Acquisition method, device and system

Through the public network gateway, the public network packets are identified and extracted from the virtual machine's public network packets using elastic identification and acquisition rules, and the problem of being unable to monitor public network packets separately in the existing technology is solved, and the accurate identification and security analysis of public network packets is achieved.

CN120263436APending Publication Date: 2025-07-04HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410490695.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-01-04
Filing Date
2024-04-19
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

The existing technology cannot effectively extract public network messages from all network messages for monitoring and analysis, resulting in the inability to focus on monitoring and monitoring of public network messages transmitted by virtual machines within the data center.

Method used

The elastic identification and acquisition rules are obtained through the public network gateway, the data to be analyzed is identified and collected, and the public network packets of the virtual machine to be collected are identified using the elastic IP address or the full-domain elastic IP address, and the data to be analyzed is extracted from it according to the acquisition rules for monitoring.

Benefits of technology

It realizes accurate identification and monitoring of public network messages, improves the security analysis efficiency of public network messages, reduces the configuration complexity of tenants, and improves configuration flexibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263436A_ABST
    Figure CN120263436A_ABST
Patent Text Reader

Abstract

The invention discloses an acquisition method, device and system, which are used for independently extracting public network messages from all network messages (namely intranet messages and public network messages) and monitoring and analyzing the public network messages. In the application, the method comprises the following steps: a public network gateway acquires acquisition information, the acquisition information comprises an elastic identifier and an acquisition rule of a virtual machine to be acquired, and the elastic identifier is an elastic IP (elastic IP, EIP) address or a global elastic IP (global elastic IP, GEIP) address. The public network gateway identifies the public network message of the virtual machine to be collected according to the elastic identifier of the virtual machine to be collected in the process of forwarding the public network message of the M virtual machines, the M virtual machines comprise the virtual machine to be collected, and M is a positive integer. The public network gateway collects to-be-analyzed data from the public network message of the to-be-collected virtual machine according to the collection rule, and the to-be-analyzed data is used for monitoring the safety of the public network message of the to-be-collected virtual machine.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to a Chinese patent application filed with the Intellectual Property Office of the People's Republic of China on January 4, 2024, with application number 202410013243.2 and invention name “A method and device for flow log flow mirroring of EIP / GEIP”, the entire contents of which are incorporated by reference in this application. Technical Field

[0002] The embodiments of the present application relate to the field of computer technology, and in particular to a collection method, device and system. Background Art

[0003] Flow log monitoring and flow mirror monitoring are two network message monitoring technologies. Flow log monitoring is to output the metadata of network messages (or network traffic) (such as source Internet Protocol (IP) address, destination IP address, source port number, destination port number, message protocol, etc.) in the form of logs to storage devices, and then the storage devices analyze the logs (such as security analysis). Flow mirror monitoring can completely copy network messages to storage devices, and then the storage devices analyze the network messages.

[0004] Based on whether the network message is transmitted within the data center or between the data center and the public network node, the network message can be divided into intranet message and public network message. The current flow log monitoring and flow mirror monitoring are all for all network messages (i.e. intranet messages and public network messages) for monitoring and analysis. Intranet messages are often trustworthy messages. How to extract the public network message from all network messages separately and monitor and analyze the public network message is a technical problem that needs to be solved urgently. Summary of the invention

[0005] The present application provides a collection method, device and system for separately extracting public network messages from all network messages (i.e., intranet messages and public network messages) and monitoring and analyzing the public network messages.

[0006] In a first aspect, the present application provides a collection method, which can be executed by a public network gateway or a module in the public network gateway. For the convenience of description, the following is an example of execution by a public network gateway. The method includes:

[0007] The public network gateway obtains the collection information, where the collection information includes the elastic identifier of the virtual machine to be collected and the collection rule. The elastic identifier is an elastic IP (EIP) address or a global elastic IP (GEIP) address. During the process of forwarding the public network packets of M virtual machines, the public network gateway identifies the public network packets of the virtual machine to be collected according to the elastic identifier of the virtual machine to be collected. The M virtual machines include the virtual machine to be collected, and M is a positive integer. The public network gateway collects the data to be analyzed from the public network packets of the virtual machine to be collected according to the collection rule, and the data to be analyzed is used to monitor the security of the public network packets of the virtual machine to be collected.

[0008] In the above technical solution, since the public network packets transmitted between the M virtual machines and the public network node are all forwarded by the public network gateway, and each virtual machine corresponds to its own elastic identifier, the public network gateway can identify the public network packets of the virtual machine to be collected according to the elastic identifier of the virtual machine to be collected, and can identify the public network packets of the virtual machine to be collected more comprehensively and accurately. Furthermore, the public network gateway then collects the data to be analyzed from the public network packets of the virtual machine to be collected according to the collection rule, and the data to be analyzed can be used to monitor and analyze the security of the public network packets of the virtual machine to be collected.

[0009] In a possible implementation, the collection rule includes the screening conditions associated with the first session and the screening conditions associated with the second session, and the priority of the first session is higher than that of the second session. The public network packets of the virtual machine to be collected include the first public network packet. When the public network gateway collects the data to be analyzed from the public network packets of the virtual machine to be collected according to the collection rule, specifically, when the public network gateway determines that the first public network packet meets the screening conditions associated with the first session and the screening conditions associated with the first session indicate mirroring, it mirrors the first public network packet to obtain the data to be analyzed; when the public network gateway determines that the first public network packet does not meet the screening conditions associated with the first session, it determines that the first public network packet meets the screening conditions associated with the second session and the screening conditions associated with the second session indicate mirroring, and mirrors the first public network packet to obtain the data to be analyzed.

[0010] In the above technical solution, the collection rule includes the screening conditions associated with different sessions, and the priorities of different sessions are different. Therefore, when the public network gateway determines whether to mirror a certain public network packet, it can select the target session and the screening conditions associated with the target session from multiple sessions based on the priority. Furthermore, when it determines that the public network packet meets the screening conditions associated with the target session and the screening conditions associated with the target session indicate mirroring, it mirrors the public network packet to obtain the data to be analyzed, and when it determines that the public network packet does not meet the screening conditions associated with the target session, it re-selects the target session and the screening conditions associated with the target session from multiple sessions based on the priority. In this way, it helps to improve the matching efficiency.

[0011] In a possible implementation, the filtering conditions associated with the first session include a first filtering condition and a second filtering condition, and the priority of the first filtering condition is higher than that of the second filtering condition. When the public network gateway determines that the first public network packet meets the filtering conditions associated with the first session and the filtering conditions associated with the first session indicate mirroring, when mirroring the first public network packet to obtain the data to be analyzed, specifically, the public network gateway mirrors the first public network packet to obtain the data to be analyzed when determining that the first public network packet meets the first filtering condition and the first filtering condition indicates mirroring; when the public network gateway determines that the first public network packet does not meet the first filtering condition, it determines that the first public network packet meets the second filtering condition, and the second filtering condition indicates mirroring, and mirrors the first public network packet to obtain the data to be analyzed.

[0012] In the above technical solution, a single session can be associated with multiple filtering conditions, and the priorities of different filtering conditions are different. Therefore, when the public network gateway determines whether to mirror a certain public network packet according to the filtering conditions associated with the session, specifically, the public network gateway selects a target filtering condition from the multiple filtering conditions associated with the session based on the priority. Then, when determining that the public network packet meets the target filtering condition and the target filtering condition indicates mirroring, it mirrors the public network packet to obtain the data to be analyzed, and when determining that the public network packet does not meet the target filtering condition, it re-selects the target filtering condition from the multiple filtering conditions associated with the session based on the priority. In this way, it helps to improve the matching efficiency.

[0013] In a possible implementation, the collection rule further includes the filtering conditions associated with the third session, where the priority of the second session is higher than that of the third session. The public network packets of the virtual machine to be collected further include a second public network packet. The public network gateway also determines that the second public network packet meets the filtering conditions associated with the third session and the filtering conditions associated with the third session indicate non-mirroring when the second public network packet does not meet the filtering conditions associated with the first session and the filtering conditions associated with the second session.

[0014] In the above technical solution, when the public network gateway determines that a certain public network packet meets the filtering conditions associated with the third session and the filtering conditions associated with the third session indicate non-mirroring, it determines not to mirror the public network packet to obtain the data to be analyzed, and no longer determines whether the public network packet meets the filtering conditions associated with other sessions. In this way, it avoids unnecessary matching and can obtain the data to be analyzed that the tenant hopes to obtain.

[0015] Further, different collection rules include different sessions and / or different filtering conditions associated with the same session, and the filtering conditions associated with the session can indicate mirroring or non-mirroring. For example, collection rule 1 includes filtering condition 11 and filtering condition 12 associated with session 1, and filtering condition 21 and filtering condition 22 associated with session 2. Collection rule 2 includes filtering condition 11 and filtering condition 13 associated with session 1, and filtering condition 21 and filtering condition 23 associated with session 2. Among them, filtering condition 11, filtering condition 12, filtering condition 13, and filtering condition 23 indicate mirroring, and filtering condition 21 and filtering condition 22 indicate non-mirroring. The tenant can preset multiple sessions, the filtering conditions associated with each session, and the mirroring policy (i.e., whether to indicate mirroring) of the filtering conditions associated with each session, and then configure the sessions and the filtering conditions associated with the sessions included in different collection rules. In this way, it helps to improve the configuration flexibility and reduce the configuration complexity of the tenant.

[0016] In a possible implementation, the filtering condition includes any one of the following: Example 1, the filtering condition includes: the transmission direction of the public network packet is the outbound direction, and the destination IP address of the public network packet is the IP address of a preset public network node; Example 2, the filtering condition includes: the transmission direction of the public network packet is the inbound direction, and the source IP address of the public network packet is the IP address of a preset public network node; Example 3, the filtering condition includes: the source IP address and the destination IP address of the public network packet, where when the source IP address is the IP address of a preset public network node, the destination IP is the elastic identifier of the virtual machine to be collected; when the destination IP address is the IP address of a preset public network node, the source IP is the elastic identifier of the virtual machine to be collected.

[0017] In a possible implementation, the public network gateway stores the mapping relationship between the elastic identifiers and the private IP addresses of M virtual machines, where the elastic identifier of the virtual machine is the identifier of the virtual machine outside the data center, and the private IP address of the virtual machine is the identifier of the virtual machine inside the data center. The first virtual machine is any one of the M virtual machines. When the public network gateway forwards the public network packets of the M virtual machines, specifically:

[0018] The public network gateway receives the public network packet from the first virtual machine, and the source IP address in the public network packet is the private IP address of the first virtual machine; after converting the source IP address in the public network packet to the elastic identifier of the first virtual machine according to the mapping relationship and the private IP address of the first virtual machine, a new public network packet is obtained, and the new public network packet is forwarded to the public network node; or,

[0019] The public network gateway receives public network packets from public network nodes, and the destination IP address in the public network packets is the elastic identifier of the first virtual machine. After converting the destination IP address in the public network packets into the private network IP address of the first virtual machine according to the mapping relationship and the elastic identifier of the first virtual machine, a new public network packet is obtained, and the new public network packet is forwarded to the first virtual machine.

[0020] In the above technical solution, a specific implementation manner of the public network gateway when forwarding public network packets of any virtual machine is provided. In this way, it is realized that the public network gateway can obtain the public network packets of M virtual machines, and further obtain the public network packets of the virtual machine to be collected from the public network packets of the M virtual machines.

[0021] In a possible implementation manner, the collected information further includes the IP address of the destination virtual machine, and the public network gateway can also send the data to be analyzed to the destination virtual machine according to the IP address of the destination virtual machine.

[0022] In the above technical solution, the public network gateway can also send the data to be analyzed to the destination virtual machine, so that the destination virtual machine can monitor the security of the public network packets of the virtual machine to be collected according to the data to be analyzed.

[0023] Exemplarily, the IP address of the destination virtual machine is determined based on the global topology relationship, the global topology relationship is determined based on the local topology relationships of multiple data centers, and the destination virtual machine and the virtual machine to be collected are located in different data centers of multiple data centers.

[0024] In the above technical solution, in the case where the destination virtual machine and the virtual machine to be collected are located in different data centers, a determination method for the IP address of the destination virtual machine is provided.

[0025] Exemplarily, the IP address of the destination virtual machine includes the IP address of the physical device to which the destination virtual machine belongs and the private network IP address of the destination virtual machine in the physical device to which it belongs. When the public network gateway sends the data to be analyzed to the destination virtual machine according to the IP address of the destination virtual machine, specifically, it can send a virtual extensible local area network (VXLAN) packet to the destination virtual machine. Among them, the data to be analyzed is included in the inner layer packet of the VXLAN packet, the private network IP address of the destination virtual machine in the physical device to which it belongs is included in the first layer tunnel encapsulation header of the VXLAN packet, and the IP address of the physical device to which it belongs is included in the second layer tunnel encapsulation header of the VXLAN packet.

[0026] In the above technical solution, in the case where the destination virtual machine and the virtual machine to be collected are located in different data centers, a specific implementation manner for the public network gateway to send the data to be analyzed to the destination virtual machine according to the IP address of the destination virtual machine is provided.

[0027] In a possible implementation, the virtual machine to be collected includes N network cards, where N is a positive integer, and the collected information further includes the identifier of the network card to be collected, and the N network cards include the network card to be collected. When the public network gateway forwards the public network packets of M virtual machines, and identifies the public network packets of the virtual machine to be collected according to the elastic identifier of the virtual machine to be collected, specifically, when the public network gateway forwards the public network packets of M virtual machines, it identifies the public network packets of the network card to be collected according to the elastic identifier of the virtual machine to be collected and the identifier of the network card to be collected. Exemplarily, the public network gateway identifies the public network packets of the virtual machine to be collected from the public network packets of M virtual machines according to the elastic identifier of the virtual machine to be collected, and then the public network gateway identifies the public network packets of the network card to be collected from the public network packets of the virtual machine to be collected according to the identifier of the network card to be collected. Further, when the public network gateway collects the data to be analyzed from the public network packets of the virtual machine to be collected according to the collection rule, specifically, the public network gateway collects the data to be analyzed from the public network packets of the network card to be collected, and the data to be analyzed is used to monitor the security of the public network packets of the network card to be collected.

[0028] In the above technical solution, the public network gateway obtains the data to be analyzed from the public network packets transmitted by a certain network card of the virtual machine in terms of the granularity of a certain network card, so as to monitor the security of the public network packets of a certain network card, and improve the flexibility of monitoring.

[0029] In a second aspect, the present application provides a collection system, including:

[0030] A cloud management platform and a public network gateway. Among them, the cloud management platform is used to: generate collection information and send the collection information to the public network gateway; the public network gateway is used to: receive the collection information from the cloud management platform, the collection information includes the elastic identifier of the virtual machine to be collected and the collection rule, and the elastic identifier is an EIP address or a GEIP address; when forwarding the public network packets of M virtual machines, identify the public network packets of the virtual machine to be collected according to the elastic identifier of the virtual machine to be collected, where the M virtual machines include the virtual machine to be collected, and M is a positive integer; collect the data to be analyzed from the public network packets of the virtual machine to be collected according to the collection rule, and the data to be analyzed is used to monitor the security of the public network packets of the virtual machine to be collected.

