Information statistical method and device and related product
By filtering target events from data stream events, analyzing the flow identification information and calculating the initial access number, the problem of difficult to count the number of allowed accesses in the prior art is solved, and accurate statistics of the number of accesses of data streams is achieved, and troubleshooting efficiency and communication security are improved.
Patent Information
- Application Number
- CN202510254090.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-04
- Publication Date
- 2025-06-24
AI Technical Summary
The prior art is difficult to accurately count the number of allowed accesses of data streams during the reporting period, resulting in the inability to accurately locate problems between microservices, affecting troubleshooting efficiency and communication security.
By filtering the target event from the events of the current data stream, analyzing the flow identification information, obtaining the initial number of accesses in the flow information cache, and calculating the number of accesses of the current data stream in the reporting period based on the initial number of times.
It realizes accurate statistics on the number of accesses of data streams during the reporting period, improving troubleshooting efficiency and communication security.
Smart Images

Figure CN120200782A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the technical field of communication networks, and in particular, to information statistics methods, devices, and related products. Background Art
[0002] In computer science, a data stream describes the way and path of data flowing in an information system. It is used to represent the process of data transfer from one place to another, and is usually used for process control, data processing, and system analysis. The access count of a data stream can measure the access frequency and activity of a device or system to a certain website or page.
[0003] Currently, the cilium plugin is often used as a container network interface (CNI, Container Network Interface) to listen for stream access events, so as to obtain stream identification information such as the stream access relationship between microservices in the cluster (such as unit pod1 accessing pod2) and connection information related to the stream (such as source ip, destination ip), etc., and report (which can be called export). However, unfortunately, this method often fails to effectively obtain statistical information about the stream. For example, it is impossible to count the number of allowed (ACCEPT) accesses of this stream during the current reporting period. The lack of statistical information about the stream during reporting will lead to the inability to accurately locate the problems existing between microservices, affecting the troubleshooting efficiency and communication security.
[0004] In view of this, the present application provides an effective solution. Summary of the Invention
[0005] The embodiments of the present application provide an information statistics method, device, and related products, which are used to accurately count the number of accesses allowed by policies for each data stream during the reporting period and maintain communication security.
[0006] The first aspect of the embodiments of the present application provides an information statistics method, including:
[0007] Filter out the target events corresponding to the current data stream during the current reporting period from various events of the current data stream, and parse the stream identification information of the current data stream from the target event information;
[0008] Based on the stream identification information of the current data stream, obtain the initial access count corresponding to the current data stream at the start of the current reporting period from the stream information cache set;
[0009] Calculate the period access count of the current data stream during the current reporting period according to the initial access count.
[0010] Optionally, the calculating the period access count of the current data stream during the current reporting period according to the initial access count includes:
[0011] Calculate the period access times of the current data stream within the current reporting period based on the initial access times and the target event information.
[0012] Optionally, the calculating the period access times of the current data stream within the current reporting period based on the initial access times and the target event information includes:
[0013] Based on the protocol type and / or access control type of the current data stream in the target event information, determine the access times calculation logic that the current data stream conforms to; the access times calculation logic at least references the initial access times of the current data stream;
[0014] Calculate the period access times of the current data stream within the current reporting period according to the access times calculation logic and the initial access times of the current data stream.
[0015] Optionally, if the current data stream is a data stream that does not use the target protocol and the access control type is allowed, the period access times include the period allowed access times, and the process of calculating the period access times of the current data stream within the current reporting period according to the access times calculation logic and the initial access times of the current data stream includes:
[0016] Obtain the total allowed access times counted for the current data stream up to the end of the current reporting period based on the stream identification information of the current data stream, and set the initial allowed access times corresponding to the current data stream at the start of the current reporting period as the initial access times;
[0017] Subtract the initial access times of the current data stream from the total allowed access times to obtain the period allowed access times of the current data stream within the current reporting period;
[0018] Update the total allowed access times to the stream information cache set as the initial access times corresponding to the current data stream at the start of the next reporting period, so as to return to the step of subtracting the initial access times of the current data stream from the total allowed access times to obtain the period allowed access times of the current data stream within the next reporting period.
[0019] Optionally, if the current data stream is a data stream that uses the target protocol and the access control type is allowed, the period access times include the period allowed access times, and the process of calculating the period access times of the current data stream within the current reporting period according to the access times calculation logic and the initial access times of the current data stream includes:
[0020] Set the initial access count of the current data stream to 0, and accumulate the number of times the current data stream is in the new state during the current reporting period based on the initial access count to obtain the period allowed access count of the current data stream during the current reporting period.
[0021] Optionally, if the access control type of the current data stream is rejection, the period access count includes the period rejection access count. The process of calculating the period access count of the current data stream during the current reporting period according to the access count calculation logic and the initial access count of the current data stream includes:
[0022] Set the initial access count of the current data stream to 0, and on the basis of the initial access count, set that each time the current data stream is discarded during the current reporting period, the period rejection access count of the current data stream during the current reporting period increases by one.
[0023] Optionally, filtering out the target events corresponding to the current data stream during the current reporting period from various events of the current data stream includes:
[0024] Exclude the events reported by either the receiving side or the sending side of the current data stream during the current reporting period, and the events reported by the reverse flow opposite to the transmission direction of the current data stream;
[0025] Filter out the new event and discard event of the current data stream from the remaining events obtained by exclusion to form the target event.
[0026] Optionally, after obtaining the period access count, the information statistics method further includes:
[0027] When the end time of the current reporting period arrives or after that, aggregate the period access counts of multiple current data streams in a group of messages for reporting; the flow identification information between multiple current data streams is not completely the same.
[0028] Optionally, if it is selected to record the flow information of each current data stream in the flow information cache set, the flow information includes the flow identification information and / or the period access count of the current data stream. After obtaining the period access count, the information statistics method further includes:
[0029] After the flow information reporting of at least one current data stream is completed, obtain the time difference between the latest update time of each period access count and the reporting time;
[0030] Delete the flow information of the current data stream in the flow information cache set whose time difference exceeds the preset time period.
[0031] When the method described in the first aspect of the present application is specifically implemented, the content described in the second aspect of the present application can be used for implementation.
