Traffic playback method, device and system, electronic equipment and computer storage medium

By obtaining the initial basic information of network traffic, determining the timing and service information, and assigning the target server and client, the traffic replay problem in the multi-port and multi-service network environment in the existing technology is solved, and accurate traffic replay and testing effects are achieved.

CN120263667AActive Publication Date: 2025-07-04BEIJING ZHIQIAN TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510734220.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-04
Publication Date
2025-07-04
Estimated Expiration
2045-06-04

AI Technical Summary

Technical Problem

The prior art cannot effectively handle complex network environments with multiple ports and multiple services interacting simultaneously in a real network environment, resulting in one-sidedness and incompleteness of traffic analysis, and it is difficult to accurately reproduce the time series and interaction logic of the original traffic, affecting the accuracy and reliability of the test results.

Method used

Provide a traffic playback method, by obtaining the initial basic information of network traffic, determining timing information and service information, allocating the target server and client, establishing correspondence relationships, and replaying traffic data between the target client and the server, realizing multi-service and multi-port collaborative playback, and precisely controlling timing and multi-stream.

Benefits of technology

Accurate traffic playback between the target client and the server is achieved, the accuracy and reliability of network behavior simulation is improved, the accuracy and reliability of traffic testing is enhanced, and multiple network communication scenarios can be better simulated and reproduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263667A_ABST
    Figure CN120263667A_ABST
Patent Text Reader

Abstract

The invention discloses a traffic playback method, device and system, electronic equipment and a computer storage medium, and relates to the technical field of computers, in particular to the technical field of network testing and security, and the specific implementation scheme is as follows: obtaining initial basic information of network traffic, the initial basic information comprising multiple traffic data at multiple moments; based on the initial basic information, determining time sequence information of each traffic data in the network traffic and initial service information of an initial server and an initial client; based on the initial service information, distributing a target server for each piece of flow data, and establishing a service corresponding relationship between the target server and the initial server; based on the initial service information and the service corresponding relationship, distributing a target client for each piece of flow data, and establishing a customer service corresponding relationship between the target client and the target server; and according to the customer service corresponding relationship and the time sequence information, replaying each piece of traffic data between the target client and the target server, thereby improving the accuracy and reliability of the traffic test.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer technology, and particularly relates to technical fields such as network security and network testing. In particular, it relates to a traffic replay method, device, system, electronic device, and computer-readable storage medium. Background Art

[0002] In the current field of network usage analysis and testing, traffic capture and replay technologies are important means for evaluating network performance, detecting security vulnerabilities, and reproducing network problems. Existing technologies usually focus on traffic capture and replay on a single server side. This method listens to the data stream of a specific port or service, stores the captured traffic data as a file, and then replays it in the same or a similar environment to simulate the original network behavior.

[0003] In a real network environment, sometimes it is impossible to reproduce the same client, and the traffic needs to be reproduced on other clients, or traffic replay needs to be completed through the cooperation of multiple services and multiple ports. However, this single-server-side traffic capture and replay technology has obvious limitations.

[0004] The information disclosed in this background art section is only intended to enhance the overall understanding of the present invention and should not be regarded as an admission or any form of suggestion that this information constitutes prior art already known to those of ordinary skill in the art. Summary of the Invention

[0005] The purpose of the present disclosure is to solve the technical problem that the traffic capture and replay on a single server side have limitations, and provides a traffic replay method, device, system, electronic device, and computer-readable storage medium.

[0006] The first aspect of the present disclosure provides a traffic replay method, which includes: obtaining the initial basic information of network traffic, where the initial basic information includes various traffic data at multiple moments; based on the initial basic information, determining the timing information of each traffic data in the network traffic, and the initial service information of the initial server and the initial client; based on the initial service information, allocating a target server for each traffic data, and establishing a service correspondence relationship between the target server and the initial server; based on the initial service information and the service correspondence relationship, allocating a target client for each traffic data, and establishing a client correspondence relationship between the target client and the target server; and replaying each traffic data between the target client and the target server according to the client correspondence relationship and the timing information.

[0007] The second aspect of the present disclosure provides a traffic replay device, which includes: an acquisition unit configured to acquire initial basic information of network traffic, where the initial basic information includes various traffic data at multiple moments; a determination unit configured to determine, based on the initial basic information, the timing information of each traffic data in the network traffic, and the initial service information of the initial server and the initial client; a service allocation unit configured to allocate a target server for each traffic data based on the initial service information, and establish a service correspondence relationship between the target server and the initial server; a client allocation unit configured to allocate a target client for each traffic data based on the initial service information and the service correspondence relationship, and establish a customer service correspondence relationship between the target client and the target server; a replay unit configured to replay each traffic data between the target client and the target server according to the customer service correspondence relationship and the timing information.

