Method and system for deep processing of network traffic based on dynamic policy drive

By receiving security threat intelligence to generate hardware acceleration logic and screening and evaluating acceleration card resources, the problem of insufficient acceleration card resource configuration in network traffic analysis is solved, the security detection capability and resource utilization efficiency are improved, and dynamic optimization of network traffic processing is realized.

CN121530647BActive Publication Date: 2026-06-09BEIJING SHANNON NETWORK TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING SHANNON NETWORK TECHNOLOGY CO LTD
Filing Date
2025-11-11
Publication Date
2026-06-09

AI Technical Summary

Technical Problem

Existing technologies cannot accurately identify and properly configure optimal accelerator card resources in network traffic analysis, resulting in low security detection capabilities and an inability to guarantee data security during in-depth network traffic processing.

Method used

By receiving dynamic policies triggered by security threat intelligence, hardware acceleration logic is generated and candidate programmable regions that meet resource requirements are selected. Multi-dimensional cost evaluation is performed, target programmable regions are selected, and hardware acceleration logic is dynamically loaded for deep detection.

Benefits of technology

It improves the utilization efficiency of accelerator card resources, enhances the effectiveness of security threat detection, and achieves timely adaptability and dynamic optimization of network traffic processing throughout the entire process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121530647B_ABST
    Figure CN121530647B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of network flow deep processing, in particular to a network flow deep processing method and system based on dynamic strategy driving, which generates hardware acceleration logic and determines required resource demand according to detection rules in a dynamic strategy; real-time resource state data of each programmable area in an acceleration card is acquired, candidate programmable areas are screened out from all programmable areas according to the resource demand and the real-time resource state data, multi-dimensional cost evaluation results are obtained through multi-dimensional cost evaluation, and a target programmable area is selected according to the multi-dimensional cost evaluation results; the hardware acceleration logic is dynamically loaded into the target programmable area; when network flow flows, the loaded hardware acceleration logic is used to identify security threats of the network flow; when the security threats are identified, corresponding processing actions in the dynamic strategy are executed; the security detection capability in the network flow processing process is improved, and the data security in the network flow deep processing process is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network traffic deep processing technology, specifically to a network traffic deep processing method and system based on dynamic policy-driven approaches. Background Technology

[0002] To effectively address security threats in network traffic and ensure stable network operation and secure data transmission, in-depth processing and analysis of network traffic are crucial. Security detection is a core component of this process, enabling real-time identification of potential security risks such as malicious attacks and data breaches, and allowing for timely preventative and mitigation measures. Aggregation and distribution devices are used to meet the demands of large-scale network traffic collection and processing, and are widely applied in backbone networks, metropolitan area networks, and dedicated internet lines for internet information collection and analysis, and network quality optimization. Aggregation and distribution devices typically enhance their processing capabilities by integrating scalable acceleration cards. These cards provide robust hardware support for network traffic processing, accelerating packet parsing, classification, and filtering, thereby improving the efficiency and performance of network traffic processing.

[0003] However, in current network traffic analysis, accurately identifying and rationally configuring optimal accelerator card resources to achieve efficient network traffic processing when a security threat is detected has become a critical issue that urgently needs to be addressed. Existing technologies have significant shortcomings in managing the status of accelerator card resources, making it difficult to quickly and accurately select accelerator cards that meet the resource requirements for security detection when facing security threats. This leads to a decrease in the overall processing capacity of the system, making it unable to meet the needs of large-scale network traffic processing.

[0004] Therefore, a network traffic deep processing method based on dynamic policy is proposed, which can accurately find the optimal accelerator card resources and configure them reasonably, improve the security detection capability during network traffic processing, and ensure data security during network traffic deep processing. Summary of the Invention

[0005] The purpose of this invention is to provide a method and system for deep processing of network traffic based on dynamic policy-driven approaches, in order to solve the problem that when a security threat is detected in network traffic analysis, it is impossible to accurately find the optimal accelerator card resources and configure them reasonably, resulting in low security detection capabilities during network traffic processing and an inability to guarantee data security during deep processing of network traffic.

[0006] To achieve the above objectives, in one aspect, the present invention provides a method for deep processing of network traffic based on dynamic policy-driven approaches, the method comprising:

[0007] S1. Receive a dynamic policy triggered by security threat intelligence, the dynamic policy containing security threat detection rules and corresponding processing actions; generate corresponding hardware acceleration logic according to the detection rules in the dynamic policy, and determine the resource requirements required to execute the hardware acceleration logic, the resource requirements including computing resources and storage resources.

[0008] S2. Obtain real-time resource status data of each programmable region in the accelerator card, and select candidate programmable regions that meet the resource requirements from all programmable regions based on the resource requirements and the real-time resource status data.

[0009] S3. Perform a multi-dimensional cost evaluation on each candidate programmable region to obtain a multi-dimensional cost evaluation result. The multi-dimensional cost evaluation includes communication cost, timing cost, and resource fragmentation cost. Select a target programmable region from the candidate programmable regions based on the multi-dimensional cost evaluation result.

[0010] S4. Dynamically load the hardware acceleration logic into the target programmable area; perform deep detection on network traffic through the loaded hardware acceleration logic, and identify security threats in the network traffic according to the detection rules; when a security threat is identified, execute the corresponding processing action in the dynamic policy.

[0011] Furthermore, the method for filtering candidate programmable regions that meet the resource requirements from all programmable regions based on the resource requirements and real-time resource status data includes:

[0012] A programmable region resource map is constructed based on the real-time resource status data. Based on the resource requirements, the similarity between the existing resource distribution of each programmable region in the programmable region resource map and the resource form of the computational and storage resource requirements is calculated. The dynamic change trend of resource requirements is also calculated to match the resource release mode of the programmable region.

