Session table item management method and firewall equipment

By obtaining the timestamp field of the session table entry in the firewall device to judge the aging conditions, and obtaining all data blocks for deletion when the conditions are met, the problem of session table entry not being aging in time is solved, and the message forwarding performance of the firewall device is improved.

CN120185869APending Publication Date: 2025-06-20NEW H3C SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510266024.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

In the prior art, because the session table entry cannot be processed in time, the message forwarding performance of the filtered firewall device is low.

Method used

By obtaining the first data block containing the timestamp field in the session table entry, it is determined whether the aging condition is met. When the timestamp field meets the aging conditions, all data blocks of the session table entry are obtained and the session table entry is deleted based on its address information.

Benefits of technology

This method does not need to read all data information of the session table entry, saves the consumption time of data reading, and realizes timely aging of the session table entry, thereby improving the packet forwarding performance of the filtered firewall device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185869A_ABST
    Figure CN120185869A_ABST
Patent Text Reader

Abstract

The invention provides a session table item management method and firewall equipment. The method is applied to the firewall equipment. The method comprises the following steps: for any one session table item in a plurality of session table items, obtaining a first data block containing a timestamp field in the session table item; when the timestamp field meets the aging condition, obtaining all data blocks of the session table item; generating second address information of the session table item according to the first address information of all the data blocks; and deleting the session table item according to the second address information. According to the embodiment of the invention, when whether the session table item needs to be aged or not is judged, all data information of the session table item does not need to be read, so that the consumed time of data reading can be greatly saved, the purpose of carrying out aging processing on the session table item in time is achieved, and the message forwarding performance of firewall equipment is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a method for managing session entries and a firewall device. Background Art

[0002] In network security devices, fast forwarding of IP packets can be achieved through filtering firewall devices. For example, in an enterprise's internal local area network, a filtering firewall device can improve the access speed of user terminals to work-related websites such as online meetings and online office.

[0003] A filtering firewall device can maintain multiple session entries according to the storage space size, and the session entries are generated based on the five-tuple of the packet. When forwarding a packet, it is determined whether there is a session entry in the multiple session entries that matches the packet. If so, the packet sent by the user end is directly forwarded to the server end, and this method is called the fast path; otherwise, it is processed by the CPU (Central Processing Unit), and after the CPU finishes processing, the packet is forwarded to the server end, which is called the slow path.

[0004] Due to limited storage space, the number of maintained session entries is limited. The prior art generally ages (i.e., deletes from the storage space) the session entries that have not been used for a long time, so as to make the packets take the fast path as much as possible by adding new session entries. However, this method usually selects the session entries that should be aged according to all the data information of the multiple session entries, so it is necessary to read all the data information of each session entry, and reading all the data takes a long time, which easily causes the session entries to not be aged in time, resulting in the problem of low packet forwarding performance of the filtering firewall device. Summary of the Invention

[0005] In view of this, this application proposes a method for managing session entries and a firewall device to solve the problem in the related art that the packet forwarding performance of the filtering firewall device is low due to the session entries not being aged in time.

[0006] The first aspect embodiment of this application proposes a method for managing session entries, which is applied to a firewall device; the method includes:

[0007] For any one of the multiple session entries, obtain a first data block in the session entry that contains a timestamp field;

[0008] When the timestamp field meets the aging condition, obtain all the data blocks of the session entry;

[0009] Generate second address information of the session entry according to the first address information of all the data blocks;

[0010] Delete the session entry according to the second address information.

[0011] In the embodiments of the present disclosure, it is determined whether a session entry reaches the aging condition according to the timestamp field of the first data block of the session entry, and all data blocks of the session entry are obtained when the session entry reaches the aging condition. In this way, when determining whether aging processing needs to be performed on the session entry, it is not necessary to read all data information of the session entry, which can greatly save the consumption time of data reading, achieve the purpose of timely aging processing of the session entry, and further improve the packet forwarding performance of the filtering firewall device.

[0012] In the embodiments of the present application, after obtaining the first data block including the timestamp field in the session entry, the method further includes:

[0013] Determine the timestamp corresponding to the timestamp field and the aging time threshold corresponding to the session entry;

[0014] Calculate the time difference between the timestamp and the current real-time time;

[0015] When the time difference is greater than the aging time threshold, determine that the timestamp field meets the aging condition.