[0008] According to the third aspect, a traffic replay system is provided, which includes: a plurality of traffic subsystems for providing initial basic information of network traffic, where the initial basic information includes various traffic data at multiple moments, and each traffic data in the various traffic data is provided by one traffic subsystem; a replay subsystem for acquiring the initial basic information from the plurality of traffic subsystems; determining, based on the initial basic information, the timing information of each traffic data in the network traffic, and the initial service information of the initial server and the initial client; allocating a target server for each traffic data based on the initial service information, and establishing a service correspondence relationship between the target server and the initial server; allocating a target client for each traffic data based on the initial service information and the service correspondence relationship, and establishing a customer service correspondence relationship between the target client and the target server; replaying each traffic data between the target client and the target server according to the customer service correspondence relationship and the timing information.

[0009] According to the fourth aspect, an electronic device is provided, which includes: at least one processor; and a memory communicatively connected to the at least one processor, where the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method described in any implementation manner of the first aspect.

[0010] According to the fifth aspect, a non-transitory computer-readable storage medium storing computer instructions is provided, and the computer instructions are used to cause a computer to execute the method described in any implementation manner of the first aspect.

[0011] The traffic replay method and apparatus provided by the embodiments of the present disclosure first obtain the initial basic information of network traffic, where the initial basic information includes various traffic data at multiple moments; secondly, based on the initial basic information, determine the timing information of each traffic data in the network traffic, and the initial service information of the initial server and the initial client; thirdly, based on the initial service information, allocate a target server for each traffic data, and establish a service correspondence relationship between the target server and the initial server; fourthly, based on the initial service information and the service correspondence relationship, allocate a target client for each traffic data, and establish a customer service correspondence relationship between the target client and the target server; finally, replay each traffic data between the target client and the target server according to the customer service correspondence relationship and the timing information. Thereby, the replay of network traffic between the target client and the target server is realized, and multi-service multi-port collaborative replay can also be performed between the target client and the target server, achieving precise control of timing and multi-streams, being able to more precisely simulate and replay various network communication scenarios, improving the accuracy and reliability of network behavior simulation; when testing traffic data between the target client and the target server, the accuracy and reliability of traffic testing are improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Figure 1 is a flowchart according to an embodiment of the traffic replay method of the present disclosure; Figure 2 is a schematic structural diagram of traffic data replay in the present disclosure; Figure 3 is a mapping relationship diagram of the initial service information in the present disclosure; Figure 4 is a schematic structural diagram according to an embodiment of the traffic replay apparatus of the present disclosure; Figure 5 is a schematic structural diagram according to an embodiment of the traffic replay system of the present disclosure; Figure 6 is a block diagram of an electronic device for implementing the traffic replay method of the embodiments of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0013] Unless otherwise clearly stated, throughout the specification and claims, the term "comprise" or its variations such as "comprises" or "comprising" etc. will be understood to include the stated components or constituent parts, without excluding other components or other constituent parts.

[0014] The technical solutions of the present invention will be described below through specific embodiments. It should be understood that one or more steps mentioned in the present invention do not exclude the existence of other methods and steps before and after the combined steps, or other methods and steps can be inserted between these explicitly mentioned steps. It should also be understood that these examples are only used to illustrate the present invention and not to limit the scope of the present invention. Unless otherwise specified, the numbers of each method step are only for the purpose of identifying each method step, rather than restricting the arrangement order of each method or limiting the scope of implementation of the present invention. The change or adjustment of their relative relationship can also be regarded as the scope in which the present invention can be implemented under the condition of no substantial change in technical content.

[0015] There are no specific restrictions on the sources of the raw materials and instruments used in the embodiments, and they can be purchased on the market or prepared according to the conventional methods well-known to those skilled in the art.

[0016] Traditional technologies usually focus on traffic capture and playback of a single server. This method captures the data stream of a specific port or service by listening, stores the captured traffic data as a file, and then plays it back in the same or a similar environment to simulate the original network behavior.

[0017] The current traffic capture and playback technology can simulate the network traffic of a single server. However, in a real network environment, a real network communication scenario often requires multiple services and multiple ports to cooperate to complete, not only requiring the cooperation of multi-port traffic but also accompanied by the timing relationship between them. This traffic capture and playback technology for a single server has obvious limitations: it cannot effectively handle complex network environments with multi-port and multi-service simultaneous interactions, such as traffic occurring at the same moment, resulting in one-sidedness and incompleteness of traffic analysis; secondly, due to the lack of the ability to coordinate and sequence multi-terminal and multi-stream, the existing technology is difficult to accurately reproduce the time series and interaction logic of the original traffic during playback, thus affecting the accuracy and reliability of test results.

[0018] Furthermore, in traditional technologies, due to the lack of corresponding multi-stream management and timing control, when simulating typical network transmission scenarios similar to the following, such as traffic for uploading files using the FTP protocol (requiring multi-port functions); scenarios for a Trojan to go online and maintain regular communication with a cloud server (requiring strong timing control); attack traffic for lateral movement of Windows machines in the intranet using the SMB protocol (both multi-port and timing), inaccurate problems will occur.

