Flow statistical method and system, terminal, equipment, storage medium and vehicle
By implementing traffic statistics methods on the terminal, collecting and analyzing the message data of the domain controller and recording them in the corresponding service statistics table entries, the problem of high traffic analysis cost of on-board Ethernet networks in the prior art is solved, and traffic statistics for different services of the domain controller are realized, reducing costs.
Patent Information
- Application Number
- CN202311768413.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-21
- Publication Date
- 2025-06-24
AI Technical Summary
The existing service traffic detection methods are expensive and it is difficult to effectively monitor and analyze the traffic of the on-board Ethernet network, resulting in the inability to accurately determine whether inter-domain communication meets the expected network planning.
By implementing the traffic statistics method on the terminal, the traffic collector is used to collect the message data of the domain controller and parse these data to obtain the traffic data information. Then, the corresponding target business statistics table entry is found from the preset business statistics record, and the traffic data information is recorded in the table entry.
The traffic statistics of different services of the domain controller are realized, reducing the cost of traffic analysis work on the on-board Ethernet network, without modifying the domain controller's software and hardware system or using proprietary traffic statistics instruments.
Smart Images

Figure CN120200941A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the technical field of vehicles, and particularly relates to a traffic statistics method, system, terminal, device, storage medium, and vehicle. Background Art
[0002] With the development of automotive intelligence and networking, more and more electronic systems have entered the vehicle, and the volume of in-vehicle data interaction has been increasing continuously. The automotive electronic and electrical architecture is also evolving continuously. In-vehicle Ethernet has gradually become the mainstream automotive backbone network with its advantages such as high bandwidth and lightweight wiring harness. At present, the mainstream of the electronic and electrical architecture is the domain controller of cross-domain integration, and at the same time, the regional computing platform is divided based on computing power. In the cross-domain integration stage, there are generally three domain controllers: the autonomous driving domain, the intelligent cockpit domain, and the vehicle control domain. Ethernet can be used for communication between each domain controller.
[0003] Some service functions require data signal transmission between domain controllers. For example, turning on and off the headlights, turning on or off the air conditioner may require communication between the intelligent cockpit domain and the vehicle control domain. Another example is that the system logs of each domain controller can be uniformly sent to a certain domain controller and uploaded to the cloud after being uniformly processed by this domain controller. For services using Ethernet for inter-domain communication, generally, the allowed IP addresses, transport protocols, and transport layer port numbers are pre-allocated for them. For some service functions, packet loss during inter-domain communication may lead to serious functional problems, so generally, such problems are avoided through prior network planning and reasonable service deployment.
[0004] When verifying inter-domain communication, to determine whether the Ethernet service traffic meets the expected network planning and whether the service deployment is reasonable, a corresponding service traffic monitoring method needs to be provided. However, most of the existing service traffic detection methods monitor by modifying the software and hardware systems of the domain controller or using proprietary traffic statistics instruments, resulting in too high costs for traffic analysis of the in-vehicle Ethernet network. Summary of the Invention
[0005] Embodiments of this application provide a traffic statistics method, system, terminal, device, storage medium, and vehicle, which reduce the cost of traffic analysis of the in-vehicle Ethernet network.
[0006] According to the first aspect of this application, a traffic statistics method is provided. This method is applied to a terminal and includes:
[0007] Receiving packet data of at least one domain controller collected by a traffic collector and packet transmission information for transmitting the packet data; the traffic collector is connected to the at least one domain controller;
[0008] Parsing the packet data to obtain traffic data information;
[0009] From the preset service statistical records, search for the target service statistical table entry of the domain controller that corresponds to both the traffic data information and the packet transmission information. The service statistical records include multiple service statistical table entries corresponding to the domain controller, and the multiple service statistical table entries include the target service statistical table entry. The multiple service statistical table entries are used to record the traffic data information of different services in the domain controller;
[0010] Record the traffic data information in the target service statistical table entry.
[0011] In a second aspect, an embodiment of the present application provides a traffic statistics system, and the system includes:
[0012] At least one domain controller;
[0013] A traffic collector communicatively connected to the at least one domain controller for collecting packet data of the at least one domain controller and transmitting the packet data to a terminal;
[0014] A terminal communicatively connected to the traffic collector, and the terminal is configured to execute the method according to any one of the first aspect.
[0015] In a third aspect, an embodiment of the present application provides a terminal, which includes:
[0016] A receiving module for receiving packet data of at least one domain controller collected by a traffic collector and the packet transmission information for transmitting the packet data; the traffic collector is connected to the at least one domain controller;
[0017] An analysis module for analyzing the packet data to obtain traffic data information;
[0018] A search module for searching, from the preset service statistical records, for the target service statistical table entry of the domain controller that corresponds to both the traffic data information and the packet transmission information. The service statistical records include multiple service statistical table entries corresponding to each port of the domain controller, and the multiple service statistical table entries include the target service statistical table entry. The multiple service statistical table entries are used to record the traffic data information of different services in the domain controller;
[0019] A first recording module for recording the traffic data information in the target service statistical table entry.
[0020] In a fourth aspect, an embodiment of the present application provides a traffic statistics device, which includes: a processor and a memory storing computer program instructions;
[0021] When the processor executes the computer program instructions, it implements the traffic statistics method according to any one of the first aspects.
[0022] In a fifth aspect, an embodiment of the present application provides a computer storage medium. Computer program instructions are stored on the computer-readable storage medium. When the computer program instructions are executed by a processor, the traffic statistics method according to any one of the first aspects is implemented.
[0023] In a sixth aspect, an embodiment of the present application provides a computer program product. When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device is caused to execute the traffic statistics method according to any one of the first aspects.
[0024] In a seventh aspect, an embodiment of the present application provides a vehicle, which includes at least one of the traffic statistics system according to any one of the second aspects, the terminal according to any one of the third aspects, and the traffic statistics device according to any one of the fourth aspects.
