Service flow control method, device and system, equipment and storage medium
By collaborating with DPI devices and firewalls, service traffic can be identified and controlled in parallel connection mode, solving the problem that DPI devices cannot simultaneously perform service identification and traffic control, thus improving network reliability and user experience.
Patent Information
- Application Number
- CN202511295999.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-11
- Publication Date
- 2025-12-16
AI Technical Summary
When DPI devices are in parallel connection mode, existing technologies cannot simultaneously achieve service identification and traffic control of service traffic.
Through the collaborative mechanism between DPI devices and firewalls, DPI devices identify service traffic and generate traffic control policies, while firewalls execute traffic control, using 5-tuple hashes to ensure that traffic originates from the same source and ends in the same location, and sending stop commands under preset conditions to optimize resource usage.
It enables effective identification and control of service traffic in parallel connection mode, reduces network failure points, simplifies operation and maintenance, and improves network reliability and user experience.
Smart Images

Figure CN121151035A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of transmission and Internet protocol technology, and particularly relates to a service traffic control method, device, system, equipment and storage medium. BACKGROUND
[0002] Deep packet inspection (DPI) is a deep detection technology based on service traffic, which mainly performs service identification on service traffic at key points of a network, and performs filtering control on the service traffic based on a predefined policy.
[0003] At present, the deployment mode of a DPI device in a network is divided into a series mode and a parallel mode. The series mode is to directly connect the DPI device to the network. Since service traffic on the network can directly flow through the DPI device, the DPI device can perform service identification on the service traffic and directly discard control on the identified malicious packets. The parallel mode is to split the traffic in the network link or mirror a part of the traffic to the DPI device, and the DPI device performs service identification on the service traffic, but cannot directly process the service traffic.
[0004] Therefore, in the case that the DPI device is in the parallel mode, how to achieve service identification on the service traffic and traffic control on the service traffic is a technical problem to be solved by those skilled in the art. SUMMARY
[0005] The present application provides a service traffic control method, device, equipment and storage medium, so that in the case that the DPI device is in the parallel mode, service identification on the service traffic and traffic control on the service traffic can be achieved.
[0006] The present application provides a service traffic control method applied to a deep packet inspection (DPI) device, and the method comprises the following steps: receiving target service traffic after splitting or mirroring of service traffic; performing service identification on packets in the target service traffic, and generating a traffic control policy corresponding to the target service traffic; sending the traffic control policy to a firewall, and the traffic control policy is used for traffic control on the service traffic.
[0007] According to the service traffic control method provided by the present application, the traffic control policy comprises a five-tuple corresponding to the target service traffic, an action, a control policy, and a control parameter. The five-tuple is used to represent the service flow that needs to perform the control operation, the action is used to represent the start or end of the execution of the control policy, the control policy is used to represent the control operation, and the control parameter is a parameter corresponding to the control operation.
[0008] According to the method for controlling service flow provided in the application, the method further comprises: In the case of meeting the preset condition, a stop execution instruction is sent to the firewall, the stop execution instruction is used to instruct the firewall to stop performing the flow control on the target service flow; The preset condition comprises at least one of the following: Transmission Control Protocol (TCP) session ends; TCP flow table aging; User Datagram Protocol (UDP) flow table aging.
[0009] According to the method for controlling service flow provided in the application, the method further comprises: The statistical information of the flow control result reported by the firewall is received; The statistical information comprises a five-tuple, a control policy, a start execution time of the control policy, an end execution time of the control policy, and a control result.
[0010] The application further provides a method for controlling service flow, applied to a firewall, the method comprising: A flow control policy sent by a Deep Packet Inspection (DPI) device is received, the flow control policy is generated by the DPI device after receiving target service flow obtained by splitting or mirroring of service flow, and performing service identification on packets in the target service flow; Flow control is performed on the service flow based on the flow control policy.
[0011] According to the method for controlling service flow provided in the application, the flow control policy comprises a five-tuple corresponding to the target service flow, an action, a control policy, and a control parameter; The five-tuple is used to represent the service flow that needs to perform the control operation, the action is used to represent the start or end of the execution of the control policy, the control policy is used to represent the control operation, and the control parameter is a parameter corresponding to the control operation.
[0012] According to the method for controlling service flow provided in the application, the flow control is performed on the service flow based on the flow control policy, comprising: generate a flow control policy flow table corresponding to the service traffic based on the flow control policy, wherein the flow control policy flow table comprises a five-tuple corresponding to the target service traffic, the action, the control policy, and the control parameter; perform flow control on the service traffic based on the flow control policy flow table.
[0013] According to the method for controlling service traffic provided in the present application, the method further comprises: confirm the service traffic based on the five-tuple in the flow control policy flow table when the service traffic is received; perform the control policy on the service traffic based on the action and the control parameter in the flow control policy flow table when the service traffic is confirmed to be service traffic that needs to perform a control operation.
[0014] According to the method for controlling service traffic provided in the present application, the method further comprises: receive a stop execution instruction sent by the DPI device, wherein the stop execution instruction is sent when a preset condition is met; stop performing flow control on the target service traffic based on the stop execution instruction; wherein the preset condition comprises at least one of the following: a transmission control protocol (TCP) session is ended; a TCP flow table is aged; a user datagram protocol (UDP) flow table is aged.
[0015] According to the method for controlling service traffic provided in the present application, the method further comprises: generate statistical information for a flow control result, wherein the statistical information comprises a five-tuple, a control policy, a start execution time of the control policy, an end execution time of the control policy, and a control result; report the statistical information to the DPI device.
[0016] According to the method for controlling service traffic provided in the present application, the method further comprises: delete the flow control policy flow table corresponding to the service traffic.
