Gateway shunting detection method and device, equipment and storage medium

By obtaining gateway shunt function information and rules, constructing simulated data packets for gateway simulation communication, combining shunt rule identification and verification of traffic information, the problem of complex and low efficiency of gateway shunt detection in the existing technology is solved, and efficient and accurate shunt function verification and load balancing are achieved.

CN120166050APending Publication Date: 2025-06-17SHENZHEN FENGRUNDA TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510278534.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-10
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

When performing gateway shunt detection, the networking is complex, the testing efficiency is low, the coverage is insufficient, and it is difficult to automate, resulting in high testing costs and long time.

Method used

By obtaining gateway shunt function information and gateway shunt rules, constructing simulated data packets for gateway simulation communication, determining the disguised traffic packet information, and identifying the shunt channel and verifying the traffic packet information based on the shunt rules to complete gateway shunt detection.

Benefits of technology

Significantly reduce the load of a single network interface, realize reasonable traffic allocation and load balancing, improve overall network performance and stability, simplify the test environment, reduce manual operations, improve test efficiency and accuracy, and reduce test costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120166050A_ABST
    Figure CN120166050A_ABST
Patent Text Reader

Abstract

The invention discloses a gateway shunting detection method and device, equipment and a storage medium, and relates to the technical field of automatic testing, and the method comprises the steps: obtaining gateway shunting function information and a gateway shunting rule; constructing a simulation data packet based on the gateway shunting function information, performing gateway simulation communication, and determining camouflage flow packet information; and identifying a shunting channel based on the gateway shunting rule, verifying the camouflage flow packet information, determining a gateway test result, and completing gateway shunting detection based on the gateway test result. The simulation data packet is constructed and gateway simulation communication is carried out to determine the camouflage flow packet information, the flow distribution rule is combined to identify the channel and verify the flow packet information to determine the test result to complete gateway flow distribution detection, the load of a single network interface is significantly reduced, the flow is reasonably distributed to a plurality of channel ports, load balancing is realized, the load is reduced, and the detection efficiency is improved. And efficient and accurate shunting function verification is realized, the test environment is simplified through an automatic process, and manual operation is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of automated testing technologies, and particularly to a gateway shunt detection method, apparatus, device, and storage medium. Background Art

[0002] With the continuous increase in network traffic, it has become particularly important to perform policy shunting on gateway devices. The policy shunting function can distribute traffic to different WAN ports according to preset rules to achieve load balancing, bandwidth optimization, and reasonable utilization of network resources. In order to ensure that the shunting function of the gateway device can work properly, especially in the dual-WAN mode, the accuracy and stability of policy shunting directly affect network performance and user experience. Therefore, it is necessary to perform effective detection and verification on it.

[0003] Currently, existing practices mainly rely on manual testing or testing based on multiple devices. Among them, testers need to build a complex network environment, manually configure devices and send data packets to verify the shunting function, and record and analyze the results through monitoring tools. However, the existing practices have complex network configurations, low testing efficiency, insufficient coverage, and are difficult to automate, resulting in high testing costs and long time consumption. Therefore, how to perform automated gateway shunt detection more comprehensively, efficiently, and accurately has become an urgent problem to be solved.

[0004] The above content is only used to assist in understanding the technical solution of this application, and does not represent an admission that the above content is prior art. Summary of the Invention

[0005] The main purpose of this application is to provide a gateway shunt detection method, apparatus, device, and storage medium, aiming to solve the technical problem of how to perform automated gateway shunt detection more comprehensively, efficiently, and accurately.

[0006] To achieve the above object, this application proposes a gateway shunt detection method, and the method includes:

[0007] Obtain gateway shunt function information and gateway shunt rules;

[0008] Construct a simulated data packet based on the gateway shunt function information, and perform gateway simulation communication to determine the disguised traffic packet information;

[0009] Identify the shunt channel based on the gateway shunt rules, verify the disguised traffic packet information, determine the gateway test result, and complete the gateway shunt detection based on the gateway test result.

[0010] In an embodiment, the step of obtaining gateway shunt function information and gateway shunt rules includes:

[0011] Obtain gateway device connection information, data packet type forwarding rules, and port forwarding rules;

[0012] Set the gateway mode trigger policy shunt function based on the gateway device connection information, and determine the gateway shunt function information;

[0013] Determine the gateway shunt rule based on the data packet type forwarding rule and the port forwarding rule.

[0014] In one embodiment, the step of performing gateway simulation communication and determining the disguised traffic packet information includes:

[0015] Obtain the first forged data packet information and the target gateway address information to be measured;

[0016] Search for the communication address based on the first forged data packet information and the target gateway address information to be measured, and trigger gateway simulation communication for external search to determine the second forged data packet information;

[0017] Obtain the disguised traffic packet information based on the first forged data packet information and the second forged data packet information, and the disguised traffic packet information includes the disguised traffic packet channel information and the disguised traffic packet type information.

[0018] In one embodiment, the step of searching for the communication address based on the first forged data packet information and the target gateway address information to be measured, and triggering gateway simulation communication for external search to determine the second forged data packet information includes:

[0019] Search for the communication address based on the first forged data packet information and the target gateway address information to be measured, and determine the inquiry address information;

[0020] Trigger gateway simulation communication based on the inquiry address information, and externally search for the user's forged trusted address to obtain the second forged data packet information.

