Flow classification method and system based on SmartNIC

By adopting a SmartNIC-based method in the traffic classification system, using hash values ​​and hash buckets to track the network flow state and performing standardized processing, the traffic classification system calculates pressure and stability in a high concurrency environment is solved, and efficient traffic classification and processing is achieved.

CN120151291APending Publication Date: 2025-06-13NORTHEASTERN UNIV CHINA
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510304440.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

In cloud computing, big data centers and high concurrent network environments, traffic classification systems need to process massive network data packets, resulting in increased computing pressure on server CPU and GPU, and increased system delay, throughput and energy consumption, affecting real-time and stability.

Method used

The traffic classification method based on SmartNIC is adopted to monitor network traffic in real time, obtain pending data packets, and use hash values ​​and hash buckets to track network flow status to reduce the computing pressure of the server. After standardizing the pending data packets, traffic classification is performed, and efficient parallel packet processing is achieved using multi-core ARM processor and multi-queue processing mechanism.

Benefits of technology

It effectively reduces the computing pressure of server CPU and GPU, reduces system delay, throughput and energy consumption, and ensures the real-time and stability of the traffic classification system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151291A_ABST
    Figure CN120151291A_ABST
Patent Text Reader

Abstract

The invention discloses a flow classification method based on SmartNIC, and the method comprises the steps: monitoring the network flow in real time, and obtaining a to-be-processed data package in the network flow; determining a hash value of a network flow corresponding to the to-be-processed data packet, determining a hash bucket where the to-be-processed data packet is located according to the hash value, and tracking the state of the network flow according to the hash bucket; accumulating the number of the data packets to be processed to a first preset number; performing standardization processing on the target number of to-be-processed data packets to obtain a target number of target data packets; and performing traffic classification on the target number of target data packets. After the Hash value and the Hash bucket are obtained, the state of the network flow can be effectively tracked, the calculation pressure of a CPU and a GPU of a server is reduced, the system delay, the throughput and the energy consumption are reduced, and the real-time performance and the stability of a flow classification system are ensured. In addition, the invention also provides a flow classification system based on the SmartNIC.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network traffic classification, and in particular, to a traffic classification method and system based on SmartNIC. Background Art

[0002] In today's cloud computing environment, real-time network traffic classification plays a crucial role in ensuring quality of service (QoS) and enhancing network security. Accurate traffic classification can ensure that different types of network traffic are reasonably allocated, optimize bandwidth utilization, and timely monitor, identify, and isolate malicious traffic, thereby effectively preventing distributed denial of service (DDoS) attacks, data leakage, and other network threats. Currently, the mainstream method to improve traffic classification accuracy is to use machine learning (ML) models for classification. Machine learning methods can automatically extract traffic characteristics from a large amount of complex network data. Compared with traditional classification methods based on ports or deep packet inspection (DPI), ML models have stronger generalization ability and adaptability to encrypted traffic, so they have been widely used in modern network environments.

[0003] However, with the continuous expansion of the scale of data centers and the increase in the complexity of traffic classification models, the demand for computing resources for this task has increased exponentially. Especially in cloud computing, big data centers, and high-concurrency network environments, traffic classification systems often need to process a huge number of network packets and complete tasks such as feature extraction and classification inference in real time. This high computational load not only exacerbates the computational pressure on the server CPU and GPU but also may cause problems such as increased system latency, decreased throughput, and increased energy consumption, seriously affecting the real-time performance and stability of traffic classification systems. Summary of the Invention

[0004] Based on this, it is necessary to address the above problems and propose a traffic classification method and system based on SmartNIC.

[0005] A traffic classification method based on SmartNIC, the method includes:

[0006] Real-time monitor network traffic and obtain the to-be-processed packets in the network traffic;

[0007] Determine the hash value of the network flow corresponding to the to-be-processed packet, determine the hash bucket where the to-be-processed packet is located according to the hash value, and track the state of the network flow according to the hash bucket; and accumulate the number of the to-be-processed packets to a first pre-determined number;

[0008] Perform normalization processing on the target number of to-be-processed packets to obtain the target number of target packets;

[0009] Perform traffic classification on the target number of target data packets.

