Message processing method and device, electronic equipment and storage medium

By determining the business attribute information of network security event messages at the gateway and generating acceleration configuration parameters, and utilizing domain name servers and acceleration networks to achieve rapid forwarding of network security event messages, the problem of network security events not being reported in a timely manner is solved, and the processing efficiency of network security events is improved.

CN121356972APending Publication Date: 2026-01-16CHINA MOBILE GROUP JIANGSU +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511503457.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-21
Publication Date
2026-01-16

AI Technical Summary

Technical Problem

Current technologies cannot report cybersecurity incidents in a timely manner, resulting in an inability to quickly handle such incidents.

Method used

The network security event message is obtained through the gateway, its business attribute information is determined and acceleration configuration parameters are generated, the target acceleration node in the acceleration network is determined by the domain name server, and the message is transmitted to the target end through the acceleration network to achieve fast forwarding of the network security event message.

Benefits of technology

It reduces the transmission latency of network security incident messages, shortens troubleshooting time, and helps to facilitate the rapid handling of network security incidents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121356972A_ABST
    Figure CN121356972A_ABST
Patent Text Reader

Abstract

The invention discloses a message processing method and device, electronic equipment and a storage medium, and relates to the technical field of data processing. The method is applied to a message processing system, and comprises the following steps: acquiring a network security event message through a gateway, determining service attribute information of the network security event message, and determining an acceleration configuration parameter of the network security event message according to the service attribute information; determining a target acceleration node in the acceleration network through the domain name server according to the acceleration configuration parameter, and transmitting the acceleration configuration parameter and the network security event message to a target acceleration network; the acceleration network determines the node server in the target acceleration node according to the acceleration configuration parameter, determines the target acceleration path according to the node server, and transmits the network security event message to the target end according to the target acceleration path, so that rapid forwarding of the network security event message on the transmission path is realized, the transmission delay is reduced, and the transmission efficiency is improved. Therefore, the troubleshooting time is shortened, and rapid processing of network security events is facilitated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, and in particular to a message processing method, apparatus, electronic device, and storage medium. Background Technology

[0002] Cybersecurity incidents refer to events that, due to human error, software or hardware defects or malfunctions, natural disasters, or other factors, harm networks and information systems or the data within them, causing negative impacts on society. In recent years, with the rapid development of technologies such as the internet, big data, and artificial intelligence, these technologies have been widely applied across various industries, permeating people's production and lives and bringing great convenience. However, cybersecurity incidents continue to occur globally, threatening cybersecurity.

[0003] Cybersecurity incident reporting refers to the act of an enterprise or individual promptly reporting a cybersecurity incident to relevant authorities upon discovery. Its main function is to collect cybersecurity incident information, understand the nature, status, and trends of such incidents, and provide data support for relevant parties to formulate preventative measures. Cybersecurity incident reporting is a crucial link in ensuring cybersecurity. However, currently, timely reporting of cybersecurity incidents is often impossible; therefore, ensuring rapid reporting of cybersecurity incidents has become an urgent problem to be solved. Summary of the Invention

[0004] This invention provides a message processing method, apparatus, electronic device, and storage medium to solve the problem that existing technologies cannot quickly report network security incidents.

[0005] According to one aspect of the present invention, a message processing method is provided, wherein the method is applied to a message processing system, the message processing system including at least a gateway, a domain name server, and an acceleration network, the method comprising:

[0006] The network security event message is obtained through the gateway, the service attribute information of the network security event message is determined, and the acceleration configuration parameters of the network security event message are determined based on the service attribute information.

[0007] The domain name server determines the target acceleration node in the acceleration network based on the acceleration configuration parameters, and transmits the acceleration configuration parameters and the network security event message to the acceleration network.

[0008] The acceleration network determines the node server in the target acceleration node according to the acceleration configuration parameters, determines the target acceleration path according to the node server, and transmits the network security event message to the target end according to the target acceleration path.

[0009] According to another aspect of the present invention, a message processing system is provided, characterized in that it includes: a gateway, a domain name server, and an acceleration network;

[0010] The gateway is configured to acquire network security event messages, determine the service attribute information of the network security event messages, and determine the acceleration configuration parameters of the network security event messages based on the service attribute information.

[0011] The domain name server is used to determine the target acceleration node in the acceleration network according to the acceleration configuration parameters, and to transmit the acceleration configuration parameters and the network security event message to the acceleration network.

[0012] The acceleration network is used to determine the node server in the target acceleration node according to the acceleration configuration parameters, determine the target acceleration path according to the node server, and transmit the network security event message to the target end according to the target acceleration path.

[0013] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:

[0014] At least one processor; and

[0015] A memory communicatively connected to the at least one processor; wherein,

[0016] The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform a message processing method according to any embodiment of the present invention.

[0017] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement a message processing method according to any embodiment of the present invention.

[0018] The technical solution of this invention obtains network security event messages through a gateway, determines the service attribute information of the network security event messages, determines the acceleration configuration parameters of the network security event messages based on the service attribute information, determines the target acceleration node in the acceleration network through a domain name server based on the acceleration configuration parameters, transmits the acceleration configuration parameters and network security event messages to the acceleration network, determines the node server in the target acceleration node through the acceleration network based on the acceleration configuration parameters, determines the target acceleration path based on the node server, and transmits the network security event messages to the target end according to the target acceleration path. This achieves rapid forwarding of network security event messages on the transmission path, reduces transmission latency, shortens troubleshooting time, and facilitates rapid processing of network security events.