[0021] In one embodiment, the step of identifying the shunt channel based on the gateway shunt rule, verifying the disguised traffic packet information, and determining the gateway test result includes:

[0022] Obtain the target detection times information;

[0023] Identify the shunt channel based on the gateway shunt rule, and verify the disguised traffic packet information to obtain the gateway detection result;

[0024] Obtain the gateway test result based on the target detection times information and the gateway detection result.

[0025] In one embodiment, the step of identifying the shunt channel based on the gateway shunt rule, and verifying the disguised traffic packet information to obtain the gateway detection result includes:

[0026] Identify the diversion channel based on the gateway diversion rule, and determine the target channel information and the target data packet type information;

[0027] Verify the spoofed traffic packet information based on the target channel information and the target data packet type information to obtain the gateway detection result.

[0028] In one embodiment, the step of verifying the spoofed traffic packet information based on the target channel information and the target data packet type information to obtain the gateway detection result includes:

[0029] When the spoofed traffic packet channel information in the target channel information and the spoofed traffic packet information matches and the target data packet type information and the spoofed traffic packet type information match, the gateway detection result is a successful detection;

[0030] When the spoofed traffic packet channel information in the target channel information and the spoofed traffic packet information does not match or the target data packet type information and the spoofed traffic packet type information does not match, the gateway detection result is a failed detection.

[0031] In addition, to achieve the above object, the present application also proposes a gateway diversion detection device, and the gateway diversion detection device includes:

[0032] An acquisition module, configured to acquire gateway diversion function information and gateway diversion rules;

[0033] A processing module, configured to construct a simulated data packet based on the gateway diversion function information, and perform gateway simulation communication to determine the spoofed traffic packet information;

[0034] An execution module, configured to identify the diversion channel based on the gateway diversion rule, verify the spoofed traffic packet information, determine the gateway test result, and complete the gateway diversion detection based on the gateway test result.

[0035] In addition, to achieve the above object, the present application also proposes a gateway diversion detection device, and the device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the gateway diversion detection method as described above.

[0036] In addition, to achieve the above object, the present application also proposes a storage medium, and the storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium, and when the computer program is executed by a processor, the steps of the gateway diversion detection method as described above are implemented.

[0037] One or more technical solutions proposed by the present application have at least the following technical effects:

[0038] A gateway shunt detection method proposed in this embodiment obtains gateway shunt function information and gateway shunt rules; constructs a simulated data packet based on the gateway shunt function information, and conducts gateway simulation communication to determine the information of the disguised traffic packet; identifies the shunt channel based on the gateway shunt rules, and verifies the information of the disguised traffic packet to determine the gateway test result, and completes the gateway shunt detection based on the gateway test result. By obtaining the gateway shunt function information and shunt rules, constructing a simulated data packet and conducting gateway simulation communication to determine the information of the disguised traffic packet, combining the shunt rules to identify the channel and verify the traffic packet information to determine the test result, the gateway shunt detection is completed, significantly reducing the load of a single network interface, reasonably allocating traffic to multiple channel ports, achieving load balancing, reducing the load, and realizing efficient and accurate shunt function verification. By simplifying the test environment through an automated process, manual operations are reduced, the test efficiency and coverage are improved, and the test efficiency and accuracy are increased, while the test cost is reduced. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] The accompanying drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.

[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present application or in the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0041] Figure 1 It is a schematic flow chart provided for Embodiment 1 of the gateway shunt detection method of the present application;

[0042] Figure 2 It is a schematic diagram of the environment built for the gateway shunt detection method of the present application;

[0043] Figure 3 It is a schematic diagram of enabling the policy shunt function for the gateway shunt detection method of the present application;

[0044] Figure 4 It is a schematic diagram of forged packet communication for the gateway shunt detection method of the present application;

[0045] Figure 5 It is a schematic diagram of finding the communication address for the gateway shunt detection method of the present application;

[0046] Figure 6 It is a schematic diagram of externally finding the forged trusted address of the user for the gateway shunt detection method of the present application;

[0047] Figure 7 It is a schematic diagram of traffic forwarding for the gateway shunt detection method of the present application;

[0048] Figure 8 It is a schematic flowchart provided for the second embodiment of the gateway traffic splitting detection method of this application;

[0049] Figure 9 It is a schematic module structure diagram of the gateway traffic splitting detection device of an embodiment of this application;

[0050] Figure 10 It is a schematic device structure diagram of the hardware operating environment involved in the gateway traffic splitting detection method in an embodiment of this application.

[0051] The realization of the purpose, functional features, and advantages of this application will be further described with reference to the accompanying drawings in combination with the embodiments. Specific Embodiments

[0052] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of this application and are not used to limit this application.

[0053] To better understand the technical solutions of this application, the following will be described in detail in combination with the accompanying drawings of the specification and specific embodiments.

[0054] The main solution of the embodiment of this application is: obtain gateway traffic splitting function information and gateway traffic splitting rules; construct a simulated data packet based on the gateway traffic splitting function information, and perform gateway simulation communication to determine the information of the disguised traffic packet; identify the traffic splitting channel based on the gateway traffic splitting rules, and verify the information of the disguised traffic packet to determine the gateway test result, and complete the gateway traffic splitting detection based on the gateway test result.

[0055] In this embodiment, for the convenience of description, the following will be described with the identification of the gateway traffic splitting detection device as the execution subject.

