Source returning method and device

By switching from the latest resolved address set to the historical address set during the origin retrieval operation and selecting the optimal address for retry based on health parameters, the problem of origin retrieval failure caused by DNS resolution anomalies in existing technologies is solved, thereby improving the robustness and success rate of origin retrieval.

CN121442008APending Publication Date: 2026-01-30SHANGHAI HODE INFORMATION TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202511622403.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-06
Publication Date
2026-01-30

AI Technical Summary

Technical Problem

Existing origin pull technologies rely on a single DNS resolution result, which is susceptible to hijacking, pollution, or misconfiguration, resulting in low robustness and success rate of origin pull.

Method used

In the origin pull operation, the system switches from the latest parsed address set to the address set of historical origin pull requests, selects the optimal address for retrying based on health parameters, and combines blacklist filtering of abnormal addresses and port pre-detection to improve fault tolerance.

Benefits of technology

It effectively avoids system failures caused by abnormal DNS resolution results in a single instance, and improves the robustness and success rate of origin retrieval.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121442008A_ABST
    Figure CN121442008A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a source returning method and related equipment / products, and belongs to the field of communication. The back-to-source method comprises the steps of selecting a first address from a first address set in a process of initiating a back-to-source operation, and sending a first back-to-source request based on the first address; wherein the first address set is an address set which is newly analyzed according to the back-to-source domain name; switching from the first address set to a second address set under the condition of source returning failure based on the first source returning request; wherein the second address set is composed of a plurality of addresses which are used for historical back-to-source requests in the first address set; and selecting a second address from the second address set, and sending a second back-to-source request based on the second address. According to the technical scheme provided by the embodiment of the invention, system faults caused by abnormity (such as hijacking, pollution or configuration errors) of a single domain name resolution result can be effectively avoided, and the source returning robustness and success rate are improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the technical field of communication, and in particular, to a method and apparatus for source return, a computer device, a computer readable storage medium, and a computer program product. BACKGROUND

[0002] With the continuous growth of Internet traffic, content distribution networks have become a key infrastructure for improving network content transmission efficiency and optimizing end-user access experience. By caching content to edge nodes closer to users, content distribution networks effectively reduce source station load and network latency. When edge nodes do not cache the requested content or cache the expired content, they will initiate a source return request to the source station to obtain data.

[0003] Current source return technology mainly relies on the result of a single DNS resolution to select a source return address. However, the DNS resolution process may encounter hijacking, pollution, or configuration errors, resulting in systematic failures in the returned address set, which seriously affects the robustness and success rate of source return.

[0004] It should be noted that the above content is not necessarily prior art, nor is it used to limit the patent protection scope of the present application. SUMMARY

[0005] Embodiments of the present application provide a method and apparatus for source return, a computer device, a computer readable storage medium, and a computer program product to solve or alleviate one or more technical problems proposed above.

[0006] One aspect of embodiments of the present application provides a method for source return, the method comprising: In the process of initiating a source return operation, a first address is selected from a first address set, and a first source return request is sent based on the first address; wherein the first address set is an address set newly resolved according to the source domain name; In the case of source return failure based on the first source return request, switching from the first address set to a second address set; wherein the second address set is composed of a plurality of addresses in the first address set that have been used for historical source return requests; and A second address is selected from the second address set, and a second source return request is sent based on the second address.

[0007] Optionally, selecting a second address from the second address set comprises: determining a health degree parameter according to each address in the second address set; wherein the health degree parameter is a comprehensive numerical indicator quantifying the historical service quality of each address in the second address set; selecting the second address from the second address set according to the health degree parameter of each address in the second address set.

[0008] Optionally, the method further comprises: selecting the M+1th address from the second address set in case of failure of the Mth source return based on the source return, until the source return succeeds; wherein N>M≥2, and N is a preset number of times.

[0009] Optionally, the method further comprises: obtaining the source return domain name and a preset blacklist; wherein the blacklist is used to indicate abnormal addresses; resolving the source return domain name at a regular time to obtain a plurality of resolution addresses; filtering the abnormal addresses in the plurality of resolution addresses through the blacklist to obtain initial addresses; performing port preposition detection on the initial addresses to remove addresses that cannot establish a connection to obtain the first address set.

[0010] Optionally, the method further comprises: obtaining a historical success rate and a first byte time consumption of a first source return request based on a first address; updating the health degree parameter of the first address in the second address set according to the historical success rate and the first byte time consumption corresponding to the first address; and / or obtaining a historical success rate and a first byte time consumption of a second source return request based on a second address; updating the health degree parameter of the second address in the second address set according to the historical success rate and the first byte time consumption corresponding to the second address; wherein the first byte time consumption is a time interval from sending a corresponding source return request by the edge node to receiving the first byte in a corresponding response.

[0011] Optionally, the method further comprises: in case that the health degree parameter of the first address or the second address is lower than a preset value, triggering an alarm and submitting to an audit node; according to an audit result returned by the audit node, adding the first address or the second address into a blacklist.

[0012] Another aspect of the embodiments of the present application provides a source return device, the device comprising: a first sending module configured to select a first address from a first address set in the process of initiating a source return operation, and send a first source return request based on the first address; wherein the first address set is an address set newly resolved according to the source return domain name; The switching module is configured to switch from the first address set to a second address set in a case that a first back-to-source request fails; the second address set is composed of a plurality of addresses in the first address set that have been used in historical back-to-source requests; and The second sending module is configured to select a second address from the second address set and send a second back-to-source request based on the second address.

[0013] Another aspect of the embodiments of the present application provides a computer device, comprising: at least one processor; and a memory connected to the at least one processor in communication; The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method described above.

