Flow monitoring method and device for multi-cloud application gateway, computer equipment and medium

By obtaining and parsing network layer data packet information, generating application traffic reports and providing exception warnings, the resource consumption and security problems of traffic monitoring in the existing technology are solved, and more efficient traffic monitoring is achieved.

CN120301786APending Publication Date: 2025-07-11CORMORANT TECH (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510410321.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The prior art has problems such as large network resource consumption, access delay and unknown risks in traffic monitoring, especially in the case of large traffic, which is difficult to ensure security and timeliness.

Method used

By obtaining the process identifier PID, application name and packet information of the network layer data packet, parsing and generating log files, filtering based on preset filtering methods, generating application traffic reports, and issuing a warning when traffic is abnormal.

Benefits of technology

It improves the timeliness and security of traffic monitoring, can issue timely warnings in abnormal situations, reduces network resource consumption, and enhances the ability to detect unknown risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301786A_ABST
    Figure CN120301786A_ABST
Patent Text Reader

Abstract

The invention relates to the field of flow monitoring, and discloses a flow monitoring method for a multi-cloud application gateway, which comprises the following steps of: acquiring flow information, and analyzing the flow information to obtain a log file corresponding to the flow information; log files corresponding to the traffic information are screened and filtered to obtain target log files, the target log files are classified and summarized according to a preset data storage strategy and application information, and an application traffic report is generated; according to the PID corresponding to the data packet, the name of the application, the length of the data packet and the sending and receiving nodes of the data packet, obtaining the flow generated by each process, and according to the flow generated by each process and the corresponding relation between the process and the application, obtaining the flow generated when each application runs; the data traffic is compared to obtain a result, and the method of the invention can effectively improve the timeliness and security of traffic monitoring.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of traffic monitoring, and specifically to a traffic monitoring method, device, computer device and medium for a multi-cloud application gateway. Background Technique

[0002] Currently, whether in financial networks, industry networks or in wide area networks such as the Internet, the development of traffic volume has exceeded the most optimistic estimates in the past. A large number of information requests from users, continuously updated application requirements, and continuous access to services without interruption have become problems for application service providers to solve Internet services. To ensure the normal response of traffic access requests, the security monitoring of traffic is essential.

[0003] In the existing processing methods, the information in the traffic is mainly analyzed through some security software or firewalls. However, this comparison method consumes resources such as network bandwidth. When the traffic is large, it is easy to cause access delays or even losses. There are also some methods that use machine learning and neural network models to predict the traffic trend and simulate and warn of traffic security. However, this method has certain uncertainties and it is difficult to check some unknown risks. Therefore, this application proposes a traffic monitoring method, device, computer device and medium for a multi-cloud application gateway. Summary of the Invention

[0004] The purpose of the present invention is to provide a traffic monitoring method, device, computer device and medium for a multi-cloud application gateway to solve the problems raised in the above background technique.

[0005] To achieve the above purpose, the present invention provides the following technical solution: A traffic monitoring method for a multi-cloud application gateway, including the following steps:

[0006] Step S1: Obtain the process identifier PID, application name, length of the data packet, and sending and receiving nodes of the data packet corresponding to all data packets flowing in and out of the network layer, collect the traffic information sent by the network device, and parse the traffic information to obtain the log file corresponding to the traffic information;

[0007] Step S2: Based on a preset traffic screening method, perform screening and filtering processing on the log file corresponding to the traffic information to obtain a target log file, classify and summarize the target log file according to a preset data storage strategy and application information, and generate an application traffic report;

[0008] Step S3: According to the PID, application name, length of the data packet, and sending and receiving nodes corresponding to the data packet, obtain the traffic generated by each process, and according to the traffic generated by each process and the corresponding relationship between the process and the application, obtain the traffic generated when each application runs;

[0009] Step S4: Compare the data traffic in Step S2 and Step S3. If the result does not match, an abnormal warning is issued; otherwise, it is normal.

[0010] Preferably, the specific traffic generated by each process by obtaining the PID, application name, length of the data packet, and the sending and receiving nodes of the data packet corresponding to the data packet in Step S1 is as follows: After obtaining the PID, application name, length of the data packet, and the sending and receiving nodes of the data packet corresponding to the data packet each time, the length of the data packet corresponding to the same PID is accumulated to the existing length of the data packet corresponding to the PID, so as to obtain the traffic generated by each process.

[0011] Preferably, the network device in Step S1 includes a router. The specific process of classifying and summarizing the target log file according to the preset data storage policy and application information in Step S2 includes: obtaining the data compression time and data cleaning time according to the data storage policy; obtaining the corresponding IP address range according to the application information.

