A two-layer network security defense method, device and electronic equipment

By working together with an intelligent analysis platform and virtual switches, abnormal traffic is intercepted at external physical switches using network topology information. This solves the problem that Layer 2 network defense solutions cannot intercept traffic in advance, thus improving network security and stability.

CN122027372BActive Publication Date: 2026-07-17JINAN INSPUR DATA TECH CO LTD +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
JINAN INSPUR DATA TECH CO LTD
Filing Date
2026-04-15
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

In existing technologies, Layer 2 network security defense solutions cannot intercept abnormal traffic entering the host machine in advance, causing traffic to overwhelm the network and affecting business and data security.

Method used

By working together with the intelligent analysis platform and the virtual switch, abnormal traffic is identified using network topology information, and abnormal traffic is intercepted at the Layer 2 network entry point of the external physical switch to prevent it from entering the host machine.

Benefits of technology

It achieves precise interception of abnormal traffic in Layer 2 networks, avoiding the problem of traffic impacting the network and improving network security and stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122027372B_ABST
    Figure CN122027372B_ABST
Patent Text Reader

Abstract

This application discloses a Layer 2 network security defense method, apparatus, and electronic device, relating to the field of computer network and information security technology. The method includes: receiving the first data packet reported by a virtual switch; determining abnormal traffic in the first data packet based on the network topology information of the virtual switch to identify whether it is Layer 2 abnormal traffic; generating an interception suggestion and sending it to the virtual switch for confirmation if Layer 2 abnormal traffic is detected; and triggering an external physical switch to intercept subsequent data streams matching the first data packet at the Layer 2 network entry point in response to the received confirmation response from the virtual switch. This solves the technical problem that Layer 2 network security defense schemes cannot intercept abnormal traffic entering the host machine in advance, leading to network congestion, and achieves the technical effect of improving Layer 2 network security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer network and information security technology, and in particular to a two-layer network security defense method, device and electronic equipment. Background Technology

[0002] In cloud computing environments, data center network security is of paramount importance. Current mainstream security mechanisms focus on IP-level protection for Layer 3 networks, while paying insufficient attention to security threats to Layer 2 networks.

[0003] In Layer 2 networks, typical security risks include broadcast loops; in addition, there is a more insidious threat—the flooding of a large number of unknown unicast frames. Existing Layer 2 network security defense solutions in existing data centers or cloud computing data centers mostly configure security rules on the data center or cloud hosts, failing to intercept these abnormal traffic flows into the host machine in advance. This can lead to network congestion and have a very negative impact on business operations or data. Summary of the Invention

[0004] This application provides a two-layer network security defense method, apparatus, and electronic device to at least solve the problem that two-layer network security defense schemes in related technologies cannot intercept abnormal traffic entering the host machine in advance, resulting in traffic impacting the network.

[0005] This application provides a Layer 2 network security defense method applied to an intelligent analysis platform, comprising: receiving the first data packet reported by a virtual switch; determining abnormal traffic in the first data packet based on the network topology information of the virtual switch to identify whether it is Layer 2 abnormal traffic; if Layer 2 abnormal traffic is determined to exist, generating an interception suggestion and sending it to the control process of the virtual switch to request confirmation; and in response to receiving the confirmation response from the control process, triggering an external physical switch to intercept subsequent data streams matching the first data packet at the Layer 2 network ingress.

[0006] This application also provides a Layer 2 network security defense method applied to a virtual switch, comprising: reporting the first acquired data packet to an intelligent analysis platform; receiving an interception suggestion sent by the intelligent analysis platform, wherein the interception suggestion is generated by judging abnormal traffic of the first data packet based on the network topology information of the virtual switch; verifying the interception suggestion, and sending a confirmation response to the intelligent analysis platform if the verification result indicates that traffic interception is required, so that the intelligent analysis platform responds to the confirmation response and triggers an external physical switch to intercept subsequent data streams matching the first data packet at the Layer 2 network entry point.

[0007] This application also provides a Layer 2 network security defense device located in an intelligent analysis platform, comprising: a first receiving module for receiving a first data packet reported by a virtual switch; a judgment module for judging abnormal traffic of the first data packet based on the network topology information of the virtual switch to identify whether it is Layer 2 abnormal traffic; a generation module for generating an interception suggestion and sending it to the control process of the virtual switch for confirmation when Layer 2 abnormal traffic is judged to exist; and an interception module for triggering an external physical switch to intercept subsequent data streams matching the first data packet at the Layer 2 network entry point in response to receiving the confirmation response from the control process.

[0008] This application also provides a Layer 2 network security defense device located in a virtual switch, comprising: a reporting module for reporting the first acquired data packet to an intelligent analysis platform; a second receiving module for receiving an interception suggestion sent by the intelligent analysis platform, wherein the interception suggestion is generated by judging abnormal traffic of the first data packet based on the network topology information of the virtual switch; and a verification module for verifying the interception suggestion and sending a confirmation response to the intelligent analysis platform if the verification result indicates that traffic interception is required, so that the intelligent analysis platform responds to the confirmation response and triggers an external physical switch to intercept subsequent data streams matching the first data packet at the Layer 2 network entry point.

[0009] This application also provides an electronic device, including: a memory for storing a computer program; and a processor for implementing the steps of the above-described two-layer network security defense method when executing the computer program.

[0010] This application also provides a computer-readable storage medium storing a computer program, wherein the computer program is configured to perform the steps in any of the above method embodiments when it is run.

[0011] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps in any of the above method embodiments.