[0010] In one embodiment, determining the hash value of the network flow corresponding to the data packet to be processed, determining the hash bucket where the data packet to be processed is located according to the hash value, and tracking the state of the network flow according to the hash bucket; includes:

[0011] Determine the flow five-tuple of the first data, and calculate the hash value for the flow five-tuple;

[0012] Track the state of the network flow using the hash value as the key, and identify the network flow to which the data packet to be processed belongs through the hash bucket;

[0013] If the data packet to be processed belongs to a network flow that first appears in the hash bucket, create a first network flow record corresponding to the first data in the hash bucket, and mark the data packet to be processed as the first data packet of the first network flow;

[0014] If the first data packet belongs to an existing network flow in the hash bucket, update the existing network flow in the hash bucket, and mark the sequence number of the data packet to be processed in the first network flow.

[0015] In one embodiment, the accumulating the number of data packets to be processed to the first pre-number includes:

[0016] Determine the target number of data packets to be processed. If the current number of data packets to be processed is less than or equal to the target number, store the data packets to be processed and add the current number of data packets to be processed to the forwarding queue;

[0017] If the current number of data packets to be processed is greater than the target number, forward the current number of data packets to be processed.

[0018] In one embodiment, the obtaining the target number of target data packets after standardizing the target number of data packets to be processed includes:

[0019] Remove redundant header information from the target number of data packets to be processed to obtain a first data packet;

[0020] Adjust the length of the first data packet to the target length to obtain a second data packet;

[0021] Perform scaling processing on the second data packet to obtain the target data packet.

[0022] In one embodiment, after obtaining the target number of target data packets by standardizing the target number of data packets to be processed, it further includes:

[0023] Monitor network traffic in real time and determine whether the network load is greater than a preset value based on the current network traffic;

[0024] If the network load is greater than the preset value, trigger a mechanism to send the target data packet to classify the traffic of the target data packet;

[0025] If the network load remains less than the preset value within a waiting time, trigger a mechanism to forcibly send the target data packet to classify the traffic of the target data packet.

[0026] In one embodiment, classifying the traffic of the target number of target data packets includes:

[0027] Determine metadata and screen the target data packet according to the metadata to achieve classification;

[0028] The metadata includes: the batch number and traffic classification identifier for indicating the data packet to be processed.

[0029] This application also provides a traffic classification system based on SmartNIC, and the system includes:

[0030] An acquisition module for monitoring network traffic in real time and acquiring the data packets to be processed in the network traffic;

[0031] An analysis module for determining the hash value of the network flow corresponding to the data packet to be processed, determining the hash bucket where the data packet to be processed is located according to the hash value, and tracking the state of the network flow according to the hash bucket; and accumulating the number of the data packets to be processed to a first preset number;

[0032] A preprocessing module for performing normalization processing on the target number of data packets to be processed to obtain a target number of target data packets;

[0033] A traffic classification module for classifying the traffic of the target number of target data packets.

[0034] In one embodiment,

[0035] Both the analysis module and the preprocessing module are provided on the SmartNIC;

[0036] The traffic classification module is provided on the host;

[0037] The SmartNIC is communicatively connected to the host.

[0038] In one embodiment,

[0039] The analysis module is further configured to determine the flow five-tuple of the first data, calculate the hash value for the flow five-tuple, track the state of the network flow using the hash value as a key, and identify the network flow to which the to-be-processed packet belongs through the hash bucket. If the to-be-processed packet belongs to a network flow that first appears in the hash bucket, a first network flow record corresponding to the first data is created in the hash bucket, and the to-be-processed packet is marked as the first packet of the first network flow. If the first packet belongs to an existing network flow in the hash bucket, the existing network flow in the hash bucket is updated, and the sequence number of the to-be-processed packet in the first network flow is marked.