[0014] Another aspect of the embodiments of the present application provides a computer readable storage medium, which stores computer instructions, and the computer instructions are executed by a processor to implement the method described above.

[0015] Another aspect of the embodiments of the present application provides a computer program product, which comprises a computer program, and the computer program is executed by a processor to implement the method described above.

[0016] Another aspect of the embodiments of the present application provides a back-to-source system, which comprises: The decision maker is configured to: select a first address from a first address set in a process of initiating a back-to-source operation, wherein the first address set is a set of addresses newly resolved according to the back-to-source domain name; switch from the first address set to a second address set in a case that a first back-to-source request fails; wherein the second address set is composed of a plurality of addresses in the first address set that have been used in historical back-to-source requests; and select a second address from the second address set and send a second back-to-source request based on the second address; The back-to-source executor is configured to: generate a first back-to-source request according to the first address if the first address is received from the decision maker; and generate a second back-to-source request according to the second address if the second address is received from the decision maker.

[0017] Optionally, the system further comprises a health state cache, which is configured to: store a correspondence between the back-to-source domain name and the second address set and / or a health degree parameter of each address in the second address set; wherein the health degree parameter is a comprehensive numerical index quantifying a historical service quality of each address in the second address set.

[0018] Optionally, the system further comprises a blacklist, the blacklist comprising a plurality of abnormal addresses; the blacklist being configured to filter the abnormal addresses from the plurality of resolution addresses corresponding to the origin domain name.

[0019] Optionally, the system further comprises an asynchronous monitor, the asynchronous monitor being configured to update the health degree parameter of each address in the second address set, submit the abnormal address to an audit node, and / or manage the blacklist.

[0020] The technical scheme in the embodiments of the present application can have the following advantages: when the edge node initiates the origin operation, a first address is selected from the first address set newly resolved according to the origin domain name as a first address, and a first origin request is initiated based on the first address. If the first origin request fails, the first address set is switched to a second address set, wherein the second address set is composed of a plurality of addresses in the first address set that have been used for historical origin requests. Then, a second address is selected from the second address set, and a second origin request is initiated based on the second address. When the origin based on the newly resolved address (the first address) fails, the origin based on the historical origin address (the second address) is used in the embodiments of the present application, so that the system failure caused by the abnormality (such as hijacking, pollution or configuration error) of the single domain name resolution result is effectively avoided, and the robustness and success rate of the origin are improved. BRIEF DESCRIPTION OF DRAWINGS

[0021] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this specification, illustrate embodiments of the application and together with the description serve to explain exemplary implementations of the application. The illustrated embodiments are exemplary only and not limiting of the scope of the claims. In all the drawings, like reference numerals refer to like parts throughout the various figures.

[0022] Figure 1 An operation environment diagram of the origin method according to Embodiment One of the present application is schematically shown; Figure 2 A flowchart of the origin method according to Embodiment One of the present application is schematically shown; Figure 3 A sub-step flowchart of step S200 is schematically shown; Figure 4 A flowchart of the origin method according to Embodiment One of the present application is schematically shown; Figure 5 A flowchart of the origin method according to Embodiment One of the present application is schematically shown; Figure 6 A flowchart of the origin method according to Embodiment One of the present application is schematically shown; Figure 7 An exemplary application flowchart of the origin method according to Embodiment One of the present application is schematically shown; Figure 8 Fig. 1 shows a flowchart of a memory address pool obtaining process according to an embodiment of the present application; Figure 9 Fig. 2 shows a block diagram of a back-to-source device according to an embodiment of the present application; and Figure 10 Fig. 3 shows a hardware architecture diagram of a computer device according to an embodiment of the present application. DETAILED DESCRIPTION

[0023] In order to make the purposes, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and not used to limit the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts fall within the scope of protection of the present application.

[0024] It should be noted that the description of "first", "second", etc. in the embodiments of the present application is only for the purpose of description and cannot be understood as indicating or implying the relative importance of the indicated technical features or implicitly indicating the number of the indicated technical features. Therefore, the features with "first" and "second" can explicitly or implicitly include at least one of the features. In addition, the technical solutions of the various embodiments can be combined with each other, but it must be based on the fact that the technical solutions can be realized by those of ordinary skill in the art. When the combination of technical solutions contradicts each other or cannot be realized, it should be considered that the combination of technical solutions does not exist and is not within the scope of protection claimed by the present application.

[0025] It should be noted that if the present application involves the collection, storage, use, transmission and processing of data, etc., each link of the data strictly follows the laws, regulations, industry standards and regulatory requirements of the data source, use location and relevant countries and regions to ensure the legality and compliance of data activities. In the collection link, the data subject is explicitly informed of the collection purpose, method and scope in a conspicuous manner, and the collection is carried out after obtaining the legal authorization of the data subject, ensuring that the collection process follows the "minimum necessary" principle and does not collect data beyond the scope. In the storage link, the storage period is limited, and the data is deleted or anonymized and encrypted in a timely manner after achieving the storage purpose. In the use link, a strict data security protection mechanism will be implemented, and the original data will be processed according to the preset desensitization rules through field-level desensitization technology. For different types of data, various desensitization strategies such as data generalization, data anonymization and data encryption are adopted to effectively avoid the risk of sensitive information leakage and ensure that the final used data are desensitized data after security processing, thereby comprehensively protecting the rights and interests of the data subject and data security. In the transmission and processing link, the confidentiality and security of the data in the transmission and processing process are ensured.

[0026] In the description of the present application, it should be understood that the numerical reference before the step does not identify the order of execution of the steps before and after, but is only used to facilitate the description of the present application and to distinguish each step, and therefore cannot be understood as a limitation of the present application.

