[go: up one dir, main page]

CN116248471A - Flow detection system, method, device and storage medium thereof - Google Patents

Flow detection system, method, device and storage medium thereof Download PDF

Info

Publication number
CN116248471A
CN116248471A CN202211572525.3A CN202211572525A CN116248471A CN 116248471 A CN116248471 A CN 116248471A CN 202211572525 A CN202211572525 A CN 202211572525A CN 116248471 A CN116248471 A CN 116248471A
Authority
CN
China
Prior art keywords
address
traffic
label
flow
data
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN202211572525.3A
Other languages
Chinese (zh)
Inventor
杨世标
薛松荃
陈孟尝
刘思勤
赵欢
张志安
黄坤
赵堃翔
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China United Network Communications Group Co Ltd
Original Assignee
China United Network Communications Group Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China United Network Communications Group Co Ltd filed Critical China United Network Communications Group Co Ltd
Priority to CN202211572525.3A priority Critical patent/CN116248471A/en
Publication of CN116248471A publication Critical patent/CN116248471A/en
Pending legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0677Localisation of faults
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y02TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
    • Y02DCLIMATE CHANGE MITIGATION TECHNOLOGIES IN INFORMATION AND COMMUNICATION TECHNOLOGIES [ICT], I.E. INFORMATION AND COMMUNICATION TECHNOLOGIES AIMING AT THE REDUCTION OF THEIR OWN ENERGY USE
    • Y02D30/00Reducing energy consumption in communication networks
    • Y02D30/50Reducing energy consumption in communication networks in wire-line communication networks, e.g. low power modes or reduced link rate

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本申请涉及通信技术领域,尤其涉及一种流量检测系统、方法、装置及其存储介质,能够有效检测IP地址。该方法包括:识别数据流量的流量标签;流量标签为入方向流量标签和出方向流量标签中的任一项;在流量标签为入方向流量标签的情况下,确定数据流量的目的IP地址;确定目的IP地址是否为备案IP地址;在流量标签为出方向流量标签的情况下,确定数据流量的源IP地址;确定源IP地址是否为备案IP地址。本申请用于流量检测过程中。

Figure 202211572525

The present application relates to the technical field of communications, and in particular to a traffic detection system, method, device and storage medium thereof, capable of effectively detecting IP addresses. The method includes: identifying the flow label of the data flow; the flow label is any one of the inbound flow label and the outbound flow label; in the case that the flow label is the inbound flow label, determining the destination IP address of the data flow; determining Whether the destination IP address is a filing IP address; if the traffic label is an outbound traffic label, determine the source IP address of the data traffic; determine whether the source IP address is a filing IP address. This application is used in the flow detection process.

Figure 202211572525

Description

流量检测系统、方法、装置及其存储介质Flow detection system, method, device and storage medium thereof

技术领域technical field

本申请涉及通信技术领域,尤其涉及一种流量检测系统、方法、装置及其存储介质。The present application relates to the technical field of communication, and in particular to a flow detection system, method, device and storage medium thereof.

背景技术Background technique

在相关技术中,针对互联网数据中心(Internet Data Center,IDC)或网络业务提供商(Internet Service Provider,ISP)的互联网协议(Internet Protocol,IP)地址无法有效监测,易出现告警设备对用户备案地址错报的问题。因此,如何有效检测IP地址是目前亟待解决的问题。In related technologies, Internet Protocol (IP) addresses for Internet Data Centers (Internet Data Centers, IDCs) or Internet Service Providers (Internet Service Providers, ISPs) cannot be effectively monitored, and it is easy for alarm devices to record addresses for users. The problem of misstatement. Therefore, how to effectively detect the IP address is an urgent problem to be solved at present.

发明内容Contents of the invention

本申请提供一种流量检测系统、方法、装置及其存储介质,能够有效检测IP地址。The present application provides a traffic detection system, method, device and storage medium thereof, capable of effectively detecting IP addresses.

为达到上述目的,本申请采用如下技术方案:In order to achieve the above object, the application adopts the following technical solutions:

第一方面,本申请提供一种流量检测系统,该系统包括:核心路由器CR、互联网数据中心IDC设备、汇聚分流设备、以及执行单元EU;CR和IDC设备通过通信链路连接并通过通信链路互相转发数据;汇聚分流设备通过分光器接入CR和IDC设备之间的通信链路;汇聚分流设备,被配置为:获取CR和IDC设备之间转发的第一数据流量;根据预设二层报文策略为第一数据流量添加标签,生成第二数据流量,向执行单元EU发送第二数据流量;执行单元EU,被配置为:接收第二数据流量,确定第二数据流量的流量标签;流量标签为入方向流量标签和出方向流量标签中的任一项;在流量标签为入方向流量标签的情况下,确定数据流量的目的IP地址;确定目的IP地址是否为备案IP地址;在流量标签为出方向流量标签的情况下,确定数据流量的源IP地址;确定源IP地址是否为备案IP地址。In the first aspect, the present application provides a traffic detection system, which includes: a core router CR, an Internet data center IDC device, a converging and distributing device, and an execution unit EU; Mutual forwarding of data; the aggregation and distribution device accesses the communication link between the CR and the IDC device through the optical splitter; the aggregation and distribution device is configured to: obtain the first data flow forwarded between the CR and the IDC device; according to the preset Layer 2 The message policy adds a label to the first data flow, generates a second data flow, and sends the second data flow to the execution unit EU; the execution unit EU is configured to: receive the second data flow, and determine the flow label of the second data flow; The traffic label is any one of the inbound traffic label and the outbound traffic label; if the traffic label is the inbound traffic label, determine the destination IP address of the data traffic; determine whether the destination IP address is the filing IP address; If the label is an outbound traffic label, determine the source IP address of the data traffic; determine whether the source IP address is the record IP address.