[0025] The technical solutions provided by the embodiments of the present application at least bring the following beneficial effects:
[0026] Embodiments of the present application provide a traffic statistics method, system, terminal, device, storage medium, and vehicle. Among them, the traffic collector can be connected to at least one domain controller through the Internet, and data transmission can be performed between the traffic collector and the terminal. Therefore, the terminal can obtain the packet data of the domain controller collected by the traffic collector, and then search for the target service statistical entry corresponding to both the traffic data information and the packet transmission information from the preset service statistical records, and record the traffic data information in the target service statistical record. In this way, the traffic data information obtained by parsing the packet data can be recorded in the service statistical entry corresponding to each domain controller, and each service statistical entry is used to describe different services in the domain controller. Therefore, embodiments of the present application can implement traffic statistics for different services of the domain controller, and this statistical process is executed by a terminal outside the domain controller. Therefore, the present application can implement traffic statistics without modifying the software and hardware systems of the domain controller or using proprietary traffic statistics instruments for monitoring, thereby reducing the cost of traffic analysis work for in-vehicle Ethernet networks.
[0027] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application, and do not constitute an improper limitation to the present application.
[0029] Figure 1 is a flowchart of a traffic statistics method shown according to an exemplary embodiment;
[0030] Figure 2 is a schematic structural diagram of a traffic statistics system shown according to an exemplary embodiment;
[0031] Figure 3 is a schematic structural diagram of a service statistics record shown according to an exemplary embodiment;
[0032] Figure 4 is a schematic structural diagram of a packet hash table shown according to an exemplary embodiment;
[0033] Figure 5 is a schematic flowchart of finding a service statistics entry in a service statistics record shown according to an exemplary embodiment;
[0034] Figure 6 is a schematic processing diagram of statistically calculating a service peak rate shown according to an exemplary embodiment;
[0035] Figure 7 is a structural block diagram of a terminal shown according to an exemplary embodiment;
[0036] Figure 8 is a structural block diagram of a traffic statistics device shown according to an exemplary embodiment. Detailed implementation manners
[0037] In order to be able to more clearly understand the above-mentioned objects, features, and advantages of the present disclosure, the solutions of the present disclosure will be further described below. It should be noted that, without conflict, the embodiments of the present disclosure and the features in the embodiments may be combined with each other.
[0038] In the following description, many specific details are set forth in order to fully understand the present disclosure, but the present disclosure may also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only a part of the embodiments of the present disclosure, rather than all of the embodiments.
[0039] As described in the background art, for the Ethernet traffic between domain controllers, there is usually a requirement for traffic monitoring of ports and VLANs in order to reasonably plan and adjust the network topology and ensure the reasonable use of network resources. However, the chips installed on the domain controllers do not support traffic data statistics with relatively complex functions, resulting in the inability to effectively monitor and statistically calculate the traffic of the ports and VLANs of the domain controllers.
[0040] To solve the problems of the prior art, embodiments of the present application can implement traffic statistics for the message transmission ports or VLANs of a domain controller, and this statistical process is executed by a terminal outside the domain controller. Therefore, the present application can implement traffic statistics without setting a chip inside the domain controller for the above traffic statistics operation. Therefore, the present application realizes traffic statistics for the message transmission ports and VLANs of the domain controller.
[0041] Based on this, the present application provides a traffic statistics method, system, terminal, device, storage medium, and vehicle. First, the traffic statistics method provided by embodiments of the present application will be introduced below. The traffic statistics method may include:
[0042] Figure 1 The structural block diagram of the traffic statistics method provided by an embodiment of the present application is shown. As Figure 1 shown, in one embodiment, the method is applied to a terminal, and the method may include:
[0043] Step S101, receiving at least one piece of message data of a domain controller collected by a traffic collector and message transmission information for transmitting the message data; the traffic collector is connected to the at least one domain controller;
[0044] Step S102, parsing the message data to obtain traffic data information;
[0045] Step S103, searching in a preset service statistics record for a target service statistics table entry of the domain controller that corresponds to both the traffic data information and the message transmission information, the service statistics record including a plurality of service statistics table entries corresponding to the domain controller, the plurality of service statistics table entries including the target service statistics table entry, and the plurality of service statistics table entries being used to record traffic data information of different services in the domain controller;
[0046] Step S104, recording the traffic data information in the target service statistics table entry;
[0047] In the above S101, please refer to Figure 2 , Figure 2 is the structural schematic diagram of the traffic statistics system. Among them, the domain controller is a processor hardware platform that integrates and consolidates the functions of ECUs with similar and separated functions, which are stronger in performance than ECUs, to solve the problems brought by the distributed electronic and electrical architecture.
[0048] Among them, a plurality of Ethernet switches are also provided in the domain controller, and each Ethernet switch is provided with an Ethernet switch port for communicating with other domain controllers through Ethernet.
[0049] The traffic collector includes multiple Ethernet ports, and the multiple Ethernet ports are respectively connected to the Ethernet switch ports of each domain controller. The traffic forwarded between domain controllers is collected through methods such as device cascading or traffic mirroring, and after preliminary processing of the traffic, it is forwarded to the traffic statistics analysis platform on the terminal. Thus, the terminal can receive the packet data and packet transmission information collected by the traffic collector. It should be noted that when the traffic collection instrument is connected to the Ethernet switch on the domain controller, the original traffic forwarding destination and packet content will not be changed.
[0050] As an example, the packet data refers to the information data transmitted through the communication protocol. In a computer network, the packet data is usually used to represent various control information and data in network transmission.
[0051] As an example, the packet transmission information can at least include the domain controller port information; the domain controller port information refers to the information of the port from which the domain controller sends the packet data, and can be used as the identifier of the domain controller.
[0052] As an example, the traffic collector is connected to at least one domain controller through the Internet; each domain controller is interconnected, and the traffic collector is connected to at least one of the multiple domain controllers.
[0053] As an example, the terminal can include a computer, a car machine, and a mobile device, etc.
