Mirror image traffic collection and analysis method and system based on ovs
Through the ovs flow table configuration and vxlan/gre tunnel, the traffic mirroring in the virtualized network is solved, and the complexity and inefficiency of network traffic management in traditional methods is achieved, and efficient traffic monitoring and security analysis is achieved.
Patent Information
- Application Number
- CN202510451254.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-07-04
AI Technical Summary
In a large-scale virtualization environment, traditional network traffic management methods are complex in configuration, poor in scalability and low in analysis efficiency, making it difficult for network administrators to monitor and analyze network traffic in real time and cannot respond to abnormal situations in a timely manner.
The ovs-based mirror traffic acquisition and analysis method is adopted to configure mirror traffic through the ovs flow table, and cross-node communication is realized in the virtualized network using VXLAN and Gre tunnels, and the traffic is mirrored to the destination acquisition machine for analysis, including the traffic mirror configuration module, the ovs flow table management module and the mirror traffic exit module, which supports port mirroring and streaming mirroring, and monitors and counts traffic information in real time.
It improves network traffic monitoring capabilities, reduces monitoring complexity and cost, enhances network security, can promptly detect and deal with potential security threats, and realizes effective mirroring and monitoring of traffic.
Smart Images

Figure CN120263679A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of traffic monitoring, and particularly to a method and system for mirror traffic collection and analysis based on ovs. Background Art
[0002] With the development of cloud computing and virtualization technologies, the scale and complexity of data centers and enterprise networks have been continuously increasing. The application of virtualization technologies such as virtual machines (VMs) and containers has made network traffic management more important. Traditional network traffic management methods often face problems such as complex configuration, poor scalability, and low analysis efficiency when dealing with large-scale virtualized environments. This has made it difficult for network administrators to monitor and analyze network traffic in real time, and thus unable to respond promptly to abnormal situations in the network. Summary of the Invention
[0003] The purpose of the present invention is to provide a method and system for mirror traffic collection and analysis based on ovs, which collect and analyze the east-west and north-south traffic of virtual machines within the openstack platform, so as to understand the network traffic status, conduct network monitoring and corresponding traffic analysis, in order to solve the problems raised in the above background art.
[0004] To achieve the above purpose, the present invention provides the following technical solution: A method for mirror traffic collection and analysis based on ovs, which includes the following steps:
[0005] Receive the traffic mirror configuration information input by the user, where the configuration information includes the mirror port, the observation port, and the conditions of the mirror traffic, and save the configuration information to the database;
[0006] According to the configuration information in the database, update the ovs flow table, and add a target flow table for traffic mirroring to the flow table;
[0007] Utilize the updated ovs flow table set to perform mirroring processing on the traffic entering and leaving the ovs flow table, and copy the traffic that meets the mirroring conditions to the specified mirror traffic outlet.
[0008] Preferably, configure the mirror traffic port on the br-int of the host node where the source collection virtual machine is located. Use the connection port of the virtual machine's tap port on the bridge as the mirror source port, and collect the traffic entering and leaving this port as the mirror traffic; The mirror traffic configuration includes two methods: port mirroring and flow mirroring. Using the port mirroring method, configure select-src-port to represent the traffic sent by the mirror virtual machine, and configure select-dst-port to represent the traffic received by the mirror virtual machine.
[0009] Preferably, the mirrored traffic egress module exports the replicated traffic to the destination collection machine. The destination collection virtual machine and the virtual machine with the traffic to be collected belong to two different computing nodes. A VXLAN tunnel or a GRE tunnel is established between the two nodes through br-int to create a transmission tunnel for the replicated traffic and achieve cross-node communication. Among them, the GRE tunnel is mainly used to encapsulate data packets of other protocols in the IP network to achieve cross-network data transmission and is suitable for small networks or scenarios that require encrypted communication. The VXLAN tunnel is designed specifically for virtualized network environments, aiming to expand the scale of virtual networks and provide stronger isolation and flexibility. It is suitable for large network topologies such as cross-data centers and cross-regions. The tunnel type is selected according to requirements.