[0040] In one embodiment,

[0041] The preprocessing module is further configured to determine the target quantity of the to-be-processed packets to be processed. If the current quantity of the to-be-processed packets is less than or equal to the target quantity, the to-be-processed packets are stored and the current quantity of to-be-processed packets is added to the forwarding queue. If the current quantity of the to-be-processed packets is greater than the target quantity, the current quantity of to-be-processed packets is forwarded.

[0042] The present invention monitors network traffic in real time, obtains the to-be-processed packets in the network traffic, determines the hash value of the network flow corresponding to the to-be-processed packets, determines the hash bucket where the to-be-processed packets are located according to the hash value, and tracks the state of the network flow according to the hash bucket. And accumulates the quantity of the to-be-processed packets to a first pre-quantity, performs normalization processing on the target quantity of to-be-processed packets to obtain the target quantity of target packets, and classifies the traffic of the target quantity of target packets. After obtaining the hash value and the hash bucket, the state of the network flow can be effectively tracked, reducing the computing pressure on the server CPU and GPU, reducing system latency, throughput, and energy consumption, and ensuring the real-time performance and stability of the traffic classification system. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0044] Among them:

[0045] Figure 1 FIG. is an application environment diagram of a traffic classification method based on SmartNIC in one embodiment;

[0046] Figure 2 Flowchart of a traffic classification method based on SmartNIC in an embodiment;

[0047] Figure 3 Block diagram of a traffic classification system based on SmartNIC in an embodiment;

[0048] Figure 4 Flowchart of the analysis module and the preprocessing module in an embodiment;

[0049] Figure 5 Flowchart of a two - level regulation strategy of short - term window and long - term window in an embodiment;

[0050] Figure 6 Schematic diagram of a parallel pipeline scheduling mechanism in an embodiment;

[0051] Figure 7 Block diagram of a computer device in an embodiment. Detailed implementation manners

[0052] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the scope of protection of the present invention.

[0053] With the continuous expansion of the scale of the data center and the increase in the complexity of the traffic classification model, the demand for computing resources for this task has increased exponentially. Especially in cloud computing, big data centers, and high - concurrency network environments, traffic classification systems often need to process a large number of network data packets and complete tasks such as feature extraction and classification inference in real - time. This high computing load not only exacerbates the computing pressure on the server CPU and GPU but also may cause problems such as increased system latency, decreased throughput, and increased energy consumption, seriously affecting the real - time performance and stability of the traffic classification system. To solve the above - mentioned technical problems, this application provides a traffic classification method and system based on SmartNIC (intelligent network card). Figure 1 Application environment diagram of a traffic classification method based on SmartNIC in an embodiment. Refer to Figure 1, the SmartNIC-based traffic classification method is applied to a SmartNIC-based traffic classification system. The SmartNIC-based traffic classification system includes a terminal 110 and a server 120. The terminal 110 and the server 120 are connected through a network. The terminal 110 can specifically be a desktop terminal or a mobile terminal, and the mobile terminal can specifically be at least one of a mobile phone, a tablet computer, a laptop computer, etc. The server 120 can be implemented by an independent server or a server cluster composed of multiple servers. The terminal 110 is used to monitor network traffic in real time and obtain the packets to be processed in the network traffic; determine the hash value of the network flow corresponding to the packet to be processed, determine the hash bucket where the packet to be processed is located according to the hash value, and track the status of the network flow according to the hash bucket; and accumulate the number of the packets to be processed to a first preset quantity; perform normalization processing on the target quantity of the packets to be processed to obtain a target quantity of target packets, and the server 120 is used to perform traffic classification on the target quantity of target packets.

[0054] As Figure 2 shown, the SmartNIC-based traffic classification method of this application includes:

[0055] S10: Monitor network traffic in real time and obtain the packets to be processed in the network traffic;

[0056] S20: Determine the hash value of the network flow corresponding to the packet to be processed, determine the hash bucket where the packet to be processed is located according to the hash value, and track the status of the network flow according to the hash bucket; and accumulate the number of the packets to be processed to a first preset quantity.