[0013] Programmable regions whose resource morphology similarity is greater than a preset morphology similarity threshold and whose resource matching degree is greater than a preset matching degree threshold are selected as candidate programmable regions.

[0014] Furthermore, the method for constructing a programmable regional resource map based on the real-time resource status includes:

[0015] The real-time resource status data includes the computing resource dimension characteristics, storage resource dimension characteristics, and current workload status of each programmable region; the topological connection relationship between programmable regions is established according to the physical layout of the accelerator card.

[0016] A multi-dimensional resource feature vector is constructed based on the real-time resource status data and topological connectivity. The multi-dimensional resource feature vector includes the static resource attributes and dynamic operating status of the programmable region. The multi-dimensional resource feature vector is then integrated with the topological connectivity to obtain a programmable region resource map.

[0017] Furthermore, the method for constructing a multi-dimensional resource feature vector based on the real-time resource status data and topological connectivity includes:

[0018] The computing resource dimension features and storage resource dimension features are extracted from the real-time resource status data. The computing resource dimension features include the available number and distribution density of different types of computing units, and the storage resource dimension features include the available capacity and access latency of different levels of storage units.

[0019] Dynamic operating features are extracted from the current workload status, including resource utilization fluctuations and historical load change trends. After normalization of the computing resource dimension features, storage resource dimension features, and dynamic operating features, a weighted combination is performed to obtain a multi-dimensional resource feature vector.

[0020] Furthermore, the method for determining the resource consistency between the dynamic changing trend of computing resource demand and the resource release mode of the programmable region includes:

[0021] A resource release behavior model for programmable regions is established based on historical resource usage data. The resource release behavior model records the resource release patterns and response latency characteristics of each programmable region under different workload states.

[0022] Extract the dynamic resource change characteristics during the execution of hardware acceleration logic from the resource requirements. The dynamic resource change characteristics include the fluctuation cycle of resource requirements and the duration of peak resource requirements.

[0023] The matching degree between the dynamic change characteristics of the resources and the resource release behavior model of each programmable region is calculated to obtain the resource release pattern matching degree.

[0024] Furthermore, the method for calculating the matching degree between the dynamic change characteristics of the resources and the resource release behavior model of each programmable region to obtain the resource release pattern fit degree includes:

[0025] Based on the response delay characteristics in the resource release behavior model, the dynamic change characteristics of resources are aligned and compensated on the time axis to establish the resource demand time series curve after alignment and compensation; the resource release rules of the programmable area under the corresponding workload state are extracted to generate the resource supply time series curve.

[0026] The covariance matrix of the resource demand time series curve and the resource supply time series curve within the same time window is calculated. By analyzing the eigenvalue distribution of the covariance matrix, the trend consistency assessment result of the resource demand time series curve and the resource supply time series curve is obtained. The intersection ratio of the peak demand period of the resource demand time series curve and the high availability period of the resource supply time series curve is calculated to obtain the guarantee level assessment result of peak resource demand. The trend consistency assessment result and the guarantee level assessment result are weighted and fused to obtain the resource release pattern matching degree.

[0027] Furthermore, the method of dynamically loading the hardware acceleration logic into the target programmable region includes:

[0028] Based on the functional characteristics of the hardware acceleration logic and the resource characteristics of the target programmable region, corresponding hardware configuration data is generated.

[0029] The hardware configuration data is transmitted to the target programmable area through the reconfiguration interface; after the hardware configuration data is loaded, the hardware acceleration logic function component in the target programmable area is activated and the function is verified. After the function verification is passed, the hardware acceleration logic is integrated into the network traffic processing path.

[0030] Furthermore, the method for performing functional verification includes:

[0031] A corresponding set of test vectors is generated based on the detection rules. The set of test vectors includes normal network traffic patterns and abnormal traffic patterns containing security threats.

[0032] The test vector set is input into the activated hardware acceleration logic function component to obtain the processing result of the test vectors. The processing result is compared and analyzed with the expected result. The accuracy index of the function verification is calculated based on the comparison and analysis result. When the accuracy index reaches the preset verification accuracy threshold, the function verification is determined to be passed. When the function verification fails, the failed test vector is recorded and the reconfiguration process is triggered.

[0033] On the other hand, based on the same inventive concept, this invention also provides a network traffic deep processing system driven by dynamic policies. The system includes: a dynamic policy receiving and parsing module, a candidate programmable region filtering module, a target programmable region selection module, and a network traffic analysis and processing module, with each module connected in a sequential communication manner.

[0034] The dynamic policy receiving and parsing module is used to receive dynamic policies triggered by security threat intelligence, the dynamic policies containing security threat detection rules and corresponding processing actions; generate corresponding hardware acceleration logic according to the detection rules in the dynamic policies, and determine the resource requirements required to execute the hardware acceleration logic, the resource requirements including computing resources and storage resources.

[0035] The candidate programmable region filtering module is used to obtain real-time resource status data of each programmable region in the accelerator card, and filter out candidate programmable regions that meet the resource requirements from all programmable regions based on the resource requirements and the real-time resource status data.

[0036] The target programmable region selection module is used to perform multi-dimensional cost evaluation on each candidate programmable region to obtain multi-dimensional cost evaluation results. The multi-dimensional cost evaluation includes communication cost, timing cost, and resource fragmentation cost. The target programmable region is selected from the candidate programmable regions based on the multi-dimensional cost evaluation results.

[0037] The network traffic analysis and processing module is used to dynamically load the hardware acceleration logic into the target programmable area; perform deep detection of network traffic through the loaded hardware acceleration logic, and identify security threats in the network traffic according to the detection rules; when a security threat is identified, execute the corresponding processing action in the dynamic policy.

