Detection method, component, cloud environment, electronic equipment, storage medium and product

By deploying traffic detection components in the cloud environment to extract traffic features and perform security detection, the problems of high detection cost and large bandwidth consumption in the cloud computing network environment are solved, and efficient traffic security detection is achieved.

CN120602107APending Publication Date: 2025-09-05HANGZHOU ALICLOUD FEITIAN INFORMATION TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202410249615.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-05
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

In a cloud computing network environment, existing technologies require the deployment of additional drainage equipment to detect network traffic, resulting in high detection costs, poor timeliness, and large network bandwidth consumption.

Method used

Deploy traffic detection components on the communication link between the client and the server outside the cloud environment, and perform feature extraction and security detection by obtaining traffic information of access requests, avoiding the deployment of additional traffic diversion devices, reducing data transmission volume and improving detection timeliness.

Benefits of technology

It effectively reduces detection costs, reduces network bandwidth consumption, improves detection timeliness, and achieves efficient traffic security detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602107A_ABST
    Figure CN120602107A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a detection method and assembly, a cloud environment, electronic equipment, a storage medium and a product, and relates to the technical field of network security, and the method comprises the steps: obtaining an access request which is sent by a client and aims at a server; acquiring traffic information corresponding to the access request, and performing feature extraction on the traffic information to obtain traffic features corresponding to the traffic information; according to the embodiment of the invention, the method comprises the steps: carrying out the traffic safety detection of the access request according to the traffic characteristics, and executing the management and control operation for the client according to the traffic detection result, and omitting a drainage link, thereby effectively reducing the detection cost, effectively reducing the data transmission amount, greatly saving the network bandwidth, and improving the detection timeliness.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a network traffic detection method, a traffic detection component, a cloud environment, an electronic device, a computer-readable storage medium, and a computer program product. Background Art

[0002] With the development of cloud computing technology, its applications are becoming increasingly widespread. For example, cloud servers, cloud storage, cloud databases, and cloud applications can constitute an important part of the cloud computing infrastructure. To ensure the security of the cloud computing network environment and achieve network traffic protection, network traffic can be detected to determine the security of the network environment. For example, in the process of protecting and detecting network traffic on the cloud, it is often necessary to deploy additional drainage equipment to mirror the network data and analyze the network traffic based on the mirrored traffic to determine the security of the network traffic. However, in this process, the additional deployment of drainage equipment can easily increase the detection cost. At the same time, the transmission of mirrored traffic increases the amount of data transmitted, which can easily reduce the timeliness of traffic detection and lead to significant network bandwidth consumption. Summary of the Invention

[0003] The embodiments of the present application provide a network traffic detection method, component, cloud environment, electronic device, computer-readable storage medium, and computer program product to solve or partially solve the problems of high cost, poor timeliness, and consumption of additional network bandwidth in the network traffic detection process.

[0004] The present application discloses a method for detecting network traffic, which is applied to a traffic detection component deployed in a cloud environment. The traffic detection component is deployed in series on a communication link between a client outside the cloud environment and a server in the cloud environment. The method includes:

[0005] Obtaining an access request sent by the client to the server;

[0006] Obtaining traffic information corresponding to the access request, and performing feature extraction on the traffic information to obtain traffic features corresponding to the traffic information;

[0007] A traffic security detection is performed on the access request according to the traffic characteristics, and a control operation is performed on the client according to the traffic detection result.

[0008] In some optional embodiments, the traffic detection component includes at least a traffic identification unit, and the acquiring of traffic information corresponding to the access request and the feature extraction of the traffic information to obtain traffic features corresponding to the traffic information include:

[0009] The flow information corresponding to the access request is acquired through the flow identification unit, and features are extracted from the flow information to obtain flow features corresponding to the flow information.

[0010] In some optional embodiments, extracting features from the flow information to obtain flow features corresponding to the flow information includes:

[0011] Extracting at least one of a quintuple and application layer data from the traffic information;

[0012] Feature extraction is performed on at least one of the quintuple and the application layer data to obtain a traffic feature corresponding to the traffic information.

[0013] In some optional embodiments, the traffic characteristics include at least one of an IP address, a port number, a protocol type, application layer data content, a data packet size, a sending frequency, and a traffic behavior pattern.

[0014] In some optional embodiments, the traffic detection component includes at least an access control unit and a security detection unit communicatively connected to the access control unit and the traffic identification unit, respectively, wherein the access control unit and the traffic identification unit are deployed in series on the communication link. The traffic security detection is performed on the access request according to the traffic characteristics, and the control operation for the client is executed according to the traffic detection result, including:

[0015] Performing a traffic security detection on the access request according to the traffic characteristics by the security detection unit, and generating a traffic detection result for the client;

[0016] The access control unit performs a management and control operation corresponding to the traffic detection result.

[0017] In some optional embodiments, executing a control operation corresponding to the traffic detection result includes:

[0018] If the traffic detection result is passed, the access request is forwarded to the traffic identification unit, which then forwards the access request to the server and allows subsequent traffic between the client and the server to pass.

[0019] If the traffic detection result is failure, the transmission of the access request is blocked, the traffic between the client and the server is blocked, and a prompt message for the client is output, wherein the prompt message is information indicating that the client has a traffic security problem.

[0020] In some optional embodiments, the method further includes:

[0021] The traffic detection result is reported to the control device through the security detection unit. The traffic detection result is used to instruct the control device to generate a control instruction for the client. The control instruction includes one of traffic release or traffic blocking.

[0022] In some optional embodiments, after obtaining the traffic information corresponding to the access request, the method further includes:

[0023] If the traffic information carries an exemption flag, the traffic between the client and the server is allowed to pass through the access control unit.

