Multi-program traffic statistical method and system based on IPtables and cgroup

The IPtables and cgroup-based method addresses the limitations of existing traffic statistics by enabling precise classification and efficient data collection across processes and containers, improving real-time performance and system compatibility.

CN120321146APending Publication Date: 2025-07-15SHANGHAI QINIU INFORMATION TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510596509.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-09
Publication Date
2025-07-15

AI Technical Summary

Technical Problem

The prior art has problems such as granularity limitations, container blind spots, performance losses, real-time defects and high technical thresholds in program traffic statistics, making it difficult to achieve accurate program-level and container-level traffic statistics.

Method used

Using the method of combining IPtables and cgroups, by setting traffic marking operations on the POSTROUTING chain, identifying and matching target programs, using cgroups to manage traffic packets, and periodically collecting traffic statistics to display accurate traffic statistics results.

Benefits of technology

It realizes accurate traffic statistics at the program level and container level, reduces performance losses, improves real-time and compatibility, and supports multi-dimensional traffic management and visual analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321146A_ABST
    Figure CN120321146A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-program traffic statistical method and system based on IPtables and cgroup, and the method comprises the steps: S1, setting a configuration file for program recognition, setting a target object for traffic statistics and an identification strategy of the target object, and placing a traffic marking operation on a POSTROUTING chain in the IPtables; s2, identifying and matching a running instance of a target program, adding a program meeting a condition into a specified cgroup, distributing a unique class for the program, and automatically generating a corresponding IPtables marking rule at the same time; s3, periodically collecting the number of bytes of the IPtables rule, and counting and storing the traffic of each type of program; and S4, displaying a flow statistics and analysis result. According to the invention, accurate flow statistics can be realized, and good compatibility and universality are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of network monitoring and traffic analysis, and particularly to a multi-program traffic statistics method and system based on Iptables and cgroup. Background Art

[0002] Today, with the increasing maturity of cloud computing and AI development, users have an ever-growing demand for networks. Therefore, in network basic services, such as network monitoring and analysis, security and performance optimization of cloud native and microservice architectures, etc., in-depth traffic statistics and analysis are required, which is one of the basic core technologies of network services.

[0003] In the existing technologies, the solutions for program traffic statistics mainly include the following:

[0004] 1. Traffic statistics based on network devices

[0005] Typical representative systems of this technical solution, such as NetFlow, sFlow, and IPFIX, work as follows: Flow records are generated through hardware acceleration or software sampling in the forwarding plane of network devices and exported to the analysis system. Its main disadvantages are:

[0006] 1.1 Limited statistical dimensions: The minimum granularity is the five-tuple flow, and it is impossible to distinguish the traffic of multiple processes on the same host.

[0007] 1.2 Container blind spot: It is impossible to penetrate the container network namespace, and the container traffic is miscounted as the traffic of the host network card.

[0008] 2. Traffic statistics based on host packet capture

[0009] Typical representatives of this technical solution, such as tcpdump and Wireshark, work as follows: Raw data packets are captured through the libpcap library in the host network protocol stack for offline or online analysis. Its main disadvantages are:

[0010] 2.1 Performance loss: Packet capture under gigabit bandwidth can cause CPU occupancy of more than 70% (measured data).

[0011] 2.2 Real-time defect: The analysis delay is usually more than one second, making it difficult to meet the real-time control requirements.

[0012] 2.3 Lack of process association: It is necessary to manually associate / proc / net / tcp with the process PID, and the degree of automation is low.

[0013] 3. Fine-grained statistics based on eBPF

[0014] Typical representatives of this technical solution include Cilium and the BCC toolset. Their working principle is as follows: In the kernel state, eBPF programs are mounted on socket / TC / XDP hooks to directly associate traffic with the process context. Its main disadvantages are:

[0015] Technical threshold: It is necessary to master the BPF type format (BTF) and the kernel security programming model.

[0016] Compatibility limitation: Old kernels (<4.15) cannot run the complete function set. Summary of the Invention

[0017] This application provides a multi-program traffic statistics method based on IPTables and cgroup to solve the technical problems existing in the prior art, including the following steps:

[0018] S1: Set the configuration file for program recognition, set the target object of traffic statistics and its identification strategy, and place the traffic marking operation on the POSTROUTING chain in IPTables;

[0019] S2: Identify and match the running instances of the target program, add the qualified programs to the specified cgroup group, assign a unique classid to them, and automatically generate the corresponding IPTables marking rules;

[0020] S3: Periodically collect the byte count of IPTables rules, perform traffic statistics on various programs and store them;

[0021] S4: Display the traffic statistics and analysis results.