[0027] First, the terms related to the present application are explained: DNS (Domain Name System): A distributed database that converts user-readable domain names (such as www.example.com) into machine-identifiable IP addresses (such as 192.0.2.1), allowing users to access network resources without having to remember complex numerical addresses.

[0028] IP (Internet Protocol): The core protocol designed for computers to connect to each other for communication. It specifies the rules and formats for data packets to be transmitted in the network. IP addresses are unique logical addresses assigned by the IP protocol to each device (such as servers, computers) on the network, used for locating and addressing CDNs in the network environment.

[0029] CDN (Content Delivery Network): By deploying node servers at the edge of the network, it caches static and dynamic content of websites or services closer to users. When users request content, the request is directed to the edge node closest to the user or with the best service capability.

[0030] Secondly, in order to facilitate the understanding of the technical solution provided by the person skilled in the art, the related technology is explained as follows: CDN back source usually relies on DNS resolution to obtain the source station, and its main implementation methods are as follows: (1) Resolve domain name at regular intervals and cache IP for back source use. (2) Real-time DNS query when back source. However, the over-reliance on single resolution result of these two methods makes them lack effective fault tolerance mechanism when facing DNS hijacking, pollution or configuration error, thus there is a risk of causing systematic back source failure. Therefore, the present application provides a back source technical solution. In this technical solution, the above problems are overcome. See below for details.

[0031] Finally, in order to facilitate understanding, an example of a running environment is provided as follows.

[0032] As shown in Figure 1 The running environment diagram includes: a service platform 2, one or more client devices 4, and a network 6.

[0033] The service platform 2 and the one or more client devices 4 can be connected through the network 6 to realize information transmission and interaction.

[0034] The following describes the service platform 2, the client 4, the network 6, and the origin server 8 in detail.

[0035] The service platform 2 can be a content delivery network service platform. It is composed of edge nodes distributed in different geographical locations, which are used to receive resource requests from the client 4 and provide acceleration and caching services. The edge nodes can be physical servers, virtual machines, or virtualized computing instances such as containers. The service platform 2 can be composed of one or more computing devices. The one or more computing devices can include virtualized computing instances. The virtualized computing instances can include virtual machines, such as emulations of computer systems, operating systems, servers, and the like. The computing devices can load the virtual machines based on virtual images and / or other data defining specific software (e.g., operating systems, specialized applications, servers) for the emulation. Different virtual machines can be loaded and / or terminated on the one or more computing devices as the demand for different types of processing services changes. A hypervisor can be implemented to manage the use of different virtual machines on the same computing device. The service platform 2 can run one or more services or software applications that enable the performance of the methods described herein. The service platform 2 can also provide other services or software applications, which can include non-virtualized and virtualized environments. In certain embodiments, these services can be provided as web-based services or cloud services, for example, under a software as a service (SaaS) model to users of the client 4.

[0036] The service platform 2 can include one or more components that implement the functions performed by the service platform 2. These components can include software components, hardware components, or a combination thereof, executable by one or more processors. In some embodiments, the service platform 2 can provide storage, read, write, query, delete, and the like services. In other embodiments, users operating the client 4 can in turn utilize one or more client applications to interact with the service platform 2 to utilize the services provided by these components.

[0037] Network 6: A communication network connecting the client 4 and the service platform 2, the nodes within the service platform, and the service platform 2 and the origin server 8.

[0038] Origin server 8: Refers to the original storage server or server cluster of the content, which is the ultimate data source for content acceleration by the content delivery network.

[0039] The client 4 can include various types of computer devices, such as portable handheld devices, general purpose computers (such as personal computers and laptop computers), workstation computers, wearable devices, smart screen devices, self-service terminal devices, service robots, gaming systems, thin clients, various messaging devices, sensors, or other electronic devices, etc. These computer devices can run various types and versions of software applications and operating systems, such as MICROSOFT Windows, APPLE iOS, UNIX-like operating systems, Linux or Linux-like operating systems (such as GOOGLE ChromeOS); or including various mobile operating systems, such as MICROSOFT Windows, Mobile OS, iOS, Windows Phone, Android. The portable handheld devices can include cellular phones, smart phones, tablet computers, personal digital assistants, etc. The wearable devices can include head-mounted displays (such as smart glasses), etc. The gaming systems can include various handheld gaming devices, Internet-enabled gaming devices, etc. The client devices are capable of executing various different applications, such as various Internet-related applications, communication applications (such as email applications), short message service (SMS) applications, and can use various communication protocols.

[0040] Based on the operating system described above, the client 4 can also be installed with one or more applications.

[0041] The client 4 can include input / output interfaces. The input interfaces can include touchpads, touchscreens, mice, keyboards, or other sensing elements. The input interfaces can be configured to receive user instructions, which can cause the client 4 to perform various operations. The output interfaces are used to output information, such as display information, to the user.

[0042] The network 6 can be used as a transmission medium between the service platform 2 and the client 4. The network 6 includes various network devices, such as routers, switches, multiplexers, hubs, modems, bridges, repeaters, firewalls, proxy devices, and / or the like. The network can include physical links, such as coaxial cable links, twisted-pair cable links, fiber-optic links, combinations thereof, etc., or wireless links, such as cellular links, satellite links, Wi-Fi links, etc.

[0043] It is noted that the above devices are exemplary, and the number and types of devices can be adjusted in different scenarios or according to different needs. In the following, the service platform 2 (edge node) is taken as the execution subject, and the technical solutions of the present application are introduced through multiple embodiments. It is understood that these embodiments can be implemented in various forms, and should not be interpreted as being limited to the embodiments set forth herein.