[0032] The second aspect of the embodiments of the present application provides an information statistics device, including: an acquisition unit and a processing unit;
[0033] The acquisition unit is configured to filter out the target events corresponding to the current data stream during the current reporting period from various events of the current data stream, and parse the stream identification information of the current data stream from the target event information;
[0034] The processing unit is configured to obtain the initial access times corresponding to the current data stream at the start of the current reporting period from the stream information cache set based on the stream identification information of the current data stream;
[0035] The processing unit is further configured to calculate the period access times of the current data stream during the current reporting period according to the initial access times.
[0036] The third aspect of the embodiments of the present application provides an electronic device, including: a processor and a memory;
[0037] The processor is configured to communicate with the memory and execute the instructions in the memory to implement the method described in the first aspect or any specific implementation manner of the first aspect of the embodiments of the present application.
[0038] The fourth aspect of the embodiments of the present application provides a computer-readable storage medium, where the readable storage medium stores computer instructions, and when the computer instructions are executed by a processor, the method described in the first aspect or any specific implementation manner of the first aspect of the embodiments of the present application is implemented.
[0039] The fifth aspect of the embodiments of the present application provides a computer program product, where the computer program product includes computer instructions, and when the computer instructions are executed by a processor, the method described in the first aspect or any specific implementation manner of the first aspect of the embodiments of the present application is implemented.
[0040] From the above technical solutions, it can be seen that the embodiments of the present application at least have the following advantages:
[0041] The embodiments of the present application adopt a stream information cache set, which can efficiently save the corresponding relationship between the stream identification information of the data stream and its initial access times, so that the initial access times of the current data stream can be quickly found through the stream identification information, so as to quickly and accurately count the period access times of the current data stream during the current reporting period, and effectively maintain the communication security between systems or devices. Description of the Drawings
[0042] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments recorded in the present application. For those of ordinary skill in the art, other accompanying drawings can also be obtained based on these drawings.
[0043] It should be noted that although each step in the flowchart of the process involved in each embodiment (if any) is drawn in sequence according to the indication of the arrow, unless there is a clear description in this article, the execution of these steps has no strict order limitation, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in each embodiment may include multiple steps or multiple stages. These steps or stages do not necessarily need to be executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0044] Figure 1 It is a schematic diagram of the system architecture of the information statistics method according to the embodiment of the present application;
[0045] Figure 2 It is a flowchart of a process of the information statistics method according to the embodiment of the present application;
[0046] Figure 3 It is a display diagram of the statistical results of the information statistics method according to the embodiment of the present application;
[0047] Figure 4 It is another flowchart of the information statistics method according to the embodiment of the present application;
[0048] Figure 5 It is a flowchart for counting the number of non-tcp accept flows in the information statistics method according to the embodiment of the present application;
[0049] Figure 6 It is a schematic diagram of the structure of the information statistics device according to the embodiment of the present application;
[0050] Figure 7 It is a schematic diagram of the structure of an electronic device according to the embodiment of the present application. Detailed implementation manners
[0051] In order to make the purpose, technical solutions and advantages of the present application clearer, the following will further describe the present application in detail with reference to the accompanying drawings. The described embodiments should not be regarded as limitations of the present application. All other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present application.
[0052] The terms "first", "second", "third", "fourth", etc. (if any) in the description, claims and drawings of this application are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that comprises a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0053] In the following description, reference is made to "a specific embodiment" or "a specific example" or the like, which describes a subset of all possible embodiments. However, it can be understood that "a specific embodiment" or "a specific example" can be the same subset or different subsets of all possible embodiments and can be combined with each other without conflict. In the following description, the term "a plurality of" means at least two. When it is said in this application that a certain value reaches a threshold (if any), in some specific examples, it may include the case where the former is greater than the latter. If terms such as "any" or "at least one" or the like are mentioned, it may specifically refer to any one of the listed examples or any combination between these examples.
[0054] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.
[0055] Please refer to Figure 1 , Figure 1 which is a schematic diagram of the system architecture provided by the embodiments of this application. As Figure 1As shown in the figure, the system architecture may include a business server 100 and a terminal cluster. The terminal cluster may include terminal devices such as terminal device 200a, terminal device 200b, terminal device 200c, …, terminal device 200n. Among them, the above-mentioned business server 100 may be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud databases, cloud services, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The terminal devices (including terminal device 200a, terminal device 200b, terminal device 200c, …, terminal device 200n) may be intelligent terminals such as smart phones, tablet computers, laptop computers, desktop computers, palmtop computers, mobile internet devices (MIDs), wearable devices (such as smart watches, smart bracelets, etc.), intelligent computers, and intelligent vehicles. Among them, the business server 100 can establish communication connections with each terminal device in the terminal cluster, and communication connections can also be established between the terminal devices in the terminal cluster. In other words, the business server 100 can establish communication connections with each of the terminal devices such as terminal device 200a, terminal device 200b, terminal device 200c, …, terminal device 200n. For example, a communication connection can be established between terminal device 200a and the business server 100. A communication connection can be established between terminal device 200a and terminal device 200b, and a communication connection can also be established between terminal device 200a and terminal device 200c. The above communication connections are not limited to the connection method, and can be directly or indirectly connected through wired communication methods, or directly or indirectly connected through wireless communication methods, etc. Specifically, it can be determined according to the actual application scenario, and this application does not make any restrictions here.
[0056] It should be noted that the method provided in the embodiments of this application can be executed by the business server 100 as shown in Figure 1 the figure, or by a terminal device (such as any one of the terminal devices 200a, 200b, …, 200n shown in Figure 1 the figure), or jointly executed by the terminal device and the business server 100. Specifically, it can be determined according to the actual application scenario, and no restrictions are made here.
[0057] Exemplarily, the terminal device 200a can filter out the target events corresponding to the current data stream during the current reporting period from various events of the current data stream, and parse the stream identification information of the current data stream from the target event information. The terminal device 200a sends the parsed stream identification information of the current data stream to the service server 100. Based on the stream identification information of the current data stream, the service server 100 obtains the initial access count corresponding to the current data stream at the start of the current reporting period from the stream information cache set. In addition, the service server 100 can calculate the period access count of the current data stream during the current reporting period according to the initial access count. This period access count can be specifically divided into the period allowed access count allowed by the policy and the period denied access count denied by the policy, and the details can be seen below.
[0058] Both the above-mentioned terminal device 200a (for collecting stream identification information) and the service server 100 (for calculating the period access count) can be regarded as collectors. Correspondingly, the application end for collecting and / or displaying the period access count can be called a collector. This collector can be the terminal device 200a or the service server 100 itself, and there is no specific limitation.