[0054] It should be noted that before receiving the packet data and packet transmission information, the user needs to enable the traffic statistics function on the terminal so as to monitor the traffic generated when the domain controller transmits the packet data.
[0055] In the above S102, parse the packet data to obtain the traffic data information;
[0056] The above traffic data information can include IP five-tuple information (source IP, destination IP, protocol number, source port, and destination port), the VLAN ID of the packet, and the packet length of the packet, etc.
[0057] In the above 103, from the preset service statistics records, find the target service statistics table entry of the domain controller that corresponds to both the traffic data information and the packet transmission information;
[0058] Each domain controller has a corresponding service statistics record, and the port of the domain controller is corresponding to the domain controller. Therefore, when it is determined that the traffic statistics function is enabled, the target service statistics record corresponding to the domain controller can be queried from multiple service statistics records according to the port of the domain controller.
[0059] Furthermore, each port of the domain controller also has multiple service statistical table entries, which are used to count the traffic data information of different services in the port. In this way, the service statistical record includes multiple service statistical table entries. When counting the traffic data information, it is necessary to count the parsed traffic data information into the target service statistical table entry corresponding to the traffic data information, so as to clearly display the traffic data information of different services in the port.
[0060] As an example, the service statistical record is a table, such as Figure 3 shown Figure 3 is a schematic structural diagram of the service statistical record. The service statistical tables from port index 0 to port index m in the figure represent the service statistical record; and the table entry where the service statistical record node pointer is located is the service statistical table entry, and each service statistical table entry is used to record the traffic data information of different services.
[0061] It should be noted that the service statistical record can be set by pre-configuring a service configuration file in the terminal. Specifically, in one embodiment, before step 101, the method further includes:
[0062] Configuring a preset service configuration file, the service configuration file includes five-tuple information and a service identifier, and the five-tuple information and the service identifier are used to describe the characteristics of different service flows in the domain controller;
[0063] Reading the service configuration file to generate the service statistical record.
[0064] In this embodiment, the service configuration file is used to match and count the parsed traffic data information to the corresponding service. Therefore, it is necessary to pre-define the service flow characteristics of the service in the service configuration file, where the five-tuple information of the service can be specified
[0065] When defining the service flow characteristics in the configuration file, it is necessary to specify the five-tuple information of the service (source and destination IP addresses, source and destination transport layer ports, protocol number), and the service identifier (such as service name or service ID). Among them, the five-tuple information can distinguish different services, and the corresponding service is unique.
[0066] In an example, a service can be defined in the following format:
[0067] Point_Cloud_Data 172.31.3.77 24172.31.3.81 3217 11000001428670
[0068] A total of 12 fields are configured, and the meanings are as follows:
[0069] 1) Service Name: Describes the service to which the traffic belongs, i.e., Point_Cloud_Data in the above example;
[0070] 2) Source IP Address: The IPv4 traffic source IP address, i.e., 172.31.3.77 in the above example;
[0071] 3) Source IP Address Mask Length: The source IP address mask length set as needed, i.e., 24 in the above example;
[0072] 4) Destination IP Address: The IPv4 traffic destination IP address, i.e., 172.31.3.81 in the above example;
[0073] 5) Destination IP Address Mask Length: The destination IP address mask length set as needed, i.e., 32 in the above example;
[0074] 6) Protocol: The protocol used by IPv4 traffic, including TCP, UDP, ICMP, etc., i.e., 17 in the above example;
[0075] 7) Source Port Range Type: Specifies whether the matching method of the transport layer source port of IPv4 traffic is by specified port (value 1), by specified range (value 2), or ignoring the source port (value 0), i.e., 1 in the above example;
[0076] 8) Source Port or Source Begin Port Number: According to the source port range type, specifies the value of the transport layer source port number or the starting value of the range; when the range type is 0, fill in 0 here;
[0077] 9) Source End Port Number: If the source port range type is 2, fill in the ending value of the port number range, otherwise fill in 0, i.e., 0 in the above example;
[0078] 10) Destination Port Range Type: Specifies whether the matching method of the transport layer destination port of IPv4 traffic is by specified port (value 1), by specified range (value 2), or ignoring the source port (value 0);
[0079] 11) Destination_Port, or the starting value of the Destination_Begin_Port_Number of the destination port number or destination port range: Specify the value of the transport layer destination port number or the starting value of the range according to the destination port range type; when the range type is 0, fill in 0 here;
[0080] 12) Destination_End_Port_Number: If the destination port range type is 2, fill in the ending value of the port number range, otherwise fill in 0.
[0081] By reading the service configuration file, generate the service statistical record for each port. Among them, the service statistical record is a two-dimensional array with the port as the first dimension and the service as the second dimension. The service is defined through the five-tuple information. At the same time, the traffic data information also includes the five-tuple information. Therefore, the traffic data information can be recorded in the service statistical record by comparing whether the five-tuple information is the same.
[0082] It should be noted that the service statistical record can define the size of the port statistical table in the service statistical record through global variable definition. For example, limit the port number to be less than 20, and the size of the service statistical table, for example, limit the maximum number of services supported for statistics to 300.
[0083] In this embodiment, the services to be statistically analyzed can be predefined through the service configuration file. During the subsequent statistical process, the traffic data information to be statistically analyzed can be directly added to the service statistical record, improving the statistical efficiency and having a high degree of customization.
[0084] In step 104, record the traffic data information into the target service statistical table entry;
[0085] After determining the target service statistical table entry, the traffic data information can be directly recorded into the target service table entry. Among them, the service statistical table entry includes the variable length of the service name, the number of traffic time-sharing cumulative nodes for each statistical node, the configuration key-value information of the service flow, the Vlan ID to which the service flow belongs, the total number of packets of the service flow, the total number of bytes of the service flow, the number of packets forwarded within each time-sharing statistical period, the number of bytes forwarded within each time-sharing statistical period, the peak rate of this traffic, and the cumulative duration since the start of the record statistics. Finally, when generating the statistical report, calculate information such as the average rate based on totalBytes. The specific relevant information is described in the following embodiments and will not be elaborated here in this embodiment.