[0044] Embodiment One Figure 2 A flow chart of a method for source returning according to Embodiment One of the present application is shown schematically.

[0045] As shown in Figure 2 , the method for source returning can include steps S200-S204, in which: S200, in the process of initiating the source returning operation, a first address is selected from a first address set, and a first source returning request is sent based on the first address; wherein the first address set is a set of addresses newly resolved according to the source returning domain name.

[0046] S202, in the case of failure of source returning based on the first source returning request, switching from the first address set to a second address set; wherein the second address set is composed of a plurality of addresses that have been used for historical source returning requests in the first address set.

[0047] S204, a second address is selected from the second address set, and a second source returning request is sent based on the second address.

[0048] The method for source returning provided in this embodiment, when the edge node initiates the source returning operation, first selects an address from a first address set newly resolved according to the source returning domain name as a first address, and initiates a first source returning request based on the address. If the first source returning request fails, switching from the first address set to a second address set, wherein the second address set is composed of a plurality of addresses that have been used for historical source returning requests in the first address set. Then, a second address is selected from the second address set, and a second source returning request is initiated based on the address. When the source returning based on the address newly resolved (first address) fails, the source returning based on the address used for historical source returning (second address) is adopted in this embodiment, so as to effectively avoid system failure caused by abnormal (such as hijacking, pollution or configuration error) single domain name resolution result, and improve the robustness and success rate of source returning.

[0049] The steps S200-S204 and optional other steps are described in detail below. Figure 2

[0050] Step S200 S200, in the process of initiating the source returning operation, a first address is selected from a first address set, and a first source returning request is sent based on the first address; wherein the first address set is a set of addresses newly resolved according to the source returning domain name.

[0051] ​In the process of initiating the source return operation at the edge node, the first address can be selected from the first address set in various ways such as random selection, historical success rate weighting, network delay evaluation, or recent failure avoidance. The source return operation can refer to the process of the edge node obtaining resources from the source station, and can occur when the edge node cache is invalid or the requested resource is not cached. The source return operation can include HTTP / HTTPS request, request preprocessing, URL rewriting, and the like.

[0052] The first address set can be a temporary, latest network state-based memory address pool or cache database, which can directly reflect the current DNS server's resolution of the source return domain name. The first address set can be obtained from the DNS query result of the source return domain name. The first address set can be obtained in various ways such as (1) periodically (e.g., every minute) resolving the source return domain name to the DNS server to obtain a list of multiple addresses; (2) when the source return operation is triggered, calling the DNS resolution interface in real time to obtain a list of addresses, and the like.

[0053] Step S202 In the case of failure of the first source return request, the second address set is switched from the first address set; wherein the second address set is composed of multiple addresses in the first address set that have been used for historical source return requests.

[0054] If the first source return request fails, the second address set is switched from the current first address set. The second address set can be a persistent or semi-persistent, memory address pool or cache database composed of multiple addresses that have been used and associated with a health parameter. The health parameter can be obtained based on historical success rate, average response time, last success / failure time, and / or total request number, and the like.

[0055] In some embodiments, before the first source return request is initiated, it can also be detected whether the overall failure rate or average response time of all addresses in the first address set has exceeded a preset threshold. In the case of exceeding the preset threshold, the attempt on the first address set can be skipped, and the second address set is directly switched from the first address set, thereby improving the accuracy and reliability of the source return. In some embodiments, in the case that the first source return request carries a high priority identifier, the second address set can be directly used to further improve the reliability of the source return of important services.

[0056] Step S204 A second address is selected from the second address set, and a second source return request is sent based on the second address.

[0057] The second address set can be traversed, and the address corresponding to the highest current health degree parameter of each address can be directly selected as the second address, thereby improving the probability of success of the current retry. In some embodiments, the health degree parameter of each address can also be used as a weight to calculate the probability of being selected. For example, address A scores 90, and address B scores 70, so the probability of A being selected is 90 / (90+70)≈56%. Then, the address with the highest probability is selected according to the probability distribution, thereby further avoiding excessive stress on a single point. In some embodiments, the health degree parameter is also sorted, and the top N addresses are selected. Then, the second address is finally selected in a random or polling manner from the top N addresses. Then, the second back-to-source request is sent based on the selected second address.

[0058] The following provides an exemplary method of obtaining the second address.

[0059] In an optional embodiment, as shown in Figure 3 Step S204 can include: Step S300, determining a health degree parameter of each address in the second address set; wherein the health degree parameter is a comprehensive numerical indicator quantifying the historical service quality of each address in the second address set.

[0060] Step S302, selecting the second address from the second address set according to the health degree parameter of each address in the second address set.

[0061] Exemplarily, the health degree parameter can refer to a comprehensive numerical value used to quantify and evaluate the historical service quality of a certain source station. The health degree parameter can include historical success rate, response time percentile, historical score decay weight, etc. In some embodiments, after each back-to-source request is initiated to a certain address, whether successful or not, the corresponding request metadata and response details are recorded. For example, target address, timestamp, success / failure status, time consumption, failure reason (such as timeout, error, etc.). Then, the health degree parameter is calculated according to the recorded request metadata and response details. The second address is selected from the second address set according to the health degree parameter of each address in the second address set.

[0062] In this embodiment, the second address is selected from the second address set according to the health degree parameter of each address in the second address set, thereby reducing the risk of unreliable single DNS resolution results.

[0063] In an optional embodiment, the back-to-source method can also include: in the case of failure of the Mth back-to-source request, selecting the M+1th address from the second address set until the back-to-source is successful. Wherein, N>M≥2, N is a preset number of times.

