Network traffic processing method and apparatus, electronic device, and medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NEW H3C TECH CO LTD
- Filing Date
- 2025-04-30
- Publication Date
- 2026-08-07
AI Technical Summary
而由于license处于异常状态,安全设备会将所有流量丢掉,导致流量无法转发,进而导致业务失败
[0015]本说明书实施例中,安全设备通过LLDP报文告知网关设备授权信息,使得网关设备可以及时检测授权信息的有效性,并根据检测结果及时调整转发策略,从而可以使流量可以正常转发,保证用户业务正常。
Smart Images

Figure CN120200835B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of communication technology, and in particular to network traffic processing methods, devices, electronic equipment, and media. Background Technology
[0002] Currently, users have increasingly higher requirements for network security. To manage network traffic, the traditional approach is to deploy security devices at the network's egress point. This architecture can effectively protect against attacks between internal and external networks, but it cannot guarantee the security of messages exchanged within the internal network. Therefore, some users deploy security devices within their internal network to monitor internal traffic.
[0003] However, in real-world scenarios, security devices require a license to perform packet inspection and processing. If the license is in an invalid, faulty, or expired state, packets in the network can still reach the gateway device normally. When the gateway device checks packet reachability according to routing rules, it finds that Layer 2 is reachable, therefore assumes the routing rules are effective, and redirects traffic to the security device. Because the license is in an abnormal state, the security device will drop all traffic, preventing forwarding and causing service failure. Summary of the Invention
[0004] To overcome the problems existing in related technologies, this specification provides network traffic processing methods, devices, electronic devices, and media.
[0005] According to a first aspect of the embodiments of this specification, a network traffic processing method is provided, applied to a security device, the method comprising: sending a Link Layer Discovery Protocol (LLDP) message to a gateway device, the LLDP message including authorization information; receiving service traffic redirected by the gateway device; and performing a security check on the service traffic.
[0006] According to a second aspect of the embodiments of this specification, a network traffic processing method is provided, applied to a gateway device. The method includes: receiving an LLDP message sent by a security device, the LLDP message including authorization information; detecting the validity of the authorization information; if the authorization information passes the detection, configuring a target forwarding policy, the target forwarding policy being used to instruct the redirection of service traffic received through a corresponding interface to the security device; if service traffic is received through the corresponding interface, redirecting the service traffic to the security device according to the target forwarding policy.
[0007] According to a third aspect of the embodiments of this specification, a network traffic processing apparatus is provided, comprising: a first sending module, configured to send a Link Layer Discovery Protocol (LLDP) message to a gateway device, the LLDP message including authorization information; a first receiving module, configured to receive service traffic redirected by the gateway device; and an inspection module, configured to perform security checks on the service traffic.
[0008] According to a fourth aspect of the embodiments of this specification, a network traffic processing apparatus is provided, comprising: a second receiving module for receiving an LLDP message sent by a security device, the LLDP message including authorization information; a verification module for detecting the validity of the authorization information; a configuration module for configuring a target forwarding policy if the authorization information passes the detection, the target forwarding policy indicating that service traffic received through a corresponding interface is redirected to the security device; and a redirection module for redirecting service traffic received through a corresponding interface to the security device according to the target forwarding policy.
[0009] According to a third aspect of the embodiments of this specification, an electronic device is provided, comprising:
[0010] processor;
[0011] Memory used to store processor-executable instructions;
[0012] The processor is configured to execute the network traffic processing method described in the first aspect or any of its corresponding embodiments.
[0013] According to a fourth aspect of the embodiments of this specification, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions, the computer instructions being configured to cause a computer to perform the network traffic processing method of the first aspect or any corresponding embodiment described above.
[0014] The technical solutions provided in the embodiments of this specification may include the following beneficial effects:
[0015] In the embodiments described in this specification, the security device informs the gateway device of authorization information through LLDP messages, enabling the gateway device to detect the validity of the authorization information in a timely manner and adjust the forwarding strategy accordingly, thereby ensuring that traffic can be forwarded normally and guaranteeing the normal operation of user services.
