Link configuration processing method and device for software system

By crawling and analyzing the data traffic of the software system, and automatically configuring the links required for new functions, the problem of low configuration efficiency when expanding functions in the software system is solved and link configuration efficiency is improved.

CN120342857AActive Publication Date: 2025-07-18TIANJIN ANHUA JINHE TECH CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510812808.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-07-18
Estimated Expiration
2045-06-18

AI Technical Summary

Technical Problem

The problem of low configuration efficiency when expanding functions in software systems is required for operation and maintenance personnel.

Method used

During the operation of the software system, the links required for new functions are captured, and the links required for new functions are analyzed and configured automatically to complete the link configuration process, reducing manual intervention.

Benefits of technology

It improves link configuration efficiency, reduces the workload of operation and maintenance personnel and the need to rely on manual experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342857A_ABST
    Figure CN120342857A_ABST
Patent Text Reader

Abstract

The invention discloses a link configuration processing method and device for a software system. The method comprises the following steps: capturing data traffic generated when the software system runs; obtaining a new function configured in the software system; acquiring predetermined data and / or service of the software system required to be used by the new function; the captured data traffic is analyzed, and the analysis is used for searching for the preset traffic using the preset data and / or service from the data traffic; and acquiring a link capable of accessing the predetermined data and / or service from the predetermined flow, and configuring the link capable of accessing the predetermined data and / or service to the new function. According to the method and the device, the problem of relatively low configuration efficiency due to the need of operation and maintenance personnel during function expansion in a software system is solved, so that the link configuration efficiency can be improved to a certain extent.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the software field, and more particularly, to a method and apparatus for processing link configuration of a software system. Background Art

[0002] A software system generally includes multiple services. For example, services for providing web pages, services for providing databases, services for providing email, etc. Each service runs on a server (including physical servers and / or cloud servers here), and each service provides services at a certain IP address and port, and these IP addresses and port numbers are generally mastered by operation and maintenance personnel.

[0003] In the related art, it is desired that the software system be more flexible and easy to expand, and this expansion work may also be provided to ordinary users (the users here refer to the users who use this software system). For example, users can configure to achieve their desired functions. When the software system expands its functions, it needs to use some original services on the software system. At this time, operation and maintenance personnel are required to perform configuration. For operation and maintenance personnel, they also need to perform security evaluation and other work before configuration, and the efficiency is relatively low. Summary of the Invention

[0004] Embodiments of this application provide a method and apparatus for processing link configuration of a software system, so as to at least solve the problem of relatively low efficiency in configuration by operation and maintenance personnel during function expansion in a software system.

[0005] According to one aspect of this application, a method for processing link configuration of a software system is provided, including: during the operation of the software system, capturing the data traffic generated during the operation of the software system; obtaining a new function configured in the software system, where the new function is a software function provided for users by using existing services and / or data in the software system; obtaining the predetermined data and / or services of the software system required by the new function; analyzing the captured data traffic, where the analysis is used to find the predetermined traffic that uses the predetermined data and / or services from the data traffic; obtaining the link capable of accessing the predetermined data and / or services from the predetermined traffic, and configuring the link accessing the predetermined data and / or services for the new function.

[0006] Further, the data traffic includes at least one of the following: data traffic between various service ends of the software system, data traffic between the client and various service ends.

[0007] Further, the step of configuring a link capable of accessing the predetermined data and / or service for the new function includes: obtaining whether the asset corresponding to the link capable of accessing the predetermined data and / or service is in the asset table, where the asset includes a network address and / or a port number. If the asset is not in the asset table, then look for another link capable of accessing the predetermined data and / or service until the asset corresponding to the found link is in the asset table, and then configure the found link for the new function.

[0008] Further, it also includes: obtaining all assets in the captured traffic, and after auditing and classifying the assets, configuring the obtained assets in the asset table. Among them, auditing and classifying the assets includes: classifying the assets into newly discovered assets, non-occurring assets, or different assets. The newly discovered assets are those with network addresses and / or port numbers that appear in the traffic but are not included in the asset table; the non-occurring assets are the assets existing in the asset table but without traffic accessing the asset in the traffic; the difference means that the access type in the traffic is inconsistent with the service type corresponding to the asset.