[0017] The present application further provides a device for controlling service traffic, which is applied to a deep packet inspection (DPI) device, and comprises: a receiving unit configured to receive target service traffic obtained by splitting or mirroring service traffic; A processing unit is configured to perform service identification on packets in the target service traffic, and generate a traffic control policy corresponding to the target service traffic; A sending unit is configured to send the traffic control policy to a firewall, where the traffic control policy is used to perform traffic control on the service traffic.
[0018] According to the application, the traffic control policy includes a five-tuple corresponding to the target service traffic, an action, a control policy, and a control parameter. The five-tuple is used to represent service traffic that needs to perform a control operation, the action is used to represent starting or ending execution of the control policy, the control policy is used to represent a control operation, and the control parameter is a parameter corresponding to the control operation.
[0019] According to the application, the sending unit is further configured to send a stop execution instruction to the firewall in a case where a preset condition is met, where the stop execution instruction is used to instruct the firewall to stop performing traffic control on the target service traffic. The preset condition includes at least one of the following: A transmission control protocol (TCP) session ends; A TCP flow table ages; A user datagram protocol (UDP) flow table ages.
[0020] According to the application, the receiving unit is further configured to receive statistical information about a traffic control result reported by the firewall. The statistical information includes a five-tuple, a control policy, a start execution time of the control policy, an end execution time of the control policy, and a control result.
[0021] The application further provides a service traffic control device applied to a firewall, where the device includes: A receiving unit is configured to receive a traffic control policy sent by a deep packet inspection (DPI) device, where the traffic control policy is generated by the DPI device after receiving target service traffic obtained by splitting or mirroring service traffic. A processing unit is configured to perform traffic control on the service traffic based on the traffic control policy.
[0022] According to the application, the traffic control policy includes a five-tuple corresponding to the target service traffic, an action, a control policy, and a control parameter. The five-tuple is used to represent the service traffic that needs to perform the control operation, the action is used to represent the start or end of the execution of the control policy, the control policy is used to represent the control operation, and the control parameter is a parameter corresponding to the control operation.
[0023] According to the service traffic control device provided in the application, the processing unit is used to perform traffic control on the service traffic based on the traffic control policy, and the traffic control includes: Based on the traffic control policy, a flow control policy flow table corresponding to the service traffic is generated, and the flow control policy flow table includes the five-tuple corresponding to the target service traffic, the action, the control policy, and the control parameter. Based on the flow control policy flow table, traffic control is performed on the service traffic.
[0024] According to the service traffic control device provided in the application, the processing unit is used to perform traffic control on the service traffic based on the flow control policy flow table, and the traffic control includes: In the case of receiving the service traffic, the service traffic is confirmed based on the five-tuple in the flow control policy flow table. In the case of confirming that the service traffic is the service traffic that needs to perform the control operation, the control policy is executed on the service traffic based on the action and the control parameter in the flow control policy flow table.
[0025] According to the service traffic control device provided in the application, the receiving unit is further used to receive a stop execution instruction sent by the DPI device, and the stop execution instruction is sent in the case of meeting a preset condition. The processing unit is further used to stop the execution of the traffic control on the target service traffic based on the stop execution instruction. The preset condition includes at least one of the following: Transmission Control Protocol (TCP) session ends; TCP flow table aging; User Datagram Protocol (UDP) flow table aging.
[0026] According to the service traffic control device provided in the application, the processing unit is further used to generate statistical information for the traffic control result, and the statistical information includes the five-tuple, the control policy, the start execution time of the control policy, the end execution time of the control policy, and the control result. The statistical information is reported to the DPI device.
[0027] According to the service traffic control device provided in the application, the processing unit is further used to delete the flow control policy flow table corresponding to the service traffic.
[0028] The application further provides a service traffic control system, characterized by comprising the service traffic control device according to any one of the preceding aspects, and the service traffic control device according to any one of the preceding aspects.
[0029] The application further provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and capable of running on the processor, wherein the processor implements the service traffic control method according to any one of the preceding aspects when executing the computer program.
[0030] The application further provides a computer readable storage medium, which stores a computer program, and the computer program implements the service traffic control method according to any one of the preceding aspects when executed by a processor.
[0031] The application further provides a computer program product comprising a computer program, and the computer program implements the service traffic control method according to any one of the preceding aspects when executed by a processor.
[0032] The application provides a service traffic control method, device, equipment and storage medium, the DPI device receives the target service traffic after the service traffic is split or mirrored; the packets in the target service traffic are subjected to service identification, and a traffic control strategy corresponding to the target service traffic is generated; the traffic control strategy is sent to the firewall, and the traffic control strategy is used for traffic control of the service traffic. In this way, in the case that the DPI device is in the parallel mode, the DPI device and the firewall cooperate to realize control of the service traffic, so that the DPI device and the firewall can each play their own advantages, the service identification of the service traffic can be realized, and the traffic control of the service traffic can also be realized, not only effectively solving the problems of network reliability decline, operation and fault positioning complexity caused by the DPI device being serially connected into the network to increase a fault point, but also effectively reducing the service processing delay and improving the user experience. BRIEF DESCRIPTION OF DRAWINGS
[0033] In order to more clearly illustrate the technical solutions of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.
[0034] Figure 1 An architecture schematic diagram of a DPI device serially connected and deployed in a network is provided for the embodiments of the present application.
[0035] Figure 2 An architecture schematic diagram of a DPI device parallelly connected and deployed in a network is provided for the embodiments of the present application.
[0036] Figure 3 A flowchart of a service traffic control method provided in an embodiment of the present application.
[0037] Figure 4 A flowchart of another service traffic control method provided in an embodiment of the present application. Figure 5 A flowchart of still another service traffic control method provided in an embodiment of the present application.
[0038] Figure 6 A structural diagram of a service traffic control device provided in an embodiment of the present application.
[0039] Figure 7 A structural diagram of another service traffic control device provided in an embodiment of the present application.
