Mirror image traffic processing method, medium, computer equipment and program product
Through the interconnection of the shunt switch with traffic acquisition equipment and analysis equipment, the problem of incomplete image traffic on the cloud platform is solved, complete traffic analysis and refined filtering are realized, and the reliability and accuracy of traffic analysis are improved.
Patent Information
- Application Number
- CN202410200332.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-02-22
- Publication Date
- 2025-08-22
AI Technical Summary
The existing technology cannot obtain the complete mirror traffic of the cloud platform, resulting in the traffic analysis equipment being unable to conduct comprehensive analysis and the inability to achieve refined filtering of traffic and homologous homosink analysis.
Through the interconnection of the out-of-cloud traffic acquisition equipment, in-cloud traffic acquisition equipment and traffic analysis equipment, the connection path between each traffic acquisition equipment and the traffic analysis equipment is opened, and the in-cloud mirror traffic is collected and sent to the traffic analysis equipment, and the traffic shaping and filtering are performed through the gateway equipment.
It realizes a more complete traffic analysis of the cloud platform, improves the reliability and accuracy of traffic analysis, and realizes refined filtering and homologous homosensory analysis based on user needs.
Smart Images

Figure CN120528844A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of cloud computing technology, and in particular to a method, medium, computer device, and program product for processing mirrored traffic. Background Art
[0002] A cloud platform provides various computing services over the internet, allowing users to access computing resources, storage space, and application services on demand. Traffic analysis is required for purposes such as optimizing traffic performance, security monitoring, and resource optimization. Related technologies use traffic filters or splitters to mirror cloud platform traffic and send the resulting mirrored traffic to traffic analysis devices for analysis. However, neither traffic filters nor splitters can capture the entire mirrored traffic of the cloud platform, making it impossible for traffic analysis devices to perform traffic analysis based on the complete cloud platform traffic. Summary of the Invention
[0003] In a first aspect, an embodiment of the present disclosure provides a method for processing mirrored traffic, which is applied to a diversion switch, wherein the diversion switch is communicatively connected to a first traffic collection device, a second traffic collection device, a third traffic collection device and a traffic analysis device, wherein the first traffic collection device is used to collect first off-cloud mirrored traffic corresponding to traffic between a cloud platform and the Internet, the second traffic collection device is used to collect second off-cloud mirrored traffic corresponding to traffic between the cloud platform and a tenant's computer room, the third traffic collection device is used to collect intra-cloud mirrored traffic corresponding to traffic between devices within the cloud platform, and the traffic analysis device is used to perform traffic analysis on the cloud platform based on the first off-cloud mirrored traffic, the second off-cloud mirrored traffic and the intra-cloud mirrored traffic; the method includes: receiving the first off-cloud mirrored traffic sent by the first traffic collection device, the second off-cloud mirrored traffic sent by the second traffic collection device and the intra-cloud mirrored traffic sent by the third traffic collection device; and sending the first off-cloud mirrored traffic, the second off-cloud mirrored traffic and the intra-cloud mirrored traffic to the traffic analysis device for traffic analysis.
[0004] In a second aspect, an embodiment of the present disclosure provides a system for processing mirrored traffic, the system comprising: an off-cloud traffic collection device, for collecting off-cloud mirrored traffic corresponding to traffic between a cloud platform and off-cloud devices; an on-cloud traffic collection device, for collecting on-cloud mirrored traffic corresponding to traffic between devices within the cloud platform; a traffic analysis device, for performing traffic analysis on the cloud platform based on the off-cloud mirrored traffic and the on-cloud mirrored traffic; and a diversion switch, connected to the off-cloud traffic collection device, the on-cloud traffic collection device and the traffic analysis device, for executing the method described in any embodiment of the present disclosure.
[0005] In a third aspect, an embodiment of the present disclosure provides a computer-readable storage medium having computer instructions stored thereon, which, when executed by a processor, implements the method described in any embodiment of the present disclosure.
[0006] In a fourth aspect, an embodiment of the present disclosure provides a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in any embodiment of the present disclosure when executing the program.
[0007] In a fifth aspect, an embodiment of the present disclosure provides a computer program product, including a computer program, which implements the method described in any embodiment of the present disclosure when executed by a processor.
[0008] The disclosed embodiments interconnect off-cloud traffic collection devices, on-cloud traffic collection devices, and traffic analysis devices through a traffic diversion switch, thereby establishing a connection path between each of the traffic collection devices and the traffic analysis device. This allows the mirrored traffic within the cloud collected by each traffic collection device to be transmitted to the traffic analysis device through this connection path. Because the traffic analysis device can obtain a more complete mirrored traffic on the cloud platform, it can perform a more complete traffic analysis of the cloud platform, improving the reliability and accuracy of the traffic analysis. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] Figure 1A and Figure 1B It is a schematic diagram of an application scenario of an embodiment of the present disclosure.
[0010] Figure 2 It is a schematic diagram of the system architecture of an embodiment of the present disclosure.
[0011] Figure 3 is a schematic diagram of a system architecture of another embodiment of the present disclosure.
[0012] Figure 4 Schematic diagram of mirrored traffic and its header information according to an embodiment of the present disclosure.
[0013] Figure 5 Schematic diagram of the filtering process of mirrored traffic according to an embodiment of the present disclosure.
[0014] Figure 6 Schematic diagram of the relationship between tenant ID, network ID and ENI ID in the embodiment of the present disclosure.
[0015] Figure 7 It is a schematic diagram of the transmission process of mirrored traffic on a diversion switch according to an embodiment of the present disclosure.
[0016] Figure 8 The figure is a flowchart of a method for processing mirrored traffic according to an embodiment of the present disclosure.
[0017] Figure 9 The figure is a flowchart of a method for processing mirrored traffic according to another embodiment of the present disclosure.
[0018] Figure 10 The figure is a flowchart of a method for processing mirrored traffic according to another embodiment of the present disclosure.
[0019] Figure 11 is a schematic diagram of a computer device according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0020] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. When the following description refers to the drawings, identical numerals in different figures represent identical or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all possible implementations consistent with one or more embodiments of the present disclosure. Rather, they are merely examples of apparatuses and methods consistent with certain aspects of one or more embodiments of the present disclosure, as detailed in the appended claims.
[0021] It should be noted that, in other embodiments, the steps of the corresponding method are not necessarily performed in the order shown and described in this disclosure. In some other embodiments, the method may include more or fewer steps than those described in this disclosure. In addition, a single step described in this disclosure may be broken down into multiple steps for description in other embodiments; and multiple steps described in this disclosure may be combined into a single step for description in other embodiments.
[0022] During the operation of services on the cloud platform, traffic will be generated. Figure 1A and Figure 1B As shown, the above traffic includes the traffic generated by the mutual access between the cloud platform and devices outside the cloud (hereinafter referred to as off-cloud traffic), and the traffic generated by the mutual access between devices on the cloud platform (hereinafter referred to as on-cloud devices) (hereinafter referred to as intra-cloud traffic). Furthermore, the off-cloud traffic includes the traffic generated by the mutual access between the cloud platform and the Internet (hereinafter referred to as the first off-cloud traffic), and the traffic generated by the mutual access between the cloud platform and the user's computer room (hereinafter referred to as the second off-cloud traffic). In order to optimize the traffic performance, security monitoring, resource optimization, etc. of the cloud platform, it is necessary to perform traffic analysis on the cloud platform. When performing traffic analysis, the traffic generated on the cloud platform is usually mirrored to obtain mirrored traffic, and then the mirrored traffic is sent to the traffic analysis device for traffic analysis. Among them, the mirrored traffic corresponding to the first off-cloud traffic is called the first off-cloud mirrored traffic, the mirrored traffic corresponding to the second off-cloud traffic is called the second off-cloud mirrored traffic, and the mirrored traffic corresponding to the intra-cloud traffic is called the intra-cloud mirrored traffic.
[0023] Traffic mirroring solutions in related technologies often have the following problems:
[0024] (1) The complete traffic of the cloud platform cannot be obtained. Generally, the first cloud-outside traffic and the second cloud-outside traffic are mirrored by an optical splitter to obtain the first cloud-outside mirrored traffic and the second cloud-outside mirrored traffic, and the first cloud-outside mirrored traffic and the second cloud-outside mirrored traffic are sent to the traffic analysis device outside the cloud for traffic analysis, such as Figure 1A As shown in the figure, for intra-cloud traffic, a mirror filter replicates the intra-cloud traffic to generate intra-cloud mirrored traffic. This mirrored traffic is then sent to traffic analysis software installed on a virtual machine on the cloud platform for analysis. However, an optical splitter cannot capture intra-cloud traffic, and a mirror filter cannot capture traffic outside the cloud. Therefore, neither an optical splitter nor a mirror filter can capture the complete cloud platform traffic. Furthermore, intra-cloud mirrored traffic captured by a mirror filter can only be sent to the traffic analysis software within the cloud platform and cannot be exported outside the cloud platform.
[0025] (2) The mirrored traffic collected by the traffic collection device will all be sent to the traffic analysis device, making it impossible to achieve fine-grained filtering of the traffic.
[0026] (3) The traffic sent by a device (assuming it is called the first device) to another device (assuming it is called the second device) and the traffic returned by the second device to the first device may be sent to different traffic analysis devices for traffic analysis, and it is impossible to achieve the same source and destination of the traffic (that is, the traffic sent by the first device to the second device and the traffic sent by the second device to the first device are sent to the same traffic analysis device for traffic analysis).
