Data plane multi-tenant abnormal traffic detection method and system
By introducing tenant mapping tables and multi-tenant decision tree modules into the data plane of the cloud data center, using path coding and parameter storage and search methods, the problems of inability to detect 0day attack traffic, poor real-time processing performance and not supporting multi-tenant policy isolation in the existing technology are solved, and real-time abnormal traffic detection and cleaning of multi-tenant is realized.
Patent Information
- Application Number
- CN202510336011.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-06-24
AI Technical Summary
The existing technology cannot effectively detect 0day attack traffic, and the real-time processing performance is poor, and it does not support the isolation of the abnormal traffic cleaning strategy of multi-tenant.
By introducing tenant mapping tables and multi-tenant decision tree modules into the data plane, using path coding and parameter storage and search methods, real-time abnormal traffic detection and cleaning of multi-tenant is realized.
Real-time abnormal traffic detection and cleaning of multi-tenants in cloud data centers is realized, and tenants can customize abnormal traffic filtering strategies, and avoid the problem of unbalanced resource utilization.
Smart Images

Figure CN120200798A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of abnormal traffic monitoring in cloud data centers, and particularly to a method and system for detecting abnormal traffic of multi-tenants in a data plane. Background Art
[0002] A cloud data center is a new type of data center based on a cloud computing architecture and highly virtualized, including a computer system and supporting communication, storage, and security devices. Compared with traditional data centers, it has great advantages in terms of resource utilization rate, resource management granularity, and scalability. By virtualizing computing and storage resources, cloud service providers can provide services for a large number of tenants on unified hardware resources. Currently, cloud data centers have become the core assets in the Internet.
[0003] However, the destruction of cloud data center hosts and a successful attack on the cloud network will directly affect multiple cloud services at the same time, causing significant economic losses. Due to the huge value of the services carried by cloud data centers, malicious behaviors of attackers against cloud services have become frequent, complex, and dynamic in recent years, and there is a continuous need to detect malicious or abnormal traffic.
[0004] Traditional rule- and signature-based traffic detection schemes filter malicious traffic by pre-distributing matching rules. This scheme usually requires maintaining a malicious traffic rule library for generating malicious traffic matching rules. For malicious traffic already in the knowledge base, the rule-based scheme can achieve a high classification accuracy at a high processing rate and is easy to deploy in network devices with large bandwidths. However, the rule-based method requires a large amount of cumbersome knowledge base and rule maintenance, and the deployed rules can only filter malicious traffic already in the knowledge base and do not have the generalization ability to identify 0day attack traffic.
[0005] Abnormal traffic detection technology based on machine learning does not require cumbersome manual rule generation and matching and can achieve a high detection accuracy. At the same time, deep learning models have a certain generalization ability and can effectively identify 0day attack traffic. However, the prediction process of machine learning models, especially deep learning models, is computationally complex and has a high overhead, making it difficult to perform real-time analysis and processing on high-speed forwarded traffic. Therefore, even with high accuracy and good generalization ability, they can only be deployed offline.
[0006] In recent years, with the development of programmable switches and smart network cards, in-network computing has provided a new solution for the online deployment of machine learning models. Compared with the bypass node deployment scheme, in-network computing abandons the complex traffic traction and traffic injection mechanisms, saves the transmission delay from the switch to the traffic cleaning center, and better guarantees the real-time performance of data packets. Deploying a machine learning model inside a network element node with line rate forwarding not only realizes the real-time performance of traffic detection but also ensures the detection ability for 0-day attack traffic. Therefore, it has received extensive attention in recent years.
[0007] The in-network decision tree on the data plane can achieve line rate data packet processing, thus realizing high-speed abnormal traffic cleaning. And since the decision tree generation only requires a labeled data set, it avoids the cumbersome rule configuration and rule maintenance. Moreover, due to the generalization ability of the machine learning model, it has a certain ability to detect 0-day attack traffic.
[0008] Existing in-network decision tree-based abnormal traffic detection modules are all based on global models. The so-called global model is to use a single classifier to realize the prediction of all data labels. The global model does not support the isolation of multi-tenant traffic filtering rules and flexible customization. Therefore, it is not suitable for network traffic detection in cloud data centers.