[0059] For another example, the terminal device 200a can be responsible for filtering out the target events, and the service server 100 is responsible for performing other operation steps such as parsing and calculating.
[0060] Next, the method of the present application will be further described in detail, and some specific possible implementation examples will be provided. In actual applications, the implementation contents among these examples can be combined or implemented separately according to the corresponding functional principles and application logics as needed. If combined, the execution order between the combined examples can be determined according to their respective processing logics, and can be specifically determined by the actual scenario.
[0061] Please refer to Figure 2 , a specific embodiment of an information statistics method provided by the first aspect of the present application includes the following operation steps:
[0062] Step S21: Filter out the target events corresponding to the current data stream during the current reporting period from various events of the current data stream, and parse the stream identification information of the current data stream from the target event information;
[0063] In practical applications, listening to flow access events (such as cilium events) can clearly understand the connection access relationships between microservices in the cluster and traffic details (such as flow identification information), which is very helpful for locating problems between microservices. For example, when it is found that the number of connections is too large, problems such as possible SYN Flood attacks, UDP Flood attacks, scanning attacks, occupying the cache queue, and occupying resources may be discovered, resulting in service unavailability; sending a large number of packets regularly is likely to cause a sudden increase in the cpu load; occupying the receive and transmit packet queue resources is likely to cause packet loss of service traffic; suddenly occupying the network bandwidth is likely to cause a sudden increase in service latency. However, currently, the industry does not have a good solution for obtaining the connection statistics information (i.e., the number of accesses during the data flow period) of projects such as cilium. For example, it is impossible to know when the table entry ctmap (used to record flow access information) in cilium is deleted, which results in the situation that short connection information cannot be obtained when polling for traffic; for short connections, due to their short existence time, it is possible that during the interval between two exports, the short connection has gone through the process of creation to discard, but the flow information and even the count statistics cannot be accurately obtained in a short time, resulting in the loss of this part of information and inability to display it during traffic visualization. For example, the period for polling and querying traffic is 5 minutes, while the actual existence time of a short connection may be only 2 seconds, plus the aging time of 60 seconds. Therefore, if there are many short connections attacking within a reporting period, these short connections cannot be collected for information, let alone the traffic statistics of short connections. Therefore, the embodiment of this application proposes an information statistics method, which can obtain connection statistics information based on cilium cni.
[0064] It should be added that the above-mentioned Cilium is an open-source project in the field of container networking, often used in conjunction with the container orchestration engine Kubernetes. CNI (Container Network Interface) is a specification and interface for container networking. The above-mentioned connection access relationship can be that a resource management component pod (with an independent IP address) on a certain host accesses another pod on the same or different hosts in the form of the tcp protocol.
[0065] As described above, in general, when multiple pod terminals establish a connection, an event will be reported. The event of the data stream (which can be simply referred to as the stream event) often includes stream information such as stream identification information and the status information of the stream (such as whether it is a newly created stream). Therefore, the embodiments of the present application design to monitor the stream event information to sense the stream identification information of the stream, which is convenient for subsequent statistics and reporting of the stream information. The above events can include a new event and a discard event. The new event can indicate that the data stream corresponding to this connection is newly established, and the discard event can indicate that the data stream corresponding to this connection is rejected by the network policy mechanism. For example, every time a data packet of the data stream is discarded, a drop event will be reported to indicate that this data stream is denied access.
[0066] Step S22: Based on the stream identification information of the current data stream, obtain the initial access count corresponding to the current data stream at the start of the current reporting period from the stream information cache set;
[0067] The above stream identification information can refer to the five-tuple information composed of the source IP, destination IP, protocol number, destination port, access control type (permit ACCEPT or deny deny) of the data stream, etc. The five-tuple information in the stream information cache set can be used as the key key to correspond to the key value value (i.e., the access count num during the period) of the current data stream (referred to as the current stream) associated therewith. In other words, the access counts of each data stream are identified or distinguished by the stream identification information of the data stream; at the start of the current reporting period, the value can be recorded as the initial access count.
[0068] In practical applications, by using the stream information cache set, at least part of the stream information in the case of short connections can be efficiently and concisely saved, avoiding the problem of stream information loss caused by the short existence time of short connections. As shown in the following table, the five-tuple information can at least reflect that IP1 of a certain host accesses IP2 on the same or different hosts in the manner of protocol number PROTO, and the corresponding current access relationship stream generated is permitted to be accessed by the policy, that is, the num value can be recorded as +1 time.
[0069]
[0070] Step S23: Calculate the access count during the current reporting period of the current data stream according to the initial access count.
[0071] Generally, the process of sending stream information from the collector to the collector is called an export or reporting of the data stream. To avoid information chaos caused by reporting a large amount of stream information at one time, it can be designed to report the access count during this period and even stream information such as stream identification information in each reporting period, that is, report the corresponding information in sub-periods.
[0072] In actual situations, based on the initial access count, the period access count of the current data stream within the current reporting period can be accumulated. For example, Figure 3 As shown, the period access count can be specifically divided into the period allowed access count and the period denied access count. The period allowed access count and the period denied access count can be summed up as the period cumulative access count. Taking the period denied access count as an example, the drop event of a stream and the access count have a one-to-one relationship. Multiple drop events may belong to the same stream. For example, a certain external network IP (abbreviated as a) accesses the payment system of the hospital information system HIS (abbreviated as b). The connection from a to b is a stream. However, if it is accessed 3 times and dropped 3 times, 3 drop events will be generated (the specific reason may be that the data packets in the stream are discarded). Therefore, the drop statistic num of the stream from a to b (i.e., the period denied access count) is the initial denied access count plus 3 times.
[0073] In summary, the embodiment of the present application adopts a stream information cache set, which can efficiently save the corresponding relationship between the stream identification information of the data stream and its initial access count, enabling the initial access count of the current data stream to be quickly found through the stream identification information, so as to quickly and accurately count the period access count of the current data stream within the current reporting period, and effectively maintain the communication security between systems or devices.
[0074] Based on the above example description, the method of the present application will be further described in detail below, and some specific possible implementation examples will be provided. In actual applications, the implementation contents of these examples can be combined or implemented separately according to the corresponding functional principles and application logics as needed. If combined, the execution order between the combined examples can be determined according to their respective processing logics, which can be specifically determined by the actual scenario.
