Dyeing method for flow detection, flow detection method, device and medium
By filling in the data flow field of the dyeing information, the device identification and flow identification of the detection node are generated and sent to the second detection node, the problem of difficulty in determining the correspondence relationship between the service flow and the detection node is solved, and efficient flow detection is achieved.
Patent Information
- Application Number
- CN202311834341.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-27
- Publication Date
- 2025-06-27
AI Technical Summary
When multiple detection nodes perform flow-access detection, since there is only flow identification of data packets in the dyeing information and no device identification of the detection node, the correspondence between the service flow and the detection node cannot be determined, which reduces the efficiency of flow-access detection.
By filling in the data stream field of the dyeing information with the device identifier of the first detection node and the flow identifier assigned by the server to the first detection node, a target data message is generated and sent to the second detection node, so that the second detection node can quickly perform detection based on the above-mentioned dyeing information.
It realizes that the device identification of the detection node and the flow identification are quickly corresponded without increasing system overhead while keeping the length of the original dyeing information data unchanged, which improves the efficiency of flow detection.
Smart Images

Figure CN120223585A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a coloring method for in-flow detection, an in-flow detection method, an electronic device, and a storage medium. Background Art
[0002] In-flow detection technology is a technology used for fault location and performance detection of data packets during transmission. By using in-flow detection technology, the transmission performance of data packets sent by users can be detected, which has the characteristics of good real-time performance and high accuracy.
[0003] When performing in-flow detection on multiple detection nodes, since only the flow identifier of the data packet exists in the coloring information and there is no device identifier of the detection node, the corresponding relationship between the service flow and the detection node cannot be determined, reducing the efficiency of in-flow detection; in the related technical solutions, two extended fields are added to the packet header information to represent the flow identifier of the data packet and the device identifier of the detection node, but the above solutions cannot be compatible with the original detection system and will increase the system overhead. Summary of the Invention
[0004] This application provides a coloring method for in-flow detection, an in-flow detection method, an electronic device, and a storage medium.
[0005] An embodiment of this application provides a coloring method for in-flow detection, which is applied to a first detection node. The method includes: generating a target data packet according to the obtained coloring information and the data packet to be detected; wherein, the coloring information includes a data flow field, and the data flow field is filled with the device identifier of the first detection node and the flow identifier assigned by the server to the first detection node, and the flow identifier is used to identify the service flow corresponding to the data packet to be detected processed by the first detection node; sending the target data packet to a second detection node.
[0006] An embodiment of this application provides an in-flow detection method, which is applied to a second detection node. The method includes: in response to the target data packet sent by the first detection node, obtaining the coloring information and the data packet to be detected in the target data packet; wherein, the coloring information includes a data flow field, and the data flow field is filled with the device identifier of the first detection node and the flow identifier assigned by the server to the first detection node, and the flow identifier is used to identify the service flow corresponding to the data packet to be detected processed by the first detection node; performing in-flow detection on the data packet to be detected according to the coloring information to obtain a detection result.
[0007] An embodiment of the present application provides a coloring method for in-flow detection, which is applied to a server. The method includes: responding to an identification acquisition request sent by a first detection node, and acquiring the device identification of the first detection node; according to the device identification of the first detection node, allocating a corresponding flow identification for the first detection node, where the flow identification is used to identify the service flow corresponding to the data packet to be detected processed by the first detection node; generating an identification acquisition response according to the device identification of the first detection node, the flow identification of the first detection node, and the detection category information; and sending the identification acquisition response to the first detection node.
[0008] An embodiment of the present application provides an electronic device, including: one or more processors; a memory, on which one or more programs are stored. When the one or more programs are executed by the one or more processors, the one or more processors implement any one of the coloring methods for in-flow detection or in-flow detection methods in the embodiments of the present application.
[0009] An embodiment of the present application provides a readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements any one of the coloring methods for in-flow detection or in-flow detection methods in the embodiments of the present application.
[0010] According to the coloring method for in-flow detection, in-flow detection method, electronic device, and storage medium in the embodiments of the present application, by filling the device identification of the first detection node and the flow identification allocated by the server to the first detection node in the data stream field of the coloring information, where the flow identification is used to identify the service flow corresponding to the data packet to be detected processed by the first detection node, it is possible to quickly correspond the device identification of the first detection node with the flow identification of the first detection node on the premise of keeping the data length of the original coloring information unchanged, without adding additional system overhead, and ensuring compatibility with the original detection system; further, by generating a target data packet according to the coloring information and the data packet to be detected, and sending the target data packet to a second detection node, so that the second detection node can quickly detect the data packet to be detected according to the above coloring information, improving the efficiency of in-flow detection.
[0011] More descriptions about the above embodiments and other aspects of the present application and their implementation manners are provided in the accompanying drawings, specific implementation manners, and claims. Description of the Drawings
[0012] Figure 1 A schematic structural diagram of an in-flow detection data packet provided by a related embodiment is shown.
[0013] Figure 2 A schematic flowchart of the coloring method for in-flow detection provided by an embodiment of the present application is shown.
[0014] Figure 3Shows a schematic structural diagram of the target data packet provided by the embodiments of the present application.
[0015] Figure 4 Shows a schematic flow diagram of the in-flow detection method provided by the embodiments of the present application.
[0016] Figure 5 Shows a schematic flow diagram of the coloring method for in-flow detection provided by the embodiments of the present application.
[0017] Figure 6 Shows a schematic diagram of the in-flow detection system provided by the embodiments of the present application.
[0018] Figure 7 Shows a block diagram of the composition of the first detection node provided by the embodiments of the present application.
[0019] Figure 8 Shows a block diagram of the composition of the second detection node provided by the embodiments of the present application.
[0020] Figure 9 Shows a block diagram of the composition of the server provided by the embodiments of the present application.
