Traffic data detection method and device, electronic equipment and storage medium

Through the automated traffic data detection method, the matching of target traffic data and historical communication relationship information is solved, and the high cost and inefficiency problems caused by manual tag settings are achieved, and more efficient and accurate abnormal detection is achieved, which is suitable for a variety of computing environments.

CN120263434APending Publication Date: 2025-07-04TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410015385.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-02
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

In the prior art, manual setting of workload tags can detect abnormal traffic data, resulting in high cost and low efficiency.

Method used

By obtaining the characteristic data of the target traffic data, using historical communication relationship information to match, the abnormal detection results of the traffic data are automatically determined, and manual tag settings are avoided.

Benefits of technology

Reduces the cost of abnormal detection, improves detection efficiency and accuracy, is suitable for various scenarios such as micro-isolation and cloud services, supports more workload types, and is suitable for hybrid cloud environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263434A_ABST
    Figure CN120263434A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a traffic data detection method and device, electronic equipment and a storage medium, and the method comprises the steps that an anomaly detection party can obtain target traffic data obtained by collecting the traffic of a to-be-detected workload by a data collection party, the method comprises the following steps: acquiring target traffic data, extracting feature data of a target working load corresponding to the target traffic data and feature data of a source working load to obtain target communication relationship information, and then searching historical communication relationship information matched with the target communication relationship information from a historical data set, the historical data set comprises historical communication relation information corresponding to the traffic data of the workload collected in a set historical time period, so as to determine an anomaly detection result of the target traffic data according to a search result corresponding to the target communication relation information. According to the technical scheme, the anomaly detection cost can be reduced, and the anomaly detection efficiency can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computers, and in particular, to a traffic data detection method and apparatus, an electronic device, a storage medium, and a program product. Background Art

[0002] In order to improve the security of each workload in the network, it is necessary to detect the traffic of each workload. Among them, a workload refers to a unit running in a computing environment.

[0003] In the related art, usually, tags of each workload are set manually, and then, based on the tags of the workload corresponding to the traffic data, it is determined whether the traffic data is abnormal. Setting tags for each workload requires a large amount of human resources and time, thus increasing the cost of anomaly detection and reducing the efficiency of anomaly detection. Summary of the Invention

[0004] Embodiments of the present application provide a traffic data detection method and apparatus, an electronic device, a storage medium, and a program product, which can reduce the cost of anomaly detection and improve the efficiency of anomaly detection.

[0005] According to one aspect of the embodiments of the present application, a traffic data detection method is provided. The method includes:

[0006] Obtaining target traffic data collected by a data collector for the traffic of a workload to be detected;

[0007] Extracting feature data of a destination workload and feature data of a source workload corresponding to the target traffic data to obtain target communication relationship information;

[0008] Searching in a historical data set for historical communication relationship information that matches the target communication relationship information; wherein, the historical data set includes historical communication relationship information corresponding to traffic data of workloads collected within a set historical time period;

[0009] Determining an anomaly detection result of the target traffic data according to a search result corresponding to the target communication relationship information.

[0010] According to one aspect of the embodiments of the present application, a traffic data detection method is provided. The method includes:

[0011] Collecting the traffic of a workload to be detected to obtain target traffic data;

[0012] Send the target traffic data to an anomaly detection party, so that the anomaly detection party extracts the feature data of the destination workload and the feature data of the source workload corresponding to the target traffic data, obtains target communication relationship information, searches for historical communication relationship information matching the target communication relationship information from a historical data set, and determines the anomaly detection result of the target traffic data according to the search result corresponding to the target communication relationship information; wherein, the historical data set contains historical communication relationship information corresponding to the traffic data of the workload collected within a set historical time period.

[0013] According to one aspect of the embodiments of the present application, a traffic data detection device is provided. The device includes:

[0014] An acquisition module, configured to acquire target traffic data obtained by a data acquisition party through collecting the traffic of a workload to be detected;

[0015] An extraction module, configured to extract the feature data of the destination workload and the feature data of the source workload corresponding to the target traffic data, and obtain target communication relationship information;

[0016] A search module, configured to search for historical communication relationship information matching the target communication relationship information from a historical data set; wherein, the historical data set contains historical communication relationship information corresponding to the traffic data of the workload collected within a set historical time period;

[0017] A detection module, configured to determine the anomaly detection result of the target traffic data according to the search result corresponding to the target communication relationship information.

[0018] In an exemplary embodiment, based on the foregoing solution, the device further includes a construction module, configured to:

[0019] Acquire the historical traffic data of the workload collected by the data acquisition party within the set historical time period;

[0020] Extract the feature data of the destination workload and the feature data of the source workload corresponding to the historical traffic data, and obtain the historical communication relationship information corresponding to the historical traffic data;

[0021] Construct the historical data set according to the extracted historical communication relationship information.

[0022] In an exemplary embodiment, based on the foregoing solution, the construction module is specifically configured to:

[0023] Extract the source Internet protocol address and the destination Internet protocol address from the historical traffic data;

[0024] Search for the attribute information of the workload to which the source Internet protocol address belongs, and obtain the characteristic data of the source workload corresponding to the historical traffic data;

[0025] Search for the attribute information of the workload to which the destination Internet protocol address belongs, and obtain the characteristic data of the destination workload corresponding to the historical traffic data;

[0026] Construct the historical communication relationship information corresponding to the historical traffic data according to the characteristic data of the destination workload and the characteristic data of the source workload corresponding to the historical traffic data.

[0027] In an exemplary embodiment, based on the foregoing solution, the construction module is specifically configured as:

[0028] Search for the workload to which the source Internet protocol address belongs;

[0029] Use the attribute information of the found workload as the characteristic data of the source workload corresponding to the historical traffic data; wherein, the attribute information of the found workload includes at least one of the affiliation information, location information, service information, and operating environment information corresponding to the found workload.

[0030] In an exemplary embodiment, based on the foregoing solution, the construction module is specifically configured as:

[0031] Search for the identification information of the workload to which the source Internet protocol address belongs, and extract a set number of characters from the identification information in the order from front to back;

[0032] Use the set number of characters as the characteristic data of the source workload corresponding to the historical traffic data.

[0033] In an exemplary embodiment, based on the foregoing solution, the construction module is specifically configured as:

[0034] If the attribute information of the workload to which the source Internet protocol address belongs is not found, use the source Internet protocol address as the characteristic data of the source workload corresponding to the historical traffic data.

[0035] In an exemplary embodiment, based on the foregoing solution, when the historical data set further includes communication parameters of a set type corresponding to each historical communication relationship information, the detection module is specifically configured as:

[0036] If a target historical communication relationship information matching the target communication relationship information is found in the historical data set, extract the communication parameters of the set type corresponding to the target historical communication relationship information from the historical data set;

[0037] Obtain communication parameters of a set type corresponding to the target communication relationship information according to the target traffic data;

[0038] If the communication parameters of the set type corresponding to the target communication relationship information match the communication parameters of the set type corresponding to the target historical communication relationship information, determine that the target traffic data is normal traffic data.

[0039] In an exemplary embodiment, based on the foregoing solution, the detection module is specifically configured as follows:

[0040] Obtain the target communication relationship information corresponding to multiple pieces of target traffic data collected within a set detection time period;

[0041] From the multiple pieces of target traffic data, find the quantity of the target traffic data corresponding to each piece of target communication relationship information, and calculate the communication frequency corresponding to each piece of target communication relationship information according to the quantity of the target traffic data corresponding to each piece of target communication relationship information;

[0042] Use the communication frequency corresponding to each piece of target communication relationship information as the communication parameters of the set type corresponding to each piece of target communication relationship information.

[0043] In an exemplary embodiment, based on the foregoing solution, the search module is specifically configured as follows:

[0044] Obtain the importance of the workload to be detected, and calculate a similarity threshold according to the importance; wherein, the similarity threshold is positively correlated with the importance;

[0045] From the multiple pieces of historical communication relationship information included in the historical data set, find the historical communication relationship information whose similarity to the target communication relationship information is greater than or equal to the similarity threshold;

[0046] Use the found historical communication relationship information as the historical communication relationship information that matches the target communication relationship information.

[0047] In an exemplary embodiment, based on the foregoing solution, the acquisition module is specifically configured as follows:

[0048] Send a data collection instruction to the data collector, so that the data collector collects the traffic of the workload to be detected according to the data collection instruction to obtain target traffic data; wherein, the workload to be detected includes at least one of a container, a service component, a virtual machine, and a host;

[0049] Receive the target traffic data sent by the data collector.

[0050] In an exemplary embodiment, based on the foregoing solution, the acquisition module is specifically configured as follows:

[0051] Find the target node to which the workload to be detected belongs from multiple nodes; where each node contains a data collector and multiple workloads.

[0052] Send a data collection instruction to the data collector included in the target node, so that the data collector included in the target node finds the workload to be detected from the multiple workloads included in the target node according to the data collection instruction, and collects the traffic of the found workload to be detected to obtain target traffic data.

[0053] According to one aspect of the embodiments of the present application, an electronic device is provided, including:

[0054] One or more processors;

[0055] A storage device for storing one or more computer programs, which when executed by the one or more processors, cause the electronic device to implement the traffic data detection method as described above.

[0056] According to one aspect of the embodiments of the present application, a computer-readable storage medium is provided, on which a computer program is stored, which when executed by a processor of an electronic device, causes the electronic device to implement the traffic data detection method as described above.

[0057] According to one aspect of the embodiments of the present application, a computer program product is provided, including a computer program, which when executed by a processor, implements the traffic data detection method as described above.

[0058] In the technical solution provided by the embodiments of the present application, the anomaly detection party can obtain the target traffic data collected by the data collector for the traffic of the workload to be detected, and extract the feature data of the destination workload and the feature data of the source workload corresponding to the target traffic data to obtain target communication relationship information. Then, from the historical data set, find the historical communication relationship information that matches the target communication relationship information, where the historical data set contains the historical communication relationship information corresponding to the traffic data of the workload collected within a set historical time period, so as to determine the anomaly detection result of the target traffic data according to the search result corresponding to the target communication relationship information; compared with the related art, taking the historical communication relationship information corresponding to the traffic data of the workload within a set historical time period as a standard, and determining whether the target traffic data is abnormal by whether the target communication relationship information corresponding to the target traffic data of the workload to be detected matches the historical communication relationship information, there is no need to manually set labels for the workload, saving the anomaly detection cost and improving the anomaly detection efficiency.