[0027] To solve at least one of the above problems, the present disclosure proposes a mirror traffic processing system, see Figure 2 and Figure 3 , the processing system includes a traffic collection device 10, a shunt switch 12 and a traffic analysis device 14. Among them, the traffic collection device 10 is used to collect the mirror traffic corresponding to the traffic generated on the cloud platform, and send the collected mirror traffic to the shunt switch 12. The shunt switch 12 can forward the received mirror traffic to at least one traffic analysis device 14 for traffic analysis. When the number of traffic analysis devices 14 is greater than 1, the specific traffic analysis device 14 to which the traffic is sent can be determined according to actual needs. Further, the above-mentioned processing system can also include a gateway device 16 (such as Figure 3 As shown. The shunt switch 12 can forward the mirrored traffic sent by the traffic collection device 10 to the gateway device 16 for processing. The gateway device 16 can forward the processed mirrored traffic to the traffic analysis device 14 through the shunt switch 12 for traffic analysis. The functions of each component in the above processing system are described below with examples.
[0028] In some embodiments, the traffic collection device 10 includes an off-cloud traffic collection device and an on-cloud traffic collection device, wherein the off-cloud traffic collection device is used to collect off-cloud mirror traffic corresponding to traffic between the cloud platform and off-cloud devices, and the on-cloud traffic collection device is used to collect on-cloud mirror traffic corresponding to traffic between devices within the cloud platform. Figure 3 , the off-cloud traffic collection device includes a first traffic collection device 120 and a second traffic collection device 140. Correspondingly, the off-cloud mirror traffic includes the first off-cloud mirror traffic collected by the first traffic collection device 120 and the second off-cloud mirror traffic collected by the second traffic collection device 140. The first off-cloud mirror traffic is the mirror traffic corresponding to the traffic between the cloud platform and the Internet, and the second off-cloud mirror traffic is the mirror traffic corresponding to the traffic between the cloud platform and the user's computer room. The on-cloud traffic collection device can be Figure 3 The third traffic collection device 160 in the flow collection device 10 is described below by taking the example that the traffic collection device 10 includes the first traffic collection device 120, the second traffic collection device 140, and the third traffic collection device 160, and the mirrored traffic includes the first off-cloud mirrored traffic, the second off-cloud mirrored traffic, and the on-cloud mirrored traffic. It can be understood that the traffic collection device 10 can also include only one or two of the above three devices, and accordingly, the mirrored traffic can only include one or two of the above three mirrored traffic. The diversion switch 12 can forward both the off-cloud mirrored traffic and the on-cloud mirrored traffic to the traffic analysis device 14, so that the traffic analysis device 14 performs traffic analysis on the cloud platform based on the off-cloud mirrored traffic and the on-cloud mirrored traffic.
[0029] The above embodiment adds a traffic diversion switch 12 to the original traffic processing architecture. The diversion switch 12 interconnects with the third traffic collection device 160 and the traffic analysis device 14, thereby establishing a connection path between the third traffic collection device 160 and the traffic analysis device 14. This allows the cloud-based mirrored traffic collected by the third traffic collection device 160 to be transmitted to the traffic analysis device 14 via this connection path. Furthermore, the diversion switch 12 can also connect to the first and second traffic collection devices 120, 140, thereby establishing a connection path between the first and second traffic collection devices 120, 140, and the traffic analysis device 14. This allows the first and second off-cloud mirrored traffic collected by the first and second traffic collection devices 120, 140 to be transmitted to the traffic analysis device 14 via the corresponding connections. In this way, the traffic analysis device 14 can obtain both on-cloud and off-cloud mirrored traffic. Because the traffic analysis device 14 can obtain a more complete view of the mirrored traffic on the cloud platform, it can perform a more comprehensive traffic analysis of the cloud platform, improving the reliability and accuracy of the traffic analysis.
[0030] The first traffic collection device 120 and the second traffic collection device 140 can be optical splitters or flow dividers, and the third traffic collection device 160 can be a mirror filter. Traffic between the cloud platform and the internet, referred to as the first off-cloud traffic in the aforementioned embodiment, includes traffic from the cloud platform to the internet and traffic from the internet to the cloud platform. The first traffic collection device 120 can replicate the traffic between the cloud platform and the internet to obtain the first off-cloud mirror traffic. Traffic between the cloud platform and the user's computer room, referred to as the second off-cloud traffic in the aforementioned embodiment, includes traffic from the cloud platform to the user's computer room and traffic from the user's computer room to the cloud platform. The second traffic collection device 140 can replicate the traffic between the cloud platform and the user's computer room to obtain the second off-cloud mirror traffic. Within the cloud platform, different devices may need to communicate and interact. In this case, traffic between devices within the cloud platform is generated, referred to as the intra-cloud traffic in the aforementioned embodiment. The third traffic collection device 160 can replicate the traffic between cloud devices to obtain the intra-cloud mirror traffic.
[0031] In some embodiments, one or more virtual private cloud (VPC) networks can be created on the cloud platform. VPC is a service for creating private networks on the cloud platform. It provides a logically isolated network environment, allowing tenants to create and manage their own virtual networks within the cloud platform. Each tenant can create one or more VPC networks. Furthermore, tenants can create one or more Elastic Compute Service (ECS) instances in each VPC network. Various services can run on ECS instances, such as database services, HTTP services, file storage and sharing services, etc. The third traffic collection device 160 can be a software program running on the ECS instance, such as the mirror filter in the aforementioned embodiment. On this basis, the intra-cloud traffic can be the traffic between different ECS instances on the same VPC network, or the traffic between different ECS instances on different VPC networks. When the intra-cloud traffic is the traffic between ECS instances on the VPC network, the intra-cloud traffic can also be referred to as VPC traffic, and accordingly, the intra-cloud mirror traffic can be referred to as VPC mirror traffic. Each ECS instance can correspond to an Elastic Network Interface (ENI) instance. ECS instances are interconnected through ENI instances, thereby enabling mutual access between ECS instances.
[0032] In some embodiments, the first traffic collection device 120, the second traffic collection device 140, and the third traffic collection device 160 may be connected to the core switch (DSW) of the cloud platform. Figure 3As shown, the first traffic collection device 120 can be connected to the core switch via an external network access switch (ISW), the second traffic collection device 140 can be connected to the core switch via an internal network access switch (CSW), and the third traffic collection device 160 can be connected to the core switch via a server access switch (ASW). The diversion switch 12 can be connected to the core switch. By connecting a separate diversion switch 12, the pressure on the core switch of the cloud platform can be reduced, thereby reducing the impact on the backbone network of the cloud platform, and achieving the minimum impact of the traffic mirroring function on the business.
[0033] When the cloud platform accesses the Internet, the ECS instance running on the cloud device can send traffic to the server access switch, which forwards the traffic to the core switch, which forwards the traffic to the external network access switch, and forwards the traffic to the Internet side through the external network access switch. Furthermore, the Internet side may include multiple servers, so the load balancing device 18 can be used to load balance multiple servers. In an embodiment of load balancing, the load balancing device 18 can be connected to the core switch through an integrated access switch (LSW). The ECS instance can send traffic to the server access switch, which forwards the traffic to the core switch, which forwards the traffic to the integrated access switch, and then the integrated access switch forwards the traffic to the load balancing device 18 for load balancing processing. The load balancing device 18 can determine the target server on the Internet side based on the load conditions of each server on the Internet side, and forward the traffic carrying the identification information of the target server on the Internet side to the core switch through the integrated access switch, which is forwarded by the core switch to the external network access switch, and then the external network access switch forwards the traffic to the target server. For example, the target server can be obtained by polling various servers on the Internet side, or by selecting from various servers on the Internet side using other load balancing algorithms.
[0034] Similarly, when the Internet accesses the cloud platform, the Internet can forward traffic to the ECS instance through the ISW, DSW, LSW, load balancing device 18, LSW, DSW, and ASW in sequence. The functions of each switch and load balancing device 18 can be found in the aforementioned embodiment and will not be repeated here. The first traffic collection device 120 can copy the traffic obtained from the external network access switch to obtain the first off-cloud mirror traffic, which can also be called the I-side split traffic. The first traffic collection device 120 can be connected to the shunt switch 12 via an optical fiber and send the first off-cloud mirror traffic to the shunt switch 12 via the optical fiber connection. The transmission path of the first off-cloud mirror traffic is shown as a solid line in the figure.
[0035] When the cloud platform accesses the user's computer room, the ECS instance can send traffic to the server access switch, which forwards the traffic to the core switch, which forwards the traffic to the intranet access switch, and forwards the traffic to the user's computer room through the intranet access switch. Furthermore, the user's computer room may include multiple servers, so the load balancing device 18 can be used to load balance multiple servers. In an embodiment of load balancing, the load balancing device 18 can be connected to the core switch through an integrated access switch (LSW). The ECS instance can send traffic to the server access switch, which forwards the traffic to the core switch, which forwards the traffic to the integrated access switch, and then the integrated access switch forwards the traffic to the load balancing device 18 for load balancing processing. The load balancing device 18 can determine the target server in the user's computer room based on the load conditions of each server in the user's computer room, and forward the traffic carrying the target server in the user's computer room to the intranet access switch through the integrated access switch, and then the intranet access switch forwards the traffic to the target server.
[0036] Similarly, when a user's computer room accesses the cloud platform, the user's computer room can forward traffic to the ECS instance through the CSW, LSW, load balancing device 18, LSW, DSW, and ASW in sequence. The second traffic collection device 140 can replicate the traffic obtained from the intranet access switch to obtain a second off-cloud mirrored traffic, which can also be referred to as C-side split traffic. The second traffic collection device 140 can be connected to the split switch 12 via an optical fiber and send the second off-cloud mirrored traffic to the split switch 12 via the optical fiber. The transmission path of the second off-cloud mirrored traffic is shown as the long dashed line in the figure.