[0024] The embodiment of the present application further discloses a cloud environment, wherein the cloud environment includes at least a server and a traffic detection component, wherein the traffic detection component includes at least a security detection unit, an access control unit deployed in series on a communication link between a client outside the cloud environment and a server in the cloud environment, and a traffic identification unit; wherein the security detection unit is deployed in a bypass manner in the cloud environment and is in communication connection with the access control unit and the traffic identification unit; wherein,

[0025] The access control unit is used to obtain the access request sent by the client to the server;

[0026] The traffic identification unit is used to obtain traffic information corresponding to the access request, and perform feature extraction on the traffic information to obtain traffic features corresponding to the traffic information;

[0027] The security detection unit is used to perform traffic security detection on the access request according to the traffic characteristics,

[0028] The access control unit is used to perform management and control operations on the client according to the traffic detection result.

[0029] In some optional embodiments, the traffic identification unit is specifically configured to:

[0030] extracting at least a corresponding quintuple and application layer data from the traffic information;

[0031] Feature extraction is performed on one of the quintuple and the application layer data to obtain a traffic feature corresponding to the traffic information.

[0032] In some optional embodiments, the traffic characteristics include at least one of an IP address, a port number, a protocol type, application layer data content, a data packet size, a sending frequency, and a traffic behavior pattern.

[0033] In some optional embodiments, the access control unit is specifically configured to:

[0034] If the traffic detection result is passed, the access request is forwarded to the traffic identification unit, which then forwards the access request to the server and allows subsequent traffic between the client and the server to pass.

[0035] If the flow detection result is failure, the transmission of the access request is blocked, the flow between the client and the server is blocked, and a prompt message for the client is output.

[0036] In some optional embodiments, the traffic identification unit is further configured to:

[0037] If the traffic information carries an inspection exemption mark, the access request is sent to the server.

[0038] The embodiment of the present application further discloses a traffic detection component, which is deployed in a cloud environment. The traffic detection component comprises at least a security detection unit, an access control unit deployed in series on a communication link between a client outside the cloud environment and a server in the cloud environment, and a traffic identification unit; wherein the security detection unit is deployed in a bypass manner in the cloud environment and is in communication connection with the access control unit and the traffic identification unit; wherein,

[0039] The access control unit is used to obtain the access request sent by the client to the server;

[0040] The traffic identification unit is used to obtain traffic information corresponding to the access request, and perform feature extraction on the traffic information to obtain traffic features corresponding to the traffic information;

[0041] The security detection unit is used to perform traffic security detection on the access request according to the traffic characteristics,

[0042] The access control unit is used to perform management and control operations on the client according to the traffic detection result.

[0043] In some optional embodiments, the traffic identification unit is specifically configured to:

[0044] extracting at least a corresponding quintuple and application layer data from the traffic information;

[0045] Feature extraction is performed on one of the quintuple and the application layer data to obtain a traffic feature corresponding to the traffic information.

[0046] In some optional embodiments, the traffic characteristics include at least one of an IP address, a port number, a protocol type, application layer data content, a data packet size, a sending frequency, and a traffic behavior pattern.

[0047] In some optional embodiments, the access control unit is specifically configured to:

[0048] If the traffic detection result is passed, the access request is forwarded to the traffic identification unit, which then forwards the access request to the server and allows subsequent traffic between the client and the server to pass.

[0049] If the flow detection result is failure, the transmission of the access request is blocked, the flow between the client and the server is blocked, and a prompt message for the client is output.

[0050] In some optional embodiments, the traffic identification unit is further configured to:

[0051] If the traffic information carries an inspection exemption mark, the access request is sent to the server.

[0052] The embodiment of the present application further discloses an electronic device, comprising a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus;

[0053] The memory is used to store computer programs;

[0054] The processor is used to implement the method described in the embodiment of the present application when executing the program stored in the memory.

[0055] The embodiment of the present application further discloses a computer-readable storage medium having instructions stored thereon, which, when executed by one or more processors, causes the processors to execute the method described in the embodiment of the present application.

[0056] An embodiment of the present application further discloses a computer program product, including a computer program, characterized in that when the computer program is executed by a processor, the method described in the embodiment of the present application is implemented.

[0057] The embodiments of the present application include the following advantages:

[0058] In an embodiment of the present application, in a cloud computing scenario, by deploying a traffic detection component on the communication link between a client outside the cloud environment and a server within the cloud environment, when data is interacted between the client and the server, the traffic detection component can obtain an access request sent by the client to the server, then obtain traffic information corresponding to the access request, and perform feature extraction on the traffic information to obtain traffic characteristics corresponding to the traffic information, and then perform traffic security detection on the access request based on the traffic characteristics, and perform management and control operations on the access request based on the traffic detection results. By deploying the traffic detection component between the client and the server, on the one hand, there is no need to deploy corresponding drainage equipment at the entrance outside the cloud environment, eliminating the drainage link and effectively reducing the detection cost. On the other hand, by extracting traffic characteristics from the traffic information and performing detection based on the traffic characteristics, the data transmission volume can be effectively reduced, the timeliness of detection can be improved, and the network bandwidth can be greatly saved. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] Figure 1 This is a flowchart of a method for detecting network traffic provided in an embodiment of the present application;

[0060] Figure 2 is a schematic diagram of an application scenario provided in an embodiment of the present application;

[0061] Figure 3 is a schematic diagram of an application scenario provided in an embodiment of the present application;

[0062] Figure 4 is a schematic diagram of an application scenario provided in an embodiment of the present application;

[0063] Figure 5 This is a structural block diagram of a flow detection component provided in an embodiment of the present application;

[0064] Figure 6 This is a block diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0065] In order to make the above-mentioned purposes, features and advantages of the present application more obvious and easy to understand, the present application is further described in detail below with reference to the accompanying drawings and specific implementation methods.

