Traffic replay method and device, system, electronic device, and computer storage medium
By obtaining the initial basic information of network traffic, determining the timing and service information, and allocating target servers and clients, the problem of traffic replay in multi-port, multi-service network environments in the existing technology is solved, and multi-service and multi-port collaborative replay is achieved, thereby improving the accuracy and reliability of network behavior simulation and traffic testing.
Patent Information
- Application Number
- CN202510734220.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-04
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2045-06-04
AI Technical Summary
Existing technologies cannot effectively handle complex network environments with multiple ports and multiple services interacting simultaneously in real network environments, resulting in one-sided and incomplete traffic analysis. It is difficult to accurately reproduce the time series and interaction logic of the original traffic, affecting the accuracy and reliability of the test results.
A traffic replay method is provided. By obtaining the initial basic information of network traffic, determining the timing information and service information, allocating the target server and client, establishing a corresponding relationship, and replaying the traffic data between the target client and server, multi-service and multi-port collaborative replay is achieved, and timing and multi-stream are precisely controlled.
It achieves accurate replay of network traffic between the target client and server, improves the accuracy and reliability of network behavior simulation, enhances the accuracy and reliability of traffic testing, and can better simulate and replicate various network communication scenarios.
Smart Images

Figure CN120263667B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of computer technology, and in particular relates to technical fields such as network security and network testing, and more particularly to a traffic replay method and device, system, electronic device, and computer-readable storage medium. Background Art
[0002] In the current field of network usage analysis and testing, traffic capture and replay technology is an important means of evaluating network performance, detecting security vulnerabilities, and reproducing network issues. Existing technologies typically focus on traffic capture and replay on a single server. This method monitors data flows on a specific port or service, stores the captured traffic data in a file, and then replays it in the same or similar environment to simulate the original network behavior.
[0003] In a real network environment, it is sometimes impossible to reproduce the same client, and the traffic needs to be reproduced on other client, or multiple services and multiple ports need to collaborate to complete traffic replay. However, this single-server traffic capture and playback technology has obvious limitations.
[0004] The information disclosed in this background technology section is only intended to enhance understanding of the overall background of the invention and should not be regarded as an admission or any form of suggestion that the information constitutes the prior art already known to a person skilled in the art. Summary of the Invention
[0005] The purpose of the present disclosure is to solve the technical problem of limitations in traffic capture and playback on a single server, and to provide a traffic replay method and device, system, electronic device, and computer-readable storage medium.
[0006] A first aspect of the present disclosure provides a traffic replay method, which includes: obtaining initial basic information of network traffic, the initial basic information including multiple traffic data at multiple moments; determining, based on the initial basic information, the timing information of each traffic data in the network traffic, and the initial service information of the initial server and the initial client; assigning a target server to each traffic data based on the initial service information, and establishing a service correspondence between the target server and the initial server; assigning a target client to each traffic data based on the initial service information and the service correspondence, and establishing a customer service correspondence between the target client and the target server; and replaying each traffic data between the target client and the target server according to the customer service correspondence and the timing information.
[0007] A second aspect of the present disclosure provides a traffic replay device, which includes: an acquisition unit, configured to acquire initial basic information of network traffic, the initial basic information including multiple traffic data at multiple moments; a determination unit, configured to determine, based on the initial basic information, the timing information of each traffic data in the network traffic, the initial service information of the initial server and the initial client; a service allocation unit, configured to allocate a target server to each traffic data based on the initial service information, and establish a service correspondence between the target server and the initial server; a client allocation unit, configured to allocate a target client to each traffic data based on the initial service information and the service correspondence, and establish a customer service correspondence between the target client and the target server; a replay unit, configured to replay each traffic data between the target client and the target server according to the customer service correspondence and the timing information.
[0008] According to a third aspect, a traffic replay system is provided, which includes: multiple traffic subsystems for providing initial basic information of network traffic, wherein the initial basic information includes multiple traffic data at multiple moments, and each type of traffic data is provided by a traffic subsystem; a replay subsystem for obtaining the initial basic information from the multiple traffic subsystems; based on the initial basic information, determining the timing information of each traffic data in the network traffic, and the initial service information of the initial server and the initial client; based on the initial service information, assigning a target server to each traffic data, and establishing a service correspondence between the target server and the initial server; based on the initial service information and the service correspondence, assigning a target client to each traffic data, and establishing a customer service correspondence between the target client and the target server; and replaying each traffic data between the target client and the target server according to the customer service correspondence and the timing information.
[0009] According to a fourth aspect, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method described in any implementation manner of the first aspect.
[0010] According to a fifth aspect, a non-transitory computer-readable storage medium storing computer instructions is provided, where the computer instructions are used to cause a computer to execute the method as described in any implementation of the first aspect.
