A method, system, product, and medium for automatic generation and verification of network policies.

By sending baseline and feature detection streams from edge nodes, link limitations are identified and addressed, ensuring that high-priority business data packets are transmitted completely and transparently in the enterprise's distributed network. This solves the problem of network policy inconsistency caused by intermediate devices and improves transmission quality and stability.

CN121530716BActive Publication Date: 2026-05-26LINGBO TECH (BEIJING) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
LINGBO TECH (BEIJING) CO LTD
Filing Date
2025-12-09
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

In enterprise distributed networks, unmanaged intermediate devices cause high-priority business data packets to be silently lost or stripped due to hardware limitations, resulting in inconsistencies between the network policy execution effect and the monitoring status.

Method used

By sending baseline and feature detection streams through edge nodes, link restriction types are identified, and targeted fragmentation adaptation or tunnel hiding encapsulation is implemented to ensure that high-priority service labels are transmitted completely.

Benefits of technology

It improves the consistency between network policy execution results and monitoring status, avoids service QoS failures caused by intermediate device limitations, and enhances transmission quality and stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121530716B_ABST
    Figure CN121530716B_ABST
Patent Text Reader

Abstract

A method, system, product, and medium for automatic generation and verification of network policies are disclosed, relating to the field of computer network communication. The method includes: controlling edge nodes to send unlabeled standard-size baseline probe streams and labeled full-size feature probe streams to terminal plug-ins; if only the baseline stream is connected, the link is marked as blocking-type restricted; if both are connected but feature stream labels are missing, it is marked as stripped-type restricted; for blocking links, encapsulation conforming to a size threshold is used; for stripped links, tunneling protocol-based label-hiding encapsulation is used; the encapsulated data packets are sent to the terminal plug-in to remove the outer protocol layer and restore the original service data packets, verifying header integrity; if the priority label is abnormal, an alarm is triggered and the protocol type is switched. Implementing the technical solution provided in this application improves the consistency of network policy execution effect and monitoring status.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer network communication, and in particular to a method, system, product, and medium for automatically generating and verifying network policies. Background Technology

[0002] Currently, with the deepening of enterprise digital transformation, large chain operations (such as retail, catering, and logistics outlets) are increasingly reliant on wide area network (WAN) interconnection. To ensure the efficient operation of core businesses such as point-of-sale (POS) settlement, inventory synchronization, and remote video monitoring, building a distributed enterprise network has become a key infrastructure supporting business continuity.

[0003] In related technologies, a centralized management and control solution based on Software-Defined Wide Area Network (SD-WAN) is typically used to implement the operation and maintenance of multi-branch networks. A central controller deployed in the cloud maintains a global network topology view and, based on preset service intent templates, uniformly distributes traffic scheduling and Quality of Service (QoS) policies (e.g., assigning high priority to voice traffic) to the edge gateway devices (CPEs) of each branch. Simultaneously, standard probing protocols such as Bidirectional Forwarding Detection (BFD) or ICMP Echo are used to periodically detect link connectivity and packet loss rates between edge gateways or between gateways and core devices. Routing paths are dynamically adjusted based on real-time detection data to ensure that network configuration remains consistent with the expected service policies.

[0004] However, when unmanaged Layer 2 transparent forwarding devices (such as unmanaged switches or hubs) exist between the branch office's edge gateway and the service terminals, these devices are invisible in the controller's logical topology. If the issued service policy requires data packets to carry specific protocol fields (such as VLAN tags) or have a large frame length, and the hardware specifications of the aforementioned invisible intermediate devices are limited and do not support these characteristics, silent packet loss or field stripping will occur. In this case, since standard probe packets are usually short packets and do not carry complex service attributes, they can still successfully penetrate the device, causing monitoring indicators to show that the network is normal, but in reality, high-priority service data is difficult to transmit, resulting in a decrease in the consistency between the network policy execution effect and the monitoring status. Summary of the Invention

[0005] This application provides a method, system, product, and medium for automatically generating and verifying network policies, which can improve the consistency between the execution effect and monitoring status of network policies.

[0006] The first aspect of this application provides a method for automatically generating and validating network policies, the method comprising:

[0007] The control edge node sends a baseline probe stream and a feature probe stream to the terminal plug-in and obtains the transmission results. If the baseline probe stream is connected but the feature probe stream is not, the link between the edge node and the terminal plug-in is marked as a blocking restricted link. If both the baseline probe stream and the feature probe stream are connected, but the feature probe stream received by the terminal plug-in lacks a specific service label, the link between the edge node and the terminal plug-in is marked as a stripped restricted link. In response to the link being marked as a blocking restricted link, the blocking restricted link is encapsulated using a size threshold conforming to the baseline probe stream to obtain an encapsulated data packet. In response to the link being marked as a stripped restricted link, a tunneling protocol is used to hide the specific service label on the stripped restricted link to obtain an encapsulated data packet. The encapsulated data packet is sent to the terminal plug-in. The terminal plug-in receives the encapsulated data packet, removes the outer transport protocol message, and obtains the original service data packet carrying a high-priority label. The original service data packet is obtained, and the integrity of the header fields is verified. If the priority label of the original service data packet is inconsistent with the preset value, an alarm is triggered and the encapsulation protocol type is switched.

[0008] In the above embodiments, by utilizing the differentiated performance of the benchmark and feature detection streams, implicit blocking or label stripping restrictions in the link are identified, and fragmentation adaptation or tunnel hiding encapsulation are implemented accordingly. This ensures that service data packets can circumvent the physical limitations or cleaning strategies of intermediate devices, allowing high-priority service labels to be completely transmitted to the terminal. This avoids soft faults where the network is connected but the service QoS fails, ensuring that the actual transmission quality matches the preset policy expectations, and ultimately improving the consistency between the network policy execution effect and the monitoring status.

[0009] In conjunction with some embodiments of the first aspect, in some embodiments, in response to a link being marked as a stripped-down restricted link, a tunneling protocol is used to hide specific service labels on the stripped-down restricted link to obtain encapsulated data packets, specifically including:

[0010] Multiple protocol spoofing detection streams are constructed, each simulating the header and payload statistics of Hypertext Transfer Protocol (HTTP), Domain Name System (DNS), and Encrypted Transport Protocol (ETH). Edge nodes are controlled to send these detection streams to terminal plugins, and the transmission jitter and throughput attenuation rates of each stream are obtained from the terminal plugins. Based on these jitter and throughput attenuation rates, the protocol type with the highest transmission affinity is selected as the target spoofing protocol from the protocol types corresponding to the detection streams. The original business data packets carrying high-priority tags are fragmented, and the fragmented data is used as the application layer payload, encapsulated in the payload field of the target spoofing protocol, and the corresponding standard header is added to generate the encapsulated data packet.

[0011] In the above embodiments, the multi-protocol spoofing probe stream is used to actively assess the network’s scrutiny of different application layer protocols and selects the protocol with the highest transmission affinity as the spoofing shell. The business traffic is dynamically disguised as compliant traffic with the least interference in the current network environment, thereby avoiding blocking or rate limiting for specific protocols and improving the survivability and transmission stability of business data in strong scrutiny or complex network environments.

[0012] In conjunction with some embodiments of the first aspect, in some embodiments, after selecting the protocol type with the highest transmission affinity from the protocol types corresponding to the protocol spoofing detection stream as the target spoofing protocol, the method further includes:

[0013] When the target masquerading protocol is a plaintext application layer protocol, a dynamic entropy value identifier is injected into the resource locator of the target masquerading protocol and an integrity check code is embedded in the payload field when generating the encapsulated data packet; the protocol response message fed back by the terminal plugin to the encapsulated data packet is obtained; if the status code of the protocol response message indicates successful transmission, but the protocol response message lacks the acknowledgment verification information corresponding to the dynamic entropy value identifier, or the payload content of the protocol response message presents the characteristics of the intermediate device's redirection page, the target masquerading protocol is forcibly switched to an encrypted transmission protocol, and the original business data packet is encapsulated into the encrypted payload of the encrypted transmission protocol.