[0016] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this specification. Attached Figure Description
[0017] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this specification and, together with the description, serve to explain the principles of this specification.
[0018] Figure 1 This is a schematic diagram of a system architecture illustrated in this specification according to an exemplary embodiment.
[0019] Figure 2 This is a flowchart illustrating a network traffic processing method according to an exemplary embodiment of this specification.
[0020] Figure 3 This is a hardware structure diagram of a computer device containing the network traffic processing device in the embodiments of this specification.
[0021] Figure 4 This is a block diagram illustrating a network traffic processing apparatus according to an exemplary embodiment of this specification.
[0022] Figure 5 This is a block diagram illustrating another network traffic processing apparatus according to an exemplary embodiment of this specification. Detailed Implementation
[0023] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this specification. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this specification as detailed in the appended claims.
[0024] The terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to be limiting of this specification. The singular forms “a,” “the,” and “the” as used in this specification and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the associated listed items.
[0025] It should be understood that although the terms first, second, third, etc., may be used in this specification to describe various information, this information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this specification, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."
[0026] The embodiments described in this specification will now be described in detail.
[0027] The following combination Figure 1 The system architecture of the network traffic processing methods and apparatus applicable to the embodiments of this specification will be described. It should be noted that... Figure 1 The examples shown are merely examples of system architectures that can be applied to the embodiments of this specification, in order to help those skilled in the art understand the technical content of this specification, but do not mean that the embodiments of this specification cannot be used in other devices, systems, environments or scenarios.
[0028] Figure 1 This is a schematic diagram of a system architecture illustrated in this specification according to an exemplary embodiment.
[0029] like Figure 1 As shown, the system architecture may include, for example, an AC (access controller), an AP (access point), an access switch, a core switch, and security devices.
[0030] According to embodiments of this specification, an access point (AP) can be used to transmit wireless signals (e.g., Wi-Fi signals) and connect terminal devices (e.g., mobile phones, laptops, etc.). An access switch can be used to provide PoE (Power over Ethernet). A core switch can act as a gateway device, providing data conversion services between multiple networks, such as data conversion services between a local area network (LAN) and the Internet. Optionally, the core switch can also act as a DHCP server, assigning IP addresses to APs.
[0031] According to embodiments of this specification, security devices can be used to detect and filter traffic. Security devices may include, for example, firewalls, intrusion detection systems (IDS), and intrusion prevention systems (IPS). Gateway devices can be used for traffic routing and forwarding, directing traffic through security devices for detection and filtering.
[0032] According to the embodiments in this specification, the security device can be deployed as a standalone device bypassing the gateway device. Policy-based routing redirects all traffic flowing through the gateway (including outbound, inbound, and internal forwarding traffic) to the security device for inspection. After security checks, packets continue to be forwarded along their original paths.
[0033] Alternatively, security devices can be integrated into gateway devices as security modules. For example, a security software package can be integrated into the gateway device, and after loading, the security package forms a security module. The security module connects to the physical interface, can automatically obtain a management address via DHCP, automatically generate policy routing rules, and redirect all traffic flowing through the gateway device to the security module for processing.
[0034] The network traffic processing method provided in the embodiments of this specification will be described in detail below. For example... Figure 2 As shown, Figure 2 This is a flowchart illustrating a network traffic processing method according to an exemplary embodiment of this specification. The network traffic processing method provided in the embodiments of this specification may include the following steps.
[0035] In step S210, the security device sends a Link Layer Discovery Protocol (LLDP) message to the gateway device. The LLDP message includes authorization information.
[0036] According to embodiments of this specification, authorization information may indicate whether a security device is authorized to perform security checks on traffic. Authorization information may, for example, include a license.
[0037] In step S220, after the gateway device receives the LLDP message, it checks the validity of the authorization information.
[0038] According to embodiments of this specification, the gateway device can, for example, view the status of authorization information. If the authorization information is in a normal state, it is determined that the authorization information has passed the test; if the authorization information is in an abnormal state such as invalid, faulty, or expired, it is determined that the authorization information has failed the test. The status of the authorization information can be provided to the gateway device by security devices or other devices.