[0011] The traffic replay method and device provided by the embodiments of the present disclosure first obtain the initial basic information of the network traffic, which includes multiple traffic data at multiple moments; secondly, based on the initial basic information, determine the timing information of each traffic data in the network traffic, the initial service information of the initial server and the initial client; thirdly, based on the initial service information, assign a target server to each traffic data, and establish a service correspondence between the target server and the initial server; thirdly, based on the initial service information and the service correspondence, assign a target client to each traffic data, and establish a customer service correspondence between the target client and the target server; finally, based on the customer service correspondence and the timing information, replay each traffic data between the target client and the target server. Thus, the replay of the network traffic between the target client and the target server is realized, and multi-service and multi-port collaborative replay can also be performed on the target client and the target server, realizing precise control of timing and multi-stream, and being able to more accurately simulate, replicate and replay multiple network communication scenarios, thereby improving the accuracy and reliability of network behavior simulation; when the traffic data is tested on the target client and the target server, the accuracy and reliability of the traffic test are improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Figure 1 is a flow chart of an embodiment of a traffic replay method according to the present disclosure;
[0013] Figure 2 It is a structural diagram of traffic data replay in the present disclosure;
[0014] Figure 3 It is a mapping relationship diagram of the initial service information in this disclosure;
[0015] Figure 4 is a structural diagram of an embodiment of a traffic replay device according to the present disclosure;
[0016] Figure 5 is a structural diagram of an embodiment of a traffic replay system according to the present disclosure;
[0017] Figure 6 It is a block diagram of an electronic device used to implement the traffic replay method of an embodiment of the present disclosure. DETAILED DESCRIPTION
[0018] Unless expressly stated otherwise, throughout the specification and claims, the term "comprise" or variations such as "include" or "comprising", etc., will be understood to include the stated components or parts but not to exclude other components or parts.
[0019] The technical solutions of the present invention are described below by means of specific embodiments. It should be understood that one or more steps mentioned in the present invention do not exclude the presence of other methods and steps before and after the combination step, or other methods and steps may be inserted between these explicitly mentioned steps. It should also be understood that these examples are only used to illustrate the present invention and are not used to limit the scope of the present invention. Unless otherwise specified, the numbering of each method step is only for the purpose of identifying each method step, and does not limit the order of arrangement of each method or the scope of implementation of the present invention. Changes or adjustments in their relative relationships can also be regarded as the scope of implementation of the present invention without substantial changes in the technical content.
[0020] The sources of the raw materials and instruments used in the examples are not particularly limited and can be purchased from the market or prepared according to conventional methods known to those skilled in the art.
[0021] Traditional technologies typically focus on traffic capture and replay on a single server. This method listens to the data flow of a specific port or service, stores the captured traffic data as a file, and then replays it in the same or similar environment to simulate the original network behavior.
[0022] Current traffic capture and playback technology can simulate network traffic from a single server. However, in a real network environment, a real network communication scenario often requires the coordination of multiple services and multiple ports. This requires not only the coordination of traffic from multiple ports but also the timing relationship between them. This single-server traffic capture and playback technology has obvious limitations: it cannot effectively handle complex network environments where multiple ports and multiple services interact simultaneously, such as traffic occurring at the same time, resulting in one-sided and incomplete traffic analysis. Secondly, due to the lack of coordinated and time-sequential processing capabilities for multiple terminals and multiple flows, existing technologies have difficulty accurately reproducing the time series and interaction logic of the original traffic during playback, thus affecting the accuracy and reliability of test results.
[0023] Furthermore, traditional technologies lack corresponding multi-stream management and timing control, resulting in inaccuracies when simulating typical network transmission scenarios such as traffic using the FTP protocol to upload files (requiring multi-port functionality); scenarios where a Trojan goes online and maintains regular communication with a cloud server (requiring strong timing control); and attack traffic using the SMB protocol to move laterally against Windows machines within the intranet (which has both multi-port and timing).
[0024] In order to solve the problem of reproducing multi-port and multi-service network traffic in the existing technology, the present invention provides a traffic replay method. Figure 1 A flow chart 100 of an embodiment of a traffic replay method is shown, and the traffic replay method includes the following steps:
[0025] Step 101: Obtain initial basic information of network traffic.
[0026] In this embodiment, the initial basic information includes multiple traffic data at multiple times, that is, the network traffic includes: multiple types of traffic, each type of traffic has corresponding traffic data, and the multiple traffic data can be the amount of data transmitted by the initial server and the initial client at multiple times, and the initial server and the initial client can both be multiple.
[0027] In this embodiment, the initial basic information may be recorded in the original file (such as Figure 2 By reading the original file, the initial basic information can be obtained. The initial basic information may include: the protocol of the network traffic, the address and port of the client of the corresponding protocol data, the address and port of the server, as well as the transmitted traffic data and time.
[0028] Step 102: Based on the initial basic information, determine the time sequence information of each flow data in the network flow, and the initial service information of the initial server and the initial client.
