Gateway packet capturing method, gateway equipment, electronic equipment and storage medium

By adopting a dual-processing core architecture in the gateway equipment, the packet capture and detection tasks are separated, and the problem of inefficient packet capture of traditional gateway equipment is solved, and more efficient packet capture operations are achieved.

CN120343112APending Publication Date: 2025-07-18WUHAN SIPU TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510746318.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-05
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The packet capture efficiency of traditional gateway devices is mainly due to the control core that needs to process packet forwarding and packet capture tasks at the same time, resulting in delay and inefficiency.

Method used

Using a dual-processing core architecture, the first processing core is responsible for continuously crawling data packets and storing them in memory space. The second processing core detects the packet capture conditions and controls the packet capture operation of the first processing core, separates the packet capture and detection tasks to reduce mutual interference.

Benefits of technology

Through the separation of packet capture and detection operations, the packet capture delay is reduced and the packet capture efficiency of gateway equipment is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120343112A_ABST
    Figure CN120343112A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication, and discloses a gateway packet capturing method, gateway equipment, electronic equipment and a computer readable storage medium. The gateway packet capturing method is applied to gateway equipment comprising a first processing core and a second processing core, and comprises the following steps: continuously capturing data packets by the first processing core, and storing target data of each captured data packet into a set memory space; and the second processing core detects whether the target data in the set memory space satisfies a set capture stop condition, and the first processing core stops capturing the data packet in response to the target data satisfying the set capture stop condition. According to the invention, the problem of low gateway packet capturing efficiency can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a method for a gateway to capture packets, a gateway device, an electronic device, and a computer-readable storage medium. Background Art

[0002] Today, with the accelerating digital transformation, the scale and complexity of networks have increased explosively. As the hub between different networks, the gateway bears core functions such as traffic forwarding and security protection. Gateway packet capture, as an important means for network monitoring, fault diagnosis, and security auditing, directly affects the effectiveness of network management.

[0003] In the field of network security, as a core protection device, a security gateway device needs to monitor and analyze network traffic in real time to detect potential threats. Traditional packet capture methods usually synchronously process data packets by the control core, that is, directly filter and store when receiving packets. The control core needs to process both packet forwarding and packet capture tasks simultaneously, which is likely to cause delays and result in low packet capture efficiency of the gateway device. Summary of the Invention

[0004] In view of this, it is necessary to provide a method for a gateway to capture packets, a gateway device, an electronic device, and a computer-readable storage medium to solve the problem of low packet capture efficiency of the gateway.

[0005] To solve the above problems, this application provides a method for a gateway to capture packets, which is applied to a gateway device including a first processing core and a second processing core, and includes: the first processing core continuously captures data packets and stores the target data of each captured data packet in a set memory space; the second processing core detects whether the target data in the set memory space meets a set packet capture stop condition, and in response to the target data meeting the set packet capture stop condition, the first processing core stops capturing data packets.

[0006] In an optional embodiment, the gateway device includes a global linked list. After storing the target data of each captured data packet in the set memory space, the method for the gateway to capture packets further includes: the first processing core adds the set memory space to the global linked list.

[0007] In an optional embodiment, the detecting whether the target data in the set memory space meets a set packet capture stop condition includes: at intervals of a set time period, the second processing core respectively detects whether the target data in each set memory space in the global linked list meets the set packet capture stop condition; in response to any target data meeting the set packet capture stop condition, the first processing core stops capturing data packets.

[0008] In an alternative embodiment, after the first processing core stops capturing data packets, the gateway packet capturing method further includes: the second processing core writes all the target data in the global linked list into a target file, clears the global linked list, and saves the target file. When the first processing core stops capturing data packets, that is, when the second processing core detects that the target data in the set memory space meets the set packet capture stop condition, it indicates that there may be a problem with the data packets captured by the gateway device. At this time, the second processing core writes all the target data in the global linked list into the target file, which can back up the relevant data of the suspected problematic data packets, facilitating subsequent verification of the relevant data. At the same time, clearing the global linked list can also delete the relevant data suspected of having problems, thereby avoiding the impact of this part of the data on the network security of the gateway device.