[0009] According to another aspect of the present application, there is also provided a link configuration processing device for a software system, including: a capture module, configured to capture the data traffic generated during the operation of the software system during the operation of the software system; a first acquisition module, configured to acquire a new function configured in the software system, where the new function is a software function provided for users by the existing services and / or data in the software system; a second acquisition module, configured to acquire the predetermined data and / or service of the software system required by the new function; an analysis module, configured to analyze the captured data traffic, where the analysis is used to find the predetermined traffic that uses the predetermined data and / or service from the data traffic; a configuration module, configured to obtain a link capable of accessing the predetermined data and / or service from the predetermined traffic and configure the link accessing the predetermined data and / or service for the new function.

[0010] Further, the data traffic includes at least one of the following: the data traffic between each server of the software system, the data traffic between the client and each server.

[0011] Further, the configuration module is configured to: obtain whether the asset corresponding to the link capable of accessing the predetermined data and / or service is in the asset table, where the asset includes a network address and / or a port number. If the asset is not in the asset table, then look for another link capable of accessing the predetermined data and / or service until the asset corresponding to the found link is in the asset table, and then configure the found link for the new function.

[0012] Further, the configuration module is further configured to: obtain all assets in the captured traffic, and after auditing and classifying the assets, configure the obtained assets in an asset table, where auditing and classifying the assets includes: classifying the assets into newly discovered assets, non-occurring assets, or differential assets, where the newly discovered assets are network addresses and / or port numbers that appear in the traffic and are not included in the asset table; the non-occurring assets are assets existing in the asset table, but there is no traffic accessing the asset in the traffic; the difference is that the access type in the traffic is inconsistent with the service type corresponding to the asset.

[0013] According to another aspect of the present application, there is also provided an electronic device, including a memory and a processor; wherein, the memory is used to store one or more computer instructions, and wherein, the one or more computer instructions are executed by the processor to implement the above method steps.

[0014] According to another aspect of the present application, there is also provided a readable storage medium, on which computer instructions are stored, and wherein, when the computer instructions are executed by a processor, the above method steps are implemented.

[0015] In the embodiments of the present application, during the operation of the software system, the data traffic generated during the operation of the software system is captured; the new functions configured in the software system are obtained, where the new functions are software functions that facilitate the existing services and / or data in the software system to provide to users; the predetermined data and / or services of the software system required by the new functions are obtained; the captured data traffic is analyzed, where the analysis is used to find the predetermined traffic that uses the predetermined data and / or services from the data traffic; the link that can access the predetermined data and / or services is obtained from the predetermined traffic, and the link accessing the predetermined data and / or services is configured for the new function. By the present application, the problem that the configuration efficiency is relatively low when the functions in the software system are extended and requires operation and maintenance personnel is solved, so that the link configuration efficiency can be improved to a certain extent. Description of the Drawings

[0016] The drawings constituting a part of the present application are used to provide a further understanding of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:

[0017] Figure 1 is a schematic diagram of the software system architecture according to the embodiments of the present application; and,

[0018] Figure 2 is a flowchart of the link configuration processing method of the software system according to the embodiments of the present application. Detailed Embodiments

[0019] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other. The present application will be described in detail below with reference to the drawings and in combination with the embodiments.

[0020] It should be noted that the steps shown in the flowchart of the drawings may be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than here.

[0021] In the following embodiments, a software system is split into three parts: a database, a data interface (which can also be simply referred to as an interface), and an application system. Among them, the application system can be understood as a system that interacts with users. For example, in a BS system, the interaction system is the WEB page, and the user selects the required functions through the WEB page and then calls the data in the database to display to the user. The data interface is presented for developers to use, and developers can process the data in the database through the data interface. The database is used to store data. The database and the application system need to provide services through a server, and the server mentioned here can be a real server or a cloud service. The database and the application system will be configured with corresponding network addresses (IP addresses) and ports (Port). In the following embodiments, the IP address and the port are referred to as assets. The application system and the data interface are connected to the database through a link. It should be noted that the data interface can also access the database through the application system, that is, the data interface can directly connect to the database or access the database through the service provided by the server where the application system is located. For example, if the application system is a web system and its service is provided through port 80 of a predetermined IP address, the user can access port 80 of this IP address through a browser to use the application system, and software developers can also pass parameters, etc. through port 80 of this predetermined IP address (i.e., the data interface). After the application system obtains the parameters, it accesses the database and processes the data in the database.