[0066] As an example, in order to achieve security protection and detection of network traffic on the cloud without changing the physical topology of the current network structure, during the relevant traffic detection process, the traffic path is changed by diversion, so that the traffic is diverted to the corresponding target device, and then the target device analyzes the traffic. However, in this process, it is necessary to deploy additional hardware equipment (such as splitters, splitters, etc.) at the entrance outside the cloud environment, which increases the detection cost and complexity. In addition, diversion adds additional traffic paths, especially for cross-computer room diversion scenarios. The delay in detection becomes more and more obvious, and the diversion method requires the transmission of traffic, which increases the network bandwidth and easily puts a heavy burden on network equipment.

[0067] In this regard, in the present application, in a cloud computing scenario, by deploying a traffic detection component on the communication link between a client outside the cloud environment and a server within the cloud environment, when data is interacted between the client and the server, the traffic detection component can obtain the access request sent by the client to the server, and then obtain the traffic information corresponding to the access request, and perform feature extraction on the traffic information to obtain the traffic characteristics corresponding to the traffic information, and then perform traffic security detection on the access request based on the traffic characteristics, and perform management and control operations on the access request based on the traffic detection results. By deploying the traffic detection component between the client and the server, on the one hand, there is no need to deploy corresponding drainage equipment at the entrance outside the cloud environment, eliminating the drainage link and effectively reducing the detection cost. On the other hand, by extracting traffic characteristics from the traffic information and performing detection based on the traffic characteristics, it can effectively reduce the data transmission volume, improve the timeliness of detection, and greatly save network bandwidth.

[0068] Reference Figure 1 , shows a flowchart of the steps of a network traffic detection method provided in an embodiment of the present application, which is applied to a traffic detection component deployed in a cloud environment. The traffic detection component is deployed in series on the communication link between a client outside the cloud environment and a server in the cloud environment. Specifically, the following steps may be included:

[0069] Step 101: obtaining an access request sent by the client to the server;

[0070] In the embodiments of the present application, network traffic detection can be applied to remote office access, client application access, resource access, cross-cloud environment access, etc. Specifically, for remote office access: when employees use remote office tools (such as VPN (Virtual Private Network) and remote desktop) outside the cloud to access corporate resources in the cloud, traffic detection can be used to ensure the security of access. For example, VPN traffic can be monitored, and user authentication and access behavior can be checked to identify abnormal login attempts or unauthorized access.

[0071] For client application access, when users use terminal devices or applications outside the cloud to access applications within the cloud, traffic security detection and response can be performed. For example, by monitoring data traffic from applications in real time, application propagation, abnormal data transmission, or unauthorized access can be detected and prevented.

[0072] For resource access, when shared resources or applications within the cloud need to be accessed from outside the cloud, security can be ensured by detecting access traffic. For example, an intrusion detection system can be used to detect traffic from specific IP addresses to determine whether there are potential security risks.

[0073] For cross-cloud access, when resources within a cloud need to interact with other cloud service providers outside the cloud, access traffic can be monitored and restricted. For example, firewalls and access control lists can be used to control traffic, allowing only traffic that complies with security policies to pass.

[0074] In the specific implementation, for the traffic detection component, by deploying it in the same cloud environment as the server, and deploying it in series on the communication link between the client outside the cloud environment and the server in the cloud environment, it can effectively avoid deploying corresponding drainage equipment at the entrance outside the cloud environment, saving equipment costs. At the same time, based on the traffic detection component, the traffic in the communication link is feature extracted and analyzed, which effectively reduces the data transmission volume, improves the detection timeliness, and saves network bandwidth.

[0075] Optionally, the traffic detection component may be a component deployed on the server, or a component independently deployed in the same cloud environment as the server. The traffic detection component may be in software form, which is not limited by the present invention.

[0076] In one example, referring to Figure 2 , shows a schematic diagram of an application scenario provided in an embodiment of the present application, wherein a corresponding server is deployed in a cloud environment, and a client located outside the cloud environment can access the server. During the access process, a traffic detection device is deployed on the communication link between the server and the client. The traffic detection component can obtain the access request sent by the client to the server and perform traffic security detection based on the access request to achieve detection and protection of network traffic. It should be noted that the client can be a user terminal or an application deployed on the user terminal, etc., and the present invention does not limit this.

[0077] Optionally, the access control unit and the traffic identification unit can be deployed in series on the path that the business traffic must pass through, and can also be integrated with the gateway and maintain a communication connection with the security detection unit, thereby avoiding the deployment of drainage equipment to change the forwarding path of the business traffic. In addition, the access control unit, the traffic identification unit, and the security detection unit can be deployed separately, or some units can be combined for deployment to save costs, improve deployment flexibility, and reduce the impact on business traffic. For example, the access control unit and the traffic identification unit can be combined and deployed on the path that the business traffic must pass through, and the security detection unit can be deployed in bypass mode. Alternatively, the access control unit and the traffic identification unit can be deployed in series on the path that the business traffic must pass through, and the security detection unit can be deployed in bypass mode, etc. This application does not impose any restrictions on this.

[0078] Step 102: Obtaining traffic information corresponding to the access request, and performing feature extraction on the traffic information to obtain traffic features corresponding to the traffic information;

[0079] In an embodiment of the present application, after obtaining the access request sent by the client, the traffic detection component can further obtain the traffic information corresponding to the access request, and perform feature extraction on the traffic information to obtain the corresponding traffic features, so as to perform traffic security detection based on the traffic features, and then process the access request based on the traffic detection results, for example, blocking the access request, forwarding the access request to the server, etc., thereby achieving traffic detection while ensuring data interaction between the client and the server.