[0037] When devices on the cloud access each other, assuming that two ECS instances running on the cloud devices (for ease of distinction, the two ECS instances will be referred to as the first ECS instance and the second ECS instance below) access each other, the first ECS instance can forward the traffic to the core switch through the server access switch connected to the ECS instance, and then forward the traffic to the server access switch connected to the second ECS instance through the core switch, and then the server access switch connected to the second ECS instance forwards the traffic to the second ECS instance. A mirror filter can be deployed on each ECS instance. The mirror filter can copy the traffic of the ECS instance to obtain the mirror traffic in the cloud, and forward the mirror traffic in the cloud to the core switch through the server access switch connected to the ECS instance where it is located, and then forward the mirror traffic in the cloud to the diversion switch 12 through the core switch.
[0038] The offload switch 12 can obtain the first off-cloud mirrored traffic, the second off-cloud mirrored traffic, and the on-cloud mirrored traffic sent by the core switch, and forward these mirrored traffic to the traffic analysis device 14. The traffic analysis device 14 can perform traffic analysis on the cloud platform based on the first off-cloud mirrored traffic, the second off-cloud mirrored traffic, and the on-cloud mirrored traffic sent by the offload switch 12, including but not limited to monitoring information such as the quantity, rate, source, and destination of traffic on the cloud platform, analyzing the usage, performance bottlenecks, and anomalies of applications running on the cloud platform, and detecting and identifying malicious behavior in traffic on the cloud platform.
[0039] See also Figure 2 and Figure 3 The shunt switch 12 includes multiple ports, and the traffic collection device 10 for collecting different types of mirrored traffic is connected to different ports of the shunt switch 12. The traffic collection device 10 for collecting different types of mirrored traffic may include an off-cloud traffic collection device and / or an on-cloud traffic collection device, etc. The off-cloud traffic collection device may be used to collect the mirrored traffic corresponding to the traffic between the cloud platform and off-cloud devices (referred to as off-cloud mirrored traffic), and the on-cloud traffic collection device may be used to collect the mirrored traffic corresponding to the traffic between devices within the cloud platform (referred to as on-cloud mirrored traffic). Further, as Figure 3 As shown, the cloud traffic collection device includes a first cloud traffic collection device 120 and a second cloud traffic collection device 140. The first cloud traffic collection device 120 is used to collect the first cloud mirror traffic corresponding to the traffic between the cloud platform and the Internet, and the second cloud traffic collection device 140 is used to collect the second cloud mirror traffic corresponding to the traffic between the cloud platform and the user's computer room. Figure 3 The point traffic collection device 160 in the cloud. The type of the mirrored traffic is used to indicate whether the mirrored traffic is the off-cloud mirrored traffic or the on-cloud mirrored traffic.
[0040] The diversion switch 12 can pre-store the correspondence between each port and the type of mirrored traffic. Continuing with the previous embodiment, port BAGG1 of the diversion switch 12 is connected to the first traffic collection device 120. Therefore, port BAGG1 can obtain the first off-cloud mirrored traffic collected by the first traffic collection device 120. Therefore, the correspondence between port BAGG1 and the first off-cloud mirrored traffic can be stored. Similarly, the correspondence between port BAGG2 and the second off-cloud mirrored traffic, as well as the correspondence between the three-layer VLAN virtual interface and the cloud mirrored traffic, can also be stored. When any port of the diversion switch 12 has mirrored traffic input, the diversion switch 12 can determine the type of mirrored traffic input by the port based on the above correspondence. In some embodiments, the traffic collection device 10 for collecting different types of mirrored traffic is connected to ports of different VLAN domains of the diversion switch 12.
[0041] Continue to see Figure 3 The tributary switch 12 is also connected to the gateway device 16. The tributary switch 12 can send the first off-cloud mirrored traffic, the second off-cloud mirrored traffic, and the intra-cloud mirrored traffic received from the core switch to the gateway device 16 for pre-processing, and obtain the first off-cloud mirrored traffic, the second off-cloud mirrored traffic, and the intra-cloud mirrored traffic processed by the gateway device 16, and send these processed mirrored traffic to the traffic analysis device 14 for traffic analysis.
[0042] The pre-processing of various types of mirrored traffic by the gateway device 16 includes, but is not limited to, traffic shaping processing and traffic filtering processing. Among them, traffic shaping processing refers to adjusting the mirrored traffic to a specified structure. In some embodiments, different types of mirrored traffic have different structures. In order to facilitate the processing of mirrored traffic, various types of mirrored traffic can be unified into the same structure through traffic shaping processing. The above structure can, for example, refer to whether the mirrored traffic includes a Virtual Extensible LAN (VXLAN) header, or the number of layers of header information of the mirrored traffic. For example, the mirrored traffic that does not include a VXLAN header and the mirrored traffic that includes a VXLAN header are unified as including a VXLAN header, or the mirrored traffic that includes only one layer of header information and the mirrored traffic that includes two layers of header information are unified as including two layers of header information.
[0043] Because different types of mirrored traffic have different structures, to unify the various types of mirrored traffic into the same structure, gateway device 16 can obtain the type of mirrored traffic sent by the diversion switch 12 and perform traffic shaping on the mirrored traffic based on the type of the mirrored traffic. In some embodiments, the type of the mirrored traffic can be obtained by the diversion switch 12 and sent to the gateway device 16. After obtaining the mirrored traffic, the diversion switch 12 can add tag information indicating the traffic type to the mirrored traffic and send the mirrored traffic carrying the tag information to the gateway device 16. Gateway device 16 can parse the tag information from the received mirrored traffic and perform traffic shaping on the received mirrored traffic based on the traffic type indicated by the parsed tag information.
[0044] Among them, the marking information can be the code corresponding to each type of mirrored traffic, or other information that can uniquely identify different types of mirrored traffic. Assume that the code corresponding to the first off-cloud mirrored traffic is CODE1, the code corresponding to the second off-cloud mirrored traffic is CODE2, and the code corresponding to the in-cloud mirrored traffic is CODE3. When the diversion switch 12 receives the first off-cloud mirrored traffic, the first off-cloud mirrored traffic carrying the code "CODE1" can be sent to the gateway device 16. After the gateway device 16 parses the code "CODE1" from the first off-cloud mirrored traffic, it can determine that the currently received mirrored traffic is the first off-cloud mirrored traffic, and use the traffic shaping method corresponding to the first off-cloud mirrored traffic to perform traffic shaping on the first off-cloud mirrored traffic. The processing method for other types of mirrored traffic is similar and will not be repeated here.
[0045] Virtualized environments deployed within the cloud typically include network devices or functions that support VXLAN. Public cloud service providers' virtual network solutions typically support VXLAN technology. VXLAN is a technology that extends Ethernet within virtualized environments. It is primarily used to transmit data packets within virtual networks within the cloud. When data packets flow within a virtual network within the cloud, a VXLAN header is added to identify the isolation and extension of the virtual network. Therefore, mirrored traffic within the cloud typically includes a VXLAN header.
[0046] However, cloud platforms typically decapsulate VXLAN headers on their edge devices, converting traffic back into regular Ethernet packets before routing them to the appropriate virtual machines or services. Therefore, when traffic reaches the cloud platform from devices outside the cloud (such as on-premises networks or enterprise data centers), it typically does not carry a VXLAN header. In other words, the first and second off-cloud mirrored traffic typically do not include a VXLAN header.
[0047] When performing traffic shaping, gateway device 16 can add a VXLAN header to the first off-cloud mirrored traffic and the second off-cloud mirrored traffic, thereby unifying the first off-cloud mirrored traffic, the second off-cloud mirrored traffic, and the on-cloud mirrored traffic into mirrored traffic including a VXLAN header. The VXLAN header may include, but is not limited to, the following information:
[0048] The VXLAN Network Identifier (VNI) is used to distinguish different VXLAN networks. Each VXLAN network has a unique VNI.
[0049] Header information used to indicate the encapsulation protocol, such as IP header information or UDP header information. VXLAN can use IP protocol or UDP protocol as the encapsulation protocol. Therefore, the VXLAN header can also contain IP header information or UDP header information, including source IP address, destination IP address, source port number, destination port number, protocol type, and other information.
[0050] like Figure 4 As shown, when adding a VXLAN header to the first and second off-cloud mirrored traffic, tag information indicating the traffic type can be added to the VXLAN header. The VNI and header information indicating the encapsulation protocol can also be added to the VXLAN header. Furthermore, the VXLAN headers added to the first and second off-cloud mirrored traffic can also include indication information indicating that the mirrored traffic is not on-cloud mirrored traffic. This information can be a special VNI, for example, a VNI of all zeros. By adding this indication information, off-cloud mirrored traffic can be distinguished from on-cloud mirrored traffic.
[0051] Because the intra-cloud mirrored traffic carries a VXLAN header, but the original VXLAN header carried by the intra-cloud mirrored traffic (including information such as the VNI and header information used to indicate the encapsulation protocol) does not include tag information indicating the traffic type, the tag information indicating the traffic type can be added to the VXLAN header of the intra-cloud mirrored traffic, thereby rewriting the original VXLAN header carried by the intra-cloud mirrored traffic.
[0052] Traffic filtering involves filtering out target mirrored traffic that meets specified conditions from mirrored traffic. Specified conditions include, but are not limited to, at least one of the following: the tenant to which the mirrored traffic belongs, the VPC network to which the mirrored traffic belongs, the ENI instance to which the mirrored traffic belongs, the source and destination addresses of the mirrored traffic, etc. In related art, all mirrored traffic collected by the traffic collection device 10 is forwarded to the traffic analysis device. This makes it difficult for the traffic analysis device to analyze specific traffic based on user needs. The disclosed embodiments implement traffic filtering on mirrored traffic, enabling refined filtering of mirrored traffic based on user needs, thereby achieving more refined traffic analysis. Furthermore, the processing power of the gateway device 16 is far greater than that of the backend traffic analysis device 14. Therefore, forwarding the originally collected, coarse-grained mirrored traffic to the gateway device 16 for traffic filtering fully utilizes the processing power of the gateway device 16 and reduces the impact on the original traffic analysis process of the traffic analysis device 14. Access control lists (ACLs) can be configured on the gateway device 16, and these ACLs can be processed using the DPDK (Data Plane Development Kit) framework. DPDK provides a dedicated library, libdpdk_acl, for implementing ACL functionality on DPDK. This library uses multi-core processing technology and efficient data structures to process large numbers of ACL rules in high-speed network environments, thereby improving ACL processing performance.
