Traffic data control method and device and electronic equipment
By obtaining and judging the source IP address and destination IP address of the target data packet, distinguishing internal and external communications, the problem that existing traffic control algorithms cannot distinguish traffic categories is solved, and reasonable control of data transmission is achieved, and network resource utilization and security is improved.
Patent Information
- Application Number
- CN202510880632.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-08-12
AI Technical Summary
The existing traffic control algorithms cannot effectively distinguish and filter different categories of traffic, resulting in a large amount of invalid data being transmitted to the receiving system, occupying resources, affecting the normal operation of the system and increasing network transmission costs.
By obtaining the source IP address and destination IP address of the target data packet, it is determined whether the target unit and the communication unit are in internal communication, and decide whether to transmit the data packet based on the judgment results, and use the source IP address database and network segment judgment to make precise distinction.
Effectively filter out internal communication data, reasonably control the amount of data transmitted to the receiving system, reduce network bandwidth usage, improve network resource utilization, reduce data transmission costs, and enhance network security and controllability.
Smart Images

Figure CN120474988A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and more specifically, to a flow data control method, device, and electronic device. Background Art
[0002] In the digital age, where network and system data traffic is exploding, efficiently and effectively managing and controlling this traffic has become a core issue for ensuring stable network and system operation. The goal of traffic control algorithms is to ensure reliable service even under high loads, preventing system crashes or resource exhaustion caused by overload.
[0003] Currently, common flow control technologies primarily focus on controlling the data transmission rate, but they don't consider the traffic types of the application scenarios. This results in a large amount of invalid data being transmitted to the receiving system, wasting network bandwidth and overloading the receiving system, impacting normal system operation. Summary of the Invention
[0004] In order to at least overcome the above-mentioned deficiencies in the prior art, the purpose of the present application is to provide a flow data control method, device and electronic device.
[0005] In a first aspect, an embodiment of the present application provides a flow data control method, the flow data control method comprising: Acquire a target data packet sent by a target unit to a communication unit, and / or acquire the target data packet sent by the communication unit and received by the target unit; Detecting the target data packet to determine the source IP address and destination IP address of the target data packet; Determining whether the target unit and the communication unit are in internal communication according to the source IP address and the destination IP address of the target data packet; If the target unit and the communication unit are not in internal communication, transmitting the target data packet to a receiving system; If the target unit and the communication unit are in internal communication, the target data packet is not transmitted to the receiving system.
[0006] In a possible implementation, the method further includes: Obtain the source IP address database corresponding to each target unit in the same network environment; The step of determining whether the target unit and the communication unit are in internal communication based on the source IP address and the destination IP address of the target data packet includes: Determine whether the source IP address exists in the source IP address database corresponding to the target unit; If the source IP address does not exist in the source IP address database corresponding to the target unit, the target unit and the communication unit are not communicating internally; If the source IP address exists in the source IP address database corresponding to the target unit, determining whether the destination IP address exists in the source IP address database corresponding to the target unit; If the destination IP address does not exist in the source IP address database corresponding to the target unit, the target unit and the communication unit are not in internal communication.
[0007] In a possible implementation, after the step of determining whether the destination IP address exists in the source IP address database corresponding to the target unit, the method further includes: Determine whether the network segment where the source IP address is located is the same as the network segment where the destination IP address is located; If the network segment where the source IP address is located is different from the network segment where the destination IP address is located, then the target unit and the communication unit are not communicating internally; If the network segment where the source IP address is located is the same as the network segment where the destination IP address is located, the target unit and the communication unit are in internal communication.
[0008] In one possible implementation, the step of determining whether the network segment in which the source IP address is located is the same as the network segment in which the destination IP address is located includes: The subnet mask is used to determine whether the network segment where the source IP address is located is the same as the network segment where the destination IP address is located.
[0009] In a possible implementation, after the step of obtaining a source IP address database corresponding to each target unit in the same network environment, the method further includes: Determine whether the source IP address exists in the source IP address database corresponding to the target unit; If the source IP address does not exist in the source IP address database corresponding to the target unit, the source IP address is stored in the source IP address database corresponding to the target unit.
[0010] In a possible implementation, the step of obtaining a source IP address database corresponding to each target unit in the same network environment includes: For each target unit in the same network environment, obtaining the data packets to be detected received or sent by each target unit within a preset time period; Detecting each of the data packets to be detected, and obtaining the source IP address of each of the data packets to be detected; The source IP address of each of the data packets to be detected is stored in a source IP address database corresponding to each of the target units.