[0010] Preferably, independent of the existing network architecture and without affecting the original tunnel communication, a VXLAN / GRE tunnel is established unidirectionally from the source virtual machine node with the traffic to be collected to the destination collection machine node. On the basis of the original network, the network function is expanded. On the premise that the floating network and the service data network are connected, the floating IP of the peer destination virtual machine is used as the VTEP of the tunnel, independent of the bridge and VTEP for establishing the VXLAN tunnel in the existing architecture, ensuring the flexibility of function expansion and the stability of the entire platform function. A GRE / VXLAN port is established on the br-int bridge of the compute node compute-002 to establish a GRE / VXLAN tunnel with the virtual machine receiving the mirrored traffic. The address of the other end of the tunnel is the floating IP address bound to the virtual machine. After the mirrored data packet is re-encapsulated with UDP on the GRE / VXLAN port of br-int, it is sent to the peer VTEP port, and the encapsulated data packet is sent to the core switch through the data network card of the compute node according to the route and then sent to the compute node where the destination collection virtual machine is located through the switch.
[0011] Preferably, the traffic mirroring execution module monitors the traffic flowing in and out of the OVS flow table in real time. For the traffic that meets the mirroring conditions, it is replicated to the specified mirrored traffic egress according to the preset rules, and at the same time, the relevant information of the mirrored traffic is counted for network administrators to conduct network monitoring and fault management. The mirrored traffic can be used for security audits, intrusion detection, and business analysis and other demand scenarios. During the operation of the system, network packets are analyzed through traffic mirroring to locate the cause of faults, and the service traffic is mirrored and replicated and forwarded to a dedicated cloud server analysis cluster for real-time analysis. In the production environment, mirroring operations should be used carefully and as needed, and mirroring queries should be performed regularly to delete useless mirrors to avoid putting pressure on network performance.
[0012] A system for a method of collecting and analyzing mirrored traffic based on OVS includes a traffic mirroring configuration module, an OVS flow table management module, a traffic mirroring execution module, and a mirrored traffic egress module;
[0013] A traffic mirroring configuration module, which is used to receive the traffic mirroring configuration information input by the user. The configuration information includes the mirroring port, the observation port, and the conditions for mirroring traffic, and saves the configuration information to the database;
[0014] An ovs flow table management module, which is used to update the ovs flow table according to the configuration information in the database and add a target flow table for traffic mirroring to the flow table;
[0015] A traffic mirroring execution module, which is used to mirror the traffic entering and leaving the ovs flow table by using the updated ovs flow table set;
[0016] A mirrored traffic export module, which is used to export the copied traffic to the destination collection machine.
[0017] Preferably, the traffic mirroring configuration module configures the mirroring traffic port on the br-int of the host node where the source collection virtual machine is located, uses the connection port of the virtual machine's tap port on the bridge as the mirroring source port, and collects the traffic entering and leaving this port as the mirroring traffic; among them, the mirroring traffic configuration includes two methods: port mirroring and flow mirroring. When using the port mirroring method, configuring select-src-port means mirroring the traffic sent by the virtual machine, and configuring select-dst-port means mirroring the traffic received by the virtual machine.
[0018] Preferably, when the mirrored traffic export module exports the copied traffic to the destination collection machine, the destination collection virtual machine and the virtual machine with the traffic to be collected belong to two different computing nodes. A vxlan tunnel or a gre tunnel is established between the two nodes through the br-int to establish a transmission tunnel for the copied traffic to achieve cross-node communication; among them, the gre tunnel is mainly used to encapsulate the data packets of other protocols in the IP network to achieve cross-network data transmission, and is suitable for small networks or scenarios that require encrypted communication; the vxlan tunnel is designed specifically for the virtualized network environment, aiming to expand the scale of the virtual network and provide stronger isolation and flexibility, and is suitable for large network topologies such as cross-data centers and cross-regions. Select the tunnel type according to the requirements.
[0019] Preferably, independent of the existing network architecture and without affecting the original tunnel communication, a VXLAN / GRE tunnel is unidirectionally established from the source virtual machine node to be collected to the destination collection machine node, expanding the network function on the basis of the original network. On the premise that the floating network is connected to the service data network, the floating IP of the peer destination virtual machine is used as the VTEP of the tunnel, independent of the bridge and VTEP for establishing the VXLAN tunnel in the existing architecture, ensuring the flexibility of function expansion and the stability of the entire platform function; a GRE / VXLAN port is established on the br-int bridge of the compute node compute-002 for establishing a GRE / VXLAN tunnel with the virtual machine receiving the mirror traffic. The address of the other end of the tunnel is the floating IP address bound to the virtual machine. After the mirrored data packet is re-encapsulated with UDP at the GRE / VXLAN port of br-int, it is sent to the peer VTEP port, and the encapsulated data packet is sent to the core switch through the data network card of the compute node according to the route, and then sent to the compute node where the destination collection virtual machine is located through the switch.
