Detection method and assembly, cloud environment, electronic device, storage medium and product

WO2025186648A8PCT designated stage Publication Date: 2025-10-02CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/051503
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-05
Filing Date
2025-02-13
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

In a cloud computing network environment, existing network traffic detection technologies have high costs, poor timeliness, and consume additional network bandwidth.

Method used

Deploy traffic detection components on the communication link between the client outside the cloud environment and the server within the cloud environment, extract features and perform security detection by obtaining traffic information of access requests, and execute corresponding control operations.

Benefits of technology

It reduces the detection cost, reduces the amount of data transmission, improves the detection timeliness, and saves network bandwidth.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025051503_02102025_PF_FP_ABST
    Figure IB2025051503_02102025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to the technical field of network security, and disclose a detection method and assembly, a cloud environment, an electronic device, a storage medium, and a product. The method comprises: acquiring an access request for the server sent by the client; acquiring traffic information corresponding to the access request, and performing feature extraction on the traffic information, to obtain a traffic feature corresponding to the traffic information; on the basis of the traffic feature, performing traffic security detection on the access request, and executing a management and control operation for the client on the basis of the traffic detection result, so as to eliminate a traffic redirection link, thereby effectively reducing detection costs and data transmission volume, greatly saving network bandwidth, and improving the timeliness of detection.
Need to check novelty before this filing date? Find Prior Art