[0040] Figure 8 A physical structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0041] In order to make the objectives, technical solutions and advantages of the present application clearer, the technical solutions in the present application will be described clearly and completely below with reference to the drawings in the present application. Obviously, the described embodiments are some but not all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.
[0042] In the embodiments of the present application, “at least one” means one or more, and “multiple” means two or more. “And / or” describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent the following three cases: A exists alone, A and B exist together, and B exists alone, where A and B can be singular or plural. In the textual description of the present application, the character “ / ” generally represents an “or” relationship between the associated objects before and after it.
[0043] The technical solutions provided in the embodiments of the present application can be applied to a service traffic processing scenario. DPI is a kind of deep detection technology based on service traffic, which detects different network application layer loads, such as HyperText Transfer Protocol (HTTP) and Domain Name System (DNS), and determines the legitimacy of the service traffic by detecting the payload of the message in the service traffic.
[0044] The DPI device can complete fine identification of services on a link, analysis of service traffic flow direction, service traffic proportion statistics, service proportion shaping, and application layer denial of service attack, filtering of viruses and Trojan horses, and control of abuse of peer to peer (P2P), and the like, by identifying service traffic at key points of a network and filtering and controlling the service traffic based on a pre-defined policy.
[0045] Currently, the deployment mode of the DPI device in the network is divided into a serial mode and a parallel mode. In the serial mode, the DPI device is directly connected to the network. For example, refer to FIG. 1. Figure 1 Figure 1 An architecture schematic diagram in which a DPI device provided by an embodiment of the present application is deployed in a network in a serial mode, and the DPI device is deployed at an Internet Data Center (IDC) export. In the serial mode, the DPI device can not only identify service traffic, but also directly discard malicious packets and the like after identification. However, such deployment also has problems. For example, on the one hand, it increases a fault point in the network, causing the reliability of the overall network to decrease, and also brings more challenges to operation and maintenance and fault location. On the other hand, because uplink and downlink packets of a data stream can flow through different DPI devices, there is a problem that asymmetric traffic cannot be identified, which can cause services to be unable to be identified. On the other hand, it also increases the processing delay of services, causing the service experience to decrease, and can become a performance bottleneck in the network.
[0046] In view of the above problems of the DPI device deployed in the serial mode, the DPI device can be deployed in the network in the parallel mode. However, in the parallel mode, the DPI device can only identify service traffic, but cannot directly process the service traffic.
[0047] In order to enable the DPI device in the parallel mode to not only identify service traffic, but also control the service traffic, a control method of service traffic provided by an embodiment of the present application can be implemented by an architecture as shown in FIG. 2. For example, refer to FIG. 3. Figure 2 Figure 2 An architecture schematic diagram in which a DPI device provided by an embodiment of the present application is deployed in a network in a parallel mode. The DPI device deployed in the parallel mode and a firewall can cooperate to identify service traffic and control the service traffic. Figure 2
[0048] The service traffic sent by the terminal can reach the convergence and distribution device through splitting or mirroring, and the convergence and distribution device sends the split or mirrored service traffic to the DPI device deployed in the convergence mode through five-tuple hashing, so that the same source and same destination of the traffic are ensured, and the asymmetric traffic problem is solved.
[0049] The DPI device deployed in the convergence mode is mainly used for receiving the split or mirrored service traffic, and performing service identification on the split or mirrored service traffic. In addition, the DPI device deployed in the convergence mode can further perform service traffic statistical analysis and TCP connection control functions, etc. The specific settings can be made according to actual needs. After the service identification on the split or mirrored service traffic is performed, the traffic control strategy corresponding to the service traffic is generated and is delivered to the firewall.
[0050] The firewall is mainly used for performing traffic control on the service traffic based on the traffic control strategy delivered by the DPI device. Since the firewall itself is a traffic control device at the transport layer, it is very suitable for completing the traffic control function.
[0051] In combination with the above description, the control of the service traffic is realized through the cooperation of the DPI device and the firewall. In the cooperation process, the DPI device is used to perform its suitable service traffic identification and traffic statistical analysis, etc., and the traffic control function based on the five-tuple is more suitable for being completed by the firewall which is specially used for the traffic control at the transport layer. Such division of labor can make the DPI device and the firewall each play their own advantages, realize the service identification on the service traffic and the traffic control on the service traffic, achieve the optimal efficiency of the overall solution, effectively solve the problems of the decrease of network reliability, the complexity of operation and maintenance and fault location caused by the increase of one fault point by the series connection of the DPI device into the network, effectively reduce the service processing delay, improve the user experience, and also avoid the situation that the DPI device becomes the network bottleneck.
[0052] It can be understood that the execution subject of the control method of the service traffic provided by the present application can be the DPI device or the firewall, or the control device of the service traffic arranged in the DPI device or the firewall. The control device of the service traffic can be realized by software, hardware or a combination of the two, and the specific settings can be made according to actual needs.
[0053] In the following, the control method of the service traffic provided by the present application will be described in detail through the following several specific embodiments. It can be understood that the following several specific embodiments can be combined with each other, and the same or similar concepts or processes can not be described in some embodiments.
[0054] Figure 3A flowchart of a service traffic control method provided by an embodiment of the present application is applied to a DPI device, and an example is shown in FIG. 3. Figure 3 The service traffic control method can include the following steps. S301, receiving target service traffic after splitting or mirroring of service traffic.
[0055] For example, in the case of parallel deployment of the DPI device, the target service traffic after splitting or mirroring of service traffic can be received by the convergence shunting device, and the specific process includes that when a terminal initiates service access to an ICP server, the service access corresponding service traffic is split or mirrored to the convergence shunting device, and the convergence shunting device sends the split or mirrored service traffic to the DPI device in parallel deployment through the five-tuple hash method, so that the DPI device receives the target service traffic after splitting or mirroring of service traffic, which can ensure the same source and same destination of the traffic and solve the problem of asymmetric traffic.