[0020] Preferably, the traffic mirroring execution module monitors the traffic flowing in and out of the OVS flow table in real time. For the traffic that meets the mirroring conditions, it is copied to the specified mirror traffic outlet according to the preset rules, and at the same time, the relevant information of the mirror traffic is counted for network administrators to conduct network monitoring and fault management; the mirrored traffic can be used for security audits, intrusion detection, and business analysis and other demand scenarios. During the operation of the system, the network packets are analyzed through traffic mirroring to locate the cause of the fault, and the service traffic is mirrored and forwarded to a dedicated cloud server analysis cluster for real-time analysis; moreover, in the production environment, mirroring operations should be used carefully and as needed, and mirror queries should be performed regularly to delete useless mirrors to avoid putting pressure on network performance.
[0021] Compared with the prior art, the beneficial effects of the present invention are:
[0022] The method and system for mirroring traffic collection and analysis based on OVS proposed by the present invention configure mirrors through the OVS bridge, and use the configured mirrors for the ports connected to the virtual machines to export the traffic in and out of the virtual machines to the destination virtual machines for traffic collection, and perform subsequent traffic analysis according to different requirements, improving the monitoring ability of network traffic. Especially in the OVN distributed network environment, effective mirroring and monitoring of traffic are realized; the complexity and cost of network monitoring are reduced, and an efficient traffic mirroring function can be realized through simple configuration; the network security is enhanced, and potential security threats can be discovered and processed in a timely manner through real-time monitoring and analysis of traffic. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 It is a communication architecture diagram of the system of the present invention;
[0024] Figure 2 This is the traffic flow diagram of the present invention. Detailed implementation manners
[0025] In order to clearly and completely describe the objectives, technical solutions of the present invention, and make the advantages more clearly understood, the following further details the embodiments of the present invention with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are some, rather than all, embodiments of the present invention, and are only used to explain the embodiments of the present invention, not to limit the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0026] Embodiment 1, the present invention provides a technical solution: a method for mirroring traffic collection and analysis based on ovs, which includes the following steps:
[0027] Receive the traffic mirroring configuration information input by the user. The configuration information includes the mirror port, the observation port, and the conditions for mirroring traffic, and save the configuration information to the database; according to the configuration information in the database, update the ovs flow table, and add a target flow table for traffic mirroring in the flow table; use the updated ovs flow table set to perform mirroring processing on the traffic entering and leaving the ovs flow table, and copy the traffic that meets the mirroring conditions to the specified mirror traffic outlet.
[0028] Configure the mirror traffic port on the br-int of the host node where the source collection virtual machine is located. Use the connection port of the virtual machine's tap port on the bridge as the mirror source port, and collect the traffic entering and leaving this port as the mirror traffic; the mirror traffic configuration includes two methods: port mirroring and flow mirroring. Using the port mirroring method, configure select-src-port to represent the traffic sent by the mirror virtual machine, and configure select-dst-port to represent the traffic received by the mirror virtual machine.
[0029] The mirror traffic outlet module exports the copied traffic to the destination collection machine. The destination collection virtual machine and the virtual machine with the traffic to be collected belong to two different computing nodes. Establish a vxlan tunnel or a gre tunnel between the two nodes through the br-int to establish a transmission tunnel for the copied traffic and achieve cross-node communication; among them, the gre tunnel is mainly used to encapsulate data packets of other protocols in the IP network to achieve cross-network data transmission, and is suitable for small networks or scenarios that require encrypted communication; the vxlan tunnel is designed specifically for virtualized network environments, aiming to expand the scale of virtual networks and provide stronger isolation and flexibility, and is suitable for large network topologies such as cross-data centers and cross-regions. Select the tunnel type according to the requirements.
