Message detection method and device and computer readable storage medium
By directly performing message detection in the shared memory area of the message transmission module, the problem of low detection efficiency caused by waste of computer memory resources is solved, and more efficient message detection is achieved.
Patent Information
- Application Number
- CN202510989717.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-17
- Publication Date
- 2025-09-30
AI Technical Summary
In the prior art, there is a problem of wasting computer memory resources during message detection, resulting in low detection efficiency.
By sharing a memory area between the first memory and the second memory of the message transmission module, the message detection module directly reads the storage address of the target message from the second memory for detection, thereby avoiding unnecessary data copying and memory waste.
It improves the efficiency of message detection, simplifies system design and management, and enhances processing speed and response capabilities.
Smart Images

Figure CN120729604A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing, and in particular to a message detection method, device and computer-readable storage medium. Background Art
[0002] Packet inspection is crucial for ensuring network communication security, data integrity, and compliance, timely detecting and preventing potential threats and anomalous behavior, and ensuring stable system operation and business continuity. Currently, the primary approach is to use the IPS / IDS inspection engine as a subsidiary process of the DPDK process, utilizing the shared memory mechanism provided by the DPDK suite to copy packets and pass them to the IPS / IDS engine for inspection. However, this approach wastes computer memory and computing resources, resulting in low packet inspection efficiency.
[0003] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention
[0004] The embodiments of the present invention provide a message detection method, device and computer-readable storage medium to at least solve the technical problem in the related art that when detecting messages, computer memory resources are wasted, resulting in low message detection efficiency.
[0005] According to one aspect of an embodiment of the present invention, a message detection method is provided, including: reading a storage address of a target message from a first memory, wherein the storage address is the address of the target message in a second memory, the first memory and the second memory are areas in a message transmission module that at least a message detection module is allowed to access, the message transmission module is used to receive the target message, store the target message in the second memory, and determine the storage address corresponding to the target message in the second memory, and store the storage address in the first memory; detect the target message stored in the storage address in the second memory to obtain a message detection result.
[0006] Optionally, before reading the storage address of the target message from the first memory, it also includes: sending a connection request to the message transmission module; receiving response information fed back by the message transmission module, wherein the response information includes the first thread number of the message transmission thread in the message transmission module and the memory address of the first memory in the message transmission module; determining the second thread number of the message detection thread in the message detection module based on the response information; determining a third thread number of target transmission queue groups from a plurality of to-be-selected transmission queue groups based on the first thread number and the second thread number, so as to transmit the message information between the corresponding message transmission thread and the corresponding message detection thread through the corresponding target transmission queue group, so that the corresponding message transmission module and the corresponding message detection thread are transmitted one-to-one, wherein the third thread number is the smaller number between the first thread number and the second thread number, and the message information is the storage address and message detection result corresponding to the target message.
[0007] Optionally, the target message stored in the storage address in the second memory is detected to obtain a message detection result, including: determining a message description parameter corresponding to the target message, wherein the message description parameter is used to locate multiple predetermined message fields in the target message; based on the message description parameter, determining the message positions corresponding to the multiple predetermined message fields of the target message; executing corresponding detection programs on the multiple predetermined message fields respectively to obtain multiple sub-detection results; and determining the message detection result corresponding to the target message based on the multiple sub-detection results.
[0008] Optionally, reading the storage address of the target message from the first memory includes: sending a message detection instruction to the message information receiving queue in the first memory according to a predetermined period, wherein the message detection instruction is used to determine whether the storage address of the target message exists in the message information receiving queue; receiving an instruction response result fed back by the message information receiving queue; and when the instruction response result is that the storage address of the target message exists in the message information receiving queue, sending a message acquisition instruction to the message information receiving queue in the first memory to obtain the storage address of the target message in the message information receiving queue.
[0009] Optionally, after detecting the target message stored in the storage address in the second memory and obtaining the message detection result, it also includes: determining the message identifier corresponding to the target message; determining the detection information based on the message identifier and the message detection result; sending the detection information to the detection information sending queue corresponding to the target message in the first memory, so as to perform the target operation on the target message based on the detection information.
[0010] Optionally, sending a message detection instruction to the message information receiving queue in the first memory according to a predetermined period includes: when the first memory includes multiple message information receiving queues, sending the message detection instruction to the multiple message information receiving queues at the same time according to the predetermined period.
[0011] According to one aspect of an embodiment of the present invention, a message detection method is provided, including: receiving a target message and storing the target message in a second memory; determining a storage address corresponding to the target message in the second memory area; and sending the storage address to a first memory, wherein the first memory and the second memory are areas in a message transmission module that are at least allowed to be accessed by a message detection module.