[0056] S302, performing service identification on the packets in the target service traffic, and generating a traffic control policy corresponding to the target service traffic.
[0057] For example, when the DPI device performs service identification on the packets in the target service traffic, it can include at least four possible implementation manners. In one possible implementation manner, the service identification is performed based on the port number, that is, the DPI device analyzes the source port or destination port of the packets in the target service traffic to determine the application type thereof, for example, HTTP usually uses port 80, so as to perform service identification on the packets.
[0058] In another possible implementation manner, the service identification is performed based on protocol features, that is, the DPI device deeply analyzes the application layer load content of the packets in the target service traffic to match specific protocol features, such as HTTP, DNS, etc., so as to perform service identification on the packets.
[0059] In yet another possible implementation manner, the service identification is performed based on traffic behavior, that is, the transmission mode, frequency, and other behavior characteristics of the data flow in the target service traffic are analyzed to determine the service type thereof, so as to perform service identification on the packets.
[0060] In yet another possible implementation manner, the service identification is performed based on content filtering, that is, the specific content of the packets in the target service traffic is detected, such as keywords, file types, etc., so as to perform service identification on the packets.
[0061] It can be understood that, in the embodiments of the present application, when the DPI device performs service identification on the packets in the target service traffic, only the above four possible implementation manners are taken as examples for description, but the embodiments of the present application are not limited to the above four possible implementation manners.
[0062] For example, when the DPI device generates the traffic control policy corresponding to the target service traffic, the DPI device can obtain the Internet Protocol (IP) address and the account information of a user when the user accesses the network, and establish a relationship based on the IP and the account information to generate the traffic control policy corresponding to the target service traffic of the user. Alternatively, the DPI device can perform deep packet detection on the application layer load of the data packets in the target service traffic, such as HTTP, DNS, and the like, to determine the legitimacy of the data packets, and generate the traffic control policy corresponding to the target service traffic. The specific implementation can be set according to actual needs. In addition, the DPI device can also perform the function of Transmission Control Protocol (TCP) connection control.
[0063] According to the above description, after the DPI device performs service identification on the packets in the target service traffic and generates the traffic control policy corresponding to the target service traffic, the DPI device can send the traffic control policy to the firewall, that is, perform S303, and the firewall performs the traffic control function. Since the firewall is a traffic control device at the transport layer, it is very suitable for implementing the traffic control function.
[0064] S303, sending the traffic control policy to the firewall, the traffic control policy being used for traffic control on the service traffic.
[0065] It can be seen that, in the embodiments of the present application, the DPI device receives the target service traffic after the service traffic is split or mirrored, performs service identification on the packets in the target service traffic, and generates the traffic control policy corresponding to the target service traffic. The DPI device sends the traffic control policy to the firewall, and the traffic control policy is used for traffic control on the service traffic. In this way, when the DPI device is in the parallel mode, the DPI device and the firewall cooperate to control the service traffic, so that the DPI device and the firewall can play their respective advantages, that is, the service identification on the service traffic and the traffic control on the service traffic can be realized, which not only effectively solves the problems of network reliability reduction, operation and fault positioning complexity caused by the increase of a fault point when the DPI device is connected in series in the network, but also effectively reduces the service processing delay and improves the user experience.
[0066] For example, in the embodiments of the present application, the traffic control policy includes a five-tuple corresponding to the target service traffic, an action, a control policy, and a control parameter.
[0067] The quintuple is used to represent the service traffic that needs to perform the control operation, and is used to represent the start or end of the execution of the control policy, the control policy is used to represent the control operation, and the control parameter is the parameter corresponding to the control operation.
[0068] For example, the quintuple can include the source IP, source port, destination IP, destination port and protocol type of the data flow, which is used to inform the firewall to perform the control operation on which quintuple data flow.
[0069] For example, the control policy can be packet loss control or rate limiting control, etc., which can be set according to actual needs. When the control policy is packet loss control, the corresponding control parameter can be a related parameter of the packet loss control. When the control policy is rate limiting control, the corresponding control parameter can be a related parameter of the rate limiting control, such as a specific rate limiting value.
[0070] For example, in the embodiment of the present application, the stop execution instruction is sent to the firewall under the condition that the preset condition is met, and the stop execution instruction is used to instruct the firewall to stop performing traffic control on the target service traffic. The preset condition includes at least one of the following: Transmission Control Protocol (TCP) session ends; TCP flow table aging; User Datagram Protocol (UDP) flow table aging.
[0071] For example, in the embodiment of the present application, after the DPI device identifies the service traffic and generates the corresponding traffic control policy, a message is sent to the firewall to start executing the control policy. The delivery of the message can be realized through various protocols. For example, in the RestFul API protocol, the reference code is as follows: URL: https: / / firewall IP address:port / openapi / TrafficContrl Request method: POST POST / openapi / TrafficContrl HTTP / 1.1 Accept: image / jpeg, ……, …, Content-Type: application / json Content-Length: ×× { "TrafficID": "100.1.1.100,2000,200.1.1.200,80,TCP", "Action": "Start", "Policy": "Discard", "Parameter": "0" } After the Transmission Control Protocol (TCP) session ends, the TCP flow table ages, and / or the UDP flow table ages, the DPI device issues a stop execution instruction to the firewall, instructing the firewall to stop executing traffic control on the target traffic. This not only reduces unnecessary resource occupation and releases corresponding flow table resources, avoiding waste of memory and processing capacity due to long-term maintenance of invalid sessions, but also optimizes firewall performance, stops traffic control on invalid or ended sessions, reduces the burden on the firewall, and makes it more focused on processing active traffic, thereby improving overall network throughput and response speed. In addition, it can also avoid misjudgment and policy conflicts, and by timely clearing invalid sessions, it can prevent the firewall from continuing to execute control policies on ended sessions, reduce traffic misjudgment or conflicts caused by policy residues, and improve the accuracy and reliability of traffic management. The reference code is as follows: URL: https: / / firewall's IP address:port / openapi / TrafficContrl Request method: POST POST / openapi / TrafficContrl HTTP / 1.1 Accept: image / jpeg, ……, …, Content-Type: application / json Content-Length: ×× { "TrafficID": "100.1.1.100,2000,200.1.1.200,80,TCP", "Action": "Stop", "Policy": "Discard", "Parameter": "0" } For example, in the embodiment of the present application, the firewall can generate statistical information on the traffic control result after performing traffic control on the service traffic based on the traffic control policy, wherein the statistical information comprises a five-tuple, the control policy, the start execution time of the control policy, the end execution time of the control policy, and the control result; and the statistical information is reported to the DPI device, so that the DPI device can more accurately identify the traffic type, determine whether there is abnormal behavior such as Denial of Service (DOS) attack, virus propagation, and support traffic filtering and optimization of the control policy. In addition, the statistical information can also provide data support for network operation, facilitate fault diagnosis, performance analysis and security situation awareness, so as to ensure the stable operation of the network.
