FPGA-based high-speed serial connection drainage backflow anomaly detection message blocking implementation method
By adopting a hardware acceleration architecture based on FPGA and using a collaborative processing method of traffic redirection and reflow, mirroring and recoloring, the performance bottleneck of network attack traffic detection and blocking in high-speed network environments has been solved, achieving efficient and real-time network security protection, ensuring business continuity and reducing costs.
Patent Information
- Application Number
- CN202511163867.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-20
- Publication Date
- 2026-02-06
- Estimated Expiration
- 2045-08-20
AI Technical Summary
In high-speed network environments, existing x86-based software solutions struggle to achieve efficient and real-time network attack traffic detection and blocking, exhibiting performance bottlenecks and stability issues. In particular, at interface speeds of 100G and above, it is difficult to guarantee the integrity of traffic mirroring and the transmission delay of blocking commands.
Employing an FPGA-based hardware acceleration architecture, and through a collaborative processing approach of traffic redirection and reflow, mirroring and recoloring, a high-speed, efficient, and real-time network security protection system is constructed. FPGA is used for packet parsing, policy selection, and high-speed flow table lookup to achieve accurate detection and timely blocking of network attack traffic.
It enables real-time detection and blocking of network attack traffic at 400G line speed, ensuring business continuity, reducing processing costs, and possessing high-density integration and cost advantages, filling the technological gap in the field of high-speed network security protection.
Smart Images

Figure CN120729971B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computers, and in particular to a high-speed serial connection abnormality detection packet plugging implementation method based on FPGA. BACKGROUND
[0002] In the wave of network technology evolution, the leap of interface rate has always been the core driving force for the transformation of security protection system. When the interface rate stays at 1G, 2.5G, 10G, 40G stage, the software solution based on x86 architecture has occupied the mainstream market by virtue of its flexible adaptation ability. Such solution relies on the general computing ability of CPU, and can quickly respond to new attack features through code iteration, showing significant portability and upgrade advantage in the scene with limited traffic scale. However, the inherent stability short board of software system is also accompanied, and problems such as memory leakage and process crash are difficult to eliminate, which directly leads to more than 90% of the deployment solutions in the industry to choose parallel or non-serial mode.
[0003] With the popularization of 100G interface in backbone network and commercialization of 400G interface in supercomputing center, the performance bottleneck of software architecture is completely exposed. When the single interface traffic breaks through 100G, the instruction cycle of x86 processor cannot match the line speed processing demand, and even if multi-machine cluster load balancing is adopted, the low delay forwarding characteristics required by serial deployment cannot be realized. At this time, the parallel scheme is in a more embarrassing situation: on the one hand, the integrity of traffic mirroring is difficult to guarantee, and the sampling analysis technology adopted by some manufacturers will lead to 10%-15% of attack samples missing; on the other hand, the transmission delay of blocking instructions is amplified by high-speed traffic, and the test under 400G environment in a laboratory shows that the average time from attack traffic to blocking is 2.3 seconds, which is enough to cause TB level data leakage.
[0004] The core to solve this problem lies in building a hybrid architecture of "hardware acceleration + flexible programmable". From the reliability dimension, a telecom-level hardware platform must be used as the foundation, generally by sinking high-frequency operations such as TCP handshake verification and DDoS feature matching to the hardware layer through ASIC or FPGA chip to solidify the key forwarding logic, and realizing 99.999% of fault-free running time. At the same time, FPGA is introduced as a programmable intermediate layer, which not only retains the line speed processing ability of hardware acceleration, but also can quickly respond to new attack modes through firmware update.
[0005] In terms of deployment mode, the implementation of the cascaded architecture requires overcoming three technical bottlenecks: First, adopting a dual-active redundancy design, with the primary / backup switchover time controlled within 50ms to ensure that a single point of failure does not affect business continuity; second, developing an intelligent traffic scheduling chip to achieve microsecond-level traffic splitting at 400G line speed, avoiding single-point computing power overload; and third, constructing a separate architecture of "hardware forwarding plane + software control plane," so that abnormal fluctuations in the control plane will not be transmitted to the forwarding plane. Test data from a certain vendor shows that this architecture, in a continuous 72-hour 400G full-load stress test, has a forwarding performance attenuation rate of less than 0.5%, far superior to the 3% attenuation threshold of the software solution.
[0006] In terms of cost and integration, this solution utilizes FPGA technology and a comprehensive hardware-software architecture centered on the hardware architecture. Employing a processing approach of redirection and reflow, mirroring and recoloring, it provides a high-speed, efficient, and real-time solution for effectively detecting, blocking, and controlling network attack traffic, malicious information, and illegal websites. While meeting design requirements, it achieves both high-density integration and cost advantages, offering a practical technical solution for addressing such critical issues and filling a gap in the market. Summary of the Invention
[0007] To achieve the above objectives, the technical solution adopted by this invention is: a method for blocking abnormal detection messages in high-speed serial connection current diversion and return based on FPGA, the method comprising:
[0008] Receive raw messages from the link and input them into the FPGA;
[0009] The message is parsed, and the protocol fields in the original message are extracted.
[0010] If the corresponding referral strategy is selected based on the protocol fields, the referral message will be obtained; if there is no corresponding referral strategy, the data of the high-speed flow table on the FPGA will be queried and updated.
[0011] If the traffic redirection strategy is successful, the traffic redirection message is mirrored and encapsulated; the encapsulated traffic redirection message is input into the traffic redirection message processing strategy, and backflow and backwash judgments are performed.
[0012] If the backflow and back-dyeing are deemed successful, a backflow and back-dyeing message will be obtained.
[0013] The backflow and backflow-colored messages are distinguished and judged. If they are backflow messages, they are decapsulated, the messages are obtained and output. In the process of distinguishing backflow and backflow-colored messages, if they are backflow-colored messages, they are processed for backflow-colored flow table and stored in high-speed flow table to expand the data of high-speed flow table.
[0014] Further, the backflow backflow message is distinguished and judged, if it is not a backflow message, then end.
[0015] Further, if there is no hit drainage strategy, then the corresponding blocking strategy is selected according to the protocol field;
[0016] If the corresponding blocking strategy is hit, the original message is discarded, and it is judged whether the discarded original message is drained, if yes, the discarded original message is encapsulated and drained through the drainage message processing strategy, the discarded original message carries the strategy and information hit by the discarded original message.
[0017] Further, if there is no hit blocking strategy, the original message is output to the link.
[0018] Further, it is judged whether the discarded original message needs to be drained, if not, then end.
[0019] Further, the drainage strategy is at least one or more of the global drainage strategy based on flow, the drainage strategy based on feature message, the drainage strategy based on five-tuple mask rule and the drainage strategy based on flexible five-tuple rule.
[0020] Further, the mirror strategy is at least one or more of the global mirror strategy based on flow, the mirror strategy based on feature message, the mirror strategy based on five-tuple mask rule, the mirror strategy based on flexible five-tuple rule.
[0021] Further, the blocking strategy is at least one or more of the blocking strategy based on feature message, the blocking strategy based on five-tuple mask rule, the blocking strategy based on flexible five-tuple rule.
[0022] Further, when the blocking strategy and the drainage strategy are simultaneously judged to be valid, the drainage message executes the blocking strategy, and when the drainage message is drained, the drainage message carries the flag and the strategy information of the hit blocking strategy.
[0023] Further, when the drainage message processing strategy receives the drainage message, it is judged whether the drainage message is misjudged, and the misjudged message is backflowed to the link.
[0024] Compared with the prior art, the technical scheme innovatively adopts the cooperative processing idea of drainage and backflow, mirror and backflow, and constructs a high-speed, efficient and real-time network security protection system, which can accurately detect and timely block network attack traffic, bad information and illegal website access.
[0025] The traffic redirection mechanism uses multi-dimensional strategies to direct suspicious traffic to the backend detection module; the backflow mechanism ensures that normal traffic is processed and returned to the original path, guaranteeing business continuity. Mirroring technology replicates and analyzes critical traffic, while the backflow mechanism dynamically updates the detection results to the flow table, enabling precise control over subsequent similar traffic.
[0026] This solution leverages FPGA hardware acceleration, achieving line-rate processing speeds and enabling real-time responses to millions of frames per second of packet traffic, meeting the demands of high-speed network environments. While satisfying high-density integrated design requirements, it significantly reduces the processing cost per unit of traffic through optimized hardware architecture and algorithms, resulting in a substantial cost advantage.
[0027] This technology effectively solves core problems such as real-time interception of network attacks and precise filtering of malicious information, providing a practical solution for the protection of critical information infrastructure. Its innovative architecture and domestically developed design fill the technological gap in the field of high-speed network security protection, and promote the independent and controllable development of core network security technologies. Attached Figure Description
[0028] Figure 1 This is a flowchart illustrating the implementation method of the high-speed serial flow diversion and return anomaly detection message blocking based on FPGA of the present invention.
[0029] Figure 2 This is a schematic diagram of the encapsulation structure of the redirection message and return message of the present invention.
[0030] Figure 3 This is a schematic diagram of the mirror message encapsulation structure of the present invention.
[0031] Figure 4 This is a schematic diagram of the backwash message encapsulation structure of the present invention.