[0086] In this embodiment, the traffic collector can be connected to at least one domain controller through the Internet or the automotive Ethernet, and data can be transmitted between the traffic collector and the terminal. Therefore, the terminal can obtain the message data of the domain controller collected by the traffic collector, and then search for the target service statistical table entry corresponding to both the traffic data information and the message transmission information from the preset service statistical record, and record the traffic data information in the target service statistical record. In this way, the traffic data information obtained by parsing the message data can be recorded in the service statistical table entry corresponding to each domain controller, and each service statistical table entry is used to describe different services in the domain controller. Therefore, the embodiment of the present application can implement traffic statistics for different services of the domain controller, and this statistical process is executed by a terminal outside the domain controller. Therefore, the present application can achieve traffic statistics without modifying the software and hardware systems of the domain controller or using a proprietary traffic statistics instrument for monitoring, thereby reducing the cost of traffic analysis work for the in-vehicle Ethernet network.
[0087] In an embodiment of the present application, the step of searching for the target service statistical table entry of the domain controller corresponding to both the traffic data information and the message transmission information from the preset service statistical record includes:
[0088] Search for a target hash node that matches both the traffic data information and the message transmission information from the pre-obtained message hash table according to the traffic data information and the message transmission information;
[0089] When the target hash node exists in the message hash table, determine the service statistical table entry in the target hash node as the target service statistical table entry.
[0090] After parsing to obtain the traffic data information, in order to match the traffic data information with the service statistical table entry to obtain the target service statistical table entry, it is necessary to traverse each service statistical table entry based on the traffic data information, but in this way, the search efficiency is too low. To avoid traversing and searching in the service statistical table using the five-tuple information in the traffic data information every time a message data is received, in this embodiment, a method of storing message information in a message hash table is adopted to improve the search efficiency.
[0091] Specifically, multiple hash nodes are stored in the above-mentioned message hash table, and the hash node includes the mapping relationship between the traffic data information, the message transmission information, and the service statistical table entry; after obtaining the traffic data information, the target hash node can be matched in the message hash table through the traffic data information and the message transmission information, and then the target service statistical table entry is determined from the target hash node.
[0092] Specifically, in one embodiment, searching for a target hash node that matches the traffic data information in a pre-acquired packet hash table according to the traffic data information and the packet transmission information includes:
[0093] Using the five-tuple information and the port as the first key value, searching for the hash node corresponding to the first key value in the packet hash table to obtain the target hash node.
[0094] As Figure 4 shown, Figure 4 is a schematic structural diagram of the packet hash table; the packet hash table is constructed based on the packet data received by the terminal. Each hash node stores the five-tuple information, port, and service statistics entry involved in in-vehicle Ethernet communication. Therefore, only by performing a hash calculation on the parsed five-tuple information and port with the packet hash table can the target service statistics entry corresponding to the five-tuple information and port be determined.
[0095] After the terminal receives packet data and parses the data traffic information, it is necessary to associate and store the data traffic information and the packet transmission information in the hash node of the packet hash table, and perform a hash calculation on all the hash nodes to obtain a hash linked list composed of hash nodes with common characteristics. As Figure 4 shown, hash node 1-1, hash node 1-2, and hash node 1-3, whose common characteristic is the head node pointer of linked list 1. It should be noted that the common characteristic is obtained by performing a hash calculation based on the port and five-tuple information to get the same value, and using this value as an index, the head node pointer of linked list 1 can be found.
[0096] In this embodiment, by setting up the packet hash table and then calculating with the traffic data information through the packet hash table, the target hash statistics entry corresponding to the traffic data information can be quickly determined, improving the efficiency of traffic statistics.
[0097] In one embodiment of the present application, after searching for a target hash node that matches both the traffic data information and the packet transmission information from a pre-acquired packet hash table according to the traffic data information and the packet transmission information, the method further includes:
[0098] In the case where the target hash node does not exist in the packet hash table, creating a new hash node according to the five-tuple information and the port to obtain the first hash node;
[0099] Using the five-tuple information and the port as the second key value, traversing the service statistics records to search for the service statistics entry corresponding to the second key value in the service statistics records to obtain the first service statistics entry;
[0100] Associate and store the five-tuple information, the port, and the first service statistical entry in the first hash node.
[0101] In this embodiment, if the target hash node does not exist in the packet hash table, it indicates that the traffic data information parsed this time is the information received by the terminal for the first time. Therefore, it is necessary to store the five-tuple information and the port in the traffic data information in the packet hash table, so that when the same five-tuple information and port are received later, the corresponding service statistical entry can be quickly located.
[0102] Therefore, when the target hash node does not exist in the packet hash table, a first hash node is newly created, and at the same time, the traffic data information is stored in the first hash node. Further, using the five-tuple information and the port as the second key value, traverse the service statistical records, find the first service statistical entry from the service statistical records, and finally associate and store the five-tuple information, the port, and the first service statistical entry in the first hash node. A new hash node is formed. After the same five-tuple information and port are received again later, it can be directly matched from the packet hash table without having to traverse the service statistical records again, improving the efficiency of traffic statistics.
[0103] In addition, it should be noted that if no corresponding first service statistical entry is found during the process of traversing the service statistical records using the five-tuple information and the port as the second key value, it means that the service statistical entry for this service is not configured in the service statistical records, that is, the service corresponding to the five-tuple information and the port is not the service that the user wants to count. The packet data corresponding to the five-tuple information and the port can be marked as an undefined packet, and the five-tuple information and the port can be marked as illegal values.