[0019] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0020] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0021] Figure 1 This is a flowchart of a message processing method provided according to Embodiment 1 of the present invention;

[0022] Figure 2 This is a flowchart of a message processing method provided in Embodiment 2 of the present invention;

[0023] Figure 3 This is a schematic diagram of the architecture of a message processing system according to Embodiment 3 of the present invention;

[0024] Figure 4 This is a flowchart of a message processing method provided according to Embodiment 3 of the present invention;

[0025] Figure 5 This is a schematic diagram of an accelerated network architecture provided according to Embodiment 3 of the present invention;

[0026] Figure 6 This is an example diagram of a node server relationship diagram provided in Embodiment 3 of the present invention;

[0027] Figure 7 This is a schematic diagram of the structure of a message processing system according to Embodiment 4 of the present invention;

[0028] Figure 8 This is a schematic diagram of the structure of an electronic device that implements a message processing method according to an embodiment of the present invention. Detailed Implementation

[0029] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0030] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0031] Example 1

[0032] Figure 1 This is a flowchart of a message processing method according to Embodiment 1 of the present invention. This embodiment is applicable to situations where a target accelerated path is determined for the transmission of network security event messages. The method can be executed by a message processing system, which can be implemented in hardware and / or software. The message processing system can be configured in an electronic device and includes at least a gateway, a domain name server, and an accelerated network. The message processing system method includes, for example... Figure 1 As shown, the method includes:

[0033] S110. Obtain network security event messages through the gateway, determine the service attribute information of the network security event messages, and determine the acceleration configuration parameters of the network security event messages based on the service attribute information.

[0034] A gateway can be understood as a bridge device connecting two or more different networks. Its core function is to realize protocol conversion and data forwarding between different networks. When data needs to be transmitted from one network (such as a home intranet) to another network (such as the Internet), it must be processed by the gateway; otherwise, devices on different networks cannot communicate directly. In one embodiment, the gateway may include a Deep Packet Inspection (DPI) gateway. A network security incident refers to an event that, due to human error, software or hardware defects or failures, natural disasters, etc., harms a network and information system or the data therein, causing a negative impact on society. Network security incident messages can be sent through a message sending terminal. For example, the message sending terminal may include personal user terminals, enterprise-level terminals, IoT terminals, and dedicated system terminals. It should be noted that network security incident messages sent through an application may be sent automatically by the application or sent through the application after human judgment. Business attribute information refers to the attribute information of network security incident messages related to business. For example, business attribute information may include at least application type and business type. Acceleration configuration parameters can be understood as the parameters that need to be configured for network acceleration. For example, acceleration configuration parameters may include the target acceleration domain name and the target acceleration type. Generally, the target acceleration domain name can correspond to the application type, and the target acceleration type can be related to the business type. For example, the target acceleration type can at least include Internet Protocol (IP) security type, service-aware type, GPRS acceleration algorithm type, and business data acceleration type, etc.

[0035] In this embodiment, the gateway can receive the initial message sent by the message sending terminal, parse the initial message, and identify the data header and data content of the initial message. It then determines the identification information, application type, and service type corresponding to the initial message. Generally, agreed-upon identification information is added to the message header to indicate that the current message involves a network security event. When the identification information is determined to be the identification information corresponding to a network security event, the initial message is determined to be a network security event, and the application type and service type of the initial message are used as the service attribute information of the network security event. The accelerated domain name matching the application type is determined as the target accelerated domain name, and the target acceleration type is determined according to the service type. Generally, there can be a correspondence between the service type and the target acceleration type, and the target accelerated domain name and target acceleration type can be used as acceleration configuration parameters for network security event messages.

[0036] S120. Determine the target acceleration node in the acceleration network through the domain name server based on the acceleration configuration parameters, and transmit the acceleration configuration parameters and network security event messages to the acceleration network.

[0037] Domain Name Servers (DNS) are one of the core infrastructures of the Internet, and their core function is to translate human-remembered domain names into computer-recognizable IP addresses. Accelerated networks are a type of dedicated network architecture that optimizes network transmission paths, shortens data transmission distances, and improves protocol efficiency to reduce data transmission latency, decrease packet loss rates, and increase throughput, thereby optimizing user access experience or improving the efficiency of business data transmission. In practical applications, there can be multiple target acceleration nodes, and the target acceleration node corresponding to a network security event message can be determined according to acceleration configuration parameters.

[0038] In this embodiment, the acceleration network can be associated with the target acceleration domain name. The target acceleration domain name can be extracted from the acceleration configuration parameters, and the acceleration network can be matched according to the target acceleration domain name. The successfully matched acceleration node is taken as the target acceleration node, and the acceleration configuration parameters and network security event messages are transmitted to the acceleration network to achieve network acceleration.

[0039] S130. Determine the node server in the target acceleration node according to the acceleration configuration parameters through the acceleration network, determine the target acceleration path according to the node server, and transmit the network security event message to the target end according to the target acceleration path.

[0040] In this context, "node server" refers to candidate node servers, which can be filtered through acceleration configuration parameters. The target acceleration path can be understood as the optimal acceleration path, determined based on the target acceleration type in the acceleration configuration parameters. The destination can be a network security incident processing center, such as the network security incident handling center of a software provider for enterprise server security software, or an emergency command center for public safety incidents. In actual operation, the acceleration network can include a central controller and node servers. The central controller obtains the sender's acceleration permission identifier to verify whether the current packet sender has acceleration permissions. The identity information of senders with acceleration permissions is already backed up in the central controller. The acceleration network includes multiple node servers, each corresponding to an acceleration type, and the acceleration type determines the routing path.

[0041] In this embodiment, the node server can be matched with the target acceleration type in the acceleration configuration parameters, and the successfully matched node server can be selected. Generally, there can be one or more target acceleration types, and a corresponding node server can be determined for each target acceleration type. For different target acceleration types, different node servers are selected when processing packets of the corresponding acceleration type based on the performance of the node servers. For example, when the acceleration type is GPRS encryption algorithm type, a node server that can quickly process encryption and decryption algorithms can be selected; when the acceleration type is service awareness type, since service awareness type packets often contain logic for judging awareness data based on set rules, a node server that can quickly parse the rules can be selected. Therefore, a node server that can be used for acceleration is selected based on the acceleration type corresponding to the acceleration data in the security event packet. To improve the efficiency of determining the corresponding node server, a correspondence table between each node server and the target acceleration type can be set in advance, so that a node server that can be used for the current packet acceleration can be quickly determined based on the acceleration type in the packet and the correspondence table.