[0014] In the above embodiments, a closed-loop verification mechanism using dynamic entropy values ​​and checksums is employed to identify transparent proxying or content hijacking of plaintext traffic by intermediate devices, determining "false connections" where the status code is normal but the content has been tampered with. Once an abnormal receipt or redirection characteristic is detected, a forced switch to an encrypted transmission channel is initiated, breaking the concealment of man-in-the-middle attacks. Furthermore, dynamic protocol upgrades shield against malicious tampering, thereby ensuring the integrity and transmission security of business data in an untrusted network environment.

[0015] In conjunction with some embodiments of the first aspect, in some embodiments, in response to a link being marked as a blocking restricted link, the blocking restricted link is encapsulated using a size threshold conforming to a baseline probe flow to obtain encapsulated data packets, specifically including:

[0016] The control edge node sends multiple sets of reference probe streams at a preset gradient increment rate and calculates the round-trip delay variance of each set of reference probe streams. If the round-trip delay variance exceeds a preset congestion jitter threshold, and the packet loss rate of the reference probe stream shows a positive linear correlation with the gradient increment rate, the token filling rate of the traffic shaping device is calculated based on the rate inflection point where the round-trip delay variance changes abruptly. According to the token filling rate and the preset fragmentation size, the target transmission time interval for maintaining the link in a non-congested state is calculated. The original service data packets are divided into multiple small fragments using the preset fragmentation size, and the small fragments are discretized, encapsulated, and transmitted according to the target transmission time interval.

[0017] In the above embodiments, the token filling rate of intermediate devices is inferred from the abrupt change points of the delay variance detected by gradient probing, and a discrete fragmentation and transmission strategy is constructed accordingly. This reshapes the originally bursty large packet traffic into a smooth pulse flow that adapts to the physical bottleneck of the link. Thus, without triggering congestion queuing or rate-limited packet loss in intermediate devices, the effective bandwidth of the limited link is utilized, solving the problem of transmission interruption caused by MTU limitation and traffic shaping in harsh network environments, and improving the penetration ability and transmission stability of service data in heterogeneous networks.

[0018] In conjunction with some embodiments of the first aspect, in some embodiments, after dividing the original service data packet into multiple small fragments using a preset fragmentation size, and discretizing and encapsulating the small fragments according to the target transmission time interval, the method further includes:

[0019] The full transmission time is obtained by multiplying the total number of fragments after the original service data packet is segmented by the target transmission time interval. When the full transmission time exceeds the preset intermediate device reassembly timeout threshold, a target stateless protocol with single-packet interaction characteristics is selected from the preset stateless protocol feature library, and an atomic independent encapsulation strategy is constructed. An independent application layer header is added to each tiny fragment using a header template, and the corresponding logical sequence number is injected into the transaction identifier field to generate multiple stateless protocol messages. The stateless protocol messages are sent to the terminal plugin according to the target transmission time interval.

[0020] In the above embodiments, when excessive transmission time is detected, the associated fragmented data is converted into independent stateless protocol messages and atomically encapsulated. The transaction identifier carries the logical sequence, making each fragment an independent transaction in the eyes of the intermediate device without waiting for context. This eliminates the need for the intermediate device to reassemble fragments, ensuring that even if the data packets are transmitted discretely at extremely low rates, the reassembly timeout and packet loss mechanism of the intermediate device will not be triggered. This breaks through the reassembly deadlock limitation under low-speed links and ensures the reliable delivery of large-size service data in extremely restricted networks.

[0021] In conjunction with some embodiments of the first aspect, in some embodiments, after triggering an alarm and switching the encapsulation protocol type, the method further includes:

[0022] Based on the historical throughput model of the original service data packets, a background mimicry noise stream with the same bandwidth characteristics is generated, and the background mimicry noise stream and the encapsulated data packets are injected concurrently into the link; the transmission quality index of the encapsulated data packets during the existence of the background mimicry noise stream is statistically analyzed; when the transmission quality index is lower than the preset no-load benchmark value, the adaptive encapsulation strategy is adjusted to a constant bit rate obfuscation mode, and invalid data is filled in to maintain the transmission rate at the service peak level.

[0023] In the above embodiments, by filling in invalid data, the bursts and waveform characteristics of the service traffic are smoothed out, and it becomes a constant flow that cannot be matched by features in the eyes of intermediate devices. This disables the QoS control mechanism based on traffic fingerprinting, improves the concealment of the service flow in complex network environments, and ensures transmission stability and high priority treatment in strong traffic control scenarios.

[0024] In conjunction with some embodiments of the first aspect, in some embodiments, after the tunneling protocol used hides specific service labels on the stripped-down restricted link and obtains the encapsulated data packet, the method further includes:

[0025] Extract the source port number of the probe data packet that was successfully connected in the baseline probe stream and use it as the path affinity identifier; forcibly overwrite the source port number of the outer transport protocol message of the encapsulated data packet with the path affinity identifier, map the encapsulated data packet to the same physical transport path as the baseline probe stream; inject a stream type distinguisher into the payload header of the encapsulated data packet.

[0026] In the above embodiments, by utilizing the consistency of five-tuple hashes, service flows can reside on established firewall channels or load-balanced paths, thereby avoiding path drift or session reconstruction failures caused by port changes. This solves the connectivity jitter problem in multi-path networks and ensures deterministic transmission and real-time connectivity of service data in complex routing environments.

[0027] In a second aspect, embodiments of this application provide an automatic network policy generation and verification system, which includes: one or more processors and a memory; the memory is coupled to the one or more processors and is used to store computer program code, which includes computer instructions, and the one or more processors call the computer instructions to cause the automatic network policy generation and verification system to perform the method described in the first aspect and any possible implementation thereof.

[0028] Thirdly, embodiments of this application provide a computer program product containing instructions that, when the computer program product is run on a network policy automatic generation and verification system, cause the network policy automatic generation and verification system to execute the method described in the first aspect and any possible implementation thereof.

[0029] Fourthly, embodiments of this application provide a computer-readable storage medium including instructions that, when executed on a network policy automatic generation and verification system, cause the network policy automatic generation and verification system to perform the method described in the first aspect and any possible implementation thereof.

[0030] Understandably, the network policy automatic generation and verification system provided in the second aspect, the computer program product provided in the third aspect, and the computer storage medium provided in the fourth aspect are all used to execute the network policy automatic generation and verification method provided in the embodiments of this application. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.

[0031] One or more technical solutions provided in the embodiments of this application have at least the following technical effects or advantages:

[0032] 1. This application utilizes the differentiated performance of benchmark and feature detection streams to identify implicit blocking or label stripping restrictions in the link, and accordingly implements fragmentation adaptation or tunnel-hidden encapsulation. This ensures that service data packets can circumvent the physical limitations or cleaning strategies of intermediate devices, allowing high-priority service labels to be completely transmitted to the terminal. This avoids soft faults where the network is connected but the service QoS fails, ensuring that the actual transmission quality matches the preset policy expectations, and ultimately improving the consistency between network policy execution effect and monitoring status.

[0033] 2. This application proactively assesses the network's scrutiny of different application layer protocols through multi-protocol spoofing detection flow, and selects the protocol with the highest transmission affinity as the spoofing shell, dynamically disguising business traffic as compliant traffic with the least interference in the current network environment, thereby avoiding blocking or rate limiting for specific protocols and improving the survivability and transmission stability of business data in strong scrutiny or complex network environments.