[0030] Independent of the existing network architecture, without affecting the original tunnel communication, a unidirectional vxlan / gre tunnel is established from the source virtual machine node to be collected to the destination collection machine node, expanding the network function on the basis of the original network. On the premise that the floating network is connected to the service data network, the floating Ip of the peer destination virtual machine is used as the vtep of the tunnel, independent of the bridge and vtep for establishing the vxlan tunnel in the existing architecture, ensuring the flexibility of function expansion and the stability of the entire platform function; a gre / vxlan port is established on the br-int bridge of the compute node compute-002 to establish a gre / vxlan tunnel with the virtual machine receiving the mirror traffic. The address of the other end of the tunnel is the floating Ip address bound to the virtual machine. After the mirrored data packet is re-encapsulated with UDP on the gre / vxlan port of br-int, it is sent to the peer vtep port, and the encapsulated data packet is sent to the core switch through the data network card of the compute node according to the route, and then sent to the compute node where the destination virtual machine to be collected is located through the switch.
[0031] The traffic mirror execution module monitors the traffic flowing in and out of the ovs flow table in real time. For the traffic that meets the mirroring conditions, it is copied to the specified mirror traffic outlet according to the preset rules, and at the same time, the relevant information of the mirror traffic is counted for network administrators to conduct network monitoring and fault management; the mirrored traffic can be used for security audits, intrusion detection, and business analysis and other demand scenarios. During the operation of the system, network packets are analyzed through traffic mirroring to locate the cause of faults, and the service traffic mirror is copied and forwarded to a dedicated cloud server analysis cluster for real-time analysis; in the production environment, mirroring operations should be used carefully and as needed, and mirror queries should be performed regularly to delete useless mirrors to avoid putting pressure on network performance.
[0032] Embodiment 2, based on Embodiment 1, proposes a system for an ovs-based mirror traffic collection and analysis method, specifically including:
[0033] In the existing openstack network architecture, the openvswitch virtual switch is used for layer 2 communication between virtual machines and business traffic communication between different nodes. In the overall network architecture, br-int (ovs bridge) is used to connect with the virtual machine interface tap to isolate different networks; br-tun (ovs bridge) is used to establish tunnels between different nodes to ensure the communication of virtual machine east-west traffic.
[0034] VXLAN is a virtualized tunnel communication technology that encapsulates L2 Ethernet frames into UDP packets (i.e., L2 over L4) and transmits them in an L3 network. This technology realizes the communication of virtual machines across physical subnets by creating a logically layer 2 network, solving the limitations of traditional VLANs in terms of scalability. Under the existing network architecture, OVS is combined with the VXLAN tunnel technology. OVS is responsible for implementing the encapsulation and decapsulation of VXLAN tunnels, providing an efficient, flexible, and secure network connection solution for the platform. This tunnel communication technology is also used in the mirror traffic collection function proposed in this patent to establish a network connection between the destination receiving traffic node and the source collection node.
[0035] The mirror traffic collection and analysis method proposed in this patent mainly includes a traffic mirror configuration module, an OVS flow table management module, a traffic mirror execution module, and a mirror traffic export module. Among them, the traffic mirror configuration module is responsible for receiving the traffic mirror configuration information input by the user and saving it to the database; the OVS flow table management module updates the OVS flow table according to the configuration information in the database and adds a target flow table for traffic mirroring to the flow table; the traffic mirror execution module uses the updated OVS flow table set to mirror the traffic entering and leaving the OVS flow table.
[0036] Through the traffic mirror configuration module, the mirror port, observation port, and conditions for mirror traffic (such as IP address, MAC address, protocol type, etc.) can be flexibly configured. The configuration information will be saved to the database for use by the OVS flow table management module. In this method, the mirror traffic port is configured on the br-int (OVS bridge) of the host node where the source collection virtual machine is located, and the connection port of the virtual machine's tap port on the bridge is used as the mirror source port, and the traffic entering and leaving this port (i.e., the traffic entering and leaving the source virtual machine) is collected through mirroring.
[0037] The OVS flow table management module reads the latest traffic mirror configuration information from the database regularly or according to changes in the configuration information, and updates the OVS flow table accordingly. A target flow table for traffic mirroring is added to the flow table to ensure that traffic meeting the conditions can be correctly mirrored.
[0038] The traffic mirror execution module monitors the traffic entering and leaving the OVS flow table in real time. For traffic meeting the mirroring conditions, it copies it to the specified mirror traffic export according to the preset rules. At the same time, this module is also responsible for counting the relevant information of the mirror traffic for network administrators to conduct network monitoring and fault management.
[0039] The mirrored traffic egress module exports the replicated traffic to the destination collection machine. The destination collection virtual machine and the virtual machine with the traffic to be collected belong to two different computing nodes. A VXLAN tunnel is established between the two nodes through br-int (OVS bridge) to create a transmission tunnel for the replicated traffic and achieve cross-node communication.