[0012] According to one aspect of an embodiment of the present invention, a message detection device is provided, including: a reading module for reading a storage address of a target message from a first memory, wherein the storage address is the address of the target message in a second memory, the first memory and the second memory are areas in a message transmission module that at least a message detection module is allowed to access, the message transmission module is used to receive the target message, store the target message in the second memory, and determine the storage address corresponding to the target message in the second memory, and store the storage address in the first memory; a detection module is used to detect the target message stored in the storage address in the second memory to obtain a message detection result.
[0013] According to one aspect of an embodiment of the present invention, a message detection device is provided, including: a receiving module for receiving a target message and storing the target message in a second memory; a determining module for determining a storage address corresponding to the target message in the second memory area; and a sending module for sending the storage address to a first memory, wherein the first memory and the second memory are areas in a message transmission module that are at least allowed to be accessed by a message detection module.
[0014] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is provided, which includes a stored executable program, wherein when the executable program runs, the device where the computer-readable storage medium is located is controlled to execute any one of the above-mentioned message detection methods.
[0015] According to another aspect of an embodiment of the present invention, an electronic device is provided, including: a memory storing an executable program; and a processor for running the program, wherein any one of the above-mentioned message detection methods is executed when the program is running.
[0016] According to another aspect of an embodiment of the present invention, a computer program product is provided, including a computer program, which implements the steps of any one of the above-mentioned message detection methods when executed by a processor.
[0017] In an embodiment of the present invention, a storage address of a target message is read from a first memory, wherein the storage address is the address of the target message in a second memory, and the first memory and the second memory are areas in the message transmission module that at least the message detection module is allowed to access. The message transmission module is used to receive the target message, store the target message in the second memory, and determine the storage address corresponding to the target message in the second memory, and store the storage address in the first memory; the target message stored in the storage address in the second memory is detected to obtain a message detection result. By reading the storage address of the target message from the first memory, the target message stored in the storage address in the second memory is detected to obtain a message detection result. Since the first memory and the second memory are both shared memory areas with the message detection module in the message transmission module, the message detection module can directly access the target message in the second memory according to the received storage address, detect the target message, and obtain a detection result, thereby improving the detection efficiency and solving the technical problem in the related art that when detecting a message, computer memory resources are wasted, resulting in low message detection efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0019] Figure 1 This is a flow chart of a message detection method according to an embodiment of the present invention;
[0020] Figure 2 is a flow chart of another message detection method according to an embodiment of the present invention;
[0021] Figure 3 This is a flow chart of a traditional message detection method provided by an optional embodiment of the present invention;
[0022] Figure 4 This is a flowchart of a message detection method provided by an optional embodiment of the present invention;
[0023] Figure 5 This is a schematic diagram of a message interaction bidirectional queue provided by an optional embodiment of the present invention;
[0024] Figure 6 This is a flow chart of a message detection method provided by an optional embodiment of the present invention;
[0025] Figure 7This is a structural block diagram of a message detection device according to an embodiment of the present invention;
[0026] Figure 8 is a structural block diagram of another message detection device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0027] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0028] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0029] First, some nouns or terms that appear in the description of the embodiments of the present application are subject to the following interpretations:
[0030] VPP: A high-performance, open-source network packet processing framework for modern network scenarios. It features vectored packet processing capabilities and can be used to build data packet processing applications.
[0031] DPDK: A high-performance network driver component designed to provide packet processing solutions for data plane applications.
[0032] Example 1
[0033] According to an embodiment of the present invention, a method embodiment of message detection is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0034] Figure 1Flowchart of a message detection method according to an embodiment of the present invention. Figure 1 As shown, the method includes the following steps:
[0035] Step S102, read the storage address of the target message from the first memory, wherein the storage address is the address of the target message in the second memory, the first memory and the second memory are areas in the message transmission module that at least the message detection module is allowed to access, the message transmission module is used to receive the target message, store the target message in the second memory, and determine the storage address corresponding to the target message in the second memory, and store the storage address in the first memory.
[0036] In step S102 provided in the present application, the message detection module reads the storage address of the target message from the first memory.
[0037] Among them, the first memory is involved. The first memory refers to a memory area shared with the message detection module in the message transmission module, which is used to store the storage address of the target message.
[0038] Among them, the target message is involved, and the target message refers to the message that needs to be security checked.
[0039] Among them, the second memory is involved. The second memory refers to a memory area shared with the message detection module in the message transmission module and is used to store the target message.
[0040] Among them, the message transmission module is involved. The message transmission module refers to the module responsible for receiving, storing and transmitting message data packets, such as the high-performance packet processing framework (VPP, Vector Packet Processing).
[0041] This involves a packet inspection module, which is responsible for inspecting the contents of packet data to detect potential network threats or abnormal behavior. Examples include intrusion prevention systems (IPS) and intrusion detection systems (IDS).