[0034] 3. This application uses a closed-loop verification mechanism based on dynamic entropy values ​​and checksums to identify transparent proxying or content hijacking of plaintext traffic by intermediate devices, and to determine "false connections" where the status code is normal but the content has been tampered with. Once abnormal receipts or redirection characteristics are detected, a forced switch to an encrypted transmission channel is initiated, breaking the concealment of man-in-the-middle attacks. Furthermore, dynamic protocol upgrades shield against malicious tampering, thereby ensuring the integrity and transmission security of business data in untrusted network environments. Attached Figure Description

[0035] Figure 1 This is a flowchart illustrating the automatic generation and verification method for network policies in an embodiment of this application;

[0036] Figure 2 This is another flowchart illustrating the automatic generation and verification method of network policies in this application embodiment;

[0037] Figure 3 This is an exemplary hardware structure diagram of the network policy automatic generation and verification system in the embodiments of this application. Detailed Implementation

[0038] The terminology used in the following embodiments of this application is for the purpose of describing particular embodiments only and is not intended to be limiting of this application. As used in the specification and appended claims of this application, the singular expressions “a,” “an,” “the,” “the,” “the,” and “this” are intended to include the plural expressions as well, unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in this application refers to and includes any or all possible combinations of one or more of the listed items.

[0039] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as implying or suggesting relative importance or implicitly indicating the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature, and in the description of the embodiments of this application, unless otherwise stated, "multiple" means two or more.

[0040] In related technologies, QoS policies are typically issued to edge gateways based on the global view of the SD-WAN controller, and link connectivity is detected using standard protocols such as ICMP or BFD. However, this mechanism has a blind spot: when there is an invisible, unmanaged intermediate device between the edge gateway and the terminal, if the device does not support large frame lengths or specific service tags (such as VLAN tags) due to hardware limitations, it will silently drop or strip service data packets. Since standard probe packets are usually short and do not carry service attributes, they can still successfully penetrate the device, causing the controller to mistakenly judge the network as normal, while high-priority services are actually blocked. This phenomenon of "connected but not reaching" causes a disconnect between network monitoring metrics and actual service experience, reducing the consistency between policy execution and monitoring status.

[0041] In this embodiment, by controlling edge nodes to concurrently send unlabeled baseline probe streams and full-size feature probe streams carrying specific labels, implicit blocking or stripping restrictions in the link are identified. Once an anomaly is detected, the encapsulation strategy is dynamically adjusted according to the link characteristics: for blocking links, a size encapsulation conforming to the threshold is used; for stripping links, a tunneling protocol is used to hide the label. This mechanism ensures that service data can bypass the physical bottlenecks or cleaning strategies of intermediate devices, allowing high-priority labels to be transmitted back to the terminal intact, thereby eliminating soft faults where the network is connected but the service is not, and improving the consistency between network policy execution effect and monitoring status.

[0042] Figure 1 This is a flowchart illustrating the automatic generation and verification method for network policies in this application, including the following steps:

[0043] S101. Control the edge node to send the baseline probe stream and feature probe stream to the terminal plug-in, and obtain the transmission results.

[0044] In this context, edge nodes refer to network access devices deployed at enterprise branches or stores, such as SD-WAN CPEs or gateway devices; terminal plug-ins refer to lightweight software agents running on business terminals (such as cash registers and office PCs) to cooperate with edge nodes for end-to-end network quality monitoring; baseline probe streams refer to data streams used to probe basic network connectivity, typically consisting of ICMP or UDP protocols; standard size refers to the size of a data packet conforming to the Ethernet minimum transmission unit or regular transmission unit, such as 64 bytes or 128 bytes, which is a preset value, usually set based on RFC standard documents or extensive live network testing experience; feature probe streams refer to data streams used to probe the network's ability to process special packets; specific service tags refer to QoS tags used to identify service priorities, such as DSCP (Differential Service Code Point) or VLAN tags; full size refers to the size of a data packet close to the link's maximum transmission unit (MTU), such as 1500 bytes, which is a preset value, usually set based on the Ethernet standard MTU value.

[0045] The edge node first generates two different sets of data packet sequences according to the preset detection strategy.

[0046] The first group is the baseline probe flow. Edge nodes construct standard IP packets, set the TOS / DSCP field in the IP header to 0 (Best Effort), and fill the payload to the standard size, aiming to simulate the most common network traffic to obtain the basic connectivity status of the link.

[0047] The second group is the feature detection flow. Edge nodes construct IP packets with specific attributes, modify the DSCP field in the IP header to the value corresponding to high-priority services (such as EF or AF41), and fill the payload to a full size close to the MTU limit, aiming to simulate real high-priority large packet service traffic.

[0048] Edge nodes send these two sets of probe streams concurrently or sequentially, and start timers to listen for feedback signals or echo responses from terminal plugins. Transmission results are obtained by statistically analyzing metrics such as packet loss rate and latency.

[0049] In some embodiments, controlling edge nodes to send probe streams can be achieved in a variety of ways:

[0050] Optionally, ICMP protocol can be used for probing: 1. The edge node constructs ICMP Echo Request messages, one set of which is 64 bytes with a TOS field of 0, and the other set of which is 1472 bytes (1500 bytes including the header) with a TOS field of 46; 2. The edge node sends the above ICMP messages to the IP address of the terminal plugin and records the sending timestamp; 3. The edge node receives the ICMP Echo Reply messages returned by the terminal plugin and calculates the round-trip time and packet loss.

[0051] It is understandable that probe streams can also be sent using TCP SYN / ACK handshake packets or custom protocol probes, and this is not a limitation here.

[0052] S102. When the baseline probe stream is connected and the feature probe stream is not connected, mark the link between the edge node and the terminal plug-in as a blocking restricted link.

[0053] Among them, connectivity refers to the successful arrival of data packets from the source to the destination and the receipt of acknowledgment feedback; disconnection refers to the loss, timeout, or explicit rejection of data packets by intermediate devices during transmission; blocking restricted links refer to a link state where, although the physical link is open, data packets with specific characteristics (such as large packets or specific tags) cannot pass due to configuration limitations of intermediate network devices (such as firewalls and routers) (such as MTU limits or ACL policies); tagging refers to attaching specific attribute tags to the link in the link state database for subsequent use by the policy engine.

[0054] Logical judgment is made by comparing the transmission results of the baseline probe stream and the feature probe stream. When the packet loss rate of the baseline probe stream (small packet, unlabeled) is lower than the preset packet loss rate threshold (this threshold is usually determined based on long-term quality statistics and service tolerance experiments of a large number of live network links, indicating that the basic network layer is reachable and the route is correct), it means that the basic network layer is reachable and the route is correct.

[0055] At this point, if the packet loss rate of the feature-detection flow (large packets, tagged) is extremely high (e.g., 100%) or completely unresponsive, it is determined that the link is being targeted for blocking. This blocking is usually not a physical failure, but rather due to the presence of devices on the intermediate path that do not support large MTUs, causing fragments to be dropped, or firewall policies that are blocking traffic with specific DSCP tags. Based on this, the link's status is updated to blocking-restricted, and this status will serve as the basis for subsequent decisions regarding triggering fragmentation encapsulation or MSS adjustment policies.

[0056] S103. When both the baseline probe stream and the feature probe stream are connected, but the feature probe stream received by the terminal plugin is missing a specific service label, mark the link between the edge node and the terminal plugin as a stripped-off restricted link.

