Port traffic detection method, device and equipment based on Tofino switch, medium and program product

By detecting port traffic on Tofino switches and using current and historical traffic rates to identify abnormal traffic, this technology overcomes the shortcomings of traditional detection techniques on Tofino switches, enabling accurate identification and anomaly detection of traffic fluctuations.

CN121334005APending Publication Date: 2026-01-13CHINA TELECOM CLOUD TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511815885.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-04
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

Traditional network detection technologies cannot provide sufficient detail and real-time performance when dealing with Tofino switches, making it difficult to accurately reflect the dynamic changes and trends of traffic. This results in insufficient ability to detect and analyze traffic bursts, fluctuations, and abnormal traffic patterns within a short period of time.

Method used

By performing traffic detection on the target ports of the switch, raw traffic data is obtained, current and historical traffic rates are calculated, abnormal traffic is identified using a moving average model and a preset deviation ratio, and a periodic detection mechanism is adopted to accurately identify abnormal traffic fluctuations.

Benefits of technology

It implements port-level granularity for abnormal traffic detection, which can locate specific abnormal ports, distinguish between sudden business traffic and abnormal attack traffic, improve detection accuracy, and capture hidden anomalies such as instantaneous traffic mutations and slow growth.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121334005A_ABST
    Figure CN121334005A_ABST
Patent Text Reader

Abstract

The invention relates to a port traffic detection method, device and equipment based on a Tofino switch, a medium and a program product. The method comprises the following steps: carrying out traffic detection on a target port of a switch to obtain original traffic data passing through the target port in a current detection period; determining a current traffic rate of the target port in the current detection period according to the original traffic data; acquiring a historical flow rate of the target port in at least one historical detection period; and performing abnormal traffic identification on the target port according to the current traffic rate and the historical traffic rate to obtain a traffic identification result of the target port in the current detection period. By adopting the method, the accuracy of port flow detection of the Tofino switch can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a method, apparatus, network device, computer-readable storage medium, and computer program product for port traffic detection based on a Tofino switch. Background Technology

[0002] In cloud computing environments, network traffic is dynamic, bursty, and diverse. The overlapping of peak and off-peak hours across different tenants in time and space makes the distribution of network traffic across different ports and links unpredictable. This unstable network traffic can lead to increased service latency, packet loss, application performance degradation, and even service interruption, impacting user experience and service reliability. Therefore, to ensure service quality, network operators and cloud service providers need to effectively monitor and manage the network to ensure the rational allocation and optimization of network resources.

[0003] However, traditional network detection techniques have many limitations when dealing with Tofino switches. Traditional detection methods based on port counters and simple statistics cannot provide sufficient detail and real-time performance, making it difficult to accurately reflect the dynamic changes and trends of traffic. This results in insufficient ability to detect and analyze short-term traffic bursts, fluctuations, and abnormal traffic patterns. Summary of the Invention

[0004] Therefore, it is necessary to provide a method, apparatus, network device, computer-readable storage medium, and computer program product for port traffic detection based on Tofino switches that can improve detection accuracy in response to the above-mentioned technical problems.

[0005] Firstly, this application provides a port traffic detection method based on a Tofino switch, the method comprising:

[0006] Traffic detection is performed on the target port of the switch to obtain the raw traffic data passing through the target port within the current detection period;

[0007] The current traffic rate of the target port in the current detection period is determined based on the original traffic data.

[0008] Obtain the historical traffic rate of the target port within at least one historical detection period;

[0009] Based on the current traffic rate and the historical traffic rate, abnormal traffic is identified for the target port to obtain the traffic identification result of the target port within the current detection period.

[0010] Secondly, this application also provides a port traffic detection device based on a Tofino switch, the device comprising:

[0011] The detection module is used to perform traffic detection on the target port of the switch and obtain the raw traffic data passing through the target port within the current detection period;

[0012] The determination module is used to determine the current traffic rate of the target port within the current detection period based on the original traffic data;

[0013] The acquisition module is used to acquire the historical traffic rate of the target port within at least one historical detection period;

[0014] The identification module is used to identify abnormal traffic of the target port based on the current traffic rate and the historical traffic rate, and to obtain the traffic identification result of the target port within the current detection period.

[0015] In one embodiment, the raw traffic data includes raw inbound through traffic count and raw outbound through traffic count, and the current traffic rate includes current inbound through traffic rate and current outbound through traffic rate;

[0016] The determining module is used to determine the current inbound flow rate based on the original inbound flow count and the current detection time period; and to determine the current outbound flow rate based on the original outbound flow count and the current detection time period.

[0017] In one embodiment, the at least one historical detection period includes multiple historical detection periods; the identification module is configured to determine the average historical traffic rate of each of the multiple historical detection periods based on the historical traffic rates within the multiple historical detection periods; determine the current traffic deviation ratio in the current detection period based on the average historical traffic rate of each of the multiple historical detection periods and the current traffic rate; and perform abnormal traffic identification on the target port based on the preset deviation ratio and the current traffic deviation ratio to obtain the traffic identification result of the target port in the current detection period.

[0018] In one embodiment, the identification module is configured to determine a target average of the plurality of historical flow rate averages; and to determine the current flow deviation ratio within the current detection period based on the target average and the current flow rate.

[0019] In one embodiment, the traffic identification result includes normal traffic and abnormal traffic; the identification module is used to determine that the traffic passing through the target port in the current detection period is normal traffic when the current traffic deviation ratio is less than a preset deviation ratio; and to determine that the traffic passing through the target port in the current detection period is abnormal traffic when the current traffic deviation ratio is not less than the preset deviation ratio.