[0080] In some optional embodiments, the traffic detection component includes at least a traffic identification unit, and the traffic information corresponding to the access request can be obtained through the traffic identification unit, and features can be extracted from the traffic information to obtain traffic features corresponding to the traffic information. In the process of extracting the traffic features, the traffic identification unit can first extract at least one of a quintuple and application layer data from the traffic information, and then perform feature extraction on at least one of the quintuple and application layer data to obtain traffic features corresponding to the traffic information. Optionally, the traffic features include at least one of an IP address, a port number, a protocol type, application layer data content, a packet size, a sending frequency, and a traffic behavior pattern.

[0081] The quintuple is the five elements used to uniquely identify a network connection in network communications, including the source IP address, destination IP address, source port, destination port number, and protocol type. The source IP address can be the client's IP address; the destination IP address can be the server's IP address; the source port number identifies the application or service from which the packet originates, used to distinguish communications between different applications on the same host; the destination port number identifies the application or service to which the packet is sent, used to distinguish different services or applications; and the protocol type refers to the transport protocol used by the packet, such as TCP (Transmission Control Protocol), UDP (User Datagram Protocol), or ICMP (Internet Control Message Protocol). The protocol type determines the method and rules for packet transmission.

[0082] Protocol information can be the protocol information used by data packets transmitted in network communications. Each data packet contains information about its source, destination, and exchange protocol. Different network communication protocols may correspond to different protocol information, and network communication protocols may include IP, TCP, UDP, and ICMP. It should be noted that the quintuple and protocol information contain the necessary information to describe data packet transmission, while the transmission protocol information indicates the rules and methods for data packet transmission, thereby ensuring that the data can correctly reach the target host on the network.

[0083] Furthermore, application layer data refers to data generated and processed by applications. After passing through the transport layer (e.g., TCP or UDP) and the network layer (e.g., IP), it is ultimately transmitted over the network to its destination. The content and format of application layer data depend on the specific application and protocol. For example, HTTP (Hypertext Transfer Protocol) transmits hypertext documents between web browsers and web servers. Application layer data includes web page content such as HTML documents, CSS (Cascading Style Sheets) style sheets, and JavaScript scripts. FTP (File Transfer Protocol) is used to transfer files between clients and servers. Application layer data includes the files to be transferred, including text files, images, video, and audio. SMTP (Simple Mail Transfer Protocol) is used for sending and transmitting emails. Application layer data includes email information such as the email subject, body content, attachments, recipients, and senders; DNS (Domain Name System): resolves domain names into corresponding IP addresses, and application layer data is data containing domain name query requests and corresponding IP addresses; VoIP (Voice over IP): conducts voice communication over the Internet, and application layer data is encoded voice signals used for transmission and reproduction as sound signals in the Internet.

[0084] In one example, after obtaining the traffic information corresponding to the access request, the traffic identification unit can extract the quintuple and application layer data from the traffic information, and perform feature extraction on at least one of the quintuple and application layer data to obtain corresponding traffic features, including extracting the source IP address, destination IP address, source port number, destination port number and protocol type from the quintuple, extracting the protocol type from the protocol information, and extracting the application layer data content, data packet size, sending frequency, traffic behavior pattern, etc. from the application layer data, so as to perform traffic security detection on the traffic corresponding to the access request based on the extracted traffic features, and then process the access request based on the traffic detection results to achieve network protection and detection.

[0085] Step 103: Perform a traffic security check on the access request according to the traffic characteristics, and perform a control operation on the client according to the traffic check result.

[0086] In an embodiment of the present application, the security detection unit in the security detection component, which is respectively connected to the access control unit and the traffic identification unit, can receive the traffic characteristics sent by the traffic identification unit, and then perform traffic security detection on the access request based on the traffic characteristics, generate a traffic detection result for the access request, and send the traffic detection result to the access control unit, which executes management and control operations corresponding to the traffic detection result.

[0087] By deploying traffic security detection components between the client and the server, on the one hand, there is no need to deploy corresponding traffic diversion equipment at the entrance outside the cloud environment, avoiding traffic mirroring and effectively reducing detection costs. On the other hand, by extracting traffic features from traffic information and performing detection based on traffic features, it can effectively reduce data transmission volume, improve the timeliness of detection, and greatly save network bandwidth.

[0088] In a specific implementation, based on different traffic characteristics, the security detection unit can perform traffic security detection based on at least one traffic characteristic, for example, IP address: the source IP address and destination IP address of the traffic, which can analyze the source and destination of the traffic and detect abnormal or illegal IP addresses; port number: the source port number and destination port number of the traffic, which can analyze the service type and communication method of the traffic and detect abnormal or illegal port usage; protocol type: the protocol type used by the traffic, such as TCP, UDP, ICMP, etc., which can analyze the protocol distribution of the traffic and detect abnormal or illegal protocol usage; application layer data content: the characteristics of the application layer data transmitted in the traffic, such as text, images, audio, etc., which can use text mining, image processing, sound recognition and other technologies to extract and analyze the data content; data packet size: the number of bytes of a single data packet, which can analyze statistical information such as the average size, maximum size, and minimum size of the data packet to help evaluate the data load and transmission performance of the traffic; sending frequency: the sending frequency of the data packet or the duration of the traffic. It can analyze the transmission rate, burstiness and continuity of traffic and detect abnormal traffic behavior; Traffic behavior pattern: Based on the time series data of traffic, it can analyze the behavior pattern of traffic, such as periodicity, regularity, abnormal behavior, etc.