[0057] Among them, "missing" means that when a data packet arrives at its destination, the value in the header field is inconsistent with the initial value when it was sent, specifically that it is reset to the default value; "specific service label" refers to the high-priority QoS mark set in S101; "stripped restricted link" means that there is a cleaning device in the middle of the link, which modifies or clears specific header fields of the data packet, but does not discard the link state of the data packet.

[0058] When both sets of probe streams in S101 successfully reach the terminal plugin, it indicates that there is no hard blocking policy on the link. At this point, the terminal plugin needs to deeply parse the IP header of the received probe streams.

[0059] The terminal plugin reads the TOS / DSCP field value from the IP header and compares it with the preset expected value (i.e., the value set by the sender). If the sender sets it to EF (Expedited Forwarding, corresponding to a value of 46), while the receiver reads CS0 (corresponding to a value of 0), it indicates that an edge router of the operator or an internal cleaning device in the link is performing "QoS Bleaching." Although the service can continue, high-priority guarantees fail. The link is marked as stripped and restricted, a state that will trigger subsequent tunnel hiding strategies.

[0060] In some embodiments, the determination and marking of stripped links can be achieved in multiple ways:

[0061] Optional, field comparison based on terminal feedback: 1. The terminal plugin parses the received feature detection packet, extracts the DSCP value, and writes it into the payload of the feedback message and returns it to the edge node; 2. The edge node receives the feedback message and compares the DSCP value sent with the received DSCP value; 3. If the two are not equal and the received value is 0, then mark it as "Tag_Stripped" in the link attribute table of the controller.

[0062] It is understandable that marking can also be achieved by means of two-way probe verification (i.e., sending confirmation in reverse), and this is not limited here.

[0063] S104. In response to the link being marked as a blocking restricted link, the blocking restricted link is encapsulated using a size threshold that conforms to the reference probe flow to obtain encapsulated data packets.

[0064] Among them, response refers to the action of automatically triggering the corresponding processing logic after the system detects a specific status flag; size threshold refers to the data packet size of the reference probe flow that is verified as passable in S101, or the secure transmission unit size calculated by the path MTU discovery mechanism; encapsulation refers to the process of adding a new protocol header to the outside of the original data packet to adapt to the transmission environment.

[0065] When a link is marked as blocking-restricted, it means that the original full-size service packets cannot pass directly. The size of the baseline probe stream is read as the security MTU threshold for that link. When processing subsequent original service packets, the edge node checks the packet length. If the total length of the original packet plus the encapsulation header exceeds this threshold, a fragmentation or segmentation mechanism is initiated. The original large packet is cut into several smaller pieces smaller than the threshold, and a tunnel header (such as a VXLAN or IPsec header) is added to each piece, ensuring that the physical size of the final encapsulated packet is strictly smaller than the link's restriction threshold, thereby avoiding packet loss behavior from intermediate devices.

[0066] S105. In response to the link being marked as a stripped-down restricted link, a tunneling protocol is used to hide specific service labels on the stripped-down restricted link to obtain encapsulated data packets.

[0067] Among them, tunneling protocol refers to a network protocol that encapsulates data packets of one protocol within data packets of another protocol for transmission. Common examples include GRE, VXLAN, and Geneve. Hiding refers to placing critical information in a data area (usually an inner header) that intermediate network devices cannot parse or access. Encapsulated data packets refer to composite data packets with an outer header and an inner payload after being processed by tunneling protocol.

[0068] When a link is marked as stripped restricted, directly labeling it in the IP header will result in it being erased by intermediate devices.

[0069] The tunnel encapsulation logic is enabled, placing the original service data packet carrying the high-priority label as the payload inside the tunnel protocol. The edge node constructs a new outer IP header, which may not carry a label or may carry a spoofed label, while the actual original header carrying the high-priority label is wrapped inside the tunnel. Since intermediate scrubbing equipment typically only processes the outermost IP header and cannot deeply unpack and modify the data inside the tunnel, the priority label of the original service packet can traverse the scrubbing area within the tunnel until it reaches the terminal plugin where it is decapsulated.

[0070] In some embodiments, label hiding and encapsulation can be implemented in a variety of ways:

[0071] Optionally, UDP tunnel encapsulation (such as VXLAN) can be used: 1. Keep the DSCP field of the original IP packet unchanged (such as EF); 2. Add a VXLAN header and a UDP header before the original packet; 3. Build an outer IP header, and the outer DSCP can be set to the default value, and transmit the original packet as the data part of UDP.

[0072] It is understandable that hiding can also be achieved by using application-layer SOCKS5 proxy encapsulation, etc., which is not limited here.

[0073] In some embodiments, when the link is marked as a stripped-down restricted link, the protocol with the highest transmission affinity can be selected by constructing a multi-protocol masquerading probe stream and combined with a dynamic entropy value verification mechanism to combat transparent proxy hijacking by intermediate devices, thereby achieving highly reliable covert transmission in complex network censorship environments.

[0074] First, edge nodes construct multiple sets of protocol spoofing probe streams. These probe streams not only involve port changes but also simulate the header characteristics (such as User-Agent and Query Name) and payload statistics (such as packet length distribution and interaction timing) of HTTP (Hypertext Transfer Protocol), DNS (Domain Name Resolution Protocol), and TLS (Telecommunications Recording Protocol). Edge nodes send these probe streams and evaluate them based on the jitter and throughput decay values ​​reported by the terminal plugins. These two metrics reflect the "censorship" level of different protocols by the intermediate devices—if a certain type of protocol is deeply scanned, its forwarding latency and jitter will typically increase significantly. Based on this, the protocol with the best performance across all metrics (i.e., the highest transmission affinity) is selected as the target spoofing protocol.

[0075] Next, to prevent "man-in-the-middle attacks" or "transparent proxy hijacking," a dynamic entropy verification mechanism is introduced. When the selected target masquerading protocol is a plaintext protocol (such as HTTP), the edge node injects a dynamic entropy identifier (such as a randomly generated SessionID or Token) into the Resource Locator (URL) parameter when generating the encapsulated data packet. This identifier changes continuously over time to prevent repeated attacks. Simultaneously, an integrity checksum proportional to this dynamic entropy identifier (i.e., a specific mathematical mapping relationship) is embedded in the payload field. Upon receiving the packet, the terminal plugin verifies this mathematical relationship. If the protocol response message from the terminal displays a "200 OK" status code but lacks corresponding acknowledgment verification information, or if the payload content becomes an advertising redirect page from the operator (i.e., exhibiting redirect page characteristics), it can immediately identify that the traffic has been hijacked by an intermediate device. At this point, a forced switching logic is triggered, abandoning plaintext masquerading and switching to an encrypted transmission protocol (such as HTTPS / TLS) to encapsulate the original business data packet in an encrypted payload, using encryption technology to completely shield the intermediate device from eavesdropping and tampering.

[0076] Finally, after determining the secure protocol, the original business data packets carrying high-priority tags are fragmented and inserted into the payload field of the target masquerading protocol as application layer payload. A standard protocol header is then added to generate the final encapsulated data packet.

[0077] Through the above technical steps, the affinity-based protocol optimization ensures that traffic is disguised as the "least regulated" form; through closed-loop verification of dynamic entropy value and check code, the hijacking behavior of transparent proxy is identified and avoided, thereby improving the anti-interference capability and security of data transmission while ensuring business connectivity.

[0078] S106. Send the encapsulated data packet to the terminal plugin.

[0079] Sending refers to outputting the constructed binary data stream to the transmission medium through the physical network interface; the terminal plug-in is the target entity of the receiving end, uniquely identified by its IP address and port number.