[0056] Due to the complex network configuration, low test efficiency, insufficient coverage, and difficulty in automation in the prior art, the test cost is high and the time consumption is long.

[0057] This application provides a solution: obtain gateway traffic splitting function information and gateway traffic splitting rules; construct a simulated data packet based on the gateway traffic splitting function information, and perform gateway simulation communication to determine the information of the disguised traffic packet; identify the traffic splitting channel based on the gateway traffic splitting rules, and verify the information of the disguised traffic packet to determine the gateway test result, and complete the gateway traffic splitting detection based on the gateway test result.

[0058] As can be seen from the above embodiments, the present application obtains gateway shunt function information and shunt rules, constructs simulated data packets and conducts gateway simulation communication to determine the information of the disguised traffic packets, combines the shunt rules to identify channels and verify the traffic packet information to determine the test results, completes the gateway shunt detection, significantly reduces the load of a single network interface, reasonably distributes traffic to multiple channel ports, realizes load balancing, reduces the load, and realizes efficient and accurate shunt function verification. By automating the process, the test environment is simplified, manual operations are reduced, the test efficiency and coverage are improved, and the test efficiency and accuracy are increased while the test cost is reduced.

[0059] Based on this, an embodiment of the present application provides a gateway shunt detection method. Referring to Figure 1 , Figure 1 is a schematic flowchart of the first embodiment of the gateway shunt detection method of the present application.

[0060] In this embodiment, the gateway shunt detection method includes steps S10 to S30:

[0061] Step S10, obtaining gateway shunt function information and gateway shunt rules;

[0062] It should be noted that the gateway shunt function information reflects the characteristic of the function enabling state of the gateway device for policy shunting of traffic in the dual-WAN mode, and the gateway shunt rule reflects the characteristic of allocating traffic of different types and priorities to the specified WAN port.

[0063] It can be understood that the gateway shunt function information is used to determine under what conditions the gateway triggers the policy shunting function and how to allocate traffic to different channels. The gateway shunt rule can represent the specific policy of traffic allocation to achieve load balancing and resource optimization, and may include data packet type, target port, and priority information.

[0064] In addition, it should be noted that, as Figure 2 shown, Figure 2 is a schematic diagram of the environment built for the gateway shunt detection method of the present application. The network configuration is simple. A notebook computer is externally connected to network card 1 and network card 2, and is connected to the gateway management ap through network card 1 and network card 2 respectively and then to the gateway under test. By obtaining the gateway shunt function information and shunt rules, the shunt behavior of the gateway can be accurately controlled and verified, traffic can be reasonably distributed to multiple WAN ports, load balancing can be realized, and the load of a single network interface can be reduced, improving the overall performance and stability of the network. At the same time, through automated detection means, the construction of the test environment is simplified, manual operations are reduced, the test efficiency and accuracy are improved, and the test cost is significantly reduced.

[0065] For ease of understanding, the example of obtaining gateway traffic splitting function information and gateway traffic splitting rules is used for illustration. Here, the information collection device is the information collection module, and the storage device is the memory.

[0066] The information collection module obtains gateway device connection information, such as the gateway connection status, obtains packet type forwarding rules, such as forwarding UDP packets or forwarding TCP packets, obtains port forwarding rules, such as wan1 port and wan2 port, and sets the gateway mode trigger policy traffic splitting function based on the gateway device connection information to determine the gateway traffic splitting function information, that is, as Figure 3 shown. Figure 3 This is a schematic diagram of enabling the policy traffic splitting function for the gateway traffic splitting detection method of this application. The automated computer uses the paramikl module of the python library to connect to the DUT gateway device through wireless connection. At this time, the functions inside the gateway background can be controlled. One of the dual-wan mode can be selected in the gateway to enable the policy traffic splitting. Then, connect to the gateway through paramikl, send commands to the router through the background to enable the policy traffic splitting function, determine the gateway traffic splitting rules based on the packet type forwarding rules and the port forwarding rules, and perform subsequent processing based on the gateway traffic splitting function information and the gateway traffic splitting rules.

[0067] In a feasible implementation manner, step S10 may include steps A11 to A13:

[0068] Step A11, obtaining gateway device connection information, packet type forwarding rules, and port forwarding rules;

[0069] It should be noted that the gateway device connection information reflects the connection status and configured characteristics of the gateway device in the dual-WAN mode, the packet type forwarding rule reflects the characteristics of the gateway's processing strategy for different types of packets, and the port forwarding rule reflects the characteristics of the gateway's configuration for directing specific packets to specific WAN ports.

[0070] It can be understood that by obtaining gateway device connection information, packet type forwarding rules, and port forwarding rules, the traffic splitting behavior of the gateway can be precisely controlled and verified, the connection status and configuration of the gateway can be clarified, making the setting of traffic splitting rules more reasonable and effective, avoiding improper traffic distribution caused by configuration errors. Combining the packet type and port forwarding rules can achieve refined management of different types of traffic, reasonably distribute traffic to multiple WAN ports, achieve load balancing, reduce the load on a single network interface, and improve the overall performance and stability of the network. In addition, through automated detection means, the construction of the test environment is simplified, manual operations are reduced, the test efficiency and accuracy are improved, and the test cost is significantly reduced.