[0020] In one embodiment, the detection module is used to detect the port status of each port of the switch, the port status including an on state and a off state; to filter out target ports whose port status is on from the ports, to perform traffic detection on the target ports, and to obtain the raw traffic data passing through the target ports in the current detection period.

[0021] Thirdly, this application also provides a network device, including a switching chip, a memory, and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:

[0022] Traffic detection is performed on the target port of the switch to obtain the raw traffic data passing through the target port within the current detection period;

[0023] The current traffic rate of the target port in the current detection period is determined based on the original traffic data.

[0024] Obtain the historical traffic rate of the target port within at least one historical detection period;

[0025] Based on the current traffic rate and the historical traffic rate, abnormal traffic is identified for the target port to obtain the traffic identification result of the target port within the current detection period.

[0026] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the following steps:

[0027] Traffic detection is performed on the target port of the switch to obtain the raw traffic data passing through the target port within the current detection period;

[0028] The current traffic rate of the target port in the current detection period is determined based on the original traffic data.

[0029] Obtain the historical traffic rate of the target port within at least one historical detection period;

[0030] Based on the current traffic rate and the historical traffic rate, abnormal traffic is identified for the target port to obtain the traffic identification result of the target port within the current detection period.

[0031] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, performs the following steps:

[0032] Traffic detection is performed on the target port of the switch to obtain the raw traffic data passing through the target port within the current detection period;

[0033] The current traffic rate of the target port in the current detection period is determined based on the original traffic data.

[0034] Obtain the historical traffic rate of the target port within at least one historical detection period;

[0035] Based on the current traffic rate and the historical traffic rate, abnormal traffic is identified for the target port to obtain the traffic identification result of the target port within the current detection period.

[0036] The aforementioned port traffic detection method, apparatus, network device, computer-readable storage medium, and computer program product based on Tofino switches obtains raw traffic data passing through the target port within the current detection period by detecting traffic at the target port of the switch. Based on the raw traffic data, the current traffic rate of the target port within the current detection period is determined, and the historical traffic rate of the target port within at least one historical detection period is obtained. Based on the current and historical traffic rates, abnormal traffic is identified at the target port, yielding the traffic identification result for the target port within the current detection period. This allows for port-level granular detection, pinpointing specific abnormal ports. Furthermore, by comparing the current traffic rate with multi-period historical baselines, abnormal traffic fluctuations deviating from normal patterns can be accurately identified, effectively distinguishing between sudden service traffic and abnormal attack traffic, thus improving detection accuracy. Moreover, the periodic continuous detection mechanism can capture both instantaneous traffic surges and slowly growing, hidden anomalies, enhancing the accuracy of abnormal port traffic detection. Attached Figure Description

[0037] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0038] Figure 1This is an application environment diagram of a port traffic detection method based on a Tofino switch in one embodiment;

[0039] Figure 2 This is a flowchart illustrating a port traffic detection method based on a Tofino switch in one embodiment.

[0040] Figure 3 This is a schematic diagram of the port traffic detection step based on a Tofino switch in one embodiment;

[0041] Figure 4 This is a flowchart illustrating a network topology based on a Tofino switch in another embodiment;

[0042] Figure 5 This is a schematic diagram illustrating the process of the control plane issuing configurations by constructing entries in the data plane forwarding table in another embodiment;

[0043] Figure 6 This is a schematic diagram of the normal port traffic rate curve in another embodiment;

[0044] Figure 7 This is a schematic diagram illustrating the actual rate detected by the target port during the streaming process in another embodiment;

[0045] Figure 8 This is a schematic diagram of an abnormal port traffic rate in another embodiment;

[0046] Figure 9 This is a structural block diagram of a port traffic detection device based on a Tofino switch in one embodiment;

[0047] Figure 10 This is a diagram of the internal structure of a network device in one embodiment. Detailed Implementation

[0048] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0049] First, the key terms used in this application are explained as follows:

[0050] Tofino switches are high-performance network switches built on Barefoot Networks' Tofino series chips.

[0051] Cloud servers are elastic computing resources provided by cloud service providers through virtualization technology. Users can rent resources such as CPU, memory, and storage on demand without having to manage physical hardware.

[0052] gRPC is an RPC framework that allows client applications to directly call functions on remote servers as if they were local functions.

[0053] The moving average model is a time series forecasting method that uses the average value of past data as the forecast value.

[0054] The deviation ratio (DR) refers to the deviation rate between the current rate and the predicted rate.

[0055] The ipv4_lpm table refers to the table used by the data plane to forward data based on IP address prefixes.

[0056] It should be noted that the terms "first," "second," etc., used in this application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "comprising" and "having," and any variations thereof, used in this application, are intended to cover non-exclusive inclusion. The term "multiple" used in this application refers to two or more. The term "and / or" used in this application refers to one of the embodiments, or any combination of multiple embodiments.

[0057] The port traffic detection method based on Tofino switches provided in this application can be applied to, for example... Figure 1 In the application environment shown, the first network device 102 communicates with the second network device 106 through a Tofino switch 104. When the first network device 102 sends traffic data to the second network device 106 through the target port of the Tofino switch 104, the Tofino switch 104 performs traffic detection on the target port to obtain the raw traffic data passing through the target port within the current detection period. Based on the raw traffic data, the Tofino switch 104 determines the current traffic rate of the target port within the current detection period and obtains the historical traffic rate of the target port within at least one historical detection period. Based on the current traffic rate and the historical traffic rate, the Tofino switch 104 identifies abnormal traffic at the target port and obtains the traffic identification result of the target port within the current detection period.