[0042] In this step, the message detection module can directly read the target message's storage address from the message transmission module's first memory, thereby locating the target message in the message transmission module's second memory and performing detection without copying the message data again. This step allows the message detection module to directly access the second memory for detection, avoiding duplicate data copying when messages are transmitted between different modules, reducing unnecessary computer resource waste and memory burden, and improving the processing speed of message detection.
[0043] Step 104: Detect the target message stored in the storage address in the second memory to obtain a message detection result.
[0044] In step S104 provided in the present application, the message detection module obtains the message detection result of the target message.
[0045] Among them, the message detection results are involved. The message detection results refer to the conclusions drawn by the message detection module after analyzing the target message, such as whether the target message is safe, whether it contains malicious code, whether it complies with network policies or service level agreements (SLAs), and other information.
[0046] In this step, the message detection module directly accesses and reads the data of the target message in the second memory of the message transmission module according to the storage address, then performs in-depth analysis and detection on the data, and finally generates a message detection result.
[0047] Through this step, detection is performed directly at the data storage location, avoiding multiple copies of data packets, reducing intermediate links in data processing, and reducing complex data flows between different system components, making system design and implementation simpler and easier to manage, and improving the processing efficiency and response speed of the entire system.
[0048] Through the above steps S102-S104, the storage address of the target message is read from the first memory, wherein the storage address is the address of the target message in the second memory, the first memory and the second memory are areas in the message transmission module that at least the message detection module is allowed to access, the message transmission module is used to receive the target message, store the target message in the second memory, and determine the storage address corresponding to the target message in the second memory, and store the storage address in the first memory; the target message stored in the storage address in the second memory is detected to obtain the message detection result. By reading the storage address of the target message from the first memory, the target message stored in the storage address in the second memory is detected to obtain the message detection result. Since the first memory and the second memory are both shared memory areas with the message detection module in the message transmission module, the message detection module can directly access the target message in the second memory according to the received storage address, detect the target message, and obtain the detection result, thereby improving the detection efficiency and solving the technical problem in the related art that when detecting the message, computer memory resources are wasted, resulting in low message detection efficiency.
[0049] As an optional embodiment, before reading the storage address of the target message from the first memory, it also includes: sending a connection request to the message transmission module; receiving response information fed back by the message transmission module, wherein the response information includes the first thread number of the message transmission thread in the message transmission module and the memory address of the first memory in the message transmission module; determining the second thread number of the message detection thread in the message detection module based on the response information; determining a third thread number of target transmission queue groups from multiple to-be-selected transmission queue groups based on the first thread number and the second thread number, so as to transmit the message information between the corresponding message transmission thread and the corresponding message detection thread through the corresponding target transmission queue group, so that the corresponding message transmission module and the corresponding message detection thread are transmitted one-to-one, wherein the third thread number is the smaller number between the first thread number and the second thread number, and the message information is the storage address and message detection result corresponding to the target message.
[0050] In this embodiment, the specific steps of determining the target transmission queue group between the message transmission thread and the message detection thread are described.
[0051] Among them, a connection request is involved, and the connection request refers to a request initiated by the message detection module for establishing a communication connection with the message transmission module.
[0052] Among them, the response information is involved, and the response information refers to the message that the message transmission module responds to the connection request and feeds back its own message transmission thread information and memory address information.
[0053] Among them, the message transmission thread is involved. The message transmission thread refers to the task thread that receives, sends and stores messages in the message transmission module.
[0054] Here, the number of first threads is involved, and the number of first threads refers to the number of message transmission threads in the message transmission module.
[0055] Among them, the message detection thread is involved, and the message detection thread refers to the task thread that performs message detection in the message detection module.
[0056] Among them, the number of second threads is involved, and the number of second threads refers to the number of message detection threads in the message detection module.
[0057] The third number of threads is involved, and the third number of threads refers to the number of target transmission queue groups determined according to the first number of threads and the second number of threads.
[0058] Among them, the target transmission queue group is involved. The target transmission queue group refers to a bidirectional lock-free queue used to efficiently transmit message information between the message transmission thread and the message detection thread.
[0059] In this step, the message detection module actively initiates a request to establish a connection (i.e., a connection request) to the message transmission module in order to start the interaction between the two. The response information fed back by the message transmission module includes the number of its internal message transmission threads (i.e., the first number of threads) and the memory address of the first memory. Based on the number of message transmission threads, the message detection module adjusts the second number of threads of the message detection thread to ensure that the number of threads of both parties matches to achieve a one-to-one efficient mapping between threads. A target transmission queue group equal to the third number of threads is selected from the preset transmission queue group. Each target transmission queue group is a bidirectional lock-free queue, including a message information receiving queue and a detection information sending queue. The third number of threads is determined by the smaller of the first number of threads and the second number of threads. Each group of queues serves a pair of message transmission threads and message detection threads, thereby achieving fast lock-free transmission of message information.