[0080] After completing the S104 or S105 encapsulation process, the edge node places the generated encapsulated data packet into the transmission queue. The network driver looks up the interface according to the routing table and obtains the MAC address of the next-hop gateway through the ARP protocol to construct a link-layer frame.

[0081] To ensure path consistency, the transmission process may involve specific port selection strategies (such as port cloning) to ensure that the encapsulated data packets hit the same physical path as the probe flow when passing through the load balancer. Finally, the data packets leave the edge node, travel through the Internet or a leased network, and are delivered to the network location where the terminal plugin is located.

[0082] In some embodiments, the sending of encapsulated data packets can be achieved in multiple ways:

[0083] Optionally, sending based on the standard Socket interface: 1. Create a raw socket or UDP socket; 2. Call the sendto() function, specifying the destination IP as the terminal plugin address and the destination port as the negotiated tunnel port; 3. Write the encapsulated data buffer into the kernel protocol stack for sending.

[0084] It is understandable that this can also be achieved by means of hardware offloading, etc., which is not limited here.

[0085] In some embodiments, when there are multiple physical transmission paths in the network environment and the intermediate device adopts a load balancing strategy based on 5-tuple hash, the transmission path of the service data packet can be forcibly locked by extracting and reusing the source port number of the successful probe, thereby ensuring that the service flow and the probe flow take the same physical link.

[0086] First, usable path information is extracted from previous probe results. The baseline probe stream records sent in S101 are traced back, and probe packets that successfully received feedback from the terminal plugin (i.e., connectivity) are selected. The source port number in the header of these packets is extracted and defined as the path affinity identifier.

[0087] Next, when constructing the outer transport protocol message (such as the UDP header) encapsulating the data packet, instead of letting the operating system randomly assign a new source port, the underlying Socket API (such as bind or setsockopt) is directly called to forcibly overwrite the source port number with the path affinity identifier extracted above. This is because intermediate load balancing devices (such as ECMP routers) typically use a hash algorithm (Hash(source IP, destination IP, source port, destination port, protocol)) to select the outgoing interface. Since the source IP, destination IP, destination port, and protocol are usually fixed, as long as the source port remains consistent, the hash result will inevitably be consistent, thus forcing intermediate devices to map the encapsulated data packet to the exact same physical transmission path as the baseline probe stream (e.g., WAN1 port instead of the lower-quality WAN2 port).

[0088] In addition, to prevent terminal plugin confusion, a preset stream type distinguisher (such as a specific Magic Number) is injected into the payload header of the encapsulated data packet. This distinguisher is a constant predefined based on the communication protocol design specification, used to clearly inform the receiving end that this is service data and not probe retransmission.

[0089] The above technical steps solve the "path drift" problem in multi-link load balancing environments. By reusing source ports to achieve soft locking of physical paths, the potential for inconsistencies between probed paths and service paths is eliminated, ensuring that the detected good links are the links actually used by the service, thereby improving the determinism and reliability of network policy execution.

[0090] S107. The terminal plug-in receives the encapsulated data packet and removes the outer transport protocol message to obtain the original service data packet carrying the high priority label.

[0091] Among them, removing the outer transport protocol message refers to the decapsulation process, that is, stripping away the tunnel header or masquerade header added by the edge node; restoration refers to restoring the data to its original state before encapsulation.

[0092] The terminal plugin listens on a specific port (such as UDP 4789 or a custom port). When it receives an encapsulated data packet from an edge node, it first performs a validity check.

[0093] After successful verification, the plugin locates the start of the inner payload according to the negotiated tunnel protocol format. The plugin then strips and discards the outer IP header, UDP header, or tunnel protocol header, extracting the internal payload. Since the original service packet was placed intact within the payload in S105, the extracted data is the unmodified original service data packet carrying a high-priority tag.

[0094] S108. Obtain the original business data packet and verify the integrity of the header fields.

[0095] Among them, acquisition refers to reading the data structure from the decapsulated memory area; verification refers to verifying through algorithms whether the data has been tampered with or damaged during transmission and decapsulation; and the integrity of the header fields refers to whether the key information in the IP header (especially the DSCP / TOS mark, source / destination IP) is consistent with that sent by the sender.

[0096] After reconstructing the original business data packet, the terminal plugin needs to verify whether the packet is intact. This integrity verification is not just a mathematical checksum check, but more importantly, a verification of the business semantics.

[0097] The plugin reads the DSCP field from the original IP header to determine if high-priority values ​​(such as EF) are still retained. If it was determined in S103 that the link would strip the label and tunnel hiding was performed in S105, then theoretically the unpacked inner packet should retain the original label. If the verification finds that the label is still missing, it indicates that the tunneling strategy may have failed, or that the intermediate device has deep cleaning capabilities that can penetrate the tunnel.

[0098] In some embodiments, header field integrity verification can be implemented in multiple ways:

[0099] Optionally, comparison based on preset feature values: 1. Extract the DSCP field value from the IP header of the original service data packet; 2. Read the preset DSCP expected value (e.g., 46) that the service type should have in the configuration file; 3. Compare whether the extracted value is equal to the expected value. If they are equal, the integrity check passes.

[0100] It is understandable that methods such as Cyclic Redundancy Check (CRC) can also be used to achieve this, and no specific method is specified here.

[0101] S109. If the priority flag of the original service data packet is inconsistent with the preset value, trigger an alarm and switch the encapsulation protocol type.

[0102] Inconsistency refers to the difference between the restored original packet label (e.g., DSCP=0) and the expected high-priority label (e.g., DSCP=46); triggering an alarm refers to generating a system event to notify the operation and maintenance personnel or the upper-level management system; switching the encapsulation protocol type refers to automatically changing the tunnel protocol or masquerading strategy used in S105 (e.g., switching from UDP tunnel to TCP masquerading, or from plaintext tunnel to encrypted tunnel).

[0103] If the S108 verification result shows that the priority tag is missing, it indicates that the current encapsulation strategy has failed to fool the intermediate network devices, or that the network environment has changed (e.g., the intermediate devices have upgraded their DPI capabilities). The current strategy is deemed invalid, and an alarm log is immediately generated and reported to the cloud controller. Simultaneously, to ensure business continuity, a strategy rotation mechanism is automatically triggered. For example, if a GRE tunnel is currently being used and the tags have been cleaned, it may switch to an HTTP spoofing protocol or an encrypted transmission protocol, attempting to evade the intermediate devices' cleanup through more advanced spoofing methods until verification succeeds.

[0104] In some embodiments, alarm and protocol switching can be implemented in a variety of ways:

[0105] Optionally, state machine-based switching logic: 1. Detecting DSCP inconsistency triggers a policy failure event; 2. The state machine transitions from the "GRE_Tunnel" state to the "TLS_Tunnel" state; 3. Calling the configuration interface to reload the network driver's encapsulation module and sending an SNMP Trap alarm to the network management platform.

[0106] Optional, dynamic optimization based on a scoring mechanism: 1. Record the number of times the integrity check of the current protocol fails and deduct the health score; 2. Traverse the protocol library and select the backup protocol with the highest current health score (such as Websocket tunnel); 3. Send new configuration parameters to edge nodes and terminal plugins, and record a high-priority Syslog log.

[0107] It is understandable that manual intervention and confirmation followed by switching can also be used to achieve this, and no specific method is specified here.

[0108] In the above embodiments, by differentiating the baseline and feature detection streams, implicit blocking or label stripping restrictions in the link are identified, and fragmentation adaptation or tunnel hiding encapsulation are implemented accordingly. This ensures that service data packets can circumvent the physical limitations or cleaning strategies of intermediate devices, allowing high-priority service labels to be completely transmitted to the terminal. This avoids soft faults where the network is connected but the service QoS is invalid, ensuring that the actual transmission quality matches the preset policy expectations, and ultimately improving the consistency between the network policy execution effect and the monitoring status.

