Traffic detection method, electronic equipment and readable storage medium
By carrying the identification and path information in the traffic for matching, using SRv6's PeerLocator, the high resource consumption problem caused by traditional five-tuple matching technology is solved, and efficient flow-by-flow detection and specific path status monitoring are achieved.
Patent Information
- Application Number
- CN202510894101.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-08-15
AI Technical Summary
Traditional traffic detection methods rely on five-tuple matching technology, resulting in high node resource consumption, inability to efficiently implement flow-by-flow detection for specific traffic, and the status of specific paths cannot be monitored.
By carrying identification information and path information in the traffic to match, avoiding additional encapsulation and decapsulation operations, the PeerLocator of SRv6 is directly embedded in IPv6 messages, realizing flow-by-flow detection of specific traffic.
It simplifies the complexity of traffic detection, improves detection efficiency, and can identify the status of a specific transmission path, supporting end-to-end traffic detection of multiple service types.
Smart Images

Figure CN120499050A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of communication technology, and in particular to a flow detection method, an electronic device, and a readable storage medium. Background Art
[0002] Traditional traffic detection methods typically rely on matching techniques based on five-tuples. The five-tuple consists of the source IP address, destination IP address, protocol number, source port number, and destination port number. This information is used to identify and classify network traffic. By matching this five-tuple information with pre-defined access control lists (ACLs), the behavior of specific traffic can be effectively managed and monitored. However, while five-tuple matching technology can achieve precise identification, this method requires decapsulating the five-tuple information carried by each service flow in multiple service flows one by one to find the traffic to be detected. This significantly increases node resource consumption and cannot effectively implement in-stream detection of specific traffic. Summary of the Invention
[0003] The embodiments of the present application provide a flow detection method, an electronic device, and a readable storage medium, which can efficiently implement in-flow detection of specific flow.
[0004] In order to solve the above technical problems, this application is implemented as follows: In a first aspect, a traffic detection method is provided, which is applied to a node. The method includes: in response to receiving a first traffic, matching the first identification information and the first path information carried by the first traffic in at least one second traffic detection information, wherein each second traffic detection information includes second identification information, second path information and detection items corresponding to the traffic to be detected, the first path information includes the necessary nodes corresponding to the first traffic, and the second path information includes the necessary nodes corresponding to the traffic to be detected; in response to the first identification information matching the second identification information in the target second traffic detection information, and the first path information matching the second path information in the target second traffic detection information, performing in-flow detection on the first traffic based on the detection items in the target second traffic detection information, wherein the at least one second traffic detection information includes the target second traffic detection information.
[0005] In a second aspect, a flow detection method is provided, which is applied to a controller, and the method includes: obtaining a second mapping table, wherein the second mapping table includes at least one second flow detection information, each second flow detection information includes second identification information, second path information and detection items corresponding to a flow to be detected, and the second path information includes the necessary nodes corresponding to the flow to be detected; for each second flow detection information, determining at least one detection node for detecting the flow to be detected from the included second path information; constructing a first mapping table corresponding to each detection node, wherein the first mapping table includes the second flow detection information corresponding to the flow to be detected detected by the detection node; and sending each first mapping table to the corresponding detection node.
[0006] In a third aspect, an electronic device is provided, comprising a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the program or instructions are executed by the processor, the steps of the method described in the first aspect are implemented, or the steps of the method described in the second aspect are implemented.
[0007] In a fourth aspect, a readable storage medium is provided, in which at least one computer program is stored. When the computer program is loaded and executed by a processor, the steps of the method described in the first aspect or the steps of the method described in the second aspect are implemented.
[0008] In a fifth aspect, a computer program product is provided, which includes program instructions. When the program instructions are executed by a computer, the computer implements the steps of the method described in the first aspect, or implements the steps of the method described in the second aspect.
[0009] In an embodiment of the present application, in response to receiving a first flow, the first identification information and the first path information carried by the first flow are matched in at least one second flow detection information, wherein each second flow detection information includes second identification information, second path information and detection items corresponding to the flow to be detected, the first path information includes the necessary nodes corresponding to the first flow, and the second path information includes the necessary nodes corresponding to the flow to be detected. In response to the first identification information matching the second identification information in the target second flow detection information, and the first path information matching the second path information in the target second flow detection information, the first flow is detected based on the detection items in the target second flow detection information, wherein at least one second flow detection information includes the target second flow detection information. In this way, by matching specific flow through identification information and path information, additional encapsulation and decapsulation operations are avoided, thereby simplifying the complexity of flow matching and improving the efficiency of flow detection. In addition, when detecting the flow of a specific transmission path, the state of the specific transmission path can also be detected, thereby identifying whether the path through which the flow passes is the optimal path.
[0010] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0012] Figure 1 A flow chart of a flow detection method provided by an exemplary embodiment of the present application is shown; Figure 2 A schematic diagram of a link for flow detection provided by an exemplary embodiment of the present application is shown; Figure 3 A schematic diagram of a link for traffic transmission provided by another exemplary embodiment of the present application is shown; Figure 4 Another flow chart of a flow detection method provided by an exemplary embodiment of the present application is shown; Figure 5 A schematic structural diagram of an electronic device provided by an exemplary embodiment of the present application is shown. DETAILED DESCRIPTION
[0013] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0014] Figure 1 A flow chart of a traffic detection method provided by an exemplary embodiment of the present application is shown. When applied to a node, the method may include the following steps: S110: In response to receiving the first traffic, matching the first identification information and the first path information carried by the first traffic with at least one second traffic detection information.
[0015] Among them, each second flow detection information includes second identification information, second path information and detection items corresponding to the flow to be detected, the first path information includes the necessary nodes corresponding to the first flow, and the second path information includes the necessary nodes corresponding to the flow to be detected.
