Method, device and system for detecting traffic behavior
By acquiring data packet information and using filtering and temporary storage modules to detect the impact behavior of packet flows, the problem of inaccurate detection in existing technologies is solved, enabling accurate attribution of network performance SLO violations and flexible information reporting.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2024-11-20
- Publication Date
- 2026-05-22
AI Technical Summary
Existing technologies are unable to accurately detect and describe suspicious flow behavior, leading to inaccurate attribution of network performance SLO violations.
By acquiring packet information from data packets, and based on rate and traffic thresholds, the impact information of the message flow is determined. The filtering and temporary storage modules are used to accurately detect the impact behavior, including the filtering module recording flow information and the temporary storage module mitigating the impact of short-term burst flows.
It enables accurate detection of message flow impact behavior, improves the accuracy of network performance SLO violation attribution, reduces detection overhead, and supports flexible information reporting.
Smart Images

Figure CN122073564A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network technology, and in particular to a method, apparatus and system for detecting traffic behavior. Background Technology
[0002] Service level objectives (SLOs) are quantifiable metrics of an application's network performance requirements. For example, an application might require 99% of remote procedure calls (RPCs) to complete within 10 milliseconds. When network performance violates or fails to meet the SLO requirements of a network application (referred to as an SLO violation), it significantly impacts user experience and can lead to business losses. Therefore, timely identification of the causes of SLO violations (attribution) is crucial for network management.
[0003] Since most SLO violations can be attributed to packet queuing and loss caused by network resource contention, the cause of SLO violations can be determined by detecting suspicious traffic behaviors that may lead to them (such as heavy hitter (HH) behavior, heavy changer (HC) behavior, and burst traffic behavior). HH behavior refers to traffic behavior that consumes a large amount of bandwidth or resources. HC behavior refers to traffic behavior where the number of bytes in traffic changes more than a threshold between two adjacent time periods.
[0004] However, among the technologies related to detecting suspicious epidemic behavior, it is impossible to accurately detect and describe suspicious epidemic behavior. Summary of the Invention
[0005] This application provides a method, apparatus, and system for detecting traffic behavior. This method can accurately detect traffic behaviors with both high rate and high volume. The technical solution provided in this application is as follows.
[0006] Firstly, this application provides a method for detecting traffic behavior. This method is applied to a packet forwarding node and includes: acquiring packet information of data packets flowing through the packet forwarding node, the packet information including the flow identifier (ID) of the packet flow to which the data packet belongs, the size of the data packet, and the timestamp of the data packet; and determining the impact information of the packet flow based on the packet information, a rate threshold, and a traffic threshold. Here, one piece of impact information of the packet flow describes the behavior of a traffic segment within the packet flow. The behavior of the traffic segment is represented by the amount of traffic transmitted within the time period indicated by the impact information, where the rate of traffic in the traffic segment is greater than or equal to the rate threshold, and the size of traffic in the traffic segment is greater than or equal to the traffic threshold.
[0007] The impact information describing the flow behavior of a packet flow refers to the impact behavior of that packet flow. In this application, impact behavior specifically refers to the flow behavior where the packet flow rate is consistently higher than a given rate threshold for a period of time, and the total flow of the flow exceeds a given flow threshold at the end of this period. The method provided in this application enables the detection of impact behavior occurring in traffic segments within a packet flow passing through a packet forwarding node. Compared to related technologies, the impact behavior detected by this application, described by impact information, has accurate time boundaries (i.e., the time period indicated by the impact information), thus making it more accurate in attributing network performance SLO violations based on the impact behavior detected by this application.
[0008] In one possible design, the packet forwarding node includes a filtering module comprising k recording units, each recording unit for recording flow information of packet flows passing through the packet forwarding node. For the first recording unit among the k recording units, the first flow information recorded based on any packet flow passing through the packet forwarding node includes the flow ID, flow start time, timestamp of the last received data packet, flow size, and the latest reception time of the next data packet estimated based on a rate threshold. For the first data packet received by the packet forwarding node, where the first data packet is a data packet of the first packet flow passing through the packet forwarding node, the aforementioned determination of the impact information of the packet flow based on packet information, rate threshold, and flow threshold includes: determining the recording unit in the filtering module that has a mapping relationship with the first packet flow to which the first data packet belongs as the first recording unit based on the flow ID in the packet information of the first data packet; and, in the case where it is determined based on the rate and rate threshold of the first data packet that the second flow information is used to replace the first flow information recorded in the first recording unit, if the flow size in the first flow information is greater than or equal to the flow threshold, then the flow ID, time information, and flow size in the first flow information are determined as impact information. The second stream information is the stream information obtained based on the packet information of the first data packet.
[0009] In another possible design, before determining the flow ID, time information, and traffic size in the first flow information as influencing information, the method further includes: determining to replace the first flow information with second flow information when the flow ID in the packet information of the first data packet is the same as the flow ID in the first flow information and the rate of the first data packet is less than a rate threshold; or when the flow ID in the packet information of the first data packet is the same as the flow ID in the first flow information, the rate of the first data packet is greater than or equal to the rate threshold, and the traffic size in the first flow information is greater than or equal to a segmentation threshold. Specifically, when the timestamp of the first data packet is greater than the latest reception time, the rate of the first data packet is less than the rate threshold; when the timestamp of the first data packet is less than or equal to the latest reception time, the rate of the first data packet is greater than or equal to the rate threshold. The segmentation threshold is greater than the traffic threshold.
[0010] In another possible design approach, the method also includes replacing the first-stream information in the first recording unit with the second-stream information.
[0011] Through the above-mentioned possible design methods, the packet forwarding node with the detection device can obtain accurate description information of the traffic segments in the packet flow that have caused the influencing behavior based on the rate of the data packets through the filtering module. This description information is the aforementioned influence information.
[0012] This application determines whether the data packet rate exceeds a rate threshold by comparing the timestamp of the data packet with the latest reception time in the flow information recorded by the filtering module. Furthermore, it extracts impact information from the flow information recorded in the filtering module at the boundary between the rate exceeding and not exceeding the rate threshold, thereby achieving the goal of locating impact behavior based on rate. In addition, for fine-grained extraction of impact information and analysis of impact behavior, this application also extracts impact information from the recorded flow information when the data packet rate exceeds the rate threshold but the traffic volume in the recorded flow information exceeds a preset segmentation threshold.
[0013] Thus, the impact information obtained by this application through the above two methods can accurately and finely locate (by the time period included in the impact information) the impact behavior of the packet flow, thereby providing accurate information for attributing SLO violations to network performance and improving the accuracy of SLO violation attribution.
[0014] In another possible design, the message forwarding node also includes a temporary storage module. This module comprises k recording units, each recording the flow information of the message stream flowing through the message forwarding node. The flow information recorded by the second recording unit in the temporary storage module includes the flow ID, flow start time, timestamp of the last received data packet, flow size, and the latest estimated reception time of the next data packet based on a rate threshold. The flow information recorded by the second recording unit is based on any message stream flowing through the message forwarding node. Before determining the recording unit in the filtering module that has a mapping relationship with the first message stream to which the first data packet belongs, based on the flow ID in the packet information of the first data packet, the method further includes: determining the recording unit in the temporary storage module that has a mapping relationship with the first message stream to which the first data packet belongs, based on the flow ID in the packet information of the first data packet, as the second recording unit; and determining the data to update the flow information recorded in the second recording unit using the packet information of the first data packet, based on the rate and rate threshold of the first data packet.
[0015] In another possible design, when determining the data for updating the flow information recorded in the second recording unit using the packet information of the first data packet based on the rate and rate threshold of the first data packet, after determining the recording unit in the filtering module that has a mapping relationship with the first message flow to which the first data packet belongs as the first recording unit based on the flow ID in the packet information of the first data packet, the method further includes: updating the freshness of the flow information recorded in the first recording unit based on a first freshness factor determined according to the first data packet. The freshness is used to indicate whether to continue maintaining the currently recorded flow information in the first recording unit. Maintenance includes the operation of updating the data of the currently recorded flow information of the first recording unit based on the received data packet. The first freshness factor is used to indicate the degree of influence of the first data packet on the freshness of the flow information recorded in the first recording unit.
[0016] In another possible design, the message forwarding node is configured with a matching table, which indicates the freshness factor corresponding to different combinations of traffic size range and packet interval range. Before updating the freshness of the flow information recorded in the first recording unit, the method further includes: querying the matching table based on the range of the size of the first data packet and the range of the packet interval of the first data packet to determine the first freshness factor.
[0017] In another possible design, the determination to update the flow information recorded in the second recording unit using the packet information of the first data packet, based on the rate and rate threshold of the first data packet, includes: when the flow ID in the packet information of the first data packet is the same as the flow ID in the flow information recorded by the second recording unit, and the rate of the first data packet is greater than or equal to the rate threshold; or, when the flow ID in the packet information of the first data packet is the same as the flow ID in the flow information recorded by the second recording unit, the rate of the first data packet is greater than or equal to the rate threshold, and the traffic size in the first flow information is less than the segmentation threshold, the determination is made to update the flow information recorded in the second recording unit using the packet information of the first data packet. Wherein, when the timestamp of the first data packet is less than or equal to the latest reception time in the flow information recorded by the second recording unit, the rate of the first data packet is greater than or equal to the rate threshold. The segmentation threshold is greater than the traffic threshold.
[0018] In another possible design, for the second data packet in the first message stream received by the message forwarding node after receiving the first data packet, the aforementioned determination of the message stream impact information based on packet information, rate threshold, and traffic threshold includes: determining the second recording unit in the temporary storage module that has a mapping relationship with the first message stream to which the second data packet belongs, based on the flow ID in the packet information of the second data packet; when it is determined based on the rate and rate threshold of the second data packet that the flow information obtained based on the packet information of the second data packet is used to replace the original flow information recorded in the second recording unit, the first recording unit in the filtering module that has a mapping relationship with the first message stream to which the second data packet belongs is determined based on the flow ID in the packet information of the second data packet; when the freshness of the third flow information originally recorded in the first recording unit meets the preset condition and the traffic size of the third flow information is greater than or equal to the traffic threshold, the flow ID, time information, and traffic size in the third flow information are determined as impact information.
[0019] In another possible design, the method further includes: when determining, based on the rate and rate threshold of the second data packet, to replace the original stream information recorded in the second recording unit with the stream information obtained from the packet information of the second data packet, replacing the original fourth stream information recorded in the second recording unit with the stream information obtained from the packet information of the second data packet, and sending the fourth stream information to the filtering module; when the freshness of the original third stream information recorded in the first recording unit meets the preset conditions, replacing the third stream information with the fourth stream information, wherein the stream ID of the fourth stream information is different from the stream ID of the third stream information.
[0020] Through the above-mentioned possible design methods, this application achieves the goal of obtaining impact information through a temporary storage module and a filtering module.
[0021] The application includes a temporary storage module for storing message flow information and a filtering module for filtering large flows. By introducing a temporary storage module, this application alleviates the problem of short-lived bursts of flow failing to be detected due to message flow conflicts. Here, a short-lived burst of flow refers to flow whose rate far exceeds a rate threshold but whose volume is less than a volume threshold. By retaining and maintaining the message flow information in the temporary storage module for as long as possible, this application ensures that even short-lived bursts can be detected and affect behavior.
[0022] In another possible design approach, a message flow includes multiple impact information. For the first impact information and the second impact information belonging to the same message flow, which are determined sequentially by the message forwarding node, the method also includes: controlling the second impact information to reuse the flow ID in the first impact information for storage.
[0023] This possible design enables compressed (compression achieved through aggregation) storage of impact information, thereby reducing the overhead required for message forwarding nodes with detection devices to report impact information.
[0024] In another possible design approach, the method further includes: when the rates indicated by the first impact information and the rates indicated by the second impact information are within the same rate range, performing an aggregation operation on the first impact information and the second impact information to aggregate them into a single impact information for storage. The aggregation operation includes aggregating the traffic magnitude and time information from the first impact information and the second impact information.
[0025] This possible design enables compressed storage of the reused stream ID, thereby reducing the overhead required for message forwarding nodes with detection devices to report impact information.
[0026] In another possible design approach, when the traffic size recorded in the first-stream information is less than the traffic threshold, the traffic size included in the first-stream information and the rate determined based on the first-stream information are identified as missing information. The missing information is used to adjust the parameters used when detecting traffic behavior, and the parameters include at least one of the rate threshold, the traffic threshold, or the segmentation threshold.
[0027] This possible design allows for the adjustment of parameters used when detecting traffic behavior by taking into account the omission of information when the traffic volume is less than the traffic threshold.
[0028] For example, when there is too much missing information (such as the traffic volume exceeding a certain amount, or the proportion relative to the impact information exceeding a proportion threshold), it indicates that the amount of impact information is small. Therefore, the amount of impact information detected can be increased by reducing the value of the parameter, thereby improving the detection accuracy.
[0029] For example, when there is too little missing information (such as traffic volume below a certain amount, or a proportion below a threshold relative to the amount of impact information), it indicates a large amount of impact information. Therefore, to reduce reporting overhead, the parameter value can be increased to reduce the amount of impact information detected, thereby reducing the overhead required to report impact information. Thus, by controlling the amount of missing information, a balance can be struck between the accuracy of detecting impact information and the overhead of reporting it.
[0030] In another possible design, the method further includes receiving parameters sent by the control device, including at least one of a rate threshold, a flow threshold, or a segmentation threshold used for detecting flow behavior.
[0031] With this possible design, the message forwarding node deploying the detection device can receive parameters adjusted in real time by the control device, and update the parameters in a timely manner to detect the impact information.
[0032] In another possible design approach, the method also includes reporting the impact information to the control device.
[0033] With this possible design, after the message forwarding node of the deployed detection device reports the detected impact information to the control device, the control device can centrally manage this information and query it in real time when the user queries, and provide the user with the information they need so that the user can perform SLO violation attribution analysis.
[0034] In another possible design approach, the above-mentioned reporting of impact information to the control device includes: reporting all the determined impact information to the control device when the number of determined impact information exceeds a threshold; or, periodically reporting all the determined impact information within a period of time to the control device.
[0035] This possible design allows for flexible and varied methods for message forwarding nodes deploying detection devices to report impact information.
[0036] Secondly, this application provides a method for detecting traffic behavior, applied to a control device. The method includes: receiving impact information of a message flow reported by a message forwarding node. The impact information of the message flow is determined based on packet information, a rate threshold, and a traffic threshold of data packets flowing through the message forwarding node. The packet information includes the flow ID of the message flow to which the data packet belongs, the size of the data packet, and the timestamp of the data packet. One piece of impact information of the message flow describes the behavior of a traffic segment within the message flow. The behavior of the traffic segment is represented by the amount of traffic transmitted within the time period indicated by the impact information, and the rate of traffic in the traffic segment is greater than or equal to the rate threshold, and the size of traffic in the traffic segment is greater than or equal to the traffic threshold.
[0037] Through this application, the control device can receive impact information detected by message forwarding nodes equipped with detection devices, centrally manage this information, and instantly query and provide users with the required information when they query, so that users can perform SLO violation attribution analysis. Because the impact information detected by the detection device in this application can pinpoint the impact behavior of message flows with fine granularity and accuracy (by locating the time period indicated by the impact information), this application can improve the accuracy of SLO violation attribution.
[0038] In one possible design, the method further includes: when the time interval between receiving impact information reported by the message forwarding node is less than a duration threshold, or when the number of impact information reported by the message forwarding node within a preset duration exceeds a quantity threshold, adjusting at least one of the rate threshold, traffic threshold, or segmentation threshold used for detecting traffic behavior; and sending the adjusted rate threshold, traffic threshold, and / or segmentation threshold to the message forwarding node.
[0039] Through this possible design, the control device can adjust the parameters used by the detection device to detect traffic behavior in real time and promptly send the adjusted parameters to the detection device so that the detection device can update the parameters in a timely manner to detect impact information. Since the value of the parameters affects the amount of impact information detected by the detection device, and thus the overhead required for the detection device to report the impact information to the control device, the value of the parameters also affects the accuracy of the impact information detection. Therefore, the method of this application can balance the accuracy of impact information detection and the overhead required to report impact information according to the actual situation of the user by adjusting the value of the parameters, thereby meeting the personalized needs of different users and improving the user experience. Here, "user" refers to the user of the network to which the method provided in this application is applied.
[0040] In another possible design approach, the impact information is used to analyze the reasons for SLO violations in network performance.
[0041] Thirdly, this application provides a traffic behavior detection device applied to a packet forwarding node. The device includes: an acquisition unit for acquiring packet information of data packets flowing through the packet forwarding node, the packet information including the flow ID of the packet flow to which the data packet belongs, the size of the data packet, and the timestamp of the data packet; and a determination unit for determining impact information of the packet flow based on the packet information, a rate threshold, and a traffic threshold. Here, one piece of impact information of the packet flow describes the behavior of a traffic segment within the packet flow. The behavior of the traffic segment is represented by the amount of traffic transmitted within the time period indicated by the impact information. The rate of traffic in the traffic segment is greater than or equal to the rate threshold, and the size of traffic in the traffic segment is greater than or equal to the traffic threshold.
[0042] In one possible design, the packet forwarding node includes a filtering module comprising k recording units, each recording unit for recording flow information of packet flows passing through the packet forwarding node. For the first recording unit among the k recording units, the first flow information recorded based on any packet flow passing through the packet forwarding node includes the flow ID, flow start time, timestamp of the last received packet, flow size, and the latest reception time of the next packet estimated based on a rate threshold. For the first packet received by the packet forwarding node, where the first packet is a packet from the first packet flow passing through the packet forwarding node, the determining unit is specifically used to: determine the recording unit in the filtering module that has a mapping relationship with the first packet flow to which the first packet belongs, based on the flow ID in the packet information of the first packet; and, in the case where the second flow information is used to replace the first flow information recorded in the first recording unit based on the rate and rate threshold of the first packet, if the flow size in the first flow information is greater than or equal to the flow threshold, then the flow ID, time information, and flow size in the first flow information are determined as influencing information. The second flow information is the flow information obtained based on the packet information of the first packet.
[0043] In another possible design, the determining unit is further configured to, before determining the flow ID, time information, and traffic size in the first flow information as influencing information, determine to replace the first flow information with second flow information when: the flow ID in the packet information of the first data packet is the same as the flow ID in the first flow information, and the rate of the first data packet is less than a rate threshold; or, the flow ID in the packet information of the first data packet is the same as the flow ID in the first flow information, the rate of the first data packet is greater than or equal to the rate threshold, and the traffic size in the first flow information is greater than or equal to a segmentation threshold. Specifically, when the timestamp of the first data packet is greater than the latest reception time, the rate of the first data packet is less than the rate threshold; when the timestamp of the first data packet is less than or equal to the latest reception time, the rate of the first data packet is greater than or equal to the rate threshold. The segmentation threshold is greater than the traffic threshold.
[0044] In another possible design, the detection device further includes a replacement unit for replacing the first stream information in the first recording unit with the second stream information.
[0045] In another possible design, the message forwarding node further includes a temporary storage module comprising k recording units, each recording unit for recording flow information of message flows passing through the message forwarding node. For the flow information recorded by the second recording unit in the temporary storage module, the flow information recorded by the second recording unit includes the flow ID, flow start time, timestamp of the last received data packet, flow size, and the latest reception time of the next data packet estimated based on a rate threshold. The flow information recorded by the second recording unit is the flow information recorded based on any message flow passing through the message forwarding node. The determining unit is further configured to, before determining the recording unit in the filtering module that has a mapping relationship with the first message flow to which the first data packet belongs, as the first recording unit based on the flow ID in the packet information of the first data packet, determine the recording unit in the temporary storage module that has a mapping relationship with the first message flow to which the first data packet belongs, as the second recording unit based on the flow ID in the packet information of the first data packet; and to determine, based on the rate of the first data packet and a rate threshold, the data used to update the flow information recorded in the second recording unit using the packet information of the first data packet.