结合第一方面,在一种可能的实现方式中,系统还包括:告警输出设备;EU,还被配置为:在目的IP地址或源IP地址不为备案IP地址的情况下,生成告警信息;向告警输出设备发送告警信息;告警输出设备,还被配置为:输出告警信息。In combination with the first aspect, in a possible implementation manner, the system further includes: an alarm output device; the EU is further configured to: generate alarm information when the destination IP address or the source IP address is not the filing IP address; Send alarm information to an alarm output device; the alarm output device is also configured to: output alarm information.

第二方面,本申请提供一种流量检测方法,方法包括:识别数据流量的流量标签;流量标签为入方向流量标签和出方向流量标签中的任一项;在流量标签为入方向流量标签的情况下,确定数据流量的目的IP地址;确定目的IP地址是否为备案IP地址;在流量标签为出方向流量标签的情况下,确定数据流量的源IP地址;确定源IP地址是否为备案IP地址。In the second aspect, the present application provides a flow detection method, the method includes: identifying the flow label of the data flow; the flow label is any one of the flow label in the inbound direction and the flow label in the outbound direction; In this case, determine the destination IP address of the data traffic; determine whether the destination IP address is the filing IP address; if the traffic label is the outbound traffic label, determine the source IP address of the data traffic; determine whether the source IP address is the filing IP address .

结合第二方面,在一种可能的实现方式中,流量标签为汇聚分流设备获取到数据流量之后,根据预设二层报文策略为数据流量添加的标签。With reference to the second aspect, in a possible implementation manner, the traffic label is a label added to the data traffic according to a preset Layer 2 packet policy after the convergence and distribution device acquires the data traffic.

结合第二方面,在一种可能的实现方式中,方法还包括:在目的IP地址或源IP地址不为备案IP地址的情况下,生成告警信息;向告警输出设备发送告警信息。With reference to the second aspect, in a possible implementation manner, the method further includes: generating alarm information when the destination IP address or the source IP address is not the record IP address; and sending the alarm information to an alarm output device.

第三方面,本申请提供一种流量检测装置,该装置包括:装置包括:处理单元;处理单元,用于识别数据流量的流量标签;流量标签为入方向流量标签和出方向流量标签中的任一项;在流量标签为入方向流量标签的情况下,处理单元,还用于确定数据流量的目的IP地址;处理单元,还用于确定目的IP地址是否为备案IP地址;在流量标签为出方向流量标签的情况下,处理单元,还用于确定数据流量的源IP地址;处理单元,还用于确定源IP地址是否为备案IP地址。In a third aspect, the present application provides a flow detection device, which includes: the device includes: a processing unit; the processing unit is used to identify the flow label of the data flow; the flow label is any one of the inbound flow label and the outbound flow label One item; when the flow label is an inbound flow label, the processing unit is also used to determine the destination IP address of the data flow; the processing unit is also used to determine whether the destination IP address is an IP address for filing; In the case of a direction flow label, the processing unit is also used to determine the source IP address of the data flow; the processing unit is also used to determine whether the source IP address is a filing IP address.

结合第三方面,在一种可能的实现方式中,流量标签为汇聚分流设备获取到数据流量之后,根据预设二层报文策略为数据流量添加的标签。In combination with the third aspect, in a possible implementation manner, the traffic label is a label added to the data traffic according to a preset Layer 2 packet policy after the convergence and distribution device obtains the data traffic.

结合第三方面,在一种可能的实现方式中,装置还包括:通信单元;在目的IP地址或源IP地址不为备案IP地址的情况下,处理单元,还用于生成告警信息;通信单元,用于向告警输出设备发送告警信息。In combination with the third aspect, in a possible implementation manner, the device further includes: a communication unit; when the destination IP address or the source IP address is not the record IP address, the processing unit is also used to generate alarm information; the communication unit , used to send alarm information to the alarm output device.

第四方面,本申请提供了一种流量检测装置,该装置包括:处理器和通信接口;通信接口和处理器耦合,处理器用于运行计算机程序或指令,以实现如第二方面和第二方面的任一种可能的实现方式中所描述的流量检测方法。In a fourth aspect, the present application provides a flow detection device, which includes: a processor and a communication interface; the communication interface is coupled to the processor, and the processor is used to run computer programs or instructions to achieve the second aspect and the second aspect The traffic detection method described in any possible implementation manner of .