[0057] Specifically, determine the flow five-tuple of the first data, and calculate the hash value for the flow five-tuple; use the hash value as a key to track the status of the network flow, and identify the network flow to which the packet to be processed belongs through the hash bucket; if the packet to be processed belongs to a network flow that first appears in the hash bucket, create a first network flow record corresponding to the first data in the hash bucket, and mark the packet to be processed as the first packet of the first network flow; if the first packet belongs to an existing network flow in the hash bucket, update the existing network flow in the hash bucket, and mark the order of the packet to be processed in the first network flow; at the same time, determine the target quantity of the packets to be processed required. If the current quantity of the packets to be processed is less than or equal to the target quantity, store the packets to be processed and add the current quantity of the packets to be processed to the forwarding queue; if the current quantity of the packets to be processed is greater than the target quantity, forward the current quantity of the packets to be processed.

[0058] Further, utilize the RSS hardware feature built into the SmartNIC to calculate the hash value of the flow five-tuple of the packet to be processed, and allocate the packet to be processed to different processing queues according to the preset queue mapping rules. This process is executed by hardware standardization to ensure efficient and consistent calculation of the hash value, which is used as the unique identifier of the network flow corresponding to the packet to be processed for hash bucket indexing.

[0059] As Figure 4 shown, adopt a multi-core ARM processor architecture and combine it with a multi-queue processing mechanism to allocate different network flows to multiple processing cores to achieve efficient parallel packet processing. Specifically, when the packet to be processed arrives at the SmartNIC, first utilize the RSS hardware feature built into the SmartNIC to calculate the hash value of the flow five-tuple of the packet to be processed. Use the hash value as the key to query the status of the network flow, and use a hash bucket to identify the network flow to which the packet to be processed belongs. If the packet to be processed belongs to an existing network flow in the hash bucket, update the existing network flow in the hash bucket and mark the sequence number of the packet to be processed in the first network flow. S30: Standardize the target number of packets to be processed to obtain the target number of target packets.

[0060] Specifically, remove the redundant header information in the target number of packets to be processed to obtain the first packet; adjust the length of the first packet to the target length to obtain the second packet; perform scaling processing on the second packet to obtain the target packet.

[0061] Further, after obtaining the target number of packets to be processed, first, perform data interception on the packets to be processed: remove the redundant header information in the packets to be processed to obtain the first packet to ensure the unity of the input format and improve the processing efficiency. Then, perform length padding on the first packet: adjust the packet to be processed to the target length to obtain the second packet to adapt to the input requirements of the traffic classification model. Finally, perform normalization processing on the second packet: perform scaling processing on the second packet to optimize the stability of the model and improve the accuracy and robustness of the inference process. To cope with the dynamically changing network characteristics, combine a traffic-aware dynamic batch submission mechanism to dynamically adjust the batch data submission strategy according to the real-time network traffic to optimize the processing efficiency and adapt to different network load conditions.

[0062] S40: Classify the target number of target packets according to the traffic.

[0063] Specifically, determine the metadata, and screen the target packets according to the metadata to achieve classification; the metadata includes: the batch quantity and traffic classification identifier used to indicate the packet to be processed.

[0064] In one embodiment, after step S30, it further includes: monitoring network traffic in real time, determining whether the network load is greater than a preset value according to the current network traffic; if the network load is greater than the preset value, triggering a mechanism for sending the target data packet to classify the traffic of the target data packet; if the network load is continuously less than the preset value within a waiting time, triggering a mechanism for forcibly sending the target data packet to classify the traffic of the target data packet.

[0065] Specifically, after completing the standardization processing of the data packet, it will be temporarily stored in the submission queue. This mechanism adaptively adjusts the submission strategy of the data batch by sensing the real-time network load to ensure the efficiency and real-time nature of the traffic classification task.