[0072] For example, when the control policy in the statistical information is packet loss control or speed limit control, the control result represents the number of discarded packets, the number of bytes, etc. during packet loss or speed limit, which can be set according to actual needs.
[0073] For example, when the firewall generates statistical information on the traffic control result, the statistical information on the traffic control result can be generated based on the statistics of traffic data, for example, real-time updating in the "traffic trend" module of the "overview" page, or based on the statistics of session data, and the relevant information is counted at the end of the session to generate the statistical information on the traffic control result. The specific implementation can be set according to actual needs.
[0074] For example, the firewall can periodically report the statistical information to the DPI device, or report the statistical information together after the control ends. The specific implementation can be set according to actual needs. For example, the firewall can report the statistical information to the DPI device through syslog or other protocols.
[0075] In combination with the above description, the DPI device performs service identification on the packets in the target service traffic, and generates a traffic control policy corresponding to the target service traffic, and sends the traffic control policy to the firewall. Correspondingly, the firewall can perform traffic control based on the traffic control policy, and the specific implementation can be referred to the embodiment shown in Figure 4 .
[0076] Figure 4 For another flowchart of a service traffic control method provided by the embodiment of the present application, applied to a firewall, for example, refer to Figure 4 , the service traffic control method can comprise: S401, receiving a traffic control policy sent by a deep packet inspection (DPI) device, wherein the traffic control policy is generated by the DPI device after receiving target service traffic obtained by splitting or mirroring of service traffic, and performing service identification on the packets in the target service traffic.
[0077] For example, in the embodiments of the present application, the traffic control policy includes a five-tuple corresponding to target service traffic, an action, a control policy, and a control parameter. The five-tuple is used to represent service traffic that needs to perform a control operation, the action is used to represent the start or end of the execution of the control policy, the control policy is used to represent a control operation, and the control parameter is a parameter corresponding to the control operation.
[0078] For example, the five-tuple can include the source IP, source port, destination IP, destination port, and protocol type of a data flow, and is used to inform the firewall to perform a control operation on which five-tuple data flow.
[0079] For example, the control policy can be a packet loss control or a rate limiting control, etc., and can be set according to actual needs. When the control policy is a packet loss control, the corresponding control parameter can be a related parameter of the packet loss control. When the control policy is a rate limiting control, the corresponding control parameter can be a related parameter of the rate limiting control, such as a specific rate limiting value, etc.
[0080] It should be noted that in S401, the specific implementation of the traffic control policy is similar to the specific implementation of the DPI device generating the traffic control policy in S302 described above. For details, please refer to the related description of the DPI device generating the traffic control policy in S302 described above. In this embodiment of the present application, further description is not repeated.
[0081] S402, based on the traffic control policy, performing traffic control on the service traffic.
[0082] As can be seen, in the embodiments of the present application, the firewall receives the traffic control policy sent by the deep packet inspection DPI device, and performs traffic control on the service traffic based on the traffic control policy. In this way, in the case that the DPI device is in the parallel mode, the control of the service traffic is realized through the cooperation of the DPI device and the firewall, which not only realizes the service identification of the service traffic, but also realizes the traffic control of the service traffic, effectively solves the problems of network reliability decline, operation and fault location complexity caused by the increase of a fault point by the serial connection of the DPI device into the network, and effectively reduces the service processing delay and improves the user experience.
[0083] For example, in S402 described above, when the firewall performs traffic control on the service traffic based on the traffic control policy, it can first generate a flow control policy flow table corresponding to the service traffic based on the traffic control policy, the flow control policy flow table including a five-tuple corresponding to target service traffic, an action, a control policy, and a control parameter; and then perform traffic control on the service traffic based on the flow control policy flow table, thereby realizing the traffic control of the service traffic.
[0084] For example, in the embodiment of the present application, when the firewall performs traffic control on the service traffic based on the flow control policy flow table, it can first determine whether the service traffic is received, and in the case where the service traffic is received, it can determine whether the service traffic is the service traffic that needs to perform a control operation based on the quintuple in the flow control policy flow table; and in the case where the service traffic is determined to be the service traffic that needs to perform a control operation, it can perform a control policy on the service traffic based on the action and control parameter in the flow control policy flow table, so as to realize traffic control on the service traffic.
[0085] For example, in the embodiment of the present application, after the firewall performs traffic control on the service traffic based on the flow control policy, it can further generate statistical information for the traffic control result; wherein the statistical information includes the quintuple, the control policy, the start execution time of the control policy, the end execution time of the control policy, and the control result; and report the statistical information to the DPI device, so that the DPI device can obtain the statistical information of the traffic control result.
[0086] For example, when the control policy in the statistical information is packet loss control or speed limit control, the control result represents the number of discarded packets, the number of bytes, etc. during the packet loss or speed limit, which can be set according to actual needs.
