Network traffic processing method and device, electronic equipment and medium

By using LLDP messages to pass authorization information between security devices and gateway devices, the shortcomings of traditional network architecture in the security management of interactive messages between intranets are solved, and normal traffic forwarding is achieved under abnormal security device license states to ensure business continuity.

CN120200835AActive Publication Date: 2025-06-24NEW H3C TECH CO LTD
View PDF 13 Cites 0 Cited by

Patent Information

Application Number
CN202510561559.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-06-24
Estimated Expiration
2045-04-30

AI Technical Summary

Technical Problem

Traditional network architectures have shortcomings in the security management of interactive messages between intranets, especially in the abnormal license state of security equipment, which may cause traffic to be forwarded normally, resulting in service failure.

Method used

By using Link Layer Discovery Protocol (LLDP) messages between security devices and gateway devices, authorization information is passed, so that gateway devices can detect the effectiveness of authorization information in a timely manner and adjust the forwarding strategy based on the detection results.

Benefits of technology

It realizes that in the abnormal state of security equipment license, timely adjusts the forwarding strategy to ensure normal forwarding of network traffic and avoid business failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200835A_ABST
    Figure CN120200835A_ABST
Patent Text Reader

Abstract

The invention provides a network traffic processing method and device, electronic equipment and a medium. The method comprises the following steps that: security equipment sends a link layer discovery protocol (LLDP) message to gateway equipment, wherein the LLDP message comprises authorization information; the gateway device receives an LLDP message sent by the security device, and detects the validity of the authorization information; if the authorization information passes the detection, a target forwarding strategy is configured, and the target forwarding strategy is used for indicating that the service flow received by the corresponding interface is redirected to the security equipment; if the service traffic is received through the corresponding interface, redirecting the service traffic to the security device according to the target forwarding strategy; the security device receives the service traffic redirected by the gateway device; and performing security check on the service flow.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of communication technologies, and in particular, to methods, devices, electronic devices, and media for network traffic processing. Background Art

[0002] Currently, users have increasingly high requirements for network security. To manage the network-wide traffic, the traditional approach is to deploy security devices at the network egress. This architecture can effectively protect against attacks between the internal and external networks, but it cannot guarantee the security of the interactive messages between the internal networks. For this reason, some users will deploy security devices in the internal network to monitor the internal traffic.

[0003] However, in the actual usage scenario, the security device needs a license to perform message inspection and processing. When the license is in an abnormal state such as invalidation, failure, or expiration, the messages in the network can reach the gateway device normally. When the gateway device detects the reachability of the message according to the routing rules and finds that the layer 2 is reachable, it considers that the routing rules take effect and will then redirect the traffic to the security device. Since the license is in an abnormal state, the security device will discard all the traffic, resulting in the inability to forward the traffic and further causing the business to fail. Summary of the Invention

[0004] To overcome the problems existing in the related technologies, this specification provides methods, devices, electronic devices, and media for network traffic processing.

[0005] According to the first aspect of the embodiments of this specification, a network traffic processing method is provided, which is applied to a security device. The method includes: sending a Link Layer Discovery Protocol (LLDP) message to a gateway device, where the LLDP message includes authorization information; receiving the service traffic redirected by the gateway device; and performing a security check on the service traffic.

[0006] According to the second aspect of the embodiments of this specification, a network traffic processing method is provided, which is applied to a gateway device. The method includes: receiving an LLDP message sent by a security device, where the LLDP message includes authorization information; detecting the validity of the authorization information; if the authorization information passes the detection, configuring a target forwarding policy, where the target forwarding policy is used to indicate redirecting the service traffic received by the corresponding interface to the security device; and if service traffic is received through the corresponding interface, redirecting the service traffic to the security device according to the target forwarding policy.

[0007] According to a third aspect of the embodiments of the present specification, a network traffic processing device is provided, including: a first sending module, configured to send Link Layer Discovery Protocol (LLDP) packets to a gateway device, where the LLDP packets include authorization information; a first receiving module, configured to receive service traffic redirected by the gateway device; and an inspection module, configured to perform security inspection on the service traffic.

[0008] According to a fourth aspect of the embodiments of the present specification, a network traffic processing device is provided, including: a second receiving module, configured to receive LLDP packets sent by a security device, where the LLDP packets include authorization information; a verification module, configured to detect the validity of the authorization information; a configuration module, configured to configure a target forwarding policy if the authorization information passes the detection, where the target forwarding policy is used to indicate redirecting service traffic received on a corresponding interface to the security device; and a redirection module, configured to, if service traffic is received on a corresponding interface, redirect the service traffic to the security device according to the target forwarding policy.

