Self-adaptive virtual sniffing system based on mirror image warehouse and deployment method
Through the mirror warehouse adaptive virtual sniffing system, the rapid batch deployment and adaptive configuration of virtual sniffing devices are realized, solving the deployment complexity and real-time problems in the existing technology, and improving network security protection capabilities and system stability.
Patent Information
- Application Number
- CN202510551244.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-08-19
AI Technical Summary
The existing virtual sniffing system deployment method requires manual configuration of network parameters. The configuration process is complex and error-prone, and it is impossible to sense network topology changes in real time. The static IP allocation strategy is prone to sniffing interruption or network paralysis, and it is impossible to achieve batch operations and mirror warehouse support.
The adaptive virtual sniffing system based on the mirror warehouse obtains operating parameters through the information collection module. The framework deployment module packages the parameters into standardized container images. The adaptive initial module adjusts the device status in real time, the detection module performs active and passive detection, and the batch deployment module dynamically allocates the IP address, and the status switching module adjusts the device status in real time to avoid conflicts.
It realizes rapid batch deployment of sniffing equipment, reduces the risk of deployment errors, supports large-scale network expansion, enhances network security protection capabilities, reduces manual operation and maintenance frequency and cost, and avoids network performance degradation.
Smart Images

Figure CN120512271A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cyberspace sniffing behavior perception, and specifically to an adaptive virtual sniffing system and deployment method based on an image repository. Background Art
[0002] In a network-based attack chain, reconnaissance is the first step for attackers to launch an attack and is also an important means for attackers to obtain information about the target. Through reconnaissance, attackers can obtain basic information about the target network, such as network topology, host information, and service information, providing important evidence for subsequent attacks. Therefore, sniffing behavior perception in cyberspace can effectively discover and identify attackers' reconnaissance behavior, and have the opportunity to cut off the attack chain in the early stages, thereby improving network security protection capabilities.
[0003] Common virtual sniffing systems and deployment methods require manual configuration of network parameters during use. The configuration process is complex and error-prone, and it is unable to perceive network topology changes in real time. Static IP allocation strategies are prone to IP conflicts with newly added physical devices, which can easily lead to sniffing interruptions or network paralysis. Batch operations cannot be performed through a unified platform, and the lack of image repository support makes it impossible to achieve one-time packaging and multi-point reuse. Therefore, we propose an adaptive virtual sniffing system and deployment method based on an image repository. Summary of the Invention
[0004] The purpose of the present invention is to provide an adaptive virtual sniffing system and deployment method based on an image repository.
[0005] To achieve the above objectives, the present invention provides the following technical solution: an adaptive virtual sniffing system based on an image repository, the adaptive virtual sniffing system comprising:
[0006] The information collection module collects information from different image repositories, obtains the target repository, collects the operating parameters of different image repositories on the virtual sniffing device, and obtains warehouse cases;
[0007] The framework deployment module packages the operating parameters, adaptive configuration algorithm, and multi-protocol parsing unit of the virtual sniffing device into a standardized container image, stores it in a unified image repository, establishes a management unit for the image repository, and uses the management unit to batch deploy devices. After the user selects the target device, the management unit automatically pulls the corresponding standardized container image and then installs the standardized container image to the corresponding device. At the same time, the image replication has a built-in initialization script to automatically adapt to different network environments.
[0008] The adaptive initialization module collects the network status of the device in real time, obtains the offline and online status of the device, and runs different operating parameters according to the different status of the device;
[0009] The detection module establishes a detection unit, which includes active detection and passive detection. Active detection uses the ARP protocol to scan network devices, obtain the basic IP-MAC mapping table, and send probe messages in real time to update the device online status. Passive detection parses SSDP, mDNS, LLDP, and OSPF protocol data to extract service information, topology information, and routing information to obtain network device information.
[0010] Deploy modules in batches to obtain a dynamic IP address pool. During each deployment, allocate 25% of the dynamic IP address pool for virtual sniffing devices to go online. At the same time, reserve 25% of the dynamic IP address pool to handle sudden physical device access.
[0011] The state switching module detects the traffic information of network devices in real time, obtains the number of network device parameters, and establishes a switching threshold. When the number of network device parameters exceeds the switching threshold, it automatically applies for a dynamic IP pool address and puts the device into an offline state.
