Method and apparatus for processing traffic data
By introducing network processor (NP) devices and probe devices into the traffic analysis system, the header information of encrypted traffic data packets is identified and compressed to generate spliced data packets. This solves the problems of increased server quantity and data loss in the traffic analysis system, and achieves performance improvement and data integrity assurance.
Patent Information
- Application Number
- PCT/CN2025/102224
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-05
- Filing Date
- 2025-06-19
- Publication Date
- 2026-01-08
AI Technical Summary
When dealing with a significant increase in network traffic, existing traffic analysis systems require an increase in the number of servers to ensure stability and performance, leading to increased costs for operators. At the same time, reducing the number of XDR documents may result in data loss and affect user experience.
By introducing network processor (NP) devices and probe devices into the traffic analysis system, the header information of encrypted traffic data packets is identified and compressed to generate spliced data packets, which are then sent to the probe devices for analysis. This offloads the server's computing tasks, ensuring data integrity and improving performance.
Without increasing the number of servers, improve the performance and data integrity of the traffic analysis system, reduce reliance on servers, and ensure uninterrupted business requirements.
Smart Images

Figure CN2025102224_08012026_PF_FP_ABST
Abstract
Description
Method and device for processing traffic data
[0001] The present application claims priority to the Chinese patent application No. 202410909869.1, filed on July 5, 2024, and entitled "Method and device for processing traffic data", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0002] The present application relates to the field of network communication, and in particular to a method and device for processing traffic data. BACKGROUND
[0003] With the continuous development of network technology, the types of applications and services provided by the network have been greatly enriched. At the same time, the diversification of services and the increasing number of users have led to a significant increase in network traffic, and with the advent of the 5G era, the growth rate of traffic has become even more rapid.
[0004] Traditional traffic analysis systems (such as Customer Experience Management (CEM) systems) are usually composed of collection devices and servers. First, the collection devices collect traffic in the network and perform identification and analysis to generate XDR invoices. Then, the invoices XDR are reported to the server. Further, the server calculates and stores the data in the invoices XDR, and finally generates reports related to customer experience. Therefore, with the significant increase in network traffic, the number of servers (such as CEM platform servers) in the traffic analysis system (such as CEM system) needs to be increased to ensure the stability and performance of the traffic analysis system in processing traffic data, which undoubtedly increases the investment pressure and cost of operators in the field of service experience.
[0005] The solution of the prior art is to reduce the number of invoices XDR to reduce the processing load of the platform server in the traffic analysis system, thereby improving the performance of the traffic analysis system in processing traffic data. At the same time, the reduction in the number of invoices XDR can also reduce the number of platform servers in the traffic analysis system to reduce costs.
[0006] However, this method of reducing the number of bill XDRs can cause the user's data to be lost, especially in the scenario of customer complaints, and the loss of bills can cause the corresponding problem bill of the complaint to be unable to be queried, thereby causing the user's dissatisfaction and poor service experience. Therefore, a technical solution for traffic data processing is needed, which can improve the performance of the traffic analysis system while reducing the dependence of the traffic analysis system on the number of servers, and also ensure the integrity of the data in the process of traffic data processing, thereby improving the performance of the traffic analysis system (such as the CEM system) in processing traffic data without increasing the number of servers, controlling costs, and also ensuring that the traffic analysis system does not lose bills in the process of traffic data processing, to meet the lossless business requirements of the traffic analysis system. SUMMARY
[0007] The embodiments of the present application provide a method and device for processing traffic data, which can improve the performance of the traffic analysis system, reduce the dependence of the traffic analysis system on the number of servers, and also ensure the integrity of the traffic data.
[0008] In a first aspect, the embodiments of the present application provide a method for processing traffic data, applied to a network processor (NP) device in a traffic analysis system, which can also include a probe device; the method can include:
[0009] receiving a first data packet and identifying whether the first data packet is a target data packet using a target encryption protocol; if so, intercepting the header information of the target data packet; concatenating the header information of N target data packets into a concatenated data packet, N being a positive integer greater than 1; sending the concatenated data packet to the probe device, the concatenated data packet being used by the probe device for traffic analysis.
[0010] A conventional traffic analysis system (for example, a customer experience management (CEM) system) is usually composed of a collection device and a server. In the process of traffic data processing, the traffic in a network is first collected by the collection device, and then identified and parsed to generate XDR detailed lists. The XDR detailed lists are then reported to the server. Further, the data in the XDR detailed lists are calculated and stored by the server, and finally, reports related to customer experience are generated. Therefore, with a substantial increase in network traffic, the number of servers (for example, CEM platform servers) in the traffic analysis system needs to be increased to ensure the stability and performance of the traffic analysis system in processing traffic data, which undoubtedly increases the investment pressure and cost of operators in the field of service experience. The existing solution is to reduce the number of XDRs by, for example, setting filtering rules or sampling in the collection device, to reduce the processing load of the servers in the traffic analysis system, to improve the performance of the traffic analysis system in processing traffic data, and to reduce the number of servers required in the traffic analysis system to reduce costs. However, the above method of reducing the number of XDRs sacrifices the integrity of the data to improve the performance of the traffic analysis system in processing traffic data, which may result in the loss of user data, especially in the context of customer complaints. The loss of detailed lists may result in the inability to query the corresponding problem detailed lists, thereby causing user dissatisfaction and poor service experience. Therefore, to solve the technical problem, the embodiments of the present application can add a network processor (NP) device and a probe device to the traffic analysis system to perform specific compression and decompression preprocessing on network traffic data, thereby offloading part of the computing tasks of the servers in the traffic analysis system to reduce the processing load of the server side, improving the performance of the traffic analysis system in processing traffic data, reducing the dependence of the traffic analysis system on the number of servers, and ensuring the integrity of the traffic data to meet the lossless service requirements of the traffic analysis system. Specifically, in the method for processing traffic data provided by the embodiments of the present application, the encrypted traffic data packets (i.e., target data packets) in the network traffic data (i.e., first data packets) are first identified by the network processor (NP) device, and then the header information of the encrypted traffic data packets is intercepted for compression, that is, the header information of the intercepted N encrypted traffic data packets is spliced into a spliced data packet. Finally, the spliced data packet is sent to the probe device by the network processor (NP) device for traffic analysis.Since the flow analysis system usually only needs to analyze the header information of the encrypted traffic data packets (i.e., target data packets), the spliced data packets containing only the header information of the encrypted traffic data packets are sent to the probe device for flow analysis, which can ensure the integrity of data in the flow analysis system and effectively reduce the PPS of the traffic data packets sent by the network processor NP device to the probe device, thereby reducing the processing load of the subsequent probe device and improving the performance of the flow analysis system in processing traffic data. Meanwhile, through the specific compression and decompression preprocessing of the network processor NP device and the probe device on the traffic data, part of the computing tasks of the server in the flow analysis system can be unloaded to reduce the processing load of the server in the flow analysis system, so that the performance of the flow analysis system is improved, and the dependence of the flow analysis system on the number of servers is reduced, thereby improving the performance of the flow analysis system in processing traffic data without increasing the number of servers and controlling the cost.
[0011] In a possible implementation, the identifying whether the first data packet is a target data packet using a target encryption protocol can include: judging whether a port number of the first data packet matches a preset port number; if yes, determining that the first data packet is the target data packet using the target encryption protocol; and if no, determining that the first data packet is a second data packet not using the encryption protocol. According to the embodiment of the present application, whether the network traffic data (i.e., the first data packet) received by the network processor NP device matches the preset port number is judged to determine whether the first data packet is a target data packet using a target encryption protocol. Further, when the port number of the first data packet matches the preset port number, it is determined that the first data packet is a target data packet using a target encryption protocol; and when the port number of the first data packet does not match the preset port number, it is determined that the first data packet is a second data packet not using a target encryption protocol. Through the embodiment of the present application, the efficiency and accuracy of the network processor NP device in identifying encrypted traffic (i.e., target data packets) can be effectively improved, so that the subsequent network processor NP device can perform compression traffic processing on the encrypted traffic.
[0012] In a possible implementation, the first data packet can include packet header information and a packet body; and the method further includes: if it is identified that the first data packet is the target data packet using the target encryption protocol, determining whether the packet body of the target data packet is an encrypted message; if the packet body of the target data packet is the encrypted message, determining that the target data packet is an encrypted data packet using the target encryption protocol; and if the packet body of the target data packet is a non-encrypted message, determining that the target data packet is a payload data packet using the target encryption protocol. According to the embodiment, since analyzing the complete information of the payload data packet (i.e., the data packet without payload data) is very important for the traffic analysis system to determine the network connection state and perform security detection, if the network processor NP device identifies that the first data packet is the target data packet using the target encryption protocol through the packet header information, the network processor NP device can further determine whether the target data packet is the payload data packet using the encryption protocol by judging whether the packet body of the target data packet is the encrypted message. Specifically, if the packet body of the target data packet is the encrypted message, it is determined that the target data packet is the encrypted data packet using the target encryption protocol; and if the packet body of the target data packet is the non-encrypted message, it is determined that the target data packet is the payload data packet using the target encryption protocol. According to the embodiment, the payload data packet using the target encryption protocol in the target data packet can be effectively identified, so that the network processor NP device can send the original data packet of the payload data packet to the probe device for more accurate traffic data analysis while performing the compressed traffic processing on the target data packet (which can include the payload data packet), thereby improving the security and performance of the traffic analysis system.
[0013] In a possible implementation, the method further includes: if it is determined that the first data packet is the target data packet using the target encryption protocol, determining the target encryption protocol type used by the target data packet according to the port number and the port type of the target data packet. According to the embodiment, the target data packet using the target encryption protocol can be identified through port matching, and the target encryption protocol type used by the target data packet can be further determined according to the port number and the port type of the target data packet. For example, when the target data packet is UDP PORT=443, it is determined that the target encryption protocol type used by the target data packet is the Quic protocol; and when the target data packet is UDP PORT=443, it is determined that the target encryption protocol type used by the target data packet is the TLS protocol or the SSL protocol. According to the embodiment, the target encryption protocol type used by the target data packet can be quickly and accurately identified, so as to subsequently determine, according to the target encryption protocol type, whether the packet body of the target data packet is the encrypted message.
[0014] In a possible implementation, the determining whether the packet body of the target data packet is an encrypted message can include: identifying whether the target data packet is a preset message; if yes, determining that the packet body of the target data packet is the non-encrypted message; and if no, determining that the packet body of the target data packet is the encrypted message. According to the embodiment of the present application, whether the target data packet using the target encryption protocol is a preset message is identified, to determine whether the packet body of the target data packet is an encrypted message. Specifically, if it is identified that the target data packet is a preset message, it is determined that the packet body of the target data packet is a non-encrypted message; and if it is identified that the target data packet is not a preset message, it is determined that the packet body of the target data packet is an encrypted message. According to the embodiment of the present application, the network processor NP device can simply and efficiently identify whether the packet body of the target data packet using the target encryption protocol is an encrypted message, to determine whether the target data packet is a payload packet, so as to send the original data packet of the payload packet to the probe device for more accurate traffic data analysis while performing traffic compression processing on the target data packet (including the payload packet) using the target encryption protocol, thereby improving the security and performance of the traffic analysis system.
[0015] In a possible implementation, the target encryption protocols used by the target data packets are different, and the corresponding preset messages are different. According to the embodiment of the present application, for the target data packets using different target encryption protocols (for example, Quic and TLS / SSL), the corresponding preset messages used to determine whether the packet body of the target data packet is an encrypted message are also different. For example, for the data packet using the Quic protocol, the preset message can be an initial message; and for the data packet using the TLS / SSL protocol, the preset message can be a client-side Client Hello or server-side Server Hello message. According to the embodiment of the present application, the network processor NP device can quickly and accurately determine whether the packet body of the target data packet using different target encryption protocol types is an encrypted message, to determine whether the target data packet is a payload packet, so as to send the original data packet of the payload packet to the probe device for more accurate traffic data analysis while performing traffic compression processing on the target data packet (including the payload packet) using the target encryption protocol, thereby improving the security and performance of the traffic analysis system.
[0016] In a possible implementation, the network processor NP device comprises one or more packet assembly circular queues, and the method further comprises: distributing the packet header information to a corresponding packet assembly circular queue according to a mobile terminal internet protocol address MSIP in the packet header information. In the network processor NP device, one or more packet assembly circular queues can be included, each of which can correspond to one or more mobile terminal internet protocol addresses MSIP. The packet header information of the intercepted target data packet is distributed to the corresponding packet assembly circular queue according to the corresponding mobile terminal internet protocol address MSIP, and is processed in the corresponding packet assembly circular queue. In this way, the network processor NP device can realize shunting and specialized processing of the packet header information of the encrypted traffic data (i.e., the target data packet) of different mobile terminals through different packet assembly circular queues, which is beneficial to providing more accurate traffic analysis documents when the probe device processes the data packets output by different packet assembly circular queues. Meanwhile, the packet header information of the encrypted traffic data (i.e., the target data packet) can be processed in a concurrent manner through the packet assembly circular queue, so as to improve the efficiency of the network processor NP device in processing traffic data, thereby improving the overall processing performance of the traffic analysis system. It should be noted that in some embodiments, a large number of threads for processing packet header information can be included in the network processor NP device, and one or more packet assembly circular queues can be included in each thread, so that each thread can concurrently receive the packet header information of the target data packet and distribute the packet header information to the corresponding packet assembly circular queue in each thread, so as to further improve the efficiency of the network processor NP device in processing traffic data. The embodiments of the present application are not limited in this regard.
[0017] In a possible implementation, the step of splicing the packet header information of the N target data packets into a spliced data packet can comprise: when the target packet assembly circular queue receives the packet header information of the N target data packets, the packet header information of the N target data packets is spliced into the spliced data packet, and N is a positive integer greater than 1. In the case where the target packet assembly circular queue receives the packet header information of the N target data packets, the packet header information of the N target data packets is spliced into a spliced data packet. In this way, the network processor NP device can improve the efficiency of generating a spliced data packet through multiple packet assembly circular queues, accelerate the processing speed of the network processor NP device in processing traffic data, and improve the overall performance of the traffic analysis system.
