An optimization method for solving TCP connection reset caused by multiple identical SYN packets
By using the HASH table and spin lock mechanism to handle the SYN packets in the TCP handshake, the TCP connection reset problem caused by multiple identical SYN packets is solved to ensure TCP connection stability and reliability.
Patent Information
- Application Number
- CN202510713713.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-05-30
Smart Images

Figure CN120238563B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of connection optimization, and specifically provides an optimization method for solving TCP connection reset caused by multiple identical SYN packets. Background Art
[0002] During the TCP handshake process, due to the complexity and uncertainty of the environment, various message interactions may occur. For example, when the TCP performs the first handshake, if the server receives two or more identical SYN messages sent by the client at the same time (such as when the communication parties are configured in the bond3 mode), then according to the logic of the current Linux protocol stack, the server will respond with SYN-ACK messages to each SYN message sent by the client. When the server assembles the SYN-ACK message, to avoid attacks, it will randomly generate the sequence number of the message. Usually, the source of this sequence number is the quadruple and the timestamp. For the same connection in the above scenario, the quadruple is the same, but the timestamps of the SYN-ACK messages generated by the server are different, so the finally generated sequence numbers will also be different. Subsequently, the client will also respond with ACK messages to each SYN-ACK message sent by the server. Here, according to the requirements of the TCP protocol, the acknowledgment number of the ACK message is the sequence number of the SYN-ACK message +1. When the server receives these ACK messages, if the acknowledgment numbers of the ACK messages do not match, the TCP connection will be reset and the connection will be interrupted. Summary of the Invention
[0003] To solve the above problems, the purpose of the present invention is to provide an optimization method for solving TCP connection reset caused by multiple identical SYN packets. When receiving multiple identical SYN packets, the server appropriately processes the multiple identical SYN packets so that it will not send multiple different SYN-ACK packets to respond to the client, avoiding the connection reset problem caused by identical SYN packets.
[0004] An optimization method for solving TCP connection reset caused by multiple identical SYN packets according to the present invention. A TCP connection needs to go through a handshake stage between the server and the client. The optimization method is used for the server and the client to determine and process the SYN packets to be processed during the handshake stage.
[0005] The optimization method includes the following steps:
[0006] Step S0: Use a structure to save the first HASH table and the second HASH table. The first HASH table stores multiple linked lists; the linked lists are used to store the connection information of the processed SYN packets, and the second HASH table stores multiple spin locks; each spin lock corresponds to protecting a linked list in the first HASH table.
[0007] Step S1: The client sends the SYN packet to be processed to the server;
[0008] Step S2: The thread of the server obtains the HASH value based on the SYN packet to be processed sent by the client, obtains the linked list corresponding to the HASH value from the first HASH table, and obtains the corresponding spin lock from the second HASH table;
[0009] Step S3: After the thread of the server obtains the corresponding spin lock from the second HASH table, the thread of the server sequentially takes out the connection information of the processed SYN packet from the linked list corresponding to the HASH value and compares it with the connection information of the SYN packet to be processed;
[0010] Step S4: If there is connection information of a processed SYN packet in the linked list corresponding to the HASH value that is the same as the connection information of the SYN packet to be processed, the thread of the server discards the SYN packet to be processed, no longer processes the SYN packet to be processed, and releases the corresponding spin lock;
[0011] Step S5: If there is no connection information of a processed SYN packet in the linked list corresponding to the HASH value that is the same as the connection information of the SYN packet to be processed, the thread of the server marks the SYN packet to be processed as a processed SYN packet, stores the connection information of the processed SYN packet in the linked list corresponding to the HASH value, then releases the corresponding spin lock, and then enters Step S6 to continue processing the marked processed SYN packet;
[0012] Step S6: The thread of the server obtains the SYN-ACK packet based on the processed SYN packet and sends the SYN-ACK packet to the client;
[0013] Step S7: The client receives the SYN-ACK packet sent by the thread of the server;
[0014] Step S8: The client processes the SYN-ACK packet to obtain the ACK packet and sends the ACK packet to the thread of the server;
[0015] Step S9: The thread of the server receives the ACK packet, and the handshake phase ends.
[0016] A further improvement of the present invention is that Step S2 includes the following steps:
[0017] Step S21: The thread of the server receives the SYN packet to be processed sent by the client;
[0018] Step S22: The thread of the server obtains the connection information of the SYN packet to be processed based on the SYN packet to be processed;
[0019] Step S23: The thread of the server performs HASH calculation based on the connection information of the SYN packet to be processed to obtain the HASH value corresponding to the SYN packet to be processed;
[0020] Step S24: The thread of the server obtains the linked list corresponding to the HASH value from the first HASH table based on the HASH value corresponding to the SYN packet to be processed;
[0021] Step S25: The thread of the server finds the corresponding spin lock from the second HASH table based on the HASH value and requests to obtain the corresponding spin lock.