[0104] In an example, the five-tuple information includes: the first source IP, the first destination IP, the first protocol number, the first source port, and the first destination port. As Figure 5 shown, Figure 5 is a schematic flow diagram for finding the service statistical entry in the service statistical records. Further, finding the service statistical entry corresponding to the second key value from the service statistical records can be performed through the following steps:
[0105] Find multiple service statistical nodes corresponding to the port in the traffic statistical records. The service statistical nodes are used to describe the positions where the service statistical entries are located and correspond to the service statistical entries one by one;
[0106] Based on the arrangement order of the service statistical nodes, sequentially determine the target node among the multiple service statistical nodes;
[0107] Compare whether the second protocol number in the target node is the same as the first protocol number in the five-tuple information;
[0108] If the protocol numbers are the same, calculate the first value after the second source IP in the target node acts on the mask and the second value after the first source IP in the five-tuple information acts on the mask respectively;
[0109] If the first value and the second value are the same, determine whether the configuration flag of the first source port number is 1, where the first source port number being 0 means not caring about the source port number, 1 means specifying the source port number value, and 2 means specifying the source port number value range;
[0110] When the configuration flag of the first source port number is 1, determine whether the second source port value in the target node is equal to the first source port value;
[0111] If they are equal, determine whether the configuration flag of the first destination port number is 1;
[0112] In addition, when the configuration flag of the first source port number is not 1, determine whether the configuration flag of the first source port number is 2 and whether the first source port number value is within the source port number range preset by the target node;
[0113] When the configuration flag of the first source port number is 2 and the first source port number value is within the source port number range preset by the target node, determine whether the configuration flag of the first destination port number is 1;
[0114] When the configuration flag of the first destination port number is 1, determine whether the first destination port is equal to the second destination port in the target node;
[0115] If the first destination port is equal to the second destination port in the target node, end the matching and return the matching service statistics table entry;
[0116] When the configuration flag of the first destination port number is 2, determine whether the first destination port value is within the destination port range of the target node;
[0117] If the first destination port value is within the destination port range of the target node, end the matching and return the matching service statistics table entry.
[0118] In this embodiment, by comparing the five-tuple information with each service statistics table entry in the service statistics record to determine the service statistics table entry corresponding to the five-tuple information, it is possible to find the service statistics table entry from the service statistics record when there is no target hash node in the packet hash table, ensuring the accuracy of traffic statistics.
[0119] In an embodiment of the present application, after recording the traffic data information into the target service statistical table entry, the method further includes:
[0120] In a preset first period, based on the timestamp, calculate the position of the traffic data information in the traffic time-sharing cumulative node in the target service statistical table entry, where the traffic time-sharing cumulative node is used to record the traffic data information received within a second period, and the second period is less than the first period;
[0121] Record the traffic data information into the position;
[0122] In the first period, starting from the position as the starting node, sequentially obtain the traffic rate of the traffic data information recorded by each traffic time-sharing cumulative node;
[0123] Determine the traffic rate with the largest data in the first period as the first traffic rate peak value.
[0124] In this embodiment, the message transmission information includes the timestamp when the message data is received. After the terminal parses and obtains the traffic data information, it is necessary to store the traffic data information in time segments. Therefore, an array rcvBytesInCycle[a···z] is also set in the traffic statistical table entry. Each data element in the array is used to record the total traffic received within this time period at a fixed time granularity. Each data element is called a traffic time-sharing cumulative node, and this time period is the second period. As Figure 6 shown, Figure 6 It is a processing schematic diagram for statistically calculating the service peak rate. Among them, the squares from 0 to 29 are traffic time-sharing cumulative nodes. After receiving the traffic data information, it is necessary to record the traffic data information into one of the nodes.
[0125] In an example, the total number of service time-sharing cumulative nodes can be set to 30. Each time-sharing cumulative node records the total length of the messages matched within every 0.1 second, and the message information within 3 seconds can be recorded in total.
[0126] In this embodiment, the traffic rate is statistically calculated with the first period as a statistical period. Therefore, it is necessary to determine which traffic time-sharing cumulative node in one of the periods the received message data is recorded into. To determine the position of this node, it can be determined by the timestamp when the terminal receives the message data.
[0127] Specifically, the position can be calculated through the following expression:
[0128] a) When the time stamp unit is nanoseconds, the calculation expression is: ((timeStamp / 1000000000) % sampleArrayTime) * 10 + (timeStamp / 100000000) % 10
[0129] b) When the time stamp unit is milliseconds, the calculation expression is: ((timeStamp / 1000) % sampleArrayTime) * 10 + (timeStamp / 100) % 10
[0130] Among them, timeStamp is the time stamp, and sampleArrayTime refers to the total time of each time - sharing cumulative node in the service statistical table item.
[0131] In an example, assume that the unit of the time stamp marked on the message by the traffic collection instrument is nanoseconds (ns), and the time stamp value of a received message is 12345678912. The method for calculating its corresponding time - sharing cumulative node position using the above calculation expression is as follows:
[0132] (1) Calculate which 0.1 - second it is currently: 12345678912 / 100000000 = 123;
[0133] (2) Calculate which second it is currently: 12345678912 / 1000000000 = 12;
[0134] (3) Calculate the position of the time - sharing cumulative node = (12 % 3) * 10 + 123 % 10 = 3, that is, the received message at this time will be counted into the 4th time - sharing cumulative node of the service statistical table. The value 3 in the formula means that the time - sharing cumulative node of the service can cumulatively collect the traffic for 3 seconds in total.
[0135] After calculating the traffic data information within one cycle, determine the value with the maximum traffic rate in each traffic time - sharing cumulative node as the first traffic rate peak value.
[0136] Since only the traffic rate peak value within one cycle is statistically counted in the above - mentioned embodiment, and there may be multiple first cycles during the entire traffic statistical process, it is necessary to determine the traffic rate peak value during the entire traffic statistical process as the final target traffic rate peak value.