[0029] In this embodiment, the content of the initial basic information of network traffic may be relatively messy. In order to better sort out the traffic information, the file recording the initial basic information can be parsed first, such as by Figure 2 The Parser parsing class shown parses the pcap file, organizes the traffic data in the initial basic information into a standardized formatted structure with multiple server ends as dimensions, classifies the standardized formatted structure into two dimensions: time series and service ports, and establishes a mapping relationship between each traffic data and its corresponding time series and service port.
[0030] In this embodiment, the above step 102 includes: determining the flow data and time of the network flow based on the initial basic information, sorting the flow data based on the time of the flow data, and obtaining the timing information of the flow data; clustering the flow data belonging to the same server and server port, client and client port together as the current class flow cluster, sorting the flow data in the flow cluster based on the time of the flow data in the flow cluster, obtaining the sending order of the flow data in the flow cluster, taking the earliest time in the flow cluster as the reference time, determining the time difference between the time of each flow data in the flow cluster and the basic time, and associating the sending order, time difference and reference time of each flow data with the flow data. This association relationship is Figure 3 The mapping in points to the traffic data, and uses the traffic cluster, the sending order of the traffic data, the time difference, and the reference time as the initial service information of the traffic data.
[0031] Step 103: Based on the initial service information, a target server is assigned to each flow data, and a service correspondence relationship is established between the target server and the initial server.
[0032] In this embodiment, the service correspondence is the relationship between the service of the target server and the service of the initial server, such as the target server A corresponds to the initial server C, the IP address A11 of the target server A corresponds to the IP address C34 of the initial server C, and the port A32 of the target server A corresponds to the port C52 of the initial server C.
[0033] In this embodiment, the initial service information includes the server, server port, client, and client port of the traffic data. Based on the server and server port in the initial service information, the same service can be allocated to the traffic data of the same initial server on the current machine, and the service can be started according to the port and IP address on the current machine to obtain the target server, establish the relationship between the IP address and port of the target server of the same traffic data and the IP address and port of the initial server, and use this relationship as the service correspondence between the target server and the initial server.
[0034] Step 104 : Based on the initial service information and the service correspondence, a target client is assigned to each flow data, and a customer service correspondence is established between the target client and the target server.
[0035] In this embodiment, the initial service information is used to indicate the relationship between the service of the initial server and the service of the initial client, such as the correspondence between the IP address and port of the initial client of the traffic data and the IP address and port of the initial server of the traffic data. The service correspondence is used to indicate the relationship between the IP address and port of the target server of the traffic data and the IP address and port of the initial server.
[0036] In this embodiment, the above step 104 includes: determining the number of target clients based on the IP address and port of the target server in the service correspondence. At this time, the same number of clients can be directly determined according to the number of target servers in the service correspondence; determining the port of the target client based on the IP address and port of the initial client in the initial service information. At this time, the same number of ports as the initial clients can be directly allocated to the target client according to the port of the current machine; after determining the number and port of the target clients, determining the IP address of the target client based on the IP address of the current machine, establishing a connection between the target clients and the target clients according to the service correspondence and the information of the target clients determined above, and establishing a relationship between the IP address and port of the target server of the traffic data and the IP address and port of the target server, and using this relationship as the customer service correspondence.
[0037] Step 105: replay various traffic data between the target client and the target server according to the customer service correspondence and the timing information.
[0038] In this embodiment, based on the timing information of each flow data, the transmission time of each flow data between the target client and the target server is determined. When the flow data is replayed, new flow data corresponding to the flow data can be transmitted between the target client and the target server according to the transmission time.
[0039] In this embodiment, each flow data in the network flow is data that carries the information of the initial server and the initial client. In order to better achieve the replay of the flow data, it is necessary to replace the initial server information (such as the IP address and port of the initial server) carried in each flow data with the target server information (such as the IP address and port of the target server), and replace the initial client information (such as the IP address and port of the initial client) carried with the target client information (such as the IP address and port of the target client) to form new flow data, and control the target server and target client to transmit the new flow data.
[0040] The traffic replay method provided by the embodiment of the present disclosure first obtains the initial basic information of the network traffic, and the initial basic information includes multiple traffic data at multiple moments; secondly, based on the initial basic information, determines the timing information of each traffic data in the network traffic, the initial service information of the initial server and the initial client; thirdly, based on the initial service information, assigns a target server to each traffic data, and establishes a service correspondence between the target server and the initial server; thirdly, based on the initial service information and the service correspondence, assigns a target client to each traffic data, and establishes a customer service correspondence between the target client and the target server; finally, based on the customer service correspondence and the timing information, replicates and replays each traffic data between the target client and the target server. Thus, the replay of the network traffic between the target client and the target server is realized, and multi-service and multi-port collaborative replay can also be performed on the target client and the target server, realizing precise control of timing and multi-stream, and being able to more accurately simulate, replicate and replay multiple network communication scenarios, thereby improving the accuracy and reliability of network behavior simulation; when the traffic data is tested on the target client and the target server, the accuracy and reliability of the traffic test are improved.