[0016] In the embodiments of the present application, by calculating the time difference between the timestamp of the first data block in the session entry and the current real-time time, when the time difference is greater than the aging time threshold, it is determined that the timestamp field meets the aging condition, which can efficiently and accurately determine whether the session entry needs to be aged, and further improve the aging processing efficiency of the session entry.

[0017] In the embodiments of the present application, the firewall device includes a first chip and a second chip. After obtaining all the data blocks, the method further includes:

[0018] Generate feature information of the session entry according to all the data blocks;

[0019] Determine the remaining transmission quantity of the feature information in the current transmission period, where the remaining transmission quantity refers to the remaining quantity of the preset transmission quantity of the feature information in the current transmission period;

[0020] When the remaining transmission quantity meets the transmission condition, call the first chip to send the feature information of the session entry to the second chip.

[0021] In the embodiments of the present application, when the remaining transmission quantity meets the transmission condition, calling the first chip to send the feature information of the session entry to the second chip includes:

[0022] Determine whether the remaining number of tokens in the token bucket in the current sending period is greater than 0, where the remaining number of tokens is used to represent the remaining sending quantity; a preset number of tokens are delivered to the token bucket in each sending period; the preset number is used to represent the preset sending quantity of the feature information in each sending period.

[0023] If the remaining number of tokens is greater than 0, then call the first chip to send the feature information of the session entry to the second chip, and perform a decrement operation on the remaining number of tokens to obtain a new remaining number of tokens.

[0024] In the embodiment of the present application, by determining whether the remaining number of tokens in the token bucket in the current sending period is greater than 0, if the remaining number of tokens is greater than 0, then calling the first chip to send the feature information of the session entry to the second chip, it can make the feature information be reported to the second chip evenly, avoiding the situation that the second chip processes too much feature information in a short time and causing the second chip to be overloaded.

[0025] In the embodiment of the present application, the second chip includes multiple processing cores; calling the first chip to send the feature information of the session entry to the second chip includes:

[0026] Determine a target processing core according to at least one of the feature information of the session entry and the status information of the multiple processing cores;

[0027] Send the feature information of the session entry to the target processing core.

[0028] In the embodiment of the present application, determining a target processing core according to at least one of the feature information of the session entry and the status information of the multiple processing cores, and sending the feature information of the session entry to the target processing core can ensure that each processing core in the second chip can receive the feature information, avoiding the situation that a single processing core in the second chip processes too much feature information and causing the single processing core to be overloaded.

[0029] In the embodiment of the present application, determining a target processing core according to at least one of the feature information of the session entry and the status information of the multiple processing cores includes:

[0030] Read a processing core mapping field from the feature information of the session entry, and determine the target processing core according to the processing core mapping field;

[0031] Alternatively, perform a hash operation on the five-tuple information in the feature information of the session entry, and determine the target processing core according to the hash operation result;

[0032] Alternatively, determine the target processing core according to the preset processing order of the multiple processing cores and the current processing status of each processing core.

[0033] In an embodiment of the present application, the method further includes:

[0034] Receiving a packet to be forwarded from a client;

[0035] If there is no target session entry corresponding to the packet to be forwarded in the multiple session entries, creating the target session entry according to the five-tuple information of the packet to be forwarded.

[0036] An embodiment of the second aspect of the present application provides a firewall device, which includes a first chip, a second chip, and a session memory: Multiple session entries are stored in the session memory, where

[0037] The first chip is configured to, for any one of the multiple session entries stored in the session memory, obtain a first data block including a timestamp field in the session entry; and when the timestamp field meets the aging condition, obtain all data blocks of the session entry; and send all the data blocks to the second chip;

[0038] The second chip is configured to generate second address information of the session entry according to the first address information of all the data blocks, and send the second address information to the first chip;

[0039] The first chip is further configured to receive the second address information and delete the session entry in the session memory according to the second address information.

[0040] An embodiment of the third aspect of the present application provides a chip, which is used as the first chip and includes a communication interface, a memory, and a processor. The communication interface is used to connect the chip to the second chip in the firewall device; computer instructions are stored in the memory, and the processor executes the computer instructions to execute the management method of the session entry provided in the embodiment of the first aspect above.

[0041] An embodiment of the fourth aspect of the present application provides a network security device, which includes a memory and a processor. The memory and the processor are communicatively connected to each other. Computer instructions are stored in the memory, and the processor executes the computer instructions to execute the management method of the session entry described in the first aspect above.

[0042] An embodiment of the fifth aspect of the present application provides a computer-readable storage medium, on which computer instructions are stored. The computer instructions are used to cause a computer to execute the management method of the session entry described in the first aspect above.