第五方面,本申请提供了一种计算机可读存储介质,计算机可读存储介质中存储有指令,当指令在终端上运行时,使得终端执行如第二方面和第二方面的任一种可能的实现方式中描述的流量检测方法。In the fifth aspect, the present application provides a computer-readable storage medium, where instructions are stored in the computer-readable storage medium, and when the instructions are run on the terminal, the terminal executes any one of the second aspect and the second aspect. The flow detection method described in the implementation of .

在本申请中,上述流量检测装置的名字对设备或功能模块本身不构成限定,在实际实现中,这些设备或功能模块可以以其他名称出现。只要各个设备或功能模块的功能和本申请类似,属于本申请权利要求及其等同技术的范围之内。In this application, the names of the above-mentioned flow detection devices do not limit the equipment or functional modules themselves. In actual implementation, these equipment or functional modules may appear with other names. As long as the functions of each device or functional module are similar to those of the present application, they fall within the scope of the claims of the present application and their equivalent technologies.

本申请的这些方面或其他方面在以下的描述中会更加简明易懂。These or other aspects of the present application will be more clearly understood in the following description.

基于上述技术方案,本申请实施例提供的流量检测方法,通过流量检测装置识别数据流量的流量标签,若流量标签为入方向流量标签,则确定数据流量的目的IP地址,流量检测装置再确定目的IP地址是否属于备案IP地址,若流量标签为出方向流量标签,则确定数据流量的源IP地址,流量检测装置再确定源IP地址是否属于备案IP地址,能够有效检测IP地址,避免出现告警设备对用户备案地址错报的问题。Based on the above technical solution, the flow detection method provided by the embodiment of the present application uses the flow detection device to identify the flow label of the data flow. If the flow label is an inbound flow label, the destination IP address of the data flow is determined, and the flow detection device determines the destination again. Whether the IP address belongs to the record IP address, if the traffic label is the outbound traffic label, then determine the source IP address of the data flow, and then the traffic detection device determines whether the source IP address belongs to the record IP address, which can effectively detect the IP address and avoid alarm equipment The problem of misreporting the user's filing address.

附图说明Description of drawings

图1为本申请提供的一种流量检测装置的结构示意图;Fig. 1 is a schematic structural diagram of a flow detection device provided by the present application;

图2为本申请提供的一种流量检测系统的示意图;Fig. 2 is a schematic diagram of a flow detection system provided by the present application;

图3为本申请提供的一种流量检测方法的流程图;Fig. 3 is a flow chart of a flow detection method provided by the present application;

图4为本申请提供的另一种流量检测方法的流程图;FIG. 4 is a flow chart of another flow detection method provided by the present application;

图5为本申请提供的一种流量检测装置的结构示意图;FIG. 5 is a schematic structural diagram of a flow detection device provided by the present application;

图6为本申请提供的另一种流量检测装置的结构示意图。FIG. 6 is a schematic structural diagram of another flow detection device provided by the present application.

具体实施方式Detailed ways

下面结合附图对本申请实施例提供的一种流量检测系统、方法、装置及其存储介质进行详细地描述。A flow detection system, method, device and storage medium thereof provided in the embodiments of the present application will be described in detail below with reference to the accompanying drawings.

本文中术语“和/或”,仅仅是一种描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B这三种情况。The term "and/or" in this article is just an association relationship describing associated objects, which means that there can be three relationships, for example, A and/or B can mean: A exists alone, A and B exist simultaneously, and there exists alone B these three situations.

本申请的说明书以及附图中的术语“第一”和“第二”等是用于区别不同的对象,或者用于区别对同一对象的不同处理,而不是用于描述对象的特定顺序。The terms "first" and "second" in the specification and drawings of the present application are used to distinguish different objects, or to distinguish different processes for the same object, rather than to describe a specific sequence of objects.

此外,本申请的描述中所提到的术语“包括”和“具有”以及它们的任何变形,意图在于覆盖不排他的包含。例如包含了一系列步骤或单元的过程、方法、系统、产品或设备没有限定于已列出的步骤或单元,而是可选地还包括其他没有列出的步骤或单元,或可选地还包括对于这些过程、方法、产品或设备固有的其它步骤或单元。In addition, the terms "including" and "having" mentioned in the description of the present application and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units is not limited to the listed steps or units, but optionally also includes other unlisted steps or units, or optionally also includes Other steps or elements inherent to the process, method, product or apparatus are included.

需要说明的是,本申请实施例中,“示例性的”或者“例如”等词用于表示作例子、例证或说明。本申请实施例中被描述为“示例性的”或者“例如”的任何实施例或设计方案不应被解释为比其它实施例或设计方案更优选或更具优势。确切而言,使用“示例性的”或者“例如”等词旨在以具体方式呈现相关概念。It should be noted that, in the embodiments of the present application, words such as "exemplary" or "for example" are used as examples, illustrations or descriptions. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of the present application shall not be interpreted as being more preferred or more advantageous than other embodiments or design schemes. Rather, the use of words such as "exemplary" or "such as" is intended to present related concepts in a concrete manner.