[0032] Figure 5 This is a schematic diagram illustrating the backwash message format of the present invention. Detailed Implementation
[0033] The technical solutions of the implementation method and system for high-speed serial current diversion and return anomaly detection and packet blocking based on FPGA provided by the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of the embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0034] like Figure 1 As shown, a method for blocking high-speed serial current diversion and return anomaly detection messages based on FPGA is described. This method includes:
[0035] The original message in the receiving link is input into the FPGA.
[0036] Specifically, the input of the original message in the receiving link into the FPGA is the starting link of the entire process, and the efficient and stable operation of this link directly affects the accuracy and real-time performance of subsequent abnormality detection and message blocking.
[0037] The receiving link is usually composed of a physical layer interface, a data link layer processing module, etc. The original message is transmitted in the form of high-speed serial data stream in the link, which contains rich network information such as source address, destination address, protocol type, data payload, etc.
[0038] When the original message enters the receiving link, it is first subjected to signal conversion and recovery by the physical layer interface. The physical layer interface converts the analog electrical or optical signals transmitted externally into digital signals recognizable by the FPGA, and realizes the synchronization of data and clock through clock data recovery technology, ensuring that the data can be accurately sampled under high-speed transmission. Subsequently, the synchronized digital signal is sent to the data link layer processing module, which performs preliminary processing such as frame synchronization and CRC check on the data, and eliminates invalid frames caused by transmission errors to ensure the integrity of the original message data entering the FPGA.
[0039] The method comprises: parsing the message and extracting the protocol field in the original message.
[0040] Specifically, after the original message is successfully input into the FPGA, parsing the message and extracting the protocol field is a key prerequisite for subsequent abnormality detection. This step aims to accurately extract the core information for judging whether the message is abnormal from the vast amount of original data, and provides reliable data support for the subsequent detection algorithm.
[0041] The FPGA uses a parallel pipeline architecture for message parsing, which can fully utilize the hardware resources of the FPGA to realize real-time parsing of high-speed messages. When the message data is read out from the buffer, it first enters the frame header identification module. This module can quickly locate the starting position of the frame header according to the characteristics of different network protocols.
[0042] After completing the Ethernet frame parsing, the data enters the network layer protocol parsing module. If the message contains IP protocol, this module will parse the IP header and extract the source IP address, destination IP address, IP protocol version, time to live, protocol type, etc. Among them, the source IP address and the destination IP address are the core information for judging the source and destination of the message, and the protocol type field indicates the transport layer protocol used by the upper layer, providing guidance for the next step of transport layer parsing.
[0043] For the analysis of the transport layer protocol, for the TCP protocol, the source port number, the destination port number, the sequence number, the acknowledgement number, and the control bits are extracted; for the UDP protocol, the source port number and the destination port number are mainly extracted. These port number information can clearly indicate the application program or service corresponding to the message, and the specific process of communication can be further determined in combination with the IP address, and the control bits of the TCP can reflect the establishment, maintenance and closing state of the connection, which is an important feature for detecting abnormal connection.
[0044] In the analysis process, the FPGA also verifies the length and checksum of the message, and if it finds a message with a checksum error or an abnormal length, it will be marked as an invalid message and discarded directly to avoid invalid data occupying subsequent processing resources. At the same time, in order to deal with protocol nesting and complex message structure, the analysis module uses configurable analysis rules that can be flexibly adapted according to the protocol types that may appear in the actual network environment, ensuring that even when encountering unknown protocols or custom protocols, basic address and port fields can be extracted, ensuring the compatibility and scalability of the analysis process.
[0045] Through the above analysis process, the FPGA can complete the extraction of the protocol fields of a single frame message within nanoseconds, integrating the key information scattered in the message into structured data. These data will be sent to the anomaly detection module for subsequent flow diversion and reflux state judgment and abnormal behavior analysis.
[0046] The method comprises: selecting a corresponding flow diversion strategy according to the protocol field, thereby obtaining a flow diversion message; if there is no corresponding flow diversion strategy, querying and updating the data of the high-speed flow table through the high-speed flow table outside the FPGA.
[0047] Specifically, the step of selecting a corresponding flow diversion strategy according to the protocol field is the core of implementing high-speed serial flow diversion, and its efficiency directly determines the processing capacity of the entire anomaly detection and plugging system.
[0048] The extracted protocol fields cover key information such as source IP address, destination IP address, source port number, destination port number, and protocol type, which together constitute the basis for judging the flow diversion path. A series of preset flow diversion strategies are stored in the FPGA in advance, which are based on network topology, security requirements, and business priority.
[0049] When the parsed protocol field completely matches the matching condition of a preset diversion strategy, the FPGA will immediately trigger the execution mechanism corresponding to the strategy, mark the original packet as a diversion packet, and guide it to the preset diversion path through the internal high-speed data channel. During the marking process, specific identification information such as diversion channel number and priority label will be added to the diversion packet to enable the subsequent backflow processing link to accurately identify and perform corresponding operations. At the same time, the FPGA will monitor the transmission process of the diversion packet in real time to ensure that it does not lose or out-of-order in the diversion path, ensuring the reliability of the diversion.
[0050] If the parsed protocol field does not have a corresponding preset diversion strategy, the FPGA will need to query and update data with the high-speed flow table attached externally. The high-speed flow table is a dynamic data structure based on SRAM or DDR4 high-speed storage medium, which stores the mapping relationship between the active traffic characteristics and the corresponding diversion strategy in the current network, and can support millions of query operations per second, perfectly adapting to the processing needs of high-speed packets.
[0051] The FPGA connects with the external high-speed flow table through a dedicated high-speed interface. When a query is needed, the FPGA will process the extracted protocol field according to a specific hash algorithm to generate a corresponding flow table index. Using this index, the FPGA can quickly locate the matching table entry in the high-speed flow table. If a matching flow table entry is found, the packet is marked as a diversion packet and the flow table entry is updated according to the packet transmission state, such as packet counter and last active time, to reflect the latest situation of the traffic.
[0052] If no matching flow table entry is found in the high-speed flow table, it means that the traffic characteristics corresponding to the packet are first appearing or not covered by the preset strategy. At this time, the FPGA will insert the protocol field information of the packet as a new flow table entry into the high-speed flow table according to the preset flow table update rule, and assign it a default diversion strategy. When inserting a new table entry, an LRU replacement algorithm is used to manage the high-speed flow table. When the flow table storage space is insufficient, the table entries that have not been accessed for a long time are automatically discarded to ensure that the flow table always stores the most active traffic characteristics. At the same time, the newly inserted flow table entry will be marked as a pending state, and its diversion strategy will be adjusted and optimized according to the actual network operation through interaction with the controller, realizing dynamic updating and adaptive management of the high-speed flow table data.
[0053] Through the above protocol field-based steering strategy selection and the query and update mechanism of the high-speed flow table, the FPGA can realize flexible and efficient steering of various types of messages, which not only ensures fast processing under the preset strategy, but also adapts to the changes of network traffic through the dynamic flow table, thereby laying a solid foundation for subsequent anomaly detection and backflow processing.
[0054] Further, the steering strategy is at least one or more of a flow-based global steering strategy, a feature message-based steering strategy, a steering strategy based on a five-tuple mask rule, and a flexible five-tuple rule-based steering strategy.
[0055] Specifically, the flow-based global steering strategy is to steer the first N messages of each flow for steering processing. This strategy has a separate control enable switch, and the size of N can be set by software. This strategy is used to steer the first N messages of all flows to the background software for business identification, attack detection, and other function identification and judgment.
[0056] The flow-based global steering strategy takes the flow table as the core basis and focuses on steering the first N messages of each flow in the network. This strategy plays an important role in accurately selecting key data and providing support for background deep analysis in the entire message processing flow.
[0057] The flow table not only stores the basic feature information of each flow, such as source IP address, destination IP address, source port number, destination port number, and protocol type, which constitute the unique identifier of the flow, but also records the number of messages that have been processed for each flow, and other state information. These information provides a data basis for accurately identifying the "first N messages". After the message is parsed and the protocol fields are extracted, the FPGA determines the flow to which the message belongs according to these fields, and quickly queries the processing status of the flow in the flow table.
[0058] The steering processing mechanism of the first N messages of each flow is as follows: for a newly appeared flow, when its first message arrives, the FPGA queries the flow table and finds that there is no processing record for the flow, so it marks the message as a steering message, and creates an entry for the flow in the flow table, recording the number of steered messages as 1; when the second message of the flow arrives, if the number of steered messages is less than N, it continues to be marked as a steering message and updates the corresponding count in the flow table; and so on, until the number of steered messages of the flow reaches N, and the subsequent messages are no longer subjected to steering operation and are processed according to the normal forwarding path.
[0059] This strategy is equipped with a separate control enable switch, which is integrated in the form of a hardware register inside the FPGA, and the switch is turned on and off by writing specific instructions to the register through software. When the switch is on, the global traffic steering strategy takes effect, and the first N packets of all flows are steered to the background software; when the switch is off, the strategy is suspended, regardless of the number of flows recorded in the flow table, no additional steering of packets is performed, this design enables the strategy to be flexibly started and stopped according to actual business needs, reducing unnecessary steering overhead and improving overall processing efficiency when background analysis is not needed.