[0040] This method is independent of the existing network architecture and does not affect the original tunnel communication. A VXLAN / GRE tunnel is established unidirectionally from the source virtual machine node with traffic to be collected to the destination collection machine node. On the basis of the original network, the network function is extended. On the premise that the floating network and the service data network are connected, the floating IP of the peer destination virtual machine is used as the VTEP of the tunnel, independent of the bridge and VTEP for establishing the VXLAN tunnel in the existing architecture, ensuring the flexibility of function expansion and the stability of the entire platform function.
[0041] GRE tunnels are mainly used to encapsulate packets of other protocols in the IP network to achieve cross-network data transmission and are suitable for small networks or scenarios that require encrypted communication; VXLAN tunnels are designed specifically for virtualized network environments, aiming to expand the scale of virtual networks and provide stronger isolation and flexibility. They are suitable for large network topologies such as cross-data centers and cross-regions, and the tunnel type can be selected according to requirements.
[0042] Combined with the attached Figure 1 The specific configuration is as follows: vm01 is the virtual machine for receiving mirrored traffic, and a floating IP address is bound to establish a communication tunnel (GRE tunnel / VXLAN tunnel) with the peer. vm02 is a VPC internal network virtual machine used for the virtual machine to be mirrored, and the traffic in and out of virtual machine vm02 is mirrored to virtual machine vm01.
[0043] A GRE / VXLAN port is established on the br-int bridge of the computing node compute-002 to establish a GRE / VXLAN tunnel with the virtual machine vm01 that receives the mirrored traffic. The address of the peer end of the tunnel is the floating IP address bound to the virtual machine vm01. After the mirrored data packet is re-encapsulated with UDP on the GRE / VXLAN port of br-int, it is sent to the peer VTEP port, and according to the routing, the encapsulated data packet is sent to the core switch through the data network card of the computing node compute-002 and then to the computing node compute-001 as Figure 1 shown.
[0044] Add a GRE port or a VXLAN port on br-int to receive the traffic command of the mirrored virtual machine:
[0045] ovs-vsctl add-port br-int sgre2 -- set interface sgre2 type=gre options:remote_ip=100.162.2.74 options:key=0x0010
[0046] ovs-vsctl add-port br-int svxlan -- set interface svxlan type=vxlan options:remote_ip=100.162.2.74 options:key=0x0010
[0047] Configuration of mirrored traffic: Mirroring is divided into port mirroring and flow mirroring. Port mirroring copies all packets received or sent by the mirrored port to the specified observation port. Flow mirroring combines mirroring with flow classification, only copying packets that meet specific conditions and filtering out packets that the packet analysis device is not interested in, providing more refined control for packet analysis and improving the working efficiency of the packet analysis device. This patent adopts the method of port mirroring.
[0048] Appendix Figure 1 Port qvo0905a02c-09 in the appendix is the port where the virtual machine vm02 with mirrored traffic is connected to the br-int bridge. The traffic entering and leaving this port is the traffic entering and leaving the virtual machine vm02. Configure the replication of port traffic for this source port on the br-int bridge. Configuring select-src-port means mirroring the traffic sent by the virtual machine, and configuring select-dst-port means mirroring the traffic received by the virtual machine, which can be selected according to different virtual machines.
[0049] ovs-vsctl ----id=@p1 get port qvo0905a02c-09 ----id=@sgre2 get ports gre2 ----id=@m create mirror name=m0 select-src-port=@p1 output_port=@sgre2 -- set bridge br-int mirrors=@m
[0050] ovs-vsctl ----id=@p1 get port qvo0905a02c-09 ----id=@svxlan get port svxlan ----id=@m create mirror name=m0 select-src-port=@p1 output_port=@svxlan --set bridge br-int mirrors=@m
[0051] After the mirror traffic configuration is completed, traffic testing can be carried out. Perform external access on virtual machine vm02 and conduct a simple packet capture test on virtual machine vm01. The traffic of vm02's external access can be captured on virtual machine vm01. If the configuration is successful, traffic collection and analysis can be performed as needed. The specific traffic flow can be referred to in the appendix Figure 2 , appendix Figure 2 In the appendix, the red traffic is the normal business access traffic, and the blue traffic is the direction after replication to the destination collection and analysis virtual machine.