[0064] For example, a second address is selected from the second address set after the first backsource request (M=1) fails, and a second backsource request (M=2) is initiated. If the second backsource request (M=2) also fails, a third address is selected from the second address set, and a third backsource request (M=3) is initiated. This process continues, and if the Mth request fails, an M+1th attempt is initiated, until a backsource request succeeds or the total number of attempts reaches an upper limit N (preset number of times).

[0065] In this embodiment, after each backsource request fails, the next optimal address is selected from the historical address set (second address set) for retry, until success or the preset maximum number of attempts (preset number of times) is reached, thereby improving the fault tolerance of backsource.

[0066] In an optional embodiment, as shown in Figure 4 The backsource method can further include: Step S400: obtaining the backsource domain name and a preset blacklist; wherein the blacklist is used to indicate abnormal addresses.

[0067] Step S402: periodically resolving the backsource domain name to obtain a plurality of resolution addresses.

[0068] Step S404: filtering the abnormal addresses in the plurality of resolution addresses through the blacklist to obtain initial addresses.

[0069] Step S406: performing port pre-probing on the initial addresses to remove addresses that cannot establish a connection, to obtain the first address set.

[0070] For example, the backsource domain name can be periodically resolved at a fixed frequency to obtain a plurality of resolution addresses, for example, DNS resolution is triggered once every 30 seconds or once every minute. In some embodiments, the plurality of resolution addresses can be compared with the current first address set, and only the changed addresses are updated, thereby improving efficiency. In some embodiments, queries can be initiated to multiple DNS servers simultaneously to improve resolution success rate. The resolution results in a short period of time are cached to avoid too frequent queries.

[0071] The latest blacklist can be periodically pulled from a local configuration file, a distributed configuration center, or an API interface. The blacklist refers to a list used to identify and exclude abnormal addresses, so that these abnormal addresses are filtered out after DNS resolution. In some embodiments, the blacklist can include abnormal addresses manually configured by an operation and maintenance personnel, for example, known hijacked addresses, addresses with malicious behavior in history, etc. The blacklist can also include addresses with long-term failure or extremely low health score automatically added from the second address set.

[0072] The plurality of resolved addresses can be compared with a plurality of abnormal addresses in the blacklist, and the abnormal addresses in the plurality of resolved addresses can be filtered to obtain initial addresses. Then, port pre-probing is performed on the initial addresses to remove addresses that cannot establish a connection to obtain a first address set. Specifically, for each address in the initial address set, a TCP connection (three-way handshake) can be attempted to be initiated, and a very short timeout time (such as 200-500 milliseconds) can be set. If the connection is successfully established within the timeout time, the connection is disconnected, and the address is marked as a normal address. If the connection times out, is rejected, or an error occurs, the address is marked as an abnormal address and removed.

[0073] In the embodiment, the plurality of resolved addresses of the plurality of back-to-source domain names are filtered by the blacklist and port pre-probing, so that the failure probability of the back-to-source request is reduced.

[0074] In an optional embodiment, as shown in Figure 5 The back-to-source method can further include: In step S500, a historical success rate and a first byte time consumption of a first back-to-source request based on a first address are obtained.

[0075] In step S502, a health degree parameter of the first address in the second address set is updated according to the historical success rate and the first byte time consumption corresponding to the first address. And / or In step S506, a historical success rate and a first byte time consumption of a second back-to-source request based on a second address are obtained.

[0076] In step S508, a health degree parameter of the second address in the second address set is updated according to the historical success rate and the first byte time consumption corresponding to the second address.

[0077] The first byte time consumption is a time interval from sending the corresponding back-to-source request by the edge node to receiving the first byte in the corresponding response.

[0078] Exemplarily, the historical success rate and the first byte time consumption of the first back-to-source request corresponding to the first address and the historical success rate and the first byte time consumption of the second back-to-source request corresponding to the second address can be obtained. The historical success rate refers to the proportion of the back-to-source requests that are determined to be successful in the back-to-source requests initiated to a certain address within a certain time window. The historical success rate can be calculated based on a fixed number of requests, or can be based on all requests within a fixed time period (such as in the past 5 minutes). The first byte time consumption can be a time interval from the end of sending the last byte of the request by the edge node to the reception of the first byte of the response data returned by the source station, which is used to reflect the network delay and the processing delay of the source station.

[0079] The health degree parameter of the first address in the second address set can be updated according to the historical success rate and the first-byte time consumption corresponding to the first address. The health degree parameter of the second address in the second address set can be updated according to the historical success rate and the first-byte time consumption corresponding to the second address. In some embodiments, the health degree parameter can be calculated by configuring different weights for the historical success rate and the first-byte time consumption. For example, in a financial service, the weight of the success rate can be higher. In a video on demand service, the weight of the first-byte time consumption can be higher. In some embodiments, time decay can be introduced, so that the performance of recent source return requests has a greater impact on the health degree parameter, thereby responding more quickly to changes in address state. In some embodiments, the monitor of the edge node can be configured to periodically traverse the second address set, and the expired address records can be eliminated by using the resolution time corresponding to each address, so that the expired address records can be avoided from being incorrectly selected as the optimal address when the network environment changes.

[0080] In the present embodiment, the health degree score of each address is updated by the historical success rate and the first-byte time consumption, so that the second address set can truly reflect the real-time service quality of each source station, thereby ensuring that the currently most reliable address can be preferentially selected for source return, and the overall success rate and response speed of the source return request are effectively improved.

[0081] In an optional embodiment, as shown in Figure 6 the source return method can further include: Step S600, in a case where the health degree parameter of the first address or the second address is lower than a preset value, triggering an alarm and submitting to an audit node.

[0082] Step S602, according to the audit result returned by the audit node, adding the first address or the second address to a blacklist.