[0053] See also Figure 5 , a traffic filtering policy can be configured on the gateway device 16, and the traffic filtering policy is used to indicate the configuration information of the mirrored traffic to be sent to the traffic analysis device. The mirrored traffic collected by the traffic collection device 10 carries the network information of the mirrored traffic. After obtaining the mirrored traffic collected by the traffic collection device 10, the gateway device 16 can determine whether the network information carried in the mirrored traffic hits the configuration information included in the traffic filtering policy. The traffic filtering policy may include at least one piece of configuration information. If the network information carried in the mirrored traffic is consistent with any piece of configuration information included in the traffic filtering policy, it is determined that the network information carried in the mirrored traffic hits the configuration information included in the traffic filtering policy (referred to as hit), otherwise it is determined that the network information carried in the mirrored traffic does not hit the configuration information included in the traffic filtering policy (referred to as miss).
[0054] If it is a hit, the gateway device 16 can determine the mirrored traffic as the target mirrored traffic and send the target mirrored traffic to the traffic analysis device 14 for traffic analysis. If it is a miss, the gateway device 16 can discard the mirrored traffic and not forward it subsequently.
[0055] The network information carried in the mirrored traffic may include, but is not limited to, at least one of a network address (such as source IP address, destination IP address, source MAC address, destination MAC address), source port number, destination port number, VLAN ID, and VNI. The configuration information in the traffic filtering policy may include, but is not limited to, at least one of a tenant ID, a VPC network ID, an ENI ID of an ENI instance, a network address, and a port number. Different types of traffic filtering policies may contain different types of configuration information.
[0056] In some embodiments, the network information includes the network address of the mirrored traffic, and the configuration information includes at least one target network address. If the network address included in the network information is consistent with any target network address included in the configuration information, then it is determined that the network information hits the configuration information. For example, assuming that the network address carried in the mirrored traffic is IP1, and the target network address in the configuration information includes {IP1, IP2}, then the network address carried in the mirrored traffic is consistent with IP1 in the target network address. Therefore, the network information in the mirrored traffic hits the configuration information, and the mirrored traffic can be sent to the traffic analysis device 14. In this way, the mirrored traffic carrying the specified network address can be sent to the traffic analysis device 14 on the gateway device 16. On the one hand, the traffic analysis device 14 does not need to analyze all the mirrored traffic of the cloud platform, which reduces the amount of data processing during the traffic analysis process and improves the efficiency of the traffic analysis. On the other hand, the mirrored traffic of the specified network address can be analyzed according to user needs, which improves the targeted nature of the traffic analysis.
[0057] Furthermore, the configuration information may also include a target tenant identifier. A tenant asset table may be obtained, and further, based on the tenant asset table, it may be determined whether the network information in the mirrored traffic matches the configuration information. The tenant asset table may be used to record various assets belonging to the tenant, where the assets include but are not limited to at least one of a network address, a VPC network, and an ENI instance. Assume that the cloud platform includes tenant 1 with tenant identifier U1 and tenant 2 with tenant identifier U2. The VPC networks subordinate to U1 include VPC network 1 with network identifier VPC_1 and VPC network 2 with network identifier VPC_2, and the VPC networks subordinate to U2 include VPC network 3 with network identifier VPC_3, VPC network 4 with network identifier VPC_4, and VPC network 5 with network identifier VPC_5. The ENI instances subordinate to VPC network 1 include ENI instance 1 with ENI identifier ENI_1 and ENI instance 2 with ENI identifier ENI_2. The network addresses (using IP addresses as an example) corresponding to ENI instance 1 include IP1 and IP2, and the network addresses corresponding to ENI instance 2 include IP3 and IP4. For the sake of brevity, the ENI identifiers subordinate to other network identifiers are not described again. Based on the above subordinate relationships, we can get the following: Figure 6 The tenant asset relationship shown in the figure includes the corresponding asset relationship table including the correspondence between the tenant ID, the network ID of the VPC network, the ENI ID of the ENI instance, and the network address.
[0058] The network address corresponding to the target tenant identifier can be determined based on the tenant asset table. If the network address included in the network information is consistent with any target network address included in the configuration information, and the network address included in the network information is the network address corresponding to the target tenant identifier, then it is determined that the network information hits the configuration information. Specifically, it can be first determined whether the target network address included in the configuration information includes the network address included in the network information. If so, then it can be determined based on the tenant asset table whether the tenant identifier corresponding to the network address included in the network information is the target tenant identifier. If so, then it is determined that the network information hits the configuration information. Alternatively, it can be first determined whether the network address corresponding to the target tenant identifier in the target network address, then it can be determined whether the network address included in the network information includes the network address corresponding to the target tenant identifier. If so, then it is determined that the network information hits the configuration information.
[0059] In this way, the mirrored traffic of the target network address of the target tenant can be filtered out. For example, when the mirrored traffic is the first off-cloud mirrored traffic corresponding to the traffic between the cloud platform and the Internet, the network address is the public network address of the tenant of the cloud platform. By configuring the target tenant identifier and the target network address in the configuration information, the mirrored traffic corresponding to the traffic between the cloud platform and the target network address of the tenant corresponding to the target tenant identifier (hereinafter referred to as the target tenant) can be filtered out. For another example, when the mirrored traffic is the second off-cloud mirrored traffic corresponding to the traffic between the cloud platform and the computer room of the user outside the cloud, the network address is the network address of the cloud platform. By configuring the target tenant identifier and the target network address in the configuration information, the mirrored traffic corresponding to the traffic between the target network address of the target tenant and the computer room of the user outside the cloud can be filtered out. For another example, when the mirrored traffic is the intra-cloud mirrored traffic corresponding to the traffic between the devices within the cloud platform, the network address is the network address of the cloud platform. By configuring the target tenant identifier and the target network address in the configuration information, the mirrored traffic corresponding to the traffic between the target network address of the target tenant and other addresses of the cloud platform can be filtered out.
[0060] Furthermore, the configuration information may also include a network identifier of the VPC network and / or an ENI identifier of the ENI instance. If the configuration information includes the network identifier of the VPC network, when determining whether the network information matches the configuration information, it may be further determined whether the network address included in the network information is the network address corresponding to the network identifier in the configuration information. If the configuration information includes the ENI identifier of the ENI instance, when determining whether the network information matches the configuration information, it may be further determined whether the network address included in the network information is the network address corresponding to the ENI identifier in the configuration information.
[0061] When the mirrored traffic includes the second off-cloud mirrored traffic corresponding to the traffic between the cloud platform and the user's computer room, the network information may also include the VLAN identifier of the VLAN domain to which the mirrored traffic belongs. On the intranet access switch, the VPC network can connect to the user's computer room through VLAN. Each VPC network can correspond to one or more VLAN domains and connect different computer rooms through different VLAN domains. Different VLAN domains are identified by different VLAN identifiers. The correspondence between the VLAN identifier and the network identifier of the VPC network can be established in advance. By carrying the VLAN identifier in the network information of the mirrored traffic, the target network identifier corresponding to the VLAN identifier included in the network information can be determined based on the correspondence between the VLAN identifier and the network identifier. If the target network identifier is consistent with any network identifier included in the configuration information, it is determined that the network information hits the configuration information.
[0062] Furthermore, the configuration information also includes a target tenant identifier. The correspondence between the tenant identifier and the network identifier in the tenant asset table can be obtained to determine the network identifier corresponding to the target tenant identifier. If the target network identifier is consistent with any network identifier included in the configuration information, and the target network identifier is the network identifier corresponding to the target tenant identifier, it is determined that the network information hits the configuration information. Specifically, it can be determined first whether the target network identifier exists in the network identifiers included in the configuration information. If so, it is determined whether the tenant identifier corresponding to the target network identifier is the target tenant identifier based on the tenant asset table. If so, it is determined that the network information hits the configuration information. Alternatively, it is also possible to first determine the network identifier corresponding to the target tenant identifier in the network identifiers included in the configuration information, and then determine whether the target network identifier exists in the network identifier corresponding to the target tenant identifier. If so, it is determined that the network information hits the configuration information.
[0063] When the mirrored traffic includes the mirrored traffic within the cloud corresponding to the traffic between devices within the cloud platform, the network information may include the VNI of the virtual network to which the mirrored traffic belongs. The ENI instance of the cloud platform and the VNI are usually one-to-one corresponding. Therefore, a correspondence between the VNI and the ENI identifier of the ENI instance of the cloud platform can be established in advance. The configuration information includes at least one ENI identifier. Based on the correspondence between the VNI and the ENI identifier, the target ENI identifier corresponding to the VNI included in the network information can be determined. If the target ENI identifier is consistent with any ENI identifier included in the configuration information, it is determined that the network information hits the configuration information. In this way, it is only necessary to configure the ENI identifier on the gateway device 16, and based on the correspondence between the ENI identifier and the VNI, the mirrored traffic of the specified virtual network can be filtered out, and the mirrored traffic of the specified virtual network can be sent to the traffic analysis device 14 as the target mirrored traffic.