[0019] Aiming at the defect of reproducing multi-port and multi-service network traffic in the prior art, the present disclosure provides a traffic replay method. Figure 1 Flow 100 of an embodiment of the traffic replay method is shown. The above traffic replay method includes the following steps: Step 101, obtain the initial basic information of the network traffic.

[0020] In this embodiment, the initial basic information includes various traffic data at multiple moments, that is, the network traffic includes: various types of traffic, each type of traffic has corresponding traffic data, and the various traffic data may be the data volumes transmitted by the initial server and the initial client at multiple moments, and both the initial server and the initial client may be multiple.

[0021] In this embodiment, the initial basic information may be the information recorded in the original file (such as Figure 2 the pcap file), and the initial basic information can be obtained by reading the original file. The initial basic information may include: the protocol of the network traffic, the address and port of the client of the corresponding protocol data, the address and port of the server, and information such as the transmitted traffic data and time.

[0022] Step 102: Based on the initial basic information, determine the timing information of each traffic data in the network traffic, and the initial service information of the initial server and the initial client.

[0023] In this embodiment, the content in the initial basic information of the network traffic may be relatively messy. To better sort out the traffic information, the file recording the initial basic information can be parsed first. For example, Figure 2 parse the pcap file through the Parser parsing class shown, organize the traffic data in the initial basic information into a normalized and formatted structure with multiple servers as the dimension, classify the normalized and formatted structure in two dimensions of timing and service port, and establish a mapping relationship between each traffic data and its corresponding timing and service port.

[0024] In this embodiment, the above step 102 includes: based on the initial basic information, determine the traffic data and time of the network traffic, sort the traffic data based on the time of the traffic data to obtain the timing information of the traffic data; cluster the traffic data belonging to the same server and server port, client and client port together as the current traffic cluster, sort the traffic data in the traffic cluster based on the time of the traffic data in the traffic cluster to obtain the sending order of the traffic data in the traffic cluster, use the earliest time in the traffic cluster as the reference time, determine the time difference between the time of each traffic data in the traffic cluster and the basic time, and associate the sending order, time difference, reference time of each traffic data with the traffic data. This association relationship is Figure 3 the mapping in to the traffic data, and use the traffic cluster, the sending order of the traffic data, the time difference, and the reference time as the initial service information of the traffic data.

[0025] Step 103: Based on the initial service information, assign a target server for each traffic data, and establish a service correspondence relationship between the target server and the initial server.

[0026] In this embodiment, the service correspondence relationship is the relationship between the service of the target server and the service of the initial server. For example, target server A corresponds to initial server C, the IP address A11 of target server A corresponds to the IP address C34 of initial server C, and the port A32 of target server A corresponds to the port C52 of initial server C.

[0027] In this embodiment, the initial service information includes the server of the traffic data, the server port, the client, and the client port. Based on the server and the server port in the initial service information, the traffic data of the same initial server can be assigned the same service on the current machine, and the service can be started according to the port and IP address on the current machine to obtain the target server. Then, establish the relationship between the IP address and port of the target server of the same traffic data and the IP address and port of the initial server, and use this relationship as the service correspondence relationship between the target server and the initial server.

[0028] Step 104: Based on the initial service information and the service correspondence relationship, assign a target client for each traffic data, and establish a customer service correspondence relationship between the target client and the target server.

[0029] In this embodiment, the initial service information is used to represent the relationship between the service of the initial server and the service of the initial client, such as the correspondence relationship between the IP address and port of the initial client of the traffic data and the IP address and port of the initial server of the traffic data. The service correspondence relationship is used to represent the relationship between the IP address and port of the target server of the traffic data and the IP address and port of the initial server.

[0030] In this embodiment, the above Step 104 includes: based on the IP address and port of the target server in the service correspondence relationship, determine the number of target clients. At this time, the same number of clients can be directly determined according to the number of target servers in the service correspondence relationship; based on the IP address and port of the initial client in the initial service information, determine the port of the target client. At this time, the same number of ports as the initial client can be directly assigned to the target client according to the port of the current machine; after determining the number and port of the target client, determine the IP address of the target client based on the IP address of the current machine. According to the service correspondence relationship and the information of the target client determined above, establish a connection between the target client and the target client, and establish the relationship between the IP address and port of the target server of the traffic data and the IP address and port of the target server, and use this relationship as the customer service correspondence relationship.

[0031] Step 105: Replay each traffic data between the target client and the target server according to the customer service correspondence and the timing information.

[0032] In this embodiment, based on the timing information of each traffic data, the transmission time of each traffic data between the target client and the target server is determined. When replaying this traffic data, the corresponding new traffic data of this traffic data can be transmitted between the target client and the target server according to the transmission time.