Description

[0001]Detection Method, Component, Cloud Environment, Electronic Device, Storage Medium, and Product. This disclosure claims priority to Chinese patent application number 202410249615.1, filed with the China Patent Office on March 5, 2024, and entitled "Detection Method, Component, Cloud Environment, Electronic Device, Storage Medium, and Product," the entire contents of which are incorporated herein by reference. Technical Field: This disclosure relates to the field of network security technology, and more particularly to a network traffic detection method, a traffic detection component, a cloud environment, an electronic device, a computer-readable storage medium, and a computer program product. Background: With the development of cloud computing technology, its applications are becoming increasingly widespread. For example, cloud servers, cloud storage, cloud databases, and cloud applications can constitute important components of cloud computing infrastructure. To ensure the security of a cloud computing network environment and achieve network traffic protection, network traffic can be detected to determine the security of the network environment. For example, when performing security protection and detection on cloud network traffic, it's often necessary to deploy additional traffic diversion equipment to mirror network data and analyze the mirrored traffic to determine its security. However, in this process, the additional deployment of traffic diversion equipment can easily increase detection costs. Furthermore, the transmission of mirrored traffic increases the amount of data transmitted, which can reduce the timeliness of traffic detection and lead to significant network bandwidth consumption. The present disclosure provides a network traffic detection method, components, cloud environment, electronic device, computer-readable storage medium, and computer program product to address or partially address the issues of high cost, poor timeliness, and excessive network bandwidth consumption associated with network traffic detection. The present disclosure discloses a method for detecting network traffic, which is applied to a traffic detection component deployed in a cloud environment. The traffic detection component is deployed in series on a communication link between a client outside the cloud environment and a server in the cloud environment. The method includes: obtaining an access request sent by the client to the server; obtaining traffic information corresponding to the access request, and performing feature extraction on the traffic information to obtain traffic characteristics corresponding to the traffic information; performing traffic security detection on the access request based on the traffic characteristics, and executing control operations on the client based on the traffic detection results.In some optional embodiments, the traffic detection component includes at least a traffic identification unit. Obtaining traffic information corresponding to the access request, performing feature extraction on the traffic information, and obtaining traffic characteristics corresponding to the traffic information includes: obtaining traffic information corresponding to the access request via the traffic identification unit, performing feature extraction on the traffic information, and obtaining traffic characteristics corresponding to the traffic information. In some optional embodiments, extracting features from the traffic information and obtaining traffic characteristics corresponding to the traffic information includes: extracting at least one of a quintuple and application layer data from the traffic information; and performing feature extraction on at least one of the quintuple and the application layer data to obtain traffic characteristics corresponding to the traffic information. In some optional embodiments, the traffic characteristics include at least one of an IP address, a port number, a protocol type, application layer data content, a packet size, a transmission frequency, and a traffic behavior pattern. In some optional embodiments, the traffic detection component includes at least an access control unit and a security detection unit that is communicatively connected to the access control unit and the traffic identification unit respectively, and the access control unit and the traffic identification unit are deployed in series on the communication link. The traffic security detection is performed on the access request according to the traffic characteristics, and the management and control operations for the client are executed according to the traffic detection results, including: performing traffic security detection on the access request according to the traffic characteristics by the security detection unit to generate a traffic detection result for the client; and executing a management and control operation corresponding to the traffic detection result by the access control unit. In some optional embodiments, executing a control operation corresponding to the traffic detection result includes: if the traffic detection result is a pass, forwarding the access request to the traffic identification unit, forwarding the access request to the server via the traffic identification unit, and allowing subsequent traffic between the client and the server; if the traffic detection result is a fail, blocking the transmission of the access request, blocking traffic between the client and the server, and outputting a prompt message to the client, wherein the prompt message indicates that the client has a traffic security issue. In some optional embodiments, the process further includes: reporting the traffic detection result to a control device via the security detection unit, wherein the traffic detection result is used to instruct the control device to generate a control instruction for the client, wherein the control instruction includes one of allowing or blocking traffic.In some optional embodiments, after obtaining traffic information corresponding to the access request, the method further includes: if the traffic information carries an inspection exemption flag, allowing traffic between the client and the server to pass through via the access control unit. The disclosed embodiments also disclose a cloud environment, comprising at least a server and a traffic detection component, wherein the traffic detection component comprises at least a security detection unit, an access control unit deployed in series on a communication link between a client outside the cloud environment and the server in the cloud environment, and a traffic identification unit; wherein the security detection unit is deployed in a bypass manner within the cloud environment and is in communication with the access control unit and the traffic identification unit; wherein the access control unit is configured to obtain an access request sent by the client to the server; the traffic identification unit is configured to obtain traffic information corresponding to the access request and perform feature extraction on the traffic information to obtain traffic features corresponding to the traffic information; the security detection unit is configured to perform traffic security detection on the access request based on the traffic features; and the access control unit is configured to execute control operations on the client based on the traffic detection results. In some optional embodiments, the traffic identification unit is specifically configured to: extract at least a corresponding quintuple and application layer data from the traffic information; and perform feature extraction on one of the quintuple and the application layer data to obtain traffic features corresponding to the traffic information. In some optional embodiments, the traffic features include at least one of an IP address, a port number, a protocol type, application layer data content, a packet size, a transmission frequency, and a traffic behavior pattern. In some optional embodiments, the access control unit is specifically configured to: if the traffic detection result is a pass, forward the access request to the traffic identification unit, which then forwards the access request to the server and allows subsequent traffic between the client and the server; if the traffic detection result is a fail, block the transmission of the access request, block traffic between the client and the server, and output a prompt message to the client. In some optional embodiments, the traffic identification unit is further configured to: if the traffic information carries an inspection exemption flag, send the access request to the server.The present disclosure also discloses a traffic detection component, which is deployed in a cloud environment and includes at least a security detection unit, an access control unit deployed in series on a communication link between a client outside the cloud environment and a server in the cloud environment, and a traffic identification unit. The security detection unit is deployed in a bypass manner within the cloud environment and is in communication with the access control unit and the traffic identification unit. The access control unit is configured to obtain an access request sent by the client to the server. The traffic identification unit is configured to obtain traffic information corresponding to the access request and perform feature extraction on the traffic information to obtain traffic characteristics corresponding to the traffic information. The security detection unit is configured to perform traffic security detection on the access request based on the traffic characteristics, and the access control unit is configured to perform control operations on the client based on the traffic detection results. In some optional embodiments, the traffic identification unit is specifically configured to: extract corresponding quintuples and application layer data from the traffic information; and perform feature extraction on one of the quintuples and the application layer data to obtain traffic