Flow processing system and method integrating convergence shunting and deep packet inspection, and flow processing cluster
By integrating the traffic processing system of convergence, diversion and deep packet inspection, the problems of high system complexity and resource waste caused by separate deployment are solved, and efficient data processing scheduling and stable network communication are achieved.
Patent Information
- Application Number
- CN202510820042.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-19
- Publication Date
- 2025-09-19
AI Technical Summary
The separate deployment of convergence and splitter devices and DPI servers in the existing technology leads to high system complexity, waste of resources, high operation and maintenance costs, and lack of unified scheduling capabilities.
A traffic processing system integrating convergence and diversion with deep packet inspection is adopted. The power connection and data interaction between the convergence and diversion module and the deep packet inspection module are realized through the backplane connection module. The logic control module unifies the scheduling and control to build a unified traffic processing platform.
It improves data processing and scheduling efficiency, reduces maintenance costs, enhances system stability and fault response speed, and forms a highly integrated traffic processing solution with compact structure, fast response and stable operation.
Smart Images

Figure CN120675941A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network communication technology, and in particular to a traffic processing system, a processing method, and a traffic processing cluster integrating aggregation, diversion, and deep packet inspection. Background Art
[0002] In existing information security management systems, it is typically necessary to deploy both convergence and splitter devices and DPI (deep packet inspection) server devices. The convergence and splitter devices are primarily responsible for collecting target traffic from network links, performing rule matching, and distributing it. The DPI server, based on a general-purpose server platform, performs in-depth analysis of the distributed data streams, including protocol identification, content restoration, and log generation.
[0003] However, in existing solutions, the aggregation and splitter devices and DPI servers often need to be connected and coordinated through intermediate switching devices. This separate deployment architecture has the following problems: First, such systems usually occupy a large amount of computer room space and equipment resources, are complex to deploy, and have redundant wiring; second, due to the physical and logical independence of the two devices, the linkage capabilities between the systems are limited, resulting in cumbersome configuration and low coordination efficiency; third, the introduction of intermediate links also increases the system's failure points and security risks, affecting the overall stability and reliability; in addition, the operation and maintenance and management of multiple heterogeneous devices require additional manpower and technical resources, which increases the system's operating costs. Summary of the Invention
[0004] In response to the shortcomings of the existing technology, the present application provides a traffic processing system, processing method and traffic processing cluster that integrates aggregation, diversion and deep packet inspection, which is at least used to solve the problems of high system complexity, waste of deployment resources, high operation and maintenance costs and lack of unified scheduling capabilities caused by the separation of aggregation and diversion equipment and DPI server deployment in the existing technology.
[0005] In order to achieve the above objectives and other advantages, some embodiments of the present application provide the following aspects:
[0006] In a first aspect, some embodiments of the present application provide a traffic processing system integrating aggregation, splitting, and deep packet inspection, including:
[0007] At least one convergence and distribution module, configured to receive mirrored traffic from a communication link and perform data screening, traffic replication, and distribution scheduling on the mirrored traffic;
[0008] At least one deep packet inspection module, configured to receive the target data stream output by the convergence and diversion module, and perform protocol parsing, content identification, and behavior log generation on the target data stream;
[0009] a backplane connection module, the backplane connection module being connected to the convergence and distribution module and the deep packet inspection module, respectively, and being used to provide a power connection and a physical communication channel for the convergence and distribution module and the deep packet inspection module, so as to realize data exchange and control signal transmission between the convergence and distribution module and the deep packet inspection module;
[0010] A logic control module is in communication with the backplane connection module and is used to uniformly schedule and control the operating status of the convergence and diversion module and the deep packet inspection module to achieve multi-module collaborative processing and centralized management.
[0011] In a second aspect, some embodiments of the present application further provide a traffic processing method integrating convergence, splitting, and deep packet inspection, the method being applied to any of the above-described traffic processing systems, the method comprising:
[0012] The service data flow of the communication core equipment is mirrored at the optical layer through the optical splitter to generate mirrored traffic;
[0013] Input the mirrored traffic to the input port of the convergence and shunting module, perform data screening, traffic replication and distribution scheduling through the convergence and shunting module, and forward the mirrored traffic to the corresponding deep packet inspection module through the output port of the convergence and shunting module;
[0014] In the deep packet inspection module, protocol parsing, content identification, and behavior log generation are performed on the received target traffic;
[0015] The generated log information is transmitted to the shared layer platform via optical fiber through the output port of the deep packet inspection module.
[0016] In a third aspect, some embodiments of the present application further provide a traffic processing cluster, comprising a plurality of traffic processing systems as described above, wherein the plurality of traffic processing systems are deployed in a cluster manner, interconnected with each other through a cluster management bus, and construct a cluster-level unified resource pool and a unified service interface through virtualization management logic, wherein the unified service interface is used to provide cluster-level data access, configuration management, and task scheduling services to upper-level business systems;
[0017] The traffic processing cluster includes:
[0018] A cluster control module, configured to collect and aggregate the operating status and resource load information of a plurality of the traffic processing systems, and to construct a resource status mapping relationship for abstract management;
[0019] The cluster scheduling module is used to select the optimal port resources and processing capacity resources from the unified resource pool according to the resource status mapping relationship and the preset traffic scheduling rules, and dynamically dispatch the received mirrored traffic to the selected traffic processing system for processing, so as to achieve unified scheduling and load balancing of cluster-level port resources and processing capacity.
[0020] Compared with related technologies, the solution provided in the embodiments of this application solves the problems of complex connection structure, redundant resource deployment, and decentralized scheduling and control caused by the physical separation of convergence and diversion equipment and DPI servers in the existing technology by constructing a unified traffic processing platform with integrated convergence and diversion and deep packet inspection functions. By integrating two types of key processing modules into the same platform, through the high-speed physical connection and unified control architecture of the backplane, this system can achieve more efficient data processing and scheduling capabilities and more reliable log reporting paths, which helps to improve the stability, maintainability and fault response speed of the system in complex application scenarios, reduce maintenance costs, improve overall operational efficiency, and form a highly integrated traffic processing solution with a compact structure, fast response, and stable operation. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other implementation methods can be obtained based on these drawings without paying any creative work.