[0021] Figure 10 Shows a block diagram of the composition of the electronic device provided by the embodiments of the present application. Detailed implementation manners
[0022] To enable those skilled in the art to better understand the technical solutions of the present application, the following makes descriptions of the exemplary embodiments of the present application in conjunction with the accompanying drawings. Various details of the embodiments of the present application are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present application. Similarly, for the sake of clarity and conciseness, the descriptions of well-known functions and structures are omitted below.
[0023] Without conflict, the embodiments of the present application and the features in the embodiments can be combined with each other.
[0024] As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items. The terms used herein are for the purpose of describing particular embodiments only and are not intended to limit the present application. As used herein, the singular forms "a" and "the" are also intended to include the plural forms unless the context clearly indicates otherwise. It will also be understood that when the terms "comprises" and / or "consists of" are used in this specification, the specified features, integers, steps, operations, elements, and / or components are present, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. Terms such as "connected" or "coupled" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect.
[0025] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning that is consistent with their meaning in the context of the relevant art and this application, and will not be interpreted in an idealized or overly formal sense unless expressly so defined herein.
[0026] The in-flow detection technology is a technology for fault location and performance detection of data packets during transmission. By using the in-flow detection technology, the transmission performance of the data packets sent by users can be detected, and it has the characteristics of good real-time performance and high accuracy.
[0027] In the prior art, since only the identifier for characterizing the service flow exists in the coloring information, and it is impossible to accurately determine which detection node processes the service flow only relying on the identifier of the service flow, the corresponding relationship between the service flow and the detection node cannot be clarified.
[0028] In order to clarify the corresponding relationship between the service flow and the detection node, the relevant technical solutions will add two new fields in the coloring information to characterize the type and data length of the detection node. For example, Figure 1 The structural schematic diagram of the in-flow detection data packet provided by the related embodiment is shown. As Figure 1 shown, the in-flow detection data packet includes: Option Type, Opt Data Len which is the data length of the selected type, the coloring information including the data flow field, and the data packet to be transmitted.
[0029] Among them, Option Type and Opt Data Len are newly added fields used to characterize the type and data length of the detection node. That is, Option Type represents the identifier of the detection node; Opt Data Len represents the length of the data field corresponding to Option Type, in bytes.
[0030] However, compared with the data structure in the prior art that only includes coloring information and the data packet to be transmitted, the newly added Option Type and Opt Data Len increase the data length, resulting in a larger system overhead and being incompatible with the data structure in the original in-flow detection system.
[0031] This application provides a coloring method for in-flow detection, an in-flow detection method, an electronic device, and a storage medium to solve the above problems.
[0032] Figure 2 The flowchart of the coloring method for in-flow detection provided by the embodiments of this application is shown. This method can be applied to the first detection node. As Figure 2 shown, the coloring method for in-flow detection in the embodiments of this application includes but is not limited to the following steps.
[0033] Step S201: Generate a target data packet based on the obtained coloring information and the data packet to be detected.
[0034] Among them, the coloring information includes a data flow field, and the device identifier of the first detection node and the flow identifier assigned by the server to the first detection node are filled in the data flow field. The flow identifier is used to identify the service flow corresponding to the data packet to be detected processed by the first detection node.
[0035] The service flow corresponding to the data packet to be detected refers to the data flow formed by the transmission of data of a service between multiple detection nodes. Each service flow corresponds to a flow identifier to facilitate distinguishing the data flows between different services.
[0036] It should be noted that the data packet to be detected can be the service data packet in the service flow received by the first detection node or the service data packet generated by the first detection node; and this data packet to be detected is the packet that the first detection node needs to send to the second detection node.
[0037] By encapsulating the coloring information and the data packet to be detected to generate a target data packet, it is possible to perform packet detection on the target data packet based on this coloring information during the transmission process to determine the transmission characteristics of the target data packet, such as whether there is a packet loss phenomenon in the target data packet and what the transmission delay corresponding to the target data packet is, etc.
[0038] Step S202: Send the target data packet to the second detection node.
[0039] Among them, the second detection node is the receiving node of the target data packet (for example, the second detection node needs to use the data packet to be detected to complete its service processing) or the forwarding node (for example, when the second detection node receives the target data packet, the second detection node will also forward the target data packet to other detection nodes). Moreover, since the data flow field filled with the device identifier of the first detection node and the flow identifier of the first detection node is unique throughout the network, when the second detection node receives the target data packet, the second detection node can uniquely determine the data packet to be detected sent by the first detection node based on the data flow field carried by the first detection node. Furthermore, the second detection node can perform in-flow detection on the data packet to be detected, which can accelerate the recognition speed of the data packet to be processed and improve the efficiency of in-flow detection. In this embodiment, by filling the device identifier of the first detection node and the flow identifier assigned by the server to the first detection node in the data flow field of the coloring information, where the flow identifier is used to identify the service flow corresponding to the data packet to be detected processed by the first detection node, it is possible to quickly correspond the device identifier of the first detection node with the flow identifier of the first detection node without changing the data length of the original coloring information, without adding additional system overhead, and ensuring compatibility with the original detection system. Further, by generating the target data packet based on the coloring information and the data packet to be detected and sending the target data packet to the second detection node, the second detection node can quickly detect the data packet to be detected according to the above coloring information, improving the efficiency of in-flow detection.
[0040] Figure 3 Show a schematic structural diagram of the target data packet provided by an embodiment of the present application. As Figure 3 shown, the target data packet includes coloring information and the data packet to be detected. Among them, the coloring information includes a data flow field and detection category information, and the device identifier and the flow identifier are filled in the data flow field.
[0041] In some embodiments, different division ratios can be used to respectively determine the data lengths occupied by the device identifier and the flow identifier. For example, if the data length of the data flow field is set to 20 bits (bit), the first 8 bits of the data flow field can be set to represent the device identifier, and the subsequent 12 bits can be set to represent the flow identifier.
[0042] Among them, the detection category information includes at least one of the following: packet loss detection information, delay detection information, data transmission path detection information, wrong packet information, and bandwidth utilization information.
