Policy flow control method and device based on P4 language and deep packet inspection
Through a policy flow control method based on P4 language and deep packet detection, a distributed flow control architecture is built, and P4 programmable switches and DPUs are used for traffic supervision, which solves the problem of insufficient dynamic and real-time in the existing technology, and realizes efficient network traffic control, supporting dynamic adaptation and high throughput in complex network environments.
Patent Information
- Application Number
- CN202510884240.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-06-30
AI Technical Summary
The existing network traffic control technology has shortcomings in dynamic, real-time and application-layer perception, and cannot effectively deal with complex network environments such as port multiplexing and IP spoofing attacks.
Using a strategic flow control method based on P4 language and deep packet detection, a distributed flow control architecture is built, and traffic supervision is performed through P4 programmable switches and data processor DPUs. Combining the dual-rate three-color marking model and token bucket algorithm, the precise issuance of dynamic flow control rules and bandwidth adaptation is achieved.
It significantly improves the dynamic adaptability of network traffic control, supports HTTPS port multiplexing scenarios, eliminates centralized controller delay, realizes 10 Gigabit level traffic concurrency, adaptive bandwidth fluctuation compensation, and the overall throughput exceeds 100Gbps, and the memory usage of rules issuing is reduced by 40%.
Smart Images

Figure CN120389988A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the technical field of network layer traffic control, and in particular, to a policy flow control method and device based on the P4 language and deep packet inspection. Background Art
[0002] Currently, traditional network traffic control mainly relies on the following related technologies: First, access control based on ACL statically matches traffic through predefined IP quintuples (source / destination IP, port, protocol) (for example, a firewall prohibits access to sensitive ports from a specific IP segment). Its advantages are simple deployment and strong hardware compatibility, but static rules cannot dynamically adapt to port multiplexing (such as HTTPS uniformly using port 443) or IP spoofing attacks. Second, the queue scheduling mechanism uses algorithms such as FIFO, PQ, and WFQ to allocate bandwidth resources (for example, WFQ allocates a high-priority queue for VoIP traffic to ensure call quality). Although it can alleviate sudden congestion, it relies on manual configuration of weights and is difficult to sense changes in application requirements in real time (such as dynamic adjustment of video stream bitrates). Finally, token bucket traffic shaping controls the traffic peak rate based on the RFC2697 / 2698 standard by issuing tokens (such as a CDN edge node restricting a single user's sudden download). Although it can precisely control the bandwidth, it requires predefined thresholds and cannot adapt to network state fluctuations. These related technologies generally have common defects such as insufficient dynamicity, limited real-time performance, weak application layer awareness, and scalability bottlenecks. Therefore, developing a policy flow control method and device based on the P4 language and deep packet inspection to effectively overcome the defects in the above-mentioned related technologies has become an urgent technical problem in the industry. Summary of the Invention
[0003] In view of the above problems existing in the prior art, the embodiments of the present invention provide a policy flow control method and device based on the P4 language and deep packet inspection.
[0004] In a first aspect, the embodiments of the present invention provide a policy flow control method based on the P4 language and deep packet inspection, including: constructing a distributed flow control architecture, connecting to the XDR subsystem through a front-end system to implement traffic protocol identification and dynamic issuance of flow control rules; using a P4 programmable switch to implement basic traffic processing, combining with a data processor DPU to complete predetermined service processing, and performing traffic supervision through a dual-rate three-color marking model; forwarding traffic to the XDR subsystem through an L3 interface, matching the flow control rules issued by the L2 interface based on the protocol identification result, and generating a binary tuple including the destination IP, port, and rule information; sending the binary tuple to the P4 device of the corresponding service board through an L4 interface, dynamically loading the flow control rules, and implementing traffic matching and control based on the destination IP and port; under the distributed flow control architecture, streamlining the routing rules through the master control card IP and service card number carried by the L3 interface to avoid redundant rule loading.
[0005] Based on the content of the above method embodiments, in the embodiments of the present invention, a policy flow control method based on P4 language and deep packet inspection is provided. The front-end system consists of a main control board and service boards. The main control board controls peripheral devices through CPLD, and the service boards cooperate to process traffic through CPU, DPU, and P4 switches.