[0064] Furthermore, the configuration information also includes a target tenant identifier and a target network identifier for the cloud platform's VPC network. A tenant asset table can be obtained, which includes a correspondence between tenant identifiers, network identifiers, and ENI identifiers. Based on the tenant asset table, a target network identifier corresponding to the target tenant identifier and an ENI identifier corresponding to the target network identifier can be determined. If the target ENI identifier is consistent with any ENI identifier included in the configuration information, and the target ENI identifier is the ENI identifier corresponding to the target tenant identifier and the target network identifier, then it is determined that the network information matches the configuration information.
[0065] In the above embodiment, tenant identifier, network identifier and ENI identifier are used to filter the mirror traffic, so that it is possible to filter the mirror traffic of different granularities (tenant granularity, VPC network granularity, ENI instance granularity), thereby achieving refined filtering and improving the accuracy of traffic filtering.
[0066] In the above embodiment, the number of gateway devices 16 can be greater than or equal to one. When the number of gateway devices 16 is greater than one, the traffic collection device 10 can be connected to the traffic collection device 10 via the load balancing device 18. The traffic collection device 12 can send the mirrored traffic collected by the traffic collection device 10 to the load balancing device 18. The load balancing device 18 can perform load balancing on the received mirrored traffic to determine a target gateway device among the multiple gateway devices 16. The load balancing device 18 can then add identification information of the target gateway device to the mirrored traffic and send the mirrored traffic carrying the identification information of the target gateway device to the traffic collection device 12. The traffic collection device 10 can then send the mirrored traffic output by the load balancing device 18 to the corresponding target gateway device based on the identification information of the target gateway device. The traffic collection device 10 can include at least one of a first traffic collection device 120, a second traffic collection device 140, and a third traffic collection device 160. Accordingly, the mirrored traffic can include at least one of first off-cloud mirrored traffic, second off-cloud mirrored traffic, and on-cloud mirrored traffic. In this manner, load balancing can be achieved across multiple gateway devices 16, improving the performance of the gateway devices 16.
[0067] like Figure 3 As shown, when multiple gateway devices 16 are included, the transmission path of the in-cloud mirrored traffic (as shown by the short dashed line in the figure) is as follows: the ECS instance sends the in-cloud mirrored traffic to the server access switch, the server access switch sends the in-cloud mirrored traffic to the core switch, the core switch forwards the in-cloud mirrored traffic to the load balancing device 18 via the integrated access switch, and after the load balancing device 18 determines the target gateway device, it sends the in-cloud mirrored traffic carrying the identification information of the target gateway device via the integrated access switch to the core switch, which then forwards it to the diversion switch 12. The diversion switch 12 sends the in-cloud mirrored traffic to the target gateway device for filtering, shaping, and other processing, and then sends the in-cloud mirrored traffic to the traffic analysis device 14.
[0068] In some embodiments, the traffic analysis device 14 can subscribe to the type of mirrored traffic to be processed by the device from the shunt switch 12. The traffic analysis device 14 includes, but is not limited to, a network performance monitoring device (NPM), a network detection and response device (NDR), and the like. Each traffic analysis device 14 can process at least one type of mirrored traffic. For example, assuming that the mirrored traffic processed by the NPM device is the first off-cloud mirrored traffic, and the mirrored traffic processed by the NDR device includes the first off-cloud mirrored traffic, the second off-cloud mirrored traffic, and the in-cloud mirrored traffic, the NPM device can subscribe to the first off-cloud mirrored traffic from the shunt switch 12, and the NDR device can subscribe to the first off-cloud mirrored traffic, the second off-cloud mirrored traffic, and the in-cloud mirrored traffic from the shunt switch 12.
[0069] Users can configure subscription information for each traffic analysis device 14 on the diversion switch 12. The subscription information indicates the type of mirrored traffic processed by the traffic analysis device. Based on the subscription information, the diversion switch 12 can then send each type of mirrored traffic to the traffic analysis device 14 that has subscribed to that type of mirrored traffic. Since different traffic analysis devices 14 are typically connected to different ports of the diversion switch 12, subscription information can be configured for each port of the diversion switch 12. Based on each port's subscription information, the mirrored traffic of the type subscribed to by that port is sent to the traffic analysis device 14 connected to that port. Each traffic analysis device 14 can subscribe to at least one type of mirrored traffic from the diversion switch 12. If a traffic analysis device 14 subscribes to more than one type of mirrored traffic, it can simply be connected to multiple ports of the diversion switch 12. In related art, mirror filters can only send mirrored traffic to a single destination. However, by using the diversion switch 12 and having the traffic analysis device 14 subscribe to mirrored traffic from the diversion switch 12, the disclosed embodiments enable different traffic analysis devices 14 to consume the same mirrored traffic.
[0070] See also Figure 7, the first traffic collection device 120 for collecting the first off-cloud mirror traffic can be connected to the port BAGG1 of the shunt switch 12, and the second traffic collection device 140 for collecting the second off-cloud mirror traffic can be connected to the port BAGG2 of the shunt switch 12, and both port BAGG1 and port BAGG2 can be Layer 2 aggregation ports. A Layer 2 aggregation port refers to a network device that aggregates multiple physical interfaces into one logical interface. In this way, the bandwidth and reliability of the network can be improved, and the load balancing of the network can also be achieved. The third traffic collection device 160 for collecting the mirror traffic within the cloud can be connected to the Layer 3 VLAN virtual interface of the shunt switch 12. For further information, see Figure 7 The diversion switch 12 includes multiple ports, and the ports used to send different types of mirrored traffic belong to different VLAN domains. The number of VLAN domains to which each port belongs can be greater than or equal to 1. For example, assume that the multiple ports of the diversion switch 12 include port BAGG3, port BAGG4, and port BAGG5, and that the VLAN domain to which port BAGG3 belongs includes the first VLAN domain, the VLAN domain to which port BAGG4 belongs includes the first VLAN domain, the second VLAN domain, and the third VLAN domain, and the VLAN domain to which port BAGG5 belongs includes the third VLAN domain. The first VLAN domain is used to send first off-cloud mirrored traffic, the second VLAN domain is used to send second off-cloud mirrored traffic, and the third VLAN domain is used to send intra-cloud mirrored traffic. Traffic analysis device 14 is connected to a port in the target VLAN domain of the diversion switch. The type of mirrored traffic sent by the port in the target VLAN domain matches the subscription information of traffic analysis device 14. Continuing with the previous example, if the mirrored traffic subscribed to by a traffic analysis device 14 (denoted as device 1) includes the first off-cloud mirrored traffic, then device 1 is connected to port BAGG3. If the mirrored traffic subscribed by another traffic analysis device 14 (denoted as device 2) includes the first off-cloud mirrored traffic, the second off-cloud mirrored traffic, and the on-cloud mirrored traffic, then device 2 is connected to port BAGG4. If the mirrored traffic subscribed by yet another traffic analysis device 14 (denoted as device 3) includes the on-cloud mirrored traffic, then device 3 is connected to port BAGG5. Figure 7 , you can configure a Layer 2 aggregate interface (BAGG6 in the figure) on the Layer 3 VLAN virtual interface. Layer 2 aggregate interface BAGG6 can receive mirrored traffic from Layer 2 aggregate interfaces BAGG1 and BAGG2, and send the mirrored traffic to Layer 2 aggregate interfaces BAGG3, BAGG4, and BAGG5.
[0071] Branch switch 12 can broadcast the mirrored traffic of the first off-cloud mirrored traffic, the second off-cloud mirrored traffic, and the on-cloud mirrored traffic, whose type matches the subscription information, to the ports in the target VLAN domain, so that the ports in the target VLAN domain send the mirrored traffic of the type matching the subscription information to traffic analysis device 14 for traffic analysis. Continuing with the previous example, and taking device 1 as an example, branch switch 12 can broadcast the first off-cloud mirrored traffic to the VLAN domain to which port BAGG3 belongs, and to all other ports except port BAGG3. These other ports then broadcast the first off-cloud mirrored traffic to device 1.
[0072] In related technologies, the traffic sent from device A to device B and the traffic returned from device B to device A may be sent to different traffic analysis devices for analysis. This prevents the traffic analysis device from obtaining the complete traffic flow between devices A and B, hindering traffic analysis. To address this issue, a dedicated splitter is required, which increases the cost of traffic analysis.
[0073] Based on this, the embodiment of the present disclosure can obtain the initial source address and the initial destination address in the mirrored traffic through the gateway device 16, and map the initial source address and the initial destination address to the target source address and the target destination address, respectively, wherein the target source address and the target destination address respectively correspond one-to-one to the unordered set including the initial source address and the initial destination address. The above-mentioned one-to-one correspondence means that no matter which of the two addresses is the initial source address and which is the initial destination address, the target source address corresponds one-to-one to the set including the above two addresses, and the target destination address also corresponds one-to-one to the set including the above two addresses. For example, the two addresses are respectively recorded as address 1 and address 2. The target source address and target destination address determined when address 1 is the initial source address and address 2 is the initial destination address are the same as the target source address and target destination address determined when address 2 is the initial source address and address 1 is the initial destination address. Moreover, when either or both of address 1 and address 2 change, the determined target source address and target destination address also change.
[0074] After obtaining the target source address and the target destination address, the gateway device 16 can send the mirrored traffic including the target source address and the target destination address to the traffic analysis device 14 for traffic analysis. Since the traffic sent by device A to another device B and the traffic returned by device B to device A correspond to the same unordered set, the traffic sent by device A to another device B and the traffic returned by device B to device A will be mapped to the same target source address and the same target destination address, and the mirrored traffic including the same target source address and the same target destination address will be sent to the same traffic analysis device 14, thereby achieving the same source and destination of the traffic. The above solution can be implemented by simply configuring the corresponding software code on the general gateway device 16, without the need for a dedicated splitter, thereby reducing the cost of traffic analysis. The following examples illustrate the specific method of obtaining the target source address and the target destination address.