[0071] Step A12: Set the gateway mode trigger policy shunt function based on the gateway device connection information, and determine the gateway shunt function information;

[0072] It can be understood that the gateway device connection information may include the network interface connection status of the gateway, the enabled status of the WAN port, and the connection relationship between the gateway and the external network, so as to determine whether the gateway device is in the dual-WAN mode and clarify the configuration of the network interface.

[0073] Step A13: Determine the gateway shunt rule based on the packet type forwarding rule and the port forwarding rule.

[0074] It can be understood that the packet type forwarding rule specifies which types of packets, such as TCP, UDP, and ICMP packets, are forwarded to a specific WAN port. Based on the protocol type and priority of the packet, it ensures that the gateway can reasonably allocate traffic to different network channels according to the preset policy, realizing the optimized management and load balancing of traffic. The port forwarding rule specifies the way different types of traffic are forwarded through the WAN port, such as WAN1 or WAN2, ensuring that the traffic can be transmitted along the preset path.

[0075] Step S20: Construct a simulated packet based on the gateway shunt function information, and perform gateway simulation communication to determine the camouflaged traffic packet information;

[0076] It should be noted that the camouflaged traffic packet information reflects the characteristics of the traffic packets constructed by the gateway in the simulation test environment.

[0077] It can be understood that the camouflaged traffic packet information may include ICMP packets and ARP packets, which are used to simulate gateway communication, test whether the gateway shunts the packets according to the predetermined rules, significantly reduce the load of a single network interface, reasonably allocate traffic to multiple channel ports, realize load balancing, and reduce the load.

[0078] For easy understanding, taking the determination of the camouflaged traffic packet information as an example for illustration, where the information collection device is the information collection module, the storage device is the memory, and the processing device is the processing module.

[0079] The information collection module obtains the first forged packet information, such as constructing Packet A, that is, as Figure 4 shown Figure 4This is a schematic diagram of forged packet communication for the gateway shunt detection method of this application. Use scapy to forge an A packet and send it to the router under test. Among them, the A packet is an ICMP packet, which contains a newly constructed mac address and ip address. Obtain the target gateway address information to be measured, that is, obtain the mac address table of the gateway under test DUT. Based on the first forged packet information and the target gateway address information to be measured, find the communication address and determine the inquiry address information, that is, as Figure 5 shown Figure 5 This is a schematic diagram of finding the communication address for the gateway shunt detection method of this application. Use the mac address table of the gateway under test to query whether the mac address of the A packet is stored. Since the forged address is not in the target gateway address information to be measured, the router under test will send an inquiry packet to arp to query the address information externally, including the ip of the mac address of the A packet. Based on the inquiry address information, trigger gateway simulation communication and externally find the user-forged trusted address to obtain the second forged packet information, that is, as Figure 6 shown Figure 6 This is a schematic diagram of externally finding the user-forged trusted address for the gateway shunt detection method of this application. Receive the reply from the user during external query, indicating that the mac of the A packet exists. The user can freely construct the second forged packet information, such as the B packet. Among them, the B packet is an ARP packet, which can be composed of the mac address and ip address of an automated computer, plus the response content of ARP. The ip address of the B packet is the address forged by the user. Because the automated computer is directly connected to the router, the router will be recorded in the arp table. At this time, the computer has obtained the trust of the router, and the forged address is stored in the target gateway address information to be measured. Based on the first forged packet information and the second forged packet information, obtain the disguised traffic packet information. The disguised traffic packet information includes disguised traffic packet channel information and disguised traffic packet type information. Based on the disguised traffic packet information, perform subsequent processing.

[0080] In a feasible implementation manner, step S20 may include steps B11 to B13:

[0081] Step B11, obtain the first forged packet information and the target gateway address information to be measured;

[0082] It should be noted that the first forged packet information reflects the constructed ICMP packet, which has the characteristics of a brand-new mac address and ip address.

[0083] It can be understood that the forged address in the first forged packet information is not in the target gateway address information to be measured. Only after the gateway under test cannot query it can the simulation communication be triggered to inquire whether there is an address of the first forged packet information in an externally trusted device.

[0084] Step B12: Based on the first forged data packet information and the target gateway address information to be measured, search for communication addresses, trigger gateway simulation communication for external search, and determine the second forged data packet information;

[0085] It should be noted that the second forged data packet information reflects the constructed ARP packet, which consists of the mac address and ip address of an automated computer, plus the characteristics of the ARP response content.

[0086] It can be understood that the second forged data packet information can forge the mac address at will to gain the trust of the gateway.

[0087] In a feasible implementation manner, step B12 may include steps C11 - C12:

[0088] Step C11: Based on the first forged data packet information and the target gateway address information to be measured, search for communication addresses and determine the inquiry address information;

[0089] It should be noted that the inquiry address information reflects the characteristic of seeking an address from a trusted device when the traffic packet forwarding address cannot be found internally.

[0090] It can be understood that the inquiry address information is an ARP query request actively initiated by the gateway when it fails to recognize the forged data packet, that is, an address resolution protocol query request. The purpose is to determine whether the source of the forged data packet is true and credible, effectively avoiding misjudgment caused by the direct injection of forged data packets during the test, and improving the accuracy and reliability of the test.

[0091] Step C12: Based on the inquiry address information, trigger gateway simulation communication and externally search for the user - forged trusted address to obtain the second forged data packet information.