[0012] As a further solution of the present invention: after obtaining the warehouse cases in the information collection module, the warehouse area size characteristics, sniffing time, data collection frequency and the interval distance of different virtual sniffing devices of the warehouse cases are extracted to obtain case characteristics, and at the same time, the characteristics of the warehouse area size characteristics, sniffing time, data collection frequency and the interval distance of different virtual sniffing devices in the target warehouse are extracted to obtain retrieval characteristics.
[0013] As a further solution of the present invention: after the retrieval features and case features in the information acquisition module are obtained, the retrieval feature values and case feature values in the retrieval features and case features are analyzed, and the parameter matching degree between the target warehouse and different warehouse cases is calculated based on the retrieval feature values and case feature values. Let the retrieval feature value be J T , let the case characteristic value be A T , let the number of retrieval feature values and case feature values be K, let the parameter matching degree between the target warehouse and different warehouse cases be M P , calculate the parameter matching degree between the target warehouse and different warehouse cases, and sort them in descending order. The specific formula is as follows:
[0014]
[0015] Obtain a matching table and then display the matching table.
[0016] As a further solution of the present invention: when different devices in the adaptive initial module operate with different operating parameters, an operating mode is set for the offline state and the online state of the device;
[0017] When the device is online, it will first obtain the dynamic IP pool address, subnet mask and gateway network configuration information through the DHCP protocol after startup, and then automatically identify and record the DNS, DHCP service address and key network parameters to obtain the operating parameters;
[0018] When the device is offline, it obtains a link-local address and automatically switches to the link-local address. At the same time, it supplements network information through passive detection and gradually transitions to the online state.
[0019] As a further solution of the present invention: the service information in the detection module is obtained by obtaining the service location and server description via the SSDP protocol;
[0020] Topology information is obtained by parsing the device port ID and neighbor IP address through the LLDP protocol;
[0021] Routing information is obtained by learning subnet division and hop count through OSPF and RIP protocols.
[0022] As a further solution of the present invention: after obtaining the service information, topology information and routing information in the detection module, the active detection data and the passive detection data are integrated to generate a dynamic network topology map, and at the same time, the required IP address pool is analyzed to obtain a backup IP address pool to avoid the risk of address exhaustion, wherein the upper limit of the backup IP address pool is 75% of the dynamic IP pool address.
[0023] As a further solution of the present invention: when the batch deployment module is deployed, an online conflict processing unit and an offline conflict processing unit are established, wherein the online conflict processing unit monitors ARP requests in real time and detects whether the physical device uses the virtual IP. When it is detected that the physical device uses the virtual IP, the IP that conflicts with the virtual IP is analyzed, and the conflicting IP is taken offline. At the same time, the offline processed IP is returned to the dynamic IP address pool and marked as to be reallocated. When the physical device is not detected to use the virtual IP, it will continue to run. When the physical device is offline, the offline conflict processing unit starts a delay detection mechanism. When it is detected that the same IP is only in one location, it determines that the IP is not occupied. At this time, the virtual sniffing IP is analyzed, and it is reactivated to update the address pool status.
[0024] As a further solution of the present invention: the state switching module also includes a load balancing control unit, which uses the load balancing control unit to limit the concurrent number of virtual sniffing devices to no more than 30% of the network bandwidth, and dynamically adjusts the detection frequency according to the traffic peak.
[0025] In addition, a deployment method of an adaptive virtual sniffing system based on an image repository is also provided, and the deployment method includes the following steps:
[0026] S100: After the user selects the target device, the management unit automatically pulls the corresponding standardized container image;
[0027] S200, installing the standardized container image to the corresponding device, and at the same time copying the built-in initialization script in the image to automatically adapt to different network environments;
[0028] S300 allocates 25% of the address pool from the dynamic IP address pool for the virtual sniffing device to go online, and reserves 25% of the address pool from the dynamic IP address pool to cope with sudden access of physical devices.
[0029] By adopting the above technical solution, compared with the prior art, the beneficial effects of the present invention are:
[0030] 1. This invention uses mirroring encapsulation and one-click scheduling deployment to achieve rapid batch deployment of sniffing devices, significantly shortening the deployment cycle. The automated initialization script adapts to multiple network environments, eliminating manual configuration steps, reducing the risk of deployment errors, and supporting elastic expansion from a single node to a large-scale network. Through the collaboration of active scanning and passive listening, it covers multi-dimensional information such as network topology, services, and routing. Configuration is completed through self-learning network parameters, reducing the frequency and cost of manual operation and maintenance. The detection intensity is adjusted according to real-time traffic to avoid network performance degradation caused by sniffing task overload.