[0006] Based on the content of the above method embodiments, in the embodiments of the present invention, a policy flow control method based on P4 language and deep packet inspection is provided. The P4 Meter adopts a dual token bucket structure, including a C bucket and a P bucket, corresponding to the CIR / CBS and PIR / PBS parameters respectively, to achieve hierarchical control of committed information rate and peak information rate.
[0007] Based on the content of the above method embodiments, in the embodiments of the present invention, a policy flow control method based on P4 language and deep packet inspection is provided. After avoiding redundant rule loading, it further includes: the L1 interface transmits service-independent instructions, including mirroring and blocking; the L2 interface transmits service-related instructions, including application rate limiting and blocking; the L3 interface forwards a predetermined number of packets and NetFlow statistical information before forwarding.
[0008] Based on the content of the above method embodiments, in the embodiments of the present invention, a policy flow control method based on P4 language and deep packet inspection is provided. The XDR subsystem performs traffic shaping through the token bucket algorithm of RFC 2697 / 2698 standards, and combines P4 language-related devices to achieve real-time token replenishment and excess traffic marking.
[0009] Based on the content of the above method embodiments, in the embodiments of the present invention, a policy flow control method based on P4 language and deep packet inspection is provided. The distributed flow control architecture forms a processing matrix with a predetermined density through linear stacking of service boards, and the main control board uniformly manages the service boards to eliminate the performance bottleneck of the centralized controller.
[0010] Based on the content of the above method embodiments, in the embodiments of the present invention, a policy flow control method based on P4 language and deep packet inspection is provided. The matching delay of the flow control rules is less than or equal to 50 milliseconds, and the committed information rate and peak information rate parameters are dynamically adjusted to achieve bandwidth adaptive fluctuation compensation.
[0011] Second aspect, embodiments of the present invention provide a policy flow control device based on P4 language and deep packet inspection, including: a first main module for implementing the construction of a distributed flow control architecture, connecting to the XDR subsystem through a front-end system, and realizing traffic protocol identification and dynamic issuance of flow control rules; a second main module for implementing basic traffic processing using a P4 programmable switch, combining with a data processor DPU to complete predetermined service processing, and performing traffic supervision through a dual-rate three-color marking model; a third main module for implementing forwarding traffic to the XDR subsystem through an L3 interface, matching the flow control rules issued by the L2 interface based on the protocol identification result, and generating a binary tuple including the destination IP, port, and rule information; a fourth main module for implementing sending the binary tuple to the P4 device of the corresponding service board through an L4 interface, dynamically loading the flow control rules, and realizing traffic matching and control based on the destination IP and port; a fifth main module for implementing streamlining routing rules through the master control card IP and service card number carried by the L3 interface under the distributed flow control architecture to avoid redundant rule loading.
[0012] Third aspect, embodiments of the present invention provide an electronic device, including:
[0013] At least one processor, at least one memory, and a communication interface; wherein,
[0014] The processor, memory, and communication interface communicate with each other;
[0015] The memory stores program instructions executable by the processor, and the processor invokes the program instructions to execute the policy flow control method based on P4 language and deep packet inspection provided by any one of the various implementation manners of the first aspect.
[0016] Fourth aspect, embodiments of the present invention provide a non-transitory computer-readable storage medium, and the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions cause the computer to execute the policy flow control method based on P4 language and deep packet inspection provided by any one of the various implementation manners of the first aspect.