[0009] According to a third aspect of the embodiments of the present specification, an electronic device is provided, including:

[0010] a processor;

[0011] a memory for storing executable instructions of the processor;

[0012] wherein the processor is configured to execute the network traffic processing method according to the first aspect or any corresponding embodiment thereof.

[0013] According to a fourth aspect of the embodiments of the present specification, a computer-readable storage medium is provided, on which computer instructions are stored, and the computer instructions are used to cause a computer to execute the network traffic processing method according to the first aspect or any corresponding embodiment thereof.

[0014] The technical solutions provided by the embodiments of the present specification may include the following beneficial effects:

[0015] In the embodiments of the present specification, the security device informs the gateway device of the authorization information through LLDP packets, so that the gateway device can timely detect the validity of the authorization information and timely adjust the forwarding policy according to the detection result, so that the traffic can be normally forwarded and the user service can be guaranteed to be normal.

[0016] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present specification. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The accompanying drawings here are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with this specification, and are used together with the specification to explain the principles of this specification.

[0018] Figure 1 It is a schematic diagram of the system architecture shown according to an exemplary embodiment of this specification.

[0019] Figure 2 It is a flowchart of a network traffic processing method shown according to an exemplary embodiment of this specification.

[0020] Figure 3 It is a hardware structure diagram of the computer device where the network traffic processing device in the embodiment of this specification is located.

[0021] Figure 4 It is a block diagram of a network traffic processing device shown according to an exemplary embodiment of this specification.

[0022] Figure 5 It is a block diagram of another network traffic processing device shown according to an exemplary embodiment of this specification. Detailed implementation manners

[0023] Here, the exemplary embodiments will be described in detail, and the examples are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with this specification. On the contrary, they are merely examples of devices and methods consistent with some aspects of this specification as detailed in the appended claims.

[0024] The terms used in this specification are only for the purpose of describing specific embodiments and are not intended to limit this specification. The singular forms "a", "the", and "said" used in this specification and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more of the associated listed items.

[0025] It should be understood that although the terms first, second, third, etc. may be used in this specification to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of this specification, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".

[0026] Next, the embodiments of this specification will be described in detail.

[0027] The following Figure 1 describes the system architecture of the system that can apply the network traffic processing method and device in the embodiments of this specification. It should be noted that Figure 1 the figure shown is only an example of the system architecture that can apply the embodiments of this specification, to help those skilled in the art understand the technical content of this specification, but it does not mean that the embodiments of this specification cannot be used in other devices, systems, environments or scenarios.

[0028] Figure 1 is a schematic diagram of the system architecture shown according to an exemplary embodiment of this specification.

[0029] As Figure 1 shown, the system architecture may include, for example, an AC (Access Controller), an AP (Access Point), an access switch, a core switch, and a security device.

[0030] According to the embodiments of this specification, the AP can be used to transmit wireless signals (such as Wi-Fi signals) and connect to terminal devices (such as mobile phones, laptops, etc.). The access switch can be used to provide POE (Power Over Ethernet). The core switch can be used as a gateway device and can provide data conversion services between multiple networks. For example, it can provide data conversion services between a local area network and the Internet. Optionally, the core switch can also be used as a DHCP server to assign IP addresses to the APs.

[0031] According to the embodiments of this specification, the security device can be used to detect and filter traffic. The security device may include, for example, a firewall, an Intrusion Detection System (IDS), an Intrusion Prevention System (IPS), etc. The gateway device can be used for traffic routing and forwarding, guiding traffic to pass through the security device for detection and filtering.

[0032] According to the embodiments of this specification, the security device can be deployed as an independent device on the bypass of the gateway device, and all traffic flowing through the gateway (including outbound, inbound, and internal forwarding traffic) can be redirected to the security device for detection through policy routing. After security inspection, the packets are forwarded along the original path.

[0033] Alternatively, the security device can be integrated into the gateway device in the form of a security module. For example, a security software package can be integrated on the gateway device, and after being loaded, the security software package can form a security module. The security module is connected to the physical interface, can automatically obtain the management address through DHCP, automatically generate policy routing rules, and redirect all traffic flowing through the gateway device to the security module for processing.

[0034] The network traffic processing method provided in the embodiments of this specification will be described in detail below. As Figure 2 shown, Figure 2 is a flowchart of a network traffic processing method shown in this specification according to an exemplary embodiment. The network traffic processing method provided in the embodiments of this specification may include the following steps.

