A network traffic monitoring method, device, apparatus and storage medium

CN121690813BActive Publication Date: 2026-09-18CETC CYBERSPACE SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511959523.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-12-24
Publication Date
2026-09-18
Estimated Expiration
2045-12-24

AI Technical Summary

Technical Problem

[0003]然而,现有相关方案中,通常基于IP地址(Internet Protocol,网际互连协议)、URI(Uniform Resource Identifier,统一资源标识符)或通用HTTP(Hypertext TransferProtocol,超文本传输协议)头部进行限流,但由于在密码服务场景中,不同业务应用(即使属于同一用户)对密码运算的实时性和带宽需求差异巨大,导致控制粒度不足;并且,其难以应对突发性的大量请求,且不同请求类型的密码运算对TPS(Transactions Per Second,每秒事务处理量)、BPS(Bits Per Second,位每秒)差异极大的情况

Benefits of technology

[0055]As can be seen, in this application, a preset password service platform is used to configure the rate limiting configuration file in the OpenResty gateway component of the preset password service platform through the page interaction component and the Ingress control component. The rate limiting configuration file includes first rate limiting rule information for transaction processing speed and/or second rate limiting rule information for data transmission rate for each application. After the rate limiting configuration file is configured, when a password calculation service request sent by a client is received through the OpenResty gateway component, based on the rate limiting configuration file, the local cache or Redis cache component, and the application identifier information in the password calculation service request, it is determined whether to reject the current password calculation service request to complete the network traffic control operation. During the network traffic control process, the monitoring component on any node of the preset password service platform collects traffic data from the Redis cache component and, in conjunction with preset anomaly detection rules, determines the target monitoring result and the alarm trigger judgment result corresponding to the target monitoring result to complete the network traffic monitoring operation. In other words, this application configures the rate limiting configuration file in the OpenResty gateway component through the page interaction component and Ingress control component in the preset password service platform. Then, when the OpenResty gateway component receives a password calculation service request sent by the client, it determines whether to reject the current password calculation service request based on the rate limiting configuration file, the local cache or Redis cache component, and the application identification information in the password calculation service request. In addition, the monitoring component on any node in the preset password service platform collects traffic data from the Redis cache component and combines it with preset anomaly detection rules to determine the target monitoring result and the corresponding alarm trigger judgment result. In this way, the problems existing in the existing related solutions can be solved, effectively realizing accurate and real-time network traffic control and monitoring in both TPS and BPS rate limiting scenarios, and providing early warnings. This ensures accurate rate limiting in multi-replica Nginx Ingress Controller container Pod scenarios and alleviates the performance degradation caused by frequent access to remote dictionary services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121690813B_ABST
    Figure CN121690813B_ABST
Patent Text Reader

Abstract

The application discloses a network flow monitoring method and device, equipment and storage medium, relates to the computer technical field, is applied to the preset password service platform, and includes: configuring the flow limiting configuration file in the OpenResty gateway component through the page interaction component and Ingress control component in the platform;Flow limiting configuration file includes flow limiting rule information for transaction processing speed and / or data transmission rate;When the OpenResty gateway component receives a password calculation service request, whether the request is rejected is determined based on the flow limiting configuration file, local cache or Redis cache component;Flow data in the Redis cache component is collected by the monitoring component on any node in the platform to determine the target monitoring result and alarm triggering judgment result.The application can effectively realize accurate and real-time network flow control and monitoring in two flow limiting scenarios of transaction processing speed and data transmission rate, and early warning.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to a method, apparatus, device, and storage medium for monitoring network traffic. Background Technology

[0002] The cryptographic service platform provides unified cryptographic computation services to application systems, including general cryptographic computation capabilities such as symmetric encryption / decryption and session keys. The platform's stability, security, and response efficiency directly impact all business systems that rely on it; therefore, rate limiting of the cryptographic computation service is one of its core safeguards.

[0003] However, existing solutions typically limit rates based on IP addresses (Internet Protocol), URIs (Uniform Resource Identifiers), or general HTTP (Hypertext Transfer Protocol) headers. But in cryptographic service scenarios, different business applications (even those belonging to the same user) have vastly different real-time and bandwidth requirements for cryptographic operations, resulting in insufficient control granularity. Furthermore, they struggle to handle sudden surges in requests, and the cryptographic operations of different request types have drastically different TPS (Transactions Per Second) and BPS (Bits Per Second). Summary of the Invention

[0004] In view of this, the purpose of this invention is to provide a network traffic monitoring method, apparatus, device, and storage medium that can solve the problems existing in existing related solutions, effectively achieve accurate and real-time network traffic control and monitoring in both TPS and BPS rate limiting scenarios, and provide early warnings. This ensures accurate rate limiting in multi-replica Nginx Ingress Controller container Pod scenarios and mitigates the performance degradation caused by frequent access to remote dictionary services. The specific solution is as follows:

[0005] Firstly, this application provides a network traffic monitoring method applied to a preset password service platform, comprising:

[0006] The rate limiting configuration file in the OpenResty gateway component of the preset password service platform is configured through the page interaction component and Ingress control component in the preset password service platform; wherein, the rate limiting configuration file includes first rate limiting rule information for transaction processing speed and / or second rate limiting rule information for data transmission rate corresponding to each application;

[0007] After the rate limiting configuration file is configured, when a password calculation service request sent by a client is received through the OpenResty gateway component, the system determines whether to reject the current password calculation service request based on the rate limiting configuration file, the local cache or Redis cache component, and the application identification information in the password calculation service request, so as to complete the network traffic control operation.

[0008] During network traffic control, the monitoring component on any node of the preset password service platform collects traffic data from the Redis cache component, and combines it with preset anomaly detection rules to determine the target monitoring result and the alarm trigger judgment result corresponding to the target monitoring result, so as to complete the network traffic monitoring operation.

[0009] Optionally, configuring the rate limiting configuration file in the OpenResty gateway component of the preset password service platform through the page interaction component and Ingress control component includes:

[0010] The system obtains and sets rate limiting rule information corresponding to the password calculation service interfaces of each application through the interactive interface of the page interaction component in the preset password service platform; the rate limiting rule information includes first rate limiting rule information for transaction processing speed and / or second rate limiting rule information for data transmission rate.

[0011] The rate limiting rule information is sent to the Ingress control component in the preset password service platform through the interactive interface in the page interaction component and by means of annotation.