[0012] This application utilizes an intelligent analysis platform for intelligent judgment of abnormal traffic, overcoming the limitations of existing solutions that rely on static rules or host-side filtering. Furthermore, by incorporating a confirmation mechanism within the control process, the interception action can be precisely moved forward to the Layer 2 entry point of the external physical switch, preventing abnormal traffic from intruding into the network. Therefore, it solves the technical problem of Layer 2 network security defense solutions failing to intercept abnormal traffic entering the host machine in advance, leading to network congestion and achieving the technical effect of improving Layer 2 network security. Attached Figure Description

[0013] To more clearly illustrate the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0014] Figure 1 This is a hardware structure block diagram of a computer terminal for a two-layer network security defense method according to an embodiment of this application;

[0015] Figure 2 This is a network architecture diagram of a two-layer network security defense system according to an embodiment of this application;

[0016] Figure 3 This is a flowchart illustrating a two-layer network security defense method according to an embodiment of this application;

[0017] Figure 4 This is a flowchart illustrating a two-layer network security defense method according to another embodiment of this application;

[0018] Figure 5 This is a structural block diagram of a two-layer network security defense device according to an embodiment of this application;

[0019] Figure 6 This is a structural block diagram of a two-layer network security defense device according to another embodiment of this application;

[0020] Figure 7 This is a structural block diagram of a two-layer network security defense device according to another embodiment of this application. Detailed Implementation

[0021] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of this application.

[0022] It should be noted that, in the description of this application, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. The terms "first," "second," etc., in this application are used to distinguish similar objects and are not used to describe a specific order or sequence.

[0023] To enable those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0024] The specific application environment architecture or specific hardware architecture on which the execution of the two-layer network security defense method depends is described here.

[0025] The methods and embodiments provided in this application can be executed on a computer terminal or similar computing device. Taking running on a computer terminal as an example, Figure 1 This is a hardware structure block diagram of a computer terminal for a two-layer network security defense method according to an embodiment of this application. Figure 1 As shown, a computer terminal may include one or more ( Figure 1 Only one is shown in the diagram. A processor 102 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and a memory 104 for storing data are also shown. The computer terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the computer terminal described above. For example, the computer terminal may also include components that are more complex than those described above. Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.

[0026] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the two-layer network security defense method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, thus implementing the aforementioned method. The memory 104 may include high-speed random access memory and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to a computer terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0027] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by a communication provider for the computer terminal. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module used for wireless communication with the Internet.

[0028] The two-layer network security defense method in this application mainly targets the defense against unknown unicast and external multicast packets outside the data center.

[0029] Among these, unknown unicast signals from outside the data center can impact the bandwidth of physical network interface cards (NICs) and the bandwidth of virtual switches on the data center host machine.

[0030] For external multicast packets, Layer 2 multicast packets are flooded to every network interface card (NIC) in the data center. However, for OVS master-slave bonding, the physical switch cannot determine the master device. When the physical switch receives a data frame with a destination MAC address of a multicast address (such as 01:00:5E.xx.xx.xx or 33:33.xx.xx.xx.xx) and there is no corresponding forwarding entry in its forwarding table, it will broadcast the frame to all ports except the receiving port (i.e., flood) to ensure that multicast members can receive the packet. Thus, when the multicast traffic is high, it will greatly consume the performance of the host machine.

[0031] Figure 2 This is a network architecture diagram of a two-layer network security defense system according to an embodiment of this application. The method can be applied to... Figure 2 On the two-tier network security defense system shown, such as Figure 2 As shown, the system includes a cloud host and an external physical switch; when the cloud host determines that traffic interception is necessary after traffic analysis, it can send an interception command to the external physical switch through out-of-band control commands.

[0032] The cloud server further includes the following components: Open Virtual Switch Database (OVSDB), Open Virtual Switch (OVS) user-space process, Artificial Intelligence (AI) platform, OVS kernel-space datapath, and network interface card.

[0033] In this embodiment, the OVS user-space process can be the virtual switch daemon (vswitchd).

[0034] The collaboration relationships between the components in the cloud server are as follows:

[0035] OVSDB: A configuration database running within the cloud host, used to record in real time the binding relationships of all virtual ports and physical network cards of the cloud host, as well as the port media access control (MAC) address mapping table. The port MAC address mapping table is a structured data table maintained in OVSDB that describes the correspondence between each logical port of the virtual switch and its bound valid Ethernet MAC address.

[0036] Network interface card (NIC): It is the physical channel for data to enter and exit the cloud host. Other components use it to collect traffic, identify identities, and perform protection.

[0037] OVS kernel-mode datapath: Deployed in the cloud host kernel space, it is responsible for high-speed forwarding of data packets obtained from the network interface card. When the first data packet (referred to as the first packet) is received, it is copied in parallel and sent to two user-mode components through the Netlink multicast mechanism: the OVS user-mode process and the AI ​​platform, realizing low-latency parallel distribution of traffic collection.

[0038] Netlink is a socket mechanism for communication between the Linux kernel and user-space processes, specifically used for exchanging control information and data between the kernel and user space.

[0039] The AI ​​platform is used for intelligent analysis and security determination of the first packet; specifically, it is used to query and obtain the MAC address binding information, port status and network topology of all ports in the virtual switch in real time by calling the remote interface of OVSDB, so as to make a decision on whether the network traffic is abnormal.

[0040] For example, if the first packet received is a unicast message and its destination MAC address is not registered in OVSDB on any legitimate port, it is determined to be an unknown unicast, which may be caused by network scanning, MAC spoofing or external attack.

[0041] If the first packet received is a multicast message, and based on the port and primary / backup binding mode recorded in OVSDB, this multicast traffic will cause redundant flooding on the physical switch side, then it is determined to be an abnormal multicast, which has significant bandwidth consumption and performance impact risks.

[0042] After completing the above intelligent analysis and generating interception suggestions, the AI ​​platform sends the interception suggestions to the OVS user-space process Vswitchd, requesting it to perform secondary verification based on local flow table rules to verify whether the interception suggestions are consistent with the current forwarding policy of the virtual switch, thereby avoiding false interception caused by topology synchronization delay or configuration conflict.