[0031] 2. The present invention can clearly understand the differences between different warehouses in virtual sniffing scenarios through feature extraction, and can intuitively see the similarity between the target warehouse and existing cases, thereby enhancing the versatility of the system under different network environments, warehouse scales, and business needs. By seamlessly switching between soft and hard online states, the system can independently select the initialization mode according to network conditions, ensuring offline degradability and online upgradeability. Through batch allocation and real-time conflict detection, the virtual IP and physical devices can coexist seamlessly, avoiding network interruptions. The delay detection mechanism after the physical device goes offline balances IP reuse efficiency and network stability, reducing the risk of resource contention.
[0032] 3. This invention generates a real-time topology map by integrating multi-source data, significantly improving the recognition coverage of attacker reconnaissance behavior. Passive analysis of protocol traffic can identify encryption or non-standard services missed by traditional means, enhancing the comprehensiveness of threat perception. At the same time, it utilizes the real-time detection and offline mechanism of conflicting IP addresses to reduce the cost of network troubleshooting. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 This is a system flow chart in an embodiment of the present invention. DETAILED DESCRIPTION
[0034] The specific embodiments of the present invention will be further described below in conjunction with the accompanying drawings. It should be noted that the description of these embodiments is used to help understand the present invention, but does not constitute a limitation of the present invention.
[0035] In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0036] Example 1:
[0037] The adaptive virtual sniffing system based on the image warehouse of the present invention is used in large enterprise parks, which have a large number of office areas, production workshops, R&D centers, etc. The network structure is complex and the access devices are diverse, covering office computers, servers, industrial control equipment, Internet of Things sensors, etc. Enterprises attach great importance to network security and need to detect potential network attacks in a timely manner to ensure the security of sensitive enterprise data and the normal operation of business.
[0038] Traditionally, cyberspace sniffing behavior awareness has primarily been achieved by deploying various types of traffic detection devices to capture attackers' reconnaissance activities. Deploying such devices typically requires manual configuration based on basic Layer 2 cyberspace information. This involves numerous steps and is complex. Furthermore, any configuration errors often make it difficult to achieve effective results.
[0039] Therefore, in order to effectively solve the above problems, this application proposes an adaptive virtual sniffing system based on a mirror repository, as shown in the accompanying drawings of the specification. Figure 1 As shown, the adaptive virtual sniffing system includes:
[0040] The information collection module collects information from different image repositories, obtains the target repository, collects the operating parameters of different image repositories on the virtual sniffing device, and obtains warehouse cases;
[0041] The framework deployment module packages the operating parameters, adaptive configuration algorithm, and multi-protocol parsing unit of the virtual sniffing device into a standardized container image, stores it in a unified image repository, establishes a management unit for the image repository, and uses the management unit to batch deploy devices. After the user selects the target device, the management unit automatically pulls the corresponding standardized container image and then installs the standardized container image to the corresponding device. At the same time, the image replication has a built-in initialization script to automatically adapt to different network environments.
[0042] The adaptive initialization module collects the network status of the device in real time, obtains the offline and online status of the device, and runs different operating parameters according to the different status of the device;
[0043] The detection module establishes a detection unit, which includes active detection and passive detection. Active detection uses the ARP protocol to scan network devices, obtain the basic IP-MAC mapping table, and send probe messages in real time to update the device online status. Passive detection parses SSDP, mDNS, LLDP, and OSPF protocol data to extract service information, topology information, and routing information to obtain network device information.
[0044] ARP protocol, or Address Resolution Protocol, is a network layer protocol in the TCP / IP protocol stack. It is mainly used to resolve IP addresses to corresponding MAC addresses and plays a key role in local area network communications.
[0045] MAC address, also known as media access control address or physical address, is the unique identifier of a network device at the data link layer. It is a string of codes burned into the network card chip by the network device manufacturer during production.
[0046] The basic IP-MAC mapping table is a data table used by network devices to record the correspondence between IP addresses and MAC addresses. It plays a key role in network communications. It associates the IP address at the network layer with the MAC address at the data link layer to ensure accurate data transmission at different layers.