[0012] The Ingress control component verifies and integrates the rate limiting rule information stored in the Ingress resources corresponding to each application to determine the processed rule information.

[0013] The Ingress control component determines the key-value prefix corresponding to each of the processed rule information.

[0014] The Ingress control component dynamically configures the processed rule information and the corresponding key-value prefix into the target field of the rate limiting configuration file of the OpenResty gateway component in the preset password service platform.

[0015] Optionally, when a password computation service request sent by a client is received through the OpenResty gateway component, determining whether to reject the current password computation service request based on the rate limiting configuration file, the local cache or Redis cache component, and the application identifier information in the password computation service request, in order to complete the network traffic control operation, includes:

[0016] When a password calculation service request sent by a client is received through the OpenResty gateway component and in conjunction with the corresponding encrypted channel, the application identification information in the password calculation service request is obtained.

[0017] Using the OpenResty gateway component and the rate limiting configuration file, the target rule information corresponding to the application identification information is determined;

[0018] The OpenResty gateway component matches the Uniform Resource Identifier corresponding to the cryptographic computation service request with the regular expression in the target rule information to determine the matching result.

[0019] The OpenResty gateway component, based on the matching results, local cache, or Redis cache component, determines whether to reject the current password calculation service request to complete the network traffic control operation.

[0020] Optionally, determining whether to reject the current password calculation service request through the OpenResty gateway component and based on the matching result, local cache, or Redis cache component includes:

[0021] If the matching result indicates that any of the regular expressions corresponding to the first rate limiting rule information are matched, then the first target key value is determined through the OpenResty gateway component;

[0022] The OpenResty gateway component is used to query the traffic data in the local cache that corresponds to the first target key value and reflects the transaction processing speed, so as to determine the first data query result.

[0023] If the first data query result indicates that the query was successful, then the first data query result is used to determine whether the remaining capacity of the current cache in the local cache is greater than the amount of data requested by the password calculation service, so as to determine the first judgment result;

[0024] If the first judgment result is yes, then it is determined that the password calculation service request has successfully passed the first request judgment operation;

[0025] If the first data query result indicates that the query failed or the first judgment result is negative, then based on the leaky bucket algorithm, the corresponding bucket balance query is performed on the traffic data reflecting the transaction processing speed corresponding to the first target key value in the Redis cache component to determine the second data query result.

[0026] If the second data query result indicates that the remaining bucket capacity is greater than the first preset threshold, then the second data query result is used to determine whether the current remaining cache capacity in the Redis cache component is greater than the amount of data requested by the password calculation service, so as to determine the second judgment result;

[0027] If the second judgment result is yes, then it is determined that the password calculation service request has successfully passed the first request judgment operation;

[0028] If the second determination result is negative, then the current request for cryptographic calculation service is rejected.

[0029] Optionally, determining whether to reject the current password calculation service request through the OpenResty gateway component and based on the matching result, local cache, or Redis cache component includes:

[0030] If the matching result indicates that any of the regular expressions corresponding to the second rate limiting rule information are matched, then the second target key value is determined through the OpenResty gateway component;

[0031] The OpenResty gateway component is used to query the traffic data reflecting the data transmission rate corresponding to the second target key value in the local cache in order to determine the third data query result;

[0032] If the third data query result indicates that the query was successful, then the third data query result is used to determine whether the remaining capacity of the current cache in the local cache is greater than the amount of data requested by the password calculation service, so as to determine the third judgment result;

[0033] If the third judgment result is yes, then it is determined that the password calculation service request has successfully passed the second request judgment operation;

[0034] If the third data query result indicates that the query failed or the third judgment result is negative, then based on the leaky bucket algorithm, the corresponding bucket balance query is performed on the traffic data reflecting the data transmission rate corresponding to the second target key value in the Redis cache component to determine the fourth data query result.

[0035] If the fourth data query result indicates that the remaining bucket capacity is greater than the second preset threshold, then the fourth data query result is used to determine whether the current remaining cache capacity in the Redis cache component is greater than the amount of data requested by the password calculation service, so as to determine the fourth judgment result.

[0036] If the fourth judgment result is yes, then it is determined that the cryptographic calculation service request has successfully passed the second request judgment operation;

[0037] If the fourth determination result is negative, then the current request for cryptographic calculation service is rejected.

[0038] Optional, also includes:

[0039] If the cryptographic computation service request successfully passes the first request judgment operation and the second request judgment operation, then the OpenResty gateway component is used to authenticate the cryptographic computation service request to determine the authentication result.

[0040] If the authentication result indicates that the authentication is successful, the password calculation service request is stored in the pending request queue.

[0041] Optionally, the step of collecting traffic data from the Redis cache component through the monitoring component on any node of the preset password service platform, and determining the target monitoring result and the alarm trigger judgment result corresponding to the target monitoring result by combining preset anomaly detection rules, includes:

[0042] For any node in the preset password service platform, the traffic data in the Redis cache component is collected through the monitoring component on the current node and in combination with the preset monitoring period to determine the data collection results; the data collection results include traffic data reflecting the transaction processing speed and traffic data reflecting the data transmission rate;

[0043] The monitoring component analyzes the data collection results and uses the corresponding target monitoring results and preset anomaly detection rules to determine the alarm trigger judgment result.

[0044] If the alarm triggering judgment indicates that the current target monitoring result meets the alarm triggering condition, then the target monitoring result is sent to the alarm component on the current node through the monitoring component;

[0045] The alarm component determines the alarm information corresponding to the target monitoring result and, in conjunction with preset alarm rules, triggers alarm measures.

[0046] The alarm component reports the alarm information to the page interaction component.

[0047] Secondly, this application provides a network traffic monitoring device applied to a preset password service platform, comprising:

[0048] The rate limiting configuration module is used to configure the rate limiting configuration file in the OpenResty gateway component of the preset password service platform through the page interaction component and Ingress control component in the preset password service platform; wherein, the rate limiting configuration file includes first rate limiting rule information for transaction processing speed and / or second rate limiting rule information for data transmission rate corresponding to each application;

[0049] The traffic control module is used to determine whether to reject the current password calculation service request after the configuration of the rate limiting configuration file is completed, when a password calculation service request sent by a client is received through the OpenResty gateway component, based on the rate limiting configuration file, the local cache or Redis cache component, and the application identification information in the password calculation service request, so as to complete the network traffic control operation.