[0017] The policy flow control method and device based on P4 language and deep packet inspection provided by the embodiments of the present invention realize intelligent flow control through a distributed architecture and P4 language, significantly improving the dynamic adaptation ability. The XDR subsystem is used to identify the protocol type in real time and accurately issue rules to the corresponding service boards through the L4 interface, supporting the HTTPS port multiplexing scenario; the distributed N-to-N architecture eliminates the latency of the centralized controller, and combined with the linear stacking processing matrix of the service boards, it realizes gigabit-level traffic concurrency; the P4 Meter dual token bucket mechanism and three-color marking support bandwidth adaptive fluctuation compensation; the hardware co-design enables the CPU / DPU / P4 switch to divide labor to process general logic, advanced services and line-speed forwarding, with the overall throughput exceeding 100 Gbps and the memory occupancy of rule issuance reduced by 40%, effectively coping with dynamic application scenarios and complex network environments. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or in the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0019] Figure 1 It is a schematic flow chart of the policy flow control method based on P4 language and deep packet inspection provided by the embodiments of the present invention;
[0020] Figure 2 It is a schematic structural diagram of the policy flow control device based on P4 language and deep packet inspection provided by the embodiments of the present invention;
[0021] Figure 3 It is a schematic physical structure diagram of the electronic device provided by the embodiments of the present invention;
[0022] Figure 4 It is a schematic structural framework diagram of the unified DPI system provided by the embodiments of the present invention;
[0023] Figure 5 It is a schematic diagram of the interface configuration principle provided by the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention. In addition, the technical features in each embodiment or a single embodiment provided by the present invention can be combined with each other arbitrarily to form a feasible technical solution. Such combination is not restricted by the order of steps and / or the structure composition mode, but must be based on the ability of those of ordinary skill in the art to implement. When the combination of technical solutions results in contradictions or cannot be implemented, it should be considered that such combination of technical solutions does not exist and is not within the protection scope required by the present invention. If there are step numbers in the following embodiments, they are only set for convenience of explanation and illustration, and no limitation is imposed on the order between steps. The execution order of each step in the embodiments can be adaptively adjusted according to the understanding of those skilled in the art.
[0025] The embodiments of the present invention provide a policy flow control method based on P4 language and deep packet inspection. Refer to Figure 1 , the method includes: constructing a distributed flow control architecture, connecting to the XDR subsystem through a front-end system to implement dynamic distribution of traffic protocol identification and flow control rules; using a P4 programmable switch to implement basic traffic processing, combining with a data processor DPU to complete predetermined service processing, and performing traffic supervision through a dual-rate three-color marking model; forwarding traffic to the XDR subsystem through an L3 interface, matching the flow control rules issued by the L2 interface based on the protocol identification result, and generating a binary tuple containing the destination IP, port, and rule information; sending the binary tuple to the P4 device of the corresponding service board through an L4 interface, dynamically loading the flow control rules, and implementing traffic matching and control based on the destination IP and port; under the distributed flow control architecture, streamlining the routing rules through the master control card IP and service card number carried by the L3 interface to avoid redundant rule loading.
[0026] Specifically, ACL-based access control: Static traffic matching is performed through predefined IP quintuples (source / destination IP, port, protocol). For example, in a firewall, access to sensitive ports from specific IP segments is prohibited. Its advantages are simple deployment and strong hardware compatibility, but it lacks dynamic adaptability and cannot handle port multiplexing (such as HTTPS uniformly using port 443) or IP spoofing attacks. Queue scheduling mechanism: Algorithms such as FIFO (First In First Out), PQ (Priority Queue), and WFQ (Weighted Fair Queue) are used to allocate bandwidth resources. For example, WFQ can allocate a high-priority queue for VoIP traffic to ensure call quality. Such solutions can alleviate congestion caused by bursty traffic, but they rely on manual configuration of weights and are difficult to perceive the real-time requirements of applications (such as the dynamic change of video stream bitrate). Token bucket traffic shaping: Based on the RFC 2697 / 2698 standards, the traffic peak is controlled by the token issuance rate, and excess traffic is marked or discarded. A typical application is that CDN edge nodes limit the burst download traffic of a single user to prevent link overload. Although it can precisely control the bandwidth, it requires predefined thresholds and cannot adapt to changes in network conditions (such as bandwidth fluctuations).
[0027] Based on the content of the above method embodiments, as an optional embodiment, in the policy flow control method based on P4 language and deep packet inspection provided in the embodiments of the present invention, the front-end system consists of a main control board and service boards. The main control board controls peripheral devices through a CPLD, and the service boards cooperate to process traffic through a CPU, DPU, and P4 switch.
[0028] Based on the content of the above method embodiments, as an optional embodiment, in the policy flow control method based on P4 language and deep packet inspection provided in the embodiments of the present invention, the P4 Meter adopts a dual-token bucket structure, including a C bucket and a P bucket, corresponding to the CIR / CBS and PIR / PBS parameters respectively, to achieve hierarchical control of the committed information rate and peak information rate.