[0047] SSDP is an application layer protocol based on UDP, which is mainly used to realize automatic discovery of devices and services in local area networks;
[0048] UDP is the User Datagram Protocol, a lightweight communication protocol located at the transport layer, which has unique characteristics and application scenarios in network data transmission;
[0049] mDNS is a protocol for implementing domain name resolution in a local network. It allows devices to perform domain name resolution in a local area network by broadcasting without a traditional DNS server.
[0050] DNS servers are key devices on the Internet responsible for converting domain names into corresponding IP addresses. They play an indispensable role in network communications, mainly in domain name resolution, load balancing, and network management.
[0051] LLDP is a data link layer protocol used to discover information about neighboring devices in a local area network, including the device's port ID, device identifier, and neighbor IP address.
[0052] OSPF is an interior gateway protocol used for routing within an autonomous system. It determines the best route by calculating link status.
[0053] Service information refers to the description of various services on the network, including service location, server description, etc.
[0054] Topology information is used to describe the connection relationship between various devices in the network, including device port ID and neighbor IP address;
[0055] Routing information includes key content such as subnet division and hop count, which guides how data packets are transmitted from the source node to the destination node in the network;
[0056] Deploy modules in batches to obtain a dynamic IP address pool. During each deployment, allocate 25% of the dynamic IP address pool for virtual sniffing devices to go online. At the same time, reserve 25% of the dynamic IP address pool to handle sudden physical device access.
[0057] An IP address pool is a set of assignable IP addresses set up for efficient allocation and management of IP addresses in network management. It plays a key role in network planning and device access. An IP address pool consists of multiple consecutive or discontinuous IP addresses, which usually belong to the same network segment.
[0058] The state switching module detects the traffic information of network devices in real time, obtains the number of network device parameters, and establishes a switching threshold. When the number of network device parameters exceeds the switching threshold, it automatically applies for a dynamic IP pool address and puts the device into an offline state.
[0059] Specifically, collect information from different image repositories, obtain the target warehouse, collect operating parameters of different image repositories in the virtual sniffing device, obtain warehouse cases, package the operating system, adaptive configuration algorithm, protocol parsing module and initialization script of the virtual sniffing device into a standardized container image, and then upload the image to a unified managed image warehouse, support version control and multi-environment compatibility verification, select the target device or node through the management unit, trigger the automated deployment instruction, the platform pulls the image from the image warehouse and distributes it to the target device, completes the automated installation and environment adaptation, automatically loads the initialization script when the device is started for the first time, identifies the network interface and tries to obtain basic configuration information, collects the network status of the device in real time, obtains the offline status and online status of the device, and according to the different status of the device Make the device run with different operating parameters, broadcast detection requests through the ARP protocol, establish a preliminary IP-MAC address mapping table, regularly update the device online status table, mark active devices and offline devices, monitor network traffic, and parse SSDP, mDNS, LLDP and other protocol data packets in real time. Extract key parameters such as service location, device port information, subnet routing rules, and add them to the network topology map. Allocate addresses in batches from the available IP address pool according to a preset ratio for virtual sniffing equipment to go online. After each batch is deployed, monitor the network load in real time and dynamically adjust the subsequent allocation strategy. In the soft online state, complete parameter learning by continuously detecting network information. When sufficient configuration information is obtained, automatically apply for a dynamic IP address, switch to the hard online state and start the sniffing task.
[0060] Example 2:
[0061] After obtaining the warehouse case in the information collection module, the warehouse area size characteristics, sniffing time, data collection frequency, and the distance between different virtual sniffing devices are extracted to obtain the case characteristics. At the same time, the characteristics of the warehouse area size characteristics, sniffing time, data collection frequency, and the distance between different virtual sniffing devices in the target warehouse are extracted to obtain the retrieval characteristics.
[0062] After the retrieval features and case features in the information collection module are obtained, the retrieval feature values and case feature values in the retrieval features and case features are analyzed, and the parameter matching degree between the target warehouse and different warehouse cases is calculated based on the retrieval feature values and case feature values. Let the retrieval feature value be J T , let the case characteristic value be A T , let the number of retrieval feature values and case feature values be K, let the parameter matching degree between the target warehouse and different warehouse cases be M P , calculate the parameter matching degree between the target warehouse and different warehouse cases, and sort them in descending order. The specific formula is as follows:
[0063]
[0064] Obtain a matching table and then display the matching table;
[0065] When different devices in the adaptive initialization module run different operating parameters, set the operating mode for the offline and online states of the device;
[0066] When the device is online, it will first obtain the dynamic IP pool address, subnet mask and gateway network configuration information through the DHCP protocol after startup, and then automatically identify and record the DNS, DHCP service address and key network parameters to obtain the operating parameters;
[0067] When the device is offline, it obtains a link-local address and automatically switches to the link-local address. At the same time, it supplements network information through passive detection and gradually transitions to the online state.