[0043] Upon receiving a confirmation response from Vswitchd and confirming the need for interception, the AI ​​platform sends a precise Layer 2 interception command to the external physical switch via the northbound interface. This blocks subsequent traffic flows matching the first packet at the entry point of the physical switch at the network edge, ensuring that abnormal packets are effectively intercepted before entering the cloud host's network card.

[0044] Vswitchd is used to collect traffic via Netlink multicast communication and to perform the final virtual network layer actions. Specifically, after receiving an interception suggestion, it determines whether the traffic should be intercepted based on its local flow table, port status, and the issued OpenFlow rules. If the verification passes, it returns a confirmation response to the AI ​​platform; if there is a conflict or uncertainty, it returns a rejection or pending signal.

[0045] In addition, external physical switches are used to perform precise interception actions at the very edge of the network.

[0046] Traditional solutions typically perform judgment and interception within the controller or virtual switch. However, in this embodiment, the AI ​​platform and physical switch are separated. Through instruction coordination and a two-layer security defense mechanism built by the OVS kernel-mode datapath, OVS user-mode processes, and the AI ​​platform, network security defense and bandwidth optimization are achieved.

[0047] Based on the aforementioned Layer 2 network security defense system, the Layer 2 network security defense method provided in this application uses Netlink multicast configuration to send received packets to the Vswitchd process and the AI ​​platform respectively, so that the AI ​​platform and the Vswitchd process can determine whether to intercept the packets. This method can more efficiently handle complex network environments and massive data packets, and solve network security problems caused by unknown unicast and external multicast packets outside the data center.

[0048] The method will be described in detail below with reference to the execution flow of the two-layer network security defense method provided in the embodiments of this application.

[0049] Figure 3 This is a flowchart illustrating a two-layer network security defense method according to an embodiment of this application, as shown below. Figure 3 As shown, the method includes the following steps:

[0050] Step S302: Receive the first data packet reported by the virtual switch; wherein, the virtual switch may be OVS;

[0051] Step S304: Based on the network topology information of the virtual switch, perform abnormal traffic determination on the first data packet to identify whether it is Layer 2 abnormal traffic;

[0052] Step S306: If abnormal Layer 2 traffic is detected, an interception suggestion is generated and sent to the virtual switch to request confirmation; wherein, the control process is functionally equivalent to the OVS user-space process Vswitchd in the above embodiment;

[0053] Step S308: In response to receiving the acknowledgment response from the virtual switch, the external physical switch is triggered to intercept subsequent data streams that match the first data packet at the Layer 2 network ingress.

[0054] Through the steps described in this application embodiment, abnormal traffic is intelligently determined based on an intelligent analysis platform, overcoming the limitations of existing technical solutions that rely on static rules or host-side filtering. Simultaneously, combined with the confirmation mechanism of the control process, the interception action can be precisely moved forward to the Layer 2 entry point of the external physical switch, preventing abnormal traffic from intruding into the network. Therefore, it can solve the technical problem that Layer 2 network security defense solutions cannot intercept abnormal traffic entering the host machine in advance, leading to traffic impact on the network, thus achieving the technical effect of improving Layer 2 network security.

[0055] In this embodiment, the two-layer network security defense method is applied to an intelligent analysis platform, which is functionally equivalent to the aforementioned AI platform.

[0056] This intelligent analysis platform implements a point defense mechanism that combines active detection and passive defense to achieve accurate identification and source blocking of abnormal traffic in Layer 2 networks:

[0057] Active detection: The intelligent analysis platform analyzes the first packet data reported by the virtual switch in real time, and dynamically determines whether the packet is abnormal traffic based on the port MAC binding relationship, physical interface status and virtual network topology information recorded in the database of the virtual switch. For example, unknown unicast with destination MAC not in the valid mapping table, or illegal multicast that causes redundancy flooding in the primary and backup binding scenario.

[0058] Passive defense: When the intelligent analysis platform confirms abnormal traffic, it does not rely on the host machine to drop the traffic locally. Instead, it triggers the external physical switch to perform precise interception at the data link layer through the command coordination mechanism. That is, it sends a Layer 2 ACL rule based on the destination MAC address to the physical switch, which forces hardware-level blocking before the traffic enters the host machine's physical network card, thus preventing abnormal packets from impacting the virtual switch and host machine resources from the source.

[0059] In one embodiment, the first data packet is reported via multicast communication over a network link and is simultaneously reported to the intelligent analysis platform and the control process of the virtual switch.

[0060] In one embodiment, the network link multicast communication method is configured as follows: the virtual switch kernel-mode datapath (OVS kernel-mode datapath) sends the first data packet to a predefined multicast group; receiving the first data packet reported by the virtual switch includes: the intelligent analysis platform receiving the first data packet by listening to the predefined multicast group.

[0061] In an exemplary embodiment, to achieve efficient, low-latency analysis and collaborative response to Layer 2 network traffic, OVS on the data center host utilizes the multicast characteristics of the Netlink socket mechanism (i.e., network link multicast communication method) provided by the Linux kernel to simultaneously send the first packet of the OVS kernel-mode datapath to vswitchd and the intelligent analysis platform.

[0062] Specifically, when OVS receives a new data packet (i.e., the first packet) that has never matched a flow table before, it simultaneously sends the first packet from the kernel-level datapath to the OVS user-space process Vswitchd and the intelligent analysis platform deployed on the host machine via a pre-configured Netlink multicast channel, enabling parallel processing. In this way, the intelligent analysis platform can acquire and analyze network traffic information in real time and independently, without waiting for the processing results of Vswitchd or relaying them through Vswitchd. Traditional SDN controllers typically need to "pull" traffic information from switches via southbound interfaces (such as OpenFlow) or wait for switches to "report" traffic information. This embodiment achieves proactive, parallel data push to the analysis components, reducing latency.

[0063] In this embodiment, the Netlink multicast group uses an independently defined multicast address.