[0075] In some embodiments, the initial source address and the initial destination address may be compared to obtain a comparison result. The initial source address and the initial destination address may be re-determined based on the comparison result, and hash processing may be performed on the re-determined initial source address and the newly determined initial destination address to obtain a hash value. Based on the hash value, the re-determined initial source address and the re-determined initial destination address may be mapped to the target source address and the target destination address, respectively.
[0076] The initial source address and the initial destination address are re-determined based on the comparison result. Alternatively, the smaller of the initial source address and the initial destination address is re-determined as the initial source address, and the larger of the initial source address and the initial destination address is re-determined as the initial destination address. Alternatively, the larger of the initial source address and the initial destination address is re-determined as the initial source address, and the smaller of the initial source address and the initial destination address is re-determined as the initial destination address. Regardless of whether it is traffic sent by device A to device B or traffic returned by device B to device A, the comparison result obtained by comparing the initial source address and the initial destination address is the same. Therefore, based on the comparison result, the same initial source address and the same initial destination address can be re-determined for the traffic sent by A to device B and the traffic returned by device B to device A.
[0077] For example, assume that the address of device A is recorded as Address 1, the address of device B is recorded as Address 2, and assume that Address 1 is greater than Address 2. When device A sends traffic to device B, the initial source address is Address 1, and the initial destination address is Address 2. When device B sends traffic to device A, the initial source address is Address 2, and the initial destination address is Address 1. Assuming that the smaller of the initial source address and the initial destination address is determined as the initial source address, and the larger of the initial source address and the initial destination address is determined as the initial destination address, then whether device A sends traffic to device B or device B sends traffic to device A, the re-determined initial source address is the smaller of Address 1 and Address 2 (i.e., Address 2), and the re-determined initial destination address is the larger of Address 1 and Address 2 (i.e., Address 1).
[0078] Since an address usually consists of multiple segments, when comparing the initial source address and the initial destination address, you can start with the first segment and compare each segment of the initial source address with the corresponding segment of the initial destination address in sequence. If the first segments of the initial source address and the initial destination address are the same, continue comparing the second segments of the initial source address and the initial destination address, and so on, until a target segment of different size is determined. The address with the larger value in the target segment is determined as the larger address, and the address with the smaller value in the target segment is determined as the smaller address.
[0079] Taking IP addresses as an example, assuming the initial source address is 202.108.22.5 and the initial destination address is 202.108.0.0, the first segments of the two addresses are compared first. Since the first segments of both the initial source address and the initial destination address are 202, the second segments of the two addresses are compared. Since the second segments of both the initial source address and the initial destination address are 108, the third segments of the two addresses are compared. Since the third segment of the initial source address is larger than the third segment of the initial destination address, the initial destination address 202.108.0.0 is re-determined as the initial source address, and the initial source address 202.108.22.5 is re-determined as the initial destination address.
[0080] After the initial source address and the initial destination address are re-determined, the re-determined initial source address and the re-determined initial destination address can be used together as input to calculate a hash value, and based on the hash value, the determined initial source address can be mapped to the target source address, and based on the hash value, the determined initial destination address can be mapped to the target destination address.
[0081] For example, when the initial source address and the initial destination address are both IP addresses, the first two segments of the predetermined private IP address can be determined as the first two segments of the target source address and the target destination address respectively, and the last two segments of the re-determined initial source address can be summed with the hash value respectively to obtain the sum results corresponding to the last two segments of the re-determined initial source address, and the sum results corresponding to the last two segments of the initial source address can be determined as the last two segments of the target source address respectively, and the last two segments of the re-determined initial destination address can be summed with the hash value respectively to obtain the sum results corresponding to the last two segments of the re-determined initial destination address, and the sum results corresponding to the last two segments of the initial destination address can be determined as the last two segments of the target destination address respectively. Assuming the first two segments of the private IP address are 172 and 16, respectively, and the hash value is 3, the re-determined initial source address 202.108.0.0 can be mapped to the target source address 172.16.3.3, and the re-determined initial destination address 202.108.22.5 can be mapped to the target source address 172.16.25.8. Because the target source address and the target source address are private IP addresses, mirrored traffic carrying these private IP addresses will not be sent to the public network. In some embodiments, both the target source address and the target source address are addresses not connected to the diversion switch 12. This prevents the mirrored traffic from being sent to devices connected to the private network.
[0082] The above embodiment provides a specific method for determining the target source address and the target source address. It should be understood that the above method is merely illustrative and is not intended to limit the present disclosure. In other examples, other methods may be used to obtain the target source address and the target source address, as long as the obtained target source address and the target source address both correspond one-to-one with the unordered set including the initial source address and the initial destination address.
[0083] For example, {source address, destination address} can be mapped to a new address, and the mapping relationship between {source address, destination address} and the new address can be stored. When traffic from address 1 to address 2 is obtained, the source address is address 1 and the destination address is address 2. The mapping relationships between {source address = address 1, destination address = address 2} and {source address = address 2, destination address = address 1} and the new address can be queried. If the mapping relationships between {source address = address 1, destination address = address 2} and {source address = address 2, destination address = address 1} and the new address are not found, then {source address = address 1, destination address = address 2} and {source address = address 2, destination address = address 1} are mapped to the same new address, and the mapping relationships between {source address = address 1, destination address = address 2} and the new address, as well as the mapping relationship between {source address = address 2, destination address = address 1} and the new address, are stored. The new addresses can be selected sequentially from a pre-established address pool, so that each selected new address can be guaranteed to be different.
[0084] In some embodiments, both the initial source address and the initial destination address are MAC addresses. Each segment of the re-determined initial source address can be summed with the hash value to obtain each segment of the target source address. Each segment of the re-determined initial destination address can be summed with the hash value to obtain each segment of the target destination address. Taking the initial source address as an example, assuming the initial source address is 00:11:22:33:44 and the hash value is 3, the resulting target source address is 03:14:25:36:47.
[0085] When the address information includes the initial source port number and the initial destination port number, the initial source port number and the hash value may be summed to obtain the target source port number, and the initial destination port number and the hash value may be summed to obtain the target destination port number.
[0086] After obtaining the target source address and target destination address, gateway device 16 can generate header information for the mirrored traffic, including the target source address and target destination address. Gateway device 16 can send the mirrored traffic including this header information to the diversion switch 12. Diversion switch 12 can broadcast the mirrored traffic including this header information to traffic analysis device 14 for traffic analysis. Because the traffic sent from device A to device B and the traffic sent from device B to device A are mapped to the same target source address and target destination address, these traffic flows are sent to the same traffic analysis device 14.
[0087] As described above, different types of mirrored traffic have different structures. If the mirrored traffic type is first off-cloud mirrored traffic or second off-cloud mirrored traffic, the mirrored traffic header information typically does not include a VXLAN header. Therefore, gateway device 16 can add a VXLAN header to the mirrored traffic header information. This VXLAN header includes the target source address and the target destination address. If the mirrored traffic type is intra-cloud mirrored traffic, the mirrored traffic header information typically includes a VXLAN header. Therefore, gateway device 16 can directly add the target source address and the target destination address to the mirrored traffic header information, thereby achieving traffic co-origin and co-destination while also implementing traffic shaping.
[0088] The embodiment of the present disclosure also provides a method for processing mirrored traffic, which is applied to a shunt switch 12. The shunt switch 12 is connected to an off-cloud traffic collection device, an on-cloud traffic collection device, and a traffic analysis device 14. The off-cloud traffic collection device is used to collect off-cloud mirrored traffic corresponding to traffic between the cloud platform and off-cloud devices. The on-cloud traffic collection device is used to collect on-cloud mirrored traffic corresponding to traffic between devices within the cloud platform. The traffic analysis device 14 is used to perform traffic analysis on the cloud platform based on the off-cloud mirrored traffic and the on-cloud mirrored traffic. Figure 8 , the method comprising:
[0089] Step S12: receiving the off-cloud mirror traffic sent by the off-cloud traffic collection device and the on-cloud mirror traffic sent by the on-cloud traffic collection device;
[0090] Step S14: Send the off-cloud mirror traffic and the on-cloud mirror traffic to the traffic analysis device 14 for traffic analysis.
[0091] The above method can be executed by the traffic diversion switch 12 in the aforementioned processing system embodiment. The off-cloud traffic collection device may include the first off-cloud traffic collection device 120 and / or the second off-cloud traffic collection device 140 in the aforementioned embodiment. Accordingly, the off-cloud mirrored traffic may include the first off-cloud mirrored traffic and / or the second off-cloud mirrored traffic in the aforementioned embodiment. The on-cloud traffic collection device may include the third traffic collection device 160 in the aforementioned embodiment. The functions of each device in the method embodiment are detailed in the aforementioned system embodiment and will not be repeated here.
[0092] The embodiment of the present disclosure also provides a method for processing mirrored traffic, which is applied to a gateway device 16. The gateway device 16 is connected to a traffic collection device 10 and a traffic analysis device 14. The traffic collection device 10 is used to collect mirrored traffic corresponding to traffic generated on the cloud platform, and the traffic analysis device 14 is used to perform traffic analysis on the cloud platform based on the mirrored traffic. Figure 9 , the method comprising:
[0093] Step S22: Acquire the mirrored traffic sent by the traffic collection device; the mirrored traffic carries the network information of the mirrored traffic;
[0094] Step S24: obtaining a pre-configured traffic filtering policy; the traffic filtering policy is used to indicate configuration information of the target mirrored traffic to be sent to the traffic analysis device;
[0095] Step S26: When it is determined that the network information matches the configuration information, the mirrored traffic is sent to the traffic analysis device 14 to perform traffic analysis on the cloud platform.