[0043] Among them, data reservation bits can be used to identify packet error information and / or bandwidth utilization information, so as to count the packet error situation in the data packet to be detected based on the identified packet error information, and obtain the packet error ratio; and / or, based on the identified bandwidth utilization information, determine the ratio between the bandwidth occupied by the data packet to be detected and the configured bandwidth in the communication system (i.e., bandwidth utilization).
[0044] For example, it is set that L represents packet loss detection information, that is, during the in-flow detection process, it is necessary to detect the packet loss situation (such as the number of packet losses, packet loss ratio, etc.) of the data packet to be detected.
[0045] It can also be set that D represents delay detection information, that is, during the in-flow detection process, it is necessary to detect the delay information (such as the magnitude of the transmission delay, etc.) of the data packet to be detected.
[0046] Using the above data structure to represent the target data packet can ensure compatibility with the original detection system without increasing additional system overhead, enabling the second detection node to obtain both the device identifier of the first detection node and the flow identifier of the service flow corresponding to the data packet to be detected processed by the first detection node, so that the second detection node can quickly detect the data packet to be detected and improve the efficiency of in-flow detection.
[0047] In some exemplary embodiments, before generating the target data packet according to the obtained coloring information and the data packet to be detected in step S201, the method further includes: sending an identifier acquisition request to the server, where the identifier acquisition request includes the device identifier of the first detection node; in response to the identifier acquisition response feedback by the server, obtaining the flow identifier and detection category information assigned by the server to the first detection node; and determining the coloring information based on the device identifier of the first detection node, the flow identifier of the first detection node, and the detection category information.
[0048] Among them, the device identifier of the first detection node includes: the device coding information of the first detection node and / or the network address information of the first detection node. The device coding information of the first detection node is the coding value and / or physical address set when the first detection node leaves the factory. The network address information of the detection node may include at least one of the following information: the port number of the detection node, the data transmission protocol number corresponding to the detection node, and the Internet Protocol (IP) address of the detection node.
[0049] It should be noted that the identity acquisition request sent by the first detection node to the server is a request message for acquiring the flow identity and / or detection category information assigned by the server to the first detection node. By the server assigning a flow identity of the service flow corresponding to the data packet to be detected processed by the first detection node, it can be clarified which service flow the data packet to be detected processed by the first detection node belongs to, so as to correspond the device identity of the first detection node with the flow identity of the service flow, which is convenient for the first detection node to update the coloring information, so that the coloring information can better indicate the in-flow detection of the data packet to be detected and improve the efficiency of in-flow detection.
[0050] In some exemplary embodiments, the data flow field includes a first field and a second field; the method for determining the coloring information includes: filling the device identity of the first detection node into the first field and filling the flow identity of the first detection node into the second field; determining the coloring information according to the data flow field and the detection category information.
[0051] Wherein, the data lengths of the first field and the second field in the data flow field may be the same or different. For example, based on a preset ratio and the original data length of the data flow field, the data lengths of the first field and the second field are determined to facilitate filling different identity information in the first field and the second field.
[0052] For example, if it is set that the data lengths of the first field and the second field are the same, and the original data length of the data flow field is 20 bit, then it can be calculated that the data lengths of both the first field and the second field are 10 bit.
[0053] For another example, if the preset ratio is set to 2:3 and the original data length of the data flow field is 20 bit, then it can be calculated that the data length of the first field is 20 * 2 / 5 = 8 bit, and the data length of the second field is 20 * 3 / 5 = 12 bit.
[0054] Moreover, the sequence order of the first field and the second field in the data flow field can also be set, as long as the data structures of the data flow fields used by each detection node are the same. For example, the first field occupies the first 8 bit (or, the first field occupies the last 8 bit) in the data flow field, and the second field occupies the last 12 bit (or, the first field occupies the first 12 bit) in the data flow field.
[0055] By filling the device identifier of the first detection node into the first field and filling the flow identifier of the first detection node into the second field, the filled data flow field can represent both the device identifier of the first detection node and the flow identifier of the first detection node, thereby realizing the correspondence between the first detection node and the flow identifier corresponding to the data packet to be detected processed by it, and accelerating the speed of in-flow detection of the data packet to be detected.
[0056] In some exemplary embodiments, before generating the target data packet according to the obtained coloring information and the data packet to be detected in step S201, the method further includes: screening multiple service data packets in the received service flow according to the access control list information to obtain an initial screened packet set; sampling the service data packets in the initial screened packet set to obtain the data packet to be detected.
[0057] The access control list information includes at least one of the following information: the network address of the first detection node, the data transmission protocol number, and the port number information of the first detection node.
[0058] Access Control Lists (ACL) information is a list of instructions applied to router interfaces. ACL information is used to indicate which data packets the router can receive and which data packets to reject.
[0059] When the first detection node processes multiple received service data packets according to the ACL information, if it is determined that a certain service data packet matches a certain ACL statement in the ACL information, it will skip the remaining other statements in the ACL information and determine to receive (or reject) the service data packet according to the content of the matching ACL statement.
[0060] If the content of the i-th service data packet does not match the j-th statement in the ACL information, the (j + 1)-th statement in the ACL information will be used to match the i-th service data packet until all statements in the ACL information have been matched. Wherein, both i and j are integers greater than or equal to 1; i and j can be the same or different.
[0061] For example, when the first detection node obtains N data packets, it can sequentially screen the N data packets based on the network address (and / or, data transmission protocol number, and / or, port number information of the first detection node) in the access control list information to determine which data packets the first detection node can receive. Wherein, N is an integer greater than or equal to 1.
[0062] For example, when it is determined that a certain data packet among N data packets satisfies at least one of the following conditions, it is determined that the service data packet in the initial screening packet set is obtained:
[0063] The network address of the target node of a certain data packet is the same as the network address of the first detection node;
[0064] The port number information of the target node of a certain data packet is the same as the port number information of the first detection node;
[0065] The data transmission protocol number of the target node of a certain data packet is the same as the data transmission protocol number used by the first detection node (for example, both use the protocol number of Internet Protocol version 4 (IPv4)).