[0050] The traffic monitoring module is used to collect traffic data from the Redis cache component through the monitoring component on any node of the preset password service platform during the network traffic control process, and combine it with preset anomaly detection rules to determine the target monitoring result and the alarm trigger judgment result corresponding to the target monitoring result, so as to complete the network traffic monitoring operation.

[0051] Thirdly, this application provides an electronic device, comprising:

[0052] Memory, used to store computer programs;

[0053] A processor is used to execute the computer program to implement the steps of the aforementioned network traffic monitoring method.

[0054] Fourthly, this application provides a computer-readable storage medium for storing a computer program, which, when executed by a processor, implements the steps of the aforementioned network traffic monitoring method.

[0055] As can be seen, in this application, a preset password service platform is used to configure the rate limiting configuration file in the OpenResty gateway component of the preset password service platform through the page interaction component and the Ingress control component. The rate limiting configuration file includes first rate limiting rule information for transaction processing speed and / or second rate limiting rule information for data transmission rate for each application. After the rate limiting configuration file is configured, when a password calculation service request sent by a client is received through the OpenResty gateway component, based on the rate limiting configuration file, the local cache or Redis cache component, and the application identifier information in the password calculation service request, it is determined whether to reject the current password calculation service request to complete the network traffic control operation. During the network traffic control process, the monitoring component on any node of the preset password service platform collects traffic data from the Redis cache component and, in conjunction with preset anomaly detection rules, determines the target monitoring result and the alarm trigger judgment result corresponding to the target monitoring result to complete the network traffic monitoring operation. In other words, this application configures the rate limiting configuration file in the OpenResty gateway component through the page interaction component and Ingress control component in the preset password service platform. Then, when the OpenResty gateway component receives a password calculation service request sent by the client, it determines whether to reject the current password calculation service request based on the rate limiting configuration file, the local cache or Redis cache component, and the application identification information in the password calculation service request. In addition, the monitoring component on any node in the preset password service platform collects traffic data from the Redis cache component and combines it with preset anomaly detection rules to determine the target monitoring result and the corresponding alarm trigger judgment result. In this way, the problems existing in the existing related solutions can be solved, effectively realizing accurate and real-time network traffic control and monitoring in both TPS and BPS rate limiting scenarios, and providing early warnings. This ensures accurate rate limiting in multi-replica Nginx Ingress Controller container Pod scenarios and alleviates the performance degradation caused by frequent access to remote dictionary services. Attached Figure Description

[0056] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0057] Figure 1A flowchart of a network traffic monitoring method provided in this application;

[0058] Figure 2 This application provides a schematic diagram of a network traffic monitoring system deployment.

[0059] Figure 3 A flowchart illustrating the configuration of a rate limiting rule provided in this application;

[0060] Figure 4 A schematic diagram of a network traffic control process provided in this application;

[0061] Figure 5 A flowchart illustrating the execution of a first request determination operation provided in this application;

[0062] Figure 6 A flowchart illustrating the execution of a second request determination operation provided in this application;

[0063] Figure 7 A schematic diagram of a network traffic monitoring device provided in this application;

[0064] Figure 8 This application provides a structural diagram of an electronic device. Detailed Implementation

[0065] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0066] Existing solutions typically use IP address, URI, or common HTTP headers for rate limiting. However, in cryptographic service scenarios, different business applications (even those belonging to the same user) have vastly different real-time and bandwidth requirements for cryptographic operations, resulting in insufficient control granularity. Furthermore, these solutions struggle to handle sudden surges in requests, and the cryptographic operations for different request types have significantly different effects on TPS and BPS.

[0067] To address this, this application provides a network traffic monitoring solution that solves the problems existing in related solutions, effectively achieves accurate and real-time network traffic control and monitoring in both TPS and BPS rate limiting scenarios, and can provide early warnings. This not only ensures accurate rate limiting in multi-replica Nginx Ingress Controller container Pod scenarios, but also alleviates the performance degradation caused by frequent access to remote dictionary services.

[0068] See Figure 1 As shown, this embodiment of the invention discloses a network traffic monitoring method applied to a preset password service platform, including:

[0069] Step S11: Configure the rate limiting configuration file in the OpenResty gateway component of the preset password service platform through the page interaction component and Ingress control component in the preset password service platform; wherein, the rate limiting configuration file includes first rate limiting rule information for transaction processing speed and / or second rate limiting rule information for data transmission rate corresponding to each application.

[0070] In this embodiment, combined with Figure 2 As shown, firstly, the rate limiting rule information sent by the configuration administrator is obtained through the page interaction component. Then, combined with the Ingress control component, the rate limiting configuration file in the OpenResty gateway component is dynamically updated. Specifically: through the interactive interface of the page interaction component in the preset password service platform, rate limiting rule information corresponding to the password calculation service interface of each application is obtained and set; the rate limiting rule information includes first rate limiting rule information for transaction processing speed and / or second rate limiting rule information for data transmission rate; through the interactive interface of the page interaction component, and using annotations, the rate limiting rule information is sent to the Ingress control component in the preset password service platform; through the Ingress control component, the rate limiting rule information stored in the Ingress resources corresponding to each application is verified and integrated to determine the processed rule information; through the Ingress control component, the key-value prefix corresponding to each processed rule information is determined; through the Ingress control component, the processed rule information and the corresponding key-value prefix are dynamically configured into the target field in the rate limiting configuration file of the OpenResty gateway component in the preset password service platform.

[0071] Understandably, OpenResty is a high-performance web platform based on Nginx and LuaJIT (Lua Just-In-Time Compiler), combining Nginx's high concurrency capabilities with Lua's flexible scripting capabilities, supporting the migration of Lua code at various stages of request processing. Nginx is a lightweight, high-performance HTTP and reverse proxy web server. Furthermore, combined with... Figure 2 As shown, the preset password service platform can be built on Kubernetes (K8s for short, an open-source container orchestration platform).

[0072] Furthermore, the OpenResty component's rate limiting configuration file is the Nginx configuration file, and this component sets the rate limiting rules as input parameters to the Lua script. Afterwards, the component reloads Nginx and the rules take effect immediately.