[0022] Further, in step S2 of identifying and matching the running instances of the target program, the matching methods include:

[0023] If the running instance of the target program is a local process, obtain its PID by name matching, and parse the net_cls path from / proc / {pid} / cgroup;

[0024] If the running instance of the target program is a container instance, retrieve the container ID through the Docker command, and then parse the cgroup mount point in combination with the system path structure;

[0025] If the running instance of the target program is a container name prefix scenario, automatically generate a unique classid for each newly discovered container and write it into the corresponding net_cls control file.

[0026] Further, step S2 also includes a conflict management step, and its method is:

[0027] Use the increment logic of the instance number segment in the classid encoding strategy to prevent classid conflicts caused by container restart or concurrent generation;

[0028] Recycle the allocated classid and automatically release the occupied number when the container or process exits.

[0029] Furthermore, the method for allocating classid in step S2 is as follows: adopt hierarchical decimal encoding, with the first three digits being the system number, the middle four digits being the program identifier, and the last three digits being the increment number of the program instance.

[0030] Furthermore, the configuration file for program recognition includes: program name, program type, classid encoding rule, and collection frequency.

[0031] Furthermore, S4: Display the traffic statistics and analysis results in the program dimension, including displaying traffic data classified by process name, container ID, or prefix.

[0032] Furthermore, S4: Display the traffic statistics and analysis results in the line dimension: Aggregate and display according to the physical network card (interface) dimension to adapt to multi-network card hosts.

[0033] Furthermore, S4: Display the traffic statistics and analysis results as a time series chart, including visualization components such as the system integrated bandwidth trend chart and the total traffic ranking, etc., to observe the resource usage changes during long-term operation.

[0034] The present invention also provides a multi-program traffic statistics system based on Iptables and cgroup to implement the multi-program traffic statistics method based on Iptables and cgroup, including:

[0035] A program configuration unit for setting the configuration file for program recognition, setting the target object of traffic statistics and its identification strategy, and placing the traffic marking operation on the POSTROUTING chain in Iptables;

[0036] An automatic recognition and binding unit for identifying and matching the running instances of the target program, adding the qualified programs to the specified cgroup group, allocating a unique classid for them, and automatically generating the corresponding Iptables marking rules, so as to achieve accurate classification of the network traffic of the target program;

[0037] A traffic collection and storage unit for periodically collecting the number of bytes of Iptables rules and performing traffic statistics on various programs;

[0038] A traffic display unit for displaying the traffic statistics and analysis results.

[0039] The present invention also provides an electronic device, including: a processor, a storage medium, and a bus. The storage medium stores machine-readable instructions executable by the processor. When the electronic device runs, the processor communicates with the storage medium through the bus, and the processor executes the machine-readable instructions to execute the multi-program traffic statistics method based on IPTables and cgroup as described above.

[0040] In the method and system disclosed in this application, in practical applications, multiple modules can be deployed on one target server, or each module can be independently deployed on different target servers. In particular, according to needs, in order to provide more powerful computing and processing capabilities, the modules can also be deployed to a cluster of target servers as needed.

[0041] It can be seen that the technical effects achieved by the technical solution adopted in this application are as follows:

[0042] 1. Marking is achieved when traffic enters the network protocol stack, and traffic allocation and statistics are carried out with the help of cgroup, so as to achieve accurate traffic statistics at the program level and container level.

[0043] 2. IPTables performs preliminary screening and marking, simplifies the traffic processing flow, and efficiently manages and statistics traffic in the kernel state through cgroup, effectively avoiding performance losses caused by frequent context switches in the user state.

[0044] 3. The combination of IPTables and cgroup adopted can be seamlessly deployed on conventional Linux distributions and various kernel versions, has good compatibility and universality, and at the same time makes less changes to the existing operating system configuration, greatly reducing the deployment difficulty.

[0045] 4. It is built-in with multiple traffic statistics dimensions, supports statistics based on multiple features such as process name, container name, cgroup path, etc., and realizes flexible and accurate traffic management through rich classification means and simple configuration, significantly improving the practicability and scalability of the system.