[0022] A further improvement of the present invention is that in step S9, after the thread of the server receives the ACK packet, it further determines whether the ACK packet is legal; if the ACK packet is legal, it indicates that the handshake between the client and the server is successful, and the client and the server establish a TCP connection.
[0023] A further improvement of the present invention is that after the client and the server establish a TCP connection, the server re-obtains the corresponding spin lock from the second HASH table based on the HASH value obtained in step S2, and after re-obtaining the spin lock, removes the connection information of the processed SYN packet corresponding to the HASH value from the linked list corresponding to the HASH value. After completion, the corresponding spin lock is released.
[0024] A further improvement of the present invention is that the connection information includes quadruple information and network namespace information.
[0025] Advantages of the present invention:
[0026] In the process of TCP connection, the present invention records the processing of the SYN packet in the first handshake into the linked list of the first HASH table, so as to determine the processing logic of the SYN packets with the same content that may be received subsequently, rather than repeatedly processing all received SYN packets.
[0027] When it is found that there is already a SYN packet with the same quadruple in the first HASH table, it can be determined that the SYN packets with the same content have been or are being processed. Then, other SYN packets with the same content except the first SYN packet will not be processed at all. Correspondingly, the SYN-ACK packets corresponding to the subsequent SYN packets with the same content will not be sent either. Thus, the sequence number and acknowledgment number of the TCP three-way handshake will not be damaged, and the TCP connection will be successfully completed. Without this mechanism, the TCP connection may be reset due to the mismatch of the sequence number and acknowledgment number. Description of the Drawings
[0028] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0029] Figure 1 It is a flow schematic diagram of the present invention. Specific embodiments
[0030] The following combines the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Many specific details are set forth in the following description to facilitate a full understanding of the present invention. However, the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar generalizations without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0031] The purpose of the present invention is to provide an optimization method for solving the TCP connection reset caused by multiple identical SYN packets. When multiple identical SYN packets are received, the server properly processes the multiple identical SYN packets so that it does not send multiple different SYN-ACK packets to respond to the client.
[0032] An optimization method for solving the TCP connection reset caused by multiple identical SYN packets in the present invention, as Figure 1 shown, the optimization method is used for the server and the client to determine and process the SYN packets to be processed during the handshake phase.
[0033] The optimization method includes the following steps:
[0034] Step S0: Use a structure to save the first HASH table and the second HASH table. The server addresses from the first HASH table by calculating the connection information of the SYN packets to be processed. The first HASH table stores multiple linked lists, and the linked lists are used to store the connection information of the processed SYN packets. One linked list can store the connection information of multiple processed SYN packets. The connection information mainly includes quadruple information and network namespace information. The reason for using a linked list to save the connection information is to prevent the occurrence of HASH conflicts (for example, different quadruple and network namespace information may generate the same HASH value, and one HASH value corresponds to one linked list in the first HASH table).
[0035] The members of the second HASH table are multiple spin locks. Each spin lock corresponds to protecting one linked list in the first HASH table. After the thread of the server obtains the spin lock, it can obtain the permission to operate on the corresponding linked list in the first HASH table.
[0036] Step S1: The client sends a SYN packet to be processed to the server.
[0037] Step S2: The thread of the server obtains the HASH value based on the SYN packet to be processed sent by the client, and obtains the linked list corresponding to the HASH value from the first HASH table and the corresponding spin lock from the second HASH table.
[0038] This step is refined into the following steps:
[0039] Step S21: The thread of the server receives the SYN packet to be processed sent by the client.
[0040] Step S22: The thread of the server obtains the connection information of the SYN packet to be processed based on the SYN packet to be processed.
[0041] Step S23: The thread of the server performs HASH calculation based on the connection information of the SYN packet to be processed to obtain the HASH value corresponding to the SYN packet to be processed.
[0042] Step S24: The thread of the server addresses from the first HASH table based on the HASH value corresponding to the SYN packet to be processed, and obtains the linked list corresponding to the HASH value.
[0043] Step S25: The thread of the server finds the corresponding spin lock from the second HASH table based on the HASH value, and requests to obtain the corresponding spin lock, so as to ensure the uniqueness of the thread of the server operating on the linked list corresponding to the HASH value.