[0016] The first identification information is used to identify the first traffic flow, and the first path information is used to indicate the transmission path of the first traffic flow, that is, the first path information includes the necessary nodes for the first traffic flow. In one exemplary embodiment, in a peer-to-peer (P2P) network, the necessary nodes may be peer nodes. The second identification information is used to identify the corresponding traffic flow to be detected, and the second path information is used to indicate the transmission path of the corresponding traffic flow to be detected, that is, the second path information includes the necessary nodes for the traffic flow to be detected, and the necessary nodes include detection nodes for detecting the traffic flow to be detected, with the current node being one of the detection nodes. The detection item indicates detection information related to the corresponding traffic flow to be detected. In another exemplary embodiment, the address information of each necessary node can be identified by a PeerLocator. Since the SRv6 PeerLocator is directly embedded in the IPv6 packet, it can avoid additional encapsulation and decapsulation operations while implementing in-stream detection of specific traffic, thereby simplifying the complexity of traffic detection.
[0017] S120: In response to the first identification information matching the second identification information in the target second flow detection information, and the first path information matching the second path information in the target second flow detection information, perform in-flow detection on the first flow based on the detection items in the target second flow detection information.
[0018] The at least one second flow detection information includes target second flow detection information.
[0019] It is understandable that after the first traffic starts from the entry node, it will be forwarded by the routing node and eventually reach the destination node, wherein the routing node includes a necessary node corresponding to the first traffic, and the necessary node includes a detection node for detecting the first traffic. When the first traffic arrives at the current node, the current node needs to determine whether the first traffic needs to be detected while forwarding the first traffic. Therefore, it will match the first identification information and the first path information carried by the first traffic in at least one second traffic detection information. If there is second traffic detection information that matches the first traffic in at least one second traffic detection information, it is determined that the first traffic needs to be detected, and the matching second traffic detection information is determined to be the target second traffic detection information. Then, based on the detection items in the target second traffic detection information, the first traffic is detected along the flow. In the matching process, the first identification information of the first traffic is matched with the second identification information corresponding to the traffic to be detected in each second traffic detection information, and the first path information of the first traffic is matched with the second path information corresponding to the traffic to be detected in each second traffic detection information. If both match, it is determined that the match is successful. In related technologies, ACLs are used to define conditions for allowing or denying specific network traffic. For example, an ACL rule might be "Allow detection of traffic with source IP address xx.xx.x.xx, destination IP address xx.xx.xx, protocol number 6, source port number 1, and destination port number 2." When a node receives service traffic, it extracts the five-tuple information from the service traffic and matches it against the rules in the ACL. If a match is found, the node detects the service traffic according to the instructions in the ACL rule. However, the use of the five-tuple requires checking these fields hop by hop, which increases the processing burden on the node and may also lead to increased complexity and latency in traffic detection. Furthermore, the five-tuple-based detection method can only identify the source and destination IP addresses of the service flow. However, service traffic may pass through multiple intermediate nodes during transmission, and the five-tuple cannot provide information about these intermediate nodes. Therefore, it is impossible to detect traffic along a specific path or monitor the status of a specific path, making it impossible to determine whether the service traffic is traversing the optimal path. In an embodiment of the present application, the first traffic carries the first path information, and each traffic to be detected also corresponds to the second path information. Therefore, direct matching can be performed, which can avoid the complexity of traditional five-tuple encapsulation. Moreover, based on the second path information, the current node can also detect the business traffic of a specific transmission path, and at the same time detect the status of the specific transmission path, thereby identifying whether the path passed by the business traffic is the optimal path.In addition, the address information of each must-pass node can be identified through PeerLocator. Since the PeerLocator of SRv6 is directly embedded in the IPv6 message, it avoids additional encapsulation and decapsulation operations based on the ability to implement in-flow detection of specific traffic, thereby simplifying the complexity of traffic detection.
[0020] In addition, the traffic detection method provided in the embodiment of the present application can be applied to SRv6 networks. SRv6 can support multiple service types and can use the second path information to quickly identify the traffic from one must-pass node to another must-pass node, thereby realizing end-to-end traffic detection.
[0021] In an exemplary embodiment, performing follow-up detection on the first flow based on the detection item in the target second flow detection information may include the following steps: Step 1: Receive the start detection instruction sent by the controller.
[0022] Among them, the detection start instruction is used to instruct the use of the corresponding detection point to detect the first flow. The detection point refers to a specific location set on the detection node for detecting the flow. The detection point may include the input interface and output interface of the detection node. The detection point is determined by the controller. It can be understood that in a peer-to-peer network (Peer to Peer, P2P), each peer node is both the receiver and the sender of the flow, and the detection point is used to monitor the data transmission of the node, so the input interface and output interface of the node can be set as the detection point. For example, Figure 2 As shown, it is assumed that CE1 is the entry node of the first traffic, CE2 is the exit node of the first traffic, PE1, PE2, PE3, and PE4 are the nodes that the first traffic must pass through, among which the detection nodes are PE1, PE3, and PE4. Therefore, detection points can be set at the entry and exit interfaces of PE1, PE3, and PE4.
[0023] Step 2: Utilize the detection point to detect the first flow based on the detection item in the target second flow detection information.
[0024] When it is necessary to use the detection node to perform in-flow detection on the first flow based on the detection items in the target second flow detection information, the controller issues a detection start instruction to each detection node, thereby instructing the detection point corresponding to each detection node to detect the first flow. In this embodiment, by setting a detection point on each detection node and using the detection point for detection, it is possible to avoid detecting irrelevant data within the node, thereby avoiding the introduction of a large amount of noise data, thereby improving detection efficiency and accuracy.
[0025] In an embodiment of the present application, in response to receiving a first flow, the first identification information and the first path information carried by the first flow are matched in at least one second flow detection information, wherein each second flow detection information includes second identification information, second path information and detection items corresponding to the flow to be detected, the first path information includes the necessary nodes corresponding to the first flow, and the second path information includes the necessary nodes corresponding to the flow to be detected. In response to the first identification information matching the second identification information in the target second flow detection information, and the first path information matching the second path information in the target second flow detection information, the first flow is detected based on the detection items in the target second flow detection information, wherein at least one second flow detection information includes the target second flow detection information. In this way, by matching specific flow through identification information and path information, additional encapsulation and decapsulation operations are avoided, thereby simplifying the complexity of flow matching and improving the efficiency of flow detection. In addition, when detecting the flow of a specific transmission path, the state of the specific transmission path can also be detected, thereby identifying whether the path through which the flow passes is the optimal path.