[0087] For example, when the firewall generates the statistical information for the traffic control result, it can generate the statistical information for the traffic control result based on the statistics of the flow data, for example, real-time update in the "traffic trend" module of the "overview" page, or based on the statistics of the session data, and statistics the relevant information at the end of the session to generate the statistical information for the traffic control result, which can be set according to actual needs.
[0088] For example, the firewall can periodically report the statistical information to the DPI device, or report the statistical information together after the control ends, which can be set according to actual needs. For example, the firewall can report the statistical information to the DPI device through syslog and other protocols.
[0089] For example, the firewall can further receive a stop execution instruction sent by the DPI device, and stop performing the traffic control on the target service traffic based on the stop execution instruction.
[0090] The preset condition includes at least one of the following: Transmission Control Protocol (TCP) session ends; TCP flow table aging; User Datagram Protocol (UDP) flow table aging.
[0091] The firewall stops performing traffic control on the target service traffic, which not only can reduce unnecessary resource occupation, release corresponding flow table resources, avoid waste of memory and processing capacity caused by long-term maintenance of invalid sessions, but also can optimize the performance of the firewall, stop traffic control on invalid or ended sessions, reduce the burden of the firewall, make it more focused on processing active service traffic, thereby improving the overall network throughput and response speed. In addition, it can also avoid misjudgment and policy conflict, by timely clearing invalid sessions, it can prevent the firewall from continuing to execute control policies on ended sessions, reduce traffic misjudgment or conflict caused by policy residue, and improve the accuracy and reliability of traffic management.
[0092] For example, the firewall can also delete the flow control policy flow table corresponding to the service traffic, release the system resources of the firewall, and improve the efficiency of the device. At the same time, it is helpful to avoid unnecessary policy conflicts and simplify subsequent policy management. In addition, timely cleaning of unused flow control policies helps to improve the level of healthy network operation and provide more accurate data support for network optimization.
[0093] In order to facilitate the understanding of the service traffic control method provided by the embodiments of the present application, below, the service traffic control method provided by the embodiments of the present application will be described through one specific embodiment shown in the following Figure 5
[0094] Figure 5 For another service traffic control method provided by the embodiments of the present application, see Figure 5 The service traffic control method can include: S501, the terminal initiates service access to the ICP server, and the five-tuple is "100.1.1.100, 2000, 200.1.1.200, 80, TCP".
[0095] S502, the access traffic of the service access is split into a part to the convergence and distribution device.
[0096] S503, the convergence and distribution device sends the target service traffic to the DPI device according to the five-tuple hash.
[0097] S504, the DPI device performs service identification on the packets in the target service traffic, and generates a traffic control policy corresponding to the target service traffic.
[0098] S505, the DPI device sends the traffic control policy to the firewall.
[0099] S506, the firewall generates a flow control policy flow table based on the traffic control policy, and the flow control policy flow table includes the five-tuple, the action, the control policy, and the control parameter.
[0100] S507, the terminal accesses the subsequent service traffic of the ICP server to the firewall.
[0101] S508, the firewall performs the packet loss control on the service traffic based on the case that the service traffic is the service traffic needing to perform the packet loss control confirmed by the five-tuple in the flow control policy flow table.
[0102] S509, after a period of time, in the case of TCP connection closure, TCP flow table aging, or UDP flow table aging, the DPI device issues a stop execution instruction to the firewall.
[0103] S510, the firewall stops performing the packet loss control on the target service traffic, and deletes the established flow control policy flow table.
[0104] S511, the firewall reports the statistical information of the traffic control result to the DPI device through syslog, including: five-tuple, start time, end time, control policy, control result, etc.
[0105] S512, the DPI device synthesizes various statistical information to complete the external display of the service traffic.
[0106] In the embodiments of the present application, the control of the service traffic is realized by the cooperation of the DPI device and the firewall. In the cooperation process, the DPI device is used to perform the work of service traffic identification and traffic statistical analysis suitable for it, and the traffic control function based on the five-tuple is more suitable for the firewall which is specialized in the transmission layer traffic control. Such division of labor can make the DPI device and the firewall each play their own advantages, realize the service identification of the service traffic and the traffic control of the service traffic, achieve the optimal efficiency of the overall solution, not only effectively solve the problems of network reliability decline, operation and fault positioning complexity caused by the increase of a fault point by stringing the DPI device into the network, but also effectively reduce the service processing delay, improve the user experience, and also avoid the situation that the DPI device becomes the network bottleneck.
[0107] The control device of the service traffic provided by the present application is described below. The control device of the service traffic described below can be referred to each other corresponding to the control method of the service traffic described above.
[0108] Figure 6 The structure diagram of the control device of the service traffic provided by the embodiments of the present application is applied to the DPI device. For example, please refer to Figure 6 As shown in the figure, the control device of the service traffic 60 can include: The receiving unit 601 is configured to receive the target service traffic after the service traffic is split or mirrored. The processing unit 602 is configured to perform service identification on the packets in the target service flow, and generate a flow control policy corresponding to the target service flow. The sending unit 603 is configured to send the flow control policy to the firewall, and the flow control policy is used for flow control on the service flow.
[0109] For example, in the embodiments of the present application, the flow control policy includes a five-tuple corresponding to the target service flow, an action, a control policy, and a control parameter. The five-tuple is used to represent the service flow that needs to perform a control operation, the action is used to represent the start or end of the execution of the control policy, the control policy is used to represent the control operation, and the control parameter is a parameter corresponding to the control operation.
[0110] For example, in the embodiments of the present application, the sending unit 603 is further configured to send a stop execution instruction to the firewall in a case where a preset condition is met, and the stop execution instruction is used to instruct the firewall to stop performing flow control on the target service flow. The preset condition includes at least one of the following: Transmission Control Protocol (TCP) session ends; TCP flow table aging; User Datagram Protocol (UDP) flow table aging.