[0042] In practical applications, each node server can be considered as a node. Based on the connectivity between the node servers, nodes capable of direct message transmission are connected, forming edges connecting two node servers. The performance value of the next node server on the transmission path between the connected two node servers is used as the weight of the edge, thus constructing a node server relationship graph. Generally, the performance value can be determined based on factors affecting the transmission rate of the next node server and the physical distance between the two node servers. The target acceleration path is then determined according to the node server relationship graph, and the network security event message is transmitted to the target end according to the target acceleration path. Generally, the target acceleration path can be the acceleration path with the shortest physical distance. Alternatively, the distance between each node server can be determined separately, and all acceleration paths connecting to the target end can be determined based on the distance. The acceleration path with the shortest physical distance is then selected as the target acceleration path. In one embodiment, the determined target acceleration path can be re-verified to ensure that the node servers in the target acceleration path include node servers of all target acceleration types corresponding to the security event message.

[0043] In this embodiment of the invention, network security event messages are obtained through a gateway, the service attribute information of the network security event messages is determined, acceleration configuration parameters for the network security event messages are determined based on the service attribute information, the target acceleration node in the acceleration network is determined through a domain name server based on the acceleration configuration parameters, the acceleration configuration parameters and the network security event messages are transmitted to the acceleration network, the node server in the target acceleration node is determined through the acceleration network based on the acceleration configuration parameters, the target acceleration path is determined based on the node server, and the network security event messages are transmitted to the target end according to the target acceleration path. This achieves rapid forwarding of network security event messages on the transmission path, reduces transmission latency, shortens troubleshooting time, and facilitates rapid processing of network security events.

[0044] In one embodiment, before determining the node server in the target acceleration node according to acceleration configuration parameters via the acceleration network, determining the target acceleration path based on the node server, and transmitting the network security event message to the target end according to the target acceleration path, the method further includes:

[0045] Acceleration permission identifiers of the sending terminals corresponding to network security event messages are extracted by accelerating the network.

[0046] If an acceleration permission identifier is confirmed, the node server in the target acceleration node is determined through the acceleration network based on the acceleration configuration parameters.

[0047] The acceleration permission identifier can be used to verify whether the message sending terminal has acceleration permission. Generally speaking, the identity information of the message sending terminal with acceleration permission has been backed up in the acceleration network.

[0048] In this embodiment, the message-sending terminal corresponding to the network security event message can be identified. The acceleration permission identifier of the message-sending terminal is extracted from the central controller of the acceleration network. If the acceleration permission identifier exists, the node server in the target acceleration node can be determined through the acceleration network based on the acceleration configuration parameters. If it does not exist, the determination of the target acceleration path is stopped.

[0049] Example 2

[0050] Figure 2 This is a flowchart of a message processing method according to Embodiment 2 of the present invention. This embodiment is a further optimization and extension based on the above embodiments, and can be combined with various optional technical solutions in the above embodiments. Figure 2 As shown, the method includes:

[0051] S210. Receive the initial message sent by the message sending terminal through the gateway, and parse the identification information, application type and service type of the initial message according to the preset deep message detection rules.

[0052] The message sending terminal can include personal user terminals, enterprise-level terminals, IoT terminals, and dedicated system terminals. The initial message can be understood as the message sent by the message sending terminal. Preset deep packet inspection rules can be understood as pre-set rules for parsing the initial message. For example, the preset deep packet inspection rules can be DPI technology, which can be deployed on the equipment of a telecommunications operator. After a terminal subscribes to the DPI service, the data packets sent by the terminal first pass through the DPI gateway, where the DPI identifies the message identifier. Application type can be understood as a software program based on a specific technical architecture and functional implementation, representing the technical implementation level; business type can be understood as the functional scope of user needs or business goals, representing the functional level.

[0053] In this embodiment, the gateway can receive the initial message sent by the message sending terminal, parse the initial message through preset deep message detection rules, identify the IP data header (including source address and destination address) and IP data content (identify application type and content) of the message, and obtain the identification information, application type and service type of the initial message.

[0054] S220. The gateway determines the network security event message in the initial message according to the identification information, and uses the application type and service type as the service attribute information of the network security event message.

[0055] In this embodiment, identification information corresponding to network security event messages can be pre-set. When the identification information of the initial message is the same as that of the network security event message, the initial message is determined to be a network security event message, and the application type and service type are used as the service attribute information of the network security event message.

[0056] S230. Determine the acceleration domain name that matches the application type through the gateway as the target acceleration domain name, determine the target acceleration type according to the business type, and use the target acceleration domain name and target acceleration type as acceleration configuration parameters for network security event messages.

[0057] In this embodiment, the target acceleration domain name can be determined by matching the application type with the associated acceleration domain name, and the target acceleration type can be determined by the service type. Generally, the correspondence between application types and acceleration domain names can be pre-set. Since a network security event message can contain multiple data items, the number of target acceleration types can be at least one. The target acceleration type can be determined based on the actual service type. Target acceleration types can include IP security types, service-aware types, GPRS acceleration algorithm types, service data acceleration types, etc. The target acceleration domain name and target acceleration type can be used as acceleration configuration parameters for network security event messages.

[0058] S240. Match the acceleration node associated with the target acceleration domain name in the acceleration configuration parameters through the domain name server as the target acceleration node, and transmit the acceleration configuration parameters and network security event messages to the acceleration network.

[0059] In this embodiment, a domain name server can be used to match the corresponding acceleration network according to the target acceleration domain name, the successfully matched acceleration node can be used as the target acceleration node, and the acceleration configuration parameters and network security event messages can be transmitted to the acceleration network.

[0060] S250. Determine the node server in the acceleration network that matches the target acceleration type in the acceleration configuration parameters through the acceleration network.