[0018] In a possible implementation, the step of splicing the packet header information of the N target data packets into the spliced data packet can include: splicing the received packet header information of the N target data packets to generate a to-be-encapsulated packet body of the spliced data packet; and encapsulating the to-be-encapsulated packet body based on a communication protocol between the network processor NP device and the probe device to generate the spliced data packet. In this embodiment of the application, the step of how to splice the packet header information of the N target data packets into a spliced data packet can specifically include: first splicing the packet header information of the N target data packets received by the network processor NP device to generate a to-be-encapsulated packet body of the spliced data packet; and then encapsulating the generated to-be-encapsulated packet body based on a communication protocol between the network processor NP device and the probe device to generate the encapsulated spliced data packet. Through this embodiment of the application, the packet header information of the target data packets that can be used for traffic analysis and intercepted by the network processor NP device can be compressed according to a specific compression rule (that is, the packet header information of the N target data packets forms a spliced data packet), the integrity of the traffic data is ensured, and at the same time, the PPS of the traffic data packets at the export of the network processor NP device can be reduced to reduce the processing load of the subsequent probe device, thereby improving the performance of the traffic analysis system. At the same time, the to-be-encapsulated packet body formed by the packet header information of the N target data packets is encapsulated according to the communication protocol between the network processor NP device and the probe device, which can improve the security and reliability of the network processor NP device in sending the spliced data packet to the probe device, thereby further improving the performance and stability of the traffic analysis system.
[0019] In a possible implementation, the encapsulating the to-be-encapsulated packet body to generate the spliced data packet can include: modifying a value of a target field in encapsulation packet header information to a number of data packets encapsulated in the spliced data packet, and modifying a target address in the encapsulation packet header information to an address of a corresponding thread in the probe device to which the spliced data packet is sent; and adding the modified encapsulation packet header information to the to-be-encapsulated packet body to generate the spliced data packet. In the embodiment of the application, how to encapsulate the to-be-encapsulated packet body composed of packet header information of N target data packets to generate a spliced data packet can include the following steps: first, modifying a value of a target field in encapsulation packet header information used for encapsulating the to-be-encapsulated packet body to a number of data packets encapsulated in the spliced data packet (for example, the first four bytes of a DSTMAC field of a MAC address in the encapsulation packet header information can be modified to MagicNum to indicate the number of encapsulated packets), and modifying a target address (for example, a target IP address) in the encapsulation packet header information to an address of a corresponding thread in the probe device to which the spliced data packet is sent; and further, adding the modified encapsulation packet header information to the to-be-encapsulated packet body to generate a spliced data packet. According to the embodiment of the application, the target field in the encapsulation packet header information of the spliced data packet can reflect the number of data packets encapsulated in the spliced data packet, so that the probe device can determine whether the data packet is a spliced data packet by identifying the target field after receiving the data packet. Meanwhile, the target address in the encapsulation packet header information of the spliced data packet can be used to indicate the address of the thread in the probe device processing the spliced data packet, so that the probe device can send the spliced data packet to the corresponding thread for processing by identifying the target address, thereby effectively improving the processing efficiency and response speed of the probe device to improve the overall performance of the traffic analysis system.
[0020] In a possible implementation, the method further includes: if it is determined that the first data packet is the second data packet that does not use the target encryption protocol, sending the second data packet to the probe device. According to the embodiment of the application, the network processor (NP) device sends the data packet (that is, the second data packet) that does not use the target encryption protocol directly to the probe device, so that the probe device can not only analyze the packet header information of the encrypted traffic data packet (that is, the target data packet) in the network traffic, but also perform traffic analysis on the original unencrypted data packet (that is, the second data packet) in the network traffic, thereby further ensuring the integrity of data in the traffic analysis system and facilitating the probe device to perform more accurate and comprehensive traffic analysis to improve the performance of the traffic analysis system.
[0021] In a possible implementation, the method further includes: if it is determined that the target data packet is the payload packet using the target encryption protocol, sending the payload packet to the probe device. According to the embodiments of the present application, the payload packet (i.e., the data packet without payload data) using the target encryption protocol identified by the network processor (NP) device can be directly sent to the probe device, so that the probe device can more accurately analyze the complete information of the payload packet to determine the network connection state between the network processor (NP) device and the probe device and perform security detection, thereby further improving the security and performance of the traffic analysis system.
[0022] In a second aspect, the embodiments of the present application provide a method for processing flow data, which is applied to a probe device in a flow analysis system, and the system can further include a network processor (NP) device. The method can include: receiving a third data packet sent by the network processor (NP) device, wherein the third data packet includes a spliced data packet, a second data packet and a static payload packet; identifying whether the third data packet is the spliced data packet; if yes, splitting the spliced data packet into N fourth data packets, wherein the fourth data packet includes the header information of a target data packet corresponding to the spliced data packet; and generating a flow table based on the quintuple information of the fourth data packet, wherein the quintuple information includes the source address, the source port, the target address, the target port and the transmission layer protocol of the fourth data packet. According to the embodiments of the present application, the probe device receives various types of network flow data packets (i.e., third data packets) sent by the network processor (NP) device, which can include a spliced data packet composed of the header information of N target data packets, a second data packet without using a target encryption protocol, and a static payload packet using a target encryption protocol. Then, the third data packet is identified to determine whether the third data packet is a spliced data packet. Further, since the probe device cannot directly analyze the header information of N first data packets encapsulated in the spliced data packet, the spliced data packet is split to generate N fourth data packets containing the header information of encrypted flow data packets (i.e., target data packets) when the third data packet is identified as a spliced data packet, which ensures the integrity of flow data and facilitates the probe device to analyze network flow by analyzing the fourth data packet. Further, the probe device classifies the fourth data packet according to the quintuple information (which can include the source address, the source port, the target address, the target port and the transmission layer protocol of the fourth data packet) in each fourth data packet to generate a flow table, so that the probe device can subsequently perform more accurate flow analysis on the same type of fourth data packet and generate a bill, thereby improving the overall performance of the flow analysis system (such as a CEM system). According to the embodiments of the present application, compressed encrypted flow data (i.e., spliced data packets) can be identified and preprocessed by decompression, that is, the spliced data packet is split and restored to generate a fourth data packet including the header information of the corresponding target data packet, to ensure the integrity of the data available for flow analysis. Then, the fourth data packet is classified to generate a flow table, thereby improving the efficiency and accuracy of flow analysis of the probe device and improving the overall performance of the flow analysis system.Meanwhile, through the pre-processing of the specific compression and decompression of the traffic data by the network processor NP device and the probe device, part of the computing tasks of the server in the traffic analysis system can be offloaded to reduce the processing load of the server in the traffic analysis system, so that the performance of the traffic analysis system is improved, and the dependence of the traffic analysis system on the number of servers is reduced, thereby improving the performance of the traffic analysis system in processing traffic data without increasing the number of servers and controlling the cost.
[0023] In a possible implementation, the identifying whether the third data packet is the splicing data packet can include: judging whether a value of a target field in the third data packet satisfies a preset condition, the value of the target field being used to indicate a number of data packets contained in the third data packet; if the value of the target field satisfies the preset condition, determining that the third data packet is the splicing data packet; and if the value of the target field does not satisfy the preset condition, determining that the third data packet is the second data packet or the static payload packet. According to the embodiment of the present application, how to identify whether the third data packet received by the probe device is the splicing data packet can include: since the value of the target field (for example, the first 4 bytes of the DSTMAC field of the MAC address) in the encapsulation packet header information of the splicing data packet has been modified to the number of data packets encapsulated in the splicing data packet, and the value of the target field of the second data packet and the static payload packet that are not splicing data packets is 1, whether the third data packet is the splicing data packet can be judged by judging whether the value of the target field in the third data packet, which is used to indicate the number of data packets contained in the third data packet, satisfies a preset condition (for example, greater than 1 and less than 20). If the value of the target field satisfies the preset condition, it is determined that the third data packet is the splicing data packet; and if the value of the target field does not satisfy the preset condition, it is determined that the third data packet is the second data packet that does not use the target encryption protocol or the static payload packet that uses the target encryption protocol. Through the embodiment of the present application, the probe device can accurately and quickly identify whether the received third data packet is the splicing data packet, so that the probe device can subsequently perform corresponding processing on different types of data packets, thereby improving the accuracy of the traffic analysis result and improving the performance of the traffic analysis system.
[0024] In a possible implementation, the probe device includes one or more threads, and the threads correspond to the packet assembly loop queues in the network processor NP device one by one, and the method further includes: if the third data packet is identified as the splicing data packet, distributing the splicing data packet to the corresponding thread based on the target address of the splicing data packet. According to the embodiment of the application, because the one or more threads in the probe device correspond to the packet assembly loop queues in the network processor NP device one by one, and the target address in the encapsulation packet header information of the splicing data packet is modified to the address of the corresponding thread in the probe device when the splicing data packet is encapsulated through the packet assembly loop queues in the network processor NP device, the splicing data packet can be distributed to the corresponding thread for processing through the target address in the encapsulation packet header information of the splicing data packet in the case that the third data packet is identified as the splicing data packet, so that the probe device can process multiple different types of data streams (that is, splicing data packets) in parallel, thereby improving the processing efficiency of the probe device, reducing the processing delay, and improving the performance and stability of the traffic analysis system.
[0025] In a possible implementation, each of the threads corresponds to a transceiving packet queue, and the splitting the splicing data packet into N fourth data packets can include: when the target thread receives the splicing data packet, splitting the received splicing data packet into N fourth data packets through the transceiving packet queue. According to the embodiment of the application, when the target thread in the probe device receives the splicing data packet, the splicing data packet can be split into N fourth data packets containing the packet header information of the encrypted traffic data packet (that is, the target data packet) through the corresponding transceiving packet queue, so that the probe device can process a large number of splicing data packets through the corresponding transceiving packet queue of the multiple threads, thereby improving the efficiency of the probe device in processing the splicing data packet, and improving the processing performance of the traffic analysis system.
[0026] In a possible implementation, the generating the flow table based on the quintuple information of the fourth data packet can include: calculating a corresponding Hash value based on the quintuple information of each fourth data packet; and determining a Hash table entry matched with the fourth data packet based on the calculated Hash value, to generate the flow table. In the embodiments of the present application, the steps of how the probe device generates the flow table based on the quintuple information of the fourth data packet split from the spliced data packet can specifically include: first, calculating a corresponding Hash value of each fourth data packet based on the quintuple information (which can include the source address, source port, target address, target port, and transmission layer protocol of the fourth data packet) of the fourth data packet; and then, matching the calculated Hash value with a pre-established Hash table to determine a Hash table entry matched with the fourth data packet, to generate the flow table. Through the embodiments of the present application, the efficiency and accuracy of the probe device in flow classification can be improved, so that more accurate flow analysis can be performed on the generated flow table, to improve the performance of the flow analysis system.
[0027] In a possible implementation, the method further includes: calculating a pipeline indicator and an experience indicator of the fourth data packet based on the information of the flow table, to generate a first bill of XDR. In the embodiments of the present application, the information in the generated flow table is used to calculate the fourth data packets of different flows according to a corresponding pre-defined algorithm, to generate a bill of XDR (that is, the first bill of XDR) containing pipeline information (such as delay, packet loss rate, bandwidth utilization rate, and the like) and experience indicators (such as response time and the like), so that the subsequent server can directly analyze and generate a report on the generated first bill of XDR, to reduce the processing burden of the server, improve the efficiency, and reduce the dependence of the flow analysis system on the number of servers, to improve the performance of the flow analysis system (such as the CEM system) in processing flow data without increasing the number of servers and controlling the cost.
[0028] In a possible implementation, the method further includes: if it is identified that the third data packet is not the spliced data packet, calculating a pipe index and an experience index of the third data packet to generate a second invoice XDR. According to the embodiment of the application, the pipe index and the experience index are calculated for the third data packet identified as not being the spliced data packet, that is, the second data packet not using the target encryption protocol or the payload packet using the target encryption protocol, to generate the second invoice XDR containing the pipe information (such as delay, packet loss rate, bandwidth utilization rate, and the like) and the experience index (such as response time and the like), so that the probe device can analyze all the traffic data sent by the network processor NP device, to ensure the integrity of the traffic data in the traffic analysis system (for example, the CEM system), to improve the accuracy and comprehensiveness of the traffic analysis result, to meet the lossless service requirement of the traffic analysis system, and to help the operator improve the service management quality according to the traffic analysis result, thereby improving the user satisfaction.
[0029] In a possible implementation, the system further includes a server, and the method further includes: sending the first invoice XDR and / or the second invoice XDR to the server, where the first invoice XDR and / or the second invoice XDR are used for the server to perform data analysis and generate a report. According to the embodiment of the application, the probe device can send the complete invoice XDR (including the first invoice XDR and / or the second invoice XDR) to the server, so that the server (for example, the CEM platform server) can perform data analysis and generate a report (for example, a report related to customer experience) according to the invoice XDR, so that the operator can improve the service management quality according to the report, thereby improving the user satisfaction.
[0030] In a third aspect, the embodiment of the application provides a network processor NP device applied to a traffic analysis system, and the network processor NP device can include:
[0031] a receiving unit configured to receive a first data packet;
[0032] an identifying unit configured to identify whether the first data packet is a target data packet using a target encryption protocol;
[0033] a packet intercepting unit configured to intercept header information of the target data packet if it is identified that the first data packet is the target data packet using the target encryption protocol;
[0034] a packet splicing unit configured to splice the header information of N target data packets into one spliced data packet, where N is a positive integer greater than 1;
[0035] a first sending unit configured to send the spliced data packet to the probe device, where the spliced data packet is used for the probe device to perform traffic analysis.
[0036] In a possible implementation, the identifying unit is specifically configured to:
[0037] determine whether the port number of the first data packet matches a preset port number;
[0038] if yes, determine that the first data packet is the target data packet using the target encryption protocol;
[0039] if no, determine that the first data packet is a second data packet not using the encryption protocol.
[0040] In a possible implementation, the first data packet includes packet header information and a packet body; and the network processor NP device further includes:
[0041] a judging unit, configured to, if it is identified that the first data packet is the target data packet using the target encryption protocol, judge whether the packet body of the target data packet is an encrypted message;
[0042] a first determining unit, configured to, if the packet body of the target data packet is the encrypted message, determine that the target data packet is an encrypted data packet using the target encryption protocol;
[0043] a second determining unit, configured to, if the packet body of the target data packet is a non-encrypted message, determine that the target data packet is a payload packet using the target encryption protocol.