图1为本申请实施例提供的一种流量检测装置的结构示意图,如图1所示,该流量检测装置100包括至少一个处理器101,通信线路102,以及至少一个通信接口104,还可以包括存储器103。其中,处理器101,存储器103以及通信接口104三者之间可以通过通信线路102连接。Figure 1 is a schematic structural diagram of a flow detection device provided by the embodiment of the present application. As shown in Figure 1, the flow detection device 100 includes at least one processor 101, a communication line 102, and at least one communication interface 104, and may also include memory 103. Wherein, the processor 101 , the memory 103 and the communication interface 104 may be connected through a communication line 102 .

处理器101可以是一个中央处理器(central processing unit,CPU),也可以是特定集成电路(application specific integrated circuit,ASIC),或者是被配置成实施本申请实施例的一个或多个集成电路,例如:一个或多个数字信号处理器(digital signalprocessor,DSP),或,一个或者多个现场可编程门阵列(field programmable gate array,FPGA)。The processor 101 may be a central processing unit (central processing unit, CPU), or a specific integrated circuit (application specific integrated circuit, ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, For example: one or more digital signal processors (digital signal processor, DSP), or one or more field programmable gate arrays (field programmable gate array, FPGA).

通信线路102可以包括一通路,用于在上述组件之间传送信息。Communication line 102 may include a path for communicating information between the above-described components.

通信接口104,用于与其他设备或通信网络通信,可以使用任何收发器一类的装置,如以太网,无线接入网(radio access network,RAN),无线局域网(wireless localarea networks,WLAN)等。The communication interface 104 is used to communicate with other devices or communication networks, and any device such as a transceiver can be used, such as Ethernet, radio access network (radio access network, RAN), wireless local area network (wireless local area networks, WLAN), etc. .

存储器103可以是只读存储器(read-only memory,ROM)或可存储静态信息和指令的其他类型的静态存储设备,随机存取存储器(random access memory,RAM)或者可存储信息和指令的其他类型的动态存储设备,也可以是电可擦可编程只读存储器(electricallyerasable programmable read-only memory,EEPROM)、只读光盘(compact disc read-only memory,CD-ROM)或其他光盘存储、光碟存储(包括压缩光碟、激光碟、光碟、数字通用光碟、蓝光光碟等)、磁盘存储介质或者其他磁存储设备、或者能够用于包括或存储具有指令或数据结构形式的期望的程序代码并能够由计算机存取的任何其他介质,但不限于此。The memory 103 may be a read-only memory (read-only memory, ROM) or other types of static storage devices that can store static information and instructions, a random access memory (random access memory, RAM) or other types that can store information and instructions The dynamic storage device can also be an electrically erasable programmable read-only memory (electrically erasable programmable read-only memory, EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage ( including compact discs, laser discs, optical discs, digital versatile discs, blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or can be used to include or store desired program code in the form of instructions or data structures and can be stored by a computer Any other medium, but not limited to.

一种可能的设计中,存储器103可以独立于处理器101存在,即存储器103可以为处理器101外部的存储器,此时,存储器103可以通过通信线路102与处理器101相连接,用于存储执行指令或者应用程序代码,并由处理器101来控制执行,实现本申请下述实施例提供的网络质量确定方法。又一种可能的设计中,存储器103也可以和处理器101集成在一起,即存储器103可以为处理器101的内部存储器,例如,该存储器103为高速缓存,可以用于暂存一些数据和指令信息等。In a possible design, the memory 103 may exist independently of the processor 101, that is, the memory 103 may be a memory outside the processor 101. At this time, the memory 103 may be connected to the processor 101 through the communication line 102 for storing and executing Instructions or application program codes are controlled and executed by the processor 101 to implement the network quality determining method provided in the following embodiments of the present application. In yet another possible design, the memory 103 can also be integrated with the processor 101, that is, the memory 103 can be an internal memory of the processor 101, for example, the memory 103 is a cache, which can be used to temporarily store some data and instructions information etc.

作为一种可实现方式,处理器101可以包括一个或多个CPU,例如图1中的CPU0和CPU1。作为另一种可实现方式,流量检测装置100可以包括多个处理器,例如图1中的处理器101和处理器107。作为再一种可实现方式,流量检测装置100还可以包括输出设备105和输入设备106。As an implementable manner, the processor 101 may include one or more CPUs, for example, CPU0 and CPU1 in FIG. 1 . As another implementable manner, the flow detection device 100 may include multiple processors, for example, the processor 101 and the processor 107 in FIG. 1 . As yet another implementable manner, the flow detection device 100 may further include an output device 105 and an input device 106 .