[0109] In other embodiments of this application, when there is strict traffic shaping or bandwidth limitation on the link, sudden large-size service data packets may trigger congestion queuing or even rate limiting and packet loss in intermediate devices. Using the network policy automatic generation and verification method provided in this application, the token rate can be inferred from latency jitter and discretely fragmented for transmission, thereby achieving lossless transmission in physically constrained networks.

[0110] like Figure 2 The diagram shown is another flowchart illustrating the automatic generation and verification method for network policies provided in this application, including the following steps:

[0111] S201. Control the edge node to send the baseline probe stream and feature probe stream to the terminal plug-in, and obtain the transmission results.

[0112] S202. When the baseline probe stream is connected but the feature probe stream is not connected, mark the link between the edge node and the terminal plug-in as a blocking restricted link.

[0113] S203. When both the baseline probe stream and the feature probe stream are connected, but the feature probe stream received by the terminal plugin is missing a specific service label, the link between the edge node and the terminal plugin is marked as a stripped-off restricted link.

[0114] Steps S201-S203 and Figure 1 Steps S101-S103 in the illustrated embodiment are similar and can be found in the descriptions of steps S101-S103, which will not be repeated here.

[0115] S204. Control the edge nodes to send multiple sets of reference probe streams at a preset gradient increment rate, and calculate the round-trip delay variance of each set of reference probe streams.

[0116] Among them, the preset gradient increment rate refers to the speed of sending data packets increasing step by step according to a certain step size until the nominal bandwidth of the link is reached or packet loss occurs. It is preset according to the basic bandwidth specification of the link (such as 10Mbps or 100Mbps) and the test accuracy requirements, and is usually set to 5% of the link bandwidth as the step size; the reference probe stream refers to the test stream composed of standard-sized (such as 64 bytes) data packets without special tags; the round-trip time variance value is a statistical measure of the dispersion of the round-trip time (RTT) of a series of data packets, which is used to reflect the stability of network transmission.

[0117] The edge node initiates a rate scan process, starting by sending the first set of baseline probe streams at a low rate. Subsequently, the edge node gradually increases the sending rate according to a preset gradient. At each rate level, the edge node records the sending timestamp and the received acknowledgment timestamp for each probe packet, and calculates the RTT for each packet.

[0118] Then, statistical analysis is performed on the RTT of all packets within the group to calculate the variance. The smaller the variance value, the smoother the transmission; a sudden increase in variance value usually means that buffers in the link are starting to accumulate, which is a precursor to network congestion. Through this stress test, a rate-jitter curve can be plotted.

[0119] In some embodiments, gradient-incremental probing can be implemented in a variety of ways:

[0120] Optional, UDP-based equal-interval packet sending detection: 1. Set the initial packet sending interval T=1ms, corresponding to the rate R1; 2. Send N UDP packets, record the RTT, and calculate the variance; 3. Reduce the packet sending interval T=T-Δt, increase the rate to R2, repeat sending and recording until continuous packet loss occurs.

[0121] It is understandable that ICMP Flood mode can also be used in conjunction with kernel timestamps, etc., and this is not limited here.

[0122] S205. If the round-trip delay variance exceeds the preset congestion jitter threshold, and the packet loss rate of the baseline probe flow shows a positive linear correlation with the gradient increment rate, then the token filling rate of the traffic shaping device is calculated based on the rate inflection point where the round-trip delay variance changes abruptly.

[0123] Among them, the congestion jitter threshold refers to the critical value for determining whether a network enters a queuing congestion state. This value is usually set according to the upper limit of jitter tolerance for real-time services such as VoIP; the positive correlation linear relationship means that as the sending rate increases, the packet loss rate also increases proportionally, which is a traffic shaping characteristic; traffic shaping devices refer to gateways or routers in the network path that implement rate limiting policies; token filling rate refers to the rate at which tokens are generated in the token bucket algorithm, which physically corresponds to the commitment information rate of the link; the rate inflection point refers to the sending rate point where the delay variance suddenly and sharply increases from a stable state.

[0124] When the sending rate is low, the token bucket of the intermediate device is full, and data packets pass through directly with a small latency variance. When the sending rate exceeds the limit of the intermediate device (i.e., the token filling rate), data packets begin to queue in the intermediate device's buffer, waiting for tokens, causing the RTT to become larger and more unstable, and the latency variance to exceed the threshold.

[0125] If the rate continues to increase, the buffer overflows, and excess packets are dropped, resulting in a linear increase in packet loss rate with the rate. The instant this variance abrupt change is captured, and the corresponding transmission rate (e.g., 5 Mbps) is identified as the physical rate limit (token filling rate) of the intermediate device. This calculation process is essentially reverse engineering of the QoS parameters inside the black-box network device.

[0126] In some embodiments, token rate calculation can be implemented in a variety of ways:

[0127] Optionally, based on the inflection point detection algorithm: 1. Plot the "sending rate - delay variance" curve; 2. Use the second derivative method to find the point with the largest curve curvature, which is the inflection point; 3. Mark the x-axis rate corresponding to the inflection point as the token filling rate R_token.

[0128] Optionally, based on packet loss rate regression analysis: 1. Select sample points with packet loss rate greater than 0; 2. Perform linear regression fitting to obtain a linear equation between packet loss rate and transmission rate; 3. Calculate the intercept of the equation when packet loss rate = 0. This intercept is the maximum lossless forwarding rate of the link, which is approximately equal to the token filling rate.

[0129] It is understandable that this can also be achieved by using Kalman filtering to estimate bandwidth, etc., and this is not limited here.

[0130] S206. Calculate the target transmission time interval to maintain the link in a non-congested state based on the token filling rate and the preset fragment size.

[0131] The preset fragment size refers to the small data packet size (e.g., 512 bytes) set to avoid MTU limitations, and is usually set based on the successful size of the baseline probe stream in S101; the target transmission interval refers to the minimum waiting time between the transmission of two adjacent fragment data packets, which is used to control the overall transmission rate; maintaining the link non-congestion state means ensuring that the transmission rate does not exceed the token filling rate calculated in S205, thereby avoiding triggering the queuing or packet loss mechanism of intermediate devices.

[0132] The intermediate device's rate-limiting bottleneck is known to be R_token (e.g., 5Mbps, or 625KB / s), and it has been decided to split large packets into tiny fragments of size S_frag (e.g., 512 bytes). To allow these fragments to pass through without being dropped due to rate limiting, the transmission frequency needs to be controlled.

[0133] The calculation formula is: Target transmission time interval T_interval = S_frag / R_token. For example, 512 bytes / 625KB / s ≈ 0.8 milliseconds. This means that as long as a 512-byte packet is sent every 0.8 milliseconds, the overall rate will be exactly at the 5Mbps speed limit. This maximizes bandwidth utilization without triggering penalty packet loss from intermediate devices.

[0134] In some embodiments, time interval calculation can be implemented in multiple ways:

[0135] Optionally, calculations can be performed based on static formulas: 1. Read the R_token (in bps) output by S205; 2. Read the configured S_frag (in bits); 3. Directly perform the division operation T=S_frag / R_token and round down to the microsecond level.

[0136] Optionally, based on dynamic feedback adjustment (AIMD): 1. Set an initial interval T0; 2. Based on real-time packet loss feedback, decrease T (increase rate) if there is no packet loss, and double T (decrease rate) if there is packet loss; 3. Use the T value in the stable state as the target transmission time interval.

[0137] It is understandable that this can also be achieved using dynamic calculations with a PID controller, and this is not a limitation here.