[0046] In another possible design, the detection device further includes an update unit. When, based on the rate and rate threshold of the first data packet, it is determined that the data of the flow information recorded in the second recording unit should be updated using the packet information of the first data packet, the update unit, after determining the recording unit in the filtering module that has a mapping relationship with the first message flow to which the first data packet belongs as the first recording unit based on the flow ID in the packet information of the first data packet, updates the freshness of the flow information recorded by the first recording unit based on a first freshness factor determined according to the first data packet. Here, freshness indicates whether to continue maintaining the currently recorded flow information in the first recording unit; maintenance includes updating the data of the currently recorded flow information of the first recording unit based on received data packets. The first freshness factor indicates the degree of influence of the first data packet on the freshness of the flow information recorded in the first recording unit.
[0047] In another possible design, the message forwarding node is configured with a matching table, which indicates the freshness factor corresponding to different combinations of traffic size range and packet interval range. The detection device further includes a query unit, used to query the matching table based on the range of the size of the first data packet and the range of the packet interval of the first data packet before updating the freshness of the flow information recorded by the first recording unit, in order to determine the first freshness factor.
[0048] In another possible design, the determining unit is further configured to: determine whether to update the data in the flow information recorded in the second recording unit using the packet information of the first data packet when the flow ID in the packet information of the first data packet is the same as the flow ID in the flow information recorded by the second recording unit, and the rate of the first data packet is greater than or equal to a rate threshold; or when the flow ID in the packet information of the first data packet is the same as the flow ID in the flow information recorded by the second recording unit, the rate of the first data packet is greater than or equal to a rate threshold, and the traffic size in the first flow information is less than a segmentation threshold. Wherein, when the timestamp of the first data packet is less than or equal to the latest reception time in the flow information recorded by the second recording unit, the rate of the first data packet is greater than or equal to the rate threshold. The segmentation threshold is greater than the traffic threshold.
[0049] In another possible design, for the second data packet in the first message stream received by the message forwarding node after receiving the first data packet, the determining unit is specifically used to: determine the recording unit in the temporary storage module that has a mapping relationship with the first message stream to which the second data packet belongs as the second recording unit based on the flow ID in the packet information of the second data packet; when it is determined based on the rate and rate threshold of the second data packet that the flow information obtained based on the packet information of the second data packet is used to replace the original flow information recorded in the second recording unit, the recording unit in the filtering module that has a mapping relationship with the first message stream to which the second data packet belongs is determined based on the flow ID in the packet information of the second data packet; when the freshness of the third flow information originally recorded in the first recording unit meets the preset conditions and the traffic size of the third flow information is greater than or equal to the traffic threshold, the flow ID, time information and traffic size in the third flow information are determined as the influencing information.
[0050] In another possible design, the replacement unit is further configured to replace the originally recorded fourth stream information in the second recording unit with the stream information obtained from the packet information of the second data packet when determining, based on the rate and rate threshold of the second data packet, to replace the originally recorded stream information in the second recording unit with the stream information obtained from the packet information of the second data packet. The detection device also includes a sending unit for sending the fourth stream information to the filtering module. The replacement unit is further configured to replace the third stream information with the fourth stream information when the freshness of the originally recorded third stream information in the first recording unit meets a preset condition, wherein the stream ID of the fourth stream information is different from the stream ID of the third stream information.
[0051] In another possible design, a message flow includes multiple impact information. For the first impact information and the second impact information belonging to the same message flow, which are determined sequentially by the message forwarding node, the detection device also includes a storage unit for controlling the second impact information to reuse the flow ID in the first impact information for storage.
[0052] In another possible design, the storage unit is further configured to perform an aggregation operation on the first and second impact information when the rates indicated by the first and second impact information are within the same rate range, thereby aggregating the first and second impact information into a single impact information for storage. The aggregation operation includes aggregating the traffic magnitude and time information from the first and second impact information.
[0053] In another possible design, the determining unit is further configured to, when the flow size recorded in the first-stream information is less than a flow threshold, determine the flow size included in the first-stream information and the rate determined based on the first-stream information as omitted information. The omitted information is used to adjust the parameters used when detecting flow behavior, and the parameters include at least one of a rate threshold, a flow threshold, or a segmentation threshold.
[0054] In another possible design, the detection device further includes a receiving unit for receiving parameters sent by the control device, the parameters including at least one of a rate threshold, a flow threshold, or a segmentation threshold used for detecting flow behavior.
[0055] In another possible design, the transmitting unit is also used to report impact information to the control device.
[0056] In another possible design, the sending unit is specifically used to: report all determined impact information to the control device when the number of determined impact information exceeds a threshold; or, periodically report all determined impact information within a period to the control device.
[0057] It is understandable that the beneficial effects of the flow behavior detection device provided by the third aspect and any possible design method in the third aspect can be seen from the technical effects of the corresponding solutions provided by the first aspect and any possible design method in the first aspect, and will not be repeated here.
[0058] Fourthly, this application provides a traffic behavior detection device applied to a control device. The detection device includes a receiving unit for receiving impact information of a message flow reported by a message forwarding node. The impact information of the message flow is determined based on packet information, a rate threshold, and a traffic threshold of data packets flowing through the message forwarding node. The packet information includes the flow ID of the message flow to which the data packet belongs, the size of the data packet, and the timestamp of the data packet. One piece of impact information of the message flow describes the behavior of a traffic segment within the message flow. The behavior of the traffic segment is represented by the amount of traffic transmitted within the time period indicated by the impact information, and the rate of traffic in the traffic segment is greater than or equal to the rate threshold, and the size of traffic in the traffic segment is greater than or equal to the traffic threshold.
[0059] In one possible design, the detection device further includes: an adjustment unit, configured to adjust at least one of a rate threshold, a traffic threshold, or a segmentation threshold used for detecting traffic behavior when the time interval between receiving impact information reported by the message forwarding node is less than a duration threshold, or when the number of impact information reported by the message forwarding node within a preset duration exceeds a quantity threshold; and a sending unit, configured to send the adjusted rate threshold, traffic threshold, and / or segmentation threshold to the message forwarding node.
[0060] In another possible design approach, the impact information is used to analyze the reasons for SLO violations in network performance.
[0061] It is understandable that the beneficial effects of the flow behavior detection device provided by the fourth aspect and any possible design method in the fourth aspect can be seen from the technical effects of the corresponding solutions provided by the second aspect and any possible design method in the second aspect, and will not be repeated here.
[0062] Fifthly, this application provides a traffic behavior detection device. The detection device is applied to a packet forwarding node. The detection device includes: a processing unit for performing operations other than those related to receiving and / or sending in the methods provided by the first aspect and any possible design of the first aspect; and a transceiver unit for performing operations related to receiving and / or sending in the methods provided by the first aspect and any possible design of the first aspect.
[0063] In a sixth aspect, this application provides a traffic behavior detection device, which is applied to a control device. The detection device includes: a transceiver unit for performing operations related to receiving and / or sending in the methods provided by the second aspect and any possible design of the second aspect; and a processing unit for performing other operations besides the operations related to receiving and / or sending in the methods provided by the second aspect and any possible design of the second aspect.
[0064] In a seventh aspect, this application provides a traffic behavior detection device, comprising: a memory, a communication interface, and one or more processors. The one or more processors receive or transmit data through the communication interface, and are configured to read program instructions stored in the memory to execute the method provided by the first aspect and any possible design of the first aspect, or to execute the method provided by the second aspect and any possible design of the second aspect.
[0065] The traffic behavior detection device described in the third, fourth, fifth, sixth, or seventh aspect may be, for example, a network device with packet forwarding capability, such as a router, switch (including but not limited to hardware programmable switches), gateway, firewall, etc., or a component within the network device, such as a single board, line card, etc., or a chip used to implement some or all of the operations described in any of the above aspects and any possible design.
[0066] In one possible design, the device for detecting the aforementioned traffic behavior is a hardware programmable switch.
[0067] Eighthly, this application provides a traffic behavior detection system, which includes a detection device and a control device. The detection device is used to perform the method provided by the first aspect and any possible design of the first aspect, and the control device is used to perform the method provided by the second aspect and any possible design of the second aspect.
[0068] In a specific design, the detection device may be, for example, the flow behavior detection device provided in the third, fifth or seventh aspects above, and the control device may be, for example, the flow behavior detection device provided in the fourth, sixth or seventh aspects above.
[0069] Ninthly, this application provides a computer-readable storage medium that is a non-volatile computer-readable storage medium, the computer-readable storage medium including computer program instructions, which, when executed by a processor, a computing device including a processor, or a computer system, perform the method provided by the first aspect and any possible design of the first aspect, or perform the method provided by the second aspect and any possible design of the second aspect.
[0070] In a tenth aspect, this application provides a computer program product comprising instructions that, when executed by a processor, a computing device including a processor, or a computer system, cause the processor, the computing device including a processor, or the computer system to perform the method provided by the first aspect and any possible design of the first aspect, or to perform the method provided by the second aspect and any possible design of the second aspect.
[0071] Eleventhly, this application provides a chip that includes a processor for running program instructions or code. The chip or a device including the chip can be used to perform the methods provided by the first aspect and any possible design of the first aspect, or can be used to perform the methods provided by the second aspect and any possible design of the second aspect.
[0072] For example, the chip also includes an input interface, an output interface, and a memory. The chip's input interface, output interface, processor, and memory are connected via internal interconnection paths. The memory stores program instructions or code executed by the processor, while the input and output interfaces are used for communication and connection between the chip and other chips or devices.
[0073] It is understood that any of the traffic behavior detection devices, traffic behavior detection systems, computer-readable storage media, computer program products or chips provided above can be applied to the corresponding methods provided above. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.
[0074] In this application, the names of the aforementioned traffic behavior detection devices, traffic behavior detection systems, etc., do not limit the devices or functional modules themselves. In actual implementation, these devices or functional modules may appear under other names. As long as the functions of each device or functional module are similar to those in this application, they all fall within the protection scope of this application. Attached Figure Description
[0075] Figure 1 This is a schematic diagram illustrating the detection of flow behavior using hash streams;
[0076] Figure 2 This is a diagram illustrating the detection of flow behavior using the interval between heavy-hit packets;
[0077] Figure 3 This is a schematic diagram of the implementation environment of the method provided in the embodiments of this application;
[0078] Figure 4 This is a schematic diagram of the structure of a detection device provided in an embodiment of this application;
[0079] Figure 5 This is a schematic flowchart of a traffic behavior detection method provided in an embodiment of this application;
[0080] Figure 6 This is another flowchart illustrating the traffic behavior detection method provided in the embodiments of this application;
[0081] Figure 7 This is a schematic diagram illustrating the process of a traffic behavior detection method provided in an embodiment of this application;
[0082] Figure 8 This is a flowchart illustrating another traffic behavior detection method provided in an embodiment of this application;
[0083] Figure 9This is a schematic diagram illustrating the process of another traffic behavior detection method provided in the embodiments of this application;
[0084] Figure 10 This is a schematic diagram of a storage module provided in an embodiment of this application;
[0085] Figure 11 This is a schematic diagram of aggregated impact information provided in an embodiment of this application;
[0086] Figure 12 This is a schematic diagram illustrating the relationship between a compression / aggregation storage unit and a missing information storage unit, provided in an embodiment of this application.
[0087] Figure 13 This is another flowchart illustrating the traffic behavior detection method provided in the embodiments of this application;
[0088] Figure 14 This is a schematic diagram illustrating the addition of service bits to data packets whose traffic behavior has been detected, provided in an embodiment of this application.
[0089] Figure 15 This is a schematic diagram of the structure of a traffic behavior detection device provided in an embodiment of this application;
[0090] Figure 16 This is a schematic diagram of another traffic behavior detection device provided in an embodiment of this application;
[0091] Figure 17 This is a schematic diagram of the structure of another traffic behavior detection device provided in the embodiments of this application;
[0092] Figure 18 This is a schematic diagram of the structure of a network device provided in an embodiment of this application. Detailed Implementation
[0093] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.
[0094] To facilitate understanding, the technologies and background involved in the embodiments of this application will be explained below.
[0095] 1. Flow Identifier (FID): FID is often used to uniquely identify a message stream transmitted in a network. It is also referred to as the flow ID below. It usually includes the source address, destination address, source port, destination port and protocol number of the message stream.
[0096] 2. Detection Flow: In this embodiment of the application, the detection flow refers to the flow whose FID has been stored in the recording unit of the filtering module. The traffic of the detection flow is tracked and the flow information is maintained by the network device.
[0097] 3. Competitive Flow: In the large flow filtering algorithm, the competitive flow is the packet flow that competes with the detection flow. If the competitive flow wins the competition, it will be determined to be the larger flow. At this time, the network device uses the FID of the successful competitive flow to replace the FID of the detection flow in the filtering module recording unit.
[0098] 4. SLO violation: Network performance fails to meet the SLO requirements of the application.
[0099] 5. SLO violation attribution: The process of finding the cause of an SLO violation in the network, such as resource contention caused by high-speed flow or hardware failure.
[0100] 6. Flow behavior: Flow behavior refers to the special patterns exhibited by the packet flow over a period of time, such as the total packet flow exceeding a certain threshold and / or rapid changes in flow rate.
[0101] 7. Flow Behavior Information: This generally refers to flow information reported by packet forwarding nodes that is related to suspicious traffic behavior. In related technologies, flow behavior information is, for example, key-value pairs describing HH behavior, HC behavior, or burst behavior. The key in the key-value pair is generally the FID of the packet flow, and the value is generally the statistical volume of that packet flow.
[0102] 8. Suspicious Traffic Behavior: Suspicious traffic behavior refers to traffic behavior that may lead to SLO (Solution Logical Limit) violations in the network. For example, total packet flow exceeding a certain threshold and / or rapid changes in flow rate can cause network congestion, and therefore these traffic behaviors can be identified as suspicious traffic behavior.
[0103] 9. Influencing Behavior: As defined in the embodiments of this application, it specifically refers to traffic behavior in which a packet flow continuously exceeds a given rate threshold for a period of time, and the total traffic of the flow exceeds a given traffic threshold at the end of this period. In the scheme of the embodiments of this application, since packet flows with influencing behavior are the main cause of SLO violations in the network, the scheme of the embodiments of this application is mainly used to detect packet flows with influencing behavior.
[0104] 10. Impact Information: Specifically refers to the basic unit used in the embodiments of this application to describe and report the impact behavior of message flows. Impact information generally includes the FID of the message flow, the start time (st), the end time (edt), and the total flow (flowsize, fsize) within the time period formed by the start and end times, abbreviated as (FID, st, edt, fsize). It should be noted that one impact behavior of a message flow can correspond to multiple impact information items.
[0105] 11. Velocity threshold (vth): One of the criteria for determining whether a packet flow has an influencing behavior, measured in megabits per second (Mbps). This application embodiment does not limit the specific value of vth; the value of vth can be set according to user needs. In one example, since this application embodiment defines that the rate of the influencing behavior must be greater than vth at any given time, vth can be set to a small percentage of the network device throughput, such as 1 Mb / s, but is not limited to this.
[0106] 12. Minimum Traffic Threshold (minsize): Also known as the traffic threshold, the traffic threshold is one of the criteria for determining whether a packet flow has an impact on behavior, and its unit is bytes (B). This application embodiment does not limit the specific value of the traffic threshold; the value can be set according to user needs. In one example, since this application embodiment defines that the total traffic size affecting behavior must be greater than the traffic threshold, the traffic threshold can be set to a small proportion of the network device's internal buffer, such as 3000B.
[0107] 13. Changesize Threshold: The changesize threshold is one of the criteria for separating different impact information of the same impact behavior, and the unit is bytes. The changesize threshold enables SLO violation attribution based on accurate impact behavior. For example, a changesize threshold of 10000 bytes.
[0108] Compared to ordinary networks, high-performance networks (such as high-performance data centers) place higher demands on the detection of suspicious traffic. Because the throughput of network devices grows much faster than their internal buffers, the buffering capacity of these devices is relatively reduced. This means that even short-duration (e.g., millisecond-level) suspicious traffic can trigger momentary SLO violations. Therefore, attributing SLO violations requires accurate detection and description of suspicious traffic across all packet flows passing through the network devices.
[0109] In related technologies, the flow information recorded when detecting traffic generally includes the flow ID and the cumulative flow size (i.e., the key-value pair mentioned above). The data structures used to track and record the flow information of the packet flow when detecting suspicious flow behavior can be divided into the following two categories: (a) sketch-based data structure; (b) counter-based data structure.
[0110] Among them, "sketch" is a general term for probabilistic data structures. The sketch data structure can store information about all packet flows passing through network devices at the cost of some accuracy when there is a collision. The counter data structure can accurately detect the FID and traffic count information of packet flows passing through network nodes, but the counter data structure can only accurately measure a limited number of flows.
[0111] Currently, the commonly used behavioral detection technologies in the industry can be roughly divided into the following three categories:
[0112] (a) A detection scheme that reports suspicious flow behavior description information based on a specific period can easily reflect the relationship between flow and time. However, since the scheme reports based on a time window that is not related to flow rate characteristics, and the time window usually does not coincide with the period when suspicious flow behavior occurs in the message flow, the scheme cannot obtain the accurate time boundary of suspicious flow behavior and the internal rate distribution.
[0113] (b) The scheme of reporting suspicious flow behavior description information to the control plane based on the number of recorded data packets is still unable to obtain the accurate time boundary of suspicious flow behavior because the time window for reporting suspicious flow behavior to the control plane in this scheme usually does not coincide with the time period when the suspicious flow behavior occurs.
[0114] (c) A scheme to detect suspicious flow behavior in data plane network devices based on the rate information of the packet flow. This scheme can obtain the accurate boundary of suspicious flow behavior based on the rate. However, the lack of complex computing power of current data plane network devices makes it difficult for data plane network devices to obtain instantaneous rate information of the packet flow. Therefore, this scheme is difficult to implement.
[0115] One related technique detects flow behavior using hashflow. For example... Figure 1 As shown, hashflow technology uses a counter data structure to accurately record flow information (including FID and flow size) on the data surface, employs periodic detection methods, and checks the flow within each detection cycle. Figure 1 The interaction between the main table and the auxiliary table, two layers of hash table structures, enables the filtering and storage of large flows, effectively reducing the scope of flow information that the detection system needs to continuously maintain. The main table records flow information based on received data packets, while the auxiliary table filters large flows (i.e., flows exceeding a threshold) based on the information recorded in the main table. The data plane then reports the filtered large flow information to the control plane, enabling the control plane to analyze network performance based on this information.
[0116] In this scheme, the detection period can also be understood as the detection window. Since the detection window does not coincide with the actual time window of suspicious traffic behavior such as sudden bursts in the packet flow, it cannot accurately detect the time boundary of suspicious traffic behavior. Furthermore, the detection period is generally tens of milliseconds or several seconds, so this scheme cannot detect instantaneous bursts of behavior at the millisecond level. Additionally, due to hash collisions, this scheme needs to estimate the number of large flows passing through the data plane based on experience, setting the hash space of the hash table to 10 to 100 times that number to avoid detection errors caused by hash collisions. However, this results in excess hash space in the hash table recording and reporting many unimportant small flow information to the control plane. To improve detection accuracy, the detection period can be shortened to accurately detect traffic behavior (e.g., detecting a flow lasting 5 milliseconds with a detection period of 1 millisecond), but this incurs significant reporting overhead. Moreover, the hashflow scheme involves auxiliary tables retransmitting data to the main table, which increases resource consumption.