通过以上的实施方式的描述,所属领域的技术人员可以清楚地了解到,为描述的方便和简洁,仅以上述各功能模块的划分进行举例说明,实际应用中,可以根据需要而将上述功能分配由不同的功能模块完成,即将网络节点的内部结构划分成不同的功能模块,以完成以上描述的全部或者部分功能。上述描述的系统,模块和网络节点的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。Through the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and brevity of the description, only the division of the above-mentioned functional modules is used as an example for illustration. In practical applications, the above-mentioned functions can be allocated according to needs It is completed by different functional modules, that is, the internal structure of the network node is divided into different functional modules to complete all or part of the functions described above. For the specific working process of the system, modules, and network nodes described above, reference may be made to the corresponding process in the foregoing method embodiments, which will not be repeated here.

以下,对本申请涉及到的名词进行解释。Hereinafter, the nouns involved in this application will be explained.

1、汇聚分流设备是位于网络可视化系统最前端的设备,主要完成不同规格线路的数据接入采集、(链路层、网络层)协议解析、简单过滤、流量分发、同源同宿、负载均衡,也称作一级分流设备、粗筛设备,部署于骨干网络,通常位于运营商机房,筛选出来的数据通过专线接到用户机房。经过汇聚分流设备预处理(解析、筛选过滤)后,根据业务需求,给后端不同的业务系统输出所需要的数据。1. Convergence and distribution equipment is the front-end equipment in the network visualization system. It mainly completes data access collection of lines of different specifications, (link layer, network layer) protocol analysis, simple filtering, traffic distribution, same source and same destination, load balancing, Also known as first-level distribution equipment and coarse screening equipment, it is deployed on the backbone network, usually in the operator's computer room, and the filtered data is sent to the user's computer room through a dedicated line. After the preprocessing (analysis, screening and filtering) of the aggregation and distribution equipment, the required data is output to different back-end business systems according to business requirements.

2、分光器是一种无源器件,又称光分路器,它们不需要外部能量,只要有输入光即可。分光器由入射和出射狭缝、反射镜和色散元件组成,其作用是将所需要的共振吸收线分离出来。分光器的关键部件是色散元件,现在商品仪器都是使用光栅。2. An optical splitter is a passive device, also known as an optical splitter, they do not require external energy, as long as there is input light. The beam splitter consists of entrance and exit slits, mirrors and dispersive elements, and its function is to separate the required resonant absorption lines. The key component of the spectrometer is the dispersive element, and now commercial instruments use gratings.

3、互联网数据中心(Internet Data Center,IDC)是指一种拥有完善的设备(包括高速互联网接入带宽、高性能局域网络、安全可靠的机房环境等)、专业化的管理、完善的应用服务平台。在这个平台基础上,IDC服务商为客户提供互联网基础平台服务(服务器托管、虚拟主机、邮件缓存、虚拟邮件等)以及各种增值服务(场地的租用服务、域名系统服务、负载均衡系统、数据库系统、数据备份服务等)。3. Internet data center (Internet Data Center, IDC) refers to a comprehensive equipment (including high-speed Internet access bandwidth, high-performance local area network, safe and reliable computer room environment, etc.), professional management, perfect application services platform. On the basis of this platform, IDC service providers provide customers with basic Internet platform services (server hosting, virtual hosting, mail caching, virtual mail, etc.) and various value-added services (site rental services, domain name system services, load balancing systems, database systems, data backup services, etc.).

4、网络业务提供商(Internet Service Provider,ISP),互联网服务提供商,即向广大用户综合提供互联网接入业务、信息业务、和增值业务的电信运营商。在互联网应用服务产业链“设备供应商——基础网络运营商——内容收集者和生产者——业务提供者——用户”中,ISP处于内容收集者、生产者以及业务提供者的位置。4. Internet service provider (Internet Service Provider, ISP), Internet service provider, that is, a telecom operator that comprehensively provides Internet access services, information services, and value-added services to users. In the Internet application service industry chain "equipment suppliers - basic network operators - content collectors and producers - service providers - users", ISPs are in the position of content collectors, producers and service providers.

5、核心路由器(Core Router,CR),在因特网中,位于网络核心,主要用于数据分组选路和转发,一般具有较大吞吐量的路由器。5. Core router (Core Router, CR), located in the core of the network in the Internet, is mainly used for routing and forwarding of data packets, and is generally a router with relatively large throughput.

6、五元组是通信术语。通常是指源IP地址,源端口,目的IP地址,目的端口和传输层协议。6. Five-tuple is a communication term. Usually refers to the source IP address, source port, destination IP address, destination port and transport layer protocol.

7、入方向流量,可以理解为由核心路由器CR进入互联网数据中心IDC设备的数据流量。7. Inbound traffic can be understood as the data traffic that enters the Internet data center IDC equipment from the core router CR.

8、出方向流量,可以理解为由互联网数据中心IDC设备的发出至核心路由器CR的数据流量。8. The outbound traffic can be understood as the data traffic sent from the Internet data center IDC device to the core router CR.

9、执行部件又名执行单元(Execution Unit,EU)。9. The execution unit is also called the execution unit (Execution Unit, EU).