[0083] For example, in a case where the health degree parameter of the first address or the second address is lower than a preset value, an alarm is triggered and submitted to an audit node for manual audit. Then, the audit result is returned by the audit node, and the first address or the second address is added to a blacklist according to the audit result. The preset value can be a static threshold, for example, triggering an alarm when the health degree is lower than 30 points. The preset value can also be dynamically adjusted according to the overall state of the system or time. For example, in a peak period of service, the preset value can be increased to 50 points to improve sensitivity; or when a regional network failure is detected, the preset value is temporarily increased to reduce false positives. Multiple levels of preset values can also be set to correspond to different severity alarms. For example, triggering a warning when the health degree is lower than 60 points, and triggering a serious alarm when the health degree is lower than 30 points.

[0084] In the embodiment, the manual review process is automatically triggered by setting a health degree threshold (preset value), the abnormal address is manually reviewed, and the blacklist is updated according to the manual review result, so that when the source station has a persistent fault or is attacked by a network attack, the blacklist can be accurately updated to block the traffic scheduling to the abnormal address.

[0085] In order to make the present application easier to understand, the following will be combined with Figure 7 and 8 to provide an exemplary application.

[0086] Step S1, in the process of initiating the source return request at the edge node, the decision maker of the edge node judges whether the source return request is the first source return request (the first source return request).

[0087] Step S2A, in the case where the source return request is the first source return request, a first address is randomly selected and read from a memory address pool (a first address set), and a source return request (HTTP request) is sent.

[0088] As Figure 8 shown, the memory address pool is obtained by the following operations: Step S21, trigger asynchronous DNS resolution of the domain name at a regular time to obtain a plurality of addresses.

[0089] Step S22, filter abnormal addresses (blacklist IPs) in the plurality of addresses by the blacklist to obtain a plurality of initial addresses.

[0090] Step S23, TCP connectivity detection is performed on the plurality of initial addresses, addresses that cannot establish a connection are removed, and the remaining addresses are updated to the memory address pool.

[0091] Step S2B, in the case where the source return request is not the first source return request, a second address with the highest health degree score is selected from a plurality of addresses in a health cache database (a second address set), and a second source return request (HTTP request) is sent. The health degree parameter is a comprehensive numerical index quantifying the historical service quality of each address in the health state cache database.

[0092] Specifically, in the case of source return failure based on the Mth source return request, the M+1th address is selected from the health state cache database until the source return is successful. Wherein, N>M≥2, N is a preset number of times.

[0093] Step S3, judge whether the request is successful, and update the content in the health state cache database according to the request result.

[0094] Specifically, the historical success rate and first-byte latency of the first origin request for the first address are obtained. Then, based on the historical success rate and first-byte latency of the first address, the health parameters of multiple addresses in the health cache database are updated. The historical success rate and first-byte latency of the second origin request based on the second address are obtained. Based on the historical success rate and first-byte latency of the second address, the health parameters of the second address in the health status cache database are updated. The first-byte latency is the time interval from when the edge node sends the corresponding origin request to when it receives the first byte of the corresponding response.

[0095] This application's embodiments effectively construct a multi-layered origin-to-origin fault-tolerance system, realizing a shift from relying on existing trusted DNS resolution to relying on genuine business request feedback. Through a decision-making layer selecting the origin address, a hybrid retry strategy, a blacklist mechanism, and certain monitoring and alerting mechanisms, related problems (such as hijacking, looping, and batch DNS resolution failures) are resolved.

[0096] Example 2 Figure 9 The diagram schematically illustrates a source-return device according to Embodiment 2 of this application. This device can be divided into one or more program modules. One or more program modules are stored in a storage medium and executed by one or more processors to complete the embodiments of this application. The program module referred to in the embodiments of this application refers to a series of computer program instruction segments capable of performing a specific function. The following description will specifically introduce the functions of each program module in this embodiment. For example... Figure 9 As shown, the device 1000 may include: a first transmitting module 1100, a switching module 1200, and a second transmitting module 1300, wherein: The first sending module 1100 is used to select a first address from a first address set and send a first origin request based on the first address during the process of initiating a return-to-origin operation; wherein the first address set is the address set most recently resolved based on the origin domain name. Switching module 1200 is configured to switch from the first address set to a second address set when the first origin request fails; wherein the second address set consists of multiple addresses in the first address set that have been used for historical origin requests; and The second sending module 1300 is used to select a second address from the second address set and send a second source request based on the second address.

[0097] In an optional embodiment, the second sending module is further configured to: Determine the health parameters of each address in the second address set; wherein, the health parameters are comprehensive numerical indicators that quantify the historical service quality of each address in the second address set; selecting the second address from the second address set according to the health degree parameter of each address in the second address set.

[0098] In an optional embodiment, the apparatus further comprises a selecting module configured to: selecting the M+1th address from the second address set in the case that the Mth source request fails, until the source succeeds; wherein, N>M≥2, N is a preset number of times.

[0099] In an optional embodiment, the apparatus further comprises a filtering module configured to: obtaining the source domain name and a preset blacklist; wherein the blacklist is used to indicate abnormal addresses; resolving the source domain name at a regular time to obtain a plurality of resolution addresses; filtering the abnormal addresses in the plurality of resolution addresses through the blacklist to obtain initial addresses; performing port preposition detection on the initial addresses to remove addresses that cannot establish a connection to obtain the first address set.