[0066] This mechanism introduces a two-level adjustment strategy of a short-term window and a long-term window to achieve adaptive optimization of data submission: Short-term window strategy: This strategy monitors network traffic in real time. When a high network load is detected, it immediately triggers the submission of target data to reduce the system processing delay. For the long-term window strategy: This strategy analyzes the target data within a relatively long time range to avoid excessive delay in submitting target data in the case of low load. If the short-term window does not trigger the submission of target data, the long-term window will enforce batch submission to ensure the continuity of target data processing. As Figure 5 shown in the following two cases. First, the short-term window is mainly used to handle high network load scenarios. When the network traffic surges within a short period of time, the arrival rate of data packets increases significantly. If not submitted in time, it may lead to backlog in the system buffer, increase the data processing delay, and even affect the overall throughput. Therefore, the short-term window continuously monitors the real-time traffic situation and immediately triggers batch submission when the detected traffic exceeds the threshold. For example, in a high-concurrency server environment, sudden user requests may cause an instantaneous increase in traffic. The fast response mechanism of the short-term window can ensure that the data is submitted as soon as possible and reduce the queuing waiting time. On the other hand, the long-term window is used to handle continuous low-load scenarios. When the network traffic is low and the arrival interval of data packets is long, the system may not reach the trigger condition of the short-term window for a long time. If only relying on the short-term window at this time, the data may accumulate for a long time, resulting in an increase in processing delay and affecting the final user experience. Therefore, the long-term window will forcibly trigger batch submission when the short-term window fails to trigger submission continuously.

[0067] The specific implementation process is as follows:

[0068] S100: Initialize key parameters, where the key parameters include: the waiting time and the batch size threshold of the short-term window. Among them, the waiting time determines the waiting duration of the system within the short-term window, and is preset by the model, representing the minimum number of data packets to be processed required for a batch.

[0069] S200: The preprocessing module continuously collects the data packets to be processed transmitted by the analysis module, converts them into target data packets, and accumulates the received target data packets, where the batch size of the target data packets is Anew. Whenever a new target data packet is processed, the preprocessing module updates Anew and checks whether the condition for triggering submission is met.

[0070] S300: Short-time window trigger mechanism: If the current batch size reaches or exceeds the threshold, that is, the number of data packets accumulated within the current short-time window is sufficient, batch submission is immediately triggered. After triggering the submission, the system resets the window state, clears the submitted data, and continues to monitor the new data traffic.

[0071] S400: Long-time window trigger mechanism: If the short-time window does not meet the trigger condition, the system does not immediately submit the data, but continues to wait for seconds to accumulate more data packets to improve the efficiency of batch submission. If the batch threshold is still not reached after waiting, the system does not wait indefinitely, but sets the long-time window flag window to 1, indicating that the current is in a low-load state, and enters the long-time window monitoring stage. If the submission is still not triggered in the subsequent short-time windows and the window flag remains 1, it means that the system has failed to meet the short-time window trigger condition multiple times in a row. At this time, the long-time window forcibly submits the currently accumulated data packets to avoid long-term data retention.

[0072] S500: State reset after submission Once the batch submission is triggered (whether it is the short-time window or the long-time window), the system resets window to 0, indicating the start of a new monitoring cycle. Enter the next round of traffic monitoring, continue to collect new data packets, and decide whether to trigger submission again according to the network load situation.

[0073] This application also provides a traffic classification system based on SmartNIC, as Figure 3 shown, the system includes: an acquisition module 10, an analysis module 20, a preprocessing module 30, and a traffic classification module 40, where:

[0074] The acquisition module 10 is used to monitor network traffic in real time and acquire the data packets to be processed in the network traffic.

[0075] The analysis module 20 is used to determine the hash value of the network flow corresponding to the data packet to be processed, determine the hash bucket where the data packet to be processed is located according to the hash value, and track the state of the network flow according to the hash bucket; and accumulate the number of the data packets to be processed to the first pre-number.

[0076] The preprocessing module 30 is used to perform normalization processing on the target number of data packets to be processed to obtain the target number of target data packets.

[0077] The traffic classification module 40 is configured to perform traffic classification on a target number of target data packets.

[0078] In one embodiment,

[0079] Both the analysis module 20 and the preprocessing module 30 are disposed on the SmartNIC.

[0080] The traffic classification module 40 is disposed on the host.

[0081] The SmartNIC and the host are communicatively connected.