[0060] Through this step, the number of threads is dynamically adjusted and a multi-threaded model is established to ensure that the transmission threads in the message transmission module are paired one-to-one with the detection threads in the message detection module. This enables the system to process multiple data packets simultaneously, avoiding excessive competition and resource waste between threads, significantly improving the system's concurrent processing capabilities and overall throughput. At the same time, the use of bidirectional lock-free queues greatly reduces the waiting time and lock contention of data packets during the transmission and detection process, allowing data packets to flow almost seamlessly from the transmission module to the detection module, improving the processing speed and efficiency of the entire system.
[0061] As an optional embodiment, the target message stored in the storage address in the second memory is detected to obtain a message detection result, including: determining a message description parameter corresponding to the target message, wherein the message description parameter is used to locate multiple predetermined message fields in the target message; based on the message description parameter, determining the message positions corresponding to multiple predetermined message fields of the target message; executing corresponding detection programs on multiple predetermined message fields respectively to obtain multiple sub-detection results; and determining the message detection result corresponding to the target message based on the multiple sub-detection results.
[0062] In this embodiment, the specific steps of detecting the target message stored in the storage address in the second memory and obtaining the message detection result are described.
[0063] Among them, the message description parameters are involved. The message description parameters refer to the parameter information that describes the key fields of the target message (such as source address, destination address, protocol type, load content, etc.), which are used to guide the message detection module on how to locate and process different parts of the message.
[0064] Herein, a predetermined message field is involved, and the predetermined message field refers to a message field that requires special attention or analysis when performing message detection.
[0065] Here, a sub-detection result is involved, and the sub-detection result refers to a result obtained after a separate detection of a single predetermined message field.
[0066] In this step, before beginning detection, the message detection module first reads the message description parameters to understand the target message's structure and key field locations. This forms the foundation of the detection process. Based on these message description parameters, the message detection module can accurately locate the specific locations of multiple predetermined message fields in the secondary memory without having to traverse or parse the entire message, saving processing time and resources. A specially designed detection procedure is executed for each predetermined message field. The results of all sub-detections are comprehensively analyzed to produce the final message detection result, determining whether the target message is safe and whether there are any threats.
[0067] Through this step, the pre-processed message description parameters can be used to quickly locate key fields, avoiding the full message scanning in traditional message parsing, greatly improving the detection speed and efficiency. At the same time, targeted detection of predetermined message fields makes the message detection mechanism highly flexible and customizable, easy to adapt to the ever-changing network security environment, more accurately identify security threats, reduce the possibility of false alarms and missed alarms, and improve the execution effect of security policies.
[0068] As an optional embodiment, reading the storage address of the target message from the first memory includes: sending a message detection instruction to the message information receiving queue in the first memory according to a predetermined period, wherein the message detection instruction is used to determine whether the storage address of the target message exists in the message information receiving queue; receiving the instruction response result fed back by the message information receiving queue; when the instruction response result is that the storage address of the target message exists in the message information receiving queue, sending a message acquisition instruction to the message information receiving queue in the first memory to obtain the storage address of the target message in the message information receiving queue.
[0069] In this embodiment, the specific steps of reading the storage address of the target message from the first memory are described.
[0070] In this step, the message detection module continuously sends message detection instructions to the message information receiving queue in the first memory at a predetermined interval to query whether the storage address of the target message is ready. If the storage address exists in the message information receiving queue, the message detection module sends a message acquisition instruction to directly read the storage address. Then, based on the storage address, the module reads and analyzes the target message from the second memory.
[0071] Through this step, frequent access to the first memory is reduced, meaningless data access is avoided, and each reading operation is ensured to be necessary, which reduces the burden on computer computing resources and memory, thereby improving the efficiency of the detection process.
[0072] As an optional embodiment, after detecting the target message stored in the storage address in the second memory and obtaining the message detection result, it also includes: determining the message identifier corresponding to the target message; determining the detection information based on the message identifier and the message detection result; sending the detection information to the detection information sending queue corresponding to the target message in the first memory, so as to perform the target operation on the target message based on the detection information.
[0073] In this embodiment, the specific steps of sending the detection information are described.
[0074] Among them, a message identifier is involved. The message identifier refers to information used to uniquely identify each message data packet, such as the message's sequence number, identification code, timestamp, etc.
[0075] Among them, detection information is involved. Detection information refers to information generated based on message detection results and message identifiers, such as detected threat types, vulnerability information, security level scores, recommended processing actions (such as blocking, warning, release, etc.), etc., which are used to guide the target message processing actions of subsequent message transmission modules.
[0076] Among them, target operation is involved, which refers to the processing action on the target message determined based on the detection information and network security policy.
[0077] In this step, the target message's message identifier is first extracted to facilitate rapid location and retrieval during subsequent processing. Next, detection information is generated based on the message detection results and the message identifier. This detection information contains key details about the target message's security status. The detection information is then placed in a specific queue in the first memory, known as the detection information send queue, awaiting read and action by the message transmission module.