[0059] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and do not limit this application. Brief Description of the Drawings

[0060] Figure 1 is a schematic diagram of an implementation environment shown in an exemplary embodiment of this application;

[0061] Figure 2 is a flowchart of a traffic data detection method shown in an exemplary embodiment of this application;

[0062] Figure 3 is a flowchart of a traffic data detection method shown in another exemplary embodiment of this application;

[0063] Figure 4 is a flowchart of a traffic data detection method shown in another exemplary embodiment of this application;

[0064] Figure 5 is a schematic diagram of a traffic data detection method shown in another exemplary embodiment of this application;

[0065] Figure 6 is a flowchart of a traffic data detection method shown in another exemplary embodiment of this application;

[0066] Figure 7 is a flowchart of a traffic data detection method shown in another exemplary embodiment of this application;

[0067] Figure 8 is a flowchart of a traffic data detection method shown in another exemplary embodiment of this application;

[0068] Figure 9 is a flowchart of a traffic data detection method shown in another exemplary embodiment of this application;

[0069] Figure 10 is a flowchart of a traffic data detection method shown in another exemplary embodiment of this application;

[0070] Figure 11 is a flowchart of a traffic data detection method shown in another exemplary embodiment of this application;

[0071] Figure 12 is a flowchart of a traffic data detection method shown in another exemplary embodiment of this application;

[0072] Figure 13 is a flowchart of a traffic data detection method shown in another exemplary embodiment of this application;

[0073] Figure 14 is an interaction schematic diagram shown in an exemplary embodiment of this application;

[0074] Figure 15 It is a schematic structural diagram of accessing data shown in an exemplary embodiment of the present application;

[0075] Figure 16 It is a flowchart of extracting access relationship information shown in an exemplary embodiment of the present application;

[0076] Figure 17 It is a flowchart of detecting access data shown in an exemplary embodiment of the present application;

[0077] Figure 18 It is a schematic diagram of a traffic data detection device shown in an exemplary embodiment of the present application;

[0078] Figure 19 It is a schematic diagram of a traffic data detection device shown in another exemplary embodiment of the present application;

[0079] Figure 20 It shows a schematic structural diagram of a computer system of an electronic device suitable for implementing the embodiments of the present application. Detailed implementation manners

[0080] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0081] In the embodiments of the present application, the term "module" or "unit" refers to a computer program with a predetermined function or a part of a computer program, which works together with other related parts to achieve a predetermined goal, and can be fully or partially implemented by using software, hardware (such as a processing circuit or a memory), or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of an overall module or unit including the function of the module or unit.

[0082] The block diagrams shown in the drawings are only functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0083] The flowcharts shown in the accompanying drawings are merely illustrative and not necessarily include all the content and operations / steps, nor are they necessarily executed in the described order. For example, some operations / steps can be decomposed, while some operations / steps can be combined or partially combined. Therefore, the actual execution order may change according to the actual situation.

[0084] It should also be noted that: "a plurality of" mentioned in this application refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.

[0085] The technical solutions of the embodiments of the present application are introduced in detail below:

[0086] In the related art, usually, tags of each workload are set manually, so as to determine whether the traffic data is abnormal according to the tags of the workload corresponding to the traffic data. Setting tags for each workload requires a large amount of human resources and time, thus increasing the cost of anomaly detection and reducing the efficiency of anomaly detection. Based on this, the embodiments of the present application provide a traffic data detection method, device, electronic device, storage medium, and program product, which can reduce the cost of anomaly detection and improve the efficiency of anomaly detection.

[0087] Please refer to Figure 1 , Figure 1 which is a schematic diagram of an implementation environment involved in the present application. The implementation environment includes a data collection party 101, an anomaly detection party 102, and a node 103. At least one workload is deployed in the node 103. The data collection party 101, the anomaly detection party 102, and the node 103 can communicate with each other by wired or wireless means.

[0088] Among them, the workload refers to the unit running in the computing environment. The data collector 101 can be a terminal device or a server. The data collector 101 can be deployed in a node, or the data collector 101 can also be deployed independently. Among them, the terminal device can include, but is not limited to, smartphones, tablets, laptop computers, computers, intelligent voice interaction devices, smart home appliances, vehicle-mounted terminals, aircraft, remote driving terminals, etc.; the server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The specific forms of the terminal device and the server are not limited herein. The anomaly detector 102 can be a terminal device or a server, and the node 103 can be a terminal device, a server, a host, etc., and a workload is deployed in the node 103.

[0089] It should be noted that Figure 1 the numbers of the data collector 101, the anomaly detector 102, the node 103, and the workload in

[0090] In an exemplary embodiment, the traffic data detection method provided by the embodiments of the present application can be jointly executed by the data collection party 101 and the anomaly detection party 102. Exemplarily, the data collection party 101 can collect the traffic of the workload to be detected, obtain the target traffic data, and send the traffic data to the anomaly detection party 102; the anomaly detection party 102 extracts the feature data of the destination workload and the feature data of the source workload corresponding to the target traffic data to obtain the target communication relationship information to be detected, so as to find the historical communication relationship information matching the target communication relationship information from the historical data set; wherein, the historical data set contains the historical communication relationship information corresponding to the traffic data of the workload collected within the set historical time period; then, according to the search result corresponding to the target communication relationship information, the anomaly detection result of the target traffic data is determined. Compared with the related art, on the one hand, taking the historical communication relationship information corresponding to the traffic data of the workload within the set historical time period as a standard, it is determined whether the target traffic data is abnormal by whether the target communication relationship information corresponding to the target traffic data of the workload to be detected matches the historical communication relationship information, without manually setting labels for the workload, saving the anomaly detection cost and improving the anomaly detection efficiency; on the other hand, detecting whether the traffic data is abnormal based on the communication relationship information can improve the anomaly detection accuracy, and the historical communication relationship information and the target communication relationship information are generated based on the feature data of their respective corresponding workloads, so that the detection method can be used to detect the workload whose corresponding feature data matches the feature data included in the historical communication relationship information. In this way, among the workloads corresponding to the feature data included in the historical communication relationship information, if a new workload is added, the traffic data of the new workload can be detected for anomalies based on the historical communication relationship data, thereby improving the detection range and detection accuracy.

[0091] It should be noted that the traffic data detection method provided by the embodiments of the present invention can be applied to various scenarios. For example, it can be applied to the detection of workloads in scenarios such as micro-segmentation, cloud services, and distributed systems. Among them, micro-segmentation is a network security concept aimed at providing finer-grained network isolation and security control. By dividing the network into smaller and independent security zones, fine-grained control and protection of each zone can be achieved. In the embodiments of the present application, data related to users such as traffic data is involved. When the method of the present application is applied to a specific product or technology, user permission or consent is obtained, and the extraction, use, and processing of relevant data comply with the local security standards and local laws and regulations.

[0092] See Figure 2 , Figure 2 is a flowchart of a traffic data detection method shown in an exemplary embodiment of the present application. This method can be applied toFigure 1 The illustrated implementation environment can be executed by Figure 1 the anomaly detection party 102 in the illustrated implementation environment.

[0093] As Figure 2 shown, in an exemplary embodiment, the traffic data detection method may include steps S210 - S240, which are introduced in detail as follows:

[0094] Step S210, obtaining target traffic data collected by a data collection party for the workload to be detected.

[0095] It should be noted that a workload refers to a unit running in a computing environment, which can be a hardware unit or a software unit, and its types include but are not limited to application programs, service components, containers, hosts, virtual machines, etc.; optionally, a service component can contain multiple containers. A workload can be deployed in a node, and the node can be a terminal, a server, a virtual machine, a host, etc. The workload can have an IP (Internet Protocol Address) address, so as to communicate with the outside world (for example, other workloads), such as accessing and data transmission. When a workload communicates with the outside world, traffic will be generated. For example, if a workload sends an access request to another workload, traffic corresponding to the access request will be generated; if a workload receives a data packet sent by another workload, traffic corresponding to the data packet will be generated. The workload to be detected refers to any workload whose traffic data needs to be detected for anomalies. For example, if it is necessary to detect whether the traffic data of workload 1 is abnormal, then workload 1 is the workload to be detected; if it is necessary to detect whether the traffic of workload 2 is abnormal, then workload 2 is the workload to be detected. Specifically, which one or more workloads are used as the workload to be detected can be flexibly set according to actual needs.

[0096] To collect traffic data of a workload, a data collector is deployed to collect the traffic of the workload to be detected, obtaining target traffic data. Each communication generates a traffic data. For example, if the workload to be detected sends an access request to another workload, the data collector will collect the traffic data corresponding to the access request; if the workload to be detected receives a data packet sent by another workload, the data collector will collect the traffic data corresponding to the data packet. Among them, the target traffic data refers to any traffic data of the workload to be detected that needs to be detected for anomalies. Optionally, the traffic data corresponding to any communication behavior of the workload to be detected can be used as the target traffic data, or the traffic data corresponding to the communication behavior of the set type of the workload to be detected can be used as the target traffic data. For example, the communication behavior of the set type can include data access. The target traffic data can include the source IP address and destination IP address of the corresponding communication behavior; optionally, the target traffic data can include at least one of the identification information of the workload to be detected, the attribute information of the workload to be detected, the characteristic data of the workload to be detected, and the five-tuple information of the corresponding communication behavior (that is, the source IP address, source port, destination IP address, destination port, and transport layer protocol). Among them, for the specific introduction of the identification information, attribute information, and characteristic data of the workload, please refer to the subsequent records and will not be elaborated here.

[0097] Optionally, the data collector can be a terminal device, a server, a virtual machine, a host, etc. Among them, the data collector can be deployed in a node. Under this condition, the data collector can only collect the traffic data of multiple workloads deployed in the node to which it belongs; of course, the data collector and the workload can also be deployed in different nodes.

[0098] Optionally, before step S210, the anomaly detector can also receive anomaly detection setting parameters, where the anomaly detection setting parameters contain information about the workload to be detected, so as to determine the workload to be detected according to the anomaly detection setting parameters. In an optional example, the anomaly detection setting parameters can contain the category of the workload to be detected (for example, the department, business, etc. to which it belongs), so as to use the workload matching the category as the workload to be detected; in another optional example, the anomaly detection setting parameters can contain the identification information of the workload to be detected, so as to use the workload corresponding to the identification information as the workload to be detected. For example, the anomaly detection setting parameters can contain the IP address corresponding to the workload to be detected for anomaly detection, so as to use the workload corresponding to the IP address as the workload to be detected. The anomaly detection setting parameters can be set manually.

[0099] Step S220: Extract the feature data of the destination workload and the source workload corresponding to the target traffic data to obtain the target communication relationship information.

[0100] It should be noted that the destination workload refers to the workload corresponding to the destination IP address in the communication behavior, and the source workload refers to the workload corresponding to the source IP address in the communication behavior.

[0101] The feature data of the workload is used to describe the features of the workload, including but not limited to at least one of the attribute information, IP address, identification information, etc. of the workload.

[0102] The target communication relationship information contains the feature data of the destination workload and the source workload corresponding to the target traffic data. For example, if the target traffic data 1 corresponds to workload 1 sending a data packet to workload 2, then the corresponding target communication relationship information contains the feature data of workload 1 and workload 2, where workload 1 is the source workload and workload 2 is the destination workload; if the target traffic data 2 corresponds to workload 3 accessing workload 4, then the corresponding target communication relationship information contains the feature data of workload 3 and workload 4, where, since workload 3 accessing workload 4 usually means workload 3 sending an access request to workload 4, therefore, workload 3 is the source workload and workload 4 is the destination workload.