[0009] Inside a cloud data center such as a public cloud, the traffic data passing through the cloud gateway is often large, reaching the Tb level. The deployed traffic cleaning model must meet the following requirements: 1. To ensure that the model has the ability to detect 0-day attack traffic and avoid cumbersome rule configuration and rule maintenance, a data-driven method rather than a method based on manual filtering rules is required; 2. To achieve real-time abnormal traffic cleaning and prevent the abnormal traffic cleaning model from having too much impact on normal services, the model needs to have high throughput; 3. To realize the tenant-customized abnormal traffic filtering strategy in the cloud data center, a malicious traffic defense strategy isolation mechanism between different tenants needs to be designed.
[0010] In summary, the rule-based abnormal traffic detection model has the problem of difficult rule maintenance and does not have generalization ability, so it cannot detect 0-day attack traffic; the traffic detection model based on deep learning has poor real-time processing performance; the existing in-network machine learning models do not support the isolation of multi-tenant abnormal traffic cleaning strategies. Summary of the Invention
[0011] In order to at least partially solve the problems in the prior art that 0-day attack traffic cannot be detected, the real-time processing performance is poor, and multi-tenant abnormal traffic cleaning policy isolation is not supported, the present invention provides a data plane multi-tenant abnormal traffic detection method and system. The present invention proposes a tenant mapping table for realizing the mapping between tenant IDs and decision tree IDs. By looking up the tenant mapping table, the decision tree ID for subsequent processes to perform traffic filtering is determined. Secondly, the present invention proposes a method for parameter storage and lookup based on table entries, and uses path encoding as the node encoding of the decision tree. Through multi-tenant decision tree parameter storage and in-network computing, real-time abnormal traffic detection supporting multi-tenants in the cloud data center is realized. The present invention mainly solves the problem of conflict of abnormal traffic filtering policies among multiple tenants in the real-time abnormal traffic cleaning device based on machine learning in the cloud data center. On the premise of maintaining the 0-day attack traffic detection ability and real-time processing ability, the customization and isolation of multi-tenant defense strategies are realized.
[0012] In order to achieve the above object, the technical solution of the present invention is:
[0013] The first aspect of the present invention proposes a data plane multi-tenant abnormal traffic detection method, including:
[0014] Step 1: Extract the packet header fields and features of the packet to obtain the tenant ID corresponding to the packet and the packet feature vector, which is convenient for matching the decision tree;
[0015] Step 2: Use the preset tenant mapping table to match the tenant ID of the packet to obtain the decision tree ID corresponding to the packet, which is convenient for corresponding the decision tree to the packet to be filtered;
[0016] Step 3: Input the decision tree ID into the preset data plane multi-tenant decision tree module to complete the abnormal detection of the tenant traffic packet.
[0017] Further, the tenant mapping table is a mapping table between tenant IDs and preset decision tree IDs; the tenant mapping table includes tenant IDs and decision tree IDs.
[0018] Further, the data plane multi-tenant decision tree module includes a calculation flow split table, a first process and a second process, which is convenient for executing multiple processes at one time to detect multiple tenant traffic packets;
[0019] The calculation flow split table is used to sequentially match the decision tree ID and the calculation flow ID, and sequentially place the decision tree corresponding to the decision tree ID on the process corresponding to the calculation flow ID; wherein, each calculation flow ID corresponds to a process.
[0020] Further, both the first process and the second process include at least one data plane decision tree. The data plane decision tree includes a plurality of parameter query modules and a plurality of logical judgment modules, and the parameter query modules and the logical judgment modules are alternately connected;
[0021] The second process is delayed by one stage compared with the first process. The first parameter query module in the second process corresponds to the first logical judgment module in the first process, so that the first parameter query module in the second process and the first logical judgment module in the first process are in the same stage, making the resource occupation of each stage balanced.
[0022] Further, the parameter query module is used to query the data in the preset node parameter entry. The node parameter entry includes the action name, the preset feature ID, and the preset feature threshold; wherein, the feature ID corresponds to the feature value index in the data packet feature vector, and the feature threshold corresponds to the feature value in the data packet feature vector.
[0023] Further, the path from the root node to the internal node or the leaf node in the decision tree is encoded, and the path encoding is used as the node ID.