[0022] Figure 1 is a schematic diagram of the software system architecture according to the embodiments of the present application, as Figure 1 shown, in Figure 1 there are application system A, application system B, database C, database D, interface E, and interface F. Users (through terminals) can access application system A and application system B (terminals can also access application systems through proxies). Interface E accesses the database through application system A and application system B, and interface F can directly access the database. It should be noted that although two application systems, databases, and interfaces are shown in Figure 1 in fact, the application systems, databases, and interfaces can also be one or more. The network connections between the application systems, databases, and interfaces can be referred to as links.Figure 1 In the application system, the database, and the interface, IP addresses and ports can be configured. Therefore, the application system, the database, and the interface can also be referred to as assets. In Figure 1 the application system A plus the database C can implement a complete business function. In the following embodiments, the application system A and the database C are also referred to as business subsystems. A software system can include multiple business subsystems. When creating a new business subsystem, in addition to completing the relevant code, it is also necessary to arrange servers, databases, etc. that can support the application system for the new business subsystem. At this time, it is also necessary to allocate IP addresses and ports to the servers, databases, etc. The link between the servers and databases can also be considered. For example, link capacity, backup links, etc. The selection and configuration of these IP addresses, ports, and links can be carried out by the administrator, but the manual configuration workload is increased, and it also depends on human experience, and the efficiency is relatively low.

[0023] In the following embodiments, two methods are provided for configuring resources for the new business system. Method 1: The process of creating a subsystem based on link reachability. For example, by specifying an entry service, the creation of the subsystem can be quickly completed according to the asset list recommended by the link reachability. Method 2: The process of creating a subsystem based on data content. For example, given Zhang San's personal information, a subsystem can be constructed according to the links involving Zhang San's personal information during the access process. For a link, each link can also be sampled according to the behavior involved in the link (SQL / URL), and the business of the link can be annotated according to the capabilities of the large model.

[0024] The following is an example for illustration.

[0025] The user needs to add a function in the software system. For example, adding a function of the patient's walking path in the hospital in the medical system. This function can be called a software subsystem (or business subsystem). The system needs to obtain information such as the registration time and consultation time of the patient in each department of the hospital and the time of various operations of the patient on each self-service machine in the hospital. These information need to be read from the database, and these data are stored in database A and database B. After the user configures these functions, they do not need to know in which databases these data are located, nor do they need to know the IP addresses and port numbers of these databases.

[0026] Here, the usual processing method is to let the administrator of the software system configure database A and database B, but this configuration efficiency is relatively low. To solve this problem, in the following embodiments, a method for processing link configuration of a software system is provided. Figure 2 is a flowchart of the method for processing link configuration of a software system according to an embodiment of the present application. The following Figure 2 steps involved in the method in will be described.

[0027] Step S202, during the operation of the software system, capture the data traffic generated during the operation of the software system, where the data traffic includes at least one of the following: the data traffic between each server of the software system, the data traffic between the client and each server.

[0028] There are many methods for capturing data traffic. This will be described in combination with examples below.

[0029] In this example, a method for optimizing traffic capture based on memory design is provided, which specifically includes the following steps: start a packet capture process, perform packet capture processing on the data traffic, and obtain multiple data packets according to the single-threaded read and single-threaded write mode; cache multiple example data packets into a shared memory circular buffer pool, perform circular scheduling on the memory of the example shared memory circular buffer pool, and analyze the data read and write situation in real time. When data read and write are required, perform the process of pulling data packets; obtain the pulled multiple data packets, start a parsing process, and parse the multiple example data packets according to the single-threaded read and single-threaded write mode.

[0030] Starting a packet capture process and performing packet capture processing on the data traffic and obtaining multiple data packets according to the single-threaded read and single-threaded write mode specifically include the following steps: receive the packet capture process signal and determine the number of CPU cores; perform multi-threaded packet capture according to the packet capture process signal and the number of CPU cores to obtain multiple data packets; distribute the multiple data packets. The example caches the multiple example data packets into a shared memory circular buffer pool, performs circular scheduling on the memory of the example shared memory circular buffer pool, and analyzes the data read and write situation in real time. When data read and write are required, performing the process of pulling data packets specifically includes the following steps: cache the multiple example data packets distributed by the data packets into the shared memory circular buffer pool; perform circular scheduling on the memory of the example shared memory circular buffer pool; analyze the data read and write situation in real time to determine whether data read and write are required; when data read and write are required, perform the process of pulling data packets.