[0046] In order to have a clearer and more comprehensive understanding of this application, the following will describe the specific implementation manners of this application in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the technical solutions in the embodiments of this application, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative efforts.

[0048] Figure 1 This is a schematic flowchart of a multi-program traffic statistics method based on IPTables and cgroup according to an embodiment of the present application. Specific implementation manners

[0049] The technical solution of the present application, as a multi-program traffic statistics method based on IPTables and cgroup, includes the following steps:

[0050] S1: Set a configuration file for program identification, set the target objects of traffic statistics and their identification policies, and place the traffic marking operation on the POSTROUTING chain in IPTables;

[0051] S2: Identify and match the running instances of the target program, add the qualified programs to the specified cgroup group, assign a unique classid to them, and automatically generate the corresponding IPTables marking rules;

[0052] S3: Periodically collect the byte counts of IPTables rules, perform traffic statistics on various programs and store them;

[0053] S4: Display the traffic statistics and analysis results.

[0054] The following details the technical solution of the present application in combination with various specific embodiments.

[0055] S1: Set a configuration file for program identification, set the target objects of traffic statistics and their identification policies, and place the traffic marking operation on the POSTROUTING chain in IPTables.

[0056] In the embodiment of the present application, IPTables is a tool in the Linux kernel for configuring and managing firewall rules, providing multiple tables and chains to handle the packet flow direction, where:

[0057] The mangle table is used to modify the packet characteristics, and the POSTROUTING chain is used to operate when the packet is about to leave the host. Therefore, placing the traffic marking operation on the POSTROUTING chain can perform accurate marking after the traffic routing decision is completed, ensuring the accuracy of traffic classification.

[0058] cgroup and net_cls subsystem

[0059] cgroup (Control Group) is a resource management mechanism provided by the Linux kernel, which can group processes and limit resources.

[0060] In the embodiments of the present application, the net_cls subsystem of cgroup is used to mark and classify traffic, and traffic is mainly associated through classid.

[0061] The configuration files recognized by the program include: program name, program type, classid encoding rule, collection frequency, etc.

[0062] For the program name, it specifically includes multiple matching methods such as supporting process name, container name, container name prefix, etc.

[0063] For the program type, it specifically includes: determining whether the target is a local process, a Docker container, or a container cluster with a unified prefix;

[0064] In addition, the configuration file can support a hot update mechanism. The system can load new configurations without restarting the service by listening for file change events, and trigger subsequent automatic recognition and binding processes.

[0065] S2: Identify and match the running instances of the target program, add the qualified programs to the specified cgroup group, assign a unique classid to it, and automatically generate the corresponding IPTables marking rules, so as to achieve precise classification of the network traffic of the target program.

[0066] Based on the program recognition rules defined in the configuration file, the embodiments of the present application can automatically locate the running instances of the target program in the system and add them to the specified cgroup group. And it can support timed dynamic scanning to ensure that its binding relationship can be updated in time when the program instance starts, migrates, or restarts.

[0067] As a preferred implementation, in identifying and matching the running instances of the target program, the matching method includes:

[0068] If the running instance of the target program is a local process, obtain its PID through name matching, and parse the net_cls path from / proc / {pid} / cgroup;

[0069] An implementation of process name matching is as follows:

[0070] Obtain the process pid: pgrep -x {proc_name}

[0071] Obtain the cgroup path: cat / proc / {pid} / cgroup | grep net_cls

[0072] If the running instance of the target program is a container instance, retrieve the container ID through Docker commands, and then parse the cgroup mount point in combination with the system path structure;

[0073] Get the container ID: docker ps --filter "name={container_name}" --format "{{.ID}}"

[0074] If the running instance of the target program is in the container name prefix scenario, automatically generate a unique classid for each newly discovered container and write it into the corresponding net_cls control file.

[0075] Match the container list: docker ps --filter "name=^{prefix}" --format "{{.ID}}"

[0076] After the binding is completed, the system automatically writes the corresponding classid into the net_cls control file of the target program and generates the corresponding IPTables marking rules to achieve precise classification of outbound traffic.