[0103] Among them, the destination workload and the source workload corresponding to the target traffic data can be determined first, and then the feature data corresponding to the destination workload and the source workload can be found respectively.

[0104] Step S230: Search the historical dataset for historical communication relationship information that matches the target communication relationship information; where the historical dataset contains the historical communication relationship information corresponding to the traffic data of the workload collected within the set historical time period.

[0105] The set historical time period refers to a pre-set period of time, the time corresponding to which is earlier than the time when the target traffic data occurs. The specific values of the start time and duration corresponding to the historical time period can be flexibly set according to actual needs. The historical data set contains the communication relationship information corresponding to the traffic information of the workload collected within the set historical time period. Among them, the data collector can collect the traffic data of the workload within the set historical time period and extract the communication relationship information corresponding to the traffic data (i.e., historical communication relationship information) to construct the historical data set based on the historical communication relationship information. Among them, the method of extracting historical communication relationship information from the traffic information of the workload collected within the set historical time period is the same as the method of extracting target communication relationship information from the target traffic data. That is to say, the historical communication relationship information also contains the characteristic data of the source workload and the destination workload of its corresponding communication behavior. If the number of workloads is multiple, the historical data set contains the historical communication relationship information corresponding to the traffic data of multiple workloads respectively within the set historical time period. Optionally, the workload corresponding to the historical communication relationship information contained in the historical data set can be the same as the workload to be detected, or the workload corresponding to the historical communication relationship information is the same or similar to the category of the workload to be detected.

[0106] To determine whether the target traffic data is normal, historical communication relationship information matching the target communication relationship information corresponding to the target traffic data can be searched for in the historical data set.

[0107] Step S240, determine the anomaly detection result of the target traffic data according to the search result corresponding to the target communication relationship information.

[0108] According to the search result, it can be determined whether the target traffic data is abnormal traffic data, so as to obtain the anomaly detection result corresponding to the target traffic data.

[0109] In an optional implementation manner, if historical communication relationship information matching the target communication relationship information corresponding to the target traffic data is found in the historical data set, it is determined that the target traffic data is normal traffic data; if historical communication relationship information matching the target communication relationship information corresponding to the target traffic data is not found in the historical data set, it is determined that the target traffic data is abnormal traffic data. That is to say, the traffic data of the workload within the set historical time period is used as normal traffic data, and the communication relationship information corresponding to the target traffic data to be detected is compared with the communication relationship information corresponding to the normal traffic data. If they match, it is determined that the target traffic data is normal traffic data; if they do not match, it is determined that the target traffic data is abnormal traffic data.

[0110] Optionally, after detecting abnormal traffic data, an alarm prompt can also be given to enable relevant personnel to process the abnormal traffic data.

[0111] In Figure 2 In the illustrated embodiment, compared with the related art, on the one hand, taking the historical communication relationship information corresponding to the traffic data of the workload within the set historical time period as a standard, it is determined whether the target traffic data is abnormal by whether the target communication relationship information corresponding to the target traffic data of the workload to be detected matches the historical communication relationship information. There is no need to manually set tags for the workload, saving the cost of abnormal detection and improving the efficiency of abnormal detection; on the other hand, detecting whether the traffic data is abnormal based on the communication relationship information can improve the accuracy of abnormal detection, and the historical communication relationship information and the target communication relationship information are generated based on the characteristic data of their respective corresponding workloads, so that the detection method can be used to detect the workload whose corresponding characteristic data matches the characteristic data included in the historical communication relationship information. In this way, among the workloads corresponding to the characteristic data included in the historical communication relationship information, if a new workload is added, the traffic data of the new workload can be detected for abnormality based on the historical communication relationship data, thereby expanding the detection scope and improving the detection accuracy.

[0112] In an exemplary embodiment, referring to Figure 3 , Figure 3 is a flowchart of a traffic data detection method shown in another exemplary embodiment of the present application. This method can be applied to Figure 1 the illustrated implementation environment, which can be executed by Figure 1 the anomaly detection party 102 in the illustrated implementation environment.

[0113] As Figure 3 shown, this method includes step S310 - step S330, and step S210 - step S240, where the detailed introduction of step S310 - step S330 is as follows:

[0114] Step S310, obtain the historical traffic data of the workload collected by the data collection party within the set historical time period.

[0115] To construct a historical data set, the data collection party can collect the traffic of the workload within the set historical time period to obtain historical traffic data.

[0116] Step S320, extract the characteristic data of the destination workload and the source workload corresponding to the historical traffic data to obtain the historical communication relationship information corresponding to the historical traffic data.

[0117] Among them, the method for extracting the historical communication relationship information corresponding to the historical traffic data is the same as the method for extracting the target communication relationship information corresponding to the target traffic data. The destination workload and source workload corresponding to the historical traffic data can be determined, and then the characteristic data corresponding to the destination workload and source workload are searched for.

[0118] Step S330, construct a historical data set according to the extracted historical communication relationship information.

[0119] According to the historical communication relationship information corresponding to the extracted historical traffic data, a historical data set can be constructed.

[0120] It should be noted that Figure 3 The specific implementation details of the steps S210 - S240 shown can refer to Figure 2 the steps S210 - S240 shown, which will not be elaborated here.

[0121] In Figure 3 the embodiment shown, constructing a historical data set based on the historical communication relationship data corresponding to the historical traffic data of the workload within a set range, and performing anomaly detection on the traffic of the workload based on the historical data set can improve the anomaly detection efficiency and reduce the anomaly detection cost.

[0122] In an exemplary embodiment, referring to Figure 4 , Figure 4 is a flowchart of a traffic data detection method shown in another exemplary embodiment of the present application. This method can be applied to Figure 1 the implementation environment shown, which can be executed by Figure 1 the anomaly detection party 102 in the implementation environment shown.

[0123] As Figure 4 shown, this method includes steps S310, steps S410 - S440, step S330, and steps S210 - S240. Among them, the detailed introduction of steps S410 - S440 is as follows:

[0124] Step S410, extract the source Internet protocol address and the destination Internet protocol address from the historical traffic data.

[0125] The historical traffic data contains the source IP address and the destination IP address of its corresponding communication behavior, and the source IP address and the destination IP address can be extracted from it.

[0126] Step S420, search for the attribute information of the workload to which the source Internet protocol address belongs, and obtain the characteristic data of the source workload corresponding to the historical traffic data.

[0127] Based on the source IP address, the corresponding workload can be found, the attribute information of the workload can be obtained, and the attribute information of the workload is used as the characteristic data of the source workload corresponding to the historical traffic data.

[0128] Among them, the attribute information of the workload is used to describe the attributes of the workload. For example, it includes but is not limited to the creation time of the workload, the category of the workload, etc. Among them, the category of the workload can be classified according to different classification factors. For example, the workload can be classified according to parameters such as the affiliated party information, location information, business information, and operating environment information corresponding to the workload. The affiliated party information of the workload is used to describe the affiliated party of the workload. For example, the enterprise to which the workload belongs, the department to which it belongs in the enterprise, etc.; the location information of the workload refers to the geographical area where the workload is located. It should be understood that nodes are usually deployed in different regions. For example, an enterprise can deploy servers in different regions, and workloads can be deployed in the servers. Correspondingly, the location information of the workload refers to the geographical area where the server to which it belongs is located; the business information of the workload is used to describe which business the work service is used to implement. Using the business information of the workload as the characteristic data of the workload, in this way, even if the business is expanded or contracted, it can be accurately judged whether the traffic data of the workload corresponding to the business is abnormal; the operating environment information of the workload is used to describe the operating environment of the workload, including but not limited to the operating system corresponding to the workload.

[0129] Step S430, find the attribute information of the workload to which the destination Internet protocol address belongs, and obtain the characteristic data of the destination workload corresponding to the historical traffic data.

[0130] Based on the destination IP address, the corresponding workload can be found, the attribute information of the workload can be obtained, and the attribute information of the workload is used as the characteristic data of the destination workload corresponding to the historical traffic data.

[0131] For the specific introduction of the attribute information of the workload, please refer to the foregoing description, and it will not be repeated here.

[0132] It should be noted that Figure 4 In the method shown, taking the example of first executing step S420 and then executing step S430, in other examples, step S430 can also be executed first and then step S420, or step S420 and step S430 can be executed simultaneously. Here, the execution order of step S420 and step S430 is not restricted.

[0133] Step S440, construct the historical communication relationship information corresponding to the historical traffic data according to the characteristic data of the destination workload and the characteristic data of the source workload corresponding to the historical traffic data.

[0134] The historical communication relationship information includes the characteristic data of the destination workload corresponding to the historical traffic data and the characteristic data of the source workload.

[0135] Among them, the specific method for extracting the target communication relationship information corresponding to the target traffic data is the same as the specific method for extracting the historical communication relationship information corresponding to the historical traffic data. That is to say, the target communication relationship information corresponding to the target traffic data can be extracted in the manner of steps S410 - S440. Correspondingly, from the target traffic data, the source Internet protocol address and the destination Internet protocol address can be extracted, and the attribute information of the workload to which the source Internet protocol address belongs can be found to obtain the characteristic data of the source workload corresponding to the target traffic data; the attribute information of the workload to which the destination Internet protocol address belongs can be found to obtain the characteristic data of the destination workload corresponding to the target traffic data; according to the characteristic data of the destination workload corresponding to the target traffic data and the characteristic data of the source workload, the target communication relationship information corresponding to the target traffic data is constructed.

[0136] It should be noted that Figure 4 The specific implementation details of steps S210 - S240 shown can be referred to Figure 2 steps S210 - S240 shown, Figure 4 The specific implementation details of steps S310 and S330 shown can be referred to Figure 3 steps S310 and S330 shown, which will not be elaborated here.

[0137] In Figure 4 the embodiment shown, the attribute information of the workload is used as the characteristic data of the workload, so that the historical data set can be used to detect the workload whose corresponding attribute information matches the attribute information of the workload included in the historical communication relationship information. In this way, among the workloads corresponding to the attribute information included in the historical communication relationship information, if a new workload is added, it is possible to detect whether the traffic data of the new workload is abnormal based on the historical communication relationship information, thereby improving the accuracy of anomaly detection.

[0138] In an exemplary embodiment, referring to Figure 5 , Figure 5 is a flowchart of a traffic data detection method shown in another exemplary embodiment of the present application. This method can be applied to Figure 1 the implementation environment shown, which can be executed by Figure 1 the anomaly detection party 102 in the implementation environment shown.

[0139] As Figure 5As shown, the method includes step S310, step S410, steps S510 - S520, steps S430 - S440, step S330, and steps S210 - S240. Among them, the detailed introduction of steps S510 - S520 is as follows:

[0140] Step S510, find the workload to which the source Internet protocol address belongs.

[0141] Each workload is configured with an IP address. The workload to which the source IP address corresponding to the historical traffic data belongs can be found, so as to find the source workload corresponding to the historical traffic data.