[0009] In an alternative embodiment, the gateway packet capturing method further includes: the second processing core sends the target file to a set terminal, and the set terminal is used to perform data analysis on the target file.

[0010] In an alternative embodiment, writing all the target data in the global linked list into the target file includes: obtaining the target file format corresponding to the set terminal, and writing all the target data into the target file in the target file format. Writing the target data into the target file in the corresponding target file format can make it more convenient for the set terminal to perform data analysis on the target file.

[0011] In an alternative embodiment, the first processing core continuously captures data packets, including: obtaining a set packet capture condition; the first processing core continuously receives the data packets, and in response to the data packets meeting the set packet capture condition, captures the data packets, and in response to the data packets not meeting the set packet capture condition, forwards the data packets.

[0012] This application also provides a gateway device, including: a first processing core, configured to continuously capture data packets and store the target data of each captured data packet in a set memory space; a second processing core, configured to detect whether the target data in the set memory space meets a set packet capture stop condition, and in response to the target data meeting the set packet capture stop condition, stop capturing data packets.

[0013] This application also provides an electronic device, including a memory and a processor. Among them, the memory is used to store a program; the processor includes a first processing core and a second processing core, which are coupled to the memory, and the first processing core and the second processing core are used to execute the program stored in the memory to implement the gateway packet capturing method as described above.

[0014] The present application also provides a computer-readable storage medium for storing computer-readable programs or instructions, which can implement the gateway packet capture method as described above when executed by a processor.

[0015] The beneficial effects of the present application are as follows: Compared with the related art, in the gateway packet capture method provided by the present application, the first processing core of the gateway device continuously captures data packets, stores the target data of the data packets in a set memory space, and then the second processing core detects the target data stored in the set memory space to determine whether to stop packet capture. By assigning the packet capture operation to the first processing core and the detection operation to the second processing core, the packet capture operation and the detection operation can be separated, reducing the mutual interference between the two, thereby reducing the packet capture delay and improving the packet capture efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative efforts.

[0017] FIG. 1 is a schematic flowchart of a gateway packet capture method provided by an embodiment of the present application; Figure 2 is a schematic structural diagram of a gateway device provided by an embodiment of the present application; Figure 3 is a schematic flowchart of the first processing core continuously capturing data packets in the communication method provided by an embodiment of the present application; Figure 4 is a schematic flowchart of a gateway packet capture method provided by another embodiment of the present application; Figure 5 is a schematic structural diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0018] The following will specifically describe the preferred embodiments of the present application in conjunction with the drawings. The drawings form a part of the present application and are used together with the embodiments of the present application to explain the principle of the present application, rather than to limit the scope of the present application.

[0019] Please refer to Figure 1 , a specific embodiment of the present application discloses a gateway packet capture method applied to a gateway device 100 including a first processing core 101 and a second processing core 102 as shown in Figure 2 . The method specifically includes the following steps: Step S101: The first processing core continuously captures data packets and stores the target data of each captured data packet in a set memory space.

[0020] Step S102: The second processing core detects whether the target data in the set memory space meets the set packet capture stop condition.

[0021] Step S103: In response to the target data meeting the set packet capture stop condition, the first processing core stops capturing data packets.

[0022] Compared with the related art, in the gateway packet capture method provided by the present application, the first processing core of the gateway device continuously captures data packets, stores the target data of the data packets in the set memory space, and then the second processing core detects the target data stored in the set memory space to determine whether to stop packet capture. By allocating the packet capture operation to the first processing core and the detection operation to the second processing core, the packet capture operation and the detection operation can be separated, reducing the mutual interference between the two, thereby reducing the packet capture latency and improving the packet capture efficiency.