[0035] In step S210, the security device sends a Link Layer Discovery Protocol (LLDP) packet to the gateway device, and the LLDP packet includes authorization information.

[0036] According to the embodiments of this specification, the authorization information can indicate whether the security device has the right to perform security checks on the traffic. The authorization information can include, for example, a License.

[0037] In step S220, after receiving the LLDP packet, the gateway device detects the validity of the authorization information.

[0038] According to the embodiments of this specification, the gateway device can, for example, check the status of the authorization information. If the authorization information is in a normal state, it is determined that the authorization information passes the detection. If the authorization information is in an abnormal state such as invalid, faulty, expired, etc., it is determined that the authorization information fails the detection. The status of the authorization information can be provided to the gateway device by the security device or other devices.

[0039] Optionally, a message code can be used to represent the status of the authorization information, and the gateway device can determine the status of the authorization information through the message code of the authorization information.

[0040] In step S230, if the authorization information passes the detection, the gateway device configures a target forwarding policy, and the target forwarding policy is used to indicate redirecting the service traffic received by the corresponding interface to the security device.

[0041] According to the embodiments of this specification, the target forwarding policy can be used to control the forwarding path of the traffic. For example, it can include service traffic information to be matched, actions to be performed after matching, corresponding interfaces to which the policy is applied, etc. By configuring the target forwarding policy, the next-hop address of the corresponding interface can be set to the address of the security device.

[0042] According to the embodiments of this specification, the target forwarding policy can be, for example, a sub-policy of policy routing.

[0043] In step S240, if service traffic is received through the corresponding interface, the gateway device redirects the service traffic to the security device according to the target forwarding policy.

[0044] According to the embodiments of the present specification, when service traffic is received through the corresponding interface, the gateway device can determine whether the service traffic matches the service traffic information in the target forwarding policy. If it matches, the service traffic is sent to the next hop specified in the target forwarding policy, that is, the security device.

[0045] In step S250, after the security device receives the service traffic redirected by the gateway device, it performs a security check on the service traffic.

[0046] According to the embodiments of the present specification, the security check may include, for example, one or more of firewall rule matching, signature matching, anomaly detection, and protocol analysis. It should be noted that the security check may also include other check items, and the present specification does not make specific limitations thereon. After the service traffic passes the security check, the security device forwards the service traffic.

[0047] According to the embodiments of the present specification, the security device notifies the gateway device of the authorization information through an LLDP message, so that the gateway device can timely detect the validity of the authorization information and adjust the forwarding policy in a timely manner according to the detection result, so that the traffic can be normally forwarded and the user service can be guaranteed to be normal.

[0048] Optionally, the LLDP message may include a custom field. The security device can write the authorization information into the custom field in the LLDP message and then send the LLDP message to the gateway device. The gateway device can obtain the authorization information from the custom field of the LLDP message.

[0049] For example, the custom field may be a TLV (Type, Length, Value) field. The Type of the custom field may include the authorization information type, the Value of the custom field may include the content of the authorization information, and the Length of the custom field may include the total length of the custom field.

[0050] Optionally, when the authorization information fails the detection, if the target forwarding policy corresponding to the security device is configured, the gateway device deletes the target forwarding policy. Thus, the problem of service failure caused by forwarding traffic to the security device in the case of abnormal authorization information can be avoided.

[0051] Optionally, when the authorization information fails the detection, the gateway device can generate an exception notification to inform the user that the authorization information is abnormal.

[0052] Optionally, if the authorization information passes the detection and the remaining valid duration of the authorization information is less than the duration threshold, the gateway device starts a timer. The duration threshold can be set according to actual needs. When the timer expires, the target forwarding policy is deleted to stop traffic redirection. The timing duration of the timer is equal to the remaining valid duration minus a preset value. The preset value is greater than or equal to 0 and less than or equal to the remaining valid duration. The preset value can be set according to actual needs.

[0053] By deleting the target forwarding policy when the timer expires, packet loss of service traffic can be avoided and user services can be ensured to proceed normally.

[0054] Optionally, the security device can send a new LLDP message to the gateway device each time the authorization information is updated. The new LLDP message includes the updated authorization information to notify the gateway device to update the authorization information. Similar to the foregoing embodiments, after receiving the new LLDP message, the gateway device can verify the updated authorization information. If the authorization information fails the detection, the target forwarding policy is deleted. If the authorization information passes the detection and the remaining valid duration of the authorization information is less than the duration threshold, the timer is started. The target forwarding policy is deleted when the timer expires.