[0066] Furthermore, sample the service data packets in the initial screening packet set. For example, perform at least one of the following sampling methods on the service data packets in the initial screening packet set: simple random sampling, systematic random sampling, stratified sampling, population sampling, and overall sampling, etc., so that the obtained data packets to be detected meet the transmission requirements and the requirements of in-flow detection.
[0067] In some embodiments, the first detection node can also match the device identifier and the flow identifier of the first detection node to generate a feature correspondence relationship, and send the feature correspondence relationship to the analysis device, so that the analysis device can perform information statistics on the data packets sent by the first detection point according to the feature correspondence relationship to obtain the in-flow detection statistical result.
[0068] Among them, the in-flow detection statistical result includes at least one of the following: the packet loss ratio information of the data packets to be detected during the transmission process, the transmission delay information of the data packets to be detected, and the transmission path information of the data packets to be detected.
[0069] Figure 4 The flowchart of the in-flow detection method provided by the embodiments of the present application is shown. This method can be applied to the second detection node. As Figure 4 shown, the in-flow detection method in the embodiments of the present application includes but is not limited to the following steps.
[0070] Step S401, in response to the target data packet sent by the first detection node, obtain the coloring information and the data packet to be detected in the target data packet.
[0071] Among them, the coloring information includes a data flow field, and the data flow field is filled with the device identifier of the first detection node and the flow identifier assigned by the server to the first detection node. The flow identifier is used to identify the service flow corresponding to the data packet to be detected processed by the first detection node.
[0072] Step S402: Perform in-flow detection on the data packet to be detected according to the coloring information, and obtain a detection result.
[0073] Among them, performing in-flow detection on the data packet to be detected is to perform fault location and performance detection on the data packet to be detected during the transmission process, which can realize the detection of the transmission performance of the data packet to be detected during the transmission process, and has the characteristics of good detection real-time performance and high accuracy.
[0074] Moreover, since the device identifiers of different detection nodes are different and will not be repeated, the data flow field filled with the device identifier of the first detection node and the flow identifier of the first detection node is unique throughout the network. It can uniquely determine the data packet to be detected sent by the first detection node; furthermore, performing in-flow detection on the data packet to be detected based on this data flow field can accelerate the recognition speed of the data packet to be processed and improve the efficiency of in-flow detection.
[0075] In this embodiment, by responding to the target data packet sent by the first detection node, obtaining the coloring information and the data packet to be detected in the target data packet, it is possible to clarify the flow identifier of the service flow corresponding to the data packet to be detected that needs to be subjected to in-flow detection in the target data packet sent by the first detection node, and quickly correspond this flow identifier with the device identifier of the first detection node, without the need to add additional system overhead, and can ensure compatibility with the original detection system; performing in-flow detection on the data packet to be detected according to the coloring information makes the obtained detection result more accurate and improves the efficiency of in-flow detection.
[0076] In some exemplary embodiments, after performing in-flow detection on the data packet to be detected according to the coloring information in step S402 and obtaining a detection result, the method further includes: uploading the detection result to an analysis device.
[0077] Among them, the analysis device is used to perform statistics on the detection result according to the feature correspondence relationship to obtain an in-flow detection statistical result, and the feature correspondence relationship is the correspondence relationship between the device identifier of the first detection node and the flow identifier of the first detection node.
[0078] The in-flow detection statistical result includes at least one of the following: packet loss ratio information of the data packet to be detected during the transmission process, transmission delay information of the data packet to be detected, and transmission path information passed by the data packet to be detected.
[0079] It should be noted that the analysis device can obtain the feature correspondence of multiple detection nodes to determine the number of detection nodes that the data packet to be detected in the same service flow passes through during transmission (for example, a data packet to be detected can pass through the transmission of 5 detection nodes), as well as the device identifiers of each detection node, so as to obtain the transmission path information of the data packet to be detected in the entire transmission process of the service flow.
[0080] Furthermore, as the data packet to be detected is transmitted among multiple detection nodes (for example, transmitted between the first detection node and the second detection node, or transmitted among 5 detection nodes, etc.), the analysis device can, based on the packet loss ratio information between every two adjacent detection nodes, count the packet loss situation in the entire transmission path to determine whether the data packet to be detected has excessive packet loss, and clarify which transmission path has the highest packet loss ratio, so as to instruct the server to adjust the transmission channel of the transmission path with the highest packet loss ratio to improve the transmission efficiency of the data packet to be detected.
[0081] And / or, the analysis device, based on the transmission delay information between every two adjacent detection nodes, counts the transmission delay information of the data packet to be detected during transmission among multiple detection nodes. This is to facilitate clarifying the transmission path with a transmission delay greater than the preset delay threshold and instructing the detection node to perform abnormal processing, thereby reducing the transmission delay of the data packet to be detected and improving the transmission efficiency of the data packet to be detected.
[0082] Figure 5 The flowchart of the coloring method for in-flow detection provided by the embodiments of the present application is shown. This method can be applied to a server. As Figure 5 shown, the coloring method for in-flow detection in the embodiments of the present application includes but is not limited to the following steps.
[0083] Step S501, in response to the identity acquisition request sent by the first detection node, acquire the device identifier of the first detection node.
[0084] Among them, the identity acquisition request includes the device identifier of the first detection node. The server can obtain the device identifier of the first detection node by parsing the identity acquisition request. For example, the device coding information of the first detection node, and / or the network address information of the detection node.
[0085] Step S502, based on the device identifier of the first detection node, allocate its corresponding flow identifier to the first detection node.
[0086] Among them, the flow identifier is used to identify the service flow corresponding to the data packet to be detected processed by the first detection node.