[0031] In a possible implementation, it further includes: M virtual machines, and the first virtual machine is any one of the M virtual machines.

[0032] When the transmission direction of the public network packet is the outbound direction, the first virtual machine is used to: send the public network packet to the public network gateway. Correspondingly, when the public network gateway is used to forward the public network packets of M first virtual machines, it is specifically used to: receive the public network packet from the first virtual machine, the IP address in the public network packet is the private IP address of the first virtual machine, and according to the mapping relationship between the elastic identifiers and private IP addresses of the M first virtual machines, and the private IP address of the first virtual machine, after converting the source IP address in the public network packet into the elastic identifier of the first virtual machine, a new public network packet is obtained, and the new public network packet is forwarded to the public network node.

[0033] When the transmission direction of the public network packet is the inbound direction, when the public network gateway is used to forward the public network packets of M first virtual machines, it is specifically used to: receive the public network packet from the public network node, the destination IP address in the public network packet is the elastic identifier of the first virtual machine, and according to the mapping relationship between the elastic identifiers and private IP addresses of the M first virtual machines, and the elastic identifier of the first virtual machine, after converting the destination IP address in the public network packet into the private IP address of the first virtual machine, a new public network packet is obtained, and the new public network packet is forwarded to the first virtual machine. The first virtual machine is used to: receive the new public network packet from the public network gateway.

[0034] In a possible implementation, it further includes: a destination virtual machine, and the collected information further includes the IP address of the destination virtual machine. The public network gateway is further used to: send the data to be analyzed to the destination virtual machine according to the IP address of the destination virtual machine. The destination virtual machine is used to: receive the data to be analyzed from the public network gateway; monitor the security of the public network packets of the virtual machine to be collected according to the data to be analyzed.

[0035] In a possible implementation, it further includes: a global control platform; the global control platform is used to: receive the identifier of the destination virtual machine from the cloud management platform; determine the IP address of the destination virtual machine according to the identifier of the destination virtual machine and the global topology relationship, and send the IP address of the destination virtual machine to the cloud management platform. The destination virtual machine and the virtual machine to be collected are located in different data centers of multiple data centers.

[0036] In the above technical solution, the global control platform includes a global topology relationship, that is, which physical devices are respectively in multiple data centers, the connection relationships between these physical devices, and which virtual machines are included in each physical device, etc. In the case where the destination virtual machine and the virtual machine to be collected are located in different data centers, the cloud management platform can request the IP address of the destination virtual machine from the global control platform based on the identifier of the destination virtual machine, so that the public network gateway can send the data to be analyzed to the destination virtual machine according to the IP address of the destination virtual machine.

[0037] In a possible implementation, it further includes: a local control platform; the local control platform is used to: determine the local topology relationship corresponding to the data center to which the local control platform belongs; send the local topology relationship corresponding to the data center to which the local control platform belongs to the global control platform; the global control platform is further used to: determine the global topology relationship according to the local topology relationship corresponding to the data center to which the local control platform belongs.

[0038] In the above technical solution, each data center includes a local control platform inside. The local control platform is used to determine the local topology relationship, that is, to determine which physical devices are in this data center, the connection relationships between these physical devices, and which virtual machines are included in each physical device, etc. Then, the local control platform sends the local topology relationship to the global control platform, and the global control platform can determine the global topology relationship.

[0039] In a third aspect, the present application provides a collection device, which can be a public network gateway or a module in the public network gateway.

[0040] The collection device includes: an acquisition module, which is used to acquire acquisition information. The acquisition information includes the elastic identifier and acquisition rules of the virtual machine to be acquired. The elastic identifier is an EIP address or a GEIP address; a forwarding module, which is used to forward the public network packets of M virtual machines; an identification module, which is used to identify the public network packets of the virtual machine to be acquired according to the elastic identifier of the virtual machine to be acquired when the forwarding module forwards the public network packets of M virtual machines. The M virtual machines include the virtual machine to be acquired, and M is a positive integer; a collection module, which is used to collect the data to be analyzed from the public network packets of the virtual machine to be acquired according to the acquisition rules. The data to be analyzed is used to monitor the security of the public network packets of the virtual machine to be acquired.

[0041] In a possible implementation, the acquisition rules include the screening conditions associated with the first session and the screening conditions associated with the second session, where the priority of the first session is higher than that of the second session; the public network packets of the virtual machine to be acquired include the first public network packet. When the collection module collects the data to be analyzed from the public network packets of the virtual machine to be acquired according to the acquisition rules, it is specifically used to: when it is determined that the first public network packet meets the screening conditions associated with the first session and the screening conditions associated with the first session indicate mirroring, mirror the first public network packet to obtain the data to be analyzed; when it is determined that the first public network packet does not meet the screening conditions associated with the first session, determine that the first public network packet meets the screening conditions associated with the second session and the screening conditions associated with the second session indicate mirroring, and mirror the first public network packet to obtain the data to be analyzed.

[0042] In a possible implementation manner, the filtering conditions associated with the first session include a first filtering condition and a second filtering condition, and the priority of the first filtering condition is higher than that of the second filtering condition; when the acquisition module determines that the first public network packet meets the filtering conditions associated with the first session and the filtering conditions associated with the first session indicate mirroring, when mirroring the first public network packet to obtain the data to be analyzed, it is specifically used for: when determining that the first public network packet meets the first filtering condition and the first filtering condition indicates mirroring, mirroring the first public network packet to obtain the data to be analyzed; when determining that the first public network packet does not meet the first filtering condition, determining that the first public network packet meets the second filtering condition and the second filtering condition indicates mirroring, and mirroring the first public network packet to obtain the data to be analyzed.

[0043] In a possible implementation manner, the acquisition rule further includes a filtering condition associated with a third session, where the priority of the second session is higher than that of the third session. The public network packets of the virtual machine to be acquired further include a second public network packet. The acquisition module is further used for: when determining that the second public network packet does not meet the filtering conditions associated with the first session and the filtering conditions associated with the second session, determining that the second public network packet meets the filtering conditions associated with the third session and the filtering conditions associated with the third session indicate non-mirroring.

[0044] In a possible implementation manner, the filtering conditions include any one of the following: the transmission direction of the public network packet is the outbound direction, and the destination IP address of the public network packet is the IP address of a preset public network node; the transmission direction of the public network packet is the inbound direction, and the source IP address of the public network packet is the IP address of a preset public network node; the source IP address and destination IP address of the public network packet, where when the source IP address is the IP address of a preset public network node, the destination IP is the elastic identifier of the virtual machine to be acquired; when the destination IP address is the IP address of a preset public network node, the source IP is the elastic identifier of the virtual machine to be acquired.

[0045] In a possible implementation manner, when the forwarding module forwards the public network packets of M virtual machines, it is specifically used for: receiving the public network packet from the first virtual machine, and the source IP address in the public network packet is the private IP address of the first virtual machine; according to the mapping relationship between the elastic identifiers and private IP addresses of the M virtual machines and the private IP address of the first virtual machine, after converting the source IP address in the public network packet into the elastic identifier of the first virtual machine, obtaining a new public network packet; forwarding the new public network packet to the public network node; the first virtual machine is any one of the M virtual machines.

[0046] In a possible implementation, when the forwarding module forwards the public network packets of M virtual machines, it is specifically configured to: receive the public network packets from the public network node, where the destination IP address in the public network packets is the elastic identifier of the first virtual machine; according to the mapping relationship between the elastic identifiers and private IP addresses of the M virtual machines, and the elastic identifier of the first virtual machine, convert the destination IP address in the public network packets into the private IP address of the first virtual machine to obtain a new public network packet; forward the new public network packet to the first virtual machine; the first virtual machine is any one of the M virtual machines.

[0047] In a possible implementation, the collected information further includes the IP address of the destination virtual machine, where the IP address of the destination virtual machine is determined based on the global topology relationship, the global topology relationship is determined based on the local topology relationships of multiple data centers, and the destination virtual machine and the virtual machine to be collected are located in different data centers among the multiple data centers. The collection module is further configured to send the data to be analyzed to the destination virtual machine according to the IP address of the destination virtual machine.

[0048] In a possible implementation, the IP address of the destination virtual machine includes the IP address of the physical device to which the destination virtual machine belongs and the private IP address of the destination virtual machine in the physical device to which it belongs. When the collection module sends the data to be analyzed to the destination virtual machine according to the IP address of the destination virtual machine, it is specifically configured to: send a VXLAN packet to the destination virtual machine, where the inner packet of the VXLAN packet includes the data to be analyzed, the first layer tunnel encapsulation header of the VXLAN packet includes the private IP address of the destination virtual machine in the physical device, and the second layer tunnel encapsulation header of the VXLAN packet includes the IP address of the physical device.

[0049] In a possible implementation, the virtual machine to be collected includes N network cards, N is a positive integer, the collected information further includes the identifier of the network card to be collected, and the N network cards include the network card to be collected. When the identification module identifies the public network packets of the virtual machine to be collected, it is specifically configured to: identify the public network packets of the network card to be collected from the public network packets of the M virtual machines according to the elastic identifier of the virtual machine to be collected and the identifier of the network card to be collected. When the collection module collects the data to be analyzed from the public network packets of the virtual machine to be collected according to the collection rule, it is specifically configured to: collect the data to be analyzed from the public network packets of the network card to be collected according to the collection rule, and the data to be analyzed is used to monitor the security of the public network packets of the network card to be collected.

[0050] In a fourth aspect, the present application provides a computing device cluster, including at least one computing device, and each computing device includes a processor and a memory; the processor of at least one computing device is configured to execute instructions stored in the memory of at least one computing device, so that the computing device cluster executes the method in the first aspect or any possible implementation manner of the first aspect.

[0051] Fifth aspect, the present application provides a computer program product including instructions, which, when run by a cluster of computing devices, cause the cluster of computing devices to execute the method in the first aspect or any possible implementation manner of the first aspect described above.

[0052] Sixth aspect, the present application provides a computer-readable storage medium including computer program instructions, which, when executed by a cluster of computing devices, cause the cluster of computing devices to execute the method in the first aspect or any possible implementation manner of the first aspect described above.

[0053] For the technical effects that can be achieved by any one of the second aspect to the fifth aspect described above, reference can also be made to the description of the beneficial effects in the first aspect above, and details will not be repeated here. Description of the Drawings

[0054] Figure 1 It is a schematic architecture diagram of a virtualization technology;

[0055] Figure 2 It is a basic architecture diagram of a server running virtual machines;

[0056] Figure 3 It is a schematic format diagram of a VXLAN packet;

[0057] Figure 4 It is a schematic structure diagram of a VPC peering connection service;

[0058] Figure 5 It is a schematic architecture diagram of a data acquisition system provided by the present application;

[0059] Figure 6 It is a schematic flow diagram of a collection method provided by the present application;

[0060] Figure 7 It is a flow chart for matching public network packets provided by the present application;

[0061] Figure 8 It is a schematic format diagram of packet encapsulation provided by the present application;

[0062] Figure 9 It is a schematic architecture diagram of another data acquisition system provided by the present application;

[0063] Figure 10 It is a flow chart for a public network gateway to obtain the IP address of a destination virtual machine provided by the present application;

[0064] Figure 11 It is a schematic flow diagram for a cloud management platform to generate collection information corresponding to flow log data provided by the present application;

[0065] Figure 12A schematic flow chart for a cloud management platform provided by this application to generate acquisition information corresponding to flow mirror data;

[0066] Figure 13 Another schematic architecture diagram of a data acquisition system provided by this application;

[0067] Figure 14 A schematic structural diagram of an acquisition device provided by this application;

[0068] Figure 15 A schematic structural diagram of a computing device provided by this application;

[0069] Figure 16 A schematic structural diagram of a computing device cluster provided by this application;

[0070] Figure 17 A schematic network connection diagram of a computing device cluster provided by this application. Detailed implementation manners

[0071] First, the relevant technical features involved in the embodiments of this application will be explained. It should be noted that these explanations are for making the embodiments of this application easier to understand and should not be regarded as limiting the protection scope required by this application.

[0072] I. Virtualization technology

[0073] Figure 1 An exemplary schematic architecture diagram of a virtualization technology is shown, which mainly consists of computing virtualization, network virtualization, and storage virtualization (the latter two can be summarized as input / output (I / O) virtualization). Among them, computing virtualization provides the computing resources (such as processors and memory) of a server (or physical server, physical device, entity device, physical machine, etc.) for virtual instances to use, storage virtualization provides the storage resources (such as disks) of a server for virtual instances to use, and network virtualization provides the network resources (such as network cards) of a server for virtual instances to use. Among them, a virtual instance is, for example, a virtual machine (VM), or it can be understood that the virtualization technology shares a physical server with multiple tenants at the granularity of virtualization, enabling tenants to conveniently and flexibly use physical resources under the premise of secure isolation and greatly improving the utilization rate of physical resources.

[0074] Furthermore, Figure 1 The shown virtual machine manager (VMM) can be used to implement the functions of computing virtualization, network virtualization, storage virtualization, and the cloud management platform.

[0075] 1. Virtual Machine (VM)

[0076] A virtual machine refers to a complete computer system with the functions of a complete hardware system simulated by software and running in a completely isolated environment. All the work that can be done on a server can be achieved in a virtual machine. When creating a virtual machine on a server, a part of the hard disk and memory capacity of the physical machine needs to be used as the hard disk and memory capacity of the virtual machine. Each virtual machine has an independent hard disk and operating system, and the tenant of the virtual machine can operate the virtual machine in the same way as using a server.

[0077] For example Figure 2 Exemplarily, a basic architecture diagram of a server running virtual machines is provided. The server includes a hardware layer and a software layer. The hardware layer is the conventional configuration of the server. Among them, Peripheral Component Interconnect (PCI) devices can be, for example, network cards, Graphics Processing Units (GPUs), offload cards, etc., which can be inserted into the PCI / Peripheral Component Interconnect Express (PCIe) slots of the server; the software layer includes an operating system installed and running on the server (which can be called the host operating system relative to the operating system of the virtual machine). The virtual machine manager is set in the host operating system. The virtual machine manager can not only be used to implement the computing virtualization, network virtualization, and storage virtualization of the virtual machine and is responsible for managing the virtual machine, but also be used for logical isolation between different virtual machines and managing the virtual machine. For example, creating a virtual machine, simulating virtual hardware for the virtual machine according to the hardware layer, deleting the virtual machine, forwarding and / or processing network packets between all virtual machines running on this server (for example Figure 2 Virtual Machine 1 and Virtual Machine 2 in it) or forwarding network packets between the virtual machines on this server and the external network (virtual switching function), and processing the I / O generated by the virtual machine. The running environments in different virtual machines (such as virtual machine applications, operating systems, and virtual hardware) are completely isolated. To communicate between Virtual Machine 1 and Virtual Machine 2, network packets need to be forwarded by the virtual machine manager. The tenant can remotely log in to the virtual machine and operate the installation, setting, and uninstallation of applications in the virtual machine operating system environment.

[0078] 2. Data Center

[0079] A data center can also be referred to as a cloud data center, a cloud computing data center, etc.