[0026] In an exemplary embodiment, before matching the first identification information and first path information carried by the first traffic with at least one second traffic detection information, the method further includes: receiving a first mapping table issued by a controller, the first mapping table including at least one second traffic detection information. That is, the first mapping table is issued by the controller to the current node, and the current node will perform follow-up detection on the traffic to be detected recorded in the first mapping table. The first mapping table may be a VPN-Peer Locator mapping relationship table, that is, the first mapping table records the mapping relationship between VPN traffic and a path, where the path includes at least one peer node, and each peer node identifies its own address information via a PeerLocator.
[0027] In an exemplary embodiment, each second flow detection information includes a link detection information reporting condition and a detection flag of the corresponding flow to be detected; after performing follow-up detection on the first flow based on the detection item in the target second flow detection information, the method further includes the following steps: Step 1: In response to the detection mark in the target second flow detection information being a first mark, a detection result of a follow-up flow detection is obtained, wherein the first mark is used to indicate that the flow matching the target second flow detection information is to be detected.
[0028] Step 2: In response to the detection result satisfying the link detection information reporting condition in the target second flow detection information, the detection result is reported to the controller.
[0029] It is understood that each second flow detection information includes a link detection information reporting condition for the corresponding flow to be detected and a detection flag. The link detection information reporting condition is used to evaluate the link status of the flow to be detected, and the detection flag is used to indicate whether the flow to be detected needs to be detected. The detection flag includes a first flag and a second flag. The first flag is used to indicate that the flow matching the target second flow detection information should be detected, and the second flag is used to indicate that the flow matching the target second flow detection information should be stopped. If the detection flag in the target second flow detection information is the first flag, it indicates that the flow to be detected in the target second flow detection information needs to be detected. If the first flow matches the flow to be detected, then the first flow needs to be detected with the flow, and the detection result of the flow detection is obtained. If the detection result meets the link detection information reporting condition in the target second flow detection information, it indicates that the state of the transmission link corresponding to the first flow is relatively good. Therefore, it can be determined that the obtained detection result is relatively accurate, and the detection result is reported to the controller. In addition, if the state of the transmission link is relatively good, the risk of loss of the detection result during the reporting process can be avoided.
[0030] In another exemplary embodiment, after obtaining the detection result of the in-flight detection, the method further includes: reporting the detection result to the controller. In other words, the node does not compare the detection result with the link detection information reporting conditions in the target second flow detection information, but directly reports the detection result to the controller for evaluation. This can reduce the complexity of node-side processing.
[0031] Furthermore, in another exemplary embodiment, after obtaining the detection result of the flow detection, the method also includes: in response to the detection result not meeting the link detection information reporting condition in the target second flow detection information, updating the detection mark in the target second flow detection information to a second mark, and notifying the first detection node through the controller to update the detection mark in the target second flow detection information to the second mark, wherein the second mark is used to indicate to stop detecting the flow matching the target second flow detection information, the first detection node is other detection nodes that are not the current node in the target second path information, and the target second path information is the second path information included in the target second flow detection information.
[0032] It can be understood that when the detection result does not meet the link detection information reporting conditions in the target second traffic detection information, it means that the current link status is poor, and the detection mark in the target second traffic detection information is updated to the second mark, and the first detection node is notified through the controller to update the detection mark in the target second traffic detection information to the second mark to instruct other detection nodes to stop detecting the traffic that matches the target second traffic detection information. This can avoid invalid detection. At the same time, the controller can also know that the path through which the first traffic passes is not the optimal path. Therefore, the link can be optimized, or the transmission path of the first traffic can be re-determined, and the first traffic can be dynamically redirected from the current path to the new transmission path, and the second path information of the target second traffic detection information recorded by each detection node can be synchronously updated.
[0033] In an exemplary embodiment, each second flow detection information includes a detection tag of the corresponding flow to be detected. Before performing in-flow detection on the first flow based on the detection item in the target second flow detection information, the method further includes: in response to the detection tag in the target second flow detection information being a second tag, stopping the step of performing in-flow detection on the first flow based on the detection item in the target second flow detection information, wherein the second tag is used to indicate to stop detecting the flow matching the target second flow detection information.
[0034] In other words, if the detection flag in the target second flow detection information is the second flag, it means that the flow to be detected corresponding to the target second flow detection information does not need to be detected, so the flow to be detected in the target second flow detection information is not matched, that is, the first flow matching the flow to be detected is not detected. In this way, by setting the detection flag, the demand for flexible flow detection can be met.
[0035] In an exemplary embodiment, after performing follow-up detection on the first flow based on the detection item in the target second flow detection information, the method further includes: In response to the detection mark in the target second flow detection information being the second mark and the current node being an ingress node, obtaining a detection result of the flow-based detection; In response to the detection result satisfying the link detection information reporting condition in the target second flow detection information, the detection mark in the target second flow detection information is updated to the first mark, and the second detection node is notified through the controller to update the detection mark in the target second flow detection information to the first mark, wherein the first mark is used to indicate the detection of the flow matching the target second flow detection information, the second mark is used to indicate the stop of the detection of the flow matching the target second flow detection information, the second detection node is other detection nodes that are not the current node in the target second path information, and the target second path information is the second path information included in the target second flow detection information.
[0036] In an embodiment of the present application, the detection mark includes two states: "empty" and "valued", where the "empty" state can be represented by the second mark, and the "valued" state can be represented by the first mark.
[0037] It is understandable that after receiving the first traffic, the current node determines whether it is the first node that the first traffic enters, that is, the entry node. If it is an entry node and the detection mark in the target second traffic detection information that matches the first traffic is the second mark, then the detection result of the flow detection is obtained, and based on the detection result, it is determined whether the first traffic needs to be detected. It should be noted that the entry node is not the source node, and the entry node is the first node that the first traffic must pass through after departing from the source node. In this embodiment, the entry node makes judgments and decisions in advance based on the current link status information, and promptly feeds back to the controller, so that the controller no longer needs to make judgments based on the link information reported by the entry node, thereby improving processing efficiency.