[0061] In this embodiment, the central controller of the accelerated network can receive acceleration configuration parameters and network security event messages, determine the node servers matching the target acceleration type, and designate the node servers matching the target acceleration type as node servers. For the same target acceleration type, there can be one or more corresponding node servers.

[0062] S260. The node servers are divided into at least one node category region according to the target acceleration type through the acceleration network.

[0063] The node category area refers to the area that distinguishes the types of node servers.

[0064] In this embodiment, node servers corresponding to the same target acceleration type can be grouped into a single node category region.

[0065] S270. By accelerating the network, node servers that meet the message transmission conditions are connected according to the connectivity between node servers in each node category region, and the node server relationship graph is constructed.

[0066] In one embodiment, for node servers in a node category region, nodes whose connectivity connections between node servers satisfy the message transmission conditions can be identified. These node servers are then connected in pairs, with the connecting lines serving as edges between the two servers, and the node servers themselves treated as nodes, thus constructing a node server relationship graph. In another embodiment, the performance value of the next node server in the transmission path for each of the two connected node servers is also determined. This performance value is used as the weight of the corresponding edge, where the performance value is determined based on factors affecting the transmission rate of the next node server and the physical distance between the two node servers.

[0067] S280. Determine the target acceleration path through the acceleration network according to the node server relationship diagram and node category.

[0068] In one embodiment, determining the target acceleration path through the acceleration network according to the node server relationship graph and node category includes:

[0069] The network is accelerated to determine the node server closest to the domain name controller as the initial node, the node closest to the initial node as the first neighbor node, the path between the initial node and the first neighbor node as the first path, and the distance of the first path as the first distance.

[0070] The network accelerates the process of determining the neighboring nodes of the first neighboring node as the second neighboring node, determining the path between the first path and the second neighboring node as the second path, and determining the distance of the first path as the second distance.

[0071] The distance between the initial node and the second neighboring node is determined by accelerating the network and used as the third distance. If the second distance is less than the third distance, the second distance is used as the distance between the second neighboring node and the initial node; otherwise, the third distance is used as the distance between the second neighboring node and the initial node. This process continues until all node servers have been traversed.

[0072] Acceleration type constraints are constructed by accelerating the network according to node categories. Node servers are selected to construct acceleration paths according to the acceleration type constraints, and the acceleration path with the shortest distance is determined as the target acceleration path.

[0073] In this embodiment, the node server closest to the domain name controller can be extracted as the initial node. Then, the node closest to the initial node is determined as the first adjacent node. The path between the initial node and the first adjacent node is stored as the first path, and the distance of the first path is determined as the first distance. Next, the adjacent node of the first adjacent node is determined as the second adjacent node. The path between the first path and the second adjacent node is determined as the second path, and the distance of the first path is determined as the second distance. The distance between the initial node and the second adjacent node is determined as the third distance. If the second distance is less than the third distance, the second distance is used as the distance between the second adjacent node and the initial node; otherwise, the third distance is used. This process continues until all node servers have been traversed, i.e., the minimum distance between all nodes is determined. Then, starting from the previous node of the destination node, at least one acceleration path is determined by tracing backwards. The acceleration path must satisfy the acceleration type constraint to determine the acceleration path with the minimum distance as the target acceleration path. In one embodiment, the acceleration type constraint includes: each node category in the acceleration path includes at least one node server.

[0074] S290. Transmit network security event messages to the target end via the accelerated network according to the target accelerated path.

[0075] In this embodiment of the invention, an initial message sent by a message sending terminal is received through a gateway. The gateway parses the initial message's identification information, application type, and service type according to preset deep packet inspection rules. Based on the identification information, a network security event message is identified within the initial message. The application type and service type are used as the service attribute information of the network security event message. An acceleration domain name matching the application type is determined as the target acceleration domain name. The target acceleration type is determined according to the service type. The target acceleration domain name and target acceleration type are used as acceleration configuration parameters for the network security event message, thus achieving accurate acquisition of the network security event message. An acceleration node associated with the target acceleration domain name in the acceleration configuration parameters is matched using a domain name server. The acceleration node transmits acceleration configuration parameters and network security event messages to the acceleration network. The acceleration network then identifies the node server in the target acceleration node that matches the target acceleration type in the acceleration configuration parameters. Based on the target acceleration type, the node servers are divided into at least one node category region. Nodes that meet the message transmission conditions and are connected according to the connectivity between node servers in each node category region are used as edges connecting two node servers, thus constructing a node server relationship graph. The target acceleration path is determined according to the node server relationship graph and node categories. Network security event messages are transmitted to the target end according to the target acceleration path, achieving automatic determination of the target acceleration path and facilitating the rapid forwarding of network security event messages.

[0076] Example 3

[0077] Figure 3 This is a schematic diagram of the architecture of a message processing system according to Embodiment 3 of the present invention. This embodiment uses a DPI gateway as the gateway, an accelerated domain name as the target accelerated domain name, an acceleration type as the target acceleration type, and the optimal routing path as the target accelerated path as an example to further illustrate a message processing method. Figure 3 As shown, the message processing system includes a message sending terminal, a DPI gateway, a domain name server, a central controller, a target acceleration node, and a destination.

[0078] The DPI gateway is used to intercept messages sent by message sending terminals, identify message traffic, and forward messages with added accelerated domain name information to the domain name server after identifying preset message identification information.

[0079] Domain name servers provide domain name resolution services. Domain name resolution points domain names to IP addresses in the network space, allowing internet users to easily access websites by registering the domain name. The domain name server in this proposal is used to resolve the domain name of the message sending terminal. When an accelerated domain name is resolved, the network security event message sent by the message sending terminal is sent to the accelerated network.

[0080] The acceleration network consists of a central controller and target acceleration nodes. The central controller manages and controls the target acceleration nodes within the network. It receives network security event messages forwarded by the domain name server, parses the destination address in the message, forms an optimal routing path based on the message, and sends the optimal routing path to each node server in the target acceleration network. The node servers then forward the security event messages based on the optimal routing path until they reach their destination.