[0078] Through this step, the detection information is sent back to the first memory to build an intelligent feedback mechanism. The message transmission module can adjust its subsequent behavior according to the detection results, such as optimizing the flow control strategy, updating the security rule base, adjusting the network resource allocation, etc., to form a closed-loop control and enhance the intelligence and adaptability of the system.
[0079] As an optional embodiment, sending a message detection instruction to a message information receiving queue in the first memory according to a predetermined period includes: when the first memory includes multiple message information receiving queues, sending a message detection instruction to multiple message information receiving queues at the same time according to a predetermined period.
[0080] In this embodiment, specific steps of sending a message detection instruction to a message information receiving queue in the first memory are described when the first memory includes multiple message information receiving queues.
[0081] In this step, when multiple message information receiving queues exist in the first memory, the message detection module simultaneously sends detection instructions to multiple message information receiving queues, implementing multi-threaded or multi-process parallel detection and improving the system's overall processing capability. Through this step, in a multi-core architecture, different cores can independently send message detection instructions and message acquisition instructions, achieving concurrent detection of data packets and improving system throughput.
[0082] According to an embodiment of the present invention, a method embodiment of message detection is also provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0083] Figure 2 Flowchart of another message detection method according to an embodiment of the present invention. Figure 2 As shown, the method includes the following steps:
[0084] Step S202: Receive a target message and store the target message in a second memory.
[0085] In step S202 provided in the present application, a target message is received and stored in a second memory.
[0086] In this step, after the message transmission module captures the target message data packet, it stores it in the secondary memory for further processing or detection. This step efficiently and securely stores the target message, providing a solid foundation for subsequent processing. It is an indispensable part of building high-performance and highly reliable network systems, and is crucial for improving the processing capabilities of network devices and ensuring network security.
[0087] Step 204: Determine the storage address corresponding to the target message in the second memory area.
[0088] In step S204 provided in the present application, the storage address corresponding to the target message in the second memory area is determined.
[0089] Step 206: Send the storage address to the first memory, wherein the first memory and the second memory are areas in the message transmission module that are at least allowed to be accessed by the message detection module.
[0090] In step S206 provided in this application, the storage address is sent to the first memory.
[0091] In this step, the message transmission module first locates the target message in the second memory and obtains its storage address. This storage address is then transferred to the first memory. Since the first memory is a shared area between the message transmission module and the message detection module, the message detection module can directly read the storage address from it and then access and process the data packet at the corresponding location in the second memory. This approach avoids data packet duplication, reduces memory overhead and system computational burden, and significantly improves detection efficiency and system performance.
[0092] Based on the above embodiment and optional embodiment, an optional implementation manner is provided, which is described in detail below.
[0093] In the related art, the method for performing message detection mainly includes: a data packet processing framework (netfilter mechanism) based on the operating system kernel (Linux kernel), in the netfilter framework of the network layer protocol stack, traffic interception is achieved by registering a custom callback function to the forwarding hook point (FORWARD hook point), and then a copy of the message is sent to the IPS / IDS detection engine for threat detection after being copied through a queue or character device. Figure 3 This is a flow chart of a traditional message detection method provided by an optional embodiment of the present invention, such as Figure 3 As shown, this process involves frequent switching between user and kernel modes, as well as unnecessary packet copying overhead, resulting in severe performance bottlenecks. Furthermore, the inefficient method of the network card frequently triggering interrupts to notify the Linux kernel and central processing unit (CPU) to send and receive packets is no longer suitable for high-performance network environments. This method also causes packets to be processed through the entire kernel protocol stack within the Linux kernel, resulting in an excessively long protocol processing path, which also negatively impacts IPS / IDS detection performance.
[0094] Methods for performing packet detection also include: using DPDK technology to send and receive packets, thereby enabling the IPS / IDS detection engine to obtain packets. This method uses the IPS / IDS detection engine as a subsidiary process of the DPDK process, and uses the shared memory mechanism provided by the DPDK suite to copy the packet from DPDK and pass it to the IPS / IDS engine for detection. However, this method cannot achieve zero memory copy and requires a dedicated thread in the IPS / IDS engine to handle control information communication with the DPDK process, resulting in a waste of CPU resources. The copying of a large number of packets also results in performance loss, thereby introducing performance bottlenecks.