[0012] Preferably, the specific process of Step S3 is to create a PID directory file named after the PID corresponding to the data packet. The PID directory file stores the application name corresponding to the PID, the sending and receiving nodes of the data packet corresponding to the PID, and the traffic generated by the process corresponding to the PID. Search the PID directory file in sequence according to the application name to obtain the traffic generated by the process corresponding to the application name; superimpose the traffic generated by the process corresponding to the application name to obtain the traffic generated during the operation of the application corresponding to the application name.

[0013] According to the above device for a traffic monitoring method of a multi-cloud application gateway, it includes: a data packet information acquisition unit for acquiring the process identifier PID, application name, length of the data packet, and the sending and receiving nodes of the data packet corresponding to all data packets flowing in and out of the network layer; a traffic information collection unit for collecting the traffic information sent by the network device; a log processing unit for monitoring the traffic information in real time in the NetFlow manner, parsing the traffic information to obtain the log file corresponding to the traffic information, and then filtering and processing the log file corresponding to the traffic information based on a preset traffic screening method to obtain a target log file; a traffic report generation unit for generating an application traffic report according to the query parameter information; a traffic warning unit for performing a corresponding warning process when the traffic is abnormal based on the traffic comparison result.

[0014] A computer device for a traffic monitoring method of a multi-cloud application gateway according to the above, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the traffic monitoring method of the above multi-cloud application gateway is implemented.

[0015] A computer-readable storage medium for a traffic monitoring method of a multi-cloud application gateway according to the above. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the traffic monitoring method of the above multi-cloud application gateway is implemented.

[0016] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0017] The present invention obtains the process identifier PID, application name, length of the data packet, and sending and receiving nodes of the data packet corresponding to all data packets flowing in and out of the network layer, collects the traffic information sent by the network device, and parses the traffic information to obtain the log file corresponding to the traffic information. Then, based on the preset traffic screening method, the log file corresponding to the traffic information is screened and filtered to obtain the target log file. The target log file is classified and summarized according to the preset data storage strategy and application information, and an application traffic report is generated. Then, according to the PID, application name, length of the data packet, and sending and receiving nodes corresponding to the data packet, the traffic generated by each process is obtained. According to the traffic generated by each process and the corresponding relationship between the process and the application, the traffic generated during the operation of each application is obtained. Finally, the obtained data traffic results are compared to obtain the result, which can effectively improve the timeliness and security of traffic monitoring. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 It is a flowchart of the method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0019] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0020] Embodiment

[0021] Please refer to Figure 1 , a traffic monitoring method, device, computer device, and medium of a multi-cloud application gateway in the figure, including the following steps:

[0022] Step S1: Obtain the process identifier PID, application name, length of the data packet, and sending and receiving nodes of the data packets flowing in and out of the network layer, collect the traffic information sent by the network device, and parse the traffic information to obtain the log file corresponding to the traffic information;

[0023] Step S2: Based on a preset traffic screening method, perform screening and filtering on the log file corresponding to the traffic information to obtain a target log file, classify and summarize the target log file according to the preset data storage policy and application information, and generate an application traffic report;

[0024] Step S3: Obtain the traffic generated by each process according to the PID, application name, length of the data packet, and sending and receiving nodes of the data packet, and obtain the traffic generated during the operation of each application according to the traffic generated by each process and the corresponding relationship between the process and the application;

[0025] Step S4: Compare the data traffic in Step S2 and Step S3. If the results do not match, an exception warning is issued; otherwise, it is normal.

[0026] In this embodiment, obtaining the traffic generated by each process according to the PID, application name, length of the data packet, and sending and receiving nodes of the data packet in Step S1 is specifically as follows: After obtaining the PID, application name, length of the data packet, and sending and receiving nodes of the data packet each time, add the length of the data packet corresponding to the same PID to the existing length of the data packet of the PID, so as to obtain the traffic generated by each process.

[0027] Further, the network device in Step S1 includes a router. Classifying and summarizing the target log file according to the preset data storage policy and application information in Step S2 specifically includes: obtaining the data compression time and data cleaning time according to the data storage policy; obtaining the corresponding IP address range according to the application information.

[0028] Further, the specific process of Step S3 is as follows: Create a PID directory file named after the PID of the data packet. The PID directory file stores the application name corresponding to the PID, the sending and receiving nodes of the data packet corresponding to the PID, and the traffic generated by the process corresponding to the PID. Search the PID directory file in sequence according to the application name to obtain the traffic generated by the process corresponding to the application name; superimpose the traffic generated by the process corresponding to the application name to obtain the traffic generated during the operation of the application corresponding to the application name.