[0064] Vswitchd and the intelligent analytics platform each create and bind a listening socket for the multicast group in user space, ensuring that both receive the same initial packet data in parallel and independently at the physical and protocol layers, without blocking each other or having any dependencies.

[0065] After receiving the first packet, Vswitchd performs flow table matching and forwarding decisions according to the normal process; meanwhile, the intelligent analysis platform simultaneously starts the analysis process, and by parsing the destination MAC address, source port information and other information of the packet, it queries the topology context of the port in OVSDB, such as the MAC binding status, whether it belongs to the primary and backup binding group, and whether it is a virtual machine or container interface, to quickly determine whether the traffic constitutes an unknown unicast flood or an abnormal multicast flood.

[0066] Because data replication occurs in kernel space, network overhead is extremely low, and the two processing paths operate in complete parallelism, completing the entire process within milliseconds. This ensures both the forwarding efficiency of Vswitchd for normal traffic and enables the intelligent analysis platform to intervene in security decisions in near real-time, providing accurate and timely judgment for subsequent interception commands to physical switches. This mechanism breaks the serial latency link of "report first, then analyze, then send" in traditional SDN architectures, achieving "zero-wait parallel processing" of traffic collection and intelligent analysis, significantly improving the response speed and system throughput of Layer 2 security defenses.

[0067] In one embodiment, network topology information includes: a port media access control MAC address mapping table maintained by the virtual switch.

[0068] The intelligent analysis platform in this embodiment performs security analysis not only based on payload information such as the source / destination MAC address of the packet, but also combined with network topology information such as the port binding relationship and the correspondence between MAC address and virtual interface recorded in the port MAC address mapping table of OVSDB, to perform multi-dimensional cross-verification and achieve a comprehensive judgment on abnormal traffic.

[0069] In one embodiment, abnormal traffic includes unknown unicast attack traffic and abnormal multicast traffic. Based on the network topology information of the virtual switch, the first data packet is judged to be abnormal traffic, including: if the first data packet is a unicast message and the destination MAC address of the first data packet is not in the port MAC address mapping table, the first data packet is judged to be unknown unicast attack traffic; if the first data packet is a multicast message and the multicast message is flooded on multiple physical interfaces, the first data packet is judged to be abnormal multicast traffic.

[0070] The intelligent analysis platform analyzes traffic behavior based on network topology and MAC address information in the virtual switch database, enabling dynamic and adaptive security policies and improving defense accuracy.

[0071] In an exemplary embodiment, after receiving the first packet reported by the OVS kernel-mode datapath via Netlink multicast, the intelligent analysis platform extracts key fields of the packet, such as the destination MAC address, source port identifier, Ethernet type, and physical network interface card number to which the ingress port belongs; and queries the local cache or directly accesses OVSDB in real time to obtain the binding status of the port, the list of legal MAC addresses of the associated virtual machine / container, port role, and historical traffic records.

[0072] If a destination MAC address is detected to have no port binding record in OVSDB, and the packet frequently enters from an external physical port (e.g., exceeding the threshold M times per unit time, where M is a positive integer), it is determined to be an unknown unicast scan or flood attack.

[0073] If the destination MAC address of a multicast packet is detected to belong to a standard multicast address range (such as 01:00:5E:xx:xx:xx), but no virtual port in OVSDB is subscribed to the multicast group, and the packet enters from both physical ports bound to the primary and backup servers, it is determined to be an unexpected multicast flood.

[0074] In one exemplary embodiment, when the intelligent analysis platform receives an Ethernet header packet via Netlink multicast, it parses the destination MAC address of the packet and queries the port MAC address mapping table in OVSDB. If the destination MAC address is not in any port binding record, and the packet originates from the ingress port of an external physical switch, the intelligent analysis platform determines it to be external unknown unicast traffic. Subsequently, the intelligent analysis platform sends an interception suggestion to Vswitchd. After Vswitchd verifies that the flow table policy has no conflicts, it returns a response confirming the interception to the intelligent analysis platform. Based on the received response information, the intelligent analysis platform issues precise Layer 2 ACL rules to the external physical switch, instructing the external physical switch to discard all subsequent packets matching the destination MAC address on the corresponding ingress port, thereby blocking the flooding path before the traffic enters the host machine and preventing it from being broadcast in the Layer 2 network.

[0075] In an exemplary embodiment, when the intelligent analysis platform receives a multicast packet, it determines, based on the port configuration information in OVSDB, whether the packet originates from the physical network interface card (NIC) of the OVS primary / backup binding interface. If the multicast stream is detected to enter from two physical ports of the binding group simultaneously, and the target MAC address is not subscribed to by any virtual machine or container, the intelligent analysis platform determines this to be redundant flooding traffic. Based on this, the intelligent analysis platform issues multicast filtering rules to the external physical switch, instructing it to only allow the multicast stream through the primary physical link of the binding group, blocking the forwarding path of the backup link. This suppresses indiscriminate flooding of multicast packets to all physical NICs, preventing network stack overload and CPU resource waste caused by the host machine processing a large number of invalid multicast replicas.

[0076] In one embodiment, upon determining the presence of abnormal Layer 2 traffic, generating an interception suggestion and sending it to the virtual switch to request confirmation includes: sending the interception suggestion to the control process of the virtual switch; and receiving a confirmation response from the control process.

[0077] In one embodiment, the acknowledgment response returned by the control process is the result of verifying the interception proposal based on the control process's local flow table rules.

[0078] In one embodiment, the interception recommendation includes at least one of the following: the destination MAC address of the first data packet, the message type of the first data packet, and the recommended interception strategy.

[0079] In one embodiment, the Layer 2 network security defense method further includes: determining abnormal traffic of the first data packet based on the network topology information of the virtual switch, the characteristics of the first data packet, and the interception threshold, so as to avoid misjudgment due to brief network jitter or legitimate device coming online.