[0081] The destination can be a terminal device used by the person in charge or the department responsible for handling network security incidents, such as the person in charge's mobile phone or the computer used by the department for security management.

[0082] In one embodiment, Figure 4 This is a flowchart of a message processing method provided according to Embodiment 3 of the present invention. Figure 4 As shown, the method includes:

[0083] Step 1: Users subscribe to the DPI service on the terminal used to monitor network security incidents.

[0084] The DPI service can be deployed on gateways, and a gateway with the DPI service deployed can be called a DPI gateway. Operators deploy DPI services for deep packet inspection on gateways. After a user subscribes to this service through the operator, the service can identify packets sent by the subscribing end via the DPI gateway using DPI technology. In this proposal, DPI services are subscribed to for network terminals involved in network security incidents, such as employee computers in government and enterprise office scenarios and business servers used to provide external business services.

[0085] Step 2: Based on the DPI service subscribed by the terminal, the DPI gateway intercepts and parses the messages sent by the terminal to obtain the message identification information. If the message identification information is a network security event message identifier, the current message is marked as a network security event message, and the acceleration domain name information, acceleration permission identifier, and acceleration type corresponding to the acceleration data are added to the message.

[0086] In practical applications, DPI gateways are used for DPI technology, a deep packet inspection technology for network traffic data. DPI technology can be deployed on the equipment of telecommunications operators. After a terminal subscribes to the DPI service, the data packets sent by the terminal first pass through the DPI gateway, where the DPI identifies the packet identifier. DPI can parse the packet header (L2-L4 layers) and the payload of the application layer (L7 layer) to identify the IP header (including source and destination addresses) and IP data content (identifying the application type and content). In this proposal, the DPI service obtains traffic data, parses and reconstructs the traffic to identify the IP address, the application type of the data packet, and the corresponding service type of the data packet.

[0087] In one embodiment, network security incident messages can be sent by specific types of applications or manually by users. Regarding applications sending specific types of messages: Before performing this step, we can set the application types requiring special attention in the subscribed DPI service, such as security software installed on enterprise servers (e.g., Alibaba Cloud DDoS protection, AVG Internet Security). Messages sent by this application type may become network security incident messages and need to be sent through the accelerated network. Simultaneously, to distinguish messages sent by the application types requiring special attention, if the message is a network security incident message, agreed-upon identification information is added to the message header to indicate that the current message involves a network security incident. This mechanism can be configured on the application side; for example, when the security software detects an alarm of the highest alarm level, it sends the alarm message to the emergency management terminal, adding the identification information to the message header.

[0088] It should be noted that network security incident messages sent through applications can be sent automatically by the application or sent after human judgment (in the latter case, security software may detect an alert, send a notification to the user, and the user may determine it to be a network security incident). For messages sent manually by the user: network security incidents may not be detected and reported autonomously by security software, but rather discovered and reported manually. In this case, the user can send messages related to the network security incident via email or a communication method agreed upon with the destination.

[0089] An acceleration permission identifier is a identifier provided by the acceleration network provider to the purchaser after the user has purchased acceleration permissions. The acceleration type is determined based on the acceleration data in the message and can include IP security type, service-aware type, GPRS acceleration algorithm type, and business data acceleration type, etc. Data for different acceleration types is transmitted based on different node servers. An acceleration domain name, or alias domain name, is an alias record configured for a website address in the Content Delivery Network (CDN) service domain. This alias record is set by the CDN service provider to optimize access performance. CDNs build an acceleration network (also known as an intelligent virtual network) on top of the existing internet infrastructure by placing node servers throughout the network. This avoids potential speed bottlenecks and unstable network nodes on the internet and determines the optimal route.

[0090] Step 3: The domain name server receives the network security event message sent by the DPI gateway, identifies the accelerated domain name information in the message, and forwards the network security event message with the current accelerated domain name information to the accelerated network.

[0091] Specifically, when the DPI gateway identifies the current packet as a network security event packet, it adds accelerated domain name information to the packet, so that the domain name server (DNS server) can resolve the accelerated domain name, and then jump to the CDN node server through the central controller through the accelerated domain name to achieve network acceleration.

[0092] Step 4: The central controller of the accelerated network receives network security event messages sent by the domain name server, and obtains the acceleration permission identifier and the acceleration type of the network security event message from the network security event message.

[0093] In one embodiment, Figure 5 This is a schematic diagram of an accelerated network architecture provided according to Embodiment 3 of the present invention. Figure 5 As shown, in addition to the node servers used for acceleration, the accelerated network also includes a central controller. This central controller receives network security event messages sent by the domain name server, determines the optimal routing path based on the acceleration type, and sends the network security event messages to the node servers via the optimal routing path. The target acceleration nodes can be a large number of forwarding nodes deployed in various environments. For example, a large number of forwarding nodes can be flexibly deployed on edge clouds, point-of-presence (POP) devices, cloud regions, optical line terminals (OLTs), and mobile edge computing (MEC) devices worldwide.

[0094] The central controller manages all node servers, sending routing table entries (corresponding to the optimal routing path) to each node server and controlling the forwarding of packets from terminals. Each routing table entry contains the packet forwarding path. The node servers communicate with each other via dedicated lines or existing communication lines. For example: Figure 5 As shown by the red line, node server 1 (taking node server 1 as an example) receives the terminal message. Based on the target path corresponding to the routing table entry, node server 1 sends the message to the next hop node server (taking node server 2 as an example). Node server 2, based on the target path corresponding to the routing table entry, sends the message to the next hop node server, until the message is forwarded to the destination.

[0095] The central controller obtains the sender's acceleration permission identifier to verify whether the current packet sender has acceleration permissions. The identity information of senders with acceleration permissions has already been backed up in the central controller. The acceleration network consists of multiple node servers, each corresponding to a specific acceleration type, which determines the routing path. Therefore, obtaining the acceleration type of the network security event packet in this step is to determine the optimal routing path.