[0082] In one embodiment, the analysis module 20 is further configured to determine the flow five-tuple of the first data, and calculate the hash value for the flow five-tuple; track the state of the network flow using the hash value as a key, and identify the network flow to which the packet to be processed belongs through the hash bucket; if the packet to be processed belongs to a network flow that first appears in the hash bucket, create a first network flow record corresponding to the first data in the hash bucket, and mark the packet to be processed as the first packet of the first network flow; if the first packet belongs to an existing network flow in the hash bucket, update the existing network flow in the hash bucket, and mark the sequence number of the packet to be processed in the first network flow.

[0083] In one embodiment, the preprocessing module 30 is further configured to determine the target number of packets to be processed. If the current number of packets to be processed is less than or equal to the target number, store the packets to be processed and add the current number of packets to be processed to the forwarding queue; if the current number of packets to be processed is greater than the target number, forward the current number of packets to be processed. Since the conditions for the target data packets required by different traffic classification models in the traffic classification module 40 are different, it is necessary to determine the storage and forwarding of the target data packets according to the requirements. If the first N target data packets are required to construct the input of the model, then N target data packets need to be collected. If the current number of target data packets is less than or equal to the target number N (i.e., the model requires the first N packets of this flow), store the target data packets and add them to the forwarding queue. If the sequence number of the target data packet exceeds the target number N, forward it directly without storage to reduce the storage overhead.

[0084] In this application, the communication protocol between the SmartNIC and the host efficiently supports data adaptation and transmission for different network traffic classification models under a heterogeneous computing architecture. Since different traffic classification models may have different input formats, batch processing methods, and computing requirements, the design of this communication protocol ensures high flexibility and generality in data interaction between the SmartNIC and the host, so as to adapt to different task scenarios and improve the overall system processing efficiency.

[0085] This communication protocol mainly consists of two parts: metadata and batch data, to ensure the integrity and resolvability of data transmission. Metadata: Used to carry task-related information, including batch size, traffic classification model identifier, and possible additional parameters, to ensure that the host can correctly parse the model used in the current batch and its corresponding data format. The introduction of metadata enables the host to dynamically identify different traffic classification tasks, thereby adapting different inference models at runtime and avoiding processing errors caused by data format mismatches. At the same time, this protocol allows additional control information, such as task priority, data encryption status, and additional processing instructions, to be attached to the metadata to further optimize task scheduling and data management strategies. Batch data: Used to store actual inference input data, including preprocessed data packets or traffic feature information. Batch data is used in combination with metadata to ensure the correct parsing and processing of data. Since different traffic classification tasks may require different batch sizes or data formats, the protocol supports dynamic adaptation of variable batch sizes, enabling the system to flexibly adjust the batch scale according to the current network load and computing resource status, improving throughput and real-time performance.

[0086] This communication protocol allows the SmartNIC to dynamically adjust the submission method of batch data to adapt to different network traffic loads and computing resource states. Specifically, it implements a parallel pipeline scheduling mechanism; as Figure 6 shown, it is a schematic diagram of the parallel pipeline scheduling mechanism, which is used to optimize data transmission and computing scheduling in a heterogeneous computing architecture to reduce data transmission latency and improve system throughput. In the parallel pipeline scheduling mechanism of the present invention, the SmartNIC preprocesses traffic data and transmits the processed batch data to the host through the communication protocol. To avoid waiting problems between data transmission and computing tasks, the present invention sets up a batch data buffer at the host end to store the data transmitted by the SmartNIC. The function of this buffer is that when the host executes traffic classification tasks, it can directly read data from the buffer without waiting for the SmartNIC to transmit new batch data, thus ensuring the continuous execution of computing tasks.

[0087] Specifically, the execution process of this parallel pipeline scheduling mechanism is as follows:

[0088] S1000: Data Preprocessing: The SmartNIC performs standardization processing on the received network packets, including steps such as packet format conversion, truncation, padding, and normalization. After preprocessing, the SmartNIC constructs batches of packets that meet the input requirements of the traffic classification model according to the dynamic batch strategy in the preprocessing module.