[0011] In a possible implementation, the step of obtaining the data packets to be detected received or sent by each target unit within a preset time period includes: The data packets to be detected received or sent by each target unit within a preset time period are obtained through the mirror port of the core switch.
[0012] In a second aspect, an embodiment of the present application further provides a flow data control device, the flow data control device comprising: a receiving module, configured to obtain a target data packet sent by a target unit to a communication unit, and / or obtain the target data packet sent by the communication unit and received by the target unit; A detection module, configured to detect the target data packet and determine the source IP address and destination IP address of the target data packet; a determination module, configured to determine whether the target unit and the communication unit are in internal communication according to the source IP address and the destination IP address of the target data packet; The transmission module is used to transmit the target data packet to the receiving system if the target unit and the communication unit are not in internal communication; if the target unit and the communication unit are in internal communication, the target data packet is not transmitted to the receiving system.
[0013] In a third aspect, an embodiment of the present application further provides an electronic device, including: a memory for storing one or more programs; The processor implements the traffic data control method provided in the first aspect when the one or more programs are executed by the processor.
[0014] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the flow data control method provided in the first aspect above.
[0015] Based on any one of the above aspects, the traffic data control method, device and electronic device provided in the embodiments of the present application detect and judge the source IP address and destination IP address of the target data packet, distinguish between internal communication and external communication, and process the target data packet differently according to the communication type. In this way, it can effectively filter out internal communication data, reasonably control the amount of data transmitted to the receiving system, ensure the performance of the receiving system, reduce network bandwidth occupancy, improve network resource utilization, and at the same time reduce the cost of data transmission and enhance network security and controllability. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required in the embodiments. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.
[0017] Figure 1 One of the flow charts of the flow data control method provided in this embodiment; Figure 2 A schematic diagram of sub-steps of step S130 provided in this embodiment; Figure 3 The second flow chart of the flow data control method provided in this embodiment; Figure 4 A schematic diagram of sub-steps of step S131 provided in this embodiment; Figure 5 Flowchart 3 of the flow data control method provided in this embodiment; Figure 6 One of the communication diagrams between the target unit and the communication unit provided in this embodiment; Figure 7 The second communication diagram between the target unit and the communication unit provided in this embodiment; Figure 8 The third schematic diagram of communication between the target unit and the communication unit provided in this embodiment; Figure 9 The fourth communication diagram between the target unit and the communication unit provided in this embodiment; Figure 10 The fifth communication diagram between the target unit and the communication unit provided in this embodiment; Figure 11 The sixth schematic diagram of communication between the target unit and the communication unit provided in this embodiment; Figure 12 The seventh schematic diagram of communication between the target unit and the communication unit provided in this embodiment; Figure 13Schematic diagram of the functional modules of the electronic device provided in this embodiment; Figure 14 Schematic diagram of the functional modules of the flow data control device provided in this embodiment.
[0018] Icons: 110 - detection device; 120 - core switch; 130 - router; 800 - electronic device; 810 - processor; 820 - computer-readable storage medium; 830 - traffic data control device; 831 - receiving module; 832 - detection module; 833 - determination module; 834 - transmission module. DETAILED DESCRIPTION
[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Generally, the components of the embodiments of the present application described and shown in the drawings herein can be arranged and designed in various different configurations.
[0020] Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application for protection, but merely represents selected embodiments of the present application. All other embodiments obtained by persons of ordinary skill in the art based on the embodiments in the present application without making any creative efforts shall fall within the scope of protection of the present application.
[0021] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings.
[0022] In the description of this application, it should be noted that the terms "upper" and "lower" and the like indicate orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, or the orientations or positional relationships in which the product of this application is typically placed when in use. These terms are intended solely to facilitate the description of this application and simplify the description, and are not intended to indicate or imply that the device or element referred to must have a specific orientation, be constructed, or operate in a specific orientation. Therefore, they should not be construed as limitations on this application. Furthermore, the terms "first" and "second" and the like are used solely for distinction and should not be construed as indicating or implying relative importance.
[0023] It should be noted that, in the absence of conflict, different features in the embodiments of the present application can be combined with each other.
[0024] The inventors have found that the commonly used flow control algorithms currently include fixed window algorithm, sliding window algorithm, leaky bucket algorithm, token bucket algorithm, etc. These methods mainly achieve flow control by limiting the amount of data passing through per unit time or adjusting the data transmission speed, but do not perform flow control from the perspective of traffic category of application scenarios.
