Message rule searching method
By finding candidate five-tuple rules in the preliminary filtering hash table and the collaborative filtering hash table, the hash value is used to determine the storage location, and the five-tuple rules of the target message are quickly filtered out, which solves the problem of cumbersome search for message rules in the existing technology and improves the packet processing performance.
Patent Information
- Application Number
- CN202510353903.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-06-24
AI Technical Summary
The process of searching the rules of packets in the prior art is cumbersome, which affects the performance of packet processing.
Provides a method for searching the rules of packets. By searching candidate five-tuple rules in the preliminary filter hash table and the collaborative filter hash table, the hash value determines the storage location, and quickly filters out the five-tuple rules of the target packets.
Simplifies the search process of five-tuple rules, improves packet processing performance, and reduces search time.
Smart Images

Figure CN120200808A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network communication technologies, and in particular, to a method for finding rules of packets. Background Art
[0002] Five-tuple rule query in the field of network communication and security is to find rules matching packets in a rule library based on the five-tuple information of packets in network communication, so as to implement the processing of packets.
[0003] In related technologies, when a packet enters a device, the device first parses the packet to obtain five-tuple fields, and then matches the five-tuple rules according to these five fields. Among them, the matching method is to use 31 combination templates of five-tuples to combine the five fields of the packet to find the rule content. Therefore, whenever there is a packet, it is necessary to first combine the five-tuple fields of the packet according to 31 combination templates, and then traverse each combination in the rule library once until all combinations are traversed to obtain the finally matched five-tuple rule.
[0004] However, in related technologies, there is a technical problem that the process of finding rules of packets is relatively cumbersome, which affects the processing performance of packets. Summary of the Invention
[0005] Based on this, in view of the above technical problems, it is necessary to provide a method for finding rules of packets, which can simplify the process of finding rules of packets and improve the processing performance of packets.
[0006] In a first aspect, an embodiment of this application provides a method for finding rules of packets, including:
[0007] Finding a first candidate five-tuple rule in a preliminary screening hash table according to the address field data of a target packet; the storage location of each five-tuple rule in the preliminary screening hash table is determined according to the hash value of the address field data in each five-tuple rule;
[0008] Finding a second candidate five-tuple rule in a collaborative screening hash table according to the five-tuple combination template matching the address field data in the collaborative screening hash table and the five-tuple field data of the target packet; the storage location of each five-tuple rule in the collaborative screening hash table is determined according to the hash value of each five-tuple rule;
[0009] Determining the first candidate five-tuple rule and the second candidate five-tuple rule as the five-tuple rules of the target packet.
[0010] In the method for finding rules of a message provided by an embodiment of the present application, first, according to the address field data of a target message, a first candidate five-tuple rule is found in a preliminary screening hash table. Then, according to a five-tuple combination template that matches the address field data in a collaborative screening hash table and the five-tuple field data of the target message, a second candidate five-tuple rule is found in the collaborative screening hash table. After that, the first candidate five-tuple rule and the second candidate five-tuple rule are determined as the five-tuple rules of the target message. Among them, the storage location of each five-tuple rule in the preliminary screening hash table is determined according to the hash value of the address field data in each five-tuple rule, and the storage location of each five-tuple rule in the collaborative screening hash table is determined according to the hash value of each five-tuple rule. In this method, when finding rules for a target message, according to the address field data of the target message and the storage location of the five-tuple rules in the preliminary screening hash table, a first candidate five-tuple rule is screened out in the preliminary screening hash table. Then, according to the five-tuple field data of the target message, the five-tuple combination template that matches the address field data in the collaborative screening hash table, and the storage location of the five-tuple rules in the collaborative screening hash table, a second candidate five-tuple rule is screened out in the collaborative screening hash table to obtain the five-tuple rules of the target message. Equivalently, when performing five-tuple rule search, it only needs to screen in two hash tables based on the five-tuple field data in the target message and the storage location of the five-tuple rules in the hash table, without the need for traversal, which simplifies the process of finding five-tuple rules and improves the processing performance of messages.
[0011] In one embodiment, finding a first candidate five-tuple rule in a preliminary screening hash table according to the address field data of a target message includes:
[0012] According to the address field data, calculate the hash value of the address field data;
[0013] According to the hash value of the address field data, determine the storage location of the first candidate five-tuple rule;
[0014] According to the storage location, obtain the first candidate five-tuple rule from the preliminary screening hash table.
[0015] In the method for finding rules of a message provided by an embodiment of the present application, first, according to the address field data, calculate the hash value of the address field data. Then, according to the hash value of the address field data, determine the storage location of the first candidate five-tuple rule. After that, according to the storage location, obtain the first candidate five-tuple rule from the preliminary screening hash table. In this method, by calculating the hash value of the address field data of the target message, the storage location of the first candidate five-tuple rule can be quickly located, and then the first candidate five-tuple rule can be quickly obtained based on this storage location, providing position positioning for the acquisition of the first candidate five-tuple rule and improving the search efficiency of the first candidate five-tuple rule.
[0016] In one embodiment, obtaining a first candidate quintuple rule from a preliminary screening hash table according to a storage location includes:
[0017] Obtaining a plurality of quintuple rules at the storage location according to the storage location;
[0018] Comparing the address field data of each quintuple rule with the address field data of the target packet, and determining the quintuple rules with the same address field data as the target packet among the quintuple rules as the first candidate quintuple rules.
[0019] In the method for finding rules of a packet provided by the embodiments of the present application, first, according to the storage location, a plurality of quintuple rules at the storage location are obtained. Then, the address field data of each quintuple rule is compared with the address field data of the target packet, and the quintuple rules with the same address field data as the target packet among the quintuple rules are determined as the first candidate quintuple rules. In this method, when obtaining the first candidate quintuple rules from the storage location, first, all the quintuple rules stored at this location are obtained from the storage location, and then the quintuple rules with the same address field data as the target packet are screened out from these quintuple rules as the first candidate quintuple rules. Equivalently, after obtaining the quintuple rules based on the storage location, further screening is performed based on the matching of the address field data, making the screened first candidate quintuple rules more accurate and improving the screening accuracy of the first candidate quintuple rules.
[0020] In one embodiment, finding a second candidate quintuple rule in a collaborative screening hash table according to a quintuple combination template matching the address field data and the quintuple field data of the target packet includes:
[0021] Determining the packet field data corresponding to the quintuple combination template according to the quintuple combination template and the quintuple field data;
[0022] Determining the storage location of the second candidate quintuple rule according to the hash value of the packet field data;
[0023] Obtaining the second candidate quintuple rule from the collaborative screening hash table according to the storage location.
[0024] In the method for finding rules of a message provided by an embodiment of the present application, first, according to a five-tuple combination template and five-tuple field data, the message field data corresponding to the five-tuple combination template is determined. Then, according to the hash value of the message field data, the storage location of a second candidate five-tuple rule is determined. After that, according to the storage location, the second candidate five-tuple rule is obtained from a collaborative screening hash table. In this method, by substituting the five-tuple field data into the five-tuple combination template, the message field data matching the five-tuple combination template is obtained, so that the storage location of the second candidate five-tuple rule can be quickly determined based on the hash value of the message field data, and the second candidate five-tuple rule is obtained from this storage location. Equivalently, through the five-tuple combination template and the five-tuple field data, the message field data that can quickly locate the second candidate five-tuple rule is obtained, so that the storage location of the second candidate five-tuple rule can be quickly determined based on the hash value of the message field data, improving the search efficiency of the second candidate five-tuple rule.
[0025] In one embodiment, obtaining the second candidate five-tuple rule from the collaborative screening hash table according to the storage location includes:
[0026] Obtaining multiple five-tuple rules at the storage location according to the storage location;
[0027] Comparing each five-tuple rule with the message field data, and determining the five-tuple rules that are the same as the message field data in each five-tuple rule as the second candidate five-tuple rules.
[0028] In the method for finding rules of a message provided by an embodiment of the present application, first, according to the storage location, multiple five-tuple rules at the storage location are obtained. Then, each five-tuple rule is compared with the message field data, and the five-tuple rules that are the same as the message field data in each five-tuple rule are determined as the second candidate five-tuple rules. In this method, when obtaining the second candidate five-tuple rule from the storage location of the second candidate five-tuple rule, first, all the five-tuple rules stored at this location are obtained from the storage location, and then the five-tuple rules that are the same as the message field data are screened out from these five-tuple rules as the second candidate five-tuple rules. Equivalently, after obtaining the five-tuple rules based on the storage location, further screening is performed based on the matching of the complete field data of the five-tuple rules, making the screened second candidate five-tuple rules more accurate and improving the screening accuracy of the second candidate five-tuple rules.
[0029] In one embodiment, before searching for the first candidate five-tuple rule in the preliminary screening hash table according to the address field data of the target message, the method further includes:
[0030] Parsing the target message to obtain the five-tuple field data of the target message;
[0031] Obtain the source address field data and destination address field data in the five-tuple field data according to the five-tuple field data of the target message;
[0032] Determine the source address field data and destination address field data as the address field data of the target message.
[0033] In the method for finding rules of a message provided by an embodiment of the present application, by parsing the target message, the five-tuple field data of the target message is obtained. Then, according to the five-tuple field data of the target message, the source address field data and destination address field data in the five-tuple field data are obtained. After that, the source address field data and destination address field data are determined as the address field data of the target message. In this method, after receiving the target message, by parsing the target message, the included five-tuple field data is obtained, and the source IP address field data and destination IP address field data are obtained from the five-tuple field data as the address field data of the target message, providing data support for the rule screening of the target message.