[0068] DHCP is a network protocol used to simplify the process of configuring IP addresses for devices on a network;
[0069] The subnet mask is a 32-bit binary number used to distinguish the network part and the host part of the IP address;
[0070] Gateway network configuration information: A gateway is a gateway connecting one network to another. Gateway network configuration information includes the gateway's IP address and other content;
[0071] DNS is the server address for domain name resolution;
[0072] DHCP service address is the server address that provides DHCP service;
[0073] Key network parameters include IP address, subnet mask, default gateway, etc. The IP address is the identifier of the device on the network, just like the house number in real life, used to uniquely identify a device on the network;
[0074] Link-local addresses are mainly used within the local link. Link-local addresses are only valid within the local link. Their scope is strictly limited to the local link and will not be forwarded by the router to other networks. Local links include Ethernet segments and wireless LANs.
[0075] Specifically, the warehouse area size characteristics, sniffing time, data collection frequency and the interval distance of different virtual sniffing devices of the warehouse case are extracted to obtain case characteristics. At the same time, the characteristics of the warehouse area size characteristics, sniffing time, data collection frequency and the interval distance of different virtual sniffing devices in the target warehouse are extracted to obtain retrieval characteristics. The retrieval feature values and case feature values in the retrieval features and case characteristics are analyzed, and the parameter matching degree between the target warehouse and different warehouse cases is calculated based on the retrieval feature values and case feature values. They are sorted in descending order to obtain a matching table, and then the matching table is displayed. When in the online state, the device actively requests network configuration through the DHCP protocol. After successfully obtaining the configuration, the DNS, DHCP service address and key network parameters are recorded. If the DHCP service is unavailable or the configuration fails, the device automatically switches to the link local address to complete the network card initialization. In the soft online state, it relies on the subsequent detection module to gradually complete the network information, providing a basis for the transition to the hard online state.
[0076] Example 3:
[0077] The service information in the detection module is obtained by obtaining the service location and server description through the SSDP protocol;
[0078] Topology information is obtained by parsing the device port ID and neighbor IP address through the LLDP protocol;
[0079] Routing information is obtained by learning subnet division and hop count through OSPF and RIP protocols;
[0080] LLDP is a data link layer protocol used to automatically discover each other's identities, functions, and physical connection information between network devices. It plays a key role in network management, troubleshooting, and topology construction.
[0081] Routing information is obtained by learning subnet division and hop count through OSPF and RIP protocols;
[0082] OSPF is an open shortest path first protocol, which is an interior gateway protocol used for routing within an autonomous system.
[0083] RIP is one of the earliest dynamic routing protocols. It is based on the distance vector algorithm. Routers exchange routing information by periodically broadcasting their routing tables to adjacent routers.
[0084] Distance vector algorithm is an algorithm widely used in computer network routing, mainly used to determine the best transmission path for data packets from source node to destination node;
[0085] After obtaining service information, topology information, and routing information from the detection module, the active and passive detection data are integrated to generate a dynamic network topology map. At the same time, the required IP address pool is analyzed to obtain a backup IP address pool to avoid the risk of address exhaustion. The upper limit of the backup IP address pool is 75% of the dynamic IP pool addresses.
[0086] Dynamic network topology map is a visualization tool that directly displays the connection relationship and real-time status changes of devices in the network. It presents the network topology structure in a graphical way based on the real-time information of network devices.
[0087] When deploying the batch deployment module, an online conflict processing unit and an offline conflict processing unit are established. The online conflict processing unit monitors ARP requests in real time to detect whether the physical device uses the virtual IP. When it is detected that the physical device uses the virtual IP, it analyzes the IP that conflicts with the virtual IP and takes the conflicting IP offline. At the same time, the offline IP is returned to the dynamic IP address pool and marked as to be reallocated. When the physical device is not detected to be using the virtual IP, it will continue to run. When the physical device is offline, the offline conflict processing unit starts the delay detection mechanism. The delay detection mechanism defaults to 10 minutes. When the same IP is detected in only one location, it is determined that the IP is not occupied. At this time, the virtual sniffing IP is analyzed and reactivated to update the address pool status.