[0058] In this system, the first network device 102 can be a terminal or a server, and the second network device 106 can also be a terminal or a server. Terminals can be, but are not limited to, various personal computers, laptops, smartphones, tablets, drones, low-altitude aircraft, IoT devices, and portable wearable devices. IoT devices can include smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, projection devices, switches, etc. Portable wearable devices can include smartwatches, smart bracelets, head-mounted displays, etc. Head-mounted displays can be virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, etc. Servers can be independent physical servers, server clusters or distributed systems composed of multiple physical servers, or cloud servers providing cloud computing services. Cloud servers include, for example, cloud hosts.

[0059] In one exemplary embodiment, such as Figure 2 As shown, a port traffic detection method based on a Tofino switch is provided, which can be applied to network devices (such as...) Figure 1 Taking the Tofino switch as an example, the explanation includes:

[0060] Step 202: Perform traffic detection on the target port of the switch to obtain the raw traffic data passing through the target port within the current detection period.

[0061] Raw traffic data refers to traffic data passing through the target port within the current detection period. Raw traffic data includes at least one of raw inbound traffic data or raw outbound traffic data. Raw inbound traffic data includes raw inbound through traffic counts and may also include raw inbound dropped traffic counts. Raw outbound traffic data includes raw outbound through traffic counts and may also include raw outbound dropped traffic counts.

[0062] Raw inbound traffic data refers to the traffic data flowing into the switch during the current detection period. Raw outbound traffic data refers to the traffic data flowing out of the switch during the current detection period.

[0063] In one embodiment, the target port is the port through which the first cloud host and the second cloud host communicate with each other, and the first cloud host is used to send traffic to the second cloud host. The first cloud host includes at least one cloud host, and the second cloud host includes at least one cloud host.

[0064] Specifically, network devices can periodically detect traffic at the target port of a switch to obtain raw traffic data passing through the target port within the current detection period. For example, a period of 10 seconds or 60 seconds may be used, but this is not the only possibility.

[0065] In this embodiment, the network device can detect at least one of the original inbound traffic data or the original outbound traffic data of the target port of the switch within the current detection period, and use at least one of the original inbound traffic data or the original outbound traffic data as the original traffic data.

[0066] In one embodiment, traffic detection is performed on the target port of the switch to obtain raw traffic data passing through the target port within the current detection period, including:

[0067] The system detects the port status of each port on the switch, including whether the port is on or off. It then selects the target port that is on and performs traffic detection on the target port to obtain the raw traffic data passing through the target port within the current detection period.

[0068] The port status includes an open state and a closed state. The open state represents the normal state of the target port, while the closed state represents the abnormal state of the target port.

[0069] Specifically, network devices can periodically detect the port status of each port on the switch and identify and filter target ports that are in an open state. Periodic traffic detection is then performed on these target ports to obtain raw traffic data passing through them within the current detection period.

[0070] In one embodiment, when the port status of each port is closed, the process returns to the step of detecting the port status of each port of the switch and continues execution.

[0071] In this embodiment, a port status pre-screening mechanism is introduced, achieving intelligent optimization of detection resources and a significant improvement in result reliability. First, by only detecting traffic on ports that are in the UP state, invalid monitoring on physically disconnected or administratively disabled ports is effectively avoided, greatly reducing the resource overhead of data collection and processing. Second, this mechanism ensures the authenticity and representativeness of traffic data, eliminating interference from zero or abnormal traffic caused by physically unavailable ports, allowing subsequent rate calculations and anomaly identification to focus more on active links actually carrying services. Finally, this design improves detection efficiency while enhancing the accuracy of anomaly alarms, avoiding misjudgments of inactive ports, and enabling operations and maintenance personnel to focus more on truly potential network performance and security issues.

[0072] Step 204: Determine the current traffic rate of the target port within the current detection period based on the original traffic data.

[0073] The raw flow data includes at least one of the raw inbound flow count or the raw outbound flow count.

[0074] The current traffic rate refers to the traffic rate passing through the target port within the current detection period. Specifically, the traffic rate passing through the target port within a unit of time in the current detection period refers to the traffic passing through the target port.

[0075] Specifically, the network device can determine the current inbound traffic rate based on the original inbound traffic count and the current detection period. It can also determine the current outbound traffic rate based on the original outbound traffic count and the current detection period. At least one of the current inbound and outbound traffic rates is used as the current traffic rate of the target port within the current detection period.

[0076] In one embodiment, the raw traffic data includes the raw inbound through traffic count and the raw outbound through traffic count, the current traffic rate includes the current inbound through traffic rate and the current outbound through traffic rate, and the current detection period is characterized by the current detection time period.

[0077] The current traffic rate of the target port within the current detection period is determined based on the original traffic data, including: determining the current inbound traffic rate based on the original inbound traffic count and the current detection time period; and determining the current outbound traffic rate based on the original outbound traffic count and the current detection time period.

[0078] Specifically, the network device determines the incoming traffic rate per unit time based on the original incoming traffic count and the current detection period. This incoming traffic rate is the current incoming traffic rate of the target port in the current detection period.

[0079] For example, the ratio of the original incoming flow rate to the current detection time period can be used as the current incoming flow rate.

[0080] The network device determines the outbound traffic rate per unit time based on the original outbound traffic count and the current detection period. This outbound traffic rate is the current outbound traffic rate of the target port in the current detection period.

[0081] For example, the ratio of the original outbound flow count to the current detection time period can be used as the current outbound flow rate.