[0087] It should be noted that a service flow includes multiple data packets. The data packet to be detected is the packet that needs to be processed by the first detection node among the multiple data packets. By allocating the corresponding flow identifier to the first detection node, the device identifier of the first detection node and the flow identifier of the first detection node (i.e., the flow identifier corresponding to the service flow) can be associated, so as to realize the matching of the service flow corresponding to the data packet to be detected processed by the first detection node and accelerate the recognition speed of the data packet to be detected.
[0088] Step S503: Generate an identifier acquisition response based on the device identifier of the first detection node, the flow identifier of the first detection node, and the detection category information.
[0089] Among them, the detection category information is the information used to characterize the detection type for performing in-flow detection on the data packet to be detected. The detection category information includes at least one of the following: packet loss detection information, delay detection information, and data transmission path detection information.
[0090] By integrating the device identifier of the first detection node, the flow identifier of the first detection node, and the detection category information, an identifier acquisition response is generated, so that the identifier acquisition response can reflect the detection information of the data packet to be detected processed by the first detection node that the server hopes for, facilitating the first detection node to quickly fill in its corresponding coloring information and accelerating the in-flow detection speed of the data packet to be detected.
[0091] Step S504: Send the identifier acquisition response to the first detection node.
[0092] Among them, based on the obtained port number of the first detection node, the data transmission protocol number corresponding to the first detection node, and the IP address of the first detection node, the identifier acquisition response can be encapsulated, and the encapsulated message is sent to the first detection node, so that the first detection node can quickly and accurately obtain the flow identifier and detection category information of the first detection node it expects to obtain.
[0093] In this embodiment, by obtaining the device identifier of the first detection node, the node that needs to be allocated a flow identifier is identified; then, according to the device identifier of the first detection node, the corresponding flow identifier is allocated to the first detection node, so that the flow identifier can identify the service flow corresponding to the data packet to be detected processed by the first detection node, facilitating the first detection node to associate the flow identifier with its device identifier and accelerating its processing efficiency of service data; further, based on the device identifier of the first detection node, the flow identifier of the first detection node, and the detection category information, an identifier acquisition response is generated and sent to the first detection node, enabling the first detection node to quickly and accurately obtain the flow identifier allocated by the server for it, realizing the rapid correspondence between the service flow and the first detection node and improving the processing efficiency of the data packets in the service flow.
[0094] Figure 6 A schematic diagram showing the in-flow detection system provided by an embodiment of the present application. As Figure 6 shown, the in-flow detection system includes but is not limited to the following devices. A plurality of detection nodes (e.g., a first detection node 601, a second detection node 602, ……, an eighth detection node 608), a first server 611, a second server 612, and an analysis device 620.
[0095] Among them, the device identifier of each detection node includes: the device coding information of the detection node (e.g., the coding value and / or physical address set when the device leaves the factory), and / or, the network address information of the detection node (e.g., the port number of the detection node, the data transmission protocol number corresponding to the detection node, and the IP address of the detection node, etc.).
[0096] When data packets are transmitted between the respective detection nodes, the data structure of the target data packet shown in Figure 6 is adopted. As Figure 6 shown, the first field of the target data packet is the device identifier (for example, set to 5), the second field is the flow identifier (e.g., set to 100), the third field is the detection category information, and the remaining fields are the data packets to be transmitted that need to be transmitted.
[0097] The "L" in the detection category information represents packet loss detection information, that is, during the in-flow detection process, it is necessary to detect the packet loss situation of the data packet to be detected (such as the number of lost packets, the packet loss ratio, etc.).
[0098] The "D" represents delay detection information, that is, during the in-flow detection process, it is necessary to detect the delay information of the data packet to be detected (such as the magnitude of the transmission delay, etc.).
[0099] The "C" represents the validity of "L", that is, only when "C" is set to valid, the coloring information of the "L" bit is detected.
[0100] The "R" represents a reserved bit, which can be initialized to 0.
[0101] The first server 611 is used to obtain the device identifier of the fifth detection node 605, and allocate its corresponding flow identifier based on the device identifier of the fifth detection node 605. This flow identifier is used to identify the service flow corresponding to the data packet to be detected processed by the fifth detection node 605; generate an identifier acquisition response according to the device identifier of the fifth detection node 605, the flow identifier of the fifth detection node 605, and the detection category information; send the identifier acquisition response to the fifth detection node 605, so that the fifth detection node 605 can obtain the flow identifier corresponding to its device identifier, which is convenient for the fifth detection node 605 to dye the data packet to be transmitted to the third detection node 603 (or, the fourth detection node 604) and generate dyeing information.
[0102] The function of the second server 612 is similar to that of the first server 611, except that it is used to obtain the device identifier of the eighth detection node 608, allocate a flow identifier for the eighth detection node 608 correspondingly, and perform corresponding information processing, which will not be elaborated here.
[0103] The analysis device 620 is used to receive the detection results sent by each detection node. This detection result can represent the detection situation obtained during the per-flow detection between different detection nodes; further, the analysis device 620 will perform statistics on the detection results according to the feature correspondence relationship to obtain the per-flow detection statistical result.
[0104] Among them, the feature correspondence relationship is the correspondence relationship between the device identifier of the detection node corresponding to the detection result (for example, the fifth detection node 605) and the flow identifier of this detection node (that is, the fifth detection node 605); the per-flow detection statistical result includes at least one of the following: the packet loss ratio information of the data packet to be detected during the transmission process, the transmission delay information of the data packet to be detected, and the transmission path information that the data packet to be detected passes through.
[0105] In some embodiments, the first server 611 samples multiple data packets in the network flow (NetFlow) (for example, the maximum sampling ratio is 1:1) to obtain a new service flow and establish a flow table for this new service flow.
[0106] Among them, NetFlow is a unidirectional data packet flow transmitted between the same source IP address and destination IP address, and all data packets have the same transport layer source and destination port numbers.