[0024] Further, the logical judgment module specifically includes:
[0025] Step 1: Shift the node ID to the left by 1 bit, leaving the lowest bit of the node ID vacant to facilitate storing the judgment result of the current-level decision tree node;
[0026] Step 2: Index the feature value corresponding to the feature ID from the data packet feature vector, and compare the feature value with the feature threshold. If the feature value is greater than the feature threshold, execute Step 3; otherwise, continue to execute the parameter query and logical judgment modules in the next stage of the decision tree;
[0027] Step 3: Let the node ID = node ID + 1, and use the lowest bit of the node ID to store the judgment result of the current-level decision tree node.
[0028] Further, both the tenant mapping table and the data plane multi-tenant decision tree module are set in the data plane;
[0029] A decision tree management module is also set in the control plane. The decision tree management module is used to update and modify the data in the tenant mapping table and the data plane multi-tenant decision tree module.
[0030] A second aspect of the present invention proposes a data plane multi-tenant abnormal traffic detection system, including:
[0031] A preprocessing module, configured to extract the data packet header fields and features from the data packet to obtain the tenant ID corresponding to the data packet and the data packet feature vector;
[0032] A tree matching module, which is used to match the tenant ID of a data packet by using a preset tenant mapping table to obtain the decision tree ID corresponding to the data packet;
[0033] A parameter matching module, which is used to input the decision tree ID into a preset data plane multi-tenant decision tree module to complete the anomaly detection of tenant traffic data packets.
[0034] Advantages of the present invention:
[0035] (1) The present invention realizes the query of model node parameters of tenants by a multi-tenant decision tree according to the decision tree ID (dtid) and the node ID (nodeid). The node ID is organized in a path encoding manner, so as to set different nodeid lengths at different decision tree depths to save the SRAM resources of the switch.
[0036] (2) The present invention stores the feature ID and feature threshold corresponding to each internal node of the decision tree in the node parameter entry. When a sample point reaches a certain node of the decision tree, the corresponding parameters are obtained through an action (get_feature), and by splitting the entry corresponding to the node at a deeper level of the decision tree, it is possible to prevent the occupancy of stage forwarding resources corresponding to the deeper level of the decision tree from exceeding the limit. The present invention can be deployed in a P4 switch. During the process of equalizing the occupancy of decision tree resources, the present invention stores the query of node parameters of different tenants misaligned at different stages of the P4 switch, so as to realize the balanced utilization of switch resources at different stages to support the deployment of more decision trees.
[0037] (3) The present invention can support the flexible customization of traffic filtering policies by multi-tenants in a cloud data center, is applicable to the cloud data center scenario, and supports the customization and isolation of multi-tenant defense policies. Description of the drawings
[0038] Figure 1 It is one of the flowcharts of a data plane multi-tenant abnormal traffic detection method provided by an embodiment of the present invention.
[0039] Figure 2 It is a schematic diagram of a data plane multi-tenant abnormal traffic detection method provided by an embodiment of the present invention.
[0040] Figure 3 It is the second flowchart of a data plane multi-tenant abnormal traffic detection method provided by an embodiment of the present invention.
[0041] Figure 4 It is a schematic diagram of an entry distribution equalization scheme provided by an embodiment of the present invention.
[0042] Figure 5Schematic diagram of the architecture design of the data plane decision tree provided by the embodiment of the present invention.
[0043] Figure 6 Schematic diagram of the relationship between the parameter query module and the logic decision module of the decision tree at the same level provided by the embodiment of the present invention.
[0044] Figure 7 Schematic diagram of the decision tree path encoding scheme provided by the embodiment of the present invention.
[0045] Figure 8 Schematic diagram of the tenant mapping table provided by the embodiment of the present invention.
[0046] Figure 9 Schematic diagram of the decision tree node parameter query provided by the embodiment of the present invention.
[0047] Figure 10 Schematic diagram of the decision tree logic decision module provided by the embodiment of the present invention.
[0048] Figure 11 Architecture diagram of a data plane multi-tenant abnormal traffic detection system provided by the embodiment of the present invention. Detailed implementation manners
[0049] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0050] Embodiment 1
[0051] As Figure 1 、 Figure 2 and Figure 3 shown, a data plane multi-tenant abnormal traffic detection method includes:
[0052] S101: Extract the header fields and features of the data packet to obtain the tenant ID corresponding to the data packet and the data packet feature vector.