[0080] The data center may include a cloud management platform, an internal network of the data center, and multiple servers (i.e., physical servers), and each server can be virtualized into one or more virtual machines. Among them, the cloud management platform is used to provide access interfaces (such as interfaces or application programming interfaces (APIs)). Tenants can operate the client to remotely access the access interface, register cloud accounts and passwords on the cloud management platform, and log in to the cloud management platform. After the cloud management platform successfully authenticates the cloud accounts and passwords, tenants can further pay on the cloud management platform to select and purchase virtual machines of specific specifications. After the successful payment and purchase, the cloud management platform provides the remote login account password of the purchased virtual machine, and the client can remotely log in to the virtual machine and install and run the tenant's applications in the virtual machine.

[0081] Furthermore, the logical functions of the cloud management platform can be divided as follows: console, computing management service, network management service, storage management service, authentication service, image management service, etc. Among them, the console provides an interface or API to interact with tenants. The computing management service is used to manage the servers running virtual machines and containers and bare metal servers. The network management service is used to manage network services. The storage management service is used to manage storage services. The authentication service is used to manage the account passwords of tenants. The image management service is used to manage virtual machine images.

[0082] 3. Virtual Private Cloud (VPC)

[0083] Tenants can create virtual machine 1 and virtual machine 2 in the data center and set virtual machine 1 and virtual machine 2 in VPC1. Also, create virtual machine 3 and virtual machine 4 and set virtual machine 3 and virtual machine 4 in VPC2. Tenants can set the private network segments of VPC1 and VPC2 through the client in the access interface provided by the cloud management platform. The two can be the same or different. VPC1 and VPC2 are similar to two independent local area networks. Tenants can further set the private network addresses of virtual machine 1 and virtual machine 2 in VPC1 and set the private network addresses of virtual machine 3 and virtual machine 4 in VPC2 in the interface provided by the cloud management platform. Virtual machine 1 and virtual machine 2 can communicate with each other in VPC1 (can ping each other), and virtual machine 3 and virtual machine 4 can communicate with each other in VPC2. However, virtual machines located in different VPCs cannot communicate. For example, pinging the private network address 192.168.1.4 of virtual machine 3 in virtual machine 1 will not get a response.

[0084] The above characteristics of the VPC network fully simulate the characteristics of the local area network in the public cloud, enabling the tenant's local computer to be set in an environment similar to the local network after going to the cloud, and even the local devices can not modify their own private network addresses after going to the cloud.

[0085] The isolation principle of the VPC can be implemented based on the virtual extensible LAN (VXLAN) technology. For example Figure 3It is a schematic diagram of the format of a VXLAN packet. The VXLAN packet encapsulates the inner packet in the data part (payload) of a User Datagram Protocol (UDP) packet. The data part of the UDP packet carries a VXLAN header, an inner Ethernet header, an inner IP header, and the data part (payload) of the IP packet. The inner packet includes an inner Ethernet header, an inner IP header, and the data part of the IP packet. The inner Ethernet header records the source and destination Medium Access Control (MAC) addresses of the inner packet. The inner IP header records the source and destination IP addresses of the inner packet. The VXLAN packet also includes a tunnel encapsulation header, which includes an outer Ethernet header, an outer IP header, an outer UDP header, and a VXLAN header. The VXLAN header includes a VXLAN Flags field, a Reserved field, and a Virtual Network Infrastructure (VNI). The outer Ethernet header records the source and destination MAC addresses of the VXLAN Tunnel End Point (VTEP). The outer IP header records the source and destination IP addresses of the VXLAN tunnel end point. The VXLAN tunnel end point can also be referred to as a VTEP device. The VTEP device is the endpoint of the VXLAN tunnel and is used to encapsulate the inner packet: add an outer Ethernet header, an outer IP header, an outer UDP header, and a VXLAN header to the inner packet to generate a VXLAN packet and send it to other VTEP devices. It can also de-encapsulate the VXLAN packet received from other VTEP devices: strip off the outer Ethernet header, outer IP header, outer UDP header, and VXLAN header of the VXLAN packet to obtain the inner packet and obtain the VNI from the VXLAN header. During the VXLAN encapsulation process, the VTEP device uses the Layer 2 packet as the inner packet of the VXLAN packet, records the source MAC address as the MAC address of the VTEP device and the destination MAC address as the MAC address of the next-hop device in the outer Ethernet header of the tunnel encapsulation header of the VXLAN packet, records the source IP address as the IP address of the VTEP device and the destination IP address as the IP address of the VTEP device at the other end of the tunnel in the outer IP header of the tunnel encapsulation header of the VXLAN packet, and records the VNI in the VNI field of the VXLAN header of the VXLAN packet.Different VPCs are distinguished by VNI. The servers running virtual machines in the data center are provided with VXLAN tunnel endpoints, which can be implemented through the protocol stack of the operating system or through network cards.

[0086] Considering that two local area networks can communicate with each other, the public cloud network provides a VPC peering service to simulate this scenario, enabling VPC1 to connect to VPC2. Tenants can configure the interconnection between VPC1 and VPC2 in the cloud management platform, and then when attempting to ping virtual machine 3 from virtual machine 1, a response packet can be obtained on virtual machine 1.

[0087] Figure 4 An exemplary structural schematic diagram of the VPC peering service is provided. After the VPC peering service is configured, a connection is established between port 1 and port 2. The IP packet can be forwarded from port 1 to port 2. The IP packet coming out of port 2 is correspondingly set with the VNI2 corresponding to VPC2. The VXLAN tunnel endpoint 2 encapsulates the IP packet and VNI2 into the VXLAN packet 2 and sends it to the VXLAN tunnel endpoint 1 for decapsulation and then sends it to VPC2 through the logical bridge, thereby realizing cross-VPC intercommunication. For the specific packet transmission, refer to Figure 4 each step in

[0088] 4. Elastic IP (EIP) address

[0089] To enable cloud resources to access the public network, the public cloud provides EIP addresses, which can be bound to elastic compute service (ECS) instances (equivalent to virtual machines) to achieve public network access to resources. Combined with Figure 4In an example, a tenant purchases an EIP address on a cloud management platform and configures the EIP address to be bound to virtual machine 3. At this time, the public network gateway (for example, a network address translation (NAT) gateway) records the correspondence between the EIP address, VNI2 (VNI2 corresponding to VPC2), and the private network address of virtual machine 3 in VPC2. When a public network tenant accesses the EIP address and sends a web access request with the destination IP address being the EIP address, this request is routed to the data center in the Internet. The public network gateway receives this request, identifies that this request is to be sent to VPC2 based on the EIP address, modifies the destination IP address of the web access request to the private network address of virtual machine 3 in VPC2, encapsulates the modified web access request into VXLAN packet 1. VXLAN packet 1 arrives at VXLAN tunnel terminal 1 via the internal network for decapsulation, and then the web access request is sent to router 2 according to VNI2. Router 2 then forwards this request to VXLAN tunnel terminal 2 for encapsulation and then to virtual machine 3. Virtual machine 3 sends the web page to be accessed as a response packet to the public network gateway according to the web access request. The destination IP address of the response packet is the public network address of the client (which is carried in the source IP address of the web access request). When the tenant decides to stop using the EIP address, the tenant can set the EIP address to be unbound from virtual machine 3 in the cloud management platform. At this time, the public network gateway eliminates the recorded correspondence between the EIP address, VNI2, and the private network address of virtual machine 3, and the web access request from the client for the EIP address will not be forwarded by the public network gateway to virtual machine 3.

[0090] Global Elastic IP (GEIP) addresses provide global public network access capabilities, support tenants to specify a global region to create public IP addresses, and can be bound across regions to instances in any region on the cloud (such as ECS instances, load balancer instances, etc.) to achieve communication between cloud resources and the public network. The usage scope of GEIP addresses is wider than that of EIP addresses. For example, if a tenant purchases a GEIP address in Shanghai, then the tenant can bind this GEIP address to a virtual machine in Shanghai or bind this GEIP address to a virtual machine in Beijing (that is, the virtual machine bound by the GEIP address is not limited by the purchase region); if a tenant purchases an EIP address in Shanghai, then the tenant can only bind this EIP address to a virtual machine in Shanghai and cannot bind this GEIP address to a virtual machine in Beijing (that is, the virtual machine bound by the EIP address is limited by the purchase region).

[0091] For ease of description, in this application, the EIP address and the GEIP address can be collectively referred to as elastic identifiers. Further, in the following examples, it is assumed that the elastic identifier is the EIP for illustration purposes. Of course, the following examples are also applicable to the scenario where the elastic identifier is the GEIP, and the EIP can be replaced with the GEIP for understanding.

[0092] II. Technologies for Network Packet Monitoring and Analysis

[0093] Flow logs and flow mirroring are two technologies for network packet monitoring and analysis.

[0094] 1. Flow Logs

[0095] Flow logs are a technology for recording network packets. It can output the metadata of network packets (such as source IP address, destination IP address, source port number, destination port number, packet protocol, etc.) in the form of logs for monitoring, analysis, and storage.

[0096] Flow logs can be widely applied in the following scenarios: (1) Intrusion detection: Flow logs can be used to detect intrusion events, such as malicious network packets, abnormal tenant behavior, and data leakage. (2) Threat intelligence: Flow logs can be used to collect threat intelligence, such as malware signatures, attack patterns, and attackers' tools and techniques. (3) Compliance: Flow logs can be used to determine whether network packets meet compliance requirements.

[0097] In flow log collection, the collection object can specifically be a VPC, a virtual machine, or a virtual machine network card. Exemplarily, when the collection object is a virtual machine network card, a collection rule is configured in the virtual machine network card, and the virtual machine network card collects flow log data according to the collection rule and the packets flowing through the virtual machine network card, and sends the flow log data to the storage device; when the collection object is a virtual machine, a collection rule can be configured in all the virtual machine network cards included in the virtual machine, and each virtual machine network card collects flow log data according to the collection rule and the packets flowing through the virtual machine network card, and sends the flow log data to the storage device; when the collection object is a VPC, a collection device is set in the VPC, the packets of each virtual machine network card in the VPC will flow through the collection device, a collection rule is configured in the collection device, and the collection device collects flow log data according to the collection rule and the packets flowing through each virtual machine network card, and sends the flow log data to the storage device. Further, the collection rule is, for example, to collect the packets received by the virtual machine network card, the packets rejected by the virtual machine network card, or all the packets transmitted by the virtual machine network card. The storage device is, for example, an object storage service on the cloud.

[0098] 2. Flow Mirroring

[0099] Flow mirroring is a technology that copies network packets to a storage device for monitoring and analysis. It can copy the complete data packets of network packets to the storage device for in-depth analysis and detection.

[0100] Flow mirroring is widely used in the following scenarios: (1) Network security analysis: Flow mirroring can be used to analyze network packets to identify attacks, malware, and other security threats. (2) Data leakage detection: Flow mirroring can be used to detect data leakage, such as the transmission or deletion of sensitive data. (3) Security incident response: Flow mirroring can be used to support security incident response, for example, to provide detailed information on the attack scene.

[0101] In the flow mirroring collection, the collection object (or mirror source) is usually a virtual machine. The collection rules are configured in the virtual machine network card included in the virtual machine. The virtual machine network card performs a mirroring operation according to the collection rules (or mirroring rules) and the messages flowing through the virtual machine network card, and sends the flow mirroring data after the mirroring operation to the storage device (or mirroring destination). Furthermore, the collection rules are, for example, mirroring operations on messages that meet pre-set source IP address, destination IP address, message protocol, source port number, destination port number and other conditions. Among them, the storage device is, for example, another virtual machine or an elastic load balancing (ELB) and other devices.

[0102] In the above-mentioned flow log collection, it is necessary to perform flow log collection on all messages transmitted by the virtual machine (including public network messages (also known as external network messages) and intranet messages of the data center), but it is impossible to perform flow log collection on the public network messages alone. In the above-mentioned flow mirror collection, it is necessary to perform flow mirror collection on all messages transmitted by the virtual machine (including public network messages and intranet messages), or set the IP address of the public network node to be collected (such as the source IP address or the destination IP address) in the collection rule, but this method of setting the IP address of the public network node in the collection rule cannot enumerate the IP addresses of all public network nodes. As mentioned above, it is also impossible to perform flow mirror collection on the public network messages transmitted by the virtual machine.

[0103] The intranet messages in the data center are often trustworthy messages, so it is necessary to focus on monitoring the public network messages. How to collect, analyze and monitor the public network messages transmitted by the virtual machines in the data center is a technical problem that needs to be solved urgently.

[0104] like Figure 5Schematic diagram of the architecture of a data acquisition system applicable to the method of this application. Among them, it includes a data center, the Internet, public network node 1, and public network node 2. Among them, the data center can be a public cloud data center, a private cloud data center, or a hybrid cloud data center. Inside the data center, there are a public network gateway, a VPC, a cloud management platform, and storage devices. The public network gateway accesses the Internet and establishes network connections with public network node 1 and public network node 2 respectively. The public network gateway is also connected to the cloud management platform. The public network gateway can be a hardware network device, or a physical server cluster, a virtual machine, or a virtualized network function (VNF), etc.

[0105] Public network node 1 and public network node 2 are sites with public IP addresses. Public network node 1 is set with public IP address 1, and public network node 2 is set with public IP address 2. Public network node 1 and public network node 2 are located outside the data center. The public network node can also be called an external network node.

[0106] Figure 5 For the descriptions of the devices in, reference can also be made to the descriptions in the above Figures 1 to 4 Related embodiments.

[0107] The cloud management platform provides an access interface. Tenants can remotely access this access interface through an operation client, and then create virtual machine 1 and virtual machine 2 inside the VPC, and set the private IP address 1 and private IP address 2 of virtual machine 1 and virtual machine 2 in the VPC respectively. Further, the tenant can also purchase EIP address 1 and EIP address 2 for virtual machine 1 and virtual machine 2 respectively. That is, virtual machine 1, private IP address 1, and EIP address 1 are bound together, and virtual machine 2, private IP address 2, and EIP address 2 are bound together. EIP address 1 can be used for virtual machine 1 to transmit public network packets with the public network node, and EIP address 2 can be used for virtual machine 2 to transmit public network packets with the public network node.

[0108] Further, the public network gateway stores the mapping relationship among the virtual machine identifier, the private IP address, and the EIP address. When a virtual machine needs to access a public network node, or when a public network node needs to access a virtual machine, the public network gateway can convert the private IP address and EIP address of this virtual machine. Combined with Figure 5For example, when virtual machine 1 needs to access public network node 1, virtual machine 1 constructs a public network message with private network IP address 1 as the source IP address and the public network IP address 1 of public network node 1 as the destination IP address, and sends the public network message to the public network gateway. The public network gateway converts private network IP address 1 to EIP address 1 according to the mapping relationship, and then forwards the obtained public network message to public network node 1; when public network node 1 needs to access virtual machine 1, public network node 1 constructs a public network message with public network IP address 1 as the source IP address and EIP address 1 as the destination IP address, and sends the public network message to the public network gateway. The public network gateway converts the destination IP address in the public network message from EIP address 1 to private network IP address 1 according to the mapping relationship, and then forwards the obtained public network message to virtual machine 1. The access of virtual machine 2 to public network node 1, the access of public network node 1 to virtual machine 2, the access of virtual machine 1 to public network node 2, or the access of public network node 2 to virtual machine 1, etc. are all similar.