[0038] Compared with the prior art, the beneficial effects of the present invention are:

[0039] 1. Based on dynamic strategy-driven approach, by acquiring real-time resource status data of each programmable region in the accelerator card and combining it with the resource requirements of the hardware acceleration logic, candidate programmable regions that meet the resource requirements are accurately selected from all programmable regions, so that the available resources can be initially and accurately identified, effectively improving the overall basic efficiency of accelerator card resource utilization.

[0040] 2. After screening the candidate programmable regions, a multi-dimensional cost evaluation is further performed on each candidate programmable region. This allows for consideration of the compatibility between the programmable region and the hardware acceleration logic from multiple perspectives. The target programmable region that best matches the resource utilization, data transmission efficiency, and processing time order is selected, which significantly enhances the compatibility between resources and security detection requirements, thereby improving the effectiveness of security threat detection.

[0041] 3. Driven by dynamic policies, it can not only trigger corresponding dynamic policies in real time based on security threat intelligence and generate hardware acceleration logic containing detection rules and processing actions, but also quickly execute the corresponding processing actions in the dynamic policies when security threats are identified. This enables network traffic processing to adapt to the ever-changing security threat environment in a timely manner, and realizes dynamic optimization of the entire process from resource screening and logic loading to threat detection and processing. Attached Figure Description

[0042] Figure 1 This is a flowchart of the network traffic deep processing method based on dynamic policy-driven method according to Embodiment 1 of the present invention.

[0043] Figure 2 This is a schematic diagram of the module composition of the network traffic deep processing system based on dynamic policy driving according to Embodiment 2 of the present invention. Detailed Implementation

[0044] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0045] Example 1: As Figure 1 As shown, this embodiment provides a method for deep processing of network traffic based on dynamic policy-driven approaches. The method includes:

[0046] S1. Receive dynamic policies triggered by security threat intelligence. These dynamic policies include security threat detection rules and corresponding processing actions. Generate corresponding hardware acceleration logic based on the detection rules in the dynamic policies, and determine the resource requirements for executing the hardware acceleration logic, including computing and storage resources. In practical applications, security threat intelligence may originate from multiple channels. For example, network security monitoring platforms may push the latest discovered DDoS attack characteristics, malicious code propagation patterns, or data leakage risk indicators in real time. When this security threat intelligence reaches the network traffic processing system, it triggers the corresponding dynamic policies. Dynamic policies refer to predefined or real-time generated response plans for specific security threats. Their core includes two elements: first, detection rules, which define how to identify security threats; and second, processing actions, which specify the specific operations to be performed after a threat is detected. For example, if security threat intelligence indicates that a botnet is launching a DDoS attack through a specific port, the security threat intelligence will trigger a dynamic policy. The detection rules in the dynamic policy may include: monitoring traffic patterns originating from a specific IP range, accessing a specific port, having packet sizes within a certain range, and request frequencies exceeding a threshold; the corresponding actions may be: immediately discarding packets that meet the conditions, recording attack source information, and sending alarm notifications to the security management platform. After receiving the dynamic policy, the detection rules need to be converted into a form that can be executed by hardware; this is the process of generating hardware acceleration logic. Since modern network traffic processing needs to complete detection in real time within high-speed data streams, software processing alone often cannot meet performance requirements. Therefore, it is necessary to utilize the programmable hardware resources in the accelerator card to implement hardware acceleration of the detection logic. The generation process is actually a compilation and conversion process, converting the logical judgment conditions, packet field matching requirements, statistical counting functions, etc., described in the detection rules into configuration data that can be understood and executed by FPGA programmable logic or other hardware accelerators. During the conversion process, the resource requirements required to execute this hardware acceleration logic are analyzed and determined, specifically including two main categories: computing resources and storage resources.

[0047] S2. Obtain real-time resource status data of each programmable region in the accelerator card, and select candidate programmable regions that meet the resource requirements from all programmable regions based on the resource requirements and the real-time resource status data.

[0048] S3. Perform a multi-dimensional cost evaluation on each candidate programmable region to obtain the multi-dimensional cost evaluation results. The multi-dimensional cost evaluation includes communication cost, timing cost, and resource fragmentation cost. Select the target programmable region from the candidate programmable regions based on the multi-dimensional cost evaluation results. The multi-dimensional cost evaluation measures the suitability of each candidate programmable region from three different perspectives. Communication cost examines the length of the entire communication path from the network data stream to the candidate programmable region, after processing, and then transmitted to the next level if the hardware acceleration logic is deployed in the candidate programmable region, and how much transmission delay will be generated. Generally, regions with physical locations closer to the data entry point have lower communication costs. Timing cost focuses on whether the timing characteristics of the candidate programmable region, such as clock frequency and processing pipeline depth, match the performance requirements of the hardware acceleration logic. High timing cost indicates a potential performance bottleneck. Resource fragmentation cost evaluates the availability of remaining resources in the candidate programmable region after deployment. If the remaining resources are too fragmented after deployment and difficult to be utilized by subsequent tasks, then the fragmentation cost is high. Based on the evaluation results of these three dimensions, calculate the overall cost of each candidate programmable region and select the one with the lowest cost and the most suitable as the target programmable region.

[0049] S4. Dynamically load the hardware acceleration logic into the target programmable area; perform deep inspection of network traffic using the loaded hardware acceleration logic, and identify security threats in the network traffic according to the inspection rules; when a security threat is identified, execute the corresponding processing action in the dynamic policy. The loaded hardware acceleration logic will perform deep inspection of network traffic according to the inspection rules. During the inspection process, key fields of data packets will be extracted and compared with the features defined in the inspection rules to determine whether they match the characteristic pattern of a security threat. Once the hardware acceleration logic identifies a data packet or a segment of traffic in the network traffic that matches the characteristics of a security threat, it will immediately execute the predefined processing action in the dynamic policy. The processing action can take various forms depending on the threat type and policy settings, such as directly discarding malicious data packets to prevent attacks from entering the internal network, redirecting suspicious traffic to the security analysis system for further analysis, or generating alarm logs to notify security operations personnel.