[0073] It is important to understand that, in combination Figure 2 and Figure 3 As shown, the main process for setting TPS or BPS traffic limiting rules can be summarized as follows:

[0074] (1) The page interaction component sets appropriate TPS or BPS traffic limiting rules for the service interfaces of different computing services of different applications (distinguished by App-ID), namely, the cryptographic computing service interface (distinguished by URI). For example, the categories of cryptographic computing service interfaces can be divided into: generating random numbers, digest operation, MAC operation (multiply-accumulate operation), encryption asymmetric operation, decryption asymmetric operation, signature asymmetric operation, signature verification asymmetric operation, and encryption / decryption symmetric operation, etc.; each rate limiting rule can be divided into multiple fields, namely rule name, rule type, rate limit, and interface rule; among them, App-ID, Application-Identity, is the application identification information; the rule type is divided into two types: BPS and TPS. The rate limit corresponding to BPS represents the request rate, while the rate limit corresponding to TPS represents the traffic rate; the interface rule is generally a regular expression.

[0075] (2) Page interaction components are sent to Ingress control components through annotations. Note that different applications have corresponding Ingress resources. Therefore, annotations need to be sent to the Ingress resources corresponding to the application.

[0076] (3) The Ingress control component needs to examine and integrate the TPS or BPS traffic limiting rules in the Ingress resources and filter out illegal or duplicate rate limiting rules.

[0077] (4) The Ingress control component will generate a unique key value prefix for each interface’s TPS or BPS traffic limit rule. This value will be used in the OpenResty first-level cache and Redis second-level cache (Remotedictionary server).

[0078] (5) The Ingress control component will dynamically configure the integrated rate limiting rules and the generated Key value prefix into the configuration file of the OpenResty gateway module and the location field corresponding to the interface, and ensure that the Nginx / OpenResty service is reloaded and takes effect immediately.

[0079] Step S12: After completing the configuration of the rate limiting configuration file, when a password calculation service request sent by a client is received through the OpenResty gateway component, based on the rate limiting configuration file, the local cache or Redis cache component, and the application identification information in the password calculation service request, it is determined whether to reject the current password calculation service request in order to complete the network traffic control operation.

[0080] In this embodiment, combined with Figure 2 and Figure 4 As shown, when any node in the platform receives a password computation service request from a client, it will perform matching and judgment related to the first and second rate limiting rules to determine whether the request meets the current rate limiting requirements. If not, it will be rejected. Specifically: when the password computation service request from the client is received through the OpenResty gateway component and in conjunction with the corresponding encrypted channel, the application identifier information in the password computation service request is obtained; the target rule information corresponding to the application identifier information is determined through the OpenResty gateway component and in conjunction with the rate limiting configuration file; the Uniform Resource Identifier corresponding to the password computation service request is matched with the regular expression in the target rule information through the OpenResty gateway component to determine the matching result; and the password computation service request is rejected based on the matching result, the local cache, or the Redis cache component, to complete the network traffic control operation. It should be understood that the local cache of the OpenResty gateway component is the OpenResty first-level cache, and the cache in the Redis cache component is the Redis second-level cache.

[0081] In other words, after clients from different users establish a secure encrypted channel with the server (i.e., the OpenResty gateway component), they will include a pre-defined App-ID in the request header of the password calculation service request, indicating that the user can use the application service corresponding to the App-ID. Then, the OpenResty gateway component will iterate through all rate limiting rules related to that App-ID, matching the URI of this request with the regular expressions in the rate limiting rules. If a match is successful, it can obtain the corresponding Key value in the cache and perform subsequent judgment operations based on that Key value.

[0082] Furthermore, in combination Figure 5As shown, the first request judgment operation corresponding to the first rate limiting rule, in this embodiment, includes: if the matching result indicates that any regular expression corresponding to the first rate limiting rule information is matched, then the first target key value is determined through the OpenResty gateway component; the traffic data reflecting the transaction processing speed corresponding to the first target key value in the local cache is queried through the OpenResty gateway component to determine the first data query result; if the first data query result indicates that the query is successful, then the remaining capacity of the current cache in the local cache is determined using the first data query result to determine whether it is greater than the data volume of the cryptographic computation service request to determine the first judgment result; if the first judgment result is yes, then the cryptographic computation service request is determined to have successfully passed the first... The request involves a judgment operation. If the first data query result indicates a query failure or the first judgment result is negative, then based on the leaky bucket algorithm, a corresponding bucket balance query is performed on the traffic data reflecting transaction processing speed corresponding to the first target key value in the Redis cache component to determine the second data query result. If the second data query result indicates that the queried bucket balance is greater than a first preset threshold, then the second data query result is used to determine whether the current remaining cache capacity in the Redis cache component is greater than the data volume requested by the cryptographic computation service to determine the second judgment result. If the second judgment result is positive, then the cryptographic computation service request is determined to have successfully passed the first request judgment operation. If the second judgment result is negative, then the current cryptographic computation service request is determined to be rejected.

[0083] In other words, in this embodiment, the system first accesses the OpenResty first-level cache to query the TPS content corresponding to the Key value. If the content is found, it further checks whether there is a sufficient number of available request attempts. If so, the OpenResty first-level cache capacity is updated based on this judgment, and the amount of data requested in this request is subtracted. If no TPS content is found, or if there is no remaining number of request attempts, the system accesses the Redis second-level cache component to attempt to prefetch one-tenth of the TPS bucket capacity. If the attempt succeeds, the system is determined accordingly. If the attempt fails, the password calculation service request is rejected.

[0084] Combination Figure 6As shown, the second request judgment operation corresponding to the second rate limiting rule, in this embodiment, includes: if the matching result indicates that any regular expression corresponding to the second rate limiting rule information is matched, then the second target key value is determined through the OpenResty gateway component; the traffic data reflecting the data transmission rate corresponding to the second target key value in the local cache is queried through the OpenResty gateway component to determine the third data query result; if the third data query result indicates that the query is successful, then the remaining capacity of the current cache in the local cache is determined using the third data query result to determine whether it is greater than the data volume of the cryptographic calculation service request to determine the third judgment result; if the third judgment result is yes, then the cryptographic calculation service request is determined to have successfully passed the second rate limiting rule. The process involves several steps: First, a request for judgment is initiated. If the third data query result indicates a query failure or the third judgment result is negative, then based on the leaky bucket algorithm, a corresponding bucket balance query is performed on the traffic data reflecting the data transmission rate corresponding to the second target key value in the Redis cache component to determine the fourth data query result. If the fourth data query result indicates that the queried bucket balance is greater than a second preset threshold, then the fourth data query result is used to determine whether the current remaining cache capacity in the Redis cache component is greater than the data volume requested by the cryptographic computation service to determine the fourth judgment result. If the fourth judgment result is positive, then the cryptographic computation service request is determined to have successfully passed the second request judgment operation. If the fourth judgment result is negative, then the current cryptographic computation service request is determined to be rejected.