[0060] The size of N can be set by software, and a special configuration register is provided inside the FPGA to store the value of N, and software can read and write to this register through a bus interface. The value of N usually ranges from 1 to several thousand, and the specific value can be adjusted according to the characteristics of the flow in the network and the processing capacity of the background software. Moreover, the setting of N is dynamic, and during system operation, software can modify the value of N in real time according to the changes in network traffic and the effect of business analysis, so that the steering strategy is always in the optimal state.
[0061] The core function of this strategy is to steer the first N packets of all flows to the background software, providing a key data source for the background software to carry out business identification, attack detection and other functions. For business identification, the first few packets of a flow often contain key features such as protocol handshake information and application identification, and the background software can quickly determine the type of the flow, such as video stream, file transfer stream, instant messaging stream, etc., providing a basis for subsequent differentiated processing and bandwidth allocation. In terms of attack detection, many network attack behaviors will exhibit abnormal characteristics in the initial stage of the flow, and since only the first N packets are steered, a large amount of data transmission caused by steering the entire flow is avoided, ensuring the information needed for background analysis while minimizing the occupation of network bandwidth and background processing resources.
[0062] The steering strategy based on feature packets is based on feature lookup table, for a specific feature, software can set the packet that hits this feature to be steered for processing. The core logic is to perform lookup operation on the features carried by the packet itself, and for packets that meet specific features, software can set rules in advance to include them in the steering processing range. This strategy has strong pertinence and flexibility, and can accurately capture packets with specific attributes in the network.
[0063] The message features mentioned herein encompass a wide range of content, including specific values in protocol fields, such as a source IP address in a certain network segment, a destination port number of 80 or 443, a common service port, an ICMP protocol type, etc., as well as specific strings or characteristic codes in the data payload. These features are pre-processed and stored in a dedicated feature table, which is similar to a high-speed flow table and also uses high-speed storage media to support the FPGA's rapid query of message features.
[0064] When the FPGA completes the analysis of the message and extracts the relevant fields and content, it will start the feature-based table lookup process. First, the FPGA will extract the corresponding feature information from the parsed message according to the pre-set feature extraction rules. Then, the FPGA will compare the extracted feature information with the entries in the feature table one by one. The comparison process uses a parallel search algorithm, which can complete the matching check of a single frame of message with all entries in the feature table in a very short time.
[0065] Software plays a key role in rule-making and configuration in this strategy. Staff can flexibly set the feature table through the software interface or programming interface. When it is necessary to divert messages with a certain specific feature, the software will write the information corresponding to the feature into the feature table and associate it with the diversion label, and set the diversion path for the message that hits the feature.
[0066] The software's settings for the feature table not only include adding new feature entries, but also support modifying and deleting existing entries. When the network environment changes and some original features are no longer needed, the software can quickly delete the corresponding feature table entries. When it is necessary to adjust the diversion strategy for a certain feature message, such as changing the diversion path or canceling the diversion, the software can directly modify the configuration information associated with the feature entry. The entire process does not need to interrupt the normal operation of the FPGA, ensuring the real-time and convenience of policy adjustment.
[0067] In addition, to cope with complex and variable network scenarios, the software also supports the combination of features, i.e., multiple different features can be logically combined to form more accurate diversion rules. When a message meets all the conditions in the combined features, it is determined to hit the feature, triggering the diversion process. This combination setting method further improves the accuracy of the diversion strategy and effectively avoids the occurrence of mis-diversion.
[0068] The advantage of the feature message-based diversion strategy is that it can focus on messages with specific significance in the network. Through flexible software configuration, the diversion target can be adjusted at any time according to actual needs, which can be used for security detection to capture potential threat messages in time, and can also be used for business monitoring to analyze the traffic of messages of specific business types, providing strong support for network management and optimization. At the same time, since only messages that hit specific features are diverted, the amount of diversion data is greatly reduced, and the pressure on the background processing resources is reduced. In cooperation with the global diversion strategy based on flow, a multi-level and comprehensive diversion system is constructed.
[0069] The diversion strategy based on five-tuple mask rules can configure any mask rules for five-tuple information, and divert the messages that hit the mask rules. It takes the five-tuple information of the message as the core, and through the configuration of any mask rules, it implements diversion processing on the messages that hit the rules, which can meet the diversified and refined diversion needs in the network.
[0070] Five-tuple information is the most critical identifying information in network messages, which specifically includes source IP address, destination IP address, source port number, destination port number, and transport layer protocol type. These five elements together constitute the basic characteristics of a flow, which can uniquely identify a specific communication process in the network. The mask rule is to determine the field part that needs to be concerned by setting the mask bit based on the five-tuple information. Through the mask rule, messages with similar characteristics can be classified into a category, and batch diversion processing of messages within a certain range can be realized.
[0071] When configuring the diversion strategy based on five-tuple mask rules, the software provides an intuitive and flexible configuration interface. The staff can set the mask for each element in the five-tuple according to actual needs. Taking the source IP address as an example, if you want to divert all messages from the 192.168.1.0 / 24 network segment, you can set the mask of the source IP address to 255.255.255.0. At this time, as long as the first 24 bits of the source IP address of the message are 192.168.1, regardless of the last 8 bits, it will be determined to hit the mask rule. For port numbers, if you want to divert messages with source port numbers between 1024 and 65535, you can set the source port mask to 0xFFFF and cooperate with the port range rule to make the port numbers within the range hit.
[0072] In addition to setting the mask for a single five-tuple element, this strategy also supports setting mask rules for multiple element combinations. This combined mask rule can further narrow the diversion range and improve the accuracy of diversion, avoiding the misdiversion of irrelevant messages.
[0073] When the FPGA receives the packet and completes the parsing, the quintuple information in the packet is extracted and compared with the pre-configured quintuple mask rule. During the comparison process, the FPGA processes each element of the quintuple according to the mask rule and only compares the effective bits specified by the mask. If the processed quintuple information is completely consistent with the matching value in the mask rule, it is determined that the packet hits the rule, and the diversion mechanism is triggered to send the packet to the background processing module through the preset diversion path.
[0074] The advantage of this strategy lies in its strong flexibility and adaptability. By configuring different mask rules, both precise diversion of specific individual packets and batch diversion of a certain type or range of packets can be achieved. At the same time, the configuration of mask rules is dynamic, and during system operation, staff can modify the mask rules through software at any time according to network traffic changes and business needs, without the need to restart the system, ensuring the real-time and scalability of the diversion strategy.
[0075] In practical applications, the diversion strategy based on quintuple mask rules can be widely used in various scenarios. For example, in network monitoring, mask rules can be configured to divert all packets accessing a specific server to analyze the server's access situation; in security protection, mask rules can be configured for known attack source IP addresses to divert all packets from the source to a security detection engine for deep detection; in bandwidth management, mask rules can be used to divert large-volume video streams for bandwidth limitation or quality optimization.
[0076] Compared with the global flow-based diversion strategy and the feature packet-based diversion strategy, the quintuple mask rule-based diversion strategy focuses more on precise matching of packet communication identifiers and can achieve macro-to-micro full-range diversion control through flexible mask settings. The three strategies complement each other and together build an efficient and reliable diversion system, providing strong support for subsequent anomaly detection and packet blocking.
[0077] The flexible quintuple rule diversion strategy can perform rule matching on a single arbitrary 5-tuple and divert the flow that hits the strategy.
[0078] The core is the ability to perform precise rule matching on a single arbitrary 5-tuple. When the 5-tuple information of a flow matches the pre-set rule exactly, the flow is diverted. This strategy greatly improves the accuracy and relevance of diversion and better meets the diversion needs in specific scenarios.
[0079] The single arbitrary quintuple mentioned here covers all possible combinations in network communication, which can be a combination of a specific source IP address, a specific destination IP address, a specific source port number, a specific destination port number, and a specific protocol type, or a combination of some fixed elements and some flexible elements. However, when matching rules, the quintuple information of the flow must fully correspond to each item in the preset rule.
[0080] In terms of rule configuration, the software provides a detailed and convenient operation interface. According to actual business needs, staff can manually input or select specific quintuple element values to build a single quintuple rule. After configuration is complete, the rule is stored in a dedicated rule table in the FPGA. The rule table uses a high-speed storage structure to ensure that the FPGA can quickly read and compare rules.
[0081] When the FPGA parses the received packet and extracts the quintuple information of the flow, it immediately compares the quintuple with the single arbitrary quintuple rule in the rule table. During the comparison process, the FPGA accurately matches each element of the quintuple, i.e., the source IP address must be exactly the same as the source IP address in the rule, and the destination IP address, source port number, destination port number, and protocol type must also correspond one by one. This accurate comparison mechanism avoids false positives due to fuzzy matching and ensures that only flows that fully comply with the rules are diverted.
[0082] Once it is determined that a flow hits the preset single arbitrary quintuple rule, the FPGA will immediately start the flow diversion process for that flow. Unlike the flow diversion for individual packets, the flow diversion object here is the entire flow, i.e., from the first hit packet of the flow, all subsequent packets belonging to the flow will be continuously diverted to the designated background processing module. During the diversion process, the FPGA will mark the flow, and through the internal flow tracking mechanism, it will identify the subsequent packets belonging to the flow in real time, ensuring the continuity and integrity of the diversion.