[0033] In this embodiment, each traffic data in the network traffic is data carrying the initial server and initial client information. To better implement the replay of traffic data, it is necessary to replace the initial server information (such as the IP address and port of the initial server) carried in each traffic data with the target server information (such as the IP address and port of the target server), and replace the initial client information (such as the IP address and port of the initial client) carried with the target client information (such as the IP address and port of the target client) to form new traffic data, and control the target server and the target client to transmit the new traffic data.

[0034] The traffic replay method provided by the embodiments of the present disclosure, first, obtains the initial basic information of the network traffic, and the initial basic information includes various traffic data at multiple moments; secondly, based on the initial basic information, determines the timing information of each traffic data in the network traffic, and the initial service information of the initial server and the initial client; thirdly, based on the initial service information, assigns a target server to each traffic data, and establishes a service correspondence between the target server and the initial server; fourthly, based on the initial service information and the service correspondence, assigns a target client to each traffic data, and establishes a customer service correspondence between the target client and the target server; finally, according to the customer service correspondence and the timing information, replicate and replay each traffic data between the target client and the target server. Thereby, the replay of the network traffic between the target client and the target server is realized, and multi-service multi-port collaborative replay can also be performed between the target client and the target server, realizing precise control of timing and multi-streams, and being able to more precisely simulate, replicate and replay various network communication scenarios, improving the accuracy and reliability of network behavior simulation; when testing traffic data between the target client and the target server, the accuracy and reliability of traffic testing are improved.

[0035] Optionally, the replayed traffic data can be data under various test scenarios. The traffic data can help developers and testers better understand the behavior of the system under specific conditions. The above traffic replay method further includes: when replaying each traffic data between the target client and the target server, testing the traffic between the target client and the target server under different scenarios to obtain test results. Among them, different scenarios can include: file data transfer scenarios based on the FTP (File Transfer Protocol) protocol under multiple ports, scenarios of trojan horse going online, maintaining communication with the cloud server regularly, and scenarios of lateral movement attacks on machines in the intranet using a specific protocol (such as the SMB protocol) regularly under multiple ports.

[0036] In some optional ways of the present disclosure, the above determining the timing information of each traffic data in the network traffic, and the initial service information of the initial server and the initial client based on the initial basic information includes: based on the initial basic information, performing parsing on the network traffic by the customer service to determine multiple traffic data, and the IP address and port of the initial server corresponding to each traffic data, and the IP address and port of the initial client, and using the IP address and port of the initial server and the IP address and port of the initial client corresponding to each traffic data as the initial service information of the initial server and the initial client corresponding to each traffic data; based on the initial basic information and multiple traffic data, obtaining the traffic time of each traffic data; based on the traffic time of multiple traffic data, determining the timing information of each traffic data.

[0037] In this optional implementation manner, as Figure 3 shown, the NetFlowCollections class classifies and organizes multiple traffic data and records the traffic information in two different dimensions of timing and initial server port information. Among them, the timing and multi-server information are only pointers to record relevant information and record the location of the traffic data.

[0038] In this optional implementation manner, the traffic time includes: packet capture time, packet capture file time, request phase time, timestamp format and protocol specification. The timing information is the sorting order information of the traffic times of multiple traffic data, and different parts of the traffic time can be sorted according to different test scenario requirements to obtain the timing information. For example, for the test scenario of regular communication, the above determining the timing information of each traffic data based on the traffic time of multiple traffic data includes: sorting multiple traffic data based on the packet capture time of each traffic data in multiple traffic data to obtain the timing information of each traffic data.

[0039] The method for determining the timing information and initial service information of traffic data provided by this alternative implementation determines the initial service information by parsing the customer service for network traffic; determines the timing information of traffic data through the traffic time of the traffic data, and completely records the timing information of multiple traffic data in the network traffic, providing a reliable implementation for obtaining the initial service information and timing information.

[0040] In some alternative implementations of the present disclosure, the above-mentioned method of allocating a target server for each traffic data based on the initial service information and establishing a service correspondence relationship between the target server and the initial server includes: determining the first quantity of different initial servers and the second quantity of the ports of the initial server based on the initial service information; determining the service of the current machine based on the first quantity and different initial servers; starting the service based on the IP address and port information of the current machine and the second quantity, using the service as the target server, establishing a correspondence relationship between the IP address and port of the target server and the IP address and port of the initial server, and using this correspondence relationship as the service correspondence relationship.

[0041] In this alternative implementation, the first quantity of different initial servers refers to the number of different initial servers. For example, if there are a total of 5 initial servers and 2 of them are the same among the 5 initial servers, then the number of different initial servers is 4. Based on the first quantity and the 5 initial servers, 4 types of services can be set on the current machine, and each type of service corresponds to one initial server.

[0042] In this alternative implementation, the current machine can be a physical machine or a virtual machine. When starting the service on the current machine, ports that meet the requirements of the second quantity will be configured for the service based on the IP address and port of the current machine, and the configured ports will be monitored in real time after the service is started.