[0025] Taking the scenario of traffic analysis for target units within the same network environment as an example, the traffic transmitted to the receiving system can include valid data and invalid data. Valid data refers to data that has practical value to the receiving system and can be processed and utilized by the system; invalid data refers to data that has no practical value or analytical significance to the receiving system.
[0026] Existing flow control algorithms, however, are unable to distinguish and filter these different types of traffic and can only control the traffic rate. This results in a large amount of invalid data being transmitted to the receiving system, which not only consumes the receiving system's resources but can also cause system overload and affect normal operation. Furthermore, excessive invalid data transmission wastes network bandwidth resources and increases network transmission costs.
[0027] In view of this, this embodiment provides a solution that can solve the above-mentioned problem. The solution provided by this embodiment is described in detail below.
[0028] Please refer to Figure 1 , Figure 1 Example A flow chart of a flow data control method provided by this embodiment, the flow data control method may include the following steps.
[0029] Step S110 , obtaining a target data packet sent by a target unit to a communication unit, and / or obtaining the target data packet sent by the communication unit and received by the target unit.
[0030] In this embodiment, target data packets entering and leaving the target unit can be obtained, including target data packets sent by the target unit to the communication unit and target data packets sent by the communication unit and received by the target unit. Among them, the target unit can refer to the unit currently performing flow control, usually the sender or receiver of the target data packet, and the communication unit can refer to the unit that interacts with the target unit for data, which can be other departments or institutions in the same intranet environment.
[0031] Specifically, the target data packet may be obtained through the mirror port of the core switch 120 .
[0032] In the above design, by obtaining the target data packets entering and leaving the target unit, the target data packets sent or received by the target unit can be detected at the same time, ensuring that the traffic data of two-way communication is controlled and avoiding detection omissions.
[0033] Step S120: Detect the target data packet to determine the source IP address and destination IP address of the target data packet.
[0034] In this embodiment, the target data packet obtained in step S110 can be tested to obtain the source IP address and destination IP address of the target data packet. The source IP address refers to the sender's address, and the destination IP address refers to the receiver's address. For example, when the target unit sends the target data packet to the communication unit, the source IP address can refer to the address of the target unit, and the destination IP address can refer to the address of the communication unit; when the target unit receives the target data packet sent by the communication unit, the source IP address can refer to the address of the communication unit, and the destination IP address can refer to the address of the target unit.
[0035] Specifically, the target data packet may be obtained through the mirror port of the core switch 120 deployed in the target unit.
[0036] Step S130: determining whether the target unit and the communication unit are in internal communication according to the source IP address and the destination IP address of the target data packet.
[0037] The target data packets obtained in step S110 may be internal communication data packets within the unit, data packets from internal devices of the unit accessing other units in the intranet environment, data packets from devices of other units accessing services provided by the unit in the intranet environment, etc. Therefore, in this embodiment, it is possible to determine whether the target unit and the communicating unit are communicating internally based on the source IP address and destination IP address of the target data packets obtained in step S120, and filter the amount of data transmitted to the receiving system based on the determination result.
[0038] Internal communication refers to the direct data exchange between different devices (or nodes) within the same sub-unit (or department) within the same network environment. In this case, different devices (or nodes) within the same network environment can refer to computers, servers, printers, etc. For example, if device A and device B are both connected to the same router, when device A sends a file to device B, or device B requests a resource on device A, this communication process occurs entirely within the internal network and does not pass through the external network. Therefore, it is considered internal communication.
[0039] Step S140: If the target unit and the communication unit are not in internal communication, the target data packet is transmitted to the receiving system.
[0040] In step S150 , if the target unit and the communication unit are in internal communication, the target data packet is not transmitted to the receiving system.
[0041] In this embodiment, if the target unit and the communication unit are in internal communication, the target data packet may not be transmitted to the receiving system; if the target unit and the communication unit are not in internal communication, the target data packet may be transmitted to the receiving system. The receiving system may be a system for further processing, analyzing, or recording the data packet, such as a security monitoring system, a traffic analysis system, etc.
[0042] It can be seen that based on the above design, the traffic data control method provided in the embodiment of the present application detects and judges the source IP address and destination IP address of the target data packet, distinguishes internal communication from external communication, and processes the target data packet differently according to the communication type. In this way, it can effectively filter out internal communication data, reasonably control the amount of data transmitted to the receiving system, ensure the performance of the receiving system, reduce the occupancy of network bandwidth, and improve the utilization rate of network resources. At the same time, it can also reduce the cost of data transmission and enhance the security and controllability of the network.