[0022] Figure 1 This is a structural diagram of a traffic processing system integrating aggregation, diversion and deep packet inspection provided by an embodiment of the present application;
[0023] Figure 2 This is a flow chart of a traffic processing method integrating convergence, diversion and deep packet inspection provided by an embodiment of the present application;
[0024] Figure 3 This is a data flow diagram of a traffic processing system that integrates aggregation, diversion and deep packet inspection provided by an embodiment of the present application. DETAILED DESCRIPTION
[0025] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0026] First embodiment
[0027] The first embodiment of the present application relates to a traffic processing system integrating traffic aggregation, distribution, and deep packet inspection, including:
[0028] At least one convergence and diversion module is used to receive mirror traffic from the communication link and perform data screening, traffic replication, and distribution scheduling on the mirror traffic.
[0029] In this embodiment, the convergence and distribution module includes: a plurality of first input ports, a plurality of first output ports, a data screening unit, a traffic replication unit, a traffic label processing unit, and a distribution scheduling processing unit;
[0030] The plurality of first input ports are used to receive mirrored traffic from the plurality of communication links;
[0031] The data screening unit is used to screen the mirrored traffic based on a preset matching rule to extract a target data flow that meets the conditions, wherein the preset matching rule includes at least one of a protocol type, a source address, a destination address, a port number, and an application identifier;
[0032] The traffic replication unit is used to replicate the target data stream to support multi-channel parallel processing;
[0033] The traffic label processing unit is used to add label content representing the traffic scheduling policy to the target data flow;
[0034] The distribution scheduling processing unit is used to select a target output path from multiple first output ports according to the label content and the operating status of multiple deep packet inspection modules, and distribute the target data stream to the corresponding deep packet inspection module.
[0035] Reference Figure 1As shown, this traffic processing system adopts a modular architecture design, combined with functional zoning and interface standardization strategies to achieve a high-density, integrated device deployment structure. The convergence and diversion modules and deep packet inspection modules in the system are respectively implemented in the form of pluggable boards with independent functions, specifically including convergence and diversion boards and deep packet inspection processing boards (DPI processing boards). Each board can be installed in a standard slot inside the chassis, and power connections, high-speed communication channels and control signal channels are established through the system backplane, thereby building an integrated platform with unified power supply, high-speed interconnection and centralized scheduling capabilities. The dotted lines in the figure represent network communication interface connections, which are used to transmit control signals and operating status data, such as configuration instructions, status queries and alarm response signals between the logical control unit and each functional module; while the solid lines represent optical fiber physical connections, which are mainly used for high-speed transmission of mirrored data streams, such as the data interaction link between the convergence and diversion boards and the deep packet inspection processing boards. The entire traffic processing system supports multiple service slots, each of which can be flexibly populated with either a convergence and diversion board or a DPI processing board based on application requirements. This creates an N:M configurable distributed architecture, enabling customized load capacity and module resource allocation for different scenarios. For example, in a configuration with eight service slots, four slots are deployed with convergence and diversion boards for collecting and dispatching mirrored traffic, and the remaining four slots are deployed with DPI processing boards for deep protocol parsing and behavior log generation.
[0036] Based on this modular design, the system supports flexible configuration of multiple convergence and distribution boards and multiple deep packet inspection processing boards based on business needs, effectively adapting to network traffic processing scenarios of varying scale and complexity. Furthermore, this architecture offers excellent scalability and maintainability, supporting hot-swappable and dynamic reconfiguration modules, significantly improving system deployment efficiency, operational stability, and fault recovery capabilities. It provides a high-performance, scalable processing platform for deep traffic identification and behavior analysis in large-scale network environments.
[0037] The multiple first input ports of the aggregation and distribution module are used to receive mirrored traffic from different communication links (such as carrier network links, enterprise dedicated lines, or inter-IDC interconnection links). Mirrored traffic is typically generated by an upstream switch or network probe. The received mirrored traffic includes both upstream and downstream directions. The system divides and processes the traffic based on port logic or VLAN division to support direction-specific analysis.
[0038] The data screening unit is used to identify and screen the content of the received original mirrored traffic. It has an embedded multi-dimensional rule matching engine that can extract features from the five-tuple (protocol, source address, destination address, source port, destination port) and application identification field. System administrators can dynamically issue multi-dimensional rule matching strategies through the configuration interface, such as filtering out protocols with no business value such as DNS and ICMP, thereby retaining effective communication at the application layer such as HTTP / HTTPS. Its multi-dimensional rule matching strategy can include the joint application of regular expression rule matching mechanism and IP address whitelist / blacklist mechanism. Through regular expressions, matching patterns in protocol fields, application features or data content can be flexibly defined, thereby achieving accurate screening of diverse communication features; at the same time, combined with IP whitelist and blacklist configurations, rapid filtering and security control can be achieved based on source / destination addresses.
[0039] The traffic replication unit is used to perform one-to-many replication operations after validating a target data stream. For example, the system can simultaneously replicate and distribute the same filtered target data stream to multiple deep packet inspection modules, improving detection coverage and recognition accuracy, effectively handling complex protocol parsing and behavior recognition tasks.
[0040] Furthermore, the traffic replication unit supports on-demand replication policies and mirroring strength adjustment mechanisms. The on-demand replication policy allows for flexible configuration of the number of replicas based on service type or traffic priority. For example, high-priority or security-sensitive traffic can be configured with multiple redundant replicas to enhance detection and fault tolerance. For less sensitive traffic, only a single copy is forwarded to avoid resource waste, thereby achieving dynamic load regulation and optimal efficiency allocation of system resources.
[0041] The traffic label processing unit is used to add label content for scheduling and service identification to each copied target data stream. This label content can not only be used to indicate the scheduling policy, but also encapsulate service context parameters, such as service priority, industry category, data region, and whether it is sensitive information marked.
[0042] Furthermore, to improve label adaptability and scheduling accuracy, the system supports a dual-mode label generation mechanism. On the one hand, a rule-based static binding mechanism can directly generate labels based on predefined traffic characteristics (such as IP range, protocol type, port number, etc.); on the other hand, the system can also use a dynamic evaluation mechanism to adjust label content based on the current module load status, resource utilization, or real-time policy changes, so that the label is more consistent with the current system operating environment and scheduling objectives, thereby improving the accuracy and response efficiency of overall traffic processing.