[0031] The example specifically includes the following steps for performing circular scheduling on the memory of the example shared memory circular buffer pool: perform circular traversal memory calls on the shared memory circular buffer pool; when the memory in the shared memory circular buffer pool is full during traversal, overwrite and store in the example shared memory circular buffer pool. The example obtains the pulled multiple data packets, starts a parsing process, and parses the multiple example data packets according to the single-threaded read and single-threaded write mode specifically includes the following steps: obtain the pulled multiple data packets; receive the parsing process signal; perform multi-threaded parsing on the multiple example data packets according to the parsing process signal and the number of CPU cores.

[0032] Step S204, obtain the new functions configured in the software system, where the new functions are software functions that facilitate the services in the software system to provide to users.

[0033] Step S206, obtain the predetermined data and / or services of the software system required by the new function.

[0034] Step S208, analyze the captured data traffic, wherein the analysis is used to find the predetermined traffic that uses the predetermined data and / or services from the data traffic.

[0035] Step S210, obtain the link that can access the predetermined data and / or services from the predetermined traffic, and configure the link that can access the predetermined data and / or services to the new function.

[0036] It should be noted here that since the traffic can be publicly captured, various access links exposed in the traffic (the links here include interfaces, etc.) are also safe for the software system. This is because the administrator will not expose the links that can pose a security threat to the software system. Therefore, the links obtained through the analysis of the captured traffic can be normally accessed and used. At the same time, for each newly added function, the administrator does not need to make configurations, and these configurations can be automatically completed by the software. Therefore, the above steps solve the problem that the configuration efficiency is relatively low when the function is extended in the software system, thereby improving the link configuration efficiency to a certain extent.

[0037] As an optional implementation manner, when searching for the link corresponding to the predetermined data, if multiple links are found, construct the access path of the predetermined data according to the start point and end point of the multiple links, and determine at least one point in the access path according to the access path and the new function to be configured to the new function.

[0038] Optionally, the above Figure 2 The step of configuring the link that can access the predetermined data and / or services to the new function may further include the following steps: obtain whether the asset corresponding to the link that can access the predetermined data and / or services is in the asset table, wherein the asset includes a network address and / or a port number. If the asset is not in the asset table, find another link that can access the predetermined data and / or services until the asset corresponding to the found link is in the asset table, and then configure the found link to the new function.

[0039] Optionally, it may further include: obtaining all assets in the captured traffic, and after auditing and classifying the assets, allocating the obtained assets in an asset table, where auditing and classifying the assets includes: classifying the assets into newly discovered assets, non-occurring assets, or discrepant assets, where the newly discovered assets are network addresses and / or port numbers that appear in the traffic but are not included in the asset table; the non-occurring assets are assets existing in the asset table, but there is no traffic accessing the asset in the traffic; the discrepancy means that the access type in the traffic is inconsistent with the service type corresponding to the asset. For example, the configuration is consistent (IP + PORT are the same), but the service configuration is inconsistent (such as Mysql in the asset table, but the actual traffic shows an Oracle access protocol). Through the above mechanism, the asset table is iterated to ensure that the asset table is consistent with the actual situation.

[0040] MySQL is a relational database management system. MySQL is one of the most popular relational database management systems. In terms of WEB applications, MySQL is a relatively good relational database management system (Relational Database Management System, abbreviated as RDBMS), one of the application software. MySQL is a relational database management system. Relational databases store data in different tables instead of putting all data in a large warehouse, which increases speed and improves flexibility. The SQL language used by MySQL is the most commonly used standardized language for accessing databases. MySQL software adopts a dual-licensing policy, divided into community edition and commercial edition. Due to its small size, fast speed, low total cost of ownership, especially the feature of open source code, MySQL is generally chosen as the website database for the development of small and medium-sized and large websites.

[0041] Oracle - Database, also known as Oracle - RDBMS, or simply Oracle for short. It is a relational database management system of Oracle Corporation. It has good portability, is easy to use, and has strong functions, suitable for various large, medium, small, and microcomputer environments. It is a database solution with high efficiency, good reliability, and suitable for high throughput.

[0042] For the above examples of database A and database B, use Figure 2The method shown in the figure searches for the traffic involving accessing Database A and Database B through the collected traffic, and then configures the new function according to the access links in the traffic, so that the new function can access Database A and Database B, and further enables the realization of the new function. In the above step S210, the links capable of accessing the predetermined data and / or services are obtained from the predetermined traffic, and the links capable of accessing the predetermined data and / or services are configured for the new function. As an alternative implementation, multiple links capable of accessing the predetermined data and / or services are obtained from the predetermined traffic, sorted, and the sorted multiple links are configured for the new function; among them, the new function preferentially uses the first one of the sorted multiple links to access the predetermined data / services, and in the case of an exception when using the first one, uses the second link after the first one of the sorted multiple links to access the predetermined data and / or services, and so on.