[0082] In one embodiment, the raw traffic data includes raw inbound traffic count, raw outbound traffic count, raw inbound discarded traffic count, and raw outbound discarded traffic count; the valid inbound traffic count can be determined based on the raw inbound traffic count and the raw inbound discarded traffic count; and the current inbound traffic rate can be determined based on the valid inbound traffic count and the current detection time period.

[0083] For example, the difference between the original incoming flow count and the original incoming discard flow count is calculated. This difference is the effective incoming flow count. The ratio of this difference to the current detection time period is calculated. This ratio is the current incoming flow rate.

[0084] The effective outbound flow count can be determined based on the original outbound flow count and the original outbound discard flow count; the current outbound flow rate can be determined based on the effective outbound flow count and the current detection time period.

[0085] For example, calculate the difference between the original outbound through traffic count and the original outbound discard traffic count. This difference is the valid outbound through traffic count. Calculate the ratio of this difference to the current detection time period. This ratio is the current outbound through traffic rate.

[0086] In this embodiment, by separately collecting and calculating independent rate metrics for inbound and outbound traffic, accurate detection and in-depth analysis of bidirectional asymmetry in port traffic are achieved. On the one hand, this design can accurately identify abnormal patterns in network traffic direction. For example, a surge in inbound traffic may reflect DDoS attacks or scanning behavior, while abnormal outbound traffic may indicate forwarding anomalies. On the other hand, by calculating rates based on the raw counts and detection period time of inbound and outbound traffic respectively, a more detailed performance baseline can be obtained, effectively detecting problems such as unidirectional link congestion, policy routing anomalies, or asymmetric routing. This bidirectional independent detection mechanism not only improves the dimensionality and accuracy of anomaly detection but also provides richer and more reliable decision-making basis for subsequent network fault location, security threat analysis, and capacity planning.

[0087] Step 206: Obtain the historical traffic rate of the target port within at least one historical detection period.

[0088] Historical traffic rate refers to the traffic rate passing through the target port within a historical detection period. Specifically, the traffic rate passing through the target port within a historical detection period refers to the traffic passing through the target port per unit time within that period.

[0089] Specifically, the network device can obtain historical traffic data of the target port within at least one historical detection period. The original traffic data refers to the traffic data that passed through the target port within the historical detection period.

[0090] For each historical detection period, the network device can determine the historical traffic rate for that historical detection period based on the historical traffic data and the historical detection period itself.

[0091] In one embodiment, historical traffic data refers to traffic data passing through the target port within a historical detection period. Historical traffic data includes at least one of historical inbound traffic data or historical outbound traffic data. Historical inbound traffic data includes historical inbound through traffic counts and may also include historical inbound dropped traffic counts. Historical outbound traffic data includes historical outbound through traffic counts and may also include historical outbound dropped traffic counts.

[0092] Historical inbound traffic data refers to traffic data flowing into the switch during the historical monitoring period. Historical outbound traffic data refers to traffic data flowing out of the switch during the historical monitoring period.

[0093] In one embodiment, historical traffic data includes historical inbound traffic count and historical outbound traffic count, historical traffic rate includes historical inbound traffic rate and historical outbound traffic rate, and historical detection period is characterized by historical detection time period.

[0094] Determine the historical traffic rate of the target port within the historical detection period based on historical traffic data, including:

[0095] Based on historical inbound traffic counts and historical detection time periods, determine the historical inbound traffic rate; based on historical outbound traffic counts and historical detection time periods, determine the historical outbound traffic rate.

[0096] Step 208: Based on the current traffic rate and historical traffic rate, identify abnormal traffic on the target port and obtain the traffic identification result of the target port in the current detection period.

[0097] The traffic identification results include those representing normal traffic and those representing abnormal traffic. Normal traffic identification results indicate that traffic passing through the target port within the current detection period is considered normal traffic. Abnormal traffic identification results indicate that traffic passing through the target port within the current detection period is considered abnormal traffic.

[0098] Specifically, network devices can determine the current traffic deviation ratio of a target port within the current detection period based on the current traffic rate and historical traffic rates. Abnormal traffic is then identified for the target port based on this current traffic deviation ratio, yielding the traffic identification result for the target port within the current detection period.

[0099] In one embodiment, a preset deviation ratio is obtained, and abnormal traffic is identified for the target port based on the preset deviation ratio and the current traffic deviation ratio, so as to obtain the traffic identification result of the target port in the current detection period.

[0100] In one embodiment, at least one historical detection period includes multiple historical detection periods; based on the current traffic rate and historical traffic rate, abnormal traffic is identified on the target port to obtain the traffic identification result of the target port within the current detection period, including:

[0101] Based on the historical traffic rates over multiple historical detection periods, the average historical traffic rate for each of the multiple historical detection periods is determined. Based on the average historical traffic rate over multiple historical detection periods and the current traffic rate, the current traffic deviation ratio for the current detection period is determined. Based on the preset deviation ratio and the current traffic deviation ratio, abnormal traffic is identified for the target port, and the traffic identification result for the target port in the current detection period is obtained.

[0102] Specifically, network devices can calculate the average historical traffic rate for each of the multiple historical detection periods based on the historical traffic rates within those periods. For example, the average historical traffic rate for each of the multiple historical detection periods can be calculated using the following formula:

[0103]

[0104] in, x=[ x 1 , x 2 , x 3 ,..., x n ] Time-series data representing the historical traffic rate of the target port. The 1st Historical flow rates over n historical detection cycles. Let W represent the average historical flow rate corresponding to the i-th historical detection period. W is the given moving window size, where... .