[0089] In one example, taking the IP address as an example, after the security detection unit obtains the source IP address (client's IP address) and target IP address sent by the traffic identification unit, it can detect whether the source IP address and target IP address are legal IP addresses according to the whitelist and blacklist, and obtain the traffic detection result corresponding to the client. If the traffic detection result is passed, the traffic will not be blocked, and the release action can be sent to the access control unit to ensure that subsequent traffic is smoothly forwarded to the server, that is, the access control unit can forward the access request to the traffic identification unit, and forward the access request to the server through the traffic identification unit, so that the server can normally interact with the client after receiving the access request, and the access control unit can release the traffic between the client and the server; if the traffic detection result is not passed, the security detection unit will send the blocking action to the access control unit, and the access control unit will block the transmission of subsequent traffic of the access request, that is, block subsequent traffic between the client and the server, and output a prompt message for the client, which is information that prompts the client that there is a traffic security problem.

[0090] In addition, after the security detection unit completes the traffic security detection according to the traffic characteristics, it can also report the traffic detection results to the management and control device, so that the management and control device can generate a management and control instruction for the client based on the traffic detection results. If the traffic detection result is passed, the management and control device can generate a traffic release for the client; if the traffic detection result is not passed, the management and control device can generate a traffic blocking for the client, and then the management and control device can send the management and control instruction to the access control unit so that the access control unit performs traffic processing operations for the client. The relevant process can refer to the description in the aforementioned embodiment and will not be repeated here.

[0091] Taking the sending frequency of data packets as an example, after obtaining the sending frequency or traffic duration sent by the traffic identification unit, the security detection unit can compare the sending frequency or traffic duration with the preset detection threshold. For example, when the sending frequency is greater than or equal to the first preset threshold, it can be judged as abnormal; when the sending frequency is less than the first preset threshold, it can be judged as normal. Correspondingly, when the traffic duration is greater than or equal to the second preset threshold, it can be judged as abnormal; when the traffic duration is less than the second preset threshold, it can be judged as normal, etc., so that the security detection unit can obtain the corresponding traffic detection result based on the traffic characteristics, and determine the corresponding control operation based on the traffic detection result, and send the control operation to the access control unit, and the access control unit executes the control operation for the client.

[0092] By deploying traffic detection components between the client and the server, on the one hand, there is no need to deploy corresponding traffic diversion equipment at the entrance outside the cloud environment, avoiding traffic mirroring and effectively reducing detection costs. On the other hand, by extracting traffic features from traffic information and performing detection based on traffic features, it can effectively reduce data transmission volume, improve the timeliness of detection, and greatly save network bandwidth.

[0093] It should be noted that in the above examples, IP address, sending frequency and traffic duration are used as examples for illustrative purposes. It can be understood that traffic security detection can also be performed based on at least two traffic characteristics to improve the accuracy of traffic detection and ensure the security of traffic detection.

[0094] In addition, after obtaining the traffic information corresponding to the access request, the access control unit can also detect whether the traffic information has a corresponding exemption mark. If the traffic information carries the exemption mark, the access request will be sent to the server, and the server will perform the operation corresponding to the access mark; if the traffic information does not carry the exemption mark, the traffic security test can be performed through the above-mentioned traffic detection process, thereby performing traffic security test on the client through the exemption mark, which not only ensures security, but also reduces interference with whitelist clients and improves the flexibility of data interaction.

[0095] It should be noted that the embodiments of the present application include but are not limited to the above examples. It is understandable that those skilled in the art can also make settings according to actual needs under the guidance of the ideas of the embodiments of the present application, and the present application does not impose any restrictions on this.

[0096] In an embodiment of the present application, in a cloud computing scenario, by deploying a traffic detection component on the communication link between a client outside the cloud environment and a server within the cloud environment, when data is interacted between the client and the server, the traffic detection component can obtain an access request sent by the client to the server, then obtain traffic information corresponding to the access request, and perform feature extraction on the traffic information to obtain traffic characteristics corresponding to the traffic information, and then perform traffic security detection on the access request based on the traffic characteristics, and perform management and control operations on the access request based on the traffic detection results. By deploying the traffic detection component between the client and the server, on the one hand, there is no need to deploy corresponding drainage equipment at the entrance outside the cloud environment, eliminating the drainage link and effectively reducing the detection cost. On the other hand, by extracting traffic characteristics from the traffic information and performing detection based on the traffic characteristics, the data transmission volume can be effectively reduced, the timeliness of detection can be improved, and the network bandwidth can be greatly saved.

[0097] In order to enable those skilled in the art to better understand the technical solutions in the embodiments of the present application, the following examples are provided for illustrative purposes:

[0098] Reference Figure 3 , shows a schematic diagram of the communication device provided in an embodiment of the present application, wherein the client can be located outside the cloud environment, the traffic detection component can be composed of an access control unit, a traffic detection unit and a security detection unit, the three are connected in pairs, and the traffic detection unit is connected to the server, so that in the process of detecting the traffic, the access control unit can obtain the access request sent by the client to the server, the traffic identification unit can obtain the traffic information corresponding to the access request, and extract the traffic characteristics corresponding to the traffic information, and transmit the traffic characteristics to the security detection unit, the security detection unit performs traffic security detection according to the traffic characteristics, and sends the traffic detection results to the access control unit, the access control unit can perform processing operations for the access request based on the traffic detection results, including blocking, forwarding and alarm prompts, etc., so that by deploying the traffic detection component between the client and the server, on the one hand, there is no need to deploy corresponding diversion equipment at the entrance outside the cloud environment, avoiding traffic mirroring and effectively reducing the detection cost, and on the other hand, by extracting traffic characteristics from the traffic information and performing detection based on the traffic characteristics, it can effectively reduce the data transmission volume, improve the timeliness of detection, and greatly save network bandwidth.