[0050] The method for selecting candidate programmable regions that meet the resource requirements from all programmable regions based on the resource requirements and real-time resource status data includes:

[0051] A programmable region resource map is constructed based on the real-time resource status data. Based on the resource requirements, the similarity between the existing resource distribution of each programmable region in the resource map and the resource form of the computing and storage resource requirements in the resource requirements is calculated. The dynamic change trend of the resource requirements is also calculated to match the resource release pattern of the programmable region. Resource form similarity refers to the spatial distribution and composition of resources. The resource requirements of hardware acceleration logic are often not simple numerical requirements but have specific structural characteristics, such as requiring a specific ratio of computing and storage resources, or requiring resources to be relatively concentrated rather than dispersed in physical location. The system analyzes the existing resource distribution of each programmable region and compares it with the ideal form of the computing and storage resource requirements defined in the resource requirements. For example, assuming the hardware acceleration logic requires 10 DSP units with 20KB of adjacent storage space, this requirement reflects a computationally intensive characteristic that requires frequent access to the local cache. The system will examine each programmable region. Although programmable region A has sufficient DSP units and storage capacity, its storage is scattered across multiple physical locations, resulting in inconsistent access latency. In contrast, the DSPs and storage in programmable region B are configured adjacent to each other, and their resource configurations are highly similar to their requirements. In this case, the resource configuration similarity of programmable region B will be significantly higher than that of programmable region A.

[0052] Programmable regions with resource morphological similarity greater than a preset morphological similarity threshold and resource compatibility greater than a preset compatibility threshold are selected as candidate programmable regions. Only when the resource morphological similarity of a programmable region exceeds both the preset morphological similarity threshold and the preset compatibility threshold is it considered a truly qualified candidate region. This dual screening mechanism ensures both spatial resource structure matching and temporal resource supply and demand coordination, resulting in high-quality candidate programmable regions. The preset morphological similarity threshold and preset compatibility threshold are determined using statistical analysis methods based on historical deployment experience. For example, setting the morphological similarity threshold to around 0.85 ensures that the selected candidate programmable regions have a high probability of successful deployment. The preset compatibility threshold focuses on the temporal matching effect. The system tracks and records the performance of hardware acceleration logic under different resource compatibility levels, paying particular attention to whether resource shortages occur during peak resource demand periods and whether resources are wasted during off-peak demand periods. For example, the preset compatibility threshold is typically set around 0.7.

[0053] The method for constructing a programmable regional resource map based on the real-time resource status includes:

[0054] The real-time resource status data includes the computational resource dimension characteristics, storage resource dimension characteristics, and current workload status of each programmable region. A topological connection relationship between programmable regions is established based on the physical layout of the accelerator card. Constructing a programmable region resource map requires organizing the scattered resource status information into a systematic knowledge representation. Real-time resource status data is the raw input for constructing the map, containing multiple dimensions of information for each programmable region. Computational resource dimension characteristics describe the types of computing units the region possesses, such as lookup tables (LUTs), triggers (FFs), DSP modules, RAM blocks, etc., the available quantity of each type, and the utilization rate of these resources. Storage resource dimension characteristics detail the storage resource situation at different levels, including on-chip BRAM capacity, distributed RAM capacity, external DDR interface access capabilities, and the latency characteristics of accessing these storage components. The current workload status reflects the current operating status of the programmable region—whether it is idle, lightly loaded, medium-loaded, or fully loaded—and the type of task being executed. In addition to collecting the resource status of each programmable region itself, it is also necessary to understand the interrelationships between these programmable regions. The physical layout of the accelerator card determines the connection method between programmable areas. Some programmable areas are physically adjacent, resulting in short data transmission paths and low latency; while other programmable areas, although rich in resources, are located in remote areas, requiring access through multiple levels of interconnection. Based on the physical layout information of the accelerator card, the topological connection relationship between programmable areas is established, identifying which areas are directly connected, which require relay, and the bandwidth and latency characteristics of data transmission.

[0055] A multi-dimensional resource feature vector is constructed based on the real-time resource status data and topological connections. This multi-dimensional resource feature vector includes the static resource attributes and dynamic operating status of the programmable regions. The multi-dimensional resource feature vector is then integrated with the topological connections to obtain a programmable region resource map. The multi-dimensional resource feature vector is a numerical representation of the characteristics of each programmable region, integrating static resource attributes and dynamic operating status. Static resource attributes include the inherent hardware configuration of the programmable region, such as the total number of computing units, storage capacity limit, and supported maximum operating frequency. Dynamic operating status changes in real time, including runtime information such as current resource utilization and task queue length. Static attributes and dynamic status are organized into feature vectors according to a certain structure, with each dimension corresponding to a type of feature index. The multi-dimensional resource feature vectors of all programmable regions are integrated with the previously established topological connections to form a graph-structured data model. Nodes in the graph represent each programmable region and its resource feature vector, and edges represent the topological connections and connection attributes between regions.

[0056] The method for constructing a multidimensional resource feature vector based on the real-time resource status data and topological connectivity includes:

[0057] The real-time resource status data is used to extract computational resource dimension features and storage resource dimension features. The computational resource dimension features include the available quantity and distribution density of different types of computational units, while the storage resource dimension features include the available capacity and access latency of different levels of storage units. Accelerator cards contain diverse types of computational units, each suited to different types of computational tasks. It is necessary to determine the current availability of each type of computational unit and their physical spatial distribution density. For the extraction of storage resource dimension features, the focus is on the availability of different levels of storage units. Modern accelerator cards typically contain multi-tiered storage systems, including high-speed but small-capacity registers and distributed RAM, medium-speed and medium-capacity BRAM, and large-capacity but slower-access external DDR storage. It is necessary to determine the remaining available capacity of each level of storage units, and more importantly, to label the latency characteristics of accessing these storage units, as different detection tasks have different sensitivities to storage access latency, requiring precise matching.