[0092] It can be understood that the measured router will record the mac address and ip address of packet A in the arp address, and at the same time will respond to the request of packet A by replying with an ICMP reply packet, thus completing arp spoofing, gaining the trust of the gateway, and obtaining the second forged data packet information, which includes a forged ip address at will.

[0093] Step B13: Based on the first forged data packet information and the second forged data packet information, obtain the disguised traffic packet information, where the disguised traffic packet information includes disguised traffic packet channel information and disguised traffic packet type information.

[0094] It can be understood that the disguised traffic packet channel information indicates the transmission path selected after the forged data packet is processed by the gateway, such as WAN1 or WAN2, and the disguised traffic packet type information reflects the protocol type of the forged data packet, such as TCP, UDP, and ICMP.

[0095] Step S30: Identify the shunt channel based on the gateway shunt rule, verify the spoofed traffic packet information, determine the gateway test result, and complete the gateway shunt detection based on the gateway test result.

[0096] It should be noted that the gateway test result reflects the characteristics of the actual test result of the gateway shunt function.

[0097] For ease of understanding, taking the determination of the gateway test result as an example, the information collection device is the information collection module, the storage device is the memory, and the execution device is the execution module.

[0098] The information collection module obtains the target detection times information, that is, uses multi-threading to send and receive packets on a large scale, identifies the shunt channel based on the gateway shunt rule, and determines the target channel information and the target data packet type information. That is, uses paramikl to set the gateway, set the test rules, such as the wan port of the forged ip address goes through wan1 port or wan2 port, and the allowed packets are UDP packets or TCP packets. Access the ac through the ap using the wireless network card, use the forged address that has passed deception, and use scapy to send TCP and UDP packets to the gateway. After the gateway receives the packets sent from the forged ip address, it determines the port that the packets of this address should be sent to, such as Figure 7 shown Figure 7 This is the traffic forwarding schematic diagram of the gateway shunt detection method of this application. The set rule is that TCP packets with the address 192.168.1.115 are forwarded through the WAN2 port. Then when the wireless network card passes through the gateway, it will be sent to WAN2. Use scapy to capture the packets of the network card to determine whether all the set rules are accurately effective. When the spoofed traffic packet channel information in the target channel information and the spoofed traffic packet information matches and the target data packet type information and the spoofed traffic packet type information match, the gateway detection result is detection success. When the spoofed traffic packet channel information in the target channel information and the spoofed traffic packet information does not match or the target data packet type information and the spoofed traffic packet type information do not match, the gateway detection result is detection failure. The gateway test result is obtained based on the target detection times information and the gateway detection result. That is, use the threading library and the scapy library, use multi-threading to send and receive packets on a large scale, and test whether the packets sent by each forged ip match the rules and the network card that receives the packets. If the above expectations are met, the test passes, and use openxl to write the results to ex cel. If any of the expected results are not met, the test fails.

[0099] A gateway shunt detection method proposed in this embodiment obtains gateway shunt function information and gateway shunt rules; constructs a simulated data packet based on the gateway shunt function information, and performs gateway simulation communication to determine the information of the disguised traffic packet; identifies the shunt channel based on the gateway shunt rules, and verifies the information of the disguised traffic packet to determine the gateway test result, and completes the gateway shunt detection based on the gateway test result. This solves the technical problem of how to perform automated gateway shunt detection more efficiently and accurately. Compared with the prior art, this application obtains the gateway shunt function information and rules, constructs a simulated data packet and performs gateway simulation communication to determine the information of the disguised traffic packet, uses the shunt rules to identify the shunt channel and verify the information of the disguised traffic packet to complete the gateway shunt detection, significantly simplifies the construction of the test environment for policy shunting in the dual-WAN mode, including the accompanying test switch, multiple accompanying test PCs, the networking environment connected by network cables and manual operations. Moreover, after simplifying the test environment, the test is carried out in an automated manner, improving the test efficiency, reducing the test cost. At the same time, it significantly reduces the load of a single network interface, realizes the reasonable distribution of traffic and load balancing, and improves the overall performance and stability of the network.

[0100] Based on the first embodiment of this application, in the second embodiment of this application, the same or similar content as that in the above-mentioned first embodiment can be referred to the above introduction and will not be repeated hereinafter.

[0101] In this embodiment, referring to Figure 8 , Figure 8 is a schematic flowchart provided for the second embodiment of the gateway shunt detection method of this application. Step S30 specifically includes steps S31 to S33:

[0102] Step S31, obtain the information of the target detection times;

[0103] It should be noted that the information of the target detection times reflects the characteristics of the number of times of verifying the disguised traffic packet using multiple threads.

[0104] It can be understood that the information of the target detection times can specify the number of times of verifying the disguised traffic packet during the test. Through multiple detections, it is ensured that the test result can truly reflect the actual performance of the gateway shunt function.

[0105] For the convenience of understanding, the example of obtaining the information of the target detection times is used for illustration. Among them, the information collection device is the information collection module, the storage device is the memory, and the execution device is the execution module.

[0106] The information collection module obtains the target detection times information, that is, using the threading library and the scapy library, utilizing multi-threading, obtaining the number of multi-threads to get the target detection times information, performing large-scale packet sending and receiving, and checking whether each packet sent by the forged IP is consistent with the rules, the received packets, and the network card. Subsequent processing is performed based on the target detection times information.

