helps prevent unauthorized access, enhances the trust between the communicating parties, and improves the security and integrity of network communication.
[0107] Step S204: The target terminal receives and parses the encrypted target configuration policy to obtain the command to enable local area network mirroring.
[0108] In step S204 of some embodiments, the target terminal receives and parses the encrypted target configuration policy to obtain the plaintext target configuration policy.
[0109] Furthermore, obtain the command to enable LAN mirroring from the target configuration policy.
[0110] In this embodiment, the target terminal receives and parses the encrypted target configuration policy to obtain the command to enable local area network mirroring, which optimizes the configuration process, reduces manual operations, and improves work efficiency.
[0111] Steps S201 to S204 as illustrated in this embodiment generate a target configuration policy on the server side, which helps improve the effectiveness and relevance of the configuration and simplifies the traffic mirroring configuration process. The server side encrypts the target configuration policy using a security and confidentiality protocol and sends the encrypted target configuration policy to the target terminal, which improves communication security. The target terminal establishes a secure connection with the server using a security and confidentiality protocol, which helps prevent unauthorized access, enhances the trust between the two communicating parties, and improves the security and integrity of network communication. The target terminal receives and parses the encrypted target configuration policy to obtain the LAN mirroring enable command, which optimizes the configuration process, reduces manual operation, and improves work efficiency.
[0112] Please see Figure 3 In some embodiments, step S103 may include, but is not limited to, steps S301 to S303:
[0113] Step S301: Configure the integrated switch chip built into the integrated chip using the command-line tool in the Linux system on the target terminal.
[0114] In step S301 of some embodiments, the target terminal configures the integrated switch chip built into the integrated chip using ethtool.
[0115] Optionally, the integrated switch chip can be configured via the target terminal using CLI (command line interface).
[0116] Optionally, access the port of the switch chip and configure the source port to mirror.
[0117] For example, the command-line code is as follows:
[0118] #Log in to the switch via SSH
[0119] ssh <username> @ <switch-ip>
[0120] #Enter the password to enter configuration mode
[0121] conf igure termina l
[0122] Step S302: Configure the source port of the switch to mirroring mode.
[0123] In step S302 of some embodiments, the source port of the switch is configured to mirror mode via a command-line tool.
[0124] Step S303: Copy the network traffic of the LAN port to the mirror port.
[0125] In step S303 of some embodiments, network traffic from the LAN port is copied to the mirror port using a command-line tool.
[0126] Optionally, after configuring mirroring on the switch port, you can use tcpdump to capture traffic on the mirrored port.
[0127] For example, the command-line code for configuring the image is shown below:
[0128] # Determine the source port and target mirror port.
[0129] # Enable port mirroring and copy data from the source port to the mirror port.
[0130] spanning-tree portmonitor <source-port>
[0131] #Save configuration
[0132] end
[0133] wr ite memory
[0134] Steps S301 to S303, as shown in the embodiments of this application, configure the integrated switch chip built into the target terminal using the command-line tool in the Linux system. Configure the source port of the switch to mirroring mode and copy the network traffic of the LAN port to the mirror port. This simplifies the traffic mirroring process, improves the accuracy of mirroring configuration, reduces operational complexity, and improves work efficiency.
[0135] Taking the terminal as an IP-free execution unit (such as a firewall without IP) and the server as a control center as an example, Figure 4 This is a flowchart illustrating a specific implementation of the traffic mirroring method provided in this application when the terminal is a network connection without an IP execution unit. Figure 4 The method may include, but is not limited to, steps S401 to S405.
[0136] Step S401: In the network port control list page, identify the target terminal whose status is "online" and click the "Edit" button on the right.
[0137] Understandably, for IP-free execution units (i.e., terminals) already online at the management center, a separate settings list will be displayed. This list includes options to enable or disable LAN mirroring; by default, LAN mirroring is disabled. After selecting the desired function, the administrator clicks the save button to save the configuration to the management center.
[0138] In some embodiments, click "Policy" at the top of the management center, click "Protection and Security" on the left, and click "Network Port Control" under the "Protection and Security" sub-item to open the network port control list page.
[0139] Next, click the "Edit" button on the right to open the network port control editing page.
[0140] For example, a schematic diagram of the network port control list page is shown below. Figure 5 As shown in the diagram. Here, 1 represents a policy control, 2 represents a security control, 3 represents a network port control, and 4 represents an edit button. The settings list displays the terminal's original policies and the edit controls. The original policies include the target terminal, whether LAN mirroring is enabled, the encryption method, and the connection password.