[0109] Considering that all public network messages transmitted by virtual machines within the data center will pass through the public network gateway, the public network gateway can be used to collect flow log data or flow mirror data of virtual machines (hereinafter collectively referred to as data to be analyzed), and then send the data to be analyzed to the storage device for analysis.

[0110] Such as Figure 6 FIG. is a schematic flowchart of a collection method provided by the present application by way of example. The collection method can be executed by the public network gateway in the data center, and the data center may further include M virtual machines, where M is a positive integer.

[0111] Step 601, the public network gateway obtains collection information.

[0112] Among them, the collection information can specifically be received by the public network gateway from the cloud management platform, that is, the cloud management platform generates collection information based on tenant operations and sends the collection information to the public network gateway (specifically, refer to the descriptions in the following Figure 11 And Figure 12 Related embodiments).

[0113] Among them, the collection information includes the elastic identifier of the virtual machine to be collected and the collection rule.

[0114] Exemplarily, the collection information further includes a collection category, and the collection category is used to indicate whether the public network gateway collects flow log data as the data to be analyzed (that is, the data to be analyzed is flow log data) or collects flow mirror data as the data to be analyzed (that is, the data to be analyzed is flow mirror data).

[0115] The elastic identifier of the virtual machine to be collected is the EIP address or GEIP address of the virtual machine to be collected. The elastic identifier of the virtual machine to be collected is used to indicate which (or which) of the M virtual machines the public network gateway needs to collect data from in the public network message. Among them, the virtual machines to be collected can be one or more. Exemplarily, the collection information includes the elastic identifiers of M virtual machines, that is, the public network gateway needs to collect data from the public network messages of M virtual machines. For the convenience of description, the following is an example of a virtual machine to be collected. Combined with Figure 5 In the example, the data center includes virtual machines 1 and 2, and the elastic identifier of the virtual machine to be collected is EIP address 1. Then, the elastic identifier of the virtual machine to be collected is used to indicate that the public network gateway needs to collect data in the public network message of virtual machine 1.

[0116] When the public network gateway collects flow log data as data to be analyzed,

[0117] The collection rules may include screening conditions, wherein the screening conditions may be used to instruct the public network gateway to collect the flow log data of which public network messages, and the screening conditions may be: public network messages received by the virtual machine, public network messages sent by the virtual machine, public network messages refused to be received by the virtual machine, public network messages transmitted by the virtual machine, etc. The collection rules may also include the time interval for aggregating the flow log data. Optionally, the collection rules also include collection indicators, such as source IP address, destination IP address, source port number, destination port number, message protocol, etc.

[0118] When the public network gateway collects flow mirroring data as data to be analyzed:

[0119] In the first example, the collection rule includes a filtering condition associated with a session. When the collection rule includes filtering conditions associated with multiple sessions, the collection rule also includes the priority of each session. Furthermore, when a session is associated with multiple filtering conditions, the collection rule may also include the priorities of the multiple filtering conditions associated with the session. Optionally, the collection rule also includes a session or a session identifier.

[0120] Table 1 is an exemplary form of a collection rule provided in the present application. The collection rule includes priority 1 for session 1, priority 2 for session 2, and priority 3 for session 3, wherein priority 1 is higher than priority 2, and priority 2 is higher than priority 3. The collection rule also includes filter conditions 11 and filter conditions 12 associated with session 1, as well as priority 11 of filter condition 11 and priority 12 of filter condition 12, wherein priority 11 is higher than priority 12; filter conditions 21 and filter conditions 22 associated with session 2, as well as priority 21 of filter condition 21 and priority 22 of filter condition 22, wherein priority 21 is higher than priority 22; and filter condition 3 associated with session 3.

[0121] Table 1

[0122]

[0123] The second example, the collection rule includes a filtering condition. When the collection rule includes multiple filtering conditions, the collection rule also includes the priority of each filtering condition.

[0124] As shown in Table 2, another form of the collection rule provided exemplarily by this application, the collection rule includes filtering condition 1 and priority 1, filtering condition 2 and priority 2, filtering condition 3 and priority 3, where priority 1 is higher than priority 2, and priority 2 is higher than priority 3.

[0125] Table 2

[0126] Identification of screening conditions Priority of screening conditions Screening condition 1 Priority 1 Screening condition 2 Priority 2 Screening condition 3 Priority 3

[0127] Furthermore, the filtering condition may include one or more of the following parameters: the message direction (or transmission direction) of the public network message, the source IP address of the public network message, the destination IP address of the public network message, the source port number of the public network message, the destination port number of the public network message, the message protocol of the public network message. Among them, the message direction includes the outbound direction and the inbound direction. The outbound direction means that the public network message is sent from the virtual machine to the public network node, and the inbound direction means that the public network message is sent from the public network node to the virtual machine. The message protocol is, for example, the address resolution protocol (ARP), the internet control message protocol (ICMP), the user datagram protocol (UDP), the transmission control protocol (TCP), the file transfer protocol (FTP), the hypertext transfer protocol (HTTP), etc.

[0128] The following exemplarily provides an implementation manner in which the filtering condition includes parameters:

[0129] Example 1, the filtering condition includes: the transmission direction of the public network message is the outbound direction, and the destination IP address of the public network message is the IP address of a preset public network node. It can be understood that the preset public network node is used to indicate which (or which) public network nodes the public network gateway needs to collect data in the public network messages sent by the virtual machine to be collected. The preset public network node can be any one or more of multiple public network nodes. Combined with Figure 5In an example, if the preset public network node is public network node 1, then the destination IP address of the public network message is public network IP address 1. Or, if the preset public network node is public network node 2, then the destination IP address of the public network message is public network IP address 2.

[0130] Example 2, the filtering conditions include: the transmission direction of the public network message is the incoming direction, and the source IP address of the public network message is the IP address of the preset public network node. It can be understood that the preset public network node is used to indicate which (or which) public network nodes' data in the public network messages sent to the virtual machine to be collected the public network gateway needs to collect. The preset public network node can be any one or more of multiple public network nodes. For specific examples, please refer to Example 1.

[0131] Example 3, the filtering conditions include: the source IP address and the destination IP address of the public network message. Among them, the source IP address is specifically the elastic identifier of the virtual machine to be collected, and the destination IP is specifically the IP address of the preset public network node. That is to say, the public network gateway needs to collect the data in the public network messages sent from the virtual machine to be collected to the preset public network node. For the description of the preset public network node, please refer to Example 1 above.

[0132] Example 4, the filtering conditions include: the source IP address and the destination IP address of the public network message. Among them, the source IP address is specifically the IP address of the preset public network node, and the destination IP is specifically the elastic identifier of the virtual machine to be collected. That is to say, the public network gateway needs to collect the data in the public network messages sent from the preset public network node to the virtual machine to be collected. For the description of the preset public network node, please refer to Example 1 above.

[0133] In a possible way, the filtering conditions are used to match the public network message. When the public network gateway determines that the public network message matches the filtering conditions, it performs a mirroring operation on the public network message; when the public network gateway determines that the public network message does not match the filtering conditions, it does not perform a mirroring operation on the public network message. That is to say, it directly forwards the public network message without performing any operations (specifically, please refer to the description in step 602). It can also be understood that in this possible example, the mirroring policy associated with the filtering conditions is mirroring, or the filtering conditions indicate mirroring (or mirroring operation).

[0134] In another possible way, the collection rule also includes a mirroring policy. Among them, the mirroring policy is mirroring or not mirroring. In the first example above, when each session is associated with multiple filtering conditions, each filtering condition can be further associated with a mirroring policy. When each session is associated with one filtering condition, each session (or rather, the filtering condition associated with this session) can be further associated with a mirroring policy; in the second example above, when the collection rule includes multiple filtering conditions, each filtering condition can be further associated with a mirroring policy.

[0135] It can be understood that the screening condition is used to match public network packets, and the mirroring policy associated with the screening condition is used to indicate whether to perform mirroring operations on the public network packets when the public network packets match the screening condition. Specifically, when the public network gateway determines that the public network packets match the screening condition, and the mirroring policy associated with the screening condition is mirroring (or, the screening condition indicates mirroring), mirroring operations can be performed on the public network packets; when the public network gateway determines that the public network packets match the screening condition, and the mirroring policy associated with the screening condition is non-mirroring (or, the screening condition indicates non-mirroring), there is no need to perform mirroring operations on the public network packets; when the public network gateway determines that the public network packets do not match any one of the parameters in the screening condition, there is no need to perform mirroring operations on the public network packets, that is, the public network gateway does not need to continue to determine whether the mirroring policy associated with the screening condition is mirroring or non-mirroring (or, does not need to continue to determine whether the screening condition indicates mirroring or non-mirroring).

[0136] Step 602, during the process of the public network gateway forwarding the public network packets of M virtual machines, according to the elastic identifier of the virtual machine to be collected, identify the public network packets of the virtual machine to be collected from the public network packets of the M virtual machines.

[0137] In the public network gateway, there is a mapping relationship between the elastic identifiers of M virtual machines outside the data center and the private network IP addresses inside the data center. Exemplarily, the M virtual machines are represented as virtual machine 1 to virtual machine M, and the following mapping relationship is stored in the public network gateway: (the elastic identifier of virtual machine 1 and the private network IP address of virtual machine 1), (the elastic identifier of virtual machine 2 and the private network IP address of virtual machine 2), ……, (the elastic identifier of virtual machine M and the private network IP address of virtual machine M), etc.

[0138] The public network gateway can forward the public network packets of M virtual machines according to this mapping relationship. Taking any one of the M virtual machines as an example below, this any one virtual machine can be denoted as the first virtual machine.

[0139] When the public network gateway forwards the public network packets of the first virtual machine, specifically, the public network gateway receives the public network packets from the first virtual machine, the source IP address in the public network packets is the private network IP address of the first virtual machine, and the public network gateway converts the source IP address in the public network packets into the elastic identifier of the first virtual machine according to the mapping relationship and the private network IP address of the first virtual machine, and then obtains a new public network packet, and forwards the new public network packet to the public network node. Optionally, the public network packets also include a destination IP address, and the public network gateway can forward the new public network packet to the public network node according to the destination IP address. Correspondingly, after receiving the new public network packet, the public network node can determine that the source IP address is the elastic identifier of the first virtual machine.

[0140] Alternatively, the public network gateway receives a public network message from a public network node. The destination IP address in the public network message is the elastic identifier of the first virtual machine. After the public network gateway converts the destination IP address in the public network message into the private network IP address of the first virtual machine according to the mapping relationship and the elastic identifier of the first virtual machine, a new public network message is obtained, and the new public network message is forwarded to the first virtual machine.

[0141] It can be understood that the public network messages of the M virtual machines will all flow through the public network gateway, and the public network gateway can identify the public network message of the virtual machine to be collected from the public network messages of the M virtual machines according to the elastic identifier of the virtual machine to be collected.

[0142] For example, the M virtual machines are virtual machine 1 to virtual machine M. The public network gateway will forward the public network messages of virtual machine 1, the public network messages of virtual machine 2,..., the public network messages of virtual machine M. And when the transmission direction of the public network message of a certain virtual machine is the incoming direction, the destination IP address of the public network message of this virtual machine is the elastic identifier of this virtual machine. When the transmission direction of the public network message of a certain virtual machine is the outgoing direction, the source IP address of the public network message of this virtual machine is the elastic identifier of this virtual machine. Further, the virtual machine to be collected is virtual machine 2. The public network gateway can identify the public network message with the destination IP address being EIP address 2 or the source IP address being EIP address 2 from all the forwarded public network messages according to the elastic identifier of virtual machine 2 (such as EIP address 2) as the public network message of virtual machine 2.

[0143] Step 603, the public network gateway collects the data to be analyzed from the public network message of the virtual machine to be collected according to the collection rule.

[0144] Among them, the data to be analyzed is used to analyze and / or monitor the public network message of the virtual machine to be collected. Exemplarily, the data to be analyzed is used to monitor the security of the public network message of the virtual machine to be collected.

[0145] It should be noted in advance that the public network message of the virtual machine to be collected may include multiple public network messages. In this application, the public network messages following the same parameters can be regarded as the same public network message, and the parameters may include the source IP address, destination IP address, message protocol, source port number, destination port number, etc. Combined with Figure 5In the example, the public network packet sent by virtual machine 1 through port 1 of virtual machine 1 to port 1 of public network node 1 based on the HTTP protocol is denoted as public network packet 1; the public network packet sent by virtual machine 1 through port 2 of virtual machine 1 to port 1 of public network node 1 based on the HTTP protocol is denoted as public network packet 2; the public network packet sent by virtual machine 1 through port 1 of virtual machine 1 to port 1 of public network node 1 based on the TCP protocol is denoted as public network packet 3; the public network packet sent by public network node 1 through port 1 of public network node 1 to port 1 of virtual machine 1 based on the HTTP protocol is denoted as public network packet 4; the public network packet sent by public network node 2 through port 1 of public network node 2 to port 1 of virtual machine 1 based on the TCP protocol is denoted as public network packet 5, and so on. Alternatively, in the present application, any public network packet (or any packet, any message) transmitted by the virtual machine to be collected can be considered as a public network packet.

[0146] For ease of description, the following uses the example where the public network packets of the virtual machine to be collected include a first public network packet and a second public network packet for illustration.

[0147] When the public network gateway collects flow log data as the data to be analyzed:

[0148] Example A, the filtering condition is the public network packets received by the virtual machine. When the public network gateway determines that the packet direction of the first public network packet is the incoming direction, it collects flow log data from the first public network packet according to the collection metrics; when the public network gateway determines that the packet direction of the second public network packet is the outgoing direction, it determines not to collect the flow log data in the second public network packet.

[0149] Example B, the filtering condition is the public network packets sent by the virtual machine. When the public network gateway determines that the packet direction of the first public network packet is the outgoing direction, it collects flow log data from the first public network packet according to the collection metrics; when the public network gateway determines that the packet direction of the second public network packet is the incoming direction, it determines not to collect the flow log data in the second public network packet.

[0150] Example C, the filtering condition is the public network packets transmitted by the virtual machine. Then the public network gateway can collect flow log data from the first public network packet and the second public network packet respectively according to the collection metrics.