[0142] Step S520, use the attribute information of the found workload as the characteristic data of the source workload corresponding to the historical traffic data; among them, the attribute information of the found workload includes at least one of the ownership information, location information, service information, and operating environment information corresponding to the found workload.

[0143] After finding the workload to which the source IP address corresponding to the historical traffic data belongs, at least one of the attribute information such as the ownership information, location information, service information, and operating environment information corresponding to this workload can be obtained as the characteristic data of the source workload corresponding to the historical traffic data.

[0144] Among them, the specific method of extracting the characteristic data of the destination workload corresponding to the historical traffic data is similar to the specific method of extracting the characteristic data of the source workload corresponding to the historical traffic data. That is to say, the characteristic data of the destination workload corresponding to the historical traffic data can be extracted according to steps S510 - S520. Correspondingly, find the workload to which the destination IP address corresponding to the historical traffic data belongs, and use at least one of the attribute information such as the ownership information, location information, service information, and operating environment information corresponding to this workload as the characteristic data of the destination workload corresponding to the historical traffic data.

[0145] Among them, the specific method of extracting the target communication relationship information corresponding to the target traffic data is the same as the specific method of extracting the historical communication relationship information corresponding to the historical traffic data. That is to say, the characteristic data corresponding to the source workload and the destination workload of the target traffic data can be extracted in the way of steps S510 - S520. Correspondingly, at least one of the attribute information such as the ownership information, location information, service information, and operating environment information corresponding to the source workload of the target traffic data can be used as the characteristic data of the source workload corresponding to the target traffic data; at least one of the attribute information such as the ownership information, location information, service information, and operating environment information corresponding to the destination workload of the target traffic data can be used as the characteristic data of the destination workload corresponding to the target traffic data.

[0146] It should be noted that Figure 5 For the specific implementation details of the steps S210 - S240 shown, reference can be made to Figure 2 the steps S210 - S240 shown Figure 5 For the specific implementation details of the steps S310 and S330 shown, reference can be made to Figure 3 the steps S310 and S330 shown Figure 5 For the specific implementation details of the steps S410, S430 - S440 shown, reference can be made to Figure 4 the steps S410, S430 - S440 shown, which will not be elaborated here.

[0147] In Figure 5 the embodiment shown, at least one of the party information, location information, service information, and operating environment information corresponding to the workload is used as the characteristic data of the workload. In this way, if the workload corresponding to the party information changes (for example, a new workload is added or the IP address of the workload changes), it is also possible to detect whether the traffic data of the changed workload corresponding to the party information is abnormal based on the historical communication relationship information. Similarly, when the workloads corresponding to the location information, service information, and operating environment information change respectively, it is also possible to detect whether the traffic data of the changed workloads is abnormal based on the historical communication relationship information, thereby improving the accuracy of anomaly detection.

[0148] In an exemplary embodiment, refer to Figure 6 , Figure 6 which is a flowchart of a traffic data detection method shown in another exemplary embodiment of the present application. This method can be applied to Figure 1 the implementation environment shown, and it can be executed by Figure 1 the anomaly detection party 102 in the implementation environment shown.

[0149] As Figure 6 shown, this method includes steps S310, S410, S610 - S620, S430 - S440, S330, and steps S210 - S240. Among them, the detailed introduction of steps S610 - S620 is as follows:

[0150] Step S610, search for the identification information of the workload to which the source Internet protocol address belongs, and extract a set number of characters from the identification information in the order from front to back.

[0151] The identification information of the workload is used to uniquely identify the workload, which can be at least one of the name of the workload, the identification number of the workload, etc. The identification information of the workload is usually set in a specific manner. The first few characters in the identification information can usually characterize the category to which the workload belongs. For example, the identification information of the workload can be set according to the category of the workload + the identification number in that category. Correspondingly, the first few digits of the identification information are the category of the workload. Therefore, a set number of characters can be extracted from the identification information of the workload in the order from front to back as the characteristic data of the workload.

[0152] In an optional implementation manner, it can be first determined whether the identification information of the workload is generated in the manner of "category of the workload + identification number in that category". If so, a set number of characters are extracted from the identification information in the order from front to back. Wherein, the set number is the number of characters occupied by the category of the workload in the name.

[0153] Step S620, use a set number of characters as the characteristic data of the source workload corresponding to the historical traffic data.

[0154] Use a set number of characters as the characteristic data of the source workload corresponding to the historical traffic data, so as to determine whether the traffic data is abnormal according to the communication relationship between the categories of the workloads. In this way, the communication relationship of the workloads of the same category can be detected, thereby improving the detection accuracy.

[0155] Among them, the specific manner of extracting the characteristic data of the destination workload corresponding to the historical traffic data is similar to the specific manner of extracting the characteristic data of the source workload corresponding to the historical traffic data. That is to say, the characteristic data of the destination workload corresponding to the historical traffic data can be extracted according to steps S610 - S620. Correspondingly, find the identification information of the workload to which the destination IP address corresponding to the historical traffic data belongs, and extract a set number of characters from the identification information in the order from front to back, and use the set number of characters as the characteristic data of the destination workload corresponding to the historical traffic data. For example, assume that the name of the workload is named in the form of "business - identification number", and the historical traffic data is that the workload "business a - 001" accesses the workload "business b - 002", then the extracted historical communication relationship information is "business a" accesses "business b".

[0156] Among them, the specific method for extracting the target communication relationship information corresponding to the target traffic data is the same as the specific method for extracting the historical communication relationship information corresponding to the historical traffic data. That is to say, the characteristic data corresponding to the source workload and the destination workload of the target traffic data can be extracted in the manner of steps S610 - S620. Correspondingly, find the identification information of the workload to which the source Internet protocol address corresponding to the target traffic data belongs, and extract a set number of characters from the identification information in the order from front to back, and use the set number of characters as the characteristic data of the source workload corresponding to the target traffic data; find the identification information of the workload to which the destination Internet protocol address corresponding to the target traffic data belongs, and extract a set number of characters from the identification information in the order from front to back, and use the set number of characters as the characteristic data of the destination workload corresponding to the target traffic data.

[0157] It should be noted that Figure 6 The specific implementation details of the steps S210 - S240 shown can be referred to Figure 2 the steps S210 - S240 shown Figure 6 The specific implementation details of the steps S310 and S330 shown can be referred to Figure 3 the steps S310 and S330 shown Figure 6 The specific implementation details of the steps S410, S430 - S440 shown can be referred to Figure 4 the steps S410, S430 - S440 shown, which will not be elaborated here.

[0158] In Figure 6 the embodiment shown, the first set number of characters of the identification information of the workload is used as the characteristic data of the workload. Since the identification information of the workload usually characterizes the category of the workload, in this way, when the workload corresponding to this type changes, it can also detect whether the traffic data of the changed workload is abnormal based on the historical communication relationship information, thereby improving the accuracy of anomaly detection.

[0159] In an exemplary embodiment, refer to Figure 7 , Figure 7 which is a flowchart of a traffic data detection method shown in another exemplary embodiment of the present application. This method can be applied to Figure 1 the implementation environment shown, and it can be executed by Figure 1 the anomaly detection party 102 in the implementation environment shown

[0160] As Figure 7 shown, this method includes S310, steps S410 - S440, step S710, step S330, and steps S210 - S240. Among them, the detailed introduction of step S710 is as follows:

[0161] Step S710: If the attribute information of the workload to which the source Internet protocol address belongs is not found, then use the source Internet protocol address as the characteristic data of the source workload corresponding to the historical traffic data.

[0162] During the process of searching for the attribute information of the workload to which the source IP address of the historical traffic data belongs, if the workload to which the source IP address belongs is not found, or although the workload to which the source IP address belongs is found, but the attribute information of the workload to which the source IP address belongs is not found, then the source IP address can be directly used as the characteristic data of the source workload corresponding to the historical traffic data.

[0163] Among them, if the attribute information of the workload to which the destination IP address of the historical traffic data belongs is not found, then use the destination IP address as the characteristic data of the source workload corresponding to the historical traffic data.

[0164] Among them, the specific method of extracting the target communication relationship information corresponding to the target traffic data is the same as the specific method of extracting the historical communication relationship information corresponding to the historical traffic data. That is to say, the characteristic data corresponding to the source workload and the destination workload of the target traffic data can be extracted according to Step S710. Correspondingly, if the attribute information of the workload to which the source IP address of the target traffic data belongs is not found, then use the source IP address as the characteristic data of the source workload corresponding to the historical traffic data; if the attribute information of the workload to which the destination IP address of the target traffic data belongs is not found, then use the destination IP address as the characteristic data of the destination workload corresponding to the historical traffic data.

[0165] It should be noted that Figure 7 The specific implementation details of the steps S210 - S240 shown can refer to Figure 2 the steps S210 - S240 shown, Figure 7 The specific implementation details of the steps S310 and S330 shown can refer to Figure 3 the steps S310 and S330 shown, Figure 7 The specific implementation details of the steps S410 - S440 shown can refer to Figure 4 the steps S410 - S440 shown, which will not be elaborated here.

[0166] In Figure 7 In the embodiment shown, under the condition that the attribute information of the workload is not found, the IP address is used as the characteristic data of the workload, thereby improving the accuracy of anomaly detection.

[0167] In an exemplary embodiment, refer to Figure 8 , Figure 8The flowchart of the traffic data detection method shown in another exemplary embodiment of the present application. This method can be applied to Figure 1 the implementation environment shown, which can be executed by Figure 1 the anomaly detection party 102 in the implementation environment shown.

[0168] As Figure 8 shown, under the condition that the historical dataset also contains the data transmission parameters of the set type corresponding to each historical communication relationship information, this method includes step S210 - step S230, and step S810 - step S830. The detailed introduction of step S810 - step S830 is as follows:

[0169] Step S810, if the target historical communication relationship information matching the target communication relationship information is found in the historical dataset, then the communication parameters of the set type corresponding to the target historical communication relationship information are extracted from the historical dataset.

[0170] The historical dataset not only contains historical communication relationship information, but also includes the communication parameters of the set type corresponding to each historical communication relationship information. Among them, the communication parameters of the set type include but are not limited to at least one of communication frequency, the amount of data transmitted during communication, communication time period, etc. Which communication parameters are specifically selected as the communication parameters of the set type can be flexibly set according to actual needs.

[0171] Among them, the communication frequency corresponding to the historical communication relationship information can be calculated in the following way: Obtain the historical communication relationship information corresponding to multiple historical traffic data collected within the set historical time period, so as to obtain multiple historical communication relationship information. Since there may be at least two pieces of historical traffic data with the same corresponding communication relationship information, therefore, from the multiple pieces of historical traffic data, find the historical traffic data corresponding to each historical communication relationship information, and calculate the communication frequency corresponding to each historical communication relationship information according to the number of historical traffic data corresponding to each historical communication relationship information. Among them, the communication frequency corresponding to each historical communication relationship information = the number of historical traffic data corresponding to each historical communication relationship information / the duration of the set historical time period.