[0083] The flexible quintuple rule diversion strategy has unique value in practical applications. In network troubleshooting, when a specific communication flow appears abnormal, the flow can be diverted to an analysis tool by configuring its quintuple rule to analyze the entire flow of packets and quickly locate the fault cause. In specific business assurance, for special communication flows of key businesses, rules can be configured to divert them to processing channels with higher priority, ensuring stable transmission of the business. In security auditing, for specific flows involving sensitive information transmission, the flow can be recorded and audited throughout the process through diversion processing to meet compliance requirements.
[0084] Compared with the diversion strategy based on the five-tuple mask rule, the diversion strategy of flexible five-tuple rule focuses on "precise matching", does not use mask to range screen elements, but matches specific five-tuple combinations, and therefore has irreplaceable advantages when a certain specific flow needs to be processed individually. Meanwhile, the rules of the strategy also support dynamic updating, and the staff can add, modify or delete single five-tuple rules in the rule table at any time according to needs, so that the diversion strategy can quickly adapt to changes in the network environment
[0085] The method comprises: if the hit diversion strategy, performing mirror strategy on the diversion packet and encapsulating; inputting the encapsulated diversion packet into the diversion packet processing strategy, and performing backflow and back-tint judgment.
[0086] Specifically, the diversion packet is encapsulated by VxLAN, and the encapsulation format is as shown in Figure 2 The source and destination port numbers in the diversion packet are both 4789.
[0087] Specifically, when the packet hits the preset diversion strategy, it enters the mirror strategy implementation and encapsulation link of the diversion packet. This link is the key link connecting diversion and subsequent processing, and its processing effect directly affects the transmission quality of the diversion packet and the accuracy of subsequent judgment.
[0088] The core of the mirror strategy is to copy or split the diversion packet to meet different business needs. According to the actual application scenario, the mirror strategy can be divided into multiple types, and a special mirror processing module is provided in the FPGA. The module will copy or split the diversion packet in real time according to the preset mirror rule. The copying process adopts a parallel processing mechanism to ensure that the mirror operation does not affect the transmission delay of the original packet in the high-speed packet transmission scenario.
[0089] After completing the mirror processing, the diversion packet needs to be encapsulated. The purpose of encapsulation is to add specific identification information and control fields to the diversion packet, so that it can be accurately identified and managed in the subsequent transmission and processing process. The contents of encapsulation usually include diversion strategy identification, metadata of the original packet, check field, etc. The encapsulation process is completed by the encapsulation engine in the FPGA. The engine uses an efficient protocol encapsulation algorithm to complete the encapsulation of a single frame of diversion packet within microseconds. The encapsulated diversion packet will form a frame structure that conforms to a specific format. This frame structure not only meets the interface requirements of the back-end processing module, but also carries enough control information to provide a basis for the subsequent execution of the diversion packet processing strategy.
[0090] After the encapsulated flow-off message is input into the flow-off message processing strategy, the first task is to perform flow-back and flow-reaction judgment. The flow-back judgment mainly determines whether the flow-off message needs to be returned to the original transmission path after being processed by the background processing module. The judgment basis is usually based on the feedback result of the background processing module. For example, if the background processing determines that the flow-off message is normal service traffic and needs to continue to be transmitted to the destination address, the flow-back mechanism is triggered; if it is determined to be an abnormal message, it does not need to flow back and is directly blocked. The flow-back judgment module in the FPGA will receive the feedback signal of the background processing module in real time, and combine the identification information encapsulated in the flow-off message to quickly make a decision on whether to flow back.
[0091] The flow-reaction judgment is to determine whether the flow-back flow-off message needs to be marked or modified to reflect the result of the background processing. The flow-reaction judgment is also completed by a special module in the FPGA. According to the instructions of the background processing and the preset flow-reaction rules, the module performs necessary marking or field modification on the flow-back message. The modification process uses atomic operation to ensure the consistency and integrity of the message.
[0092] During the flow-back and flow-reaction judgment process, the FPGA maintains high-speed communication with the background processing module, and exchanges processing results and control instructions in real time through a dedicated control channel. In order to cope with the high-concurrency flow-off message processing scene, the judgment process adopts a pipeline processing architecture, and multiple flow-off messages can perform judgment operations in parallel at different processing stages, greatly improving the processing efficiency. At the same time, the judgment result is recorded in real time to the internal log module, which records the processing time, flow-back state, flow-reaction marking and other information of the flow-off message, providing a basis for subsequent system debugging and performance analysis.
[0093] Through the above mirror encapsulation, flow-back and flow-reaction judgment process, the flow-off message can complete the whole process management from flow-off to processing and possible flow-back according to the preset strategy, which not only ensures that the background processing module can obtain enough flow data for analysis, but also ensures the smooth transmission of normal service traffic, realizing the organic combination of abnormal detection and network normal operation.
[0094] Further, the mirror strategy is at least one or more of a global mirror strategy based on flow, a mirror strategy based on feature message, a mirror strategy based on five-tuple mask rule, or a mirror strategy based on flexible five-tuple rule. The mirror strategy is independently managed and configured. The difference between the mirror strategy and the flow-off strategy is that the mirror is copied from the original message stream. The forwarding process of the original message stream is unchanged. The flow-off strategy changes the forwarding process of the original message stream, and the message stream hit by the flow-off strategy is processed by the flow-off strategy. The message stream processed by the flow-off is returned to the original forwarding path.
[0095] The global mirroring strategy based on flow table is to mirror the first N packets of each flow. This strategy has a separate control enable switch, and the size of N can be set by software. This strategy is used to mirror the first N packets of all flows to the background software for business identification, attack detection and other functions. The core logic of this strategy is to mirror the first N packets of each flow based on the flow table. This strategy provides an efficient and targeted data source for the business identification and attack detection functions of the background software by accurately selecting the initial packets of the flow.
[0096] The flow table plays a key role here, as it stores basic information about each flow in the network, including the unique identifier of the flow, the state of the flow, and the count of processed packets for the flow. When a packet enters the processing flow, the FPGA determines the flow to which it belongs based on the information in the packet, and queries the flow table for the relevant records of that flow to determine whether to perform a mirroring operation on the current packet.
[0097] The mirroring process of the first N packets of each flow has clear targeting. For a newly emerging flow, when its first packet arrives, the FPGA queries the flow table and finds that the packet count for that flow is 0, triggering the mirroring mechanism and mirroring the packet. At the same time, the packet count for that flow in the flow table is incremented by 1. When the second packet of the flow arrives, if the count is still less than N, mirroring is continued and the count is updated until the count reaches N. At this point, the subsequent packets of the flow are no longer mirrored and are transmitted along the normal path. This processing method ensures that the background software can obtain key information at the initial stage of each flow, while avoiding the large data transmission pressure caused by mirroring the entire flow, achieving a good balance between efficiency and information integrity.
[0098] This strategy is equipped with a separate control enable switch, which provides a convenient way for flexible activation and deactivation of the strategy. The control enable switch is usually integrated in the form of a hardware register inside the FPGA, and the staff can control the switch state by writing specific instructions to the register through software. When the switch is on, the global mirroring strategy takes effect, and the first N packets of all flows will be mirrored according to the rules. When the switch is off, the strategy is suspended and no mirroring is performed. This design allows the strategy to be quickly turned off to save system resources when background analysis is not needed, or quickly turned on when needed, adapting to different network operation scenarios.
[0099] The size of N can be flexibly set by software, allowing the strategy to be dynamically adjusted according to actual needs. Software can modify the value of N by accessing the configuration register inside the FPGA, and the value range of N usually ranges from 1 to hundreds or even thousands.
[0100] The core role of this strategy is to mirror the first N packets of all flows to the background software, providing support for the implementation of various functions. In terms of traffic identification, the first N packets of a flow often contain key information such as protocol characteristics, handshake information, etc. The background software can quickly determine the type of traffic to which the flow belongs, such as video stream, file transfer stream, etc., providing a basis for subsequent differentiated services and resource allocation. For attack detection, many attack behaviors will exhibit abnormal characteristics in the initial stage of the flow, such as probe packets of port scanning attacks, initial connection packets of malware, etc. The background software can detect potential attack signs in time by analyzing these first N mirrored packets and generate corresponding detection results to provide decision support for subsequent protection measures.
[0101] In addition, since only the first N packets of each flow are mirrored, this strategy greatly reduces the occupation of network bandwidth and background storage and processing resources. Compared with mirroring the entire flow, the data volume is greatly reduced, but the key information in the initial stage of the flow is preserved, ensuring the effective operation of the background functions while improving the overall performance and resource utilization of the system
[0102] The mirroring strategy based on feature packets is based on feature lookup table of packets. For a specific feature, the software can set the packets that hit this feature for mirroring processing. The core mechanism is to match the features carried by the packets themselves. For packets that meet specific features, the software pre-set rules make them included in the mirroring processing range, thereby providing accurate analysis data for the background software.