[0117] Another related technique detects flow behavior using the High Hit Inter-packet Gap (HH-IPG) method. Specifically, HH-IPG can determine the boundaries of flow behavior based on the rate of the packet flow, thus accurately detecting the flow of packets. For example... Figure 2 As shown, HH-IPG determines the boundaries of flow behavior based on the traffic volume counted by counters (counter = 4 or counter = 3) and the rate of packet flow. For example... Figure 2 As shown, HH-IPG determines the boundary of time window A, which is based on the traffic size and packet flow rate at counter = 4, as the boundary of one flow behavior, and determines the boundary of time window B, which is based on the traffic size and packet flow rate at counter = 3, as the boundary of another flow behavior.
[0118] However, since it is difficult to obtain the instantaneous rate of the packet flow at the data plane, HH-IPG compares the exponentially weighted moving-average (EWMA) of rate-related inter-packet gaps (IPGs) with a fixed threshold to determine the rate characteristics of the packet flow. However, EWMA has high hysteresis, and IPG itself cannot fully reflect the rate characteristics of the packet flow. Therefore, HH-IPG may incorrectly delineate the boundaries of flow behavior, for example... Figure 2 The actual HH behavior framed in the Chinese text is divided into different time windows of popular behavior.
[0119] Another related technology uses a printqueue scheme to detect packet flow behavior. Specifically, the printqueue employs a multi-layered data structure to store packet information for different time intervals, essentially a scheme based on a counter data structure. To support fine-grained detection and querying for arbitrary time periods, the printqueue divides the data structure into T layers of equal size (T is an integer greater than 1). Each unit in each layer is responsible for storing flow information for a specific time period, and the stored time period increases exponentially with the number of data structure layers.
[0120] However, because printqueue uses a packet-by-packet measurement method, and the first-level printqueue of the data structure retains information about all data packets, the data plane incurs significant reporting overhead when reporting detected flow behavior information to the control plane. Therefore, this solution cannot support large-scale deployment. To avoid excessive reporting overhead, the printqueue detection module can be deployed locally on the network devices of the data plane. However, this lacks centralized unified analysis and requires specific network devices (such as specific switches) to provide additional query interfaces for users to query the detection results. This increases the hardware requirements of the switch and reduces the convenience of user queries.
[0121] Based on this, embodiments of this application provide a method for detecting traffic behavior. This method is applied to a packet forwarding node and includes: acquiring packet information of data packets flowing through the packet forwarding node. The packet information includes the flow ID of the packet flow to which the data packet belongs, the size of the data packet, and the timestamp of the data packet. Based on the acquired packet information, a rate threshold, and a traffic threshold, the method determines the impact information of the packet flow. Specifically, one piece of impact information for the packet flow describes the behavior of a traffic segment within the packet flow. The behavior of the traffic segment is represented by the amount of traffic transmitted within the time period indicated by the impact information, and the rate of traffic in the traffic segment is greater than or equal to the rate threshold, and the size of traffic in the traffic segment is greater than or equal to the traffic threshold.
[0122] It can be seen that the flow behavior described by the impact information of the packet flow is the impact behavior that occurs in the packet flow (i.e., the impact behavior defined in the embodiments of this application). In other words, the method provided in the embodiments of this application can detect the impact behavior occurring in traffic segments within the packet flow passing through the packet forwarding node. Compared with related technologies, the impact behavior detected by the embodiments of this application, described by the impact information, has accurate time boundaries (i.e., the time period indicated by the impact information), thus making it more accurate in attributing network performance SLO violations based on the impact behavior detected by the embodiments of this application.
[0123] refer to Figure 3 , Figure 3A schematic diagram of the implementation environment of the method provided in the embodiments of this application is shown.
[0124] like Figure 3 As shown, the implementation environment includes at least one detection device, such as... Figure 3 The detection devices 310, 320, and 330 are shown. The detection devices are deployed in a network at packet forwarding nodes (such as switches, routers, gateways, firewalls, etc., where switches include, but are not limited to, hardware programmable switches) used to detect packet flows passing through the packet forwarding nodes by executing the method provided in this application embodiment. This allows for the determination of the impact information of the packet flows within the packet forwarding nodes, thereby achieving the purpose of detecting the impact behavior of the packet flows within the packet forwarding nodes.
[0125] In practical applications, in one example, the above-mentioned detection device is deployed in every packet forwarding node in the network, that is, the detection device is deployed in all nodes of the network.
[0126] In another example, some packet forwarding nodes in the network are equipped with detection devices. In this case, it is necessary to ensure that at least one packet forwarding node along the forwarding path of any packet stream forwarded through the network is equipped with the aforementioned detection device. In this way, no packet streams transmitted in the network will be missed.
[0127] Optionally, continue to refer to Figure 3 Furthermore, the implementation environment of the method provided in this application embodiment may also include a control device. In this case, the detection device, acting as the data plane, detects the packet flow, while the control device, acting as the control plane, acquires and summarizes the detection results from the data plane. Therefore, when a user needs to attribute network performance SLO violations, they can query the impact behavior of relevant packet flows from the control device and perform attribution analysis.
[0128] For example, the control device can be implemented as any computing device, which can be implemented as a server, network management device / system, network cloud engine (NCE), network analyzer, etc., and is not limited to this.
[0129] In an exemplary embodiment, the control device may also adjust the parameters required by the detection device to determine the impact information of the message flow based on the quantity or period of the impact information reported by the detection device. Alternatively, it may be understood as adjusting the parameters used by the detection device when detecting traffic behavior (such as impact behavior), such as rate threshold, flow threshold, or segmentation threshold, to control the quantity of impact information determined by the detection device, thereby controlling the overhead required by the detection device to report the impact information to the control device. For a detailed description, please refer to the description in the method embodiments below, which will not be repeated here.
[0130] It should be understood that the above content is an exemplary description of the implementation environment of the method provided in the embodiments of this application, and does not constitute a limitation on the implementation environment of the method. As those skilled in the art know, as business needs change, the implementation environment can be adjusted according to application requirements, and the embodiments of this application do not list them one by one.
[0131] This application also provides a traffic behavior detection device. The detection device executes the method provided in this application to detect influencing behaviors in a packet flow passing through a packet forwarding node. The detection device can be deployed on any packet forwarding node that forwards a packet flow. The packet forwarding node can be any network device with packet forwarding capabilities, such as a switch (e.g., a hardware programmable switch), router, gateway, or firewall.
[0132] In this embodiment of the application, in order to achieve the purpose of detecting influencing behaviors in the packet flow passing through the packet forwarding node, such as Figure 4 As shown, the detection device 400 deployed at the packet forwarding node includes a filtering module. The filtering module is used to filter traffic segments whose rate exceeds the rate threshold and whose traffic exceeds the traffic threshold, and to determine the flow information of the traffic segment as an impact information of the packet flow.
[0133] Optionally, the detection device 400 may also include a temporary storage module for temporarily storing the flow information of each message flow passing through the message forwarding node.
[0134] Optionally, the detection device 400 may also include a storage module for storing the impact information determined by the screening module, such as compressed storage or aggregated storage. Compressed storage and aggregated storage can compress the impact information, thereby reducing the overhead required for the detection device to report the impact information to the control device.
[0135] The detailed functions implemented by the temporary storage module, the filtering module, and the storage module can be found in the description of the method embodiments below, and will not be repeated here.
[0136] The method for detecting traffic behavior provided in the embodiments of this application will now be described with reference to the accompanying drawings.
[0137] refer to Figure 5 , Figure 5 A schematic flowchart of a traffic behavior detection method provided in an embodiment of this application is shown. Optionally, this method is applied to... Figure 3 The implementation environment shown is provided by [the entity / organization], and is provided by [the entity / organization] with [the following]. Figure 4 The detection device with the structure shown performs the operation. For example... Figure 5 As shown, the method includes the following steps 101 to 102.
[0138] Step 101: The detection device obtains the packet information of the data packets flowing through the message forwarding node. The packet information includes the flow ID of the message flow to which the data packet belongs, the size of the data packet, and the timestamp of the data packet.
[0139] A detection device is deployed in the message forwarding node. In this way, whenever the message forwarding node receives a data packet and parses the packet header to forward the data packet, the detection device can obtain the packet information parsed by the message forwarding node from the header of the received data packet.
[0140] The Flow ID (FID, denoted as f) in the packet information can be a 5-tuple of the data packet, specifically including the source address, source port, destination address, destination port, and transport protocol. Alternatively, the FID in the packet information can also be a user-defined character or character field. This application does not limit this.
[0141] The size of a data packet in the packet information refers to the number of bytes included in the data packet, which is denoted as psize in this embodiment of the application.
[0142] The timestamp (ts) of a data packet in packet information refers to the timestamp carried by the data packet. The time represented by the ts of the data packet can be the time when the data packet was sent, such as the time when the previous hop node of the packet forwarding node sent the data packet to the packet forwarding node. The time represented by the ts of the data packet can also be the time when the packet forwarding node arrived at the packet forwarding node, that is, the time when the packet forwarding node received the data packet. There is no limitation on which one. For ease of description, the following description will take the example where the ts of the data packet is the time when the data packet arrives at the packet forwarding node.
[0143] Step 102: The detection device determines the impact information of the message flow based on the rate threshold, the flow threshold, and the acquired packet information.
[0144] In this context, an impact message in the message stream describes the behavior of a traffic segment within the message stream. The behavior of the traffic segment is represented by the amount of traffic transmitted within the time period indicated by the impact message, and the rate of traffic in the traffic segment is greater than or equal to a rate threshold, and the amount of traffic in the traffic segment is greater than or equal to a traffic threshold. It can be seen that the behavior of the traffic segment described here is the impact behavior defined in the embodiments of this application.
[0145] In this embodiment, to detect the impact behavior of traffic, the detection device records and maintains flow information of packet flows passing through packet forwarding nodes. For any packet flow passing through a packet forwarding node, such as the first packet flow, the flow information recorded and maintained and updated by the detection device based on each received data packet includes: the flow ID of the first packet flow, the flow start time (denoted as st), the last received data packet time ts, the size of the first packet flow received between st and ts (abbreviated as flow size (fpsize)), and the latest reception time of the next data packet estimated based on the rate threshold (denoted as maxt). Thus, the flow information recorded and maintained by the detection device can be represented as (f, maxt, fsize, st, ts).
[0146] For example, the flow information obtained by the detection device when maintaining the flow information of the first message flow based on the first data packet of the first message flow includes: the flow ID of the first message flow, st, the ts of the first data packet, the size of the first message flow received between st and ts of the first data packet, and the latest reception time (i.e., maxt) of the next data packet of the first data packet estimated based on the rate threshold.
[0147] The `maxt` of the next data packet predicted based on the rate threshold is determined by the `ts` and size of the currently received data packet, as well as the rate threshold. In one example, `maxt = ts + psize / vth`, where `ts` is the timestamp of the currently received data packet, `psize` is the size of the current data packet, and `vth` is the rate threshold. It can be understood that when `vth` is not 1, `maxt` can be determined using a matching table similar to that used to determine the freshness factor below, which will not be elaborated upon here.
[0148] As can be seen, since the traffic rate must be greater than or equal to a rate threshold in the traffic impact behavior defined in this application embodiment, this application embodiment maintains the traffic information of the traffic flow based on the rate of each data packet in the traffic flow after initially recording the traffic flow information, thereby determining the impact information of the traffic flow based on the maintained traffic information. However, since it is difficult for network nodes to obtain the rate of each data packet in the traffic, this application embodiment introduces the maxt of the next data packet calculated based on the rate threshold in the traffic flow information recorded by the traffic flow passing through the packet forwarding node for detecting traffic impact behavior. In this way, the detection device can determine whether the rate of the currently received data packet is greater than the rate threshold by judging whether the ts (i.e., the arrival time of the currently received data packet) is less than maxt.
[0149] Specifically, if the ts of the data packet currently received by the message forwarding node is less than maxt, which is determined based on the size, timestamp, and rate threshold of the previous data packet, it means that the data packet arrived at the message forwarding node before maxt arrived, and in this case, the rate of the data packet exceeds the rate threshold. If the ts of the data packet currently received by the message forwarding node is greater than maxt, which is determined based on the size, timestamp, and rate threshold of the previous data packet, it means that the data packet arrived at the message forwarding node after maxt arrived, and in this case, the instantaneous rate of the data packet does not exceed the rate threshold, or can be interpreted as being less than or below the rate threshold.
[0150] In the first embodiment, the detection device deployed in the packet forwarding node includes a filtering module. The filtering module includes k (k is a positive integer) recording units. Each recording unit is used to record the flow information of the packet flow passing through the packet forwarding node. The description of the flow information can be referred to the above description and will not be repeated here. For example, the flow information recorded by the first recording unit among the k recording units included in the filtering module is denoted as the first flow information. The first flow information is the flow information recorded based on any packet flow passing through the packet forwarding node. The first flow information includes: flow ID, st, ts of the last received data packet, traffic size, and maxt of the next data packet estimated based on the rate threshold. Here, the first recording unit is any one of the k recording units included in the filtering module.
[0151] In one example, the k record units mentioned above can be k hash spaces addressed by a hash algorithm. Each hash space can be implemented by a register. That is, the record units can be implemented by registers, including but not limited to registers.
[0152] Taking the first data packet in the first message stream received by the message forwarding node as an example, the detection device can obtain the packet information of the first data packet. As described in step 101, the packet information of the first data packet includes the flow ID of the first message stream, the timestamp of the first data packet, and the size of the first data packet. Therefore, referring to... Figure 6 , Figure 6 This is another flowchart illustrating the traffic behavior detection method provided in this application embodiment. Optionally, this method is applied to... Figure 3 The implementation environment shown is provided by [the entity / organization], and is provided by [the entity / organization] with [the following]. Figure 4 The detection device with the structure shown is used.
[0153] like Figure 6 As shown, the process by which the detection device determines the impact information of the message flow based on packet information, rate threshold, and flow threshold includes the following steps 1021 to 1022.
[0154] Step 1021: Based on the flow ID in the packet information of the first data packet, the detection device determines the first record unit in the filtering module that has a mapping relationship with the first message flow to which the first data packet belongs.
[0155] After obtaining the packet information of the first data packet by executing step 101, the detection device can determine the record unit that has a mapping relationship with the first message stream in the filtering module based on the flow ID of the first message stream contained in the packet information of the first data packet. For example, the detection device can perform a hash operation on the flow ID of the first message stream contained in the packet information of the first data packet, and the result of the hash operation indicates the hash position of the record unit that has a mapping relationship with the first message stream in the filtering module.
[0156] For simplicity, the embodiments of this application will be described below using the example of a detection device determining a recording unit in a filtering module that has a mapping relationship with the first message stream as the first recording unit based on the flow ID of the first message stream contained in the packet information of the first data packet.
[0157] Optionally, the first recording unit may already contain stream information, such as the first stream information mentioned above.
[0158] Optionally, the first record unit can be empty.
[0159] Step 1022: When the detection device determines to replace the first stream information recorded in the first recording unit with the second stream information based on the rate and rate threshold of the first data packet, if the traffic size in the first stream information is greater than or equal to the traffic threshold, then the stream ID, time information, and traffic size in the first stream information are determined as influencing information. The second stream information is the stream information obtained based on the packet information of the first data packet.
[0160] In step 1022, after determining the first recording unit that has a mapping relationship with the first message stream, the detection device first determines the update operation to be performed on the first recording unit based on the rate of the first data packet and the rate threshold. When the update operation is to replace the first stream information recorded in the first recording unit with second stream information, the detection device determines the impact information based on the first stream information. That is, when the detection device determines, based on the rate of the first data packet and the rate threshold, that the first stream information recorded in the first recording unit is replaced with second stream information, it determines the impact information based on the first stream information.
[0161] The second flow information is derived from the packet information of the first data packet. The flow ID of the second flow information is the flow ID of the first message flow. The maxt in the second flow information is calculated based on the rate threshold, ts in the packet information of the first data packet, and psize. The st in the second flow information is the ts of the first data packet. The fsize in the second flow information is the packet size (i.e., psize) of the first data packet.
[0162] Taking the first record unit as an example where the first stream information is recorded, in case a, when the detection device determines that the stream ID in the packet information of the first data packet is the same as the stream ID in the first stream information and the rate of the first data packet is less than the rate threshold, it can be determined that the update operation performed on the first record unit is to replace the first stream information with the second stream information.
[0163] The detection device can determine whether the flow ID in the packet information of the first data packet is the same as the flow ID in the first flow information by comparing the flow ID in the packet information of the first data packet with the flow ID in the first flow information. The detection device can also determine the relationship between the rate of the first data packet and the rate threshold by comparing the ts of the first data packet and the maxt of the first flow information. For example, if the detection device determines that the ts of the first data packet is greater than the maxt in the first flow information, it can determine that the rate of the first data packet is less than the rate threshold. As another example, if the detection device determines that the ts of the first data packet is less than or equal to the maxt in the first flow information, it can determine that the rate of the first data packet is greater than or equal to the rate threshold.
[0164] In this embodiment, when the detection device determines that the flow ID in the packet information of the first data packet is the same as the flow ID in the first flow information, and the ts of the first data packet is greater than the maxt in the first flow information, it indicates that no packet flow conflict occurred when the detection device used the first recording unit of the filtering module to record the flow information of the packet flow. However, the first data packet failed to arrive before the maxt in the first flow information originally recorded in the first recording unit (i.e., timed out). Therefore, the rate of the first data packet is lower than the rate threshold, which indicates that the flow behavior described by the first flow information originally recorded in the first recording unit with a rate greater than the rate threshold has ended. At this time, the filtering module of the detection device can determine to replace the first flow information originally recorded by the first recording unit with the second flow information. In this case, the operation of the filtering module replacing the first flow information originally recorded by the first recording unit with the second flow information can be called a "timeout-based update operation".
[0165] Since the number of record units in the filtering module is limited, there are cases where different message streams map to the same record unit, which is called a message stream conflict.
[0166] In case b, when the detection device determines that the flow ID in the packet information of the first data packet is the same as the flow ID in the first flow information, the rate of the first data packet is greater than or equal to the rate threshold, and the traffic size in the first flow information is greater than or equal to the segmentation threshold, it can also determine that the update operation performed on the first recording unit is to replace the first flow information with the second flow information. In this embodiment, the segmentation threshold is greater than the traffic threshold.
[0167] The explanation of the detection device determining that the flow ID in the packet information of the first data packet is the same as the flow ID in the first flow information, and determining that the rate of the first data packet is greater than or equal to the rate threshold, can be referred to the description in case a, and will not be repeated here.
[0168] When the detection device determines that the flow ID in the packet information of the first data packet is the same as the flow ID in the first flow information, and the rate of the first data packet is greater than or equal to the rate threshold, it indicates that no packet flow conflict occurred when the detection device used the first recording unit of the filtering module to record the flow information of the packet flow. Furthermore, the first data packet arrived at the packet forwarding node before the maxt value in the first flow information originally recorded in the first recording unit, meaning the rate of the first data packet is greater than or equal to the rate threshold. Therefore, it indicates that the flow behavior described by the first flow information originally recorded in the first recording unit, where the rate is greater than the rate threshold, has not ended. In addition, if the fsize value in the first flow information originally recorded in the first recording unit is greater than the segmentation threshold, it means that the flow size of the first packet flow recorded by the filtering module based on the received data packet is sufficiently large. Therefore, to ensure fine-grained positioning of the impact behavior, the filtering module of the detection device can determine to replace the first flow information originally temporarily stored in the first recording unit with information based on the second flow information. In this case, the operation of the filtering module replacing the first flow information originally recorded in the first recording unit with information based on the second flow information can be called an "update operation based on excessive flow."
[0169] Optionally, in this application embodiment, there is also a situation c, where the detection device determines that the flow ID in the packet information of the first data packet is different from the flow ID in the first flow information. This indicates that a message flow conflict has occurred when the detection device uses the first recording unit of the filtering module to record the flow information of the message flow, that is, different message flows are mapped to the same recording unit of the filtering module.
[0170] In this case, in the first possible implementation, the screening module of the detection device can determine to replace the first-stream information with the second-stream information.