[0095] In view of this, an optional embodiment of the present invention provides a packet detection method that introduces VPP (the same as the above-mentioned packet transmission module) as the forwarding layer of the IPS / IDS detection engine. By adding an IPS / IDS plug-in module to the VPP, traffic is directed to the IPS / IDS detection engine (the same as the above-mentioned packet detection module) for scanning. The high performance of VPP in packet transmission and reception solves the low packet reception efficiency problem of traditional kernel-based implementation methods. In addition, the optional embodiment of the present invention achieves a zero-copy memory effect by implementing a mechanism for transmitting data packets in a lockless queue between the VPP and the IPS / IDS detection engine, avoiding the data packet copy overhead in the DPDK solution. Moreover, the optional embodiment of the present invention avoids the deep coupling of the packet forwarding framework and the IPS / IDS detection engine by building a complete control and message interaction application programming interface (API) on the VPP side, namely the traffic steering module, and providing it to the IPS / IDS engine for use. This allows for more convenient and rapid iteration and upgrade of the detection engine. This method has significant advantages in improving performance, reducing false positives and false negatives, enhancing stability, and simplifying deployment and management, providing a new solution for network security protection.
[0096] Figure 4 This is a flowchart of a message detection method provided by an optional embodiment of the present invention. Figure 4 As shown in the figure, two nodes (enq-node and deq-node) are introduced in the IPS / IDS plug-in module. The enq-node is mounted on the unicast arc (ip4-unicast arc and ip4-output arc) to obtain inbound and outbound messages, collect basic message information and node operation information, etc. The deq-node is responsible for returning messages sent to the IPS / IDS detection engine and sending the messages to subsequent nodes of the VPP for processing based on the node operation information cached by the enq-node.
[0097] The design of the IPS / IDS plug-in module solves the message flow process, but it does not yet address the message interaction logic between VPP and the IPS / IDS detection engine. Therefore, based on VPP and the Linux memory file descriptor mechanism (memfd mechanism), a bidirectional lock-free queue is designed to address the overhead caused by message copying. Figure 5 This is a schematic diagram of a message interaction bidirectional queue provided by an optional embodiment of the present invention, such as Figure 5 As shown, the details are as follows:
[0098] First, using the memfd shared memory mechanism provided by Linux, a new shared memory (same as the first memory described above) is established between the VPP and the IPS / IDS detection engine. This shared memory is used to store the description information of the packets to be transferred and queue maintenance information. The packet description information includes the packet pool number, packet offset, packet length, and detection result. The queue maintenance information includes the head and tail node information of the queue entry and exit.
[0099] Secondly, ensure that the number of VPP worker threads (the first number corresponding to the message transmission threads) and the number of IPS / IDS detection engine worker threads (the second number corresponding to the message detection threads) are the same, forming a one-to-one correspondence to avoid CPU concurrency and lock contention overhead. Each pair of worker threads is bound to a bidirectional lock-free queue (the same as the target transmission queue group), namely enq_ring (the same as the message information receiving queue) and deq_ring (the same as the detection information sending queue), which are used by VPP to transmit messages to the IPS / IDS detection engine and VPP to obtain return messages from the IPS / IDS detection engine, respectively.
[0100] Finally, the enq-node node in the IPS / IDS plug-in module is responsible for collecting packet information and storing it in the enq_ring queue. The deq-node node in the IPS / IDS plug-in module is responsible for obtaining the packet information returned by the IPS / IDS detection engine from the deq_ring.
[0101] To avoid coupling between the IPS / IDS engine and the forwarding framework, a dedicated API, the Traffic Steering Module, was designed. This API includes the logic for establishing a control channel between the IPS / IDS detection engine and the VPP process, obtaining packet information from the enq_ring queue, and placing packet information and detection results in the deq_ring queue. This Traffic Steering Module exists as a dynamic library and is available to the IPS / IDS detection engine for invocation.
[0102] Figure 6 This is a flow chart of a message detection method provided by an optional embodiment of the present invention, such as Figure 6 As shown, the detailed steps of the message detection method provided by the optional embodiment of the present invention are specifically introduced below.
[0103] S1. Read the storage address of the target message from the first memory.
[0104] The IPS / IDS detection engine uses the API of the traffic steering module to retrieve batch messages from the enq_ring queue (the same storage address as above).
[0105] Previously, VPP used vectorization in the enq-node to process and transmit messages in batches, improving the hit rate and accelerating data packet processing. By adding message information to the enq_ring queue, zero memory copy can be achieved, and messages can be quickly sent to the IPS / IDS detection engine for threat and vulnerability detection.
[0106] S2. Detect the target message stored in the storage address in the second memory to obtain a message detection result.
[0107] The IPS / IDS detection engine scans packets based on features and rules, and after detection, uses the API of the traffic steering module to send the packets to the deq_ring queue.
[0108] Afterwards, in the deq-node node, the IPS / IDS plug-in module in the VPP retrieves the return message and the detection result of the message from the deq_ring queue (the same as the detection information mentioned above). In the intrusion prevention system (IPS) mode, the original destination address of the corresponding message is added to the blocking list based on the detection result, and the current message is immediately discarded. Network administrators can handle threats based on the alarm information, such as adding a blocking list, an allow list, a signature suppression list, etc., and can block all traffic in a certain area based on the address information where the threat occurs.