[0058] Dynamic operational features are extracted from the current workload status. These features include resource utilization fluctuations and historical load change trends. The computing resource dimension features, storage resource dimension features, and dynamic operational features are normalized and then weighted to obtain a multi-dimensional resource feature vector. Dynamic operational features are derived from monitoring data of the current workload status, analyzing the fluctuations in programmable area resource utilization to determine if there are periodic peaks and troughs, and the magnitude of these fluctuations. This information reflects the stability of the programmable area workload. Historical monitoring data is retrieved to analyze the load change trend of the programmable area over a past period—whether it is gradually increasing, gradually decreasing, or remaining stable—which helps predict future resource availability changes. After extracting these three types of features, normalization is required because their dimensions and numerical ranges differ, mapping all feature values ​​to a unified numerical range, typically between 0 and 1. Weighting aims to assign different weight coefficients based on the importance of different features to resource matching decisions. For example, for some latency-sensitive detection tasks, the storage access latency feature should receive a higher weight. After weighted combination, multiple feature dimensions are integrated into a unified multidimensional resource feature vector, which represents the resource status and operating characteristics of the programmable area.

[0059] The method for determining the resource consistency between the dynamic trend of computing resource demand and the resource release mode of programmable area includes:

[0060] A resource release behavior model for programmable regions is established based on historical resource usage data. This model records the resource release patterns and response latency characteristics of each programmable region under different workloads. The resource release behavior model is a predictive behavior model based on historical resource usage data. The system continuously collects historical resource usage data for each programmable region, recording when resources are released, how much is released, and the response speed under different workloads. The process of establishing the resource release behavior model is similar to creating a profile of the programmable region's operating mode. For example, the system might observe that when region A performs traffic statistics tasks, it typically reaches peak resource usage within 10 minutes of task initiation, then gradually releases resources, taking 5 minutes to fully release them. This release process exhibits low response latency and can quickly respond to new resource demands. Region B, when performing similar tasks, releases resources more slowly and exhibits significant response latency. These regular behavioral patterns are recorded in the resource release behavior model, establishing a unique resource supply characteristic profile for each programmable region.

[0061] The system extracts dynamic resource change characteristics during the execution of hardware acceleration logic from the resource requirements. These characteristics include the fluctuation cycle of resource requirements and the duration of peak resource requirements. The resource consumption of network security detection tasks is not constant but fluctuates with changes in traffic characteristics and threat complexity. The system analyzes how resource requirements change during the execution of hardware acceleration logic to identify the fluctuation cycle of resource requirements. For example, a DDoS detection logic may require a large amount of computing resources to process massive data packets during peak traffic periods, while resource requirements decrease significantly during low traffic periods, exhibiting a clear periodic fluctuation. The system also needs to identify the duration of peak resource requirements, i.e., how long the highest resource demand will last, which determines the duration for which the programmable area needs to stably provide high resource supply.

[0062] The resource release pattern matching degree is calculated by matching the dynamic change characteristics of the resources with the resource release behavior model of each programmable region. If the resource release pattern of a programmable region can precisely match the demand change rhythm of the hardware acceleration logic, providing sufficient resources during peak demand periods and allowing other tasks to utilize its resources during off-peak periods, then the matching degree is high. Conversely, if the resource release timing of a programmable region is out of sync with peak demand, or if the release response is too slow to meet sudden demands, the matching degree will be low. Through this matching degree calculation, the system can select those programmable regions that are most suitable for carrying hardware acceleration logic in terms of time dynamic characteristics.

[0063] The method for calculating the matching degree between the dynamic change characteristics of the resources and the resource release behavior model of each programmable region to obtain the resource release pattern fit degree includes:

[0064] Based on the response latency characteristics in the resource release behavior model, time-axis alignment compensation is performed on the dynamic changes in resources to establish a time-series curve of resource demand after alignment compensation. Resource release patterns of programmable regions under corresponding workload states are extracted to generate a time-series curve of resource supply. Specific calculations of the resource release pattern fit require more refined time-series analysis methods. Because there is a time difference between changes in resource demand and the response of resource supply, time-axis alignment compensation is necessary. The time-axis alignment compensation process considers the response latency characteristics recorded in the resource release behavior model, shifting or adjusting the dynamic changes in resources on the time axis accordingly to ensure that demand and supply remain consistent on the time reference. For example, if the hardware acceleration logic needs to add resources at a certain time t, and the resource release behavior model of a certain programmable region shows that the resource release response latency of that region is 2 minutes, then the system will shift the resource demand time point forward by 2 minutes during alignment to ensure that the resource release of that programmable region can respond precisely when the actual demand arrives. After completing such time-axis alignment compensation, the system establishes an aligned time-series curve of resource demand, which depicts the trajectory of resource demand changes over time after time correction. Resource release patterns under corresponding workload states are extracted from the resource release behavior model of the programmable region to generate resource supply time-series curves. The resource supply time-series curves show how the amount of resources that the programmable region can provide changes over time.