在相关技术中,在采集设备数据检测流量时,一般是使用DNS数据源,从总数据中提取属性符合机房内的数据,再进行模拟请求。之后先进行http(get/post)请求,若模拟请求结果返回值不在合理范围内的数据,再次进行https(get/post)请求,以此实现活跃IP数据漏报发现和活跃域名数据漏报发现。因此种方法主要是通过比对http和https请求结果返回值发现漏报数据,对设备性能有一定要求,资源占用较为明显。In related technologies, when collecting device data to detect traffic, DNS data sources are generally used to extract attributes from the total data that match the data in the computer room, and then simulate requests. Afterwards, make an http (get/post) request first, and if the result of the simulated request returns data that is not within a reasonable range, make an https (get/post) request again, so as to realize the detection of missing active IP data and active domain name data. . Therefore, this method mainly finds missing data by comparing the return values of http and https request results, which has certain requirements on device performance and consumes more resources.

目前,针对互联网数据中心(Internet Data Center,IDC)或网络业务提供商(Internet Service Provider,ISP)的互联网协议(Internet Protocol,IP)地址没有更好的检测方法,无法实现有效检测IP地址,导致易出现告警设备对用户备案地址错报的问题。At present, there is no better detection method for Internet Protocol (IP) addresses of Internet Data Centers (Internet Data Center, IDC) or Internet Service Providers (Internet Service Providers, ISPs), and it is impossible to effectively detect IP addresses, resulting in It is easy for the alarm device to misreport the user's record address.

为了解决现有技术中不能有效检测IP地址的问题,本申请提供一种如图2所示的流量检测系统20。In order to solve the problem that the IP address cannot be effectively detected in the prior art, the present application provides a traffic detection system 20 as shown in FIG. 2 .

如图2所示,本申请提供的流量检测系统20包括核心路由器CR201、互联网数据中心IDC设备202、汇聚分流设备203、以及执行单元EU204。As shown in FIG. 2 , the traffic detection system 20 provided by this application includes a core router CR201 , an Internet data center IDC device 202 , a converging and distributing device 203 , and an execution unit EU204 .

其中,核心路由器CR201和互联网数据中心IDC设备202通过通信链路连接并通过通信链路互相转发数据;汇聚分流设备203通过分光器接入核心路由器CR201和互联网数据中心IDC设备202之间的通信链路;汇聚分流设备203,被配置为:获取核心路由器CR201和互联网数据中心IDC设备202之间转发的第一数据流量;根据预设二层报文策略为第一流量数据添加标签,生成第二数据流量,向执行单元EU204发送第二数据流量。Among them, the core router CR201 and the Internet data center IDC device 202 are connected through a communication link and forward data to each other through the communication link; the convergence and distribution device 203 is connected to the communication link between the core router CR201 and the Internet data center IDC device 202 through an optical splitter The aggregation and distribution device 203 is configured to: obtain the first data flow forwarded between the core router CR201 and the Internet data center IDC device 202; add a label to the first flow data according to the preset layer 2 packet policy, and generate a second The data flow is to send the second data flow to the execution unit EU204.

执行单元EU204,被配置为:接收第二数据流量,确定第二数据流量的流量标签;流量标签为入方向流量标签和出方向流量标签中的任一项;在流量标签为入方向流量标签的情况下,确定数据流量的目的IP地址;确定目的IP地址是否为备案IP地址;在流量标签为出方向流量标签的情况下,确定数据流量的源IP地址;确定源IP地址是否为备案IP地址。The execution unit EU204 is configured to: receive the second data flow, and determine the flow label of the second data flow; the flow label is any one of the flow label in the inbound direction and the flow label in the outbound direction; In this case, determine the destination IP address of the data traffic; determine whether the destination IP address is the filing IP address; if the traffic label is the outbound traffic label, determine the source IP address of the data traffic; determine whether the source IP address is the filing IP address .

在一种可能的实现方式中,核心路由器CR201在与互联网数据中心IDC设备202进行数据流量交换过程中,若某一数据流量进入互联网数据中心IDC设备202,则该数据流量为入方向数据流量;若某一数据流量从互联网数据中心IDC设备202发出,则该数据流量为出方向数据流量。In a possible implementation manner, when the core router CR201 exchanges data traffic with the Internet data center IDC device 202, if a certain data traffic enters the Internet data center IDC device 202, the data traffic is inbound data traffic; If a certain data traffic is sent from the Internet data center IDC device 202, the data traffic is outbound data traffic.

可选的,汇聚分流设备203包括多个端口,该多个端口分别用于获取不同方向的流量,或者获取不同IDC设备和CR设备之间的流量。Optionally, the aggregation and distribution device 203 includes multiple ports, and the multiple ports are respectively used to obtain traffic in different directions, or to obtain traffic between different IDC devices and CR devices.

一种示例,汇聚分流设备203上包括两个端口,两个端口分别为端口A31和端口B32。其中,端口A31用于获取CR201和IDC202之间的入方向流量;端口B32用于获取CR201和IDC202之间的出方向流量。In one example, the convergence and distribution device 203 includes two ports, and the two ports are port A31 and port B32 respectively. Among them, port A31 is used to obtain the inbound flow between CR201 and IDC202; port B32 is used to obtain the outbound flow between CR201 and IDC202.