[0088] ARP requests are used to obtain the corresponding MAC address when the target IP address is known, ensuring that data frames at the data link layer can be accurately delivered to the target device;
[0089] MAC address, also known as media access control address, is a unique identifier of a network device at the data link layer and is embedded in the network card chip of the network device.
[0090] A virtual IP is an IP address that does not correspond to a real physical network interface on the network. It can be used like a real IP address through software or network device configuration.
[0091] Conflicting IPs means that two or more devices are assigned the same IP address in the same network environment;
[0092] The state switching module also includes a load balancing control unit, which uses the load balancing control unit to limit the number of concurrent virtual sniffing devices to no more than 30% of the network bandwidth, and dynamically adjust the detection frequency according to the traffic peak;
[0093] The state switching module detects the flow information of network devices in real time, including the flow volume, the number of network device parameters, etc., and provides this information to the load balancing control unit. The load balancing control unit determines the current network load situation based on this information in order to implement the corresponding control strategy;
[0094] The state switching module establishes a switching threshold. When the number of network device parameters exceeds the switching threshold, it triggers corresponding actions, such as automatically applying for a dynamic IP pool address to put the device offline. The load balancing control unit also refers to this switching threshold and its own restrictions on network bandwidth and the number of concurrent virtual sniffing devices to collaboratively determine whether the device status needs to be adjusted.
[0095] The load balancing control unit dynamically adjusts the detection frequency based on traffic peaks, which also affects the frequency with which the state switching module obtains and analyzes network device traffic information. When traffic peaks occur, a higher detection frequency allows the state switching module to capture changes in network status more promptly, allowing it to make decisions more quickly. For example, during traffic peaks, it may be easier to trigger a device to go offline to ensure stable network operation. During traffic troughs, appropriately reducing the detection frequency can reduce system resource consumption.
[0096] Specifically, the service information is obtained by parsing the device port ID and neighbor IP through the LLDP protocol, the topology information is obtained by parsing the device port ID and neighbor IP through the LLDP protocol, the routing information is obtained by learning the subnet division and hop count through the OSPF / RIP protocol, and the active scanning and passive detection data are integrated to generate a dynamic network topology including devices, services, and subnets. At the same time, the required IP address pool is analyzed to obtain a backup IP address pool to avoid the risk of address exhaustion. The upper limit of the backup IP address pool is 75% of the dynamic IP pool address. At the same time, it is detected whether the physical device uses a virtual IP. When it is detected that the physical device uses a virtual IP When the virtual IP is offline, it will analyze the IP that conflicts with the virtual IP and take the conflicting IP offline. At the same time, the offline IP will be returned to the dynamic IP address pool and marked as waiting for reallocation. When no physical device is detected using the virtual IP, it will continue to run. When the physical device is offline, the offline conflict processing unit will start a 10-minute delay detection. After confirming that the IP is not occupied, it will analyze the virtual sniffing IP, re-enable it, update the address pool status, and dynamically adjust the detection frequency and concurrent number of the virtual sniffing device according to the real-time network traffic, set the bandwidth usage threshold, and avoid network performance degradation due to overload of the sniffing task.