[0043] In a possible implementation, before step S110 , a source IP address database corresponding to each target unit in the same network environment may be obtained.
[0044] In this embodiment, before acquiring a target data packet, a corresponding source IP address database can be pre-built for each target unit, wherein the source IP address database includes each source IP address entering and leaving the target unit. By building this source IP address database, it is possible to quickly determine whether an IP address belongs to the internal network of a target unit.
[0045] When testing target data packets to determine whether the target unit and the communication unit are communicating internally, the source IP address and destination IP address of each target data packet must be queried in the corresponding source IP address database. Specifically, a determination can be made first as to whether the source IP address and / or destination IP address exist in the source IP address database corresponding to the target unit. Based on the determination, a determination can be made as to whether the target unit and the communication unit are communicating internally. In actual use, testing can be performed for each session. In network communications, a session refers to a series of data exchange processes between two devices. A session typically includes multiple data packets that together complete a specific task (such as file transfer, web browsing, etc.).
[0046] Please refer to Figure 2 , step S130 may include the following sub-steps.
[0047] Step S131, determining whether the source IP address exists in the source IP address database corresponding to the target unit.
[0048] Step S132: If the source IP address does not exist in the source IP address database corresponding to the target unit, the target unit and the communication unit are not in internal communication.
[0049] Step S133: If the source IP address exists in the source IP address database corresponding to the target unit, determine whether the destination IP address exists in the source IP address database corresponding to the target unit.
[0050] Step S134: If the destination IP address does not exist in the source IP address database corresponding to the target unit, the target unit and the communication unit are not in internal communication.
[0051] In this embodiment, when the target unit sends or receives a target data packet, it can first determine whether the source IP address of the target data packet exists in the source IP address database corresponding to the target unit. If the source IP address of the target data packet does not exist in the source IP address database corresponding to the target unit, it means that the target data packet may be a data packet from other units in the same network environment to access this unit, that is, the target unit and the communication unit are not communicating internally, and the target data packet can be transmitted to the receiving system.
[0052] If the source IP address of the target data packet exists in the source IP address database corresponding to the target unit, the destination IP address of the target data packet is further checked. Specifically, it can be determined whether the destination IP address of the target data packet exists in the source IP address database corresponding to the target unit. If the destination IP address of the target data packet does not exist in the source IP address database corresponding to the target unit, it means that the target data packet may be a data packet of the target unit accessing other units in the same network environment, that is, the target unit and the communication unit are not communicating internally, and the target data packet can be transmitted to the receiving system.
[0053] In one possible implementation, see Figure 3 In step S133, when the destination IP address exists in the source IP address database corresponding to the target unit, the flow data control method may further include the following steps.
[0054] Step S135 , determining whether the network segment where the source IP address is located is the same as the network segment where the destination IP address is located.
[0055] Step S136: If the network segment where the source IP address is located is different from the network segment where the destination IP address is located, the target unit and the communication unit are not in internal communication.
[0056] Step S137: If the network segment where the source IP address is located is the same as the network segment where the destination IP address is located, the target unit and the communication unit are in internal communication.
[0057] In this embodiment, if both the source IP address and the destination IP address of the target data packet exist in the source IP address database corresponding to the target unit, a further determination is made as to whether the source IP address and the destination IP address belong to the same network segment. If the source IP address and the destination IP address belong to the same network segment, it indicates that the target unit and the communication unit are communicating internally, and the target data packet is not uploaded to the receiving system. If the source IP address and the destination IP address do not belong to the same network segment, it indicates that the target unit and the communication unit are not communicating internally, and the target data packet needs to be uploaded to the receiving system. The same network segment may refer to the logical network area where devices with the same network address are located in the network.
[0058] In one possible implementation, in step S135, when determining whether the network segment where the source IP address is located is the same as the network segment where the destination IP address is located, the subnet mask can be used to determine whether the network segment where the source IP address is located is the same as the network segment where the destination IP address is located.
[0059] In this embodiment, the subnet mask of the current network environment can be obtained first, and then the source IP address and the destination IP address can be performed AND operations respectively according to the subnet mask to calculate their network addresses. If the network addresses of the source IP address and the destination IP address are the same, it means that the source IP address and the destination IP address belong to the same network segment; if the network addresses of the source IP address and the destination IP address are different, it means that the source IP address and the destination IP address do not belong to the same network segment.