[0171] In a second possible implementation, the filtering module of the detection device can also determine whether to replace the first-stream information with second-stream information based on the freshness of the first-stream information recorded by the first recording unit. For example, when the detection device determines that the relationship between the freshness of the first-stream information recorded by the first recording unit and the freshness threshold meets a preset condition, it determines to replace the first-stream information with second-stream information. In this case, the operation of the filtering module replacing the original first-stream information recorded by the first recording unit with second-stream information can be called a "stream-switching-based update operation". As another example, when the detection device determines that the relationship between the freshness of the first-stream information recorded by the first recording unit and the freshness threshold does not meet a preset condition, it determines not to perform any operation on the first recording unit.
[0172] The freshness of the first-stream information is used to indicate whether to continue maintaining the first-stream information in the first recording unit. Maintenance includes updating the data of the first-stream information recorded in the first recording unit based on the received data packets.
[0173] Additionally, preset conditions may include, for example, that the freshness of the first-stream information is greater than a freshness threshold, or that the freshness of the first-stream information is less than a freshness threshold. It can be seen that in the second possible implementation, the recording unit of the filtering module, in addition to recording the stream information, also maintains the freshness of the stream information. For an explanation of how the filtering module maintains the freshness of the stream information in the recording unit, please refer to the relevant description below; it will not be repeated here.
[0174] Subsequently, if the filtering module of the detection device determines that the first flow information in the first record unit is to be replaced by the second flow information, and the flow size in the first flow information is greater than or equal to the flow threshold, then the filtering module determines the flow ID, time information and flow size in the first flow information as the impact information of the message flow identified by the flow ID.
[0175] For example, when the first flow information is "f1, maxt1, st1, ts1, fsize1", where f1 represents the flow ID of flow f1, maxt1 is the maximum value of the next data packet belonging to flow f1 estimated based on the rate threshold, st1 is the start time of flow f1, ts1 is the timestamp of the last received data packet belonging to flow f1, and fsize1 is the traffic size of flow f1 during the period from st1 to ts1, the detection device determines "f1, st1, ts1, fsize1" as the first influence information of flow f1, and records it as "f1, st1, ent1, fsize1", where ent1 = ts1 and represents the end time of the behavior of the traffic segment described by influence information 1, correspondingly, st1 represents the start time of the behavior of the traffic segment described by influence information 1, and fsize1 represents the traffic size of the traffic segment described by influence information 1.
[0176] Specifically, when the filtering module determines to replace the first-stream information in the first recording unit with the second-stream information based on "timeout-based update operation" and "stream switching-based update operation", the filtering module compares the traffic size and traffic threshold in the first-stream information to determine whether the traffic size in the first-stream information is greater than or equal to the traffic threshold.
[0177] When the filtering module determines to replace the first-stream information in the first record unit with the second-stream information based on the "update operation based on excessive traffic", since one of the conditions of the "update operation based on excessive traffic" is that the traffic size of the first-stream information is greater than or equal to the segmentation threshold, and the segmentation threshold is greater than the traffic threshold, in this case, the traffic size of the first-stream information must be greater than the traffic threshold. Therefore, the filtering module does not need to compare the traffic size in the first-stream information with the traffic threshold to determine whether the traffic size in the first-stream information is greater than or equal to the traffic threshold.
[0178] Optionally, when the filtering module of the detection device determines to replace the first flow information in the first recording unit with the second flow information, if the flow size in the first flow information is less than the flow threshold, the filtering module determines the flow size in the first flow information and the rate determined based on the first flow information as the missing information of the message flow identified by the flow ID. The missing information is used to adjust the parameters used when detecting flow behavior. The parameters are, for example, at least one of the rate threshold, flow threshold, or segmentation threshold.
[0179] Typically, the traffic behavior described by the missing information exists between the influencing behaviors, which can be regarded as the trough between the influencing rows. This part of the traffic behavior does not meet the conditions of the influencing behavior (rate greater than rate threshold, traffic size greater than traffic threshold), so it can be used as reference information for adjusting the aforementioned parameters.
[0180] For example, when the amount of missing information is too large, or when the proportion of missing information to influencing information exceeds a certain threshold, the values of the rate threshold, flow threshold, and / or segmentation threshold can be appropriately increased to raise the threshold for detecting influencing behavior, thereby reducing the number of detected influencing information. This application does not specifically limit the value of the proportion threshold in its embodiments.
[0181] For example, when the amount of missing information is too small, or the proportion of missing information to the amount of impact information is lower than the proportion threshold, the values of the rate threshold, flow threshold, and / or segmentation threshold can be appropriately reduced to lower the threshold for detecting impact behavior, thereby increasing the amount of impact information detected.
[0182] When the screening module of the detection device determines that the first-stream information in the first recording unit should be replaced with the second-stream information, it also replaces the first-stream information in the first recording unit with the second-stream information in order to start maintaining the second-stream information.
[0183] In one example, when the recording unit is implemented as a register, the detection device, upon determining that the first stream information in the first recording unit is to be replaced by the second stream information, uses the second stream information to reassign the register that serves as the first recording unit. Reassigning the register means clearing the register and then reassigning the value.
[0184] In addition, in this embodiment of the application, there is also case d, where when the detection device determines that the flow ID in the packet information of the first data packet is the same as the flow ID in the first flow information and the rate of the first data packet is greater than or equal to the rate threshold, the filtering module of the detection device updates the data in the first flow information according to the packet information of the first data packet.
[0185] It can be seen that case d indicates that no packet flow conflict occurred when the detection device used the first recording unit of the filtering module to record the flow information of the packet flow, and the rate of the first data packet is greater than or equal to the rate threshold, indicating that a flow behavior described by the first flow information originally temporarily stored in the first recording unit with a rate greater than the rate threshold has not ended. Therefore, the filtering module uses the packet information of the first data packet to update the data of the first flow information originally temporarily stored in the first recording unit.
[0186] Specifically, the filtering module updates the fsize of the first flow information to the sum of the original fsize and the size of the first data packet, updates the ts of the first flow information to the ts of the first data packet, and updates the maxt in the first flow information to the maxt calculated based on the ts, psize, and rate threshold of the first data packet. In this way, flow information maintenance is achieved for the first message flow with a rate greater than the rate threshold.
[0187] In this embodiment of the application, there is also a situation e, where the detection device determines that the flow ID in the packet information of the first data packet is the same as the flow ID in the first flow information, the rate of the first data packet is greater than or equal to the rate threshold, but the flow size (i.e., fsize) in the first flow information is less than the segmentation threshold, and the filtering module of the detection device updates the data in the first flow information according to the packet information of the first data packet.
[0188] As can be seen, case e indicates that no packet flow conflict occurred when the detection device used the first recording unit of the filtering module to record the flow information of the packet flow, and the rate of the first data packet is greater than or equal to the rate threshold, indicating that the flow behavior described by the first flow information originally stored in the first recording unit with a rate greater than the rate threshold has not ended. In addition, the fsize in the first flow information originally recorded in the first recording unit is less than the segmentation threshold, indicating that the size of the first packet flow recorded by the filtering module is not large enough at this time, so it will not affect the fine-grained positioning behavior. Therefore, the filtering module uses the packet information of the first data packet to update the data of the first flow information originally stored in the first recording unit. For detailed update instructions, please refer to the description of case d, which will not be repeated here.
[0189] For cases d and e, the operation of the filtering module using the packet information of the first data packet to update the data of the first stream information originally temporarily stored in the first record unit is called "stream information data update operation".
[0190] In other cases, if the first recording unit is empty, the filtering module of the detection device can obtain the second stream information based on the packet information of the first data packet and assign it to the first recording unit. In this case, the detection device will not generate any information affecting the process.
[0191] To better understand the method described in step 102, a specific example will be provided below.
[0192] Taking a scenario where the first data packet of the first message flow is packet p, the flow ID of the first message flow is f2, the ts of packet p is 6800, the size of packet p (i.e., psize) is 1000, and the flow information obtained based on the packet information of packet p is flow information 2, as an example, the filtering module can calculate the maxt of the next data packet of packet p based on the ts, psize, and rate threshold of packet p. Taking a rate threshold of 1 Mbit / s as an example, then maxt = 6800 + 1000 / 1 = 7800. Therefore, flow information 2 is "f = f2, maxt = 7800, fsize = 1000, st = 6800, ts = 6800". (Reference) Figure 7 , Figure 7 The illustration shows a process diagram of a traffic behavior detection method provided in an embodiment of this application.
[0193] like Figure 7 As shown, after the detection module obtains the packet information of packet p (i.e., "f2, ts = 6800, psize = 1000") through step 101, the detection module sends the packet information of packet p to the filtering module. The filtering module then determines the record unit 1 that has a mapping relationship with the first message stream based on the flow ID in the packet information of packet p. For example, the filtering module performs a hash operation on f2, and the hash result indicates record unit 1.
[0194] Next, in possible case 11 (corresponding to case c described above), the flow information 1 recorded in recording unit 1 is the flow information of the second message flow with flow ID f1 (e.g., Figure 7 The given information, "f = f1, maxt = 7000, fsize = 3000, st = 5000, ts = 6500", indicates that the flow ID of the p packet is different from the flow ID of the original flow information 1 recorded in recording unit 1. Therefore, the filtering module replaces the flow information 1 in recording unit 1 with flow information 2, and determines the flow ID, time information, and fsize in the original flow information 1 recorded in recording unit 1 as an influence information of the second message flow, specifically "f = f1, fsize = 3000, st = 5000, ent = 6500".
[0195] In possible case 12 (corresponding to case a described above), the stream information 1 recorded in recording unit 1 is the stream information of the first message stream with stream ID f2 (e.g., Figure 7 The given information, "f = f2, maxt = 6500, fsize = 5000, st = 4000, ts = 5500", indicates that the flow ID of packet p is the same as the flow ID of flow information 1 originally recorded in recording unit 1. Furthermore, the ts (6800) of packet p is greater than the maxt (6500) in flow information 1, meaning the rate of packet p is less than the rate threshold. At this point, the flow behavior described by flow information 1, where the rate is greater than the rate threshold, has ended. Therefore, the filtering module replaces flow information 1 in recording unit 1 with flow information 2, and determines the flow ID, time information, and fsize in the original flow information 1 recorded in recording unit 1 as an influence information of the first message flow, specifically "f = f2, fsize = 5000, st = 4000, ent = 5500".
[0196] In possible case 13 (corresponding to case b described above), the stream information 1 recorded in the recording unit is the stream information of the first message stream with stream ID f2 (e.g., Figure 7The shown "f = f2, maxt = 7000, fsize = 11000, st = 4000, ts = 6000" means that the stream ID of the p packet is the same as the stream ID of the stream information 1 originally recorded in the recording unit 1. Furthermore, the ts (i.e., 6800) of the p packet is less than the maxt (i.e., 7000) in flow information 1, meaning that the rate of the p packet is greater than the rate threshold. At this time, the flow behavior described by flow information 1 with a rate greater than the rate threshold has not ended. However, if the segmentation threshold is set to 10000, then the fsize (i.e., 11000) recorded in flow information 1 is greater than the segmentation threshold. This indicates that the flow described by flow information 1 recorded in recording unit 1 is large enough. In order to achieve fine-grained positioning of the impact behavior, the filtering module can replace flow information 1 in recording unit 1 with flow information 2, and determine the flow ID, time information and fsize in the flow information 1 originally recorded in recording unit 1 as an impact information of the first message flow, specifically "f = f2, fsize = 11000, st = 4000, ent = 6000".
[0197] In possible case 14 (corresponding to case d described above), the flow information 1 recorded in recording unit 1 is the flow information of the first message flow with flow ID f2 (e.g., Figure 7 The given information, "f = f2, maxt = 7000, fsize = 11000, st = 4000, ts = 6000", indicates that the flow ID of packet p is the same as the flow ID of flow information 1 originally recorded in recording unit 1. Furthermore, the ts (6800) of packet p is less than the maxt (7000) in flow information 1, meaning the rate of packet p is greater than the rate threshold. Since the flow behavior described in flow information 1, where the rate is greater than the rate threshold, has not ended, the filtering module uses the packet information of packet p to update the maxt, fsize, and ts of flow information 1 in recording unit 1, thus obtaining the updated flow information "f = f2, maxt = 7800, fsize = 12000, st = 4000, ent = 6800".
[0198] In possible case 15 (corresponding to case e described above), the flow information 1 recorded in recording unit 1 is the flow information of the first message flow with flow ID f2 (e.g., Figure 7The shown "f = f2, maxt = 7000, fsize = 8000, st = 4000, ts = 6000" means that the stream ID of the p packet is the same as the stream ID of the stream information 1 originally recorded in the recording unit 1. Furthermore, the ts (6800) of packet p is less than the maxt (7000) in flow information 1, meaning that the rate of packet p is greater than the rate threshold. At this time, the flow behavior described by flow information 1 with a rate greater than the rate threshold has not ended. Also, if the segmentation threshold is set to 10000, then the fsize (8000) recorded in flow information 1 is less than the segmentation threshold. This means that the flow described by flow information 1 recorded in recording unit 1 is not particularly large. Continuing to update and maintain the data of flow information 1 in the filtering module will not affect the fine-grained positioning behavior. Therefore, the filtering module uses the packet information of packet p to update the maxt, fsize and ts of flow information 1 in recording unit 1, thereby obtaining the updated flow information "f = f2, maxt = 7800, fsize = 9000, st = 4000, ent = 6800".
[0199] It can be seen that in possible scenarios 14 and 15, the detection device will not generate any impact information based on the p packet.
[0200] Thus, through the method described in steps 101 to 102, the detection device can obtain accurate description information of the traffic segments in the packet flow that have caused the influencing behavior through the filtering module. This description information is the aforementioned influencing information. By obtaining the influencing information, this embodiment of the application can accurately locate the influencing behavior of the packet flow, thereby providing accurate information for attributing SLO violations to network performance and improving the accuracy of SLO violation attribution.
[0201] In the second embodiment, when there is a packet flow conflict, the filtering module in the above-described method removes the flow information of the short-term burst traffic from the filtering module by performing an "update operation based on flow switching". If the size of the burst traffic does not exceed the flow threshold at this time, the detection device will not obtain the impact information in the flow information of the burst traffic, that is, it cannot detect the impact behavior of the burst traffic.
[0202] Based on this, the present application embodiment further includes a temporary storage module for temporarily storing the flow information of the packet flow in the detection device described above. This temporary storage module also includes k recording units, each recording unit for recording the flow information of the packet flow passing through the packet forwarding node. For the flow information recorded by the second recording unit in the temporary storage module, the flow information recorded by the second recording unit includes the flow ID, flow start time (i.e., st), timestamp of the last received data packet (i.e., ts), flow size (i.e., fsize), and the latest reception time of the next data packet estimated based on the rate threshold (i.e., maxt). The flow information recorded by the second recording unit is the flow information recorded based on any packet flow passing through the packet forwarding node. It can be seen that the format and content of the flow information recorded and maintained in the temporary storage module are the same as those recorded and maintained in the filtering module.
[0203] In this case, refer to Figure 8 , Figure 8 A flowchart illustrating another traffic behavior detection method provided in an embodiment of this application is shown. Optionally, this method is applied to... Figure 3 The implementation environment shown is provided by [the entity / organization], and is provided by [the entity / organization] with [the following]. Figure 4 The detection device with the structure shown performs the operation. For example... Figure 8 As shown, after executing step 101 and before executing step 1021, the detection device first executes the following steps 201 to 202.
[0204] Step 201: Based on the flow ID in the packet information of the first data packet, the detection device determines the second record unit as the record unit in the temporary storage module that has a mapping relationship with the first message flow to which the first data packet belongs.
[0205] Here, for a detailed explanation of step 201, please refer to the description in step 1021 where the detection device determines the first record unit in the filtering module that has a mapping relationship with the first message stream to which the first data packet belongs, based on the flow ID in the packet information of the first data packet. It will not be repeated here.
[0206] Step 202: Based on the rate and rate threshold of the first data packet, the detection device determines the data to update the stream information recorded in the second recording unit using the packet information of the first data packet.
[0207] Step 202 includes: when the flow ID in the packet information of the first data packet is the same as the flow ID in the flow information recorded by the second recording unit, and the rate of the first data packet is greater than or equal to the rate threshold; or when the flow ID in the packet information of the first data packet is the same as the flow ID in the flow information recorded by the second recording unit, the rate of the first data packet is greater than or equal to the rate threshold, and the flow size in the first flow information is less than the segmentation threshold, determining to use the packet information of the first data packet to update the data of the flow information recorded in the second recording unit.
[0208] Specifically, when the ts of the first data packet is less than or equal to the maxt in the flow information recorded by the second recording unit, the rate of the first data packet is greater than or equal to the rate threshold. Furthermore, the segmentation threshold is greater than the flow threshold. For a detailed explanation of step 202, please refer to the descriptions of cases d and e in step 1022 above, which will not be repeated here.
[0209] Based on the descriptions of cases d and e in step 1022, it can be seen that in step 202, the second recording unit of the temporary storage module of the detection device will not generate the replaced stream information. Here, the "replaced stream information" is denoted as switching information.
[0210] In this case, the detection device sends a message carrying the packet information of the first data packet and a service bit with a value of the first value (denoted as m = the first value) to the filtering module. In response to the service bit with a value of the first value, the filtering module performs the above steps 1021 to 1022 based on the packet information of the first data packet.
[0211] The service bit is used to indicate the subsequent operations that the detection device needs to perform. In this embodiment, when the service bit is set to a first value (such as 0), it indicates that the temporary storage module of the detection device has not generated switching information. At this time, the detection device needs to determine the impact information by executing steps 1021 to 1022.
[0212] It should be noted that when the detection module includes a temporary storage module, in case c above, when the detection device executes step 1022, the filtering module of the detection device does not perform any operation on the first flow information recorded in the first recording unit. This is because the flow information of the first packet flow to which the first data packet belongs has been temporarily stored in the second recording unit of the temporary storage module. Therefore, it is not necessary to use the second flow information obtained based on the packet information of the first data packet to replace the first flow information recorded in the first recording unit of the filtering module. This allows the flow information of sudden short flows (such as the first flow information) to continue to be retained in the filtering module for maintenance and updates, thereby increasing the probability of detecting the impact behavior of sudden short flows.
[0213] In other words, when the detection module includes a temporary storage module, after the detection device updates the second recording unit of the temporary storage module based on the packet information of the first data packet, it sends the packet information of the first data packet to the filtering module and executes the above steps 1021 to 1022. The situations in which the filtering module generates impact information include the situations a and b mentioned above, namely, the impact information obtained by the filtering module performing an "update operation based on timeout" on a recording unit, and the impact information obtained by the filtering module performing an "update operation based on excessive traffic" on the first recording unit.
[0214] After the detection device executes steps 202 and 1021 in sequence, in addition to executing step 1022, the detection device also executes the following step 203.
[0215] Step 203: The detection device updates the freshness of the stream information recorded by the first recording unit based on the first freshness factor determined according to the first data packet.
[0216] Freshness (denoted as fre) is used to indicate whether to continue maintaining the current record's stream information in the first record unit. Maintenance includes updating the stream information of the current record in the first record unit based on the received data packets (i.e., "stream information data update operation").
[0217] For example, when the freshness of the streaming information recorded in the first recording unit exceeds a freshness threshold, the detection device stops maintaining the streaming information in the first recording unit. Conversely, when the freshness of the streaming information recorded in the first recording unit does not exceed the freshness threshold, the detection device needs to continue maintaining and updating the streaming information in the first recording unit. This application embodiment does not specifically limit the value of the freshness threshold. Of course, it can also be designed such that: when the freshness of the streaming information recorded in the first recording unit does not exceed the freshness threshold, the detection device stops maintaining the streaming information in the first recording unit; when the freshness of the streaming information recorded in the first recording unit exceeds the freshness threshold, the detection device needs to continue maintaining and updating the streaming information in the first recording unit.