[0038] In an exemplary embodiment, the method also includes: in response to receiving an adjustment instruction issued by the controller, updating the detection mark in the target second flow detection information according to the adjustment instruction, wherein the adjustment instruction includes a first adjustment instruction instructing to adjust the detection mark to a first mark or a second adjustment instruction instructing to adjust the detection mark to a second mark, the first adjustment instruction is generated based on that the detection result of the first flow meets the link detection information reporting condition in the target second flow detection information, and the second adjustment instruction is generated based on that the detection result of the first flow does not meet the link detection information reporting condition in the target second flow detection information, the first mark is used to indicate to detect the flow matching the target second flow detection information, and the second mark is used to indicate to stop detecting the flow matching the target second flow detection information.
[0039] It can be understood that the detection mark in each second flow detection information can be dynamically modified. After receiving the adjustment instruction for the target second flow detection information issued by the controller, the detection mark indicated by the adjustment instruction is modified. The adjustment instruction can be a first adjustment instruction or a second adjustment instruction. When the adjustment instruction is the first adjustment instruction, the detection mark in the target second flow detection information is adjusted to the first mark. When the adjustment instruction is the second adjustment instruction, the detection mark in the target second flow detection information is adjusted to the second mark. Among them, the first adjustment instruction is generated based on the detection result of the first flow meeting the link detection information reporting condition in the target second flow detection information. That is to say, if the detection result of the first flow meets the link detection information reporting condition in the target second flow detection information, it means that the current link state is better and flow detection can be performed. Therefore, the detection mark in the target second flow detection information is adjusted to the first mark. If the detection result of the first flow does not meet the link detection information reporting condition in the target second flow detection information, it means that the current link state is poor. The controller can also know that the path through which the flow passes is not the optimal path. Therefore, the link can be optimized, or the transmission path of the flow can be re-determined, and the flow can be dynamically redirected from the current path to the new transmission path, and the second path information of the target second flow detection information recorded by each detection node is synchronously updated. In order to avoid invalid detection, the detection mark in the target second flow detection information is adjusted to the second mark.
[0040] In an exemplary embodiment, the method also includes: in response to the current node being an entry node and obtaining the path information, identification information and detection items of at least one flow to be detected, generating second flow detection information corresponding to each flow to be detected based on the path information, identification information and detection items of each flow to be detected; based on the at least one second flow detection information, constructing a second mapping table, and reporting the second mapping table to the controller.
[0041] It can be understood that the second mapping table can be constructed by the entry node. After the entry node completes the construction of the second mapping table, it feeds back to the controller. The controller then determines the first mapping table corresponding to each detection node based on the second mapping table. The first mapping table includes the second traffic detection information corresponding to the traffic to be detected by each detection node.
[0042] In an exemplary embodiment, after performing in-flow detection on the first flow based on the detection items in the target second flow detection information, the method further includes: obtaining a detection result of the in-flow detection; reporting the detection result to the controller according to a preset period; or, in response to receiving a reporting instruction issued by the controller, reporting the detection result to the controller. It is understood that the detection node can report the detection result according to a preset period or after receiving a reporting instruction issued by the controller, thereby increasing the flexibility of reporting the detection result.
[0043] In an exemplary embodiment, the method further includes: sending a first message to a controller, wherein the first message includes at least one candidate path between a first node and an adjacent second node and path status information corresponding to each candidate path, the first path information includes a first node and a second node, and the first node is a current node; receiving a second message returned by the controller based on the first message, wherein the second message is used to instruct the first node to forward the first traffic to the second node through a target path, and the target path is determined by the controller from at least one candidate path based on the path status information corresponding to each candidate path.
[0044] It can be understood that the first node and the second node are nodes that the first traffic must pass through, and there may be one or more paths between the two nodes. For example, Figure 3 As shown, the must-pass node PE1 and the must-pass node PE2 are adjacent, and there are three paths between PE1 and PE2, among which path L1 includes ①, path L2 includes the path ② between the P1 node, PE1 and P1, and the path ③ between P1 and PE2, and path L3 includes the path ④ between the P2 node, the P3 node, PE1 and P2, the path ⑤ between P2 and P3, and the path ⑥ between P3 and PE2. Therefore, after PE1 receives the first traffic, when forwarding the traffic to PE2, it can select one of the three paths to transmit the first traffic. In this embodiment, the first node can send a first message to the controller to instruct the controller to determine the target path for forwarding the traffic from at least one candidate path between the first node and the adjacent second node, so that the controller will determine the optimal path, i.e., the target path, from at least one candidate path based on the path status information of each candidate path.
[0045] Figure 4 A flow chart of a flow detection method provided by an exemplary embodiment of the present application is shown, which is applied to a controller. The method may include the following steps: S410: Obtain a second mapping table.
[0046] The second mapping table includes at least one second flow detection information, each second flow detection information includes second identification information corresponding to the flow to be detected, second path information and detection items, and the second path information includes the necessary nodes corresponding to the flow to be detected.
[0047] The second identification information is used to identify the corresponding traffic to be detected, and the second path information is used to indicate the transmission path of the corresponding traffic to be detected. That is, the second path information includes the nodes that the traffic to be detected must pass through, and the detection items are used to indicate the detection content related to the corresponding traffic to be detected. In one exemplary embodiment, the address information of each required node can be identified by PeerLocator. Because the SRv6 PeerLocator is directly embedded in the IPv6 packet, it can avoid additional encapsulation and decapsulation operations while implementing in-stream detection of specific traffic, thereby simplifying the complexity of traffic detection.
[0048] In an exemplary embodiment, S410 may include one of the following: (1) Receive a second mapping table sent by the ingress node, wherein the second mapping table is determined by the ingress node based on the second identification information, the second path information, and the detection item corresponding to each flow to be detected.
[0049] (2) Constructing a second mapping table based on the second identification information, the second path information, and the detection item corresponding to each flow to be detected sent by the ingress node.