[0137] Specifically, in one embodiment, after determining the traffic rate peak value with the largest value in the first cycle as the first traffic rate peak value, the method further includes:
[0138] During the traffic statistical process, sequentially obtain the second traffic rate peak value within each of the first cycles;
[0139] In the case where the second peak flow rate is greater than the first peak flow rate, determine the second peak flow rate as the target peak flow rate.
[0140] In this embodiment, during the process of obtaining traffic statistics, the second peak flow rate of each first period can be obtained, and then the second peak flow rate with the largest value is selected from multiple second peak flow rates as the target peak flow rate. It should be noted that the process of traffic statistics can be the time period from when the user enables the traffic statistics function to when the user ends the traffic statistics function.
[0141] In addition, in another embodiment of the present application, as Figure 6 shown, the target peak flow rate can also be calculated by setting a window. Specifically, after determining the peak flow rate with the largest value in the first period as the first peak flow rate, the method further includes:
[0142] In the first period, traverse the traffic time-sharing nodes in the target service statistical table entry in sequence according to a preset window in a preset order, and calculate the third flow rate within a preset third period. The preset window is a window with the third period as the step length and a preset number of traffic time-sharing nodes as the size, and the third period is less than the first period;
[0143] Determine the third flow rate with the largest value as the target peak flow rate.
[0144] As an example, as Figure 6 shown, the window size can be 10 (that is, 10 traffic time-sharing cumulative nodes are taken each time), the step length is 1, and the traffic time-sharing cumulative nodes in the service statistical table entry are traversed from left to right to calculate the flow rate per second.
[0145] As an example, the flow rate per second can also be obtained according to the traffic received in each traffic time-sharing cumulative node and the period of the traffic time-sharing node. For example, if the period of the traffic time-sharing node is 0.1s, the flow rate within one second is the traffic received within 0.1s multiplied by 10; or if the period of the traffic time-sharing node is 0.2s, the flow rate within one second is the traffic received within 0.1s multiplied by 5.
[0146] Through the above steps, the second peak flow rate within each first period can be calculated, and then the flow rate peak with the largest value is selected from the second peak flow rates as the target peak flow rate. The flow rate peak in the target statistical table entry is accurately calculated, improving the accuracy of traffic statistics.
[0147] In an embodiment of the present application, after determining the second peak flow rate as the target peak flow rate when the second peak flow rate is greater than the first peak flow rate, the method further includes:
[0148] Obtaining the sum of the packet data received during the traffic statistics;
[0149] Calculating the average flow rate of the target service statistical entry based on the sum of the packet data and the statistical period of the traffic statistics process;
[0150] Recording the target peak flow rate and the average flow rate in the target service statistical entry.
[0151] In this embodiment, the above sum of the packet data is the total number of the packet data received during the traffic statistics process. And the average flow rate is the quotient of the sum of the packet data and the statistical period.
[0152] After calculating the above target peak flow rate and average flow rate, recording the two values in the target service statistical entry, thereby completing the statistics of the relevant traffic data in the target service statistical entry.
[0153] In this embodiment, by calculating the average flow rate and recording this value in the target service statistical entry, the record of the target service statistical entry is improved, and at the same time, the traffic statistics is realized, and the accuracy of the statistics is improved.
[0154] In an embodiment of the present application, after recording the target peak flow rate and the average flow rate in the target service statistical entry, the method further includes:
[0155] When the traffic statistics ends, outputting a service traffic statistics report corresponding to the service statistical record, and outputting a packet information report corresponding to the packet hash table.
[0156] When the service traffic statistics ends, generating a service traffic statistics report and generating a packet information report at the same time.
[0157] The service traffic statistics report includes the following statistical information of each service: (1) port (2) service name (3) IP five-tuple information (4) VLAN ID (5) total number of bytes (6) total number of packets (7) target peak flow rate (8) average flow rate.
[0158] The packet information report includes the following information of each packet: (1) port (2) IP five-tuple information (3) VLAN ID (4) total number of bytes (5) total number of packets.
[0159] It should be noted that the traffic data information is also stored in the message hash table, so the message information report corresponding to the message hash table can also be output.
[0160] In this embodiment, by outputting the service traffic statistics report and the message information report, the service traffic conditions of each port can be intuitively displayed.
[0161] It should be noted that the application scenarios described in the embodiments of the present application above are for more clearly explaining the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those of ordinary skill in the art know that with the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems; moreover, the new embodiments of the present application can be combined with each other, and the new solutions formed by combining each embodiment are within the protection scope of the present application.
[0162] Based on the same inventive concept, the present application also provides a terminal. Specifically, it will be described in detail in combination with Figure 7 for detailed description.
[0163] Figure 7 shows a schematic hardware structure diagram of the terminal 230 provided by the embodiment of the present invention.
[0164] As Figure 7 shown, the terminal 230 may include:
[0165] A receiving module 701, configured to receive the message data of at least one domain controller collected by a traffic collector and the message transmission information for transmitting the message data; the traffic collector is connected to the at least one domain controller;
[0166] A parsing module 702, configured to parse the message data to obtain traffic data information;
[0167] A searching module 703, configured to search, from a preset service statistic record, for a target service statistic entry of the domain controller that corresponds to both the traffic data information and the message transmission information, where the service statistic record includes a plurality of service statistic entries corresponding to each port of the domain controller, the plurality of service statistic entries include the target service statistic entry, and the plurality of service statistic entries are used to record the traffic data information of different services in the domain controller;
[0168] A first recording module 704, configured to record the traffic data information into the target service statistic entry.
[0169] Optionally, the searching module 703 may include:
[0170] A first search sub-module, configured to search, according to the traffic data information and the packet transmission information, for a target hash node that matches both the traffic data information and the packet transmission information in a pre-acquired packet hash table, where the packet hash table stores a plurality of hash nodes, and each hash node includes a mapping relationship between traffic data information, packet transmission information, and a service statistical entry;
[0171] A determination sub-module, configured to, when the target hash node exists in the packet hash table, determine the service statistical entry in the target hash node as the target service statistical entry.