[0029] Specifically, the P4 Meter is a traffic policing mechanism based on the programmable data plane. Its core design combines the token bucket algorithm with the Two-Rate Three-Color Marker (trTCM) model. The following is a detailed analysis of its working mechanism: The P4 Meter uses two independent token buckets (bucket C and bucket P), corresponding to two rate parameters respectively: CIR (Committed Information Rate): the committed rate, corresponding to the CBS (Committed Burst Size) bucket, which is used to ensure the basic traffic bandwidth. PIR (Peak Information Rate): the peak rate, corresponding to the PBS (Peak Burst Size) bucket, which allows burst traffic but strictly limits it. Each token bucket generates tokens at a fixed rate (CIR / PIR), and the number of tokens does not exceed the bucket capacity (CBS / PBS). The excess tokens are discarded to ensure that the burst traffic does not exceed the preset threshold. When a data packet arrives, the P4 Meter processes it according to the following logic: Red marking (discarding): If the size of the data packet exceeds the remaining tokens in bucket P, it is directly marked as red without deducting tokens. Yellow marking (rate-limited forwarding): If bucket P is sufficient but bucket C is insufficient, it is marked as yellow, and the tokens in bucket P are deducted without updating bucket C. Green marking (normal forwarding): If both buckets are sufficient, it is marked as green, and the tokens in both buckets are deducted. Regardless of whether the data packet passes or not, the token buckets are continuously replenished over time to ensure the continuity of traffic policing.
[0030] Based on the content of the above method embodiments, as an optional embodiment, in the policy flow control method based on the P4 language and deep packet inspection provided in the embodiments of the present invention, after avoiding redundant rule loading, it further includes: The L1 interface transmits service-independent instructions, including mirroring and blocking; the L2 interface transmits service-related instructions, including application rate limiting and blocking; the L3 interface forwards a predetermined number of packets before forwarding and NetFlow statistical information.
[0031] Specifically, it can be referred to Figure 5, the flow control rules are sent to the XDR subsystem through the L2 interface in the figure. When the traffic arrives at the front-end machine, the traffic will be forwarded to the XDR through the L3 interface. At this time, the XDR subsystem will perform protocol identification based on the traffic forwarded by the L3 interface. After successful protocol identification, it will match the rules sent from the L2 interface. If the rules can be matched at this time, the binary group information (destination IP, destination port, and flow control rule information) of the current traffic will be sent to the P4 of the service board through the L4 interface. The P4 of the service board will then add flow control rules based on the binary group. At this time, the service board only needs to match the destination IP and port in the packet to perform flow control, and can adapt to dynamic application scenarios without caring about the specific application corresponding to the traffic. The descriptions and contents of each interface can be seen in Table 1.
[0032] Table 1
[0033]
[0034] From the system architecture diagram of the unified DPI, it can be obtained that the relationship between the xdr and the service board is N:N, and at the same time, there is also an N:N relationship between the front-end machine system and the XDR. In this distributed architecture, the performance bottleneck brought by the centralized controller is completely avoided. In the distributed scenario, in order to solve the accurate sending of the rules generated by the L4 interface, the traffic information forwarded by the L3 interface contains information about the corresponding service card (mainly including the IP of the front-end machine main control card, the number of the service card, etc.). The XDR will accurately send the flow control rules to the P4 of the corresponding service board according to the information of the L3 interface, avoiding the P4 of other service boards receiving useless rules and resulting in insufficient memory.
[0035] Based on the content of the above method embodiment, as an optional embodiment, in the policy flow control method based on the P4 language and deep packet inspection provided in the embodiment of the present invention, the XDR subsystem performs traffic shaping through the token bucket algorithm of the RFC 2697 / 2698 standard, and combines the P4 language-related devices to achieve real-time token replenishment and excess traffic marking.
[0036] Specifically, it can be seen in Figure 4The unified DPI system primarily consists of chassis-type devices and general-purpose application servers. The hardware platform for the XDR subsystem is a general-purpose application server, as is the hardware platform for the interface adapter subsystem. These can also be co-located on a single general-purpose server. The hardware platform for the front-end processor subsystem is a chassis-type device comprised of multiple heterogeneous logical processors, further divided into a main control board (MCU) and service boards (SBUs). The MCU is responsible for unified management of the other SBUs, ensuring that the SBUs are linearly stacked to form a high-port-density, high-computing-power service processing matrix, thus implementing the core functions of unified DPI. The MCU's control logic consists of a CPU and a CPLD. Due to its low computing power, the CPU is only responsible for general control logic, while the CPLD is responsible for controlling peripherals (such as fans, LEDs, and power supplies). The SBU's control logic consists of a CPU, a DPU, a programmable switch chip, and a CPLD. Due to its low computing power, the CPU is only responsible for general control logic. The DPU is a high-performance processing unit responsible for advanced service traffic processing. The programmable switch chip implements basic service traffic processing using the P4 programming language.