[0044] In a possible implementation, the judging unit is specifically configured to:
[0045] identify whether the target data packet is a preset message;
[0046] if yes, determine that the packet body of the target data packet is the non-encrypted message; and if no, determine that the packet body of the target data packet is the encrypted message.
[0047] In a possible implementation, the network processor NP device includes one or more packet assembly circular queues; and the network processor NP device further includes:
[0048] a distributing unit, configured to distribute the packet header information to a corresponding packet assembly circular queue according to a mobile terminal internet protocol address MSIP in the packet header information.
[0049] In a possible implementation, the packet assembly unit is specifically configured to:
[0050] when a target packet assembly circular queue receives N pieces of packet header information of the target data packet, splice the N pieces of packet header information of the target data packet into the spliced data packet, N being a positive integer greater than 1.
[0051] In one possible implementation, the packet assembly unit is specifically used for:
[0052] The header information of the received N target data packets is concatenated to generate the packet body to be encapsulated from the concatenated data packets;
[0053] Based on the communication protocol between the network processor NP device and the probe device, the packet to be encapsulated is encapsulated to generate the spliced data packet.
[0054] In one possible implementation, the packet assembly unit is specifically used for:
[0055] The value of the target field in the encapsulation header information is modified to the number of data packets encapsulated in the spliced data packet, and the target address in the encapsulation header information is modified to the address of the thread corresponding to which the spliced data packet is sent in the probe device;
[0056] The modified encapsulation header information is added to the packet body to be encapsulated to generate the spliced data packet.
[0057] In one possible implementation, the network processor NP device further includes:
[0058] The second sending unit is configured to send the second data packet to the probe device if it is determined that the first data packet is the second data packet that does not use the target encryption protocol.
[0059] In one possible implementation, the network processor NP device further includes:
[0060] The third sending unit is configured to send the static payload to the probe device if it is determined that the target data packet is the static payload using the target encryption protocol.
[0061] Fourthly, embodiments of this application provide a probe device for use in a flow analysis system, the probe device comprising:
[0062] The receiving unit is used to receive a third data packet sent by the network processor NP device, the third data packet including a spliced data packet, a second data packet and a static payload;
[0063] The identification unit is used to identify whether the third data packet is the spliced data packet;
[0064] The packet splitting unit is used to split the concatenated data packet into N fourth data packets if the third data packet is identified as the concatenated data packet. The fourth data packets include the header information of the target data packet corresponding to the concatenated data packet.
[0065] a flow table generating unit, configured to generate a flow table based on five-tuple information of the fourth data packet, the five-tuple information comprising a source address, a source port, a target address, a target port, and a transport layer protocol of the fourth data packet.
[0066] In a possible implementation, the identifying unit is specifically configured to:
[0067] determine whether a value of a target field in the third data packet satisfies a preset condition, the value of the target field being used to indicate a data packet number contained in the third data packet;
[0068] if the value of the target field satisfies the preset condition, determine that the third data packet is the spliced data packet;
[0069] if the value of the target field does not satisfy the preset condition, determine that the third data packet is the second data packet or the payload packet.
[0070] In a possible implementation, the probe device comprises one or more threads, and the threads correspond to packet assembly loop queues in the network processor NP device in a one-to-one manner. The probe device further comprises:
[0071] a distribution unit, configured to, if it is identified that the third data packet is the spliced data packet, distribute the spliced data packet to a corresponding thread based on a target address of the spliced data packet.
[0072] In a possible implementation, each of the threads corresponds to a packet receiving and sending queue. The packet disassembling unit is specifically configured to:
[0073] when the target thread receives the spliced data packet, disassemble the received spliced data packet into N fourth data packets through the packet receiving and sending queue.
[0074] In a possible implementation, the flow table generating unit is specifically configured to:
[0075] calculate a corresponding hash value based on the five-tuple information of each fourth data packet;
[0076] determine a hash table entry matched with the fourth data packet based on the calculated hash value, to generate the flow table.
[0077] In a possible implementation, the probe device further comprises:
[0078] a first bill generating unit, configured to calculate a pipe index and an experience index of the fourth data packet based on information of the flow table, to generate a first bill XDR.
[0079] In a possible implementation, the probe device further includes:
[0080] The second slip generation unit is configured to, if it is identified that the third data packet is not the spliced data packet, calculate a pipe index and an experience index of the third data packet to generate a second slip XDR.
[0081] In a possible implementation, the system further includes a server; and the probe device further includes:
[0082] The sending unit is configured to send the first slip XDR and / or the second slip XDR to the server, so that the server performs data analysis and generates a report based on the first slip XDR and / or the second slip XDR.
[0083] In a fifth aspect, an embodiment of the present application provides a network processor (NP) device, which includes a processor, a memory and a communication interface, wherein the processor is configured to support the network processor (NP) device to implement corresponding functions in the method for processing traffic data provided in the first aspect; the memory is coupled with the processor and stores necessary program instructions and data of the network processor (NP) device; and the communication interface is configured to enable the network processor (NP) device to communicate with other devices or a communication network.
[0084] In a sixth aspect, an embodiment of the present application provides a probe device, which includes a processor, a memory and a communication interface, wherein the processor is configured to support the probe device to implement corresponding functions in the method for processing traffic data provided in the second aspect; the memory is coupled with the processor and stores necessary program instructions and data of the probe device; and the communication interface is configured to enable the probe device to communicate with other devices or a communication network.
[0085] In a seventh aspect, an embodiment of the present application provides a chip system, which can include a processor configured to support the network processor (NP) device to implement functions involved in the first aspect, or configured to support the probe device to implement functions involved in the second aspect; in a possible design, the chip system further includes a memory and an interface circuit, and the memory is configured to store necessary program instructions and data of the data sending device. The chip system can be composed of a chip, or can include a chip and other discrete devices.
[0086] In an eighth aspect, an embodiment of the present application provides a computer storage medium, which is configured to store computer software instructions used in the processor of the network processor (NP) device provided in the first aspect, or configured to store computer software instructions used in the processor of the probe device provided in the second aspect, and the computer storage medium includes a program configured to perform the functions designed in the above aspects.
[0087] In a ninth aspect, an embodiment of the present application provides a computer program, which comprises instructions, when the computer program is executed by a computer, causes the computer to perform the flow executed by the processor in the network processor NP device in the first aspect or the probe device in the second aspect. BRIEF DESCRIPTION OF DRAWINGS
[0088] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the background art, the drawings needed to be used in the embodiments of the present application or the background art will be described below.
[0089] FIG. 1A is a structural schematic diagram of a customer experience management CEM system in the prior art.
[0090] FIG. 1B is a schematic diagram of the relationship between traffic growth and the number of customer experience management CEM platform servers in the prior art.
[0091] FIG. 1C is a schematic diagram of a customer experience management CEM platform downgrading scheme in the prior art.
[0092] FIG. 2 is a schematic diagram of a traffic analysis system architecture of an exemplary application environment of a traffic data processing method and device provided by an embodiment of the present application.
[0093] FIG. 3A is a structural schematic diagram of a network processor NP device provided by an embodiment of the present application.
[0094] FIG. 3B is a structural schematic diagram of a probe device provided by an embodiment of the present application.
[0095] FIG. 4 is a flow schematic diagram of a traffic data processing method provided by an embodiment of the present application.
[0096] FIG. 5 is a flow schematic diagram of another traffic data processing method provided by an embodiment of the present application.
[0097] FIG. 6 is a flow schematic diagram of another traffic data processing method provided by an embodiment of the present application.
[0098] FIG. 7 is a flow schematic diagram of a method for generating a splicing data packet based on an encrypted traffic data packet provided by an embodiment of the present application.
[0099] FIG. 8 is a structural schematic diagram of another network processor NP device 204 provided by an embodiment of the present application.
[0100] FIG. 9 is a structural schematic diagram of another probe device 205 provided by an embodiment of the present application.
[0101] FIG. 10 is a structural schematic diagram of another network processor NP device 204 provided by an embodiment of the present application.
[0102] FIG. 11 is a structural schematic diagram of another probe device 205 provided by an embodiment of the present application. DETAILED DESCRIPTION
[0103] The embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.
[0104] In the description of embodiments of the disclosure, the term "includes" and its conjugations are open-ended, i.e., "includes but is not limited to". The term "based on" is intended to mean "based, at least in part, on". The term "one embodiment" or "an embodiment" means "at least one embodiment". The terms "a first", "a second", etc. can refer to different or same objects. Other explicit or implicit definitions can also be included below.
[0105] The terms "first", "second", "third", and "fourth" and the like in the description and in the claims of the present application are used for distinguishing between similar objects, not for describing a particular sequential or chronological order. Further, the terms "comprises", "comprising", "includes", "including" and the like are to be construed open-ended, i.e., to mean including, but not limited to. Exemplary, non-limiting, processes, devices, systems, products, or apparatuses that can include, consist essentially of, or consist of, the steps or units listed in the specification, can include additional steps or units, and further can consist of or consist essentially of one or more additional steps or units.
[0106] Reference herein to "embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the application. The appearances of the phrase that the phrase in various places in the specification are not necessarily all referring to the same embodiment, or are necessarily referring to some common or identical embodiments, are not necessarily mutually exclusive, and the articles "a", "an" and "the" are not necessarily referring to the singular unless the content clearly dictates otherwise. It is expressly understood that the embodiments described herein can be combined with any of the other embodiments.
[0107] First, some terms in the present application are explained and described to facilitate understanding by those skilled in the art.
[0108] (1) The Customer Experience Management (CEM) platform is a comprehensive customer experience management platform. It uses digital technology to manage the overall customer experience of the company from all angles, including product, service, brand, marketing, channel, and other touchpoints. The platform captures customer experience feedback in various interactive scenarios in real time, thereby gaining a deeper understanding of customer needs, pain points, and preferences.
[0109] (2) XDR detail (also known as a bill) is based on Internet full data processing, signaling process and business transmission process of the session level detailed record, contains all the user information, therefore, the bill contains very rich data analysis and mining value.
[0110] (3) Network packet processing (Network Processor, NP) equipment is a programmable processor designed specifically for processing data packets, which can directly complete the general task of network data processing.
[0111] (4) Packets per second (PPS) is a unit of measuring the number of data packets processed per second by a network device or interface. In the field of network, packets per second is usually used to describe the processing capacity of network devices or interfaces, especially in routers, switches, firewalls and other devices.
[0112] (5) Transmission Control Protocol (TCP) is a connection-oriented, reliable, byte stream-based transport layer communication protocol. TCP aims to adapt to the layered protocol hierarchy supporting multi-network applications. TCP is a connection-oriented protocol that requires a reliable connection with the other party before transmitting data. The process of establishing a connection is three-way handshake, and the process of disconnecting is four-way handshake, ensuring the reliability of data transmission.
[0113] (6) User Datagram Protocol (UDP) is a transport layer protocol in the OSI reference model, which is a connectionless transport layer protocol that provides transaction-oriented simple unreliable information transfer service. UDP is a connectionless protocol that does not require a connection before data transmission.
[0114] (7) Network processor (Network Processor, NP) equipment is a hardware device specially designed for processing network data packets. They have high programmability and flexibility, and can perform various network functions such as packet filtering, routing, forwarding, load balancing, traffic control, etc.
[0115] (8) Header is the beginning part of the data packet, which contains the meta information and control information required for transmission and processing of data. For example, the source address, destination address, protocol identifier, sequence number and timestamp of the data packet.
[0116] (9) Payload is the part of the data packet that actually transmits user data or application data, also known as payload.
[0117] (10) Thread is the smallest execution unit that can be scheduled by the operating system. It is an entity within a process and is the basic unit of CPU scheduling and dispatching. Each thread has its own execution flow and state, and can execute specific tasks independently. Unlike processes, multiple threads can execute concurrently in the context of the same process, sharing the resources of that process (such as memory space, open files, etc.).
[0118] (11) Circular queue is a special queue data structure with a fixed-size buffer. It forms a loop between the end and the beginning of the queue, which can effectively utilize limited storage space.
[0119] (12) Hash value is generated by a hash function. The hash function maps the input (such as the content of a data packet) to a fixed-size hash value, and the process is deterministic, that is, the same input will always produce the same hash value. The hash value can uniquely identify the content of the data packet, regardless of the size of the data packet, and the length of the generated hash value is fixed. Hash values can be used for fast lookup, comparison and matching of data packets, especially in routing, firewalls and traffic analysis, which can be used to quickly identify duplicate data packets or compare content.
[0120] (13) Hash table is a data structure (array) used to implement hash mapping or associative array. It maps keys to a location in the table through a hash function, enabling efficient lookup, insertion and deletion operations.
[0121] (14) Flow table is a data structure defined and maintained by the controller, used to implement traffic forwarding and processing logic in network devices (such as SDN switches). Each flow table contains multiple entries (Entries), each of which defines a matching condition and related operations for a data flow (Flow).
[0122] First, analyze and propose the technical problems to be solved in this application.
[0123] In the prior art, a traffic analysis system, especially a customer experience management (CEM) system, usually guarantees customer experience by collecting and analyzing traffic in a packet switched (PS) service network. For example, referring to FIG. 1A, which is a structural schematic diagram of a CEM system in the prior art. As shown in FIG. 1A, the current CEM system is composed of a collection device 101 and a CEM platform 102, wherein the collection device 101 is mainly responsible for collecting traffic data packets in the network, identifying and analyzing them, and then generating XDR slips (also known as bills), and then reporting the XDR slips to the CEM platform 102. The number of XDR slips generated by the collection device 101 is in a linear relationship with the traffic in the network, that is, the more traffic data generated per second in the network, the more XDRs generated per second by the collection device 101. The CEM platform 102 is usually composed of multiple CEM platform servers, which are mainly responsible for receiving XDR slips, calculating and storing data in the XDR slips, and finally generating reports related to customer experience.