[0151] When the public network gateway collects flow mirroring data as the data to be analyzed, it can match any public network packet (denoted as the target public network packet) in the public network packets of the virtual machine to be collected based on the following two parts:

[0152] Part 1. The public network gateway determines a target session and the filtering conditions associated with the target session from multiple sessions according to the priorities of the multiple sessions in the collection rule. Further, the public network gateway matches the target public network packet with the filtering conditions associated with the target session. When it is determined that the target public network packet does not meet the filtering conditions associated with the target session, it continues to match other sessions whose priorities are after the target session (at this time, this other session is the target session); when the public network gateway determines that the target public network packet meets the filtering conditions associated with the target session, it determines whether to mirror the target public network packet according to the mirroring policy associated with the filtering conditions, and ends the matching. In addition, if the public network gateway determines that there are no other sessions after the target session, it also ends the matching. For details, please refer to Figure 7 the flowchart of matching the public network packet shown in (a) of

[0153] Part 2. When the public network gateway matches the filtering conditions associated with the target session (it can be understood that Part 2 is the specific implementation of one matching in Part 1), specifically, the public network gateway determines a target filtering condition from the multiple filtering conditions associated with the target session according to the priorities of the multiple filtering conditions associated with the target session, and matches the target public network packet with the target filtering condition. When the public network gateway determines that the target public network packet does not meet the target filtering condition, it continues to match other filtering conditions whose priorities are after the target filtering condition among the multiple filtering conditions associated with the target session (at this time, this other filtering condition is the target filtering condition); when it is determined that the target public network packet meets the target filtering condition, it determines whether to mirror the target public network packet according to the mirroring policy associated with the target filtering condition (equivalent to the mirroring policy associated with the filtering conditions associated with the target session), and ends the matching. In addition, if the public network gateway determines that there are no other filtering conditions after the target filtering condition associated with the target session, it can continue to determine other sessions after the target session. For details, please refer to Figure 7 the flowchart of matching the public network packet shown in (b) of

[0154] The following exemplarily provides possible ways for the public network gateway to mirror the first public network packet to obtain data to be analyzed:

[0155] Possible way 1. The collection rule includes the filtering conditions associated with the first session. When the public network gateway determines that the first public network packet meets the filtering conditions associated with the first session and the filtering conditions associated with the first session indicate mirroring, it mirrors the first public network packet to obtain the data to be analyzed.

[0156] The filtering conditions associated with the first session include multiple filtering conditions. The public network gateway sequentially determines the target filtering condition from the multiple filtering conditions associated with the first session according to the priority of the filtering conditions, and determines whether the first public network packet meets the target filtering condition. Furthermore, when it is determined that the first public network packet meets the target filtering condition and the target filtering condition indicates mirroring, the first public network packet is mirrored to obtain the data to be analyzed.

[0157] Exemplarily, the filtering conditions associated with the first session include a first filtering condition. When the public network gateway determines that the first public network packet meets the first filtering condition and the first filtering condition indicates mirroring, the first public network packet is mirrored to obtain the data to be analyzed. Optionally, the filtering conditions associated with the first session further include a second filtering condition. When sorted by priority, the second filtering condition is after the first filtering condition. When the public network gateway determines that the first public network packet does not meet the first filtering condition (here, it is not limited whether the first filtering condition indicates non-mirroring), if it is determined that the first public network packet meets the second filtering condition and the second filtering condition indicates mirroring, the first public network packet is mirrored to obtain the data to be analyzed.

[0158] In a second possible way, the acquisition rule includes the filtering conditions associated with the first session and the filtering conditions associated with the second session. The priority of the first session is higher than that of the second session, or in other words, when sorted by priority, the second session is after the first session. When the public network gateway determines that the first public network packet does not meet the filtering conditions associated with the first session (here, it is not limited whether the filtering conditions associated with the first session indicate mirroring), it continues to determine whether the first public network packet meets the filtering conditions associated with the second session. Further, when the public network gateway determines that the first public network packet meets the filtering conditions associated with the second session and the filtering conditions associated with the second session indicate mirroring, the first public network packet is mirrored to obtain the data to be analyzed.

[0159] When the public network gateway determines that the first public network packet does not meet the filtering conditions associated with the first session, specifically, the first session is associated with multiple filtering conditions. The public network gateway sequentially determines whether the first public network packet meets the multiple filtering conditions associated with the first session according to the priority of the filtering conditions, and determines that the first public network packet does not meet all the filtering conditions associated with the first session. For example, the first session is associated with a first filtering condition and a second filtering condition. When sorted by priority, the second filtering condition is after the first filtering condition. After the public network gateway sequentially determines that the first public network packet does not meet the first filtering condition and the second filtering condition, it determines that the first public network packet does not meet the filtering conditions associated with the first session.

[0160] When the public network gateway determines that the first public network packet meets the filtering conditions associated with the second session, for the specific implementation method, reference can be made to the implementation method of "the public network gateway determines that the first public network packet meets the filtering conditions associated with the first session" in the first possible way.

[0161] In addition, the public network gateway can also determine not to mirror the second public network message:

[0162] Exemplarily, the collection rule includes not only the screening conditions associated with the first session and the screening conditions associated with the second session, but also the screening conditions associated with the third session. Among them, the priority of the first session is higher than that of the second session, and the priority of the second session is higher than that of the third session. Or rather, when sorted based on priority, the second session is after the first session, and the third session is after the second session. After the public network gateway determines that the second public network message does not meet the screening conditions associated with the first session and the screening conditions associated with the second session, it determines that the second public network message meets the screening conditions associated with the third session, and the screening conditions associated with the third session indicate not to mirror. When the public network gateway determines that the second public network message meets the screening conditions associated with the third session, specifically, reference can be made to the implementation method of "the public network gateway determines that the first public network message meets the screening conditions associated with the first session" in possible manner 1. The difference is that the screening conditions associated with the third session indicate not to mirror. It can be understood that the public network gateway can determine not to mirror the second public network message, nor continue to match the screening conditions associated with other sessions for the second public network message.

[0163] It should be added that the above is only an example with the collection rule including the screening conditions associated with the first session, the screening conditions associated with the second session, and the screening conditions associated with the third session, and the priority of the first session is higher than that of the second session, and the priority of the second session is higher than that of the third session. In this application, the following scenarios are also possible:

[0164] Scenario 1, the collection rule includes the screening conditions associated with the first session, the screening conditions associated with the second session, and the screening conditions associated with the third session. The priority of the third session is higher than that of the first session, and the priority of the first session is higher than that of the second session.

[0165] When the public network gateway determines to mirror the first public network message, specifically, the public network gateway first determines that the first public network message does not meet the screening conditions associated with the third session, and then determines that the first public network message meets the screening conditions associated with the first session, and the screening conditions associated with the first session indicate to mirror, so the first public network message is mirrored to obtain analysis data. Or, when the public network gateway determines to mirror the first public network message, specifically, the public network gateway first sequentially determines that the first public network message does not meet the screening conditions associated with the third session and the screening conditions associated with the first session, and then determines that the first public network message meets the screening conditions associated with the second session, and the screening conditions associated with the second session indicate to mirror, so the first public network message is mirrored to obtain analysis data.

[0166] When the public network gateway determines not to mirror the second public network packet, specifically, the public network gateway determines that the second public network packet meets the screening conditions associated with the third session, and the screening conditions associated with the third session indicate not to mirror. Among them, the public network gateway no longer matches the screening conditions associated with the first session and the screening conditions associated with the second session for the second public network packet.

[0167] Scenario 2, the collection rule further includes the screening conditions associated with the first session. The priority of the first session is higher than that of the second session, the priority of the second session is higher than that of the first session, and the priority of the first session is higher than that of the third session.

[0168] When the public network gateway determines not to mirror the second public network packet, specifically, when the public network gateway first determines that the second public network packet does not meet the screening conditions associated with the first session, the screening conditions associated with the second session, and the screening conditions associated with the first session, it further determines that the second public network packet meets the screening conditions associated with the third session, and the screening conditions associated with the third session indicate not to mirror.

[0169] Scenario 3, the collection rule includes the screening conditions associated with the first session, the screening conditions associated with the second session, the screening conditions associated with the third session, and the screening conditions associated with the fourth session. The priority of the first session is higher than that of the second session, the priority of the second session is higher than that of the third session, and the priority of the third session is higher than that of the fourth session.

[0170] When the public network gateway determines not to mirror the second public network packet, specifically, when the public network gateway first sequentially determines that the second public network packet does not meet the screening conditions associated with the first session, the screening conditions associated with the second session, and the screening conditions associated with the third session, it further determines that the second public network packet meets the screening conditions associated with the fourth session, and the screening conditions associated with the fourth session indicate not to mirror.

[0171] Of course, the screening conditions associated with the session in the collection rule can also be other ways, and this application will not list them one by one.

[0172] Similarly, the filtering conditions associated with the first session above include the first filtering condition and the second filtering condition, which are only illustrative. The filtering conditions associated with each session can also be in other various ways. For example, the filtering conditions associated with the first session further include a third filtering condition, and the priority of the second filtering condition is higher than that of the third filtering condition. When the public network gateway determines that the first public network packet meets the filtering conditions associated with the first session, specifically, after the public network gateway determines that the first public network packet does not meet the first filtering condition and the second filtering condition, it further determines that the first public network packet meets the third filtering condition, and the third filtering condition indicates mirroring. Similarly, the filtering conditions associated with the first session can also be in other ways, and the filtering conditions associated with the second session, the third session, and the fourth session can also be in other ways, which will not be exemplified one by one in this application.

[0173] To better explain the above matching method, the following is an example:

[0174] The collection rules include the filtering conditions associated with Session 1 and the filtering conditions associated with Session 2.

[0175] Session 1 is used to collect the public network packets that follow Message Protocol A when the virtual machine to be collected accesses Public Network Node 1, and does not collect the public network packets that follow Message Protocol B when the virtual machine to be collected accesses Public Network Node 1;

[0176] Session 2 is used to collect the public network packets that follow Message Protocol A when the virtual machine to be collected accesses Public Network Node 2, and does not collect the public network packets that follow Message Protocol B when the virtual machine to be collected accesses Public Network Node 1.

[0177] Among them, the priority of Session 1 is higher than that of Session 2.

[0178] The filtering conditions included in the filtering conditions associated with Session 1 and the mirroring policies corresponding to each filtering condition are as follows:

[0179] Filtering Condition 11: The transmission direction of the public network packet is the outbound direction, the destination IP address of the public network packet is IP Address 1 of Public Network Node 1; the message protocol followed by the public network packet is Message Protocol A; the mirroring policy is mirroring;

[0180] Filtering Condition 12: The transmission direction of the public network packet is the outbound direction, the destination IP address of the public network packet is IP Address 1 of Public Network Node 1; the message protocol followed by the public network packet is Message Protocol B; the mirroring policy is non-mirroring.

[0181] The filtering conditions included in the filtering conditions associated with Session 2 and the mirroring policies corresponding to each filtering condition are as follows:

[0182] Filtering condition 21: The transmission direction of the public network message is the outbound direction, the destination IP address of the public network message is the IP address 2 of public network node 2; the message protocol followed by the public network message is message protocol A; the mirroring policy is mirroring.

[0183] Filtering condition 22: The transmission direction of the public network message is the outbound direction, the destination IP address of the public network message is the IP address 2 of public network node 2; the message protocol followed by the public network message is message protocol B; the mirroring policy is non-mirroring.

[0184] When the public network gateway forwards a certain public network message of the virtual machine to be collected, it can further determine whether to mirror the public network message according to the collection rules and the public network messages of the virtual machine to be collected. Specifically, there can be the following examples a to e:

[0185] Example a, the public network messages of the virtual machine to be collected include public network message 1. The transmission direction of public network message 1 is the outbound direction, the destination IP address is the IP address 1 of public network node 1, and it follows message protocol A. Then the public network gateway determines that public network message 1 meets the filtering condition 11 in session 1, and the filtering condition 11 indicates mirroring, so it mirrors public network message 1.

[0186] Example b, the public network messages of the virtual machine to be collected include public network message 2. The transmission direction of public network message 2 is the inbound direction, the source IP address is the IP address 1 of public network node 1, and it follows message protocol A. Then the public network gateway determines that public network message 2 does not meet the filtering condition 11 and filtering condition 12 associated with session 1, and does not meet the filtering condition 21 and filtering condition 22 associated with session 2, so it determines not to mirror public network message 2.

[0187] Example c, the public network messages of the virtual machine to be collected include public network message 3. The transmission direction of public network message 3 is the outbound direction, the destination IP address is the IP address 1 of public network node 1, and it follows message protocol B. Then the public network gateway first determines that public network message 3 does not meet the filtering condition 11 associated with session 1, and then determines that it meets the filtering condition 12 associated with session 1, and the filtering condition 12 indicates non-mirroring, so it does not mirror public network message 3.

[0188] Example d, the public network messages of the virtual machine to be collected include public network message 4. The transmission direction of public network message 4 is the outbound direction, the destination IP address is the IP address 2 of public network node 2, and it follows message protocol A. After the public network gateway determines that public network message 4 does not meet the filtering condition 11 and filtering condition 12 associated with session 1, it determines that public network message 4 meets the filtering condition 21 associated with session 2, and the filtering condition 21 indicates mirroring, so it mirrors public network message 4.

[0189] Example e. The public network packets of the virtual machine to be collected include public network packet 5. The transmission direction of public network packet 5 is the outbound direction, and the destination IP address is IP address 2 of public network node 2, following packet protocol B. Then, after the public network gateway determines that public network packet 5 does not meet the screening conditions 11 and 12 associated with session 1 and the screening condition 21 associated with session 2, and determines that public network packet 5 meets the screening condition 22 associated with session 2, and the screening condition 22 indicates not to mirror, the public network gateway does not mirror public network packet 5.

[0190] It should be added that the above takes the public network gateway collecting flow log data from the public network packets of the virtual machine to be collected as the data to be analyzed, or the public network gateway collecting flow mirroring data from the public network packets of the virtual machine to be collected as the data to be analyzed as an example. In this application, the public network gateway can also collect both flow log data and flow mirroring data from the public network packets of the virtual machine to be collected as the data to be analyzed.

[0191] Optionally, Figure 6 The related embodiments further include:

[0192] Step 604, the public network gateway sends the data to be analyzed to the storage device.

[0193] Among them, the data to be analyzed is used for the storage device to analyze and / or monitor the public network packets of the virtual machine to be collected.

[0194] Exemplarily, the data to be analyzed is used for the storage device to monitor the security of the public network packets of the virtual machine to be collected. That is, the storage device can receive the data to be analyzed from the public network gateway and monitor the security of the public network packets of the virtual machine to be collected according to the data to be analyzed. For example, the storage device stores the data to be analyzed from the public network gateway and displays the data to be analyzed to the tenant. For another example, the storage device periodically analyzes the data to be analyzed stored in the storage device. When the storage device determines that the security of the public network packets of the virtual machine to be collected does not meet the security requirements, it issues an alarm to the tenant. For yet another example, after receiving the analysis instruction from the tenant, the storage device generates an analysis result according to the data to be analyzed and displays the analysis result to the tenant, etc. In this application, the storage device can also be referred to as an analysis device, a monitoring device, etc.

[0195] Exemplarily, when the public network gateway sends the data to be analyzed to the storage device, specifically, the public network gateway obtains the IP address of the storage device and sends the data to be analyzed to the storage device according to the IP address of the storage device. Among them, the public network gateway can obtain the IP address of the storage device from the cloud management platform or can also obtain the IP address of the storage device from the global control platform (see Figure 9 in the architecture).

[0196] Further, the storage device may be located in the same data center as the public network gateway or in different data centers. The storage device may be a physical device or a virtual machine deployed in a physical device (or referred to as a tunnel terminal). Exemplarily, when the data to be analyzed is flow log data, the storage device may be a physical device; when the data to be analyzed is flow mirroring data, the storage device may be a virtual machine.