[0053] Specifically, input multiple tenant traffic data packets into a programmable switch for preprocessing.
[0054] S102: Use the preset tenant mapping table to match the tenant ID of the data packet to obtain the decision tree ID corresponding to the data packet.
[0055] Specifically, the tenant mapping table is a mapping table between the tenant IDs in the cloud data center and the decision tree IDs of the data plane multi-tenant decision tree. By setting up the tenant mapping table, it is possible to decouple the processes of adding and deleting tenants in the cloud data center from the management of the data plane decision tree, thus simplifying the management and maintenance of the data plane decision tree.
[0056] Packets arriving at the programmable data plane first need to match the tenant mapping table. Its matching field contains a variable, which is the tenant ID. The tenant mapping table parameter contains a variable, which is the decision tree ID.
[0057] S103: Input the decision tree ID into a preset data plane multi-tenant decision tree module to complete the anomaly detection of tenant traffic packets.
[0058] Specifically, the data plane multi-tenant decision tree module includes a computing flow splitting table, a first process, and a second process.
[0059] The computing flow splitting table is used to sequentially match the decision tree ID and the computing flow ID, and sequentially place the decision tree corresponding to the decision tree ID on the process corresponding to the computing flow ID; among them, each computing flow ID corresponds to a process.
[0060] Specifically, as Figure 4 shown, both the first process and the second process include data plane decision trees, and the data plane decision trees are alternately composed of a parameter query module and a logic decision module in stages. The parameter query module is used to query the data in the preset node parameter entry. The node parameter entry includes the action name, a preset feature ID, and a preset feature threshold. Among them, the feature ID corresponds to the eigenvalue index in the packet feature vector, and the feature threshold corresponds to the eigenvalue in the packet feature vector.
[0061] However, since the logic decision module occupies much more static random access memory (SRAM) resources than the parameter query module, it leads to extremely unbalanced resource consumption in different stages of the pipeline. In the case of extremely unbalanced resource consumption, when the maximum number of decision trees supported for deployment is reached, the resource utilization rate of the stage where the parameter query module is located is relatively high, while the resource utilization rate of the logic decision stage is relatively low. This results in a waste of resources and a low overall resource utilization rate of the switch. This limits the number of decision trees that the switch can support for deployment.
[0062] The present invention proposes a set of table entry balancing mechanisms. That is, place different tenant decision trees into different computing processes, respectively denoted as the first process (process 1) and the second process (process 2), as Figure 4As shown. Process 1 and Process 2 have the same structure, but Process 2 is shifted one stage later than Process 1, so that the parameter query modules and logic decision modules of the two processes are misaligned, making the resource occupation of each stage balanced. The matching domain of the calculation flow split table includes only one variable, the decision tree ID, and the parameters include the calculation flow ID, namely Calculation Flow 1 and Calculation Flow 2.
[0063] Specifically, in order to provide flexible policy formulation for multi-tenants, the present invention designs a framework for a data plane multi-tenant decision tree. Figure 5 Shows the overall architecture of the multi-tenant decision tree. The calculation process of the multi-tenant decision tree is to alternately perform parameter query and logic decision, as Figure 6 shown. In order to support the runtime generation, update and deletion of the model and reduce the node management complexity. It is designed from four aspects.
[0064] Path encoding: Compared with numbering each node in the decision tree, the present invention adopts the path encoding method. By using the path of the sample from the root node to the internal node or leaf node in the decision tree to encode the internal nodes. Using path encoding, the data plane can calculate the next node ID through the left shift operator and addition operation without looking up the table entries, thus effectively saving the relatively scarce table entry resources. Using path encoding as the node encoding, that is, the node encoding lengths of the same depth are the same, that is, the node encoding length of level i is i. Therefore, in the multi-tenant solution, the number of bits occupied by the node ID field of the table entry can be set, and by reducing the matching field length of the low-level matching action table, the occupancy of the switch forwarding resources (SRAM) is reduced. The path encoding is shown as Figure 7 shown.
[0065] Feature access: The present invention stores the feature ID and feature threshold corresponding to each internal node of the decision tree in the table entry. When a sample point reaches a certain node of the data plane decision tree, the feature ID and feature threshold obtained through the get_feature (obtain feature) action are used to extract the corresponding feature from the packet header vector (PHV) for judgment and comparison. For leaf nodes, the result of the leaf node is obtained through get_label (obtain label).