[0041] Optionally, the replayed traffic data can be data under various test scenarios. The traffic data can help developers and testers better understand the behavior of the system under specific conditions. The above-mentioned traffic replay method also includes: when replaying each traffic data between the target client and the target server, testing the traffic between the target client and the target server in different scenarios to obtain test results, where the different scenarios may include: file data transmission scenarios based on the FTP (File Transfer Protocol) protocol under multiple ports, scenarios in which a Trojan horse goes online and maintains regular communication with the cloud server, and scenarios in which a specific protocol (such as the SMB protocol) is used periodically under multiple ports to perform lateral movement attacks on machines in the intranet.
[0042] In some optional methods of the present disclosure, the above-mentioned determination of the timing information of each flow data in the network flow, the initial service information of the initial server and the initial client based on the initial basic information includes: based on the initial basic information, performing customer service parsing on the network traffic, determining multiple flow data and the IP address and port of the initial server, the IP address and port of the initial client corresponding to each flow data, and using the IP address and port of the initial server, the IP address and port of the initial client of each flow data as the initial service information of the initial server and the initial client of each flow data; obtaining the flow time of each flow data based on the initial basic information and multiple flow data; and determining the timing information of each flow data based on the flow time of multiple flow data.
[0043] In this optional implementation, if Figure 3 As shown in the figure, the NetFlowCollections class categorizes and organizes multiple flow data sets, recording flow information in two different dimensions: time series and initial server port information. The time series and multi-server information merely record pointers to related information and the location of the flow data.
[0044] In this optional implementation, traffic time includes: packet capture time, packet capture file time, request phase time, timestamp format and protocol specifications. Timing information is the sorting order information of traffic time for multiple traffic data sets. Different portions of traffic time can be sorted to obtain timing information based on the requirements of different test scenarios. For example, for a test scenario involving periodic communication, determining the timing information for each traffic data set based on the traffic time of multiple traffic data sets includes sorting the multiple traffic data sets based on the packet capture time of each of the multiple traffic data sets to obtain the timing information for each of the multiple traffic data sets.
[0045] This optional implementation provides a method for determining the timing information and initial service information of traffic data, which determines the initial service information by performing customer service analysis on the network traffic; determines the timing information of the traffic data by the traffic time of the traffic data, and completely records the timing information of multiple traffic data in the network traffic, providing a reliable implementation method for obtaining the initial service information and timing information.
[0046] In some optional implementations of the present disclosure, the above-mentioned allocating a target server end to each traffic data based on the initial service information and establishing a service correspondence between the target server end and the initial server end includes: determining a first number of different initial server ends and a second number of ports of the initial server end based on the initial service information; determining the service of the current machine based on the first number and the different initial server ends; starting the service based on the IP address and port information of the current machine and the second number, taking the service as the target server end, establishing a correspondence between the IP address and port of the target server end and the IP address and port of the initial server end, and taking the correspondence as the service correspondence.
[0047] In this optional implementation, the first number of different initial server terminals refers to the number of different initial server terminals. For example, if there are 5 initial server terminals in total and 2 of the 5 initial server terminals are the same, then the number of different initial server terminals is 4. Through the first number and 5 initial server terminals, 4 services can be set on the current machine, where each service corresponds to an initial server terminal.
[0048] In this optional implementation, the current machine can be a physical machine or a virtual machine. When the service is started on the current machine, a port that meets the second quantity requirement will be configured for the service based on the IP address and port of the current machine, and the configured port will be monitored in real time after the service is started.
[0049] The method for establishing a service correspondence relationship provided by this optional implementation method determines the first number of different initial service terminals based on the initial service information, determines the target service terminal based on the first number, and establishes a service correspondence relationship, providing a reliable implementation method for establishing a service correspondence relationship.
[0050] In some optional implementations of the present disclosure, the above-mentioned allocating a target server to each traffic data based on the initial service information and establishing a service correspondence between the target server and the initial server includes: classifying and reorganizing the traffic data according to different initial server ends; allocating the same service on the current machine to the traffic data of the same initial server end, so that each traffic data corresponds to one service; starting the service based on the IP address and port information of the current machine, using the service as the target server end, establishing a correspondence between the IP address and port of the target server end and the IP address and port of the initial server end, and using the correspondence as the service correspondence.
[0051] In this optional implementation, if Figure 2 As shown in the figure, the ServerDispatcher class is a custom server dispatch management class. Its function is to classify and reorganize the traffic data according to different servers based on the initial service information recorded in NetFlowCollections, and assign each group of traffic from the same server to the same service server, and start these service servers according to the new IP address and port information of the current machine, as shown in the figure. Figure 2 There are three target servers, namely Server_1, Server_2, and Server_3, and a mapping relationship is made between each set of service information and the re-listening address information of the current server (for example, the IP address of the initial server of the traffic data is 192.168.1.1 and the port is 8080, which corresponds to the IP address of the current target server is 10.0.0.1 and the port is 9090). The mapping relationship information is saved to obtain the service correspondence.