[0197] When the storage device is a virtual machine deployed in a physical device (or referred to as the destination virtual machine) and the destination virtual machine is located in a different data center from the public network gateway, the IP address of the destination virtual machine obtained by the public network gateway may specifically include the IP address of the physical device to which the destination virtual machine belongs (or referred to as the target physical device) and the private network IP address of the destination virtual machine within the target physical device. It can be understood that within multiple data centers, the IP address of a physical device is globally unique. Therefore, after the public network gateway determines the IP address of the target physical device, it can locate the target physical device, and then the public network gateway locates the destination virtual machine from the target physical device.

[0198] Further, when the public network gateway sends the data to be analyzed to the storage device, specifically, it may encapsulate the IP address of the physical device to which the destination virtual machine belongs, the private network IP address of the destination virtual machine within the target physical device, and the data to be analyzed into a data packet to be analyzed, and send the data packet to be analyzed to the storage device. Exemplarily, Figure 8 As shown in the schematic diagram of a packet encapsulation format provided exemplarily for this application, the data packet to be analyzed is specifically a VXLAN packet. Among them, the data to be analyzed serves as the data part of the inner packet of the VXLAN packet. The inner packet of the VXLAN packet has been encapsulated twice before. Among them, the tunnel encapsulation header obtained by the first encapsulation includes the private network IP address of the destination virtual machine within the target physical device (equivalent to the external IP header), and the tunnel encapsulation header of the second encapsulation includes the IP address of the target physical device (equivalent to the external IP header). Of course, the inner packet of the VXLAN packet may also include an internal IP header and an internal Ethernet header. Each layer of the tunnel encapsulation header also includes a VXLAN header, an external UDP header, and an external public network header. For specific details, reference can be made to Figure 3 the description of the existing VXLAN packet.

[0199] Such as Figure 9 As shown in the schematic diagram of the architecture of another data collection system applicable to the method of this application, which includes a global controller and multiple data centers ( Figure 9Data centers 1 and 2 are shown (however, the number of data centers is not limited in this application). Inside each data center, there may be a local control platform which can be used to determine the local topology relationship of its affiliated data center. The local topology relationship is used to indicate which physical devices are inside the data center, the connection relationships between these physical devices, and which virtual machines are included in each physical device, etc.; each local control platform is respectively connected to the global controller, and each local control platform can also be used to send the local topology relationship of its affiliated data center to the global controller. The global controller is used to receive the local topology relationships of each local control platform and determine the global topology relationship according to the local topology relationships of each local control platform. The global control platform is also connected to the cloud management platform inside each data center. After a certain cloud management platform obtains the identifier of the target virtual machine (i.e., the device identifier presented to the tenant, such as the number of the target virtual machine) based on the tenant's operation, it can obtain the IP address of the target virtual machine (i.e., the IP address of the target physical device and the private network IP address of the target virtual machine inside the target physical device) from the global control platform, and then carry the IP address of the target virtual machine in the collected information and send it to the public network gateway. Of course, inside each data center, there may also be a public network gateway, physical devices, VPCs, virtual machines, etc. For details, please refer to Figure 4 or Figure 5 the description in the relevant embodiments.

[0200] Figure 10 This is a flowchart for a public network gateway to obtain the IP address of a target virtual machine provided exemplarily in this application.

[0201] Step 1001, the local control platform obtains the local topology relationship of the data center to which the local control platform belongs.

[0202] Step 1002, the local control platform sends the local topology relationship of the data center to which the local control platform belongs to the global control platform. Correspondingly, the global control platform obtains the local topology relationships of the data centers to which multiple local control platforms belong.

[0203] Step 1003, the global control platform determines the global topology relationship according to the local topology relationships of the data centers to which multiple local control platforms belong.

[0204] Combined with Figure 9For example, the data center 1 includes physical device 1 and physical device 2. Physical device 1 includes virtual machine 11 and virtual machine 12, and physical device 2 includes virtual machine 21, virtual machine 22, and virtual machine 23. The local control platform 1 can determine the local topology relationship 1 as shown in Table 3 below. Similarly, the local control platform 2 can determine a local topology relationship 2 similar to Table 3. The local control platform 1 sends the local topology relationship 1 to the global control platform, and the local control platform 2 sends the local topology relationship 2 to the global control platform. The global control platform combines the local topology relationship 1 and the local topology relationship 2 into a global topology relationship (it can also be understood that the global topology relationship includes the local topology relationship 1 and the local topology relationship 2).

[0205] Table 3

[0206]

[0207] Step 1004, the cloud control platform determines the identifier of the destination virtual machine and sends the identifier of the destination virtual machine to the global control platform. Correspondingly, the global control platform receives the identifier of the destination virtual machine from the cloud control platform.

[0208] Step 1005, the global control platform determines the IP address of the destination virtual machine according to the identifier of the destination virtual machine and the global topology relationship.

[0209] Among them, the IP address of the destination virtual machine includes the IP address of the physical device (i.e., the target physical device) to which the destination virtual machine belongs and the private network IP address of the destination virtual machine within the target physical device. Combining with the example in step 1003, if the identifier of the destination virtual machine is the identifier 12 of virtual machine 12, then the global control platform can determine that the IP address of the destination virtual machine includes the IP address 1 of physical device 1 and the IP address 12 of virtual machine 12.

[0210] Step 1006, the global control platform sends the IP address of the destination virtual machine to the cloud control platform. Correspondingly, the cloud control platform receives the IP address of the destination virtual machine from the global control platform.

[0211] Step 1007, the cloud control platform sends the IP address of the destination virtual machine to the public network gateway. Correspondingly, the public network gateway receives the IP address of the destination virtual machine from the cloud control platform. Among them, the IP address of the destination virtual machine can be carried in the acquisition information, that is, the cloud control platform sends the acquisition information to the public network gateway, and the acquisition information also includes the IP address of the destination virtual machine.

[0212] Alternatively, in step 1006 above, the global control platform may send the IP address of the destination virtual machine to the public network gateway, and the public network gateway receives the IP address of the destination virtual machine from the global control platform. Correspondingly, the collected information may not include the IP address of the destination virtual machine. Or, in step 1006 above, the global control platform may send the correspondence between the identifier and the IP address of the destination virtual machine to the public network gateway, and the public network gateway receives the correspondence between the identifier and the IP address of the destination virtual machine from the global control platform. Correspondingly, the collected information may include the identifier of the destination virtual machine, and the public network gateway determines the IP address of the destination virtual machine according to the correspondence and the identifier of the destination virtual machine.

[0213] In the above technical solution, since the public network packets transmitted between the M virtual machines and the public network nodes all pass through the public network gateway for forwarding, and each virtual machine corresponds to its own elastic identifier, the public network gateway can identify the public network packets of the virtual machine to be collected according to the elastic identifier of the virtual machine to be collected, and can identify the public network packets of the virtual machine to be collected more comprehensively and accurately. Furthermore, the public network gateway then collects the data to be analyzed from the public network packets of the virtual machine to be collected according to the collection rules, and the data to be analyzed can be used to monitor and analyze the security of the public network packets of the virtual machine to be collected.

[0214] It should be added that the above public network gateway collects the public network packets of the virtual machine to be collected, that is, the public network gateway collects the public network packets flowing through all network cards of the virtual machine to be collected in units of the virtual machine to be collected. In addition, in this application, the public network gateway may also collect the public network packets flowing through a certain network card to be collected of the virtual machine to be collected in units of the network card to be collected.

[0215] In a possible manner, the virtual machine to be collected includes N network cards, N is a positive integer, and the collected information further includes the identifier of the network card to be collected, and the N network cards include the network card to be collected. During the process of forwarding the public network packets of the M virtual machines, the public network gateway identifies the public network packets of the network card to be collected from the public network packets of the M virtual machines according to the elastic identifier of the virtual machine to be collected and the identifier of the network card to be collected.

[0216] Exemplarily, during the process of forwarding the public network packets of the M virtual machines, the public network gateway first identifies the public network packets of the virtual machine to be collected from the public network packets of the M virtual machines according to the elastic identifier of the virtual machine to be collected, and then, the public network gateway further identifies the public network packets of the network card to be collected from the public network packets of the virtual machine to be collected according to the identifier of the network card to be collected. Combined with Figure 5In an example, virtual machine 1 includes network card 11 and network card 12. The information to be collected includes the elastic identifier of the virtual machine to be collected and the identifier of the network card to be collected. Among them, the virtual machine to be collected is virtual machine 1, the network card to be collected is network card 11, the elastic identifier of virtual machine 1 is "EIP address 1", and the identifier of network card 11 is "eth11". Then, during the process of the public network gateway forwarding the public network packets of M virtual machines, it can first identify the public network packets of virtual machine 1 from the public network packets of the virtual machines it forwards according to EIP address 1. Then, the public network gateway can further identify the public network packets flowing through network card 11 from the public network packets of virtual machine 1 according to eth11.

[0217] Furthermore, after the public network gateway identifies the public network packets flowing through the network card to be collected, it can continue to collect the data to be analyzed from the public network packets of the network card to be collected according to the collection rules. Specifically, refer to the description in step 603. You can understand it by replacing "the public network packets of the virtual machine to be collected" with "the public network packets of the network card to be collected".

[0218] In the above technical solution, the public network gateway obtains the data to be analyzed from the public network packets transmitted by a certain network card of the virtual machine in terms of the granularity of a certain network card of the virtual machine, so as to monitor the security of the public network packets of a certain network card and improve the flexibility of monitoring.

[0219] In addition, the cloud management platform cloud is used to provide an access interface, and the tenant can remotely access the access interface by operating the client. Or understand that the tenant can operate in the display interface provided by the client to purchase the computing service of the virtual machine, the elastic identifier corresponding to the virtual machine in the data center, and select the virtual machine to be collected from the purchased virtual machines, and set the collection rules to collect the public network packets of the virtual machine to be collected.

[0220] Combined with Figure 11 and Figure 12 Exemplarily illustrate two implementation methods for the cloud management platform to generate the collection information:

[0221] Figure 11 Show a schematic flow diagram of the cloud management platform generating the collection information corresponding to the flow log data:

[0222] Step 1101, the client generates the first purchase information in response to the tenant's first purchase operation and sends the first purchase information to the cloud management platform.

[0223] Correspondingly, the cloud management platform receives the first purchase information from the client.

[0224] Among them, the first purchase information can be used to indicate that the tenant purchases m virtual machines, where m is a positive integer. Exemplarily, the first purchase information includes the number m of virtual machines.

[0225] Step 1102, in response to the first purchase information, the cloud management platform creates m virtual machines for the tenant within the data center.

[0226] Exemplarily, the cloud management platform binds the m virtual machines to the tenant's cloud account, so that the tenant can log in to the cloud account and use the m virtual machines. Optionally, the cloud management platform determines the identifiers and private network IP addresses of the m virtual machines. It can be understood that the identifier of the virtual machine is used to be presented to the tenant, and the identifier of the virtual machine can be the number, name, geographical location, etc. of the virtual machine. The private network IP address of the virtual machine is the IP address of the virtual machine within the data center, and the private network IP address of the virtual machine can be presented to the tenant or not presented to the tenant.

[0227] Step 1103, in response to the tenant's second purchase operation, the client generates second purchase information and sends the second purchase information to the cloud management platform.

[0228] Correspondingly, the cloud management platform receives the second purchase information from the client.

[0229] The second purchase information can be used to indicate that the tenant purchases n elastic identifiers, where n is a positive integer. Exemplarily, the second purchase information includes the number n of elastic identifiers. Exemplarily, the second purchase information further includes the identifiers of n virtual machines, and the n virtual machines are included in the m virtual machines. The identifiers of the n virtual machines are specified by the tenant, that is, the tenant can determine which n of the m virtual machines to purchase elastic identifiers for.

[0230] Step 1104, in response to the second purchase information, the cloud management platform creates n elastic identifiers for the tenant within the data center and binds the n elastic identifiers to the identifiers of the n virtual machines (or rather, the private network IP addresses of the n virtual machines).

[0231] Taking the above steps 1101 to 1104 as an example, the cloud management platform receives the first purchase information, and the first purchase information includes the number 5 of virtual machines. The cloud management platform can create 5 virtual machines (denoted as virtual machine 1 to virtual machine 5) for the tenant within the data center, and the identifiers of the virtual machine 1 to virtual machine 5 are respectively denoted as VM1 to VM5. Further, the cloud management platform receives the second purchase information, and the second purchase information includes the number 2 of elastic identifiers, as well as VM1 and VM2. The cloud management platform can create 2 elastic identifiers (denoted as EIP address 1 and EIP address 2) for the tenant within the data center, and bind VM1 to EIP address 1 and bind VM2 to EIP address 2.

[0232] Step 1105, in response to the tenant's third purchase operation, the client generates third purchase information and sends the third purchase information to the cloud management platform.

[0233] Correspondingly, the cloud management platform receives the third purchase information.

[0234] The third purchase information can be used to indicate the storage service purchased by the tenant. Among them, when the tenant uses the storage service, the flow log data can be stored in the storage device. Further, the third purchase information may include the identifier of the storage device, and the identifier of the storage device can be selected by the tenant himself. The identifier of the storage device can specifically be the number of the storage device, the name of the storage device, the address location of the storage device, such as which data center it is located in, which area it is located in, etc. Optionally, the tenant can not only purchase storage services on the cloud management platform through the client, but also purchase other services, such as computing services, analysis services, monitoring services, etc. Optionally, the following "storage service" can also be replaced with this other service.

[0235] Step 1106, in response to the third purchase information, the cloud management platform determines the IP address of the storage device according to the identifier of the storage device, and binds the IP of the storage device and the storage service.

[0236] Further, when the storage device is a physical device, the cloud management platform stores the corresponding relationship between the identifier of the physical device and the IP address of the physical device, and the cloud management platform can determine the IP address of the storage device by itself;

[0237] When the storage device is a virtual machine, the cloud management platform can send the identifier of the storage device (that is, the identifier of the target virtual machine) to the global control platform and receive the IP address of the target virtual machine of the global control platform (see Figure 10 related embodiments).

[0238] Step 1107, in response to the tenant's operation of creating a flow log, the client generates operation information and sends the operation information to the cloud management platform.

[0239] Correspondingly, the cloud management platform receives the operation information from the client.

[0240] Among them, the operation information includes the identifier of the storage service, the elastic identifier of the virtual machine to be collected, and the collection rule. Among them, the identifier of the storage service is selected by the tenant from the identifiers of the multiple services he purchased. The elastic identifier of the virtual machine to be collected is selected by the tenant from the elastic identifiers he purchased. The elastic identifier of the virtual machine to be collected is, for example, the EIP or GEIP of the virtual machine to be collected. The collection rule is input by the tenant in the display interface of the client. The collection rule includes filtering conditions. The filtering conditions are, for example, public network packets received by the virtual machine, public network packets sent by the virtual machine, public network packets rejected by the virtual machine, public network packets transmitted by the virtual machine, etc. The collection rule may also include the time interval for aggregating the flow log data, collection metrics, etc. For specific implementation, refer to the description in step 601.

[0241] Step 1108: The cloud management platform determines the IP address of the storage device bound to the identifier of the storage service in response to the operation information (as described in Step 1106), and generates collection information based on the IP address of the storage device, the elastic identifier of the virtual machine to be collected, and the collection rule.