[0066] Tenant design: By adding a variable dtid of the decision tree ID to the node parameter table entry, different decision trees in the same programmable switch are distinguished by dtid. At the same time, a mapping from different tenants to different decision trees is set in front of the data plane decision tree. By adding dtid, multiple different decision trees can be stored in the same node parameter table entry. That is, the flow tables corresponding to the decision tree nodes of the same depth are located in the same node parameter table entry.
[0067] Pipeline folding: According to the pipeline architecture of the P4 switch, the present invention adopts the technology of pipeline folding. By means of the data packet loopback scheme, the number of stages is increased, thereby increasing the maximum depth of the deployed multi-tenant decision tree and preventing the problem that it is difficult to deploy the decision tree model due to insufficient number of stages in the P4 switch.
[0068] Specifically, according to the decision tree ID and the node ID, query the parameters in the node parameter entry. Among them, the node parameter entry includes three parts: the action name, the feature ID, and the feature threshold. Among them, the feature ID corresponds to the feature value index in the data packet feature vector, and the feature threshold corresponds to the feature value in the data packet feature vector.
[0069] After completing the parameter query, execute the logical judgment module. The so-called logical judgment module includes three steps:
[0070] 1. Shift the nodeid (node ID) left by 1 bit, that is, leave the lowest bit of the nodeid free to store the judgment result of the current-level decision tree node, and the default value filled in the lowest bit is 0.
[0071] 2. Index the feature value fv corresponding to the feature ID from the feature vector of the tenant traffic data packet, and compare fv with the feature threshold Fthres. If fv > Fthres, jump to step 3; otherwise, perform the parameter query module and the logical judgment module of the next level of the decision tree, that is, jump out of the logical judgment module of the current level.
[0072] 3. Let nodeid = nodeid + 1, that is, use the lowest bit of nodeid to store the judgment result of the current-level decision tree node.
[0073] First, after the data packet enters the programmable switch, the present invention matches the tenant mapping table according to the tenant ID of the tenant in the cloud data center to determine the decision tree ID for traffic cleaning in the subsequent process. Secondly, match the calculation flow splitting table to determine the calculation flow to enter. Finally, determine the label of the data packet by alternately matching the multi-level node parameter entries and the logical judgment module, and perform packet loss and normal forwarding actions according to whether the label value is malicious traffic. In the cloud data center scenario, on the premise of ensuring that tenants can flexibly customize abnormal traffic cleaning rules, line-rate abnormal traffic cleaning is achieved through the multi-tenant data plane decision tree.
[0074] Embodiment 2
[0075] Based on the above embodiment, the present invention proposes a specific implementation manner of a data plane multi-tenant abnormal traffic detection method, which specifically includes:
[0076] Preprocess two tenant traffic data packets, complete the feature extraction of the two tenant traffic data packets pkt, and the extracted features are stored in metadata (meta-data), that is, the feature vector of the data packet pkt is meta.FV, and the i-th feature value is meta.FV[i]. The feature vector values of the data packets pkt1 and pkt2 are shown in Table 1.
[0077] Table 1 Feature vector values of data packet pkt
[0078] Feature ID pkt1 Feature Value pkt2 Feature Value 0 8 2 1 21 32 2 187 156 3 218 307 4 78 33
[0079] The tenant ID of pkt1 is id1 = 2, and the tenant ID of pkt2 is id2 = 1.
[0080] Match the tenant ID with the decision tree ID, Figure 8 for the tenant mapping table.
[0081] For example, if the tenant ID of pkt1 is id1 = 2, then by matching the tenant mapping table, the decision tree with dtid = 1 needs to be used for traffic filtering. From the tenant ID of pkt2 being id2 = 1, it can be seen that the mapped dtid = 1. In summary, the mapping from the tenant ID to the decision tree ID is completed.
[0082] After completing the mapping between the tenant ID and the decision tree ID, further query the parameters and perform node logic judgment based on the decision tree ID and the node ID.