[0034] In one embodiment, the method further includes:
[0035] In response to a request for adding a target five-tuple rule, obtain the five-tuple field data of the target five-tuple rule;
[0036] According to the five-tuple field data of the target five-tuple rule, add the target five-tuple rule to the rule storage hash table.
[0037] In the method for finding rules of a message provided by an embodiment of the present application, in response to a request for adding a target five-tuple rule, obtain the five-tuple field data of the target five-tuple rule. Then, according to the five-tuple field data of the target five-tuple rule, add the target five-tuple rule to the rule storage hash table. In this method, when receiving a request for adding a target five-tuple rule, first obtain the five-tuple field data of the target five-tuple rule, and then based on the five-tuple field data, add the target five-tuple rule to the rule storage hash table for storing five-tuple rules, providing an optional way for quickly adding five-tuple rules, thereby laying a data foundation for finding five-tuple rules of the target message.
[0038] In one embodiment, the rule storage hash table includes a preliminary screening hash table; adding the target five-tuple rule to the rule hash table according to the five-tuple field data of the target five-tuple rule includes:
[0039] Search the preliminary screening hash table according to the address field data in the five-tuple field data;
[0040] If there is no candidate five-tuple rule in the preliminary screening hash table whose address field data of the five-tuple rule is the same as that of the target five-tuple rule, add the target five-tuple rule to the preliminary screening hash table;
[0041] If there is a candidate five-tuple rule in the preliminary screening hash table, add the target five-tuple rule according to the candidate five-tuple rule.
[0042] In the method for finding rules of a message provided by an embodiment of the present application, by searching the preliminary screening hash table according to the address field data in the five-tuple field data, if there is no candidate five-tuple rule in the preliminary screening hash table whose address field data of the five-tuple rule is the same as that of the target five-tuple rule, add the target five-tuple rule to the preliminary screening hash table. If there is a candidate five-tuple rule in the preliminary screening hash table, add the target five-tuple rule according to the candidate five-tuple rule. In this method, first, according to the address field data in the five-tuple field data of the target five-tuple rule, search in the preliminary screening hash table. If there is no five-tuple rule in the preliminary screening hash table with the same address field data as the target five-tuple rule, directly add the target five-tuple rule to the preliminary screening hash table. Otherwise, based on the five-tuple rule with the same address field data as the target five-tuple rule, add the target five-tuple rule. Equivalently, first determine whether the target five-tuple rule belongs to the five-tuple rules in the preliminary screening hash table. If so, directly store it in the preliminary screening hash table. If not, store it based on other methods. This improves the storage efficiency of the target five-tuple rule, thereby improving the rule storage performance.
[0043] In one embodiment, the rule storage hash table further includes a collaborative screening hash table; adding the target five-tuple rule according to the candidate five-tuple rule includes:
[0044] If the candidate five-tuple rule is the same as the target five-tuple rule, end the addition of the target five-tuple rule;
[0045] If the candidate five-tuple rule is different from the target five-tuple rule, query the collaborative screening hash table according to the target five-tuple rule and complete the addition of the target five-tuple rule.
[0046] In the method for finding rules of a message provided by an embodiment of the present application, if the candidate five-tuple rule is the same as the target five-tuple rule, the addition of the target five-tuple rule is ended; if the candidate five-tuple rule is different from the target five-tuple rule, the collaborative screening hash table is queried according to the target five-tuple rule, and the addition of the target five-tuple rule is completed. In this method, the candidate five-tuple rule is compared with the target five-tuple rule. When the candidate five-tuple rule is the same as the target five-tuple rule, it indicates that the target five-tuple rule has been stored in the preliminary screening hash table, and the storage of the target five-tuple rule is ended; when the candidate five-tuple rule is different from the target five-tuple rule, it indicates that the target five-tuple rule is not stored in the preliminary screening hash table, and further search is performed in the collaborative screening hash table to complete the addition of the target five-tuple rule, making the storage of the target five-tuple rule more detailed and improving the storage accuracy of the target five-tuple rule, thereby improving the search accuracy of the five-tuple rule.
[0047] In one embodiment, querying the collaborative screening hash table according to the target five-tuple rule and completing the addition of the target five-tuple rule includes:
[0048] If the target five-tuple rule exists in the collaborative screening hash table, the addition of the target five-tuple rule is ended;
[0049] If the target five-tuple rule does not exist in the collaborative screening hash table, the target five-tuple rule is added to the collaborative screening hash table, and the template count of the five-tuple combination template of the target five-tuple rule is updated.
[0050] In the method for finding rules of a message provided by an embodiment of the present application, if the target five-tuple rule exists in the collaborative screening hash table, the addition of the target five-tuple rule is ended; if the target five-tuple rule does not exist in the collaborative screening hash table, the target five-tuple rule is added to the collaborative screening hash table, and the template count of the five-tuple combination template of the target five-tuple rule is updated. In this method, when querying the collaborative screening hash table according to the target five-tuple rule, it is determined whether the target five-tuple rule exists in the collaborative screening hash table. If it exists, there is no need to store the target five-tuple rule again, and the storage of the target five-tuple rule is ended. If it does not exist, the target five-tuple is stored in the collaborative screening hash table to complete the addition of the target five-tuple rule, enabling the target five-tuple rule to be quickly and accurately stored in the corresponding position and improving the storage accuracy of the target five-tuple rule.
[0051] In a second aspect, an embodiment of the present application further provides a device for finding rules of a message, including:
[0052] A preliminary screening module, configured to search for a first candidate five-tuple rule in a preliminary screening hash table according to the address field data of a target message; the storage location of each five-tuple rule in the preliminary screening hash table is determined according to the hash value of the address field data in each five-tuple rule;
[0053] A collaborative screening module, configured to search for a second candidate five-tuple rule in a collaborative screening hash table according to a five-tuple combination template that matches the address field data in the collaborative screening hash table and the five-tuple field data of the target message; the storage location of each five-tuple rule in the collaborative screening hash table is determined according to the hash value of each five-tuple rule;
[0054] A rule determination module, configured to determine the first candidate five-tuple rule and the second candidate five-tuple rule as the five-tuple rule of the target message.
[0055] In a third aspect, the present application further provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the steps of the method in any one of the embodiments in the first aspect or the second aspect are implemented.
[0056] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method in any one of the embodiments in the first aspect or the second aspect are implemented.
[0057] In a fifth aspect, the present application further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the method in any one of the embodiments in the first aspect or the second aspect are implemented.
[0058] The method for finding rules of a message provided by an embodiment of the present application first finds a first candidate five-tuple rule in a preliminary screening hash table according to the address field data of a target message, and then finds a second candidate five-tuple rule in a collaborative screening hash table according to the five-tuple combination template matching the address field data in the collaborative screening hash table and the five-tuple field data of the target message. After that, the first candidate five-tuple rule and the second candidate five-tuple rule are determined as the five-tuple rule of the target message. Among them, the storage location of each five-tuple rule in the preliminary screening hash table is determined according to the hash value of the address field data in each five-tuple rule, and the storage location of each five-tuple rule in the collaborative screening hash table is determined according to the hash value of each five-tuple rule. In this method, when finding rules for a target message, according to the address field data of the target message and the storage location of the five-tuple rules in the preliminary screening hash table, a first candidate five-tuple rule is screened out in the preliminary screening hash table, and then according to the five-tuple field data of the target message, the five-tuple combination template matching the address field data in the collaborative screening hash table, and the storage location of the five-tuple rules in the collaborative screening hash table, a second candidate five-tuple rule is screened out in the collaborative screening hash table to obtain the five-tuple rule of the target message. Equivalently, when performing five-tuple rule search, it only needs to screen in two hash tables based on the five-tuple field data in the target message and the storage location of the five-tuple rules in the hash table, without traversal, which simplifies the five-tuple rule search process and improves the message processing performance. Brief Description of the Drawings
[0059] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0060] Figure 1 It is the internal structure diagram of a computer device in an embodiment;
[0061] Figure 2 It is the flowchart of the method for finding rules of a message in an embodiment;
[0062] Figure 3 It is the flowchart of finding the first candidate five-tuple rule in an embodiment;
[0063] Figure 4 It is the flowchart of obtaining the first candidate five-tuple rule in an embodiment;
[0064] Figure 5 It is the flowchart of finding the second candidate five-tuple rule in an embodiment;
[0065] Figure 6 It is a schematic flow diagram for obtaining the second candidate five-tuple rule in an embodiment;
[0066] Figure 7 It is a schematic flow diagram for determining the address field data in an embodiment;
[0067] Figure 8 It is a schematic flow diagram for adding a rule in an embodiment;
[0068] Figure 9 It is a schematic flow diagram for adding a rule in another embodiment;
[0069] Figure 10 It is a schematic flow diagram for deleting a rule in an embodiment;
[0070] Figure 11 It is a schematic diagram of a hash table in an embodiment;
[0071] Figure 12 It is a schematic diagram of a preliminary screening hash table in an embodiment;
[0072] Figure 13 It is a schematic diagram of a collaborative screening hash table in an embodiment;
[0073] Figure 14 It is a schematic flow diagram for adding a rule in another embodiment;
[0074] Figure 15 It is a schematic flow diagram for deleting a rule in another embodiment;
[0075] Figure 16 It is a schematic flow diagram for querying a rule in an embodiment;
[0076] Figure 17 It is a schematic structural diagram of a rule lookup device for a message in an embodiment. Detailed implementation manners
[0077] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0078] The technical background of the embodiments of the present application will be described below first.