[0075] Exemplarily, the stream information cache set can be divided into a non-tcp cache table and a tcp cache table. The tcp cache table (based on the five-tuple of source IP, destination IP, protocol number, destination port number, and access control) mainly records the aggregation information of the aggregated stream based on the source port number (such as tcp stream) and the stream information of the deny stream; the non-tcp stream statistics cache table (based on source IP, destination IP, protocol, destination port number, and source port number) mainly records the statistical information of each non-tcp detailed stream (stream not aggregated by source port).
[0076] The ct map is a global large table entry for the entire system currently. Since reading the ct map takes a long time, has low efficiency, and needs to be read regularly, there may be a situation where short connections cannot read it. Therefore, a cache table is added and used to increase the statistical efficiency and accuracy. Specifically, information can be read from the cilium ct map and stored in two cache tables, that is, the cache tables are constructed. When the traffic collector exporter starts, it obtains the traffic access relationships within the entire kubernetes (i.e., k8s) cluster (which can contain multiple pods, and these pods can be on one or more hosts) from the cilium ct map once. To reduce the processing of duplicate events and resource occupancy and improve efficiency, only the in - direction, non - icmp related type of flow information can be obtained and stored in the flow cache table. The processing during the above storage can be as follows:
[0077] If it is tcp traffic (such as the first access relationship flow: ip1 tcp ip2), use the five - tuple information of source IP, destination IP, protocol number, destination port, access control, etc. to search the tcp flow cache table. If it does not exist, add it to the tcp flow cache table, and set the flow statistics to 1; if it is found to exist, increase the corresponding flow statistics by 1 and update it to the tcp flow cache table. The format of the Tcp flow cache table can be as follows:
[0078]
[0079] If it is non - tcp traffic (such as the second access relationship flow: ip1 icmp related ip2), use the five - tuple information of source IP, destination IP, protocol number, destination port (if it is icmp traffic, set the destination port to 0), and the access control type of ACCEPT to search the non - tcp flow cache table. If it does not exist, use the five - tuple as the key and the source port of the flow (if it is icmp traffic, use the id in the icmp packet as the source port) as the value to update the non - tcp flow cache table; if the flow exists in the non - tcp flow cache table, add the source port to the value list of the table entry. The format of the non - tcp flow cache table can be as follows:
[0080]
[0081] It should be added that the above non - icmp related type of flow information is the flow information generated by the icmp unreachable corresponding to the access relationship. For example, if ip1 accesses ip2 via tcp, two access relationship flows will be generated, the flows of ip1 tcp ip2 and ip1 icmprelated ip2).
[0082] The above in - direction is for the incoming direction of the pod when creating a connection; when pod1 and pod2 are on the same host and pod1 accesses pod2, an out - direction ct map entry will be created when pod1 sends out, and an in - direction ct map entry will be created when entering pod2. These two entries are duplicate, only with different directions, so they need to be filtered out to avoid information redundancy, which may consume resources or increase costs such as lookup. For non - icmp related, each flow will create a new icmp ct map entry associated with icmprelated, so it can also be filtered out to avoid information redundancy.
[0083] The embodiments of this application can overcome the existing problem that it is difficult to obtain access statistics for short - connections. The inventor found that when a network connection is established, an event will be reported. By listening to the flags in the event (such as the new - connection flag), it can be known whether it is a newly - created connection, or in other words, whether it is a flow in the new - connection state, and then record it; subsequently, when a short - connection accesses, access events will also be reported one by one, so as to obtain the access information and statistics of the short - connection.
[0084] Compared with the tcp traffic, the non - tcp flow cache table has an additional value of the source port: this is to facilitate looking up the ct map to obtain the statistics of each flow when exporting. Because when looking up the ct map for non - tcp flows, more accurate information beyond the five - tuple is required, so the source port needs to be recorded.
[0085] In some specific examples, the specific operation process of "filtering out the target event corresponding to the current data flow in the current reporting period from various events of the current data flow" in step S21 above may include: excluding the events reported by either the receiving side or the sending side of the current data flow in the current reporting period, and the events reported by the reverse flow with the opposite transmission direction to the current data flow; filtering out the new - connection event and discard event of the current data flow from the remaining events obtained by exclusion to form the target event.
[0086] Such as Figure 4As shown, for the current flow, its cilium event can be read and the target event can be filtered out. Specifically, the cilium event can be listened to sense events such as the creation and discard of the flow, the end event of the TCP flow, and the periodic sampling event of the same flow, etc., to avoid the loss of flow events. The flow events contain the five-tuple information of the data flow, the sampling point information, the access control information (allow and discard), and the status information of the current flow (i.e., whether it is newly created). The duplicate information can be filtered out according to the collection point information and the flow status information. The filtering process is as follows: Filter out the events on the non-pod receiving side (equivalent to filtering out the flow information on the non-pod receiving side), and filter out the events reported by the reverse flow; After filtering out these events, what remains are the in-direction trace events (mainly new creation events) and drop events mentioned above. In other words, in order to reduce the processing of duplicate events and improve efficiency, only the in-direction trace events (i.e., the events of the pod receiving side traffic) and all drop events can be retained and processed. This trace event is mainly a new creation event.
[0087] It should be supplemented that the two access pods may be on different hosts. When the pods on different hosts are sent to another host, events will also be reported. In order to reduce the duplicate reporting of events, reduce the recorded duplicate data flows, and avoid the aggregation processing of data, the above can choose to collect only the events on the pod receiving side. Of course, it is also possible to choose to collect only the events on the pod sending side. Further, the flow information of the current flow can be updated to the flow cache table for subsequent statistics of the access times during this period.
[0088] In some specific examples, the specific operation process of the above step S23 may include: calculating the access times during the current reporting period of the current data flow according to the initial access times and the target event information.
[0089] As described above, the event information can record whether the current flow is allowed (accept) or denied (deny) access by the policy. Therefore, as a possible implementation method, it can be designed that the initial access times at the beginning of each reporting period is set to 0. The access times during the current reporting period of the same flow = (the access times allowed during the period + the initial access times allowed 0) + (the access times denied during the period + the initial access times allowed 0) = the number of times the current flow is recorded as accept during the current reporting period + the number of times the current flow is recorded as deny during the current reporting period; In reality, this algorithm often has certain limitations and error rates, that is, this algorithm is not applicable to the access times statistics of all flows, and it should be selected according to the specific situation.