[0096] The above method can be executed by the gateway device 16 in the aforementioned processing system embodiment. The traffic filtered by the gateway device 16 may include at least one of the first off-cloud mirrored traffic, the second off-cloud mirrored traffic, and the on-cloud mirrored traffic in the aforementioned embodiment. Accordingly, the traffic collection device 10 may include at least one of the first traffic collection device 120, the second traffic collection device 140, and the third traffic collection device 160 in the aforementioned embodiment. The functions of each device in the method embodiment are detailed in the aforementioned system embodiment and are not further described here.
[0097] In some embodiments, the number of the configuration information is greater than or equal to 1; the method further includes: when the network information is consistent with any piece of configuration information, determining that the network information hits the configuration information.
[0098] In some embodiments, the network information includes the network address of the mirrored traffic, and the configuration information includes at least one target network address; when the network information is consistent with any one of the configuration information, determining that the network information hits the configuration information includes: if the network address included in the network information is consistent with any one of the target network addresses included in the configuration information, determining that the network information hits the configuration information.
[0099] In some embodiments, the configuration information also includes a target tenant identifier; if the network address included in the network information is consistent with any one of the target network addresses included in the configuration information, determining that the network information hits the configuration information includes: obtaining a tenant asset table, the tenant asset table including a correspondence between tenant identifiers and network addresses; determining the network address corresponding to the target tenant identifier based on the tenant asset table; if the network address included in the network information is consistent with any one of the target network addresses included in the configuration information, and the network address included in the network information is the network address corresponding to the target tenant identifier, determining that the network information hits the configuration information.
[0100] In some embodiments, if the mirrored traffic includes a first off-cloud mirrored traffic corresponding to the traffic between the cloud platform and the Internet and / or a second off-cloud mirrored traffic corresponding to the traffic between the cloud platform and the user's computer room, the network address is the public network address of the tenant of the cloud platform; if the mirrored traffic includes an intra-cloud mirrored traffic corresponding to the traffic between devices within the cloud platform, the network address is the network address of the cloud platform.
[0101] In some embodiments, the network information includes a VLAN identifier of a virtual local area network (VLAN) domain to which the mirrored traffic belongs, and the VLAN identifier corresponds to a network identifier of a virtual private cloud (VPC) network of the cloud platform. When the network information is consistent with any piece of configuration information, determining that the network information hits the configuration information includes: based on a correspondence between the VLAN identifier and the network identifier, determining a target network identifier corresponding to the VLAN identifier included in the network information; if the target network identifier is consistent with any one of the network identifiers included in the configuration information, determining that the network information hits the configuration information.
[0102] In some embodiments, the configuration information also includes a target tenant identifier; if the target network identifier is consistent with any network identifier included in the configuration information, determining that the network information hits the configuration information includes: obtaining a tenant asset table, the tenant asset table including a correspondence between tenant identifiers and network identifiers; determining the network identifier corresponding to the target tenant identifier based on the tenant asset table; if the target network identifier is consistent with any network identifier included in the configuration information, and the target network identifier is the network identifier corresponding to the target tenant identifier, determining that the network information hits the configuration information.
[0103] In some embodiments, the network information includes a virtual network identifier VNI of the virtual network to which the mirrored traffic belongs, the VNI corresponds to the ENI identifier of the elastic network interface ENI instance of the cloud platform, and the configuration information includes at least one ENI identifier; when the network information is consistent with any one of the configuration information, determining that the network information hits the configuration information includes: based on the correspondence between the VNI and the ENI identifier, determining the target ENI identifier corresponding to the VNI included in the network information; if the target ENI identifier is consistent with any one of the ENI identifiers included in the configuration information, determining that the network information hits the configuration information.
[0104] In some embodiments, the configuration information also includes a target tenant identifier and a target network identifier of the VPC network of the cloud platform; if the target ENI identifier is consistent with any one of the ENI identifiers included in the configuration information, determining that the network information hits the configuration information includes: obtaining a tenant asset table, the tenant asset table including a correspondence between the tenant identifier, the network identifier and the ENI identifier; determining the target network identifier corresponding to the target tenant identifier and the ENI identifier corresponding to the target network identifier based on the tenant asset table; if the target ENI identifier is consistent with any one of the ENI identifiers included in the configuration information, and the target ENI identifier is the ENI identifier corresponding to the target tenant identifier and the target network identifier, determining that the network information hits the configuration information.
[0105] The embodiment of the present disclosure also provides a method for processing mirrored traffic, which is applied to a gateway device 16. The gateway device 16 is connected to a traffic collection device 10 and a traffic analysis device 14. The traffic collection device 10 is used to collect mirrored traffic corresponding to traffic generated on the cloud platform, and the traffic analysis device 14 is used to perform traffic analysis on the cloud platform based on the mirrored traffic. Figure 10 , the method comprising:
[0106] Step S32: Acquire the mirrored traffic sent by the traffic collection device 10; the mirrored traffic includes the original source address and the original destination address of the mirrored traffic;
[0107] Step S34: mapping the initial source address and the initial destination address to a target source address and a target destination address, respectively, wherein the target source address and the target destination address respectively correspond one-to-one to the unordered set including the initial source address and the initial destination address;
[0108] Step S36: Send the mirrored traffic including the target source address and the target destination address to the traffic analysis device 14 to perform traffic analysis on the cloud platform; wherein, the mirrored traffic including the same target source address and the same target destination address is sent to the same traffic analysis device 14.
[0109] In some embodiments, mapping the initial source address and the initial destination address to the target source address and the target destination address, respectively, includes: comparing the sizes of the initial source address and the initial destination address to obtain a comparison result; redetermining the initial source address and the initial destination address based on the comparison result; performing hash processing on the redetermined initial source address and the redetermined initial destination address to obtain a hash value; and mapping the redetermined initial source address and the redetermined initial destination address to the target source address and the target destination address, respectively, based on the hash value.
[0110] In some embodiments, the initial source address and the initial destination address are both IP addresses; the mapping of the re-determined initial source address and the re-determined initial destination address to the target source address and the target destination address, respectively, based on the hash value includes: determining the first two segments of the predetermined private IP address as the target source address and the first two segments of the target destination address, respectively; summing the last two segments of the re-determined initial source address with the hash value, respectively, to obtain the summed results corresponding to the last two segments of the re-determined initial source address, and determining the summed results corresponding to the last two segments of the initial source address as the last two segments of the target source address, respectively; summing the last two segments of the re-determined initial destination address with the hash value, respectively, to obtain the summed results corresponding to the last two segments of the re-determined initial destination address, and determining the summed results corresponding to the last two segments of the initial destination address as the last two segments of the target destination address, respectively.
[0111] In some embodiments, the re-determining the initial source address and the initial destination address based on the comparison result includes: re-determining the smaller of the initial source address and the initial destination address as the initial source address, and re-determining the larger of the initial source address and the initial destination address as the initial destination address; or re-determining the larger of the initial source address and the initial destination address as the initial source address, and re-determining the smaller of the initial source address and the initial destination address as the initial destination address.
[0112] In some embodiments, the re-determined initial source address and the re-determined initial destination address are mapped to the target source address and the target destination address respectively based on the hash value, including: summing each segment of the re-determined initial source address with the hash value respectively to obtain each segment of the target source address; summing each segment of the re-determined initial destination address with the hash value respectively to obtain each segment of the target destination address.
[0113] In some embodiments, sending the mirrored traffic including the target source address and the target destination address to the traffic analysis device includes: generating header information of the mirrored traffic; including the target source address and the target destination address in the header information; and sending the mirrored traffic including the header information to the traffic analysis device.
[0114] In some embodiments, the type of the mirrored traffic includes at least one of the following: a first off-cloud mirrored traffic corresponding to the traffic between the cloud platform and the Internet; a second off-cloud mirrored traffic corresponding to the traffic between the cloud platform and the tenant's computer room; and an intra-cloud mirrored traffic corresponding to the traffic between devices within the cloud platform.
[0115] In some embodiments, the method further includes: if the type of the mirrored traffic is the first off-cloud mirrored traffic or the second off-cloud mirrored traffic, adding a virtual extensible local area network (VXLAN) header including the target source address and the target destination address to the header information of the mirrored traffic; if the type of the mirrored traffic is the intra-cloud mirrored traffic, adding the target source address and the target destination address to the header information of the mirrored traffic; wherein, the header information of the first off-cloud mirrored traffic or the second off-cloud mirrored traffic does not include the VXLAN header, and the header information of the intra-cloud mirrored traffic includes the VXLAN header.
[0116] In some embodiments, the gateway device is communicatively connected to the traffic collection device and the traffic analysis device through a diversion switch; sending the mirrored traffic including the target source address and the target destination address to the traffic analysis device includes: sending the mirrored traffic including the target source address and the target destination address to the diversion switch, so that the diversion switch broadcasts the mirrored traffic including the target source address and the target destination address to the traffic analysis device.
[0117] The above method can be executed by the gateway device 16 in the aforementioned processing system embodiment. The traffic filtered by the gateway device 16 may include at least one of the first off-cloud mirrored traffic, the second off-cloud mirrored traffic, and the on-cloud mirrored traffic in the aforementioned embodiment. Accordingly, the traffic collection device 10 may include at least one of the first traffic collection device 120, the second traffic collection device 140, and the third traffic collection device 160 in the aforementioned embodiment. The functions of each device in the method embodiment are detailed in the aforementioned system embodiment and are not further described here.
[0118] An embodiment of the present disclosure further provides a computer device, which includes at least a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in any of the aforementioned embodiments when executing the program.
[0119] Figure 11 FIG2 shows a more specific hardware structure diagram of a computing device provided by an embodiment of the present disclosure. The device may include: a processor 22, a memory 24, an input / output interface 26, a communication interface 28, and a bus 30. The processor 22, the memory 24, the input / output interface 26, and the communication interface 28 are connected to each other within the device via the bus 30.