[0050] The second path information corresponding to each traffic flow to be tested is determined based on the routing information of the traffic flow to be tested. It is understood that in an SRv6 network, traffic routing information is determined by a segment list, which is an ordered list of IPv6 addresses, each representing the SID of a peer node. Traffic is encapsulated with an Segment Routing Header (SRH) at the ingress node and forwarded hop by hop according to the order in the segment list, ensuring that traffic passes through designated nodes along the preset path, thereby achieving precise control of the traffic path. Therefore, based on the traffic routing information, the traffic transmission path, namely the second path information, can be determined.
[0051] In an exemplary embodiment, the detection items corresponding to different to-be-detected flows may be the same or different.
[0052] In an exemplary embodiment, the second path information corresponding to different to-be-detected traffic may be the same or different.
[0053] S420: For each piece of second traffic detection information, determine at least one detection node for detecting the traffic to be detected from the included second path information.
[0054] It's understandable that if each flow to be detected corresponds to the same detection node, then when multiple flows to be detected arrive at the detection node simultaneously, the node's processing capacity will be insufficient, or even cause congestion. Therefore, it is necessary to determine the detection node corresponding to each flow to be detected to improve detection stability. In addition, the path information corresponding to each flow to be detected may be different, so it is necessary to determine the corresponding detection node for each flow to be detected.
[0055] S430: Construct a first mapping table corresponding to each detection node.
[0056] The first mapping table includes second traffic detection information corresponding to the traffic to be detected detected by the detection node. The first mapping table may be a VPN-Peer Locator mapping relationship table, that is, the first mapping table records the correspondence between traffic and paths, where the path includes at least one peer node, and the at least one peer node includes the detection node, and each peer node identifies its own address information using a Peer Locator.
[0057] S440: Send each first mapping table to a corresponding detection node.
[0058] Regarding the above S430-S440, it can be understood that the second mapping table includes second flow detection information corresponding to multiple flows to be detected. If the second mapping table is sent to each detection node, the following situation may exist: For example, it is assumed that the second mapping table includes second flow detection information L1 and second flow detection information L2, wherein the necessary nodes in the second transmission path information in L1 and L2 include node a, node b, and node c, but the detection node corresponding to L1 is only node a, and the detection node corresponding to L2 is node b. If the entire second mapping table is sent to node a, then node a will also detect the flow when receiving the flow that matches L2. If the entire second mapping table is sent to node b, then node b will also detect the flow when receiving the flow that matches L1. Therefore, in order to avoid false detection, it is necessary to construct a first mapping table corresponding to each detection node, and send each first mapping table to the corresponding detection node. In this way, each detection node only needs to detect specific flow.
[0059] In related technologies, ACLs are used to define conditions for allowing or denying specific network traffic. For example, an ACL rule might be "Allow detection of traffic with source IP address xx.xx.x.xx, destination IP address xx.xx.xx, protocol number 6, source port number 1, and destination port number 2." When a node receives service traffic, it extracts the five-tuple information from the service traffic and matches it against the rules in the ACL. If a match is found, the node detects the service traffic according to the instructions in the ACL rule. However, the use of the five-tuple requires checking these fields hop by hop, which increases the processing burden on the node and may also lead to increased complexity and latency in traffic detection. Furthermore, the five-tuple-based detection method can only identify the source and destination IP addresses of the service flow. However, service traffic may pass through multiple intermediate nodes during transmission, and the five-tuple cannot provide information about these intermediate nodes. Therefore, it is impossible to detect traffic along a specific path or monitor the status of a specific path, making it impossible to determine whether the service traffic is traversing the optimal path. In an embodiment of the present application, each detection node corresponds to a first mapping table, and the first mapping table includes second traffic detection information corresponding to the traffic to be detected by the detection node, and each second traffic detection information includes second identification information, second path information and detection items corresponding to the traffic to be detected. Therefore, when the detection node receives the traffic, it can directly match it, which can avoid the complexity of traditional five-tuple encapsulation. Moreover, based on the second path information, the detection node can detect the business traffic of a specific transmission path, and at the same time detect the status of the specific transmission path, thereby identifying whether the path through which the business traffic passes is the best path. In addition, the address information of each necessary node can be identified by PeerLocator. At the same time, in the SRv6 network, PeerLocator is directly embedded in the IPv6 message. Therefore, each detection node can avoid additional encapsulation and decapsulation operations on the basis of realizing in-flow detection of specific traffic based on the first mapping table, thereby simplifying the complexity of traffic detection.
[0060] In addition, the traffic detection method provided in the embodiment of the present application can be applied to SRv6 networks. SRv6 can support multiple service types. The second path information can be used to quickly identify the traffic from one must-pass node to another must-pass node, thereby realizing end-to-end traffic detection.
[0061] In an embodiment of the present application, by obtaining a second mapping table, wherein the second mapping table includes at least one second flow detection information, each second flow detection information includes second identification information, second path information and detection items corresponding to the flow to be detected, and the second path information includes the necessary nodes corresponding to the flow to be detected, for each second flow detection information, at least one detection node for detecting the flow to be detected is determined from the included second path information, and a first mapping table corresponding to each detection node is constructed, wherein the first mapping table includes the second flow detection information corresponding to the flow to be detected detected by the detection node, and each first mapping table is sent to the corresponding detection node, so that the detection node can perform efficient on-flow detection of specific flow based on the first mapping table. In addition, it can also enable the detection node to detect the status of the specific transmission path while detecting the flow of the specific transmission path, thereby identifying whether the path through which the flow passes is the optimal path.
[0062] In an exemplary embodiment, each second flow detection information also includes link detection information reporting conditions and detection marks; after sending each first mapping table to the corresponding detection node, the method also includes: in response to receiving an adjustment instruction for the target second flow detection information, forwarding the adjustment instruction to the fourth detection node.