[0052] In this optional implementation, the current machine refers to the machine where the service is located, and the current machine can be an actual physical machine or a virtual machine.
[0053] This optional implementation provides a method for establishing service correspondences by grouping traffic data and assigning the same service to traffic data from the same initial server. Based on the IP address and port information of the current machine, the service is started, the target server is determined, and a service correspondence is established, providing another reliable implementation method for establishing service correspondences.
[0054] In some optional implementations of the present disclosure, the above-mentioned allocation of target clients to each traffic data based on the initial service information and service correspondence, and establishment of a customer service correspondence between the target client and the target server include: based on the initial service information, allocating the traffic data by group, and allocating target clients and ports of target clients with different addresses to each traffic data in groups; based on the allocation results of each traffic data and the initial service information, determining the IP address and port of the initial server corresponding to the address and port of each target client; based on the address and port of each target client and the service correspondence, determining the correspondence between the IP address and port of the target client and the IP address and port of the target server, and using the correspondence as the customer service correspondence.
[0055] In this optional implementation, if Figure 2 As shown, the ClientDispatcher class is used for custom client distribution management classes. Its functions include loading data and distributing target clients, as well as replaying traffic data on the target client and target server.
[0056] Among them, loading data and assigning target clients include: according to the initial service information recorded in NetFlowCollections and the service correspondence input by the ServerDispatcher class, the traffic is distributed by group and each target client with different addresses is assigned, such as Figure 2 As shown, there are three target clients, namely Client_1, Client_2, and Client_3. Disassembling the client-client correspondence, each target client needs to connect to the target server's IP address, so that the target client can send data traffic to the target server. It should be noted that each target client is connected through its own connection (such as Figure 2 The target client Client_1 connects to socket_1_1, socket_1_2, socket_1_3; Client_2 connects to socket_2_1, socket_2_2, socket_2_3; Client_3 connects to socket_3_1) and connects to the corresponding target server, where the connection is a communication connection based on IP address and port.
[0057] This optional implementation method provides a method for establishing a customer service correspondence relationship. Based on the initial service information, the traffic data is distributed by group, and target clients with different addresses and ports of the target clients are distributed to each traffic data in groups; based on the distribution results of each traffic data and the initial service information, the IP address and port of the initial server corresponding to the address and port of each target client are determined; based on the address and port of each target client and the service correspondence relationship, the correspondence between the IP address and port of the target client and the IP address and port of the target server is determined, and the correspondence relationship is used as the customer service correspondence relationship, providing a reliable implementation method for obtaining the customer service correspondence relationship.
[0058] In some optional implementations of the present disclosure, the above-mentioned replaying of each traffic data between the target client and the target server based on the customer service correspondence and timing information includes: determining the address and port of the target server to be connected, and the address and port of the target client to which each traffic data is to be connected based on the customer service correspondence; and controlling each traffic data to be replayed between the address and port of the target server to be connected, and the address and port of the target client according to the timing information of each traffic data.
[0059] In this optional implementation, the ClientDispatcher class initiates the replay execution. After starting the replay, it controls the timing and order of the replay for each target client based on the timing information of the NetFlowCollections, thus uniformly managing and scheduling the order of the replayed data traffic to replicate the timing information of the network traffic.
[0060] The method for replaying traffic data provided by this optional implementation method determines the address and port of the target server to be connected, and the address and port of the target client, based on the customer service correspondence relationship; according to the timing information of each traffic data, each traffic data is controlled to be replayed between the address and port of the target server to be connected, and the address and port of the target client, and accurately replays and replicates traffic with strict multi-port timing, providing a reliable implementation method for the replay of traffic data.
[0061] Further references Figure 4 As an implementation of the methods shown in the above figures, the present disclosure provides an embodiment of a traffic replay device, which is similar to Figure 1 Corresponding to the method embodiment shown, the device can be specifically applied to various electronic devices.
[0062] like Figure 4As shown, the traffic replay device 400 provided in this embodiment includes: an acquisition unit 401, a determination unit 402, a service allocation unit 403, a client allocation unit 404, and a replay unit 405. The acquisition unit 401 can be configured to acquire initial basic information of network traffic, which includes multiple types of traffic data at multiple time points. The determination unit 402 can be configured to determine, based on the initial basic information, the timing information of each traffic data item in the network traffic, and the initial service information of the initial server and initial client. The service allocation unit 403 can be configured to assign a target server to each traffic data item based on the initial service information, and establish a service correspondence between the target server and the initial server. The client allocation unit 404 can be configured to assign a target client to each traffic data item based on the initial service information and the service correspondence, and establish a customer service correspondence between the target client and the target server. The replay unit 405 can be configured to replay each traffic data item between the target client and the target server based on the customer service correspondence and the timing information.
[0063] In this embodiment, the specific processing of the traffic replay device 400: the acquisition unit 401, the determination unit 402, the service allocation unit 403, the customer allocation unit 404, and the replay unit 405 and the technical effects thereof can be referred to respectively. Figure 1 The relevant descriptions of step 101, step 102, step 103, step 104 and step 105 in the corresponding embodiment are not repeated here.