[0100] In an optional embodiment, the apparatus further comprises an updating module configured to: obtaining a historical success rate and a first byte time consumption of a first source request based on a first address; updating the health degree parameter of the first address in the second address set according to the historical success rate and the first byte time consumption corresponding to the first address; and / or obtaining a historical success rate and a first byte time consumption of a second source request based on a second address; updating the health degree parameter of the second address in the second address set according to the historical success rate and the first byte time consumption corresponding to the second address; wherein, the first byte time consumption is a time interval from sending a corresponding source request by the edge node to receiving the first byte in a corresponding response.

[0101] In an optional embodiment, the apparatus further comprises a joining module configured to: in the case that the health degree parameter of the first address or the second address is lower than a preset value, triggering an alarm and submitting to an audit node; according to an audit result returned by the audit node, adding the first address or the second address to a blacklist.

[0102] Embodiment three Figure 10This illustration schematically depicts the hardware architecture of a computer device 10000 suitable for implementing a back-to-source method according to Embodiment 3 of this application. In some embodiments, the computer device 10000 may be a rack server, blade server, tower server, or cabinet server (including standalone servers or server clusters composed of multiple servers), etc. Figure 10 As shown, the computer device 10000 includes, but is not limited to: a memory 10010, a processor 10020, and a network interface 10030 that can communicate and be linked with each other via a system bus. Wherein: The memory 10010 includes at least one type of computer-readable storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 10010 may be an internal storage module of a computer device 10000, such as the hard disk or memory of the computer device 10000. In other embodiments, the memory 10010 may also be an external storage device of the computer device 10000, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the computer device 10000. Of course, the memory 10010 may also include both the internal storage module and the external storage device of the computer device 10000. In this embodiment, the memory 10010 is typically used to store the operating system and various application software installed on the computer device 10000, such as the program code for the back-to-source method. In addition, the memory 10010 can also be used to temporarily store various types of data that have been output or will be output.

[0103] In some embodiments, processor 10020 may be a central processing unit (CPU), controller, microcontroller, microprocessor, or other chip. Processor 10020 is typically used to control the overall operation of computer device 10000, such as performing control and processing related to data interaction or communication with computer device 10000. In this embodiment, processor 10020 is used to run program code stored in memory 10010 or process data.

[0104] The network interface 10030 can include a wireless network interface or a wired network interface, and is generally used to establish a communication link between the computer device 10000 and other computer devices. For example, the network interface 10030 is used to connect the computer device 10000 with an external terminal through a network, establish a data transmission channel and a communication link between the computer device 10000 and the external terminal, and the like. The network can be an Intranet, the Internet, a Global System of Mobile communication (GSM), a Wideband Code Division Multiple Access (WCDMA), a 4G network, a 5G network, Bluetooth, Wi-Fi, and the like wireless or wired network.

[0105] It should be noted that, Figure 10 Only the computer device with the components 10010-10030 is shown, but it should be understood that all the shown components are not required to be implemented, and more or fewer components can be alternatively implemented.

[0106] In this embodiment, the source return method stored in the memory 10010 can also be divided into one or more program modules, and executed by one or more processors (such as the processor 10020) to complete the source return method in the embodiments of the present application.

[0107] Embodiment Four The embodiments of the present application also provide a computer readable storage medium, and the computer readable storage medium has a computer program stored thereon, wherein the computer program is executed by a processor to implement the steps of the source return method in the embodiments.

[0108] In this embodiment, the computer readable storage medium includes a flash memory, a hard disk, a multimedia card, a card-type memory (for example, an SD or DX memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read only memory (ROM), an electrically erasable programmable read only memory (EEPROM), a programmable read only memory (PROM), a magnetic memory, a magnetic disk, an optical disk, etc. In some embodiments, the computer readable storage medium can be an internal storage unit of the computer device, for example, a hard disk or a memory of the computer device. In other embodiments, the computer readable storage medium can also be an external storage device of the computer device, for example, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device. Of course, the computer readable storage medium can also include both the internal storage unit and the external storage device of the computer device. In this embodiment, the computer readable storage medium is usually used to store an operating system and various application software installed on the computer device, for example, program codes of the source returning method in the embodiments, etc. In addition, the computer readable storage medium can also be used to temporarily store various data that have been output or will be output.

[0109] Embodiment five The embodiments of the present application further provide a computer program product, comprising a computer program which, when executed by a processor, implements the method in the above embodiments.

[0110] Obviously, those skilled in the art should understand that each module or each step of the above-mentioned embodiments of the present application can be implemented by using a general computer device, which can be concentrated on a single computer device or distributed on a network composed of multiple computer devices, and optionally, each module or each step can be implemented by using program codes executable by a computer device, so that each module or each step can be stored in a storage device and executed by a computer device, and in some cases, the steps shown or described can be executed in an order different from that shown here, or each module or each step can be manufactured into an individual integrated circuit module, or multiple modules or steps can be manufactured into a single integrated circuit module. Therefore, the embodiments of the present application are not limited to any specific combination of hardware and software.

[0111] Embodiment six The embodiments of the present application further provide a source returning system, and specific technical details and effects can be referred to the embodiment one.

[0112] The source returning system comprises a decision maker and a source returning executor.

[0113] The decision maker is configured to: select a first address from a first address set in a process of initiating a back-to-source operation, wherein the first address set is a set of addresses newly resolved according to the back-to-source domain name; switch from the first address set to a second address set in a case where a back-to-source fails based on the first back-to-source request; wherein the second address set is composed of a plurality of addresses in the first address set that have been used for historical back-to-source requests; and select a second address from the second address set and send a second back-to-source request based on the second address. The back-to-source executor is configured to: generate a first back-to-source request according to the first address if the first address is received from the decision maker; and generate a second back-to-source request according to the second address if the second address is received from the decision maker.