[0096] Step 5: When the message sending terminal's acceleration permission identifier is successfully authenticated, the central controller determines the optimal acceleration path based on the acceleration type of the network security event message and the path selection algorithm.

[0097] In one embodiment, step 5 includes steps 5.1-5.3.

[0098] Step 5.1: Obtain at least one acceleration type corresponding to the acceleration data in the network security event message.

[0099] Step 5.2: Select node servers from the acceleration network that conform to the acceleration type determined in 5.1. Based on the acceleration type that the node servers conform to, partition the selected node servers: node servers that conform to the same acceleration type belong to the same partition, and node servers that conform to different acceleration types belong to different partitions.

[0100] Specifically, for different acceleration types, different node servers are selected based on their performance when processing packets of the corresponding acceleration type. For example, when the acceleration type is GPRS encryption algorithm type, a node server capable of quickly processing encryption and decryption algorithms can be selected; when the acceleration type is service-aware type, since service-aware type packets often contain logic for judging the sensed data based on set rules, a node server capable of quickly parsing the rules can be selected. Therefore, node servers suitable for acceleration are selected based on the acceleration type corresponding to the acceleration data in the security event packet.

[0101] To improve the efficiency of the central controller in determining the corresponding node server, this proposal pre-sets a mapping table between each node server and the acceleration type, enabling the central controller to quickly determine the node server that can be used for the acceleration of the current message based on the acceleration type in the message and the mapping table.

[0102] In one embodiment, Figure 6 This is an example diagram of a node server relationship diagram provided in Embodiment 3 of the present invention, such as... Figure 6 As shown, the current network security incident packets are accelerated through IP security, service awareness, and business data acceleration types. Node servers 1 and 7 meet the IP security type requirement, while nodes 2, 8, and 6 meet the service awareness type requirement. Node servers 3 and 5 meet the business data acceleration type requirement.

[0103] Correspondingly, the node servers are partitioned: node servers 1 and 7 belong to one partition, node servers 2, 8 and 6 belong to the same partition, and node servers 3 and 5 belong to the same partition.

[0104] Step 5.3: Using each node server as a node, based on the connectivity between the node servers, connect nodes that can directly transmit messages, forming edges connecting two node servers; construct a node server relationship graph based on the performance value of the next node server on the transmission path between the connected two node servers. For example... Figure 6 As shown in the diagram, 0 represents the initial node and 4 represents the destination node. The performance value is determined based on various factors affecting the transmission rate of the subsequent node server and the physical distance between the two node servers. Factors affecting the transmission rate include bandwidth, network latency, and hardware configuration. A weighted sum is calculated for different factors affecting the transmission rate and the physical distance between the two node servers to obtain the node server's performance value. This performance value is then used as the weight of an edge and added to the node server relationship graph.

[0105] In one embodiment, step 5.3, based on the aforementioned node server relationship diagram, determines the optimal acceleration path from node server 0 to node server 4, including:

[0106] Use a table to record the initial values ​​of the distances from node server 0 to all nodes, such as setting the initial values ​​to infinity; in addition, to determine the optimal path, record the previous node of the current node, as shown in Table 1:

[0107] Table 1 Node distance values ​​(1)

[0108]

[0109] In one embodiment, step 5.3 includes steps 5.3.1-5.3.4.

[0110] Step 5.3.1: Start marking the nodes from the initial node.

[0111] Step 5.3.2: Each time, select the node closest to the initial node from the unmarked nodes and mark it, and store the path from the initial node to the nearest node; for the neighboring nodes of the newly marked node, calculate the distance value from the stored path to the neighboring node. If the distance value is less than the distance from the starting point of the neighboring node recorded in the table, then update the distance from the initial node to the neighboring node in Table 1 to the newly calculated distance value, as well as the preceding node of the neighboring node;

[0112] Step 5.3.3: Repeat the above marking process until all nodes are marked. From the final table, trace back from the node before the destination node to determine at least one path.

[0113] by Figure 6For example, determining the optimal path is as follows: start marking from the initial node 0, with the distance from node 0 to the initial node 0 being 0. Change the initial distance value corresponding to node 0 from infinity to 0, as shown in Table 2 below:

[0114] Table 2 Node Distance Values ​​(2)

[0115]

[0116] Next, select the neighboring nodes of the newly marked node (node ​​0) Figure 6 Let's consider nodes 1, 2, and 7. Calculate the distances from the stored path (currently only node 0) to the neighboring node (corresponding to 8, 11, and 4 respectively). Compare the calculated distances with the distances from the neighboring node to the initial node recorded in the table. Since the distances recorded in the table are all infinity, update the distances from the initial node to the neighboring node (corresponding to 8, 11, and 4 respectively) in the table with the newly calculated distances, as well as the preceding node of the neighboring node, as shown in Table 3 below.

[0117] Table 3 Node Distance Values ​​(3)

[0118]

[0119] Repeat the above marking process: Select the node closest to the initial node from the unmarked nodes (1~8) and mark it. As shown in Table 3 above, among the unmarked nodes, the node closest to the initial node is node 7. Mark node 7 and store the path from the initial node 0 to node 7: 0→7.

[0120] Next, select the neighboring nodes of the newly marked node (node ​​7) Figure 6 In the table (nodes 2, 8, and 6), calculate the distances from the stored path (0→7) to the neighboring nodes (corresponding to 11, 11, and 5 respectively). Compare the calculated distances with the distances from the neighboring node to the initial node recorded in the table. If the calculated distance is less than the distance recorded in the table, update the distance in the table to the calculated distance (the distance value of node 2 stored in the table is 11, which is equal to the newly calculated distance value and does not need to be updated; the distance value of node 8 is infinite, so it is updated to the newly calculated distance value of 11; the distance value of node 6 is infinite, so it is updated to the newly calculated distance value of 5). At the same time, update the preceding nodes of the neighboring nodes, as shown in Table 4 below:

[0121] Table 4 Node Distance Values ​​(4)

[0122]

[0123] Repeat the above marking process: Select the node closest to the initial node from the unmarked nodes (1~6, 8) and mark it. As shown in Table 4 above, among the unmarked nodes, the node closest to the initial node is node 6. Mark node 6 and store the path from the initial node 0 to node 6: 0→7→6.