[0043] The distribution scheduling unit is used to intelligently distribute target data streams based on label content and real-time operational status information from deep packet inspection modules. This real-time operational status information includes CPU utilization, memory usage, processing queue length, and congestion status indicators for each deep packet inspection module. Based on this real-time operational status information and the label content attached to the target data stream (such as priority and industry category), the distribution scheduling unit uses a software-based load balancing algorithm for dynamic distribution. Supported scheduling algorithms include round-robin scheduling, minimum connection count strategy, and minimum load strategy.
[0044] To accommodate deployment requirements of varying business scales, the convergence and distribution modules support on-demand expansion of the number of first input ports and first output ports. Input links and output paths can be bound and decoupled through a logical mapping table. The input and output ports on the convergence and distribution modules are often implemented based on standard Ethernet interfaces, and their speeds depend on the specific port type, such as 10G, 25G, 40G, and 100G Ethernet interfaces. The upper limit of each port's speed is determined by the PHY chip used and the electrical / optical port standard. For QSFP28 interfaces, it is typically 100G; for SFP+ interfaces, it is typically 10G; it can also support multi-speed adaptation, such as 10 / 25G.
[0045] At least one deep packet inspection module is used to receive the target data stream output by the convergence and diversion module, and perform protocol parsing, content identification and behavior log generation processing on the target data stream.
[0046] In this embodiment, the deep packet inspection module includes: at least one second input port, at least one second output port, a protocol parsing unit, a content identification unit, and a log generation unit;
[0047] The second input port is used to receive the target data stream distributed by the convergence and distribution module;
[0048] The protocol parsing unit is used to perform multi-layer protocol decoding operations on the target data stream to identify the type of network communication protocol carried in the target data stream and extract the corresponding application data content;
[0049] The content identification unit is used to restore the application data content to extract the application layer information objects contained therein and identify the communication behavior characteristics corresponding to the application layer information objects;
[0050] The log generation unit is used to generate structured log data based on the communication behavior characteristics, the structured log data including the communication session identifier, access time, source address, destination address, protocol type and content summary fields;
[0051] The second output port is used to upload structured log data to an external sharing layer platform.
[0052] Specifically, the deep packet inspection module is equipped with two 100G second input ports (high-speed input ports) for receiving target data streams output from the convergence and distribution modules to meet the requirements of deep inspection of large traffic flows. The deep packet inspection module is also equipped with two 10G second output ports (log output ports) for outputting log results to the shared layer platform. Due to the relatively small bandwidth requirements, 10G is usually sufficient for reporting performance.
[0053] The protocol parsing unit is used to perform multi-layer protocol decoding operations on the target data stream sent from the convergence and diversion module to the deep packet inspection module to achieve layered restoration and structured analysis of network communication content. Specifically, the protocol parsing unit parses the communication protocol fields carried in the target data packet layer by layer according to the hierarchical structure of the OSI model or the TCP / IP protocol stack. For the data link layer (such as the Ethernet layer), it extracts information such as the source / destination MAC address and Ethernet type field; for the network layer (such as the IP layer), it parses the source IP address, destination IP address, TTL, protocol type field, etc.; for the transport layer (such as the TCP / UDP layer), it extracts transmission control information such as the source port, destination port, sequence number, acknowledgment number, and flag bit; for the application layer, it further identifies high-level service protocols such as HTTP, HTTPS, SMTP, POP3, FTP, DNS, SSH, TLS, etc. based on the network communication protocol type of the transport layer. Through protocol parsing, it extracts the application data content carried by the application layer from the target data packet, including the application protocol header field and the business payload content it carries, for restoring user communication behavior, identifying access objects and content characteristics, etc.
[0054] The content identification unit further processes the application data extracted by the protocol parsing unit to restore application-layer information objects and identify communication behavior characteristics. This unit reconstructs the high-level business semantics of network communication through semantic understanding and feature analysis of the original application-layer data. Specifically, the content identification unit comprises a semantic restoration engine and a behavioral feature identification module. The semantic restoration engine performs semantic-level reconstruction of the payload content within the protocol parsing results, including extracting and identifying textual information, extracting image data, analyzing multimedia data fragments, and restoring software file data. The semantic restoration engine supports format recognition, content decompression, and encoding parsing, ensuring the integrity of the content for structured analysis before distribution and processing. The behavioral feature identification module further performs pattern matching on the restored application-layer information objects against a pre-set communication behavior feature library to identify the presence of specific communication behavior characteristics during the communication process. Communication behavior characteristics include user login behavior, sensitive information transmission, illegal resource access, and data outbound communication.
[0055] The log generation unit is used to perform structured recording processing on the identified communication behavior features to form standardized log data that can be used for analysis and auditing. Based on the behavior recognition results output by the content recognition unit, the log generation unit uniformly encodes and fields the communication metadata and behavior features in accordance with the preset log format specifications. The generated structured log data includes the following field information: communication session identifier (used to uniquely identify a complete session process), access time (records the time point or time interval when the communication behavior occurs), source address and destination address (including source IP, source port, destination IP, destination port), protocol type (records the identified application layer protocol type), behavior content summary field (used to describe the core feature content of the communication behavior). The log generation unit can support multiple output formats (such as JSON, XML, CSV, etc.) to adapt to the access requirements of different log systems. The generated structured log data can be uploaded to an external shared layer platform through the second output port. The shared layer platform may include a security information and event management system, an audit analysis platform, a log archiving system, etc.
[0056] The backplane connection module is connected to the convergence and diversion module and the deep packet inspection module respectively, and is used to provide power connection and physical communication channel for the convergence and diversion module and the deep packet inspection module to realize data interaction and control signal transmission between the convergence and diversion module and the deep packet inspection module.
[0057] In this embodiment, the backplane connection module includes: a plurality of card slots, a high-speed communication bus, and a control signal channel;
[0058] Each card slot establishes power supply connection and high-speed data communication connection with the aggregation and distribution module or deep packet inspection module through a dedicated plug-in port;
[0059] High-speed communication bus, which connects multiple card slots and is used to transmit mirrored data streams between the aggregation and distribution modules and the deep packet inspection module;
[0060] The control signal channel is used to establish a two-way communication link between the logic control module and the aggregation and distribution module or the deep packet inspection module to transmit operation control instructions, module status query requests, feedback response signals and fault alarm information.
[0061] Specifically, multiple card slots are located within the system chassis, housing either convergence and distribution modules or deep packet inspection modules. Each card slot is equipped with a dedicated connector corresponding to the functional module. These connectors utilize a separate wiring structure for power pins and high-speed communication pins, enabling automatic power connection and initialization of high-speed communication channels upon module insertion.