[0242] Figure 12 The figure shows a schematic flow diagram of the cloud management platform generating collection information corresponding to flow mirror data:

[0243] Step 1201: The client generates first purchase information in response to the tenant's first purchase operation and sends the first purchase information to the cloud management platform. Correspondingly, the cloud management platform receives the first purchase information from the client.

[0244] Step 1202: The cloud management platform creates m virtual machines for the tenant within the data center in response to the first purchase information.

[0245] Step 1203: The client generates second purchase information in response to the tenant's second purchase operation and sends the second purchase information to the cloud management platform. Correspondingly, the cloud management platform receives the second purchase information from the client.

[0246] Step 1204: The cloud management platform creates n elastic identifiers for the tenant within the data center in response to the second purchase information, and binds the n elastic identifiers to the identifiers of the n virtual machines (or rather, the private IP addresses of the n virtual machines).

[0247] Among them, for the content not described in detail in Steps 1201 to 1204, reference can be made to the description in the above Steps 1101 to 1104.

[0248] Step 1205: The client generates first creation information in response to the tenant's first creation operation and sends the first creation information to the cloud management platform.

[0249] Correspondingly, the cloud management platform receives the first creation information from the client.

[0250] The first creation information is used to create sessions and the filtering conditions associated with the sessions. Among them, the filtering conditions associated with the sessions can be input by the tenant in the display interface of the client. The sessions can be one or more. When there are multiple sessions, the first creation information also includes the priorities of each of the multiple sessions. The filtering conditions associated with a certain session can be one or more. When there are multiple filtering conditions associated with the session, the first creation information also includes the priorities of each of the multiple filtering conditions associated with the session. The filtering conditions can include one or more of the following parameters: packet direction, source IP address, destination IP address, source port number, destination port number, and packet protocol. Optionally, the first creation information also includes the mirroring policy corresponding to the filtering conditions associated with the session, and the mirroring policy can be mirroring or non-mirroring. For specific implementation, refer to the description in step 601.

[0251] Step 1206, the cloud management platform creates sessions and the filtering conditions associated with the sessions in response to the first creation operation.

[0252] Step 1207, the client generates first association information in response to the tenant's first association operation and sends the first association information to the cloud management platform.

[0253] Correspondingly, the cloud management platform receives the first association information from the client.

[0254] The first association information is used to associate sessions for the flow mirroring operation. Among them, the flow mirroring operation can be associated with one or more sessions, each session can be associated with one or more filtering conditions, and when the flow mirroring operation is associated with multiple sessions, each of the multiple sessions has a priority, and when a session is associated with multiple filtering conditions, each of the multiple filtering conditions associated with the session has a priority.

[0255] Step 1208, the cloud management platform associates the flow mirroring operation with the sessions and filtering conditions in response to the first association information.

[0256] Among them, the flow mirroring operation and the sessions and filtering conditions associated with it constitute the collection rule.

[0257] It can be understood that in the above steps 1205 and 1206, the tenant can create multiple sessions and create multiple filtering conditions for each session. Furthermore, in the above steps 1207 and 1208, the tenant can select some or all of the sessions created by the tenant to associate with the flow mirroring operation, and further select some or all of the filtering conditions associated with the selected sessions to associate with the flow mirroring operation.

[0258] For example, in the above steps 1205 and 1206, the tenant creates Sessions 1 to 5. Among them, Session 1 is associated with Filter Conditions 11 to 13, Session 2 is associated with Filter Conditions 21 to 24, Session 3 is associated with Filter Conditions 31 to 34, Session 4 is associated with Filter Conditions 41 to 45, and Session 5 is associated with Filter Conditions 51 to 55. In the above steps 1207 and 1208, the tenant can associate the traffic mirroring operation with Filter Conditions 11 and 12 associated with Session 1, Filter Conditions 21 and 22 associated with Session 2, and Filter Conditions 31 and 32 associated with Session 3 to obtain a collection rule.

[0259] In addition, the tenant can associate sessions and filter conditions with multiple traffic mirroring operations respectively. For example, the tenant associates Filter Conditions 11 and 12 associated with Session 1, Filter Conditions 21 and 22 associated with Session 2, and Filter Conditions 31 and 32 associated with Session 3 with Traffic Mirroring Operation 1 to obtain Collection Rule 1; and associates Session 3 (including all filter conditions associated with Session 3) and Session 5 (including all filter conditions associated with Session 5) with Traffic Mirroring Operation 2 to obtain Collection Rule 2.

[0260] In this way, the tenant only needs to create multiple sessions and the filter conditions associated with each session, and then associate the mirroring operation with the sessions and filter conditions, which helps to reduce the tenant's configuration workload.

[0261] Step 1209, the client generates second association information in response to the tenant's second association operation, and sends the second association information to the cloud management platform.

[0262] Correspondingly, the cloud management platform receives the second association information from the client.

[0263] The second association information is used to associate a mirror source and a mirror destination with the traffic mirroring operation. Among them, the mirror source is the virtual machine to be collected, and the mirror destination is the storage device for the data to be analyzed. Exemplarily, the second association information includes the elastic identifier of the virtual machine to be collected and the IP address of the storage device.

[0264] Step 1210, the cloud management platform associates the traffic mirroring operation with the mirror source and the mirror destination respectively in response to the second association information.

[0265] It can be understood that the tenant can associate the mirror source and the mirror destination with multiple traffic mirroring operations respectively. Combining with the example in the above step 1208, the tenant associates the elastic identifier of the virtual machine 1 to be collected and the IP address of the storage device 1 with Traffic Mirroring Operation 1, and associates the elastic identifier of the virtual machine 2 to be collected and the IP address of the storage device 2 with Traffic Mirroring Operation 2.

[0266] Step 1211, the cloud management platform generates collection information. Specifically, the cloud management platform generates the collection information corresponding to the flow mirroring operation according to the mirror source, mirror destination, and session filtering conditions respectively associated with the flow mirroring operation.

[0267] Combined with the example in the above step 1210, the cloud management platform generates the collection information 1 corresponding to the flow mirroring operation 1. The collection information 1 includes the collection rule 1, the elastic identifier of the virtual machine 1 to be collected, and the IP address of the storage device 1. The public network gateway can mirror the data to be analyzed from the public network packets of the virtual machine 1 to be collected according to the collection rule 1, and send the obtained data to be analyzed to the storage device 1 according to the IP address of the storage device 1. Also, the cloud management platform generates the collection information 2 corresponding to the flow mirroring operation 2. The collection information 2 includes the flow mirroring operation 2, the collection rule 2, the elastic identifier of the virtual machine 2 to be collected, and the IP address of the storage device 2. The public network gateway can mirror the data to be analyzed from the public network packets of the virtual machine 2 to be collected according to the collection rule 2, and send the obtained data to be analyzed to the storage device 2 according to the IP address of the storage device 2.

[0268] The above Figures 6 to 12 In the related embodiments, the public network gateway is not only used to forward public network packets, but also used to match public network packets and obtain the data to be analyzed from public network packets. Thus, it may cause the problem of heavy load on the public network gateway. Or, the operations of the public network gateway to match public network packets and obtain the data to be analyzed from public network packets may affect the performance of the public network gateway to forward public network packets.

[0269] Therefore, as Figure 13 shown in the schematic diagram of the architecture of another data collection system provided by this application. Compared with the data collection system Figure 5 shown, a splitter, a flow log processing device, and a flow mirroring processing device are further introduced.

[0270] Among them, the splitter can be used to mirror the public network packets of M virtual machines. The flow log processing device is used to obtain the public network packets of M virtual machines from the splitter, and then obtain the public network packets of the virtual machine to be collected from the public network packets of M virtual machines, and collect the flow log data from the public network packets of the virtual machine to be collected; the flow mirroring processing device is used to obtain the public network packets of M virtual machines from the splitter, and then obtain the public network packets of the virtual machine to be collected from the public network packets of M virtual machines, and perform mirroring processing (i.e., mirroring operation) on the public network packets of the virtual machine to be collected to obtain the flow mirroring data. The public network gateway is used to forward and process the public network packets of M virtual machines.

[0271] For the convenience of description, the following takes the public network packets of the first virtual machine as an example for illustration. The first virtual machine is any one of the M virtual machines.

[0272] When the first virtual machine sends a public network message (denoted as public network message A) to a public network node:

[0273] The public network message A first passes through the public network gateway. The public network gateway can first perform address conversion on the source IP in the public network message A (i.e., the private network IP address of the first virtual machine) to obtain a new public network message (denoted as public network message B). The source IP in the public network message B is the elastic identifier of the first virtual machine. Further, the public network gateway sends the public network message B to the optical splitter. The optical splitter mirrors the public network message B to obtain three copies of the public network message B, sends one copy of the public network message B to the public network node, and sends the other two copies of the public network message B to the flow log processing device and the flow mirroring processing device respectively. Further, the flow log processing device can determine whether to obtain flow log data from the public network message after determining that the source IP carried in the public network message B is the elastic identifier of the virtual machine to be collected; if the flow mirroring processing device determines that the source IP carried in the public network message is the elastic identifier of the virtual machine to be collected, it determines whether to perform mirroring processing on the public network message.

[0274] When the public network node sends a public network message (denoted as public network message A) to the first virtual machine:

[0275] The destination IP in the public network message A is the elastic identifier of the first virtual machine. The public network message A first passes through the optical splitter. The optical splitter mirrors the public network message A to obtain three copies of the public network message A, sends one copy to the public network gateway. The public network gateway performs address conversion on the destination IP in the public network message A to obtain a public network message B. The destination IP in the public network message B is the private network IP address of the first virtual machine, and the public network message B is sent to the first virtual machine. The optical splitter also sends the other two copies of the public network message A to the flow log processing device and the flow mirroring processing device respectively. Further, the flow log processing device can determine whether to obtain flow log data from the public network message after determining that the target IP carried in the public network message A is the elastic identifier of the virtual machine to be collected; if the flow mirroring processing device determines that the target IP carried in the public network message is the elastic identifier of the virtual machine to be collected, it determines whether to perform mirroring processing on the public network message.

[0276] It can be understood that the elastic identifiers and collection rules of the virtual machines to be collected are configured in the flow log processing device and the flow mirroring processing device. Exemplarily, the flow log processing device and the flow mirroring processing device are respectively connected to the cloud management platform. When the cloud management platform generates the collection rules corresponding to the flow log data, it sends the collection rules corresponding to the flow log data to the flow log processing device; when the cloud management platform generates the collection rules corresponding to the flow mirroring data, it sends the collection rules corresponding to the flow mirroring data to the flow mirroring processing device.

[0277] Further, the storage device may include a storage device corresponding to the flow log processing device and a storage device corresponding to the flow mirroring processing device. When the flow log processing device obtains flow log data, it sends the flow log data to the storage device corresponding to the flow log processing device; when the flow mirroring processing device obtains flow mirror image data, it sends the flow mirror image data to the storage device corresponding to the flow mirroring processing device.

[0278] The present application also provides a collection device, as Figure 14 shown, including:

[0279] An acquisition module, configured to acquire acquisition information, where the acquisition information includes the elastic identifier and acquisition rules of the virtual machine to be acquired, and the elastic identifier is an EIP address or a GEIP address; a forwarding module, configured to forward the public network packets of M virtual machines; an identification module, configured to, when the forwarding module forwards the public network packets of M virtual machines, identify the public network packets of the virtual machine to be acquired according to the elastic identifier of the virtual machine to be acquired, where the M virtual machines include the virtual machine to be acquired, and M is a positive integer; an acquisition module, configured to acquire the data to be analyzed from the public network packets of the virtual machine to be acquired according to the acquisition rules, and the data to be analyzed is used to monitor the security of the public network packets of the virtual machine to be acquired. Among them, the acquisition module, the forwarding module, the identification module, and the acquisition module can all be implemented by software or can be implemented by hardware. Exemplarily, next, taking the acquisition module as an example, the implementation manner of the acquisition module will be introduced. Similarly, the implementation manners of the forwarding module, the identification module, and the acquisition module can refer to the implementation manner of the acquisition module.

[0280] As an example of a software functional unit, the acquisition module may include code running on a computing instance. Among them, the computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above computing instance may be one or more. For example, the acquisition module may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running this code may be distributed in the same region, or may be distributed in different regions. Further, the multiple hosts / virtual machines / containers for running this code may be distributed in the same availability zone (AZ), or may be distributed in different AZs, and each AZ includes one data center or multiple geographically proximate data centers. Among them, generally, one region may include multiple AZs. Similarly, the multiple hosts / virtual machines / containers for running this code may be distributed in the same VPC, or may be distributed in multiple VPCs. Among them, generally, one VPC is set within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set in each VPC, and the interconnection between VPCs is achieved through the communication gateway.

[0281] As an example of a hardware functional unit, the acquisition module may include at least one computing device, such as a server. Alternatively, the acquisition module may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). Among them, the above PLD may be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The multiple computing devices included in the acquisition module may be distributed in the same region or in different regions. The multiple computing devices included in the acquisition module may be distributed in the same availability zone (AZ) or in different AZs. Similarly, the multiple computing devices included in the acquisition module may be distributed in the same virtual private cloud (VPC) or in multiple VPCs. The multiple computing devices may be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0282] It should be noted that in other embodiments, the acquisition module may be used to execute Figures 6 to 13 any step in the related method embodiment regarding the public network gateway method, and the forwarding module may be used to execute Figures 6 to 13 any step in the related method embodiment regarding the public network gateway method, and the identification module may be used to execute Figures 6 to 13 any step in the related method embodiment regarding the public network gateway method, and the acquisition module may be used to execute Figures 6 to 13 any step in the related method embodiment regarding the public network gateway method. The steps to be implemented by the acquisition module, the forwarding module, the identification module, and the acquisition module can be specified as needed, and the acquisition device's entire function can be implemented by separately implementing Figures 6 to 13 different steps in the related method embodiment regarding the public network gateway method.

[0283] The present application also provides a collection system, which includes a collection device and a cloud management platform. The collection device is specifically a public network gateway. Optionally, the collection system further includes a global control platform and a local control platform. The collection device, the cloud management platform, the global control platform, and the local control platform can all be implemented by software or by hardware. Exemplarily, the implementation manner of the collection device will be introduced next. Similarly, the implementation manners of the cloud management platform, the global control platform, and the local control can refer to the implementation manner of the collection device.

[0284] As an example of a software functional unit, the collection device may include code running on a computing instance. Among them, the computing instance may be at least one of computing devices such as a physical host (computing device), a virtual machine, a container, etc. Further, the above-mentioned computing devices may be one or more. For example, the collection device may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running the application program may be distributed in the same region or in different regions. The multiple hosts / virtual machines / containers for running the code may be distributed in the same AZ or in different AZs, and each AZ includes one data center or multiple geographically proximate data centers. Among them, generally one region may include multiple AZs. Similarly, the multiple hosts / virtual machines / containers for running the code may be distributed in the same VPC or in multiple VPCs. Among them, generally one VPC is set within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set in each VPC, and the interconnection between VPCs is realized through the communication gateway.