[0103] The packet features here cover a wide range of dimensions, including fixed identifiers in protocol fields, specific source IP address segments, destination port numbers, and protocol types, as well as feature codes in data payloads, such as virus feature strings and specific application identifier fields. It also involves behavior attributes of packets, such as abnormal packet length and TTL value jump. These features are systematically stored in a feature table outside the FPGA. The feature table is built with high-speed storage media to support nanosecond-level lookup table responses to meet real-time processing needs in high-speed network environments.
[0104] When a packet enters the FPGA processing flow, it first passes through the analysis module to extract key information, and then enters the feature matching engine. The engine will extract the corresponding feature fields from the packet according to the pre-set feature extraction rules and perform parallel comparison with the entries in the feature table. The comparison process uses hardware-accelerated hash algorithms or exact matching algorithms, which can complete the simultaneous verification of multiple features in a single clock cycle, ensuring that even under a packet flow of millions of frames per second, feature matching can be achieved without blocking.
[0105] Software plays a core role in feature configuration and rule management in this strategy. Staff can add, modify or delete feature entries in the feature table through a graphical interface or command line tools.
[0106] During software configuration, hierarchical and combined feature settings are also supported. This combined feature mechanism greatly improves the accuracy of mirroring and avoids irrelevant packets occupying mirroring bandwidth. In addition, the software regularly maintains the feature table and automatically cleans up invalid features that have not been hit for a long time through an aging mechanism, ensuring efficient use of storage resources.
[0107] When the FPGA feature matching engine determines that a packet hits a certain feature in the feature table, it will immediately trigger the mirroring processing flow. The mirroring module will copy the packet in real time to generate a mirror copy identical to the original packet. One copy continues along the original path to ensure network communication is not affected, while the other copy is encapsulated with a mirror identifier and sent to the backend analysis device through a dedicated mirror channel. The encapsulation process uses a lightweight protocol that only adds necessary metadata to minimize additional overhead on mirror traffic.
[0108] The advantage of this strategy is its high flexibility and accuracy. By focusing on packets with specific features, it can provide targeted analysis samples for backend software and avoid bandwidth waste caused by global mirroring. In practical applications, this strategy can be widely used in security monitoring, business analysis, fault diagnosis and other scenarios. For example, when an unknown attack occurs in the network, administrators can quickly add attack features through software to mirror related packets for reverse analysis, thereby quickly generating defense rules, demonstrating the closed-loop processing capability of "from accurate mirroring to deep analysis to rapid response".
[0109] The mirroring strategy based on five-tuple mask rules can configure arbitrary mask rules for five-tuple information and mirror packets that hit the mask rules. Its core is to configure arbitrary mask rules for five-tuple information to achieve directional mirroring of packets that hit the rules, providing targeted traffic data for analysis and monitoring by backend software.
[0110] Five-tuple information includes source IP address, destination IP address, source port number, destination port number and protocol type, which together form the core identifier of network packets. Mask rules are used to set specific mask values to filter each field in the five-tuple, thereby determining the range of packets that need to be mirrored.
[0111] During the configuration process, the software provides an intuitive and flexible operation interface, and the staff can set mask rules for each field of the quintuple according to actual needs. For the source IP address and the destination IP address, the mask is represented by a 32-bit binary number, and the value of each bit determines whether the corresponding IP address bit participates in matching, 1 means that the bit needs to be matched accurately, and 0 means that the bit is ignored. For the source port number and the destination port number, the mask is a 16-bit binary number, and by setting different mask values, matching of specific ports or port ranges can be achieved. The mask of the protocol type field is an 8-bit binary number, and by setting the mask, packets of specific protocol types can be filtered out, such as only mirroring packets of TCP protocol or UDP protocol.
[0112] In addition to setting mask rules for a single field, the strategy also supports the configuration of multi-field combined mask rules. A combination rule of "source IP address is 10.0.0.0 / 8 network segment, destination port number is 80, and protocol type is TCP" can be configured, and only packets that meet all three conditions will be determined as a hit rule and mirrored. This combined configuration method greatly improves the accuracy of mirroring and can accurately capture traffic with specific combination characteristics, avoiding unrelated packets occupying mirror resources.
[0113] When the FPGA receives a packet, it will first parse the packet and extract the quintuple information, and then compare it with the pre-configured quintuple mask rules. During comparison, FPGA will process each field of the quintuple according to the mask rule and only compare the effective bits specified by the mask. If the processed quintuple information is exactly the same as the matching value in the rule, it is determined that the packet hits the rule, and the mirroring mechanism is triggered.
[0114] During the mirroring process, the mirror module inside the FPGA will copy the packet that hits the rule in real time to generate a mirror copy that is exactly the same as the original packet. Among them, the original packet continues to transmit along the normal path to ensure that network communication is not affected; the mirror copy is added with mirror identification information such as rule number, hit timestamp, etc., which helps the background software to distinguish mirror packets matched by different rules. Subsequently, the mirror copy is sent to the background analysis device such as the traffic monitoring system, intrusion detection system, etc. through a dedicated high-speed mirror channel. In order to ensure the efficient transmission of the mirror channel, the addition of mirror identification information adopts a lightweight design, which only occupies a small amount of additional bandwidth, avoiding affecting the overall network performance.
[0115] The advantage of this strategy lies in its strong flexibility and adaptability. By configuring different mask rules, both precise mirroring of specific individual packets and batch mirroring of certain types or ranges of packets can be achieved. At the same time, the configuration of mask rules supports dynamic updating, and staff can modify the rules through software at any time according to changes in network traffic and business needs, without the need to restart the system, ensuring that the mirroring strategy can quickly respond to changes in the network environment.
[0116] In practical applications, the mirroring strategy based on five-tuple mask rules can be widely used in various scenarios. In network security protection, mask rules can be configured to mirror packets from specific suspicious network segments and access specific ports, facilitating the detection of potential attack behavior by the background system; in business analysis, mask rules can be configured for the IP address and port of the key business server to mirror all access to the server, analyze the traffic characteristics and running status of the business; in bandwidth management, mask rules can be used to mirror the packets of high-traffic applications to provide data support for bandwidth allocation and optimization.
[0117] Compared with other mirroring strategies, the mirroring strategy based on five-tuple mask rules can accurately locate the traffic that needs attention in complex network environments due to its flexible matching capability for network core identifiers, providing efficient and valuable mirroring data for the background software, and is an important part of the network monitoring and analysis system.
[0118] The flexible five-tuple rule mirroring strategy performs rule matching on a single arbitrary five-tuple and mirrors the flow that hits the strategy. Its core is to perform rule matching on a single arbitrary five-tuple, and when the five-tuple information of a flow exactly matches the preset rule, the flow is mirrored, which can accurately lock specific traffic and provide highly focused data support for background analysis.
[0119] Here, the single arbitrary five-tuple refers to a specific and unique combination of source IP address, destination IP address, source port number, destination port number, and protocol type. It can be any possible five-tuple combination in the network, either a specific protocol and source port combination used by a specific user accessing a specific server, or any other five-tuple information with a clear identifier. This focus on a single five-tuple enables the mirroring strategy to accurately capture specific flows.
[0120] In terms of rule configuration, the software provides detailed and meticulous operation methods. Staff can manually input or select specific five-tuple element values through a dedicated configuration interface to build mirroring rules for a single five-tuple. After configuration, the rule is stored in a dedicated rule table in the FPGA, and the rule table uses a high-speed storage structure to ensure that the FPGA can quickly read and perform matching operations.
[0121] When the FPGA receives the packet and completes the parsing, the five-tuple information of the flow to which the packet belongs is extracted, and then it is compared with the single arbitrary five-tuple rule stored in the rule table one by one. During the comparison process, the FPGA will strictly match each element of the five-tuple. The source IP address must be exactly the same as the source IP address in the rule, and the destination IP address, source port number, destination port number and protocol type also need to be matched one by one, without any deviation. This accurate comparison mechanism ensures that only the flow that completely matches the preset rule can be hit, avoiding irrelevant traffic from being mirrored due to ambiguous matching, greatly improving the accuracy of mirroring.
[0122] Once it is determined that a flow hits the flexible five-tuple rule, the FPGA will immediately start mirroring processing for the flow. Unlike mirroring for individual packets, the mirroring object here is the entire flow, that is, from the first hit packet of the flow, all subsequent packets belonging to the flow will be continuously mirrored. The flow tracking module inside the FPGA will monitor the subsequent packets of the flow in real time, accurately identify the packets belonging to the flow through the five-tuple information, and ensure the continuity and integrity of mirroring.
[0123] During the mirroring process, the mirroring module of the FPGA will copy each packet of the hit flow in real time to generate a mirror copy identical to the original packet. The original packet continues to transmit along the normal path, ensuring smooth network communication; the mirror copy is added with specific mirror identification, such as the unique identification of the flow, the number of the hit rule, etc., which helps the background software to clearly identify the flow to which the mirror packet belongs and the corresponding rule. Then, the mirror copy is sent to the background analysis device, such as the deep packet inspection system, the service analysis platform, etc., through the dedicated high-speed mirror channel.