[0083] Decision process for pkt1:
[0084] 1. When pkt1 enters the root node for judgment, by querying the DTL1 entry as shown in Figure 9 , match dtid = 1, nodeid = 0b0 to get the action as get_feature, and the parameters are the feature index fi = 3 and the threshold thres = 256 respectively.
[0085] 2. pkt1 enters the logic judgment module as shown in Figure 10 . Since:
[0086] pkt1.meta.FV[3] = 218 < thres = 256
[0087] Therefore:
[0088] nodeid = (nodeid << 1) + 0 = 0b0
[0089] 3. pkt1 enters Figure 9DTL2 entry matching in it: Matching dtid = 1, nodeid = 0b0 results in an action of get_feature, with parameters being feature index fi = 0 and threshold thres = 6 respectively.
[0090] 4. pkt1 enters Figure 10 the logical decision module as shown. Since:
[0091] pkt1.meta.FV[0] = 8 > thres = 6
[0092] Therefore:
[0093] nodeid = (nodeid << 1) + 1 = 0b01
[0094] 5. pkt1 enters Figure 9 DTL3 entry matching in it: Matching dtid = 1, nodeid = 0b01 results in an action of get_label, with the decision label of pkt1 being malicious as the parameter.
[0095] Thus, the decision of the multi-tenant decision tree on packet pkt1 is completed.
[0096] Decision process of pkt2:
[0097] 1. When pkt2 enters the root node for decision, by querying the DTL1 entry as shown Figure 9 Matching dtid = 1, nodeid = 0b0 results in an action of get_feature, with parameters being feature index fi = 3 and threshold thres = 256 respectively.
[0098] 2. pkt2 enters the logical decision module as shown Figure 10 Since:
[0099] pkt1.meta.FV[3] = 307 > thres = 256
[0100] Therefore:
[0101] nodeid = (nodeid << 1) + 1 = 0b1
[0102] 3. pkt2 enters Figure 9 DTL2 entry matching in it: Matching dtid = 1, nodeid = 0b1 results in an action of get_feature, with parameters being feature index fi = 1 and threshold thres = 24 respectively.
[0103] 4. pkt2 enters Figure 10 the logical decision module as shown. Since:
[0104] pkt1.meta.FV[1] = 32 > thres = 24
[0105] Therefore:
[0106] nodeid = (nodeid << 1) + 1 = 0b11
[0107] 5. pkt2 enters Figure 9 The DTL3 table entry match in: The match of dtid = 1 and nodeid = 0b11 results in the action of get_label, and the parameters are the judgment labels benign (benign) of pkt2 respectively.
[0108] So far, the multi-tenant decision tree has completed the judgment of the data packet pkt2.
[0109] After completing the matching and logical judgment of DTL1 - 3, if the label is benign, the data packet is normally forwarded. If the label is malicious, the data packet is discarded, thus completing the cleaning of abnormal traffic.
[0110] The tenant mapping table and the data plane multi-tenant decision tree module of the present invention are both set in the data plane. A decision tree management module is also set in the control plane corresponding to the data plane. The decision tree management module is used to update and modify the data in the tenant mapping table and the data plane multi-tenant decision tree module.
[0111] Embodiment 3
[0112] Based on the above embodiment, as Figure 11 shown, the present invention provides a data plane multi-tenant abnormal traffic detection system, including:
[0113] A preprocessing module, used for extracting the data packet header fields and features of the data packet to obtain the tenant ID corresponding to the data packet and the data packet feature vector.
[0114] A tree matching module, used for matching the tenant ID of the data packet by using a preset tenant mapping table to obtain the decision tree ID corresponding to the data packet.
[0115] A parameter matching module, used for inputting the decision tree ID into a preset data plane multi-tenant decision tree module to complete the abnormal detection of the tenant traffic data packet.
[0116] It should be noted that a data plane multi-tenant abnormal traffic detection system provided by an embodiment of the present invention is to implement the above-mentioned data plane multi-tenant abnormal traffic detection method. Its functions can be specifically referred to the above method embodiments, and will not be elaborated here.