characteristics corresponding to the traffic information. In some optional embodiments, the traffic characteristics include at least one of an IP address, a port number, a protocol type, application layer data content, a packet size, a transmission frequency, and a traffic behavior pattern. In some optional embodiments, the access control unit is specifically configured to: if the traffic detection result is a pass, forward the access request to the traffic identification unit, which then forwards the access request to the server and allows subsequent traffic between the client and the server; if the traffic detection result is a fail, block the transmission of the access request, block traffic between the client and the server, and output a prompt message to the client. In some optional embodiments, the traffic identification unit is further configured to: if the traffic information carries an exemption flag, send the access request to the server. The present disclosure also discloses an electronic device comprising a processor, a communication interface, a memory, and a communication bus. The processor, the communication interface, and the memory communicate with each other via the communication bus. The memory is configured to store a computer program. The processor is configured to implement the method described in the present disclosure when executing the program stored in the memory. The present disclosure also discloses a computer-readable storage medium storing instructions that, when executed by one or more processors, cause the processors to perform the method described in the present disclosure.The present disclosure also discloses a computer program product, including a computer program. When executed by a processor, the computer program implements the method described in the present disclosure. The present disclosure has the following advantages: In a cloud computing scenario, a traffic detection component is deployed on the communication link between a client outside the cloud environment and a server within the cloud environment. When data is exchanged between the client and the server, the traffic detection component can obtain access requests sent by the client to the server, then obtain traffic information corresponding to the access request, perform feature extraction on the traffic information to obtain traffic features corresponding to the traffic information, perform traffic security detection on the access request based on the traffic features, and perform control operations on the access request based on the traffic detection results. Deploying the traffic detection component between the client and the server eliminates the need for deploying traffic diversion equipment at the entrance outside the cloud environment, eliminating the need for traffic diversion, effectively reducing detection costs. Furthermore, by extracting traffic features from the traffic information and performing detection based on the traffic features, data transmission volume can be effectively reduced, detection timeliness can be improved, and network bandwidth can be significantly saved. BRIEF DESCRIPTION OF THE DRAWINGS Figure 1 is a flowchart of a method for detecting network traffic provided in an embodiment of the present disclosure; Figure 2 is a schematic diagram of an application scenario provided in an embodiment of the present disclosure; Figure 3 is a schematic diagram of an application scenario provided in an embodiment of the present disclosure; Figure 4 is a schematic diagram of an application scenario provided in an embodiment of the present disclosure; Figure 5 is a block diagram of a traffic detection component provided in an embodiment of the present disclosure; and Figure 6 is a block diagram of an electronic device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION To make the above-mentioned objects, features, and advantages of the present disclosure more readily understood, the present disclosure is further described in detail below with reference to the accompanying drawings and specific embodiments. As an example, to achieve secure protection and detection of cloud network traffic without changing the physical topology of the current network structure, during the relevant traffic detection process, traffic diversion is used to change the traffic path, thereby directing the traffic to the corresponding target device, which then analyzes the traffic. However, in this process, corresponding hardware equipment (such as splitters and diverters) needs to be deployed at the entrance outside the cloud environment, which increases the detection cost and complexity. In addition, the diversion adds additional traffic paths, especially for cross-computer room diversion scenarios. The detection delay becomes more and more obvious. In addition, the diversion method requires the transmission of traffic, which increases the network bandwidth and easily brings a heavy burden to the network equipment.In this regard, in the present disclosure, in a cloud computing scenario, a traffic detection component is deployed on the communication link between a client outside the cloud environment and a server within the cloud environment. This allows the client and server to interact with data by obtaining access requests sent by the client to the server, then obtaining traffic information corresponding to the access request, performing feature extraction on the traffic information to obtain traffic characteristics corresponding to the traffic information, then performing traffic security detection on the access request based on the traffic characteristics, and executing control operations on the access request based on the traffic detection results. Deploying the traffic detection component between the client and the server eliminates the need to deploy corresponding traffic diversion equipment at the entrance outside the cloud environment, eliminating the need for the diversion process and effectively reducing detection costs. Furthermore, by extracting traffic characteristics from the traffic information and performing detection based on the traffic characteristics, the traffic transmission volume can be effectively reduced, detection timeliness can be improved, and network bandwidth can be significantly saved. FIG1 shows a flowchart of a method for detecting network traffic provided in an embodiment of the present disclosure. The method is applied to a traffic detection component deployed in a cloud environment. The traffic detection component is deployed in series on a communication link between a client outside the cloud environment and a server within the cloud environment. Specifically, the method may include the following steps: Step 101: Obtain an access request sent by the client to the server. In the embodiment of the present disclosure, network traffic detection can be applied to remote office access, client application access, resource access, cross-cloud environment access, and the like. Specifically, for remote office access, when an employee uses remote office tools (such as VPN (Virtual Private Network) or Remote Desktop) outside the cloud to access enterprise resources within the cloud, traffic detection can be used to ensure access security. For example, VPN traffic can be monitored and user authentication and access behavior can be checked to identify abnormal login attempts or unauthorized access. For client application access, when users use terminal devices or applications outside the cloud to access applications within the cloud, traffic security detection and response can be performed. For example, by real-time monitoring of data traffic from applications, application propagation, abnormal data transmission, or unauthorized access can be detected and prevented. For resource access, when shared resources or applications within the cloud need to be accessed from outside the cloud, security can be ensured by inspecting access traffic. For example, an intrusion detection system can be used to detect traffic from specific IP addresses to determine whether there are potential security risks. For cross-cloud access, when resources within the cloud need to interact with other cloud service providers outside the cloud, access traffic can be monitored and restricted.For example, firewalls and access control lists are used to control traffic, allowing only traffic that complies with security policies to pass. In a specific implementation, by deploying the traffic detection component in the same cloud environment as the server and deploying it in series on the communication link between the client outside the cloud environment and the server in the cloud environment, the deployment of corresponding traffic diversion equipment at the entrance outside the cloud environment can be effectively avoided, saving equipment costs. Furthermore, by extracting and analyzing traffic features in the communication link based on the traffic detection component, data transmission volume is effectively reduced, improving detection timeliness while saving network bandwidth. Alternatively, the traffic detection component can be deployed on the server or independently deployed in the same cloud environment as the server. The traffic detection component can be in software form, which is not limited in this disclosure. In one example, referring to FIG2 , a schematic diagram of an application scenario provided in an embodiment of the present disclosure is shown. A corresponding server is deployed in a cloud environment, and a client located outside the cloud environment can access the server. During the access process, a traffic detection device deployed on the communication link between the server and the client can obtain access requests sent by the client to the server and perform traffic security checks based on the access requests, thereby implementing network traffic detection and protection. It should be noted that the client can be a user terminal or an application deployed on the user terminal, and this disclosure does not limit this. Optionally, the access control unit and the traffic identification