[0099] Reference Figure 4 , shows a schematic diagram of an application scenario provided in an embodiment of the present application. In remote office access, when an employee uses a remote office tool outside the cloud to access corporate resources in the cloud, the remote office tool can send a corresponding access request to the server in the cloud environment to obtain the corresponding corporate resources. During the access process, the traffic identification unit can obtain the traffic information corresponding to the access request, extract the traffic characteristics corresponding to the traffic information, and transmit the traffic characteristics to the security detection unit. The security detection unit performs traffic security detection based on the traffic characteristics and sends the traffic detection result to the access control unit. The access control unit can perform processing operations for the access request based on the traffic detection result. If the traffic detection result is passed, the traffic will not be blocked, and the release action can be sent to the access control unit to ensure that subsequent traffic is smoothly forwarded to the server. That is, the access control unit can forward the access request to the traffic identification unit, which forwards the access request to the server through the traffic identification unit, so that the server can normally exchange data with the client after receiving the access request. The access control unit can release the traffic between the client and the server; if the traffic detection result is not passed, the blocking action is sent to the access control unit to block the transmission of subsequent traffic of the access request and output a prompt message for the access request.

[0100] It should be noted that for the method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the embodiments of the present application are not limited by the order of the actions described, because according to the embodiments of the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present application.

[0101] Reference Figure 5 , shows a structural block diagram of a traffic detection component provided in an embodiment of the present application, wherein the traffic detection component 50 is deployed in a cloud environment, and the traffic detection component 50 at least includes a security detection unit 503, an access control unit 501 deployed in series on a communication link between a client outside the cloud environment and a server in the cloud environment, and a traffic identification unit 502; wherein the security detection unit 503 is deployed in a bypass manner in the cloud environment and is in communication connection with the access control unit 501 and the traffic identification unit 502; wherein,

[0102] The access control unit 501 is used to obtain the access request sent by the client to the server;

[0103] The traffic identification unit 502 is configured to obtain traffic information corresponding to the access request, and perform feature extraction on the traffic information to obtain traffic features corresponding to the traffic information;

[0104] The security detection unit 503 is used to perform traffic security detection on the access request according to the traffic characteristics.

[0105] The access control unit 501 is used to perform management and control operations on the client according to the traffic detection result.

[0106] In some optional embodiments, the traffic identification unit 502 is specifically configured to:

[0107] extracting at least a corresponding quintuple and application layer data from the traffic information;

[0108] Feature extraction is performed on one of the quintuple and the application layer data to obtain a traffic feature corresponding to the traffic information.

[0109] In some optional embodiments, the traffic characteristics include at least one of an IP address, a port number, a protocol type, application layer data content, a data packet size, a sending frequency, and a traffic behavior pattern.

[0110] In some optional embodiments, the access control unit 501 is specifically configured to:

[0111] If the traffic detection result is passed, the access request is forwarded to the traffic identification unit 502, and the traffic identification unit 502 forwards the access request to the server, and allows subsequent traffic between the client and the server;

[0112] If the flow detection result is failure, the transmission of the access request is blocked, the flow between the client and the server is blocked, and a prompt message for the client is output.

[0113] In some optional embodiments, the traffic identification unit 502 is further configured to:

[0114] If the traffic information carries an inspection exemption mark, the access request is sent to the server.

[0115] In addition, an embodiment of the present application further discloses a cloud environment, wherein the cloud environment includes at least a server and a traffic detection component, wherein the traffic detection component includes at least a security detection unit, an access control unit deployed in series on a communication link between a client outside the cloud environment and a server in the cloud environment, and a traffic identification unit; wherein the security detection unit is deployed in a bypass manner in the cloud environment and is in communication connection with the access control unit and the traffic identification unit; wherein,

[0116] The access control unit is used to obtain the access request sent by the client to the server;

[0117] The traffic identification unit is used to obtain traffic information corresponding to the access request, and perform feature extraction on the traffic information to obtain traffic features corresponding to the traffic information;

[0118] The security detection unit is used to perform traffic security detection on the access request according to the traffic characteristics,

[0119] The access control unit is used to perform management and control operations on the client according to the traffic detection result.

[0120] In some optional embodiments, the traffic identification unit is specifically configured to:

[0121] extracting at least a corresponding quintuple and application layer data from the traffic information;

[0122] Feature extraction is performed on one of the quintuple and the application layer data to obtain a traffic feature corresponding to the traffic information.

[0123] In some optional embodiments, the traffic characteristics include at least one of an IP address, a port number, a protocol type, application layer data content, a data packet size, a sending frequency, and a traffic behavior pattern.

[0124] In some optional embodiments, the access control unit is specifically configured to:

[0125] If the traffic detection result is passed, the access request is forwarded to the traffic identification unit, which then forwards the access request to the server and allows subsequent traffic between the client and the server to pass.

[0126] If the flow detection result is failure, the transmission of the access request is blocked, the flow between the client and the server is blocked, and a prompt message for the client is output.

[0127] In some optional embodiments, the traffic identification unit is further configured to:

[0128] If the traffic information carries an inspection exemption mark, the access request is sent to the server.

[0129] As for the component embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0130] In addition, an embodiment of the present application also provides an electronic device, including: a processor, a memory, and a computer program stored in the memory and runnable on the processor. When the computer program is executed by the processor, the various processes of the above-mentioned network traffic detection method embodiment are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0131] In addition, an embodiment of the present application also discloses a computer program product, including a computer program, characterized in that when the computer program is executed by a processor, it implements the method described in the embodiment of the present application, implements the various processes of the above-mentioned network traffic detection method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0132] The present application also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, each process of the above-mentioned network traffic detection method embodiment is implemented, and the same technical effect is achieved. To avoid repetition, the above-mentioned computer-readable storage medium is not described here. The computer-readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0133] Figure 6 A schematic diagram of the hardware structure of an electronic device for implementing various embodiments of the present application.