[0055] Thus, the security device can update the authorization information of the security device in a timely manner and adjust the forwarding policy according to the validity of the authorization information, so as to ensure both the security function in the normal state of the authorization information and the normal user services in the abnormal state of the authorization information.

[0056] Corresponding to the foregoing method embodiments, this specification also provides embodiments of a network traffic processing apparatus and a terminal to which it is applied.

[0057] The embodiments of the network traffic processing apparatus in this specification can be applied to computer devices, such as servers or terminal devices. The apparatus embodiments can be implemented through software, or through hardware or a combination of software and hardware. Taking software implementation as an example, as a logically meaningful apparatus, it is formed by the corresponding computer program instructions in the non-volatile memory being read into the memory and run by the processor where it is located. From a hardware perspective, as Figure 3 shown, it is a hardware structure diagram of the computer device where the network traffic processing apparatus in the embodiments of this specification is located. In addition to Figure 3 the processor 310, memory 330, network interface 320, and non-volatile memory 340 shown, for the server or electronic device where the apparatus 331 is located in the embodiments, usually according to the actual functions of the computer device, other hardware may also be included, which will not be elaborated here.

[0058] As Figure 4 shown, Figure 4The following is a block diagram of a network traffic processing device shown in this specification according to an exemplary embodiment. The device includes:

[0059] A first sending module 410, configured to send a Link Layer Discovery Protocol (LLDP) packet to a gateway device, where the LLDP packet includes authorization information;

[0060] A first receiving module 420, configured to receive service traffic redirected by the gateway device;

[0061] An inspection module 430, configured to perform security inspection on the service traffic.

[0062] Optionally, the LLDP packet includes a custom field; the device may further include:

[0063] A writing module, configured to write the authorization information into the custom field in the LLDP packet.

[0064] Optionally, the device may further include:

[0065] A second sending module, configured to send a new LLDP packet to the gateway device when the authorization information is updated. The new LLDP packet includes the updated authorization information to notify the gateway device to update the authorization information.

[0066] Correspondingly, this specification further provides an electronic device, which includes a processor; and a memory for storing processor-executable instructions. Wherein, the processor is configured to: send a Link Layer Discovery Protocol (LLDP) packet to a gateway device, where the LLDP packet includes authorization information; receive service traffic redirected by the gateway device; perform security inspection on the service traffic.

[0067] As Figure 5 shown, Figure 5 The following is a block diagram of another network traffic processing device shown in this specification according to an exemplary embodiment. The device includes:

[0068] A second receiving module 510, configured to receive an LLDP packet sent by a security device, where the LLDP packet includes authorization information;

[0069] A verification module 520, configured to detect the validity of the authorization information;

[0070] A configuration module 530, configured to configure a target forwarding policy if the authorization information passes the detection. The target forwarding policy is used to indicate redirecting the service traffic received on the corresponding interface to the security device;

[0071] A redirection module 540, configured to redirect the service traffic to the security device according to the target forwarding policy if the service traffic is received through the corresponding interface.

[0072] Optionally, the device may further include:

[0073] A deletion module, configured to delete the target forwarding policy if the target forwarding policy corresponding to the security device is configured when the authorization information fails the detection.

[0074] Optionally, the device may further include:

[0075] A notification module, configured to generate an exception notification when the authorization information fails the detection.

[0076] Optionally, the device may further include:

[0077] A timing module, configured to start a timer if the authorization information passes the detection and the remaining valid duration of the authorization information is less than the duration threshold, and delete the target forwarding policy when the timer expires. The timing duration of the timer is equal to the remaining valid duration minus a preset value.

[0078] Optionally, the LLDP packet includes a custom field that carries authorization information; the device may further include:

[0079] An acquisition module, configured to acquire the authorization information from the custom field of the LLDP packet.

[0080] Correspondingly, this specification also provides an electronic device, which includes a processor; a memory for storing instructions executable by the processor; wherein, the processor is configured to: receive an LLDP packet sent by a security device, the LLDP packet including authorization information; detect the validity of the authorization information; if the authorization information passes the detection, configure a target forwarding policy, the target forwarding policy being used to indicate redirecting the service traffic received on the corresponding interface to the security device; if service traffic is received through the corresponding interface, redirect the service traffic to the security device according to the target forwarding policy.