[0097] Working principle:
[0098] First, information of different mirror warehouses is collected to obtain the target warehouse. The operating parameters of different mirror warehouses in virtual sniffing devices are collected to obtain warehouse cases. The warehouse area size characteristics, sniffing time, data collection frequency and the interval distance of different virtual sniffing devices of the warehouse cases are extracted to obtain case characteristics. At the same time, the characteristics of the warehouse area size characteristics, sniffing time, data collection frequency and the interval distance of different virtual sniffing devices in the target warehouse are extracted to obtain retrieval characteristics. The retrieval feature values and case feature values in the retrieval features and case features are analyzed, and the parameter matching degree between the target warehouse and different warehouse cases is calculated based on the retrieval feature values and case feature values. The matching degrees are sorted in descending order to obtain a matching table, which is then displayed. The operating system, adaptive configuration algorithm, protocol parsing module and initialization script of the virtual sniffing device are packaged into a standardized container image, and then the image is uploaded to a unified managed image warehouse, supporting version control and multi-environment compatibility verification. The target device or node is selected through the management unit to trigger the automatic deployment instruction. The platform pulls the image from the image warehouse and distributes it to the target device to complete the automated installation and environment adaptation. When the device is started for the first time, the initialization script is automatically loaded, the network interface is identified and the basic configuration information is attempted to be obtained. The network status of the device is collected in real time, the offline status and online status of the device are obtained, and different operating parameters are made to run according to the different status of the device. When in the online state, the device actively requests network configuration through the DHCP protocol After successfully obtaining the configuration, the DNS, DHCP service address and key network parameters are recorded. If the DHCP service is unavailable or the configuration fails, the device automatically switches to the link-local address to complete the network card initialization. In the soft online state, it relies on the subsequent detection module to gradually complete the network information, providing a basis for the transition to the hard online state. Through the ARP protocol broadcast detection request, a preliminary IP-MAC address mapping table is established, the device online status table is updated regularly, active devices and offline devices are marked, network traffic is monitored, and SSDP, mDNS, LLDP and other protocol data packets are parsed in real time. Key parameters such as service location, device port information, subnet routing rules, etc. are extracted and added to the network topology map. The device port ID and neighbor information are parsed through the LLDP protocol. It obtains service information from the IP address, parses the device port ID and neighbor IP address through the LLDP protocol to obtain topology information, and obtains routing information by learning subnet division and hop count through the OSPF / RIP protocol. It integrates active scanning and passive detection data to generate a dynamic network topology including devices, services, and subnets. At the same time, it analyzes the required IP address pool and obtains a spare IP address pool to avoid the risk of address exhaustion. The upper limit of the spare IP address pool is 75% of the dynamic IP pool address. Addresses are allocated in batches from the available IP address pool according to the preset ratio for the online virtual sniffing device. After each batch is deployed, the network load is monitored in real time and the subsequent allocation strategy is dynamically adjusted. At the same time, it detects whether the physical device uses the virtual IP. When it is detected that the physical device uses the virtual IP,It will analyze the IPs that conflict with the virtual IPs and take them offline. At the same time, it will return the offline IPs to the dynamic IP address pool and mark them for reallocation. When no physical device is detected using the virtual IP, it will continue to run. When the physical device is offline, the offline conflict processing unit will start a 10-minute delay detection. After confirming that the IP is not occupied, it will analyze the virtual sniffing IP and re-enable it. In the soft online state, it completes parameter learning by continuously detecting network information. When sufficient configuration information is obtained, it automatically applies for a dynamic IP address, switches to the hard online state, and starts the sniffing task. It dynamically adjusts the detection frequency and concurrency of the virtual sniffing device according to real-time network traffic, sets a bandwidth usage threshold, and avoids network performance degradation due to sniffing task overload. At this point, the entire workflow ends.
[0099] Although the present invention is disclosed above with reference to preferred embodiments, this is not intended to limit the present invention. Any person skilled in the art may make possible changes and modifications without departing from the spirit and scope of the present invention. Therefore, any modifications, equivalent variations, and modifications made to the above embodiments in accordance with the technical essence of the present invention without departing from the content of the technical solution of the present invention shall fall within the scope of protection defined by the claims of the present invention.
Claims
1. An adaptive virtual sniffing system based on an image repository, characterized in that: The adaptive virtual sniffing system includes: The information collection module collects information from different image repositories, obtains the target repository, collects the operating parameters of different image repositories on the virtual sniffing device, and obtains warehouse cases; The framework deployment module packages the operating parameters, adaptive configuration algorithm, and multi-protocol parsing unit of the virtual sniffing device into a standardized container image, stores it in a unified image repository, establishes a management unit for the image repository, and uses the management unit to batch deploy devices. After the user selects the target device, the management unit automatically pulls the corresponding standardized container image and then installs the standardized container image to the corresponding device. At the same time, the image replication has a built-in initialization script to automatically adapt to different network environments. The adaptive initialization module collects the network status of the device in real time, obtains the offline and online status of the device, and runs different operating parameters according to the different status of the device; The detection module establishes a detection unit, which includes active detection and passive detection. Active detection uses the ARP protocol to scan network devices, obtain the basic IP-MAC mapping table, and send probe messages in real time to update the device online status. Passive detection parses SSDP, mDNS, LLDP, and OSPF protocol data to extract service information, topology information, and routing information to obtain network device information. Deploy modules in batches to obtain a dynamic IP address pool. During each deployment, allocate 25% of the dynamic IP address pool for virtual sniffing devices to go online. At the same time, reserve 25% of the dynamic IP address pool to handle sudden physical device access. The state switching module detects the traffic information of network devices in real time, obtains the number of network device parameters, and establishes a switching threshold. When the number of network device parameters exceeds the switching threshold, it automatically applies for a dynamic IP pool address and puts the device into an offline state.