[0111] For example, in the embodiments of the present application, the receiving unit 601 is further configured to receive statistical information on a flow control result reported by the firewall. The statistical information includes a five-tuple, a control policy, a start execution time of the control policy, an end execution time of the control policy, and a control result.
[0112] The service flow control device 60 provided in the embodiments of the present application can execute the technical solutions of the service flow control method of the DPI device side in any of the above embodiments, and has similar implementation principles and beneficial effects to the service flow control method of the DPI device side. For details, refer to the implementation principles and beneficial effects of the service flow control method of the DPI device side, which will not be described here.
[0113] Figure 7 Another service flow control device provided in the embodiments of the present application is shown in a structural schematic diagram, which is applied to a firewall. For example, refer to FIG. 7. Figure 7 As shown in the figure, the service flow control device 70 can include: The receiving unit 701 is configured to receive a traffic control policy sent by a deep packet inspection (DPI) device, wherein the traffic control policy is generated by the DPI device after performing service identification on a target service flow obtained by splitting or mirroring service flow. The processing unit 702 is configured to perform traffic control on the service flow based on the traffic control policy.
[0114] For example, in the embodiments of the present application, the traffic control policy comprises a five-tuple corresponding to the target service flow, an action, a control policy, and a control parameter. The five-tuple is used to represent the service flow that needs to perform a control operation, the action is used to represent the start or end of the execution of the control policy, the control policy is used to represent the control operation, and the control parameter is a parameter corresponding to the control operation.
[0115] For example, in the embodiments of the present application, the processing unit 702 is configured to perform traffic control on the service flow based on the traffic control policy, including: generating a flow control policy flow table corresponding to the service flow based on the traffic control policy, wherein the flow control policy flow table comprises the five-tuple corresponding to the target service flow, the action, the control policy, and the control parameter; performing traffic control on the service flow based on the flow control policy flow table.
[0116] For example, in the embodiments of the present application, the processing unit 702 is configured to perform traffic control on the service flow based on the flow control policy flow table, including: in a case where the service flow is received, confirming the service flow based on the five-tuple in the flow control policy flow table; in a case where the service flow is confirmed as the service flow that needs to perform a control operation, performing the control policy on the service flow based on the action and the control parameter in the flow control policy flow table.
[0117] For example, in the embodiments of the present application, the receiving unit 701 is further configured to receive a stop execution instruction sent by the DPI device, wherein the stop execution instruction is sent in a case where a preset condition is met. The processing unit 702 is further configured to stop performing traffic control on the target service flow based on the stop execution instruction. The preset condition comprises at least one of the following: a transmission control protocol (TCP) session is ended; a TCP flow table is aged; a user datagram protocol (UDP) flow table is aged.
[0118] For example, in this embodiment of the application, the processing unit 702 is further configured to generate statistical information for the flow control results; wherein, the statistical information includes a quintuple, a control policy, the start execution time of the control policy, the end execution time of the control policy, and the control result; The statistical information is reported to the DPI device.
[0119] For example, in this embodiment of the application, the processing unit 702 is further configured to delete the flow control policy flow table corresponding to the service traffic.
[0120] The service traffic control device 70 provided in this application embodiment can execute the technical solution of the service traffic control method on the firewall side in any of the above embodiments. Its implementation principle and beneficial effects are similar to those of the service traffic control method on the firewall side. For details, please refer to the implementation principle and beneficial effects of the service traffic control method on the firewall side, which will not be repeated here.
[0121] This application also provides a traffic control system, characterized in that it includes the traffic control device described in any of the above claims, and the implementation principle and beneficial effects of the traffic control device described in any of the above claims are similar to those of the traffic control method described above. For details, please refer to the implementation principle and beneficial effects of the traffic control method described above, which will not be repeated here.
[0122] Figure 8 This is a schematic diagram of the physical structure of an electronic device provided in an embodiment of this application, such as... Figure 8 As shown, the electronic device may include a processor 810, a communications interface 820, a memory 830, and a communication bus 840, wherein the processor 810, communications interface 820, and memory 830 communicate with each other via the communication bus 840. The processor 810 can invoke logical instructions in the memory 830 to execute a service traffic control method, which includes: receiving target service traffic after splitting or mirroring the service traffic; identifying services in the packets of the target service traffic and generating a traffic control policy corresponding to the target service traffic; and sending the traffic control policy to a firewall, wherein the traffic control policy is used to control the service traffic.
[0123] or, Receive a traffic control policy sent by a deep packet inspection (DPI) device, the traffic control policy being generated by the DPI device after receiving target service traffic after splitting or mirroring of service traffic; and perform traffic control on the service traffic based on the traffic control policy.
[0124] In addition, the logical instructions in the memory 830 described above can be implemented in the form of a software function unit and sold or used as an independent product, and can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or part of the technical solutions can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the various embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various program code storage media.
[0125] On the other hand, the present application also provides a computer program product, the computer program product comprising a computer program, the computer program being stored on a computer readable storage medium, and the computer program being executed by a processor, so that the computer can execute the control method of the service traffic provided by the above-mentioned method, the method comprising: receiving target service traffic after splitting or mirroring of service traffic; performing service identification on packets in the target service traffic, and generating a traffic control policy corresponding to the target service traffic; and sending the traffic control policy to a firewall, the traffic control policy being used for traffic control on the service traffic.
[0126] Or, Receive a traffic control policy sent by a deep packet inspection (DPI) device, the traffic control policy being generated by the DPI device after receiving target service traffic after splitting or mirroring of service traffic; and perform traffic control on the service traffic based on the traffic control policy.