[0064] In one embodiment of the present disclosure, the above-mentioned determination unit 402 is configured to: based on the initial basic information, perform customer service analysis on the network traffic, determine multiple traffic data and the IP address and port of the initial server, the IP address and port of the initial client corresponding to each traffic data, and use the IP address and port of the initial server, the IP address and port of the initial client of each traffic data as the initial service information of the initial server and the initial client of each traffic data; based on the initial basic information and multiple traffic data, obtain the traffic time of each traffic data; based on the traffic time of multiple traffic data, determine the timing information of each traffic data.
[0065] In one embodiment of the present disclosure, the above-mentioned service allocation unit 403 is configured to: determine the first number of different initial server terminals and the second number of ports of the initial server terminals based on the initial service information; determine the service of the current machine based on the first number and the different initial server terminals; start the service based on the IP address, port information and the second number of the current machine, use the service as the target server, establish a correspondence between the IP address and port of the target server and the IP address and port of the initial server, and use the correspondence as the service correspondence.
[0066] In one embodiment of the present disclosure, the above-mentioned service allocation unit 403 is configured to: classify and reorganize the traffic data according to different initial server terminals; allocate the same service on the current machine to the traffic data of the same initial server terminal, so that each traffic data corresponds to one service; based on the IP address and port information of the current machine, start the service, use the service as the target server terminal, establish a correspondence between the IP address and port of the target server terminal and the IP address and port of the initial server terminal, and use this correspondence as the service correspondence.
[0067] In one embodiment of the present disclosure, the above-mentioned customer allocation unit 404 is configured to: allocate traffic data by group based on the initial service information, and allocate target clients and ports of target clients with different addresses to each traffic data in groups; determine the IP address and port of the initial server corresponding to the address and port of each target client based on the allocation result of each traffic data and the initial service information; determine the correspondence between the IP address and port of the target client and the IP address and port of the target server based on the address and port and service correspondence of each target client, and use the correspondence as the customer service correspondence.
[0068] In one embodiment of the present disclosure, the above-mentioned replay unit 405 is configured to: determine the address and port of the target server to be connected, and the address and port of the target client to which each traffic data is to be connected based on the customer service correspondence relationship; and control each traffic data to be replayed between the address and port of the target server to be connected, and the address and port of the target client according to the timing information of each traffic data.
[0069] In the traffic replay device provided in the embodiment of the present disclosure, first, the acquisition unit 401 acquires the initial basic information of the network traffic, and the initial basic information includes a variety of traffic data at multiple moments; secondly, the determination unit 402 determines the timing information of each traffic data in the network traffic, the initial service information of the initial server and the initial client based on the initial basic information; thirdly, the service allocation unit 403 allocates a target server to each traffic data based on the initial service information, and establishes a service correspondence between the target server and the initial server; thirdly, the client allocation unit 404 allocates a target client to each traffic data based on the initial service information and the service correspondence, and establishes a customer service correspondence between the target client and the target server; finally, the replay unit 405 replays each traffic data between the target client and the target server according to the customer service correspondence and the timing information. As a result, network traffic can be replayed between the target client and the target server, and multi-service and multi-port collaborative replay can be performed on the target client and the target server, achieving precise control of timing and multi-streams. It can more accurately simulate, replicate and replay various network communication scenarios, improving the accuracy and reliability of network behavior simulation; when testing traffic data on the target client and the target server, the accuracy and reliability of traffic testing are improved.
[0070] Further references Figure 5 As an implementation of the methods shown in the above figures, the present disclosure provides an embodiment of a traffic replay system. Figure 1 The method embodiment shown corresponds to the embodiment shown.
[0071] like Figure 5 As shown, the traffic replay system 500 provided in this embodiment includes: multiple traffic subsystems 501 and a replay subsystem 502.
[0072] Multiple traffic subsystems 501 are used to provide initial basic information of network traffic, wherein the initial basic information includes multiple traffic data at multiple moments, and each type of traffic data is provided by a traffic subsystem.
[0073] In this embodiment, traffic subsystem 501 can be a device that transmits traffic in a network, such as a client or server. The traffic subsystem includes an initial client and an initial server, which are the devices that actually transmit traffic. Multiple traffic subsystems can be multiple client pairs consisting of an initial client and an initial server. The time of traffic data sent by two different client pairs can be the same or different.
[0074] The replay subsystem 502 is used to obtain initial basic information from multiple traffic subsystems; based on the initial basic information, determine the timing information of each traffic data in the network traffic, the initial service information of the initial server and the initial client; based on the initial service information, assign a target server to each traffic data, and establish a service correspondence between the target server and the initial server; based on the initial service information and the service correspondence, assign a target client to each traffic data, and establish a customer service correspondence between the target client and the target server; according to the customer service correspondence and the timing information, replay each traffic data between the target client and the target server.