unit can be deployed in series along the path that service traffic must pass through, or integrated with a gateway, maintaining a communication connection with the security detection unit. This prevents the deployment of traffic diversion devices from changing the forwarding path of service traffic. In addition, the access control unit, traffic identification unit, and security detection unit can be deployed separately, or some units can be deployed together to save costs, improve deployment flexibility, and reduce the impact on business traffic. For example, the access control unit and traffic identification unit can be deployed together on a route that business traffic must pass through, and the security detection unit can be deployed in a bypass manner. Alternatively, the access control unit and traffic identification unit can be deployed in series on a route that business traffic must pass through, and the security detection unit can be deployed in a bypass manner. This disclosure does not impose any restrictions on this.Step 102: Obtain traffic information corresponding to the access request and perform feature extraction on the traffic information to obtain traffic features corresponding to the traffic information. In embodiments of the present disclosure, after obtaining the access request sent by the client, the traffic detection component may further obtain traffic information corresponding to the access request and perform feature extraction on the traffic information to obtain corresponding traffic features. This allows for traffic security detection based on the traffic features. The traffic detection component then processes the access request based on the traffic detection results, for example, by blocking the access request or forwarding it to the server. This ensures data exchange between the client and the server while achieving traffic detection. In some optional embodiments, the traffic detection component includes at least a traffic identification unit. The traffic identification unit may then obtain traffic information corresponding to the access request and perform feature extraction on the traffic information to obtain traffic features corresponding to the traffic information. During the traffic feature extraction process, the traffic identification unit may first extract at least one of a quintuple and application layer data from the traffic information, then perform feature extraction on at least one of the quintuple and application layer data to obtain traffic features corresponding to the traffic information. Optionally, the traffic characteristics include at least one of an IP address, a port number, a protocol type, application layer data content, a data packet size, a sending frequency, and a traffic behavior pattern. Among them, the quintuple can be five elements used to uniquely identify a network connection in network communication, including source IP address, destination IP address, source port, destination port number, and protocol type. The source IP address (Source IP Address) can be the IP address of the client; the destination IP address (Destination IP Address) can be the IP address of the server; the source port number (Source Port): the source port number identifies the application or service from which the data packet originates, and is used to distinguish communications between different applications on the same host; the destination port number (Destination Port) can be the destination port number that identifies the application or service to which the data packet is to be sent, and is used to distinguish different services or applications; the protocol type (Protocol) can refer to the transmission protocol used by the data packet, such as TCP (Transmission Control Protocol), UDP (User Datagram Protocol), ICMP (Internet Control Message Protocol), etc.The protocol type determines the method and rules for data packet transmission. Protocol information refers to the protocol used by data packets transmitted during network communications. Each data packet contains information about its source, destination, and exchange protocol. Different network communication protocols may correspond to different protocol information, such as IP, TCP, UDP, and ICMP. It should be noted that the quintuple and protocol information contain the necessary information to describe data packet transmission, while the transport protocol information specifies the rules and methods for data packet transmission, ensuring that the data reaches the target host correctly across the network. Application layer data refers to data generated and processed by applications. After passing through the transport layer (such as TCP or UDP) and the network layer (such as IP), it is ultimately transmitted across the network to its destination. The content and format of application layer data depend on the specific application and protocol. For example, HTTP (Hypertext Transfer Protocol) is used to transfer hypertext documents between web browsers and web servers. Application layer data includes web page content such as HTML documents, CSS (Cascading Style Sheets) style sheets, and JavaScript scripts. FTP (File Transfer Protocol) is used to transfer files between clients and servers. Application layer data is the file itself to be transferred, including text files, images, videos, audio, etc. SMTP (Simple Mail Transfer Protocol) is used to send and transmit emails. Application layer data includes email information such as the email subject, body content, attachments, recipients, and senders; DNS (Domain in Name System): resolves domain names into corresponding IP addresses. Application layer data is data containing domain name query requests and corresponding IP addresses; VoIP (Voice over IP): conducts voice communication through the network. Application layer data is encoded voice signals used for transmission and reproduction as sound signals in the network.In one example, after obtaining traffic information corresponding to an access request, the traffic identification unit may extract a quintuple and application layer data from the traffic information and perform feature extraction on at least one of the quintuple and the application layer data to obtain corresponding traffic features. This includes extracting information such as the source IP address, destination IP address, source port number, destination port number, and protocol type from the quintuple; extracting information such as the protocol type from the protocol information; and extracting information such as the application layer data content, packet size, transmission frequency, and traffic behavior patterns from the application layer data. Based on the extracted traffic features, the unit then performs traffic security detection on the traffic corresponding to the access request. The unit then processes the access request based on the traffic detection results to implement network protection and detection. In step 103, the unit performs traffic security detection on the access request based on the traffic features and executes control operations on the client based on the traffic detection results. In the disclosed embodiments, the security detection unit, which is communicatively connected to the access control unit and the traffic identification unit in the security detection component, receives traffic characteristics transmitted by the traffic identification unit. It then performs traffic security detection on the access request based on the traffic characteristics, generates a traffic detection result for the access request, and transmits the traffic detection result to the access control unit, which then executes control operations corresponding to the traffic detection result. Deploying the traffic security detection component between the client and the server eliminates the need for deploying traffic diversion equipment at the ingress outside the cloud environment, avoiding traffic mirroring and effectively reducing detection costs. Furthermore, by extracting traffic characteristics from traffic information and performing detection based on these characteristics, data transmission volume can be effectively reduced, detection timeliness can be improved, and network bandwidth can be significantly conserved.In a specific implementation, based on different traffic characteristics, the security detection unit may perform traffic security detection based on at least one traffic characteristic. For example, IP address: The source and destination IP addresses of the traffic can be used to analyze the source and destination of the traffic and detect abnormal or illegal IP addresses; port number: The source and destination port numbers of the traffic can be used to analyze the service type and communication mode of the traffic and detect abnormal or illegal port usage; protocol type: The protocol type used by the traffic, such as TCP, UDP, ICMP, etc., can be used to analyze the protocol distribution of the traffic and detect abnormal or illegal protocol usage; application layer data content: The characteristics of the application layer data transmitted in the traffic, such as text, images, audio, etc., can be used to extract and analyze the data content using technologies such as text mining, image processing, and sound recognition; packet size: The number of bytes in a single packet, which can be used to analyze statistical information such as the average, maximum, and minimum packet sizes to help evaluate the data load and transmission performance of the traffic; and transmission frequency: The frequency of packet transmission or the duration of the traffic. It can analyze the transmission rate, burstiness and continuity of traffic, and detect abnormal traffic behavior; Traffic behavior pattern: Based on the time series data of traffic, it can analyze the behavior pattern of traffic, such as periodicity, regularity, abnormal behavior, etc. In one example, taking an IP address as an example, after obtaining the source IP address (the client's IP address) and the destination IP address sent by the traffic identification unit, the