以下,结合该示例对汇聚分流设备203获取流量的过程进行说明。Hereinafter, the process of acquiring traffic by the converging and distributing device 203 will be described with reference to this example.

汇聚分流设备203通过分光器,获取到核心路由器CR201在与互联网数据中心IDC设备202进行数据流量交换过程中的第一数据流量。若第一数据流量为入方向数据流量,则分光器通过将该第一数据流量发送至汇聚分流设备203,端口A31上配置有预设二层报文策略,通过预设二层报文策略对第一数据流量添加入方向流量标签,生成第二数据流量。示例性的,入方向流量标签可以为vlan10。The convergence and distribution device 203 obtains the first data traffic of the core router CR201 and the Internet data center IDC device 202 during data traffic exchange through the optical splitter. If the first data traffic is data traffic in the inbound direction, the optical splitter sends the first data traffic to the converging and splitting device 203, and the port A31 is configured with a preset Layer 2 message policy, and the preset Layer 2 message policy is used to An inbound traffic label is added to the first data traffic to generate the second data traffic. Exemplarily, the traffic label in the inbound direction may be vlan10.

又一种示例,汇聚分流设备203通过分光器,获取到核心路由器CR201在与互联网数据中心IDC设备202进行数据流量交换过程中的第一数据流量。若第一数据流量为出方向数据流量,则分光器通过将该第一数据流量发送至汇聚分流设备203,端口B32上配置有预设二层报文策略,通过预设二层报文策略对第一数据流量添加出方向流量标签,生成第二数据流量。示例性的,出方向流量标签可以为vlan20。In another example, the converging and splitting device 203 acquires the first data traffic of the core router CR201 during data traffic exchange with the Internet data center IDC device 202 through the optical splitter. If the first data traffic is data traffic in the outgoing direction, the optical splitter sends the first data traffic to the converging and splitting device 203, and the port B32 is configured with a preset layer 2 message policy, and the preset layer 2 message policy is used to A traffic label in the outbound direction is added to the first data traffic to generate the second data traffic. Exemplarily, the outbound traffic label may be vlan20.

以下,结合示例对执行单元EU204进行流量检测的过程进行说明。In the following, the flow detection process of the execution unit EU204 will be described with reference to an example.

又一种示例,汇聚分流设备203将生成的第二数据流量发送至执行单元EU204。执行单元EU204识别第二数据流量的流量标签,若第二数据流量的流量标签为vlan10,则执行单元EU204确定第二数据流量为入方向流量,执行单元EU204再通过五元组分析确定第二数据流量的目的IP地址。最后由执行单元EU204将第二数据流量的目的IP地址与存储单元DU206中的备案IP地址对比,确定目的IP地址是否超出备案IP地址的范围。In another example, the convergence and distribution device 203 sends the generated second data traffic to the execution unit EU204. The execution unit EU204 identifies the flow label of the second data flow. If the flow label of the second data flow is vlan10, the execution unit EU204 determines that the second data flow is inbound flow, and the execution unit EU204 determines the second data flow through quintuple analysis. The destination IP address of the traffic. Finally, the execution unit EU204 compares the destination IP address of the second data flow with the registered IP address in the storage unit DU206 to determine whether the destination IP address exceeds the range of the registered IP address.

又一种示例,汇聚分流设备203将生成的第二数据流量发送至执行单元EU204。执行单元EU204识别第二数据流量的流量标签,若第二数据流量的流量标签为vlan20,则执行单元EU204确定第二数据流量为出方向流量,执行单元EU204再通过五元组分析确定第二数据流量的源IP地址。最后由执行单元EU204将第二数据流量的源IP地址与存储单元DU206中的备案IP地址对比,确定源IP地址是否超出备案IP地址的范围。In another example, the convergence and distribution device 203 sends the generated second data traffic to the execution unit EU204. The execution unit EU204 identifies the flow label of the second data flow. If the flow label of the second data flow is vlan20, the execution unit EU204 determines that the second data flow is outbound flow, and the execution unit EU204 determines the second data flow through quintuple analysis. The source IP address of the traffic. Finally, the execution unit EU204 compares the source IP address of the second data flow with the registered IP address in the storage unit DU206 to determine whether the source IP address exceeds the range of the registered IP address.

一种可能的实现方式中,如图2所示,该流量检测系统20还包括:告警输出设备205;执行单元EU204,还被配置为:在目的IP地址或源IP地址不为备案IP地址的情况下,生成告警信息;向告警输出设备205发送告警信息。In a possible implementation, as shown in FIG. 2 , the traffic detection system 20 further includes: an alarm output device 205; an execution unit EU204, which is also configured to: In some cases, generate warning information; send the warning information to the warning output device 205 .

告警输出设备205,还被配置为:输出告警信息。The alarm output device 205 is further configured to: output alarm information.