[0023] In some embodiments of the present application, please refer to Figure 3 , in step S101, the first processing core continuously capturing data packets specifically includes: Step S201: Obtain the set packet capture condition.

[0024] In this step, the set packet capture condition is specifically related packet capture parameters set in advance according to the need for data packets, and may specifically include but are not limited to the following parameters.

[0025] (1) Specify the packet capture interface (such as Ethernet interface, wireless interface, etc.).

[0026] (2) Set the source / destination IP address range for filtering traffic in a specific IP segment.

[0027] (3) Define the port number range, for example, only capture traffic on the specified port (such as 80, 443, etc.).

[0028] (4) Select the protocol type (such as TCP, UDP, ICMP, etc.).

[0029] (5) Set the duration of packet capture or the upper limit of the number of packets.

[0030] Step S202: The first processing core continuously receives data packets, captures the data packets in response to the data packets meeting the set packet capture condition, and forwards the data packets in response to the data packets not meeting the set packet capture condition.

[0031] In this step, the first processing core continuously receives data packets. For each received data packet, it determines whether the relevant parameters of the data packet are consistent with the packet capture parameters in the pre-set packet capture conditions according to the packet capture parameters in the pre-set packet capture conditions. If the relevant parameters of the data packet are consistent with the pre-set packet capture parameters, it is considered that the data packet meets the set packet capture conditions, and the data packet is captured; otherwise, if the relevant parameters of the data packet are inconsistent with the pre-set packet capture parameters, it is considered that the data packet does not meet the set packet capture conditions, and the data packet is not captured. Instead, the data packet is sent to the next network terminal.

[0032] In some embodiments of the present application, the set memory space in step S101 may specifically be a memory space that is pre-set in the memory and used to store the target data in the captured data packets. Pre-setting the storage space to store the target data of the captured data packets can more quickly determine the storage location of the target data and improve the packet capture efficiency; at the same time, since the storage location of the pre-set storage space is fixed, the second processing core in subsequent step S102 can more accurately read the target data when detecting whether the target data in the set memory space meets the set stop packet capture conditions, thereby improving the reliability of the entire packet capture process.

[0033] Or in some other embodiments of the present application, the set memory space may also be to apply for a corresponding storage space in the storage device as the set memory space for each captured data packet. In this way, the storage space in the storage device can be better utilized.

[0034] In some embodiments of the present application, the target data of the data packet may specifically include the data carried in the data packet and the relevant capture data generated when the first processing core captures the data packet. Based on the different types of data packets, the relevant capture data generated when the first processing core captures the data packet may also be different. The specific relevant capture data may include the capture timestamp of the data packet, meta-information data such as the protocol type, source / destination IP address, and port number of the data packet, and extended information data such as the length and checksum of the data packet.

[0035] In some embodiments of the present application, the set stop packet capture conditions in step S102 may specifically include pre-set judgment conditions. For example, it may include but is not limited to: (1) Keyword matching: Check whether the target data contains specific keywords or key phrases.

[0036] (2) Protocol anomaly detection: Analyze whether the protocol field of the target data conforms to the pre-set normal communication mode.

[0037] (3) Traffic feature analysis: Judge whether the data packet is an abnormal data packet according to the characteristics such as the size and frequency of the traffic corresponding to the target data.

[0038] The second processing core determines whether the target data in each set memory space meets the set packet capture stop condition. If the target data in any one of the set memory spaces meets the set packet capture stop condition, for example, if the protocol field of a target data does not conform to the preset normal communication mode, it is determined that the target data meets the set packet capture stop condition, and the first processing core stops capturing data packets; conversely, if the target data in each set memory space does not meet the set packet capture stop condition, the first processing core continues to capture data packets.