[0079] The flexible five-tuple rule refers to data with five network packet fields. Among them, the five network packet fields are the source Internet Protocol address (SIP), the destination IP address (DIP), the source port number (SPORT), the destination port number (DPORT), and the protocol number (PROTO) of the four-layer protocol type. Each field can be valid or invalid. There are 31 valid combination methods for the flexible five-tuples. Each combination is called a template, that is, there are 31 templates, and each template is shown in Table 1 below.
[0080] Table 1
[0081]
[0082] The flexible IP five-tuple rule refers to the flexible five-tuple rule that definitely has the SIP or DIP field. That is, it does not consider the cases without IP fields such as SPORT, DPORT, PROTO, SPORT+DPORT, SPORT+PROTO, DPORT+PROTO, and SPORT+DPORT+PROTO. Therefore, there are 24 valid combination methods for the IP five-tuple rule.
[0083] Each template type may have a large number of rules. Users can issue a large number of the above rules to the device, and the overall capacity can reach the order of thousands or even hundreds of millions. In the related technology, when a packet enters the device, the device parses the packet to obtain the five-tuple fields of the packet, namely SIP, DIP, SPORT, DPORT, and PROTO, and matches the five-tuple rule according to these five fields. The matching method is to combine the five tuple fields of the packet in the combination methods of the above 31 templates respectively to find the rule content. When the combined fields of the packet are exactly equal to the content of the rule, it is considered that the rule is hit. After hitting the rule, the packet is processed according to the action data in the rule. Therefore, 31 searches are required whenever there is a packet. Since it is impossible to predict what rules the user issues, and it is impossible to predict in advance what template's rule content a packet may hit, all template situations need to be searched to determine the hit rule, which will affect the processing performance of the packet.
[0084] Based on this, the embodiments of the present application provide a method for finding rules of a message. When finding rules for a target message, according to the address field data of the target message and the storage location of the five-tuple rules in the preliminary screening hash table, the first candidate five-tuple rules are screened out in the preliminary screening hash table. Then, according to the five-tuple field data of the target message, the five-tuple combination template matching the address field data in the collaborative screening hash table, and the storage location of the five-tuple rules in the collaborative screening hash table, the second candidate five-tuple rules are screened out in the collaborative screening hash table to obtain the five-tuple rules of the target message. Equivalently, when performing five-tuple rule search, it only needs to screen in two hash tables based on the five-tuple field data in the target message and the storage location of the five-tuple rules in the hash table, without traversal, which simplifies the five-tuple rule search process and improves the message processing performance. Of course, the technical solutions provided in the embodiments of the present application are not limited to only solving the above problems, and there are other technical effects, which can be specifically referred to the following embodiments for description.
[0085] It should be noted that the beneficial effects or technical problems solved by the embodiments of the present application are not limited to this one, and there may be other implicit or related problems, which can be specifically referred to the description of the following embodiments.
[0086] The application environment of the method for finding rules of a message provided by the embodiments of the present application will be described below. It can be applied to a computer device. The computer device can be a server, and its internal structure diagram can be as Figure 1 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a method for finding rules of a message. Those skilled in the art can understand that Figure 1 the structure shown in
[0087] The technical solution of the present application and how the technical solution of the present application solves the above technical problems will be described in detail below with specific embodiments. These several specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below with reference to the accompanying drawings.
[0088] In an exemplary embodiment, as Figure 2 shown, a method for finding rules of a message is provided. Taking the computer device in Figure 1 as an example, the method includes the following steps 201 to step 203. Wherein:
[0089] S201, according to the address field data of the target message, find the first candidate five-tuple rule in the preliminary screening hash table; the storage location of each five-tuple rule in the preliminary screening hash table is determined according to the hash value of the address field data in each five-tuple rule.
[0090] The address field data refers to the actual content corresponding to the SIP field or the DIP field in the five-tuple field of the target message. For example, if the actual content corresponding to the SIP field is 1.1.1.1, then the SIP field data is 1.1.1.1. The preliminary screening hash table refers to a hash table storing five-tuple rules, which is used for the preliminary screening of five-tuple rules during rule search. Among them, the storage location of each five-tuple rule in the preliminary screening hash table is determined according to the hash value of the address field data in the five-tuple rule. For example, a five-tuple rule is 1.1.1.1 + 1234. Among them, 1.1.1.1 is the SIP field data in the address field data, and 1234 is the source port number field data. When storing the five-tuple rule 1.1.1.1 + 1234 into the preliminary screening hash table, the hash value of 1.1.1.1 can be calculated, and then the storage location corresponding to the hash value can be found according to the hash value, and the five-tuple rule can be stored in this storage location.
[0091] In the embodiment of the present application, when finding the rule corresponding to the target message, first, according to the address field data of the target message, search in the preliminary screening hash table to screen out the first candidate five-tuple rule corresponding to the target message from the preliminary screening hash table.
[0092] In one embodiment, the method for finding the first candidate five-tuple rule in the preliminary screening hash table according to the address field data of the target packet may be to determine a storage location according to the hash value of the address field data, and then determine all the five-tuple rules stored in this storage location as the first candidate five-tuple rules. Or, from all the five-tuple rules stored in this storage location, filter out the five-tuple rules whose address field data is the same as the address field data of the target packet as the first candidate five-tuple rules.
[0093] In another embodiment, the method for finding the first candidate five-tuple rule in the preliminary screening hash table according to the address field data of the target packet may be to determine a storage location according to the hash value of the address field data, and then obtain all the five-tuple rules of this storage location according to this storage location. After that, based on a preset screening condition, obtain the first candidate five-tuple rule from all the five-tuple rules of this storage location. For example, the preset screening condition may be to use the five-tuple rules whose address field data is the same as the address field data of the target packet as the first candidate five-tuple rules, or it may be to determine the five-tuple rules that include the address field data but do not include the port number field (SPORT field and DPORT field) data and the protocol number field (PROTO field) data as the first candidate five-tuple rules. Among them, the preset screening condition is not limited to the above examples, and in actual situations, it can be set based on the storage method of the rules in the preliminary screening hash table and the actual business requirements, etc.
[0094] S202, according to the five-tuple combination template matching the address field data in the collaborative screening hash table and the five-tuple field data of the target packet, find the second candidate five-tuple rule in the collaborative screening hash table; the storage location of each five-tuple rule in the collaborative screening hash table is determined according to the hash value of each five-tuple rule.
[0095] The collaborative screening hash table refers to a hash table storing five-tuple rules, which is used to collaboratively and preliminarily screen the hash table for finding five-tuple rules. Among them, the five-tuple rules stored in the collaborative screening hash table are different from those stored in the preliminary screening hash table, that is, the five-tuple rules stored in the preliminary screening hash table will not be stored in the collaborative screening hash table again. Therefore, when performing five-tuple rule lookup, for the integrity of the five-tuple rules, after looking up in the preliminary screening hash table, it is also necessary to perform a lookup in the collaborative screening hash table to achieve a comprehensive lookup of the five-tuple rules, improve the accuracy of five-tuple rule lookup, and thus improve the accuracy of message processing. The storage location of each five-tuple rule in the collaborative screening hash table is determined according to the hash table of each five-tuple rule. For example, a five-tuple rule is 1.1.1.1 + 1122, where 1.1.1.1 is the SIP field data in the address field data and 1122 is the source port number field data. When storing the five-tuple rule 1.1.1.1 + 1122 into the collaborative screening hash table, the hash value of 1.1.1.1 + 1122 can be calculated, and then the storage location corresponding to this hash value can be found according to this hash value, and the five-tuple rule can be stored at this storage location.
[0096] The five-tuple combination template matching the address field data refers to the five-tuple combination template of the five-tuple rules whose address field data in the collaborative screening hash table is the same as the address field data of the target message. For example, taking the address field data as the SIP field data as an example, the SIP field data of the target message is 1.1.1.1, and there are five-tuple rules 1.1.1.1 + 1122, 1.1.1.1 + 2.2.2.2, and 1.2.2.2 + 1234 + 1100 in the hash table. Among them, the five-tuple combination template of 1.1.1.1 + 1122 is SIP + SPORT, the five-tuple combination template of 1.1.1.1 + 2.2.2.2 is SIP + DIP, and the five-tuple combination template of 1.2.2.2 + 1234 + 1100 is SIP + SPORT + DPORT. Then, the five-tuple rules whose address field data is the same as the address field data of the target message are 1.1.1.1 + 1122 and 1.1.1.1 + 2.2.2.2, and their corresponding five-tuple combination templates are SIP + SPORT and SIP + DIP respectively. Then, the five-tuple combination templates in the collaborative screening hash table matching the address field data are SIP + SPORT and SIP + DIP. Among them, the five-tuple combination template refers to the effective combination method of the five tuples in the five-tuple, specifically referring to Table 1 above, and there are 31 five-tuple combination templates in total.
[0097] The template for the combination of five-tuple rules matching the address field data in the collaborative screening hash table can be the template count of the combination template of the five-tuple rules corresponding to the same address field data as the target packet in the collaborative screening hash table directly output by the preliminary screening hash table after finding the first candidate five-tuple rule in the preliminary screening hash table. Among them, when outputting the template count, the combination template of the five-tuple is also output, so the computer device can determine the combination template of the five-tuple rules matching the address field data based on the output template count and the combination template of the five-tuple. For example, the combination template of the five-tuple with a template count greater than zero is determined as the combination template of the five-tuple rules matching the address field data. In the embodiments of the present application, the combination template of the five-tuple rules matching the address field data in the collaborative screening hash table is determined through the template count, which improves the determination efficiency of the combination template of the five-tuple, and thus further improves the search efficiency of the five-tuple rules.