[0172] Optionally, the first search sub-module is specifically configured to:
[0173] Using the five-tuple information and the port as a first key value, search in the packet hash table for a hash node corresponding to the first key value to obtain the target hash node.
[0174] Optionally, the terminal 230 includes:
[0175] A new creation sub-module, configured to, when the target hash node does not exist in the packet hash table, create a hash node according to the five-tuple information and the port to obtain a first hash node;
[0176] A second search sub-module, configured to use the five-tuple information and the port as a second key value to traverse the service statistical records, and search in the service statistical records for a service statistical entry corresponding to the second key value to obtain a first service statistical entry;
[0177] A storage sub-module, configured to associatively store the five-tuple information, the port, and the first service statistical entry into the first hash node.
[0178] Optionally, the terminal 230 includes:
[0179] A calculation module, configured to, in a preset first period, calculate, based on the time stamp, the position of the traffic data information in a traffic time-sharing cumulative node in the target service statistical entry, where the traffic time-sharing cumulative node is used to record traffic data information received within a second period, and the second period is less than the first period;
[0180] A recording module, configured to record the traffic data information at the position;
[0181] A first acquisition module, configured to, in the first period, starting from the position as a starting node, sequentially acquire the traffic rate of the traffic data information recorded by each traffic time-sharing cumulative node;
[0182] The first determination module is configured to determine the traffic rate with the largest value in the first period as the first traffic rate peak value.
[0183] Optionally, the terminal 230 includes:
[0184] The second acquisition module is configured to sequentially acquire the second traffic rate peak values within each of the first periods during the traffic statistics process;
[0185] The second determination module is configured to determine the second traffic rate peak value as the target traffic rate peak value when the second traffic rate peak value is greater than the first traffic rate peak value.
[0186] Optionally, the terminal 230 includes:
[0187] The third acquisition module is configured to acquire the sum of the packet data received during the traffic statistics process;
[0188] The second calculation module is configured to calculate the traffic rate average value of the target service statistical table entry based on the sum of the packet data and the statistical period of the traffic statistics process;
[0189] The second recording module is configured to record the target traffic rate peak value and the traffic rate average value into the target service statistical table entry.
[0190] Optionally, the terminal 230 is specifically configured to:
[0191] When the traffic statistics ends, output a service traffic statistics report corresponding to the service statistical record, and output a packet information report corresponding to the packet hash table.
[0192] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, only the above division of each functional unit and module is used as an example. In practical applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of each functional unit and module are only for the convenience of mutual distinction and do not limit the protection scope of the present application. The specific working processes of the units and modules in the above system can refer to the corresponding processes in the foregoing method embodiments and will not be described in detail here.
[0193] Figure 8The figure shows a schematic hardware structure diagram of a traffic statistics device provided by an embodiment of the present invention.
[0194] The traffic statistics device may include a processor 801 and a memory 802 storing computer program instructions.
[0195] Specifically, the above-mentioned processor 801 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present invention.
[0196] The memory 802 may include a mass storage for data or instructions. By way of example and not limitation, the memory 802 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disc, a magneto-optical disc, a magnetic tape, or a universal serial bus (USB) drive or a combination of two or more of these. In a suitable case, the memory 802 may include a removable or non-removable (or fixed) medium. In a suitable case, the memory 802 may be inside or outside the integrated gateway disaster recovery device. In a specific embodiment, the memory 802 is a non-volatile solid state memory.
[0197] In a specific embodiment, the memory 802 may include a read only memory (ROM), a random access memory (RAM), a magnetic disk storage media device, an optical storage media device, a flash memory device, an electrical, optical, or other physical / tangible memory storage device. Thus, generally, the memory 802 includes one or more tangible (non-transitory) computer-readable storage media (e.g., a memory device) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors 801), it is operable to perform the operations described with reference to the method according to one aspect of the present application.
[0198] The processor 801 reads and executes the computer program instructions stored in the memory 802 to implement any one of the traffic statistics methods in the above embodiments.
[0199] In one example, the traffic statistics device may further include a communication interface 803 and a bus 804. Among them, as shown in the figure, the processor 801, the memory 802, and the communication interface 803 are connected through the bus 804 to complete the communication with each other.
[0200] The communication interface 803 is mainly used to implement the communication between the various modules, devices, units, and / or devices in the embodiments of the present invention.
[0201] The bus 804 includes hardware, software, or both. By way of example and not limitation, the bus 804 may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, a wireless bandwidth interconnect, a Low Pin Count (LPC) bus, a memory bus, a MicroChannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses or a combination of two or more of these. Where appropriate, the bus 804 may include one or more buses 804. Although embodiments of the present application describe and illustrate specific buses 804, the present application contemplates any suitable bus 804 or interconnect.
[0202] In addition, in combination with the method in the above embodiments, embodiments of the present application can be implemented by providing a storage medium. Program instructions are stored on the storage medium; when the program instructions are executed by a processor, any one of the methods in the above embodiments is implemented.
[0203] Embodiments of the present application further provide a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement each process of the above method embodiments, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0204] It should be understood that the chip mentioned in embodiments of the present application may also be referred to as a system-on-chip, system chip, chip system, or system-on-chip.
[0205] Embodiments of the present application provide a computer program product. The program product is stored in a storage medium. The program product is executed by at least one processor to implement each process of the above method embodiments, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0206] It should be clear that the present application is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and illustrated as examples. However, the method process of the present application is not limited to the specific steps described and illustrated. Those skilled in the art can make various changes, modifications, and additions, or change the order between steps after understanding the spirit of the present application.
[0207] The functional modules shown in the above structural block diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application-specific integrated circuit (ASIC), appropriate firmware, a plug-in, a functional card, and so on. When implemented in software, the elements of the present application are programs or code segments used to perform the required tasks. The program or code segment can be stored in a machine-readable medium or transmitted via a data signal carried in a carrier wave over a transmission medium or a communication link. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical discs, hard disks, fiber optic media, radio frequency (RF) links, and so on. The code segment can be downloaded via a computer network such as the Internet, an intranet, and so on.