[0062] A high-speed communication bus is used to establish a high-speed data exchange path between multiple card slots. This communication bus connects the aggregation and distribution modules with the deep packet inspection module, supporting low-latency, high-bandwidth transmission of mirrored data streams between different modules. Preferably, the communication bus can use PCIe, SRIO, InfiniBand, or a customized backplane interconnect protocol to meet the throughput requirements of high-density data flow processing scenarios.
[0063] The control signal channel establishes a bidirectional communication link between the logic control module and each convergence and distribution module or deep packet inspection module to achieve centralized system-level scheduling and control. This channel supports the transmission of various types of control signals, such as operation control instructions such as start, pause, and parameter refresh; status query requests for module operation status and resource utilization; module response information such as status feedback and execution confirmation; and fault alarm information such as link interruption, module anomaly, and data retention.
[0064] The design of the backplane connection structure enables seamless integration between functional modules, hot-swap support, and highly reliable data and control signal exchange, providing hardware foundation support for the modular deployment, centralized management, and high-availability operation of this system.
[0065] The logic control module is in communication with the backplane connection module and is used to uniformly schedule and control the operating status of the convergence and diversion modules and the deep packet inspection module to achieve multi-module collaborative processing and centralized management.
[0066] In this embodiment, the status monitoring unit is used to periodically obtain the operating status information of the convergence and distribution module and the deep packet inspection module;
[0067] A fault detection unit is used to compare the operating status information with a preset fault threshold to determine whether there is an abnormality in the convergence and distribution module or the deep packet inspection module, and trigger an alarm signal when an abnormality is detected;
[0068] The task scheduling unit is used to dynamically adjust the load distribution strategy of the target data flow according to the operation status information to achieve dynamic balancing of system-level resources and traffic scheduling optimization;
[0069] The configuration interface unit is used to receive system configuration instructions issued by the external configuration platform and synchronously distribute the corresponding parameters to the convergence and distribution module and the deep packet inspection module to achieve unified configuration management.
[0070] Specifically, the status monitoring unit is used to periodically collect and monitor the operating status of each convergence and diversion module and deep packet inspection module in the traffic processing system. It can actively initiate a status query instruction to each module at a preset time interval, or passively receive the status feedback signal reported by the module. The operating status information includes: the on-off status used to determine whether the physical link of each input and output port remains connected; the port rate information reflecting the current link transmission rate and bandwidth utilization; the CPU utilization rate used to measure the computing resource usage of the processing unit inside the module; the memory utilization rate of the monitoring module memory resource usage status; the data processing queue length used to determine whether the module currently has data backlog or congestion; the cache usage status used to evaluate the cache occupancy ratio and read and write efficiency, etc.
[0071] The fault detection unit is used to determine in real time whether there are potential faults or performance anomalies in the traffic processing system based on the operating status information obtained by the status monitoring unit. For example, if the CPU utilization or memory usage of a convergence and distribution module or deep packet inspection module consistently exceeds the set threshold, the module is deemed overloaded. If the data processing queue length or cache usage exceeds the safety limit, the data flow is deemed congested or delayed. If the fault detection unit determines that a module or link is abnormal, it immediately triggers the internal alarm mechanism and generates a corresponding fault alarm signal.
[0072] In addition, the fault detection unit can report abnormal information to the system management platform for reference by upper-level business or operation and maintenance systems; it can also automatically call backup paths or idle modules according to configuration policies to perform fault avoidance and load transfer operations to ensure that the system's overall traffic processing tasks are not interrupted.
[0073] The task scheduling unit collects operational status parameters from each system module through the status monitoring unit. These include the traffic rate, cache utilization, and queue depth of the first output port of each convergence and distribution module, as well as the CPU utilization, memory usage, processing queue length, interface connectivity, and number of current tasks of each deep packet inspection module. This operational status information is normalized and weighted to construct a real-time load assessment model, which comprehensively reflects the load and processing capacity limits of each module in the system.
[0074] On this basis, the task scheduling unit performs policy matching and load decision-making according to system-preset or dynamically issued scheduling algorithm rules. It can adopt a minimum load priority strategy, targeting the deep packet inspection module with the lowest current load score as the target for data flow delivery. Alternatively, it can adopt a weighted round-robin strategy, dynamically adjusting the distribution frequency of each module based on its processing capacity and current load distribution. Furthermore, it supports capacity-aware scheduling. When a module's load approaches a preset threshold (e.g., CPU utilization exceeding 85%), it temporarily removes it from the task distribution path and switches to an idle module or one configured as a hot standby for replacement processing. Once the above scheduling strategy is determined, the task scheduling unit sends control instructions to the convergence and diversion modules to adjust the output path selection mechanism of the distribution scheduling processing unit. It also modifies the traffic label content to indicate the address or number of the new target deep packet inspection module, ensuring that the target data flow is distributed and transmitted along the optimized path. During operation, if the system encounters a module anomaly, link interruption, or performance bottleneck, the task scheduling unit can also trigger a fault avoidance mechanism, suspending task distribution to the anomalous module, enabling an alternative path, or temporarily limiting non-critical traffic.
[0075] The configuration interface unit is used to receive system configuration instructions issued by an external configuration platform (such as a system management system, operation and maintenance terminal, etc.). The configuration interface unit supports multiple communication protocols (such as NetConf, SNMP, RESTful API, etc.), parses and executes various configuration parameters in the system configuration instructions, such as protocol filtering rules, load scheduling strategies, alarm threshold settings, log level control, etc., and synchronously distributes relevant configuration parameters to various aggregation and distribution modules and deep packet inspection modules to achieve centralized and automated system configuration management.
[0076] Furthermore, the logic control module also includes:
[0077] The module identification unit is used to identify the module type by reading the module identification code or detecting the port level status when the convergence and distribution module or the deep packet inspection module is inserted into the corresponding card slot;
[0078] The parameter initialization unit is used to load the communication protocol parameters, link rate parameters and processing capacity parameters corresponding to the module type from the preset configuration parameter library, and perform an automatic initialization process on the aggregation and distribution module or the deep packet inspection module.