[0098] The five-tuple field data of the target packet refers to the actual content corresponding to the five-tuple field in the target packet. Among them, after parsing the target packet, the five-tuple field data of the target packet can be obtained.
[0099] In the embodiments of the present application, after screening out the first candidate five-tuple rule in the preliminary screening hash table, continue to search in the collaborative screening hash table according to the combination template of the five-tuple rules matching the address field data in the collaborative screening hash table and the five-tuple field data of the target packet to screen out the second candidate five-tuple rule.
[0100] Exemplarily, according to the combination template of the five-tuple rules matching the address field data in the collaborative screening hash table and the five-tuple field data of the target packet, the method of searching for the second candidate five-tuple rule in the collaborative screening hash table can be to substitute the five-tuple field data of the target packet into the combination template of the five-tuple rules matching the address field data to obtain candidate field data, and then search for the five-tuple rule identical to the candidate field data in the collaborative screening hash table. If found, the five-tuple rule identical to the candidate field data is determined as the second candidate five-tuple rule.
[0101] S203, determine the first candidate five-tuple rule and the second candidate five-tuple rule as the five-tuple rules of the target packet.
[0102] After finding the first candidate five-tuple rule and the second candidate five-tuple rule, determine the first candidate five-tuple rule found in the preliminary screening hash table and the second candidate five-tuple rule found in the collaborative screening hash table as the five-tuple rules of the target packet. Further, according to the preset priority screening strategy, the five-tuple rule with the highest priority can be selected from the first candidate five-tuple rule and the second candidate five-tuple rule as the five-tuple rule finally used to process the target packet.
[0103] It should be noted that in the embodiments of the present application, when searching for the five-tuple rule corresponding to the target packet, the address field can be used as the SIP field first to search in the preliminary screening hash table and the collaborative screening hash table once, and then the address field can be used as the DIP field to search in the preliminary screening hash table and the collaborative screening hash table once. Finally, all the first candidate five-tuple rules and the second candidate five-tuple rules found under the two address fields are determined as the five-tuple rules corresponding to the target packet. Further, according to the preset priority screening strategy, the five-tuple rule with the highest priority is screened out as the five-tuple rule finally used to process the target packet. In addition, if there is no five-tuple combination template in the collaborative screening hash table that matches the address field data of the target packet, there is no need to search in the collaborative screening hash table anymore, and the first candidate five-tuple rule found in the preliminary screening hash table is directly used as the five-tuple rule corresponding to the target packet.
[0104] In the method for searching for rules of packets provided by the embodiments of the present application, first, according to the address field data of the target packet, the first candidate five-tuple rule is searched in the preliminary screening hash table. Then, according to the five-tuple combination template in the collaborative screening hash table that matches the address field data and the five-tuple field data of the target packet, the second candidate five-tuple rule is searched in the collaborative screening hash table. After that, the first candidate five-tuple rule and the second candidate five-tuple rule are determined as the five-tuple rules corresponding to the target packet. Among them, the storage location of each five-tuple rule in the preliminary screening hash table is determined according to the hash value of the address field data in each five-tuple rule, and the storage location of each five-tuple rule in the collaborative screening hash table is determined according to the hash value of each five-tuple rule. In this method, when searching for rules for the target packet, according to the address field data of the target packet and the storage location of the five-tuple rules in the preliminary screening hash table, the first candidate five-tuple rule is screened out in the preliminary screening hash table. Then, according to the five-tuple field data of the target packet, the five-tuple combination template in the collaborative screening hash table that matches the address field data, and the storage location of the five-tuple rules in the collaborative screening hash table, the second candidate five-tuple rule is screened out in the collaborative screening hash table to obtain the five-tuple rules of the target packet. Equivalently, when searching for five-tuple rules, only based on the five-tuple field data in the target packet and the storage location of the five-tuple rules in the hash table, screening can be performed in the two hash tables without traversal, which simplifies the process of searching for five-tuple rules and improves the processing performance of packets.
[0105] Based on the above embodiments, an embodiment is provided to illustrate the process of searching for the first candidate five-tuple rule.
[0106] In an exemplary embodiment, as Figure 3As shown in the figure, to find the first candidate five-tuple rule in the preliminary screening hash table according to the address field data of the target packet, it includes:
[0107] S301, calculate the hash value of the address field data according to the address field data.
[0108] As mentioned above, the storage location of each five-tuple rule in the preliminary screening hash table is determined according to the hash value of the address field data in the five-tuple rule. Therefore, when searching for the five-tuple rule in the preliminary screening hash table, it is necessary to calculate the hash value according to the address field data to determine the storage location of the five-tuple rule.
[0109] Exemplarily, use the hash algorithm to perform hash processing on the address field data of the target packet to obtain the hash value of the address field data. Among them, the hash algorithm can adopt algorithms such as MD5 algorithm, SHA-1 algorithm, and SHA-256 algorithm.
[0110] S302, determine the storage location of the first candidate five-tuple rule according to the hash value of the address field data.
[0111] In the embodiment of the present application, according to the hash value of the address field data, the hash bucket corresponding to the hash value is determined, and the hash bucket is determined as the storage location of the first candidate five-tuple rule.
[0112] S303, obtain the first candidate five-tuple rule from the preliminary screening hash table according to the storage location.
[0113] After determining the storage location of the first candidate five-tuple rule, obtain the first candidate five-tuple rule from the storage location.
[0114] Exemplarily, according to the storage location of the first candidate five-tuple rule, obtain all the five-tuple rules at the storage location, and determine all the obtained five-tuple rules as the first candidate five-tuple rule.
[0115] Exemplarily, according to the storage location of the first candidate five-tuple rule, obtain all the five-tuple rules at the storage location, and then compare the address field data of each five-tuple rule with the address field data of the target packet. If the address field data of a certain five-tuple rule is the same as the address field data of the target packet, then determine the five-tuple rule as the first candidate five-tuple rule.
[0116] In the method for finding rules of packets provided by the embodiments of the present application, first, according to the address field data, the hash value of the address field data is calculated. Then, according to the hash value of the address field data, the storage location of the first candidate five-tuple rule is determined. After that, according to the storage location, the first candidate five-tuple rule is obtained from the preliminary screening hash table. In this method, by calculating the hash value of the address field data of the target packet, the storage location of the first candidate five-tuple rule can be quickly located, and then the first candidate five-tuple rule can be quickly obtained based on this storage location, providing position positioning for the acquisition of the first candidate five-tuple rule and improving the search efficiency of the first candidate five-tuple rule.
[0117] Based on the above embodiments, an embodiment of the process for obtaining the first candidate five-tuple rule is provided for description.
[0118] In an exemplary embodiment, as Figure 4 shown, obtaining the first candidate five-tuple rule from the preliminary screening hash table according to the storage location includes:
[0119] S401, according to the storage location, obtain multiple five-tuple rules at the storage location.
[0120] When obtaining the first candidate five-tuple rule according to the storage location, first obtain all the five-tuple rules stored at this storage location from this storage location.
[0121] S402, compare the address field data of each five-tuple rule with the address field data of the target packet, and determine the five-tuple rules with the same address field data as the target packet among each five-tuple rule as the first candidate five-tuple rules.
[0122] After obtaining all the five-tuple rules at this storage location, obtain the address field data of each five-tuple rule, compare the address field of each five-tuple rule with the address field data of the target packet, and determine the five-tuple rules with the same address field data as the target packet among each five-tuple rule as the first candidate five-tuple rules.
[0123] For example, all quintuple rules of the storage location are 1.1.1.1 + 1010 (SIP + SPORT), 1.1.1.1 + 1234 (SIP + SPORT), 2.2.2.2 + 1000 + 1234 (SIP + SPORT + DPORT). The address field data of the target packet is 1.1.1.1. After comparing the address field data of the target packet with the address field data in all quintuple rules of the storage location, only the address field data in the quintuple rule 2.2.2.2 + 1000 + 1234 is different from the address field of the target packet. Then, the quintuple rules 1.1.1.1 + 1010 and 1.1.1.1 + 1234 are determined as the first candidate quintuple rules.
[0124] In the method for finding rules of packets provided by the embodiments of the present application, first, according to the storage location, multiple quintuple rules of the storage location are obtained. Then, the address field data of each quintuple rule is compared with the address field data of the target packet, and the quintuple rules in which the address field data is the same as the address field data of the target packet are determined as the first candidate quintuple rules. In this method, when obtaining the first candidate quintuple rules from the storage location, first, all quintuple rules stored at this location are obtained from the storage location, and then the quintuple rules in which the address field data is the same as the quintuple field data of the target packet are screened out from these quintuple rules as the first candidate quintuple rules. Equivalently, after obtaining the quintuple rules based on the storage location, further screening is performed based on the matching of the address field data, making the screened first candidate quintuple rules more accurate and improving the screening accuracy of the first candidate quintuple rules.
[0125] Based on any of the foregoing embodiments, an embodiment for the process of finding the second candidate quintuple rules is provided for illustration.