[0037] Based on the content of the above method embodiment, as an optional embodiment, the policy flow control method based on P4 language and deep packet inspection provided in the embodiment of the present invention, the distributed flow control architecture forms a predetermined density processing matrix through linear stacking of business boards, and the main control board uniformly controls the business boards to eliminate the performance bottleneck of the centralized controller.
[0038] Based on the content of the above method embodiment, as an optional embodiment, the policy flow control method based on P4 language and deep packet inspection provided in the embodiment of the present invention has a matching delay of less than or equal to 50 milliseconds, and dynamically adjusts the committed information rate and peak information rate parameters to achieve adaptive bandwidth fluctuation compensation.
[0039] The policy flow control method based on P4 language and deep packet inspection provided by the embodiment of the present invention realizes intelligent flow control through distributed architecture and P4 language, significantly improving dynamic adaptability. It adopts XDR subsystem to identify protocol types in real time and accurately issues rules to corresponding business boards through L4 interface, supporting HTTPS port reuse scenarios. The distributed N-to-N architecture eliminates the latency of the centralized controller and combines with the linear stacking processing matrix of the business boards to achieve 10G-level traffic concurrency. The P4 Meter dual token bucket mechanism and three-color marking support bandwidth adaptive fluctuation compensation. The hardware collaborative design enables the CPU / DPU / P4 switch to divide the work of processing general logic, advanced services and line-speed forwarding. The overall throughput exceeds 100Gbps and the memory usage of rule issuance is reduced by 40%, effectively coping with dynamic application scenarios and complex network environments.
[0040] The implementation basis of each embodiment of the present invention is achieved through programmed processing by a device with processor functions. Therefore, in engineering practice, the technical solutions and functions of each embodiment of the present invention can be encapsulated into various modules. Based on this actual situation, on the basis of the above embodiments, an embodiment of the present invention provides a policy flow control device based on P4 language and deep packet inspection, which is used to execute the policy flow control method based on P4 language and deep packet inspection in the above method embodiments. Refer to Figure 2 , the device includes: a first main module, which is used to implement the construction of a distributed flow control architecture, connect to the XDR subsystem through a front-end system, and realize traffic protocol identification and dynamic issuance of flow control rules; a second main module, which is used to implement basic traffic processing using a P4 programmable switch, complete predetermined service processing in combination with a data processor DPU, and perform traffic supervision through a dual-rate three-color marking model; a third main module, which is used to implement forwarding traffic to the XDR subsystem through an L3 interface, match the flow control rules issued by the L2 interface based on the protocol identification result, and generate a binary tuple including the destination IP, port, and rule information; a fourth main module, which is used to send the binary tuple to the P4 device of the corresponding service board through an L4 interface, dynamically load the flow control rules, and realize traffic matching and control based on the destination IP and port; a fifth main module, which is used to streamline the routing rules through the master control card IP and service card number carried by the L3 interface in the distributed flow control architecture, and avoid redundant rule loading.
[0041] The policy flow control device based on P4 language and deep packet inspection provided by the embodiment of the present invention adopts Figure 2 several modules among them, realizes intelligent flow control through a distributed architecture and P4 language, significantly improves the dynamic adaptation ability, uses the XDR subsystem to identify the protocol type in real time and accurately issue rules to the corresponding service board through the L4 interface, and supports the HTTPS port multiplexing scenario; the distributed N-to-N architecture eliminates the latency of the centralized controller, combines the linear stacking processing matrix of the service board, and realizes gigabit-level traffic concurrency; the P4 Meter dual token bucket mechanism and three-color marking support bandwidth adaptive fluctuation compensation; the hardware co-design enables the CPU / DPU / P4 switch to divide the work to process general logic, advanced services, and line-speed forwarding, the overall throughput breaks through 100 Gbps, and the memory occupancy of rule issuance is reduced by 40%, effectively coping with dynamic application scenarios and complex network environments.