[0043] Additional aspects and advantages of the present application will be given in part in the following description, become apparent in part from the following description, or be learned by practice of the present application. Description of the Drawings

[0044] By reading the following detailed description of the preferred embodiments, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present application. Also, throughout the drawings, the same reference numerals are used to denote the same components.

[0045] In the drawings:

[0046] Figure 1 A schematic structural diagram of an existing filtering firewall device provided by an embodiment of the present application is shown;

[0047] Figure 2 A schematic flowchart of a method for managing session table entries provided by an embodiment of the present application is shown;

[0048] Figure 3 A schematic diagram of a bank interleaved access mode provided by an embodiment of the present application is shown;

[0049] Figure 4 A schematic diagram of reporting rate of restricted feature information provided by an embodiment of the present application is shown;

[0050] Figure 5 A schematic diagram of determining the target processing core from multiple processing cores provided by an embodiment of the present application is shown;

[0051] Figure 6 A schematic structural diagram of a firewall device provided by an embodiment of the present application is shown;

[0052] Figure 7 A schematic structural diagram of a network security device provided by an embodiment of the present application is shown;

[0053] Figure 8 A schematic diagram of a storage medium provided by an embodiment of the present application is shown. Detailed Embodiments

[0054] The exemplary embodiments of the present application will be described in more detail below with reference to the drawings. Although the exemplary embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present application can be more thoroughly understood and the scope of the present application can be fully conveyed to those skilled in the art.

[0055] It should be noted that unless otherwise specified, the technical terms or scientific terms used in this application shall have the ordinary meanings understood by those skilled in the art to which this application pertains.

[0056] The following describes the technical scenarios involved in the embodiments of this application.

[0057] The filtering firewall device adopts an architecture mode combining FPGA (Field-Programmable Gate Array) and CPU (Central Processing Unit). For example Figure 1 As shown: The first chip (FPGA) is between the network switching device (SW) and the second chip (CPU). The FPGA communicates with the network switching device through a 100GE interface for high-speed communication (including packet receiving and sending processing), and the FPGA communicates with the CPU through a PCIE interface for high-speed communication (including session table item downlink flushing and management, etc.).

[0058] The FPGA will establish multiple session table entries based on information such as the five-tuple of the packet. When the client forwards a packet to the server, the FPGA will perform an exact match on the packet forwarded by the SW to determine whether there is a corresponding session in the multiple session table entries. If so, the packet will be directly transferred out of the FPGA to the SW internally, enabling the SW to forward the packet to the Server. This transmission path is called the fast path; otherwise, the packet will be first sent to the CPU for processing, and after the CPU finishes processing, it will return to the FPGA, and finally the FPGA will forward it to the SW, enabling the SW to forward the packet to the Server, which is called the slow path. To improve the packet forwarding performance (let the packet take the fast path as much as possible), on the one hand, more session table entries need to be established in the FPGA, but this will also occupy more hardware resources. On the other hand, sessions that have not been used for a long time can be aged.

[0059] Due to limited storage space, the number of maintained session table entries is limited. The prior art generally ages session table entries that have not been used for a long time (i.e., delete them from the storage space) to enable the packet to take the fast path as much as possible by adding new session table entries.

[0060] However, this method usually selects the session entry to be aged according to all the data information of multiple session entries. For example, there are multiple session entries stored in the session memory, and each session entry has multiple data blocks (such as burst0, burst1, and burst2). When determining whether each session entry needs to be aged, it is necessary to scan and read burst0, burst1, and burst2 of each session entry, and determine whether the session entry needs to be aged according to burst0, burst1, and burst2. In this process, since it is necessary to scan and read each data block (brust) of the session entry, the scanning and reading efficiency of the session entry is low; in the case of low scanning and reading efficiency of the session entry, it is easy to take a long time to scan and read all the data of each session entry when making an aging determination for multiple session entries, which is likely to cause the session entry not to be aged in time and the aging processing efficiency is low. Furthermore, it will also lead to the problem of low packet forwarding performance of the filtering firewall device.

[0061] According to an embodiment of the present application, an embodiment of a method for managing session entries is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0062] In this embodiment, a method for managing session entries is provided, which can be used in a firewall device. Figure 2 It is a flowchart of a method for managing session entries according to an embodiment of the present application, as Figure 2 shown, and the process includes the following steps:

[0063] Step S101, for any one of multiple session entries, obtain a first data block in the session entry that includes a timestamp field.