[0124] For example, referring to FIG. 1B, which is a schematic diagram of the relationship between traffic growth and the number of CEM platform servers in the prior art. As shown in FIG. 1B, as the network traffic grows significantly, that is, the amount of data transmitted in the network increases significantly in units of gigabits per second (Gbps), the number of service experience servers (i.e., CEM platform servers) in the CEM system also increases significantly. This is because when the amount of traffic data generated per second (i.e., the number of packets per second (PPS)) increases, the number of XDR slips generated per second by the CEM system also increases accordingly. If the number of CEM platform servers is insufficient, the CEM system may have a processing bottleneck, resulting in slower data processing speed, decreased system performance, or even system crash. Therefore, in order to ensure the stability and performance of the CEM system, the number of CEM platform servers needs to be increased to process XDR slips, which undoubtedly increases the investment cost and pressure of operators in the field of service experience. In addition, the rapid growth of traffic also promotes the continuous expansion of hardware, making customers complain about the heaviness of the platform. With the advent of the 5G era, traffic growth is even more rapid, and the number of CEM platform servers will increase even more. Therefore, the solution in the prior art is to reduce the number of XDR slips to reduce the processing load of the CEM platform servers, thereby improving the performance and stability of the CEM system. At the same time, the reduction of the number of XDR slips can also reduce the number of platform servers in the CEM system to reduce costs.
[0125] Exemplarily, please refer to FIG. 1C, which is a schematic diagram of a CEM platform downgrading scheme in the prior art. As shown in FIG. 1C, in the prior art, the method for reducing the number of XDRs usually includes the following scheme one and scheme two:
[0126] Scheme one: configuring a filtering rule: reducing the number of bills XDRs generated per second by the collection device 101 by setting a filtering rule in the collection device 101, for example, filtering users by the International Mobile Subscriber Identity (IMSI) to reduce the collected traffic data, or filtering out the traffic data of some network elements by the IP address of the network element, and the like, to reduce the number of bills XDRs.
[0127] Scheme two: bill sampling: reducing the number of XDRs that the CEM platform server needs to process by sampling the bills XDRs generated by the collection device 101.
[0128] Although the above schemes can improve the performance and stability of the CEM platform by reducing the number of XDRs, and at the same time, reduce the number of CEM platform servers to reduce costs, they all have the problem that the user's traffic data may be lost, that is, at the expense of data integrity to improve the stability and performance of the CEM system, and at the same time, reduce the number of CEM platform servers to reduce costs. However, for many customers, data integrity is particularly important, especially in the context of customer complaints, missing bills may result in the inability to query the corresponding problem bills for complaints, resulting in low customer acceptance and poor customer service experience.
[0129] Therefore, in order to solve the problem that the current traffic analysis system's traffic data collection and processing technology does not meet the actual business requirements, and to achieve the goal of improving the performance and stability of the traffic analysis system while ensuring that the lossless business requirements of the traffic analysis system are met, considering the shortcomings of the prior art, the technical problems actually solved by the present application include one or more of the following two aspects:
[0130] 1、In the process of improving the performance of the traffic analysis system, the dependence of the traffic analysis system on the number of servers can be reduced. In the prior art, the number of XDRs generated per second by the collection device of the traffic analysis system (such as a CEM system) is in linear relationship with the traffic in the network. When the traffic rises, the number of XDRs generated per second by the traffic analysis system also increases accordingly. At this time, in order to improve the performance of the traffic analysis system and maintain the stability of the traffic analysis system, the prior art increases the number of servers to improve the efficiency of processing XDRs, which undoubtedly increases the investment pressure of the operator in the field of service experience. Therefore, a technical scheme for processing traffic data is needed, which can improve the performance of the traffic analysis system in processing traffic data, and also reduce the dependence of the traffic analysis system on the number of servers to improve cost competitiveness.
[0131] 2、Ensure the integrity of traffic data to meet the lossless service requirements of the traffic analysis system. The prior art usually reduces the number of XDRs generated by the collection device to reduce the number of servers in the traffic analysis system. However, the current method of reducing the number of XDRs (such as configuring filtering rules, sampling XDRs, etc.) sacrifices data integrity to improve the stability and performance of the traffic analysis system (such as a CEM system). At the same time, the reduction of the number of XDRs can also reduce the number of CEM platform servers to reduce costs. However, this method of reducing the number of XDRs may result in the loss of user data, especially in the context of customer complaints. The loss of XDRs may result in the inability to query the problem XDR corresponding to the complaint, thereby causing user dissatisfaction and poor service experience. Therefore, a technical scheme for processing traffic data is needed, which can improve the processing performance of the traffic analysis system while ensuring the integrity of the traffic data, so as to ensure that the traffic analysis system does not lose XDRs in the process of processing traffic data, which is conducive to improving the service quality of the operator and improving the satisfaction of users.
[0132] In summary, the existing traffic data processing technology cannot meet the needs of operators in controlling costs and improving the performance of the traffic analysis system and the lossless service requirements of traffic data. Therefore, the traffic data processing method provided in the present application can be used to solve part or all of the above technical problems.
[0133] FIG. 2 is a schematic diagram of the architecture of a traffic analysis system in an exemplary application environment of a method and device for processing traffic data according to an embodiment of the present application. As shown in FIG. 2, the traffic analysis system can include at least one terminal device 201 (only three are shown in FIG. 2), a network 202, at least one collection device 203 (only two are shown in FIG. 2), at least one network processor NP device 204 (only two are shown in FIG. 2), at least one probe device 205 (only one is shown in FIG. 2), and at least one server 206 (only one is shown in FIG. 2).
[0134] The terminal device 201 can be a cellular phone, a cordless phone, a smart phone, a Session Initiation Protocol (SIP) phone, a Wireless Local Loop (WLL) station, a smart bracelet, a smart wearable device, an MP3 player, an MP4 player, a Personal Digital Assistant (PDA), a handheld device with wireless communication function, a computing device or other processing device connected to a wireless modem, an in-vehicle device, etc. supporting wireless mobile communication video services. The terminal device 201 can also be a Pad, a computer with wireless transceiver function, a Virtual Reality (VR) terminal device, an Augmented Reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical treatment, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc.
[0135] The network 202 is a medium for providing communication links between the terminal device 201, the collection device 203, the network processor NP device 204, the probe device 205 and the server 206. The network 202 can include various connection types, such as wired, wireless communication links or fiber optic cables, etc.
[0136] The collection device 203 is usually deployed at the network port of the network and can be used to capture the data packets of the network traffic passing through the network port. The network port can be an interface of a network device (such as a router, a switch, a firewall), or a physical interface or a virtual interface connected to a network link. The data packets collected by the collection device 203 can include data packets from various network protocols, such as TCP, UDP, ICMP, etc. In addition, the collection device 203 also has a simple mirroring capability, which can copy mirror traffic based on rules of network layer information (such as source IP address, source port number, destination IP address, destination port number, protocol type, etc.) to provide to the network processor NP device 204.
[0137] The network processor NP device 204 is a device for processing traffic data applied to a traffic analysis system provided by the present application, which can be deployed on a core router or a switch of a network, or run as a virtual network function (VNF) in a cloud environment. The network processor NP device 204 is used to identify and process data packets of encrypted traffic, to realize compression of the packet per second PPS of encrypted traffic, so that the packet per second PPS of the traffic data packets exported by the network processor NP device 204 is reduced, thereby reducing the packet per second PPS that needs to be processed by the probe device 205, to reduce the processing load of the probe device 205.
[0138] The probe device 205 is another device for processing traffic data applied to a traffic analysis system provided by the present application. The probe device 205 can be deployed in the server 206, or exist as a standalone device. The probe device 205 is mainly used to receive the compressed traffic packet per second PPS of the network processor NP device 204, and generate a bill XDR based on the compressed traffic packet per second PPS.
[0139] The server 206 is a device for data analysis and report generation of the bill XDR generated by the probe device 205 in the traffic analysis system. Exemplarily, when the traffic analysis system is a customer experience management CEM system, all the servers 206 in the traffic analysis system collectively constitute a customer experience management CEM platform server. The customer experience management CEM platform is mainly responsible for receiving the bill XDR generated by the probe device 205, calculating and storing the data in the XDR, and finally generating a report related to customer experience, to help enterprises comprehensively understand and optimize the experience of customers when using products or services. It should be noted that the present application only exemplarily introduces one possible type of server 206 in the traffic analysis system. In other embodiments, the server 206 can also be other types of servers to support other different functions and needs, which are not limited by the present application.
[0140] It can be understood that the system architecture in FIG. 2 is only an exemplary embodiment in the embodiments of the present application, and the system architecture in the embodiments of the present application includes but is not limited to the above-described system architecture.
[0141] Based on the above system architecture, the embodiments of the present application provide a network processor NP device 204 applied to the above system architecture, please refer to FIG. 3A, which is a structural schematic diagram of a network processor NP device provided by the embodiments of the present application. The network processor NP device 204 can include a packet receiving module 2001, a protocol analyzing module 2002, a port identifying module 2003, an encrypted packet identifying module 2004, a packet cutting module 2005, a distribution module 2006, a packet assembling module 2007, an encapsulating module 2008, and a packet sending module 2009. The specific description of each module in the network processor NP device 204 is as follows.
[0142] The packet receiving module 2001 is used to receive data packets of network traffic mirrored from the network interface. These data packets are mirror copies of various traffic in the network, rather than direct data streams.
[0143] The protocol analyzing module 2002 is used to analyze the received data packets according to the common protocol stack of the Internet, such as identifying the basic network layer and transport layer protocols, such as IP header, TCP / UDP header, and other information.
[0144] The port identifying module 2003 is used to identify whether the data packet uses a target encryption protocol (such as one or more of the Quic and TLS / SSL (i.e., HTTPS) encryption protocols) through the port number. In a possible implementation, the port identifying module 2003 can identify whether the data packet uses the target encryption protocol by judging whether the port number of the data packet matches the preset port number. For example, when the UDP port number of the data packet is 443, it is identified that the target encryption protocol used by the data packet is the Quic protocol; when the TCP port number of the data packet is 443, it is identified that the target encryption protocol used by the data packet is the TLS protocol or the SSL protocol. Through the port identifying module 2003, the type of encrypted data stream can be identified, so as to further process the encrypted data stream.
[0145] The encrypted packet identification module 2004 is configured to identify whether the packet body of the identified data packet (i.e., a target data packet) using a target encryption protocol (e.g., Quic and TLS / SSL) is an encrypted packet. In a possible implementation, the encrypted packet identification module 2004 can determine whether the packet body of the data packet is an encrypted packet by identifying whether the data packet is a preset message. For data packets (i.e., target data packets) using different target encryption protocols (e.g., Quic and TLS / SSL), the corresponding preset messages are different. For example, for a data packet using the Quic protocol, the preset message can be an initial message; for a data packet using the TLS / SSL protocol, the preset message can be a client-side Client Hello message or a server-side Server Hello message. If it is identified that the data packet is a preset message, the packet body of the data packet is a non-encrypted packet, otherwise, the packet body of the data packet is an encrypted packet. The embodiments of the present application only exemplarily introduce several possible types of preset messages, and in other embodiments, due to the differences in encryption protocols and / or application scenarios, the types of preset messages can include but are not limited to the above-mentioned several types, and the embodiments of the present application are not limited thereto.
[0146] The packet cutting module 2005 is configured to cut the identified data packet using the target encryption protocol (e.g., Quic or TLS / SSL).
[0147] The distribution module 2006 is configured to distribute the obtained packet header information (e.g., IP and TCP / UDP header information) of the data packet to a corresponding packet assembly circular queue according to the mobile terminal internet protocol address MSIP in the packet header information. Each packet assembly circular queue can be used to process data packets of a specific MSIP address or a plurality of MSIP addresses, which can improve the processing efficiency, especially in the case of high load and large traffic, can effectively improve the processing efficiency and throughput of the system, reduce the processing delay and resource consumption, and improve the performance of the network processor NP device.
[0148] The packet assembly module 2007 is configured to splice the header information (e.g., IP and TCP / UDP header information) of N data packets into a to-be-encapsulated packet body of a spliced data packet, so as to reduce the number of packets per second PPS of the data packets transmitted by the network processor NP device 204 to the probe device 205, thereby improving the transmission speed of the data packets while ensuring data integrity, reducing the processing load of the probe device, and improving the efficiency and performance of the overall system.
[0149] The encapsulation module 2008 encapsulates the to-be-encapsulated packet to generate a spliced data packet based on an interface (communication protocol) between the network processor NP device 204 and the probe device 205. In a possible implementation, the encapsulation process of the encapsulation module 2008 can include modifying a value of a target field in encapsulation packet header information to a number of data packets encapsulated in the spliced data packet (for example, modifying the first four bytes of a target MAC address to MagicNum to represent the number of data packets encapsulated in the spliced data packet), modifying a target address (for example, a target IP address) in the encapsulation packet header information to an address of a corresponding thread in the probe device to which the spliced data packet is sent, and further adding the modified encapsulation packet header information to the to-be-encapsulated packet, thereby generating an encapsulated spliced data packet.
[0150] The sending packet module 2009 sends the spliced data packet to the probe device 205 through a network port, so that the probe device 205 can use the spliced data packet for further traffic analysis.
[0151] It can be understood that the structure of the network processor NP device 204 in FIG. 3A is only an exemplary implementation in the embodiments of the present application, and the structure of the network processor NP device 204 in the embodiments of the present application can include but is not limited to the above structure.
[0152] Further, based on the system architecture in FIG. 2, the embodiments of the present application provide a probe device 205 applied to the system architecture, please refer to FIG. 3B, which is a structural schematic diagram of a probe device provided by the embodiments of the present application. The probe device 205 can include a packet receiving module 3001, an analysis module 3002, an identification module 3003, a packet disassembling module 3004, a traffic data identification module 3005, a bill generating module 3006, and a bill sending module 3007. The specific description of each module in the probe device 205 is as follows.
[0153] The packet receiving module 3001 receives the data packet sent by the network processor NP device 204.
[0154] The analysis module 3002 analyzes the received data packet according to a network protocol (such as TCP, UDP, IP, etc.). For example, it can include analyzing the header information, payload, and possible encapsulation levels (such as data link layer, network layer, and transport layer) of the data packet.