[0079] Specifically, the module identification unit is used to automatically identify the module type when the convergence and diversion module or deep packet inspection module is inserted into the corresponding board slot in the system chassis. The module identification process can be carried out by reading the unique identification code stored in the module (such as the device information in the EEPROM chip) or detecting the level status of the slot port to achieve rapid determination and registration of the module type. This identification mechanism helps the system dynamically perceive the composition of the currently deployed modules. After the module type identification is completed, the parameter initialization unit is used to retrieve the initialization parameters that match the module type from the preset configuration parameter library, including communication protocol parameters (such as supported L2 / L3 protocol types), link rate parameters (such as 10G / 40G / 100G), and processing capacity parameters (such as the maximum number of concurrent flows, throughput, cache capacity, etc.). After loading the corresponding parameters, the system automatically sends initialization instructions to the target module to complete the necessary communication handshake, port configuration and status synchronization, thereby ensuring that the newly inserted module can smoothly access the overall traffic processing process without interrupting the normal operation of the system.
[0080] Furthermore, the logic control unit is configured with a distribution path mapping table for recording the data distribution path relationship between each convergence and diversion module and one or more deep packet inspection modules;
[0081] When any deep packet inspection module fails or is unavailable, the logic control unit redirects the target data stream originally distributed to the deep packet inspection module to other deep packet inspection modules that are idle or within the load receiving range according to the distribution path mapping table.
[0082] Specifically, to improve the system's fault tolerance and continuous service capabilities in the event of module failure or reduced processing power, in this embodiment, the logical control unit is configured with a distribution path mapping table. This mapping table is used to record the data distribution path relationship between each convergence and distribution module and its corresponding one or more deep packet inspection modules. This mapping table is automatically generated by the system based on the initial deployment structure and is dynamically maintained during operation based on module hot plugging, configuration updates, or changes in operating status.
[0083] During system operation, if the logical control unit detects that any DPI module has failed (e.g., a link is down, CPU utilization exceeds the limit, or a response timeout occurs) or becomes unavailable, the logical control unit automatically identifies the target data flow path originally distributed to that module based on the distribution path mapping table and queries other DPI modules that are idle or whose load is within acceptable range. The logical control unit then redirects the target data flow, forwarding it to an alternative module in a timely manner to avoid data processing interruption.
[0084] During the redirection process, the logic control unit automatically adjusts the data path based on a variety of distribution optimization strategies, including least-load priority (which prioritizes the module with the lowest current processing load), round-robin (which distributes traffic in a fixed order), and failover priority (which attempts alternate paths based on a preset module priority order). These distribution optimization strategies allow the system to make informed choices among the multiple available deep packet inspection modules, ensuring efficient redirection.
[0085] In addition, to adapt to dynamic changes in system status, the logical control unit further supports real-time modification and updating of the distribution path mapping table, including adding new mapping relationships, deleting invalid paths, or adjusting the priority parameters of existing paths, thereby achieving adaptive optimization of the distribution path.
[0086] Therefore, when the system encounters events such as module failure, software and hardware upgrades, configuration changes, or temporary offline events, it can automatically adjust the data flow forwarding path without interruption, effectively avoiding the impact of abnormal modules on the overall business process.
[0087] Second embodiment
[0088] The second embodiment of the present application relates to a traffic processing method that integrates convergence and diversion with deep packet inspection, which is applied to the traffic processing system as described in the first embodiment. The method can be used to complete the deep processing process of mirroring, identifying, restoring and log reporting of business traffic in the communication core network without interfering with the main communication path. Figure 2 As shown, the method may include the following steps:
[0089] Step S1: The service data flow of the communication core device is mirrored at the optical layer through the optical splitter to generate mirrored traffic;
[0090] Step S2: Input the mirrored traffic to the input port of the convergence and diversion module, perform data screening, traffic replication and distribution scheduling through the convergence and diversion module, and forward the mirrored traffic to the corresponding deep packet inspection module through the output port of the convergence and diversion module;
[0091] Step S3: performing protocol parsing, content identification, and behavior log generation on the received target traffic in the deep packet inspection module;
[0092] Step S4: The generated log information is transmitted to the shared layer platform via optical fiber through the output port of the deep packet inspection module.
[0093] Specifically, refer to Figure 3As shown, the service traffic carried by the core devices NE1 and NE2 in the communication network (key data exchange nodes deployed in the target network environment, which can be core routers, switches or service gateways, etc.) is first mirrored at the optical layer through an optical splitter set between the main links. The optical splitter is used to non-destructively separate the passing data optical signal, thereby generating a mirrored traffic that is completely consistent with the original data content. The mirrored traffic retains the complete message structure and application layer payload information of the original traffic, including the Ethernet frame header, IP header field, transport layer information (such as TCP / UDP port number) and application layer protocol content (such as HTTP request, DNS query, SMTP email content, etc.). The mirroring process does not interfere with the main link communication, ensuring that the actual running traffic in the network can be synchronously perceived and copied without affecting the service transmission performance.
[0094] After the mirrored data stream is mirrored by the optical splitter, it is input to the input ports (I1 and I2) of the convergence and diversion modules through optical fiber links. After the convergence and diversion modules receive the mirrored traffic, the data screening unit first performs a rule-based screening operation to retain only the target data stream that requires further analysis. After the screening is completed, the target data stream is sent to the traffic replication unit for one-to-many replication. The replicated data stream is attached with a label representing the scheduling policy by the traffic label processing unit. The distribution scheduling processing unit then selects the distribution path based on the label content and the current load status of each module in the system. Finally, the processed target data stream is output through the output ports (O1 and O2) of the convergence and diversion modules and sent to the input ports (G1 and G2) of the corresponding deep packet inspection modules, forming high-bandwidth physical interconnection paths O1→G1 and O2→G2.
[0095] The target data stream is input to the deep packet inspection module via optical fiber. The protocol parsing unit performs multi-layer protocol decoding, parsing the Ethernet layer, IP layer, transport layer (TCP / UDP), and application layer protocols (HTTP, SMTP, FTP, etc.), and extracting the application data content from the application layer. The content identification unit performs semantic restoration on the application data content, identifying and extracting information objects such as text, images, audio, and executable files. Simultaneously, it uses a rule library to match behavioral features, identifying, for example, login operations, sensitive data leakage, and abnormal communications. The parsing and identification results are ultimately passed to the log generation unit, which generates structured log data including source / destination addresses, access time, protocol type, and communication summaries. This structured log data is output through the output ports (T1 and T2) in the deep packet inspection module and uploaded to an external shared layer platform via optical fiber links. This shared layer platform can be a locally deployed security management system, log server, or cloud data center, supporting log indexing, auditing, compliance analysis, behavior tracking, and attack detection. The multi-path reporting design of the T1 / T2 interface can enhance the redundancy and real-time performance of log data upload, ensuring stable output capabilities in high-concurrency processing scenarios.