[0039] In some embodiments of the present application, when the second processing core in step S102 respectively detects whether the target data in each set memory space in the global linked list meets the set packet capture stop condition, specifically, for each data packet captured by the first processing core, after the target data is stored in the set memory space, the second processing core immediately checks the target data in the set memory space. Or in some other embodiments of the present application, it can also be that the second processing core uniformly checks all the target data stored in the set memory space by the first processing core within a preset time period at each interval. Or in still some other embodiments of the present application, it can also be that after the number of data packets captured by the first processing core reaches a set number threshold, the second processing core uniformly checks all the target data of the set number threshold.

[0040] Furthermore, when the second processing core checks the target data in multiple set memory spaces, specifically, it can check the target data in each set memory space one by one, or it can also check the target data in multiple set memory spaces simultaneously in parallel. It can be specifically set according to the actual data processing capacity and data processing function of the second processing core.

[0041] In some embodiments of the present application, a global linked list may also be set in the gateway device. On this basis, after the target data of each captured data packet is stored in the set memory space in step S101, the first processing core may also add the set memory space storing the target data to the global linked list. In the subsequent step S102, when the second processing core detects whether the target data in the set memory space meets the set packet capture stop condition, it can directly read the target data from the global linked list for detection and judgment. Among them, a linked list is a data structure composed of a series of nodes (Nodes), and each node contains data and a pointer (or reference) to the next node. And the "global linked list" refers to a linked list with a global scope, that is, the head node, operation functions, etc. of the linked list can be accessed within the global scope of the device, rather than being limited to a certain function or module. In the present application, the first processing core adding the set memory space to the global linked list means taking the set memory space storing the target data as a node in the global linked list. By setting a global linked list that can be accessed by the entire gateway device and adding the set memory space storing the target data as a node in the global linked list, the second processing core can directly obtain the target data from the global linked list for detection and comparison, thereby improving the efficiency of the second processing core in obtaining the target data, improving the overall verification efficiency of the second processing core, and further improving the overall packet capture efficiency of the gateway device.

[0042] On this basis, specifically, in step S102, detecting whether the target data in the set memory space meets the set packet capture stop condition may be: at every set time interval, the second processing core respectively detects whether the target data in each set memory space in the global linked list meets the set packet capture stop condition. If there is any target data in any set memory space that meets the set packet capture stop condition, the first processing core stops capturing data packets.

[0043] In some embodiments of the present application, the above global linked list may specifically be pkt_list. That is, each node in pkt_list is a pkt structure, and the global linked list is composed of multiple pkt structures. On this basis, specifically, in step S101, storing the target data of each captured data packet in the set memory space may be, for example, that the first processing core applies for a set memory space of the pkt structure for each data packet to the gateway device, then stores the target data of the data packet in the pkt structure, and finally takes this pkt structure as a node in pkt_list.

[0044] Please refer to Figure 4 , in some embodiments of the present application, after the first processing core stops capturing data packets, the gateway packet capture method may further include: Step S104: The second processing core writes all the target data in the global linked list into a target file, clears the global linked list, and saves the target file.

[0045] In this step, when the first processing core stops capturing data packets, that is, when the second processing core detects that the target data in the set memory space meets the set packet capture stop condition, it indicates that there may be a problem with the data packets captured by the gateway device. At this time, the second processing core writes all the target data in the global linked list into the target file, so as to back up the relevant data of the suspected problematic data packets, which is convenient for subsequent verification of the relevant data. At the same time, clearing the global linked list can also delete the relevant data suspected of having problems, thus avoiding the impact of this part of the data on the network security of the gateway device.

[0046] In some embodiments of the present application, after the second processing core writes all the target data in the global linked list into the target file, it can also send the target file to a set terminal, and the set terminal performs further data analysis on the target file, so as to better analyze the data packets captured by the gateway device and help the user understand the packet capture results of the gateway device. Among them, the set terminal can be, for example, a set server. The second processing core can send the target file to the set server through communication protocols such as HTTP / HTTPS, and analyze the target file in the set server. Subsequently, the user can download the analysis results of the target file from the set server according to actual needs.