[0285] As an example of a hardware functional unit, the collection device may include at least one computing device, such as a server, etc. Or, the collection device may also be a device implemented by ASIC or PLD, etc. Among them, the above-mentioned PLD may be implemented by CPLD, FPGA, GAL or any combination thereof. The multiple computing devices included in the collection device may be distributed in the same region or in different regions. The multiple computing devices included in the collection device may be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the collection device may be distributed in the same VPC or in multiple VPCs. Among them, the multiple computing devices may be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0286] The present application also provides a computing device 100. As Figure 15As shown, the computing device 100 includes: a bus 102, a processor 104, a memory 106, and a communication interface 108. The processor 104, the memory 106, and the communication interface 108 communicate with each other via the bus 102. The computing device 100 may be a server. It should be understood that the present application does not limit the number of processors and memories in the computing device 100.

[0287] The bus 102 may be a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 15 only one line is shown in the figure, but it does not mean that there is only one bus or one type of bus. The bus 104 may include a path for transmitting information between various components of the computing device 100 (for example, the memory 106, the processor 104, and the communication interface 108).

[0288] The processor 104 may include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0289] The memory 106 may include volatile memory, such as random access memory (RAM). The processor 104 may also include non-volatile memory, such as read-only memory (ROM), flash memory, a hard disk drive (HDD), or a solid state drive (SSD).

[0290] The memory 106 stores executable program code, and the processor 104 executes the executable program code to implement the functions of the foregoing acquisition module, forwarding module, recognition module, and acquisition module respectively, so as to implement Figures 6 to 13 the public network gateway method in the related method embodiments. That is, the memory 106 stores instructions for executing Figures 6 to 13 the public network gateway method in the related method embodiments.

[0291] Alternatively, executable code is stored in the memory 106, and the processor 104 executes the executable code to implement the functions of the aforementioned public network gateway, cloud management platform, global control platform, and regional control platform respectively, thereby implementing Figures 6 to 13 the methods in the related method embodiments. That is to say, instructions for executing Figures 6 to 13 the methods in the related method embodiments are stored on the memory 106.

[0292] The communication interface 103 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement the communication between the computing device 100 and other devices or communication networks.

[0293] Embodiments of the present application further provide a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smart phone.

[0294] As Figure 16 shown, the computing device cluster includes at least one computing device 100. Instructions for executing Figures 6 to 13 the methods in the related method embodiments can be stored in the memory 106 of one or more computing devices 100 in the computing device cluster.

[0295] In some possible implementation manners, instructions for executing Figures 6 to 13 part of the instructions in the public network gateway method in the related method embodiments can also be stored separately in the memory 106 of one or more computing devices 100 in the computing device cluster. In other words, a combination of one or more computing devices 100 can jointly execute Figures 6 to 13 the instructions in the public network gateway method in the related method embodiments.

[0296] It should be noted that different memories 106 in different computing devices 100 in the computing device cluster can store different instructions for respectively implementing some functions of the public network gateway. That is to say, the instructions stored in the memories 106 of different computing devices 100 can implement the functions of one or more modules among the acquisition module, the forwarding module, the identification module, and the collection module.

[0297] In some possible implementation manners, one or more computing devices in the computing device cluster can be connected through a network. Among them, the network can be a wide area network or a local area network, etc. Figure 17 Shows a possible implementation manner. As Figure 17, two computing devices 100A and 100B are connected via a network. Specifically, they are connected to the network through the communication interfaces in each computing device. In this type of possible implementation, the instructions for implementing the acquisition module and the forwarding module functions are stored in the memory 106 of the computing device 100A. At the same time, the instructions for implementing the recognition module and the acquisition module functions are stored in the memory 106 of the computing device 100B.

[0298] Figure 17 The connection method between the computing device clusters shown can be considered. Since the acquisition method provided in this application requires a large amount of processing (or acquisition) data, it is considered to hand over the functions implemented by the recognition module and the acquisition module to the computing device 100B for execution.

[0299] It should be understood that Figure 17 The functions of the computing device 100A shown in can also be completed by multiple computing devices 100. Similarly, the functions of the computing device 100B can also be completed by multiple computing devices 100.

[0300] The embodiments of this application also provide another computing device cluster. The connection relationship between the computing devices in this computing device cluster can be similarly referred to Figure 17 The connection method of the computing device cluster. The difference is that the memory 106 in one or more computing devices 100 in this computing device cluster may store the same instructions for executing Figures 6 to 13 The methods in the relevant method embodiments.

[0301] In some possible implementation manners, the memory 106 of one or more computing devices 100 in this computing device cluster may also separately store the instructions for executing Figures 6 to 13 Some of the instructions in the relevant method embodiments. In other words, the combination of one or more computing devices 100 can jointly execute Figures 6 to 13 The instructions in the relevant method embodiments.

[0302] It should be noted that the memory 106 in different computing devices 100 in the computing device cluster may store different instructions for executing some functions of the acquisition system. That is, the instructions stored in the memory 106 of different computing devices 100 can implement the functions of one or more devices among the public network gateway, cloud management platform, global control platform, and local control platform.

[0303] The embodiments of this application also provide a computer program product containing instructions. The computer program product can be software or a program product containing instructions that can run on a computing device or be stored in any available medium. When the computer program product runs on at least one computing device, it causes at least one computing device to execute Figures 6 to 13The method in the related method embodiments.

[0304] The embodiments of the present application further provide a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive), etc. The computer-readable storage medium includes instructions that instruct the computing device to execute Figures 6 to 13 The method in the related method embodiments.

[0305] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present invention.

Claims

1. A collection method, characterized in that, Including: Obtain collection information, where the collection information includes the elastic identifier of the virtual machine to be collected and a collection rule, and the elastic identifier is an Elastic Internet Protocol (EIP) address or a Global Elastic Internet Protocol (GEIP) address; During the process of forwarding the public network packets of M virtual machines, identify the public network packets of the virtual machine to be collected according to the elastic identifier of the virtual machine to be collected, where the M virtual machines include the virtual machine to be collected, and M is a positive integer; Collect data to be analyzed from the public network packets of the virtual machine to be collected according to the collection rule, and the data to be analyzed is used to monitor the security of the public network packets of the virtual machine to be collected.

2. The method according to claim 1, characterized in that, The collection rule includes a screening condition associated with a first session and a screening condition associated with a second session, where the priority of the first session is higher than the priority of the second session; The public network packets of the virtual machine to be collected include first public network packets; The step of collecting data to be analyzed from the public network packets of the virtual machine to be collected according to the collection rule includes: When it is determined that the first public network packet meets the screening condition associated with the first session and the screening condition associated with the first session indicates mirroring, mirror the first public network packet to obtain the data to be analyzed; When it is determined that the first public network packet does not meet the screening condition associated with the first session, determine that the first public network packet meets the screening condition associated with the second session and the screening condition associated with the second session indicates mirroring, and mirror the first public network packet to obtain the data to be analyzed.

3. The method according to claim 2, wherein The screening condition associated with the first session includes a first screening condition and a second screening condition, where the priority of the first screening condition is higher than the priority of the second screening condition; The step of, when it is determined that the first public network packet meets the screening condition associated with the first session and the screening condition associated with the first session indicates mirroring, mirroring the first public network packet to obtain the data to be analyzed includes: When it is determined that the first public network packet meets the first screening condition and the first screening condition indicates mirroring, mirror the first public network packet to obtain the data to be analyzed; When it is determined that the first public network packet does not meet the first screening condition, determine that the first public network packet meets the second screening condition and the second screening condition indicates mirroring, and mirror the first public network packet to obtain the data to be analyzed.

4. The method according to claim 2 or 3, characterized in that The collection rule further includes a screening condition associated with a third session, where the priority of the second session is higher than the priority of the third session; The public network packets of the virtual machine to be collected further include second public network packets; The method further includes: When it is determined that the second public network packet does not meet the screening conditions associated with the first session and the second session, determine that the second public network packet meets the screening condition associated with the third session and the screening condition associated with the third session indicates no mirroring.

5. The method according to any one of claims 2 to 4, characterized in that The screening condition includes any one of the following: The transmission direction of the public network message is the outbound direction, and the destination Internet Protocol (IP) address of the public network message is the IP address of a preset public network node; The transmission direction of the public network message is the inbound direction, and the source IP address of the public network message is the IP address of a preset public network node; The source IP address and destination IP address of the public network message. When the source IP address is the IP address of a preset public network node, the destination IP is the elastic identifier of the virtual machine to be collected. When the destination IP address is the IP address of a preset public network node, the source IP is the elastic identifier of the virtual machine to be collected.

6. The method according to any one of claims 1-5, characterized in that, Forwarding the public network messages of M virtual machines includes: Receiving a public network message from a first virtual machine, where the source IP address in the public network message is the private IP address of the first virtual machine; After converting the source IP address in the public network message to the elastic identifier of the first virtual machine according to the mapping relationship between the elastic identifiers and private IP addresses of the M virtual machines and the private IP address of the first virtual machine, a new public network message is obtained; Forwarding the new public network message to the public network node; Wherein, the first virtual machine is any one of the M virtual machines.

7. The method according to any one of claims 1-6, characterized in that, Forwarding the public network messages of M virtual machines includes: Receiving a public network message from a public network node, where the destination IP address in the public network message is the elastic identifier of the first virtual machine; After converting the destination IP address in the public network message to the private IP address of the first virtual machine according to the mapping relationship between the elastic identifiers and private IP addresses of the M virtual machines and the elastic identifier of the first virtual machine, a new public network message is obtained; Forwarding the new public network message to the first virtual machine; Wherein, the first virtual machine is any one of the M virtual machines.

8. The method according to any one of claims 1-7, characterized in that, The collected information further includes the IP address of the destination virtual machine, and the IP address of the destination virtual machine is determined based on the global topology relationship, and the global topology relationship is determined based on the local topology relationships of multiple data centers. The destination virtual machine and the virtual machine to be collected are in different data centers among the multiple data centers; The method further includes: Sending the data to be analyzed to the destination virtual machine according to the IP address of the destination virtual machine.

9. The method according to claim 8, wherein The IP address of the destination virtual machine includes the IP address of the physical device to which the destination virtual machine belongs and the private IP address of the destination virtual machine in the physical device; Sending the data to be analyzed to the destination virtual machine according to the IP address of the destination virtual machine includes: Sending a Virtual eXtensible Local Area Network (VXLAN) message to the destination virtual machine, where the inner layer message of the VXLAN message includes the data to be analyzed, the first layer tunnel encapsulation header of the VXLAN message includes the private IP address of the destination virtual machine in the physical device, and the second layer tunnel encapsulation header of the VXLAN message includes the IP address of the physical device.

10. The method according to any one of claims 1-9, characterized in that, The virtual machine to be collected includes N network cards, N is a positive integer, the collected information further includes the identifier of the network card to be collected, and the N network cards include the network card to be collected; During the process of forwarding the public network packets of M virtual machines, according to the elastic identifier of the virtual machine to be collected, identifying the public network packets of the virtual machine to be collected includes: During the process of forwarding the public network packets of the M virtual machines, according to the elastic identifier of the virtual machine to be collected and the identifier of the network card to be collected, identifying the public network packets of the network card to be collected; The collecting, according to the collection rule, the data to be analyzed from the public network packets of the virtual machine to be collected includes: The collecting, according to the collection rule, the data to be analyzed from the public network packets of the network card to be collected, where the data to be analyzed is used to monitor the security of the public network packets of the network card to be collected.

11. A collection system, characterized in that, Including: A cloud management platform and a public network gateway; The cloud management platform is used for: Generating collection information and sending the collection information to the public network gateway; The public network gateway is used for: Receiving the collection information from the cloud management platform, where the collection information includes the elastic identifier of the virtual machine to be collected and the collection rule, and the elastic identifier is an Elastic Internet Protocol (EIP) address or a Global Elastic Internet Protocol (GEIP) address; During the process of forwarding the public network packets of M virtual machines, according to the elastic identifier of the virtual machine to be collected, identifying the public network packets of the virtual machine to be collected, where the M virtual machines include the virtual machine to be collected, and M is a positive integer; According to the collection rule, collecting the data to be analyzed from the public network packets of the virtual machine to be collected, where the data to be analyzed is used to monitor the security of the public network packets of the virtual machine to be collected.

12. The system according to claim 11, wherein Further including: The M virtual machines, where the first virtual machine is any one of the M virtual machines; The first virtual machine is used for: Sending public network packets to the public network gateway; When the public network gateway is used to forward the public network packets of the M first virtual machines, specifically used for: Receiving the public network packets from the first virtual machine, where the source Internet Protocol (IP) address in the public network packets is the private IP address of the first virtual machine; According to the mapping relationship between the elastic identifiers and private IP addresses of the M first virtual machines, and the private IP address of the first virtual machine, after converting the source IP address in the public network packets into the elastic identifier of the first virtual machine, obtaining a new public network packet; Forwarding the new public network packet to a public network node.

13. The system according to claim 11, wherein Further including: The M virtual machines, where the first virtual machine is any one of the M virtual machines; When the public network gateway is used to forward the public network packets of the M first virtual machines, specifically used for: Receiving the public network packets from the public network node, where the destination IP address in the public network packets is the elastic identifier of the first virtual machine; According to the mapping relationship between the elastic identifiers and private IP addresses of the M first virtual machines, and the elastic identifier of the first virtual machine, after converting the destination IP address in the public network packets into the private IP address of the first virtual machine, obtaining a new public network packet; Forwarding the new public network packet to the first virtual machine; The first virtual machine is used for: Receiving the new public network packet from the public network gateway.

14. The system according to any one of claims 11-13, characterized in that, Further including: Destination virtual machine; the collected information further includes the IP address of the destination virtual machine; The public network gateway is further configured to: Send the data to be analyzed to the destination virtual machine according to the IP address of the destination virtual machine; The destination virtual machine is configured to: Receive the data to be analyzed from the public network gateway; Monitor the security of the public network packets of the virtual machine to be collected according to the data to be analyzed.

15. The system according to any one of claims 11-14, characterized in that, It further includes: Global control platform; The global control platform is configured to: Receive the identifier of the destination virtual machine from the cloud management platform; Determine the IP address of the destination virtual machine according to the identifier of the destination virtual machine and the global topology relationship; Send the IP address of the destination virtual machine to the cloud management platform.

16. The system according to claim 15, wherein, It further includes: Local control platform; The local control platform is configured to: Determine the local topology relationship corresponding to the data center to which the local control platform belongs; Send the local topology relationship corresponding to the data center to which the local control platform belongs to the global control platform; The global control platform is further configured to: Determine the global topology relationship according to the local topology relationship corresponding to the data center to which the local control platform belongs.

17. A cluster of computing devices, characterized in that, It includes a module for executing the method according to any one of claims 1-10.

18. A cluster of computing devices, characterized in that, It includes at least one computing device, and each computing device includes a processor and a memory; The processor of the at least one computing device is configured to execute the instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1-10.

19. A computer program product comprising instructions, characterized in that, When the instructions are run by the computing device cluster, the computing device cluster executes the method according to any one of claims 1-10.

20. A computer-readable storage medium, characterized in that, It includes computer program instructions, and when the computer program instructions are executed by the computing device cluster, the computing device cluster executes the method according to any one of claims 1-10.