[0043] The method for establishing a service correspondence relationship provided by this alternative implementation determines the first quantity of different initial servers based on the initial service information, determines the target server based on the first quantity, and establishes the service correspondence relationship, providing a reliable implementation for the establishment of the service correspondence relationship.

[0044] In some alternative implementations of the present disclosure, the above-mentioned method of allocating target servers to respective traffic data based on initial service information and establishing a service correspondence relationship between the target servers and the initial servers includes: classifying and reorganizing the traffic data according to different initial servers; allocating the traffic data of the same initial server to the same service on the current machine, so that each traffic data corresponds to a service; based on the IP address and port information of the current machine, starting the service, using the service as the target server, and establishing a correspondence relationship between the IP address and port of the target server and the IP address and port of the initial server, and using this correspondence relationship as the service correspondence relationship.

[0045] In this alternative implementation, as Figure 2 shown, the ServerDispatcher class is a custom class for server allocation management. Its function is to classify and reorganize the traffic data according to the initial service information recorded in NetFlowCollections, and allocate the traffic of each group of the same server to the same service Server, and start these services Server according to the new IP address and port information of the current machine, as Figure 2 shown in the figure, there are three target servers, namely Server_1, Server_2, and Server_3, and establish a mapping relationship between each group of service information and the re-listened address information of the current Server (for example, the IP address of the initial server of the traffic data is 192.168.1.1, the port is 8080, and the corresponding IP address of the current target server is 10.0.0.1, the port is 9090), and save the mapping relationship information, that is, obtain the service correspondence relationship.

[0046] In this alternative implementation, the current machine refers to the machine where the service is located, and the current machine can be an actual physical machine or a virtual machine.

[0047] The method for establishing the service correspondence relationship provided by this alternative implementation groups the traffic data, allocates the traffic data of the same initial server to the same service; based on the IP address and port information of the current machine, starts the service, determines the target server, and establishes the service correspondence relationship, providing another reliable implementation method for the establishment of the service correspondence relationship.

[0048] In some alternative implementations of the present disclosure, the above-mentioned method of allocating target clients to each traffic data based on the initial service information and the service correspondence relationship, and establishing the customer service correspondence relationship between the target client and the target server includes: allocating the traffic data in groups based on the initial service information, and allocating target clients at different addresses and the ports of the target clients to each traffic data in units of groups; determining the IP addresses and ports of the initial servers corresponding to the addresses and ports of each target client based on the allocation results of each traffic data and the initial service information; determining the correspondence relationship between the IP addresses and ports of the target client and the IP addresses and ports of the target server based on the addresses and ports of each target client and the service correspondence relationship, and using this correspondence relationship as the customer service correspondence relationship.

[0049] In this alternative implementation, as Figure 2 shown, the ClientDispatcher class is a custom client allocation management class, and its functions include loading data and allocating target clients, and replaying traffic data between the target client and the target server.

[0050] Among them, loading data and allocating target clients includes: allocating traffic in groups according to the initial service information recorded in NetFlowCollections and the service correspondence relationship input by the ServerDispatcher class, and allocating to target clients at different addresses. As Figure 2 shown, there are 3 target clients, namely Client_1, Client_2, and Client_3. Decompose the customer service correspondence relationship and input the IP addresses of the target servers that each target client Client needs to connect to, so that the target client Client can send data traffic to the target server Server. It should be noted that each target client is connected to the corresponding target server through its own connections (such as Figure 2 the connections socket_1_1, socket_1_2, socket_1_3 of the target client Client_1 in ; the connections socket_2_1, socket_2_2, socket_2_3 of Client_2; the connection socket_3_1 of Client_3), where the connection is a communication connection based on IP addresses and ports.

[0051] This optional implementation provides a method for establishing a customer service correspondence relationship. Based on the initial service information, traffic data is allocated in groups, and different target clients and the ports of the target clients at different addresses are allocated to each traffic data in units of groups; based on the allocation results of each traffic data and the initial service information, the IP addresses and ports of the initial servers corresponding to the addresses and ports of each target client are determined; based on the addresses and ports of each target client and the service correspondence relationship, the correspondence relationship between the IP address and port of the target client and the IP address and port of the target server is determined, and this correspondence relationship is used as the customer service correspondence relationship, providing a reliable implementation method for obtaining the customer service correspondence relationship.

[0052] In some optional implementations of the present disclosure, the above-mentioned replaying of each traffic data between the target client and the target server according to the customer service correspondence relationship and the timing information includes: based on the customer service correspondence relationship, determining the address and port of the target server to which each traffic data is to be connected and the address and port of the target client; according to the timing information of each traffic data, controlling each traffic data to be replayed between the address and port of the target server to which it is to be connected and the address and port of the target client.

[0053] In this optional implementation, the ClientDispatcher class starts the replay execution. After starting the replay, according to the timing information of NetFlowCollections, the time and order of the replay of each target client Client are controlled, so as to uniformly manage and schedule the order of the replayed data traffic to achieve the purpose of replicating the timing information of the network traffic.