[0172] The communication time period corresponding to the historical communication relationship information can be calculated in the following way: Determine at least one piece of historical traffic data corresponding to each historical communication relationship information, and aggregate the communication times corresponding to this at least one piece of historical traffic data to obtain the communication time period.

[0173] The data volume corresponding to the historical communication relationship information can be calculated in the following manner: Determine at least one piece of historical traffic data corresponding to each piece of historical communication relationship information. From the data volumes respectively corresponding to this at least one piece of historical traffic data, select the maximum data volume and the minimum data volume, and determine the data volume range corresponding to this historical communication relationship information based on the maximum data volume and the minimum data volume; alternatively, the median or the mode can be selected from the data volumes respectively corresponding to this at least one piece of historical traffic data as the data volume corresponding to this historical communication relationship information.

[0174] Under this condition, if a target historical communication relationship information that matches the target communication relationship information is found from the historical dataset, in order to improve the anomaly detection accuracy, communication parameters of a set type corresponding to the target historical communication relationship information can be extracted from the historical dataset.

[0175] Step S820, according to the target traffic data, obtain communication parameters of a set type corresponding to the target communication relationship information.

[0176] For the target communication relationship information, its corresponding communication parameters of a set type also need to be extracted. During the extraction process, it can be extracted according to the target traffic data.

[0177] Among them, if the communication parameters of the set type include communication time, the communication time corresponding to the target communication relationship information can be determined according to the communication time corresponding to the target traffic data; if the communication parameters of the set type include data flow, the data flow corresponding to the target communication relationship information can be determined according to the data volume corresponding to the target traffic data.

[0178] Step S830, if the communication parameters of the set type corresponding to the target communication relationship information match the communication parameters of the set type corresponding to the target historical communication relationship information, then determine that the target traffic data is normal traffic data.

[0179] If the communication parameters of the set type corresponding to the target communication relationship information match the communication parameters of the set type corresponding to the target historical communication relationship information, then determine that the target traffic data is normal traffic data;

[0180] Optionally, if the communication parameters of the set type corresponding to the target communication relationship information do not match the communication parameters of the set type corresponding to the target historical communication relationship information, then determine that the target traffic data is abnormal traffic data.

[0181] It should be noted that Figure 8 The specific implementation details of the steps S210 - S230 shown can be referred to Figure 2 the steps S210 - S230 shown, and will not be elaborated here.

[0182] In Figure 8In the illustrated embodiment, detecting whether the traffic data is abnormal based on the historical communication relationship information and the communication parameters of the set type corresponding to the historical communication relationship can improve the accuracy of anomaly detection.

[0183] In an exemplary embodiment, referring to Figure 9 , Figure 9 is a flowchart of a traffic data detection method shown in another exemplary embodiment of the present application. This method can be applied to Figure 1 the illustrated implementation environment, which can be executed by Figure 1 the anomaly detection party 102 in the illustrated implementation environment.

[0184] As Figure 9 shown, the method includes step S210 - step S230, step S810, step 910 - step S930, and step S830. Among them, the detailed introduction of step S910 - step S930 is as follows:

[0185] Step S910, obtain the target communication relationship information corresponding to each of the multiple pieces of target traffic data collected within the set detection time period.

[0186] Among them, the set detection time period is a time period preset for detecting whether the traffic of the workload to be detected is abnormal, and its specific duration can be flexibly set according to actual needs. Optionally, the duration of the set detection time period is the same as the duration of the set historical time period, or it is possible to periodically detect whether the traffic of the workload to be detected is abnormal, where the set detection time period is the time period corresponding to each detection cycle.

[0187] It is possible to obtain multiple pieces of target traffic data collected within the set detection time period and extract the target communication relationship information corresponding to each piece of target traffic data.

[0188] Step S920, from the multiple pieces of target traffic data, find the number of target traffic data corresponding to each piece of target communication relationship information, and calculate the communication frequency corresponding to each piece of target communication relationship information according to the number of target traffic data corresponding to each piece of target communication relationship information.

[0189] After extracting the target communication relationship information corresponding to multiple target traffic data, multiple pieces of target communication relationship information can be obtained. Since there may be at least two pieces of communication relationship information corresponding to the target traffic data that are the same, for each piece of target communication relationship information, its corresponding target traffic data can be found from multiple target traffic data, and then, according to the number of target traffic data corresponding to each piece of target communication relationship information, the communication frequency corresponding to each piece of target communication relationship information can be calculated, where the communication frequency corresponding to each piece of target communication relationship information = the number of target traffic data corresponding to each piece of target communication relationship information / the duration of the set detection time period. For example, assume that the set detection time period is 1 minute. Within 1 minute, 3 pieces of target traffic data are collected, namely workload 1 sends data packets to workload 2, workload 2 sends data packets to workload 4, and workload 1 sends data packets to workload 2. Then, the target communication relationship information extracted therefrom is respectively the characteristic data of workload 1 and the characteristic data of workload 2, the characteristic data of workload 2 and the characteristic data of workload 4, the characteristic data of workload 1 and the characteristic data of workload 2. Among them, the number of target traffic data corresponding to the characteristic data of workload 1 and the characteristic data of workload 2 is 2 pieces, and the corresponding communication frequency is 2 pieces / minute. The number of target traffic data corresponding to the characteristic data of workload 2 and the characteristic data of workload 4 is 1 piece, and the corresponding communication frequency is 1 piece / minute.

[0190] Among them, the calculation method of the communication frequency corresponding to the historical communication relationship information is similar to that of the communication frequency corresponding to the target communication relationship information. Correspondingly, obtain the historical communication relationship information corresponding to multiple historical traffic data collected within the set historical time period; from multiple historical traffic data, find the number of historical traffic data corresponding to each piece of historical communication relationship information, and calculate the communication frequency corresponding to each piece of historical communication relationship information according to the number of historical traffic data corresponding to each piece of historical communication relationship information.

[0191] Step S930, use the communication frequency corresponding to each piece of target communication relationship information as the communication parameter of the set type corresponding to each piece of target communication relationship information.

[0192] Use the communication frequency corresponding to each piece of target communication relationship information as the communication parameter of the set type corresponding to this target communication relationship information, that is to say, the communication parameter of the set type includes the communication frequency.

[0193] It should be noted that Figure 9 The specific implementation details of steps S210 - S230 shown can be referred to Figure 2 Steps S210 - S230 shown, Figure 9 The specific implementation details of steps S810 and S830 shown can be referred to Figure 8The steps S810 and S830 shown are not described herein again.

[0194] In Figure 9 the illustrated embodiment, since the workload is attacked, its corresponding communication frequency usually changes. Therefore, detecting whether the traffic data is abnormal based on the historical communication relationship information and the communication frequency corresponding to the historical communication relationship can improve the accuracy of anomaly detection.

[0195] In an exemplary embodiment, refer to Figure 10 , Figure 10 which is a flowchart of a traffic data detection method shown in another exemplary embodiment of the present application. This method can be applied to Figure 1 the illustrated implementation environment, and it can be executed by Figure 1 the anomaly detection party 102 in the illustrated implementation environment.

[0196] As Figure 10 shown, this method includes steps S210 - S220, steps S1010 - S1030, and step S240. Among them, the detailed introduction of steps S1010 - S1030 is as follows:

[0197] Step S1010: Obtain the importance of the workload to be detected, and calculate the similarity threshold according to the importance; wherein, the similarity threshold is positively correlated with the importance.

[0198] The importance of the workload is used to characterize the importance degree of the workload, and it can be determined according to the category of the workload, for example, the department, business, etc. to which the workload belongs.

[0199] According to the importance, the similarity threshold corresponding to the workload to be detected can be calculated. The similarity threshold is used to determine whether the target communication relationship information corresponding to the workload to be detected matches the historical communication relationship information. The higher the importance of the workload to be detected, the higher the corresponding similarity threshold, and the lower the importance of the workload to be detected, the lower the corresponding similarity threshold.

[0200] Step S1020: Search for the historical communication relationship information in the multiple historical communication relationship information included in the historical data set whose similarity to the target communication relationship information is greater than or equal to the similarity threshold.

[0201] After calculating the similarity threshold corresponding to the workload to be detected, the similarity between the target communication relationship information corresponding to the workload to be detected and the historical communication relationship information included in the historical data set can be calculated to search for the historical communication relationship information whose similarity to the target communication relationship information is greater than or equal to the similarity threshold.

[0202] Step S1030, use the found historical communication relationship information as the historical communication relationship information that matches the target communication relationship information.

[0203] Optionally, if historical communication relationship information with a similarity greater than or equal to the similarity threshold with the target communication relationship information is found, it is determined that the target communication relationship information matches the historical communication relationship information.

[0204] If no historical communication relationship information with a similarity greater than or equal to the similarity threshold with the target communication relationship information is found, it is determined that there is no historical communication relationship information in the historical dataset that matches the target communication relationship information, and the target traffic data corresponding to the target communication relationship information is determined to be abnormal traffic data. That is, for a workload to be detected with a higher importance level, the corresponding similarity threshold is higher, making it more difficult to find historical communication relationship information that matches the target communication relationship information. If the similarity between the target traffic data and the historical communication relationship information is slightly lower, it will be determined as abnormal traffic data to ensure the security of the workload to be detected with a higher importance level; for a workload to be detected with a lower importance level, the corresponding similarity threshold is lower, making it easier to find historical communication relationship information that matches the target communication relationship information. Even if the similarity between the target traffic data and the historical communication relationship information is slightly lower, it can be determined that the target traffic data matches the historical communication relationship information, thus saving resources.

[0205] For example, in an optional example, for a workload to be detected with a relatively high importance level, it is determined that the target communication relationship information matches the historical communication relationship information only when the characteristic data of the source workload in the target communication relationship information matches the characteristic data of the source workload in the historical communication relationship information, and the characteristic data of the destination workload in the target communication relationship information matches the characteristic data of the destination workload in the historical communication relationship information; for a workload to be detected with a relatively low importance level, it is determined that the target communication relationship information matches the historical communication relationship information when the characteristic data of the source workload in the target communication relationship information matches the characteristic data of the source workload in the historical communication relationship information, and the characteristic data of the destination workload in the target communication relationship information matches the characteristic data of the destination workload in the historical communication relationship information, or when the characteristic data of the source workload in the target communication relationship information matches the characteristic data of the destination workload in the historical communication relationship information, and the characteristic data of the destination workload in the target communication relationship information matches the characteristic data of the source workload in the historical communication relationship information. In another optional example, for a workload to be detected with a relatively high importance level, the matching of the characteristic data of the source workload in the target communication relationship information and the characteristic data of the source workload in the historical communication relationship information may mean that they are the same; for a workload to be detected with a relatively low importance level, the matching of the characteristic data of the source workload in the target communication relationship information and the characteristic data of the source workload in the historical communication relationship information may mean that their similarity is greater than 90%; for example, assuming that the characteristic data of the source workload in the historical communication relationship information is Department 1 and Business 1, and the characteristic data of the source workload in the target communication relationship information corresponding to the workload to be detected is Department 2 and Business 1, if the importance level of this workload to be detected is relatively high, it is determined that the characteristic data of the source workload in the historical communication relationship information does not match the characteristic data of the source workload in the target communication relationship information; if the importance level of this workload to be detected is relatively low, since they have the same business, it can be determined that the characteristic data of the source workload in the historical communication relationship information matches the characteristic data of the source workload in the target communication relationship information.