[0039] Optionally, message codes can be used to represent the status of authorization information, and the gateway device can determine the status of authorization information through the message codes of the authorization information.
[0040] In step S230, if the authorization information passes the detection, the gateway device configures a target forwarding policy, which is used to instruct the service traffic received by the corresponding interface to be redirected to the security device.
[0041] According to embodiments of this specification, a target forwarding policy can be used to control the forwarding path of traffic. For example, it may include the service traffic information to be matched, the action to be performed after matching, and the corresponding interface to which the policy is applied. By configuring the target forwarding policy, the next-hop address of the corresponding interface can be set to the address of the security device.
[0042] According to embodiments of this specification, the target forwarding policy may be, for example, a sub-policy of policy routing.
[0043] In step S240, if service traffic is received through the corresponding interface, the gateway device redirects the service traffic to the security device according to the target forwarding policy.
[0044] According to the embodiments of this specification, when receiving service traffic through the corresponding interface, the gateway device can determine whether the service traffic matches the service traffic information in the target forwarding policy. If they match, the service traffic is sent to the next hop specified in the target forwarding policy, i.e., the security device.
[0045] In step S250, after the security device receives the service traffic redirected by the gateway device, it performs a security check on the service traffic.
[0046] According to embodiments of this specification, security checks may include one or more of the following: firewall rule matching, signature matching, anomaly detection, and protocol analysis. It should be noted that security checks may also include other check items, which are not specifically limited in this specification. After the service traffic passes the security check, the security device forwards the service traffic.
[0047] According to the embodiments in this specification, the security device informs the gateway device of authorization information through LLDP messages, enabling the gateway device to detect the validity of the authorization information in a timely manner and adjust the forwarding policy in a timely manner based on the detection results, thereby enabling traffic to be forwarded normally and ensuring the normal operation of user services.
[0048] Optionally, LLDP messages may include custom fields. A security device can write authorization information into these custom fields within the LLDP message and then send the LLDP message to the gateway device. The gateway device can then retrieve the authorization information from the custom fields in the LLDP message.
[0049] For example, this custom field can be a TLV(Type, Length, Value) field. The Type of the custom field can include the type of authorization information, the Value of the custom field can include the content of the authorization information, and the Length of the custom field can include the total length of the custom field.
[0050] Optionally, if the gateway device fails the authorization information check and a corresponding target forwarding policy for the security device is already configured, it can delete that target forwarding policy. This avoids the problem of forwarding traffic to the security device and causing service failure when the authorization information is abnormal.
[0051] Optionally, if the authorization information fails the detection, the gateway device can generate an exception notification to inform the user that the authorization information is abnormal.
[0052] Optionally, if the authorization information passes the detection and the remaining valid duration of the authorization information is less than the duration threshold, the gateway device starts a timer. The duration threshold can be set according to actual needs. When the timer expires, the target forwarding policy is deleted to stop traffic redirection. The timer's duration is equal to the remaining valid duration minus a preset value. The preset value is greater than or equal to 0 and less than or equal to the remaining valid duration. The preset value can be set according to actual needs.
[0053] By deleting the target forwarding policy when the timer expires, packet loss in business traffic can be avoided, ensuring the normal operation of user services.
[0054] Optionally, the security device can send a new LLDP message to the gateway device each time the authorization information is updated. This new LLDP message includes the updated authorization information to notify the gateway device to update the authorization information. Similar to the previous embodiment, upon receiving the new LLDP message, the gateway device can verify the updated authorization information. If the authorization information fails the verification, the target forwarding policy is deleted. If the authorization information passes the verification and the remaining validity period of the authorization information is less than a timeout threshold, a timer is started. The target forwarding policy is deleted when the timer expires.
[0055] Therefore, security devices can update their authorization information in a timely manner and adjust their forwarding strategies based on the validity of the authorization information. This ensures both the security functions when the authorization information is normal and the normal operation of user services when the authorization information is abnormal.
[0056] Corresponding to the embodiments of the aforementioned methods, this specification also provides embodiments of a network traffic processing device and the terminal to which it is applied.