[0208] It should also be noted that the exemplary embodiments mentioned in the present application describe some methods or systems according to a series of steps or devices. However, the present application is not limited to the order of the above steps. That is, the steps can be executed in the order mentioned in the embodiments, can be different from the order in the embodiments, or several steps can be executed simultaneously.
[0209] As described above with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and program products according to embodiments of the present disclosure. It should be understood that each block in the flowchart and / or block diagram, and the combination of blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to generate a machine such that the instructions executed by the processor of the computer or other programmable data processing device enable the implementation of the functions / actions specified in one or more blocks of the flowchart and / or block diagram. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It can also be understood that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can also be implemented by dedicated hardware that performs the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0210] The above is only the specific implementation manner of the present application. Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, modules, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein. It should be understood that the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present application.
Claims
1. A traffic statistics method, characterized in that, Including: Receiving the message data of at least one domain controller collected by a traffic collector and the message transmission information for transmitting the message data; The traffic collector is connected to the at least one domain controller; Analyzing the message data to obtain traffic data information; Searching in a preset service statistics record for a target service statistics table entry of the domain controller that corresponds to both the traffic data information and the message transmission information, where the service statistics record includes multiple service statistics table entries corresponding to the respective domain controllers, and the multiple service statistics table entries are used to record traffic data information of different services in the domain controller; Recording the traffic data information in the target service statistics table entry.
2. The traffic statistics method according to claim 1, characterized in that, The searching in a preset service statistics record for a target service statistics table entry of the domain controller that corresponds to both the traffic data information and the message transmission information includes: According to the traffic data information and the message transmission information, searching in a pre-acquired message hash table for a target hash node that matches both the traffic data information and the message transmission information, where the message hash table stores multiple hash nodes, and each hash node includes a mapping relationship between traffic data information, message transmission information, and a service statistics table entry; When the target hash node exists in the message hash table, determining the service statistics table entry in the target hash node as the target service statistics table entry.
3. The traffic statistics method according to claim 2, wherein The traffic data information includes five-tuple information; the message transmission information includes the port of the domain controller that transmits the message data; The searching in a pre-acquired message hash table for a target hash node that matches the traffic data information according to the traffic data information and the message transmission information includes: Using the five-tuple information and the port as a first key value, searching in the message hash table for a hash node corresponding to the first key value to obtain the target hash node.
4. The traffic statistics method according to claim 3, characterized in that After the searching in a pre-acquired message hash table for a target hash node that matches both the traffic data information and the message transmission information according to the traffic data information and the message transmission information, the method further includes: When the target hash node does not exist in the message hash table, creating a new hash node according to the five-tuple information and the port to obtain a first hash node; Using the five-tuple information and the port as a second key value, traversing the service statistics record to search in the service statistics record for a service statistics table entry corresponding to the second key value to obtain a first service statistics table entry; Associatively storing the five-tuple information, the port, and the first service statistics table entry in the first hash node.
5. The traffic statistics method according to claim 1, wherein The message transmission information includes a timestamp when the message data is received; After the recording the traffic data information in the target service statistics table entry, the method further includes: In a preset first period, based on the time stamp, calculate the position of the traffic time-sharing cumulative node where the traffic data information is located in the target service statistical table entry. The traffic time-sharing cumulative node is used to record the traffic data information received within a second period, and the second period is less than the first period; Record the traffic data information into the position; In the first period, starting from the position as the starting node, sequentially obtain the traffic rate of the traffic data information recorded by each traffic time-sharing cumulative node; Determine the traffic rate with the largest value in the first period as the first traffic rate peak; After determining the traffic rate with the largest value in the first period as the first traffic rate peak, the method further includes: During the traffic statistics process, sequentially obtain the second traffic rate peaks within each first period; When the second traffic rate peak is greater than the first traffic rate peak, determine the second traffic rate peak as the target traffic rate peak.
6. The traffic statistics method according to claim 5, characterized in that, After determining the second traffic rate peak as the target traffic rate peak when the second traffic rate peak is greater than the first traffic rate peak, the method further includes: Obtain the sum of the packet data received during the traffic statistics process; Based on the sum of the packet data and the statistical period of the traffic statistics process, calculate the traffic rate average value of the target service statistical table entry; Record the target traffic rate peak and the traffic rate average value into the target service statistical table entry.
7. A traffic statistics system, characterized in that, The system includes: At least one domain controller; A traffic collector communicatively connected to the at least one domain controller, for collecting the packet data of the at least one domain controller and transmitting the packet data to the terminal; A terminal communicatively connected to the traffic collector, and the terminal is used to execute the method according to any one of claims 1-6.
8. A terminal, characterized in that, The terminal includes: A receiving module, configured to receive the packet data of at least one domain controller collected by the traffic collector and the packet transmission information for transmitting the packet data; the traffic collector is connected to the at least one domain controller; An analysis module, configured to analyze the packet data to obtain traffic data information; A search module, configured to search, from a preset service statistical record, for the target service statistical table entry of the domain controller corresponding to both the traffic data information and the packet transmission information. The service statistical record includes multiple service statistical table entries corresponding to each port of the domain controller, and the multiple service statistical table entries include the target service statistical table entry, and the multiple service statistical table entries are used to record the traffic data information of different services in the domain controller; A first recording module, configured to record the traffic data information into the target service statistical table entry.
9. A traffic statistics device, characterized in that, The device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, the method according to any one of claims 1-6 is implemented.
10. A computer-readable storage medium, characterized in that, Computer program instructions are stored on the computer-readable storage medium, and when the computer program instructions are executed by a processor, the method described in any one of claims 1-6 is implemented.
11. A vehicle, characterized in that, The vehicle includes at least one of the traffic statistics system described in claim 7, the terminal described in claim 8, and the traffic statistics device described in claim 9.