[0060] In some examples, if there is a network environment with a subnet mask of 255.255.255.0, and the source IP address is 192.168.1.10, and the destination IP address is 192.168.1.20, then the network segment of the source IP address is 192.168.1.0 / 24, and the network segment of the destination IP address is 192.168.1.0 / 24. Therefore, the source IP address and the destination IP address belong to the same network segment, and the target unit and the communication unit are communicating internally.
[0061] In other examples, if there is a network environment with a subnet mask of 255.255.255.0, and the source IP address is 192.168.1.10, and the destination IP address is 192.168.2.20, then the network segment of the source IP address is 192.168.1.0 / 24, and the network segment of the destination IP address is 192.168.2.0 / 24. Therefore, the source IP address and the destination IP address do not belong to the same network segment, and the target unit and the communication unit are not internal communications.
[0062] In one possible implementation, see Figure 4 , step S131 may include the following sub-steps.
[0063] Step S131a: Determine whether the source IP address exists in the source IP address database corresponding to the target unit.
[0064] Step S131b: If the source IP address does not exist in the source IP address database corresponding to the target unit, the source IP address is stored in the source IP address database corresponding to the target unit.
[0065] In this embodiment, after obtaining the source IP address database corresponding to each target unit, the source IP address database can also be updated in real time. Specifically, when detecting the source IP address of a target data packet, it can be determined whether the source IP address exists in the source IP address database corresponding to the target unit. If not, the source IP address is stored in the source IP address database and the detection is terminated. The source IP address of the target data packet is detected again when the next target data packet is obtained.
[0066] In one possible implementation, see Figure 5 When obtaining the source IP address database corresponding to each target unit in the same network environment, the traffic data control method may further include the following steps.
[0067] Step S210 : for each target unit in the same network environment, obtaining the data packets to be detected received or sent by each target unit within a preset time period.
[0068] Step S220: Detect each of the data packets to be detected and obtain the source IP address of each of the data packets to be detected.
[0069] Step S230: storing the source IP address of each of the data packets to be detected in the source IP address database corresponding to each of the target units.
[0070] In this embodiment, prior to step S110, for each target unit (an institution or organization in the same network environment), data packets to be detected that enter and exit the target unit within a preset time period are obtained. By analyzing the source IP addresses in the data packets to be detected, a corresponding source IP address database is constructed for each target unit. For example, the preset time period may be three hours.
[0071] In one possible implementation, in step S210, when obtaining the data packets to be detected received or sent by each target unit within a preset time period, the data packets to be detected received or sent by each target unit within the preset time period can be obtained through the mirror port of the core switch 120.
[0072] In this embodiment, the detection device 110 deployed on the core switch 120 of each target unit can be used to obtain the data packets to be detected received or sent by each target unit within a preset time period, and then the source IP address of the data packets to be detected can be detected.
[0073] In some examples, if unit 1, unit 2, ..., unit n are different target units in the same network environment, the external unit refers to other sub-units other than the current unit in the same network environment.
[0074] Please refer to Figure 6 Taking unit 1 as the local unit, when devices within unit 1 (such as PC1, PC2, etc.) access each other, the detection device 110 deployed on the core switch 120 of this unit can detect that the source IP address and destination IP address of the target data packet are both the IP addresses of devices within unit 1 (such as the IP addresses of hosts such as PC1 and PC2). Moreover, since the IP addresses of devices within the same unit are almost all on the same network segment, it can be determined that this communication is internal communication and the target data packet is not reported. If the detection device 110 deployed on the core switch 120 of this unit detects that the source IP address and destination IP address of the target data packet are not in the source IP address database, then this communication is not considered internal communication and the target data packet is reported. At the same time, the source IP address of the target data packet is stored in the source IP address database of this unit. As the source IP address database is updated in real time, the probability of such data packets being reported will gradually decrease. In this way, internal communication data can be effectively filtered out and the amount of data transmitted to the receiving system can be reasonably controlled.
[0075] Please refer to Figure 7 For example, if a device in unit 1 accesses a device in another target unit, such as unit 2, while other target units, such as unit 2, do not access unit 1, the source IP addresses detected by detection device 110 deployed on the core switch 120 of this unit can all be device IP addresses within unit 1 (e.g., the IP addresses of hosts such as PC1 and PC2). The destination IP addresses may not exist in the source IP address database of this unit. Therefore, this communication will not be considered internal, and the target data packet will be reported. The data packets reported in this scenario meet the requirements for traffic detection and analysis.