[0105] Next, the network device can determine the current traffic deviation ratio in the current detection period based on the average historical traffic rate and the current traffic rate in each of the multiple historical detection periods.

[0106] Based on the comparison between the preset deviation ratio and the current traffic deviation ratio, abnormal traffic is identified for the target port, and the traffic identification result of the target port within the current detection period is obtained.

[0107] In this embodiment, a dynamic traffic baseline is constructed using the average rate over multiple historical periods instead of single-point data. This effectively smooths out normal fluctuations caused by business cycle variations and reduces false alarms. Furthermore, by calculating the deviation ratio between the current rate and the dynamic baseline and combining it with a preset threshold, a quantitative assessment of the degree of anomaly is achieved. This allows for the sensitive detection of sudden anomalies that significantly deviate from historical patterns (such as attack traffic) as well as the identification of slowly deviating, covert anomalies. This effectively overcomes the shortcomings of traditional static threshold methods, which are difficult to adapt to natural changes in business traffic. The anomaly detection mechanism can autonomously adjust with the evolution of network business patterns, maintaining a balance between high detection rate and low false alarm rate in complex and ever-changing real-world environments.

[0108] In one embodiment, determining the current flow deviation ratio within the current detection period based on the average historical flow rate over multiple historical detection periods and the current flow rate includes:

[0109] Determine the target mean of multiple historical flow rate averages; based on the target mean and the current flow rate, determine the current flow deviation ratio within the current detection period.

[0110] Specifically, the network device can calculate a target average of multiple historical traffic rate averages, calculate the difference between the current traffic rate and the target average, and use the ratio of the difference to the target average as the current traffic deviation ratio within the current detection period.

[0111] For example, the target mean can be calculated using the following formula. :

[0112]

[0113] Among them, sequence [M A 1 ,M A 2 ,...,M A n - w+1 ] Each element in the table represents the average historical flow rate.

[0114] The current flow deviation ratio (DR) can be calculated using the following formula:

[0115]

[0116] in, This represents the current traffic rate.

[0117] In this embodiment, by further aggregating multiple historical period averages into a target average, a more stable and representative long-term traffic benchmark is constructed, effectively enhancing the robustness and anti-interference capability of anomaly detection. On the one hand, secondary aggregation of multiple historical averages can effectively filter short-term random fluctuations and occasional noise, forming essential characteristics that reflect the inherent traffic features of the port, thereby avoiding the impact of accidental anomalies in individual historical periods on the benchmark. On the other hand, calculating the current deviation ratio based on this target average allows the detection logic to focus more on substantial anomalies that deviate from the long-term steady state, improving the ability to detect slow threats such as persistent attacks or gradual performance degradation, while reducing the risk of misjudgment caused by changes in normal business cycles or sudden but reasonable traffic.

[0118] In one embodiment, the traffic identification result includes normal traffic and abnormal traffic; based on a preset deviation ratio and the current traffic deviation ratio, abnormal traffic identification is performed on the target port to obtain the traffic identification result of the target port within the current detection period, including:

[0119] If the current traffic deviation ratio is less than the preset deviation ratio, the traffic passing through the target port in the current detection period is determined to be normal traffic; if the current traffic deviation ratio is not less than the preset deviation ratio, the traffic passing through the target port in the current detection period is determined to be abnormal traffic.

[0120] Specifically, if the current traffic deviation ratio is less than the preset deviation ratio, the traffic passing through the target port within the current detection period is determined to be normal traffic. If the current traffic deviation ratio is not less than the preset deviation ratio, the traffic passing through the target port within the current detection period is determined to be abnormal traffic.

[0121] In this embodiment, by clearly comparing the quantified traffic deviation ratio with a preset threshold, the determination of abnormal traffic is automated and the decision-making is made objective, significantly improving the efficiency of operation and maintenance response and the consistency of detection results. On the one hand, the clear threshold rules transform complex traffic pattern recognition into executable and verifiable logical judgments, facilitating automated alarm and handling by the system and reducing the subjectivity and delay of manual analysis. On the other hand, this design uses a single but crucial deviation ratio threshold as a dividing line, ensuring both the efficiency and interpretability of the algorithm, and allowing operation and maintenance personnel to flexibly adjust the preset ratio according to network tolerance, thereby achieving a balance between sensitivity and stability. This ensures that while efficiently capturing real anomalies, the false alarm rate is effectively controlled, providing a clear and reliable triggering basis for subsequent operations such as fault isolation, security blocking, or capacity expansion.

[0122] The aforementioned port traffic detection method based on Tofino switches performs traffic detection on the target port of the switch to obtain the raw traffic data passing through the target port within the current detection period. Based on the raw traffic data, the current traffic rate of the target port within the current detection period is determined, and the historical traffic rate of the target port within at least one historical detection period is obtained. Based on the current traffic rate and the historical traffic rate, abnormal traffic is identified on the target port, obtaining the traffic identification result of the target port within the current detection period. This allows for port-level granular detection, pinpointing specific abnormal ports. Furthermore, by comparing the current traffic rate with multi-period historical baselines, abnormal traffic fluctuations deviating from normal patterns can be accurately identified, effectively distinguishing between sudden service traffic and abnormal attack traffic, thus improving detection accuracy. Moreover, the periodic continuous detection mechanism can capture both instantaneous traffic surges and slowly growing, hidden anomalies, enhancing the accuracy of abnormal port traffic detection.