[0141] Understandably, each policy corresponds to a terminal and the editing controls for that line.
[0142] The edit button is associated with the target terminal.
[0143] In step S402, after selecting "Enable LAN Mirroring", click "Save".
[0144] In some embodiments, after selecting "Enable LAN Mirroring" and clicking "Save", the local area network mirroring function of the target terminal is enabled on the network port control editing page on the server side.
[0145] Understandably, this is equivalent to responding to the first instruction by enabling the local area network mirroring function of the target terminal on the network port control editing page on the server side.
[0146] The server-side network port control editing page displays the target terminal, whether LAN mirroring is enabled, the encryption method, and the connection password.
[0147] For example, a schematic diagram of the network port control editing page is shown below. Figure 6 As shown in the image. Here, 1 indicates that the LAN mirroring control is enabled, 2 represents the save button, and the network port control editing page displays the target terminal, whether LAN mirroring is enabled, the encryption method, and the connection password.
[0148] Understandably, the fields on the network port control editing page are used to modify old policies and generate new policies. The target configuration policy is generated based on the target terminal, whether LAN mirroring is enabled, the encryption method, and the connection password on the network port control editing page.
[0149] Step S403: Click the "Terminal Policy" control that appears in the upper right corner, and then click "Confirm Data - Execute Distribution" in the pop-up window.
[0150] In some embodiments, after clicking "Save", click the "Terminal Policy" control that appears in the upper right corner of the network port control list page to open the policy data page.
[0151] For example, a schematic diagram of the network port control list page of the terminal policy control is shown below. Figure 7 As shown.
[0152] Further, on the strategy data page, click "Confirm Data - Execute and Issue".
[0153] The process involves generating a target configuration policy on the server side, and then sending the policy to the target terminal after clicking "Confirm Data - Execute and Distribute".
[0154] In some embodiments, a corresponding configuration policy is generated through a control center (i.e., a server), including specific instructions for enabling or disabling the LAN mirroring function. The configuration data packets are encrypted using an SSL security protocol and sent to the execution unit (i.e., the target terminal).
[0155] It is understandable that this is equivalent to generating a target configuration policy on the server side, which includes LAN mirroring instructions; encrypting the target configuration policy on the server side using a security and confidentiality protocol; and sending the encrypted target configuration policy to the target terminal.
[0156] Furthermore, traffic can be filtered by protocol, traffic type, etc., and only the filtered network image can be copied to the mirror port.
[0157] For example, a schematic diagram of the strategy data page is shown below. Figure 8 As shown. The "Old Content" column displays the old policies of the target terminal, while the "New Content" column displays the target configuration policies to be issued. The target configuration policies include the target terminal (i.e., SA-NAC), the command to enable LAN mirroring, the API address, the encryption method, and the connection password for the connecting user.
[0158] Step S404: Connect to the mirror network port and capture traffic.
[0159] In some embodiments, the execution unit (i.e., the target terminal) establishes a secure connection with the control center (i.e., the server) via the SSL protocol to ensure the confidentiality and integrity of the communication data. After receiving the configuration data packet (i.e., the target configuration policy) issued by the control center, the execution unit parses the instructions in it to obtain the instruction to enable local area network mirroring.
[0160] This is understandable; it's equivalent to enabling LAN mirroring via the command-line tool application on the target terminal, configuring the source port to mirror mode.
[0161] Furthermore, the execution unit uses the command-line tools in the Linux system to configure the integrated switch chip. It configures one port of the switch to mirroring mode, copying network traffic from the LAN port (i.e., the source port) to the mirror port.
[0162] Alternatively, traffic monitoring and management can be performed by connecting the mirror port to an operations and maintenance laptop or device and using relevant packet analysis and management tools.
[0163] Step S405: Enable LAN mirroring in batches.
[0164] In some embodiments, in response to clicking the batch settings button on the network port control list page, the local area network mirroring function for multiple target terminals is enabled on the network port control add page on the server side.
[0165] For example, a diagram of the network port control add page is shown below. Figure 9 As shown in the diagram. In SA-NAC, the left box represents unselected terminals, and the right box represents target terminals. Multiple target terminals can be selected by dragging or clicking the >> button.