[0107] When the fifth detection node 605 receives multiple service data packets in a new service flow and needs to process these service data packets (such as data forwarding or data parsing, etc.), the fifth detection node 605 will screen the multiple service data packets according to the access control list information to obtain an initial screened packet set; sample the service data packets in the initial screened packet set to obtain the data packets to be detected.
[0108] Among them, the access control list information includes at least one of the following information: the network address of the fifth detection node 605, the data transmission protocol number, and the port number information of the fifth detection node 605.
[0109] It should be noted that since the port numbers of the User Datagram Protocol (UDP) ports are randomly generated, the UDP port number information carried in each service data packet is inaccurate. Therefore, when screening service data packets, only the quadruple information of the service data packet (i.e., source IP address, destination IP address, data transmission protocol number, and destination port) can be used to match the access control list information.
[0110] After processing multiple service data packets in a new service flow in the above manner, the obtained data packets to be detected can be matched with the processing requirements of the fifth detection node 605, improving the accuracy of data packet sampling.
[0111] After determining the data packets to be detected, the fifth detection node 605 will also send an identifier acquisition request to the first server 611 to obtain the flow identifier assigned by the first server 611 to the fifth detection node 605.
[0112] In response to the identifier acquisition request sent by the fifth detection node 605, the first server 611 obtains the device identifier of the fifth detection node 605 carried in the identifier acquisition request; then, based on the device identifier of the fifth detection node 605, it assigns the corresponding flow identifier to the fifth detection node 605. This flow identifier is used to identify the service flow corresponding to the data packets to be detected processed by the fifth detection node 605. Further, the first server 611 generates an identifier acquisition response according to the device identifier of the fifth detection node 605, the flow identifier of the fifth detection node 605, and the detection category information; and sends the identifier acquisition response to the fifth detection node 605.
[0113] When the fifth detection node 605 receives the identity acquisition response, the fifth detection node 605 obtains the flow identity and detection category information of the fifth detection node 605 through parsing the identity acquisition response; then, the device identity of the fifth detection node 605 and the flow identity of the fifth detection node 605 are respectively filled in the data flow field in the coloring information, and the detection category information in the coloring information is updated based on the obtained detection category information; then, a target data packet is generated according to the obtained coloring information and the data packet to be detected, and the target data packet is sent to the third detection node 603 (or the fourth detection node 604).
[0114] For example, if it is set that the data flow field in the coloring information occupies a total of 20 bits, the device identity of the fifth detection node 605 can be filled in the first 8 bits of the data flow field in the coloring information, and the flow identity of the fifth detection node 605 can be filled in the subsequent 12 bits. Since the device identities of different detection nodes are different and do not repeat, the data flow field filled with the device identity of the fifth detection node 605 and the flow identity of the fifth detection node 605 is unique throughout the network. The data flow field in the coloring information can be used to uniquely determine the fifth detection node 605 and clarify the flow identity of the service flow corresponding to the fifth detection node 605.
[0115] Among them, the detection category information includes at least one of the following: packet loss detection information, delay detection information, data transmission path detection information, packet error information, and bandwidth utilization information.
[0116] When the third detection node 603 receives the target data packet sent by the fifth detection node 605, the third detection node 603 performs in-flow detection on the data packet to be detected based on the detection category information in the target data packet, so as to determine the possible packet loss information during the transmission of the data packet to be detected, and / or analyze the delay of data transmission, so as to determine the detection result.
[0117] In some embodiments, before data transmission, the third detection node 603 (and / or the fifth detection node 605) also determines a feature correspondence relationship based on the correspondence relationship between the device identity of the third detection node 603 (and / or the fifth detection node 605) and the flow identity of the third detection node 603 (and / or the fifth detection node 605), and sends the feature correspondence relationship to the analysis device 620, so that the analysis device 620 can perform statistics on the detection results based on the feature correspondence relationship to obtain the in-flow detection statistical results.
[0118] Among them, the in-flow detection statistical results include at least one of the following: packet loss ratio information of the data packet to be detected during transmission, transmission delay information of the data packet to be detected, and transmission path information passed by the data packet to be detected.
[0119] In this embodiment, by filling the device identifier of the detection node (e.g., the fifth detection node 605) and the flow identifier assigned by the server to the detection node in the data stream field of the coloring information, where the flow identifier is used to identify the service flow corresponding to the data packet to be detected processed by the detection node, it is possible to quickly correspond the device identifier of the detection node with the flow identifier of the detection node without increasing additional system overhead while keeping the data length of the original coloring information unchanged, and it can ensure compatibility with the original detection system. Moreover, the server can assign a corresponding flow identifier to the detection node based on the obtained device identifier of the detection node, so that the device identifier of the detection node matches its corresponding flow identifier and can be quickly recognized by other detection nodes, thereby improving the detection speed of flow detection.
[0120] Figure 7 The block diagram showing the composition of the first detection node provided by the embodiment of the present application is as follows. Figure 7 As shown, the first detection node 700 includes but is not limited to the following modules.
[0121] The generation module 701 is configured to generate a target data packet according to the obtained coloring information and the data packet to be detected.
[0122] Among them, the coloring information includes a data stream field, and the device identifier of the first detection node and the flow identifier assigned by the server to the first detection node are filled in the data stream field. The flow identifier is used to identify the service flow corresponding to the data packet to be detected processed by the first detection node.
[0123] The first sending module 702 is configured to send the target data packet to the second detection node.
[0124] It should be noted that the first detection node 700 in this embodiment can implement any coloring method for flow detection applied to the first detection node in the embodiment of the present application.
[0125] According to the first detection node of the embodiment of the present application, by filling the device identifier of the first detection node and the flow identifier assigned by the server to the first detection node in the data stream field of the coloring information, where the flow identifier is used to identify the service flow corresponding to the data packet to be detected processed by the first detection node, it is possible to quickly correspond the device identifier of the first detection node with the flow identifier of the first detection node without increasing additional system overhead while keeping the data length of the original coloring information unchanged, and it can ensure compatibility with the original detection system; further, by generating a target data packet according to the coloring information and the data packet to be detected using the generation module and sending the target data packet to the second detection node using the first sending module, the second detection node can quickly detect the data packet to be detected according to the above coloring information, improving the efficiency of flow detection.