[0138] S207. The original service data packet is divided into multiple tiny fragments using a preset fragment size, and the tiny fragments are discretized, encapsulated, and sent according to the target sending time interval.

[0139] Among them, micro-fragments refer to the data blocks after being segmented; discretized encapsulation and transmission refers to the discontinuous and rhythmic transmission of data packets, which presents a discrete pulse pattern on the time axis rather than a continuous burst stream.

[0140] Edge nodes intercept large raw service data packets and cut them into three 512-byte fragments. Instead of sending all three packets at once like a conventional protocol stack, a timer is started. The first fragment is sent, then the node sleeps for the target's transmission interval, the second fragment is sent, the node sleeps again, and finally the third fragment is sent. This fragmented, uniform transmission method results in a smooth, low-speed stream, adapting to the token bucket filling rate of intermediate devices, thus enabling reliable transmission of service data in physically constrained and challenging links.

[0141] In some embodiments, discrete transmission can be implemented in a variety of ways:

[0142] Optionally, based on a software timer: 1. Place the segmented fragments into a queue; 2. Start a high-precision timer (such as hrtimer); 3. Each time a timer interrupt is triggered, retrieve a fragment from the queue and call the network card driver to send it.

[0143] It is understandable that flow control can also be implemented at the application layer using the token bucket algorithm, but this is not a limitation here.

[0144] In some embodiments, if the transmission time is too long due to rate limiting, which may trigger the intermediate device reassembly timeout, packet loss due to intermediate device fragment reassembly timeout can be avoided by atomically encapsulating the fragments as independent stateless protocol messages.

[0145] First, a timeout risk assessment is performed. The total number of fragments after the original service data packet is split is calculated by multiplying it by the target transmission time interval calculated by S206, thus obtaining the total transmission time. For example, if the packet is split into 10 fragments with an interval of 100ms, the total time is 1 second. This time is compared with a preset intermediate device reassembly timeout threshold (e.g., IP fragmentation reassembly is typically 60 seconds, but some strict firewalls may only require 0.5 seconds; this threshold is usually based on the default configuration parameters of common network equipment manufacturers). If the total transmission time exceeds this threshold, it means that if traditional IP fragmentation is used, the intermediate device will empty its buffer due to timeout before receiving all fragments, leading to transmission failure.

[0146] Initiate the atomic independent encapsulation strategy. Select a target stateless protocol (such as DNS Query or SNMP Trap) with single-packet interaction characteristics from the pre-built stateless protocol feature library. The characteristic of these protocols is that each packet is an independent transaction, and intermediate devices will not reassemble them across packets.

[0147] Next, a header template and a fragment logical sequence number mapping table are constructed. The header template is used to disguise each tiny fragment as an independent transaction (e.g., disguised as an independent DNS query request); the mapping table is used to record "which fragment of the original large packet this DNS request is actually". An independent application layer header is added to each tiny fragment using the header template, and the corresponding logical sequence number is cleverly injected into the transaction identifier field (such as DNSTransaction ID) of the target stateless protocol. In this way, contiguous fragments that originally belonged to the same large packet become multiple independent small packets that are unrelated on the physical network.

[0148] Finally, these disguised stateless protocol messages are still sent to the terminal plugin according to the target sending time interval.

[0149] Through the above technical steps, the associated fragmented streams are transformed into independent atomic transaction streams, eliminating the need for intermediate devices to reassemble fragments. This ensures that even if data packets are sent very slowly, the reassembly timeout mechanism of intermediate devices will not be triggered, thus guaranteeing the reliable transmission of large-size business data in limited networks with extremely low bandwidth.

[0150] S208. In response to the link being marked as a stripped-down restricted link, a tunneling protocol is used to hide specific service labels on the stripped-down restricted link to obtain encapsulated data packets.

[0151] S209. Send the encapsulated data packet to the terminal plugin.

[0152] S210: The terminal plug-in receives the encapsulated data packet and removes the outer transport protocol message to obtain the original service data packet carrying the high priority tag.

[0153] S211. Obtain the original business data packet and verify the integrity of the header fields.

[0154] S212. If the priority flag of the original service data packet is inconsistent with the preset value, trigger an alarm and switch the encapsulation protocol type.

[0155] In some embodiments, while verifying the integrity of the header fields, stress testing can also be performed by injecting background mimicry noise streams, and the system can be dynamically adjusted to a constant bit rate obfuscation mode based on the test results, thereby counteracting intelligent QoS rate limiting based on traffic characteristics.

[0156] First, a digital twin of the business traffic is created. Based on the historical throughput model of the original business data packets (i.e., traffic waveform statistics over a past period), a set of background simulated noise streams with the same bandwidth characteristics (such as burst frequency and average rate) is generated. This set of noise streams consists of randomly generated invalid data, but is highly similar to real business traffic in statistical characteristics.

[0157] Next, this noise stream is injected concurrently into the link along with the actual encapsulated data packets, artificially creating the illusion of high load. At this time, the transmission quality metrics (such as latency and packet loss rate) of the encapsulated data packets are closely monitored during the presence of the noise stream.

[0158] Because some intelligent flow control devices do not limit the rate normally, but only trigger rate limiting when specific service traffic reaches a certain threshold, this potential rate limiting behavior can be actively induced by injecting noise. If the statistically observed transmission quality indicators are significantly lower than the preset no-load baseline value (this baseline value is the ideal indicator measured under idle link conditions), it indicates that there is an intelligent rate limiting strategy in the link targeting this type of service waveform. In this case, the adaptive encapsulation strategy is adjusted to a constant bit rate obfuscation mode. In this mode, data is no longer sent on demand, but invalid data is continuously filled in, forcing the transmission rate to always remain at the service peak level. In this way, the data flow becomes a flat straight line on the time axis, smoothing out the waveform characteristics of the service traffic, making it impossible for intermediate devices to identify and rate limit based on the burst characteristics of traffic.

[0159] Through the above technical steps, the system proactively applies pressure to detect and expose hidden QoS policies, and uses the CBR mode to eliminate traffic fingerprints. This makes the service traffic appear as a featureless constant flow in the eyes of intermediate devices, thereby ensuring the stability and high priority of service transmission in complex traffic control networks.

[0160] Steps S208-S212 and Figure 1 Steps S105-S109 in the illustrated embodiment are similar and can be found in the descriptions of steps S105-S109, which will not be repeated here.

[0161] In the above embodiments, the token filling rate of intermediate devices is inferred by using the abrupt change points of delay variance detected by gradient probing, and a discretized fragmentation transmission strategy is constructed accordingly. This reshapes the originally bursty large packet traffic flow into a smooth pulse flow that strictly adapts to the physical bottlenecks of the link. Thus, without triggering congestion queuing or rate-limited packet loss in intermediate devices, the effective bandwidth of the limited link is utilized, solving the transmission interruption problem caused by MTU limitations and traffic shaping in harsh network environments, and improving the penetration capability and transmission stability of service data in heterogeneous networks.

[0162] The following describes an exemplary network policy automatic generation and verification system 300 provided in an embodiment of this application. Figure 3 This is an exemplary hardware structure diagram of the network policy automatic generation and verification system 300 provided in this application embodiment.

[0163] In some embodiments, the network policy automatic generation and verification system 300 is a computer device or includes a computer device. The computer device includes a processor, memory, and a network interface connected via a system bus. The processor of the computer device provides computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The database of the computer device stores data. The network interface of the computer device is used to communicate with other external terminals or servers via a network connection. In some embodiments, the network interface can be a wired network interface; in some embodiments, the network interface can also be a wireless network interface. When the computer program is executed by the processor, it implements the methods in the embodiments of this application.