[0080] The interception threshold is defined as the maximum number of unintended unicast / multicast packets allowed to be received within a preset time window, targeting a specific MAC address or port. This threshold can be adjusted based on historical traffic behavior data, specifically including:

[0081] If a destination MAC address appears for the first time within the most recent time window T1 and is not bound in OVSDB, the initial threshold is set to N0 times.

[0082] If the MAC address appears N1 times or more in the subsequent time window T2 and there is still no valid binding record, the threshold will be automatically raised to N2 times to tolerate legitimate network behaviors such as brief device initialization or ARP broadcast.

[0083] If the MAC address appears N3 times or more consecutively within a shorter time window T3, it is considered an attack and the interception process is triggered.

[0084] For multicast packets, if the same multicast address enters from both physical ports bound to the primary and backup servers within time window T4, and no virtual port in OVSDB subscribes to the multicast group, the multicast flooding threshold is automatically triggered, set to R times / second; if the multicast traffic exceeds R times / second within a unit of time, it is judged as abnormal.

[0085] Where T1, T2, T3, and T4 represent different duration windows used for traffic statistics, in seconds or minutes, and can be configured according to network size; T1≥T2>T3, and T4≈T3;

[0086] N0, N1, N2, and N3 are the initial threshold, the threshold for triggering an increase, the threshold after the increase, and the attack determination threshold, respectively, and are all non-negative integers; N0 <N1≤N2<N3;

[0087] R is the multicast traffic rate threshold, measured in packets per second, used to determine whether flooding has occurred.

[0088] Through the aforementioned dynamic threshold mechanism, the system can adaptively adjust the judgment sensitivity according to the network environment, effectively distinguishing between legitimate occasional traffic and persistent attack traffic, and significantly reducing the false interception rate.

[0089] Historical traffic behavior data may include: whether similar traffic has occurred on the port within a preset time period, and whether it has been accompanied by ARP storms or MAC address drift.

[0090] In one exemplary embodiment, the intelligent analysis platform calculates an interception threshold based on the MAC binding records of each port in the OVSDB and the frequency of the first occurrence of the target MAC address within the past 5 minutes. For example, if an unknown unicast MAC address appears ≥3 times within 10 seconds, the threshold is triggered, and it is determined to be an attack; if it appears only once, and the MAC address has not appeared in the OVSDB before, but belongs to a legitimate MAC address of a newly launched virtual machine, the threshold is not triggered to avoid false interception.

[0091] In one embodiment, the two-layer network security defense method further includes: when the confirmation response is a confirmation of interception, writing the destination MAC address, source address, timestamp, and interception result of the first data packet into the training set as training samples; and periodically performing incremental training on the intelligent analysis platform based on the training set.

[0092] In an exemplary embodiment, after the intelligent analysis platform receives the acknowledgment response returned by the OVS user-space process Vswitchd, the intelligent analysis platform immediately extracts key fields from the network packet header of the first packet: destination MAC address (e.g., 00:11:22:33:44:55), source MAC address (e.g., aa:bb:cc:dd:ee:ff), and packet capture timestamp (accurate to microseconds). These are then correlated with the judgment results previously obtained by the intelligent analysis platform (e.g., "unknown unicast attack" or "unregistered multicast flooding") to form a structured training sample, which is stored in the local training set database. The sample format can be: {src_mac, dst_mac, timestamp, threat_type, action=blocked}.

[0093] In this embodiment, the training set is aggregated hourly. At the end of each hour, the system automatically starts a lightweight incremental training task, calling a pre-trained lightweight neural network model (such as a small MLP). Only 500-2000 new samples are used for parameter fine-tuning. The model input consists of MAC address hash codes and time frequency statistical features, and the output is the anomaly confidence score. After training, the system backtracks and verifies legitimate traffic over the past 24 hours in an isolated environment. If the false positive rate does not increase by more than 0.1% and the recall rate remains stable, a hot model update mechanism is triggered, seamlessly loading the new model into the intelligent analysis platform instance, replacing the original model. The entire process requires no service restart or interruption of traffic analysis.

[0094] In other embodiments of this application, interception can also be performed using IP addresses to achieve collaborative defense against Layer 3 traffic anomalies. When the virtual switch supports IP layer traffic identification (e.g., enabling VXLAN, GRE tunneling, or deploying an OVS version that supports IP packet resolution), the intelligent analysis platform can, upon receiving the first packet, combine the IP-MAC binding relationship recorded in the OVSDB, the virtual machine IP address allocation table, or network subnet topology information to perform abnormal behavior analysis on the source / destination IP address of the first packet. For example, it can identify attack patterns such as high-frequency scanning IPs, known malicious IPs, unauthorized IP flooding, or unauthorized cross-subnet access, and generate corresponding interception suggestions. The verification and confirmation process of this interception suggestion can completely reuse the mechanism of the aforementioned MAC address-based embodiment: that is, Vswitchd performs a secondary verification based on whether there is a legitimate forwarding rule matching the IP address in the local flow table. If the verification fails, a confirmation response is sent, triggering the external physical switch to block subsequent data flows matching the IP at the Layer 2 network entry point. Since IP address identification and filtering rely on upper-layer protocol encapsulation, its processing logic is highly consistent with the MAC address scheme. Only the matching field needs to be replaced from dl_dst to nw_src or nw_dst. Therefore, its system architecture, communication mechanism, and collaborative process can all follow the aforementioned embodiments without requiring reconstruction of the basic framework. This achieves a flexible defense capability with a single mechanism and multi-layer extensions; therefore, specific implementation details will not be elaborated here. This application also provides a Layer 2 network security defense method applicable to virtual switches. Figure 4 This is a flowchart illustrating a two-layer network security defense method according to another embodiment of this application, as shown below. Figure 4 As shown, the method includes the following steps:

[0095] Step S402: The first data packet obtained is reported to the intelligent analysis platform;

[0096] Step S404: Receive interception suggestions from the intelligent analysis platform. The interception suggestions are generated based on the network topology information of the virtual switch to determine abnormal traffic in the first data packet.