[0123] In one embodiment, a port traffic detection method based on a Tofino switch is provided, applied to a network device, comprising:

[0124] Detect the port status of each port on the switch, including whether the port is on or off;

[0125] Select the target ports that are in the open state from all ports, perform traffic detection on the target ports, and obtain the raw traffic data passing through the target ports in the current detection period; the raw traffic data includes the raw inbound traffic count and the raw outbound traffic count.

[0126] The current traffic rate of the target port within the current detection period is determined based on the original traffic data. The current traffic rate includes the current inbound traffic rate and the current outbound traffic rate. The current inbound traffic rate is determined based on the original inbound traffic count and the current detection time period, and the current outbound traffic rate is determined based on the original outbound traffic count and the current detection time period.

[0127] Obtain the historical traffic rate of the target port within at least one historical detection period;

[0128] The average historical flow rate for each of the multiple historical detection periods is determined based on the historical flow rate over the multiple historical detection periods.

[0129] Determine the target mean of multiple historical flow rate averages, and based on the target mean and the current flow rate, determine the current flow deviation ratio within the current detection period;

[0130] If the current traffic deviation ratio is less than the preset deviation ratio, the traffic passing through the target port within the current detection period is determined to be normal traffic.

[0131] If the current traffic deviation ratio is not less than the preset deviation ratio, the traffic passing through the target port within the current detection period is determined to be abnormal traffic.

[0132] In one embodiment, such as Figure 3 As shown, a port traffic detection system based on a Tofino switch is provided, specifically applied in the scenario of detecting port traffic fluctuations on a Tofino switch. In this scenario, the system is a port traffic fluctuation detection system based on a Tofino switch. The purpose of this system is to enhance the detection of port traffic changes, enabling real-time acquisition of port status, traffic, and detection of port traffic fluctuations, timely detection of abnormal traffic, and providing strong support for network troubleshooting.

[0133] The system functionally includes three detection modules, such as Figure 3 As shown, there are port status detection unit, port traffic detection unit, and port traffic anomaly detection unit, respectively.

[0134] Port Status Detection Unit: This unit is mainly responsible for detecting the port status of the Tofino switch being used. This unit uses the gRPC interface to subscribe to the port status changes of the switch. When the port status (down) of the monitored target port changes to the closed state, this unit will upload the information to the detection platform.

[0135] Port Traffic Detection Unit: This unit primarily detects the port traffic of the Tofino switch in use. It periodically reads raw traffic data from target ports that are in the UP (Up) state. The raw traffic data includes the raw outbound traffic count, raw inbound traffic count, raw outbound dropped traffic count, and raw inbound dropped traffic count for the target port. In each detection cycle, the unit calculates the traffic rate for that cycle, recording it as the current inbound traffic rate and the current outbound traffic rate. This unit then uploads the raw outbound traffic count, raw inbound traffic count, raw outbound dropped traffic count, raw inbound dropped traffic count, current inbound traffic rate, and current outbound traffic rate of the target port to the detection platform.

[0136] Port Traffic Anomaly Detection Unit: This unit mainly detects whether the traffic of the target port is abnormal within the current detection period based on the current inbound traffic rate and the current outbound traffic rate calculated by the port traffic detection unit.

[0137] Specifically, a moving average model is selected based on the characteristics of network traffic. The moving average model is a time series forecasting method that uses the average of historical traffic rates over multiple historical monitoring periods as the predicted value. For data with random fluctuations, the moving average can smooth the data and eliminate some short-term fluctuations.

[0138] set up x=[ x 1 , x 2 , x 3 ,..., x n ] This represents time-series data indicating the historical traffic rate of the target port, where... This represents the historical flow rate for the nth historical detection period, given a window size. The formula for calculating the moving average (i.e., the historical average flow rate) using the moving average model is as follows:

[0139]

[0140] in, This represents the moving average of a window of size w starting from the i-th data point, i.e., the historical average flow rate.

[0141] To determine the current flow rate To determine if the current flow deviation ratio (DR) is normal, the following formula is used for calculation:

[0142]

[0143] in, It is a moving average sequence [M A 1 ,M A 2 ,...,M A n-w+1 ] The average value (i.e., the target mean) is:

[0144]

[0145] when At that time, the current traffic rate of the target port is considered to be... It's normal traffic; when At that time, the current flow rate is considered to be... This refers to abnormal traffic. Where T is a threshold set based on actual conditions, i.e., a preset deviation ratio.

[0146] In one embodiment, the effectiveness of a Tofino switch port traffic fluctuation detection system can be verified using the following method: The specific implementation plan is as follows:

[0147] Constructing network topology, such as Figure 4 As shown, there are two cloud hosts in the topology, namely cloud host 1 and cloud host 2, and one Tofino switch. Both cloud hosts can communicate with each other through the Tofino switch.

[0148] The data plane is designed, which includes a table, ipv4_lpm, to distribute traffic to different destination IPs. The goal is to enable cloud host 1 and cloud host 2 to communicate with each other, providing a foundation for subsequent traffic construction.

[0149] The control plane is designed, and configurations are distributed by constructing table entries in the data plane forwarding table, such as... Figure 5 As shown, forwarding logic is sent to the data plane by constructing entries in the ipv4_lpm table.