[0064] In an embodiment of the present application, each session entry is generated according to the five-tuple information of a packet. The five-tuple information of the packet includes, but is not limited to: source IP address, destination IP address, source port number, destination port number, and transport layer protocol. Each session entry has multiple data blocks (such as burst0, burst1, and burst2), and the first data block refers to the data block that includes a timestamp field among all the above data blocks, such as burst0.

[0065] In an embodiment of the present application, the multiple session entries are stored in a session storage device, and the session storage device may refer to a storage device built in the firewall device or an external storage device of the firewall device, which is not specifically limited here.

[0066] In some specific embodiments, when the session storage device is a storage device externally attached to a firewall device, the session storage device includes multiple memory modules, such as RDIMM memory modules (Registered DIMM, dual in-line memory module with register). Sessions in each RDIMM memory module (DDR4_64 composed of 16 DDR4 chips) are scanned independently. The specification of each RDIMM is 16GB, including 4 bankgroups, each bankgroup contains 4 banks, and each bank is composed of 128K rows and 1024 columns; the FPGA converts 1024*64bit of each row into 128*512bit and presents it to the logical user interface; the size of each session entry is 3*512bit, so each RDIMM memory module can store approximately 80 million sessions. 512bit is 1 data block burst of the session entry.

[0067] In some specific embodiments, when the session storage device is a storage device externally attached to a firewall device, the multiple memory modules in the session storage device can be scanned and accessed cyclically according to a scanning interval to read the first data block (i.e., burst0) of each session entry.

[0068] In the embodiments of the present application, during the process of cyclically scanning and accessing the multiple memory modules in the session storage device, in order to improve the access efficiency of each memory module, a bank interleaving method can be adopted for access, such as Figure 3 shown: accessing the first bank in each bankgroup in the memory module in parallel can obtain the access order, that is, "bank0→bank4→bank8→bank12"; after any first bank access is completed, the next bank in the same bankgroup can be accessed, and thus the further access order can be obtained, that is, "bank1→bank5→bank9→bank13"; repeat the above operations until all banks in the memory module are accessed.

[0069] In some specific embodiments, after the above step S101, the method further includes steps S201 - S203:

[0070] Step S201, determining the timestamp corresponding to the timestamp field and the aging time threshold corresponding to the session entry.

[0071] In the embodiments of the present application, the aging time thresholds corresponding to different session entries are different. For example, the aging time thresholds of the session entries for TCP (Transmission Control Protocol) packets and UDP (User Datagram Protocol) packets are different.

[0072] Step S202: Calculate the time difference between the timestamp and the current real-time time.

[0073] Step S203: When the time difference is greater than the aging time threshold, determine that the timestamp field meets the aging condition.

[0074] In the embodiments of the present application, if the time difference is less than or equal to the aging time threshold, the timestamp field does not meet the aging condition, which means that the session entry does not need to be aged; on the contrary, if the time difference is greater than the aging time threshold, the timestamp field meets the aging condition, which means that the session entry needs to be aged.

[0075] Step S102: When the timestamp field meets the aging condition, obtain all data blocks of the session entry.

[0076] In the embodiments of the present application, when the timestamp field meets the aging condition, it can be determined that the session entry containing the timestamp field needs to be aged. Therefore, the session entries containing the timestamp field are screened out from multiple session entries, so as to obtain all data blocks of the session entry (such as burst0, burst1, and burst2).

[0077] Among them, in the process of obtaining all data blocks of the session entry, all data information of the session entry can be scanned and read according to the first address information of the first data block to obtain all data blocks of the session entry.

[0078] In some specific embodiments, the firewall device includes a first chip (such as an FPGA) and a second chip (such as a CPU). After step S102, the method further includes steps S301 - S303:

[0079] Step S301: Generate feature information of the session entry according to all data blocks.

[0080] Step S302: Determine the remaining transmission quantity of the feature information in the current transmission cycle.

[0081] Among them, the remaining transmission quantity refers to the remaining quantity of the preset transmission quantity of the feature information in the current transmission cycle.

[0082] Step S303: When the remaining transmission quantity meets the transmission condition, call the first chip to send the feature information of the session entry to the second chip. Here, the transmission condition can be understood as the remaining transmission quantity being greater than 0.