[0057] The embodiments of the network traffic processing device described in this specification can be applied to computer devices, such as servers or terminal devices. The device embodiments can be implemented through software, hardware, or a combination of both. Taking software implementation as an example, as a logical device, it is formed by the processor reading the corresponding computer program instructions from non-volatile memory into memory and executing them. From a hardware perspective, such as... Figure 3 The diagram shown is a hardware structure diagram of a computer device containing the network traffic processing device as described in this specification, except... Figure 3 In addition to the processor 310, memory 330, network interface 320, and non-volatile memory 340 shown, the server or electronic device where the device 331 is located in the embodiment may also include other hardware depending on the actual function of the computer device, which will not be described in detail here.
[0058] like Figure 4 As shown, Figure 4This is a block diagram illustrating a network traffic processing apparatus according to an exemplary embodiment of this specification. The apparatus includes:
[0059] The first sending module 410 is used to send a Link Layer Discovery Protocol (LLDP) message to the gateway device. The LLDP message includes authorization information.
[0060] The first receiving module 420 is used to receive service traffic redirected by the gateway device;
[0061] Inspection module 430 is used to perform security checks on business traffic.
[0062] Optionally, the LLDP message includes custom fields; the device may also include:
[0063] The write module is used to write authorization information into custom fields in LLDP messages.
[0064] Optionally, the device may further include:
[0065] The second sending module is used to send a new LLDP message to the gateway device when the authorization information is updated. The new LLDP message includes the updated authorization information to notify the gateway device to update the authorization information.
[0066] Accordingly, this specification also provides an electronic device including a processor; a memory for storing processor-executable instructions; wherein the processor is configured to: send Link Layer Discovery Protocol (LLDP) messages to a gateway device, the LLDP messages including authorization information; receive service traffic redirected by the gateway device; and perform security checks on the service traffic.
[0067] like Figure 5 As shown, Figure 5 This is a block diagram illustrating another network traffic processing apparatus according to an exemplary embodiment of this specification, the apparatus comprising:
[0068] The second receiving module 510 is used to receive LLDP messages sent by the security device, the LLDP messages including authorization information;
[0069] Verification module 520 is used to check the validity of authorization information;
[0070] The configuration module 530 is used to configure the target forwarding policy if the authorization information passes the detection. The target forwarding policy is used to indicate that the service traffic received by the corresponding interface should be redirected to the security device.
[0071] The redirection module 540 is used to redirect service traffic to the security device according to the target forwarding policy if service traffic is received through the corresponding interface.
[0072] Optionally, the device may further include:
[0073] The deletion module is used to delete the target forwarding policy if the authorization information fails the detection and a target forwarding policy corresponding to the security device has been configured.
[0074] Optionally, the device may further include:
[0075] The notification module is used to generate an exception notification if the authorization information fails the check.
[0076] Optionally, the device may further include:
[0077] The timing module is used to start a timer if the authorization information passes the detection and the remaining valid duration of the authorization information is less than the duration threshold. When the timer expires, the target forwarding policy is deleted. The timer duration is equal to the remaining valid duration minus a preset value.
[0078] Optionally, the LLDP message includes a custom field carrying authorization information; the device may also include:
[0079] The acquisition module is used to retrieve authorization information from custom fields in LLDP messages.
[0080] Accordingly, this specification also provides an electronic device including a processor; a memory for storing processor-executable instructions; wherein the processor is configured to: receive an LLDP message sent by a security device, the LLDP message including authorization information; detect the validity of the authorization information; if the authorization information passes the detection, configure a target forwarding policy, the target forwarding policy being used to instruct the redirection of service traffic received through the corresponding interface to the security device; if service traffic is received through the corresponding interface, redirect the service traffic to the security device according to the target forwarding policy.
[0081] According to the embodiments in this specification, the security device informs the gateway device of authorization information through LLDP messages, enabling the gateway device to detect the validity of the authorization information in a timely manner and adjust the forwarding policy in a timely manner based on the detection results, thereby enabling traffic to be forwarded normally and ensuring the normal operation of user services.
[0082] The specific implementation process of the functions and roles of each module in the above device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.