[0155] The identification module 3003 is configured to identify whether the received data packet is a spliced data packet. In a possible implementation, the identification module 3003 can determine whether the data packet is a spliced data packet by judging whether a value of a target field (for example, the first four bytes of a target MAC address) in the data packet satisfies a preset condition. For example, whether the value MagicNum of the first four bytes of the target MAC address (DSTMAC) of the data packet satisfies a preset spliced packet identification condition (for example, MagicNum is greater than 1 and less than 20) can be checked to determine whether the data packet is a spliced packet.
[0156] The unpacking module 3004 is configured to split the spliced data packet into N original data packets each containing only header information (for example, IP and TCP / UDP packet header information).
[0157] The traffic data identification module 3005 is configured to generate a flow table and a user table based on five-tuple information (including a source address, a source port, a target address, a target port, and a transport layer protocol) of the split single data packet.
[0158] The bill generation module 3006 is configured to calculate user plane pipe and experience indexes according to a predefined user plane algorithm, thereby generating bills (XDRs) containing pipe information and experience indexes. The bills can include traffic statistics, user behavior analysis and other information, to facilitate subsequent business analysis and management.
[0159] The bill sending module 3007 is configured to send the generated bills XDRs to a server of an upper-layer analysis system (for example, the customer experience management CEM platform 102) through a northbound sending interface, to facilitate analysis and optimization decision-making by an operator or a network administrator.
[0160] It can be understood that the structure of the probe device 205 in FIG. 3B is only an exemplary embodiment in the embodiments of the present application, and the structure of the probe device 205 in the embodiments of the present application can include but is not limited to the above structure.
[0161] Based on the system architecture provided in FIG. 2, the structure of the network processor NP device provided in FIG. 3A, the structure of the probe device provided in FIG. 3B, and the traffic data processing method provided in the present application, the technical problems proposed in the present application are analyzed and solved.
[0162] Please refer to FIG. 4, which is a flow diagram of a method for processing traffic data according to an embodiment of the present application. The method can be applied to the system architecture shown in FIG. 2. The network processor NP device 204 can be configured to support and perform the method steps S400-S403 shown in FIG. 4. The probe device 205 can be configured to support and perform the method steps S404-S407 shown in FIG. 4. The method can include the following steps S400-S407.
[0163] Step S400: The network processor NP device 204 receives a first data packet and identifies whether the first data packet is a target data packet using a target encryption protocol.
[0164] Step S401: If yes, the network processor NP device 204 intercepts the header information of the target data packet.
[0165] Specifically, the network processor NP device receives network traffic data (i.e., a first data packet) and identifies the encrypted traffic data packet (i.e., a target data packet using a target encryption protocol) in the network traffic data. Further, for the target data packet using the target encryption protocol (e.g., one or more of Quic protocol, TLS protocol, and SSL protocol), the header information of the encrypted traffic data packet (i.e., the target data packet) is intercepted. This can retain the key information (source address, target address, protocol type, timestamp, etc.) in the encrypted traffic data packet that can be used for traffic analysis, and can also reduce the size of the encrypted traffic data packet. This is beneficial for reducing the processing load of the network processor NP device while ensuring the integrity of the traffic data, thereby improving the performance of the traffic analysis system.
[0166] In a possible implementation, the determining whether the first data packet is a target data packet using a target encryption protocol can include: determining whether a port number of the first data packet matches a preset port number; if yes, determining that the first data packet is the target data packet using the target encryption protocol; and if no, determining that the first data packet is a second data packet not using the encryption protocol. Specifically, the embodiment of the present application determines whether the network traffic data (i.e., the first data packet) received by the network processor NP device matches the preset port number (for example, 443) to determine whether the first data packet is a target data packet using a target encryption protocol. Further, when the port number of the first data packet matches the preset port number, it is determined that the first data packet is a target data packet using a target encryption protocol; when the port number of the first data packet does not match the preset port number, it is determined that the first data packet is a second data packet not using the target encryption protocol. Through the embodiment of the present application, the efficiency and accuracy of the network processor NP device in identifying encrypted traffic (i.e., target data packets) can be effectively improved, so that the network processor NP device can subsequently perform compression traffic processing on the encrypted traffic (i.e., target data packets).
[0167] In a possible implementation, the method further includes: if it is determined that the first data packet is the target data packet using the target encryption protocol, determining a target encryption protocol type used by the target data packet according to a port number and a port type of the target data packet. Specifically, the embodiment of the present application can determine the target encryption protocol type used by the target data packet according to the port number and the port type of the target data packet while identifying the target data packet using the target encryption protocol through port matching. For example, when the target data packet is UDP PORT=443, it is determined that the target encryption protocol type used by the target data packet is the Quic protocol; and when the target data packet is UDP PORT=443, it is determined that the target encryption protocol type used by the data packet is the TLS protocol or the SSL protocol. Through the embodiment of the present application, the target encryption protocol type used by the target data packet can be quickly and accurately identified, so that the packet body of the target data packet using different target encryption protocol types can be subsequently determined to be an encrypted message.
[0168] In a possible implementation, the first data packet comprises packet header information and packet body; and the method further comprises: if the first data packet is identified as the target data packet using the target encryption protocol, determining whether the packet body of the target data packet is an encrypted message; if the packet body of the target data packet is the encrypted message, determining that the target data packet is an encrypted data packet using the target encryption protocol; and if the packet body of the target data packet is a non-encrypted message, determining that the target data packet is a payload data packet using the target encryption protocol. Specifically, since analyzing the complete information of the payload data packet (i.e., the data packet without payload data) is very important for the traffic analysis system to determine the network connection state and perform security detection, etc., in the case that the network processor NP device identifies the first data packet as the target data packet using the target encryption protocol through the packet header information, the network processor NP device can further determine whether the target data packet is a payload data packet using the encryption protocol by determining whether the packet body of the target data packet is an encrypted message. Further, if the packet body of the target data packet is an encrypted message, it is determined that the target data packet is an encrypted data packet using the target encryption protocol; and if the packet body of the target data packet is a non-encrypted message, it is determined that the target data packet is a payload data packet using the target encryption protocol. Through the embodiments of the present application, the payload data packet using the target encryption protocol can be effectively identified, so that the network processor NP device can send the original data packet of the payload data packet to the probe device for more accurate traffic data analysis while performing traffic compression processing on the target data packet (which can include the payload data packet), thereby improving the security and performance of the traffic analysis system.
[0169] In a possible implementation, the determining whether the packet body of the target data packet is an encrypted message comprises: identifying whether the target data packet is a preset message; if yes, determining that the packet body of the target data packet is the non-encrypted message; and if no, determining that the packet body of the target data packet is the encrypted message. Specifically, the embodiments of the present application determine whether the packet body of the target data packet using the target encryption protocol is an encrypted message by identifying whether the target data packet is a preset message. Specifically, if the target data packet is identified as a preset message, it is determined that the packet body of the target data packet is a non-encrypted message; and if the target data packet is not identified as a preset message, it is determined that the packet body of the target data packet is an encrypted message. Through the embodiments of the present application, the network processor NP device can simply and efficiently identify whether the packet body of the target data packet using the target encryption protocol is an encrypted message, to determine whether the target data packet is a payload data packet, so as to send the original data packet of the payload data packet to the probe device for more accurate traffic data analysis while performing traffic compression processing on the target data packet using the target encryption protocol (including the payload data packet), thereby improving the security and performance of the traffic analysis system.
[0170] In a possible implementation, the target data packet uses different target encryption protocols, and the corresponding preset messages are different. According to the embodiment of the present application, for the target data packet using different target encryption protocols (for example, Quic and TLS / SSL), the corresponding preset messages used to determine whether the packet body of the target data packet is an encrypted message are also different. For example, for the data packet using the Quic protocol, the preset message can be an initial message; and for the data packet using the TLS / SSL protocol, the preset message can be a client-side Client Hello message or a server-side Server Hello message. Through the embodiment of the present application, the network processor NP device can quickly and accurately determine whether the packet body of the target data packet using different target encryption protocol types is an encrypted message, so as to determine whether the target data packet is a static load packet, so as to send the original data packet of the static load packet to the probe device for more accurate traffic data analysis while performing traffic compression processing on the target data packet (including the static load packet) using the target encryption protocol, thereby improving the security and performance of the traffic analysis system.
[0171] In a possible implementation, the network processor NP device includes one or more packet assembly circular queues, and the method further includes: distributing the packet header information to the corresponding packet assembly circular queue according to the mobile terminal internet protocol address MSIP in the packet header information. Specifically, one or more packet assembly circular queues can be included in the network processor NP device, and each packet assembly circular queue can correspond to one or more mobile terminal internet protocol addresses MSIP. According to the embodiment of the present application, the packet header information of the intercepted target data packet is distributed to the corresponding packet assembly circular queue for processing according to the corresponding mobile terminal internet protocol address MSIP, so that the network processor NP device can realize the shunting and specialized processing of the packet header information of the encrypted traffic data (that is, the target data packet) of different mobile terminals through different packet assembly circular queues, which is beneficial to providing more accurate traffic analysis documents when the probe device processes the data packets output by the different packet assembly circular queues, and at the same time, the packet assembly circular queues can be used to concurrently process the packet header information of the encrypted traffic data (that is, the target data packet), so as to improve the efficiency of the network processor NP device in processing traffic data, thereby improving the overall processing performance of the traffic analysis system. It should be noted that in some embodiments, a large number of threads for processing packet header information can be included in the network processor NP device, and one or more packet assembly circular queues can be included in each thread, so as to realize the concurrent reception of the packet header information of the target data packet by each thread and the distribution of the packet header information to the corresponding packet assembly circular queue in each thread, so as to further improve the efficiency of the network processor NP device in processing traffic data, and the embodiment of the present application is not limited in this regard.
[0172] Step S402: The network processor NP device 204 splices the packet header information of N target data packets into a spliced data packet.
[0173] Specifically, the embodiment of the present application splices the packet header information of N encrypted traffic data packets (i.e., target data packets) into a spliced data packet, N being a positive integer greater than 1. Through the embodiment of the present application, the integrity of data in the traffic analysis system can be ensured, and the number of traffic data packets per second PPS sent by the network processor NP device to the probe device can be effectively reduced, thereby reducing the processing load of the subsequent probe device and improving the performance of the traffic analysis system in processing traffic data.
[0174] In a possible implementation, the step of splicing the packet header information of N target data packets into a spliced data packet can include: when the target packet assembly circular queue receives the packet header information of N target data packets, splicing the packet header information of N target data packets into the spliced data packet, N being a positive integer greater than 1. Specifically, the embodiment of the present application can splice the packet header information of N target data packets received into a spliced data packet when the target packet assembly circular queue receives the packet header information of N target data packets. Through multiple packet assembly circular queues, the efficiency of the network processor NP device in generating spliced data packets can be improved, and the speed of the network processor NP device in processing traffic data can be accelerated, so as to improve the overall performance of the traffic analysis system.
[0175] In a possible implementation, the step of splicing the packet header information of the N target data packets into the spliced data packet can include: splicing the received packet header information of the N target data packets to generate a to-be-encapsulated packet body of the spliced data packet; and encapsulating the to-be-encapsulated packet body based on a communication protocol between the network processor NP device and the probe device to generate the spliced data packet. Specifically, the step of how to splice the packet header information of the N target data packets into a spliced data packet can include: first splicing the packet header information of the N target data packets received by the network processor NP device to generate a to-be-encapsulated packet body of a spliced data packet; and then encapsulating the generated to-be-encapsulated packet body based on a communication protocol between the network processor NP device and the probe device to generate an encapsulated spliced data packet. Through the embodiments of the present application, the packet header information of the target data packets that can be used for traffic analysis and intercepted by the network processor NP device can be compressed according to a specific compression rule (i.e., the packet header information of the N target data packets forms a spliced data packet), which guarantees the integrity of the traffic data and reduces the packet per second PPS of the traffic data packets at the export of the network processor NP device, thereby reducing the processing load of the subsequent probe device and improving the performance of the traffic analysis system. Meanwhile, the to-be-encapsulated packet body formed by the packet header information of the N target data packets is encapsulated according to the communication protocol between the network processor NP device and the probe device, which can improve the security and reliability of the network processor NP device in sending the spliced data packet to the probe device, thereby further improving the performance and stability of the traffic analysis system.
[0176] In a possible implementation, the encapsulating the to-be-encapsulated packet body to generate the spliced data packet can include: modifying a value of a target field in encapsulation packet header information to a number of data packets encapsulated in the spliced data packet, and modifying a target address in the encapsulation packet header information to an address of a corresponding thread in the probe device to which the spliced data packet is sent; and adding the modified encapsulation packet header information to the to-be-encapsulated packet body to generate the spliced data packet. Specifically, as to how to encapsulate the to-be-encapsulated packet body composed of packet header information of N target data packets to generate a spliced data packet, the step can specifically include: first modifying a value of a target field in encapsulation packet header information used for encapsulating the to-be-encapsulated packet body to a number of data packets encapsulated in the spliced data packet (for example, the first four bytes of a DSTMAC field of a MAC address in the encapsulation packet header information can be modified to MagicNum, which is used to indicate the number of encapsulated packets), while modifying a target address (for example, a target IP address) in the encapsulation packet header information to an address of a corresponding thread in the probe device to which the spliced data packet is sent; and further adding the modified encapsulation packet header information to the to-be-encapsulated packet body to generate a spliced data packet. Through the embodiment, the target field in the encapsulation packet header information of the spliced data packet can reflect the number of data packets encapsulated in the spliced data packet, so that the probe device can determine whether the data packet is a spliced data packet by identifying the target field after receiving the data packet. Meanwhile, the target address in the encapsulation packet header information of the spliced data packet can be used to indicate the address of the thread in the probe device processing the spliced data packet, so that the probe device can send the spliced data packet to the corresponding thread for processing by identifying the target address, thereby effectively improving the processing efficiency and response speed of the probe device, and improving the overall performance of the traffic analysis system.
[0177] Step S403: The network processor NP device 204 sends the spliced data packet to the probe device 205.