2. The adaptive virtual sniffing system based on the image repository according to claim 1, characterized in that: After obtaining the warehouse case in the information collection module, the warehouse area size characteristics, sniffing time, data collection frequency and the interval distance of different virtual sniffing devices of the warehouse case are extracted to obtain the case characteristics. At the same time, the characteristics of the warehouse area size characteristics, sniffing time, data collection frequency and the interval distance of different virtual sniffing devices in the target warehouse are extracted to obtain the retrieval characteristics.
3. The adaptive virtual sniffing system based on the image repository according to claim 2, characterized in that: After the retrieval features and case features in the information collection module are obtained, the retrieval feature values and case feature values in the retrieval features and case features are analyzed, and the parameter matching degree between the target warehouse and different warehouse cases is calculated based on the retrieval feature values and case feature values. Let the retrieval feature value be J T , let the case characteristic value be A T , let the number of retrieval feature values and case feature values be K, let the parameter matching degree between the target warehouse and different warehouse cases be M P , calculate the parameter matching degree between the target warehouse and different warehouse cases, and sort them in descending order. The specific formula is as follows: Obtain a matching table and then display the matching table.
4. The adaptive virtual sniffing system based on the image repository according to claim 1, characterized in that: When different devices in the adaptive initialization module operate with different operating parameters, the operating mode is set for the offline state and the online state of the device; When the device is online, it will first obtain the dynamic IP pool address, subnet mask and gateway network configuration information through the DHCP protocol after startup, and then automatically identify and record the DNS, DHCP service address and key network parameters to obtain the operating parameters; When the device is offline, it obtains a link-local address and automatically switches to the link-local address. At the same time, it supplements network information through passive detection and gradually transitions to the online state.
5. The adaptive virtual sniffing system based on the image repository according to claim 1, characterized in that: The service information in the detection module is obtained by obtaining the service location and server description through the SSDP protocol; Topology information is obtained by parsing the device port ID and neighbor IP address through the LLDP protocol; Routing information is obtained by learning subnet division and hop count through OSPF and RIP protocols.
6. The adaptive virtual sniffing system based on the image repository according to claim 5, characterized in that: After obtaining the service information, topology information and routing information in the detection module, the active detection data and passive detection data are integrated to generate a dynamic network topology map. At the same time, the required IP address pool is analyzed to obtain a backup IP address pool to avoid the risk of address exhaustion. The upper limit of the backup IP address pool is 75% of the dynamic IP pool address.
7. The adaptive virtual sniffing system based on the image repository according to claim 1, characterized in that: When the batch deployment module is deployed, an online conflict processing unit and an offline conflict processing unit are established, wherein the online conflict processing unit monitors ARP requests in real time and detects whether the physical device uses the virtual IP. When it is detected that the physical device uses the virtual IP, the IP that conflicts with the virtual IP is analyzed, and the conflicting IP is taken offline. At the same time, the offline IP is returned to the dynamic IP address pool and marked as to be reallocated. When the physical device is not detected to use the virtual IP, it will continue to run. When the physical device is offline, the offline conflict processing unit starts the delay detection mechanism. When it is detected that the same IP is only in one location, it is determined that the IP is not occupied. At this time, the virtual sniffing IP is analyzed, and it is reactivated to update the address pool status.
8. The adaptive virtual sniffing system based on the image repository according to claim 1, characterized in that: The state switching module also includes a load balancing control unit, which uses the load balancing control unit to limit the number of concurrent virtual sniffing devices to no more than 30% of the network bandwidth, and dynamically adjusts the detection frequency according to the traffic peak.
9. The deployment method of the adaptive virtual sniffing system based on the image repository according to any one of claims 1 to 8 is characterized in that: The deployment method includes the following steps: S100: After the user selects the target device, the management unit automatically pulls the corresponding standardized container image; S200: Install the standardized container image to the corresponding device, and copy the built-in initialization script to automatically adapt to different network environments. S300 allocates 25% of the address pool from the dynamic IP address pool for the virtual sniffing device to go online, and reserves 25% of the address pool from the dynamic IP address pool to cope with sudden access of physical devices.
Citation Information
Cited By
GBase 8a database IP address switching method and device
CN121396943A