[0218] For simplicity, the embodiments of this application will be described below using the example of "when the freshness of the stream information recorded in the first recording unit exceeds the freshness threshold, the detection device stops maintaining the stream information in the first recording unit; when the freshness of the stream information recorded in the first recording unit does not exceed the freshness threshold, the detection device needs to continue maintaining and updating the stream information in the first recording unit".
[0219] When the recording unit of the filtering module records stream information and maintains the freshness of the stream information, the stream information maintained in the recording unit of the filtering module can be represented as: f, fre, maxt, fsize, st, ts. Among them, (f, re) is denoted as the first part, which is used to filter large streams, and (maxt, fsize, st, ts) is denoted as the second part, which is used to record the descriptive information of the stream.
[0220] The first freshness factor is used to indicate the degree of influence of the first data packet on the freshness of the stream information recorded in the first recording unit. In this embodiment, the freshness factor can be denoted as frenum, and when the detection device determines that the temporary storage module will not generate switching information after executing step 202, the detection device needs to determine the first freshness factor based on the first data packet.
[0221] Optionally, the detection device may determine a first freshness factor based on the size and packet interval of the first data packet, where the packet interval of the first data packet is the time interval between the first data packet and the preceding data packet in the first message stream. Then, when the detection device sends the packet information of the first data packet to the filtering module in step 202, it carries this freshness factor.
[0222] In one example, frenum can be calculated based on formula (1).
[0223]
[0224] In this context, when frenum is the first freshness factor, psize is the size of the first data packet, Δt is the packet interval of the first data packet, vth is the rate threshold, and n is a constant. The purpose of this is to limit the value of frenum from becoming too large.
[0225] Since packet forwarding nodes (such as routers and switches) do not have the ability to perform complex calculations (such as division), the detection devices deployed on packet forwarding nodes are equipped with a matching table. The matching table is used to indicate the freshness factor corresponding to different combinations of traffic size range and packet interval range.
[0226] For example, in the matching table, an item indicating a flow rate between a and b, and a packet interval between t1 and t2, corresponds to a freshness factor of A. It should be understood that the contents of the matching table are pre-calculated using a device with complex computational capabilities and configured in the detection device. It can be seen that the matching table is determined in this embodiment based on an approximate generation method using optimal piecewise constants.
[0227] In this way, the detection device determines the first freshness factor based on the size and packet interval of the first data packet, including: the detection device queries a matching table based on the range to which the size of the first data packet belongs and the range to which the packet interval of the first data packet belongs, to determine the freshness factor corresponding to the size and packet interval of the first data packet, and this freshness factor is the first freshness factor.
[0228] As can be seen, the data packet rate can be derived from the data packet size and packet interval. Therefore, the detection device can quickly obtain the freshness factor corresponding to the data packet rate by querying the matching table. Thus, the detection device does not need to be configured with complex computing capabilities, thereby improving the universality of the solution in this application.
[0229] Subsequently, after receiving the freshness factor, the filtering module updates the freshness of the flow information recorded in the first recording unit based on the freshness factor. Specifically, the filtering module updates the freshness of the flow information recorded in the first recording unit based on whether the flow ID of the flow information recorded in the first recording unit is the flow ID of the first message flow to which the first data packet belongs.
[0230] In one exemplary embodiment, when "the freshness of the stream information recorded in the first recording unit exceeds a freshness threshold, the detection device stops maintaining the stream information in the first recording unit; when the freshness of the stream information recorded in the first recording unit does not exceed the freshness threshold, the detection device needs to continue maintaining and updating the stream information in the first recording unit," if the filtering module determines that the stream ID of the stream information recorded in the first recording unit is different from the stream ID of the first message stream, then a freshness factor is added to the freshness of the stream information recorded in the first recording unit. If the filtering module determines that the stream ID of the stream information recorded in the first recording unit is the same as the stream ID of the first message stream, then the freshness factor is subtracted from the freshness of the stream information recorded in the first recording unit.
[0231] As can be seen, the embodiment of this application is designed to perform the step of updating the freshness of the flow information recorded by the first recording unit based on the currently received first data packet only after step 202. In step 202, it has already been determined that the rate of the currently received first data packet is greater than the rate threshold. Therefore, this application avoids modifying the freshness based on data packets of a low-rate but continuously arriving flow, and also avoids modifying the freshness based on continuously arriving packets that have caused a message flow conflict (corresponding to the following). Figure 9 In case 21), the freshness of the small stream data packets is modified, thus avoiding the influence of the low-rate stream on the filtering module's maintenance of the stream information of the recorded high-rate stream.
[0232] Subsequently, when the message forwarding node receives the second data packet from the first message stream after receiving the first data packet, the detection device, after obtaining the packet information of the second data packet in step 101, executes steps 204 to 206 as described below. It can be understood that the first data packet and the second data packet can be two consecutive data packets in the first message stream, or they can be non-consecutive data packets; this is not limited.
[0233] Step 204: Based on the flow ID in the packet information of the second data packet, the detection device determines the record unit in the temporary storage module that has a mapping relationship with the first message flow to which the second data packet belongs as the second record unit.
[0234] For a detailed explanation of step 204, please refer to the description of step 201, which will not be repeated here.
[0235] Step 205: If it is determined that the flow information obtained from the packet information of the second data packet will be used to replace the original flow information recorded in the second recording unit based on the rate and rate threshold of the second data packet, the detection device determines the recording unit in the filtering module that has a mapping relationship with the first message flow to which the second data packet belongs as the first recording unit based on the flow ID in the packet information of the second data packet.
[0236] The detailed description of the flow information obtained based on the packet information of the second data packet can be found in the description of the second flow information obtained based on the packet information of the first data packet, and will not be repeated here.
[0237] The detection device determines, based on the rate and rate threshold of the second data packet, to replace the original stream information (denoted as the fourth stream information) recorded in the second recording unit with the stream information obtained from the packet information of the second data packet. For a detailed description of the detection device's filtering module determining, based on the rate and rate threshold of the first data packet, to replace the original first stream information recorded in the first recording unit with the second stream information obtained from the packet information of the first data packet, please refer to cases a, b, and c in step 1022. This will not be repeated here.
[0238] In conjunction with step 1022, if the detection device determines that the fourth stream information originally recorded in the second recording unit of the temporary storage module is to be replaced by the stream information obtained based on the packet information of the second data packet, the second recording unit of the temporary storage module will generate the replaced stream information, namely the fourth stream information, which is called the switching information.
[0239] In this case, the filtering module of the detection device sends the obtained switching information (i.e., fourth-stream information) and the service bit with the second value to the filtering module. In response to the service bit with the second value, the filtering module performs step 206 as described below based on the received switching information.
[0240] The service bit is used to indicate the subsequent operations that the detection device needs to perform. In this embodiment, when the service bit is a second value (such as 1), it indicates that the temporary storage module of the detection device has generated switching information. At this time, the detection device needs to determine the impact information by executing step 206.
[0241] Furthermore, when determining, based on the rate and rate threshold of the second data packet, to replace the fourth stream information originally recorded in the second recording unit with the stream information obtained from the packet information of the second data packet, the filtering module of the detection device replaces the fourth stream information originally recorded in the second recording unit with the stream information obtained from the packet information of the second data packet, so as to start maintaining the stream information obtained from the packet information of the second data packet in the second recording unit.
[0242] Furthermore, if, based on the rate and rate threshold of the second data packet, it is determined that the flow information obtained from the packet information of the second data packet should replace the original flow information recorded in the second recording unit, the detection device determines, based on the flow ID in the packet information of the second data packet, the recording unit in the filtering module that has a mapping relationship with the first message flow to which the second data packet belongs as the first recording unit. For a detailed explanation, please refer to the description in step 1021 of the detection device determining, based on the flow ID in the packet information of the first data packet, the recording unit in the filtering module that has a mapping relationship with the first message flow to which the first data packet belongs as the first recording unit; it will not be repeated here.
[0243] Step 206: When the freshness of the third stream information originally recorded in the first recording unit meets the preset conditions and the flow rate of the third stream information is greater than or equal to the flow rate threshold, the detection device determines the stream ID, time information and flow rate in the third stream information as the influence information.
[0244] In step 206, when the freshness of the third-stream information originally recorded in the first recording unit meets a preset condition, the filtering module replaces the third-stream information with fourth-stream information. The stream ID of the fourth-stream information is different from the stream ID of the third-stream information. For a detailed explanation of why the filtering module replaces the third-stream information with fourth-stream information when the freshness of the third-stream information originally recorded in the first recording unit meets the preset condition, please refer to the description of the second possible implementation of case c in step 1022, which will not be repeated here.
[0245] In this case, the filtering module also sets an initial freshness value for the fourth-stream information recorded by the first recording unit after the fourth-stream information replaces the third-stream information. For example, the initial freshness value can be 90% of the freshness threshold. If the freshness threshold is 500, the initial freshness value can be set to 90% of the freshness threshold of 500, i.e., 450, but it is not limited to this.
[0246] Furthermore, the detection device can determine the impact information of the message flow identified by the replaced third-flow information, including the flow ID, time information, and flow rate.
[0247] To better understand the steps Figure 8 The method shown below will be illustrated with specific examples.
[0248] Let's take the data packet p of the first message stream as packet p, the flow ID of the first message stream as f2, the time span (ts) of packet p as 6800, the size (psize) of packet p as 1000, and the maxt calculated based on the ts, psize, and rate threshold of packet p as 7800, and the freshness threshold as 500, as an example. Figure 7 ,refer to Figure 9 , Figure 9This illustration shows a process diagram of another traffic behavior detection method provided in an embodiment of this application.
[0249] like Figure 9 As shown, after the detection module obtains the packet information of packet p (i.e., "f2, ts = 6800, psize = 1000") through step 101, the detection module sends the packet information of packet p to the temporary storage module. The temporary storage module then determines the second record unit that has a mapping relationship with the first message stream based on the flow ID in the packet information of packet p. For example, the temporary storage module performs a hash operation on f2, and the hash result indicates the second record unit.
[0250] Next, in possible case 21, the flow information already recorded in the second recording unit is the flow information of the second message flow with flow ID f1 (e.g., Figure 9 The given information ("f = f1, maxt = 7000, fsize = 3000, st = 5000, ts = 6500"), combined with... Figure 7 As shown in Case 11, the second recording unit of the temporary storage module generates the switching information "f = f1, maxt = 7000, fsize = 3000, st = 5000, ts = 6500".
[0251] In possible scenario 22, the flow information recorded in the second recording unit is the flow information of the first message flow with flow ID f2 (e.g., Figure 9 The given values "f = f2, maxt = 6500, fsize = 5000, st = 4000, ts = 5500" are combined with... Figure 7 As shown in Case 12, the second recording unit of the temporary storage module generates the switching information "f = f2, maxt = 6500, fsize = 5000, st = 4000, ts = 5500".
[0252] In possible scenario 23, the flow information recorded in the second recording unit is the flow information of the first message flow with flow ID f2 (e.g., Figure 9 The given values "f = f2, maxt = 7000, fsize = 11000, st = 4000, ts = 6000" are combined with... Figure 7 As shown in Case 13, the second recording unit of the temporary storage module generates the switching information "f = f2, maxt = 7000, fsize = 11000, st = 4000, ts = 6000".
[0253] In possible scenario 24, the flow information recorded in the second recording unit is the flow information of the first message flow with flow ID f2 (e.g., Figure 9The given values "f = f2, maxt = 7000, fsize = 11000, st = 4000, ts = 6000" are combined with... Figure 7 As shown in Case 14, the second recording unit of the temporary storage module will not generate switching information, and the stream information recorded in the second recording unit will be updated to "f = f2, maxt = 7800, fsize = 12000, st = 4000, ts = 6800".
[0254] In possible scenario 25, the flow information recorded in the second recording unit is the flow information of the first message flow with flow ID f2 (e.g., Figure 9 The given values "f = f2, maxt = 7000, fsize = 8000, st = 4000, ts = 6000" are combined with... Figure 7 As shown in Case 15, the second recording unit of the temporary storage module will not generate switching information, and the stream information recorded in the second recording unit will be updated to "f = f2, maxt = 7800, fsize = 9000, st = 4000, ts = 6800".
[0255] Subsequently, when the temporary storage module does not generate handover information, it calculates the freshness factor frenum(p) based on the size of the p packet and the packet interval. Taking frenum(p) = 100 as an example, the temporary storage module sends the packet information of the p packet, frenum(p) = 100, and the service bit with a first value (e.g., m = 0) to the filtering module. Alternatively, when the temporary storage module generates handover information, it sends the handover information, the flow ID of the p packet information, and the service bit with a second value (e.g., m = 1) to the filtering module. The filtering module determines the record unit in the filtering module that has a mapping relationship with the first message flow as the first record unit based on the flow ID of the p packet information.
[0256] Subsequently, in possible case 26, m = 0, indicating that the temporary storage module did not generate switching information. If the flow information already recorded in the first recording unit is the flow information of the second message flow with flow ID f1 (e.g.) Figure 9 The given information ("f = f1, fre = 120, maxt = 7000, fsize = 5000, st = 5000, ts = 6000") indicates that the stream ID in the p packet information is different from the stream ID of the stream information originally recorded in the first recording unit. In this case, the filtering module adds frenum(p) to the freshness of the stream information originally recorded in the first recording unit, resulting in an updated fre = 220.
[0257] In possible case 27, m = 0, indicating that the temporary storage module has not generated switching information. If the flow information already recorded in the first recording unit is the flow information of the first packet flow with flow ID f2 (e.g., Figure 9 The first part shown is the flow information of "f = f2, fre = 120", indicating that the flow ID in the p packet information is the same as the flow ID of the flow information originally recorded in the first recording unit. In this case, the filtering module subtracts frenum(p) from the freshness fre of the flow information originally recorded in the first recording unit to obtain the updated fre = 20. This makes the freshness of the flow information of the first message flow originally recorded in the first recording unit far away from the freshness threshold, so that the flow information of the first message flow originally recorded in the first recording unit can be retained in the first recording unit for a longer time. In addition, the descriptions of cases 31, 32 and 33 in this case correspond to the following respectively. Figure 7 The descriptions of Situations 12, 12, and 15 are provided, and Situation 31 is the impact information obtained after performing an "update operation based on timeout" on the first recording unit, and Situation 32 is the impact information obtained after performing an "update operation based on excessive traffic" on the first recording unit.
[0258] In possible case 28, m=1, indicating that the temporary storage module has generated switching information, such as switching information 1 "f=f1, maxt=7000, fsize=3000, st=5000, ts=6500". If the flow information already recorded in the first recording unit is the flow information of the third message flow with flow ID f3 (e.g.) Figure 9 The stream information shown ("f=f3, fre=120, maxt=7000, fsize=5000, st=5000, ts=6000") indicates that the stream ID in the p packet information is different from the stream ID originally recorded in the first recording unit. In this case, since the freshness value fre (120) of the stream information originally recorded in the first recording unit is less than the freshness threshold of 500, no operation is performed on the stream information originally recorded in the first recording unit, meaning that the filtering module will not have any impact on the information.
[0259] In possible case 29, m=1, indicating that the temporary storage module has generated switching information, such as switching information 1. If the flow information already recorded in the first recording unit is the flow information of the fourth message flow with flow ID f4 (e.g., Figure 9The flow information shown ("f=f4, fre=550, maxt=5500, fsize=4000, st=4000, ts=4000") indicates that the flow ID in the p packet information is different from the flow ID of the flow information originally recorded in the first recording unit. In this case, since the freshness value fre 550 of the flow information originally recorded in the first recording unit is greater than the freshness threshold 500, the filtering module replaces the flow information originally recorded in the first recording unit with the received switching information 1, and sets the initial freshness value of the switching information 1 recorded in the first recording unit to 450 (i.e., 90% of 500). When the traffic size in the flow information originally recorded in the first recording unit is greater than the traffic threshold, the flow ID, time information, and fsize in the flow information originally recorded in the first recording unit are determined as an influence information of the packet flow represented by the flow ID, specifically "f=f4, fsize=4000, st=4000, ent=5000". It can be seen that the impact information is obtained by performing a "stream-switching-based update operation" on the first recording unit.
[0260] Thus, through the methods described in steps 201 to 206, the detection device temporarily stores the flow information of the packet flow passing through the packet forwarding node for as long as possible through the temporary storage module, and filters the impact information of the flow that meets the impact behavior through the filtering module. By obtaining the impact information, this embodiment of the application can accurately locate the impact behavior of the packet flow, thereby providing accurate information for the SLO violation attribution of network performance, and thus improving the accuracy of SLO violation attribution.
[0261] Furthermore, as can be seen from the methods described in steps 201 to 206, after the detection device obtains the packet information of the data packets flowing through the packet forwarding node, the relevant data undergoes pipelined processing sequentially through the temporary storage module and the filtering module, making the data processing process conform to the single-level memory access mechanism of the packet forwarding node (such as a hardware programmable switch). The single-level memory access mechanism means that the algorithm can only access each memory region once when a data packet passes through the switch.
[0262] In addition, since the temporary storage module and the filtering module in the method described in this application embodiment perform pipelined processing of relevant data, and the update of data in the temporary storage module is entirely determined by its own judgment, the filtering module does not need to pull data from the temporary storage module again or send a clear command to the temporary storage module after filtering the large flow. This can effectively eliminate the retransmission of data packets generated in the scheme of using the temporary storage mechanism in related technologies, thereby reducing the processing overhead of the message forwarding node.
[0263] In other embodiments, to reduce the overhead required for the detection device to report impact information to the control device, the embodiments of this application may compress and aggregate the impact information obtained by the detection device when storing it, so as to reduce the size of the stored impact information, thereby reducing the overhead required for the detection device to report impact information to the control device.
[0264] Since the main overhead component of the impact information is the flow ID, which is composed of 5-tuples, the embodiments of this application can achieve compressed storage of the impact information of the same message flow by reusing the flow ID when storing the impact information of the same message flow.
[0265] Furthermore, when multiple impact information are continuously identified and these multiple impact information belong to the same message flow, if the rates indicated by these multiple impact information are within the same rate range, the detection device can perform an aggregation operation on these multiple impact information. The aggregation operation includes aggregating the flow magnitude in these multiple impact information and aggregating the time information.
[0266] For example, when a packet flow includes multiple impact information messages, for the first and second impact information messages belonging to the same packet flow, which are determined sequentially by the packet forwarding nodes, the detection device can control the second impact information to reuse the flow ID from the first impact information for storage. When the rates indicated by the first and second impact information messages are within the same rate range, the detection device performs an aggregation operation on the first and second impact information messages to aggregate them into a single impact information message for storage. The aggregation operation includes aggregating the traffic magnitude and time information from the first and second impact information messages.
[0267] In an exemplary embodiment, the operation of compressing / aggregating and storing the acquired impact information by the detection device is implemented by the storage module.
[0268] Taking registers as storage space to store impact information as an example, refer to... Figure 10 , Figure 10 A schematic diagram of a storage module provided in an embodiment of this application is shown. Figure 10 As shown, the storage module includes k record units, compressed / aggregated storage units, and ordinary storage units.
[0269] Each of the k recording units records the rate interval (denoted as vlast), pointer, and offset of the impact information previously stored through that unit. Here, the rate interval of the impact information is determined based on the update operation of the impact information obtained by the filtering module. This rate interval is used to determine the storage operation performed on the impact information (such as aggregate storage, compressed storage, or normal storage operation), and to update the pointer and / or offset according to the specific storage operation. For example, when the filtering module obtains that the update operation of the impact information is a "stream switching-based update operation," the filtering module determines the rate interval of the impact information as the first interval. When the filtering module obtains that the update operation of the impact information is a "timeout-based update operation," the filtering module determines the rate interval of the impact information as the rate interval to which the rate calculated based on st, ent, and the traffic size in the impact information belongs.