[0090] As another possible implementation, the operation of "calculating the period access times of the current data stream in the current reporting period according to the initial access times and the target event information" may include: determining the access times calculation logic that the current data stream conforms to based on the protocol type and / or access control type of the current data stream in the target event information; the access times calculation logic at least references the initial access times of the current data stream; calculating the period access times of the current data stream in the current reporting period according to the access times calculation logic and the initial access times of the current data stream.
[0091] The above protocol types can be divided into tcp protocol and non-tcp protocols (such as icmp, UDP, etc.). Such a division is because tcp flows account for the majority in the kubernetes (i.e., k8s) cluster. Using tcp traffic for division can increase the efficiency of searching, deleting, and updating; the access control type can be divided into ALLOW (ACCEPT) and DENY (deny).
[0092] Specifically, as Figure 4 shown, the inventor of the present invention found through long-term research and study that tcp traffic is statistically calculated by flow, while most other traffic is calculated by the number of packets for access times. Therefore, in order to specifically enhance the accuracy of data stream (or called traffic) statistics, or to avoid wasting computing power and time by judging each exported stream during subsequent export, the access times calculation logic applicable to the current data stream can be selected through the protocol type and / or access control type of the current data stream, so that the statistical results of the period access times of each stream are true, reliable, and effective:
[0093] (1) For non-tcp accept streams
[0094] In some specific examples, if the current data stream is a data stream that does not use the target protocol and the access control type is ALLOW, and the period access times include the period ALLOW access times, then the process of "calculating the period access times of the current data stream in the current reporting period according to the access times calculation logic and the initial access times of the current data stream" includes: obtaining the total ALLOW access times counted for the current data stream until the end of the current reporting period based on the stream identification information of the current data stream, and setting the initial ALLOW access times corresponding to the current data stream at the start of the current reporting period as the initial access times; subtracting the initial access times of the current data stream from the total ALLOW access times to obtain the period ALLOW access times of the current data stream in the current reporting period; updating the total ALLOW access times to the stream information cache set as the initial access times corresponding to the current data stream at the start of the next reporting period, and returning to the step of subtracting the initial access times of the current data stream from the total ALLOW access times to obtain the period ALLOW access times of the current data stream in the next reporting period.
[0095] In short, when the current flow is not a TCP accept flow, the initial access count is the allowed access count (i.e., the initial access count) counted when this flow arrived in the previous reporting period (i.e., at the start of the current period). It can be designed that the allowed access count during the period of the current flow = the latest count statistic in the ct map after the current reporting period arrives - the statistic when this flow arrived in the previous reporting period.
[0096] As Figure 5 shown, the cilium ct map can be searched according to the five-tuple information (source IP, destination IP, protocol number, and each recorded source port and destination port) of the current flow to obtain the latest statistic of the current flow (i.e., the total allowed access count count2). Subtracting the statistic of the current flow in the previous reporting period (i.e., the initial allowed access count count1) in the flow statistic cache table from this total allowed access count count2 can obtain the allowed access count during the current reporting period (i.e., count2 - count1); then, the calculated allowed access count during the period can be updated to the non-TCP flow statistic cache table for use in the next reporting period calculation. The above latest statistic count2 can be the total of the latest statistics of the two or more recent periods as of the current reporting period.
[0097] It should be added that the statistic (count1) of the current flow in the previous reporting period in the non-TCP flow cache table can be understood as the statistic value read from the cilium ct map when it arrived in the previous reporting period, and it can be pre-updated to the non-TCP flow cache table. The above calculation of the count for the non-TCP accept flow is mainly executed when exporting (i.e., reporting), because calculating when not exporting will consume more CPU resources and increase the time cost. For example, it will increase the number of times of searching the cilium ct map. Of course, it is also feasible to calculate when not exporting, but it requires frequent searching of the cilium ct map, resulting in a large resource overhead.
[0098] (2) For TCP accept flows
[0099] In some specific examples, if the current data flow is a data flow using the target protocol and the access control type is allowed, the access count during the period includes the allowed access count during the period. The process of "calculating the access count during the current reporting period of the current data flow according to the access count calculation logic and the initial access count of the current data flow" includes: setting the initial access count of the current data flow to 0, and accumulating the number of times the current data flow is in the new state during the current reporting period based on the initial access count to obtain the allowed access count during the current reporting period of the current data flow.
[0100] Specifically, when the current flow is a TCP accept flow, the initial allowed access count can be set to 0. Based on 0, each time the current flow is newly created within the current reporting period (i.e., a new creation event occurs), the allowed access count count is incremented by 1. That is, it is not necessary to wait until reporting to count the number of times. In other words, the calculation can be performed according to the current state of the TCP flow (whether it is a newly created state). The update of the TCP flow statistics is as follows: If it is a TCP protocol and a newly created flow, the access count is increased by 1; if it is not a newly created flow, such as an updated traffic or connection-disconnect packet, etc., the access count is not increased.
[0101] (3) For the deny flow
[0102] In some specific examples, if the access control type of the current data flow is deny and the access count during the period includes the deny access count during the period, the process of "calculating the access count during the current reporting period of the current data flow according to the access count calculation logic and the initial access count of the current data flow" includes: setting the initial access count of the current data flow to 0, and based on the initial access count, setting that each time the current data flow is discarded within the current reporting period, the deny access count during the current reporting period of the current data flow is incremented by 1.
[0103] Similarly, when the current flow is a deny flow (it is not necessary to distinguish whether it is a TCP flow), the initial deny access count can be set to 0. Based on 0, each time the current flow is dropped (i.e., a drop event occurs), the deny access count is incremented by 1. In other words, at the start of each reporting period, the initial deny access count of the deny flow starts from zero and incrementally counts as appropriate. It can be regarded as being cleared and recounted for each cycle, and the drop count is synchronously accumulated at that time and can be directly reported to the collector later.
[0104] As described above, the TCP flow performs calculations according to the current state of the TCP flow after detecting an event, so there is no need to calculate again during reporting. The same is true for drop statistics. Usually, a drop event is reported for each discarded packet. After the collector receives it, it needs to update it to the flow cache table (in the TCP flow cache table or non-TCP flow cache table). After reaching the reporting period, it is directly reported without the need to obtain the access count of non-TCP (accept) flows sent during the current reporting period by subtracting the initial statistics in the reporting period from the latest statistics in the ctmap like non-UDP accept flows. Briefly described:
[0105] For the drop flow, every time a packet is dropped, a drop event is reported, and the number of packets discarded in total during the reporting period is reported. Therefore, the dropped packets will be cached during the reporting period, and each time a drop event is received, the relevant drop flow statistics will increase by 1; when exporting, the drop flow information and statistics will be directly exported.