[0206] It should be noted that Figure 10 The specific implementation details of the steps S220 - S240 shown can be referred to Figure 2 the steps S220 - S240 shown, and will not be elaborated here.

[0207] In Figure 10In the illustrated embodiment, a similarity threshold corresponding to a workload is determined according to the importance of the workload, where the similarity threshold is positively correlated with the importance. Thus, based on the similarity threshold, it is determined whether the communication relationship information corresponding to the traffic data of the workload matches the historical communication relationship information, so as to determine whether the traffic data is abnormal based on the matching result, which can reduce the data processing volume while ensuring the accuracy of anomaly detection.

[0208] In one exemplary embodiment, refer to Figure 11 , Figure 11 is a flowchart of a traffic data detection method shown in another exemplary embodiment of the present application. This method can be applied to Figure 1 the illustrated implementation environment, which can be executed by Figure 1 the anomaly detection party 102 in the illustrated implementation environment.

[0209] As Figure 11 shown, this method includes step S1110 - step S1120, and step S230 - step S240. Among them, the detailed introduction of step S1110 - step S1120 is as follows:

[0210] Step S1110: Send a data collection instruction to the data collection party, so that the data collection party collects the traffic of the workload to be detected according to the data collection instruction, and obtains the target traffic data; where the workload to be detected includes at least one of a container, a service component, a virtual machine, and a host.

[0211] It should be noted that the categories of the workload to be detected include but are not limited to at least one of a container, a service component, a virtual machine, a host, etc.

[0212] The data collection instruction is used to instruct the data collection party to collect traffic data. When it is necessary to detect whether the traffic data of the workload to be detected is abnormal, the anomaly detection party can send a data collection instruction to the data collection party; after receiving the data collection instruction, the data collection party collects the traffic of the workload to be detected and obtains the target traffic data.

[0213] Step S1120: Receive the target traffic data sent by the data collection party.

[0214] The data collection party sends the collected target traffic data to the anomaly detection party, so that the anomaly detection party can obtain the target traffic data.

[0215] It should be noted that Figure 11 the specific implementation details of step S220 - step S240 shown in Figure 2 can refer to step S220 - step S240 shown in

[0216] In Figure 11In the illustrated embodiment, after the data collection party receives the data collection instruction from the anomaly detection party, it can collect and transmit traffic data, which can save resources. Moreover, the categories of workloads to be detected include, but are not limited to, at least one of containers, service components, virtual machines, hosts, etc., improving the applicability of traffic data detection.

[0217] In an exemplary embodiment, refer to Figure 12 , Figure 12 which is a flowchart of a traffic data detection method shown in another exemplary embodiment of the present application. This method can be applied to Figure 1 the illustrated implementation environment, which can be executed by Figure 1 the anomaly detection party 102 in the illustrated implementation environment.

[0218] As Figure 12 shown, the method includes step S1210 - step S1220, step S1120, and step S230 - step S240. Among them, the detailed introduction of step S1210 - step S1220 is as follows:

[0219] Step S1210, find the target node to which the workload to be detected belongs from multiple nodes; where each node contains a data collection party and multiple workloads.

[0220] It should be noted that Figure 12 the shown method can be applied to a system including multiple nodes, and each node contains a data collection party and multiple workloads. Among them, the node can be a terminal device, a server (such as a cloud server, etc.), etc., and the data collection party is used to collect the traffic data of multiple workloads deployed in the node to which it belongs.

[0221] When it is necessary to detect whether the traffic of the workload to be detected is abnormal, the target node to which the workload to be detected belongs can be found from multiple nodes. That is to say, the target node is the node where the workload to be detected is deployed.

[0222] Step S1220, send a data collection instruction to the data collection party included in the target node, so that the data collection party included in the target node finds the workload to be detected from the multiple workloads included in the target node according to the data collection instruction, and collects the traffic of the found workload to be detected to obtain the target traffic data.

[0223] The anomaly detection party may send a data collection instruction to the data collection party included in the target node. After receiving the data collection instruction, the data collection party included in the target node searches for the workload to be checked from the multiple workloads deployed locally (i.e., the multiple workloads included in the target node) according to the data collection instruction, and collects the traffic of the workload to be checked to obtain the target traffic data. In other words, the data collection party and the workload to be checked that it collects are deployed in the same node.

[0224] Optionally, the data collection instruction may include information about the workload to be detected, so that the data collection party in the target node searches for the workload to be detected based on the information. In an optional example, the data collection instruction may include a category of the workload (for example, the department, business, etc.) to which it belongs, so that the data collection party in the target node searches for a workload that matches the category from multiple locally deployed workloads as the workload to be checked; in another optional example, the data collection instruction may include identification information of the workload to be detected, so that the data collection party in the target node searches for a workload that matches the identification information from multiple locally deployed workloads as the workload to be detected.

[0225] Optionally, the data collector can be a client deployed in the node. In this way, in the process of detecting whether the traffic data of the workload is abnormal, the anomaly detector only needs to communicate with the client, without connecting to other third-party systems. Compared with the method of detecting anomalies of workloads based on the DaemonSet method of k8s in the related technology, the related technology does not support workloads such as virtual machines and hosts well, and does not support containers running with docker run; while the client deployed as the anomaly detector in the node is used to collect the traffic parameters of multiple workloads deployed in the node to which it belongs through the client, which has better support for workloads such as virtual machines and hosts, and can support containers running with docker run, thereby improving the accuracy of the generality of anomaly detection. Among them, k8s stands for Kubernetes, which is an open source platform for managing containers, DaemonSet is a daemon controller provided by Kubernetes, and docker run refers to a command for creating and starting containers.

[0226] It should be noted that Figure 12 The specific implementation details of steps S220 to S240 shown in FIG. Figure 2 Steps S220 to S240 are shown. Figure 12 The specific implementation details of step S1120 shown in FIG. Figure 11 The step S1120 shown is not repeated here.

[0227] In Figure 12 In the illustrated embodiment, by deploying a data collector in a node, the data collector is used to collect traffic data of the workloads deployed in its affiliated node, so that the anomaly detector is docked with the data collector, and there is no need to dock with other third-party systems, which can improve the accuracy of anomaly detection and expand the scope of use of anomaly detection.

[0228] In one exemplary embodiment, the traffic data detection method can be applied to Figure 1 the illustrated implementation environment, which can be executed by Figure 1 the data collector 101 in the illustrated implementation environment. The traffic data detection method may include the following steps: The data collector collects the traffic of the workload to be detected to obtain target traffic data, and sends the target traffic data to the anomaly detector, so that the anomaly detector extracts the feature data of the destination workload and the feature data of the source workload corresponding to the target traffic data to obtain target communication relationship information, searches for historical communication relationship information matching the target communication relationship information from the historical data set, and determines the anomaly detection result of the target traffic data according to the search result corresponding to the target communication relationship information; wherein, the historical data set contains historical communication relationship information corresponding to the traffic data of the workloads collected within a set historical time period.

[0229] Optionally, the data collector can collect periodically or in real time, or the data collector can collect after receiving a data collection instruction from the anomaly detector.

[0230] Optionally, the data collector and the workload can be deployed in a node, and each node includes a data collector and multiple workloads. The data collector is used to collect the traffic data of the multiple workloads deployed in its affiliated node.

[0231] For the specific introduction of the data collector, the workload to be detected, and the target traffic data, please refer to the description in the foregoing embodiment, which will not be elaborated here.

[0232] In one exemplary embodiment, the traffic data detection method is described by taking the implementation environment including a micro-alarm server and multiple hosts as an example, and taking the traffic data as the access data generated by the access behavior and the communication relationship information as the access relationship information. Among them, the host can be a virtual machine or a physical host, and each host includes a micro-alarm client and multiple workloads. Refer to Figure 13 , Figure 13 which is the flowchart of the traffic data detection method shown in another exemplary embodiment of the present application. As Figure 13 shown, the method includes steps S1301-step S1307, which are introduced in detail as follows:

[0233] Step S1301, the micro-alarm server receives configuration parameters.

[0234] As an anomaly detection party, the micro-alarm server can receive parameters configured by the security administrator, including but not limited to information about the workloads to be detected (e.g., IP address segments), the frequency of traffic collection, the frequency at which the micro-alarm clients send traffic data to the micro-alarm server, etc.

[0235] Optionally, after receiving the configuration parameters, the micro-alarm server can provide feedback to the security administrator to confirm receipt of the parameters.

[0236] Step S1302, each micro-alarm client obtains configuration parameters from the micro-alarm server.

[0237] After the micro-alarm server receives the configuration parameters, each micro-alarm client can obtain the configuration parameters from the micro-alarm server. Among them, the micro-alarm server can actively send the configuration parameters to each micro-alarm client, or, after receiving a pull request sent by the micro-alarm client, send the configuration parameters to the micro-alarm client.

[0238] Optionally, after each micro-alarm client obtains the configuration parameters, it can send a confirmation instruction to the micro-alarm server so that the micro-alarm server can determine that the micro-alarm client has obtained the configuration parameters.

[0239] Step S1303, each micro-alarm client sends access data of each workload deployed in the host to which it belongs to the micro-alarm server.

[0240] The workloads can access each other. As a data collection party, the micro-alarm client can collect the access data of each workload deployed in the host to which it belongs and send the access data to the micro-alarm server. For example, see Figure 14 As shown, the application environment contains multiple hosts, each host contains a micro-alarm client and multiple workloads. Each micro-alarm client can collect the access data of the workloads included in the host to which it belongs and send the access data to the micro-alarm server through the network.

[0241] Among them, for the convenience of analysis, an access data set corresponding to each workload can be constructed. The access data set can include the name of the workload and multiple pieces of access data corresponding to the workload. Each piece of access data can include the five-tuple information of the corresponding access behavior. For example, see Figure 15As shown in the figure, the micro-alarm client 1 on the host 1 collects the access data sets corresponding to the workload 1, workload 2, and workload m deployed on the host 1 respectively. Each access data set contains the name of the corresponding workload and multiple pieces of access data. Each piece of access data contains the source IP address, source port, destination IP address, destination port, and transport protocol.

[0242] Step S1304, the micro-alarm server constructs a historical access data set based on the access data sent by each micro-alarm client.