[0166] In this embodiment, enabling LAN mirroring in batches simplifies the process of setting up traffic mirroring for multiple terminals, reduces repetitive manual work, and improves work efficiency. At the same time, the visual network port control add page allows users to clearly and intuitively configure policies, which helps to improve the user experience.
[0167] It is understood that the traffic mirroring method of this application can be applied to enable or disable the traffic mirroring function. The configuration process for enabling and disabling the traffic mirroring function is similar, and this application does not impose any restrictions on this.
[0168] This invention provides a highly efficient traffic mirroring method that enables real-time network traffic analysis and risk detection without installing additional software, affecting the performance of the protected device, or interfering with other network devices.
[0169] The execution unit has no IP address and does not become a node in the network, reducing the risk of attack. The device connects to the network transparently, without altering the network topology or affecting the normal operation of other network devices. Secure communication is achieved through the SSL protocol, ensuring the confidentiality and integrity of configuration data transmission and preventing eavesdropping or tampering.
[0170] It should be noted that the device (i.e., the execution unit) has a one-to-one characteristic, enabling it to mirror all traffic passing through the protected device, ensuring data integrity and accuracy. The device is physically connected to the network in series, ensuring that the mirrored traffic cannot be maliciously tampered with or intercepted.
[0171] This invention provides a graphical configuration management interface, enabling network administrators to easily perform configurations and reducing the professional requirements for network administrators. The control center provides a separate settings list, allowing administrators to individually enable or disable LAN mirroring for each execution unit to adapt to different network needs.
[0172] The device is designed to be plug-and-play, requiring no IP address and not consuming network resources, thus simplifying the installation and configuration process and improving system flexibility.
[0173] Specifically, once a risk is identified, managers can take immediate action to develop and implement new protection strategies to improve network security and stability.
[0174] Understandably, compared to purchasing and maintaining dedicated traffic analysis equipment, this invention reduces overall costs by combining hardware and software with network access control functions, while providing greater flexibility and security.
[0175] This application embodiment enables the local area network (LAN) mirroring function of the target terminal on the network port control editing page of the server in response to the first instruction, thereby improving configuration efficiency and user experience; by generating the LAN mirroring enable command on the server side, the consistency of configuration is improved, the professional requirements of network administrators are reduced, manual operation is reduced, and the risk of human error is reduced; by enabling the LAN mirroring command through the command line tool application on the target terminal, the source port is configured to mirroring mode, simplifying the traffic mirroring process, improving the accuracy of mirroring configuration, reducing operational complexity, and improving work efficiency.
[0176] Please see Figure 10 This application also provides a traffic mirroring device that can implement the above-described traffic mirroring method. The device includes:
[0177] Function control module 1001 is used to enable the local area network mirroring function of the target terminal in response to the first instruction on the network port control editing page on the server side;
[0178] The instruction generation module 1002 is used to generate an enable LAN mirroring instruction through the server, wherein the enable LAN mirroring instruction includes a source port;
[0179] Configuration module 1003 is used to configure the source port as a mirroring mode by applying the enable LAN mirroring command through the command line tool of the target terminal.
[0180] It is understood that the content of the above method embodiments is applicable to the present device embodiments. The specific functions implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0181] This application also provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the above-described traffic mirroring method. This electronic device can be any smart terminal, including tablet computers, in-vehicle computers, etc.
[0182] It is understood that the content of the above method embodiments is applicable to this device embodiment. The specific functions implemented by this device embodiment are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0183] Please see Figure 11 , Figure 11 The hardware structure of an electronic device according to another embodiment is illustrated. The electronic device includes:
[0184] The processor 1101 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to achieve the technical solutions provided in the embodiments of this application.
[0185] The memory 1102 can be implemented as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1102 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1102 and is called and executed by the processor 1101 using the traffic mirroring method of the embodiments of this application.
[0186] Input / output interface 1103 is used to implement information input and output;
[0187] The communication interface 1104 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).
[0188] Bus 1105 transmits information between various components of the device (e.g., processor 1101, memory 1102, input / output interface 1103, and communication interface 1104);
[0189] The processor 1101, memory 1102, input / output interface 1103 and communication interface 1104 are connected to each other within the device via bus 1105.
[0190] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described traffic mirroring method.
[0191] It is understood that the content of the above method embodiments is applicable to this storage medium embodiment. The specific functions implemented in this storage medium embodiment are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those achieved in the above method embodiments.