[0126] Figure 8 The block diagram showing the components of the second detection node provided by an embodiment of the present application is as follows. As Figure 8 shown, the second detection node 800 includes but is not limited to the following modules.
[0127] A first acquisition module 801, configured to acquire the coloring information and the data packet to be detected in the target data packet in response to the target data packet sent by the first detection node.
[0128] Among them, the coloring information includes a data stream field, and the device identifier of the first detection node and the stream identifier assigned by the server to the first detection node are filled in the data stream field. The stream identifier is used to identify the service flow corresponding to the data packet to be detected processed by the first detection node.
[0129] A detection module 802, configured to perform in-flow detection on the data packet to be detected according to the coloring information to obtain a detection result.
[0130] It should be noted that the second detection node 800 in this embodiment can implement any in-flow detection method applied to the second detection node in the embodiments of the present application.
[0131] According to the second detection node of the embodiment of the present application, by the first acquisition module acquiring the coloring information and the data packet to be detected in the target data packet in response to the target data packet sent by the first detection node, it can clarify the stream identifier of the service flow corresponding to the data packet to be detected that needs to be detected in-flow in the target data packet sent by the first detection node, and quickly correspond the stream identifier with the device identifier of the first detection node, without adding additional system overhead, and can ensure compatibility with the original detection system; using the detection module to perform in-flow detection on the data packet to be detected according to the coloring information makes the obtained detection result more accurate and improves the efficiency of in-flow detection.
[0132] Figure 9 The block diagram showing the components of the server provided by an embodiment of the present application is as follows. As Figure 9 shown, the server 900 includes but is not limited to the following modules.
[0133] A second acquisition module 901, configured to acquire the device identifier of the first detection node in response to the identification acquisition request sent by the first detection node.
[0134] An allocation module 902, configured to allocate the corresponding stream identifier to the first detection node according to the device identifier of the first detection node.
[0135] Among them, the stream identifier is used to identify the service flow corresponding to the data packet to be detected processed by the first detection node.
[0136] A response generation module 903, configured to generate an identity acquisition response based on the device identity of the first detection node, the flow identity of the first detection node, and the detection category information.
[0137] A second sending module 904, configured to send the identity acquisition response to the first detection node.
[0138] It should be noted that the server 900 in this embodiment can implement any one of the coloring methods for in-flow detection applied to the server in the embodiments of the present application.
[0139] According to the server of the embodiment of the present application, the device identity of the first detection node is obtained through the second acquisition module to identify the node that needs to be allocated a flow identity; then, the allocation module uses the device identity of the first detection node to allocate the corresponding flow identity for the first detection node, so that the flow identity can identify the service flow corresponding to the data packet to be detected processed by the first detection node, facilitating the first detection node to correspond the flow identity with its device identity and accelerating its processing efficiency of service data; further, the response generation module generates an identity acquisition response based on the device identity of the first detection node, the flow identity of the first detection node, and the detection category information, and the second sending module sends the identity acquisition response to the first detection node, enabling the first detection node to quickly and accurately obtain the flow identity allocated by the server for it, realizing the quick correspondence between the service flow and the first detection node, and improving the processing efficiency of the data packets in the service flow.
[0140] It should be clear that the present application is not limited to the specific configurations and processes described and illustrated in the above embodiments. For the convenience and brevity of description, the detailed descriptions of known methods are omitted here, and the specific working processes of the systems, modules, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated here.
[0141] Figure 10 The block diagram showing the composition of an electronic device provided by an embodiment of the present application.
[0142] As Figure 10 shown, the electronic device includes: at least one processor 1001, at least one memory 1002, and one or more I / O interfaces 1003. Among them, the processor 1001, the memory 1002, and the I / O interface 1003 are interconnected through a bus 1004. The memory 1002 stores one or more computer programs, and the one or more computer programs are executed by at least one processor 1001, so that at least one processor 1001 can implement any one of the coloring methods for in-flow detection or in-flow detection methods recorded in the above embodiments.
[0143] Each module in the above electronic device can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.
[0144] An embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements any one of the dyeing methods or flow-through detection methods described in the above embodiments. The computer-readable storage medium can be a volatile or non-volatile computer-readable storage medium.
[0145] An embodiment of the present application also provides a computer program product, including computer-readable code, or a non-volatile computer-readable storage medium carrying the computer-readable code. When the computer-readable code runs in the processor of the electronic device, the processor in the electronic device executes the above dyeing method or flow-through detection method.
[0146] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and their appropriate combinations. In the hardware implementation, the division of the functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, a physical component can have multiple functions, or a function or step can be executed by several physical components in cooperation. Some or all physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or be implemented as hardware, or be implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable storage medium, which can include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium).
[0147] As is well known to those of ordinary skill in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information such as computer-readable program instructions, data structures, program modules, or other data. Computer storage media includes, but is not limited to, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), static random access memory (SRAM), flash memory or other memory technologies, portable compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical disc storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and that can be accessed by a computer. Additionally, as is well known to those of ordinary skill in the art, communication media typically embodies computer-readable program instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and can include any information delivery media.
[0148] The computer-readable program instructions described herein can be downloaded to each computing / processing device from a computer-readable storage medium or can be downloaded to an external computer or external storage device through a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, optical fiber transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium in each computing / processing device.
[0149] The computer program instructions for performing the operations of this application may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine - related instructions, microcode, firmware instructions, state - setting data, or source code or object code written in any combination of one or more programming languages, including object - oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer - readable program instructions may be executed entirely on the user's computer, partially on the user's computer, executed as a stand - alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider). In some embodiments, by using the state information of the computer - readable program instructions to customize an electronic circuit, such as a programmable logic circuit, a field - programmable gate array (FPGA), or a programmable logic array (PLA), the electronic circuit can execute the computer - readable program instructions to implement various aspects of this application.