[0097] Step S406: Verify the interception suggestion, and if the verification result indicates that traffic interception is required, send a confirmation response to the intelligent analysis platform so that the intelligent analysis platform responds to the confirmation response and triggers the external physical switch to intercept subsequent data streams that match the first data packet at the Layer 2 network entry point.

[0098] The collaborative mechanism constructed through the steps described above in this application enables attack traffic to be accurately intercepted by external physical switches before it enters the host machine. This completely avoids the problems of host machine CPU overload, memory exhaustion, and network bandwidth congestion caused by Layer 2 unknown unicast or abnormal multicast flooding in traditional solutions, and significantly improves the stability and business performance of the cloud environment.

[0099] In this embodiment, abnormal traffic includes unknown unicast attack traffic and abnormal multicast traffic.

[0100] In one embodiment, reporting the first data packet to the intelligent analysis platform includes: obtaining the first data packet from the network card through the kernel-mode data path; and simultaneously reporting the first data packet to the intelligent analysis platform and the control process of the virtual switch through network link multicast communication.

[0101] In an exemplary embodiment, the process of reporting the first acquired data packet to the intelligent analysis platform is actively triggered by the OVS kernel-mode datapath: when the data packet first arrives at the physical network card or virtual port and no matching rule is found in the kernel flow table, the datapath encapsulates the complete Ethernet frame header, VLAN tag, and part of the payload of the packet into a Netlink message and broadcasts it through a pre-configured dedicated multicast group; this multicast group is simultaneously monitored by the virtual switch's user-mode control process Vswitchd and the independently deployed AI intelligent analysis platform, and the two do not need to depend on each other or process sequentially, so they can receive the original first packet data in parallel within milliseconds; this mechanism is complete. Implemented entirely on native Netlink sockets in the Linux kernel, without relying on the OpenFlow protocol or external controllers, it avoids the control channel latency and single point of failure risks in traditional SDN architectures. At the same time, it ensures that the AI ​​platform obtains raw traffic information that has not been filtered or modified by the Vswitchd policy, guaranteeing the accuracy and completeness of security analysis. This parallel reporting method enables the AI ​​platform to independently complete intelligent judgment based on the OVSDB topology, while Vswitchd can simultaneously perform regular flow table learning. The two processes do not block each other and operate in parallel, thereby achieving zero-latency access for security detection while ensuring network forwarding efficiency. This lays a real-time and reliable data foundation for subsequent accurate interception.

[0102] In one embodiment, verifying the interception suggestion and sending a confirmation response to the intelligent analysis platform if the verification result indicates that traffic interception is required includes: receiving the interception suggestion through the control process and verifying the interception suggestion; and sending a confirmation response to the intelligent analysis platform through the control process if the verification result indicates that traffic interception is required.

[0103] In one embodiment, the interception recommendation includes at least one of the following: the destination MAC address of the first data packet, the message type of the first data packet, and the recommended interception strategy.

[0104] In one embodiment, the interception recommendation is validated by: querying the local flow table rules of the control process; and if no flow table entry matches the destination MAC address of the first data packet, determining that the validation result indicates that traffic interception is required.

[0105] In one exemplary embodiment, when verifying an interception suggestion, Vswitchd queries its local flow table to check for any flow table entries that match the destination MAC address of the first data packet and allow forwarding. If the query does not find any legitimate forwarding rules, it indicates that the MAC address has not been legitimately registered by any virtual machine or port, which is a typical unknown unicast attack. In this case, Vswitchd does not rely on the AI ​​platform's unilateral judgment, but confirms based on its own network status that the traffic has no legitimate forwarding basis, and thus determines that it needs to be intercepted, and sends a confirmation response to the AI ​​platform. This mechanism effectively avoids false blocking caused by normal network fluctuations such as ARP missynchronization and virtual machine migration delays, and realizes a security closed loop of "no local record is considered abnormal", improving the accuracy of interception and system robustness. In one embodiment, the interception suggestion includes at least one of the following: the destination IP address of the first data packet, the packet type of the first data packet, and the recommended interception strategy; then the interception suggestion is verified, including: querying the local flow table rules of the control process; if there is no flow table entry matching the IP address of the first data packet, the verification result is determined that the traffic needs to be intercepted.

[0106] In this embodiment, after making a preliminary "interception" decision, the intelligent analysis platform confirms with Vswitchd, forming a "suggestion-confirmation" interaction mechanism. This improves the accuracy of the decision and avoids false interceptions. The dynamic, self-learning intelligent judgment introduced in this embodiment can detect unknown threats and complex attack patterns.

[0107] The interception scheme described in this application can intercept traffic at the physical switch level before it enters the host machine, avoiding the delay and resource consumption of configuring security rules on the cloud host in traditional methods, thereby effectively protecting network bandwidth and service performance.

[0108] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method.

[0109] Embodiments of this application also provide a two-layer network security defense device. Figure 5 This is a structural block diagram of a two-layer network security defense device according to an embodiment of this application, such as... Figure 5 As shown, the device includes: a first receiving module 51, a determination module 52, a generation module 53, and an interception module 54.

[0110] The first receiving module 51 is used to receive the first data packet reported by the virtual switch;

[0111] The determination module 52 is used to determine abnormal traffic in the first data packet based on the network topology information of the virtual switch, so as to identify whether it is abnormal Layer 2 traffic.

[0112] The generation module 53 is used to generate an interception suggestion and send it to the control process of the virtual switch to request confirmation when it is determined that there is abnormal Layer 2 traffic.

[0113] The interception module 54 is used to trigger the external physical switch to intercept subsequent data streams that match the first data packet at the Layer 2 network ingress in response to the confirmation response received from the control process.

[0114] In one embodiment, network topology information includes: a port media access control MAC address mapping table maintained by the virtual switch.