security detection unit may check whether the source IP address and the destination IP address are valid IP addresses according to the whitelist and blacklist, and obtain a traffic detection result corresponding to the client. If the traffic detection result is a pass, the traffic will not be blocked, and a release action may be issued to the access control unit to ensure that subsequent traffic is smoothly forwarded to the server. In other words, the access control unit may forward the access request to the traffic identification unit, which then forwards the access request to the server. After receiving the access request, the server can normally exchange data with the client, and the access control unit may release traffic between the client and the server. If the traffic detection result is a fail, the security detection unit issues a blocking action to the access control unit, which blocks the transmission of subsequent traffic following the access request, i.e., blocks subsequent traffic between the client and the server, and outputs a prompt message to the client, indicating that the client has a traffic security issue.In addition, after completing the traffic security detection based on the traffic characteristics, the security detection unit may also report the traffic detection result to the control device, so that the control device can generate a control instruction for the client based on the traffic detection result. If the traffic detection result is a pass, the control device can generate a traffic release for the client; if the traffic detection result is a fail, the control device can generate a traffic blocking for the client. The control device can then send the control instruction to the access control unit so that the access control unit performs a traffic processing operation for the client. The relevant process can be referred to the description of the aforementioned embodiment and will not be repeated here. Taking the frequency of data packets as an example, after obtaining the frequency or duration of traffic sent by the traffic identification unit, the security detection unit can compare the frequency or duration with preset detection thresholds. For example, if the frequency is greater than or equal to a first preset threshold, the data is considered abnormal; if it is less than the first preset threshold, the data is considered normal. Similarly, if the duration of traffic is greater than or equal to a second preset threshold, the data is considered abnormal; if it is less than the second preset threshold, the data is considered normal. Based on the traffic characteristics, the security detection unit can obtain corresponding traffic detection results, determine the corresponding control actions based on the traffic detection results, and send the control actions to the access control unit, which then executes the control actions on the client. By deploying traffic detection components between the client and the server, there is no need to deploy corresponding traffic diversion devices at the ingress outside the cloud environment, avoiding traffic mirroring and effectively reducing detection costs. Furthermore, by extracting traffic characteristics from traffic information and performing detection based on these characteristics, data transmission volume can be effectively reduced, detection timeliness can be improved, and network bandwidth can be significantly saved. It should be noted that while the above examples use IP addresses, transmission frequency, and traffic duration as examples for illustrative purposes, it is understood that traffic security testing can also be performed based on at least two traffic characteristics to improve the accuracy and security of traffic testing. Furthermore, after obtaining traffic information corresponding to an access request, the access control unit can also detect whether the traffic information contains a corresponding exemption flag. If the traffic information contains an exemption flag, the access request is sent to the server, which then performs the operation corresponding to the access flag. If the traffic information does not contain an exemption flag, traffic security testing can be performed using the aforementioned traffic detection process. Traffic security testing can then be performed on the client based on the exemption flag, ensuring security while reducing interference with whitelisted clients and increasing the flexibility of data interaction.It should be noted that the embodiments of the present disclosure include but are not limited to the above examples. It is understood that those skilled in the art, guided by the concepts of the embodiments of the present disclosure, may further configure the embodiments according to actual needs, and the present disclosure does not impose any restrictions thereon. In the embodiments of the present disclosure, in a cloud computing scenario, a traffic detection component is deployed on the communication link between a client outside the cloud environment and a server within the cloud environment. When data is exchanged between the client and the server, the traffic detection component can obtain access requests sent by the client to the server, then obtain traffic information corresponding to the access requests, perform feature extraction on the traffic information, and obtain traffic features corresponding to the traffic information. The component then performs traffic security detection on the access requests based on the traffic features and performs control operations on the access requests based on the traffic detection results. Deploying the traffic detection component between the client and the server eliminates the need to deploy corresponding traffic diversion equipment at the entrance outside the cloud environment, eliminating the need for traffic diversion, effectively reducing detection costs. Furthermore, by extracting traffic features from the traffic information and performing detection based on the traffic features, the component can effectively reduce data transmission volume, improve detection timeliness, and significantly conserve network bandwidth. In order to enable those skilled in the art to better understand the technical solutions in the embodiments of the present disclosure, the following is an illustrative description using corresponding examples: Referring to FIG3 , a schematic diagram of a communication device provided in an embodiment of the present disclosure is shown, wherein the client may be located outside the cloud environment, and the traffic detection component may be composed of an access control unit, a traffic detection unit, and a security detection unit. The three are communicatively connected in pairs, and the traffic detection unit is connected to the server. Therefore, during the process of detecting traffic, the access control unit may obtain an access request sent by the client to the server, the traffic identification unit may obtain traffic information corresponding to the access request, extract traffic features corresponding to the traffic information, and transmit the traffic features to the security detection unit. The security detection unit performs traffic security detection based on the traffic features and sends the traffic detection results to the access control unit. The access control unit may perform processing operations on the access request based on the traffic detection results, including blocking, forwarding, and alarm prompts. Therefore, by deploying the traffic detection component between the client and the server, on the one hand, there is no need to deploy corresponding traffic diversion equipment at the entrance outside the cloud environment, thus avoiding traffic mirroring and effectively reducing detection costs. On the other hand, by extracting traffic features from the traffic information and performing detection based on the traffic features, It can effectively reduce the amount of data transmission, improve the timeliness of detection, and greatly save network bandwidth.4 , a schematic diagram of an application scenario provided in an embodiment of the present disclosure is shown. In remote office access, when an employee uses a remote office tool outside the cloud to access enterprise resources within the cloud, the remote office tool can send a corresponding access request to a server in the cloud environment to obtain the corresponding enterprise resources. During the access process, the traffic identification unit can obtain traffic information corresponding to the access request, extract traffic characteristics corresponding to the traffic information, and transmit the traffic characteristics to the security detection unit. The security detection unit performs traffic security detection based on the traffic characteristics and sends the traffic detection result to the access control unit. The access control unit can perform processing operations on the access request based on the traffic detection result. If the traffic detection result is a pass, the traffic will not be blocked, and a release action can be issued to the access control unit to ensure that subsequent traffic is smoothly forwarded to the server. In other words, the access control unit can forward the access request to the traffic identification unit, which then forwards the access request to the server. After receiving the access request, the server can normally exchange data with the client. The access control unit can release traffic between the client and the server. If the traffic detection result is a fail, a blocking action is issued to the access control unit to block the transmission of subsequent traffic of the access request and output a prompt message regarding the access request. It should be noted that, for simplicity of description, the method embodiments are described as a series of actions. However, those skilled in the art should understand that the embodiments of the present disclosure are not limited by the order of the actions described, as certain steps may be performed in a different order or