[0114] In an optional embodiment, the system further comprises a health state cache configured to: store a correspondence between the back-to-source domain name and the second address set and / or a health degree parameter of each address in the second address set; wherein the health degree parameter is a comprehensive numerical indicator quantifying a historical service quality of each address in the second address set.

[0115] In an optional embodiment, the system further comprises a blacklist comprising a plurality of abnormal addresses; the blacklist is configured to filter the abnormal addresses from a plurality of resolved addresses corresponding to the back-to-source domain name.

[0116] In an optional embodiment, the system further comprises an asynchronous monitor configured to: update the health degree parameter of each address in the second address set; submit the abnormal addresses to an audit node; and / or manage the blacklist.

[0117] It should be noted that the above is only a preferred embodiment of the present application, and does not limit the patent protection scope of the present application, and any equivalent structure or equivalent process transformation using the content of the specification and drawings, or direct or indirect application in other related technical fields, are also included in the patent protection scope of the present application.

Claims

1. A method for back source, characterized in that, The method for an edge node comprises: In the process of initiating a source return operation, a first address is selected from a first address set, and a first source return request is sent based on the first address; wherein the first address set is a set of addresses newly resolved according to the source return domain name; In the case of source return failure based on the first source return request, switching from the first address set to a second address set; wherein the second address set is composed of a plurality of addresses in the first address set that have been used for historical source return requests; and A second address is selected from the second address set, and a second source return request is sent based on the second address.

2. The method of claim 1, wherein, Selecting a second address from the second address set comprises: Determining a health degree parameter according to each address in the second address set; wherein the health degree parameter is a comprehensive numerical index quantifying the historical service quality of each address in the second address set; According to the health degree parameter of each address in the second address set, the second address is selected from the second address set.

3. The method of claim 1, wherein, The method further comprises: In the case of source return failure based on the Mth source return request, the M+1th address is selected from the second address set until the source return is successful; Wherein, N > M ≥ 2, N is a preset number of times.

4. The method according to any one of claims 1 to 3, characterized in that, The method further comprises: Obtaining the source return domain name and a preset blacklist; wherein the blacklist is used to indicate abnormal addresses; Resolving the source return domain name at regular intervals to obtain a plurality of resolved addresses; Filtering the abnormal addresses in the plurality of resolved addresses through the blacklist to obtain initial addresses; Performing port preposition detection on the initial addresses to remove addresses that cannot establish a connection to obtain the first address set.

5. The method according to any one of claims 1 to 3, characterized in that, The method further comprises: Obtaining the historical success rate and first byte time consumption of the first source return request based on the first address; According to the historical success rate and first byte time consumption corresponding to the first address, updating the health degree parameter of the first address in the second address set; and / or Obtaining the historical success rate and first byte time consumption of the second source return request based on the second address; According to the historical success rate and first byte time consumption corresponding to the second address, updating the health degree parameter of the second address in the second address set; Wherein, the first byte time consumption is the time interval from sending the corresponding source return request by the edge node to receiving the first byte of the corresponding response.

6. The method of claim 5, wherein, The method further comprises: In the case that the health degree parameter of the first address or the second address is lower than a preset value, triggering an alarm and submitting to an audit node; According to the audit result returned by the audit node, adding the first address or the second address to the blacklist.

7. A back source device, characterized by, The device comprises: A first sending module for selecting a first address from a first address set and sending a first source return request based on the first address in the process of initiating a source return operation; wherein the first address set is a set of addresses newly resolved according to the source return domain name; The switching module is configured to switch from the first address set to a second address set in a case that a first back-to-source request based on the first address set fails; the second address set is composed of a plurality of addresses in the first address set that have been used for historical back-to-source requests; and The second sending module is configured to select a second address from the second address set and send a second back-to-source request based on the second address.

8. A computer device, characterized by The system comprises: at least one processor; and a memory connected to the at least one processor in communication; wherein: the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions, and the computer instructions are executed by the processor to implement the method of any one of claims 1 to 6.

10. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method of claims 1 to 6.

11. A backsource system characterized in that, The system comprises: a decision maker configured to: select a first address from a first address set in a process of initiating a back-to-source operation, wherein the first address set is a set of addresses newly resolved according to the back-to-source domain name; switch from the first address set to a second address set in a case that a first back-to-source request based on the first address set fails; wherein the second address set is composed of a plurality of addresses in the first address set that have been used for historical back-to-source requests; and select a second address from the second address set and send a second back-to-source request based on the second address; a back-to-source executor configured to: generate a first back-to-source request according to the first address if the first address is received from the decision maker; and generate a second back-to-source request according to the second address if the second address is received from the decision maker.

12. The system of claim 11, wherein, The system further comprises a health state cache configured to: store a correspondence between the back-to-source domain name and the second address set and / or a health degree parameter of each address in the second address set; wherein the health degree parameter is a comprehensive numerical indicator quantifying historical service quality of each address in the second address set.

13. The system of claim 11, wherein, The system further comprises a blacklist comprising a plurality of abnormal addresses; the blacklist is configured to filter the abnormal addresses from a plurality of resolved addresses corresponding to the back-to-source domain name.

14. The system of claim 13, wherein, The system further comprises an asynchronous monitor configured to update the health degree parameter of each address in the second address set, submit the abnormal addresses to an audit node, and / or manage the blacklist.

Citation Information

Patent Citations

  • Back-to-source processing method and device

    CN111181782A

  • Domain name processing method, apparatus, electronic device, and storage medium

    CN113316926A

  • Data feedback routing method and system for CDN (Content Delivery Network)

    CN114448871A

  • Method and device for switching back-to-source strategy, medium and equipment

    CN115333936A

  • Source return node determination method and device and storage medium

    CN115701073A