[0077] Set net_cls.classid

[0078] Assign a classid to the target program or container:

[0079] echo {classid} > / sys / fs / cgroup / {netcls_path} / net_cls.classid

[0080] As a preferred implementation manner, the method for the embodiment of the present application to assign a unique classid is:

[0081] Set the classid format, using hierarchical decimal encoding, where the first three digits are the system number, the middle four digits are the program identifier, and the last three digits are the increment number of the program instance.

[0082] An example of setting net_cls.classid is as follows:

[0083] echo 0x00100001 > / sys / fs / cgroup / {netcls_path} / net_cls.classid

[0084] In addition, as a preferred implementation manner, it further includes a conflict management step, and the method is:

[0085] Use the increment logic of the instance number segment in the classid encoding strategy to prevent classid conflicts caused by container restart or concurrent generation. In the embodiment of the present application, the last three digits of the classid encoding are used to prevent conflicts, and the last three digits are used for the following situations:

[0086] For those that are prefixes of container names, the class ID of each container is incremented from 0 for assignment.

[0087] For those where the preset class ID has been occupied, it will be incremented by 1 based on that class ID. For example, if 314001000 is occupied, 314001001 will be assigned.

[0088] Recycle the assigned class IDs, and when the container or process exits, the occupied numbers are automatically released.

[0089] S3: Periodically collect the number of bytes of IPtables rules, perform traffic statistics on various programs and store them.

[0090] The main commands for an example implementation of creating IPtables rules for a specified network card based on the set class ID are as follows:

[0091] IPtables -t mangle -A POSTROUTING -m cgroup --cgroup {classid} -o {network card}

[0092] This application periodically collects the number of bytes of IPtables rules to implement traffic statistics for various programs.

[0093] It can be configured in terms of the collection granularity, so as to support collection intervals such as second level and minute level, and meet the accuracy and performance balance in different scenarios;

[0094] The method for calculating the bandwidth is as follows: The system records the absolute value of each collection, calculates the average bandwidth through the front and back sampling intervals. As a variant implementation, other calculation methods can also be used for calculation.

[0095] In order to further improve security, this application adopts a local storage mechanism, encrypts all collected data symmetrically and stores it in the local log file to prevent being tampered with or accidentally lost. The file adopts an incremental write and signature verification mechanism to ensure data continuity and integrity.

[0096] In addition, the function of background asynchronous reporting can also be considered. The system provides a plug-in reporting interface, and the data can be asynchronously sent to a remote traffic analysis platform or database system to avoid affecting the performance of the main collection process.

[0097] S4: Display the traffic statistics and analysis results.

[0098] View the traffic statistics data in real time through the IPtables command. An example of viewing is as follows:

[0099] IPtables -t mangle -v -S POSTROUTING

[0100] The output examples are as follows:

[0101] pkts bytes target prot opt in out source destination100 5600-all--*eth0 0.0.0.0 / 0 0.0.0.0 / 0cgroup 0x00100001

[0102] Among them, the bytes field is the traffic data of the specified program or container.

[0103] The results include the number of data packets and the total number of bytes, and can track the traffic changes of different programs or containers in real time.

[0104] This application supports displaying the statistical results from multiple perspectives, facilitating managers to quickly locate high-traffic programs or abnormal bandwidth usage situations, including one or any combination of the following methods.

[0105] Displaying the traffic statistics and analysis results is presented at the program level, including displaying traffic data classified by process name, container ID, or prefix.

[0106] Displaying the traffic statistics and analysis results is presented at the network interface level: aggregating and displaying by physical network interface (interface) dimension to adapt to multi-network interface hosts.

[0107] Displaying the traffic statistics and analysis results as a time series chart, including visualization components such as the system integrated bandwidth trend chart and the total traffic ranking, etc., to observe the resource usage changes during long-term operation.

[0108] The multi-dimensional display can assist managers in achieving efficient network resource monitoring and optimization decisions.

[0109] It is also possible to consider supporting the integration of the display results and the reporting interface into a unified Web interface to form an operation-friendly visualization dashboard.

[0110] The embodiment of this application also provides a storage medium, on which a computer program is stored. When the computer program is run by a processor, it executes the multi-program traffic statistics method based on IPtables and cgroup as described above.