[0150] Traffic forwarding: Cloud server 2 acts as the server, responsible for receiving traffic, while cloud server 1, as the client, is responsible for sending traffic. Before traffic forwarding, a detection system is started to observe the port status on the detection dashboard and check whether the traffic rate of the target port is normal. Figure 6 As shown, 1 indicates that the port status is UP. Cloud host 1 continuously streams traffic to cloud host 2 for 10 minutes, with a bandwidth of approximately 2Mbps. Immediately after the first stream ends, it streams 10Mbps bandwidth traffic to cloud host 2 for approximately 2 minutes. After the second stream ends, it immediately resumes the first stream rate and continues for a longer period. Observe on the monitoring dashboard whether the target port rate matches the actual stream rate, and check whether the traffic anomaly detection system reports the detection results. Figure 7 This indicates the actual rate detected by the target port during the traffic interception process. Both cloud host 1 and cloud host 2 receive and send traffic from the same target port, and the detection dashboard shows that the actual rate detected by the target port meets expectations. Figure 8 As can be seen, during the second flow detection, the port traffic anomaly detection unit reports the detection results. A value of 0 indicates that the traffic may be abnormal and needs to be manually checked to see if any abnormality has occurred.

[0151] In this embodiment, the proposed detection system for port traffic fluctuations based on Tofino switches enables real-time detection of switch port status and traffic conditions, as well as alarms for abnormal traffic. Real-time port status detection on the programmable switch helps maintenance personnel promptly identify any port anomalies. Furthermore, real-time port traffic statistics are implemented on the programmable switch, allowing maintenance personnel to observe port traffic rates in real-time on the monitoring dashboard. Real-time detection of abnormal port traffic is also implemented on the programmable switch. Since the maximum port speed of a Tofino switch is 100Gbps, this system can detect abnormal traffic in real time during sudden traffic surges, helping maintenance personnel to identify abnormal traffic early, prevent ports from operating at full capacity, and avoid impacting other normal services.

[0152] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps. It is understood that the steps in different embodiments can be freely combined as needed, and all non-contradictory solutions formed by such combinations are within the scope of protection of this application.

[0153] Based on the same inventive concept, this application also provides a Tofino switch-based port traffic detection device for implementing the aforementioned Tofino switch-based port traffic detection method. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more port traffic detection device embodiments provided below can be found in the limitations of the Tofino switch-based port traffic detection method described above, and will not be repeated here.

[0154] In one exemplary embodiment, such as Figure 9 As shown, a port traffic detection device 900 based on a Tofino switch is provided, comprising:

[0155] The detection module 902 is used to perform traffic detection on the target port of the switch and obtain the raw traffic data passing through the target port within the current detection period.

[0156] The determination module 904 is used to determine the current traffic rate of the target port in the current detection period based on the raw traffic data.

[0157] The acquisition module 906 is used to acquire the historical traffic rate of the target port within at least one historical detection period.

[0158] The identification module 908 is used to identify abnormal traffic on the target port based on the current traffic rate and historical traffic rate, and to obtain the traffic identification result of the target port in the current detection period.

[0159] In one embodiment, the raw traffic data includes the raw inbound through traffic count and the raw outbound through traffic count, and the current traffic rate includes the current inbound through traffic rate and the current outbound through traffic rate.

[0160] The determination module is used to determine the current inbound flow rate based on the original inbound flow count and the current detection time period; and to determine the current outbound flow rate based on the original outbound flow count and the current detection time period.

[0161] In one embodiment, at least one historical detection period includes multiple historical detection periods; the identification module is used to determine the average historical traffic rate of each of the multiple historical detection periods based on the historical traffic rate of each of the multiple historical detection periods; determine the current traffic deviation ratio in the current detection period based on the average historical traffic rate of each of the multiple historical detection periods and the current traffic rate; and identify abnormal traffic of the target port based on the preset deviation ratio and the current traffic deviation ratio to obtain the traffic identification result of the target port in the current detection period.

[0162] In one embodiment, the identification module is configured to determine the average historical flow rate based on the average historical flow rate of each of the multiple historical detection periods; and to determine the current flow deviation ratio in the current detection period based on the average historical flow rate and the current flow rate.

[0163] In one embodiment, the traffic identification result includes normal traffic and abnormal traffic; the identification module is used to determine that the traffic passing through the target port in the current detection period is normal traffic when the current traffic deviation ratio is less than a preset deviation ratio; and to determine that the traffic passing through the target port in the current detection period is abnormal traffic when the current traffic deviation ratio is not less than the preset deviation ratio.

[0164] In one embodiment, the detection module is used to detect the port status of each port of the switch, including the port status being open and closed; to filter out the target port whose port status is open from the ports, to perform traffic detection on the target port, and to obtain the raw traffic data passing through the target port in the current detection period.

[0165] The various modules in the aforementioned Tofino switch-based port traffic detection device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can run as software on the Tofino switch, enabling them to acquire underlying chip data and push detection data to other servers.

[0166] In an exemplary embodiment, a network device is provided, taking a Tofino switch as an example, whose internal structure diagram is shown in the figure above. The Tofino switch includes a port layer, a core switching layer, and a CPU management layer. The port layer, core switching layer, and CPU management layer are connected through corresponding interfaces: the management port of the port layer is connected to the CPU management layer, the 100G port of the port layer is connected to the high-speed serial interface of the core switching layer, and the core switching layer and CPU management layer are connected through a PCIe interface.

[0167] The Tofino switch's port layer provides external access and management links for the device, including two management ports (for configuration, detection, and other management operations) and 32 100G ports (for high-bandwidth network data transmission and reception). The core switching layer is the core data forwarding processing module, comprising a high-speed serial interface and a Tofino switching chip. The high-speed serial interface interfaces the 100G ports on the port layer for receiving and sending data, while the Tofino switching chip handles high-speed data forwarding, protocol processing, and other core switching logic. The CPU management layer provides control and maintenance support for the device, including an x86 multi-core CPU, memory, hard disk, and PCIe interface. The x86 multi-core CPU handles management control and protocol execution; memory provides data caching and the operating environment for the CPU; the hard disk stores configuration files, logs, and other data; and the PCIe interface facilitates information exchange between the CPU management layer and the core switching layer. These hardware components work together to enable the Tofino switch's high-speed network data forwarding, device configuration management, and other network switching functions.