[0106] For the tcp accept flow, after receiving the new connection event of a flow, the flow information will be updated to the tcp flow cache table and the statistics will increase by 1; after subsequent reporting of the same flow event, the statistics will not increase anymore. Therefore, when exporting, the flow information and statistics will be directly exported.
[0107] For non-tcp accept flows, the statistics of the flows during the reporting period are exported. When exporting, it is necessary to query the ciliumctmap to obtain the latest statistics value of the current flow minus the initial value at the start of the reporting period, so as to obtain the statistics during the reporting period.
[0108] In some specific examples, after the above step S23 (that is, obtaining the number of accesses during the period of multiple current flows), the information statistics method of the embodiments of the present application may further include (encapsulating and reporting flow information): when the end time of the current reporting period arrives or after that, aggregate the number of accesses during the period of each of the multiple current data flows in a group of messages for reporting; the flow identification information between the multiple current data flows is not completely the same.
[0109] In other words, when exporting traffic, the flow information in the flow cache table can be encapsulated into an ipfix message in the form of multiple flows, that is, an ipfix message contains multiple data sets (dataset), and each dataset corresponds to one flow information (source and destination IP, protocol number, destination port number, access control information, number of accesses during the current period), so as to reduce the number of traffic transmissions and the occupied bandwidth, as shown in the following table.
[0110]
[0111] In the above table, based on IP1, IP2, PROTO1, ACCEPT, DROP is an aggregated flow, which contains three sub-flows Flow:
[0112] Flow1: The statistics corresponding to IP1, IP2, PROTO1, ACCEPT, DROP, SPORT1 are num1;
[0113] FLOW2: The statistics corresponding to IP1, IP2, PROTO1, ACCEPT, DROP, SPORT2 are num2;
[0114] FLOW3: The statistics corresponding to IP1, IP2, PROTO1, ACCEPT, DROP, and SPORT3 are num3;
[0115] For another example, in the non - TCP flow cache table as shown below, the entry information of multiple non - TCP flows (source IP, destination IP, protocol number, destination port, access control information in the event) and the access times can be encapsulated into an IPFIX data set and sent to the collector as an IPFIX message to complete the reporting of flow information.
[0116]
[0117] In some specific examples, if it is selected to record the flow information of each current data flow in the flow information cache set, and the flow information includes the flow identification information and / or the access times during a period of the current data flow, then after the above - mentioned step S23 (that is, obtaining the access times during a period of multiple current flows), the information statistics method of the embodiment of the present application may further include (deleting invalid information in the flow information cache set): after the flow information of at least one current data flow is reported, obtain the time difference between the latest update time and the reporting time of each access time during a period; delete the flow information of the current data flow in the flow information cache set whose time difference exceeds a preset time period.
[0118] After the flow information is reported, the non - TCP flow statistical cache table can be scanned to find the time difference between the update time of each entry and the current reporting time. If the update time exceeds the preset time period, it can be considered that this flow (that is, the flow pointed to by the five - tuple such as source IP, destination IP, protocol number, source port, destination port, etc.) has no access, and its flow information can be deleted to avoid data redundancy and time - consuming lookups. In other words, the scan and deletion are performed because there may be a flow whose valid time spans multiple reporting cycles. For example, a flow lasts for 10 minutes. If it is reported once every 1 minute, without scan and deletion, all access statistics of this flow from the start to the current moment will be reported each time, instead of reporting the access times during the current 1 - minute period (that is, within the current reporting cycle).
[0119] In summary, as Figure 4 shown, the embodiment of the present application can parse the events of the current flow to obtain key information such as flow identification information (that is, five - tuple information), extract the initial access times of the current flow from the flow information cache set through the five - tuple information; calculate the access times during a period of the current flow according to the access - time calculation logic pointed to by the protocol type and / or access - control type of the current flow, and uniformly encapsulate and report the calculated access times during a period of multiple flows to the collector; and implement the deletion of timeout flow information.
[0120] Specifically, it can parse the flow information in the event, obtain the source IP, destination IP, protocol, and port information, and search the flow cache table based on the source IP, destination IP, protocol number, destination port (if it is a non-TCP and non-UDP packet, set the destination port to 0), and the access control information in the event. Among them, the classification of whether it is UDP is introduced to parse the destination port. Since non-TCP and non-UDP packets do not have a destination port number, the destination port number can be set to 0 and uniformly classified as non-TCP flow processing.
[0121] a. If the access control of the event is deny (i.e., the flow of the drop event), search the corresponding flow cache table based on the five-tuple. For each received drop event, the access count of this flow is incremented and updated to the corresponding flow cache table.
[0122] b. If the access control is ACCEPT and it is TCP traffic, search the TCP flow cache table based on the five-tuple. If the TCP flow cache table does not exist, add an entry for this flow to the cache table. If the status of this event is new, the status of the corresponding flow is also new, then the flow statistics can be set to 1, otherwise set to 0. If the five-tuple information of this flow exists in the TCP flow cache table, check the status of this flow. If it is new, increment the found flow statistics by 1, otherwise do not increment. After modifying the statistics, update it to the TCP flow cache table entry.
[0123] c. If the access control is ACCEPT and it is non-TCP flow (i.e., non-TCP accept flow), search the non-TCP flow cache table based on the five-tuple to record the source port number of the flow (since the ICMP flow does not have the concept of a source port number, use the id as the source port). At this time, the access count of non-TCP traffic can be not calculated (because there will be sampling events when receiving, and there will be many events for one flow. The access count of this flow can be calculated when exporting to reduce the number of lookups in the cilium ctmap).
[0124] Since the access counts of TCP flows and drop flows can be calculated when received, they can be directly reported when exporting. When exporting, only the access counts of non-TCP flows (such as ICMP flows, UDP flows, etc., flows that do not use the TCP protocol) need to be calculated.
[0125] Specifically, during the traffic export phase, the flow information in the TCP flow cache table can be retrieved first. For example, multiple pieces of flow information (source IP, destination IP, protocol number, destination port, access control information in the event) and the access count and other flow information can be retrieved and encapsulated as an ipfix dataset into an ipfix packet and sent to the collector to reduce the reported traffic.