[0126] In an exemplary embodiment, as Figure 5 shown, according to the quintuple combination template matching the address field data in the collaborative screening hash table and the quintuple field data of the target packet, finding the second candidate quintuple rules in the collaborative screening hash table includes:
[0127] S501, according to the quintuple combination template and the quintuple field data, determine the packet field data corresponding to the quintuple combination template.
[0128] Among them, the packet field data refers to the field data in the quintuple field data of the target packet that matches the quintuple combination template.
[0129] In the embodiments of the present application, for any five-tuple combination template, the five-tuple field data is substituted into the five-tuple combination template to obtain the message field data corresponding to the five-tuple combination template. For example, the five-tuple field data of the target message is 1.1.1.1 + 2.2.2.2 + 1000 + 2000 + 4 (SIP + DIP + SPORT + DPORT + PROTO), and the five-tuple combination template is SIP + DIP + SPORT, then the message field data corresponding to the five-tuple combination template is 1.1.1.1 + 2.2.2.2 + 1000.
[0130] S502. Determine the storage location of the second candidate five-tuple rule according to the hash value of the message field data.
[0131] After obtaining the message field data corresponding to the five-tuple combination template, calculate the hash value of the message field data to determine the storage location of the second candidate five-tuple rule according to the hash value.
[0132] Among them, the way to calculate the hash value of the message field data can still use the aforementioned hash algorithm to perform hash calculation on the message field data to obtain the hash value of the message field data. After obtaining the hash value of the message field data, determine the hash bucket corresponding to the hash value according to the hash value, and determine the hash bucket as the storage location of the second candidate five-tuple rule.
[0133] S503. Obtain the second candidate five-tuple rule from the collaborative screening hash table according to the storage location.
[0134] After determining the storage location of the second candidate five-tuple rule, obtain the second candidate five-tuple rule from the storage location.
[0135] Exemplarily, the way to obtain the second candidate five-tuple rule from the collaborative screening hash table according to the storage location can be to obtain all the five-tuple rules at the storage location according to the storage location of the second candidate five-tuple rule, and determine all the obtained five-tuple rules as the second candidate five-tuple rules.
[0136] Exemplarily, the way to obtain the second candidate five-tuple rule from the collaborative screening hash table according to the storage location can be to obtain all the five-tuple rules at the storage location according to the storage location of the second candidate five-tuple rule, and then compare each five-tuple rule with the message field data. If a certain five-tuple rule is the same as the message field data, determine the five-tuple rule as the second candidate five-tuple rule.
[0137] In the method for finding rules of a message provided by the embodiment of the present application, first, according to the five-tuple combination template and the five-tuple field data, the message field data corresponding to the five-tuple combination template is determined. Then, according to the hash value of the message field data, the storage location of the second candidate five-tuple rule is determined. After that, according to the storage location, the second candidate five-tuple rule is obtained from the collaborative screening hash table. In this method, by substituting the five-tuple field data into the five-tuple combination template, the message field data matching the five-tuple combination template is obtained. Thus, based on the hash value of the message field data, the storage location of the second candidate five-tuple rule is quickly determined, and the second candidate five-tuple rule is obtained from this storage location. Equivalently, through the five-tuple combination template and the five-tuple field data, the message field data that can quickly locate the second candidate five-tuple rule is obtained, and thus the storage location of the second candidate five-tuple rule is quickly determined based on the hash value of the message field data, improving the search efficiency of the second candidate five-tuple rule.
[0138] Based on the above embodiment, an embodiment is provided to illustrate the process of obtaining the second candidate five-tuple rule.
[0139] In an exemplary embodiment, as Figure 6 shown, obtaining the second candidate five-tuple rule from the collaborative screening hash table according to the storage location includes:
[0140] S601, according to the storage location, obtain multiple five-tuple rules at the storage location.
[0141] When obtaining the second candidate five-tuple rule according to the storage location, first obtain all the five-tuple rules stored at this storage location from this storage location.
[0142] S602, compare each five-tuple rule with the message field data, and determine the five-tuple rules that are the same as the message field data among the five-tuple rules as the second candidate five-tuple rules.
[0143] After obtaining all the five-tuple rules at this storage location, compare each five-tuple rule with the message field data, and determine the five-tuple rules that are the same as the message field data among the five-tuple rules as the second candidate five-tuple rules.
[0144] In the method for finding rules of packets provided by the embodiments of the present application, first, according to the storage location, a plurality of five-tuple rules at the storage location are obtained. Then, each five-tuple rule is compared with the packet field data, and the five-tuple rules that are the same as the packet field data in each five-tuple rule are determined as the second candidate five-tuple rules. In this method, when obtaining the second candidate five-tuple rules from the storage location of the second candidate five-tuple rules, first, all the five-tuple rules stored at this location are obtained from the storage location, and then the five-tuple rules that are the same as the packet field data are screened out from these five-tuple rules as the second candidate five-tuple rules. Equivalently, after obtaining the five-tuple rules based on the storage location, further screening is performed based on the matching of the complete field data of the five-tuple rules, making the screened second candidate five-tuple rules more accurate and improving the screening accuracy of the second candidate five-tuple rules.
[0145] Based on any of the foregoing embodiments, an embodiment is provided to illustrate the process of determining the address field data described above.
[0146] In an exemplary embodiment, as Figure 7 shown, before searching for the first candidate five-tuple rules in the preliminary screening hash table according to the address field data of the target packet, the method further includes:
[0147] S701, parse the target packet to obtain the five-tuple field data of the target packet.
[0148] In the embodiments of the present application, the computer device parses the target packet to obtain the five-tuple field data of the target packet.
[0149] Exemplarily, through a network monitoring tool or a network interface, the packet data flowing through the network is obtained, and then the IP header is extracted from the packet to obtain the source IP address and the destination IP address, so as to obtain the source IP field data and the destination IP field data in the five-tuple field data. Then, the transport layer protocol type is determined from the protocol field of the IP header, and the protocol number field data in the five-tuple field data is determined according to the transport layer protocol type. Then, according to the protocol field of the IP header, the transport layer header is extracted, and the source port and the destination port are obtained from the transport layer header, so as to obtain the source port number field data and the destination port number field data in the five-tuple field data.
[0150] S702, according to the five-tuple field data of the target packet, obtain the source address field data and the destination address field data in the five-tuple field data.
[0151] Among them, the source address field data refers to the source IP address field data in the five-tuple field data, and the destination address field data refers to the destination IP address field data in the five-tuple field data.
[0152] After obtaining the five-tuple field data of the target packet, obtain the source IP address field data from the five-tuple field data as the source address field data, and obtain the destination IP address field data from the five-tuple field data as the destination address field data.
[0153] S703, determine the source address field data and the destination address field data as the address field data of the target packet.
[0154] After obtaining the source address field data and the destination address field data, determine the source address field data and the destination address field data as the address field data of the target packet.
[0155] In the method for finding rules of packets provided by the embodiments of the present application, by parsing the target packet, the five-tuple field data of the target packet is obtained. Then, according to the five-tuple field data of the target packet, the source address field data and the destination address field data in the five-tuple field data are obtained. After that, the source address field data and the destination address field data are determined as the address field data of the target packet. In this method, after receiving the target packet, by parsing the target packet, the five-tuple field data included therein is obtained, and the source IP address field data and the destination IP address field data are obtained from the five-tuple field data as the address field data of the target packet, providing data support for the rule screening of the target packet.
[0156] Based on any of the foregoing embodiments, an embodiment is provided to illustrate the process of adding rules to the above hash table.
[0157] In an exemplary embodiment, as Figure 8 shown, the method further includes:
[0158] S801, in response to the addition request of the target five-tuple rule, obtain the five-tuple field data of the target five-tuple rule.
[0159] As mentioned above, both the preliminary screening hash table and the collaborative screening hash table store five-tuple rules. Therefore, when receiving the target five-tuple rule, it is necessary to determine whether the target five-tuple rule is stored in the preliminary screening hash table or the collaborative screening hash table, and the storage location of the target five-tuple rule.
[0160] In the embodiments of the present application, in response to the addition request of the target five-tuple rule, first obtain the five-tuple field data of the target five-tuple rule, that is, obtain the actual content corresponding to each five-tuple field.
[0161] Exemplarily, the addition request of the target five-tuple rule carries the target five-tuple rule and the five-tuple fields corresponding to each element in the target five-tuple rule. After receiving the addition request of the target five-tuple rule, obtain the five-tuple fields corresponding to each element in the target five-tuple rule from the information carried in the addition request, and then match the five-tuple fields with the corresponding elements to obtain the five-tuple field data of the target five-tuple rule. For example, if the target five-tuple rule is 1.1.1.1+1000+17, the five-tuple field of 1.1.1.1 carried in the addition request of the target five-tuple rule is SIP, the five-tuple field of 1000 is SPORT, and the five-tuple field of 17 is PROTO. Then match each five-tuple field with the corresponding element, and the data of the SIP field in the five-tuple field data is 1.1.1.1, the data of the SPORT field is 1000, and the data of the PROTO field is 17.
[0162] S802, add the target five-tuple rule to the rule storage hash table according to the five-tuple field data of the target five-tuple rule.
[0163] After obtaining the five-tuple field data of the target five-tuple rule, add the target five-tuple rule to the rule storage hash table according to the five-tuple field data.