[0107] Step S32, identify the shunt channel based on the gateway shunt rule, and verify the spoofed traffic packet information to obtain the gateway detection result;

[0108] It should be noted that the gateway detection result reflects the characteristics of the detection result of the shunt rule by the gateway during a single detection process.

[0109] For easy understanding, taking obtaining the gateway detection result as an example for illustration, where the information collection device is the information collection module, the storage device is the memory, and the execution device is the execution module.

[0110] The information collection module obtains the gateway shunt rule, identifies the shunt channel based on the gateway shunt rule, and determines the target channel information and the target data packet type information, that is, using paramikl to set the gateway, setting test rules, such as the wan port of the forged IP address going through wan1 port or wan2 port, and allowing UDP packets or TCP packets to pass through. Using the wireless network card to access the ac through the ap, using the already spoofed and forged address, using scapy to send TCP and UDP packets to the gateway. After the gateway receives the packets sent by the forged IP address, it determines the port that the packets of this address should be sent to. For example, if the rule is set that the TCP packets of 192.168.1.115 are forwarded through the WAN2 port, then when the wireless network card passes through the gateway, it will be sent to WAN2. Using scapy to capture the packets of the network card to determine whether all the set rules are accurately effective. Verify the spoofed traffic packet information based on the target channel information and the target data packet type information to obtain the gateway detection result, and perform subsequent processing based on the gateway detection result.

[0111] In a feasible implementation manner, step S32 may include steps D11 to D12:

[0112] Step D11, identify the shunt channel based on the gateway shunt rule, and determine the target channel information and the target data packet type information;

[0113] It should be noted that the target channel information reflects the characteristics of the traffic transmission path set in the gateway shunt rule, and the target data packet type information reflects the characteristics of the setting requirements for the data packet protocol type in the gateway shunt rule.

[0114] It can be understood that the target channel information refers to the specific network interface to which the disguised traffic packet should be assigned, such as WAN1 or WAN2, to ensure that traffic of different types or priorities can be directed to the correct channel according to the predetermined rules. The target data packet type information is used to identify the type of the disguised data packet, such as TCP, UDP or ICMP, to ensure that data packets conforming to the preset protocol type will be assigned to the corresponding channel.

[0115] Step D12, verify the disguised traffic packet information based on the target channel information and the target data packet type information to obtain a gateway detection result.

[0116] It can be understood that the gateway detection result can quickly locate whether there are rule matching errors or abnormal traffic splitting behaviors when the gateway processes specific disguised traffic packets, so as to discover problems in time and make adjustments, significantly improving the efficiency of testing.

[0117] In a feasible implementation manner, step D12 may include steps E11 to E12:

[0118] Step E11, when the disguised traffic packet channel information in the target channel information and the disguised traffic packet information matches and the target data packet type information and the disguised data packet type information match, the gateway detection result is a successful detection;

[0119] It can be understood that when the gateway detection result is a successful detection, it indicates that the traffic splitting rules of the gateway have been correctly executed, the disguised traffic packet has been accurately assigned to the preset traffic splitting channel, and the data packet type also meets the rule requirements, thus realizing efficient network resource management and load balancing.

[0120] Step E12, when the disguised traffic packet channel information in the target channel information and the disguised traffic packet information does not match or the target data packet type information and the disguised data packet type information do not match, the gateway detection result is a failed detection.

[0121] It can be understood that when the gateway detection result is a failed detection, it indicates that the gateway fails to correctly execute the preset traffic splitting rules when processing traffic, and there is an abnormality in the gateway traffic splitting function. Analyze the reasons for the abnormality, such as incorrect rule configuration, gateway device failure or inaccurate traffic identification, quickly identify and record the abnormal behavior of the gateway, reduce the time and cost of manual troubleshooting, significantly improve the testing efficiency and the reliability of network devices, and ensure the efficient operation of the network in a complex traffic environment.

[0122] Step S33, obtain a gateway test result based on the target detection times information and the gateway detection result.

[0123] It is understandable that the gateway test result identifies whether the gateway shunting function is correctly executed according to the expected rules by detecting success or failure, intuitively reflecting the performance of the gateway in policy shunting, enabling quick and accurate judgment of whether the performance of the gateway shunting function meets expectations. Moreover, by automatically generating the test result, subjective errors and operation mistakes that may occur in manual testing are avoided, significantly improving the test efficiency and accuracy.

[0124] For ease of understanding, an example of obtaining the target detection times information and the gateway test result is used for illustration. Among them, the information collection device is the information collection module, the storage device is the memory, and the execution device is the execution module.

[0125] The information collection module obtains the target detection times information, that is, uses the threading library and the scapy library, utilizes multi-threading, sends and receives packets on a large scale, tests whether each packet sent by the forged IP is consistent with the rule and the network card of the received packet, obtains the gateway test result, such as detection success or failure. Based on the target detection times information and the gateway test result, the gateway test result is obtained, that is, multiple tests are carried out within the target detection times information. If the gateway test results are all verification successes, the test result is test passed, and the result is recorded in excel using openxl. If a test failure appears in the gateway test results during multiple tests, the test result is test failed, and the gateway shunting detection is completed based on the test result.