[0063] Among them, the adjustment instruction includes a first adjustment instruction indicating that the detection mark of the target second flow detection information is adjusted to a first mark or a second adjustment instruction indicating that the detection mark of the target second flow detection information is adjusted to a second mark. The first adjustment instruction is reported by the third detection node based on that the detection result of the first flow meets the link detection information reporting conditions in the target second flow detection information. The second adjustment instruction is reported by the third detection node based on that the detection result of the first flow does not meet the link detection information reporting conditions in the target second flow detection information. The third detection node is the detection node in the target second path information, the target second path information is the second path information included in the target second flow detection information, and the fourth detection node is the detection node that is not the third detection node in the target second path information. The first mark is used to indicate the detection of the flow matching the target second flow detection information, and the second mark is used to indicate the stop of the detection of the flow matching the target second flow detection information. The target second flow detection information is the second flow detection information that matches the first flow in the second mapping table.
[0064] It can be understood that the detection mark in each second flow detection information can be dynamically modified. After receiving the adjustment instruction for the target second flow detection information sent by the third detection node, the adjustment instruction is forwarded to the fourth detection node, wherein the adjustment instruction can be a first adjustment instruction or a second adjustment instruction, the first adjustment instruction is used to indicate that the detection mark in the target second flow detection information is adjusted to a first mark, and the second adjustment instruction is used to indicate that the detection mark in the target second flow detection information is adjusted to a second mark. Among them, the first adjustment instruction is generated by the third detection node based on the detection result of the first flow meeting the link detection information reporting condition in the target second flow detection information. That is to say, if the detection result of the first flow meets the link detection information reporting condition in the target second flow detection information, it means that the current link state is better and flow detection can be performed, so the other detection nodes are notified to adjust the detection mark in the target second flow detection information to the first mark; if the detection result of the first flow does not meet the link detection information reporting condition in the target second flow detection information, it means that the current link state is poor, and the controller can also know that the path through which the flow passes is not the optimal path. Therefore, the link can be optimized, or the transmission path of the flow can be re-determined, and the flow can be dynamically redirected from the current path to the new transmission path, and the second path information of the target second flow detection information recorded by each detection node is synchronously updated. In order to avoid invalid detection, the other detection nodes are notified to adjust the detection mark in the target second flow detection information to the second mark.
[0065] In an exemplary embodiment, each second flow detection information further includes a link detection information reporting condition and a detection flag; after sending each first mapping table to the corresponding detection node, the method further includes the following steps: Step 1: In response to receiving a detection result of the first flow, the detection result is compared with a link detection information reporting condition in the target second flow detection information.
[0066] The target second flow detection information is the second flow detection information that matches the first flow in the second mapping table.
[0067] Step 2: In response to the detection result not meeting the link detection information reporting condition in the target second flow detection information, generate a second adjustment instruction, and send the second adjustment instruction to the fifth detection node.
[0068] Among them, the second adjustment instruction is used to indicate that the detection mark of the target second flow detection information is adjusted to the second mark, the second mark is used to indicate to stop detecting the flow that matches the target second flow detection information, and the fifth detection node is the detection node corresponding to the flow to be detected in the target second flow detection information.
[0069] It is understandable that after the detection node obtains the detection result of the first flow, it reports the detection result. The controller side compares the detection result with the link detection information reporting condition in the target second flow detection information to determine whether to adjust the detection mark in the target second flow detection information. If the detection result does not meet the link detection information reporting condition in the target second flow detection information, the detection mark in the target second flow detection information needs to be adjusted to the second mark, so a second adjustment instruction is generated and the second adjustment instruction is sent to the fifth detection node. In addition, if the detection result meets the link detection information reporting condition in the target second flow detection information, the link state is better, and the detection mark is kept as the first mark. The first mark is used to indicate that the flow matching the target second flow detection information is detected.
[0070] In another exemplary embodiment, after sending the second adjustment instruction to the fifth detection node, the method may further include: sending a first adjustment instruction to the fifth detection node in response to the target detection instruction, wherein the target detection instruction is used to indicate the flow to be detected corresponding to the target second flow detection information, and the first adjustment instruction is used to indicate that the detection mark of the target second flow detection information is adjusted to a first mark, and the first mark is used to indicate detection of the flow matching the target second flow detection information.
[0071] The above-mentioned flow detection method is further described below through two exemplary embodiments.
[0072] Example 1 Continue to refer to the above Figure 2 For example, in an L3VPN service scenario, VRF1 IPv4 traffic with source node CE1 is forwarded through the SRv6 network to destination node CE2. Assume that the peer nodes in the SRv6 network are PE1-PE2-PE3-PE4, and that PE1, PE2, PE3, and PE4 in the SRv6 network are all nodes that the VRF1 IPv4 traffic must pass through. It is necessary to monitor the network performance of the VRF1 IPv4 traffic in PE1, PE3, and PE4, as well as diagnose and locate the link status. Therefore: 1) The controller sends a first mapping table to PE1, PE3, and PE4. The first mapping table includes second traffic detection information corresponding to VRF1. The second traffic detection information includes a second traffic identifier, second path information, link detection information reporting conditions, detection flags, detection items, etc. for VRF1 IPv4 traffic. In the second path information, the address information of each peer node is identified by PeerLocator.
[0073] 2) VRF1 IPv4 traffic flows from CE1 to CE2. The service flow carries a VRF1 IPv4 traffic identifier. Upon receiving the VRF1 IPv4 traffic, the detection node at detection-supporting nodes PE1, PE3, and PE4 queries the first mapping table for second traffic detection information matching the VRF1 IPv4 traffic. If second traffic detection information matching the VRF1 IPv4 traffic exists, the detection node uses the matching second traffic detection information as the target second traffic detection information and determines whether the detection flag in the target second traffic detection information is empty. If the detection flag is empty and the detection node is the first ingress node of the traffic, i.e., PE1, PE1 first performs IOAM detection and compares the detection information with the link detection information reporting conditions to determine whether the traffic requires detection. If detection is determined to be required, PE1 reports an adjustment instruction to the controller. The adjustment instruction notifies other detection nodes to adjust the detection flag to the first flag, which indicates that the traffic matching the target second traffic detection information should be detected. PE1, PE3, and PE4 then update the detection flag in the target second traffic detection information. At the same time, the controller sets the traffic inlet and outlet of each detection node as the detection point based on the second path information corresponding to the VRF1 IPv4 traffic. PE1, PE3, and PE4 will detect the VRF1 IPv4 traffic at the detection point and send the relevant detection content in the traffic to the controller based on the detection items corresponding to the VRF1 IPv4 traffic. The controller summarizes the data reported by nodes PE1, PE3, and PE4 and processes the received data, thereby realizing in-flow detection of specific traffic.