[0065] The covariance matrix of the resource demand time series curve and the resource supply time series curve within the same time window is calculated. By analyzing the eigenvalue distribution of the covariance matrix, the trend consistency assessment result of the resource demand time series curve and the resource supply time series curve is obtained. The intersection ratio of the peak demand period of the resource demand time series curve and the high availability period of the resource supply time series curve is calculated to obtain the guarantee level assessment result of peak resource demand. The trend consistency assessment result and the guarantee level assessment result are weighted and fused to obtain the resource release pattern matching degree. With these two time series curves, their matching degree is evaluated from two perspectives. The first perspective is the trend consistency assessment. The covariance matrix of these two curves within the same time window is calculated. The covariance matrix can reveal whether the changing trends of the two curves are correlated. If resource supply also increases when resource demand rises, and supply also decreases when demand falls, showing a synchronous trend, then the covariance matrix will show a specific pattern. By analyzing the eigenvalue distribution of the covariance matrix, the degree of trend consistency between the two curves is determined. The magnitude and distribution characteristics of eigenvalues ​​can quantify the consistency of this trend. The more concentrated the eigenvalues ​​are in the positive range, the better the synchronization between the two curves, and the higher the trend consistency assessment result. The second perspective is peak availability assessment. For security detection tasks, the most critical factor is whether sufficient resources can be guaranteed during peak demand periods. The system identifies peak demand periods from the resource demand time-series curve—those time intervals with the highest resource demand. Simultaneously, it identifies high availability periods from the resource supply time-series curve—the time intervals where the region can provide a significant amount of available resources. The intersection of these two periods is calculated, representing the proportion of peak demand periods overlapping with high availability periods. This intersection ratio directly reflects whether peak resource demand can be guaranteed; a higher ratio indicates that the region can provide sufficient resource support when resources are most needed. The trend consistency assessment result and the availability assessment result reflect the degree of conformity between two different levels: overall trend matching and critical period guarantee. By setting reasonable weighting coefficients, they are integrated into a comprehensive resource release pattern conformity index. The resource release pattern conformity index comprehensively quantifies the degree of matching between the resource supply capacity of the programmable area and the resource demand of the hardware acceleration logic in terms of time dynamics.

[0066] The method of dynamically loading the hardware acceleration logic into the target programmable region includes:

[0067] Based on the functional characteristics of the hardware acceleration logic and the resource characteristics of the target programmable region, corresponding hardware configuration data is generated. Dynamically loading the hardware acceleration logic into the target programmable region is the key execution step of the entire method, requiring a transformation from logic design to hardware implementation. The hardware configuration data is generated based on the functional characteristics of the hardware acceleration logic and the resource characteristics of the target programmable region. The functional characteristics of the hardware acceleration logic determine the type of circuit logic to be implemented, including the logical structure of various functional components such as the packet parsing module, rule matching engine, statistical counter, and action execution unit. The resource characteristics of the target programmable region determine how these logical components are mapped to specific hardware resources, such as which LUTs are used to implement combinational logic, which BRAMs are used to store rule tables, and how to lay out and route them to meet timing requirements. The configuration data contains configuration information for each resource unit within the programmable region, specifying which lookup tables are configured for which logical functions, and which storage units are initialized with what content, among other detailed hardware configuration parameters.

[0068] The hardware configuration data is transmitted to the target programmable area via a reconfiguration interface. After the hardware configuration data is loaded, the hardware acceleration logic components in the target programmable area are activated and functional verification is performed. After successful functional verification, the hardware acceleration logic is integrated into the network traffic processing path. Modern FPGAs and accelerator cards typically support partial reconfiguration, allowing reconfiguration of certain areas during system operation without affecting the operation of other areas. The reconfiguration interface is a dedicated hardware channel through which configuration data is written in bitstream form to the configuration memory of the target programmable area, changing the hardware logic function of that target programmable area. After the hardware configuration data is loaded, the internal logic of the target programmable area has been reconfigured, but it cannot be used directly at this time. The system needs to activate the hardware acceleration logic components in the target programmable area, which includes initialization operations such as starting the clock signal, resetting the relevant state machine, and enabling various functional modules. After activation, functional verification must be performed to confirm that the hardware acceleration logic works correctly as expected. Only after successful functional verification will the hardware acceleration logic be integrated into the network traffic processing path. This integration process requires configuring data routing to ensure network traffic is correctly directed to the newly loaded hardware acceleration logic, and configuring output paths to ensure processed results are passed to the next processing unit or output to the network. Once integration is complete, the hardware acceleration logic begins performing security checks on actual network traffic.

[0069] The method for performing functional verification includes:

[0070] A set of test vectors is generated based on the detection rules. This set includes normal network traffic patterns and abnormal traffic patterns containing security threats. The test vectors are specially designed test data used to verify the proper functioning of the hardware acceleration logic. The test vector set contains two main categories of test samples: one category consists of test vectors for normal network traffic patterns, simulating normal network communication data packets. These test vectors are judged as safe traffic by the hardware acceleration logic and do not trigger any detection alarms. The other category consists of test vectors for abnormal traffic patterns containing security threats. These vectors intentionally include threat characteristics defined in the detection rules, such as attack signatures and abnormal behavior patterns, which the hardware acceleration logic can accurately identify. For example, if the detection rule is to identify SQL injection attacks, the test vector set will include normal database query requests as normal samples and various SQL injection attack statements as abnormal samples, including various variations such as injection based on join queries, Boolean-based blind injection attacks, and time-delay-based injection, ensuring comprehensive testing. After generating the test vector set, the system inputs this test data into the activated hardware acceleration logic functional components. The hardware-accelerated logic processes each test vector as if it were real network traffic, performing detection and judgment operations and outputting processing results. These results include information such as whether the test vector was determined to be a threat, which detection rules were triggered, and what processing actions were performed.