[0089] S2000: Data Batch Transmission: After the SmartNIC finishes preprocessing a batch of data, it transmits the batch of packets to the buffer on the host side through the SmartNIC-host communication protocol. At this time, the SmartNIC does not need to wait for the host side to complete the current batch task, but can continue to receive and process new packets, generate new batches of packets, and continue to submit packets when there is free space in the buffer.

[0090] S3000: Data Buffering and Storage: The buffer on the host side is responsible for receiving the batch of packets transmitted by the SmartNIC and manages the access of packets according to the first-in, first-out strategy. Due to the existence of the buffer, the host side does not need to directly wait for the real-time packet transmission from the SmartNIC, but can extract packets from the buffer at any time to perform the traffic classification task.

[0091] S4000: Execution of Traffic Classification Task: When the computing resources (CPU / GPU) on the host side are idle, it directly extracts the next batch of packets from the buffer for traffic classification inference. After the GPU computing task is completed, the host side can immediately obtain the next batch of packets without being stalled due to waiting for the SmartNIC to transmit packets.

[0092] S5000: Alternate Execution of Tasks: While the SmartNIC continuously submits new batches of packets, the host side also continuously obtains packets from the buffer and performs the traffic classification task. This process forms a parallel pipeline, where the SmartNIC continuously submits new task data, and the host side automatically performs calculations in a packet-driven manner without explicitly waiting for packet input for synchronization.

[0093] S6000: Task Completion and Resource Release: Once the host side completes the inference calculation of the current batch of packets, the corresponding packets in the buffer will be released to make room for the new packets subsequently submitted by the SmartNIC. In this way, the SmartNIC can continuously submit batches of packets, and the host side can stably obtain new tasks to ensure the coherence of task processing.

[0094] The present invention monitors network traffic in real time and obtains the data packets to be processed in the network traffic; determines the hash value of the network flow corresponding to the data packet to be processed, determines the hash bucket where the data packet to be processed is located according to the hash value, and tracks the status of the network flow according to the hash bucket; and accumulates the number of the data packets to be processed to a first predetermined number; performs normalization processing on the target number of data packets to be processed to obtain a target number of target data packets; and classifies the traffic of the target number of target data packets. After obtaining the hash value and the hash bucket, the status of the network flow can be effectively tracked, the computational pressure on the server CPU and GPU is reduced, the system latency, throughput, and energy consumption are reduced, and the real-time performance and stability of the traffic classification system are ensured.

[0095] Figure 7 shows the internal structure diagram of a computer device in an embodiment. The computer device may specifically be a terminal or a server. As Figure 7 shown, the computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the memory includes a non-volatile storage medium and an internal memory. The non-volatile storage medium of the computer device stores an operating system and may also store a computer program. When the computer program is executed by the processor, the processor can implement the traffic classification method based on SmartNIC. The internal memory may also store a computer program. When the computer program is executed by the processor, the processor can execute the traffic classification method based on SmartNIC. Those skilled in the art can understand that Figure 7 the structure shown in

[0096] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a non-volatile computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in this application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0097] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0098] The above-described embodiments merely represent several implementation manners of this application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of this application. It should be noted that for those of ordinary skill in the art, without departing from the concept of this application, several modifications and improvements can still be made, and these all belong to the protection scope of this application. Therefore, the protection scope of the patent of this application should be subject to the appended claims.

Claims

1. A traffic classification method based on SmartNIC, the method comprising: Monitor network traffic in real time and obtain data packets to be processed in the network traffic; Determine a hash value of the network flow corresponding to the data packet to be processed, determine a hash bucket where the data packet to be processed is located according to the hash value, and track the state of the network flow according to the hash bucket; and accumulate the number of the data packets to be processed to a first predetermined number; Standardizing the target number of data packets to be processed to obtain a target number of target data packets; Traffic classification is performed on a target number of target packets.