[0134] The electronic device 600 includes but is not limited to components such as a radio frequency unit 601, a network module 602, an audio output unit 603, an input unit 604, a sensor 605, a display unit 606, a user input unit 607, an interface unit 608, a memory 609, a processor 610, and a power supply 611. Those skilled in the art will understand that the electronic device structure involved in the embodiments of the present application does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently. In the embodiments of the present application, the electronic device includes but is not limited to a mobile phone, a tablet computer, a laptop computer, a PDA, a vehicle-mounted terminal, a wearable device, and a pedometer.

[0135] It should be understood that in the embodiments of the present application, the RF unit 601 may be used to receive and transmit signals during information transmission or calls. Specifically, it receives downlink data from the base station and transmits it to the processor 610 for processing; in addition, it transmits uplink data to the base station. Typically, the RF unit 601 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, and the like. Furthermore, the RF unit 601 may communicate with the network and other devices via a wireless communication system.

[0136] The electronic device provides users with wireless broadband Internet access through the network module 602, such as helping users to send and receive emails, browse web pages, and access streaming media.

[0137] The audio output unit 603 can convert audio data received by the RF unit 601 or the network module 602 or stored in the memory 609 into an audio signal and output it as sound. In addition, the audio output unit 603 can also provide audio output related to a specific function performed by the electronic device 600 (for example, a call signal reception sound, a message reception sound, etc.). The audio output unit 603 includes a speaker, a buzzer, a receiver, etc.

[0138] The input unit 604 is used to receive audio or video signals. The input unit 604 may include a graphics processing unit (GPU) 6041 and a microphone 6042. The graphics processor 6041 processes image data of a still picture or video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The processed image frames can be displayed on the display unit 606. The image frames processed by the graphics processor 6041 can be stored in the memory 609 (or other storage medium) or transmitted via the radio frequency unit 601 or the network module 602. The microphone 6042 can receive sound and process such sound into audio data. The processed audio data can be converted into a format that can be sent to a mobile communication base station via the radio frequency unit 601 in the case of a telephone call mode.

[0139] The electronic device 600 also includes at least one sensor 605, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor includes an ambient light sensor and a proximity sensor, wherein the ambient light sensor can adjust the brightness of the display panel 6061 according to the brightness of the ambient light, and the proximity sensor can turn off the display panel 6061 and / or the backlight when the electronic device 600 is moved to the ear. As a type of motion sensor, the accelerometer sensor can detect the magnitude of acceleration in all directions (generally three axes), and can detect the magnitude and direction of gravity when stationary. It can be used to identify the posture of the electronic device (such as horizontal and vertical screen switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), etc.; the sensor 605 can also include a fingerprint sensor, a pressure sensor, an iris sensor, a molecular sensor, a gyroscope, a barometer, a hygrometer, a thermometer, an infrared sensor, etc., which will not be repeated here.

[0140] The display unit 606 is used to display information input by the user or information provided to the user. The display unit 606 may include a display panel 6061, which may be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), or the like.

[0141] The user input unit 607 can be used to receive input digital or character information, and to generate key signal input related to the user settings and function control of the electronic device. Specifically, the user input unit 607 includes a touch panel 6071 and other input devices 6072. The touch panel 6071, also known as a touch screen, can collect user touch operations on or near it (such as operations performed by the user using any suitable object or accessory such as a finger, stylus, etc. on or near the touch panel 6071). The touch panel 6071 may include two parts: a touch detection device and a touch controller. Among them, the touch detection device detects the user's touch direction and detects the signal caused by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device and converts it into touch point coordinates, which are then sent to the processor 610, which receives and executes the command sent by the processor 610. In addition, the touch panel 6071 can be implemented using various types such as resistive, capacitive, infrared, and surface acoustic wave. In addition to the touch panel 6071, the user input unit 607 may also include other input devices 6072. Specifically, other input devices 6072 may include but are not limited to a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick, which will not be described in detail here.

[0142] Furthermore, the touch panel 6071 may be overlaid on the display panel 6061. When the touch panel 6071 detects a touch operation on or near it, it transmits the information to the processor 610 to determine the type of touch event. The processor 610 then provides a corresponding visual output on the display panel 6061 based on the type of touch event. It will be understood that in one embodiment, the touch panel 6071 and the display panel 6061 are two independent components to implement the input and output functions of the electronic device. However, in some embodiments, the touch panel 6071 and the display panel 6061 may be integrated to implement the input and output functions of the electronic device. The specific details are not limited here.

[0143] The interface unit 608 is an interface for connecting external devices to the electronic device 600. For example, the external devices may include a wired or wireless headset port, an external power supply (or battery charger) port, a wired or wireless data port, a memory card port, a port for connecting a device with an identification module, an audio input / output (I / O) port, a video I / O port, a headphone port, etc. The interface unit 608 may be used to receive input (e.g., data information, power, etc.) from the external device and transmit the received input to one or more elements within the electronic device 600, or may be used to transmit data between the electronic device 600 and the external device.

[0144] Memory 609 can be used to store software programs and various data. Memory 609 may primarily include a program storage area and a data storage area. The program storage area may store an operating system and at least one application required for a function (such as a sound playback function or an image playback function); the data storage area may store data generated based on the use of the mobile phone (such as audio data, a phone book, etc.). Furthermore, memory 609 may include high-speed random access memory and non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0145] The processor 610 is the control center of the electronic device. It connects the various components of the electronic device using various interfaces and circuits. By running or executing software programs and / or modules stored in the memory 609 and accessing data stored in the memory 609, it performs various functions of the electronic device and processes data, thereby monitoring the electronic device as a whole. The processor 610 may include one or more processing units; preferably, the processor 610 may integrate an application processor and a modem processor, wherein the application processor primarily processes the operating system, user interface, and application programs, while the modem processor primarily handles wireless communications. It is understood that the modem processor may not be integrated into the processor 610.