[0126] After that, the flow information in the non-TCP flow cache table can be retrieved to calculate the aggregated access times. Since the ACCEPT event only records the details of the access traffic without calculation and statistics, it is necessary to aggregate the access times of multiple flows based on the destination port (such as calculating Sum = num1 + num2 + num3). The calculation method is as follows: traverse the source port numbers recorded in the accept event and form a five-tuple (source IP, destination IP, protocol, destination port number, source port number) together with the aggregated flow quadruple (source IP, destination IP, protocol, destination port number); 1) Search the non-TCP flow statistics cache table based on the five-tuple to obtain the initial statistical value count1 at the start of the current sampling period. If the search fails, it means that the current flow did not exist at the start of this sampling period and is new traffic that emerged after the start of the current sampling period, and it is initialized to 0; 2) Search the cilium ct map based on the five-tuple to obtain the access times count2 of this flow in the cilium ct entry. If the search fails, the access times is 0, indicating that the flow information has aged, but the flow information still needs to be reported; 3) The statistics obtained in the second step can be updated to the non-TCP flow statistics cache table for use in the next cycle's calculation or data backup; 4) Subtract the statistics obtained in the first step from the statistics obtained in the second step (count2 - count1) to get the access times of the non-aggregated flow in the current cycle (one packet of a non-TCP flow represents one access).
[0127] It can be seen that the embodiments of the present application: 1. Can accurately provide the service access relationship within the cluster and solve the problem of inaccurate statistics obtained directly through the cilium ct map;
[0128] 2. Can obtain the five-tuple information of network traffic discarded or allowed by network policies and its access statistics and other flow information;
[0129] 3. When the collector reports flow information, it can not report the metadata of the service (the name of the service, the namespace where the service is located), thereby reducing the amount of data reported.
[0130] 4. Can perform aggregation processing on the reported flow information based on the five-tuple (source IP, destination IP, protocol number, destination port number, access control information), such as encapsulating it into an ipfix packet to reduce the reported traffic
[0131] 5. Use the form of multiple datasets in one ipfix packet to reduce the number of reported packets and the data occupied space.
[0132] Please refer to Figure 6 , a specific embodiment of an information statistics device provided in the second aspect of the present application, the information statistics device includes: an acquisition unit, a processing unit;
[0133] The acquisition unit is used to filter out the target event corresponding to the current data stream in the current reporting period from various events of the current data stream, and parse the stream identification information of the current data stream from the target event information;
[0134] The processing unit is used to obtain the initial access count corresponding to the current data stream at the start of the current reporting period from the stream information cache set based on the stream identification information of the current data stream;
[0135] The processing unit is also used to calculate the period access count of the current data stream in the current reporting period according to the initial access count.
[0136] In some examples, the processing unit is specifically used for:
[0137] Calculate the period access count of the current data stream in the current reporting period according to the initial access count and the target event information.
[0138] In some examples, the processing unit is specifically used for:
[0139] Based on the protocol type and / or access control type of the current data stream in the target event information, determine the access count calculation logic that the current data stream conforms to; the access count calculation logic at least references the initial access count of the current data stream;
[0140] Calculate the period access count of the current data stream in the current reporting period according to the access count calculation logic and the initial access count of the current data stream.
[0141] In some examples, if the current data stream is a data stream that does not use the target protocol and the access control type is allowed, and the period access count includes the period allowed access count, the processing unit is specifically used for:
[0142] Obtain the total allowed access count counted for the current data stream as of the end of the current reporting period based on the stream identification information of the current data stream, and set the initial allowed access count corresponding to the current data stream at the start of the current reporting period to the initial access count;
[0143] Subtract the initial access count of the current data stream from the total allowed access count to obtain the period allowed access count of the current data stream in the current reporting period;
[0144] Update the total allowed access count to the stream information cache set to be used as the initial access count corresponding to the current data stream at the start of the next reporting period, and return to the step of subtracting the initial access count of the current data stream from the total allowed access count to obtain the period allowed access count of the current data stream in the next reporting period.
[0145] In some examples, if the current data stream uses the target protocol and the access control type is allowed, and the access times during a period include the allowed access times during the period, the processing unit is specifically configured to:
[0146] Set the initial access times of the current data stream to 0, and based on the initial access times, accumulate the number of times the current data stream is in the new state during the current reporting period to obtain the allowed access times during the current reporting period of the current data stream.
[0147] In some examples, if the access control type of the current data stream is denied, and the access times during a period include the denied access times during the period, the processing unit is specifically configured to:
[0148] Set the initial access times of the current data stream to 0, and based on the initial access times, set that each time the current data stream is discarded during the current reporting period, the denied access times during the current reporting period of the current data stream increases by one.
[0149] In some examples, the obtaining unit is specifically configured to:
[0150] Exclude the events reported by either the receiving side or the sending side of the current data stream during the current reporting period, and the events reported by the reverse flow with the transmission direction opposite to that of the current data stream;
[0151] Filter out the new events and discard events of the current data stream from the remaining events obtained by exclusion to form target events.
[0152] In some examples, after obtaining the access times during a period, the obtaining unit is further configured to:
[0153] When the end time of the current reporting period arrives or after that, aggregate the access times during the period of multiple current data streams in a group of messages for reporting; the flow identification information between multiple current data streams is not completely the same.
[0154] In some examples, if it is selected to record the flow information of each current data stream in the flow information cache set, and the flow information includes the flow identification information and / or the access times during a period of the current data stream, after obtaining the access times during a period, the obtaining unit is further configured to:
[0155] After the flow information reporting of at least one current data stream is completed, obtain the time difference between the latest update time and the reporting time of each access time during a period;
[0156] Delete the flow information of the current data stream in the flow information cache set whose time difference exceeds the preset time period.
[0157] In the embodiments of the present application, the operations performed by each unit of the information statistics device are similar to those described in the foregoing first aspect or any specific method embodiment of the first aspect, and will not be elaborated herein. Of course, the specific implementation process of each operation in the first aspect of the present application can also be implemented with reference to the relevant descriptions in the second aspect.
[0158] Please refer to Figure 7 , the electronic device in the embodiments of the present application may include one or more processors (such as a central processing unit CPU, central processing units) and a memory, and one or more application programs or data are stored in the memory.
[0159] Among them, the memory may be volatile storage or persistent storage. The program stored in the memory may include one or more modules, and each module may include a series of instruction operations on the electronic device. Further, the processor may be configured to communicate with the memory and execute a series of instruction operations in the memory on the electronic device.