[0124] Next, select the neighboring nodes (nodes 5 and 8) of the newly marked node 6, calculate the distance values ​​(7 and 8) from the stored path to the neighboring nodes, compare and update the table, and obtain the following Table 5:

[0125] Table 5 Node Distance Values ​​(5)

[0126]

[0127] Repeat the marking process above until all nodes have been marked, resulting in the updated table shown in Table 6 below:

[0128] Table 6 Node Distance Values ​​(6)

[0129]

[0130] Based on Table 6, tracing back sequentially from the point preceding the destination node 4: the point preceding node 4 is node 5, the point preceding node 5 is node 6, the point preceding node 6 is node 7, and the point preceding node 7 is node 0 (the initial node), thus determining the optimal path as 0→7→6→5→4.

[0131] Step 5.3.4: Set acceleration type constraints for nodes in the optimal path, so that the determined path contains at least one node server for each partition, in order to determine the final optimal path.

[0132] It should be noted that the node controller needs to re-verify the determined optimal path to ensure that the node servers along the path include all node servers of the acceleration type corresponding to the security event message, such as the corresponding... Figure 6 In the diagram, node 0 directly connects to node 2. If the final optimal path is 0→2→3→4, and this path does not contain any node servers that satisfy the IP security type acceleration category, then this path will not be selected. In practice, to improve the efficiency of determining the optimal path, when constructing the node server relationship graph, the node servers are first categorized according to their acceleration type, establishing inter-class (e.g., connections between nodes 1 and 2, connections between nodes 2 and 3) or intra-class (e.g., connections between nodes 2 and 8) connections between node servers.

[0133] Step 6: Based on the acceleration path determined in Step 5, the node server accelerates the transmission of the packet to the destination.

[0134] The destination can be the processing end of a cybersecurity incident, such as the cybersecurity incident handling center of a software provider that provides security software for enterprise servers; or an emergency command center that involves public safety incidents.

[0135] The destination provides an identifier for emergency messages transmitted via the accelerated network and issues a prominent alert.

[0136] The core concept of the network acceleration-based network security event message processing method proposed in this application is as follows: A DPI gateway intercepts messages sent by the message-sending terminal, parses the messages to identify them as network security event messages, adds acceleration domain name information and acceleration type to the network security event messages, and then forwards the messages to a domain name server. The domain name server, based on the acceleration domain name information in the network security event messages, forwards the network security event messages to an acceleration network. The central controller in the acceleration network determines the optimal acceleration path based on the message's acceleration type, and the node servers in the acceleration network, based on this optimal acceleration path, accelerate the transmission of the network security event messages to the destination. This achieves rapid forwarding of network security event messages along the transmission path, reduces transmission latency, shortens troubleshooting time, and facilitates rapid processing of network security events.

[0137] Example 4

[0138] Figure 7 This is a schematic diagram of the structure of a message processing system according to Embodiment 4 of the present invention. Figure 7 As shown, the system includes: gateway 71, domain name server 72, and acceleration network 73.

[0139] Among them, gateway 71 is used to obtain network security event messages, determine the service attribute information of network security event messages, and determine the acceleration configuration parameters of network security event messages based on the service attribute information.

[0140] Domain Name Server 72 is used to determine the target acceleration node in the acceleration network based on the acceleration configuration parameters, and to transmit the acceleration configuration parameters and network security event messages to the acceleration network.

[0141] Accelerated Network 73 is used to determine the node server in the target accelerated node according to the acceleration configuration parameters, determine the target acceleration path according to the node server, and transmit network security event messages to the target end according to the target acceleration path.

[0142] The technical solution of this invention obtains network security event messages through a gateway, determines the service attribute information of the network security event messages, determines the acceleration configuration parameters of the network security event messages based on the service attribute information, determines the target acceleration node in the acceleration network through a domain name server based on the acceleration configuration parameters, transmits the acceleration configuration parameters and network security event messages to the acceleration network, determines the node server in the target acceleration node through the acceleration network based on the acceleration configuration parameters, determines the target acceleration path based on the node server, and transmits the network security event messages to the target end according to the target acceleration path. This achieves rapid forwarding of network security event messages on the transmission path, reduces transmission latency, shortens troubleshooting time, and facilitates rapid processing of network security events.

[0143] In one embodiment, gateway 71 is used for:

[0144] The system receives the initial message sent by the message sending terminal and parses the initial message's identification information, application type, and service type according to the preset deep message detection rules.

[0145] The network security event message in the initial message is determined according to the identification information, and the application type and business type are used as the business attribute information of the network security event message.

[0146] Determine the acceleration domain name that matches the application type as the target acceleration domain name, determine the target acceleration type according to the business type, and use the target acceleration domain name and target acceleration type as acceleration configuration parameters for network security event messages.

[0147] In one embodiment, the domain name server 72 is used for:

[0148] Match the acceleration node associated with the target acceleration domain name in the acceleration configuration parameters as the target acceleration node, and transmit the acceleration configuration parameters and network security event messages to the acceleration network.

[0149] In one embodiment, the acceleration network 731 is used for:

[0150] In the acceleration network, identify the node server that matches the target acceleration type in the acceleration configuration parameters as the node server;

[0151] The node servers are divided into at least one node category region according to the target acceleration type;

[0152] Based on the connectivity between node servers in each node category region, node servers that meet the message transmission conditions are connected as edges connecting two node servers, and a node server relationship graph is constructed.

[0153] Determine the target acceleration path based on the node server relationship diagram and node categories.