simultaneously depending on the embodiments of the present disclosure. Furthermore, those skilled in the art should also understand that the embodiments described in this specification are preferred embodiments, and the actions described are not necessarily required for the embodiments of the present disclosure.5 , there is shown a structural block diagram of a traffic detection component provided in an embodiment of the present disclosure. The traffic detection component 50 is deployed in a cloud environment and includes at least a security detection unit 503, an access control unit 501 deployed in series on a communication link between a client outside the cloud environment and a server in the cloud environment, and a traffic identification unit 502. The security detection unit 503 is deployed in a bypass manner in the cloud environment and is in communication with the access control unit 501 and the traffic identification unit 502. The access control unit 501 is configured to obtain an access request sent by the client to the server. The traffic identification unit 502 is configured to obtain traffic information corresponding to the access request and perform feature extraction on the traffic information to obtain traffic features corresponding to the traffic information. The security detection unit 503 is configured to perform traffic security detection on the access request based on the traffic features. The access control unit 501 is configured to execute management and control operations on the client based on the traffic detection results. In some optional embodiments, the traffic identification unit 502 is specifically configured to: extract at least a corresponding quintuple and application layer data from the traffic information; and perform feature extraction on one of the quintuple and the application layer data to obtain traffic features corresponding to the traffic information. In some optional embodiments, the traffic features include at least one of an IP address, a port number, a protocol type, application layer data content, a packet size, a transmission frequency, and a traffic behavior pattern. In some optional embodiments, the access control unit 501 is specifically configured to: if the traffic detection result is a pass, forward the access request to the traffic identification unit 502, which then forwards the access request to the server and allows subsequent traffic between the client and the server to flow; if the traffic detection result is a fail, block the transmission of the access request, block traffic between the client and the server, and output a prompt message to the client. In some optional embodiments, the traffic identification unit 502 is further configured to: if the traffic information carries an inspection exemption flag, send the access request to the server.In addition, embodiments of the present disclosure further disclose a cloud environment, comprising at least a server and a traffic detection component. The traffic detection component comprises at least a security detection unit, an access control unit deployed in series on a communication link between a client outside the cloud environment and the server in the cloud environment, and a traffic identification unit. The security detection unit is deployed in a bypass manner within the cloud environment and is in communication with the access control unit and the traffic identification unit. The access control unit is configured to obtain an access request sent by the client to the server. The traffic identification unit is configured to obtain traffic information corresponding to the access request and perform feature extraction on the traffic information to obtain traffic characteristics corresponding to the traffic information. The security detection unit is configured to perform traffic security detection on the access request based on the traffic characteristics, and the access control unit is configured to execute control operations on the client based on the traffic detection results. In some optional embodiments, the traffic identification unit is specifically configured to: extract corresponding quintuples and application layer data from the traffic information; and perform feature extraction on one of the quintuples and the application layer data to obtain traffic characteristics corresponding to the traffic information. In some optional embodiments, the traffic characteristics include at least one of an IP address, a port number, a protocol type, application layer data content, a packet size, a transmission frequency, and a traffic behavior pattern. In some optional embodiments, the access control unit is specifically configured to: if the traffic detection result is a pass, forward the access request to the traffic identification unit, which then forwards the access request to the server and allows subsequent traffic between the client and the server to flow; if the traffic detection result is a fail, block the transmission of the access request, block traffic between the client and the server, and output a prompt message to the client. In some optional embodiments, the traffic identification unit is further configured to: if the traffic information carries an exemption flag, send the access request to the server. Since the component embodiment is generally similar to the method embodiment, the description is relatively simple; for relevant details, please refer to the description of the method embodiment. In addition, an embodiment of the present disclosure further provides an electronic device, comprising: a processor, a memory, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, the various processes of the aforementioned network traffic detection method embodiment are implemented, and the same technical effects are achieved. To avoid repetition, these processes are not described here.Furthermore, embodiments of the present disclosure further disclose a computer program product, including a computer program. When executed by a processor, the computer program implements the method described in the embodiments of the present disclosure, implements each process of the aforementioned network traffic detection method embodiment, and achieves the same technical effects. To avoid repetition, these details are not described here. Embodiments of the present disclosure further provide a computer-readable storage medium, storing the computer program. When executed by a processor, the computer program implements each process of the aforementioned network traffic detection method embodiment, and achieves the same technical effects. To avoid repetition, these details are not described here. The computer-readable storage medium may be, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk. Figure 6 is a schematic diagram of the hardware structure of an electronic device implementing various embodiments of the present disclosure. The electronic device 600 includes, but is not limited to, a radio frequency unit 601, a network module 602, an audio output unit 603, an input unit 604, a sensor 605, a display unit 606, a user input unit 607, an interface unit 608, a memory 609, a processor 610, and a power supply 611. Those skilled in the art will appreciate that the electronic device structures described in the embodiments of the present disclosure do not limit the electronic device. An electronic device may include more or fewer components than illustrated, or may combine certain components or arrange the components differently. In the embodiments of the present disclosure, electronic devices include, but are not limited to, mobile phones, tablet computers, laptop computers, PDAs, in-vehicle terminals, wearable devices, and pedometers. It should be understood that in the embodiments of the present disclosure, the radio frequency unit 601 may be used to receive and transmit signals during information transmission or calls. Specifically, it receives downlink data from a base station and transmits it to the processor 610 for processing; in addition, it transmits uplink data to the base station. Typically, the radio frequency unit 601 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, and the like. Furthermore, the radio frequency unit 601 can communicate with a network and other devices via a wireless communication system. The electronic device provides users with wireless broadband Internet access through the network module 602, enabling them to send and receive emails, browse web pages, and access streaming media. The audio output unit 603 can convert audio data received by the radio frequency unit 601 or the network module 602 or stored in the memory 609 into an audio signal and output it as sound.Furthermore, the audio output unit 603 can also provide audio output related to specific functions performed by the electronic device 600 (e.g., call signal reception sound, message reception sound, etc.). The audio output unit 603 includes a speaker, a buzzer, and a receiver. The input unit 604 is used to receive audio or video signals. The input unit 604 may include a graphics processing unit (GPU) 6041 and a microphone 6042. The GPU 6041 processes image data of still images or videos captured by an image capture device (e.g., a camera) in video capture mode or image capture mode. The processed image frames can be displayed on the display unit 606. The image frames processed by the GPU 6041 can be stored in the memory 609 (or other storage medium) or transmitted via the RF unit 601 or the network module 602. The microphone 6042 can receive sound and process such sound into audio data. When in phone call mode, the processed audio data can be converted into a format that can be sent to a mobile communication base station via the radio frequency unit 601. The electronic device 600 also includes at least one sensor 605, such as a light sensor, a motion sensor, or other sensors. Specifically, the light sensor includes an ambient light sensor and a proximity sensor. The ambient light sensor can adjust the brightness of the display panel 6061 based on the brightness of the ambient light, and the proximity