[0115] In one embodiment, abnormal traffic includes unknown unicast attack traffic and abnormal multicast traffic; the determination module 52 is further configured to determine that the first data packet is unknown unicast attack traffic when the first data packet is a unicast message and the destination MAC address of the first data packet is not in the port MAC address mapping table; and to determine that the first data packet is abnormal multicast traffic when the first data packet is a multicast message and the multicast message is flooded on multiple physical interfaces.

[0116] In one embodiment, the interception recommendation includes at least one of the following: the destination MAC address of the first data packet, the message type of the first data packet, and the recommended interception strategy.

[0117] In one embodiment, the first data packet is reported via multicast communication over a network link and is simultaneously reported to the intelligent analysis platform and the control process of the virtual switch.

[0118] In one embodiment, the network link multicast communication mode is configured such that: the kernel-mode data path of the virtual switch sends the first data packet to a predefined multicast group; the first receiving module 51 is used to receive the first data packet by listening to the predefined multicast group.

[0119] In one embodiment, the control process's acknowledgment response is the result of verifying the interception proposal based on the control process's local flow table rules.

[0120] Figure 6 This is a structural block diagram of a two-layer network security defense device according to another embodiment of this application, such as... Figure 6 As shown, this two-layer network security defense device includes a training module 55 in addition to the modules mentioned above.

[0121] The training module 55 is used to write the destination MAC address, source address, timestamp, and interception result of the first data packet into the training set as training samples when the confirmation response is an confirmation of interception; and to periodically perform incremental training on the intelligent analysis platform based on the training set.

[0122] This application also provides a Layer 2 network security defense device that can be configured on a virtual switch. Figure 7 This is a structural block diagram of a two-layer network security defense device according to another embodiment of this application, such as... Figure 7 As shown, the method includes the following steps:

[0123] The reporting module 71 is used to report the first data packet acquired to the intelligent analysis platform;

[0124] The second receiving module 72 is used to receive the interception suggestion sent by the intelligent analysis platform, wherein the interception suggestion is generated by judging abnormal traffic of the first data packet based on the network topology information of the virtual switch;

[0125] The verification module 73 is used to verify the interception suggestion and send a confirmation response to the intelligent analysis platform if the verification result indicates that traffic interception is required. This causes the intelligent analysis platform to respond to the confirmation response and trigger the external physical switch to intercept subsequent data streams that match the first data packet at the Layer 2 network entry point.

[0126] In this embodiment, abnormal traffic includes unknown unicast attack traffic and abnormal multicast traffic.

[0127] In one embodiment, the reporting module 71 is further configured to obtain the first data packet from the network card via the kernel-mode data path; and simultaneously report the first data packet to the intelligent analysis platform and the control process of the virtual switch via network link multicast communication.

[0128] In one embodiment, the verification module 73 is further configured to receive interception suggestions through the control process and verify the interception suggestions; if the verification result indicates that traffic interception is required, the module sends a confirmation response to the intelligent analysis platform through the control process.

[0129] In one embodiment, the interception recommendation includes at least one of the following: the destination MAC address of the first data packet, the message type of the first data packet, and the recommended interception strategy.

[0130] In one embodiment, the verification module 73 is further configured to query the local flow table rules of the control process; if there is no flow table entry matching the destination MAC address of the first data packet, the verification result is determined to be traffic interception.

[0131] For a description of the features in the embodiments corresponding to the above-mentioned devices, please refer to the relevant descriptions of the embodiments corresponding to the two-layer network security defense method, which will not be repeated here.

[0132] Embodiments of this application also provide an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to perform the steps in any of the above embodiments of the two-layer network security defense method.

[0133] Embodiments of this application also provide a computer-readable storage medium storing a computer program, wherein the computer program is configured to execute the steps in any of the above embodiments of the two-layer network security defense method when it is run.

[0134] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.

[0135] The embodiments of this application also provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps in any of the above embodiments of the two-layer network security defense method.

[0136] Embodiments of this application also provide another computer program product, including a non-volatile computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps in any of the above embodiments of the two-layer network security defense method.

[0137] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0138] The foregoing has provided a detailed description of a two-layer network security defense method, system, and apparatus provided in this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the embodiments above are merely for the purpose of helping to understand the method and its core ideas. It should be noted that those skilled in the art can make various improvements and modifications to this application without departing from its principles, and these improvements and modifications also fall within the protection scope of the claims of this application.

Claims

1. A two-layer network security defense method, characterized in that, Applications in intelligent analytics platforms include: Receive the first data packet reported by the virtual switch; Based on the network topology information of the virtual switch, the first data packet is subjected to abnormal traffic determination to identify whether it is Layer 2 abnormal traffic. The network topology information includes: the port media access control MAC address mapping table maintained by the virtual switch, and the abnormal traffic includes unknown unicast attack traffic and abnormal multicast traffic. If abnormal Layer 2 traffic is detected, an interception suggestion is generated and sent to the virtual switch for confirmation. In response to the received confirmation response from the virtual switch, the external physical switch is triggered to intercept subsequent data streams that match the first data packet at the Layer 2 network ingress. The step of determining abnormal traffic in the first data packet based on the network topology information of the virtual switch includes: If the first data packet is a unicast message and the destination MAC address of the first data packet is not in the port media access control MAC address mapping table, then the first data packet is determined to be the unknown unicast attack traffic. If the first data packet is a multicast message, and the multicast message is flooded on the physical switch side, then the first data packet is determined to be the abnormal multicast traffic.

2. The two-layer network security defense method according to claim 1, characterized in that, in, The interception recommendation includes at least one of the following: the destination MAC address of the first data packet, the message type of the first data packet, and the recommended interception strategy.

3. The two-layer network security defense method according to claim 1, characterized in that, in, The first data packet is reported via multicast communication over a network link and is simultaneously reported to the intelligent analysis platform and the control process of the virtual switch.