[0085] In other words, in this embodiment, the system further accesses the OpenResty first-level cache to query the BPS content corresponding to the Key value. If the content is found, it further checks whether there is sufficient available request byte quota. If so, it determines and updates the OpenResty first-level cache capacity by subtracting the data size of this request. If no BPS content is found, or if there is no remaining request byte quota, it accesses the Redis second-level cache module to attempt to prefetch one-tenth of the BPS bucket capacity. If the attempt succeeds, it determines whether to prefetch. If the attempt fails, it rejects the password calculation service request.

[0086] Furthermore, in this embodiment, if both the first and second request checks corresponding to TPS and BPS pass, the current password computation service request is allowed. That is, if the password computation service request successfully passes the first and second request checks, the OpenResty gateway component authenticates the password computation service request to determine the authentication result. If the authentication result shows that the authentication is successful, the password computation service request is stored in the pending request queue. In other words, even if the request is allowed, authentication is still required. If the authentication is successful, the request is queued by the backend for processing; otherwise, if the authentication fails, the request is rejected.

[0087] Step S13: During the network traffic control process, the monitoring component on any node of the preset password service platform collects the traffic data in the Redis cache component, and combines it with the preset anomaly detection rules to determine the target monitoring result and the alarm trigger judgment result corresponding to the target monitoring result, so as to complete the network traffic monitoring operation.

[0088] In this embodiment, combined with Figure 2 As shown, in addition to network traffic control, network traffic is monitored through a monitoring component on any node in the platform to achieve early warning. Specifically, for any node in the preset password service platform, the monitoring component on the current node, combined with a preset monitoring period, collects traffic data from the Redis cache component to determine the data collection results. The data collection results include traffic data reflecting transaction processing speed and traffic data reflecting data transmission rate. The monitoring component analyzes the data collection results and uses the corresponding target monitoring results and preset anomaly detection rules to determine the alarm trigger judgment result. If the alarm trigger judgment indicates that the current target monitoring result meets the alarm triggering conditions, the monitoring component sends the target monitoring result to the alarm component on the current node. The alarm component determines the alarm information corresponding to the target monitoring result and, combined with preset alarm rules, triggers alarm measures. The alarm component reports the alarm information to the page interaction component.

[0089] In other words, once any node on the platform activates its monitoring component, this component periodically collects TPS and BPS data from the Redis secondary cache component. It then analyzes this data, and if the analysis indicates an impending or actual anomaly, it immediately notifies the alerting component on the same node. The alerting component then sends alerts via logs, emails, and other means, and also reports them to the interactive web interface, allowing the security administrator to receive the alert information.

[0090] In addition, combined Figure 2 As shown in this embodiment, the page interaction component can also query the real-time rate limiting status from the Redis second-level cache component and reflect the real-time rate limiting status to the security administrator.

[0091] In summary, this embodiment provides detailed differentiation and processing for both TPS and BPS rate limiting scenarios; by integrating monitoring data from Redis secondary cache, early warnings can be issued; TPS and BPS rate limiting rules are applicable to the cryptographic computation service, enabling precise traffic control for different interfaces of different users; combining OpenResty primary cache and Redis secondary cache for network traffic control ensures accurate rate limiting in multi-replica Nginx Ingress Controller container Pod scenarios, while also mitigating performance degradation caused by frequent access to remote dictionary services. The Nginx Ingress Controller is a Kubernetes Ingress controller based on Nginx, responsible for managing HTTP / HTTPS (Hypertext Transfer Protocol Secure) traffic from outside the cluster to services within the cluster. It dynamically generates and reloads the Nginx configuration by monitoring the Ingress resource rules of the Kubernetes cluster.

[0092] Therefore, this application configures the rate limiting profile in the OpenResty gateway component by using the page interaction component and Ingress control component in the preset password service platform. Then, when the OpenResty gateway component receives a password calculation service request from a client, it determines whether to reject the current password calculation service request based on the rate limiting profile, the local cache or Redis cache component, and the application identifier information in the password calculation service request. Furthermore, the monitoring component on any node in the preset password service platform collects traffic data from the Redis cache component and, combined with preset anomaly detection rules, determines the target monitoring result and the corresponding alarm trigger judgment result. This approach solves the problems existing in related solutions, effectively achieving accurate and real-time network traffic control and monitoring in both TPS and BPS rate limiting scenarios, and providing early warnings. This ensures accurate rate limiting in multi-replica Nginx Ingress Controller container Pod scenarios and mitigates the performance degradation caused by frequent access to remote dictionary services.

[0093] The following is combined with Figures 2 to 6 The schematic diagram disclosed herein provides a detailed description of the technical solutions of the embodiments of this application.

[0094] Combination Figure 2 As shown, the components involved in this embodiment include: a page interaction component, an Ingress control component, an OpenResty gateway component, a Redis caching component, a monitoring component, and an alarm component. The main functional descriptions of each component are as follows:

[0095] (1) Page interaction component: First, it is responsible for providing an interactive page, supporting the setting of appropriate TPS or BPS traffic limit rules for the service interfaces of different computing services of different applications, and sending them to the Ingress control component through annotation; second, it is responsible for providing a query page, supporting the query of real-time rate limit status from the Redis cache component; third, it is responsible for displaying the alarm information detected by the alarm component on the page.

[0096] (2) Ingress control component: mainly responsible for dynamically configuring the TPS or BPS traffic limit rules set by the page interaction component into the configuration file of the OpenResty gateway component, and ensuring that the Nginx / OpenResty service is reloaded and takes effect immediately.