[0192] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0193] This application also provides a computer program product that, when run on a computer, causes the computer to execute the traffic mirroring methods provided in the above-described method embodiments.
[0194] The traffic mirroring method, traffic mirroring device, electronic device, and storage medium provided in this application enable the local area network (LAN) mirroring function of the target terminal on the network port control editing page of the server in response to a first instruction, thereby improving configuration efficiency and user experience; by generating a LAN mirroring enable instruction on the server side, the consistency of configuration is improved, the professional requirements of network administrators are reduced, manual operation is reduced, and the risk of human error is reduced; by enabling the LAN mirroring instruction through the command-line tool application of the target terminal, the source port is configured to mirroring mode, simplifying the traffic mirroring process, improving the accuracy of mirroring configuration, reducing operational complexity, and improving work efficiency.
[0195] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.
[0196] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.
[0197] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0198] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or suitable combinations thereof.
[0199] The terms "first," "second," "third," "fourth," etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0200] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0201] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0202] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0203] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0204] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0205] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of the present application shall be within the scope of the claims of the present application. < / username>
Claims
1. A traffic mirroring method, characterized in that, The method includes the following steps: In response to the first instruction, the LAN mirroring function of the target terminal is enabled on the network port control editing page on the server side. The target terminal is a physical network device without an IP address. The first instruction is triggered when the LAN mirroring control is selected and clicked or the save control is selected. The first instruction includes the target terminal and the operation of enabling the LAN mirroring function. The network port control editing page includes configuration items, including the target terminal, whether to enable LAN mirroring, encryption method, and connection password. The server uses a preset template to input the target terminal and enable the LAN mirroring function, generating a target configuration policy. The target configuration policy includes an enable LAN mirroring command, which includes a source port and a mirror port. The server encrypts the target configuration policy using a security and confidentiality protocol and sends the encrypted target configuration policy to the target terminal. The target terminal establishes a secure connection with the server using the security and confidentiality protocol. The target terminal receives and parses the encrypted target configuration policy to obtain the command to enable local area network mirroring. The source port is configured to mirror mode by applying the LAN mirroring command through the command-line tool of the target terminal. The step of applying the LAN mirroring enable command via the command-line tool of the target terminal to configure the source port in mirroring mode includes: By applying the LAN mirroring command through the command-line tool of the target terminal, the integrated switch chip is configured to set the source port of the switch to mirroring mode, and the network traffic of the source port is copied to the network traffic of the mirror port.
2. The method according to claim 1, characterized in that, The method further includes: Connect the mirrored port to the maintenance equipment and perform network analysis using the maintenance equipment's analysis and management tools.
3. The method according to claim 1, characterized in that, The method further includes: In response to the second instruction, enable the LAN mirroring function for multiple target terminals on the network port control add page on the server side.
4. A flow mirroring device, characterized in that, The device includes: The function control module is used to respond to a first instruction to enable the LAN mirroring function of the target terminal on the network port control editing page on the server side. The target terminal is a physical network device without an IP address. The first instruction is triggered when the LAN mirroring control is selected and clicked or the save control is selected. The first instruction includes the target terminal and the LAN mirroring function enabling operation. The network port control editing page includes configuration items, including the target terminal, whether to enable LAN mirroring, encryption method, and connection password. The instruction generation module is used to generate an enable LAN mirroring instruction via the server, wherein the enable LAN mirroring instruction includes a source port; The configuration module is used to apply the enable LAN mirroring command through the command line tool of the target terminal to configure the source port as mirroring mode; The instruction generation module is specifically used for: The server uses a preset template to input the target terminal and enable the LAN mirroring function, generating a target configuration policy. The target configuration policy includes an enable LAN mirroring command, which includes a source port and a mirror port. The server encrypts the target configuration policy using a security and confidentiality protocol and sends the encrypted target configuration policy to the target terminal. The target terminal establishes a secure connection with the server using the security and confidentiality protocol. The target terminal receives and parses the encrypted target configuration policy to obtain the command to enable local area network mirroring. The configuration module is specifically used for: By applying the LAN mirroring command through the command-line tool of the target terminal, the integrated switch chip is configured to set the source port of the switch to mirroring mode, and the network traffic of the source port is copied to the network traffic of the mirror port.
5. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the method of any one of claims 1 to 3.
6. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 3.