[0083] In the embodiments of the present application, within each transmission period, the quantity of feature information sent by calling the first chip to the second chip is fixed, such as the above-mentioned preset transmission quantity. Therefore, when calling the first chip to send the feature information of the session entry to the second chip, it is necessary to first determine the remaining transmission quantity of the feature information within the current transmission period. If this remaining transmission quantity is greater than 0, then the first chip can be called to send the feature information of the session entry to the second chip; and after the sending is completed, perform a decrement operation on the remaining transmission quantity of the feature information within the current transmission period to obtain a new remaining transmission quantity; conversely, if this remaining transmission quantity is equal to 0, then wait until the next transmission period and re-judge whether the remaining transmission quantity is greater than 0, and call the first chip to send the feature information of the session entry to the second chip when the remaining transmission quantity is greater than 0.

[0084] In some specific embodiments, for example Figure 4 As shown: The above-mentioned step S303 includes steps S401 - S402:

[0085] Step S401: Judge whether the remaining number of tokens in the token bucket within the current transmission period is greater than 0.

[0086] In the embodiments of the present application, the remaining number of tokens is used to represent the remaining transmission quantity; a preset quantity of tokens is delivered to the token bucket within each transmission period; the preset quantity is used to represent the preset transmission quantity of the feature information within each transmission period.

[0087] Step S402: If the remaining number of tokens is greater than 0, then call the first chip to send the feature information of the session entry to the second chip, and perform a decrement operation on the remaining number of tokens to obtain a new remaining number of tokens.

[0088] In the embodiments of the present application, if the remaining number of tokens is equal to 0, then the first chip cannot be called to send the feature information of the session entry to the second chip; wait until the next transmission period and re-execute step S401 until the remaining number of tokens is greater than 0 and then call the first chip to send the feature information of the session entry to the second chip.

[0089] In the embodiments of the present application, since the session table entries that need to be aged in the RDIMM memory module are randomly distributed, for those that can support more than 80 million session table entries, within a unit time, the characteristic information that the first chip needs to report to the second chip is not uniform. Sometimes the quantity may be 0, and sometimes the quantity may be very large. The PCIE communication bandwidth between the first chip and the second chip is limited. Then, when the aging reporting rate increases to a certain extent, it may cause the CPU to be instantly overwhelmed. Considering the above situation, the present application can effectively limit the reporting rate of the characteristic information by controlling the quantity of the characteristic information sent by the first chip to the second chip in each sending cycle, so that the characteristic information is evenly sent to the second chip, avoiding the occurrence of the overload situation of the second chip.

[0090] In some specific embodiments, the second chip includes a plurality of processing cores, such as 64 cores; the above step S303 further includes steps S501 - S502:

[0091] Step S501, determine a target processing core according to at least one of the characteristic information of the session table entry and the status information of the plurality of processing cores.

[0092] In some specific embodiments, step S501 further includes step S601:

[0093] Step S601, read a processing core mapping field from the characteristic information of the session table entry, and determine the target processing core according to the processing core mapping field; or, perform a hash operation on the five-tuple information in the characteristic information of the session table entry, and determine the target processing core according to the hash operation result; or, determine the target processing core according to the preset processing order of the plurality of processing cores and the current processing status of each processing core.

[0094] In the embodiments of the present application, since the second chip is a multi-core processor including a plurality of processing cores, in order to avoid the situation that a single processing core in the second chip is overloaded, the present application distributes a plurality of characteristic information to be sent to the plurality of processing cores of the second chip, so as to ensure that each processing core of the second chip can receive the characteristic information of the session table entry evenly.

[0095] In the embodiments of the present application, determining the target processing core according to the processing core mapping field can be understood as: the processing core mapping field in the characteristic information of a certain session table entry can map out the target processing core from a plurality of processing cores; determining the target processing core according to the hash operation result can be understood as: performing a hash operation (such as the CRC32 algorithm) on the five-tuple information in the characteristic information to be sent, and determining the target processing core according to the hash operation result.

[0096] In the embodiments of the present application, for example Figure 5As shown, determining the target processing core according to the preset processing order of the multiple processing cores and the current processing status of each processing core can be understood as follows: The multiple processing cores of the second chip have a predefined processing order. For example: CPU0, CPU1,..., CPU63. That is to say, when the second chip receives the feature information, it judges the current processing status of CPU0. If CPU0 is in the working state (i.e., processing the feature information), it then judges the current processing status of CPU1, and judges the status of the multiple processing cores in the processing order until a processing core in the idle state is found, and the feature information is sent to this processing core in the idle state.

[0097] Step S502, send the feature information of the session entry to the target processing core.