[0164] Among them, the rule storage hash table includes a preliminary screening hash table and a collaborative screening hash table. Exemplarily, when adding the target five-tuple rule to the rule storage hash table, the target five-tuple rule can be added to the preliminary screening hash table or the collaborative screening hash table based on the characteristics of the five-tuple rules stored in the preliminary screening hash table and the collaborative screening hash table respectively. For example, only the five-tuple rules including address field data and port field data are stored in the preliminary screening hash table, and any five-tuple rules can be stored in the collaborative screening hash table without restricting the fields included in the five-tuple rules. Then when storing the target five-tuple rule, determine whether the target five-tuple rule is stored in the preliminary screening hash table or the collaborative screening hash table based on the field data included in the target five-tuple rule.
[0165] In the method for finding rules of a message provided in the embodiments of the present application, in response to the addition request of the target five-tuple rule, obtain the five-tuple field data of the target five-tuple rule, and then add the target five-tuple rule to the rule storage hash table according to the five-tuple field data of the target five-tuple rule. In this method, when receiving the addition request of the target five-tuple rule, first obtain the five-tuple field data of the target five-tuple rule, and then add the target five-tuple rule to the rule storage hash table that stores the five-tuple rules based on the five-tuple field data, providing an optional way for quickly adding five-tuple rules, thus laying a data foundation for finding the five-tuple rules of the target message.
[0166] Based on the above embodiments, an embodiment for the addition process of the above target five-tuple rule is provided for illustration.
[0167] In an exemplary embodiment, as Figure 9 shown, the rule storage hash table includes a preliminary screening hash table; adding the target five-tuple rule to the rule hash table according to the five-tuple field data of the target five-tuple rule includes:
[0168] S901, look up the preliminary screening hash table according to the address field data in the five-tuple field data.
[0169] In the embodiment of the present application, when storing the target five-tuple rule, first look up in the preliminary screening hash table according to the address field data in the five-tuple field data of the target five-tuple rule to determine whether there is a five-tuple rule in the preliminary screening hash table whose address field data of the five-tuple rule is the same as that of the target five-tuple rule, so as to provide a judgment basis for the storage location of the target five-tuple rule.
[0170] S902, if there is no candidate five-tuple rule in the preliminary screening hash table whose address field data of the five-tuple rule is the same as that of the target five-tuple rule, add the target five-tuple rule to the preliminary screening hash table; if there is a candidate five-tuple rule in the preliminary screening hash table, add the target five-tuple rule according to the candidate five-tuple rule.
[0171] If there is no candidate five-tuple rule in the preliminary screening hash table whose address field data of the five-tuple rule is the same as that of the target five-tuple rule, add the target five-tuple rule to the preliminary screening hash table; if there is a five-tuple rule in the preliminary screening hash table whose address field data of the five-tuple rule is the same as that of the target five-tuple rule, add the target five-tuple rule according to the candidate five-tuple rule.
[0172] Among them, the determination method of whether there is a candidate five-tuple rule in the preliminary screening hash table whose address field data of the five-tuple rule is the same as that of the target five-tuple rule is to calculate the hash value of the address field data of the target five-tuple rule, determine the storage location corresponding to the hash value according to the hash value, obtain all the five-tuple rules at the storage location, and compare the address field data of each five-tuple rule with the address field data of the target five-tuple rule to determine whether there is a candidate five-tuple rule in the preliminary screening hash table whose address field data of the five-tuple rule is the same as that of the target five-tuple rule.
[0173] In the method for finding rules of packets provided by the embodiments of the present application, by searching the preliminary screening hash table according to the address field data in the five-tuple field data, if there is no candidate five-tuple rule in the preliminary screening hash table whose address field data of the five-tuple rule is the same as that of the target five-tuple rule, the target five-tuple rule is added to the preliminary screening hash table. If there is a candidate five-tuple rule in the preliminary screening hash table, the target five-tuple rule is added according to the candidate five-tuple rule. In this method, first, according to the address field data in the five-tuple field data of the target five-tuple rule, search in the preliminary screening hash table. If there is no five-tuple rule in the preliminary screening hash table whose address field data is the same as that of the target five-tuple rule, the target five-tuple rule is directly added to the preliminary screening hash table. Otherwise, based on the five-tuple rule whose address field data is the same as that of the target five-tuple rule, the target five-tuple rule is added. Equivalently, first determine whether the target five-tuple rule belongs to the five-tuple rules in the preliminary screening hash table. If so, it is directly stored in the preliminary screening hash table. If not, it is stored based on other methods. In this way, the storage efficiency of the target five-tuple rule is improved, and thus the rule storage performance is improved.
[0174] Based on the above embodiments, another embodiment is provided to illustrate the process of adding the target five-tuple rule.
[0175] In an exemplary embodiment, the rule storage hash table further includes a collaborative screening hash table; adding the target five-tuple rule according to the candidate five-tuple rule and the target five-tuple rule includes:
[0176] If the candidate five-tuple rule is the same as the target five-tuple rule, the addition of the target five-tuple rule ends; if the candidate five-tuple rule is different from the target five-tuple rule, query the collaborative screening hash table according to the target five-tuple rule, and complete the addition of the target five-tuple rule.
[0177] In the embodiments of the present application, the candidate five-tuple rule is compared with the target five-tuple rule. If the candidate five-tuple rule is the same as the target five-tuple rule, it means that the target five-tuple rule exists in the preliminary screening hash table, and the addition of the target five-tuple rule ends.
[0178] If the candidate five-tuple rule is different from the target five-tuple rule, it indicates that the target five-tuple rule does not exist in the preliminary screening hash table, and only the five-tuple rules with the same address field data as the target five-tuple rule exist. Then, search in the collaborative screening hash table according to the target five-tuple rule and complete the addition of the target five-tuple rule. Exemplarily, compare the five-tuple rules in the collaborative screening hash table with the target five-tuple rule. If there is a five-tuple rule in the collaborative screening hash table that is the same as the target five-tuple rule, there is no need to store the target five-tuple rule again. If there is no five-tuple rule in the collaborative screening hash table that is the same as the target five-tuple rule, store the target five-tuple rule in the collaborative screening hash table.
[0179] In the method for finding rules of a message provided in the embodiments of the present application, if the candidate five-tuple rule is the same as the target five-tuple rule, the addition of the target five-tuple rule ends; if the candidate five-tuple rule is different from the target five-tuple rule, query the collaborative screening hash table according to the target five-tuple rule and complete the addition of the target five-tuple rule. In this method, compare the candidate five-tuple rule with the target five-tuple rule. When the candidate five-tuple rule is the same as the target five-tuple rule, it indicates that the target five-tuple rule has been stored in the preliminary screening hash table, and the storage of the target five-tuple rule ends; when the candidate five-tuple rule is different from the target five-tuple rule, it indicates that the target five-tuple rule is not stored in the preliminary screening hash table, and further search in the collaborative screening hash table to complete the addition of the target five-tuple rule, making the storage of the target five-tuple rule more detailed, improving the storage accuracy of the target five-tuple rule, and thus improving the search accuracy of the five-tuple rule.
[0180] Based on the above embodiments, another embodiment is provided to illustrate the process of adding the target five-tuple rule.
[0181] In an exemplary embodiment, querying the collaborative screening hash table according to the target five-tuple rule and completing the addition of the target five-tuple rule includes:
[0182] If the target five-tuple rule exists in the collaborative screening hash table, the addition of the target five-tuple rule ends; if the target five-tuple rule does not exist in the collaborative screening hash table, add the target five-tuple rule to the collaborative screening hash table and update the template count of the five-tuple combination template of the target five-tuple rule.
[0183] In the embodiment of the present application, if it is determined that there is a target five-tuple rule in the collaborative screening hash table, it means that the target five-tuple rule is stored in the collaborative screening hash table, and then the addition of the target five-tuple rule is ended; if it is determined that there is no target five-tuple rule in the collaborative screening hash table, it means that the target five-tuple rule is not stored in the collaborative screening hash table, then the target five-tuple rule is added to the collaborative screening hash table, and the template count of the five-tuple combination template of the target five-tuple rule is updated, that is, the template count of the five-tuple combination template of the target five-tuple rule is incremented by 1, so as to provide a data basis for obtaining the five-tuple combination template when looking up the five-tuple rule.
[0184] Exemplarily, the way to determine whether there is a target five-tuple rule in the collaborative screening hash table can be to calculate the hash value of the target five-tuple rule, obtain all the five-tuple rules in the storage location corresponding to this hash value, and then compare each five-tuple rule with the target five-tuple rule. If there is a five-tuple rule identical to the target five-tuple rule, it is determined that there is a target five-tuple rule in the collaborative screening hash table, otherwise not.
[0185] In the method for looking up the rules of the message provided by the embodiment of the present application, if there is a target five-tuple rule in the collaborative screening hash table, the addition of the target five-tuple rule is ended; if there is no target five-tuple rule in the collaborative screening hash table, the target five-tuple rule is added to the collaborative screening hash table, and the template count of the five-tuple combination template of the target five-tuple rule is updated. In this method, when querying the collaborative screening hash table according to the target five-tuple rule, it is determined whether there is a target five-tuple rule in the collaborative screening hash table. If there is, there is no need to store the target five-tuple rule again, and the storage of the target five-tuple rule is ended. If not, the target five-tuple is stored in the collaborative screening hash table to complete the addition of the target five-tuple rule, so that the target five-tuple rule can be stored quickly and accurately in the corresponding position, improving the storage accuracy of the target five-tuple rule.
[0186] Based on any of the foregoing embodiments, an embodiment of the deletion process of the target five-tuple rule is provided for description.
[0187] In an exemplary embodiment, as Figure 10 shown, the method further includes:
[0188] S1001, in response to a deletion request for the target five-tuple rule, obtain the five-tuple field data of the target five-tuple rule.