[0047] In some embodiments of the present application, when writing all the target data in the global linked list into the target file, the target file format corresponding to the set terminal can also be obtained, and all the target data is written into the target file in the target file format. Writing the target data into the target file in the corresponding target file format can make it more convenient for the set terminal to perform data analysis on the target file.

[0048] Please refer to Figure 2 , the embodiment of the present application also provides a gateway device 100, including: A first processing core 101 and a second processing core 102. Among them, the first processing core 101 is used to continuously capture data packets and store the target data of each captured data packet in a set memory space; the second processing core 102 is used to detect whether the target data in the set memory space meets the set packet capture stop condition, and in response to the target data meeting the set packet capture stop condition, the first processing core stops capturing data packets.

[0049] It can be understood that the gateway device 100 provided in the embodiment of the present application is a device embodiment corresponding to the foregoing method embodiment. The relevant technical details in the foregoing embodiment can also be applied to this embodiment, and similarly, the relevant technical details in this embodiment can also be applied to the foregoing embodiment.

[0050] Please refer to Figure 5, this application also correspondingly provides an electronic device 500. The electronic device 500 includes a processor 501, a memory 502, and a display 503. Among them, the processor 501 includes a first processing core 504 and a second processing core 505. Figure 5 Only some components of the electronic device 500 are shown, but it should be understood that it is not required to implement all the shown components, and more or fewer components can be alternatively implemented.

[0051] In some embodiments, the processor 501 may be a central processing unit (CPU), a microprocessor, or other data processing chips, and is used to run the program code stored in the memory 502 or process data, such as the gateway packet capture method in this application.

[0052] In some embodiments, the processor 501 may be a single server or a server group. The server group may be centralized or distributed. In some embodiments, the processor 501 may be local or remote. In some embodiments, the processor 501 may be implemented on a cloud platform. In one embodiment, the cloud platform may include a private cloud, a public cloud, a hybrid cloud, a community cloud, a distributed cloud, an internal cloud, a multi-cloud, etc., or any combination of the above.

[0053] In some embodiments, the memory 502 may be an internal storage unit of the electronic device 500, such as the hard disk or memory of the electronic device 500. In some other embodiments, the memory 502 may also be an external storage device of the electronic device 500, such as a plug-in hard disk equipped on the electronic device 500, a smart media card (SMC), a secure digital (SD) card, a flash card, etc.

[0054] Furthermore, the memory 502 may also include both the internal storage unit of the electronic device 500 and the external storage device. The memory 502 is used to store the application software installed in the electronic device 500 and various types of data.

[0055] In some embodiments, the display 503 may be an LED display, a liquid crystal display, a touch liquid crystal display, and an OLED (Organic Light-Emitting Diode) toucher, etc. The display 503 is used to display the information in the electronic device 500 and for displaying a visual user interface. The components 501-503 of the electronic device 500 communicate with each other through a system bus.

[0056] In one embodiment, when the processor 501 executes the gateway packet capture program in the memory 502, the following steps may be implemented: The first processing core 504 continuously grabs data packets and stores the target data of each grabbed data packet into a set memory space; The second processing core 505 detects whether the target data in the set memory space meets the set packet capture stop condition. In response to the target data meeting the set packet capture stop condition, the first processing core stops grabbing data packets.

[0057] It should be understood that when the processor 501 executes the gateway packet capture program in the memory 502, in addition to the above functions, other functions can also be implemented. For specific details, reference can be made to the description of the corresponding method embodiments above.

[0058] Furthermore, the embodiments of the present application do not specifically limit the type of the mentioned electronic device 500. The electronic device 500 can be a portable electronic device such as a mobile phone, a tablet computer, a personal digital assistant (PDA), a wearable device, a laptop computer, etc. Exemplary embodiments of the portable electronic device include, but are not limited to, portable electronic devices running IOS, android, microsoft, or other operating systems. The above portable electronic devices can also be other portable electronic devices, such as a laptop computer with a touch-sensitive surface (such as a touch panel). It should also be understood that in some other embodiments of the present application, the electronic device 500 may not be a portable electronic device, but a desktop computer with a touch-sensitive surface (such as a touch panel).