[0098] Step S103, generate the second address information of the session entry according to the first address information of all data blocks.

[0099] In the embodiment of the present application, after the second chip receives the feature information of the session entry, it will read the first address information of all data blocks in the feature information, then calculate the second address information of this session entry according to the first address information of all data blocks, and send this second address information to the first chip.

[0100] Step S104, delete the session entry according to the second address information.

[0101] Specifically, after the first chip receives the second address information from the second chip, it can screen out the session entry corresponding to this second address information from multiple session entries and delete this session entry.

[0102] In some specific embodiments, the method further includes:

[0103] Step S701, receive the packet to be forwarded from the client;

[0104] Step S702, if there is no target session entry corresponding to the packet to be forwarded in the multiple session entries, create the target session entry according to the five-tuple information of the packet to be forwarded.

[0105] In an embodiment of the present application, after the first chip receives a packet to be forwarded from a client, it scans multiple session entries respectively to determine whether there is a target session entry corresponding to the packet to be forwarded among the multiple session entries; if there is no target session entry corresponding to the packet to be forwarded among the multiple session entries, the target session entry is created according to the five-tuple information of the packet to be forwarded; conversely, if there is a target session entry corresponding to the packet to be forwarded among the multiple session entries, the packet to be forwarded is forwarded to the server.

[0106] In an embodiment of the present application, through a two-level scanning method, that is, first scanning to obtain the first data block containing the timestamp field in each session entry in the session storage device, and judging whether the session entry needs to be aged according to the timestamp field, and then scanning the session entries that need to be aged to obtain all the data blocks of the session entry, the total number of accesses to the session storage device can be greatly reduced, the session entry can be aged in time, and thus the packet forwarding performance of the firewall can be improved. An example is given to illustrate this:

[0107] Currently, 80 million sessions are stored in 1 RDIMM memory module, and 10 million sessions meet the aging conditions. If a one-level scanning scheme is adopted, that is, all data blocks (such as burst0, burst1, and burst2) of each session entry in 80 million sessions are scanned and read, the total number of accesses to the session storage device is 80 million * 3 = 240 million; if a two-level scanning scheme is adopted, that is, first scanning and reading the first data block (such as burst0) in each session entry in 80 million sessions, and then judging that 10 million sessions meet the aging conditions according to the obtained timestamp field, and finally scanning and reading all data blocks (such as burst0, burst1, and burst2) of 10 million sessions again. Then the total number of accesses to the session storage device is 80 million * 1 + 10 million * 3 = 110 million. In the same situation, the latter reduces 130 million DDR4 accesses compared with the former, and can greatly improve the aging efficiency of session entries.

[0108] Corresponding to the implementation manner of the above session entry management method, an embodiment of the present application further provides a firewall device for executing the session entry management method described in the above embodiment. The firewall device includes a first chip, a second chip, and a session memory: multiple session entries are stored in the session memory, where,

[0109] The first chip is configured to obtain, for any one of the multiple session entries stored in the session memory, a first data block in the session entry that includes a timestamp field; and when the timestamp field meets the aging condition, obtain all data blocks of the session entry; and send all the data blocks to the second chip;

[0110] The second chip is configured to generate second address information of the session entry according to the first address information of all the data blocks, and send the second address information to the first chip;

[0111] The first chip is further configured to receive the second address information and delete the session entry in the session memory according to the second address information.

[0112] In some specific embodiments, as Figure 6 shown, the first chip includes a scan aging module and a session management module;

[0113] The scan aging module is configured to obtain, for any one of the multiple session entries stored in the session memory, a first data block in the session entry that includes a timestamp field; and when the timestamp field meets the aging condition, obtain all data blocks of the session entry and send all the data blocks to the second chip;

[0114] The second chip is configured to receive all the data blocks, generate second address information of the session entry according to the first address information of all the data blocks; generate a session deletion command including the second address information, and send the session deletion command to the session management module;

[0115] The session management module is configured to receive the session deletion command and delete the session entry from the session storage device according to the second address information in the session deletion command.

[0116] In some specific embodiments, for example Figure 6 shown, the first chip further includes a packet matching module;

[0117] The packet matching module is configured to receive a packet to be forwarded from a client; determine whether there is a target session entry corresponding to the packet to be forwarded among the multiple session entries; if there is no target session entry corresponding to the packet to be forwarded among the multiple session entries, send the packet to be forwarded to the second chip;

[0118] The second chip is further configured to generate a session entry creation command according to the five-tuple information of the packet to be forwarded, and send the session entry creation command to the session management module;

[0119] The session management module is further configured to receive the session entry creation command from the second chip, and create a target session entry corresponding to the to-be-forwarded packet in the session storage device according to the session creation command.