[0097] (3) OpenResty gateway component: responsible for rate limiting control of password calculation service requests from different clients: First, obtain the key configuration information of rate limiting according to the rate limiting configuration file; then, access the local OpenResty first-level cache to query the rate limiting status information; if the local cache does not retrieve the rate limiting status information, access the Redis cache component to obtain the rate limiting status information, and determine whether to allow the current password calculation service request based on the retrieval result.

[0098] (4) Redis caching component: This can be a single Redis node or a multi-node Redis cluster with sentinel mode enabled. Firstly, it is responsible for storing the TPS or BPS rate limiting status of different interfaces for different password calculation services; secondly, it supports the page interaction component to query the real-time rate limiting status; and thirdly, it supports the monitoring component to collect monitoring data periodically. Furthermore, the TPS and BPS rate limiting algorithms in this component both use the leaky bucket algorithm.

[0099] (5) Monitoring component: responsible for periodically collecting the rate limiting status in the Redis caching component and detecting the rate limiting data. If an anomaly is detected or an anomaly has already occurred, the alarm component will be notified.

[0100] (6) Alarm component: responsible for issuing alarms in the form of logs, emails, etc. for abnormal information detected by the monitoring component, and also reporting to the page interaction component.

[0101] It's important to understand that, regarding the Redis caching component, when performing the first or second request judgment operation based on the leaky bucket algorithm for this password calculation service request, the processing flow of the leaky bucket algorithm will be explained using either request judgment operation as an example. Specifically: After the local cache judgment of the OpenResty gateway component fails, the remaining bucket capacity in the Redis caching component is compared with the amount of data in this request. If the latter is larger, the cache component is updated and the request is rejected; otherwise, the bucket capacity in the cache component is increased by the amount of data in this request. After increasing the bucket capacity, it is checked whether the remaining bucket capacity in the cache component is greater than a preset proportion (e.g., one-tenth of the bucket capacity). If it is not greater, the cache component is updated; otherwise, if it is greater than the preset proportion, the cache component is increased again by the amount of bucket capacity equal to the preset proportion. Then, the Redis cache is updated, and the capacity of the local cache of the OpenResty gateway component is updated according to the increase in the Redis caching component capacity. This completes the request judgment operation.

[0102] Subsequently, if both the first and second rate-limiting rules are matched, the execution status of the operation is assessed based on the first and second requests to determine whether the current password calculation service request is allowed. If both are allowed, the current password calculation service request is stored in the backend's pending request queue for later processing in order, and a response is sent back to the corresponding user's client. It can be understood that if only the first or second rate-limiting rule is matched, the execution status of the operation is assessed based on either the first or second request to determine whether the current password calculation service request is allowed.

[0103] See Figure 7 As shown in the illustration, this application also discloses a network traffic monitoring device applied to a preset password service platform, comprising:

[0104] The rate limiting configuration module 11 is used to configure the rate limiting configuration file in the OpenResty gateway component of the preset password service platform through the page interaction component and the Ingress control component in the preset password service platform; wherein, the rate limiting configuration file includes first rate limiting rule information for transaction processing speed and / or second rate limiting rule information for data transmission rate corresponding to each application;

[0105] The traffic control module 12 is used to determine whether to reject the current password calculation service request based on the rate limiting configuration file, the local cache or Redis cache component, and the application identification information in the password calculation service request when it receives a password calculation service request sent by the client through the OpenResty gateway component after the rate limiting configuration file is completed, so as to complete the network traffic control operation.

[0106] The traffic monitoring module 13 is used to collect traffic data in the Redis cache component through the monitoring component on any node of the preset password service platform during the network traffic control process, and determine the target monitoring result and the alarm trigger judgment result corresponding to the target monitoring result in combination with the preset anomaly detection rules, so as to complete the network traffic monitoring operation.

[0107] In some specific embodiments, the rate limiting configuration module 11 may specifically include:

[0108] The rule acquisition unit is used to acquire and set rate limiting rule information corresponding to the password calculation service interface of each application through the interactive interface of the page interaction component in the preset password service platform; the rate limiting rule information includes first rate limiting rule information for transaction processing speed and / or second rate limiting rule information for data transmission rate;

[0109] The rule distribution unit is used to distribute the rate limiting rule information to the Ingress control component in the preset password service platform through the interactive interface in the page interaction component and by means of annotation.

[0110] The rule processing unit is used to verify and integrate the rate limiting rule information stored in the Ingress resources corresponding to each of the applications through the Ingress control component, so as to determine the processed rule information.

[0111] The key value prefix determination unit is used to determine the key value prefix corresponding to each of the processed rule information through the Ingress control component;

[0112] The field configuration unit is used to dynamically configure the processed rule information and the corresponding key-value prefix into the target field of the rate limiting configuration file of the OpenResty gateway component in the preset password service platform through the Ingress control component.

[0113] In some specific embodiments, the flow control module 12 may specifically include:

[0114] The request receiving unit is used to obtain the application identification information in the password calculation service request when it receives a password calculation service request sent by the client through the OpenResty gateway component and in conjunction with the corresponding encrypted channel.

[0115] The rule determination unit is used to determine the target rule information corresponding to the application identification information by means of the OpenResty gateway component and in combination with the rate limiting configuration file;

[0116] The rule matching unit is used to match the Uniform Resource Identifier corresponding to the cryptographic computation service request with the regular expression in the target rule information through the OpenResty gateway component to determine the matching result;

[0117] The traffic control unit is used to determine whether to reject the current password calculation service request through the OpenResty gateway component and based on the matching result, local cache or Redis cache component, in order to complete the network traffic control operation.

[0118] In some specific embodiments, the flow control unit may specifically include:

[0119] The first key value determination subunit is used to determine the first target key value through the OpenResty gateway component if the matching result shows that the regular expression corresponding to any of the first rate limiting rule information is matched.

[0120] The first data query subunit is used to query the traffic data reflecting the transaction processing speed corresponding to the first target key value in the local cache through the OpenResty gateway component, so as to determine the first data query result;

[0121] The first judgment subunit is used to determine whether the remaining capacity of the current cache in the local cache is greater than the amount of data requested by the password calculation service if the first data query result indicates that the query was successful, so as to determine the first judgment result.

[0122] The first request passing subunit is used to determine that the cryptographic calculation service request has successfully passed the first request judgment operation if the first judgment result is yes;

[0123] The second data query subunit is used to perform a corresponding bucket balance query on the traffic data reflecting the transaction processing speed corresponding to the first target key value in the Redis cache component based on the leaky bucket algorithm if the first data query result indicates that the query failed or the first judgment result is negative, so as to determine the second data query result.