sensor can turn off the display panel 6061 and / or the backlight when the electronic device 600 is moved to the ear. An accelerometer, a type of motion sensor, can detect the magnitude of acceleration in all directions (generally three axes) and, when stationary, the magnitude and direction of gravity. This can be used to identify the electronic device's posture (e.g., switching between landscape and portrait modes, related games, magnetometer posture calibration), vibration recognition-related functions (e.g., pedometer, tapping), etc. Sensors 605 may also include fingerprint sensors, pressure sensors, iris sensors, molecular sensors, gyroscopes, barometers, hygrometers, thermometers, infrared sensors, etc., which are not detailed here. The display unit 606 is used to display information input by the user or information provided to the user. The display unit 606 may include a display panel 6061, which may be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), or the like.The user input unit 607 can be used to receive input digital or character information and generate key signal input related to user settings and function control of the electronic device. Specifically, the user input unit 607 includes a touch panel 6071 and other input devices 6072. The touch panel 6071, also known as a touch screen, can collect user touch operations on or near it (for example, operations performed on or near the touch panel 6071 using a finger, stylus, or any other suitable object or accessory). The touch panel 6071 can include two parts: a touch detection device and a touch controller. The touch detection device detects the user's touch direction and the signal generated by the touch operation, and transmits the signal to the touch controller. The touch controller receives the touch information from the touch detection device, converts it into touch point coordinates, and then sends it to the processor 610. It then receives and executes commands sent by the processor 610. Furthermore, the touch panel 6071 can be implemented using various types, such as resistive, capacitive, infrared, and surface acoustic wave. In addition to the touch panel 6071, the user input unit 607 can also include other input devices 6072. Specifically, the other input devices 6072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, on / off keys, etc.), a trackball, a mouse, and a joystick, which are not described in detail here. Furthermore, the touch panel 6071 can be overlaid on the display panel 6061. When the touch panel 6071 detects a touch operation on or near it, it transmits the information to the processor 610 to determine the type of touch event. The processor 610 then provides corresponding visual output on the display panel 6061 based on the type of touch event. It will be appreciated that, in one embodiment, the touch panel 6071 and the display panel 6061 are implemented as two independent components to implement the input and output functions of the electronic device. However, in certain embodiments, the touch panel 6071 and the display panel 6061 may be integrated to implement the input and output functions of the electronic device, and the specific details are not limited here. The interface unit 608 is an interface for connecting external devices to the electronic device 600. For example, the external devices may include a wired or wireless headset port, an external power supply (or battery charger) port, a wired or wireless data port, a memory card port, a port for connecting to a device with an identification module, an audio input / output (I / O) port, a video I / O port, a headphone port, and the like.The interface unit 608 can be used to receive input (e.g., data, power, etc.) from external devices and transmit the received input to one or more components within the electronic device 600, or can be used to transmit data between the electronic device 600 and external devices. The memory 609 can be used to store software programs and various data. The memory 609 may primarily include a program storage area and a data storage area. The program storage area can store an operating system and at least one application required for a function (e.g., sound playback, image playback, etc.); the data storage area can store data generated based on the use of the mobile phone (e.g., audio data, phone book, etc.). Furthermore, the memory 609 may include high-speed random access memory and non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state memory device. The processor 610 is the control center of the electronic device. It connects various components of the electronic device using various interfaces and lines. By running or executing software programs and / or modules stored in the memory 609 and accessing data stored in the memory 609, it performs various functions of the electronic device and processes data, thereby providing overall monitoring of the electronic device. The processor 610 may include one or more processing units. Preferably, the processor 610 may integrate an application processor and a modem processor, wherein the application processor primarily processes the operating system, user interface, and application programs, and the modem processor primarily handles wireless communications. It is understood that the modem processor may not be integrated into the processor 610. The electronic device 600 may also include a power supply 611 (such as a battery) to power various components. Preferably, the power supply 611 may be logically connected to the processor 610 via a power management system, thereby enabling the power management system to manage charging, discharging, and power consumption. In addition, the electronic device 600 includes some functional modules not shown, which will not be described in detail here. It should be noted that, as used herein, the terms "comprise," "include," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a..." does not preclude the presence of additional identical elements in the process, method, article, or apparatus comprising that element.Through the above description of the embodiments, those skilled in the art will clearly understand that the methods of the above embodiments can be implemented using software plus the necessary general-purpose hardware platform. Of course, hardware can also be used, but in many cases the former is the preferred embodiment. Based on this understanding, the technical solution of the present disclosure, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product, stored in a storage medium (such as ROM / RAM, a magnetic disk, or an optical disk), includes instructions for enabling a terminal (which can be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in the various embodiments of the present disclosure. The embodiments of the present disclosure have been described above in conjunction with the accompanying drawings, but the present disclosure is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. With the guidance of this disclosure, those skilled in the art will be able to devise various implementations without departing from the spirit of the present disclosure and the scope of protection of the claims, all of which fall within the scope of protection of the present disclosure. Those skilled in the art will appreciate that the various exemplary units and algorithm steps described in conjunction with the embodiments of the present disclosure can be implemented using electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Professionals skilled in the art may implement the described functions using different methods for each specific application, but such implementations should not be considered beyond the scope of this disclosure. Those skilled in the art will clearly understand that, for ease of description and brevity, the specific operating processes of the systems, devices, and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here. In the embodiments provided in this disclosure, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units described is merely a logical functional division. In actual implementation, other divisions may be used, such as combining or integrating multiple units or components into another system, or some features may be omitted or not implemented. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through interfaces, or indirect coupling or communication connection between devices or units, which may be electrical, mechanical, or other forms. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, ie, may be located in one place or distributed across multiple network units.Some or all of the units can be selected based on actual needs to achieve the objectives of the present embodiment. Furthermore, the functional units in the various embodiments of the present disclosure may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. If the functions are implemented as software functional units and sold or used as independent products, they may be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present disclosure, or the portion that contributes to the prior art, or a portion of the technical solution, may be embodied in the form of a software product. This computer software product, stored in a storage medium, includes instructions for enabling a computer device (such as a personal computer, a server, or a network device) to execute all or part of the steps of the methods described in the various embodiments of the present disclosure. Such storage media include various media capable of storing program code, such as USB flash drives, mobile hard drives, ROM, RAM, magnetic disks, or optical disks. The above description is merely a specific embodiment of the present disclosure, but the scope of protection of the present disclosure is not limited thereto. Any modifications or substitutions that can be readily conceived by a person skilled in the art within the technical scope disclosed herein should be included within the scope of protection of the present disclosure. Therefore, the scope of protection of the present disclosure should be based on the scope of protection of the claims.