[0043] There are many ways to sort the multiple links. As an alternative implementation, sorting the multiple links includes: obtaining the number of times each link in the multiple links appears in the traffic, where if the link appears in a complete data packet in the traffic, it is counted as one time; obtaining a first score based on the number of times, where the higher the score, the more times it appears; taking the average size of all the data packets in which the link appears and obtaining a second score based on the average size, where the higher the second score, the larger the average size; weighting the first score and the second score to obtain a score, and sorting according to the score corresponding to each link, where the higher the score, the higher the ranking.

[0044] In the above step S208, there are many implementation ways to analyze the captured data traffic to obtain the predetermined traffic that uses the predetermined data and / or services. For example, analyzing the captured data traffic to obtain the predetermined traffic that uses the predetermined data and / or services includes: obtaining the indication information of the predetermined data and / or services used by the new function, where the indication information is used to indicate the name or attribute of the predetermined data and / or services; analyzing the tags corresponding to the data traffic to obtain the data traffic with a similarity between the tags and the indication information exceeding the threshold; taking the data traffic exceeding the threshold as the predetermined traffic; where the tags are used to indicate the functions of the links where the data traffic is located.

[0045] There are many ways to tag the functions of links in data traffic. For example, a neural network model can be trained. The neural network model is trained using multiple sets of training data, where each set of training data includes the data traffic and a tag on a link, and the tag is used to indicate the function of the link. After the training converges, the data traffic that needs to be tagged is input into the neural network model, and the tag output by the neural network model is used as the tag of the link. In this example, each link can sample according to the behaviors involved in the link (SQL / URL) and implement the annotation of the link service (which can also be understood as the link function) according to the capabilities of the large model. For example, the functions of annotating the link can include: obtaining data, data query, querying public data, reporting and exchanging data, etc.

[0046] Through the above implementation, the problem that the configuration efficiency is relatively low when functional expansion is required by operation and maintenance personnel in the software system is solved, so that the link configuration efficiency can be improved to a certain extent.

[0047] In this embodiment, an electronic device is provided, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the method in the above embodiment.

[0048] The above program can run in the processor, or can also be stored in the memory (or referred to as a computer-readable medium). The computer-readable medium includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.

[0049] These computer programs can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate computer-implemented processing. Thus, the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 a process or multiple processes and / or Figure 1 boxes or multiple boxes. The corresponding different steps can be implemented by different modules.

[0050] In this embodiment, such a device or system is provided. The device is called a link configuration processing device for a software system, and includes: a capture module, configured to capture the data traffic generated during the operation of the software system; a first acquisition module, configured to acquire a new function configured in the software system, where the new function is a software function that facilitates the existing services and / or data in the software system to provide to users; a second acquisition module, configured to acquire the predetermined data and / or services of the software system required by the new function; an analysis module, configured to analyze the captured data traffic, where the analysis is used to find the predetermined traffic that uses the predetermined data and / or services from the data traffic; a configuration module, configured to acquire the link capable of accessing the predetermined data and / or services from the predetermined traffic, and configure the link for accessing the predetermined data and / or services to the new function.

[0051] This system or device is used to implement the functions of the method in the above embodiment. Each module in this system or device corresponds to each step in the method, and those that have been described in the method will not be elaborated here.

[0052] Optionally, the data traffic includes at least one of the following: the data traffic between the server ends of the software system, the data traffic between the client and each server end.

[0053] Optionally, the configuration module is configured to: acquire whether the asset corresponding to the link capable of accessing the predetermined data and / or services is in the asset table, where the asset includes a network address and / or a port number. If the asset is not in the asset table, then find another link capable of accessing the predetermined data and / or services until the asset corresponding to the found link is in the asset table, and then configure the found link to the new function.

[0054] Optionally, the configuration module is further configured to: acquire all the assets in the captured traffic, and after auditing and classifying the assets, configure the acquired assets in the asset table, where auditing and classifying the assets includes: classifying the assets into newly discovered assets, non - occurring assets or differential assets. The newly discovered assets are the network addresses and / or port numbers that appear in the traffic but are not included in the asset table; the non - occurring assets are the assets existing in the asset table, but there is no traffic accessing the asset in the traffic; the difference is that the access type in the traffic is inconsistent with the service type corresponding to the asset.