[0124] The significant advantage of this strategy lies in its unparalleled accuracy. By matching the rules for single arbitrary five-tuple, it can accurately lock specific flows for mirroring, without interfering with other irrelevant flows, effectively reducing the amount of mirrored data and reducing the occupation of background processing resources and network bandwidth. At the same time, the configuration of the rules has high flexibility, and the staff can add, modify or delete the five-tuple rules in the rule table at any time according to the actual needs, and dynamically adjust during system operation to adapt to the changes of specific flows in the network.
[0125] Specifically, the mirror packet is encapsulated in VxLAN format, and its encapsulation structure is as shown in Figure 3 To distinguish between the flow and the mirror packet, the UDP source port number is 6188.
[0126] The method comprises: if the backflow and backmatching judgment is successful, a backflow backmatching packet is obtained.
[0127] Specifically, the backflow return message is distinguished and judged, if it is a backflow message, it is unpacked to obtain the message and output; in the process of distinguishing and judging the backflow return message, if it is a backflow message, it is processed by the backflow flow table and stored in the high-speed flow table, and the data of the high-speed flow table is expanded.
[0128] Specifically, when the backflow and backflow judgment is successful, it means that the flow message meets the conditions of backflow or backflow after background processing, at this time, the backflow return message is obtained. This result is an effective connection to the previous flow, processing and judgment link, and lays a foundation for subsequent message processing or flow table updating.
[0129] Next, the backflow return message needs to be distinguished and judged, which is completed by a special identification module in the FPGA. The module will distinguish the message type according to the specific identifier in the encapsulation information of the backflow return message.
[0130] If the judgment result is a backflow message, it means that the message does not need to be marked or modified after background processing, and only needs to return to the original transmission path for continuous transmission. At this time, the FPGA will start the unpacking process. The unpacking process corresponds to the previous encapsulation process. The unpacking engine will strip off the flow strategy identifier, metadata, check field and other information added during encapsulation, and restore the complete structure of the original message. In the unpacking process, the check field will be verified to ensure that the message has not been damaged during transmission and processing. If the verification fails, the message will be marked as invalid and discarded to avoid incorrect messages entering the original transmission path. After unpacking, the original message obtained by the FPGA will be output according to its original destination address and transmission path through the corresponding output port. Thus, the whole processing flow of the message is completed, and the message successfully returns to the normal network transmission track.
[0131] If the distinguishing and judging result is a backflow message, it means that the message needs to update the related information to the flow table after background processing to realize accurate processing of subsequent similar traffic. At this time, the FPGA will process the backflow flow table. The backflow flow table processing will first extract the key information carried in the backflow message, including the five-tuple information of the original message and the strategy adjustment instruction obtained by background processing. Then, the FPGA will generate new flow table entries or update existing flow table entries according to these information.
[0132] After generating or updating the flow table entry, the FPGA stores the processed flow table entry in the high-speed flow table, thereby expanding the data of the high-speed flow table. During the storage process, the high-speed flow table adopts an efficient storage management mechanism to ensure that the new flow table entry can be quickly written, while not affecting the query and reading of other flow table entries. For the newly added flow table entry, the LRU replacement algorithm mentioned earlier is used for management, so as to ensure that the high-speed flow table always stores the most valuable flow information. In addition, the flow table entry stored in the high-speed flow table is marked as an effective state, so that it can immediately participate in subsequent packet processing. When the same type of packet enters, the FPGA can directly query the high-speed flow table to obtain the corresponding processing strategy, thereby improving the processing efficiency.
[0133] Through the differential processing of the backflow and back-tint packets, the smooth transmission of the normal backflow packets is ensured, and the dynamic updating of the back-tint packets on the flow table is realized, so that the high-speed flow table can reflect the latest business requirements and security status in the network in real time, thereby further improving the adaptability and accuracy of the entire abnormal detection and packet blocking system.
[0134] The backflow packet is encapsulated by VxLAN, and its encapsulation format is as shown in Figure 2 The source and destination port numbers in the backflow packet are both 4789.
[0135] The back-tint packet is encapsulated by a normal UDP packet, and the source and destination port numbers in the back-tint packet are 6188. Its encapsulation format is as shown in Figure 4 , and its internal part is a self-defined back-tint packet information frame format, including a back-tint packet frame header format and a back-tint information frame format, as shown in Figure 5 .
[0136] Further, if the backflow and back-tint packets are distinguished, and if it is not a backflow packet, the process is ended.
[0137] Specifically, in the process of distinguishing the backflow and back-tint packets, in addition to the two cases of being a backflow packet or a back-tint packet, there may be a case of neither being a backflow packet nor a back-tint packet. At this time, according to the processing logic, the process is directly ended.
[0138] This "not a backflow packet" case is usually due to the fact that the packet is determined to be unnecessary for any subsequent operation in the background processing process, and neither needs to return to the original transmission path nor has related information to be updated to the high-speed flow table.
[0139] When the special identification module of the FPGA identifies such a packet, it will immediately terminate the subsequent processing flow of the packet. Specifically, the FPGA will not perform unpacking operation on the packet, nor will it perform backflow stream table processing, but will directly include it in the internal abandoned packet queue. The abandoned packet queue will regularly delete the packets in the queue according to the preset cleaning mechanism to release the storage resources and processing resources of the FPGA, avoid invalid data occupying system resources, and affect the overall processing efficiency.
[0140] At the same time, the FPGA will record the processing situation of such non-backflow packets in the log, including the identification information of the packet, the time when the packet is determined as a non-backflow packet, and the reason code, etc. These log information will be stored in the internal log buffer, which is convenient for subsequent management personnel to query and analyze through software to understand the processing situation of the system for various packets, and to provide reference basis for optimizing the flow strategy and background processing logic.
[0141] The significance of this processing method lies in that it can ensure efficient use of system resources, and concentrate limited computing power and storage resources for processing valuable backflow packets and backflow stream packets, avoiding wasting resources on invalid packets. At the same time, the explicit ending mechanism also ensures the simplicity and certainty of the processing flow, making the running logic of the entire system more clear, reducing errors or redundant operations caused by ambiguous processing, and further improving the stability and reliability of the high-speed serial connection flow and backflow abnormal detection packet plugging system based on FPGA.
[0142] Further, the method further comprises: if no flow strategy is hit, a corresponding plugging strategy is selected according to a protocol field.
[0143] If the corresponding plugging strategy is hit, the original packet is discarded, and it is judged whether the discarded original packet is flow or not. If it is, the discarded original packet is encapsulated and flow is performed through the flow packet processing strategy. The discarded original packet carries the strategy and information hit by the discarded original packet.
[0144] Specifically, when the packet does not hit any flow strategy, the system will enter the plugging strategy processing flow based on the protocol field, which is an important barrier to network security and can intercept packets with potential risks in time.
[0145] When it is determined that no flow strategy is hit, the FPGA will call the internal plugging strategy matching module, which compares the protocol field extracted from the packet with the pre-configured plugging strategy library. The protocol field includes source IP address, destination IP address, protocol type, port number and other key information, which is the core basis for judging whether the packet needs to be plugged.
[0146] If the packet hits the corresponding blocking policy, the FPGA will immediately execute the operation of discarding the original packet. Before the original packet is discarded, it will undergo integrity verification to ensure that it is indeed an invalid packet that hits the blocking policy, avoiding the misdeletion of normal packets. The discarding operation is achieved by removing the original packet from the data transmission link and releasing the buffer resources it occupies, ensuring that the blocked packet cannot enter the subsequent network transmission path, thereby blocking potential threats from the source.
[0147] After discarding the original packet, the system further determines whether the discarded original packet needs to be diverted. If not, the process ends.
[0148] If the discarded original packet is determined to need to be diverted, the FPGA will perform encapsulation processing on the discarded original packet. The encapsulation content includes information such as blocking policy identification, protocol field digest of the original packet, and discarding timestamp. These information not only provide basis for back-end auditing, but also help administrators trace the details of the blocking event. The encapsulation process uses the same efficient algorithm as the diversion packet encapsulation to ensure that encapsulation is completed in a short time, and the format of the encapsulated packet meets the interface specifications of the back-end processing module.
[0149] The encapsulated diversion packet is input into the diversion packet processing policy and enters the backflow and back-rinse judgment link. At this time, the backflow judgment is mainly used to confirm whether the encapsulated diversion packet needs to be returned to a specific log recording path instead of the original transmission path, and the back-rinse judgment is used to determine whether to update the information of the blocking event to the high-speed flow table.
[0150] The entire process forms a complete security protection mechanism through accurate blocking and subsequent processing of packets that do not hit the diversion policy. It not only can intercept threat packets in time, but also can achieve dynamic response to network threats through encapsulation information and flow table updating, improving the active defense capability of the system. At the same time, the judgment and operation of each link are executed by FPGA at hardware level, ensuring that the processing delay can still be maintained at milliseconds level in high-speed network environment, meeting the real-time protection requirements.
[0151] Further, if there is no matching blocking policy, the original packet is output to the link.
[0152] Specifically, when the packet does not hit any diversion policy and does not hit any blocking policy, it means that the packet is judged by the system to be normal and legal network traffic. At this time, according to the processing logic, the system will output the original packet to the link to ensure that it can continue to complete the normal network transmission mission.