[0127] In yet another aspect, the present application also provides a computer readable storage medium, having stored thereon a computer program, which, when executed by a processor, implements the method for controlling service traffic provided by the above method, the method comprising: receiving target service traffic after the service traffic is split or mirrored; performing service identification on packets in the target service traffic, and generating a traffic control policy corresponding to the target service traffic; and sending the traffic control policy to a firewall, the traffic control policy being used for traffic control on the service traffic.
[0128] Or, Receiving a traffic control policy sent by a deep packet inspection (DPI) device, the traffic control policy being generated by the DPI device after receiving target service traffic after the service traffic is split or mirrored; and performing traffic control on the service traffic based on the traffic control policy.
[0129] The device embodiments described above are merely illustrative, wherein the units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, i.e., they can be located in one place, or distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the embodiment according to actual needs. Those skilled in the art can understand and implement without creative labor.
[0130] From the above description of the embodiments, those skilled in the art can clearly understand that the embodiments can be realized by means of software plus necessary universal hardware platforms, and of course, can also be realized by hardware. Based on such understanding, the above technical solutions, essentially or in terms of the contribution to the prior art, can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods described in each embodiment or some parts of the embodiments.
[0131] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacements to some technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for controlling business traffic, characterized in that, The method, applied to a deep packet inspection (DPI) device, includes: Receive target service traffic after it has been split or mirrored for the service traffic; The packets in the target service traffic are identified as services, and a traffic control policy corresponding to the target service traffic is generated. The traffic control policy is sent to the firewall, and the traffic control policy is used to control the traffic of the service.
2. The method according to claim 1, characterized in that, The traffic control strategy includes the five-tuple corresponding to the target service traffic, the action, the control strategy, and the control parameters. The five-tuple is used to represent the service traffic that needs to perform control operations, the action is used to represent the start or end of the execution of the control strategy, the control strategy is used to represent the control operation, and the control parameter is the parameter corresponding to the control operation.
3. The method according to claim 1 or 2, characterized in that, The method further includes: Under preset conditions, a stop execution command is sent to the firewall, which instructs the firewall to stop performing traffic control on the target service traffic; The preset conditions include at least one of the following: Transmission Control Protocol (TCP) session terminated; TCP flow table aging; User Datagram Protocol (UDP) stream table aging.
4. The method according to claim 1 or 2, characterized in that, The method further includes: Receive statistical information on traffic control results reported by the firewall; The statistical information includes a quintuple, a control strategy, the start execution time of the control strategy, the end execution time of the control strategy, and the control result.
5. A method for controlling business traffic, characterized in that, Applied to a firewall, the method includes: The DPI device receives a traffic control policy sent by a deep packet inspection (DPI) device. The traffic control policy is generated by the DPI device after receiving the target service traffic after splitting or mirroring the service traffic, and then identifying the packets in the target service traffic. Based on the aforementioned traffic control strategy, traffic control is applied to the service traffic.
6. The method according to claim 5, characterized in that, The traffic control strategy includes the five-tuple corresponding to the target service traffic, the action, the control strategy, and the control parameters. The five-tuple is used to represent the service traffic that needs to perform control operations, the action is used to represent the start or end of the execution of the control strategy, the control strategy is used to represent the control operation, and the control parameter is the parameter corresponding to the control operation.
7. The method according to claim 6, characterized in that, The process of controlling the service traffic based on the traffic control strategy includes: Based on the traffic control strategy, a flow control strategy flow table corresponding to the service traffic is generated. The flow control strategy flow table includes a five-tuple corresponding to the target service traffic, the action, the control strategy, and the control parameters. Based on the flow control policy flow table, the service traffic is subject to flow control.
8. The method according to claim 7, characterized in that, The flow control of the service traffic based on the flow control policy flow table includes: Upon receiving the service traffic, the service traffic is confirmed based on the five-tuple in the flow control policy flow table; If the traffic is confirmed to be traffic requiring control operations, the control strategy is executed on the traffic based on the action and control parameters in the flow control strategy flow table.
9. The method according to any one of claims 5-8, characterized in that, The method further includes: Receive a stop execution command sent by the DPI device, wherein the stop execution command is sent under preset conditions; Based on the stop execution instruction, the flow control of the target service traffic is stopped; The preset conditions include at least one of the following: Transmission Control Protocol (TCP) session terminated; TCP flow table aging; User Datagram Protocol (UDP) stream table aging.
10. The method according to any one of claims 5-8, characterized in that, The method further includes: Generate statistical information for the flow control results; wherein the statistical information includes a quintuple, the control policy, the start execution time of the control policy, the end execution time of the control policy, and the control result; The statistical information is reported to the DPI device.
11. The method according to claim 7, characterized in that, The method further includes: Delete the flow table of the flow control policy corresponding to the business traffic.
12. A business traffic control device, characterized in that, The device is applied to a deep packet inspection (DPI) device and includes: The receiving unit is used to receive the target service traffic after it has been split or mirrored. The processing unit is used to identify the service in the packets of the target service traffic and generate the traffic control policy corresponding to the target service traffic. The sending unit is used to send the traffic control policy to the firewall, and the traffic control policy is used to control the traffic of the service.
13. A business traffic control device, characterized in that, The device, used in a firewall, includes: The receiving unit is used to receive the traffic control policy sent by the deep packet inspection (DPI) device. The traffic control policy is generated by the DPI device after receiving the target service traffic after splitting or mirroring the service traffic, and then identifying the packets in the target service traffic. The processing unit is used to perform traffic control on the service traffic based on the traffic control strategy.
14. A control system for business traffic, characterized in that, It includes the traffic control device described in claim 12 and the traffic control device described in claim 13.
15. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the service traffic control method as described in any one of claims 1 to 4, or implements the service traffic control method as described in any one of claims 5 to 11.
16. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the traffic control method as described in any one of claims 1 to 4, or implements the traffic control method as described in any one of claims 5 to 11.
17. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the traffic control method as described in any one of claims 1 to 4, or implements the traffic control method as described in any one of claims 5 to 11.