[0055] By the above - mentioned implementation manner, the problem that the configuration efficiency is relatively low when the function of the software system is expanded and requires operation and maintenance personnel is solved, so that the link configuration efficiency can be improved to a certain extent.

[0056] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

Claims

1. A method for processing link configuration of a software system, characterized in that Including: During the operation of the software system, capturing the data traffic generated during the operation of the software system; Obtaining the new functions configured in the software system, where the new functions are software functions that facilitate the existing services and / or data in the software system to provide to users; Obtaining the predetermined data and / or services of the software system required by the new functions; Analyzing the captured data traffic, where the analysis is used to find the predetermined traffic that uses the predetermined data and / or services from the data traffic; Obtaining the link that can access the predetermined data and / or services from the predetermined traffic, and configuring the link that accesses the predetermined data and / or services to the new function.

2. The method according to claim 1, wherein The data traffic includes at least one of the following: The data traffic between the various servers of the software system, the data traffic between the client and the various servers.

3. The method according to claim 1, wherein The step of configuring the link that can access the predetermined data and / or services to the new function includes: Obtaining whether the asset corresponding to the link that can access the predetermined data and / or services is in the asset table, where the asset includes a network address and / or a port number. If the asset is not in the asset table, then searching for another link that can access the predetermined data and / or services until the asset corresponding to the found link is in the asset table, and then configuring the found link to the new function.

4. The method according to claim 3, characterized in that, Also including: Obtaining all the assets in the captured traffic, and after auditing and classifying the assets, configuring the obtained assets in the asset table, where auditing and classifying the assets includes: classifying the assets into newly discovered assets, non-appearing assets, or differential assets. The newly discovered assets are the network addresses and / or port numbers that appear in the traffic and are not included in the asset table; the non-appearing assets are the assets existing in the asset table, but there is no traffic accessing the asset in the traffic; the difference is that the access type in the traffic is inconsistent with the service type corresponding to the asset.

5. A link configuration processing device for a software system, characterized in that, Including: A capture module, used to capture the data traffic generated during the operation of the software system during the operation of the software system; A first acquisition module, used to obtain the new functions configured in the software system, where the new functions are software functions that facilitate the existing services and / or data in the software system to provide to users; A second acquisition module, used to obtain the predetermined data and / or services of the software system required by the new functions; An analysis module, used to analyze the captured data traffic, where the analysis is used to find the predetermined traffic that uses the predetermined data and / or services from the data traffic; A configuration module, used to obtain the link that can access the predetermined data and / or services from the predetermined traffic, and configure the link that accesses the predetermined data and / or services to the new function.

6. The device according to claim 5, characterized in that, The data traffic includes at least one of the following: The data traffic between the various servers of the software system, the data traffic between the client and the various servers.

7. The device according to claim 5, characterized in that, The configuration module is used for: Obtain whether the asset corresponding to the link that can access the said predetermined data and / or service is in the asset table, where the asset includes a network address and / or a port number. If the asset is not in the asset table, find another link that can access the said predetermined data and / or service until the asset corresponding to the found link is in the asset table, and then configure the found link for the new function.

8. The device according to claim 7, characterized in that, The configuration module is further configured to: Obtain all assets in the captured traffic. After auditing and classifying the assets, configure the obtained assets in the asset table, where auditing and classifying the assets includes: classifying the assets as newly discovered assets, non - appearing assets, or discrepant assets. The newly discovered assets are those with network addresses and / or port numbers that appear in the traffic but are not included in the asset table; the non - appearing assets are the assets existing in the asset table but without traffic accessing them in the traffic; the discrepancy means that the access type in the traffic is inconsistent with the service type corresponding to the asset.

9. An electronic device, comprising a memory and a processor; wherein, The memory is used to store one or more computer instructions, where the one or more computer instructions are executed by the processor to implement the method steps described in any one of claims 1 to 4.

10. A readable storage medium having computer instructions stored thereon, wherein, When the computer instruction is executed by the processor, it implements the method steps described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Traffic scheduling method, device and system

    CN111510393A

  • Storage software system tuning method and device and computer readable storage medium

    CN112269536A

  • Database traffic filtering method and system based on remote call network address

    CN116866209A

  • Method and device for determining calling relation, equipment and medium

    CN117785602A

  • Method and system for judging asset relationship based on data flow

    CN118521405A