[0071] The set of test vectors is input into the activated hardware acceleration logic function component to obtain the processing results of the test vectors. The processing results are compared and analyzed with the expected results. Based on the comparison and analysis results, the accuracy index of the function verification is calculated. When the accuracy index reaches the preset verification accuracy threshold, the function verification is considered successful. When the function verification fails, the failed test vectors are recorded and a reconfiguration process is triggered. After collecting the processing results of all test vectors, the system compares and analyzes them with the expected results. Each test vector has a pre-set correct answer; for example, the expected result for a normal traffic vector is "determined as safe, no processing required," and the expected result for an attack vector is "identified as an SQL injection attack, execute the discard action." The actual processing results are compared with the expected results one by one to determine how many test vectors were processed completely correctly and how many had misjudgments, omissions, or incorrect processing. Based on the comparison and analysis results, the accuracy index of the function verification is calculated. The accuracy is calculated by dividing the number of correctly processed test vectors by the total number of test vectors, resulting in a percentage value. A preset verification accuracy threshold, such as 95% or 98%, is set. Functional verification is considered successful only when the calculated accuracy reaches or exceeds this threshold, indicating that the hardware acceleration logic is correctly and reliably implemented. Failure to verify indicates an implementation error or functional defect in the hardware acceleration logic. The system records all failed test vectors—those test samples whose processing results do not match expectations—providing clues for problem diagnosis. Simultaneously, the system triggers a reconfiguration process, reverting to the current hardware configuration, regenerating hardware configuration data, correcting any identified issues, and re-executing the loading and verification process until functional verification succeeds. This ensures that only fully tested and correctly functioning hardware acceleration logic is applied to actual network traffic processing, guaranteeing system reliability and security.

[0072] Example 2: Based on the same inventive concept, such as Figure 2 As shown, this embodiment also provides a network traffic deep processing system based on dynamic policy-driven methods. The system includes: a dynamic policy receiving and parsing module, a candidate programmable region filtering module, a target programmable region selection module, and a network traffic analysis and processing module, with each module connected in a sequential communication manner.

[0073] The dynamic policy receiving and parsing module is used to receive dynamic policies triggered by security threat intelligence, the dynamic policies containing security threat detection rules and corresponding processing actions; generate corresponding hardware acceleration logic according to the detection rules in the dynamic policies, and determine the resource requirements required to execute the hardware acceleration logic, the resource requirements including computing resources and storage resources.

[0074] The candidate programmable region filtering module is used to obtain real-time resource status data of each programmable region in the accelerator card, and filter out candidate programmable regions that meet the resource requirements from all programmable regions based on the resource requirements and the real-time resource status data.

[0075] The target programmable region selection module is used to perform multi-dimensional cost evaluation on each candidate programmable region to obtain multi-dimensional cost evaluation results. The multi-dimensional cost evaluation includes communication cost, timing cost, and resource fragmentation cost. The target programmable region is selected from the candidate programmable regions based on the multi-dimensional cost evaluation results.

[0076] The network traffic analysis and processing module is used to dynamically load the hardware acceleration logic into the target programmable area; perform deep detection of network traffic through the loaded hardware acceleration logic, and identify security threats in the network traffic according to the detection rules; when a security threat is identified, execute the corresponding processing action in the dynamic policy.

[0077] It should be noted that the specific methods by which each module performs operations in the system described in the above embodiments have been described in detail in the embodiments related to the method, and will not be elaborated here.

[0078] Finally, it should be noted that although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for deep processing of network traffic based on dynamic policy-driven approaches, characterized in that: The method includes: Receive dynamic policies triggered by security threat intelligence, the dynamic policies containing security threat detection rules and corresponding processing actions; generate corresponding hardware acceleration logic according to the detection rules in the dynamic policies, and determine the resource requirements required to execute the hardware acceleration logic, the resource requirements including computing resources and storage resources; Obtain real-time resource status data of each programmable region in the accelerator card, and filter out candidate programmable regions that meet the resource requirements from all programmable regions based on the resource requirements and the real-time resource status data. A multi-dimensional cost evaluation is performed on each candidate programmable region to obtain a multi-dimensional cost evaluation result, which includes communication cost, timing cost, and resource fragmentation cost; a target programmable region is selected from the candidate programmable regions based on the multi-dimensional cost evaluation result; The hardware acceleration logic is dynamically loaded into the target programmable area; the loaded hardware acceleration logic is used to perform deep inspection of network traffic and identify security threats in the network traffic according to the detection rules; when a security threat is identified, the corresponding processing action in the dynamic policy is executed. The method for selecting candidate programmable regions that meet the resource requirements from all programmable regions based on the resource requirements and real-time resource status data includes: A programmable region resource map is constructed based on the real-time resource status data. Based on the resource requirements, the resource form similarity between the existing resource distribution of each programmable region in the programmable region resource map and the resource and storage resource requirements calculated in the resource requirements is calculated. The dynamic change trend of resource requirements is also calculated to match the resource release mode of the programmable region. Resource form similarity refers to the distribution form and composition structure of resources in the spatial dimension. Programmable regions with resource morphological similarity greater than a preset morphological similarity threshold and resource matching degree greater than a preset matching degree threshold are selected as candidate programmable regions. The method for constructing a programmable regional resource map based on the real-time resource status includes: The real-time resource status data includes the computing resource dimension characteristics, storage resource dimension characteristics, and current workload status of each programmable region; the topological connection relationship between programmable regions is established according to the physical layout of the accelerator card; A multi-dimensional resource feature vector is constructed based on the real-time resource status data and topological connectivity. The multi-dimensional resource feature vector includes the static resource attributes and dynamic operating status of the programmable region. The multi-dimensional resource feature vector is then integrated with the topological connectivity to obtain a programmable region resource map.

2. The method for deep processing of network traffic based on dynamic policy-driven approach according to claim 1, characterized in that, The method for constructing a multidimensional resource feature vector based on the real-time resource status data and topological connectivity includes: The computing resource dimension features and storage resource dimension features are extracted from the real-time resource status data. The computing resource dimension features include the available number and distribution density of different types of computing units, and the storage resource dimension features include the available capacity and access latency of different levels of storage units. Dynamic operating features are extracted from the current workload status, including resource utilization fluctuations and historical load change trends. After normalization of the computing resource dimension features, storage resource dimension features, and dynamic operating features, a weighted combination is performed to obtain a multi-dimensional resource feature vector.