[0074] Example 2 Continue to refer to the above Figure 2 For example, in an L3VPN service scenario, VRF1 traffic carrying attribute A originating from CE1 is forwarded over the SRv6 network to destination CE2. Assume that the peer nodes in the SRv6 network are PE1, PE2, PE3, and PE4, and that PE1, PE2, PE3, and PE4 in the SRv6 network are all nodes through which VRF1 traffic carrying attribute A must pass. It is necessary to monitor network performance and link status diagnosis and location for VRF1 traffic carrying attribute A at PE1, PE3, and PE4. Therefore: 1) The controller sends a first mapping table to PE1, PE3, and PE4. The first mapping table includes second traffic detection information corresponding to VRF1. The second traffic detection information includes a second traffic identifier, second path information, link detection information reporting conditions, detection flags, detection items, etc. for VRF1 IPv4 traffic. In the second path information, the address information of each peer node is identified by PeerLocator.
[0075] 2) When VRF1 traffic carrying attribute A flows from CE1 to CE2, the detection node at detection-supporting nodes PE1, PE3, and PE4 receives the VRF1 IPv4 traffic. The detection node queries the first mapping table for second traffic detection information that matches the VRF1 IPv4 traffic. If so, the node uses the matching second traffic detection information as the target second traffic detection information and determines whether the detection flag in the target second traffic detection information is empty. If the detection flag is the first flag, the node detects the VRF1 traffic carrying attribute A. If the node determines that the link is degraded by comparing the link status information with the link detection information reporting conditions, it automatically updates its detection flag and sends a detection flag update message to the controller, notifying other detection nodes to update the detection flag. After updating the detection flag, the node stops detecting and sending detection information.
[0076] In the above-mentioned first embodiment, detection of VRF1 IPv4 traffic is implemented, and in the above-mentioned second embodiment, detection of VRF1 traffic carrying attribute A is implemented, wherein both the VRF1 IPv4 traffic and the VRF1 traffic carrying attribute A correspond to the same second traffic detection information. Because the VRF1 traffic carrying attribute A belongs to VRF1 IPv4 traffic, after receiving the VRF1 traffic carrying attribute A, the detection node queries the first mapping table to see whether there is a second traffic detection that matches the VRF1 IPv4 traffic. If so, the VRF1 traffic carrying attribute A is detected. In other words, VRF1 traffic carrying different attributes all belong to VRF1 traffic, and both correspond to the same second identification information and second path information. Therefore, the VRF1 traffic carrying different attributes can be detected based on the second traffic detection information corresponding to the VRF1 traffic.
[0077] like Figure 5 As shown, an embodiment of the present application further provides an electronic device 500, including a processor 510 and a memory 520, wherein the memory 520 stores programs or instructions that can be run on the processor 510, and when the program or instructions are executed by the processor 510, the various processes of the embodiment shown in the above-mentioned flow detection method are implemented, and the same technical effect can be achieved. To avoid repetition, they will not be described here.
[0078] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the embodiment shown in the above-mentioned traffic detection method are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
[0079] The processor is the processor in the terminal described in the above embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk. In some examples, the readable storage medium may be a non-transitory readable storage medium.
[0080] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the embodiment shown in the above-mentioned traffic detection method, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0081] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
[0082] An embodiment of the present application further provides a computer program / program product, which is stored in a storage medium. The computer program / program product is executed by at least one processor to implement the various processes of the embodiment shown in the above-mentioned traffic detection method, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0083] It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted or combined. In addition, the features described with reference to certain examples may be combined in other examples.
[0084] Through the above description of the embodiments, those skilled in the art will clearly understand that the methods of the above embodiments can be implemented using a computer software product and the necessary general-purpose hardware platform, or alternatively, hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.) and includes a number of instructions for causing a terminal or network-side device to execute the methods described in the various embodiments of this application.
[0085] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms of implementation methods without departing from the purpose of this application and the scope of protection of the claims. These implementation methods are all within the protection of this application.
Claims
1. A traffic detection method, applied to a node, comprising: In response to receiving the first flow, matching the first identification information and the first path information carried by the first flow with at least one second flow detection information, wherein each second flow detection information includes second identification information, second path information, and a detection item corresponding to the flow to be detected, the first path information includes a necessary node corresponding to the first flow, and the second path information includes a necessary node corresponding to the flow to be detected; In response to the first identification information matching the second identification information in the target second flow detection information, and the first path information matching the second path information in the target second flow detection information, the first flow is subjected to in-flow detection based on the detection item in the target second flow detection information, wherein the at least one second flow detection information includes the target second flow detection information.
2. The method according to claim 1, characterized in that Before matching the first identification information and the first path information carried by the first traffic in at least one second traffic detection information, the method further includes: A first mapping table sent by the controller is received, where the first mapping table includes the at least one second flow detection information.
3. The method according to claim 1, characterized in that Each of the second traffic detection information includes a link detection information reporting condition and a detection flag of the corresponding traffic to be detected; After performing follow-up detection on the first flow based on the detection item in the target second flow detection information, the method further includes: In response to the detection mark in the target second flow detection information being a first mark, obtaining a detection result of the accompanying flow detection, wherein the first mark is used to indicate that the flow matching the target second flow detection information is to be detected; In response to the detection result satisfying the link detection information reporting condition in the target second flow detection information, the detection result is reported to the controller.
4. The method according to claim 3, characterized in that After obtaining the detection result of the in-flow detection, the method further includes: In response to the detection result not meeting the link detection information reporting condition in the target second flow detection information, the detection mark in the target second flow detection information is updated to a second mark, and the first detection node is notified through the controller to update the detection mark in the target second flow detection information to the second mark, wherein the second mark is used to indicate to stop detecting the flow matching the target second flow detection information, the first detection node is other detection nodes that are not the current node in the target second path information, and the target second path information is the second path information included in the target second flow detection information.