[0126] A gateway shunting detection method proposed in this embodiment obtains the target detection times information; identifies the shunting channel based on the gateway shunting rule and verifies the spoofed traffic packet information to obtain the gateway test result; obtains the gateway test result based on the target detection times information and the gateway test result. It solves the technical problem of how to perform automated gateway shunting detection more comprehensively and efficiently. Compared with the prior art, this application obtains the target detection times information, identifies the shunting channel based on the gateway shunting rule and verifies the spoofed traffic packet information to obtain the gateway test result, and then combines the target detection times information and the test result to obtain the final gateway test result. Through multi-threaded multiple evaluations and tests, the comprehensiveness and reliability of the test are improved, and at the same time, the network performance is optimized to ensure that the gateway can correctly execute the shunting function according to the preset rules.

[0127] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the gateway shunting detection method of this application. Based on this technical concept, more forms of simple transformations are within the protection scope of this application.

[0128] This application also provides a gateway shunting detection device. Please refer to Figure 9 , the gateway shunting detection device includes:

[0129] An acquisition module 10, configured to acquire gateway shunt function information and gateway shunt rules;

[0130] A processing module 20, configured to construct a simulated data packet based on the gateway shunt function information, perform gateway simulation communication, and determine spoofed traffic packet information;

[0131] An execution module 30, configured to identify a shunt channel based on the gateway shunt rules, verify the spoofed traffic packet information, determine a gateway test result, and complete gateway shunt detection based on the gateway test result.

[0132] The acquisition module 10 is further configured to acquire gateway device connection information, data packet type forwarding rules, and port forwarding rules;

[0133] Set a gateway mode trigger policy shunt function based on the gateway device connection information to determine gateway shunt function information;

[0134] Determine gateway shunt rules based on the data packet type forwarding rules and the port forwarding rules.

[0135] The processing module 20 is further configured to acquire first spoofed data packet information and target gateway address information to be tested;

[0136] Search for a communication address based on the first spoofed data packet information and the target gateway address information to be tested, and trigger gateway simulation communication for external search to determine second spoofed data packet information;

[0137] Obtain spoofed traffic packet information based on the first spoofed data packet information and the second spoofed data packet information, where the spoofed traffic packet information includes spoofed traffic packet channel information and spoofed traffic packet type information.

[0138] The processing module 20 is further configured to search for a communication address based on the first spoofed data packet information and the target gateway address information to be tested to determine inquiry address information;

[0139] Trigger gateway simulation communication based on the inquiry address information, and externally search for a user-spoofed trusted address to obtain second spoofed data packet information.

[0140] The execution module 30 is further configured to acquire target detection times information;

[0141] Identify a shunt channel based on the gateway shunt rules, and verify the spoofed traffic packet information to obtain a gateway detection result;

[0142] Obtain a gateway test result based on the target detection times information and the gateway detection result.

[0143] The execution module 30 is further configured to identify a shunt channel based on the gateway shunt rule, and determine target channel information and target data packet type information;

[0144] Verify the spoofed traffic packet information based on the target channel information and the target data packet type information to obtain a gateway detection result.

[0145] When the spoofed traffic packet channel information in the target channel information and the spoofed traffic packet information matches and the target data packet type information and the spoofed traffic packet type information match, the gateway detection result is a successful detection;

[0146] When the spoofed traffic packet channel information in the target channel information and the spoofed traffic packet information does not match or the target data packet type information and the spoofed traffic packet type information do not match, the gateway detection result is a failed detection.

[0147] The gateway shunt detection device provided in this application adopts the gateway shunt detection method in the above embodiment, and can solve the technical problem of how to perform automated gateway shunt detection more comprehensively, efficiently and accurately. Compared with the prior art, the beneficial effects of the gateway shunt detection device provided in this application are the same as those of the gateway shunt detection method provided in the above embodiment, and other technical features in the gateway shunt detection device are the same as the features disclosed in the above embodiment method, and will not be elaborated here.

[0148] This application provides a gateway shunt detection device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the gateway shunt detection method in the first embodiment above.

[0149] Refer to the following Figure 10 , which shows a schematic structural diagram of a gateway shunt detection device suitable for implementing the embodiments of this application. The gateway shunt detection device in the embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), vehicle terminals (such as vehicle navigation terminals), etc. And fixed terminals such as digital TVs and desktop computers. Figure 10 The gateway shunt detection device shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of this application.

[0150] As shown Figure 10 in the figure, the gateway shunt detection device may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to a program stored in a ROM (Read Only Memory) 1002 or a program loaded from a storage device 1003 into a RAM (Random Access Memory) 1004. In the RAM 1004, various programs and data required for the operation of the gateway shunt detection device are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other through a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems may be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 may allow the gateway shunt detection device to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows a gateway shunt detection device having various systems, it should be understood that it is not required to implement or have all the shown systems. Instead, more or fewer systems may be implemented or had.

[0151] Specifically, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart may be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes program codes for executing the method shown in the flowchart. In such an embodiment, the computer program may be downloaded and installed from a network through the communication device, or installed from the storage device 1003, or installed from the ROM 1002. When the computer program is executed by the processing device 1001, the above functions defined in the method of the embodiments disclosed in the present application are executed.

[0152] The gateway shunt detection device provided by the present application adopts the gateway shunt detection method in the above embodiments, and can solve the technical problem of how to perform automated gateway shunt detection more comprehensively, efficiently, and accurately. Compared with the prior art, the beneficial effects of the gateway shunt detection device provided by the present application are the same as those of the gateway shunt detection method provided by the above embodiments, and other technical features in the gateway shunt detection device are the same as those disclosed in the method of the previous embodiment, and will not be elaborated herein.