[0117] In summary, the present invention implements model node parameter query of tenants by multi-tenant decision tree according to decision tree ID (dtid) and node ID (nodeid). The node ID is organized in a path encoding manner, so that different nodeid lengths are set at different decision tree depths to save switch SRAM resources. The present invention stores the feature ID and feature threshold corresponding to each internal node of the decision tree in the node parameter table item. When the sample point reaches a node of the decision tree, the corresponding parameters are obtained through the action (get feature, get_feature), and the table items corresponding to the deeper nodes of the decision tree are split to prevent the stage forwarding resource occupation corresponding to the deeper level of the decision tree from exceeding the limit. The present invention can be deployed in a P4 switch. In the process of balancing the resource occupation of the decision tree, the present invention stores the node parameter queries of different tenants in different stages of the P4 switch in a dislocated manner, thereby realizing the balanced utilization of resources at different stages of the switch to support more decision tree deployments. The present invention can support the flexible customization of traffic filtering strategies by multiple tenants in a cloud data center, is used in cloud data center scenarios, and supports customization and isolation of multi-tenant defense strategies.
[0118] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A data plane multi-tenant abnormal traffic detection method, characterized in that: include: Step 1: Extract the header fields and features of the data packet to obtain the tenant ID and data packet feature vector corresponding to the data packet; Step 2: Use the preset tenant mapping table to match the tenant ID of the data packet to obtain the decision tree ID corresponding to the data packet; Step 3: Input the decision tree ID into the preset data plane multi-tenant decision tree module to complete the anomaly detection of tenant traffic data packets.
2. A data plane multi-tenant abnormal traffic detection method according to claim 1, characterized in that: The tenant mapping table is a mapping table between tenant IDs and preset decision tree IDs; the tenant mapping table includes tenant IDs and decision tree IDs.
3. A data plane multi-tenant abnormal traffic detection method according to claim 1, characterized in that: The data plane multi-tenant decision tree module includes a calculation flow splitting table, a first process and a second process; The computing flow splitting table is used to match the decision tree ID and the computing flow ID in sequence, and to place the decision tree corresponding to the decision tree ID on the process corresponding to the computing flow ID in sequence; wherein each computing flow ID corresponds to a process.
4. A data plane multi-tenant abnormal traffic detection method according to claim 3, characterized in that: The first process and the second process both include at least one data plane decision tree, the data plane decision tree includes a plurality of parameter query modules and a plurality of logic judgment modules, the parameter query modules and the logic judgment modules are alternately connected; The second process is delayed by one stage compared to the first process, and the first parameter query module in the second process corresponds to the first logic judgment module in the first process.
5. A data plane multi-tenant abnormal traffic detection method according to claim 3, characterized in that: The parameter query module is used to query the data in the preset node parameter table items, and the node parameter table items include action name, preset feature ID and preset feature threshold; wherein the feature ID corresponds to the feature value index in the data packet feature vector, and the feature threshold corresponds to the feature value in the data packet feature vector.
6. A data plane multi-tenant abnormal traffic detection method according to claim 3, characterized in that: In the decision tree, the path from the root node to the internal node or the leaf node is encoded, and the path encoding is used as the node ID.
7. A data plane multi-tenant abnormal traffic detection method according to claim 5 or 6, characterized in that: The logic judgment module specifically includes: Step 1: Shift the node ID left by 1 bit, leaving the lowest bit of the node ID free; Step 2: Index the feature value corresponding to the feature ID from the data packet feature vector, and compare the feature value with the feature threshold. If the feature value is greater than the feature threshold, execute step 3, otherwise continue to execute the parameter query and logic judgment module of the next stage of the decision tree; Step 3: Set node ID = node ID + 1, and use the lowest bit of the node ID to store the decision result of the decision tree node at this level.
8. A data plane multi-tenant abnormal traffic detection method according to claim 1, characterized in that: The tenant mapping table and the data plane multi-tenant decision tree module are both arranged in the data plane; A decision tree management module is also provided in the control plane, and the decision tree management module is used to update and modify the data in the tenant mapping table and the multi-tenant decision tree module of the data plane.
9. A data plane multi-tenant abnormal traffic detection system, characterized in that: include: A preprocessing module is used to extract the header fields and features of the data packets to obtain the tenant ID and data packet feature vector corresponding to the data packets; A tree matching module is used to match the tenant ID of the data packet using a preset tenant mapping table to obtain a decision tree ID corresponding to the data packet; The parameter matching module is used to input the decision tree ID into the preset data plane multi-tenant decision tree module to complete the anomaly detection of tenant traffic data packets.