5. The method according to claim 1, characterized in that Each second flow detection information includes a detection tag of the corresponding flow to be detected. Before performing the in-flow detection on the first flow based on the detection item in the target second flow detection information, the method further includes: In response to the detection mark in the target second traffic detection information being the second mark, stop executing the step of performing in-flow detection on the first traffic based on the detection item in the target second traffic detection information, wherein the second mark is used to indicate stopping detection of traffic matching the target second traffic detection information.
6. The method according to claim 1, characterized in that After performing follow-up detection on the first flow based on the detection item in the target second flow detection information, the method further includes: In response to the detection mark in the target second flow detection information being the second mark and the current node being an ingress node, obtaining a detection result of the accompanying flow detection; In response to the detection result satisfying the link detection information reporting condition in the target second flow detection information, the detection mark in the target second flow detection information is updated to the first mark, and the second detection node is notified through the controller to update the detection mark in the target second flow detection information to the first mark, wherein the first mark is used to indicate the detection of the flow matching the target second flow detection information, and the second mark is used to indicate the stop of the detection of the flow matching the target second flow detection information, the second detection node is other detection nodes that are not the current node in the target second path information, and the target second path information is the second path information included in the target second flow detection information.
7. The method according to claim 1, characterized in that The method further comprises: In response to receiving an adjustment instruction issued by the controller, the detection mark in the target second flow detection information is updated according to the adjustment instruction, wherein the adjustment instruction includes a first adjustment instruction instructing to adjust the detection mark to a first mark or a second adjustment instruction instructing to adjust the detection mark to a second mark, the first adjustment instruction is generated based on that the detection result of the first flow meets the link detection information reporting condition in the target second flow detection information, and the second adjustment instruction is generated based on that the detection result of the first flow does not meet the link detection information reporting condition in the target second flow detection information, the first mark is used to indicate to detect the flow matching the target second flow detection information, and the second mark is used to indicate to stop detecting the flow matching the target second flow detection information.
8. The method according to claim 1, characterized in that The method further comprises: In response to the current node being an ingress node and obtaining path information, identification information, and detection items of at least one of the to-be-detected flows, generating second flow detection information corresponding to each of the to-be-detected flows based on the path information, identification information, and detection items of each of the to-be-detected flows; Based on at least one of the second flow detection information, a second mapping table is constructed, and the second mapping table is reported to the controller.
9. A flow detection method, applied to a controller, comprising: Obtain a second mapping table, wherein the second mapping table includes at least one second flow detection information, each second flow detection information includes second identification information corresponding to a flow to be detected, second path information, and a detection item, and the second path information includes a necessary node corresponding to the flow to be detected; For each piece of the second traffic detection information, determining at least one detection node for detecting the traffic to be detected from the included second path information; Constructing a first mapping table corresponding to each detection node, wherein the first mapping table includes second flow detection information corresponding to the flow to be detected detected by the detection node; Each of the first mapping tables is sent to the corresponding detection node.
10. The method according to claim 9, characterized in that Each of the second flow detection information further includes a link detection information reporting condition and a detection flag; After sending each first mapping table to the corresponding detection node, the method further includes: In response to receiving an adjustment instruction for target second flow detection information, forwarding the adjustment instruction to a fourth detection node, wherein the adjustment instruction includes a first adjustment instruction instructing to adjust a detection flag of the target second flow detection information to a first flag or a second adjustment instruction instructing to adjust the detection flag of the target second flow detection information to a second flag, the first adjustment instruction is reported by the third detection node based on that a detection result of the first flow meets a link detection information reporting condition in the target second flow detection information, and the second adjustment instruction is reported by the third detection node based on that a detection result of the first flow does not meet a link detection information reporting condition in the target second flow detection information, the third detection node is a detection node in the target second path information, the target second path information is second path information included in the target second flow detection information, the fourth detection node is a detection node in the target second path information that is not the third detection node, the first flag is used to instruct to detect flow matching the target second flow detection information, and the second flag is used to instruct to stop detecting flow matching the target second flow detection information, and the target second flow detection information is the second flow detection information matching the first flow in the second mapping table.
11. The method according to claim 9, characterized in that Each of the second flow detection information further includes a link detection information reporting condition and a detection flag; After sending each first mapping table to the corresponding detection node, the method further includes: In response to receiving a detection result of the first flow, comparing the detection result with a link detection information reporting condition in target second flow detection information, wherein the target second flow detection information is the second flow detection information that matches the first flow in the second mapping table; In response to the detection result not meeting the link detection information reporting conditions in the target second flow detection information, a second adjustment instruction is generated and the second adjustment instruction is sent to the fifth detection node, wherein the second adjustment instruction is used to indicate that the detection mark of the target second flow detection information is adjusted to a second mark, and the second mark is used to indicate to stop detecting the flow that matches the target second flow detection information, and the fifth detection node is the detection node corresponding to the flow to be detected in the target second flow detection information.
12. The method according to claim 9, characterized in that The obtaining of the second mapping table includes: Receiving the second mapping table sent by the ingress node, wherein the second mapping table is determined by the ingress node based on the second identification information, the second path information, and the detection item corresponding to each of the to-be-detected flows; or; The second mapping table is constructed based on the second identification information, the second path information, and the detection item corresponding to each of the to-be-detected flows sent by the ingress node.
13. An electronic device, characterized in that: The method comprises a processor, a memory, and a program or instruction stored in the memory and executable on the processor, wherein the program or instruction, when executed by the processor, implements the steps of the flow detection method according to any one of claims 1 to 12.
14. A readable storage medium, characterized in that The readable storage medium stores a program or instruction, and when the program or instruction is executed by the processor, the steps of the flow detection method according to any one of claims 1 to 12 are implemented.
15. A computer program product, characterized in that The computer program product includes program instructions, and when the program instructions are executed by a computer, the computer is enabled to implement the steps of the flow detection method according to any one of claims 1 to 12.