[0076] Please refer to Figure 8Taking unit 1 as the local unit, when the internal devices of unit 2 (such as PC3, PC4, etc.) access each other, since the data is mirrored and captured by the detection device 110 deployed on the core switch 120 of each target unit, the detection device 110 can only capture the data entering and leaving the local unit. The data between the internal devices of external units does not pass through the core switch 120 of this unit. Therefore, the detection device 110 of this unit cannot obtain the data between the internal devices of external units.
[0077] Take unit 1 as the main unit. When other units such as unit 2 access unit 1, but unit 1 does not access other units such as unit 2, please refer to Figure 9 If unit 2 does not access this unit through network devices such as router 130 and firewall, the source IP address of the target data packet is the device IP of unit 2, and the destination IP address is the device IP of unit 1. Since the device IP of unit 2 does not exist in the source IP address database of unit 1, the communication data will be reported, and the device IP of unit 2 will also be placed in the source IP address database of unit 1. When the same device of unit 2 accesses unit 1 again, the device IP of unit 2 and the visited device IP of unit 1 both exist in the source IP address database of unit 1. At this time, it can be determined whether the device IP of unit 2 and the visited device IP of unit 1 are in the same network segment. If the two device IP addresses are in the same network segment, it is determined to be internal communication and the data will not be reported. Otherwise, the data will be reported. Please refer to Figure 10 If unit 2 accesses this unit through network devices such as router 130 and firewall, the source IP address of the target data packet obtained is the public IP address of unit 2 after being translated by router 130, and the destination IP address is the public IP address of unit 1 after being translated by router 130. Since the public IP address of unit 2 after being translated by router 130 does not exist in unit 1's source IP address database, the communication data will be reported, and the public IP address of unit 2 after being translated by router 130 will also be added to unit 1's source IP address database. When the same device from unit 2 subsequently accesses unit 1 again, the public IP address of unit 2 after being translated by router 130 and the IP address of the accessed device from unit 1 will both exist in unit 1's source IP address database. At this point, it can be determined whether the two IP addresses are in the same network segment. Since the public IP address and the private IP address of unit 1 stored in the source IP address database do not exist in the same network segment, this communication will not be determined as internal communication, and the data will be reported. In the above scenario, if there are multiple devices in different network segments communicating with each other within a target unit, such data will also be reported to ensure the accuracy of the determination result. The data packets reported in this scenario meet the requirements of traffic detection and analysis.
[0078] Take unit 1 as the main unit. When the device in unit 1 accesses the device in other target units, and the target units also access unit 1, please refer to Figure 11 If routers 130, firewalls, and other devices are not used for inter-unit visits, the scenarios in which this unit directly accesses other sub-units are limited (for example, this unit accesses other sub-units to upgrade their servers, which occurs less frequently). Under this condition, the scenarios in which other sub-units also access unit 1 are even more limited (for example, when this unit accesses other sub-units to upgrade their servers, other sub-units also access this unit's servers). In the above extremely limited scenarios, when this unit accesses other target units, the source IP addresses detected by the detection device 110 are all the device IP addresses of this unit (for example, the IP addresses of hosts such as PC1 and PC2), and the destination IP addresses detected are all the device IP addresses of other target units; when other target units access this unit, the source IP addresses detected are all the device IP addresses of other target units, and the destination IP addresses are all the device IP addresses of this unit. If the source IP address does not exist in the source IP address database of this unit, the source IP address will be stored in the source IP address database of this unit, and this communication will not be determined as internal communication, and the data packet will be reported. If the two devices subsequently access each other and both device IP addresses are in Unit 1's source IP list, a check is performed to determine whether the two IP addresses are in the same network segment. In a network environment, if two devices' IP addresses belong to the same network segment, they can communicate directly through a switch without going through a router. In this case, the communication between the two devices is considered internal. Therefore, in this scenario, since the two devices are in the same network environment, if the two device IP addresses belong to the same network segment, it can be determined that the communication is internal and the data is not reported. Otherwise, the data is reported.