[0270] In this embodiment, multiple rate intervals can be pre-divided based on rate thresholds. For example, taking the case where the highest rate in a rate interval is twice the lowest rate as an example of dividing the rate interval, the following can be defined: 1 times the rate threshold to 2 times the rate threshold is the third interval, 2 times the rate threshold to 4 times the rate threshold is the fourth interval, 4 times the rate threshold to 8 times the rate threshold is the fifth interval, 8 times the rate threshold to 16 times the rate threshold is the sixth interval, 16 times the rate threshold to 32 times the rate threshold is the seventh interval, and 32 times the rate threshold to ∞ is the eighth interval. The aforementioned divided rate intervals can also be expressed as the following formula (2).
[0271] Formula (2)v={[vth,2vth):3,[2vth,4vth):4,[4vth,8vth):5,[8vth,16vth):6,[16vth,32vth):7,[32vth,∞]:8}
[0272] Thus, based on the rate range representation of the current impact information, the operation type and vlast of the current impact information are obtained, and the storage module can decide on the storage method for that impact information. Refer to Table 1, which shows the storage operations performed under different conditions.
[0273] As shown in Table 1, if the impact information of flow 1 obtained by the filtering module is obtained by "update operation based on flow switching", then if the third record unit is the record unit that has a mapping relationship with flow 1 among the k record units, and if the vlast recorded in the third record unit indicates the first interval, it means that the previous impact information stored through the third record unit is also the impact information obtained by "update operation based on flow switching". In this case, the previous impact information and the currently obtained impact information do not belong to the same message flow, and the currently obtained impact information and the next impact information will not belong to the same message flow. Therefore, the storage module can perform normal storage operation on the currently obtained impact information.
[0274] If the impact information of flow 1 obtained by the filtering module is obtained by "update operation based on flow switching", and the vlast recorded in the third recording unit indicates the second to eighth intervals, it means that the previous impact information stored through the third recording unit was obtained by "update operation based on timeout" or "update operation based on excessive traffic". At this time, it means that although the impact information obtained now and the previous impact information do not belong to the same impact behavior, they belong to the same message flow (i.e., the flow ID is the same). Therefore, the storage module performs a compression storage operation on the impact information obtained now.
[0275] If the impact information of flow 1 obtained by the filtering module is obtained by "update operation based on timeout", and the vlast recorded in the third recording unit indicates the first to eighth intervals, it means that the previous impact information stored through the third recording unit was obtained by "update operation based on flow switching", "update operation based on timeout" or "update operation based on excessive traffic". In this case, it means that the impact information obtained now and the previous impact information may not belong to the same impact behavior and do not belong to the same message flow (i.e., the same flow ID). However, the impact information obtained now and the next impact information belong to the same message flow. Therefore, the storage module performs a compressed storage operation on the impact information obtained now.
[0276] If the impact information of flow 1 currently obtained by the filtering module is obtained through an "update operation based on excessive traffic," and the vlast recorded in the third recording unit indicates the first to eighth intervals, then the previous impact information stored through the third recording unit was obtained through an "update operation based on flow switching," a "timeout-based update operation," or an "update operation based on excessive traffic." In this case, the currently obtained impact information and the previous impact information may not belong to the same impact action, but they belong to the same message flow (i.e., the flow ID is the same). Therefore, the storage module performs a compressed storage operation on the currently obtained impact information. In this situation, if the rate interval of the currently obtained impact information is equal to vlast, it indicates that the currently obtained impact information and the previous impact information stored through the third recording unit belong to two consecutive segments within the same impact action. Therefore, the storage module performs an aggregation operation on the currently obtained impact information and the previous impact information.
[0277] Table 1
[0278]
[0279] In addition, the pointer in each of the k record units in the storage module is responsible for providing the location of the impact information in the compressed / aggregated storage unit or the ordinary storage unit. The specific value is allocated by either the first pointer allocator or the second pointer allocator. The first pointer allocator is used to allocate the storage location of the impact information in the compressed / aggregated storage unit, while the second pointer allocator is used to allocate the storage location of the impact information in the ordinary storage unit.
[0280] Offset refers to the amount of information that is offset within a compressed / aggregated storage unit. Offset is effective for compressed / aggregated storage units, but not for ordinary storage units.
[0281] The compressed / aggregated storage unit includes FID storage unit units and information storage units.
[0282] The FID storage unit comprises N storage spaces, each storing a stream ID, which is the stream ID of the influencing information. The information storage unit comprises M storage sub-units, each containing CL storage spaces. Each storage space stores data content from a descriptive message, excluding the stream ID. This data content includes the start transmission time (st), end time (ent), and size (fsize) of the traffic segment described by the influencing information. It can be seen that the information storage unit comprises M×CL storage spaces. N, M, and CL are all positive integers, and their specific values are not limited in this embodiment. For the compressed / aggregated storage unit, the offset refers to the offset of the influencing information within a storage sub-unit of the information storage unit, and the offset ranges from 0 to (CL-1). The position of the influencing information in the compressed / aggregated storage unit can then be obtained by pointer×CL+offset.
[0283] It can be seen that one storage space in the FID storage unit corresponds to at least one storage sub-unit in the information storage unit. In this way, for multiple impact messages with the same flow ID, their flow IDs can be stored in one storage space in the FID storage unit (such as the first storage space), and the data content of each impact message other than the flow ID can be stored in the storage space of the storage sub-unit corresponding to the first storage space.
[0284] Ordinary storage units are used to store impact information that does not require compression / aggregation.
[0285] The following is combined Figure 10 And introduce with specific examples Figure 10 The storage module shown in the diagram stores the process of influencing information.
[0286] Taking the first impact information obtained by the filtering module as an example, the filtering module determines the rate range of the impact information based on the update operation of the first impact information, denoted as v1, and sends the first impact information and v1 into the storage module.
[0287] The storage module determines, based on the flow ID in the first impact information, the third record unit that has a mapping relationship with the message flow identified by the flow ID in the k record units of the storage module (e.g., based on a hash operation of the flow ID), and determines the storage operation according to v1 and vlast recorded in the third record unit.
[0288] In case 1, when the storage module determines that v1 and vlast in the third recording unit are the same, i.e. v1 = vlast, it means that the previous impact information (denoted as the second impact information) and the first impact information stored through the third recording unit are obtained based on the same update operation.
[0289] In this scenario, if the first impact information is obtained by the filtering module through a "stream-switching-based update operation," i.e., v1 = vlast = the first interval, then the second impact information corresponding to vlast in the third recording unit is obtained from the replaced stream information in the filtering module's recording unit based on a "stream-switching-based update operation." Conversely, the first impact information for v1 is obtained from the replaced stream information in the filtering module's recording unit based on another "stream-switching-based update operation." Therefore, the stream IDs of the second impact information corresponding to vlast and the first impact information are different. Furthermore, the stream ID of the next impact information obtained by the filtering module after the first impact information is also different from the stream ID of the first impact information. Consequently, the first impact information cannot reuse the stream ID of the previous impact information for storage, and the next impact information cannot reuse the stream ID of the first impact information for storage. Therefore, the storage module determines to store the first impact information in a normal storage unit, i.e., performs a normal storage operation.
[0290] For example, the storage module instructs the second pointer allocator to increment the pointer by 1, and based on the pointer value after the increment, stores the first influence information in the storage space indicated by the pointer value in the ordinary storage unit. Furthermore, the storage module reassigns the value of v1 to vlast in the third record unit, and records the pointer value after the second pointer allocator increments by 1 in the third record unit.
[0291] In case 2, when the storage module determines that v1 and vlast in the third record unit are the same, i.e. v1 = vlast, and the first impact information is the impact information obtained by the filtering module "based on the update operation of excessive traffic", i.e. v1 = vlast = [third interval, eighth interval].
[0292] At this point, as described in Table 1, the first impact information and the second impact information belong to the same impact behavior and have the same flow ID, such as flow ID 1. Therefore, the storage module determines to store the first impact information in the compression / aggregation storage unit and performs the aggregation storage operation.
[0293] For example, the storage module addresses the storage sub-unit 1 with ID 1 based on the pointer value in the third recording unit, and addresses the storage space corresponding to the offset value in the storage sub-unit 1 based on the offset value in the third recording unit. Then, the storage module updates the ent recorded in the storage space with the ent of the first influence information, and adds the fsize of the first influence information to the fsize recorded in the storage space.
[0294] In case 3, the storage module determines that v1 and vlast in the third record unit are different, i.e., v1 ≠ vlast.
[0295] At this point, if the first impact information is the impact information obtained by the filtering module's "update operation based on flow switching," as shown in Table 1, the first impact information and the second impact information belong to different impact behaviors of the same message flow, that is, the flow IDs of the first impact information and the second impact information are the same, such as both being ID 1. Therefore, the storage module determines to store the first impact information in the compression / aggregation storage unit and performs a compression storage operation.
[0296] For example, the storage module addresses the storage sub-unit 1 with ID 1 based on the pointer value in the third record unit, increments the offset value in the third record unit by 1, and then addresses the storage space corresponding to the value after the offset is incremented by 1 in the storage sub-unit 1, so that the storage module stores the data content of the first influence information other than the stream ID in the storage space.
[0297] In case 4, the storage module determines that v1 and vlast in the third record unit are different, i.e., v1 ≠ vlast.
[0298] At this point, if the second impact information is the impact information obtained by the filtering module's "update operation based on stream switching," as shown in Table 1, the first impact information and the second impact information do not belong to the same message stream, that is, the flow IDs of the first impact information and the second impact information are different. However, the first impact information and the next impact information stored through the third recording unit (denoted as the third impact information) may belong to the same message stream, such as the message stream with flow ID 2. Therefore, the storage module determines to store the first impact information in the compression / aggregation storage unit and performs a compression storage operation.
[0299] For example, the storage module increments the pointer value by 1 and records it in the third recording unit through the first pointer allocator, and resets the offset value in the third recording unit to zero. Thus, the storage module addresses a storage space in the FID storage unit, such as storage space 1, and addresses the storage sub-unit 2 corresponding to the storage space based on the pointer value after incrementing by 1. The storage module records the stream ID 2 in storage space 1 and records the data content other than the stream ID in the first influence information in the first storage space of storage sub-unit 2.
[0300] As can be seen, Case 1 is a normal storage operation, Case 2 is an aggregated storage operation, and Cases 3 and 4 are compressed storage operations. In Cases 3 and 4, when the offset value in the third record's eye is incremented by 1 and equals CL, it means that all the storage space of the currently allocated storage sub-unit has been used up. At this time, the first pointer allocator will increment the pointer value by 1 to point to the new storage sub-unit, and the offset value needs to be returned to zero.
[0301] Optionally, in this embodiment of the application, each storage space of the compressed / aggregated storage unit is provided with a behavior description field (denoted as the extra field), the extra field including a first subfield and a second subfield.
[0302] The first subfield indicates whether the impact information recorded in the current storage space is the last impact information of an influencing behavior. For example, if the first subfield is the third value (such as 0), it means that the impact information recorded in the current storage space is not the last impact information of an influencing behavior. As another example, if the first subfield is the fourth value (such as 1), it means that the impact information recorded in the current storage space is the last impact information of an influencing behavior.
[0303] The second subfield represents the rate fluctuation range of the impact information (which can be aggregated impact information) recorded in the current storage space. In one example, this rate fluctuation range can be calculated using the following formula (3).
[0304]
[0305] Where R is an integer mapping, v is the rate interval of the last impact information recorded in the storage space, vlast is the rate interval of the previous impact information of the last impact information, and the interval length is the length of the rate interval to which v and vlast belong.
[0306] For example, refer to Figure 11 , Figure 11This diagram illustrates an aggregated impact information and extra field provided in an embodiment of this application. The impact behavior of a message flow occurring between t1 and t5 is divided into four segments based on segmentation thresholds, with average rates of 2vth, 2vth, 6vth, and 8vth for each segment. Thus, the detection device based on the method described in this embodiment can obtain the four impact information pieces shown in Table 2.
[0307] Table 2
[0308] Impact Information 1 f1, fsize1, t1, t2 Impact Information 2 f1, fsize2, t2, t3 Impact Information 3 f1, fsize3, t3, t4 Impact Information 4 f1, fsize4, t4, t5
[0309] When the rate interval is divided as
[0310] v = {[vth,2vth):3,[2vth,4vth):4,[4vth,8vth):5,[8vth,16vth):6,[16vth,32vth):7,[32vth,∞):8}. Since 2vth belongs to the rate interval "4", and 6vth and 8vth belong to the rate interval "5", the method provided in this application embodiment can aggregate influence information 1 and influence information 2 into one influence information, and influence information 3 and influence information 4 into one influence information, as shown in Table 3.
[0311] Table 3
[0312]
[0313] Taking an 8-bit extra field as an example, with the first subfield of the extra field being 1 bit and the second subfield being 7 bits, for the first row of data in Table 3, since the influencing behavior has not yet ended, the first bit of the extra field is 0. Because the two influencing information aggregated in the first row of Table 3 have the same rate, i.e., the rate fluctuation amplitude is 0, the last 7 bits of the extra field are also 0, thus the value of the extra field in the first row of Table 3 is 0.
[0314] For the second row of data in Table 3, since the influence behavior has ended, the first bit of the extra field is 1. Because the two influence messages aggregated in the first row of Table 3 have different rates, 6vht and 8vth respectively, the value of the last 7 bits of the extra field can be calculated using the formula (3) above: extra... Where R = {[0,0.1):1,[0.1,0.2):2,[0.2,0.3):3,…,[0.9,1):10}. Therefore, the extra field is: 10000101, which is 133.
[0315] Furthermore, when this application embodiment records the omitted information mentioned above during the process of determining the impact information, it combines... Figure 10 ,refer to Figure 12 , Figure 12 This illustration shows a schematic diagram of the relationship between a compression / aggregation storage unit and a missing information storage unit provided in an embodiment of this application.
[0316] like Figure 12 As shown, in each storage space of the information storage unit of the compression / aggregation storage unit, missing information belonging to the same message stream as the impact information can also be recorded. Typically, in the storage space of the information storage unit used to store the last impact information of an impact behavior of a message stream, when the first subfield (e.g., the first bit) of the extra field recorded in this storage space is the fourth value, it indicates that the impact information recorded in this storage space is the last impact information of an impact behavior of the message stream. Subsequently, before detecting the impact information of the next impact behavior of the message stream, the detection device can record the detected missing information of the message stream (including flow size (denoted as size_min) and flow rate (denoted as size_vth)) in this storage space and continuously update it until the impact information of the next impact behavior of the message stream is detected.
[0317] The method for compressing / aggregating impact information provided in this application embodiment can compress the impact information, thereby reducing overhead when message forwarding nodes with detection devices report impact information to the control device. Experiments show that by using the method described in this application embodiment to store impact information, the reporting overhead of message forwarding nodes is reduced by approximately 50% compared to not using this method.
[0318] In other embodiments, reference is made to Figure 13 , Figure 13 This illustration shows another flowchart of the traffic behavior detection method provided in an embodiment of this application. Optionally, this method can be applied to... Figure 3 The implementation environment shown, and by Figure 3 The control device and deployment shown have Figure 3 The message forwarding node of the detection device shown executes the corresponding steps to deploy the [device / device]. Figure 3 The message forwarding node of the detection device shown includes Figure 13 Taking the mutually communicating message forwarding nodes 131, 132, and 133 as an example, as shown... Figure 13 As shown, the method includes the following steps 301 to 305.
[0319] Step 301: The message forwarding node acquires and stores the impact information of the message flow passing through the message forwarding node.
[0320] Here, a detailed description of step 301 can be found in the above description of the detection device acquiring and storing impact information, and a detailed explanation of the message forwarding node storing impact information can be found in the above text. Figure 10 The relevant descriptions will not be repeated here.
[0321] Step 302: The message forwarding node reports the acquired impact information to the control device.
[0322] Optionally, the message forwarding node may report the impact information to the control device when the number of impact information exceeds a first quantity threshold. This application embodiment does not specifically limit the value of the first quantity threshold.
[0323] Optionally, the message forwarding node may periodically report impact information to the control device. Here, the embodiments of this application do not specifically limit the duration of the period.
[0324] In one exemplary implementation, when a message forwarding node reports impact information to a control device, the message forwarding node first sends a reporting request data packet to the control device. This request data packet includes the identifier of the message forwarding node, the data reporting time, the storage module identifier, the amount of impact information stored in the compressed / aggregated storage unit, and the amount of impact information stored in the ordinary storage unit. The storage module identifier is used by the control device to obtain the identifiers of the relevant storage units (including compressed / aggregated storage units, ordinary storage units, etc.) used to store the impact information.
[0325] Step 303: The control device receives the impact information and stores the impact information.
[0326] In one exemplary implementation, the control device opens the receiving port for communication with the message forwarding node and receives the reporting request data packet sent by the message forwarding node. Based on the reporting request data packet, it uses an interface (such as the p4 interface) to read the impact information stored in the relevant storage unit and restores the corresponding format of the FID storage unit and the compressed / aggregated storage unit according to the CL value, so as to restore the impact information stored by the FID storage unit and the compressed / aggregated storage unit. That is, the control device obtains the impact information reported by the message forwarding node.
[0327] In one example, the control device can name the impact information received from the message forwarding node based on the node identifier of the message forwarding node that reported the impact information, the time when the impact information was received, and the port on which the impact information was received, and store the received impact information in the form of a log. For example, for a message forwarding node identified as s3, the control device will name the impact information sent by the message forwarding node through port p1, port p2, and port p3 at time t into log files named s3_p1_t.log, s3_p2_t.log, and s3_p3_t.log respectively, and store them therein.
[0328] In this way, when the control device receives a query request from the user equipment regarding network performance anomalies, it can retrieve relevant impact information based on the file name and return the retrieved impact information to the user equipment.
[0329] In one example, the detection devices are deployed across all message forwarding nodes in the communication network.
[0330] In this scenario, the control device can obtain impact information reported by each packet forwarding node in the network. When the control device receives a query request from the user equipment (UE) containing the time period of the network performance anomaly (e.g., congestion), the identifier of the packet forwarding node, and the sending port number of the packet forwarding node, the control device can retrieve logs containing relevant impact information based on the information in the query request and the filename. The control device then returns all the impact information recorded in that log to the UE, or returns the impact information recorded in the log with the highest traffic volume (ranked by q), so that the UE can analyze the cause of the network performance anomaly, i.e., attribution of SLO violations. Here, q is a positive integer.
[0331] In another example, if the control device has a pre-defined topology of the communication network and all forwarding paths through which the message stream is transmitted, then the detection device can be deployed in at least one message forwarding node in each forwarding path.
[0332] In this scenario, the control device can obtain the impact information reported by each packet forwarding node in the network where the detection device is deployed. Furthermore, when the control device receives a query request from the user equipment (UE) containing the flow ID and time period of a packet flow experiencing network performance anomalies (such as congestion) (e.g., the fifth packet flow), the control device can determine the forwarding path used to forward the fifth packet flow from all preset forwarding paths based on the flow ID of the fifth packet flow. It can then identify the first packet forwarding node deployed with the detection device in that forwarding path, and / or determine the forwarding paths of all packet flows passing through the first packet forwarding node, as well as some or all of the packet forwarding nodes deployed with the detection device on these forwarding paths, denoted as the set of second forwarding nodes. Subsequently, the control device returns the set of second forwarding nodes and all impact information reported by the first packet forwarding node within the time period indicated in the query request to the UE, or returns the impact information of the top q in terms of traffic volume from these impact information entries, so that the UE can analyze the cause of the network performance anomaly, i.e., SLO violation attribution.