[0178] Specifically, the spliced data packet is used for traffic analysis by the probe device. In the embodiment, the spliced data packet containing only the packet header information of the encrypted traffic data packet (i.e., the target data packet) is sent to the probe device for traffic analysis, which can effectively reduce the number of traffic data packets PPS sent by the network processor NP device to the probe device per second, thereby reducing the processing load of the subsequent probe device and improving the performance of the traffic analysis system in processing traffic data.
[0179] In a possible implementation, the method further includes: if it is determined that the first data packet is the second data packet that does not use the target encryption protocol, sending the second data packet to the probe device. Specifically, by sending the data packet (i.e., the second data packet) that does not use the target encryption protocol received by the network processor NP device to the probe device directly, the probe device can not only analyze the packet header information of the encrypted data packet (i.e., the target data packet) in the network traffic, but also perform traffic analysis on the original unencrypted data packet (i.e., the second data packet) in the network traffic, thereby further ensuring the integrity of data in the traffic analysis system and facilitating the probe device to perform more accurate and comprehensive traffic analysis to improve the performance of the traffic analysis system.
[0180] In a possible implementation, the method further includes: if it is determined that the target data packet is the payload that uses the target encryption protocol, sending the payload to the probe device. Specifically, by sending the payload (i.e., the data packet without payload data) that uses the target encryption protocol identified by the network processor NP device to the probe device directly, the probe device can perform more accurate traffic data analysis on the complete information of the payload to determine the network connection state between the network processor NP device and the probe device and perform security detection, thereby further improving the security and performance of the traffic analysis system.
[0181] Step S404: The probe device 205 receives the third data packet sent by the network processor NP device 204.
[0182] Step S405: The probe device 205 identifies whether the third data packet is a spliced data packet.
[0183] Specifically, the third data packet sent by the network processor NP device can include a spliced data packet composed of the packet header information of N target data packets, a second data packet that does not use the target encryption protocol, and a payload that uses the target encryption protocol. The third data packet is further identified to determine whether the third data packet is a spliced data packet, so that the probe device can subsequently process the spliced data packet in a targeted manner to improve the accuracy of the traffic analysis result.
[0184] In a possible implementation, the identifying whether the third data packet is the spliced data packet can include: determining whether a value of a target field in the third data packet satisfies a preset condition, the value of the target field being used to indicate a number of data packets contained in the third data packet; if the value of the target field satisfies the preset condition, determining that the third data packet is the spliced data packet; and if the value of the target field does not satisfy the preset condition, determining that the third data packet is the second data packet or the static payload packet. Specifically, the step of how to identify whether the third data packet received by the probe device is the spliced data packet can include: since the value of the target field (for example, the first four bytes of the DSTMAC field of the MAC address) in the encapsulation packet header information of the spliced data packet has been modified to be the number of data packets encapsulated in the spliced data packet, and the value of the target field is 1 for the second data packet and the static payload packet that are not spliced data packets, the value of the target field in the third data packet can be used to indicate the number of data packets contained in the third data packet, and whether the third data packet is the spliced data packet can be determined by determining whether the value of the target field satisfies a preset condition (for example, greater than 1 and less than 20). If the value of the target field satisfies the preset condition, it is determined that the third data packet is the spliced data packet; and if the value of the target field does not satisfy the preset condition, it is determined that the third data packet is the second data packet that does not use the target encryption protocol or the static payload packet that uses the target encryption protocol. Through the embodiment of the present application, the probe device can accurately and quickly identify whether the received third data packet is the spliced data packet, so that the probe device can subsequently perform corresponding processing on different types of data packets, thereby improving the accuracy of the traffic analysis result and improving the performance of the traffic analysis system.
[0185] Step S406: If yes, the probe device 205 splits the spliced data packet into N fourth data packets.
[0186] Specifically, the fourth data packet includes the packet header information of the target data packet corresponding to the spliced data packet. Since the probe device cannot directly perform traffic analysis on the packet header information of the N first data packets encapsulated in the spliced data packet, in the case where it is identified that the third data packet is the spliced data packet, the spliced data packet is split to generate N fourth data packets containing the packet header information of the encrypted traffic data packet (that is, the target data packet), so as to ensure the integrity of the traffic data and facilitate the probe device to analyze the network traffic by analyzing the fourth data packet, thereby improving the efficiency of the traffic analysis and improving the performance of the traffic analysis system.
[0187] In a possible implementation, the probe device includes one or more threads, and the threads correspond to the packet assembly loop queues in the network processor NP device one by one, and the method further includes: if the third data packet is identified as the spliced data packet, distributing the spliced data packet to the corresponding thread based on a target address in a packet header of the spliced data packet. Specifically, since the one or more threads in the probe device correspond to the packet assembly loop queues in the network processor NP device one by one, and the target address in the packet header of the spliced data packet is modified to an address of the corresponding thread in the probe device when the spliced data packet is encapsulated by the packet assembly loop queues in the network processor NP device, the spliced data packet can be distributed to the corresponding thread for processing by using the target address in the packet header of the spliced data packet in the case where the third data packet is identified as the spliced data packet, so that the probe device can process multiple different types of data streams (i.e., spliced data packets) in parallel, thereby improving the processing efficiency of the probe device, reducing the processing delay, and improving the performance and stability of the traffic analysis system.
[0188] In a possible implementation, each of the threads corresponds to a transmit-receive packet queue, and the splitting the spliced data packet into N fourth data packets can include: when the target thread receives the spliced data packet, splitting the received spliced data packet into N fourth data packets by using the transmit-receive packet queue. Specifically, when the target thread in the probe device receives the spliced data packet, the spliced data packet can be split into N fourth data packets containing the packet header information of the encrypted traffic data packet (i.e., the target data packet) by using the corresponding transmit-receive packet queue, so that the probe device can process a large number of spliced data packets by using the transmit-receive packet queues corresponding to the multiple threads, thereby improving the efficiency of the probe device in processing the spliced data packets and improving the processing performance of the traffic analysis system.
[0189] Step S407: The probe device 205 generates a flow table based on the quintuple information of the fourth data packet.
[0190] Specifically, the quintuple information includes the source address, the source port, the target address, the target port, and the transport layer protocol of the fourth data packet. The probe device classifies the split fourth data packets according to the quintuple information (which can include the source address, the source port, the target address, the target port, and the transport layer protocol of the fourth data packet) in each fourth data packet to generate a flow table, so that the probe device can subsequently perform more accurate traffic analysis on the same type of fourth data packet according to the generated flow table and generate a bill, thereby improving the overall performance of the traffic analysis system (such as the CEM system).
[0191] In a possible implementation, the generating the flow table based on the quintuple information of the fourth data packet comprises: calculating a corresponding Hash value based on the quintuple information of each fourth data packet; and determining a Hash table entry matched with the fourth data packet based on the calculated Hash value, to generate the flow table. Specifically, as to how the probe device generates the flow table based on the quintuple information of the fourth data packet split from the spliced data packet, the steps can specifically comprise: first, calculating a corresponding Hash value of each fourth data packet based on the quintuple information of the fourth data packet, which can comprise a source address, a source port, a target address, a target port, and a transport layer protocol of the fourth data packet; and then, matching the calculated Hash value with a pre-established Hash table to determine a Hash table entry matched with the fourth data packet, to generate the flow table. Through the embodiments of the present application, the efficiency and accuracy of the probe device in flow classification can be improved, so that more accurate flow analysis can be performed on the generated flow table, to improve the performance of the flow analysis system.
[0192] In a possible implementation, the method further comprises: calculating a pipeline indicator and an experience indicator of the fourth data packet based on the information of the flow table, to generate a first bill of XDR. Specifically, through the information in the generated flow table, the embodiments of the present application calculate the fourth data packet of different flows according to a corresponding pre-defined algorithm, to generate a bill of XDR (that is, the first bill of XDR) containing pipeline information (such as delay, packet loss rate, bandwidth utilization rate, and the like) and experience indicators (such as response time and the like), so that the subsequent server can directly analyze and generate a report on the generated first bill of XDR, to reduce the processing burden of the server, improve the efficiency, and reduce the dependence of the flow analysis system on the number of servers, to improve the performance of the flow analysis system in processing flow data without increasing the number of servers and controlling the cost.
[0193] In a possible implementation, the method further includes: if it is identified that the third data packet is not the spliced data packet, calculating a pipe index and an experience index of the third data packet to generate a second invoice XDR. Specifically, the embodiment of the present application can perform traffic analysis on the identified third data packet which is not a spliced data packet, that is, calculate a pipe index and an experience index for a second data packet which does not use a target encryption protocol or a payload packet which uses the target encryption protocol, to generate a second invoice XDR containing pipe information (such as delay, packet loss rate, bandwidth utilization rate and the like) and experience index (such as response time and the like), so that the probe device can analyze all traffic data sent by the network processor NP device, to ensure the integrity of the traffic data in the traffic analysis system, to improve the accuracy and comprehensiveness of the traffic analysis result, to meet the lossless service requirement of the traffic analysis system, and to help the operator improve the service management quality according to the traffic analysis result, thereby improving the user satisfaction.
[0194] In a possible implementation, the system can further include a server, and the method further includes: sending the first invoice XDR and / or the second invoice XDR to the server, where the first invoice XDR and / or the second invoice XDR are used for the server to perform data analysis and generate a report. Specifically, the probe device can send the complete invoice XDR (including the first invoice XDR and / or the second invoice XDR) to the server, so that the subsequent server (for example, a CEM platform server) can perform data analysis and generate a report (such as a report related to customer experience) according to the invoice XDR, so that the operator can improve the service management quality according to the report, thereby improving the user satisfaction.
[0195] Optionally, referring to FIG. 5, FIG. 5 is a flow diagram of another method for processing traffic data according to an embodiment of the present application, which can be applied to the system architecture in FIG. 2. The network processor NP device 204 can be configured to support and perform the method flow steps S500-S509 shown in FIG. 5, and the probe device 205 can be configured to support and perform the method flow steps S510-S518 shown in FIG. 5. The method will be described below from the network processor NP device 204 side and the probe device 205 side with reference to FIG. 5. The method can include the following steps S500-S518.
[0196] Step S500: The network processor NP device 204 receives a first data packet.
[0197] Step S501: The network processor NP device 204 parses the first data packet.
[0198] Step S502: The network processor NP device 204 determines whether the port number of the first data packet matches a preset port number.
[0199] Step S503A: If yes, the network processor NP device 204 determines that the first data packet is a target data packet using the target encryption protocol, intercepts the packet header information of the target data packet, and then proceeds to step S504.
[0200] Specifically, the detailed description of steps S500-S503A can refer to the description of steps S400-S401 in FIG. 4, which will not be repeated here.
[0201] Step S503B: If no, the network processor NP device 204 determines that the first data packet is a second data packet not using the target encryption protocol, sends the second data packet to the probe device, and then proceeds to step S510.
[0202] Specifically, the detailed description of step S503B can refer to the description of step S404 in FIG. 4, which will not be repeated here.
[0203] Step S504: The network processor NP device 204 identifies whether the target data packet is a preset message.
[0204] Step S505A: If yes, the network processor NP device 204 determines that the packet body of the target data packet is a non-encrypted message, and the target data packet is a payload packet using the target encryption protocol, sends the payload packet to the probe device, and then proceeds to step S510.
[0205] Step S505B: If no, the network processor NP device 204 determines that the packet body of the target data packet is an encrypted message, and the target data packet is an encrypted data packet using the target encryption protocol.
[0206] Step S506: The network processor NP device 204 distributes the packet header information of the target data packet to the corresponding packet assembly circular queue according to the mobile terminal Internet protocol address MSIP in the packet header information of the target data packet.
[0207] Specifically, the detailed description of steps S504-S506 can refer to the description of step S401 in FIG. 4, which will not be repeated here. It should be noted that there is no specific order between steps S503A and steps S504-S506 in the embodiment of the present application, that is, step S503A can be executed before steps S504-S506, or can be executed simultaneously, and the present application is not limited thereto.
[0208] Step S507: When the target packet assembly circular queue receives N pieces of packet header information of target data packets, the network processor NP device 204 splices the received N pieces of packet header information of target data packets to generate a to-be-encapsulated packet body.
[0209] Step S508: Based on the communication protocol between the network processor NP device and the probe device, the network processor NP device 204 encapsulates the to-be-encapsulated packet body to generate a spliced data packet.
[0210] Specifically, for the related description of steps S507-S508, refer to the related description of step S402 in FIG. 4, which will not be repeated here.
[0211] Step S509: The network processor NP device 204 sends the spliced data packet to the probe device 205, and the spliced data packet is used for traffic analysis by the probe device.
[0212] Specifically, for the specific description of step S509, refer to the related description of step S403 in the method embodiment in FIG. 4, which will not be repeated here.
[0213] Step S510: The probe device 205 receives the third data packet sent by the network processor NP device 204.
[0214] Specifically, the third data packet includes the spliced data packet, the second data packet, and the dummy packet. For the specific description of step S510, refer to the related description of step S404 in FIG. 4, which will not be repeated here.
[0215] Step S511: The probe device 205 parses the third data packet.
[0216] Step S512: The probe device 205 determines whether the value of a target field in the third data packet satisfies a preset condition. The value of the target field is used to indicate the number of data packets contained in the third data packet.
[0217] Specifically, for the specific description of step S512, refer to the related description of step S405 in the method embodiment in FIG. 4, which will not be repeated here.
[0218] Step S513A: If yes, the probe device 205 determines that the third data packet is the spliced data packet, and distributes the spliced data packet to a corresponding thread based on the target address of the spliced data packet, and then goes to step S514.
[0219] Specifically, for the specific description of step S513A, refer to the related description of step S405 in the method embodiment in FIG. 4, which will not be repeated here.
[0220] Step S513B: If no, the probe device 205 determines that the third data packet is the second data packet or the dummy packet, and calculates the pipeline index and the experience index of the third data packet to generate a second bill XDR, and then goes to step S518.
[0221] Specifically, the detailed description of step S513B can refer to the description of step S407 in the method embodiment of FIG. 4, which will not be repeated here.
[0222] Step S514: When the target thread receives the spliced data packet, the probe device 205 splits the received spliced data packet into N fourth data packets through the transceiving packet queue.
[0223] Step S515: The probe device 205 calculates the corresponding hash value based on the quintuple information of each fourth data packet. The quintuple information includes the source address, source port, target address, target port, and transport layer protocol of the fourth data packet.