[0081] According to the embodiments of this specification, the security device informs the gateway device of the authorization information through the LLDP packet, so that the gateway device can timely detect the validity of the authorization information and timely adjust the forwarding policy according to the detection result, so that the traffic can be normally forwarded and the user service can be guaranteed to be normal.

[0082] The implementation processes of the functions and roles of each module in the above device are specifically described in detail in the implementation processes of the corresponding steps in the above method, and will not be elaborated here.

[0083] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the descriptions in the method embodiments. The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the objectives of the solutions in this specification. Those of ordinary skill in the art can understand and implement it without creative efforts.

[0084] The above describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be executed in a different order than in the embodiments and still achieve the desired results. Additionally, the processes depicted in the drawings do not necessarily require the specific order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0085] Those skilled in the art will readily conceive of other embodiments of this specification after considering the specification and practicing the invention herein. This specification is intended to cover any variations, uses, or adaptations of this specification, which follow the general principles of this specification and include common general knowledge or conventional technical means in the technical field not claimed in this application. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of this specification are pointed out by the following claims.

[0086] It should be understood that this specification is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of this specification is only limited by the appended claims.

[0087] The above are only the preferred embodiments of this specification and are not intended to limit this specification. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of this specification shall be included within the scope of protection of this specification.

Claims

1. A network traffic processing method, applied to a security device, characterized in that: The method comprises: Sending a Link Layer Discovery Protocol (LLDP) message to the gateway device, wherein the LLDP message includes authorization information; Receiving service traffic redirected by the gateway device; Perform a security check on the business traffic.

2. The method according to claim 1, characterized in that: The LLDP message includes a custom field; the method further includes: The authorization information is written into a custom field in the LLDP message.

3. The method according to claim 1, characterized in that: The method further comprises: In the case where the authorization information is updated, a new LLDP message is sent to the gateway device, wherein the new LLDP message includes the updated authorization information, so as to notify the gateway device to update the authorization information.

4. A network traffic processing method, applied to a gateway device, characterized in that: The method comprises: Receiving an LLDP message sent by a security device, wherein the LLDP message includes authorization information; Detecting the validity of the authorization information; If the authorization information passes the detection, a target forwarding policy is configured, wherein the target forwarding policy is used to indicate that the service traffic received by the corresponding interface is redirected to the security device; If service traffic is received through the corresponding interface, the service traffic is redirected to the security device according to the target forwarding policy.

5. The method according to claim 4, characterized in that The method further comprises: In the case that the authorization information fails to pass the detection, if a target forwarding policy corresponding to the security device has been configured, the target forwarding policy is deleted.

6. The method according to claim 5, characterized in that The method further comprises: In the event that the authorization information fails the detection, an exception notification is generated.

7. The method according to claim 4, characterized in that The method further comprises: If the authorization information passes the detection and the remaining effective duration of the authorization information is less than the duration threshold, the timer is started, and the target forwarding policy is deleted when the timer expires. The timing duration of the timer is equal to the remaining effective duration minus a preset value.

8. The method according to claim 4, characterized in that The LLDP message includes a custom field, and the custom field carries the authorization information; the method further includes: The authorization information is obtained from a custom field of the LLDP message.

9. A network traffic processing device, characterized in that: The device comprises: A first sending module, configured to send a Link Layer Discovery Protocol (LLDP) message to a gateway device, wherein the LLDP message includes authorization information; A first receiving module, configured to receive the service traffic redirected by the gateway device; The inspection module is used to perform a security inspection on the business traffic.

10. A network traffic processing device, characterized in that: The device comprises: A second receiving module, configured to receive an LLDP message sent by a security device, wherein the LLDP message includes authorization information; A verification module, used to detect the validity of the authorization information; A configuration module, configured to configure a target forwarding policy if the authorization information passes the detection, wherein the target forwarding policy is used to indicate that the service traffic received by the corresponding interface is redirected to the security device; The redirection module is used to redirect the business traffic to the security device according to the target forwarding policy if the business traffic is received through the corresponding interface.

11. An electronic device, comprising: processor; a memory for storing processor-executable instructions; The processor is configured to execute the network traffic processing method according to any one of claims 1 to 8.

12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the network traffic processing method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Method, system and equipment for preventing authentication address resolution protocol information loss

    CN101453495A

  • Method and device for configuring safety strategy

    CN107579988A

  • Link detection method and device, electronic equipment and machine readable storage medium

    CN110120897A

  • Data processing method and device

    CN113938405A

  • Illegal DHCP server positioning method and device, equipment and storage medium

    CN117914554A