2. The SmartNIC-based traffic classification method according to claim 1, characterized in that: The method of determining a hash value of a network flow corresponding to the data packet to be processed, determining a hash bucket where the data packet to be processed is located according to the hash value, and tracking a state of the network flow according to the hash bucket comprises: Determine a stream quintuple of the first data, and calculate the hash value for the stream quintuple; Tracking the state of the network flow using the hash value as a key, and identifying the network flow to which the to-be-processed data packet belongs through the hash bucket; If the data packet to be processed belongs to a network flow that appears in the hash bucket for the first time, creating a first network flow record corresponding to the first data in the hash bucket, and marking the data packet to be processed as the first data packet of the first network flow; If the first data packet belongs to an existing network flow in the hash bucket, the existing network flow in the hash bucket is updated, and the sequence number of the data packet to be processed in the first network flow is marked.

3. The SmartNIC-based traffic classification method according to claim 1, characterized in that: The accumulating the number of the to-be-processed data packets to a first predetermined number comprises: Determine a target number of packets to be processed, and if the current number of packets to be processed is less than or equal to the target number, store the packets to be processed and add the current number of packets to be processed to a forwarding queue; If the current number of the data packets to be processed is greater than the target number, the current number of data packets to be processed are forwarded.

4. The SmartNIC-based traffic classification method according to claim 1, characterized in that: The step of obtaining a target number of target data packets by standardizing the target number of data packets to be processed comprises: Removing redundant header information from the target number of data packets to be processed to obtain a first data packet; adjusting the length of the first data packet to a target length to obtain a second data packet; The second data packet is scaled to obtain the target data packet.

5. According to the SmartNIC-based traffic classification method of claim 4, after the target number of to-be-processed data packets are subjected to standardization processing to obtain the target number of target data packets, the method further comprises: Monitor network traffic in real time and determine whether the network load is greater than the preset value based on the current network traffic; If the network load is greater than the preset value, a mechanism for sending the target data packet is triggered to classify the traffic of the target data packet; If the network load is continuously smaller than the preset value within a waiting time, a mechanism for forcibly sending the target data packet is triggered to perform traffic classification on the target data packet.

6. The SmartNIC-based traffic classification method according to claim 1, characterized in that: The traffic classification of the target number of target data packets includes: Determining metadata, and screening the target data packet according to the metadata to achieve classification; The metadata includes: batch quantity and flow classification identifier for indicating the data packets to be processed.

7. A traffic classification system based on SmartNIC, characterized in that: The system comprises: The acquisition module is used to monitor network traffic in real time and obtain the data packets to be processed in the network traffic; An analysis module, configured to determine a hash value of a network flow corresponding to the data packet to be processed, determine a hash bucket where the data packet to be processed is located according to the hash value, and track a state of the network flow according to the hash bucket; and accumulate the number of the data packets to be processed to a first predetermined number; A preprocessing module, used for performing standardization processing on the target number of data packets to be processed to obtain a target number of target data packets; The traffic classification module is used to classify the traffic of a target number of target data packets.

8. The SmartNIC-based traffic classification system according to claim 6, characterized in that: The analysis module and the preprocessing module are both arranged on the SmartNIC; The traffic classification module is arranged on the host; The SmartNIC is in communication with the host.

9. The SmartNIC-based traffic classification system according to claim 7, characterized in that: The analysis module is also used to determine the flow quintuple of the first data, and calculate the hash value for the flow quintuple; track the state of the network flow using the hash value as a key, and identify the network flow to which the data packet to be processed belongs through the hash bucket; If the data packet to be processed belongs to a network flow that appears in the hash bucket for the first time, creating a first network flow record corresponding to the first data in the hash bucket, and marking the data packet to be processed as the first data packet of the first network flow; If the first data packet belongs to an existing network flow in the hash bucket, the existing network flow in the hash bucket is updated, and the sequence number of the data packet to be processed in the first network flow is marked.

10. The SmartNIC-based traffic classification system according to claim 7, characterized in that: The preprocessing module is also used to determine the target number of data packets to be processed, and if the current number of data packets to be processed is less than or equal to the target number, store the data packets to be processed and add the current number of data packets to be processed to the forwarding queue; If the current number of the data packets to be processed is greater than the target number, the current number of data packets to be processed are forwarded.

Citation Information

Cited By

  • Network traffic storage method and system based on edge bucket separation and bucket level anomaly judgment

    CN121792446A