[0189] In the embodiment of the present application, in response to a deletion request for the target five-tuple rule, first obtain the five-tuple field data of the target five-tuple rule, and delete the target five-tuple rule based on this five-tuple field data. Among them, the way to obtain the five-tuple field data of the target five-tuple rule can refer to the foregoing embodiments and will not be elaborated here.
[0190] S1002. Delete the target five-tuple rule from the rule storage hash table according to the five-tuple field data of the target five-tuple rule.
[0191] Exemplarily, the method of deleting the target five-tuple rule from the rule storage hash table according to the five-tuple field data of the target five-tuple rule may be to search the preliminary screening hash table according to the address field data in the five-tuple field data. If there is no candidate five-tuple rule in the preliminary screening hash table whose address field data is the same as the address field data of the five-tuple rule, then end the deletion of the target five-tuple rule. If there is a candidate five-tuple rule in the preliminary screening hash table, then delete the target five-tuple rule according to the candidate five-tuple rule and the target five-tuple rule.
[0192] Among them, the method of deleting the target five-tuple rule according to the candidate five-tuple rule and the target five-tuple rule may be to compare the candidate five-tuple rule with the target five-tuple rule. If the candidate five-tuple rule is the same as the target five-tuple rule, then delete the target five-tuple rule from the preliminary screening hash table; if the candidate five-tuple rule is different from the target five-tuple rule, then query the collaborative screening hash table according to the target five-tuple rule and complete the deletion of the target five-tuple rule.
[0193] When querying the collaborative screening hash table according to the target five-tuple rule, if the target five-tuple rule exists in the collaborative screening hash table, then delete the target five-tuple rule from the collaborative screening hash table and update the template count of the five-tuple combination template of the target five-tuple rule, that is, subtract 1 from the template count of the five-tuple combination template of the target five-tuple rule. If the target five-tuple rule does not exist in the collaborative screening hash table, then end the deletion of the target five-tuple rule.
[0194] In the method for finding rules of packets provided in the embodiments of the present application, in response to a deletion request for a target five-tuple rule, obtain the five-tuple field data of the target five-tuple rule, and then delete the target five-tuple rule from the rule storage hash table according to the five-tuple field data of the target five-tuple rule. In this method, when receiving a deletion request for a target five-tuple rule, first obtain the five-tuple field data of the target five-tuple rule, and then based on the five-tuple field data, delete the target five-tuple rule from the rule storage hash table that stores the five-tuple rules, providing an optional way for quickly deleting five-tuple rules.
[0195] In addition, in an exemplary embodiment, an embodiment of the process of finding five-tuple rules in the embodiments of the present application is described.
[0196] Among the 31 combination templates of the five-tuple, 24 of them have SIP or DIP fields. The embodiments of the present application can optimize the number of rule lookups for IP five-tuples, that is, those with SIP or DIP fields.
[0197] The rules use two hash tables to store data, and the hash tables can ensure the efficiency of single lookup. The management methods of the two hash tables can optimize the number of lookups. An IP five-tuple rule is an entry in the hash table. The two hash tables are as Figure 11 shown, one is Table A (preliminary screening hash table), and the other is Table B (collaborative screening hash table).
[0198] The selection method of SIP or DIP is shown in Table 2 below. When the entry data only has the SIP field, the SIP field is selected; when the entry data only has the DIP field, the DIP field is selected; when the entry data has both SIP and DIP fields, for the 4 templates such as SIP+DIP, SIP+DIP+SPORT, SIP+DIP+SPORT+PROTO, and SIP+DIP+SPORT+DPORT, the SIP field is selected, and for the other 4 templates SIP+DIP+PROTO, SIP+DIP+DPORT, SIP+DIP+DPORT+PROTO, and SIP+DIP+SPORT+DPORT+PROTO, the DIP field is selected.
[0199] Table 2
[0200]
[0201] For Table A (such as Figure 12 ), the hash values of all entries (rules) are calculated using SIP or DIP as data. The entries in Table A have two meanings. One is as the rule itself, indicating the same entry when the fields corresponding to the entry template are equal; the other is as the head node of the entries with the same SIP or DIP. When the corresponding SIP or DIP fields are equal, it indicates the same entry. The entries in Table A consist of three parts: (1) Rule data: including the values of the five-tuple, valid template values, rule action data, etc. (2) Linked list node: connecting entries with the same SIP or DIP. When the head node is deleted, if there are other rules with the same SIP or DIP on the linked list, one of the other rules on the linked list is selected as the head node. (3) Template count: recording the number of other template entries with the same SIP or DIP fields. For Table B (such as Figure 13 ), the hash value is calculated using the actual data of the entry, that is, the hash value is calculated using the corresponding fields according to what template the rule entry is. When all the fields corresponding to the entry template in Table B are equal, it indicates the same entry. The entries in Table B consist of two parts: (1) Rule data: including the values of the five-tuple, valid template values, rule action data, etc. (2) Linked list node: connecting entries with the same SIP or DIP.
[0202] Both rule addition and deletion are triggered by the user. The user adds and deletes rules according to requirements, and the rules are used to determine the behavioral actions of the traffic corresponding to the rules. For example Figure 14 and 15 are the rule addition process and the rule deletion process respectively. The rule query process is as Figure 16 shown. When a packet enters the device, the device parses the packet to obtain the five-tuple fields of the packet: SIP, DIP, SPORT, DPORT, and PROTO, and matches the five-tuple rules according to these five fields. Among them, the matching process as Figure 16 is first executed with the SIP field, and then the same matching process is executed with the DIP field.
[0203] In this embodiment, through the above rule management method, in the best case, the 24 times of IP five-tuple rule queries can be reduced to two times. In the scenario where there are multiple same SIPs or DIPs, the actual template times can also be queried according to the number of rule templates with the same SIP or DIP, without the need to query according to the maximum number of times. There is no need to add redundant rules for filtering, and there is no resource waste. Moreover, the A table and the B table are distinguished in function. They do not necessarily have to be two hash tables, and can also be one hash table, but the functions of the A table and the B table need to be implemented. It can also be three hash tables: the A table of SIP, the A table of DIP, and the B table. It can also be four hash tables: the A table of SIP, the A table of DIP, the B table entry of SIP, and the B table of DIP.
[0204] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps do not necessarily have to be executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily have to be executed at the same moment, but can be executed at different moments. The execution order of these steps or stages does not necessarily have to be sequential, but can be executed alternately or alternately with at least a part of the steps or stages in other steps or other steps.
[0205] Based on the same inventive concept, the embodiments of the present application also provide a packet rule lookup device for implementing the packet rule lookup method involved above. The implementation solutions provided by this device to solve problems are similar to the implementation solutions recorded in the above method. Therefore, the specific limitations in one or more embodiments of the packet rule lookup device provided below can refer to the limitations on the packet rule lookup method in the above text, and will not be repeated here.
[0206] In an exemplary embodiment, as Figure 17 shown, a rule lookup device 1 for packets is provided, including: a preliminary screening module 10, a collaborative screening module 20, and a rule determination module 30, where:
[0207] The preliminary screening module 10 is configured to search for a first candidate five-tuple rule in a preliminary screening hash table according to the address field data of a target packet; the storage location of each five-tuple rule in the preliminary screening hash table is determined according to the hash value of the address field data in each five-tuple rule;
[0208] The collaborative screening module 20 is configured to search for a second candidate five-tuple rule in the collaborative screening hash table according to the five-tuple combination template matching the address field data in the collaborative screening hash table and the five-tuple field data of the target packet; the storage location of each five-tuple rule in the collaborative screening hash table is determined according to the hash value of each five-tuple rule;
[0209] The rule determination module 30 is configured to determine the first candidate five-tuple rule and the second candidate five-tuple rule as the five-tuple rule of the target packet.
[0210] In one embodiment, the above-mentioned preliminary screening module 10 is further configured to:
[0211] Calculate the hash value of the address field data according to the address field data; determine the storage location of the first candidate five-tuple rule according to the hash value of the address field data; obtain the first candidate five-tuple rule from the preliminary screening hash table according to the storage location.
[0212] In one embodiment, the above-mentioned preliminary screening module 10 is further configured to:
[0213] Obtain multiple five-tuple rules at the storage location according to the storage location; compare the address field data of each five-tuple rule with the address field data of the target packet, and determine the five-tuple rule with the same address field data as the target packet among each five-tuple rule as the first candidate five-tuple rule.
[0214] In one embodiment, the above-mentioned collaborative screening module 20 is further configured to:
[0215] Determine the packet field data corresponding to the five-tuple combination template according to the five-tuple combination template and the five-tuple field data; determine the storage location of the second candidate five-tuple rule according to the hash value of the packet field data; obtain the second candidate five-tuple rule from the collaborative screening hash table according to the storage location.
[0216] In one embodiment, the above-mentioned collaborative screening module 20 is further configured to:
[0217] Obtain multiple quintuple rules of the storage location according to the storage location; compare each quintuple rule with the message field data, and determine the quintuple rules that are the same as the message field data in each quintuple rule as the second candidate quintuple rules.
[0218] In one embodiment, the above-mentioned rule lookup device 1 for messages further includes:
[0219] A message parsing module, configured to parse the target message to obtain the quintuple field data of the target message;
[0220] A field data acquisition module, configured to obtain the source address field data and the destination address field data in the quintuple field data according to the quintuple field data of the target message; an address field data determination module, configured to determine the source address field data and the destination address field data as the address field data of the target message.