[0120] In some specific embodiments, for example Figure 6 As shown, the first chip further includes a first scheduling module;

[0121] The first scheduling module is configured to screen for a target session entry corresponding to the to-be-forwarded packet in the session storage device according to the packet matching command sent by the packet matching module;

[0122] The first scheduling module is further configured to create a target session entry corresponding to the to-be-forwarded packet in the session storage device according to the session entry creation command sent by the session management module;

[0123] The first scheduling module is further configured to perform aging scanning on multiple session entries in the session storage device according to the scanning instruction sent by the scanning and aging module; for any one of the multiple session entries, obtain a first data block including a timestamp field in the session entry, and send the first data block to the scanning and aging module.

[0124] In some specific embodiments, for example Figure 6 As shown, the first chip further includes a second scheduling module;

[0125] The second scheduling module is configured to forward the to-be-forwarded packet from the packet matching module to the second chip, and forward the session entry creation command from the second chip to the session management module;

[0126] The second scheduling module is further configured to forward the feature information from the scanning and aging module to the second chip, and forward the session deletion command from the second chip to the session management module.

[0127] The firewall device provided in the above embodiments of the present application and the method for managing session entries provided in the embodiments of the present application are based on the same inventive concept, and have the same beneficial effects as the methods adopted, run or implemented by the stored application programs.

[0128] The embodiments of the present application further provide a network security device to execute the above method for managing session entries. Please refer to Figure 7 , which shows a schematic diagram of a network security device provided by some embodiments of the present application. As Figure 7As shown in the figure, the network security device 7 includes: a processor 700, a memory 701, a bus 702, and a communication interface 703. The processor 700, the communication interface 703, and the memory 701 are connected through the bus 702. A computer program that can run on the processor 700 is stored in the memory 701. When the processor 700 runs the computer program, it executes the management method of the session table entries provided in the foregoing embodiments of the present application.

[0129] Among them, the memory 701 may include a high-speed random access memory (Random Access Memory, RAM), and may also include a non-volatile memory, such as at least one disk memory. Through at least one communication interface 703 (which can be wired or wireless), a communication connection is established between this system network element and at least one other network element. The Internet, wide area network, local area network, metropolitan area network, etc. can be used.

[0130] The bus 702 can be an ISA bus, a PCI bus, an EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. Among them, the memory 701 is used to store a program. After receiving an execution instruction, the processor 700 executes the program. The management method of the session table entries disclosed in the foregoing embodiments can be applied to or implemented by the processor 700.

[0131] The processor 700 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit in the hardware of the processor 700 or by an instruction in software form. The above-mentioned processor 700 may be a general-purpose processor, including a central processing unit (Central Processing Unit, abbreviated as CPU), a network processor (Network Processor, abbreviated as NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or completed by a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 701, and the processor 700 reads the information in the memory 701 and combines its hardware to complete the steps of the above method.

[0132] The network security device provided by the embodiments of the present application and the method for managing session entries provided by the embodiments of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run, or implemented by them.

[0133] The embodiments of the present application also provide a computer-readable storage medium corresponding to the method for managing session entries provided by the foregoing embodiments. Please refer to Figure 8 , which shows that the computer-readable storage medium is an optical disc 30, on which a computer program (i.e., a program product) is stored. When the computer program is run by a processor, it will execute the method for managing session entries provided by any of the foregoing embodiments.

[0134] It should be noted that examples of the computer-readable storage medium may also include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory, or other optical and magnetic storage media, which will not be elaborated here one by one.

[0135] The computer-readable storage medium provided by the above embodiments of the present application and the method for managing session entries provided by the embodiments of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run, or implemented by the application programs stored therein.

[0136] It should be noted that:

[0137] In the specification provided here, a large number of specific details are described. However, it can be understood that the embodiments of the present application can be practiced without these specific details. In some instances, well-known structures and technologies are not shown in detail so as not to obscure the understanding of this specification.

[0138] Similarly, it should be understood that, in order to streamline the present application and help understand one or more of the various inventive aspects, in the above description of the exemplary embodiments of the present application, the various features of the present application are sometimes grouped together into a single embodiment, figure, or description thereof. However, the disclosed method should not be construed as reflecting the following schematic diagram: that the claimed present application requires more features than those expressly recited in each claim. Rather, as reflected by the following claims, the inventive aspects lie in less than all the features of the single embodiments disclosed above. Therefore, the claims following the detailed description are hereby expressly incorporated into the detailed description, where each claim itself serves as a separate embodiment of the present application.