[0052] The ovs mirror defines the source port and destination port of the mirror, but mirror operations may have a certain impact on network performance. In the production environment, it should be used carefully and as needed. Mirror queries can be performed regularly and useless mirrors can be deleted to avoid putting pressure on network performance.
[0053] View mirrors: ovs-vsctl list mirror
[0054] Clear mirrors: ovs-vsctl clear bridge br-int mirrors
[0055] The traffic collected by the mirror can be used for security audits, intrusion detection, and business analysis and other demand scenarios. During the operation of the system, due to reasons such as abnormal system software processing, network device hardware failures, computer viruses, or abnormal user usage, network traffic anomalies or error messages may occur. Through traffic mirroring, network packets can be analyzed to locate the cause of the failure. Using the mirror traffic function, business traffic can be mirrored and the traffic can be copied and forwarded to a dedicated cloud server analysis cluster for real-time analysis.
[0056] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for mirror traffic collection and analysis based on ovs, characterized in that: The steps are as follows: Receive the traffic mirroring configuration information input by the user. The configuration information includes the mirror port, the observation port, and the conditions for mirroring traffic, and save the configuration information to the database; Update the ovs flow table according to the configuration information in the database, and add a target flow table for traffic mirroring to the flow table; Use the updated ovs flow table set to perform mirroring processing on the traffic entering and leaving the ovs flow table, and copy the traffic that meets the mirroring conditions to the specified mirror traffic outlet.
2. The method for mirroring traffic collection and analysis based on OVS according to claim 1, characterized in that: Configure the mirror traffic port on the br-int of the host node where the source collection virtual machine is located. Use the connection port of the virtual machine's tap port on the bridge as the mirror source port, and collect the traffic entering and leaving this port as the mirror traffic. The mirror traffic configuration includes two methods: port mirroring and flow mirroring. Using the port mirroring method, configure select-src-port to indicate mirroring the traffic sent by the virtual machine, and configure select-dst-port to indicate mirroring the traffic received by the virtual machine.
3. The method for mirroring traffic collection and analysis based on ovs according to claim 2, wherein: The mirror traffic outlet module exports the copied traffic to the destination collection machine. The destination collection virtual machine and the virtual machine with the traffic to be collected belong to two different computing nodes. Establish a vxlan tunnel or a gre tunnel between the two nodes through br-int to establish a transmission tunnel for the copied traffic and achieve cross-node communication. Among them, the gre tunnel is mainly used to encapsulate data packets of other protocols in the IP network to achieve cross-network data transmission, and is suitable for small networks or scenarios that require encrypted communication. The vxlan tunnel is designed specifically for virtualized network environments, aiming to expand the scale of the virtual network and provide stronger isolation and flexibility, and is suitable for large network topologies such as cross-data centers and cross-regions. Select the tunnel type according to the requirements.
4. The method for mirror traffic collection and analysis based on ovs according to claim 3, characterized in that: Independent of the existing network architecture, without affecting the original tunnel communication, unidirectionally establish a vxlan / gre tunnel from the source virtual machine node to be collected to the destination collection machine node, expand the network function on the basis of the original network. On the premise that the floating network is connected to the service data network, use the floatingIp of the peer destination virtual machine as the vtep of the tunnel, independent of the bridge and vtep for establishing the vxlan tunnel in the existing architecture, to ensure the flexibility of function expansion and the stability of the entire platform function. Establish a gre / vxlan port on the br-int bridge of the computing node compute-002 to establish a gre / vxlan tunnel with the virtual machine receiving the mirror traffic. The address of the other end of the tunnel is the floatingIp address bound to the virtual machine. After re-encapsulating the mirrored data packets at the gre / vxlan port of br-int with UDP, send them to the peer vtep port, and send the encapsulated data packets to the core switch through the data network card of the computing node according to the route, and then send them to the computing node where the destination collection virtual machine is located through the switch.
5. The method for mirroring traffic collection and analysis based on ovs according to claim 4, characterized in that: The traffic mirroring execution module monitors the traffic flowing in and out of the ovs flow table in real time. For the traffic that meets the mirroring conditions, it copies it to the specified mirror traffic outlet according to the preset rules, and at the same time counts the relevant information of the mirror traffic for network administrators to conduct network monitoring and fault management. The mirrored traffic can be used for security audits, intrusion detection, and business analysis and other demand scenarios. During the system operation, network packets are analyzed through traffic mirroring to locate the cause of faults, and the service traffic mirror is copied and forwarded to a dedicated cloud server analysis cluster for real-time analysis. In the production environment, mirroring operations should be used carefully and as needed, and mirror queries should be performed regularly to delete useless mirrors to avoid putting pressure on network performance.