[0333] Understandably, taking the first forwarding path in a communication network as an example, if detection devices are deployed in multiple forwarding nodes along the first forwarding path, to avoid resource waste caused by multiple forwarding nodes repeatedly counting and detecting the impact of the first packet stream, refer to... Figure 14 If the first packet forwarding node with a detection device deployed on the side of the first forwarding path closest to the source of the first packet flow is the first node, then when the first node uses the method provided in this application embodiment to detect the traffic behavior of the first packet flow, the first node will forward the data packets of the first packet flow (such as...) Figure 14 When forwarding a regular data packet, service bits (such as the service bits in the Internet Protocol (IP) header, or the redundancy bits in the Explicit Congestion Notification (ECN) field) can be added or modified. This allows data packets with added / modified service bits to reach downstream nodes where detection devices are deployed (e.g., ...). Figure 14 After the second node, there is no need for the second node to use the method provided in this application embodiment to detect traffic behavior for data packets that add / modify service bits; it can simply forward the data packet normally.
[0334] In this context, a downstream node with a detection device refers to a node whose first forwarding path is located after the first node in the transmission direction of the first message stream and which has deployed the detection device provided in this application embodiment. Furthermore, for ordinary message forwarding nodes that receive data packets with added / modified service bits, the forwarding node can simply forward the data packets normally.
[0335] Step 304: The control device adjusts the parameters used to detect flow behavior, including at least one of a rate threshold, a flow threshold, or a segment threshold.
[0336] In one possible scenario, when the control device determines that the time interval between receiving impact information reported by the message forwarding node is less than a duration threshold, or when the control device determines that the number of impact information reported by the message forwarding node within a preset duration exceeds a second quantity threshold, the control device can determine that the message forwarding node has reported too much impact information, thereby consuming too much overhead. Therefore, the control device can adjust the parameter values used to detect traffic behavior, such as increasing the rate threshold, increasing the traffic threshold, and / or increasing the segmentation threshold.
[0337] Thus, when packet forwarding nodes use the increased parameters to detect traffic behavior, the number of impact information identified will decrease, thereby reducing the overhead required for packet forwarding nodes to report impact information. This application embodiment does not limit the specific values of the duration threshold and the second quantity threshold.
[0338] In another possible scenario, when the control device determines that the time interval between receiving impact information reported by the message forwarding node is greater than a duration threshold, or when the control device determines that the number of impact information reported by the message forwarding node within a preset duration is less than a third quantity threshold, the control device can determine that the impact information reported by the message forwarding node is too little, resulting in insufficient detection accuracy of traffic impact behavior. Therefore, the control device can adjust the parameter values used for detecting traffic behavior, such as reducing the rate threshold, reducing the traffic threshold, and / or reducing the segmentation threshold.
[0339] Thus, when message forwarding nodes use the reduced parameters to detect traffic behavior, the number of impact information identified will increase, thereby improving the detection accuracy of traffic impact behavior. This application embodiment does not limit the specific values of the duration threshold and the third quantity threshold.
[0340] In another possible scenario, the control device can adjust parameters based on the omissions reported simultaneously with the impact information reported by the message forwarding nodes. For example, if there is too much omission information (such as traffic volume exceeding a certain amount, or the proportion relative to the impact information exceeding a proportional threshold), it indicates that the amount of impact information is low. Therefore, the number of detected impact information can be increased by decreasing the parameter value, thereby improving detection accuracy. Conversely, if there is too little omission information (such as traffic volume below a certain amount, or the proportion relative to the impact information below a proportional threshold), it indicates that the amount of impact information is high. Therefore, the parameter value can be increased to reduce reporting overhead, thereby reducing the number of detected impact information and thus reducing the overhead required for reporting impact information.
[0341] Understandably, when a message forwarding node reports missing information to the control device, it does not need to report the already counted missing information every time it reports impact information. To save reporting overhead, the message forwarding node can report the counted missing information at the same time as reporting impact information to the control device when the traffic volume recorded in the already counted missing information exceeds a threshold.
[0342] Optionally, the parameters adjusted by the control device may also include the number of storage spaces included in each storage sub-unit in the information storage unit of the storage module, i.e., the value of CL, in order to maximize the use of the storage space included in each storage sub-unit and avoid insufficient or idle storage space included in the storage sub-unit.
[0343] In one example, the control unit can configure an appropriate CL value by detecting the utilization rate of the storage space included in each storage sub-unit in the message forwarding node. In another example, the control unit can also receive a CL value input by the user.
[0344] Step 305: The control device sends the adjusted rate threshold, traffic threshold and / or segmentation threshold to the message forwarding node.
[0345] In response, the message forwarding node receives the adjusted rate threshold, flow threshold and / or segmentation threshold issued by the control device, and uses the adjusted rate threshold, flow threshold and / or segmentation threshold to perform step 201 to detect the impact behavior of the message flow flowing through it.
[0346] Optionally, the message forwarding node receives the CL value issued by the control device, and then stores the acquired impact information based on the CL value issued by the control device.
[0347] By using the methods described in steps 301 to 305, the embodiments of this application not only achieve the goal of rate-based fine-grained division of flow behavior boundaries, but also effectively reduce the overhead of packet forwarding nodes reporting the impact information they detect to the control device to describe the impact behavior.
[0348] Furthermore, the impact behaviors defined in the technical solutions provided in this application can also be used for the detection of high-frequency / high-speed events in other fields, including but not limited to traffic detection within a computer, distributed denial-of-service (DDoS) attack detection, and detection of frequently clicked items on websites. Taking traffic detection within a computer as an example, the temporary storage module and filtering module described in this application can be deployed in the L2 cache of the central processing unit (CPU) and the traffic information can be directly calculated and processed by the CPU, which will not be elaborated further.
[0349] The above mainly describes the solution provided by the embodiments of this application from a methodological perspective.
[0350] To achieve the above functions, refer to Figure 15 , Figure 15 A schematic diagram of a traffic behavior detection device according to an embodiment of this application is shown. The traffic behavior detection device 1500 is applied to a packet forwarding node and is used to execute the traffic behavior detection method described above, for example, to execute... Figure 5 , Figure 6 or Figure 8 The method shown, or used to perform Figure 13 The portion of the method shown is executed by the message forwarding node. The traffic behavior detection device 1500 may include an acquisition unit 1501 and a determination unit 1502.
[0351] The acquisition unit 1501 is used to acquire packet information of data packets flowing through the packet forwarding node. The packet information includes the flow ID of the packet flow to which the data packet belongs, the size of the data packet, and the timestamp of the data packet. The determination unit 1502 is used to determine the impact information of the packet flow based on the packet information, the rate threshold, and the traffic threshold. Here, one piece of impact information of the packet flow describes the behavior of a traffic segment in the packet flow. The behavior of the traffic segment is represented by the amount of traffic transmitted within the time period indicated by the impact information. The rate of traffic in the traffic segment is greater than or equal to the rate threshold, and the size of traffic in the traffic segment is greater than or equal to the traffic threshold.
[0352] As an example, combined Figure 5 The acquisition unit 1501 can be used to execute step 101, and the determination unit 1502 can be used to execute step 102.
[0353] Optionally, the message forwarding node includes a filtering module, which includes k recording units. Each recording unit records the flow information of the message flow passing through the message forwarding node. For the first recording unit among the k recording units, the first flow information recorded based on any message flow passing through the message forwarding node includes the flow ID, flow start time, timestamp of the last received data packet, traffic size, and the latest reception time of the next data packet estimated based on the rate threshold. For the first data packet received by the message forwarding node, where the first data packet is a data packet of the first message flow passing through the message forwarding node, the determining unit 1502 is specifically used to: determine the recording unit in the filtering module that has a mapping relationship with the first message flow to which the first data packet belongs as the first recording unit based on the flow ID in the packet information of the first data packet; when it is determined that the second flow information is used to replace the first flow information recorded in the first recording unit based on the rate and rate threshold of the first data packet, if the traffic size in the first flow information is greater than or equal to the traffic threshold, then the flow ID, time information, and traffic size in the first flow information are determined as impact information. The second flow information is the flow information obtained based on the packet information of the first data packet.
[0354] As an example, combined Figure 6 The determination unit 1502 can be used to execute steps 1021 to 1022.
[0355] Optionally, the determining unit 1502 is further configured to, before determining the flow ID, time information, and traffic size in the first flow information as influencing information, determine to replace the first flow information with second flow information when: the flow ID in the packet information of the first data packet is the same as the flow ID in the first flow information, and the rate of the first data packet is less than a rate threshold; or, the flow ID in the packet information of the first data packet is the same as the flow ID in the first flow information, the rate of the first data packet is greater than or equal to the rate threshold, and the traffic size in the first flow information is greater than or equal to a segmentation threshold. Wherein, when the timestamp of the first data packet is greater than the latest reception time, the rate of the first data packet is less than the rate threshold; when the timestamp of the first data packet is less than or equal to the latest reception time, the rate of the first data packet is greater than or equal to the rate threshold. The segmentation threshold is greater than the traffic threshold.
[0356] Optionally, the flow behavior detection device 1500 further includes a replacement unit 1503, used to replace the first flow information in the first recording unit with the second flow information.
[0357] Optionally, the message forwarding node further includes a temporary storage module, which includes k recording units. Each recording unit is used to record the flow information of the message flow passing through the message forwarding node. For the flow information recorded by the second recording unit in the temporary storage module, the flow information recorded by the second recording unit includes the flow ID, flow start time, timestamp of the last received data packet, flow size, and the latest reception time of the next data packet estimated based on a rate threshold. The flow information recorded by the second recording unit is the flow information recorded based on any message flow passing through the message forwarding node. The determining unit 1502 is further configured to, before determining the recording unit in the filtering module that has a mapping relationship with the first message flow to which the first data packet belongs, as the first recording unit based on the flow ID in the packet information of the first data packet, determine the recording unit in the temporary storage module that has a mapping relationship with the first message flow to which the first data packet belongs, as the second recording unit based on the flow ID in the packet information of the first data packet; and to determine, based on the rate of the first data packet and a rate threshold, the data used to update the flow information recorded in the second recording unit using the packet information of the first data packet.
[0358] As an example, combined Figure 8 The determination unit 1502 can be used to execute steps 201 to 202.
[0359] Optionally, the traffic behavior detection device 1500 further includes an update unit 1504. When, based on the rate and rate threshold of the first data packet, it is determined that the data of the flow information recorded in the second recording unit is updated using the packet information of the first data packet, the update unit 1504 is used to determine, based on the flow ID in the packet information of the first data packet, the recording unit in the filtering module that has a mapping relationship with the first message flow to which the first data packet belongs is the first recording unit, and then updates the freshness of the flow information recorded in the first recording unit based on the first freshness factor determined according to the first data packet. Here, freshness is used to indicate whether to continue maintaining the currently recorded flow information in the first recording unit; maintenance includes updating the data of the currently recorded flow information in the first recording unit based on received data packets. The first freshness factor is used to indicate the degree of influence of the first data packet on the freshness of the flow information recorded in the first recording unit.
[0360] As an example, combined Figure 8 The update unit 1504 can be used to perform step 203.
[0361] Optionally, the message forwarding node is configured with a matching table, which indicates the freshness factor corresponding to different combinations of traffic size range and packet interval range. The traffic behavior detection device 1500 further includes a query unit 1505, which queries the matching table based on the range of the size of the first data packet and the range of the packet interval of the first data packet before updating the freshness of the flow information recorded by the first recording unit, in order to determine the first freshness factor.
[0362] Optionally, the determining unit 1502 is further configured to: determine to update the data of the flow information recorded in the second recording unit using the packet information of the first data packet when the flow ID in the packet information of the first data packet is the same as the flow ID in the flow information recorded by the second recording unit, and the rate of the first data packet is greater than or equal to a rate threshold; or when the flow ID in the packet information of the first data packet is the same as the flow ID in the flow information recorded by the second recording unit, the rate of the first data packet is greater than or equal to a rate threshold, and the traffic size in the first flow information is less than a segmentation threshold. Wherein, when the timestamp of the first data packet is less than or equal to the latest reception time in the flow information recorded by the second recording unit, the rate of the first data packet is greater than or equal to the rate threshold. The segmentation threshold is greater than the traffic threshold.
[0363] Optionally, for the second data packet in the first message stream received by the message forwarding node after receiving the first data packet, the determining unit 1502 is further specifically used to: determine the recording unit in the temporary storage module that has a mapping relationship with the first message stream to which the second data packet belongs as the second recording unit based on the flow ID in the packet information of the second data packet; when it is determined based on the rate and rate threshold of the second data packet that the flow information obtained based on the packet information of the second data packet is used to replace the original flow information recorded in the second recording unit, determine the recording unit in the filtering module that has a mapping relationship with the first message stream to which the second data packet belongs as the first recording unit based on the flow ID in the packet information of the second data packet; when the freshness of the third flow information originally recorded in the first recording unit meets the preset conditions and the traffic size of the third flow information is greater than or equal to the traffic threshold, determine the flow ID, time information and traffic size in the third flow information as the influencing information.
[0364] As an example, combined Figure 8 The determination unit 1502 can be used to execute steps 204 to 206.
[0365] Optionally, the replacement unit 1503 is further configured to replace the originally recorded fourth flow information in the second recording unit with the flow information obtained from the packet information of the second data packet when determining, based on the rate and rate threshold of the second data packet, to replace the originally recorded flow information in the second recording unit with the flow information obtained from the packet information of the second data packet. The traffic behavior detection device 1500 further includes: a sending unit 1506, configured to send the fourth flow information to the filtering module. The replacement unit 1503 is further configured to replace the third flow information with the fourth flow information when the freshness of the originally recorded third flow information in the first recording unit meets a preset condition, wherein the flow ID of the fourth flow information is different from the flow ID of the third flow information.
[0366] Optionally, a message flow includes multiple impact information. For the first impact information and the second impact information belonging to the same message flow, which are determined sequentially by the message forwarding node, the traffic behavior detection device 1500 further includes: a storage unit 1507, used to control the second impact information to reuse the flow ID in the first impact information for storage.
[0367] Optionally, the storage unit 1507 is further configured to perform an aggregation operation on the first and second impact information when the rates indicated by the first impact information and the second impact information are within the same rate range, so as to aggregate the first and second impact information into a single impact information for storage. The aggregation operation includes aggregating the traffic magnitude and time information in the first and second impact information.
[0368] Optionally, the determining unit 1502 is further configured to, when the flow size recorded in the first flow information is less than a flow threshold, determine the flow size included in the first flow information and the rate determined based on the first flow information as missing information. The missing information is used to adjust the parameters used when detecting flow behavior, and the parameters include at least one of a rate threshold, a flow threshold, or a segmentation threshold.
[0369] Optionally, the flow behavior detection device 1500 further includes a receiving unit 1508 for receiving parameters sent by the control device, the parameters including at least one of a rate threshold, a flow threshold, or a segmentation threshold used for detecting flow behavior.
[0370] As an example, combined Figure 13 The receiving unit 1508 can be used in response to step 305.
[0371] Optionally, the sending unit 1506 is also used to report impact information to the control device.
[0372] As an example, combined Figure 13 The sending unit 1506 can be used to perform step 302.
[0373] Optionally, the sending unit 1506 is specifically used to: report all determined impact information to the control device when the number of determined impact information exceeds a threshold; or periodically report all determined impact information within a period of time to the control device.
[0374] As an example, combined Figure 13 The sending unit 1506 can be used to perform step 302.
[0375] For a detailed description of the above-mentioned optional methods, please refer to the foregoing method embodiments, which will not be repeated here. Furthermore, the explanation of any of the traffic behavior detection devices 1500 provided above, as well as the description of their beneficial effects, can be found in the corresponding method embodiments described above, and will not be repeated here.
[0376] refer to Figure 16 , Figure 16 A schematic diagram of another flow behavior detection device provided in an embodiment of this application is shown. The flow behavior detection device 1600 is applied to a control device and is used to execute the flow behavior detection method described above, for example, to execute... Figure 13 The portion of the method shown is executed by the control device. The flow behavior detection device 1600 may include a receiving unit 1601.
[0377] The receiving unit 1601 is used to receive message flow impact information reported by the message forwarding node. The message flow impact information is determined based on packet information, rate thresholds, and traffic thresholds of the data packets flowing through the message forwarding node. Packet information includes the flow ID of the message flow to which the data packet belongs, the size of the data packet, and the timestamp of the data packet. One piece of impact information for a message flow describes the behavior of a traffic segment within the message flow. The behavior of the traffic segment is represented by the amount of traffic transmitted within the time period indicated by the impact information, and the rate of traffic in the traffic segment is greater than or equal to the rate threshold, and the size of traffic in the traffic segment is greater than or equal to the traffic threshold.
[0378] As an example, combined Figure 13 The receiving unit 1601 can be used to perform step 303.
[0379] Optionally, the traffic behavior detection device 1600 further includes: an adjustment unit 1602, configured to adjust at least one of the rate threshold, traffic threshold, or segmentation threshold used for detecting traffic behavior when the time interval between receiving impact information reported by the message forwarding node is less than a duration threshold, or when the number of impact information reported by the message forwarding node within a preset duration exceeds a quantity threshold; and a sending unit 1603, configured to send the adjusted rate threshold, traffic threshold, and / or segmentation threshold to the message forwarding node.
[0380] As an example, combined Figure 13 The adjustment unit 1602 can be used to execute step 304, and the sending unit 1603 can be used to execute step 305.
[0381] Optionally, the impact information is used to analyze the reasons for SLO violations in network performance.
[0382] For a detailed description of the above-mentioned optional methods, please refer to the foregoing method embodiments, which will not be repeated here. Furthermore, the explanation of any of the traffic behavior detection devices 1600 provided above, as well as the description of their beneficial effects, can be found in the corresponding method embodiments described above, and will not be repeated here.
[0383] refer to Figure 17 , Figure 17 A schematic diagram of the structure of another traffic behavior detection device provided in an embodiment of this application is shown. Figure 17 As shown, the traffic behavior detection device 1700 can be used to execute the traffic behavior detection method described above. The traffic behavior detection device 1700 may include a transceiver unit 1701 and a processing unit 1702.
[0384] In one possible implementation, the traffic behavior detection device 1700 is applied to the packet forwarding node and used to perform... Figure 5 , Figure 6 or Figure 8 The method shown, or used to perform Figure 13 The part of the method shown is executed by the message forwarding node.
[0385] In this case, the transceiver unit 1701 can be used to perform the operations related to receiving and / or sending performed by the message forwarding node or the detection device deployed in the message forwarding node as described above in the method provided in the embodiments of this application, and the processing unit 1702 is used to perform other operations besides the operations related to receiving and / or sending performed by the message forwarding node or the detection device deployed in the message forwarding node as described above in the method of the embodiments of this application.
[0386] In another possible implementation, the flow behavior detection device 1700 is applied to the control device and used to perform... Figure 13 The part of the method shown is executed by the control device.
[0387] In this case, the transceiver unit 1701 is used to perform the operations related to receiving and / or sending performed by the control device in the method provided in the embodiments of this application, and the processing unit 1702 is used to perform other operations besides the operations related to receiving and / or sending performed by the control device in the method of the embodiments of this application.
[0388] The explanation of the traffic behavior detection device 1700 and the description of its beneficial effects can be found in the corresponding method embodiments described above, and will not be repeated here.
[0389] Those skilled in the art will readily recognize that, based on the units and algorithm steps described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is implemented in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0390] It should be noted that, Figure 15 , Figure 16 or Figure 17 The module / unit division shown is illustrative and represents only one logical functional division; in actual implementation, other division methods are possible. For example, two or more functions can be integrated into a single processing module. The functions implemented by the integrated modules described above can be implemented either in hardware or as software functional modules.
[0391] This application provides a network device for implementing some or all of the functions in the traffic behavior detection method provided in this application. For example, the network device may implement some or all of the functions implemented by the detection device / packet forwarding node in the method described in this application, or it may implement some or all of the functions implemented by the control device in the method described in this application.