[0154] In one embodiment, the acceleration network 73 is further configured to:

[0155] The node server closest to the domain name controller is determined as the initial node, the node closest to the initial node is determined as the first neighbor node, the path between the initial node and the first neighbor node is stored as the first path, and the distance of the first path is determined as the first distance.

[0156] The neighboring node of the first neighboring node is determined as the second neighboring node, the path between the first path and the second neighboring node is determined as the second path, and the distance of the first path is determined as the second distance.

[0157] The distance between the initial node and the second neighboring node is determined as the third distance. If the second distance is less than the third distance, the second distance is used as the distance between the second neighboring node and the initial node. Otherwise, the third distance is used as the distance between the second neighboring node and the initial node. This process continues until all node servers have been traversed.

[0158] Acceleration type constraints are constructed according to node categories. Node servers are selected and acceleration paths are constructed according to acceleration type constraints. The acceleration path with the shortest distance is determined as the target acceleration path.

[0159] In one embodiment, the acceleration type constraint includes: each node class in the acceleration path includes at least one node server.

[0160] In one embodiment, the accelerated network is further configured to:

[0161] Extract the acceleration permission identifier of the message sending terminal corresponding to the network security event message;

[0162] If an acceleration permission identifier is confirmed, the node server is determined based on the acceleration configuration parameters.

[0163] The message processing system provided in the embodiments of the present invention can execute the message processing method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method execution.

[0164] Example 5

[0165] Figure 8This is a schematic diagram of the structure of an electronic device implementing a message processing method according to an embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0166] like Figure 8 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0167] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0168] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as a message processing method.

[0169] In some embodiments, a message processing method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the message processing method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform a message processing method by any other suitable means (e.g., by means of firmware).

[0170] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0171] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0172] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0173] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0174] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0175] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0176] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0177] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A method of processing a packet, the method comprising: The application is applied to a message processing system, and the message processing system at least comprises a gateway, a domain name server and an acceleration network, and the method comprises the following steps: obtaining a network security event message through the gateway, determining service attribute information of the network security event message, and determining acceleration configuration parameters of the network security event message according to the service attribute information; determining a target acceleration node in the acceleration network through the domain name server according to the acceleration configuration parameters, transmitting the acceleration configuration parameters and the network security event message to the acceleration network; determining a node server in the target acceleration node through the acceleration network according to the acceleration configuration parameters, determining a target acceleration path according to the node server, and transmitting the network security event message to a target end according to the target acceleration path.

2. The method of claim 1, wherein, The method comprises the following steps: receiving an initial message sent by a message sending terminal through the gateway, analyzing identification information, an application type and a service type of the initial message according to a preset deep message detection rule; determining a network security event message in the initial message according to the identification information through the gateway, taking the application type and the service type as service attribute information of the network security event message; determining an acceleration domain name matched with the application type as a target acceleration domain name through the gateway, determining a target acceleration type according to the service type, and taking the target acceleration domain name and the target acceleration type as acceleration configuration parameters of the network security event message.

3. The method of claim 1, wherein, The method comprises the following steps: matching an acceleration node associated with the target acceleration domain name in the acceleration configuration parameters as a target acceleration node through the domain name server, and transmitting the acceleration configuration parameters and the network security event message to the acceleration network.

4. The method of claim 1, wherein, The method comprises the following steps: determining a node server matched with the target acceleration type in the acceleration configuration parameters as a target acceleration node in the acceleration network; dividing the node server into at least one node category area according to the target acceleration type through the acceleration network; connecting node servers satisfying a message transmission condition as edges connecting two node servers according to the connectivity of communication between the node servers in each node category area through the acceleration network, and constructing a node server relationship graph; determining a target acceleration path according to the node server relationship graph and the node category through the acceleration network.

5. The method of claim 4, wherein, The method comprises the following steps: determining, through the acceleration network, a node server closest to a domain name controller as an initial node, determining a node closest to the initial node as a first adjacent node, storing a path between the initial node and the first adjacent node as a first path, and determining a distance of the first path as a first distance; determining, through the acceleration network, an adjacent node of the first adjacent node as a second adjacent node, determining a path between the first path and the second adjacent node as a second path, and determining a distance of the first path as a second distance; determining, through the acceleration network, a distance between the initial node and the second adjacent node as a third distance, and when it is determined that the second distance is less than the third distance, taking the second distance as a distance value between the second adjacent node and the initial node, otherwise taking the third distance as the distance value between the second adjacent node and the initial node, until all node servers are traversed; constructing an acceleration type constraint according to the node categories through the acceleration network, selecting node servers according to the acceleration type constraint to construct an acceleration path, and determining a minimum distance acceleration path as a target acceleration path.

6. The method of claim 5, wherein, The acceleration type constraint includes: at least one node server of each node category in the acceleration path.

7. The method of claim 1, wherein, Before the method of determining a node server in a target acceleration node according to the acceleration configuration parameter through the acceleration network, determining a target acceleration path according to the node server, and transmitting the network security event message to a target end according to the target acceleration path, the method further includes: extracting, through the acceleration network, an acceleration permission identifier of a message sending terminal corresponding to the network security event message; when it is determined that the acceleration permission identifier exists, determining a node server in a target acceleration node through the acceleration network according to the acceleration configuration parameter.

8. A packet processing system, characterized by The method includes: a gateway, a domain name server, and an acceleration network; The gateway is configured to obtain a network security event message, determine service attribute information of the network security event message, and determine an acceleration configuration parameter of the network security event message according to the service attribute information. The domain name server is configured to determine a target acceleration node in the acceleration network according to the acceleration configuration parameter, and transmit the acceleration configuration parameter and the network security event message to the acceleration network. The acceleration network is configured to determine a node server in a target acceleration node according to the acceleration configuration parameter, determine a target acceleration path according to the node server, and transmit the network security event message to a target end according to the target acceleration path.

9. An electronic device, comprising: The electronic device includes: at least one processor; and a memory connected to the at least one processor in communication; wherein The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the message processing method of any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions for causing the processor to implement the packet processing method in any one of claims 1-7 when executed.