[0029] An apparatus for a traffic monitoring method of a multi-cloud application gateway, comprising: a data packet information acquisition unit for acquiring the process identifier PID, application name, length of the data packet, and the sending and receiving nodes of the data packet corresponding to all data packets flowing into and out of the network layer; a traffic information collection unit for collecting the traffic information sent by the network device; a log processing unit for monitoring the traffic information in real time in the NetFlow manner, parsing the traffic information to obtain a log file corresponding to the traffic information, and then filtering and processing the log file corresponding to the traffic information based on a preset traffic screening method to obtain a target log file; a traffic report generation unit for generating an application traffic report according to the query parameter information; a traffic warning unit for performing a corresponding warning process when the traffic is abnormal based on the traffic comparison result.

[0030] A computer device for a traffic monitoring method of a multi-cloud application gateway, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the above-mentioned traffic monitoring method of the multi-cloud application gateway is implemented.

[0031] A computer-readable storage medium for a traffic monitoring method of a multi-cloud application gateway, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, the above-mentioned traffic monitoring method of the multi-cloud application gateway is implemented.

[0032] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device.

[0033] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention, and the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A traffic monitoring method for a multi-cloud application gateway, characterized in that, It includes the following steps: Step S1: Obtain the process identifier PID, application name, length of the data packet, and sending and receiving nodes of the data packets flowing in and out of the network layer, collect the traffic information sent by the network device, and parse the traffic information to obtain the log file corresponding to the traffic information; Step S2: Based on a preset traffic screening method, perform screening and filtering on the log file corresponding to the traffic information to obtain a target log file, classify and summarize the target log file according to a preset data storage policy and application information, and generate an application traffic report; Step S3: According to the PID, application name, length of the data packet, and sending and receiving nodes of the data packet, obtain the traffic generated by each process, and according to the traffic generated by each process and the corresponding relationship between the process and the application, obtain the traffic generated during the operation of each application; Step S4: Compare the data traffic in Step S2 and Step S3. If the results do not match, an exception warning is issued; otherwise, it is normal.

2. The traffic monitoring method of a multi-cloud application gateway according to claim 1, wherein: The specific method for obtaining the traffic generated by each process according to the PID, application name, length of the data packet, and sending and receiving nodes of the data packet in Step S1 is as follows: After obtaining the PID, application name, length of the data packet, and sending and receiving nodes of the data packet each time, add the length of the data packet corresponding to the same PID to the existing length of the data packet corresponding to the PID, so as to obtain the traffic generated by each process.

3. A traffic monitoring method for a multi-cloud application gateway according to claim 2, characterized in that: The network device in Step S1 includes a router.

4. The traffic monitoring method of a multi-cloud application gateway according to claim 3, characterized in that: The specific method for classifying and summarizing the target log file according to a preset data storage policy and application information in Step S2 specifically includes: Obtain the data compression time and data cleaning time according to the data storage policy; obtain the corresponding IP address range according to the application information.

5. A traffic monitoring method for a multi-cloud application gateway according to claim 4, characterized in that: The specific process of Step S3 is as follows: Create a PID directory file named after the PID corresponding to the data packet. The PID directory file stores the application name corresponding to the PID, the sending and receiving nodes of the data packet corresponding to the PID, and the traffic generated by the process corresponding to the PID. Search the PID directory file in sequence according to the application name to obtain the traffic generated by the process corresponding to the application name; superimpose the traffic generated by the process corresponding to the application name to obtain the traffic generated during the operation of the application corresponding to the application name.

6. An apparatus for a traffic monitoring method of a multi-cloud application gateway according to any one of claims 1-5, characterized in that, It includes: A data packet information acquisition unit, which is used to obtain the process identifier PID, application name, length of the data packet, and sending and receiving nodes of the data packets flowing in and out of the network layer; A traffic information collection unit, which is used to collect the traffic information sent by the network device; A log processing unit, which is used to monitor the traffic information in real time in the NetFlow manner, parse the traffic information to obtain the log file corresponding to the traffic information, and then is used to perform screening and filtering on the log file corresponding to the traffic information based on a preset traffic screening method to obtain a target log file; A traffic report generation unit for generating an application traffic report according to query parameter information; A traffic warning unit for performing a corresponding warning process when traffic is abnormal based on the traffic comparison result.

7. A computer device for a traffic monitoring method of a multi-cloud application gateway according to claims 1-5, characterized in that: It includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements a traffic monitoring method for a multi-cloud application gateway as described in any one of claims 1-5.

8. A computer-readable storage medium for a traffic monitoring method of a multi-cloud application gateway according to any one of claims 1-5, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements a traffic monitoring method for a multi-cloud application gateway as described in any one of claims 1-5.