[0042] It should be noted that the device in the device embodiment provided by the present invention can be used not only to implement the method in the above method embodiment, but also to implement the methods in other method embodiments provided by the present invention. The difference lies only in setting corresponding functional modules, and its principle is basically the same as that of the above device embodiment provided by the present invention. As long as those skilled in the art, based on the above device embodiment, refer to the specific technical solutions in other method embodiments, obtain corresponding technical means by combining technical features, and the technical solutions constituted by these technical means, and on the premise of ensuring the practicability of the technical solutions, the device in the above device embodiment can be improved to obtain corresponding device-type embodiments for implementing the methods in other method-type embodiments. For example:
[0043] Based on the content of the above device embodiment, as an optional embodiment, the policy flow control device based on P4 language and deep packet detection provided in the embodiment of the present invention further includes: a first sub-module, which is used to implement that the front-end machine system consists of a main control board and a service board. The main control board controls peripheral devices through a CPLD, and the service board collaborates to process traffic through a CPU, a DPU, and a P4 switch.
[0044] Based on the content of the above device embodiment, as an optional embodiment, the policy flow control device based on P4 language and deep packet detection provided in the embodiment of the present invention further includes: a second sub-module, which is used to implement that the P4 Meter adopts a dual token bucket structure, including a C bucket and a P bucket, corresponding to the CIR / CBS and PIR / PBS parameters respectively, to implement hierarchical control of the committed information rate and the peak information rate.
[0045] Based on the content of the above device embodiment, as an optional embodiment, the policy flow control device based on P4 language and deep packet detection provided in the embodiment of the present invention further includes: a third sub-module, which is used to implement that after avoiding redundant rule loading, it further includes: the L1 interface transmits service-independent instructions, including mirroring and blocking; the L2 interface transmits service-related instructions, including application rate limiting and blocking; the L3 interface forwards a predetermined number of packets before forwarding and NetFlow statistical information.
[0046] Based on the content of the above device embodiment, as an optional embodiment, the policy flow control device based on P4 language and deep packet detection provided in the embodiment of the present invention further includes: a fourth sub-module, which is used to implement that the XDR subsystem performs traffic shaping through the token bucket algorithm of the RFC 2697 / 2698 standard, and combines P4 language-related devices to achieve real-time token replenishment and excess traffic marking.
[0047] Based on the content of the above device embodiments, as an alternative embodiment, the policy flow control device based on the P4 language and deep packet inspection provided in the embodiments of the present invention further includes: a fifth sub-module, configured to implement that the distributed flow control architecture forms a predetermined density processing matrix through linear stacking of service boards, and the main control board uniformly manages the service boards to eliminate the performance bottleneck of the centralized controller.
[0048] Based on the content of the above device embodiments, as an alternative embodiment, the policy flow control device based on the P4 language and deep packet inspection provided in the embodiments of the present invention further includes: a sixth sub-module, configured to implement that the matching delay of the flow control rules is less than or equal to 50 milliseconds, and dynamically adjust the committed information rate and peak information rate parameters to achieve bandwidth adaptive fluctuation compensation.
[0049] The method of the embodiments of the present invention is implemented relying on an electronic device. Therefore, it is necessary to introduce the relevant electronic device. For this purpose, the embodiments of the present invention provide an electronic device, as Figure 3 shown, the electronic device includes: at least one processor, a communication interface, at least one memory, and a communication bus, wherein the at least one processor, the communication interface, and the at least one memory communicate with each other through the communication bus. The at least one processor can call the logical instructions in the at least one memory to execute all or part of the steps of the methods provided in the foregoing method embodiments.
[0050] In addition, when the logical instructions in the above at least one memory are implemented in the form of a software functional unit and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the method embodiments of the present invention. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc that can store program codes.
[0051] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative effort.
[0052] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solution, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0053] The flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of systems, methods, and computer program products according to multiple embodiments of the present invention. Based on this understanding, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and sometimes in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0054] It should be noted that the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, the elements defined by the statement "including..." do not exclude the existence of additional identical elements in the process, method, article or device including the said elements. For any similar expressions such as "predetermined threshold", "preset threshold", etc., if no specific numerical value is indicated, those of ordinary skill in the art can determine their specific numerical values through simple experiments or corresponding debugging.