[0096] Furthermore, the traffic processing method supports the combined deployment of multiple convergence and diversion modules and multiple deep packet inspection modules, specifically including:
[0097] Receive uplink and downlink mirror data streams from multiple communication links and input them to the input ports of multiple convergence and distribution modules respectively;
[0098] In each convergence and distribution module, rule matching operations are performed on the received mirrored data streams to filter out target data streams that meet the conditions;
[0099] Perform lightweight protocol identification and preliminary classification processing on the target data flow to determine the protocol type and service attributes of the target data flow;
[0100] Aggregate multiple target data streams based on their protocol type and service attributes, and send them to the deep packet inspection module through a configurable number of output ports.
[0101] Based on the preset scheduling strategy or real-time business load information in the logical control unit, the distribution path between each convergence and distribution module and each deep packet inspection module is dynamically adjusted.
[0102] Specifically, the system supports simultaneous collection of mirrored upstream and downstream traffic from multiple communication links (such as those formed by multiple core devices or distributed switching nodes). After processing through multiple optical splitters, the mirrored data streams are fed into the input ports of multiple convergence and diversion modules deployed within the system, enabling multi-source parallel access.
[0103] Each convergence and diversion module performs policy-rule matching on the received mirrored data streams to filter out target data streams requiring deep inspection. To improve front-end screening efficiency, the system integrates lightweight protocol identification and service attribute determination functions within the convergence and diversion modules. This allows for rapid protocol stack analysis of the filtered target data streams to determine the protocol type (e.g., HTTP, DNS, SMTP, etc.) and service attributes (e.g., video streaming, file transfer, remote login, etc.). This processing does not perform a full deep recovery and is primarily used for primary classification.
[0104] Based on the above identification results, the system can classify and aggregate the target data streams from multiple input ports according to business attributes, and then through one or more relatively small number of output ports configurable in each aggregation and diversion module, the number of output ports is less than the number of the first input ports. For example, the target data streams from multiple input channels can be centrally scheduled to 1, 2 or a relatively small number of output channels according to the label content and load status, so as to distribute the data streams to one or more back-end deep packet inspection modules.
[0105] During system operation, the logical control unit dynamically assesses the load distribution and efficiency of the current distribution path based on preset scheduling strategies or module load information obtained through status monitoring. It also adjusts the path mapping relationship between each convergence and diversion module and the deep packet inspection module. Scheduling strategies can adopt methods such as minimum load first, label mapping diversion, and weighted polling to ensure balanced and stable data distribution between different modules, while also enhancing the system's responsiveness to sudden traffic and high-priority services.
[0106] Furthermore, when a hot plug event of inserting, replacing, or removing the convergence and distribution module or the deep packet inspection module is detected, the traffic processing method further includes:
[0107] The logic control unit automatically identifies the module state change corresponding to the hot plug event;
[0108] Dynamically update the distribution path mapping table of the logic control unit and re-establish the data distribution path relationship between the convergence and distribution module and the deep packet inspection module;
[0109] Based on the updated distribution path mapping table, the forwarding path of the target data flow is adjusted to ensure that the hot plug event does not interrupt the overall traffic processing task of the system.
[0110] Specifically, when the system detects that the slot status of a module has changed, that is, when a module is inserted, replaced, or removed, the logic control unit first automatically identifies the type of module status change corresponding to the event through the module identification mechanism, including module type, slot position, whether it is a new addition or replacement, etc. After the identification is completed, the logic control unit will dynamically update the internally maintained distribution path mapping table based on the current system operation status and module layout, and adjust or rebuild the data flow distribution path relationship between the original convergence and diversion module and the deep packet inspection module in real time. This update process supports automatic triggering according to module status changes without manual intervention. Subsequently, the system will re-plan the forwarding path of the target data stream based on the updated distribution path mapping table to ensure that the data stream is correctly distributed to the effective deep packet inspection module.
[0111] Furthermore, when a convergence and diversion module or deep packet inspection module is removed and replaced by a new one, the system redirects the unfinished traffic processing tasks on the replaced module to the newly inserted module and synchronizes the associated context information (such as traffic labels, status tags, session tracking information, etc.), thereby achieving seamless handover of traffic processing. This task migration mechanism effectively improves the system's business continuity and seamless recovery capabilities during operations such as module upgrades and fault replacements, ensuring that the overall traffic processing tasks are not interrupted during the hot swap process and do not affect the accuracy of analysis results.
[0112] Example 3
[0113] A third embodiment of the present application relates to a traffic processing cluster, comprising a plurality of traffic processing systems as described in the first embodiment. The plurality of traffic processing systems are deployed in a cluster manner, interconnected by a cluster management bus, and construct a cluster-level unified resource pool and a unified service interface through virtualization management logic. The unified service interface is used to provide cluster-level data access, configuration management, and task scheduling services to upper-layer business systems.
[0114] The traffic processing cluster includes:
[0115] The cluster control module is used to collect and aggregate the operating status and resource load information of multiple traffic processing systems and build resource status mapping relationships for abstract management;
[0116] The cluster scheduling module is used to select the optimal port resources and processing capacity resources from the unified resource pool based on the resource status mapping relationship and preset traffic scheduling rules, and dynamically dispatch the received mirrored traffic to the selected traffic processing system for processing, so as to achieve unified scheduling and load balancing of cluster-level port resources and processing capacity.
[0117] Specifically, the traffic processing cluster consists of multiple traffic processing systems, as described in Example 1. Each traffic processing system is deployed in a cluster and interconnected via a cluster management bus. Building on this physical interconnection and logical coordination, the system further establishes a unified cluster-level resource scheduling and management mechanism.