[0146] The electronic device 600 may also include a power supply 611 (such as a battery) to supply power to each component. Preferably, the power supply 611 may be logically connected to the processor 610 through a power management system, thereby enabling the power management system to manage functions such as charging, discharging, and power consumption.

[0147] In addition, the electronic device 600 includes some functional modules not shown, which will not be described here.

[0148] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.

[0149] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0150] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.

[0151] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed in the embodiments of this application can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0152] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0153] In the embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0154] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0155] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0156] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.

[0157] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A method for detecting network traffic, characterized in that: Applied to a traffic detection component deployed in a cloud environment, the method includes: Obtaining an access request sent by the client to the server; Obtaining traffic information corresponding to the access request, and performing feature extraction on the traffic information to obtain traffic features corresponding to the traffic information; A traffic security detection is performed on the access request according to the traffic characteristics, and a control operation is performed on the client according to the traffic detection result.

2. The method according to claim 1, characterized in that The traffic detection component includes at least a traffic identification unit. The acquiring of traffic information corresponding to the access request and feature extraction of the traffic information to obtain traffic features corresponding to the traffic information include: The flow information corresponding to the access request is acquired through the flow identification unit, and features are extracted from the flow information to obtain flow features corresponding to the flow information.

3. The method according to claim 2, characterized in that The extracting features from the flow information to obtain flow features corresponding to the flow information includes: Extracting at least one of a quintuple and application layer data from the traffic information; Feature extraction is performed on at least one of the quintuple and the application layer data to obtain a traffic feature corresponding to the traffic information.

4. The method according to claim 2 or 3, characterized in that The traffic characteristics include at least one of IP address, port number, protocol type, application layer data content, data packet size, sending frequency, and traffic behavior pattern.

5. The method according to claim 2 or 3, characterized in that The traffic detection component includes at least an access control unit and a security detection unit that is communicatively connected to the access control unit and the traffic identification unit, respectively. The access control unit and the traffic identification unit are deployed in series on the communication link. The traffic security detection is performed on the access request according to the traffic characteristics, and a control operation is performed on the client according to the traffic detection result, including: Performing a traffic security detection on the access request according to the traffic characteristics by the security detection unit, and generating a traffic detection result for the client; The access control unit performs a management and control operation corresponding to the traffic detection result.

6. The method according to claim 5, characterized in that The performing of a control operation corresponding to the traffic detection result includes: If the traffic detection result is passed, the access request is forwarded to the traffic identification unit, which then forwards the access request to the server and allows subsequent traffic between the client and the server to pass. If the traffic detection result is failure, the transmission of the access request is blocked, the traffic between the client and the server is blocked, and a prompt message for the client is output, wherein the prompt message is information indicating that the client has a traffic security problem.

7. The method according to claim 5, characterized in that Also includes: The traffic detection result is reported to the control device through the security detection unit. The traffic detection result is used to instruct the control device to generate a control instruction for the client. The control instruction includes one of traffic release or traffic blocking.

8. The method according to claim 1, characterized in that After acquiring the traffic information corresponding to the access request, the method further includes: If the traffic information carries an exemption flag, the traffic between the client and the server is allowed to pass through the access control unit.

9. A cloud environment, characterized in that: The cloud environment includes at least a server and a traffic detection component, wherein the traffic detection component includes at least a security detection unit, an access control unit deployed in series on a communication link between a client outside the cloud environment and a server in the cloud environment, and a traffic identification unit; wherein the security detection unit is deployed in a bypass manner in the cloud environment and is in communication connection with the access control unit and the traffic identification unit; wherein, The access control unit is used to obtain the access request sent by the client to the server; The traffic identification unit is used to obtain traffic information corresponding to the access request, and perform feature extraction on the traffic information to obtain traffic features corresponding to the traffic information; The security detection unit is used to perform traffic security detection on the access request according to the traffic characteristics, The access control unit is used to perform management and control operations on the client according to the traffic detection result.

10. A flow detection component, characterized in that: The traffic detection component is deployed in a cloud environment, and the traffic detection component includes at least a security detection unit, an access control unit deployed in series on a communication link between a client outside the cloud environment and a server in the cloud environment, and a traffic identification unit; wherein the security detection unit is deployed in a bypass manner in the cloud environment and is in communication connection with the access control unit and the traffic identification unit; wherein, The access control unit is used to obtain the access request sent by the client to the server; The traffic identification unit is used to obtain traffic information corresponding to the access request, and perform feature extraction on the traffic information to obtain traffic features corresponding to the traffic information; The security detection unit is used to perform traffic security detection on the access request according to the traffic characteristics, The access control unit is used to perform management and control operations on the client according to the traffic detection result.

11. An electronic device, characterized in that: comprising a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; The memory is used to store computer programs; The processor is configured to implement the method according to any one of claims 1 to 8 when executing a program stored in the memory.

12. A computer-readable storage medium having instructions stored thereon, which, when executed by one or more processors, cause the processors to perform the method according to any one of claims 1 to 8.

13. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Security detection method, apparatus and system

    CN104967589A

  • Detection method and device for DDos attack

    CN107241304A

  • Security detection method, system and device and storage medium

    CN115333774A

  • Traffic safety monitoring method, equipment, device and system and readable storage medium

    CN115695009A

  • Terminal access control method, cloud gateway, electronic equipment and storage medium

    CN115967682A