[0075] In this embodiment, in the traffic replay system 500, the specific processing of the replay subsystem 502 and the technical effects thereof can be referred to in Figure 1 The relevant descriptions of step 101, step 102, step 103, step 104 and step 105 in the corresponding embodiment are not repeated here.
[0076] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0077] Figure 6 A schematic block diagram of an example electronic device 600 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their modes are provided for example only and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0078] like Figure 6 As shown, device 600 includes a computing unit 601, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 602 or a computer program loaded from a storage unit 608 into a random access memory (RAM) 603. RAM 603 may also store various programs and data required for the operation of device 600. Computing unit 601, ROM 602, and RAM 603 are interconnected via a bus 604. An input / output (I / O) interface 605 is also connected to bus 604.
[0079] Various components in device 600 are connected to I / O interface 605, including an input unit 606, such as a keyboard, mouse, etc.; an output unit 607, such as various types of displays, speakers, etc.; a storage unit 608, such as a magnetic disk, optical disk, etc.; and a communication unit 609, such as a network card, modem, wireless communication transceiver, etc. The communication unit 609 allows device 600 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0080] The computing unit 601 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the computing unit 601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 601 performs the various methods and processes described above, such as the traffic replay method. For example, in some embodiments, the traffic replay method may be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 608. In some embodiments, part or all of the computer program may be loaded and / or installed onto the device 600 via the ROM 602 and / or the communication unit 609. When the computer program is loaded into the RAM 603 and executed by the computing unit 601, one or more steps of the traffic replay method described above may be performed. Alternatively, in other embodiments, the computing unit 601 may be configured to perform the traffic replay method in any other suitable manner (e.g., via firmware).
[0081] Various embodiments of the systems and techniques described above can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0082] The program code for implementing the methods of the present disclosure may be written in any combination of one or more programming languages. Such program code may be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable traffic replay device, such that when the program code is executed by the processor or controller, the modes / operations specified in the flowcharts and / or block diagrams are implemented. The program code may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0083] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of machine-readable storage media may include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fibers, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0084] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0085] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., as an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with embodiments of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.
[0086] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved. This is not limited herein.
[0087] The foregoing descriptions of specific exemplary embodiments of the present invention are for purposes of illustration and description. These descriptions are not intended to limit the invention to the precise forms disclosed, and it is apparent that many variations and modifications are possible in light of the foregoing teachings. The exemplary embodiments have been selected and described for the purpose of explaining the specific principles of the invention and their practical application, thereby enabling those skilled in the art to realize and utilize a variety of exemplary embodiments of the invention and various options and modifications. The scope of the invention is intended to be defined by the claims and their equivalents.
Claims
1. A traffic replay method, characterized in that: The method comprises: Obtaining initial basic information of network traffic, wherein the initial basic information includes various traffic data at multiple times; Based on the initial basic information, determine the timing information of each flow data in the network flow, the initial service information of the initial server and the initial client; the method of determining the timing information of each flow data in the network flow, the initial service information of the initial server and the initial client based on the initial basic information includes: determining the flow data and time in the network flow based on the initial basic information, and sorting each flow data based on the time of each flow data; clustering the flow data belonging to the same server and server port, client and client port together as the current class flow cluster, and sorting the flow data in the flow cluster based on the time of the flow data Sequence the traffic data in the traffic cluster to obtain the sending order of the traffic data in the traffic cluster, use the earliest time in the traffic cluster as the reference time, determine the time difference between the time of each traffic data in the traffic cluster and the reference time, associate the sending order, time difference, and reference time of each traffic data with the traffic data, and use the traffic cluster, the sending order, time difference, and reference time of the traffic data as the timing information of the traffic data; use the IP address and port of the initial server of each traffic data and the IP address and port of the initial client as the initial service information of the initial server and initial client of each traffic data; Based on the initial service information, assign a target server to each flow data, and establish a service correspondence between the target server and the initial server; Based on the initial service information and the service correspondence, assign a target client to each flow data, and establish a customer service correspondence between the target client and the target server; Replay each flow data between the target client and the target server according to the customer service correspondence relationship and the timing information.
2. The method according to claim 1, characterized in that The determining, based on the initial basic information, the time sequence information of each flow data in the network flow, the initial service information of the initial server and the initial client includes: Based on the initial basic information, the network traffic is parsed to determine a plurality of traffic data and the IP address and port of the initial server and the IP address and port of the initial client corresponding to each traffic data, and the IP address and port of the initial server and the IP address and port of the initial client of each traffic data are used as the initial service information of the initial server and the initial client of each traffic data; Based on the initial basic information and the plurality of flow data, obtaining flow time of each flow data; Based on the flow time of the plurality of flow data, time series information of each flow data is determined.