[0243] For each piece of access data, the micro-alarm server can extract its access relationship information, and thus construct a historical access data set according to the access relationship information. Among them, under the condition that the name of the workload is named in the form of category-identifier, the micro-alarm server can Figure 16 extract the access relationship information by the method shown in the figure, see Figure 16 As shown in the figure, for each piece of access data, the micro-alarm server can find the name of the corresponding workload according to its source IP address. If found, the largest prefix in the name of the workload is used as the characteristic data of the access party. If not found, the source IP is used as the characteristic data of the access party. Correspondingly, for each piece of access data, the name of the corresponding workload can be found according to its destination IP address. If found, the largest prefix in the name of the workload is used as the characteristic data of the accessed party. If not found, the destination IP is used as the characteristic data of the accessed party. Then, the corresponding access relationship information is constructed according to the characteristic data of the access party and the accessed party corresponding to each piece of access data. Among them, the largest prefix in the name of the workload refers to the field as the category.

[0244] Step S1305, each micro-alarm client sends the access data of each workload deployed in its affiliated host to the micro-alarm server.

[0245] After constructing the historical access data set, each micro-alarm client can collect the access data of each workload deployed in its affiliated host and send it to the micro-alarm server. Among them, the access data contains five-tuple information.

[0246] Step S1306, the micro-alarm server performs anomaly detection on each piece of access data.

[0247] Among them, see Figure 17As shown in the figure, for each piece of access data, the micro-alarm server can look up the name of the corresponding workload based on its source IP address. If found, the maximum prefix in the name of the workload is used as the characteristic data of the access party. If not found, the source IP is used as the characteristic data of the access party. Correspondingly, for each piece of access data, the name of the corresponding workload can be looked up based on its destination IP address. If found, the maximum prefix in the name of the workload is used as the characteristic data of the accessed party. If not found, the destination IP is used as the characteristic data of the accessed party. Then, the corresponding access relationship information is constructed based on the characteristic data of the access party and the accessed party corresponding to each piece of access data. After that, the micro-alarm server can look up the historical access relationship information that matches the access relationship information corresponding to the access data from the historical dataset. If not found, the corresponding access data is determined to be abnormal access data. If found, the corresponding access data is determined to be normal access data.

[0248] It can be seen from this that the traffic data detection method generally includes three stages:

[0249] Basic configuration stage: The network administrator deploys the micro-alarm system and configures the parameters, corresponding to steps S1301 - S1302.

[0250] Traffic learning stage: The micro-alarm client collects and reports access data to the micro-alarm server. For each piece of access data, the micro-alarm server extracts the access relationship information and stores it in the historical dataset, corresponding to steps S1303 - S1304.

[0251] Traffic classification stage: The micro-alarm client collects and reports access data to the micro-alarm server. For each piece of access data, the micro-alarm server detects whether it is abnormal based on the historical dataset, corresponding to steps S1305 - S1306.

[0252] For better understanding, an example is given here. Suppose the name of the workload is named in the form of "department - business - environment - identification number". The name of workload A is: department1 - business1 - environment1 - 0, and the IP address is 168.100.1; the name of workload B is: department2 - business2 - environment2 - 0, and the IP address is 168.200.1; in the traffic learning stage, the collected access data and the corresponding access relationship information are shown in Table 1 below:

[0253]

[0254]

[0255] Table 1 Correspondingly, the historical access relationship information contained in the historical dataset is shown in Table 2 below:

[0256] Number Historical access relationship information 1 Department 1 - Service 1 - Environment 1 accesses Department 2 - Service 2 - Environment 2 2 Department 1 - Service 1 - Environment 1 accesses 200.200.0.1 3 172.16.0.1 accesses Department 1 - Service 1 - Environment 1

[0257] Table 2 In the traffic classification phase, the collected access data and the corresponding detection results are shown in Table 3 below:

[0258]

[0259]

[0260] Table 3

[0261] Among them, for the 4th piece of access data, due to workload reconstruction, etc., the IP address of workload A "Department 1 - Business 1 - Environment 1 - 0" has changed from "168.100.1" to "168.100.2". However, since the name remains unchanged, the extracted access relationship information is still "Department 1 - Business 1 - Environment 1 accesses Department 2 - Business 2 - Environment 2", which matches the historical access relationship information 1; for the 5th piece of traffic data, due to business expansion, etc., a new workload "Department 1 - Business 1 - Environment 1 - 1" has been added in Department 1 - Business 1 - Environment 1. The access relationship information extracted according to the longest prefix is "Department 1 - Business 1 - Environment 1 accesses Department 2 - Business 2 - Environment 2", which matches the historical access relationship information 1.

[0262] Step S1307, the micro - alarm server presents the anomaly detection result to the security administrator.

[0263] After determining the anomaly detection result, the anomaly detection result can also be presented to the security administrator so that the security administrator can process it according to the anomaly detection result.

[0264] Optionally, after determining that the access data is abnormal access data or normal access data, the micro - alarm server can also receive the correction information from the security administrator for this detection result. If it is determined that the access data is normal access data according to the correction information, the access relationship information corresponding to this access data is added to the historical data set. If the correction information determines that the access data is abnormal access data and there is a matching historical access relationship information in the historical data set for the access relationship information corresponding to this access data, then the access relationship information is deleted from the historical data set.

[0265] It should be noted that Figure 13 The detailed processes involved in steps S1301 - S1307 shown have been described in the foregoing embodiments, so they will not be elaborated herein.

[0266] In Figure 13 the embodiment shown, based on Figure 13The provided traffic data detection method can quickly implement anomaly detection without setting tags for container loads, enabling rapid rollout of anomaly detection in scenarios such as major security protection. At the same time, it can support more types of workloads and is applicable to scenarios such as hybrid clouds. Moreover, it can ensure the accuracy of anomaly detection under conditions of business scaling up or down.

[0267] See Figure 18 , Figure 18 which is a block diagram of a traffic data detection device shown in an exemplary embodiment of the present application. As Figure 18 shown, the device includes:

[0268] An acquisition module 1801 configured to acquire target traffic data obtained by a data acquisition party through collecting the traffic of a workload to be detected;

[0269] An extraction module 1802 configured to extract the characteristic data of the destination workload and the characteristic data of the source workload corresponding to the target traffic data to obtain target communication relationship information;

[0270] A search module 1803 configured to search for historical communication relationship information matching the target communication relationship information from a historical data set; wherein, the historical data set contains historical communication relationship information corresponding to the traffic data of workloads collected within a set historical time period;

[0271] A detection module 1804 configured to determine the anomaly detection result of the target traffic data according to the search result corresponding to the target communication relationship information.

[0272] In an exemplary embodiment, based on the foregoing solution, the device further includes a construction module configured to:

[0273] Acquire the historical traffic data of the workload collected by the data acquisition party within a set historical time period;

[0274] Extract the characteristic data of the destination workload and the characteristic data of the source workload corresponding to the historical traffic data to obtain the historical communication relationship information corresponding to the historical traffic data;

[0275] Construct a historical data set according to the extracted historical communication relationship information.

[0276] In an exemplary embodiment, based on the foregoing solution, the construction module is specifically configured to:

[0277] Extract the source Internet protocol address and the destination Internet protocol address from the historical traffic data;

[0278] Search for the attribute information of the workload to which the source Internet protocol address belongs to obtain the characteristic data of the source workload corresponding to the historical traffic data;

[0279] Search for the attribute information of the workload to which the destination Internet protocol address belongs, and obtain the characteristic data of the destination workload corresponding to the historical traffic data;

[0280] Construct the historical communication relationship information corresponding to the historical traffic data according to the characteristic data of the destination workload corresponding to the historical traffic data and the characteristic data of the source workload.

[0281] In an exemplary embodiment, based on the foregoing solution, the construction module is specifically configured as:

[0282] Search for the workload to which the source Internet protocol address belongs;

[0283] Use the attribute information of the found workload as the characteristic data of the source workload corresponding to the historical traffic data; wherein, the attribute information of the found workload includes at least one of the affiliation information, location information, service information, and operating environment information corresponding to the found workload.

[0284] In an exemplary embodiment, based on the foregoing solution, the construction module is specifically configured as:

[0285] Search for the identification information of the workload to which the source Internet protocol address belongs, and extract a set number of characters from the identification information in the order from front to back;

[0286] Use the set number of characters as the characteristic data of the source workload corresponding to the historical traffic data.

[0287] In an exemplary embodiment, based on the foregoing solution, the construction module is specifically configured as:

[0288] If the attribute information of the workload to which the source Internet protocol address belongs is not found, use the source Internet protocol address as the characteristic data of the source workload corresponding to the historical traffic data.

[0289] In an exemplary embodiment, based on the foregoing solution, when the historical data set further includes communication parameters of a set type corresponding to each historical communication relationship information, the detection module 1804 is specifically configured as:

[0290] If a target historical communication relationship information matching the target communication relationship information is found in the historical data set, extract the communication parameters of the set type corresponding to the target historical communication relationship information from the historical data set;

[0291] Obtain the communication parameters of the set type corresponding to the target communication relationship information according to the target traffic data;

[0292] If the communication parameters of the set type corresponding to the target communication relationship information match the communication parameters of the set type corresponding to the target historical communication relationship information, determine that the target traffic data is normal traffic data.

[0293] In an exemplary embodiment, based on the foregoing solution, the detection module 1804 is specifically configured as follows:

[0294] Obtain the target communication relationship information corresponding to each of the multiple pieces of target traffic data collected within the set detection time period;

[0295] From the multiple pieces of target traffic data, find the quantity of the target traffic data corresponding to each piece of target communication relationship information, and calculate the communication frequency corresponding to each piece of target communication relationship information according to the quantity of the target traffic data corresponding to each piece of target communication relationship information;

[0296] Use the communication frequency corresponding to each piece of target communication relationship information as the communication parameter of the set type corresponding to each piece of target communication relationship information.

[0297] In an exemplary embodiment, based on the foregoing solution, the search module 1803 is specifically configured as follows:

[0298] Obtain the importance of the workload to be detected, and calculate a similarity threshold according to the importance; wherein, the similarity threshold is positively correlated with the importance;

[0299] From the multiple pieces of historical communication relationship information included in the historical data set, find the historical communication relationship information whose similarity to the target communication relationship information is greater than or equal to the similarity threshold;

[0300] Use the found historical communication relationship information as the historical communication relationship information that matches the target communication relationship information.

[0301] In an exemplary embodiment, based on the foregoing solution, the acquisition module 1801 is specifically configured as follows:

[0302] Send a data collection instruction to the data collector, so that the data collector collects the traffic of the workload to be detected according to the data collection instruction, and obtains the target traffic data; wherein, the workload to be detected includes at least one of a container, a service component, a virtual machine, and a host;

[0303] Receive the target traffic data sent by the data collector.

[0304] In an exemplary embodiment, based on the foregoing solution, the acquisition module 1801 is specifically configured as follows:

[0305] Find the target node to which the workload to be detected belongs from multiple nodes; wherein, each node includes a data collector and multiple workloads;

[0306] Send a data collection instruction to the data collection party included in the target node, so that the data collection party included in the target node can find the workload to be detected from multiple workloads included in the target node according to the data collection instruction, and collect the traffic of the found workload to be detected to obtain target traffic data.