[0224] Step S516: Based on the calculated hash value, the probe device 205 determines the hash table entry matched with the fourth data packet to generate a flow table.
[0225] Step S517: Based on the information of the flow table, the probe device 205 calculates the pipeline index and experience index of the fourth data packet to generate a first bill XDR.
[0226] Step S518: The probe device 205 sends the first bill XDR and / or the second bill XDR to the server. The first bill XDR and / or the second bill XDR are used for the server to perform data analysis and generate a report.
[0227] Specifically, the detailed description of steps S514-S518 can refer to the description of steps S406-S407 in the method embodiment of FIG. 4, which will not be repeated here.
[0228] The embodiments of the present application only exemplarily introduce a possible implementation manner of the control method provided by the embodiments of the present application. In other embodiments, the terminal device can also perform more / less steps, or combine or split one or more steps, and the embodiments of the present application do not limit this.
[0229] Exemplarily, refer to FIG. 6, which is a flow diagram of another traffic data processing provided by an embodiment of the present application. As shown in FIG. 6, the traffic analysis system 600 to which the traffic data processing is applied can include the network processor NP device 204 and the probe device 205. The related descriptions of the network processor NP device 204 and the probe device 205 can refer to the related descriptions in FIG. 2, FIG. 3A and FIG. 3B above, which will not be repeated here. After the network processor NP device 204 receives the original packet (i.e., the first data packet) of the mirrored traffic data through the network port, the network processor NP device 204 parses the received data packet according to the common Internet protocol stack, and then determines whether the original packet uses an encryption protocol (i.e., a target encryption protocol, such as one or more of Quic, TLS / SSL protocols) by identifying the port number and / or the keyword. Exemplarily, when the port number of the original packet is UDP PORT==443, the original packet is identified as a target data packet using the Quic protocol; when the port number of the original packet is TCP PORT==443, the original packet is identified as a target data packet using the TLS / SSL protocol; when the port number of the original packet does not match the preset port number (e.g., 443), the original packet is determined as a second data packet not using the target encryption protocol, and the second data packet is directly sent to the probe device 205 for traffic analysis.
[0230] Further, as shown in FIG. 6, in a case where the network processor NP device 204 identifies that the original packet (i.e., the first data packet) uses a target encryption protocol (e.g., one or more of Quic, TLS / SSL protocols), the packet using the target encryption protocol (i.e., the target data packet) is packetized, i.e., the unencrypted header information of the packet (i.e., the target data packet) is intercepted. For example, for the original packet (i.e., the first data packet) using the Quic protocol, the protocol stack is IP->UDP->Quic, and for the original packet using the TLS / SSL protocol, the protocol stack is IP->TCP->TLS / SSL; through the packetization function, the original packet (i.e., the first data packet) using the Quic or TLS / SSL protocol is packetized to obtain the header information containing IP+TCP / UDP. At the same time, for the packet using the target encryption protocol (i.e., the target data packet), it is further judged whether the packet is a static payload packet, i.e., the target data packet using the target encryption protocol but not including encrypted messages in the packet body, such as judging whether the packet is a static payload packet by identifying whether the packet is a preset message. For example, for the data packet (i.e., the target data packet) using different encryption protocols, the corresponding preset message is also different. For example, for the data packet using the Quic protocol, the preset message can be an initial message; for the data packet using the TLS / SSL protocol, the preset message can be a client Client Hello or server Server Hello message. If it is identified that the packet (i.e., the target data packet) is a preset message, the packet (i.e., the target data packet) is a static payload packet, otherwise it is an encrypted data packet. The embodiments of the present application only exemplarily introduce several possible types of preset messages, and in other embodiments, due to the difference of encryption protocols and / or application scenarios, the type of preset message can include but is not limited to the above several message types, and the embodiments of the present application are not limited thereto.
[0231] Further, as shown in FIG. 6, M packet assembly loop queues (M is a positive integer greater than or equal to 1) can be included in the network processor NP device 204, and FIG. 6 exemplarily shows four packet assembly loop queues. For the packet header information (such as IP and TCP / UDP packet header information) obtained after packet slicing, the network processor NP device 204 distributes the packet header information to the corresponding packet assembly loop queue according to the mobile terminal Internet protocol address MSIP in the packet header information. Exemplarily, when a target packet assembly loop queue in the M packet assembly loop queues receives N packet header information (for example, four packet header information a, b, c, and d shown in FIG. 6), N is a positive integer greater than 1, the received N packet header information (for example, four packet header information a, b, c, and d shown in FIG. 6) is spliced to form a to-be-encapsulated packet body of a spliced data packet, and encapsulation packet header information is added to the to-be-encapsulated packet body to generate an encapsulated spliced data packet. The generation process of the encapsulation packet header information can include modifying the value of a target field in the encapsulation packet header information to the number of data packets encapsulated in the spliced data packet (for example, modifying the first four bytes of the target MAC address to MagicNum to indicate the number of data packets encapsulated in the spliced data packet), and modifying the target address (for example, the target IP address) in the encapsulation packet header information to the address of the corresponding thread in the probe device to which the spliced data packet is sent. Further, the modified encapsulation packet header information is added to the to-be-encapsulated packet body, thereby generating the encapsulated spliced data packet. Exemplarily, please refer to FIG. 7, which is a flowchart of generating a spliced data packet from a data packet based on encrypted traffic provided by an embodiment of the present application. As shown in FIG. 7, for encrypted data packets (i.e., target data packets) packet 1, packet 2, packet 3, and packet 4 using a target encryption protocol (for example, Quic protocol), the protocol stack of each data packet can include IP->UDP->Quic. After slicing the packet 1, packet 2, packet 3, and packet 4, the packet header information that only retains IP+UDP is generated. Further, by splicing and encapsulating the packet header information of the intercepted packet 1, packet 2, packet 3, and packet 4, a spliced data packet that splices four IP+UDP packet header information can be generated. The packet body of the spliced data packet includes the IP+UDP packet header information of the packet 1, packet 2, packet 3, and packet 4, and the encapsulation packet header information of the spliced data packet includes MAC+IP, wherein the first four bytes of the MAC address are MagicNum, which can be used to indicate the number of data packets encapsulated in the spliced data packet; and the IP address can be used to indicate the address of the corresponding thread in the probe device to which the spliced data packet is sent.It should be noted that the embodiments of the present application only exemplarily take the packet 1, the packet 2, the packet 3 and the packet 4 of the target encryption protocol as the Quic protocol as an example to introduce the specific steps of generating the spliced data packet, and in some embodiments, more / less or data packets using different target encryption protocols (for example, one or more of the Quic protocol, the TLS / SSL protocol) can be cut and spliced, thereby generating different spliced data packets, which are not limited in the embodiments of the present application.
[0232] Further, as shown in FIG. 6, the probe device 205 receives the data packet (that is, the third data packet, including the spliced data packet, the second data packet and the static payload packet) sent by the network processor NP device 204 through the network port, and parses the data packet according to the protocol, and then identifies whether the data packet is a spliced data packet by identifying whether the value of the target field (for example, the first 4 bytes of the MAC address) in the data packet meets the preset condition (for example, greater than 1 and less than 20). If the data packet is a spliced data packet, the target address of the spliced data packet is read, and the spliced data packet is distributed to the corresponding thread. When the target thread in the probe device 205 receives the spliced data packet, the spliced data packet can be split into N fourth data packets containing the header information of the encrypted traffic data packet (that is, the target data packet) through the corresponding transceiving packet queue, and the hash value is matched based on the quintuple information (including the source address, the source port, the target address, the target port and the transmission layer protocol of the fourth data packet) to generate a flow table, and then the pipe index and the experience index are calculated based on the information of the flow table to generate the bill XDR (that is, the first bill XDR). If it is identified that the data packet is not a spliced data packet, that is, the data packet is a second data packet not using the target encryption protocol or a static payload packet using the target encryption protocol, the pipe index and the experience index are directly calculated for the data packet to generate the bill XDR (that is, the second bill XDR). In some embodiments, the traffic analysis system (for example, the CEM system) can further include a server (for example, a CEM platform server), and all bills XDR (including the first bill XDR and / or the second bill XDR) generated by the probe device 205 are sent to the server, thereby generating a report related to user experience. Through the embodiments of the present application, the integrity of the traffic data can be ensured, and part of the calculation task of the server in the traffic analysis system can be unloaded to reduce the processing load of the server in the traffic analysis system, thereby improving the performance of the traffic analysis system, and at the same time, the dependence of the traffic analysis system on the number of servers can be reduced, thereby improving the performance of the traffic analysis system in processing traffic data without increasing the number of servers and controlling the cost.
[0233] The above describes the method of the embodiments of the present application in detail, and the related devices of the embodiments of the present application are provided below.
[0234] Please refer to Fig. 8, which is a structural schematic diagram of another network processor NP device 204 provided in the embodiment of the present application. The network processor NP device 204 can include a receiving unit 801, an identifying unit 802, a cutting unit 803, a splicing unit 804, and a first sending unit 805. The detailed description of each unit is as follows.
[0235] The receiving unit 801 is configured to receive a first data packet.
[0236] The identifying unit 802 is configured to identify whether the first data packet is a target data packet using a target encryption protocol.
[0237] The cutting unit 803 is configured to cut the header information of the target data packet if it is identified that the first data packet is the target data packet using the target encryption protocol.
[0238] The splicing unit 804 is configured to splice the header information of N target data packets into one spliced data packet, where N is a positive integer greater than 1.
[0239] The first sending unit 805 is configured to send the spliced data packet to the probe device, where the spliced data packet is used for flow analysis by the probe device.
[0240] In a possible implementation, the identifying unit 802 is specifically configured to:
[0241] determine whether the port number of the first data packet matches a preset port number;
[0242] if yes, determine that the first data packet is the target data packet using the target encryption protocol;
[0243] if no, determine that the first data packet is a second data packet not using the encryption protocol.
[0244] In a possible implementation, the first data packet includes header information and a packet body. The network processor NP device 204 further includes:
[0245] a judging unit configured to, if it is identified that the first data packet is the target data packet using the target encryption protocol, judge whether the packet body of the target data packet is an encrypted message;
[0246] a first determining unit configured to, if the packet body of the target data packet is the encrypted message, determine that the target data packet is an encrypted data packet using the target encryption protocol;
[0247] a second determining unit configured to, if the packet body of the target data packet is a non-encrypted message, determine that the target data packet is a payload packet using the target encryption protocol.
[0248] In a possible implementation, the judging unit is specifically configured to:
[0249] identify whether the target data packet is a preset message;
[0250] if yes, determine that the packet body of the target data packet is the non-encrypted message; and if no, determine that the packet body of the target data packet is the encrypted message.
[0251] In a possible implementation, the network processor NP device 204 includes one or more packet assembly circular queues, and the network processor NP device 204 further includes:
[0252] a distribution unit configured to distribute the packet header information to a corresponding packet assembly circular queue according to a mobile terminal internet protocol address MSIP in the packet header information.
[0253] In a possible implementation, the packet assembly unit 804 is specifically configured to:
[0254] when a target packet assembly circular queue receives N pieces of packet header information of the target data packet, splice the N pieces of packet header information of the target data packet into the spliced data packet, N being a positive integer greater than 1.
[0255] In a possible implementation, the packet assembly unit 804 is specifically configured to:
[0256] splice the received N pieces of packet header information of the target data packet to generate a to-be-encapsulated packet body of the spliced data packet;
[0257] encapsulate the to-be-encapsulated packet body based on a communication protocol between the network processor NP device 204 and the probe device, to generate the spliced data packet.
[0258] In a possible implementation, the packet assembly unit 804 is specifically configured to:
[0259] modify a value of a target field in the encapsulated packet header information to a number of data packets encapsulated in the spliced data packet, and modify a target address in the encapsulated packet header information to an address of a corresponding thread in the probe device to which the spliced data packet is sent;
[0260] add the modified encapsulated packet header information to the to-be-encapsulated packet body, to generate the spliced data packet.
[0261] In a possible implementation, the network processor NP device 204 further includes:
[0262] The second sending unit is configured to send the second data packet to the probe device if it is determined that the first data packet is the second data packet not using the target encryption protocol.
[0263] In a possible implementation, the network processor NP device 204 further includes:
[0264] The third sending unit is configured to send the payload packet to the probe device if it is determined that the target data packet is the payload packet using the target encryption protocol.
[0265] It should be noted that the functions of the functional units in the network processor NP device 204 described in the embodiments of the present application can refer to the related descriptions in the method embodiments described above, and will not be described here again. In the above embodiments, the descriptions of various embodiments are each focused on, and if there is no detailed part in a certain embodiment, the related description can be referred to the description of other embodiments.
[0266] Please refer to FIG. 9, which is a structural schematic diagram of another probe device 205 provided by an embodiment of the present application. The probe device 205 can include a receiving unit 901, an identifying unit 902, a packet splitting unit 903, and a flow table generating unit 904. The detailed descriptions of the units are as follows.
[0267] The receiving unit 901 is configured to receive a third data packet sent by the network processor NP device 204, wherein the third data packet includes a spliced data packet, a second data packet, and a payload packet.
[0268] The identifying unit 902 is configured to identify whether the third data packet is the spliced data packet.
[0269] The packet splitting unit 903 is configured to split the spliced data packet into N fourth data packets if it is identified that the third data packet is the spliced data packet, wherein the fourth data packets include the header information of the target data packets corresponding to the spliced data packet.
[0270] The flow table generating unit 904 is configured to generate a flow table based on the five-tuple information of the fourth data packet, wherein the five-tuple information includes the source address, the source port, the target address, the target port, and the transport layer protocol of the fourth data packet.
[0271] In a possible implementation, the identifying unit 902 is specifically configured to:
[0272] determine whether the value of a target field in the third data packet satisfies a preset condition, wherein the value of the target field is used to indicate the number of data packets included in the third data packet.
[0273] If the value of the target field meets the preset condition, the third data packet is determined as the splicing data packet.
[0274] If the value of the target field does not meet the preset condition, the third data packet is determined as the second data packet or the static data packet.