6. A system for the method of mirror traffic collection and analysis based on ovs according to claim 5, characterized in that: It includes a traffic mirroring configuration module, an ovs flow table management module, a traffic mirroring execution module, and a mirror traffic outlet module; The traffic mirroring configuration module is used to receive the traffic mirroring configuration information input by the user. The configuration information includes the mirror port, the observation port, and the conditions for mirror traffic, and saves the configuration information to the database; The ovs flow table management module is used to update the ovs flow table according to the configuration information in the database and add a target flow table for traffic mirroring to the flow table; The traffic mirroring execution module is used to perform mirroring processing on the traffic flowing in and out of the ovs flow table by using the updated ovs flow table set; The mirror traffic outlet module is used to export the copied traffic to the destination collection machine.
7. The mirror traffic collection and analysis system based on ovs according to claim 6, characterized in that: The traffic mirroring configuration module configures the mirror traffic port on the br-int of the host node where the source collection virtual machine is located, uses the connection port of the virtual machine's tap port on the bridge as the mirror source port, and collects the traffic flowing in and out of this port as mirror traffic. Among them, the mirror traffic configuration includes two methods: port mirroring and flow mirroring. When using the port mirroring method, configuring select-src-port means mirroring the traffic sent by the virtual machine, and configuring select-dst-port means mirroring the traffic received by the virtual machine.
8. The mirror traffic collection and analysis system based on ovs according to claim 7, wherein: When the mirror traffic outlet module exports the copied traffic to the destination collection machine, the destination collection virtual machine and the virtual machine whose traffic is collected belong to two different computing nodes. A vxlan tunnel or a gre tunnel is established between the two nodes through br-int to establish a transmission tunnel for the copied traffic to achieve cross-node communication. Among them, the gre tunnel is mainly used to encapsulate data packets of other protocols in the IP network to achieve cross-network data transmission, and is suitable for small networks or scenarios that require encrypted communication. The vxlan tunnel is designed specifically for virtualized network environments, aiming to expand the scale of virtual networks and provide stronger isolation and flexibility, and is suitable for large network topologies such as cross-data centers and cross-regions. The tunnel type is selected according to the requirements.
9. The mirror traffic collection and analysis system based on ovs according to claim 8, characterized in that: Independent of the existing network architecture, without affecting the original tunnel communication, a unidirectional vxlan / gre tunnel is established from the source virtual machine node to be collected to the destination collection machine node, expanding network functions on the basis of the original network. On the premise that the floating network is connected to the service data network, the floating Ip of the peer destination virtual machine is used as the vtep of the tunnel, independent of the bridge and vtep for establishing the vxlan tunnel in the existing architecture, ensuring the flexibility of function expansion and the stability of the entire platform function; a gre / vxlan port is established on the br-int bridge of the compute node compute-002 to establish a gre / vxlan tunnel with the virtual machine receiving the mirror traffic. The address of the other end of the tunnel is the floating Ip address bound to the virtual machine. After the mirrored data packet is re-encapsulated with UDP on the gre / vxlan port of br-int, it is sent to the other end vtep port, and the encapsulated data packet is sent to the core switch through the data network card of the compute node according to the route, and then sent to the compute node where the destination collection virtual machine is located through the switch.
10. The mirror traffic collection and analysis system based on ovs according to claim 9, wherein: The traffic mirror execution module monitors the traffic flowing in and out of the ovs flow table in real time. For the traffic that meets the mirroring conditions, it is copied to the specified mirror traffic outlet according to the preset rules, and at the same time, the relevant information of the mirror traffic is counted for network administrators to conduct network monitoring and fault management; the mirrored traffic can be used for security audits, intrusion detection, and business analysis and other demand scenarios. During the operation of the system, network packets are analyzed through traffic mirroring to locate the cause of faults, and the service traffic mirror is copied and forwarded to a dedicated cloud server analysis cluster for real-time analysis; moreover, in the production environment, mirroring operations should be used carefully and as needed, and mirror queries should be performed regularly to delete useless mirrors to avoid putting pressure on network performance.
Citation Information
Cited By
Full-flow mirroring method and device for virtualization environment and medium
CN120528932A