[0059] Correspondingly, the embodiments of the present application also provide a computer-readable storage medium. The computer-readable storage medium is used to store computer-readable programs or instructions. When the programs or instructions are executed by a processor, the steps or functions in the gateway packet capture methods provided by the above various method embodiments can be implemented.

[0060] Those skilled in the art can understand that all or part of the processes of implementing the methods of the above embodiments can be completed by instructing relevant hardware (such as a processor, a controller, etc.) through a computer program. The computer program can be stored in a computer-readable storage medium. Among them, the computer-readable storage medium is a disk, an optical disk, a read-only memory, or a random access memory, etc.

[0061] The above has introduced in detail the gateway packet capture method, the gateway device, the electronic device, and the computer-readable storage medium provided by the present application. Specific examples are used in this article to elaborate on the principles and implementation manners of the present application. The descriptions of the above embodiments are only used to help understand the method and its core idea of the present application; at the same time, for those skilled in the art, according to the idea of the present application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present application.

Claims

1. A gateway packet capture method, which is applied to a gateway device including a first processing core and a second processing core, and is characterized in that, including: The first processing core continuously grabs data packets and stores the target data of each grabbed data packet into a set memory space; The second processing core detects whether the target data in the set memory space meets the set packet capture stop condition. In response to the target data meeting the set packet capture stop condition, the first processing core stops grabbing data packets.

2. The gateway packet capture method according to claim 1, wherein The gateway device includes a global linked list. After storing the target data of each grabbed data packet into the set memory space, the gateway packet capture method further includes: The first processing core adds the set memory space to the global linked list.

3. The gateway packet capture method according to claim 2, wherein, The detecting whether the target data in the set memory space meets the set packet capture stop condition includes: At every set time interval, the second processing core respectively detects whether the target data in each of the set memory spaces in the global linked list meets the set packet capture stop condition; In response to any of the target data meeting the set packet capture stop condition, the first processing core stops grabbing data packets.

4. The gateway packet capture method according to claim 2, wherein After the first processing core stops grabbing data packets, the gateway packet capture method further includes: The second processing core writes all the target data in the global linked list into a target file, clears the global linked list, and saves the target file.

5. The gateway packet capture method according to claim 4, wherein The gateway packet capture method further includes: The second processing core sends the target file to a set terminal, and the set terminal is used for performing data analysis on the target file.

6. The gateway packet capture method according to claim 5, wherein, The writing all the target data in the global linked list into the target file includes: Obtaining a target file format corresponding to the set terminal, and writing all the target data into the target file in the target file format.

7. The gateway packet capture method according to claim 1, characterized in that, The first processing core continuously grabs data packets, including: Obtaining a set packet capture condition; The first processing core continuously receives the data packets. In response to the data packets meeting the set packet capture condition, it grabs the data packets. In response to the data packets not meeting the set packet capture condition, it forwards the data packets.

8. A gateway device, characterized in that, including: A first processing core, configured to continuously grab data packets and store the target data of each grabbed data packet into a set memory space; A second processing core, configured to detect whether the target data in the set memory space meets the set packet capture stop condition, and in response to the target data meeting the set packet capture stop condition, stop grabbing data packets.

9. An electronic device, characterized in that, including a memory and a processor, wherein, The memory is used for storing programs; The processor includes a first processing core and a second processing core, and is coupled to the memory. The first processing core and the second processing core are used for executing the programs stored in the memory to implement the gateway packet capture method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, For storing computer-readable programs or instructions, which can implement the gateway packet capture method according to any one of claims 1 to 7 when the programs or instructions are executed by the processor.