[0221] In one embodiment, the above-mentioned rule lookup device 1 for messages further includes:
[0222] A quintuple field data acquisition module, configured to obtain the quintuple field data of the target quintuple rule in response to an addition request of the target quintuple rule;
[0223] A rule addition module, configured to add the target quintuple rule to the rule storage hash table according to the quintuple field data of the target quintuple rule.
[0224] In one embodiment, the above-mentioned rule addition module is further configured to:
[0225] Search the preliminary screening hash table according to the address field data in the quintuple field data; if there is no candidate quintuple rule in the preliminary screening hash table whose address field data of the quintuple rule is the same as that of the target quintuple rule, add the target quintuple rule to the preliminary screening hash table; if there is a candidate quintuple rule in the preliminary screening hash table, add the target quintuple rule according to the candidate quintuple rule.
[0226] In one embodiment, the above-mentioned rule addition module is further configured to:
[0227] If the candidate quintuple rule is the same as the target quintuple rule, end the addition of the target quintuple rule; if the candidate quintuple rule is different from the target quintuple rule, query the collaborative screening hash table according to the target quintuple rule, and complete the addition of the target quintuple rule.
[0228] In one embodiment, the above-mentioned rule addition module is further configured to:
[0229] If the target five-tuple rule exists in the collaborative screening hash table, the addition of the target five-tuple rule ends; if the target five-tuple rule does not exist in the collaborative screening hash table, the target five-tuple rule is added to the collaborative screening hash table, and the template count of the five-tuple combination template of the target five-tuple rule is updated.
[0230] Each module in the above message rule lookup device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.
[0231] In an exemplary embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented:
[0232] According to the address field data of the target message, search for the first candidate five-tuple rule in the preliminary screening hash table; the storage location of each five-tuple rule in the preliminary screening hash table is determined according to the hash value of the address field data in each five-tuple rule;
[0233] According to the five-tuple combination template matching the address field data in the collaborative screening hash table and the five-tuple field data of the target message, search for the second candidate five-tuple rule in the collaborative screening hash table; the storage location of each five-tuple rule in the collaborative screening hash table is determined according to the hash value of each five-tuple rule;
[0234] Determine the first candidate five-tuple rule and the second candidate five-tuple rule as the five-tuple rules of the target message.
[0235] For each step implemented by the processor in the embodiments of this application, its implementation principle and technical effects are similar to those of the above message rule lookup method, and will not be elaborated here.
[0236] In an embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0237] According to the address field data of the target message, search for the first candidate five-tuple rule in the preliminary screening hash table; the storage location of each five-tuple rule in the preliminary screening hash table is determined according to the hash value of the address field data in each five-tuple rule;
[0238] According to the five-tuple combination template that matches the address field data in the collaborative filtering hash table and the five-tuple field data of the target message, search for the second candidate five-tuple rule in the collaborative filtering hash table; the storage location of each five-tuple rule in the collaborative filtering hash table is determined according to the hash value of each five-tuple rule;
[0239] Determine the five-tuple rule of the target message by using the first candidate five-tuple rule and the second candidate five-tuple rule.
[0240] The implementation principles and technical effects of the steps implemented when the computer program in the embodiments of the present application is executed by the processor are similar to the principles of the above message rule search method, and will not be elaborated here.
[0241] In one embodiment, a computer program product is provided, including a computer program, which when executed by a processor implements the following steps:
[0242] According to the address field data of the target message, search for the first candidate five-tuple rule in the preliminary filtering hash table; the storage location of each five-tuple rule in the preliminary filtering hash table is determined according to the hash value of the address field data in each five-tuple rule;
[0243] According to the five-tuple combination template that matches the address field data in the collaborative filtering hash table and the five-tuple field data of the target message, search for the second candidate five-tuple rule in the collaborative filtering hash table; the storage location of each five-tuple rule in the collaborative filtering hash table is determined according to the hash value of each five-tuple rule;
[0244] Determine the five-tuple rule of the target message by using the first candidate five-tuple rule and the second candidate five-tuple rule.
[0245] The implementation principles and technical effects of the steps implemented when the computer program in the embodiments of the present application is executed by the processor are similar to the principles of the above message rule search method, and will not be elaborated here.
[0246] It should be noted that the personnel information (including but not limited to personnel device information, personnel personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the personnel or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.
[0247] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memories can include read-only memory (ROM), magnetic tapes, floppy disks, flash memories, optical memories, high-density embedded non-volatile memories, resistive random access memories (ReRAM), magnetoresistive random access memories (MRAM), ferroelectric random access memories (FRAM), phase change memories (PCM), graphene memories, etc. Volatile memories can include random access memory (RAM) or external cache memories, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logics, data processing logics based on quantum computing, etc., without limitation.
[0248] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0249] The above-described embodiments merely represent several implementation manners of the present application. Their descriptions are relatively specific and detailed, but they should not be construed as limiting the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A message rule search method, characterized in that: The method comprises: According to the address field data of the target message, searching for the first candidate five-tuple rule in the preliminary screening hash table; the storage location of each five-tuple rule in the preliminary screening hash table is determined according to the hash value of the address field data in each five-tuple rule; According to the five-tuple combination template matching the address field data in the collaborative filtering hash table and the five-tuple field data of the target message, searching the second candidate five-tuple rule in the collaborative filtering hash table; the storage location of each five-tuple rule in the collaborative filtering hash table is determined according to the hash value of each five-tuple rule; The first candidate five-tuple rule and the second candidate five-tuple rule are determined as the five-tuple rule of the target message.
2. The method according to claim 1, characterized in that The step of searching the first candidate five-tuple rule in the preliminary screening hash table according to the address field data of the target message includes: Calculate a hash value of the address field data according to the address field data; Determining a storage location of the first candidate 5-tuple rule according to a hash value of the address field data; According to the storage location, the first candidate five-tuple rule is obtained from the preliminary screening hash table.
3. The method according to claim 2, characterized in that The obtaining the first candidate five-tuple rule from the preliminary screening hash table according to the storage location includes: According to the storage location, obtaining a plurality of five-tuple rules of the storage location; The address field data of each of the five-tuple rules is compared with the address field data of the target message, and the five-tuple rules in which the address field data of each of the five-tuple rules is the same as the address field data of the target message are determined as the first candidate five-tuple rules.
4. The method according to any one of claims 1 to 3, characterized in that: The searching for a second candidate five-tuple rule in the collaborative screening hash table according to the five-tuple combination template matching the address field data in the collaborative screening hash table and the five-tuple field data of the target message includes: Determining the message field data corresponding to the quintuple combination template according to the quintuple combination template and the quintuple field data; Determining a storage location of the second candidate 5-tuple rule according to a hash value of the message field data; According to the storage location, the second candidate 5-tuple rule is obtained from the collaborative screening hash table.
5. The method according to claim 4, characterized in that The acquiring the second candidate five-tuple rule from the collaborative screening hash table according to the storage location includes: According to the storage location, obtaining a plurality of five-tuple rules of the storage location; Compare each of the five-tuple rules with the message field data, and determine the five-tuple rule that is the same as the message field data among the five-tuple rules as the second candidate five-tuple rule.
6. The method according to any one of claims 1 to 3, characterized in that: Before searching the first candidate five-tuple rule in the preliminary screening hash table according to the address field data of the target message, the method further includes: Parsing the target message to obtain quintuple field data of the target message; According to the five-tuple field data of the target message, the source address field data and the destination address field data in the five-tuple field data are obtained; The source address field data and the destination address field data are determined as the address field data of the target message.
7. The method according to any one of claims 1 to 3, characterized in that: The method further comprises: In response to a request to add a target five-tuple rule, obtaining five-tuple field data of the target five-tuple rule; According to the quintuple field data of the target quintuple rule, the target quintuple rule is added to the rule storage hash table.
8. The method according to claim 7, characterized in that The rule storage hash table includes a preliminary screening hash table; the adding the target five-tuple rule to the rule hash table according to the five-tuple field data of the target five-tuple rule includes: Searching the preliminary screening hash table according to the address field data in the five-tuple field data; If there is no candidate five-tuple rule in the preliminary screening hash table whose address field data is the same as the address field data of the target five-tuple rule, then adding the target five-tuple rule to the preliminary screening hash table; If the candidate five-tuple rule exists in the preliminary screening hash table, the target five-tuple rule is added according to the candidate five-tuple rule.
9. The method according to claim 8, characterized in that The rule storage hash table also includes a collaborative screening hash table; and adding the target five-tuple rule according to the candidate five-tuple rule includes: If the candidate five-tuple rule is the same as the target five-tuple rule, then the addition of the target five-tuple rule is terminated; If the candidate five-tuple rule is different from the target five-tuple rule, the collaborative screening hash table is queried according to the target five-tuple rule, and the target five-tuple rule is added.
10. The method according to claim 9, characterized in that The querying the collaborative screening hash table according to the target five-tuple rule and completing the adding of the target five-tuple rule includes: If the target five-tuple rule exists in the collaborative screening hash table, then ending the addition of the target five-tuple rule; If the target five-tuple rule does not exist in the collaborative filtering hash table, the target five-tuple rule is added to the collaborative filtering hash table, and the template count of the five-tuple combination template of the target five-tuple rule is updated.
Citation Information
Cited By
Multi-template quintuple rule matching method and device based on FPGA
CN121357147A
FPGA-based multi-template quintuple rule matching method and device
CN121357147B