[0109] Before S1, you need to establish a connection between VPP and the IPS / IDS detection engine. The specific steps are as follows:
[0110] Through VPP's plug-in mechanism and network components, the IPS / IDS plug-in module directly reuses VPP's event polling (epoll mechanism) to monitor a specific socket file (socket file), completing the establishment of an asynchronous control channel with VPP as the server and the IPS / IDS detection engine as the client. The IPS / IDS detection engine uses the API in the traffic steering module to initiate a connection request to the server-side VPP. The VPP IPS / IDS plug-in module receives the request and returns all VPP packet pool base addresses, packet pool numbers, and the number of working threads to the IPS / IDS detection engine through the control channel. The engine performs relevant initialization. The IPS / IDS detection engine further negotiates with the VPP to establish new shared memory based on the number of worker threads and a specific queue length. This shared memory is used to establish a multi-core, multi-threaded, bidirectional, lock-free queue, which is ultimately used to exchange message data between the VPP and the IPS / IDS detection engine. Through the VPP feature node mechanism, the enq-node and deq-node defined in the IPS / IDS plug-in module are mounted to the corresponding VPP node processing graph, enabling dynamic activation / disablement of the traffic steering module, thereby controlling the effectiveness of the IPS / IDS detection engine.
[0111] Through the above optional implementation, at least the following beneficial effects can be achieved:
[0112] (1) By utilizing the high-performance vectorized processing capabilities of VPP and the message delivery mechanism of multi-core, multi-threaded, lock-free queues, lock contention is reduced while also achieving zero memory copy of messages. Therefore, the message detection method provided by the optional embodiment of the present invention can efficiently process massive data traffic, reduce latency, and improve the overall performance of the IPS / IDS system;
[0113] (2) Leveraging the flexibility and scalability of the VPP framework, the packet detection method provided in the optional embodiment of the present invention can cope with various complex network environments, reduce the risk of single point failures, and improve system stability;
[0114] (3) By utilizing the VPP plug-in mechanism, the entire packet interaction process is implemented. Detection can be performed by simply registering and calling the corresponding processing function in the IPS / IDS detection engine. This completely decouples the forwarding framework and the detection engine. The IPS / IDS detection engine can then be independently upgraded or horizontally expanded, avoiding the strong coupling problem between the kernel module and the user-mode process in traditional solutions.
[0115] It should be noted that for the aforementioned method embodiments, for simplicity of description, they are all expressed as a series of action combinations. However, those skilled in the art should be aware that the present invention is not limited by the order of the actions described, because according to the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present invention.
[0116] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods of various embodiments of the present invention.
[0117] Example 2
[0118] Figure 7 is a structural block diagram of a message detection device according to an embodiment of the present invention. Figure 7 As shown, the device includes: a reading module 702, which is used to read the storage address of the target message from the first memory, wherein the storage address is the address of the target message in the second memory, the first memory and the second memory are areas in the message transmission module that at least the message detection module is allowed to access, and the message transmission module is used to receive the target message, store the target message in the second memory, and determine the storage address corresponding to the target message in the second memory, and store the storage address in the first memory; a detection module 704, which is connected to the above-mentioned reading module 702, and is used to detect the target message stored in the storage address in the second memory to obtain a message detection result.
[0119] The above-mentioned reading module 702 and detection module 704 correspond one-to-one to steps S102 to S104. The examples and application scenarios implemented by multiple modules and corresponding steps are the same, but are not limited to the contents disclosed in the above-mentioned embodiments.
[0120] Figure 8 is a structural block diagram of another message detection device according to an embodiment of the present invention. Figure 8As shown, the device includes: a receiving module 802, used to receive the target message and store the target message in the second memory; a determination module 804, connected to the above-mentioned receiving module 802, used to determine the storage address corresponding to the target message in the second memory area; a sending module 806, connected to the above-mentioned determination module 804, used to send the storage address to the first memory, wherein the first memory and the second memory are areas in the message transmission module that are at least allowed to be accessed by the message detection module.
[0121] The above-mentioned receiving module 802, determining module 804 and sending module 806 correspond one-to-one to steps S202 to S206. The examples and application scenarios implemented by multiple modules and corresponding steps are the same, but are not limited to the contents disclosed in the above-mentioned embodiments.
[0122] Example 3
[0123] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is also provided, which includes a stored executable program, wherein when the executable program runs, the device where the computer-readable storage medium is located is controlled to execute any of the above-mentioned message detection methods.
[0124] Example 4
[0125] According to another aspect of an embodiment of the present invention, an electronic device is provided, including: a memory storing an executable program; and a processor for running the program, wherein any one of the above-mentioned message detection methods is executed when the program is running.
[0126] Example 5
[0127] According to another aspect of an embodiment of the present invention, a computer program product is further provided, including a computer program. When the computer program is executed by a processor, any of the above-mentioned message detection methods can be implemented.