[0150] The computer program product described herein may be implemented specifically in the form of hardware, software, or a combination thereof. In an alternative embodiment, the computer program product is specifically embodied as a computer storage medium. In another alternative embodiment, the computer program product is specifically embodied as a software product, such as a Software Development Kit (SDK), etc.
[0151] Aspects of this application are described herein with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of this application. It should be understood that each block of the flowcharts and / or block diagrams, and the combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer - readable program instructions.
[0152] These computer-readable program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus to produce a machine such that the instructions, when executed by the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in one or more boxes of the flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium that causes a computer, a programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer-readable medium storing the instructions comprises a manufacture including instructions for implementing various aspects of the functions / acts specified in one or more boxes of the flowchart and / or block diagram.
[0153] The computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process such that the instructions executed on the computer, other programmable data processing apparatus, or other device implement the functions / acts specified in one or more boxes of the flowchart and / or block diagram.
[0154] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a segment of code, or a portion of an instruction, and the module, segment of code, or portion of an instruction includes one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two consecutive blocks may in fact be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or acts, or by a combination of dedicated hardware and computer instructions.
[0155] Example embodiments have been disclosed herein, and although specific terms are employed, they are used in a generic and descriptive sense only and not for purposes of limitation. In some instances, it will be apparent to those skilled in the art that, unless otherwise expressly stated, the features, characteristics, and / or elements described in connection with a particular embodiment may be used singly or in combination with those described in connection with other embodiments. Accordingly, those skilled in the art will understand that various forms and details may be changed without departing from the scope of the present application as set forth by the appended claims.
Claims
1. A dyeing method for in-flow detection, wherein, Applied to the first detection node, the method includes: Generating a target data packet based on the obtained coloring information and the data packet to be detected; wherein, the coloring information includes a data flow field, and the device identifier of the first detection node and the flow identifier assigned by the server to the first detection node are filled in the data flow field, and the flow identifier is used to identify the service flow corresponding to the data packet to be detected processed by the first detection node; Sending the target data packet to the second detection node.
2. The method according to claim 1, wherein, Before generating the target data packet based on the obtained coloring information and the data packet to be detected, the method further includes: Sending an identifier acquisition request to the server, where the identifier acquisition request includes the device identifier of the first detection node; In response to the identifier acquisition response feedback by the server, obtaining the flow identifier and the detection category information assigned by the server to the first detection node; Determining the coloring information based on the device identifier of the first detection node, the flow identifier of the first detection node, and the detection category information.
3. The method according to claim 2, wherein, The detection category information includes at least one of the following: Packet loss detection information, delay detection information, data transmission path detection information, packet error information, and bandwidth utilization information.
4. The method according to any one of claims 1 to 3, wherein, The data flow field includes a first field and a second field, and the data length of the first field is the same as or different from the data length of the second field; The method for determining the coloring information includes: Filling the device identifier of the first detection node into the first field and filling the flow identifier of the first detection node into the second field; Determining the coloring information based on the data flow field and the detection category information.
5. The method according to claim 1, wherein, The device identifier of the first detection node includes: the device coding information of the first detection node and / or the network address information of the first detection node.
6. The method according to claim 1, wherein, Before generating the target data packet based on the obtained coloring information and the data packet to be detected, the method further includes: Screening multiple service data packets in the received service flow according to the access control list information to obtain an initial screening packet set; the access control list information includes at least one of the following information: the network address of the first detection node, the data transmission protocol number, and the port number information of the first detection node; Sampling the service data packets in the initial screening packet set to obtain the data packet to be detected.
7. A flow-through detection method, wherein, Applied to the second detection node, the method includes: In response to the target data packet sent by the first detection node, obtaining the coloring information and the data packet to be detected in the target data packet; wherein, the coloring information includes a data flow field, and the device identifier of the first detection node and the flow identifier assigned by the server to the first detection node are filled in the data flow field, and the flow identifier is used to identify the service flow corresponding to the data packet to be detected processed by the first detection node; Performing in-flow detection on the data packet to be detected according to the coloring information to obtain a detection result.
8. The method according to claim 7, wherein After obtaining the detection result by performing in-flow detection on the data packet to be detected according to the coloring information, the method further includes: Uploading the detection result to the analysis device; Among them, the analysis device is used to statistically analyze the detection results according to the feature correspondence relationship to obtain the in-flow detection statistical results. The feature correspondence relationship is the correspondence relationship between the device identifier of the first detection node and the flow identifier of the first detection node; the in-flow detection statistical results include at least one of the following: the packet loss ratio information of the data packet to be detected during transmission, the transmission delay information of the data packet to be detected, and the transmission path information passed by the data packet to be detected.
9. A dyeing method for in-flow detection, wherein, Applied to a server, the method includes: In response to an identifier acquisition request sent by a first detection node, acquiring the device identifier of the first detection node; According to the device identifier of the first detection node, allocating its corresponding flow identifier to the first detection node, where the flow identifier is used to identify the service flow corresponding to the data packet to be detected processed by the first detection node; Generating an identifier acquisition response according to the device identifier of the first detection node, the flow identifier of the first detection node, and the detection category information; Sending the identifier acquisition response to the first detection node.
10. An electronic device, wherein, Includes: One or more processors; A memory, on which one or more programs are stored. When the one or more programs are executed by the one or more processors, the one or more processors implement the coloring method for in-flow detection according to any one of claims 1 to 6, or the coloring method for in-flow detection according to claim 9, or the in-flow detection method according to any one of claims 7 to 8.
11. A readable storage medium, wherein, The readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the coloring method for in-flow detection according to any one of claims 1 to 6, or the coloring method for in-flow detection according to claim 9, or the in-flow detection method according to any one of claims 7 to 8.