[0083] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of the solution in this specification according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0084] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0085] Other embodiments of this specification will readily occur to those skilled in the art upon consideration of the specification and practice of the invention claimed herein. This specification is intended to cover any variations, uses, or adaptations that follow the general principles of this specification and include common knowledge or customary techniques in the art not claimed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this specification are indicated by the following claims.
[0086] It should be understood that this specification is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this specification is limited only by the appended claims.
[0087] The above description is merely a preferred embodiment of this specification and is not intended to limit this specification. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of protection of this specification.
Claims
1. A network traffic processing method, applied to a security device, characterized in that, The method includes: A Link Layer Discovery Protocol (LLDP) message is sent to the gateway device. The LLDP message includes authorization information, enabling the gateway device to perform the following operations: detect the validity of the authorization information; if the authorization information passes the detection, configure a target forwarding policy, which instructs the redirection of service traffic received through the corresponding interface to the security device; if service traffic is received through the corresponding interface, redirect the service traffic to the security device according to the target forwarding policy; if the authorization information fails the detection, and if a target forwarding policy corresponding to the security device has already been configured, delete the target forwarding policy. Receive the service traffic redirected by the gateway device; Perform security checks on the aforementioned service traffic.
2. The method according to claim 1, characterized in that, The LLDP message includes custom fields; the method further includes: Write the authorization information into a custom field in the LLDP message.
3. The method according to claim 1, characterized in that, The method further includes: If the authorization information is updated, a new LLDP message is sent to the gateway device, the new LLDP message including the updated authorization information, to notify the gateway device to update the authorization information.
4. A network traffic processing method, applied to a gateway device, characterized in that, The method includes: Receive LLDP messages sent by security devices, the LLDP messages including authorization information; Detect the validity of the authorization information; If the authorization information passes the detection, a target forwarding policy is configured, which is used to instruct the service traffic received by the corresponding interface to be redirected to the security device; If service traffic is received through the corresponding interface, the service traffic is redirected to the security device according to the target forwarding policy. If the authorization information fails the detection, and a target forwarding policy corresponding to the security device has been configured, then the target forwarding policy is deleted.
5. The method according to claim 4, characterized in that, The method further includes: If the authorization information fails the detection, an exception notification is generated.
6. The method according to claim 4, characterized in that, The method further includes: If the authorization information passes the detection and the remaining valid duration of the authorization information is less than the duration threshold, then a timer is started. When the timer expires, the target forwarding policy is deleted. The timer duration is equal to the remaining valid duration minus a preset value.
7. The method according to claim 4, characterized in that, The LLDP message includes a custom field that carries the authorization information; the method further includes: The authorization information is obtained from the custom fields of the LLDP message.
8. A network traffic processing device, applied to security equipment, characterized in that, The device includes: The first sending module is configured to send a Link Layer Discovery Protocol (LLDP) message to a gateway device. The LLDP message includes authorization information, enabling the gateway device to perform the following operations: detect the validity of the authorization information; if the authorization information passes the detection, configure a target forwarding policy, which instructs the redirection of service traffic received through the corresponding interface to the security device; if service traffic is received through the corresponding interface, redirect the service traffic to the security device according to the target forwarding policy; if the authorization information fails the detection, and if a target forwarding policy corresponding to the security device has already been configured, delete the target forwarding policy. The first receiving module is used to receive the service traffic redirected by the gateway device; The inspection module is used to perform security checks on the service traffic.
9. A network traffic processing device, characterized in that, The device includes: The second receiving module is used to receive LLDP messages sent by the security device, wherein the LLDP messages include authorization information; The verification module is used to detect the validity of the authorization information; The configuration module is used to configure a target forwarding policy if the authorization information passes the detection. The target forwarding policy is used to instruct the service traffic received by the corresponding interface to be redirected to the security device. The redirection module is used to redirect the service traffic to the security device according to the target forwarding policy if service traffic is received through the corresponding interface.
10. An electronic device, comprising: processor; Memory used to store processor-executable instructions; The processor is configured to perform the network traffic processing method according to any one of claims 1 to 7.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing the computer to perform the network traffic processing method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Data processing method and device
CN113938405A