[0128] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.
[0129] In the above embodiments of the present invention, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0130] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0131] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0132] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0133] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, etc. Various media that can store program codes.
[0134] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.
Claims
1. A message detection method, characterized in that: include: Reading a storage address of a target message from a first memory, wherein the storage address is an address of the target message in a second memory, the first memory and the second memory are areas in a message transmission module that are at least allowed to be accessed by a message detection module, the message transmission module is configured to receive the target message, store the target message in the second memory, determine the storage address corresponding to the target message in the second memory, and store the storage address in the first memory; The target message stored in the storage address in the second memory is detected to obtain a message detection result.
2. The method according to claim 1, characterized in that Before reading the storage address of the target message from the first memory, the method further includes: Send a connection request to the message transmission module; receiving response information fed back by the message transmission module, wherein the response information includes a first thread number of a message transmission thread in the message transmission module and a memory address of a first memory in the message transmission module; Determining the number of second threads of the message detection thread in the message detection module according to the response information; Based on the first number of threads and the second number of threads, a third number of target transmission queue groups are determined from multiple to-be-selected transmission queue groups, so as to transmit the message information between the corresponding message transmission thread and the corresponding message detection thread through the corresponding target transmission queue group, so that the corresponding message transmission module and the corresponding message detection thread are transmitted one-to-one, wherein the third number of threads is the smaller number between the first number of threads and the second number of threads, and the message information is the storage address and message detection result corresponding to the target message.
3. The method according to claim 1, characterized in that The detecting the target message stored in the storage address in the second memory to obtain a message detection result includes: Determining a message description parameter corresponding to the target message, wherein the message description parameter is used to locate a plurality of predetermined message fields in the target message; Determining, based on the message description parameters, message positions corresponding to the plurality of predetermined message fields of the target message; Executing corresponding detection procedures on the plurality of predetermined message fields respectively to obtain a plurality of sub-detection results; A message detection result corresponding to the target message is determined based on the multiple sub-detection results.
4. The method according to claim 1, wherein The step of reading the storage address of the target message from the first memory includes: Sending a message detection instruction to the message information receiving queue in the first memory according to a predetermined period, wherein the message detection instruction is used to determine whether the message information receiving queue has a storage address of the target message; Receive the command response result fed back by the message information receiving queue; When the instruction response result is that the storage address of the target message exists in the message information receiving queue, a message acquisition instruction is sent to the message information receiving queue in the first memory to obtain the storage address of the target message in the message information receiving queue.
5. The method according to claim 1, wherein After detecting the target message stored in the storage address in the second memory and obtaining a message detection result, the method further includes: Determining a message identifier corresponding to the target message; Determining detection information based on the message identifier and the message detection result; The detection information is sent to a detection information sending queue corresponding to the target message in the first memory, so as to perform a target operation on the target message according to the detection information.
6. The method according to claim 4, characterized in that The sending of the message detection instruction to the message information receiving queue in the first memory according to a predetermined period includes: In the case where the first memory includes a plurality of message information receiving queues, the message detection instruction is sent to the plurality of message information receiving queues simultaneously according to the predetermined period.
7. A message detection method, characterized in that: include: receiving a target message, and storing the target message in a second memory; Determine a storage address corresponding to the target message in the second memory area; The storage address is sent to a first memory, wherein the first memory and the second memory are areas in the message transmission module that are at least allowed to be accessed by the message detection module.
8. A message detection device, characterized in that: include: a reading module, configured to read a storage address of a target message from a first memory, wherein the storage address is an address of the target message in a second memory, the first memory and the second memory are areas in the message transmission module that are at least allowed to be accessed by the message detection module, the message transmission module is configured to receive the target message, store the target message in the second memory, determine the storage address corresponding to the target message in the second memory, and store the storage address in the first memory; A detection module is used to detect the target message stored in the storage address in the second memory to obtain a message detection result.
9. A message detection device, characterized in that: include: A receiving module, configured to receive a target message and store the target message in a second memory; A determination module, configured to determine a storage address corresponding to the target message in the second memory area; The sending module is used to send the storage address to the first memory, wherein the first memory and the second memory are areas in the message transmission module that are at least allowed to be accessed by the message detection module.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored executable program, wherein when the executable program is running, the device where the computer-readable storage medium is located is controlled to execute the message detection method according to any one of claims 1 to 7.
11. An electronic device, characterized in that: include: a memory storing an executable program; A processor, configured to run the program, wherein the program, when running, executes the message detection method according to any one of claims 1 to 7.
12. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Shared pointer pool-based message zero-copy processing method
CN106445838A
Inter-process communication method and device, computer equipment and storage medium
CN115576708A
Storage state detection method and device, storage medium and electronic device
CN116501580A
Packet forwarding method and apparatus, network device, and computer readable medium
WO2020125652A1