[0160] The electronic device may further include one or more power supplies, one or more wired or wireless network interfaces, one or more input / output interfaces, and / or one or more operating systems, such as Windows Server, Mac OS X, Unix, Linux, FreeBSD, etc.
[0161] The processor may perform the operations performed in the foregoing first aspect or any specific method embodiment of the first aspect, and will not be elaborated herein.
[0162] A computer-readable storage medium provided by the present application includes instructions, and when the instructions run on a computer, the computer is caused to execute the method described in the foregoing first aspect or any specific implementation manner of the first aspect.
[0163] A computer program product provided by the present application includes instructions or a computer program, and when the computer program product runs on a computer, the computer is caused to execute the method described in the foregoing first aspect or any specific implementation manner of the first aspect.
[0164] It can be understood that in various embodiments of the present application, the sequence numbers of the steps do not mean the order of execution. The execution order of each step should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application. The operation content added or refined in each example solution of the foregoing method, system or device (if any) does not necessarily have to be executed during specific implementation. If two or more operations are added, these operations can be combined or implemented separately, depending on the actual scenario.
[0165] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems (if any) and devices described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0166] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system or device, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical or other forms.
[0167] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0168] In addition, in each embodiment of the present application, the functional units can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0169] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product (or computer program product) is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a business server or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks or optical discs that can store program codes.
Claims
1. An information statistics method, characterized in that: include: Filtering out target events corresponding to the current data flow in the current reporting period from various events of the current data flow, and parsing flow identification information of the current data flow from the target event information; Based on the flow identification information of the current data flow, acquiring the initial access count corresponding to the current data flow at the beginning of the current reporting cycle from the flow information cache set; The number of accesses to the current data flow during the current reporting period is calculated according to the initial number of accesses.
2. The information statistics method according to claim 1, characterized in that: The calculating the number of accesses to the current data flow during the current reporting period according to the initial number of accesses includes: The number of accesses to the current data stream during the current reporting period is calculated according to the initial number of accesses and the target event information.
3. The information statistics method according to claim 2, characterized in that: The calculating the number of accesses to the current data stream during the current reporting period according to the initial number of accesses and the target event information includes: Based on the protocol type and / or access control type of the current data flow in the target event information, determining the access count calculation logic corresponding to the current data flow; the access count calculation logic at least references the initial access count of the current data flow; The number of accesses of the current data flow during the current reporting period is calculated according to the access number calculation logic and the initial access number of the current data flow.
4. The information statistics method according to claim 3, characterized in that: If the current data flow is a data flow that does not use the target protocol and whose access control type is allowed, the period access count includes the period allowed access count, and the process of calculating the period access count of the current data flow within the current reporting period according to the access count calculation logic and the initial access count of the current data flow includes: Based on the flow identification information of the current data flow, obtaining the total number of allowed accesses of the current data flow counted at the end of the current reporting period, and setting the initial allowed access number corresponding to the current data flow at the beginning of the current reporting period as the initial access number; Subtract the initial access count of the current data flow from the total allowed access count to obtain the allowed access count of the current data flow during the current reporting period; The total number of allowed accesses is updated to the flow information cache set as the initial number of accesses corresponding to the current data flow at the beginning of the next reporting cycle, so as to return to the step of subtracting the initial number of accesses of the current data flow from the total number of allowed accesses to obtain the number of allowed accesses of the current data flow during the next reporting cycle.
5. The information statistics method according to claim 3, characterized in that: If the current data flow is a data flow using a target protocol and the access control type is allowed, the period access count includes the period allowed access count, and the process of calculating the period access count of the current data flow within the current reporting period according to the access count calculation logic and the initial access count of the current data flow includes: The initial access count of the current data flow is set to 0, and based on the initial access count, the number of times the current data flow is in a newly created state within the current reporting period is accumulated to obtain the number of access times allowed for the current data flow within the current reporting period.
6. The information statistics method according to claim 3, characterized in that: If the access control type of the current data flow is rejection, the period access count includes the period access rejection count, and the process of calculating the period access count of the current data flow within the current reporting period according to the access count calculation logic and the initial access count of the current data flow includes: The initial access count of the current data flow is set to 0, and based on the initial access count, each time the current data flow is discarded within the current reporting period, the number of access denials for the current data flow within the current reporting period increases by one.
7. The information statistics method according to claim 1, characterized in that: The filtering out target events corresponding to the current data flow in the current reporting period from various events of the current data flow includes: Excluding events reported by either the receiving side or the sending side of the current data flow within the current reporting period, and events reported by a reverse flow opposite to the transmission direction of the current data flow; The newly created events and discarded events of the current data stream are filtered out from the remaining events obtained by exclusion to form the target event.
8. The information statistics method according to any one of claims 1 to 7, characterized in that: After obtaining the number of visits during the period, the information statistics method further includes: When or after the end time of the current reporting period arrives, the number of access times of each of the multiple current data flows during the period is aggregated into a group of messages for reporting; the flow identification information between the multiple current data flows is not completely the same.
9. The information statistics method according to any one of claims 1 to 7, characterized in that: If it is selected to record the flow information of each current data flow in the flow information cache set, the flow information includes the flow identification information of the current data flow and / or the number of accesses during the period, after obtaining the number of accesses during the period, the information statistics method further includes: After the flow information of at least one of the current data flows is reported, obtaining the time difference between the latest update time of the number of accesses during each period and the reporting time; The flow information of the current data flow whose time difference exceeds a preset period of time in the flow information cache set is deleted.
10. An information statistics device, characterized in that: include: Acquisition unit, processing unit; The acquisition unit is used to filter out the target event corresponding to the current data flow in the current reporting period from various events of the current data flow, and parse the flow identification information of the current data flow from the target event information; The processing unit is used to obtain, based on the flow identification information of the current data flow, the initial access count corresponding to the current data flow at the beginning of the current reporting cycle from the flow information cache set; The processing unit is further configured to calculate the number of accesses to the current data flow during the current reporting period according to the initial number of accesses.
11. An electronic device, characterized in that: include: Processor and memory; The processor is configured to communicate with the memory and execute instructions in the memory to implement the method according to any one of claims 1 to 9.
12. A readable storage medium, characterized in that: The readable storage medium stores computer instructions, and when the computer instructions are executed by a processor, the method according to any one of claims 1 to 9 is implemented.
13. A computer program product, characterized in that The computer program product comprises computer instructions, which implement the method according to any one of claims 1 to 9 when executed by a processor.