[0054] The method for replaying traffic data provided by this optional implementation determines the address and port of the target server to which each traffic data is to be connected and the address and port of the target client based on the customer service correspondence relationship; according to the timing information of each traffic data, controls each traffic data to be replayed between the address and port of the target server to which it is to be connected and the address and port of the target client, and accurately replays and replicates traffic with strict multi-port timing, providing a reliable implementation method for the replay of traffic data.

[0055] Further reference Figure 4 As an implementation of the methods shown in the above figures, the present disclosure provides an embodiment of a traffic replay device. This device embodiment corresponds to Figure 1 the method embodiment shown, and this device can be specifically applied to various electronic devices.

[0056] Such as Figure 4As shown in the figure, the traffic replay device 400 provided in this embodiment includes: an acquisition unit 401, a determination unit 402, a service allocation unit 403, a client allocation unit 404, and a replay unit 405. Among them, the above-mentioned acquisition unit 401 can be configured to acquire the initial basic information of network traffic, and the initial basic information includes various traffic data at multiple moments. The above-mentioned determination unit 402 can be configured to determine the timing information of each traffic data in the network traffic, the initial service information of the initial server and the initial client based on the initial basic information. The above-mentioned service allocation unit 403 can be configured to allocate a target server for each traffic data based on the initial service information, and establish a service correspondence relationship between the target server and the initial server. The above-mentioned client allocation unit 404 can be configured to allocate a target client for each traffic data based on the initial service information and the service correspondence relationship, and establish a customer service correspondence relationship between the target client and the target server. The above-mentioned replay unit 405 can be configured to replay each traffic data between the target client and the target server according to the customer service correspondence relationship and the timing information.

[0057] In this embodiment, in the traffic replay device 400: the specific processing of the acquisition unit 401, the determination unit 402, the service allocation unit 403, the client allocation unit 404, and the replay unit 405 and the technical effects brought by them can be respectively referred to Figure 1 the relevant descriptions of steps 101, 102, 103, 104, and 105 in the corresponding embodiments, which will not be elaborated here.

[0058] In an embodiment of the present disclosure, the above-mentioned determination unit 402 is configured to: perform customer service pair parsing on the network traffic based on the initial basic information, determine multiple traffic data and the IP addresses and ports of the initial server corresponding to each traffic data, and the IP addresses and ports of the initial client, and use the IP addresses and ports of the initial server and the initial client of each traffic data as the initial service information of the initial server and the initial client of each traffic data; obtain the traffic time of each traffic data based on the initial basic information and multiple traffic data; determine the timing information of each traffic data based on the traffic time of multiple traffic data.

[0059] In an embodiment of the present disclosure, the above-mentioned service allocation unit 403 is configured to: determine the first quantity of different initial servers and the second quantity of the ports of the initial server based on the initial service information; determine the service of the current machine based on the first quantity and different initial servers; start the service based on the IP address, port information of the current machine and the second quantity, use the service as the target server, establish the correspondence relationship between the IP address and port of the target server and the IP address and port of the initial server, and use this correspondence relationship as the service correspondence relationship.

[0060] In one embodiment of the present disclosure, the above service allocation unit 403 is configured to: classify and reorganize traffic data according to different initial servers; allocate the same service on the current machine to the traffic data of the same initial server, so that each traffic data corresponds to a service; based on the IP address and port information of the current machine, start the service, use the service as the target server, establish the correspondence between the IP address and port of the target server and the IP address and port of the initial server, and use this correspondence as the service correspondence.

[0061] In one embodiment of the present disclosure, the above customer allocation unit 404 is configured to: based on the initial service information, allocate traffic data in groups, and allocate target clients at different addresses and ports of the target clients to each traffic data in units of groups; based on the allocation results of each traffic data and the initial service information, determine the IP address and port of the initial server corresponding to the addresses and ports of each target client; based on the addresses and ports of each target client and the service correspondence, determine the correspondence between the IP address and port of the target client and the IP address and port of the target server, and use this correspondence as the customer service correspondence.

[0062] In one embodiment of the present disclosure, the above replay unit 405 is configured to: based on the customer service correspondence, determine the address and port of the target server and the address and port of the target client to which each traffic data is to be connected; according to the timing information of each traffic data, control each traffic data to be replayed between the address and port of the target server and the address and port of the target client to which it is to be connected.