[0118] To achieve flexible scheduling and dynamic load distribution of resources within the cluster, this embodiment introduces virtualization management logic at the logical architecture layer to abstract and uniformly manage key resources (such as processing capabilities and interface resources) in multiple physical traffic processing systems, thereby building a unified cluster resource pool and a unified service interface. Among them, key resources include but are not limited to: the analysis and processing capabilities of the deep packet inspection module; the access bandwidth and input and output capabilities of the aggregation and diversion module; the scheduling path capacity of the integrated switching processing module; interface resources (including input ports, output ports, and link channels); and the operating status information of each node. The above-mentioned key resources are modeled as measurable and schedulable virtual resource entities in the virtualization management logic. Each type of resource has a unified attribute description, capability label, and scheduling interface. Through the unified modeling mechanism, resources distributed in multiple physical traffic processing systems can be incorporated into a centralized cluster resource pool for dynamic management and unified call. The resource pool supports real-time updates of resource status, unified perception of distribution status, and on-demand scheduling. It can dynamically adjust resource allocation plans based on task requirements, operating status, or policy instructions, achieving optimal matching of cross-node resources and flexible and elastic expansion of cluster-level service capabilities. The unified service interface provides standardized access capabilities for upper-level business systems, supporting cluster-level data collection and access, policy configuration and distribution, task scheduling and control, and other functional interfaces, thereby improving the system's external service consistency and horizontal expansion capabilities.
[0119] The traffic processing cluster specifically includes the following functional modules: a cluster control module periodically collects operational status information and resource load information from multiple traffic processing systems to enable real-time perception and dynamic management of the cluster's internal resource status. This operational status information and resource load information include, but are not limited to, key operational indicators such as port utilization, processing latency, cache depth, module temperature, and fault status for the convergence and distribution modules, integrated switching processing modules, and deep packet inspection modules in each system. Based on the collected results, the cluster control module constructs a resource status mapping relationship for resource scheduling. Specifically, according to preset logical identification rules and mapping models, the operational status information and resource load information collected from each physical traffic processing system are uniformly mapped to a cluster-level logical resource identification system. The logical resource identification system can perform multi-level encoding and classification based on dimensions such as resource type (e.g., processing capacity, link bandwidth, port status), resource location (e.g., node number, slot number), and resource status (e.g., utilization, health), thereby achieving abstract expression and standardized representation of heterogeneous resources across nodes.
[0120] According to different trigger conditions (such as system initialization, new node joining, new task policy issuance or node load change, node failure, link abnormality, etc.), the cluster scheduling module is used to dynamically select the current optimal port resources and processing capacity resources from the unified resource pool based on the resource status mapping relationship constructed by the cluster control module and the preset global traffic scheduling rules, and distribute the received mirrored traffic to the target traffic processing system.
[0121] Mirrored traffic can be accessed and directed to the target node in two ways: The upper-layer access module (such as the cluster ingress switch) uniformly receives the mirrored traffic and transfers it to the cluster scheduling module for centralized scheduling and target system assignment; or the distributed edge access module directly directs the mirrored traffic to the selected traffic processing system based on the scheduling strategy and internal routing protocol (such as virtual address identification or logical path encoding based on the cluster). The scheduling process can comprehensively consider multiple dimensions (such as the resource utilization of each physical node, the scheduling path delay and bandwidth share of data transmission, and the historical performance of each traffic processing system) to achieve cluster-level port resource reuse, processing task sharing, and overall load balancing.
[0122] Compared with related technologies, the solution provided by the embodiment of the present application realizes the abstract modeling and unified management of processing resources, port resources and switching path resources by deploying multiple physical traffic processing systems in a cluster manner and introducing a cluster management bus and virtualization management logic, thereby building a cluster-level unified resource pool and a unified service interface. The system can periodically collect the operating status and load information of each processing node through the cluster control module, and build a resource status mapping relationship to provide a real-time scheduling basis for the cluster scheduling module. During the scheduling process, the system can dynamically select the optimal port and processing capacity resources from the resource pool based on multi-dimensional indicators such as current task requirements, node load and historical performance, complete the precise allocation of mirrored traffic, and achieve cross-node load balancing and optimal resource utilization. It effectively improves the scalability, scheduling flexibility and processing efficiency of the system, and adapts to the network traffic processing needs in large-scale, high-concurrency and complex business scenarios.
[0123] The step division of the above various methods is only for the purpose of clear description. During implementation, they can be combined into one step or some steps can be split and decomposed into multiple steps. As long as they include the same logical relationship, they are all within the scope of protection of this application; adding insignificant modifications or introducing insignificant designs to the algorithm or process without changing the core design of the algorithm and process are all within the scope of protection of this application.
[0124] The flowcharts or block diagrams in the accompanying drawings illustrate the possible architectures, functions and operations of the devices, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, program segment or part of code, and the module, program segment or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, as well as the combination of boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-specific system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0125] The scope of this application is defined by the appended claims rather than the foregoing description and is therefore intended to encompass within this application all changes that come within the meaning and range of equivalents of the claims. Any reference signs in the claims should not be construed as limiting the claims to which they relate. In addition, it is clear that the word "comprising" does not exclude other units or steps, and the singular does not exclude the plural. Multiple units or devices stated in a device claim may also be implemented by one unit or device through software or hardware. Words such as "first" and "second" are only used to distinguish the description and do not indicate any particular order, nor should they be understood as indicating or implying relative importance.
[0126] The above descriptions are merely specific embodiments of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art may easily propose variations or substitutions within the technical scope disclosed in the present application, and such variations or substitutions shall be encompassed within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be subject to the scope of protection of the claims, and the above descriptions shall be regarded as exemplary and non-limiting.
Claims
1. A traffic processing system integrating convergence, diversion and deep packet inspection, characterized in that: include: At least one convergence and distribution module, configured to receive mirrored traffic from a communication link and perform data screening, traffic replication, and distribution scheduling on the mirrored traffic; At least one deep packet inspection module, configured to receive the target data stream output by the convergence and diversion module, and perform protocol parsing, content identification, and behavior log generation on the target data stream; a backplane connection module, the backplane connection module being connected to the convergence and distribution module and the deep packet inspection module, respectively, and being used to provide a power connection and a physical communication channel for the convergence and distribution module and the deep packet inspection module, so as to realize data exchange and control signal transmission between the convergence and distribution module and the deep packet inspection module; A logic control module is in communication with the backplane connection module and is used to uniformly schedule and control the operating status of the convergence and diversion module and the deep packet inspection module to achieve multi-module collaborative processing and centralized management.