3. The method for deep processing of network traffic based on dynamic policy-driven approach according to claim 1, characterized in that, The method for determining the resource consistency between the dynamic trend of computing resource demand and the resource release mode of programmable area includes: A resource release behavior model for programmable regions is established based on historical resource usage data. The resource release behavior model records the resource release patterns and response latency characteristics of each programmable region under different workload states. Extract the dynamic resource change characteristics during the execution of hardware acceleration logic from the resource requirements. The dynamic resource change characteristics include the fluctuation period of resource requirements and the duration of peak resource requirements. The matching degree between the dynamic change characteristics of the resources and the resource release behavior model of each programmable region is calculated to obtain the resource release pattern matching degree.

4. The method for deep processing of network traffic based on dynamic policy-driven approach according to claim 3, characterized in that, The method for calculating the matching degree between the dynamic change characteristics of the resources and the resource release behavior model of each programmable region to obtain the resource release pattern fit degree includes: Based on the response delay characteristics in the resource release behavior model, the dynamic change characteristics of resources are aligned and compensated on the time axis to establish the resource demand time series curve after alignment and compensation; the resource release rules of the programmable area under the corresponding workload state are extracted to generate the resource supply time series curve. The covariance matrix of the resource demand time series curve and the resource supply time series curve within the same time window is calculated. By analyzing the eigenvalue distribution of the covariance matrix, the trend consistency assessment result of the resource demand time series curve and the resource supply time series curve is obtained. The intersection ratio of the peak demand period of the resource demand time series curve and the high availability period of the resource supply time series curve is calculated to obtain the guarantee level assessment result of peak resource demand. The trend consistency assessment result and the guarantee level assessment result are weighted and fused to obtain the resource release pattern matching degree.

5. The method for deep processing of network traffic based on dynamic policy-driven approach according to claim 1, characterized in that, The method for dynamically loading the hardware acceleration logic into the target programmable region includes: Based on the functional characteristics of the hardware acceleration logic and the resource characteristics of the target programmable region, corresponding hardware configuration data is generated. The hardware configuration data is transmitted to the target programmable area through the reconfiguration interface; after the hardware configuration data is loaded, the hardware acceleration logic function component in the target programmable area is activated and the function is verified. After the function verification is passed, the hardware acceleration logic is integrated into the network traffic processing path.

6. The method for deep processing of network traffic based on dynamic policy-driven approach according to claim 5, characterized in that, The method for performing functional verification includes: A corresponding set of test vectors is generated based on the detection rules. The set of test vectors includes normal network traffic patterns and abnormal traffic patterns containing security threats. The test vector set is input into the activated hardware acceleration logic function component to obtain the processing result of the test vectors. The processing result is compared and analyzed with the expected result. The accuracy index of the function verification is calculated based on the comparison and analysis result. When the accuracy index reaches the preset verification accuracy threshold, the function verification is determined to be passed. When the function verification fails, the failed test vector is recorded and the reconfiguration process is triggered.

7. A network traffic deep processing system based on dynamic policy-driven methods, characterized in that: The system includes: a dynamic policy receiving and parsing module, a candidate programmable region filtering module, a target programmable region selection module, and a network traffic analysis and processing module, with each module connected in sequence. The dynamic policy receiving and parsing module is used to receive dynamic policies triggered by security threat intelligence, the dynamic policies containing security threat detection rules and corresponding processing actions; generate corresponding hardware acceleration logic according to the detection rules in the dynamic policies, and determine the resource requirements required to execute the hardware acceleration logic, the resource requirements including computing resources and storage resources; The candidate programmable region filtering module is used to obtain real-time resource status data of each programmable region in the accelerator card, and filter out candidate programmable regions that meet the resource requirements from all programmable regions based on the resource requirements and real-time resource status data. The target programmable region selection module is used to perform multi-dimensional cost evaluation on each candidate programmable region to obtain multi-dimensional cost evaluation results, wherein the multi-dimensional cost evaluation includes communication cost, timing cost and resource fragmentation cost; and select a target programmable region from the candidate programmable regions based on the multi-dimensional cost evaluation results. The network traffic analysis and processing module is used to dynamically load the hardware acceleration logic into the target programmable area; perform deep detection of network traffic through the loaded hardware acceleration logic, identify security threats in the network traffic according to the detection rules; and execute the corresponding processing action in the dynamic policy when a security threat is identified. The method for selecting candidate programmable regions that meet the resource requirements from all programmable regions based on the resource requirements and real-time resource status data includes: A programmable region resource map is constructed based on the real-time resource status data. Based on the resource requirements, the resource form similarity between the existing resource distribution of each programmable region in the programmable region resource map and the resource and storage resource requirements calculated in the resource requirements is calculated. The dynamic change trend of resource requirements is also calculated to match the resource release mode of the programmable region. Resource form similarity refers to the distribution form and composition structure of resources in the spatial dimension. Programmable regions with resource morphological similarity greater than a preset morphological similarity threshold and resource matching degree greater than a preset matching degree threshold are selected as candidate programmable regions. The method for constructing a programmable regional resource map based on the real-time resource status includes: The real-time resource status data includes the computing resource dimension characteristics, storage resource dimension characteristics, and current workload status of each programmable region; the topological connection relationship between programmable regions is established according to the physical layout of the accelerator card; A multi-dimensional resource feature vector is constructed based on the real-time resource status data and topological connectivity. The multi-dimensional resource feature vector includes the static resource attributes and dynamic operating status of the programmable region. The multi-dimensional resource feature vector is then integrated with the topological connectivity to obtain a programmable region resource map.

Citation Information

Patent Citations

  • Network information security protection method and system based on artificial intelligence dynamic defense

    CN120165968A

  • Heterogeneous computing resource management method and device, equipment and storage medium

    CN120872596A