[0392] refer to Figure 18 , Figure 18 This is a schematic diagram of the structure of a network device provided in an embodiment of this application. For example... Figure 18 As shown, the network device 1800 includes a processor 1801, a memory 1802, a communication interface 1803, and a bus 1804. The processor 1801, memory 1802, and communication interface 1803 are interconnected via the bus 1804. Optionally, the network device 1800 also includes an input / output interface 1805, which is interconnected with the processor 1801, memory 1802, and communication interface 1803 via the bus 1804.
[0393] Processor 1801 may include a general-purpose processor and / or a dedicated hardware chip. The general-purpose processor may include a CPU, a microprocessor, or a graphics processing unit (GPU). The CPU may be a single-core processor or a multi-core processor. The dedicated hardware chip is a high-performance processing hardware module. The dedicated hardware chip includes at least one of the following: digital signal processing (DSP), data processing unit (DPU), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, neural processing unit (NPU), tensor processing unit (TPU), artificial intelligence chip, or network processor (NP). Processor 1801 may also be an integrated circuit chip with signal processing capabilities. In implementation, some or all of the functions of the methods provided in the embodiments of this application may be implemented by the integrated logic circuitry of the hardware in processor 1801 or by instructions in software form.
[0394] Memory 1802 is used to store computer programs, including operating system 1802a and executable code (i.e., program instructions) 1802b. Memory 1802 is, for example, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, or other types of static storage devices that can store static information and instructions; it is also such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), and synchronous linked dynamic random access memory (SDRAM). DRAM (SLDRAM) or other types of dynamic storage devices capable of storing information and instructions, such as read-only optical discs or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired executable code in the form of instructions or data structures and accessible by a computer, but not limited thereto. For example, memory 1802 is used to store streaming information, influence information, etc. Memory 1802 may exist independently and be connected to processor 1801 via bus 1804. Alternatively, memory 1802 and processor 1801 may be integrated together. Memory 1802 can store executable code. When the executable code stored in memory 1802 is executed by processor 1801, processor 1801 performs some or all of the functions of the method provided in the embodiments of this application. Please refer to the relevant descriptions in the foregoing embodiments for the implementation of the process by processor 1801. Memory 1802 may also include software modules and data required by other running processes, such as operating systems.
[0395] Communication interface 1803 uses transceiver modules, such as, but not limited to, transceivers, to enable communication with other devices or communication networks. For example, communication interface 1803 can be any one or any combination of the following devices: network interfaces (such as Ethernet interfaces), wireless network cards, and other devices with network access capabilities. Communication interface 1803 includes a receiving unit for receiving data / messages and a sending unit for sending data / messages.
[0396] Bus 1804 is any type of communication bus used to interconnect internal devices (e.g., memory 1802, processor 1801, communication interface 1803) of network device 1800. For example, a system bus. This embodiment illustrates the interconnection of these internal devices of network device 1800 via bus 1804. Optionally, the internal devices of network device 1800 can also communicate with each other using other connection methods besides bus 1804; for example, the internal devices of network device 1800 can be interconnected via internal logical interfaces.
[0397] Input / output interface 1805 is used to realize human-computer interaction between the user and network device 1800. For example, it enables text or voice interaction between the user and network device 1800. Input / output interface 1805 includes an input interface for the user to input information to network device 1800, and an output interface for the network device 1800 to output information to the user. As an example, the input interface includes, but is not limited to, a touchscreen, keyboard, mouse, or microphone, and the output interface includes, but is not limited to, a display screen, speaker, etc. Specifically, the touchscreen, keyboard, or mouse is used to input text / image information, the microphone is used to input voice information, the display screen is used to output text / image information, and the speaker is used to output voice information.
[0398] In one example, when the network device 1800 is implemented as the detection device described in the embodiments of this application, the input / output interface 1805 can be used to receive user-input parameters, such as at least one of the following: rate threshold, traffic threshold, segmentation threshold, and CL.
[0399] In another example, when the network device 1800 is implemented as the control device described in the embodiments of this application, the input / output interface 1805 can be used to receive query requests input by the user or to display query results to the user.
[0400] It should be noted that the aforementioned devices can be disposed on separate chips, or at least partially or entirely on the same chip. Whether to dispose of the devices independently on different chips or integrate them on one or more chips often depends on the needs of the product design. This application does not limit the specific implementation of the aforementioned devices. Furthermore, the descriptions of the processes corresponding to the various figures above each have their own emphasis; for parts of a process not described in detail in one figure, please refer to the relevant descriptions of other processes.
[0401] In the above embodiments, the methods can be implemented entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, they can be implemented entirely or partially in the form of a computer program product. The computer program product providing the program development platform includes one or more computer instructions, which, when loaded and executed on the network device 1800, implement some or all of the functions of the methods provided in the embodiments of this application.
[0402] Furthermore, computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium stores computer program instructions that provide a program development platform.
[0403] As an example, combined Figure 15 The functions implemented by the acquisition unit 1501, determination unit 1502, replacement unit 1503, update unit 1504, and query unit 1505 in the traffic behavior detection device 1500 can be achieved through... Figure 18 Processor 1801 in the middle executes Figure 18 The program code in memory 1802 is used for implementation. The function implemented by storage unit 1507 in flow behavior detection device 1500 can be achieved through... Figure 18 The functions implemented in the memory 1802 are achieved through the transmission unit 1506 and the receiving unit 1508 in the flow behavior detection device 1500. Figure 18 The communication interface shown is implemented using 1803.
[0404] As another example, combining Figure 16 The functions implemented by the receiving unit 1601 and the transmitting unit 1603 in the traffic behavior detection device 1600 can be achieved through... Figure 18 The communication interface 1803 shown is used for implementation. The function implemented by the adjustment unit 1602 in the flow behavior detection device 1600 can be achieved through... Figure 18 Processor 1801 in the middle executes Figure 18 The program code is implemented in memory 1802.
[0405] As yet another example, combined with Figure 17 The transceiver unit 1701 in the traffic behavior detection device 1700 can perform the functions through... Figure 18 The communication interface 1803 shown is implemented. The functions implemented by the processing unit 1702 in the traffic behavior detection device 1700 can be achieved through... Figure 18 Processor 1801 in the middle executes Figure 18 The program code is implemented in memory 1802.
[0406] This application also provides a traffic behavior detection system, which includes a detection device and a control device. The detection device performs the portion of the method provided in this application that is executed by the detection device or a packet forwarding node equipped with a detection device, and the control device performs the portion of the method provided in this application that is executed by the control device.
[0407] This application also provides a computer-readable storage medium, which is a non-volatile computer-readable storage medium. The computer-readable storage medium includes computer program instructions. When the computer program instructions are executed by a processor, a computing device including the processor, or a computer system, the processor, the computing device including the processor, or the computer system performs the traffic behavior detection method provided in this application.
[0408] This application also provides a computer program product containing instructions that, when executed by a processor, a computing device including a processor, or a computer system, cause the processor, the computing device including a processor, or the computer system to implement the traffic behavior detection method provided in this application.
[0409] A computer system is a system with computational processing capabilities. A computer system generally includes a processor and memory. The processor retrieves and executes instructions stored in memory to enable the computer system to implement the traffic behavior detection method described above. Optionally, the computer system may also include at least one of an input interface or an output interface. The processor, memory, input interface, and output interface of the computer system are connected through internal interconnection paths.
[0410] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware, or by a program instructing the relevant hardware to implement them. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.
[0411] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, data stored, data displayed, etc.) and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0412] This application also provides a chip that includes a processor for running program instructions or code. The chip or a device containing the chip can be used to execute the traffic behavior detection method provided in this application. Exemplarily, the chip further includes an input interface, an output interface, and a memory. The chip's input interface, output interface, processor, and memory are connected via internal interconnection paths. The memory in the chip stores program instructions or code executed by the processor, and the input and output interfaces are used for communication between the chip and other chips or devices.
[0413] In the embodiments of this application, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance. The term "at least one" refers to one or more, and the term "multiple" refers to at least two, unless otherwise expressly defined.
[0414] In this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.
[0415] It should be understood that the terminology used in the description of the various examples herein is for the purpose of describing particular examples only and is not intended to be limiting. As used in the description of the various examples and the appended claims, the singular forms “a” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0416] It should be understood that determining B based on A does not mean determining B solely based on A; B can also be determined based on A and / or other information.
[0417] It should be understood that the term "comprising" (also referred to as "includes", "including", "comprises" and / or "comprising") as used in this specification specifies the presence of the stated features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0418] It should also be understood that, in the various embodiments of this application, the sequence number of each process does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0419] The above description is merely an optional embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the concept and principles of this application should be included within the protection scope of this application.
[0420] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for detecting traffic behavior, characterized in that, Applied to message forwarding nodes, the method includes: Obtain packet information of data packets flowing through the packet forwarding node. The packet information includes the flow identifier ID of the packet flow to which the data packet belongs, the size of the data packet, and the timestamp of the data packet. Based on the packet information, rate threshold, and traffic threshold, impact information of the packet flow is determined. One piece of impact information of the packet flow is used to describe the behavior of a traffic segment in the packet flow. The behavior of the traffic segment is represented by the amount of traffic transmitted within the time period indicated by the impact information. The rate of the traffic in the traffic segment is greater than or equal to the rate threshold, and the amount of traffic in the traffic segment is greater than or equal to the traffic threshold.
2. The method as described in claim 1, characterized in that, The message forwarding node includes a filtering module, which includes k recording units. Each recording unit is used to record the flow information of the message flow passing through the message forwarding node. For the first recording unit among the k recording units, the first flow information recorded based on any message flow passing through the message forwarding node includes the flow ID, flow start time, timestamp of the last received data packet, flow size, and the latest reception time of the next data packet estimated based on the rate threshold. For the first data packet received by the packet forwarding node, where the first data packet is a data packet of the first packet flow passing through the packet forwarding node, determining the impact information of the packet flow based on the packet information, rate threshold, and traffic threshold includes: Based on the flow ID in the packet information of the first data packet, the record unit in the filtering module that has a mapping relationship with the first message flow to which the first data packet belongs is determined as the first record unit; If, based on the rate of the first data packet and the rate threshold, it is determined that the first flow information recorded in the first recording unit should be replaced with the second flow information, and if the flow size in the first flow information is greater than or equal to the flow threshold, then the flow ID, time information, and flow size in the first flow information are determined as the impact information; wherein, the second flow information is flow information obtained based on the packet information of the first data packet.
3. The method as described in claim 2, characterized in that, Before determining the stream ID, time information, and traffic volume in the first stream information as the influencing information, the method further includes: When the flow ID in the packet information of the first data packet is the same as the flow ID in the first flow information and the rate of the first data packet is less than the rate threshold, or when the flow ID in the packet information of the first data packet is the same as the flow ID in the first flow information, the rate of the first data packet is greater than or equal to the rate threshold, and the traffic size in the first flow information is greater than or equal to the segmentation threshold, it is determined to replace the first flow information with the second flow information. Wherein, when the timestamp of the first data packet is greater than the latest reception time, the rate of the first data packet is less than the rate threshold; when the timestamp of the first data packet is less than or equal to the latest reception time, the rate of the first data packet is greater than or equal to the rate threshold; and the segmentation threshold is greater than the traffic threshold.
4. The method as described in claim 2 or 3, characterized in that, The method further includes: Replace the first stream information in the first recording unit with the second stream information.
5. The method according to any one of claims 2 to 4, characterized in that, The message forwarding node further includes a temporary storage module, which includes k recording units. Each recording unit is used to record the flow information of the message flow passing through the message forwarding node. For the flow information recorded by the second recording unit in the temporary storage module, the flow information recorded by the second recording unit includes the flow ID, flow start time, timestamp of the last received data packet, flow size, and the latest reception time of the next data packet estimated based on the rate threshold. The flow information recorded by the second recording unit is the flow information recorded based on any message flow passing through the message forwarding node. Before determining the record unit in the filtering module that has a mapping relationship with the first message stream to which the first data packet belongs, based on the flow ID in the packet information of the first data packet, the method further includes: Based on the flow ID in the packet information of the first data packet, the record unit in the temporary storage module that has a mapping relationship with the first message flow to which the first data packet belongs is determined as the second record unit; Based on the rate of the first data packet and the rate threshold, data is determined to update the stream information recorded in the second recording unit using the packet information of the first data packet.
6. The method as described in claim 5, characterized in that, When, based on the rate of the first data packet and the rate threshold, it is determined that the data for updating the flow information recorded in the second recording unit using the packet information of the first data packet is used, after determining, based on the flow ID in the packet information of the first data packet, the recording unit in the filtering module that has a mapping relationship with the first message flow to which the first data packet belongs is the first recording unit, the method further includes: Based on a first freshness factor determined according to the first data packet, the freshness of the stream information recorded by the first recording unit is updated. The freshness is used to indicate whether to continue maintaining the currently recorded stream information in the first recording unit. The maintenance includes updating the data of the currently recorded stream information of the first recording unit based on the received data packet. The first freshness factor is used to indicate the degree of influence of the first data packet on the freshness of the stream information recorded in the first recording unit.
7. The method as described in claim 6, characterized in that, The message forwarding node is configured with a matching table, which is used to indicate the freshness factor corresponding to different combinations of traffic size range and packet interval range. Before updating the freshness of the stream information recorded by the first recording unit, the method further includes: The first freshness factor is determined by querying the matching table based on the range of the size of the first data packet and the range of the packet interval of the first data packet.
8. The method according to any one of claims 5 to 7, characterized in that, The step of determining the data for updating the stream information recorded in the second recording unit using the packet information of the first data packet based on the rate of the first data packet and the rate threshold includes: When the flow ID in the packet information of the first data packet is the same as the flow ID in the flow information recorded by the second recording unit, and the rate of the first data packet is greater than or equal to the rate threshold, or when the flow ID in the packet information of the first data packet is the same as the flow ID in the flow information recorded by the second recording unit, the rate of the first data packet is greater than or equal to the rate threshold, and the flow size in the first flow information is less than the segmentation threshold, it is determined to use the packet information of the first data packet to update the data of the flow information recorded in the second recording unit. Wherein, when the timestamp of the first data packet is less than or equal to the latest reception time in the flow information recorded by the second recording unit, the rate of the first data packet is greater than or equal to the rate threshold; the segmentation threshold is greater than the traffic threshold.
9. The method according to any one of claims 5 to 8, characterized in that, For the second data packet in the first message stream received by the message forwarding node after receiving the first data packet, the step of determining the impact information of the message stream based on the packet information, rate threshold, and traffic threshold includes: Based on the flow ID in the packet information of the second data packet, the record unit in the temporary storage module that has a mapping relationship with the first message flow to which the second data packet belongs is determined as the second record unit; When it is determined, based on the rate of the second data packet and the rate threshold, to replace the original flow information recorded in the second recording unit with flow information obtained from the packet information of the second data packet, the recording unit in the filtering module that has a mapping relationship with the first message flow to which the second data packet belongs is determined as the first recording unit based on the flow ID in the packet information of the second data packet. When the freshness of the third stream information originally recorded in the first recording unit meets the preset condition, and the traffic size of the third stream information is greater than or equal to the traffic threshold, the stream ID, time information and traffic size in the third stream information are determined as the impact information.
10. The method as described in claim 9, characterized in that, The method further includes: When determining, based on the rate of the second data packet and the rate threshold, to replace the original stream information recorded in the second recording unit with stream information obtained from the packet information of the second data packet, the original fourth stream information recorded in the second recording unit is replaced with stream information obtained from the packet information of the second data packet, and the fourth stream information is sent to the filtering module; When the freshness of the third stream information originally recorded in the first recording unit meets the preset condition, the fourth stream information is used to replace the third stream information, and the stream ID of the fourth stream information is different from the stream ID of the third stream information.
11. The method according to any one of claims 5 to 10, characterized in that, A message flow includes multiple impact information items. For the first and second impact information items belonging to the same message flow, which are determined sequentially by the message forwarding node, the method further includes: The second impact information is stored by reusing the stream ID from the first impact information.
12. The method as described in claim 11, characterized in that, The method further includes: When the rate indicated by the first impact information and the rate indicated by the second impact information are in the same rate range, an aggregation operation is performed on the first impact information and the second impact information to aggregate the first impact information and the second impact information into a single impact information for storage. The aggregation operation includes aggregating the traffic size and time information in the first impact information and the second impact information.
13. The method according to any one of claims 2 to 12, characterized in that, When the traffic size recorded in the first stream information is less than the traffic threshold, the traffic size included in the first stream information and the rate determined based on the first stream information are identified as missing information. The missing information is used to adjust the parameters used when detecting traffic behavior. The parameters include at least one of the rate threshold, traffic threshold, or segmentation threshold.
14. The method according to any one of claims 1 to 13, characterized in that, The method further includes: The receiver receives parameters sent by the control device, the parameters including at least one of a rate threshold, a flow threshold, or a segmentation threshold used for detecting flow behavior.
15. The method according to any one of claims 1 to 14, characterized in that, The method further includes: The impact information is reported to the control device.
16. The method as described in claim 14, characterized in that, The reporting of the impact information to the control device includes: When the number of identified impact information exceeds a threshold, all identified impact information is reported to the control device; or, all identified impact information within a periodic duration is periodically reported to the control device.
17. A method for detecting traffic behavior, characterized in that, Applied to a control device, the method includes: The message flow impact information reported by the message forwarding node is received. The impact information is determined based on the packet information, rate threshold, and traffic threshold of the data packets flowing through the message forwarding node. The packet information includes the flow identifier ID of the message flow to which the data packet belongs, the size of the data packet, and the timestamp of the data packet. One impact information of the message flow is used to describe the behavior of a traffic segment in the message flow. The behavior of the traffic segment is represented by the traffic size transmitted within the time period indicated by the impact information, and the rate of the traffic in the traffic segment is greater than or equal to the rate threshold, and the size of the traffic in the traffic segment is greater than or equal to the traffic threshold.
18. The method as described in claim 17, characterized in that, The method further includes: When the time interval between receiving the impact information reported by the message forwarding node is less than the duration threshold, or when the number of impact information reported by the message forwarding node within the preset duration exceeds the quantity threshold, at least one of the rate threshold, traffic threshold, or segmentation threshold used for detecting traffic behavior is adjusted. Send the adjusted rate threshold, traffic threshold, and / or segmentation threshold to the message forwarding node.
19. The method as described in claim 17 or 18, characterized in that, The impact information is used to analyze the reasons for violations of Service Level Objectives (SLOs) in network performance.
20. A device for detecting flow behavior, characterized in that, The detection device, applied to a message forwarding node, includes: A processing unit is configured to perform operations other than those related to receiving and / or transmitting in the method of any one of claims 1 to 16; A transceiver unit is used to perform operations related to receiving and / or transmitting in the method of any one of claims 1 to 16.
21. A device for detecting flow behavior, characterized in that, The detection device, applied to a control device, includes: A transceiver unit for performing operations related to receiving and / or transmitting in the method of any one of claims 17 to 19; A processing unit is configured to perform operations other than those related to receiving and / or transmitting in the method of any one of claims 17 to 19.
22. A device for detecting flow behavior, characterized in that, include: The device includes a memory, a communication interface, and one or more processors, the one or more processors receiving or transmitting data through the communication interface, the one or more processors being configured to read program instructions stored in the memory to perform the method as described in any one of claims 1 to 19.
23. A traffic behavior detection system, characterized in that, The detection system includes a detection device and a control device, wherein the detection device is used to perform the method as described in any one of claims 1 to 16, and the control device is used to perform the method as described in any one of claims 17 to 19.
24. A computer program product containing instructions, characterized in that, When the instructions are executed by a processor, the processor or a device including the processor performs the method as described in any one of claims 1 to 19.
25. A computer-readable storage medium, characterized in that, It includes computer program instructions, which, when executed by a processor, cause the processor or a device including the processor to perform the method as claimed in any one of claims 1 to 19.