[0120] The processor 22 can be implemented using a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided by the embodiments of the present disclosure. The processor 22 may also include a graphics card, which may be an Nvidia Titan X graphics card or a 1080Ti graphics card.
[0121] The memory 24 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage devices, dynamic storage devices, etc. The memory 24 can store an operating system and other application programs. When the technical solutions provided by the embodiments of the present disclosure are implemented through software or firmware, the relevant program codes are stored in the memory 24 and called and executed by the processor 22.
[0122] The input / output interface 26 is used to connect to input / output modules to enable information input and output. The input / output modules can be configured as components within the device (not shown) or can be externally connected to the device to provide corresponding functions. Input devices may include a keyboard, mouse, touch screen, microphone, various sensors, etc., and output devices may include a display, speaker, vibrator, indicator light, etc.
[0123] The communication interface 28 is used to connect to a communication module (not shown) to enable communication between the device and other devices. The communication module can communicate via a wired method (such as USB, network cable, etc.) or a wireless method (such as mobile network, WiFi, Bluetooth, etc.).
[0124] The bus 30 comprises a pathway for transmitting information between the various components of the device, such as the processor 22 , the memory 24 , the input / output interface 26 , and the communication interface 28 .
[0125] It should be noted that although the above device only shows the processor 22, memory 24, input / output interface 26, communication interface 28, and bus 30, in a specific implementation, the device may also include other components necessary for normal operation. In addition, those skilled in the art will understand that the above device may only include the components necessary to implement the embodiments of the present disclosure, and does not necessarily include all the components shown in the figure.
[0126] An embodiment of the present disclosure further provides a computer-readable storage medium having a computer program stored thereon, which implements the method described in any of the aforementioned embodiments when the program is executed by a processor.
[0127] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0128] An embodiment of the present disclosure further provides a computer program product, including a computer program, which implements the method described in any embodiment of the present disclosure when executed by a processor.
[0129] Through the description of the above implementation methods, it can be seen that those skilled in the art can clearly understand that the embodiments of the present disclosure can be implemented by means of software plus the necessary general hardware platform. Based on this understanding, the technical solution of the embodiments of the present disclosure, or the part that contributes to the prior art, can be embodied in the form of a software product, which can be stored in a storage medium such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or certain parts of the embodiments of the present disclosure.
[0130] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer, which may be in the form of a personal computer, laptop computer, cellular phone, image acquisition device phone, smartphone, personal digital assistant, media player, navigation device, email transceiver, game console, tablet computer, wearable device, or any combination of these devices.
[0131] Each embodiment in the present disclosure is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment. The device embodiment described above is merely illustrative, wherein the modules described as separate components may or may not be physically separated, and when implementing the embodiment of the present disclosure, the functions of each module can be implemented in the same one or more software and / or hardware. It is also possible to select some or all of the modules according to actual needs to achieve the purpose of the embodiment. A person of ordinary skill in the art can understand and implement it without paying any creative work.
[0132] The above is only a specific implementation of the embodiment of the present disclosure. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the embodiment of the present disclosure. These improvements and modifications should also be regarded as the scope of protection of the embodiment of the present disclosure.
Claims
1. A method for processing mirrored traffic, applied to a shunt switch, wherein the shunt switch is connected to an off-cloud traffic collection device, an on-cloud traffic collection device, and a traffic analysis device, wherein the off-cloud traffic collection device is used to collect off-cloud mirrored traffic corresponding to traffic between a cloud platform and off-cloud devices, the on-cloud traffic collection device is used to collect on-cloud mirrored traffic corresponding to traffic between devices within the cloud platform, and the traffic analysis device is used to perform traffic analysis on the cloud platform based on the off-cloud mirrored traffic and the on-cloud mirrored traffic; the method comprises: Receiving the off-cloud mirrored traffic sent by the off-cloud traffic collection device and the on-cloud mirrored traffic sent by the on-cloud traffic collection device; The off-cloud mirror traffic and the on-cloud mirror traffic are sent to the traffic analysis device to perform traffic analysis on the cloud platform.
2. According to the method of claim 1, the cloud traffic collection device is connected to the core switch of the cloud platform through the server access switch, and the core switch of the cloud platform is connected to the diversion switch.
3. The method according to claim 1, wherein the traffic diversion switch comprises a plurality of ports, and the off-cloud traffic collection device and the on-cloud traffic collection device are connected to different ports of the traffic diversion switch; the method further comprising: Based on the pre-stored correspondence between each of the ports and the traffic type of the mirrored traffic, the off-cloud mirrored traffic or the on-cloud mirrored traffic is determined from the mirrored traffic input from each of the ports.
4. The method according to claim 1, wherein the traffic diversion switch is further connected to a gateway device; and wherein the sending of the off-cloud mirrored traffic and the on-cloud mirrored traffic to the traffic analysis device to perform traffic analysis on the cloud platform comprises: Sending the off-cloud mirror traffic and the on-cloud mirror traffic to the gateway device, so that the gateway device pre-processes the off-cloud mirror traffic and the on-cloud mirror traffic; The pre-processing includes traffic shaping processing and / or traffic filtering processing; The pre-processed off-cloud mirror traffic and the pre-processed in-cloud mirror traffic are sent to the traffic analysis device to perform traffic analysis on the cloud platform.
5. The method according to claim 4, wherein the sending the off-cloud mirror traffic and the on-cloud mirror traffic to the gateway device so that the gateway device pre-processes the off-cloud mirror traffic and the on-cloud mirror traffic comprises: Adding tag information indicating traffic types to the off-cloud mirror traffic and the on-cloud mirror traffic respectively; The off-cloud mirror traffic and the on-cloud mirror traffic carrying the tag information are sent to the gateway device, so that the gateway device pre-processes the off-cloud mirror traffic and the on-cloud mirror traffic based on the traffic type indicated by the tag information.
6. The method according to claim 5, wherein the pre-processing includes traffic shaping; the gateway device performs traffic shaping on the off-cloud mirrored traffic and the on-cloud mirrored traffic based on the following method: Adding a virtual extensible local area network (VXLAN) header including the tag information to the off-cloud mirror traffic; Adding the tag information to the VXLAN header of the in-cloud mirrored traffic; in, The off-cloud mirror traffic does not include a VXLAN header, and the on-cloud mirror traffic includes a VXLAN header.
7. The method according to claim 4, wherein the number of the gateway devices is greater than 1, and the traffic distribution switch is connected to the off-cloud traffic collection device and the on-cloud traffic collection device via a load balancing device; Before sending the off-cloud mirror traffic and the on-cloud mirror traffic to the gateway device, the method further includes: Sending the off-cloud mirror traffic and the on-cloud mirror traffic to the load balancing device, so that the load balancing device performs load balancing processing on the off-cloud mirror traffic and the on-cloud mirror traffic; Receiving the off-cloud mirror traffic and the on-cloud mirror traffic output by the load balancing device, wherein the off-cloud mirror traffic and the on-cloud mirror traffic output by the load balancing device include identification information of corresponding target gateway devices; Based on the identification information of the target gateway device, the off-cloud mirror traffic and the on-cloud mirror traffic output by the load balancing device are sent to the corresponding target gateway device.
8. The method according to claim 1, wherein sending the off-cloud mirrored traffic and the on-cloud mirrored traffic to the traffic analysis device for traffic analysis comprises: Obtaining subscription information of the traffic analysis device, where the subscription information is used to indicate a type of mirrored traffic processed by the traffic analysis device; The mirrored traffic of the off-cloud mirrored traffic and the on-cloud mirrored traffic, the mirrored traffic of a type matching the subscription information, is sent to the traffic analysis device for traffic analysis.
9. The method according to claim 8, wherein the traffic diversion switch includes multiple ports, the ports for sending different types of mirrored traffic among the multiple ports belong to different virtual local area network (VLAN) domains, the traffic analysis device is connected to a port in a target VLAN domain of the traffic diversion switch, and the type of mirrored traffic sent by the port in the target VLAN domain matches the subscription information; and sending the mirrored traffic of the type matching the subscription information among the off-cloud mirrored traffic and the in-cloud mirrored traffic to the traffic analysis device for traffic analysis comprises: The mirror traffic of the off-cloud mirror traffic and the in-cloud mirror traffic, the mirror traffic of which the type matches the subscription information, is broadcast to the port of the target VLAN domain, so that the port of the target VLAN domain sends the mirror traffic of which the type matches the subscription information to the traffic analysis device for traffic analysis.
10. According to the method of claim 1, the off-cloud mirror traffic includes a first off-cloud mirror traffic corresponding to the traffic between the cloud platform and the Internet, and / or a second off-cloud mirror traffic corresponding to the traffic between the cloud platform and the user's computer room.
11. A system for processing mirrored traffic, the system comprising: Off-cloud traffic collection equipment is used to collect off-cloud mirror traffic corresponding to the traffic between the cloud platform and off-cloud devices; In-cloud traffic collection equipment, used to collect in-cloud mirror traffic corresponding to traffic between devices in the cloud platform; A traffic analysis device, configured to perform traffic analysis on the cloud platform based on the off-cloud mirror traffic and the on-cloud mirror traffic; as well as A traffic diversion switch is connected to the off-cloud traffic collection device, the on-cloud traffic collection device and the traffic analysis device, and is used to execute the method according to any one of claims 1 to 10.
12. A computer-readable storage medium having computer instructions stored thereon, wherein when the computer instructions are executed by a processor, the method according to any one of claims 1 to 10 is implemented.
13. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method according to any one of claims 1 to 10 when executing the program.
14. A computer program product comprising a computer program, wherein when the computer program is executed by a processor, the method according to any one of claims 1 to 10 is implemented.