Claims

Claims 1. A method for detecting network traffic, wherein: Applied to a traffic detection component deployed in a cloud environment, the method includes: obtaining an access request sent by the client to the server; obtaining traffic information corresponding to the access request, and performing feature extraction on the traffic information to obtain traffic characteristics corresponding to the traffic information; performing traffic security detection on the access request based on the traffic characteristics, and executing control operations on the client based on the traffic detection results.

2. The method according to claim 1, wherein: The traffic detection component includes at least a traffic identification unit. The obtaining of traffic information corresponding to the access request, and performing feature extraction on the traffic information to obtain traffic features corresponding to the traffic information includes: obtaining the traffic information corresponding to the access request through the traffic identification unit, and performing feature extraction on the traffic information to obtain traffic features corresponding to the traffic information.

3. The method according to claim 1 or 2, wherein: The feature extraction of the flow information to obtain the flow characteristics corresponding to the flow information includes: extracting at least one of a quintuple and application layer data from the flow information; and feature extraction of at least one of the quintuple and application layer data to obtain the flow characteristics corresponding to the flow information.

4. The method according to any one of claims 1 to 3, wherein: The traffic characteristics include at least one of an IP address, a port number, a protocol type, application layer data content, a data packet size, a sending frequency, and a traffic behavior pattern.

5. The method according to any one of claims 1 to 3, wherein: The traffic detection component includes at least an access control unit and a security detection unit that is communicatively connected to the access control unit and the traffic identification unit respectively. The access control unit and the traffic identification unit are deployed in series on the communication link. The traffic security detection is performed on the access request according to the traffic characteristics, and the management and control operations for the client are executed according to the traffic detection results, including: performing traffic security detection on the access request according to the traffic characteristics by the security detection unit to generate a traffic detection result for the client; and executing management and control operations corresponding to the traffic detection result by the access control unit.

6. The method according to claim 5, wherein: The execution of the control operation corresponding to the traffic detection result includes: if the traffic detection result is passed, forwarding the access request to the traffic identification unit, forwarding the access request to the server through the traffic identification unit, and allowing subsequent traffic between the client and the server; if the traffic detection result is failed, blocking the transmission of the access request, blocking the traffic between the client and the server, and outputting a prompt message for the client, wherein the prompt message is information that prompts the client that there is a traffic security problem.

7. The method according to claim 5 or 6, wherein: It also includes: reporting the traffic detection result to the control device through the security detection unit, the traffic detection result is used to instruct the control device to generate a control instruction for the client, and the control instruction includes one of traffic release or traffic blocking.

8. The method according to any one of claims 5 to 7, wherein: After acquiring the traffic information corresponding to the access request, the method further includes: If the traffic information carries an inspection exemption flag, the traffic between the client and the server is allowed to pass through the access control unit.

9. A cloud environment, wherein: The cloud environment includes at least a server and a traffic detection component, and the traffic detection component includes at least a security detection unit, an access control unit deployed in series on a communication link between a client outside the cloud environment and a server in the cloud environment, and a traffic identification unit; wherein the security detection unit is deployed in a bypass manner in the cloud environment and is in communication connection with the access control unit and the traffic identification unit; wherein the access control unit is used to obtain an access request sent by the client to the server; the traffic identification unit is used to obtain traffic information corresponding to the access request, and perform feature extraction on the traffic information to obtain traffic features corresponding to the traffic information; the security detection unit is used to perform traffic security detection on the access request based on the traffic features, and the access control unit is used to perform management and control operations on the client based on the traffic detection results.

10. A flow detection component, wherein: The traffic detection component is deployed in a cloud environment, and the traffic detection component includes at least a security detection unit, an access control unit deployed in series on a communication link between a client outside the cloud environment and a server in the cloud environment, and a traffic identification unit; wherein the security detection unit is deployed in a bypass manner in the cloud environment and is communicatively connected with the access control unit and the traffic identification unit; wherein the access control unit is used to obtain an access request sent by the client to the server; the traffic identification unit is used to obtain traffic information corresponding to the access request, and perform feature extraction on the traffic information to obtain traffic features corresponding to the traffic information; the security detection unit is used to perform traffic security detection on the access request based on the traffic features, and the access control unit is used to execute management and control operations on the client based on the traffic detection results.

11. An electronic device, wherein The system comprises a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus; the memory is used to store computer programs; and the processor is used to implement the method according to any one of claims 1 to 8 when executing the program stored in the memory.

12. A computer-readable storage medium having instructions stored thereon, which, when executed by one or more processors, cause the processors to perform the method according to any one of claims 1 to 8.

13. A computer program product comprising a computer program, wherein: When the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.