[0111] The embodiment of this application also provides an electronic device, including: a processor, a storage medium, and a bus. The storage medium stores machine-readable instructions executable by the processor. When the electronic device runs, the processor communicates with the storage medium through the bus, and the processor executes the machine-readable instructions to execute the multi-program traffic statistics method based on IPtables and cgroup as described in any of the above.

[0112] It should be noted that those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the storage medium can include but is not limited to: read-only memory (ROM, Read Only Memory), random access memory (RAM, Random Access Memory), magnetic disks or optical discs, etc.

[0113] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but rather will be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A multi-program traffic statistics method based on IPTables and cgroup, characterized in that It includes the following steps: S1: Set up a configuration file recognized by the program, set the target object for traffic statistics and its identification policy, and place the traffic marking operation on the POSTROUTING chain in IPTables; S2: Identify and match the running instances of the target program, add the eligible programs to the specified cgroup group, assign a unique classid to them, and automatically generate the corresponding IPTables marking rules; S3: Periodically collect the byte counts of IPTables rules, perform traffic statistics on various programs and store them; S4: Display the traffic statistics and analysis results.

2. The multi-program traffic statistics method based on IPtables and cgroup according to claim 1, characterized in that In step S2 for identifying and matching the running instances of the target program, the matching methods include: If the running instance of the target program is a local process, obtain its PID by name matching and parse the net_cls path from / proc / {pid} / cgroup; If the running instance of the target program is a container instance, retrieve the container ID through Docker commands and then parse the cgroup mount point in combination with the system path structure; If the running instance of the target program is in the scenario of container name prefix, automatically generate a unique classid for each newly discovered container and write it into the corresponding net_cls control file.

3. The multi-program traffic statistics method based on IPTables and cgroup according to claim 1 or 2, characterized in that, Step S2 also includes a conflict management step, and its method is: Use the increment logic of the instance number segment in the classid encoding policy to prevent classid conflicts caused by container restart or concurrent generation; Recycle the assigned classids and automatically release the occupied numbers when the container or process exits.

4. The multi-program traffic statistics method based on IPtables and cgroup according to claim 1, characterized in that, The method for assigning classids in step S2 is: adopt hierarchical decimal encoding, with the first three digits being the system number, the middle four digits being the program identifier, and the last three digits being the increment number of the program instance.

5. The multi-program traffic statistics method based on IPTables and cgroup according to claim 1, characterized in that S1: The configuration file for setting up program recognition includes: program name, program type, classid encoding rule, collection frequency.

6. The multi-program traffic statistics method based on IPtables and cgroup according to claim 1, characterized in that S4: Displaying the traffic statistics and analysis results is presented at the program dimension, including displaying traffic data classified by process name, container ID or prefix.

7. The multi-program traffic statistics method based on IPtables and cgroup as described in claim 1, characterized in that S4 : Displaying the traffic statistics and analysis results is presented at the line dimension: aggregated and displayed by physical network card (interface) dimension to adapt to multi-network card hosts.

8. The multi-program traffic statistics method based on IPTables and cgroup according to claim 1, characterized in that S4 : Displaying the traffic statistics and analysis results is presented as a time series chart, including visualization components such as the system integrated bandwidth trend chart and the total traffic ranking, etc., to observe the resource usage changes under long-term operation.

9. A multi-program traffic statistics system based on IPTables and cgroup, used to implement the multi-program traffic statistics method based on IPTables and cgroup according to any one of claims 1-7, characterized in that, It includes: A program configuration unit for setting up a configuration file recognized by the program, setting the target object for traffic statistics and its identification policy, and placing the traffic marking operation on the POSTROUTING chain in IPTables; An automatic identification and binding unit for identifying and matching the running instances of the target program, adding the eligible programs to the specified cgroup group, assigning a unique classid to them, and automatically generating the corresponding IPTables marking rules, so as to achieve precise classification of the network traffic of the target program; A traffic collection and storage unit, which is used to periodically collect the number of bytes of IPtables rules and perform traffic statistics on various programs; A traffic display unit, which is used to display the traffic statistics and analysis results.

10. An electronic device, characterized in that, Including: A processor, a storage medium and a bus. The storage medium stores machine-readable instructions executable by the processor. When the electronic device runs, the processor communicates with the storage medium through the bus. The processor executes the machine-readable instructions to perform the multi-program traffic statistics method based on IPtables and cgroup as described in any one of claims 1-8.