[0275] In a possible implementation, the probe device 205 includes one or more threads, and the threads correspond to the packet assembly loop queues in the network processor NP device one by one. The probe device 205 further includes:
[0276] A distribution unit is configured to, if the third data packet is identified as the splicing data packet, distribute the splicing data packet to a corresponding thread based on a target address of the splicing data packet.
[0277] In a possible implementation, each of the threads corresponds to a transceiving packet queue. The packet disassembly unit 903 is specifically configured to:
[0278] When the target thread receives the splicing data packet, the received splicing data packet is split into N fourth data packets through the transceiving packet queue.
[0279] In a possible implementation, the flow table generation unit 904 is specifically configured to:
[0280] Based on the five-tuple information of each fourth data packet, a corresponding hash value is calculated respectively.
[0281] Based on the calculated hash value, a hash table entry matched with the fourth data packet is determined to generate the flow table.
[0282] In a possible implementation, the probe device 205 further includes:
[0283] A first bill generation unit is configured to calculate a pipe index and an experience index of the fourth data packet based on information of the flow table, to generate a first bill XDR.
[0284] In a possible implementation, the probe device 205 further includes:
[0285] A second bill generation unit is configured to, if the third data packet is identified as not being the splicing data packet, calculate a pipe index and an experience index of the third data packet, to generate a second bill XDR.
[0286] In a possible implementation, the system further includes a server. The probe device 205 further includes:
[0287] The sending unit is configured to send the first bill XDR and / or the second bill XDR to the server, and the first bill XDR and / or the second bill XDR are used for data analysis and report generation by the server.
[0288] It should be noted that the functions of the functional units in the probe device 205 described in the embodiments of the present application can be referred to the related descriptions in the method embodiments, which will not be described here again. In the above embodiments, the description of each embodiment has its own emphasis, and if there is no detailed part in a certain embodiment, it can be referred to the related description of other embodiments.
[0289] As shown in FIG. 10, FIG. 10 is a structural schematic diagram of another network processor NP device 204 provided by the embodiments of the present application, which includes at least one processor 1001, at least one memory 1002, and at least one communication interface 1003. In addition, the device can also include general components such as antennas, which will not be described here in detail.
[0290] The processor 1001 can be a general central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of programs of the above solutions.
[0291] The communication interface 1003 is configured to communicate with other devices or communication networks, such as Ethernet, radio access network (RAN), core network, wireless local area network (WLAN), etc.
[0292] The memory 1002 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an Electrically Erasable Programmable Read-Only Memory (EEPROM), a Compact Disc Read-Only Memory (CD-ROM) or other optical disk storage, a magnetic disk storage or other magnetic storage devices, or any other medium capable of storing desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited to this. The memory can exist independently and be connected to the processor through a bus. The memory can also be integrated with the processor.
[0293] The memory 1002 is configured to store application program codes for implementing the above solutions, and the processor 1001 is configured to control the execution of the application program codes. The processor 1001 is configured to execute the application program codes stored in the memory 1002. The codes stored in the memory 1002 can execute part or all of the steps of the network traffic identification method provided in the above method embodiments.
[0294] It should be noted that the functions of each functional unit in the network processor NP device 204 described in the embodiments of the present application can refer to the related description in the above method embodiments, which will not be described here.
[0295] In the above embodiments, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can refer to the related description of other embodiments.
[0296] As shown in FIG. 11, FIG. 11 is a structural schematic diagram of another probe device 205 provided by the embodiments of the present application, which includes at least one processor 1101, at least one memory 1102, and at least one communication interface 1103. In addition, the device can also include an antenna and other general-purpose components, which will not be described here.
[0297] The processor 1101 can be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the above solutions.
[0298] The communication interface 1103 is configured to communicate with other devices or communication networks, such as an Ethernet, a radio access network (RAN), a core network, a wireless local area network (WLAN), and the like.
[0299] The memory 1102 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disk storage, a magnetic disk storage or other magnetic storage devices, or any other medium capable of storing desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited to this. The memory can exist independently, and is connected to the processor through a bus. The memory can also be integrated with the processor.
[0300] The memory 1102 is configured to store application program codes for implementing the above solutions, and the processor 1101 is configured to control the execution of the application program codes. The processor 1101 is configured to execute the application program codes stored in the memory 1102. The codes stored in the memory 1102 can execute part or all of the steps of the network traffic identification method provided in the above method embodiments.
[0301] It should be noted that the functions of each functional unit in the probe device 205 described in the embodiments of the present application can be referred to the related description in the above method embodiments, which will not be described here.
[0302] In the above embodiments, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments.
[0303] It should be noted that, for the foregoing method embodiments, in order to simply describe, they are all described as a series of action combinations, but those skilled in the art should know that the present application is not limited to the order of the described actions, because according to the present application, some steps can be performed in other order or at the same time. Secondly, those skilled in the art should know that the embodiments described in the specification all belong to preferred embodiments, and the actions and modules involved are not necessarily required by the present application.
[0304] In several embodiments provided in the present application, it should be understood that the disclosed apparatus can be implemented in other manners. For example, the division of the above-described apparatus embodiments is merely illustrative, and the division of the above-described units can be changed, and some units can be combined or integrated into another system, or some features can be ignored or not executed. In this way, the internal structure of the apparatus is not limited to the above.
[0305] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, that is, can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiments.
[0306] In addition, each functional unit in the embodiments of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0307] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solutions of the present application essentially or the part that contributes to the prior art, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc., and specifically can be a processor in a computer device) to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium can include: U disk, mobile hard disk, magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), and various other media that can store program codes.
[0308] The above embodiments are merely used to describe the technical solutions of the present application, rather than limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacements to some technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
A method of processing traffic data, characterized by A network processor (NP) device applied to a traffic analysis system, the method comprising: receiving a first data packet, identifying whether the first data packet is a target data packet using a target encryption protocol; if yes, intercepting a packet header information of the target data packet; splicing N packet header information of the target data packet into a spliced data packet, N being a positive integer greater than 1; sending the spliced data packet to the probe device, the spliced data packet being used for traffic analysis by the probe device. The method of claim 1, wherein The identification of whether the first data packet is a target data packet using a target encryption protocol comprises: determining whether a port number of the first data packet matches a preset port number; if yes, determining that the first data packet is the target data packet using the target encryption protocol; if no, determining that the first data packet is a second data packet not using the target encryption protocol. The method according to claim 1 or 2, characterized in that The first data packet comprises packet header information and a packet body; the method further comprises: if it is identified that the first data packet is the target data packet using the target encryption protocol, determining whether the packet body of the target data packet is an encrypted message; if the packet body of the target data packet is the encrypted message, determining that the target data packet is an encrypted data packet using the target encryption protocol; if the packet body of the target data packet is a non-encrypted message, determining that the target data packet is a static load packet using the target encryption protocol. The method according to claim 3, characterized in that The determination of whether the packet body of the target data packet is an encrypted message comprises: identifying whether the target data packet is a preset message; if yes, determining that the packet body of the target data packet is the non-encrypted message; if no, determining that the packet body of the target data packet is the encrypted message. The method according to any one of claims 1 to 4, characterized in that The network processor (NP) device comprises one or more packet assembly circular queues, and the method further comprises: distributing the packet header information to a corresponding packet assembly circular queue according to a mobile terminal internet protocol (MSIP) address in the packet header information. The method according to claim 5, characterized in that The splicing of N packet header information of the target data packet into a spliced data packet comprises: when a target packet assembly circular queue receives N packet header information of the target data packet, splicing the N packet header information of the target data packet into the spliced data packet, N being a positive integer greater than 1. The method according to claim 6, characterized in that The splicing of N packet header information of the target data packet into the spliced data packet comprises: splicing the received N packet header information of the target data packet to generate a to-be-encapsulated packet body of the spliced data packet; based on a communication protocol between the network processor (NP) device and the probe device, encapsulating the to-be-encapsulated packet body to generate the spliced data packet. The method of claim 7, wherein The encapsulation of the to-be-encapsulated packet body to generate the spliced data packet comprises: modifying a value of a target field in encapsulation packet header information to a number of encapsulated data packets in the spliced data packet, and modifying a target address in the encapsulation packet header information to an address of a corresponding thread in the probe device to which the spliced data packet is sent; adding the modified encapsulation packet header information to the to-be-encapsulated packet body to generate the spliced data packet. The method according to any one of claims 2-8, characterized in that The method further comprises: If it is determined that the first data packet is the second data packet not using the target encryption protocol, the second data packet is sent to the probe device. The method according to any one of claims 3-9, characterized in that The method further includes: If it is determined that the target data packet is the payload packet using the target encryption protocol, the payload packet is sent to the probe device. A method of processing traffic data, characterized by The method applied to a probe device in a traffic analysis system includes: Receiving a third data packet sent by the network processor (NP) device; Identifying whether the third data packet is a spliced data packet; If yes, the spliced data packet is split into N fourth data packets, the fourth data packets including the header information of the target data packet corresponding to the spliced data packet; Based on the quintuple information of the fourth data packet, a flow table is generated, the quintuple information including the source address, source port, target address, target port, and transmission layer protocol of the fourth data packet. The method of claim 11, wherein The identification of whether the third data packet is the spliced data packet includes: Judging whether the value of a target field in the third data packet meets a preset condition, the value of the target field being used to indicate the number of data packets included in the third data packet; If the value of the target field meets the preset condition, it is determined that the third data packet is the spliced data packet. The method according to claim 11 or 12, characterized in that The probe device includes one or more threads, and the threads correspond to the packet assembly circular queues in the network processor (NP) device one by one, and the method further includes: If it is identified that the third data packet is the spliced data packet, the spliced data packet is distributed to the corresponding thread based on the target address of the spliced data packet. The method of claim 13, wherein Each of the threads corresponds to a transceiving packet queue; and the splitting of the spliced data packet into N fourth data packets includes: When the target thread receives the spliced data packet, the received spliced data packet is split into N fourth data packets in the transceiving packet queue. The method according to any one of claims 11-14, characterized in that The generation of the flow table based on the quintuple information of the fourth data packet includes: Based on the quintuple information of each fourth data packet, a corresponding hash value is calculated respectively; Based on the calculated hash value, a hash table entry matching the fourth data packet is determined to generate the flow table. The method according to any one of claims 11-15, characterized in that The method further includes: Performing traffic analysis on the flow table. The method of claim 16, wherein The traffic analysis on the flow table includes: Based on the information of the flow table, a pipeline index and an experience index of the fourth data packet are calculated to generate a first bill of XDR. The method according to any one of claims 11-17, characterized in that The method further includes: If it is identified that the third data packet is not the spliced data packet, a pipeline index and an experience index of the third data packet are calculated to generate a second bill of XDR. The method according to claim 17 or 18, characterized in that The system further includes a server; and the method further includes: The first bill of XDR and / or the second bill of XDR are sent to the server, and the first bill of XDR and / or the second bill of XDR are used for data analysis and report generation by the server. A network processor (NP) device, comprising: It includes: A receiving unit is configured to receive a first data packet; An identifying unit is configured to identify whether the first data packet is a target data packet using a target encryption protocol; The packet cutting unit is configured to cut packet header information of the target data packet if it is identified that the first data packet is the target data packet using the target encryption protocol. The packet splicing unit is configured to splice the packet header information of N target data packets into one spliced data packet, where N is a positive integer greater than 1. The first sending unit is configured to send the spliced data packet to the probe device, where the spliced data packet is used for flow analysis by the probe device. A probe device characterized in that, The receiving unit is configured to receive a third data packet sent by the network processor (NP) device. The identifying unit is configured to identify whether the third data packet is a spliced data packet. The packet splitting unit is configured to split the spliced data packet into N fourth data packets if it is identified that the third data packet is the spliced data packet, where the fourth data packets include packet header information of target data packets corresponding to the spliced data packet. The flow table generating unit is configured to generate a flow table based on five-tuple information of the fourth data packets, where the five-tuple information includes source address, source port, target address, target port, and a transport layer protocol of the fourth data packets. The probe device further includes a unit configured to perform flow analysis on the flow table. The probe device according to claim 21, characterized in that The processor, the memory, and the communication interface are included, where the memory is configured to store information sending program code, and the processor is configured to invoke the program code stored in the memory to execute the method in any one of claims 1-10. A network processor (NP) device, comprising: The processor, the memory, and the communication interface are included, where the memory is configured to store information sending program code, and the processor is configured to invoke the program code stored in the memory to execute the method in any one of claims 11-19. A probe device characterized in that, The chip system includes at least one processor, a memory, and an interface circuit, the memory, the interface circuit, and the at least one processor are interconnected through a line, and the at least one memory stores instructions; when the instructions are executed by the processor, the method in any one of claims 1-10 is implemented, or the method in any one of claims 11-19 is implemented. A chip system, characterized by The computer storage medium stores a computer program, and the computer program is executed by a processor to implement the method in any one of claims 1-10 or the method in any one of claims 11-19. A computer storage medium, characterized by The computer program includes instructions, and when the computer program is executed by a computer, the computer executes the method in any one of claims 1-10 or the method in any one of claims 11-19. A computer program, characterized in that The network processor (NP) device and the probe device are included. A traffic analysis system characterized by The network processor (NP) device is configured to receive a first data packet, identify whether the first data packet is a target data packet using a target encryption protocol, cut packet header information of the target data packet if the first data packet is the target data packet, splice packet header information of N target data packets into one spliced data packet, where N is a positive integer greater than 1, and send the spliced data packet to the probe device. The probe device is configured to perform flow analysis based on the spliced data packet. The system of claim 28, wherein The probe device is particularly used for: The spliced data packet is split into N fourth data packets, the fourth data packet includes the packet header information of the target data packet corresponding to the spliced data packet; a flow table is generated based on the quintuple information of the fourth data packet, and traffic analysis is performed on the flow table; the quintuple information includes the source address, the source port, the target address, the target port and the transmission layer protocol of the fourth data packet.
Citation Information
Patent Citations
Message forwarding method, device, equipment, medium and program product
CN114567687A
Flow link analysis method and system based on Flink component
CN114979186A
Network traffic data monitoring method and device, medium and electronic equipment
CN115766142A
Dynamic IP device identification system and method for encrypted traffic
CN115766204A
Algorithm card scheduling method and device, storage medium and electronic equipment
CN118175205A