[0168] Those skilled in the art will understand that Figure 10 The structure shown is merely a block diagram of a portion of the structure related to the solution of this application and does not constitute a limitation on the network device to which the solution of this application is applied. Specific network devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0169] In one exemplary embodiment, a network device is provided, including a switching chip, a memory, and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the methods described above.

[0170] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps of the methods described above.

[0171] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of the methods described above.

[0172] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.

[0173] Those skilled in the art will understand that all or part of the hardware coordination logic for implementing the network data forwarding, device management and control functions of the Tofino switch described above can be accomplished by instructing related hardware modules through configuration programs and firmware. The configuration programs and firmware can be stored in the non-volatile storage medium of the Tofino switch. When executed, the configuration programs and firmware can include functional logic flows such as port data transmission and reception of the Tofino switch, data forwarding of the core switching chip, and device detection at the CPU management layer. Any reference to storage components or other media used in the Tofino switch description in this application can include at least one of non-volatile storage media and volatile memory. Non-volatile storage media can include hard disks, read-only memory (ROM), magnetic tape, floppy disks, flash memory, optical storage, high-density embedded non-volatile memory, resistive random access memory (ReRAM), etc. Volatile memory can include main memory, random access memory (RAM), or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The switching processing device involved in the Tofino switch in this application can be a Tofino switching chip, and may also include programmable switching chips, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), etc.; the processor involved can be an x86 multi-core CPU, and may also include general-purpose processors, central processing units, embedded processors, etc., and is not limited thereto.

[0174] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0175] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A method for port traffic detection based on Tofino switch, characterized in that, The method comprises: performing flow detection on a target port of a switch to obtain original flow data passing through the target port in a current detection period; determining a current flow rate of the target port in the current detection period according to the original flow data; obtaining historical flow rates of the target port in at least one historical detection period; performing abnormal flow identification on the target port according to the current flow rate and the historical flow rates to obtain a flow identification result of the target port in the current detection period.

2. The method of claim 1, wherein, The original flow data comprises original inbound passing flow count and original outbound passing flow count, the current flow rate comprises current inbound passing flow rate and current outbound passing flow rate, and the current detection period is represented by a current detection time period; The determining of the current flow rate of the target port in the current detection period according to the original flow data comprises: determining the current inbound passing flow rate according to the original inbound passing flow count and the current detection time period; and determining the current outbound passing flow rate according to the original outbound passing flow count and the current detection time period.

3. The method of claim 1, wherein, The at least one historical detection period comprises a plurality of historical detection periods; and the performing of the abnormal flow identification on the target port according to the current flow rate and the historical flow rates to obtain the flow identification result of the target port in the current detection period comprises: determining a historical flow rate mean value of each of the plurality of historical detection periods according to the historical flow rates in the plurality of historical detection periods; determining a current flow deviation ratio in the current detection period according to the historical flow rate mean value of each of the plurality of historical detection periods and the current flow rate; and performing the abnormal flow identification on the target port according to a preset deviation ratio and the current flow deviation ratio to obtain the flow identification result of the target port in the current detection period.

4. The method of claim 3, wherein, The determining of the current flow deviation ratio in the current detection period according to the historical flow rate mean value of each of the plurality of historical detection periods and the current flow rate comprises: determining a target mean value of the plurality of historical flow rate mean values; and determining the current flow deviation ratio in the current detection period according to the target mean value and the current flow rate.

5. The method of claim 3, wherein, The flow identification result comprises normal flow and abnormal flow; and the performing of the abnormal flow identification on the target port according to the preset deviation ratio and the current flow deviation ratio to obtain the flow identification result of the target port in the current detection period comprises: when the current flow deviation ratio is less than the preset deviation ratio, determining that the flow passing through the target port in the current detection period is normal flow; and when the current flow deviation ratio is not less than the preset deviation ratio, determining that the flow passing through the target port in the current detection period is abnormal flow.

6. The method according to any one of claims 1 to 5, characterized in that, The performing of the flow detection on the target port of the switch to obtain the original flow data passing through the target port in the current detection period comprises: detecting port states of each port of the switch, the port states including an open state and a closed state; selecting a target port with an open state from each of the ports, performing flow detection on the target port, and obtaining original flow data of the target port in a current detection period.

7. A Tofino switch based port traffic detection apparatus, characterized in that, The apparatus comprises: a detection module configured to perform flow detection on a target port of a switch and obtain original flow data of the target port in a current detection period; a determination module configured to determine a current flow rate of the target port in the current detection period according to the original flow data; an acquisition module configured to acquire a historical flow rate of the target port in at least one historical detection period; an identification module configured to perform abnormal flow identification on the target port according to the current flow rate and the historical flow rate, and obtain a flow identification result of the target port in the current detection period.

8. A network device comprising a switch chip, a memory and a processor, the memory storing a computer program, characterized in that, The processor, when executing the computer program, implements the steps of the method in any one of claims 1 to 6.

9. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program, when executed by the processor, implements the steps of the method in any one of claims 1 to 6.

10. A computer program product comprising a computer program, characterized in that, The computer program, when executed by the processor, implements the steps of the method in any one of claims 1 to 6.