[0063] In the traffic replay device provided by the embodiment of the present disclosure, first, the acquisition unit 401 acquires the initial basic information of network traffic, where the initial basic information includes various traffic data at multiple moments; second, the determination unit 402 determines the timing information of each traffic data in the network traffic, and the initial service information of the initial server and the initial client based on the initial basic information; third, the service allocation unit 403 allocates a target server for each traffic data based on the initial service information, and establishes a service correspondence relationship between the target server and the initial server; fourth, the client allocation unit 404 allocates a target client for each traffic data based on the initial service information and the service correspondence relationship, and establishes a customer service correspondence relationship between the target client and the target server; finally, the replay unit 405 replays each traffic data between the target client and the target server according to the customer service correspondence relationship and the timing information. Thus, the replay of network traffic between the target client and the target server is realized, and multi-service multi-port collaborative replay can also be performed between the target client and the target server, realizing precise control of timing and multi-streams, being able to more precisely simulate and replay various network communication scenarios, improving the accuracy and reliability of network behavior simulation; when testing traffic data on the target client and the target server, the accuracy and reliability of traffic testing are improved.

[0064] Further referring to Figure 5 , as an implementation of the methods shown in the above figures, the present disclosure provides an embodiment of a traffic replay system. This system embodiment corresponds to Figure 1 the method embodiment shown.

[0065] As Figure 5 shown, the traffic replay system 500 provided in this embodiment includes: a plurality of traffic subsystems 501, a replay subsystem 502.

[0066] The plurality of traffic subsystems 501 are used to provide the initial basic information of network traffic, where the initial basic information includes various traffic data at multiple moments, and each traffic data in the various traffic data is provided by one traffic subsystem.

[0067] In this embodiment, the traffic subsystem 501 can be a device for traffic transmission in the network, such as a client or a server; the traffic subsystem includes an initial client and an initial server, and the initial client and the initial server are actual devices for traffic transmission. The plurality of traffic subsystems can be a plurality of customer service pairs composed of an initial client and an initial server, and the time of the traffic data sent by two different customer service pairs can be the same or different.

[0068] The replay subsystem 502 is used to obtain initial basic information from multiple traffic subsystems; based on the initial basic information, determine the timing information of each traffic data in the network traffic, and the initial service information of the initial server and the initial client; based on the initial service information, allocate a target server for each traffic data, and establish a service correspondence relationship between the target server and the initial server; based on the initial service information and the service correspondence relationship, allocate a target client for each traffic data, and establish a customer service correspondence relationship between the target client and the target server; according to the customer service correspondence relationship and the timing information, replay each traffic data between the target client and the target server.

[0069] In this embodiment, in the traffic replay system 500: For the specific processing of the replay subsystem 502 and the technical effects brought by it, reference can be made to Figure 1 the relevant descriptions of steps 101, 102, 103, 104, and 105 in the corresponding embodiment, which will not be elaborated here.

[0070] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0071] Figure 6 FIG. shows a schematic block diagram of an exemplary electronic device 600 that can be used to implement the embodiments of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device, and other similar computing devices. The components shown herein, their connections and relationships, and their modes are merely examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0072] As Figure 6 shown, the device 600 includes a computing unit 601, which can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 602 or the computer program loaded from the storage unit 608 into the random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the device 600 can also be stored. The computing unit 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. The input / output (I / O) interface 605 is also connected to the bus 604.

[0073] Multiple components in device 600 are connected to I / O interface 605, including: an input unit 606, such as a keyboard, a mouse, etc.; an output unit 607, such as various types of displays, speakers, etc.; a storage unit 608, such as a disk, an optical disc, etc.; and a communication unit 609, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 609 allows device 600 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0074] The computing unit 601 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 601 executes the various methods and processes described above, such as the traffic replay method. For example, in some embodiments, the traffic replay method can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as the storage unit 608. In some embodiments, part or all of the computer program can be loaded and / or installed onto device 600 via the ROM 602 and / or the communication unit 609. When the computer program is loaded into the RAM 603 and executed by the computing unit 601, one or more steps of the traffic replay method described above can be executed. Alternatively, in other embodiments, the computing unit 601 can be configured to execute the traffic replay method in any other suitable manner (e.g., by means of firmware).

[0075] The various embodiments of the systems and technologies described above in this article can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor, and can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0076] The program code for implementing the methods of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable traffic replay device, such that the program codes, when executed by the processor or controller, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The program code may be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0077] In the context of the present disclosure, a machine-readable medium may be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0078] In order to provide interaction with a user, the systems and techniques described herein may be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, speech input, or tactile input).

[0079] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.

[0080] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and this is not limited herein.

[0081] The foregoing description of specific exemplary embodiments of the present invention is for purposes of illustration and exemplification. These descriptions are not intended to limit the invention to the precise forms disclosed, and obviously, many changes and variations are possible in light of the above teachings. The purpose of selecting and describing the exemplary embodiments is to explain the specific principles of the invention and its practical applications, so that those skilled in the art can implement and utilize the various different exemplary embodiments of the invention, as well as various different selections and changes. The scope of the invention is intended to be defined by the claims and their equivalents.

Claims

1. A traffic replay method, characterized in that, The method includes: Obtaining initial basic information of network traffic, where the initial basic information includes various traffic data at multiple moments; Based on the initial basic information, determining the timing information of each traffic data in the network traffic, and the initial service information of the initial server and the initial client; Based on the initial service information, allocating a target server for each traffic data, and establishing a service correspondence between the target server and the initial server; Based on the initial service information and the service correspondence, allocating a target client for each traffic data, and establishing a customer service correspondence between the target client and the target server; According to the customer service correspondence and the timing information, replaying each traffic data between the target client and the target server.