[0124] The second judgment subunit is used to determine whether the current remaining capacity of the Redis cache component is greater than the amount of data requested by the password calculation service if the second data query result shows that the remaining amount of the queried bucket is greater than the first preset threshold, so as to determine the second judgment result.

[0125] The second request passing subunit is used to determine that the cryptographic calculation service request has successfully passed the first request judgment operation if the second judgment result is yes;

[0126] The first request rejection subunit is used to determine to reject the current cryptographic calculation service request if the second judgment result is negative.

[0127] In some specific embodiments, the flow control unit may specifically include:

[0128] The second key value determination subunit is used to determine the second target key value through the OpenResty gateway component if the matching result shows that the regular expression corresponding to any of the second rate limiting rule information is matched.

[0129] The third data query subunit is used to query the traffic data reflecting the data transmission rate corresponding to the second target key value in the local cache through the OpenResty gateway component, so as to determine the third data query result;

[0130] The third judgment subunit is used to determine whether the remaining capacity of the current cache in the local cache is greater than the amount of data requested by the password calculation service if the third data query result indicates that the query was successful, so as to determine the third judgment result.

[0131] The third request pass subunit is used to determine that the cryptographic calculation service request has successfully passed the second request judgment operation if the third judgment result is yes;

[0132] The fourth data query subunit is used to perform a corresponding bucket balance query on the traffic data reflecting the data transmission rate corresponding to the second target key value in the Redis cache component based on the leaky bucket algorithm if the third data query result indicates that the query failed or the third judgment result is negative, so as to determine the fourth data query result.

[0133] The fourth judgment subunit is used to determine whether the current remaining capacity of the Redis cache component is greater than the amount of data requested by the password calculation service if the fourth data query result shows that the remaining amount of the queried bucket is greater than the second preset threshold, so as to determine the fourth judgment result.

[0134] The fourth request is passed by the sub-unit, which is used to determine that the cryptographic calculation service request has successfully passed the second request judgment operation if the fourth judgment result is yes;

[0135] The second request rejection subunit is used to determine to reject the current cryptographic calculation service request if the fourth judgment result is negative.

[0136] In some specific embodiments, the network traffic monitoring device may further include:

[0137] An authentication subunit is used to authenticate the password calculation service request through the OpenResty gateway component if the password calculation service request successfully passes the first request judgment operation and the second request judgment operation, so as to determine the authentication result;

[0138] The queue storage subunit is used to store the password calculation service request in the pending request queue if the authentication result indicates that the authentication is successful.

[0139] In some specific embodiments, the traffic monitoring module 13 may specifically include:

[0140] The data acquisition unit is used to collect traffic data in the Redis cache component for any node in the preset password service platform through the monitoring component on the current node and in combination with a preset monitoring period, so as to determine the data acquisition results; the data acquisition results include traffic data reflecting transaction processing speed and traffic data reflecting data transmission rate;

[0141] An anomaly detection unit is used to analyze the data acquisition results through the monitoring component, and determine the alarm trigger judgment result by using the corresponding target monitoring results and preset anomaly detection rules.

[0142] The monitoring result sending unit is used to send the target monitoring result to the alarm component on the current node through the monitoring component if the alarm triggering judgment indicates that the current target monitoring result meets the alarm triggering condition.

[0143] An alarm triggering unit is used to determine the alarm information corresponding to the target monitoring result through the alarm component, and trigger alarm measures in conjunction with preset alarm rules;

[0144] An alarm information reporting unit is used to report the alarm information to the page interaction component through the alarm component.

[0145] Furthermore, embodiments of this application also disclose an electronic device, Figure 8This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.

[0146] Figure 8 This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the network traffic monitoring method disclosed in any of the foregoing embodiments. Furthermore, the electronic device 20 in this embodiment may specifically be a computer.

[0147] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.

[0148] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221, computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0149] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of performing the network traffic monitoring method executed by the electronic device 20 as disclosed in any of the foregoing embodiments, the computer program 222 may further include a computer program capable of performing other specific tasks.

[0150] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned network traffic monitoring method. Specific steps of this method can be found in the corresponding content disclosed in the foregoing embodiments, and will not be repeated here.

[0151] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.

[0152] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0153] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0154] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0155] The technical solutions provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A network traffic monitoring method, characterized in that, Applied to pre-defined password service platforms, including: The rate limiting configuration file in the OpenResty gateway component of the preset password service platform is configured through the page interaction component and Ingress control component in the preset password service platform; wherein, the rate limiting configuration file includes first rate limiting rule information for transaction processing speed and / or second rate limiting rule information for data transmission rate corresponding to each application; After the rate limiting configuration file is configured, when a password calculation service request sent by a client is received through the OpenResty gateway component, the system determines whether to reject the current password calculation service request based on the rate limiting configuration file, the local cache or Redis cache component, and the application identification information in the password calculation service request, so as to complete the network traffic control operation. During network traffic control, the monitoring component on any node of the preset password service platform collects traffic data from the Redis cache component, and combines it with preset anomaly detection rules to determine the target monitoring result and the alarm trigger judgment result corresponding to the target monitoring result, so as to complete the network traffic monitoring operation.

2. The network traffic monitoring method according to claim 1, characterized in that, The configuration of the rate limiting configuration file in the OpenResty gateway component on the preset password service platform through the page interaction component and Ingress control component includes: The system obtains and sets rate limiting rule information corresponding to the password calculation service interfaces of each application through the interactive interface of the page interaction component in the preset password service platform; the rate limiting rule information includes first rate limiting rule information for transaction processing speed and / or second rate limiting rule information for data transmission rate. The rate limiting rule information is sent to the Ingress control component in the preset password service platform through the interactive interface in the page interaction component and by means of annotation. The Ingress control component verifies and integrates the rate limiting rule information stored in the Ingress resources corresponding to each application to determine the processed rule information. The Ingress control component determines the key-value prefix corresponding to each of the processed rule information. The Ingress control component dynamically configures the processed rule information and the corresponding key-value prefix into the target field of the rate limiting configuration file of the OpenResty gateway component in the preset password service platform.