[0153] The core basis of this processing mode is the "innocent until proven guilty" principle of network communication, that is, in the absence of evidence that the message is abnormal or threatening, it is considered normal traffic by default, ensuring the continuity and integrity of network communication. For high-speed network environment, this default release mechanism is crucial, it can avoid network delay or normal business interruption caused by excessive detection, and ensure the smooth operation of various legal applications.
[0154] Before outputting the original message to the link, FPGA will perform a series of final verification and processing operations to ensure the integrity of the output message. First, the integrity of the original message will be checked again to check whether the frame structure, CRC check value and other information of the message are damaged due to misoperation in the previous processing link. If the message is found to have integrity problems, even if it does not hit the blocking strategy, it will be marked as invalid message and discarded, to avoid damaged messages entering the link affecting other devices. Secondly, the identification information temporarily modified or added in the analysis and judgment process will be restored, such as the temporary verification mark added during analysis, to ensure that the message output to the link is consistent with the original message structure when received, and meets the network protocol specification.
[0155] After completing the verification and processing, FPGA will distribute the original message to the corresponding physical output port through the internal output port scheduling module. The output port scheduling module will select the optimal output path according to the destination address of the original message and the link load condition to avoid port congestion.
[0156] During the message output process, FPGA will monitor the output behavior in real time, record the output time, output port, message length and other information of the message, which will be stored in the system log for subsequent traffic statistics, fault diagnosis and performance analysis. At the same time, the monitoring module will detect the state of the output port in real time, and if it finds that the port is faulty or the link is interrupted, it will immediately start the port switching mechanism to switch the message to the backup port for output, ensuring that the message can successfully enter the link.
[0157] Outputting the original message that does not hit the blocking strategy to the link not only guarantees the needs of normal network communication, but also reflects the rigor of the system processing logic. It forms a complete processing system with the diversion strategy and the blocking strategy: the diversion strategy is for traffic that needs in-depth analysis, the blocking strategy is for traffic that is confirmed to be threatening, and the default output guarantees the passage of the remaining normal traffic. The three work together to meet the requirements of network security protection, and also take into account the efficiency and usability of network communication.
[0158] Further, the blocking strategy is at least one or more of a feature-based blocking strategy, a five-tuple mask rule-based blocking strategy, or a flexible five-tuple rule-based blocking strategy.
[0159] The blocking strategy based on the feature message is performed by the feature lookup table of the message. For a specific feature, the software can set the message hitting the feature for discarding processing. The core logic is to match the features of the message by lookup table. For the message hitting the specific feature, the discarding processing is performed according to the pre-set rule of the software, so as to accurately intercept the flow with potential threat.
[0160] The message features here have a wide coverage, including the fixed field information of the protocol header, the specific source MAC address, the destination MAC address, the abnormal TTL value, the protocol version number not conforming to the specification, etc.; the feature mode in the data payload, such as the virus feature code, the instruction sequence of malicious software, the feature string of sensitive information, the abnormal data packet length, etc.; and the behavior features of the message, such as the same source-destination address combination frequently appearing in a short time, the message interaction frequency not conforming to the normal communication rule, etc. After these features are sorted by the system, they are stored in the special feature blocking table. The table uses high-speed storage medium and supports fast parallel lookup operation to meet the real-time processing requirements of the message in the high-speed network environment.
[0161] When the FPGA receives the message and completes the analysis, it will enter the feature matching stage. First, the feature extraction module will extract various feature information from the message according to the pre-set extraction rule, such as the source MAC address and TTL value for the protocol header feature, and whether there is a matching pattern in the feature blocking table in the data payload feature by sliding window scanning. Then, the extracted feature information is sent to the feature matching engine, which compares it with the entries in the feature blocking table one by one.
[0162] The software plays a key role in feature configuration and rule setting in this strategy. The staff can flexibly manage the feature blocking table through the software interface or programming interface. When it is necessary to block the message with a certain specific feature, the software will record the specific information of the feature in the feature blocking table and associate it with the operation instruction of "discarding processing".
[0163] The software configuration of the feature blocking table not only supports the addition of a single feature, but also allows the combination setting of multiple features. The combination feature of "the source IP address is a suspicious network segment, and the data payload contains a specific attack instruction" can be configured. When the message meets both conditions, it will be determined as a hit rule and perform discarding processing. This combination feature setting can greatly improve the accuracy of the blocking strategy, effectively reduce the misjudgment and omission, and avoid unnecessary interception of normal messages.
[0164] When the feature matching engine determines that a packet matches a certain feature in the feature blocking table, the FPGA will immediately trigger the discard processing mechanism. First, the packet will be marked, recording the feature entry number it matches, the arrival time of the packet, the source and destination addresses, and other information. This information will be stored in the log system for subsequent security audit and policy optimization analysis. Subsequently, the FPGA will remove the packet from the data transmission link, releasing the buffer resources it occupies, ensuring that the discarded packet cannot continue to transmit in the network. At the same time, in order to prevent the related fragments or residual information of the discarded packet from affecting the system operation, the FPGA will also clean up the processing path of the packet, ensuring the stability of the system state.
[0165] The advantage of this strategy lies in its strong pertinence and flexibility. By precisely matching the features of the packet, it can directly locate and intercept threat packets, avoiding indiscriminate processing of the entire traffic, effectively protecting network security while minimizing the impact on normal network communication. In addition, the content of the feature blocking table can be updated in real time through software, and staff can quickly add corresponding feature entries according to new network threats, enabling the system to respond to various new attacks in a timely manner and improve the dynamic defense capabilities of the network.
[0166] In practical applications, the blocking strategy based on feature packets can be widely applied in various scenarios. In virus and malware protection, by blocking packets carrying virus feature codes, it prevents the spread of viruses in the network; in intrusion detection, it intercepts packets containing attack instruction sequences to resist network attacks; in sensitive information protection, it discards packets containing sensitive feature strings to prevent information leakage. This strategy, combined with other blocking strategies, forms a multi-level network security protection system, providing a solid guarantee for the stable operation of the network.
[0167] The blocking strategy based on five-tuple mask rules can configure arbitrary mask rules for five-tuple information and discard packets that match the mask rules. Its core is to configure arbitrary mask rules for five-tuple information and execute discard processing for packets that match these rules, effectively intercepting specific ranges or types of potential threat traffic.
[0168] Five-tuple information includes source IP address, destination IP address, source port number, destination port number, and protocol type, which together form the core identifier for identifying network traffic. Mask rules are used to set specific mask values to filter each field in the five-tuple to determine the range of packets to be blocked. The mask acts like a "filter", with bits set to "1" indicating precise matching and bits set to "0" indicating that they can be ignored and not participate in matching. This flexible mask setting allows the strategy to cover a wide range from a single specific packet to a certain type of packet.
[0169] The configuration of the multi-field combination mask rule can better reflect the accuracy of the strategy. For example, a combination rule of "source IP address is 10.0.0.0 / 8 network segment, destination port number is 21, and protocol type is TCP" can be configured. When the packet meets all the three conditions, it is determined to hit the rule and will be discarded. This combination rule can accurately lock the traffic with specific communication characteristics, such as packets from a certain network segment and attempting to connect through the FTP protocol, effectively avoiding the mis-blocking of irrelevant traffic.
[0170] When the FPGA receives the packet, it will first parse it and extract the five-tuple information, and then compare these information with the pre-configured five-tuple mask rule. During the comparison process, the FPGA will process each field of the five-tuple according to the mask rule, only focusing on the valid bits specified by the mask. If the processed five-tuple information is exactly the same as the matching value in the rule, it is determined that the packet hits the rule, and the discard processing mechanism is triggered.
[0171] During the discard processing, the FPGA will first mark the packet that hits the rule, recording its rule number, five-tuple information, and timestamp of being discarded, and other key information. These information will be stored in the system log for subsequent security audit, threat analysis, and policy optimization. Then, the FPGA will remove the packet from the data transmission link and release the buffer resources occupied by it, ensuring that the blocked packet cannot enter the subsequent network transmission path and completely blocking the possible threats it may bring. At the same time, in order to avoid the impact of fragments or residual information of the discarded packet on the normal operation of the system, the FPGA will also clean up the internal processing path of the packet, ensuring the stability of the system state.
[0172] In practical applications, the blocking strategy based on five-tuple mask rule can be widely used in various network security scenarios. In enterprise networks, it can be used to limit internal host access to specific external IP addresses or ports to prevent information leakage; in data centers, it can be used to intercept malicious access to specific ports of servers to ensure stable operation of servers; in campus networks, it can be used to block P2P download traffic using specific protocols to reasonably allocate network bandwidth. This strategy, combined with other blocking strategies, can jointly build a multi-level and comprehensive network security protection system, providing strong protection for the safe and stable operation of the network.
[0173] The flexible five-tuple rule blocking strategy can match rules based on a single arbitrary five-tuple and discard the flow that hits the strategy. The core of this strategy is to accurately match rules based on a single arbitrary five-tuple. When the five-tuple information of a flow exactly matches the pre-set rule, the flow is discarded, thus achieving accurate interception of specific threat flows.