[0079] Please refer to Figure 12If routers 130, firewalls and other devices are used for inter-unit visits, when unit 1 accesses unit 2, the source IP address obtained by the detection device 110 deployed on unit 1 is the IP address of the host that initiates the access request in unit 1, and the destination IP address is the public IP address of unit 2 after conversion through routers 130, firewalls and other devices. At this time, the IP address of the host that initiates the access request in unit 1 will be put into the source IP address database; and when unit 2 accesses unit 1, the source IP address obtained is the public IP address of unit 2 after conversion through router 130, and the destination IP address is the public IP address of unit 1 after conversion through router 130. At this time, unit 2 accesses unit 1 through router 1 The public IP address converted by router 30 will be placed in the source IP address database; when the source IP address does not exist in the source IP address database of this unit, the source IP address will be stored in the source IP address database of this unit, and this communication will not be judged as internal communication, and the data packet will be reported; if any device in unit 1 and unit 2 subsequently visit each other, and the host IP address that initiates the access request in unit 1 and the public IP address of unit 2 converted by router 130 are both in the source IP list, it can be determined whether the two IP addresses are in the same network segment. If the IP addresses of the two devices are in the same network segment, it can be determined as internal communication and the data will not be reported; otherwise, the data will be reported. In the above scenario, if there are multiple devices in different network segments communicating with each other within a certain target unit, in order to ensure the accuracy of the judgment result, this type of data will also be reported. The data packets reported in this scenario meet the requirements of traffic detection and analysis.
[0080] When devices within Unit 1 access each other, or when devices within Unit 1 access devices within Unit 2 or other target units, the source IP address detected by detection device 110 is the IP address of the device within the unit, regardless of whether the access occurs through router 130 or a firewall. Therefore, in these two scenarios, there's no need to discuss whether the access occurs through router 130 or a firewall. However, when devices within Unit 2 or other units access Unit 1 through router 130 or a firewall, these devices use Network Address Translation (NAT) technology to convert private IP addresses (private IP addresses refer to networks used within an organization and are valid only internally) to public IP addresses (public IP addresses are unique identifiers assigned to network devices by internet service providers and are globally unique) during data transmission. This changes the detected source IP address (for example, when a data packet is transmitted from Unit 2 to Unit 1, the source IP address of the data packet from Unit 2 is replaced with a public IP address). Therefore, it's necessary to discuss whether inter-unit access occurs through router 130 or a firewall.
[0081] This embodiment also provides an electronic device 800, please refer to Figure 13 , Figure 13 The block diagram of the electronic device 800 is shown as an example. The electronic device includes a processor 810, a computer-readable storage medium 820, and a flow data control device 830.
[0082] The computer-readable storage medium 820 and the processor 810 are electrically connected to each other directly or indirectly to enable data transmission or interaction. For example, these elements can be electrically connected to each other via one or more communication buses or signal lines. The flow data control device 830 includes a plurality of software function modules that can be stored in the computer-readable storage medium 820 in the form of software or firmware or embedded in the operating system (OS) of the flow data control device 830. The processor 810 is used to execute executable modules stored in the computer-readable storage medium 820, such as the software function modules and computer programs included in the flow data control device 830.
[0083] The computer-readable storage medium 820 may be, but is not limited to, a random access memory (RAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), etc. The computer-readable storage medium 820 is used to store a program, and the processor 810 executes the program after receiving an execution instruction.
[0084] The processor 810 may be an integrated circuit chip with signal processing capabilities. The processor 810 may be a general-purpose processor 810, including a central processing unit (CPU) 810, a network processor (NP) 810, or a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor 810 may be a microprocessor 810 or any conventional processor 810.
[0085] Please refer to Figure 14 The present embodiment further provides a flow data control device 830, which includes multiple functional modules that can be stored in a computer-readable storage medium 820 in software form. Functionally, the flow data control device 830 may include a receiving module 831, a detection module 832, a determination module 833, a transmission module 834, a second determination module 835, a third determination module 836, and a sorting module 837. Among them: The receiving module 831 may be configured to obtain a target data packet sent by a target unit to a communication unit, and / or obtain the target data packet sent by the communication unit and received by the target unit.
[0086] In this embodiment, the receiving module 831 can be used to perform Figure 1 As shown in step S110, for a detailed description of the receiving module 831, reference may be made to the description of step S110.
[0087] The detection module 832 may be configured to detect the target data packet and determine the source IP address and destination IP address of the target data packet.
[0088] In this embodiment, the detection module 832 can be used to perform Figure 1 As shown in step S120, for a detailed description of the detection module 832, reference may be made to the description of step S120.
[0089] The determining module 833 may be configured to determine whether the target unit and the communication unit are in internal communication based on the source IP address and the destination IP address of the target data packet.
[0090] In this embodiment, the determining module 833 can be used to execute Figure 1As shown in step S130, for the detailed description of the determination module 833, reference may be made to the description of step S130.
[0091] If the target unit and the communication unit are not in internal communication, the transmission module 834 can be used to transmit the target data packet to the receiving system.
[0092] In this embodiment, the transmission module 834 can be used to perform Figure 1 As shown in step S140, for the detailed description of the transmission module 834, please refer to the description of step S140.