3. The network traffic monitoring method according to claim 1, characterized in that, When a password computation service request is received from a client through the OpenResty gateway component, the system determines whether to reject the current password computation service request based on the rate limiting configuration file, the local cache or Redis cache component, and the application identifier information in the password computation service request, in order to complete the network traffic control operation, including: When a password calculation service request sent by a client is received through the OpenResty gateway component and in conjunction with the corresponding encrypted channel, the application identification information in the password calculation service request is obtained. Using the OpenResty gateway component and the rate limiting configuration file, the target rule information corresponding to the application identification information is determined; The OpenResty gateway component matches the Uniform Resource Identifier corresponding to the cryptographic computation service request with the regular expression in the target rule information to determine the matching result. The OpenResty gateway component, based on the matching results, local cache, or Redis cache component, determines whether to reject the current password calculation service request to complete the network traffic control operation.

4. The network traffic monitoring method according to claim 3, characterized in that, The step of determining whether to reject the current password calculation service request through the OpenResty gateway component and based on the matching result, local cache, or Redis cache component includes: If the matching result indicates that any of the regular expressions corresponding to the first rate limiting rule information are matched, then the first target key value is determined through the OpenResty gateway component; The OpenResty gateway component is used to query the traffic data in the local cache that corresponds to the first target key value and reflects the transaction processing speed, so as to determine the first data query result. If the first data query result indicates that the query was successful, then the first data query result is used to determine whether the remaining capacity of the current cache in the local cache is greater than the amount of data requested by the password calculation service, so as to determine the first judgment result; If the first judgment result is yes, then it is determined that the password calculation service request has successfully passed the first request judgment operation; If the first data query result indicates that the query failed or the first judgment result is negative, then based on the leaky bucket algorithm, the corresponding bucket balance query is performed on the traffic data reflecting the transaction processing speed corresponding to the first target key value in the Redis cache component to determine the second data query result. If the second data query result indicates that the remaining bucket capacity is greater than the first preset threshold, then the second data query result is used to determine whether the current remaining cache capacity in the Redis cache component is greater than the amount of data requested by the password calculation service, so as to determine the second judgment result; If the second judgment result is yes, then it is determined that the password calculation service request has successfully passed the first request judgment operation; If the second determination result is negative, then the current request for cryptographic calculation service is rejected.

5. The network traffic monitoring method according to claim 4, characterized in that, The step of determining whether to reject the current password calculation service request through the OpenResty gateway component and based on the matching result, local cache, or Redis cache component includes: If the matching result indicates that any of the regular expressions corresponding to the second rate limiting rule information are matched, then the second target key value is determined through the OpenResty gateway component; The OpenResty gateway component is used to query the traffic data reflecting the data transmission rate corresponding to the second target key value in the local cache in order to determine the third data query result; If the third data query result indicates that the query was successful, then the third data query result is used to determine whether the remaining capacity of the current cache in the local cache is greater than the amount of data requested by the password calculation service, so as to determine the third judgment result; If the third judgment result is yes, then it is determined that the password calculation service request has successfully passed the second request judgment operation; If the third data query result indicates that the query failed or the third judgment result is negative, then based on the leaky bucket algorithm, the corresponding bucket balance query is performed on the traffic data reflecting the data transmission rate corresponding to the second target key value in the Redis cache component to determine the fourth data query result. If the fourth data query result indicates that the remaining bucket capacity is greater than the second preset threshold, then the fourth data query result is used to determine whether the current remaining cache capacity in the Redis cache component is greater than the amount of data requested by the password calculation service, so as to determine the fourth judgment result. If the fourth judgment result is yes, then it is determined that the cryptographic calculation service request has successfully passed the second request judgment operation; If the fourth determination result is negative, then the current request for cryptographic calculation service is rejected.

6. The network traffic monitoring method according to claim 5, characterized in that, Also includes: If the cryptographic computation service request successfully passes the first request judgment operation and the second request judgment operation, then the OpenResty gateway component is used to authenticate the cryptographic computation service request to determine the authentication result. If the authentication result indicates that the authentication is successful, the password calculation service request is stored in the pending request queue.

7. The network traffic monitoring method according to claim 1, characterized in that, The step involves collecting traffic data from the Redis cache component through a monitoring component on any node of the preset password service platform, and combining this data with preset anomaly detection rules to determine the target monitoring result and the alarm trigger judgment result corresponding to the target monitoring result, including: For any node in the preset password service platform, the traffic data in the Redis cache component is collected through the monitoring component on the current node and in combination with the preset monitoring period to determine the data collection results; the data collection results include traffic data reflecting the transaction processing speed and traffic data reflecting the data transmission rate; The monitoring component analyzes the data collection results and uses the corresponding target monitoring results and preset anomaly detection rules to determine the alarm trigger judgment result. If the alarm triggering judgment indicates that the current target monitoring result meets the alarm triggering condition, then the target monitoring result is sent to the alarm component on the current node through the monitoring component; The alarm component determines the alarm information corresponding to the target monitoring result and, in conjunction with preset alarm rules, triggers alarm measures. The alarm component reports the alarm information to the page interaction component.

8. A network traffic monitoring device, characterized in that, Applied to pre-defined password service platforms, including: The rate limiting configuration module is used to configure the rate limiting configuration file in the OpenResty gateway component of the preset password service platform through the page interaction component and Ingress control component in the preset password service platform; wherein, the rate limiting configuration file includes first rate limiting rule information for transaction processing speed and / or second rate limiting rule information for data transmission rate corresponding to each application; The traffic control module is used to determine whether to reject the current password calculation service request after the configuration of the rate limiting configuration file is completed, when a password calculation service request sent by a client is received through the OpenResty gateway component, based on the rate limiting configuration file, the local cache or Redis cache component, and the application identification information in the password calculation service request, so as to complete the network traffic control operation. The traffic monitoring module is used to collect traffic data from the Redis cache component through the monitoring component on any node of the preset password service platform during the network traffic control process, and combine it with preset anomaly detection rules to determine the target monitoring result and the alarm trigger judgment result corresponding to the target monitoring result, so as to complete the network traffic monitoring operation.

9. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the network traffic monitoring method as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, Used to store a computer program, which, when executed by a processor, implements the network traffic monitoring method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Flow control method and device, computer equipment and storage medium

    CN113220723A

  • Intelligent gateway dynamic flow limiting implementation method

    CN113595925A