[0174] The single arbitrary quintuple refers to a specific and unique combination of source IP address, destination IP address, source port number, destination port number, and protocol type. This focus on the single quintuple allows the blocking strategy to accurately target the flow, avoiding interference with other normal flows.
[0175] In terms of rule configuration, the software provides a detailed and flexible operation mode. Staff can manually input or select specific quintuple element values through a dedicated configuration interface to build blocking rules for a single quintuple.
[0176] When the FPGA receives a packet, it first parses the packet and extracts the quintuple information from the packet. Then, based on this information, it determines the flow to which it belongs and queries the rule table for the blocking rule corresponding to this flow. During the matching process, the FPGA performs a strict and accurate comparison of each element of the quintuple. The source IP address must be exactly the same as the source IP address in the rule, and the destination IP address, source port number, destination port number, and protocol type must also correspond one by one, without any deviation. This precise matching mechanism ensures that only flows that fully meet the preset rules are hit, effectively avoiding the misblocking of normal flows.
[0177] Once a flow is determined to hit the flexible quintuple rule, the FPGA will immediately perform a discard process on the flow. First, the current packet of the flow is marked, and key information such as the rule number hit, the quintuple information of the flow, and the discard timestamp is recorded. These information will be stored in the system log, providing a basis for subsequent security auditing, threat tracing, and policy optimization. Subsequently, the FPGA removes the current packet from the data transmission link and releases the buffer resources occupied by it.
[0178] Since it is a flow-based processing, the FPGA will continuously monitor the subsequent packets of the flow through its internal flow tracking mechanism. As long as the quintuple information of the subsequent packets of the flow matches the preset blocking rule, they will be continuously discarded, ensuring that all packets of the flow cannot enter the subsequent network transmission path, completely blocking the threats that the flow may bring.
[0179] The significant advantage of this strategy lies in its high precision and flexibility. By matching rules based on a single arbitrary quintuple, it can accurately lock specific threat flows for blocking, without affecting the transmission of other normal flows, greatly improving the efficiency of network security protection. At the same time, the configuration of the rules is dynamic, and staff can add, modify, or delete quintuple rules in the rule table at any time through the software, allowing real-time adjustments during system operation to quickly respond to new security threats.
[0180] Furthermore, it is determined whether the original packet that is discarded needs to be diverted. If not, the process ends.
[0181] When the discarded original packet is determined to need to be diverted, the discarded original packet is encapsulated and diverted through the diversion packet processing strategy. The discarded original packet carries the strategy and information hit by the discarded original packet, which is used for the software system to check whether the discard is misjudged.
[0182] In addition, after the process is completed, the system automatically records the processing result, including the judgment basis and timestamp of the diversion packet that is not discarded, to ensure that the entire processing process is traceable, further guaranteeing the standardization and reliability of the system operation.
[0183] Further, the method further includes: when the blocking strategy and the diversion strategy are simultaneously determined to be valid, after the diversion packet executes the blocking strategy, the diversion packet carries the hit blocking strategy flag and strategy information when the diversion packet is processed.
[0184] Further, when the diversion packet processing strategy receives the diversion packet, it is determined whether the diversion packet is misjudged. The misjudged packet is returned to the link.
[0185] Specifically, in the network traffic processing process, there may be a special case where the blocking strategy and the diversion strategy are simultaneously determined to be valid. At this time, the system needs to be processed according to the preset priority mechanism. Generally, the blocking strategy has a higher priority, and the diversion packet will first execute the blocking strategy, and then when the packet is processed, the packet will carry the hit blocking strategy flag and strategy information, providing a basis for subsequent misjudgment investigation.
[0186] When the blocking strategy and the diversion strategy are simultaneously effective, the strategy arbitration module in the FPGA will determine that the blocking strategy is executed first. This is because the blocking strategy is mainly aimed at the traffic that has been explicitly threatened, and the priority execution can minimize the security risk. After the original packet is discarded by executing the blocking strategy, for the diversion packet that needs to enter the diversion path, the FPGA will perform special encapsulation. In addition to the conventional diversion identifier, the encapsulation content will also add the blocking strategy hit flag and detailed strategy information, including the number of the blocking strategy, the five-tuple characteristics triggering the blocking, and the specific content of the blocking rule. These information, together with the "identity tag", clearly records the reason why the diversion packet is hit by the blocking strategy, so that the subsequent processing module can quickly understand its background.
[0187] After receiving the diversion packet carrying the blocking strategy flag, the diversion packet processing strategy will start a special misjudgment detection process. This process calls the background intelligent analysis engine, combines network topology information, historical traffic feature library, business whitelist and other multi-dimensional data to determine the blocking rationality of the diversion packet.
[0188] If the system determines that the flow message is a false positive, it will immediately trigger the backflow mechanism. The backflow path of the false positive message is the same as that of the normal backflow message, but a "false positive correction" identifier is added to distinguish it from the regular backflow message. During the backflow process, the FPGA will perform unpacking processing on the false positive message, restore its original data structure, and send it to the original link through a dedicated priority channel, ensuring that the false positive message can reach the destination address in a timely manner and reducing the impact on normal traffic. At the same time, the system will record detailed information of the false positive event, including the false positive blocking policy number, message characteristics, correction time, etc., and feed these information back to the policy optimization module to automatically adjust the rule parameters of the relevant blocking policy to prevent similar false positives from occurring again.
[0189] Further, the above detailed description of one embodiment of the present application is only a preferred embodiment of the present application, and cannot be considered as limiting the scope of the present application. Any equivalent changes and improvements made within the scope of the present application shall still belong to the patent scope of the present application.
Claims
1. A method for blocking high-speed serial current diversion and return anomaly detection messages based on FPGA, characterized in that, The method includes: Receive raw messages from the link and input them into the FPGA; The message is parsed, and the protocol fields in the original message are extracted. If the corresponding referral strategy is selected based on the protocol fields, the referral message will be obtained; if there is no corresponding referral strategy, the data of the high-speed flow table on the FPGA will be queried and updated. If the traffic redirection strategy is hit, the traffic redirection message is mirrored and encapsulated; the encapsulated traffic redirection message is input into the traffic redirection message processing strategy, and backflow and back-coloring judgments are performed. If the backflow and back-dyeing are deemed successful, a backflow and back-dyeing message will be obtained. The system differentiates and judges backflow and dyeing messages. If a message is a backflow message, it is decapsulated, the message is obtained, and the output ends. During the differentiation and judgment of backflow and dyeing messages, if a message is a dyeing message, it is dyeing the flow table and stored in the high-speed flow table to expand the data of the high-speed flow table. If the traffic redirection strategy is not hit, then the corresponding blocking strategy will be selected based on the protocol fields; If the corresponding blocking policy is hit, the original packet is discarded, and it is determined whether the discarded original packet is redirected. If so, the discarded original packet is encapsulated and redirected through the redirection packet processing policy. The discarded original packet carries the policy and information that the discarded original packet hit.
2. The method for implementing high-speed serial current diversion and return anomaly detection message blocking based on FPGA according to claim 1, characterized in that, The process involves distinguishing and judging backflow and re-infection messages. If a message is not a backflow message, the process ends.
3. The method for implementing high-speed serial current diversion and return anomaly detection message blocking based on FPGA according to claim 2, characterized in that, If no blocking strategy is hit, the original packet is output to the link.
4. The method for blocking abnormal detection messages based on FPGA for high-speed serial current diversion and return according to claim 3, characterized in that, Determine whether the discarded original packet needs to be redirected; if not, end the process.
5. The method for blocking abnormal detection messages based on FPGA for high-speed serial current diversion and return as described in claim 1, characterized in that, The traffic redirection strategy is at least one or more of the following: a flow-based global traffic redirection strategy, a feature-based packet traffic redirection strategy, a five-tuple mask rule-based traffic redirection strategy, and a flexible five-tuple rule-based traffic redirection strategy.
6. The method for blocking abnormal detection messages based on FPGA for high-speed serial current diversion and return as described in claim 1, characterized in that, The mirroring strategy is at least one or more of the following: flow-based global mirroring strategy, feature-based packet mirroring strategy, five-tuple masking rule-based mirroring strategy, and flexible five-tuple rule-based mirroring strategy.
7. The method for blocking abnormal detection messages based on FPGA for high-speed serial current diversion and return according to claim 1, characterized in that, The blocking strategy is at least one or more of the following: a feature-based blocking strategy, a five-tuple masking strategy, and a flexible five-tuple rule blocking strategy.
8. The method for blocking abnormal detection messages based on FPGA for high-speed serial current diversion and return according to claim 1, characterized in that, When both the blocking and redirection strategies are deemed effective, the redirection packet executes the blocking strategy. When the redirection packet is processed, it carries the flag and strategy information of the blocked strategy that was hit.
9. The method for blocking abnormal detection messages based on FPGA for high-speed serial current diversion and return flow according to claim 8, characterized in that, When the redirection message processing strategy receives this redirection message, it determines whether the redirection message is a misjudgment. Messages that are misjudged will be redirected back into the link.
Citation Information
Patent Citations
Network abnormal flow detection system and method based on FPGA
CN114785582A
Flow blocking method based on distributed DPI system and related equipment
CN120434207A