2. The method according to claim 1, wherein The determining, based on the initial basic information, the timing information of each traffic data in the network traffic, and the initial service information of the initial server and the initial client includes: Based on the initial basic information, performing customer service pair parsing on the network traffic to determine multiple traffic data, and the IP address and port of the initial server corresponding to each traffic data, and the IP address and port of the initial client, and using the IP address and port of the initial server and the IP address and port of the initial client of each traffic data as the initial service information of the initial server and the initial client of each traffic data; Based on the initial basic information and the multiple traffic data, obtaining the traffic time of each traffic data; Based on the traffic time of the multiple traffic data, determining the timing information of each traffic data.

3. The method according to claim 1, characterized in that, The allocating a target server for each traffic data based on the initial service information, and establishing a service correspondence between the target server and the initial server includes: Based on the initial service information, determining the first quantity of different initial servers and the second quantity of the ports of the initial servers; Based on the first quantity and the different initial servers, determining the service of the current machine; Based on the IP address, port information of the current machine, and the second quantity, starting the service, using the service as the target server, and establishing a correspondence between the IP address and port of the target server and the IP address and port of the initial server, and using this correspondence as the service correspondence.

4. The method according to claim 1, wherein The allocating a target server for each traffic data based on the initial service information, and establishing a service correspondence between the target server and the initial server includes: Classifying and reorganizing the traffic data according to different initial servers; Allocating the same service on the current machine for the traffic data with the same initial server, so that each traffic data corresponds to a service; Based on the IP address and port information of the current machine, starting the service, using the service as the target server, and establishing a correspondence between the IP address and port of the target server and the IP address and port of the initial server, and using this correspondence as the service correspondence.

5. The method according to claim 1, characterized in that Based on the initial service information and the service correspondence, allocating a target client for each traffic data and establishing a customer service correspondence between the target client and the target server includes: Based on the initial service information, allocating the traffic data in groups, and allocating target clients at different addresses and ports of target clients to each traffic data in units of groups; Based on the allocation results of each traffic data and the initial service information, determining the IP address and port of the initial server corresponding to the address and port of each target client; Based on the address and port of each target client and the service correspondence, determining the correspondence between the IP address and port of the target client and the IP address and port of the target server, and using this correspondence as the customer service correspondence.

6. The method according to claim 1, characterized in that, Replaying each traffic data between the target client and the target server according to the customer service correspondence and the timing information includes: Based on the customer service correspondence, determining the address and port of the target server to which each traffic data is to be connected and the address and port of the target client; According to the timing information of each traffic data, controlling each traffic data to be replayed between the address and port of the target server to which it is to be connected and the address and port of the target client.

7. A traffic replay device, characterized in that, The apparatus includes: An acquisition unit configured to acquire initial basic information of network traffic, where the initial basic information includes various traffic data at multiple moments; A determination unit configured to determine the timing information of each traffic data, the initial service information of the initial server and the initial client in the network traffic based on the initial basic information; A service allocation unit configured to allocate a target server for each traffic data based on the initial service information and establish a service correspondence between the target server and the initial server; A customer allocation unit configured to allocate a target client for each traffic data based on the initial service information and the service correspondence and establish a customer service correspondence between the target client and the target server; A replay unit configured to replay each traffic data between the target client and the target server according to the customer service correspondence and the timing information.

8. A traffic replay system, characterized in that, The system includes: Multiple traffic subsystems for providing initial basic information of network traffic, where the initial basic information includes various traffic data at multiple moments, and each traffic data in the various traffic data is provided by one traffic subsystem; The replay subsystem is used to obtain the initial basic information from the multiple traffic subsystems; based on the initial basic information, determine the timing information of each traffic data in the network traffic, and the initial service information of the initial server and the initial client; based on the initial service information, allocate a target server for each traffic data, and establish a service correspondence relationship between the target server and the initial server; based on the initial service information and the service correspondence relationship, allocate a target client for each traffic data, and establish a customer service correspondence relationship between the target client and the target server; according to the customer service correspondence relationship and the timing information, replay each traffic data between the target client and the target server.

9. An electronic device, characterized in that, It includes: At least one processor; And A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method according to any one of claims 1-6.

10. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to execute the method according to any one of claims 1-6.

Citation Information

Patent Citations

  • Traffic playback method and device, electronic equipment and storage medium

    CN110912783A

  • Network traffic playback method and device, medium and electronic equipment

    CN115484209A

  • Traffic playback method and device, electronic equipment and storage medium

    CN115883687A

  • Replaying captured network traffic

    US20120084605A1

  • Method for fowarding data, device, storage medium and data transmission system

    US20230239358A1