2. The flow processing system according to claim 1, characterized in that: The convergence and distribution module includes: a plurality of first input ports, a plurality of first output ports, a data screening unit, a traffic replication unit, a traffic label processing unit, and a distribution scheduling processing unit; The plurality of first input ports are configured to receive mirrored traffic from a plurality of communication links; The data screening unit is used to screen the mirrored traffic based on a preset matching rule and extract a target data stream that meets the conditions, wherein the preset matching rule includes at least one of a protocol type, a source address, a destination address, a port number, and an application identifier; The traffic replication unit is used to replicate the target data flow to support multi-channel parallel processing; The traffic label processing unit is used to add label content representing the traffic scheduling policy to the target data flow; The distribution scheduling processing unit is used to select a target output path from the multiple first output ports according to the label content and the operating status of the multiple deep packet inspection modules, and distribute the target data stream to the corresponding deep packet inspection module.
3. The flow processing system according to claim 1, characterized in that: The deep packet inspection module includes: at least one second input port, at least one second output port, a protocol parsing unit, a content identification unit, and a log generation unit; The second input port is used to receive the target data stream distributed by the convergence and distribution module; The protocol parsing unit is used to perform a multi-layer protocol decoding operation on the target data stream to identify the type of network communication protocol carried in the target data stream and extract the corresponding application data content; The content identification unit is used to restore the application data content to extract the application layer information object contained therein and identify the communication behavior characteristics corresponding to the application layer information object; The log generating unit is used to generate structured log data based on the communication behavior characteristics, and the structured log data includes a communication session identifier, an access time, a source address, a destination address, a protocol type, and a content summary field; The second output port is used to upload the structured log data to an external sharing layer platform.
4. The flow processing system according to claim 1, characterized in that: The backplane connection module includes: multiple card slots, a high-speed communication bus and a control signal channel; Each of the card slots establishes a power supply connection and a high-speed data communication connection with the convergence and distribution module or the deep packet inspection module through a dedicated plug-in port; A high-speed communication bus connected to the plurality of card slots and configured to transmit the mirrored data stream between the convergence and distribution module and the deep packet inspection module; The control signal channel is used to establish a two-way communication link between the logic control module and the convergence and diversion module or the deep packet inspection module to transmit operation control instructions, module status query requests, feedback response signals and fault alarm information.
5. The flow processing system according to claim 1, characterized in that: The logic control module includes: A status monitoring unit, configured to periodically obtain operating status information of the convergence and distribution module and the deep packet inspection module; a fault detection unit, configured to compare the operating status information with a preset fault threshold to determine whether an abnormality occurs in the convergence and distribution module or the deep packet inspection module, and trigger an alarm signal when an abnormality is detected; A task scheduling unit, configured to dynamically adjust the load distribution strategy of the target data flow according to the operation status information, so as to achieve dynamic balancing of system-level resources and traffic scheduling optimization; The configuration interface unit is used to receive system configuration instructions issued by an external configuration platform and synchronously distribute corresponding parameters to the convergence and distribution module and the deep packet inspection module to achieve unified configuration management.
6. The flow processing system according to claim 1, characterized in that: The logic control module also includes: A module identification unit, configured to identify the module type by reading the module identification code or detecting the port level status when the convergence and distribution module or the deep packet inspection module is inserted into the corresponding card slot; A parameter initialization unit is used to load the communication protocol parameters, link rate parameters and processing capacity parameters corresponding to the module type from a preset configuration parameter library, and perform an automatic initialization process on the convergence and diversion module or the deep packet inspection module.
7. The flow processing system according to claim 1, characterized in that: The logic control unit is configured with a distribution path mapping table for recording the data distribution path relationship between each of the convergence and distribution modules and one or more of the deep packet inspection modules; When any deep packet inspection module fails or is unavailable, the logic control unit redirects the target data stream originally distributed to the deep packet inspection module to other deep packet inspection modules that are in an idle state or within the load receiving range according to the distribution path mapping table.
8. A traffic processing method integrating convergence, diversion and deep packet inspection, characterized in that: The method is applied to the traffic processing system according to any one of claims 1 to 7, and the method includes: The service data flow of the communication core equipment is mirrored at the optical layer through the optical splitter to generate mirrored traffic; Input the mirrored traffic to the input port of the convergence and shunting module, perform data screening, traffic replication and distribution scheduling through the convergence and shunting module, and forward the mirrored traffic to the corresponding deep packet inspection module through the output port of the convergence and shunting module; In the deep packet inspection module, protocol parsing, content identification, and behavior log generation are performed on the received target traffic; The generated log information is transmitted to the shared layer platform via optical fiber through the output port of the deep packet inspection module.
9. The traffic processing method according to claim 8, characterized in that: The method supports the combined deployment of multiple convergence and diversion modules and multiple deep packet inspection modules, specifically including: Receiving uplink and downlink mirror data streams from multiple communication links and inputting them into the input ports of the multiple convergence and distribution modules respectively; In each of the convergence and distribution modules, a rule matching operation is performed on the received mirror data stream to filter out target data streams that meet the conditions; Performing lightweight protocol identification and preliminary classification processing on the target data flow to determine the protocol type and service attributes of the target data flow; Aggregate multiple target data streams according to the protocol type and service attributes of the target data streams, and send them to the deep packet inspection module through a configurable number of output ports; Based on the preset scheduling strategy or real-time business load information in the logical control unit, the distribution path between each convergence and distribution module and each deep packet inspection module is dynamically adjusted.
10. A traffic processing cluster, characterized in that: comprising a plurality of traffic processing systems according to claims 1 to 7, wherein the plurality of traffic processing systems are deployed in a cluster manner, interconnected with each other through a cluster management bus, and construct a cluster-level unified resource pool and a unified service interface through virtualization management logic, wherein the unified service interface is used to provide cluster-level data access, configuration management, and task scheduling services to upper-layer business systems; The traffic processing cluster includes: A cluster control module, configured to collect and aggregate the operating status and resource load information of a plurality of the traffic processing systems, and to construct a resource status mapping relationship for abstract management; The cluster scheduling module is used to select the optimal port resources and processing capacity resources from the unified resource pool according to the resource status mapping relationship and the preset traffic scheduling rules, and dynamically dispatch the received mirrored traffic to the selected traffic processing system for processing, so as to achieve unified scheduling and load balancing of cluster-level port resources and processing capacity.