3. The method according to claim 1, characterized in that The allocating a target server to each flow data based on the initial service information and establishing a service correspondence between the target server and the initial server includes: Determining, based on the initial service information, a first number of different initial service terminals and a second number of ports of the initial service terminals; Determining a service of the current machine based on the first number and the different initial server ends; Based on the IP address, port information and the second quantity of the current machine, the service is started, the service is used as the target server, and a correspondence is established between the IP address and port of the target server and the IP address and port of the initial server, and the correspondence is used as the service correspondence.
4. The method according to claim 1, wherein The allocating a target server to each flow data based on the initial service information and establishing a service correspondence between the target server and the initial server includes: Classify and reorganize traffic data according to different initial servers; Assign the traffic data of the same initial server to the same service on the current machine, so that each traffic data corresponds to one service; Based on the IP address and port information of the current machine, the service is started, the service is used as the target server, and a correspondence is established between the IP address and port of the target server and the IP address and port of the initial server, and the correspondence is used as the service correspondence.
5. The method according to claim 1, characterized in that The allocating a target client to each flow data based on the initial service information and the service correspondence, and establishing a customer service correspondence between the target client and the target server includes: Based on the initial service information, the flow data is distributed by group, and a target client with a different address and a port of the target client is distributed to each flow data in a group unit; Based on the distribution results of each flow data and the initial service information, determining the IP address and port of the initial server corresponding to the address and port of each target client; Based on the address and port of each target client and the service correspondence, the correspondence between the IP address and port of the target client and the IP address and port of the target server is determined, and the correspondence is used as the customer service correspondence.
6. The method according to claim 1, characterized in that The replaying of each flow data between the target client and the target server according to the customer service correspondence relationship and the timing information includes: Based on the customer service correspondence, determine the address and port of the target server to be connected and the address and port of the target client to be connected for each flow data; According to the timing information of each flow data, each flow data is controlled to be replayed between the address and port of the target server to be connected and the address and port of the target client.
7. A traffic replay device, characterized in that: The device comprises: an acquiring unit configured to acquire initial basic information of network traffic, wherein the initial basic information includes a plurality of traffic data at a plurality of moments; The determining unit is configured to determine the timing information of each flow data in the network flow, the initial service information of the initial server and the initial client based on the initial basic information; the determining unit is further configured to: determine the flow data and time in the network flow based on the initial basic information, and sort the each flow data based on the time of each flow data; cluster the flow data belonging to the same server and server port, client and client port together as the current class flow cluster, sort the flow data in the flow cluster based on the time of the flow data in the flow cluster, obtain the sending order of the flow data in the flow cluster, use the earliest time in the flow cluster as the reference time, determine the time difference between the time of each flow data in the flow cluster and the reference time, associate the sending order, time difference and reference time of each flow data with the flow data, and use the class flow cluster, the sending order, time difference and reference time of the flow data as the timing information of the flow data; use the IP address and port of the initial server of each flow data, and the IP address and port of the initial client as the initial service information of the initial server and initial client of each flow data; A service allocation unit is configured to allocate a target service end to each flow data based on the initial service information, and establish a service correspondence relationship between the target service end and the initial service end; A client allocation unit is configured to allocate a target client to each flow data based on the initial service information and the service correspondence, and establish a customer service correspondence between the target client and the target server; The replay unit is configured to replay each flow data between the target client and the target server according to the customer service correspondence relationship and the timing information.
8. A traffic replay system, characterized in that: The system comprises: Multiple traffic subsystems, configured to provide initial basic information of network traffic, wherein the initial basic information includes multiple types of traffic data at multiple moments, each type of traffic data being provided by a traffic subsystem; A replay subsystem for obtaining the initial basic information from the multiple traffic subsystems; determining the timing information of each traffic data in the network traffic, the initial service information of the initial server and the initial client based on the initial basic information; allocating a target server to each traffic data based on the initial service information, and establishing a service correspondence between the target server and the initial server; allocating a target client to each traffic data based on the initial service information and the service correspondence, and establishing a customer service correspondence between the target client and the target server; replaying each traffic data between the target client and the target server according to the customer service correspondence and the timing information; determining the timing information of each traffic data in the network traffic, the initial service information of the initial server and the initial client based on the initial basic information includes: determining the network traffic based on the initial basic information; The flow data and time in the volume are sorted based on the time of each flow data; the flow data belonging to the same server and server port, client and client port are clustered together as the current class flow cluster, and the flow data in the flow cluster are sorted based on the time of the flow data in the flow cluster to obtain the sending order of the flow data in the flow cluster, and the earliest time in the flow cluster is used as the reference time to determine the time difference between the time of each flow data in the flow cluster and the reference time, and the sending order, time difference and reference time of each flow data are associated with the flow data, and the class flow cluster, the sending order, time difference and reference time of the flow data are used as the timing information of the flow data; the IP address and port of the initial server of each flow data, and the IP address and port of the initial client are used as the initial service information of the initial server and initial client of each flow data.
9. An electronic device, characterized in that: include: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 6.
10. A non-transitory computer-readable storage medium storing computer instructions, characterized in that: The computer instructions are used to enable the computer to execute the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Replaying captured network traffic
US20120084605A1