[0164] Those skilled in the art will understand that Figure 3 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0165] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

[0166] As used in the above embodiments, depending on the context, the term "when..." can be interpreted as "if...", "after...", "in response to determining...", or "in response to detecting...". Similarly, depending on the context, the phrase "when determining..." or "if (the stated condition or event) is interpreted as "if determining...", "in response to determining...", "when (the stated condition or event) is detected", or "in response to detecting (the stated condition or event)".

[0167] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc.

[0168] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This program can be stored in a computer-readable storage medium, and when executed, it can include the processes described in the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM or random access memory (RAM), magnetic disks, or optical disks.

Claims

1. A method for automatically generating and verifying network policies, characterized in that, include: Control the edge nodes to send baseline probe streams and feature probe streams to the terminal plugin, and obtain the transmission results; The reference probe stream consists of standard-sized data packets without service tags; The feature detection stream consists of full-size data packets carrying specific service tags; If the baseline probe stream is connected but the feature probe stream is not connected, the link between the edge node and the terminal plug-in is marked as a blocking restricted link; When both the baseline probe stream and the feature probe stream are connected, but the specific service tag is missing in the feature probe stream received by the terminal plugin, the link between the edge node and the terminal plugin is marked as a stripped-down restricted link. In response to a link being marked as the blocking restricted link, the blocking restricted link is encapsulated using a size threshold conforming to the reference probe flow to obtain encapsulated data packets; In response to the link being marked as the stripped-down restricted link, the specific service label is hidden on the stripped-down restricted link using a tunneling protocol to obtain the encapsulated data packet; The encapsulated data packet is sent to the terminal plugin; The terminal plugin receives the encapsulated data packet and removes the outer transport protocol message to obtain the original service data packet carrying a high priority tag. Obtain the original business data packet and verify the integrity of the header fields; If the priority flag of the original service data packet is inconsistent with the preset value, an alarm is triggered and the encapsulation protocol type is switched.

2. The method according to claim 1, characterized in that, In response to the link being marked as the stripped-down restricted link, a tunneling protocol is used to hide the specific service label on the stripped-down restricted link to obtain the encapsulated data packet, specifically including: Multiple sets of protocol spoofing detection streams are constructed, wherein each set of protocol spoofing detection streams simulates the header features and payload statistical features of Hypertext Transfer Protocol, Domain Name Resolution Protocol and Encryption Transfer Protocol respectively; The edge node is controlled to send the protocol spoofing probe stream to the terminal plugin, and the transmission jitter value and throughput attenuation rate of each group of probe streams fed back by the terminal plugin are obtained. Based on the transmission jitter value and the throughput attenuation rate, the protocol type with the highest transmission affinity is selected from the protocol types corresponding to the protocol spoofing detection stream as the target spoofing protocol; The original service data packets carrying the high-priority tags are fragmented, and the fragmented data is used as application layer payload, encapsulated into the payload field of the target masquerading protocol, and the standard header corresponding to the target masquerading protocol is added to generate encapsulated data packets.

3. The method according to claim 2, characterized in that, After selecting the protocol type with the highest transmission affinity from the protocol types corresponding to the protocol spoofing detection stream as the target spoofing protocol, the method further includes: When the target masquerading protocol is a plaintext application layer protocol, when generating the encapsulated data packet, a dynamic entropy value identifier is injected into the resource locator of the target masquerading protocol, and an integrity check code is embedded in the payload field; the dynamic entropy value identifier changes over time; the integrity check code is proportional to the dynamic entropy value identifier. Obtain the protocol response message fed back by the terminal plugin to the encapsulated data packet; If the status code of the protocol response message indicates successful transmission, but the protocol response message lacks the acknowledgment verification information corresponding to the dynamic entropy value identifier, or if the payload content of the protocol response message exhibits the characteristics of a redirection page of an intermediate device, the target masquerading protocol will be forcibly switched to an encrypted transmission protocol, and the original service data packet will be encapsulated into the encrypted payload of the encrypted transmission protocol.

4. The method according to claim 1, characterized in that, In response to the link being marked as the blocking restricted link, the blocking restricted link is encapsulated using a size threshold conforming to the baseline probe flow to obtain encapsulated data packets, specifically including: The edge nodes are controlled to send multiple sets of the reference probe streams at a preset gradient increasing rate, and the round-trip delay variance of each set of the reference probe streams is calculated. If the round-trip delay variance exceeds the preset congestion jitter threshold, and the packet loss rate of the baseline probe stream is positively correlated with the gradient increment rate, then the token filling rate of the traffic shaping device is calculated based on the rate inflection point where the round-trip delay variance changes abruptly. Based on the token filling rate and the preset fragment size, the target transmission time interval for maintaining a non-congested link is calculated. The original service data packet is divided into multiple tiny fragments using the preset fragment size, and the tiny fragments are discretized, encapsulated, and sent according to the target sending time interval.

5. The method according to claim 4, characterized in that, After dividing the original service data packet into multiple tiny fragments using the preset fragmentation size, and discretizing and encapsulating the tiny fragments according to the target transmission time interval, the method further includes: The full transmission time is obtained by multiplying the total number of fragments after the original service data packet is divided by the target transmission time interval. When the full transmission time exceeds a preset intermediate device reassembly timeout threshold, a target stateless protocol with single-packet interaction characteristics is selected from a preset stateless protocol feature library, and an atomic independent encapsulation strategy is constructed. The atomic independent encapsulation strategy includes the header template of the target stateless protocol and a fragment logical sequence number mapping table, wherein the fragment logical sequence number mapping table is used to map the original fragmentation order of the tiny fragments to the transaction identifier field of the target stateless protocol. The header template is used to add an independent application layer header to each of the tiny fragments, and the corresponding logical sequence number is injected into the transaction identifier field to generate multiple stateless protocol messages; The stateless protocol message is sent to the terminal plugin according to the target sending time interval.

6. The method according to claim 1, characterized in that, After triggering the alarm and switching the encapsulation protocol type, the following is also included: Based on the historical throughput model of the original service data packets, a background mimicry noise stream with the same bandwidth characteristics is generated, and the background mimicry noise stream and the encapsulated data packets are concurrently injected into the link; The transmission quality metrics of the encapsulated data packets are statistically analyzed during the presence of the background mimicry noise stream. If the transmission quality index is lower than the preset no-load baseline value, the adaptive encapsulation strategy is adjusted to a constant bit rate obfuscation mode, filling in invalid data to maintain the transmission rate at the peak service level.

7. The method according to claim 1, characterized in that, After obtaining the encapsulated data packet by hiding the specific service label on the stripped-down restricted link using a tunneling protocol, the method further includes: Extract the source port number of the successfully connected probe data packets in the baseline probe stream as a path affinity identifier; The source port number of the outer transport protocol message of the encapsulated data packet is forcibly overwritten with the path affinity identifier, and the encapsulated data packet is mapped to the same physical transport path as the reference probe stream; A stream type distinguisher is injected into the payload header of the encapsulated data packet.

8. A network policy automatic generation and verification system, characterized in that, The network policy automatic generation and verification system includes: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and the one or more processors call the computer instructions to cause the network policy automatic generation and verification system to perform the method as described in any one of claims 1-7.

9. A computer program product containing instructions, characterized in that, When the computer program product is run on the network policy automatic generation and verification system, the network policy automatic generation and verification system performs the method as described in any one of claims 1-7.

10. A computer-readable storage medium comprising instructions, characterized in that, When the instruction is run on the network policy automatic generation and verification system, the network policy automatic generation and verification system performs the method as described in any one of claims 1-7.