[0044] Step S3: After the thread of the server obtains the corresponding spin lock from the second HASH table, other threads of the server will not be able to obtain the permission to address the HASH value to operate on the linked list corresponding to the HASH value. Then, the thread of the server traverses the linked list corresponding to the HASH value, sequentially takes out the connection information of the processed SYN packets saved in the linked list and compares it with the connection information of the SYN packet to be processed, and judges whether there is the connection information of the processed SYN packet in the linked list corresponding to the HASH value that is the same as the connection information of the SYN packet to be processed.
[0045] Step S4: If there is the connection information of the processed SYN packet in the linked list corresponding to the HASH value that is the same as the connection information of the SYN packet to be processed, it indicates that there is already the same SYN packet being processed in the server, and this SYN packet to be processed does not need to be processed again. The thread of the server discards the SYN packet to be processed and releases the spin lock corresponding to the linked list; no subsequent steps are performed.
[0046] Step S5: If there is no connection information of a processed SYN packet in the linked list corresponding to the HASH value that is the same as the connection information of the SYN packet to be processed, it indicates that there is no same SYN packet being processed on the server side, and the SYN packet to be processed is the first SYN packet of this content; the SYN packet to be processed is marked as a processed SYN packet, and its connection information is stored in the linked list corresponding to the HASH value. The thread of the server releases the spin lock corresponding to this linked list from the second HASH table, and then enters Step S6 to continue processing the SYN packet marked as processed.
[0047] Step S6: The thread of the server normally processes the processed SYN packet to obtain a SYN-ACK packet, and sends the obtained SYN-ACK packet to the client;
[0048] Step S7: The client receives the SYN-ACK packet sent by the thread of the server;
[0049] Step S8: The client processes the SYN-ACK packet to obtain an ACK packet, and sends the ACK packet to the thread of the server;
[0050] Step S9: The thread of the server receives the ACK packet, and the handshake phase ends.
[0051] In this step, after the thread of the server receives the ACK packet, it further determines whether the ACK packet is legal; if the ACK packet is legal, it indicates that the handshake between the client and the server is successful, and the client and the server establish a TCP connection.
[0052] After the client and the server establish a TCP connection, the server re-obtains the corresponding spin lock from the second HASH table based on the HASH value obtained in Step S2, and after re-obtaining the corresponding spin lock, removes the connection information of the processed SYN packet corresponding to the HASH value from the linked list corresponding to the HASH value. Finally, it releases the corresponding spin lock from the second HASH table again.
[0053] After the comparison in Step S4 and Step S5, the thread of the server will send at most one SYN-ACK packet in response to the same SYN packet, and the subsequent ACK packet responded by the client will also meet the requirements. Therefore, TCP connection reset will not occur.
[0054] Abbreviations:
[0055] TCP: TCP is a connection-oriented and reliable transport layer communication protocol on top of the IP protocol. It establishes a connection through a three-way handshake, numbers and acknowledges data packets during data transmission to ensure that data is accurately transmitted between different host applications, and is widely used in network application scenarios such as web browsing, email, and file transfer.
[0056] Reset: In a TCP connection, reset is an operation to abnormally terminate the connection. When there are situations that do not conform to the TCP protocol rules, such as receiving error packets like invalid sequence numbers or unrecognized combinations of flags, the receiving party may send an RST packet to interrupt the connection, which will stop the ongoing data transmission. The occurrence of TCP connection reset will bring a bad experience to users.
[0057] HASH table: The HASH table, i.e., the hash table, is a data structure. It uses a hash function to map keys to storage locations for storing and retrieving data. In network protocol processing, the hash value can be calculated based on certain characteristics of the SYN packet and relevant information can be stored to quickly determine whether the same SYN packet has been received, improving the processing efficiency.
[0058] SYN-ACK: SYN-ACK is a type of response packet sent by the server to the client's SYN packet. It not only indicates agreement to establish a connection for synchronization but also confirms the client's connection request. It contains the new sequence number generated by the server and the confirmation information for the client's SYN packet, playing a key intermediate role in the three-way handshake.
[0059] ACK: ACK is a flag used in the TCP protocol to confirm the receipt of a data packet. During the three-way handshake for connection establishment, the client sends an ACK packet to confirm after receiving the SYN-ACK packet. During data transmission, the receiving party sends an ACK packet to confirm after receiving the data packet. Its acknowledgment number indicates the sequence number of the next data packet expected to be received, ensuring the reliability of data transmission.
[0060] Quadruple: In a network connection, the quadruple is composed of the source IP address, source port number, destination IP address, and destination port number, and is used to uniquely identify a connection in the network.