[0055] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A policy flow control method based on P4 language and deep packet inspection, characterized in that Including: Build a distributed flow control architecture, connect to the XDR subsystem through the front-end system to realize traffic protocol recognition and dynamic issuance of flow control rules; use a P4 programmable switch to implement basic traffic processing, combine with a data processor DPU to complete scheduled service processing, and perform traffic supervision through a dual-rate three-color marking model; use an L3 interface to forward traffic to the XDR subsystem, match the flow control rules issued by the L2 interface based on the protocol recognition result, and generate a binary tuple containing the destination IP, port, and rule information. Send the binary tuple to the P4 device of the corresponding service board through the L4 interface, dynamically load the flow control rules, and realize traffic matching and control based on the destination IP and port; under the distributed flow control architecture, streamline the routing rules through the master card IP and service card number carried by the L3 interface to avoid redundant rule loading.
2. The policy flow control method based on P4 language and deep packet inspection according to claim 1, wherein The front-end system consists of a master board and service boards. The master board controls peripheral devices through a CPLD, and the service boards cooperate to process traffic through a CPU, DPU, and P4 switch.
3. The policy flow control method based on P4 language and deep packet inspection according to claim 2, wherein P4Meter adopts a dual-token bucket structure, including a C bucket and a P bucket, corresponding to the CIR / CBS and PIR / PBS parameters respectively, to achieve hierarchical control of the committed information rate and peak information rate.
4. The policy flow control method based on P4 language and deep packet inspection according to claim 3, wherein After avoiding redundant rule loading, it further includes: The L1 interface transmits service-independent instructions, including mirroring and blocking; the L2 interface transmits service-related instructions, including application speed limit and blocking; the L3 interface forwards a predetermined number of packets and NetFlow statistical information before forwarding.
5. The policy flow control method based on P4 language and deep packet inspection according to claim 4, wherein The XDR subsystem performs traffic shaping through the token bucket algorithm of the RFC 2697 / 2698 standard, and combines with P4 language-related devices to achieve real-time token replenishment and excess traffic marking.
6. The policy flow control method based on P4 language and deep packet inspection according to claim 5, wherein, The distributed flow control architecture forms a processing matrix with a predetermined density through linear stacking of service boards, and the master board uniformly manages the service boards to eliminate the performance bottleneck of the centralized controller.
7. The policy flow control method based on P4 language and deep packet inspection according to claim 6, wherein The matching delay of the flow control rules is less than or equal to 50 milliseconds, and the committed information rate and peak information rate parameters are dynamically adjusted to achieve bandwidth adaptive fluctuation compensation.
8. A policy flow control device based on P4 language and deep packet inspection, characterized in that, Including: The first main module is used to build a distributed flow control architecture, connect to the XDR subsystem through the front-end system to realize traffic protocol recognition and dynamic issuance of flow control rules; the second main module is used to use a P4 programmable switch to implement basic traffic processing, combine with a data processor DPU to complete scheduled service processing, and perform traffic supervision through a dual-rate three-color marking model; the third main module is used to use an L3 interface to forward traffic to the XDR subsystem, match the flow control rules issued by the L2 interface based on the protocol recognition result, and generate a binary tuple containing the destination IP, port, and rule information; the fourth main module is used to send the binary tuple to the P4 device of the corresponding service board through the L4 interface, dynamically load the flow control rules, and realize traffic matching and control based on the destination IP and port; the fifth main module is used to streamline the routing rules through the master card IP and service card number carried by the L3 interface under the distributed flow control architecture to avoid redundant rule loading.
9. An electronic device, characterized in that, Including: At least one processor, at least one memory, and a communication interface; wherein, The processor, the memory, and the communication interface communicate with each other; The memory stores program instructions executable by the processor, and the processor invokes the program instructions to execute the method according to any one of claims 1 to 7.
10. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores computer instructions, and the computer instructions cause the computer to execute the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Method and device for defending network attack, and router
CN102143143A
Dynamic multistage flow control method based on programmable switching chip
CN112637090A
Flow control method and device
CN115834496A
Dynamic flow control method and system for live video service
CN116095006A
Deep data packet detection system, method, equipment and medium
CN118784504A