[0093] In summary, this embodiment provides a traffic data control method, device, and electronic device, which detects and judges the source IP address and destination IP address of the target data packet, distinguishes internal communication from external communication, and processes the target data packet differently according to the communication type. In this way, internal communication data can be effectively filtered out, the amount of data transmitted to the receiving system can be reasonably controlled, the network bandwidth occupancy can be reduced, the utilization rate of network resources can be improved, and the cost of data transmission can be reduced, and the security and controllability of the network can be enhanced.
[0094] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprise," "include," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.
[0095] The above description is merely a preferred embodiment of the present application and is not intended to limit the present application. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present application shall be included within the scope of protection of the present application.
Claims
1. A flow data control method, characterized in that: The method comprises: Acquire a target data packet sent by a target unit to a communication unit, and / or acquire the target data packet sent by the communication unit and received by the target unit; Detecting the target data packet to determine the source IP address and destination IP address of the target data packet; Determining whether the target unit and the communication unit are in internal communication according to the source IP address and the destination IP address of the target data packet; If the target unit and the communication unit are not in internal communication, transmitting the target data packet to a receiving system; If the target unit and the communication unit are in internal communication, the target data packet is not transmitted to the receiving system.
2. The flow data control method according to claim 1, characterized in that: The method further comprises: Obtain the source IP address database corresponding to each target unit in the same network environment; The step of determining whether the target unit and the communication unit are in internal communication based on the source IP address and the destination IP address of the target data packet includes: Determine whether the source IP address exists in the source IP address database corresponding to the target unit; If the source IP address does not exist in the source IP address database corresponding to the target unit, the target unit and the communication unit are not communicating internally; If the source IP address exists in the source IP address database corresponding to the target unit, determining whether the destination IP address exists in the source IP address database corresponding to the target unit; If the destination IP address does not exist in the source IP address database corresponding to the target unit, the target unit and the communication unit are not in internal communication.
3. The flow data control method according to claim 2, characterized in that: After the step of determining whether the destination IP address exists in the source IP address database corresponding to the target unit, the method further includes: Determine whether the network segment where the source IP address is located is the same as the network segment where the destination IP address is located; If the network segment where the source IP address is located is different from the network segment where the destination IP address is located, then the target unit and the communication unit are not communicating internally; If the network segment where the source IP address is located is the same as the network segment where the destination IP address is located, the target unit and the communication unit are in internal communication.
4. The flow data control method according to claim 3, characterized in that: The step of determining whether the network segment where the source IP address is located is the same as the network segment where the destination IP address is located includes: The subnet mask is used to determine whether the network segment where the source IP address is located is the same as the network segment where the destination IP address is located.
5. The flow data control method according to claim 2, characterized in that: After the step of obtaining a source IP address database corresponding to each target unit in the same network environment, the method further includes: Determine whether the source IP address exists in the source IP address database corresponding to the target unit; If the source IP address does not exist in the source IP address database corresponding to the target unit, the source IP address is stored in the source IP address database corresponding to the target unit.
6. The flow data control method according to claim 2, characterized in that: The step of obtaining a source IP address database corresponding to each target unit in the same network environment includes: For each target unit in the same network environment, obtaining the data packets to be detected received or sent by each target unit within a preset time period; Detecting each of the data packets to be detected, and obtaining the source IP address of each of the data packets to be detected; The source IP address of each of the data packets to be detected is stored in a source IP address database corresponding to each of the target units.
7. The flow data control method according to claim 6, characterized in that: The step of obtaining the data packets to be detected received or sent by each target unit within a preset time period includes: The data packets to be detected received or sent by each target unit within a preset time period are obtained through the mirror port of the core switch.
8. A flow data control device, characterized in that: include: a receiving module, configured to obtain a target data packet sent by a target unit to a communication unit, and / or obtain the target data packet sent by the communication unit and received by the target unit; A detection module, configured to detect the target data packet and determine the source IP address and destination IP address of the target data packet; a determination module, configured to determine whether the target unit and the communication unit are in internal communication according to the source IP address and the destination IP address of the target data packet; a transmission module, configured to transmit the target data packet to a receiving system if the target unit and the communication unit are not in internal communication; If the target unit and the communication unit are in internal communication, the target data packet is not transmitted to the receiving system.
9. An electronic device, characterized in that: The electronic device includes a processor and a computer-readable storage medium, wherein the computer-readable storage medium stores machine-executable instructions. When the machine-executable instructions are executed by the processor, the method according to any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium, characterized in that A computer program is stored thereon, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.