[0061] bond3: Bond can bind multiple network cards together, allowing two or more interfaces to act as one interface to increase network bandwidth and provide redundancy for network links. When one of the network cards fails, the server's services will not be interrupted. And bond3 is the third mode of the bond function. Its characteristic is that when sending data, the data to be sent will be sent in broadcast mode from each slave sub-interface, and when receiving data, the received data will be broadcast to each sub-interface.
[0062] The above are only the preferred embodiments of the present invention. The protection scope of the present invention is not limited to the above embodiments. All technical solutions falling within the concept of the present invention belong to the protection scope of the present invention. It should be noted that for those of ordinary skill in the art in this technical field, several improvements and refinements made without departing from the principle of the present invention should also be regarded as within the protection scope of the present invention.
Claims
1. An optimized method for solving TCP connection reset caused by multiple identical SYN packets, characterized in that Establishing a TCP connection between the server and the client requires going through a handshake phase. The optimized method is used for the server and the client to judge and process the SYN packets to be processed during the handshake phase; The optimized method includes the following steps: Step S0: Use a structure to save the first HASH table and the second HASH table. The first HASH table stores multiple linked lists; the linked lists are used to store the connection information of the processed SYN packets, and the second HASH table stores multiple spin locks; each spin lock corresponds to protecting a linked list in the first HASH table; Step S1: The client sends the SYN packet to be processed to the server; Step S2: The thread of the server obtains the HASH value based on the SYN packet to be processed sent by the client, obtains the linked list corresponding to the HASH value from the first HASH table, and obtains the corresponding spin lock from the second HASH table; Step S3: After the thread of the server obtains the corresponding spin lock from the second HASH table, the thread of the server sequentially takes out the connection information of the processed SYN packets from the linked list corresponding to the HASH value and compares it with the connection information of the SYN packet to be processed; Step S4: If there is connection information of a processed SYN packet in the linked list corresponding to the HASH value that is the same as the connection information of the SYN packet to be processed, the thread of the server discards the SYN packet to be processed, no longer processes the SYN packet to be processed, and releases the corresponding spin lock; Step S5: If there is no connection information of a processed SYN packet in the linked list corresponding to the HASH value that is the same as the connection information of the SYN packet to be processed, the thread of the server marks the SYN packet to be processed as a processed SYN packet, stores the connection information of the processed SYN packet in the linked list corresponding to the HASH value, then releases the corresponding spin lock, and then enters Step S6 to continue processing the marked processed SYN packet; Step S6: The thread of the server obtains the SYN-ACK packet based on the processed SYN packet and sends the SYN-ACK packet to the client; Step S7: The client receives the SYN-ACK packet sent by the thread of the server; Step S8: The client processes the SYN-ACK packet to obtain the ACK packet and sends the ACK packet to the thread of the server; Step S9: The thread of the server receives the ACK packet, and the handshake phase ends.
2. The optimization method for solving TCP connection reset caused by multiple identical SYN packets according to claim 1, characterized in that Step S2 includes the following steps: Step S21: The thread of the server receives the SYN packet to be processed sent by the client; Step S22: The thread of the server obtains the connection information of the SYN packet to be processed based on the SYN packet to be processed; Step S23: The thread of the server performs HASH calculation based on the connection information of the SYN packet to be processed to obtain the HASH value corresponding to the SYN packet to be processed; Step S24: The thread of the server obtains the linked list corresponding to the HASH value from the first HASH table based on the HASH value corresponding to the SYN packet to be processed; Step S25: The thread of the server finds the corresponding spin lock from the second HASH table based on the HASH value and requests to acquire the corresponding spin lock.
3. The optimized method for solving TCP connection reset caused by multiple identical SYN packets according to claim 2, characterized in that In step S9, after the thread of the server receives the ACK packet, it further determines whether the ACK packet is legal; if the ACK packet is legal, it indicates that the handshake between the client and the server is successful, and the client and the server establish a TCP connection.
4. A method for optimizing the solution to TCP connection reset caused by multiple identical SYN packets according to claim 3, characterized in that, After the client and the server establish a TCP connection, the server re-obtains the corresponding spin lock from the second HASH table based on the HASH value obtained in step S2. After re-obtaining the spin lock, it removes the connection information of the processed SYN packet corresponding to the HASH value from the linked list corresponding to the HASH value. After completion, it releases the corresponding spin lock.
5. A method for optimizing the solution to TCP connection reset caused by multiple identical SYN packets according to claim 1, characterized in that, The connection information includes quadruple information and network namespace information.
Citation Information
Patent Citations
Method and device for allocating resources
CN105099952A
Data packet detection processing method and equipment
CN113098727A