4. The two-layer network security defense method according to claim 3, characterized in that, The network link multicast communication mode is configured as follows: the kernel-mode data path of the virtual switch sends the first data packet to a predefined multicast group; receiving the first data packet reported by the virtual switch includes: The first data packet is received by listening to the predefined multicast group.

5. The two-layer network security defense method according to claim 3, characterized in that, If abnormal Layer 2 traffic is detected, an interception suggestion is generated and sent to the virtual switch for confirmation, including: Send the interception suggestion to the control process of the virtual switch; Receive the confirmation response returned by the control process.

6. The two-layer network security defense method according to claim 5, characterized in that, in, The confirmation response returned by the control process is the result of verifying the interception suggestion based on the local flow table rules of the control process.

7. The two-layer network security defense method according to claim 1, characterized in that, The method further includes: If the confirmation response is an confirmation of interception, the destination MAC address, source address, timestamp, and interception result of the first data packet are written into the training set as training samples; The intelligent analysis platform is periodically incrementally trained based on the training set.

8. A two-layer network security defense method, characterized in that, Applied to virtual switches, including: The first data packet acquired will be reported to the intelligent analysis platform; The system receives an interception suggestion from the intelligent analysis platform. The interception suggestion is generated by judging abnormal traffic of the first data packet based on the network topology information of the virtual switch. The network topology information includes: the port media access control MAC address mapping table maintained by the virtual switch. The abnormal traffic includes unknown unicast attack traffic and abnormal multicast traffic. The interception suggestion is verified, and if the verification result indicates that traffic interception is required, a confirmation response is sent to the intelligent analysis platform. In response to the confirmation response, the intelligent analysis platform triggers the external physical switch to intercept subsequent data streams that match the first data packet at the Layer 2 network entry point. Specifically, if the first data packet is a unicast message and the destination MAC address of the first data packet is not in the port media access control MAC address mapping table, the first data packet is the unknown unicast attack traffic; if the first data packet is a multicast message and the multicast message is flooded on the physical switch side, the first data packet is the abnormal multicast traffic.

9. The two-layer network security defense method according to claim 8, characterized in that, The first data packet acquired will be reported to the intelligent analysis platform, including: The first data packet is obtained from the network card via the kernel-mode data path; The first data packet is simultaneously reported to the intelligent analysis platform and the control process of the virtual switch via network link multicast communication.

10. The two-layer network security defense method according to claim 9, characterized in that, The interception suggestion is verified, and if the verification result indicates that traffic interception is required, a confirmation response is sent to the intelligent analysis platform, including: The control process receives the interception suggestion and verifies the interception suggestion. If the verification result indicates that traffic interception is required, a confirmation response is sent to the intelligent analysis platform through the control process.

11. The two-layer network security defense method according to claim 10, characterized in that, in, The interception recommendation includes at least one of the following: the destination MAC address of the first data packet, the message type of the first data packet, and the recommended interception strategy.

12. The two-layer network security defense method according to claim 11, characterized in that, The interception suggestion is validated, including: Query the local flow table rules of the control process; If no flow table entry matches the destination MAC address of the first data packet, the verification result is determined to require traffic interception.

13. A two-layer network security defense device, characterized in that, Located within the intelligent analytics platform, including: The first receiving module is used to receive the first data packet reported by the virtual switch; The determination module is used to determine abnormal traffic of the first data packet based on the network topology information of the virtual switch, so as to identify whether it is Layer 2 abnormal traffic. The network topology information includes: the port media access control MAC address mapping table maintained by the virtual switch, and the abnormal traffic includes unknown unicast attack traffic and abnormal multicast traffic. The generation module is used to generate an interception suggestion and send it to the control process of the virtual switch to request confirmation when it is determined that there is abnormal Layer 2 traffic. The interception module is used to trigger an external physical switch to intercept subsequent data streams that match the first data packet at the Layer 2 network ingress in response to receiving an acknowledgment response from the control process. The determination module is further configured to: determine the first data packet as the unknown unicast attack traffic when the first data packet is a unicast message and the destination MAC address of the first data packet is not in the port media access control MAC address mapping table; and determine the first data packet as the abnormal multicast traffic when the first data packet is a multicast message and the multicast message is flooded on the physical switch side.

14. A two-layer network security defense device, characterized in that, Located in the virtual switch, including: The reporting module is used to report the first data packet acquired to the intelligent analysis platform; The second receiving module is used to receive the interception suggestion sent by the intelligent analysis platform. The interception suggestion is generated by judging abnormal traffic of the first data packet based on the network topology information of the virtual switch. The network topology information includes: the port media access control MAC address mapping table maintained by the virtual switch. The abnormal traffic includes unknown unicast attack traffic and abnormal multicast traffic. The verification module is used to verify the interception suggestion and send a confirmation response to the intelligent analysis platform if the verification result indicates that traffic interception is required. This enables the intelligent analysis platform to respond to the confirmation response and trigger the external physical switch to intercept subsequent data streams that match the first data packet at the Layer 2 network entry point. Specifically, if the first data packet is a unicast message and the destination MAC address of the first data packet is not in the port media access control MAC address mapping table, the first data packet is the unknown unicast attack traffic; if the first data packet is a multicast message and the multicast message is flooded on the physical switch side, the first data packet is the abnormal multicast traffic.

15. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the steps of the two-layer network security defense method as described in any one of claims 1 to 7, or to implement the steps of the two-layer network security defense method as described in any one of claims 8 to 12.

16. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, wherein when the computer program is executed by a processor, it implements the steps of the two-layer network security defense method as described in any one of claims 1 to 7, or implements the steps of the two-layer network security defense method as described in any one of claims 8 to 12.

17. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the two-layer network security defense method as described in any one of claims 1 to 7, or implements the steps of the two-layer network security defense method as described in any one of claims 8 to 12.