[0139] In addition, those skilled in the art will understand that although some of the embodiments described herein include certain features included in other embodiments rather than other features, the combination of features of different embodiments is meant to be within the scope of this application and forms different embodiments. For example, in the following claims, any one of the claimed embodiments can be used in any combination.

[0140] As described above, the above are only the preferred specific embodiments of this application, but the protection scope of this application is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed in this application should be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the said claims.

Claims

1. A method for managing session entries, characterized in that: The method is applied to a firewall device; the method comprises: For any one of the multiple session table entries, obtaining a first data block containing a timestamp field in the session table entry; When the timestamp field meets the aging condition, obtaining all data blocks of the session entry; generating second address information of the session table entry according to the first address information of all the data blocks; The session entry is deleted according to the second address information.

2. The method according to claim 1, characterized in that After obtaining the first data block containing the timestamp field in the session table entry, the method further includes: Determine a timestamp corresponding to the timestamp field and an aging time threshold corresponding to the session entry; Calculate the time difference between the timestamp and the current real time; When the time difference is greater than the aging time threshold, it is determined that the timestamp field meets the aging condition.

3. The method according to claim 1 or 2, characterized in that: The firewall device includes a first chip and a second chip. After acquiring all the data blocks, the method further includes: generating characteristic information of the session table entry according to all the data blocks; Determine the remaining number of characteristic information sent in the current sending cycle, where the remaining number of characteristic information sent refers to the number of characteristic information sent in the current sending cycle. When the remaining sending quantity meets the sending condition, the first chip is called to send the characteristic information of the session table item to the second chip.

4. The method according to claim 3, characterized in that When the remaining sending quantity meets the sending condition, calling the first chip to send the characteristic information of the session table item to the second chip includes: Determine whether the number of remaining tokens in the token bucket in the current sending cycle is greater than 0, and the remaining number of tokens is used to represent the remaining sending quantity; deliver a preset number of tokens to the token bucket in each sending cycle; the preset number is used to represent the preset sending quantity of characteristic information in each sending cycle; If the number of remaining tokens is greater than 0, the first chip is called to send the characteristic information of the session table entry to the second chip, and the number of remaining tokens is reduced by one to obtain a new number of remaining tokens.

5. The method according to claim 3, characterized in that: The second chip includes a plurality of processing cores; calling the first chip to send the characteristic information of the session table entry to the second chip includes: determining a target processing core according to the feature information of the session table entry and at least one of the state information of the plurality of processing cores; The characteristic information of the session table entry is sent to the target processing core.

6. The method according to claim 5, characterized in that Determining a target processing core according to the feature information of the session table entry and at least one of the state information of the multiple processing cores includes: Reading a processing core mapping field from the characteristic information of the session table entry, and determining the target processing core according to the processing core mapping field; Alternatively, a hash operation is performed on the five-tuple information in the characteristic information of the session table entry, and the target processing core is determined according to the hash operation result; Alternatively, the target processing core is determined according to a preset processing order of the multiple processing cores and a current processing state of each processing core.

7. The method according to claim 1 or 2, characterized in that: The method further comprises: Receive messages to be forwarded from the client; If the target session entry corresponding to the message to be forwarded does not exist in the multiple session entries, the target session entry is created according to the five-tuple information of the message to be forwarded.

8. A firewall device, characterized in that: The firewall device comprises a first chip, a second chip and a session memory: the session memory stores a plurality of session entries, wherein: The first chip is configured to obtain, for any one of the plurality of session entries stored in the session memory, a first data block containing a timestamp field in the session entry; and, when the timestamp field meets an aging condition, obtain all data blocks of the session entry; and send all data blocks to the second chip; The second chip is used to generate second address information of the session table entry according to the first address information of all the data blocks, and send the second address information to the first chip; The first chip is further configured to receive the second address information, and delete the session entry in the session memory according to the second address information.

9. A chip, characterized in that: Used as a first chip, including a communication interface, a memory and a processor, The communication interface is used to connect the chip with a second chip in the firewall device; the memory stores computer instructions, and the processor executes the method described in any one of claims 1 to 7 by executing the computer instructions.

10. A network security device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the method according to any one of claims 1 to 7 by executing the computer instructions.