[0307] It should be noted that Figure 18 The provided traffic data detection device and the traffic data detection method on the abnormal detection side provided in the above embodiment belong to the same concept. The specific ways in which each module and unit perform operations have been described in detail in the method embodiment, and will not be elaborated here.

[0308] See Figure 19 , Figure 19 is a block diagram of a traffic data detection device shown in an exemplary embodiment of the present application. As Figure 19 shown, the device includes:

[0309] An acquisition module 1901, configured to collect the traffic of the workload to be detected to obtain target traffic data;

[0310] A sending module 1902, configured to send the target traffic data to the abnormal detection party, so that the abnormal detection party extracts the feature data of the destination workload and the feature data of the source workload corresponding to the target traffic data to obtain target communication relationship information, searches for historical communication relationship information matching the target communication relationship information from the historical data set, and determines the abnormal detection result of the target traffic data according to the search result corresponding to the target communication relationship information; wherein, the historical data set includes historical communication relationship information corresponding to the traffic data of the workloads collected within a set historical time period.

[0311] In an exemplary embodiment, based on the foregoing solution, the traffic data detection device is applied to a system including multiple nodes, each node includes a data collection party and multiple workloads, and the traffic data detection device is configured in any data collection party; the acquisition module 1901 is specifically configured to:

[0312] Receive a data collection instruction sent by the abnormal detection party;

[0313] According to the data collection instruction, find the workload to be detected from multiple workloads deployed locally; wherein, the workload to be detected includes at least one of a container, a service component, a virtual machine, and a host;

[0314] Collect the traffic data of the workload to be detected to obtain target traffic data.

[0315] It should be noted that Figure 19The provided traffic data detection device and the traffic data detection method on the data collection party side provided in the above embodiments belong to the same concept. The specific manners in which each module and unit perform operations have been described in detail in the method embodiments and will not be elaborated here.

[0316] An embodiment of the present application further provides an electronic device, including: one or more processors; a storage device for storing one or more computer programs, which, when executed by the one or more processors, cause the electronic device to implement the traffic data detection method provided in each of the above embodiments.

[0317] Figure 20 The structural diagram of a computer system of an electronic device suitable for implementing the embodiments of the present application is shown.

[0318] It should be noted that Figure 20 The shown computer system 2000 of the electronic device is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present application.

[0319] As Figure 20 shown, the computer system 2000 includes a central processing unit (CPU) 2001, which can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 2002 or the computer program loaded from the storage section 2008 into the random access memory (RAM) 2003, such as executing the traffic data detection method in the above embodiments. In the RAM 2003, various computer programs and data required for system operation are also stored. The CPU 2001, ROM 2002, and RAM 2003 are connected to each other through a bus 2004. The input / output (I / O) interface 2003 is also connected to the bus 2004.

[0320] In some embodiments, the following components are connected to the I / O interface 2003: an input part 2006 including a keyboard, a mouse, etc.; an output part 2007 including, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage part 2008 including a hard disk, etc.; and a communication part 2009 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication part 2009 performs communication processing via a network such as the Internet. The drive 2010 is also connected to the I / O interface 2003 as needed. A removable medium 2011, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 2010 as needed so that a computer program read from it can be installed into the storage part 2008 as needed.

[0321] Specifically, according to an embodiment of the present application, a computer program for implementing the traffic data detection method can be carried on a computer-readable medium, and the computer program can be downloaded and installed from the network through the communication part 2009, and / or installed from the removable medium 2011.

[0322] It should be noted that the computer-readable medium shown in the embodiments of the present application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium can be any tangible medium that contains or stores a computer program, and this computer program can be used by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable computer program. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer program contained in the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0323] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. Among them, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code, and the above module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, as well as the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and a computer program.

[0324] The units involved in the embodiments described in this application can be implemented in software or in hardware, and the described units can also be provided in a processor. Among them, the names of these units do not, in some cases, constitute a limitation on the unit itself.

[0325] Another aspect of this application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor of an electronic device, the electronic device implements the traffic data detection method as described above. The computer-readable storage medium can be included in the electronic device described in the above embodiments, or can exist alone without being assembled into the electronic device.

[0326] Another aspect of this application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the traffic data detection methods provided in the above various embodiments. Among them, the computer program can be stored in a computer-readable storage medium. The computer program product can be a computer program as a product, for example, an APP (Application, mobile phone application software), a web page, a small program, etc.; or, the computer program product can also be a storage medium, a device, a terminal, a virtual machine, etc. that includes the computer program.

[0327] The above content is only a preferred exemplary embodiment of this application and is not used to limit the implementation of this application. Those of ordinary skill in the art can easily make corresponding adaptations or modifications according to the main idea and spirit of this application. Therefore, the protection scope of this application should be subject to the protection scope required by the claims.

Claims

1. A flow data detection method, characterized in that, The method includes: Obtaining target traffic data collected by a data collector for the workload to be detected; Extracting the feature data of the destination workload and the feature data of the source workload corresponding to the target traffic data to obtain target communication relationship information; Searching in a historical dataset for historical communication relationship information that matches the target communication relationship information; wherein, the historical dataset contains historical communication relationship information corresponding to traffic data of workloads collected within a set historical time period; Determining an anomaly detection result of the target traffic data according to the search result corresponding to the target communication relationship information.

2. The method according to claim 1, wherein The method further includes: Obtaining historical traffic data of workloads collected by the data collector within the set historical time period; Extracting the feature data of the destination workload and the feature data of the source workload corresponding to the historical traffic data to obtain historical communication relationship information corresponding to the historical traffic data; Constructing the historical dataset according to the extracted historical communication relationship information.

3. The method according to claim 2, characterized in that The extracting the feature data of the destination workload and the feature data of the source workload corresponding to the historical traffic data to obtain historical communication relationship information corresponding to the historical traffic data includes: Extracting a source Internet protocol address and a destination Internet protocol address from the historical traffic data; Searching for attribute information of the workload to which the source Internet protocol address belongs to obtain the feature data of the source workload corresponding to the historical traffic data; Searching for attribute information of the workload to which the destination Internet protocol address belongs to obtain the feature data of the destination workload corresponding to the historical traffic data; Constructing historical communication relationship information corresponding to the historical traffic data according to the feature data of the destination workload and the feature data of the source workload corresponding to the historical traffic data.

4. The method according to claim 3, wherein The searching for attribute information of the workload to which the source Internet protocol address belongs to obtain the feature data of the source workload corresponding to the historical traffic data includes: Searching for the workload to which the source Internet protocol address belongs; Taking the attribute information of the found workload as the feature data of the source workload corresponding to the historical traffic data; wherein, the attribute information of the found workload includes at least one of the affiliation information, location information, service information, and operating environment information corresponding to the found workload.

5. The method according to claim 3, wherein The searching for attribute information of the workload to which the source Internet protocol address belongs to obtain the feature data of the source workload corresponding to the historical traffic data includes: Searching for identification information of the workload to which the source Internet protocol address belongs and extracting a set number of characters from the identification information in the order from front to back; Taking the set number of characters as the feature data of the source workload corresponding to the historical traffic data.

6. The method according to claim 3, wherein The method further includes: If no attribute information of the workload to which the source Internet protocol address belongs is found, taking the source Internet protocol address as the feature data of the source workload corresponding to the historical traffic data.

7. The method according to claim 1, characterized in that, The historical dataset further includes communication parameters of a set type corresponding to each piece of historical communication relationship information; Determining an anomaly detection result of the target traffic data according to a search result corresponding to the target communication relationship information includes: If target historical communication relationship information matching the target communication relationship information is found from the historical dataset, extract communication parameters of a set type corresponding to the target historical communication relationship information from the historical dataset; Obtain communication parameters of a set type corresponding to the target communication relationship information according to the target traffic data; If the communication parameters of the set type corresponding to the target communication relationship information match the communication parameters of the set type corresponding to the target historical communication relationship information, determine that the target traffic data is normal traffic data.

8. The method according to claim 7, wherein The obtaining communication parameters of a set type corresponding to the target communication relationship information according to the target traffic data includes: Obtain target communication relationship information corresponding to multiple pieces of target traffic data collected within a set detection time period; From the multiple pieces of target traffic data, find the quantity of target traffic data corresponding to each piece of target communication relationship information, and calculate the communication frequency corresponding to each piece of target communication relationship information according to the quantity of target traffic data corresponding to each piece of target communication relationship information; Use the communication frequency corresponding to each piece of target communication relationship information as the communication parameters of a set type corresponding to each piece of target communication relationship information.

9. The method according to claim 1, characterized in that The searching for historical communication relationship information matching the target communication relationship information from the historical dataset includes: Obtain the importance of the workload to be detected, and calculate a similarity threshold according to the importance; wherein, the similarity threshold is positively correlated with the importance; Search for historical communication relationship information from multiple pieces of historical communication relationship information included in the historical dataset, the similarity between which and the target communication relationship information is greater than or equal to the similarity threshold; Use the found historical communication relationship information as the historical communication relationship information matching the target communication relationship information.

10. The method according to claim 1, characterized in that, The obtaining target traffic data collected by a data collector for the traffic of the workload to be detected includes: Send a data collection instruction to the data collector, so that the data collector collects the traffic of the workload to be detected according to the data collection instruction to obtain target traffic data; wherein, the workload to be detected includes at least one of a container, a service component, a virtual machine, and a host; Receive the target traffic data sent by the data collector.

11. The method according to claim 10, wherein The sending a data collection instruction to the data collector, so that the data collector collects the traffic of the workload to be detected according to the data collection instruction to obtain target traffic data includes: Find a target node to which the workload to be detected belongs from multiple nodes; wherein each node includes a data collector and multiple workloads; Send a data collection instruction to the data collector included in the target node, so that the data collector included in the target node locates the workload to be detected from the multiple workloads included in the target node according to the data collection instruction, and collects the traffic of the located workload to be detected to obtain target traffic data.

12. A flow data detection device, characterized in that, The device includes: An acquisition module, configured to acquire target traffic data obtained by a data collector collecting the traffic of a workload to be detected; An extraction module, configured to extract the feature data of the destination workload and the feature data of the source workload corresponding to the target traffic data to obtain target communication relationship information; A search module, configured to search for historical communication relationship information matching the target communication relationship information from a historical data set; wherein, the historical data set includes historical communication relationship information corresponding to the traffic data of the workloads collected within a set historical time period; A detection module, configured to determine the anomaly detection result of the target traffic data according to the search result corresponding to the target communication relationship information.

13. An electronic device, characterized in that, Includes: One or more processors; A storage device for storing one or more computer programs, which, when executed by the one or more processors, cause the electronic device to implement the method according to any one of claims 1-11.

14. A computer-readable storage medium, characterized in that, A computer program is stored thereon, which, when executed by the processor of the electronic device, causes the electronic device to implement the method according to any one of claims 1-11.

15. A computer program product, characterized in that, Includes a computer program, which, when executed by a processor, implements the method according to any one of claims 1-11.