[0153] It should be understood that each part disclosed in this application can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.

[0154] As described above, the above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed in this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

[0155] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the gateway traffic splitting detection method in the above embodiments.

[0156] The computer-readable storage medium provided by this application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or combined with an instruction execution system, device, or device. The program code contained on the computer-readable storage medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0157] The above computer-readable storage medium can be included in the gateway traffic splitting detection device; it can also exist alone without being assembled into the gateway traffic splitting detection device.

[0158] The above computer-readable storage medium carries one or more programs, which, when executed by the gateway traffic splitting detection device, cause the gateway traffic splitting detection device to: obtain gateway traffic splitting function information and gateway traffic splitting rules; construct a simulated data packet based on the gateway traffic splitting function information, perform gateway simulation communication, and determine the spoofed traffic packet information; identify a traffic splitting channel based on the gateway traffic splitting rules, verify the spoofed traffic packet information, determine the gateway test result, and complete the gateway traffic splitting detection based on the gateway test result.

[0159] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0160] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0161] The modules described in the embodiments of this application can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation to the unit itself in some cases.

[0162] The readable storage medium provided by this application is a computer-readable storage medium. The computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for executing the above gateway shunt detection method, which can solve the technical problem of how to perform automated gateway shunt detection more comprehensively, efficiently, and accurately. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by this application are the same as those of the gateway shunt detection method provided in the above embodiments, and will not be elaborated here.

[0163] The above are only partial embodiments of this application, and do not limit the patent scope of this application accordingly. Any equivalent structural transformation made under the technical concept of this application by using the content of the specification and drawings of this application, or any direct / indirect application in other related technical fields, is included in the patent protection scope of this application.

Claims

1. A gateway offload detection method, characterized in that: The method includes: Obtain gateway diversion function information and gateway diversion rules; Constructing a simulated data packet based on the gateway diversion function information, and performing gateway simulated communication to determine the disguised traffic packet information; Based on the gateway diversion rule, the diversion channel is identified, and the disguised traffic packet information is verified to determine the gateway test result, and the gateway diversion detection is completed based on the gateway test result.

2. The method according to claim 1, characterized in that The step of obtaining gateway diversion function information and gateway diversion rules includes: Obtain gateway device connection information, packet type forwarding rules, and port forwarding rules; Setting a gateway mode triggering strategy diversion function based on the gateway device connection information, and determining gateway diversion function information; A gateway diversion rule is determined based on the data packet type forwarding rule and the port forwarding rule.

3. The method according to claim 1, characterized in that The steps of performing gateway simulation communication and determining the disguised traffic packet information include: Obtaining first forged data packet information and target tested gateway address information; Searching for a communication address based on the first forged data packet information and the target gateway address information, and triggering the gateway to simulate communication to perform an external search to determine the second forged data packet information; The disguised traffic packet information is obtained based on the first forged data packet information and the second forged data packet information, and the disguised traffic packet information includes the disguised traffic packet channel information and the disguised traffic packet type information.

4. The method according to claim 3, characterized in that The step of searching for a communication address based on the first forged data packet information and the target gateway address information, triggering the gateway to simulate communication for external search, and determining the second forged data packet information includes: Searching for a communication address based on the first forged data packet information and the target gateway address information to determine the inquiry address information; The gateway simulates communication based on the inquiry address information, and externally searches for the user's forged trusted address to obtain second forged data packet information.

5. The method according to claim 1, characterized in that The step of identifying the diversion channel based on the gateway diversion rule, verifying the disguised traffic packet information, and determining the gateway test result includes: Get target detection times information; Identify the diversion channel based on the gateway diversion rule, and verify the disguised traffic packet information to obtain a gateway detection result; A gateway test result is obtained based on the target detection number information and the gateway detection result.

6. The method according to claim 5, characterized in that The step of identifying the diversion channel based on the gateway diversion rule and verifying the disguised traffic packet information to obtain the gateway detection result includes: Identify the diversion channel based on the gateway diversion rule, and determine the target channel information and the target data packet type information; The disguised traffic packet information is verified based on the target channel information and the target data packet type information to obtain a gateway detection result.

7. The method according to claim 6, characterized in that The step of verifying the disguised traffic packet information based on the target channel information and the target data packet type information to obtain a gateway detection result includes: When the target channel information and the disguised traffic packet channel information in the disguised traffic packet information match, and the target data packet type information and the disguised traffic packet type information match, the gateway detection result is a detection success; When the disguised traffic packet channel information in the target channel information and the disguised traffic packet information does not match or the target data packet type information and the disguised traffic packet type information do not match, the gateway detection result is detection failure.

8. A gateway diversion detection device, characterized in that: The device comprises: An acquisition module is used to obtain gateway diversion function information and gateway diversion rules; A processing module, used to construct a simulated data packet based on the gateway diversion function information, and perform gateway simulated communication to determine the disguised traffic packet information; The execution module is used to identify the diversion channel based on the gateway diversion rule, verify the disguised traffic packet information, determine the gateway test result, and complete the gateway diversion detection based on the gateway test result.

9. A gateway diversion detection device, characterized in that: The device comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the gateway offload detection method according to any one of claims 1 to 7.

10. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the gateway offloading detection method according to any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Directional forwarding method and device based on routing, medium and product

    CN120499072A