一种示例,若目的IP地址或源IP地址超出备案IP地址,则执行单元EU4生成告警信息,由告警输出设备输出告警信息。In one example, if the destination IP address or the source IP address exceeds the filing IP address, the execution unit EU4 generates alarm information, and the alarm output device outputs the alarm information.

基于上述技术方案,本申请提供的流量检测系统,通过汇聚分流设备为第一数据流量添加流量标签并发送至执行单元EU,执行单元EU根据二层报文策略识别流量标签,进而确定第一数据流量为入方向流量还是出方向流量,若第一数据流量为入方向流量则执行单元EU确定其目的IP地址,最后将目的IP地址与备案IP地址对比,确定目的IP地址是否超出备案IP地址,相应的,若第二数据流量为出方向流量则执行单元EU确定其源IP地址,最后将源IP地址与备案IP地址对比,确定源IP地址是否超出备案IP地址,进而有效的检测IP地址,避免出现告警设备对用户备案地址错报的问题。Based on the above technical solution, the flow detection system provided by this application adds a flow label to the first data flow through the aggregation and distribution device and sends it to the execution unit EU. The execution unit EU identifies the flow label according to the layer-2 message policy, and then determines the first data flow. Whether the traffic is inbound traffic or outbound traffic, if the first data traffic is inbound traffic, the execution unit EU determines its destination IP address, and finally compares the destination IP address with the filing IP address to determine whether the destination IP address exceeds the filing IP address, Correspondingly, if the second data traffic is outbound traffic, the execution unit EU determines its source IP address, and finally compares the source IP address with the registered IP address to determine whether the source IP address exceeds the registered IP address, and then effectively detects the IP address. Avoid the problem that the alarm device misreports the user's record address.

以上,对本申请实施例提供的流量检测系统进行了介绍说明。Above, the flow detection system provided by the embodiment of the present application has been introduced and described.

以下,对本申请实施例提供的流量检测方法进行介绍说明。Hereinafter, the flow detection method provided by the embodiment of the present application will be introduced and described.

如图3所示为本申请提供的一种流量检测方法的流程图。本申请实施例提供的流量检测方法可以应用于如图2所示的流量检测系统中,执行单元EU识别数据流量的流量标签,若流量标签为入方向流量标签的情况下,执行单元EU确定数据流量的目的IP地址,并将目的IP地址与备案表中的备案IP地址进行比对,确定目的IP地址是否为备案IP地址,保证对目的IP地址进行有效监测;若在流量标签为出方向流量标签的情况下,执行单元EU确定数据流量的源IP地址,并将源IP地址与备案表中的备案IP地址进行比对,并将确定源IP地址是否为备案IP地址,能够有效的对源IP地址进行监测,避免出现告警设备对用户备案地址错报的问题。FIG. 3 is a flowchart of a flow detection method provided by the present application. The flow detection method provided by the embodiment of the present application can be applied to the flow detection system shown in Figure 2. The execution unit EU identifies the flow label of the data flow. If the flow label is an inbound flow label, the execution unit EU determines the data flow label. The destination IP address of the traffic, and compare the destination IP address with the filing IP address in the filing table to determine whether the destination IP address is the filing IP address to ensure effective monitoring of the destination IP address; if the traffic label is outbound traffic label, the execution unit EU determines the source IP address of the data traffic, compares the source IP address with the filing IP address in the filing table, and determines whether the source IP address is a filing IP address, which can effectively verify the source The IP address is monitored to avoid the problem that the alarm device misreports the user's record address.

以下,对本申请实施例提供的流量检测方法进行详细的介绍说明,如图3所示,流量检测方法可以通过以下S301-S305实现。Hereinafter, the flow detection method provided by the embodiment of the present application will be described in detail. As shown in FIG. 3 , the flow detection method can be implemented through the following S301-S305.

S301、流量检测装置识别数据流量的流量标签。S301. The flow detecting device identifies a flow label of data flow.

其中,流量标签为入方向流量标签和出方向流量标签中的任一项。Wherein, the traffic label is any one of the inbound traffic label and the outbound traffic label.

在一种可能的实现方式中,流量检测装置可以理解为执行单元EU。流量标签为汇聚分流设备获取到数据流量之后,根据预设二层报文策略为数据流量添加的标签。In a possible implementation manner, the flow detection device can be understood as an execution unit EU. The traffic label is the label added to the data traffic according to the preset Layer 2 packet policy after the aggregation and distribution device obtains the data traffic.

一种示例,流量检测装置识别数据流量的流量标签,若流量标签为入方向流量标签,入方向流量标签可以表示为Vlan10,则该数据流量为入方向数据流量,若流量标签为出方向流量标签,出方向流量标签可以表示为Vlan20,则该数据流量为出方向数据流量。In one example, the flow detection device identifies the flow label of the data flow. If the flow label is an inbound flow label, the inbound flow label can be expressed as Vlan10, then the data flow is the inbound data flow. If the flow label is the outbound flow label , the outbound traffic label can be expressed as Vlan20, then the data traffic is outbound data traffic.

S302、在流量标签为入方向流量标签的情况下,流量检测装置确定数据流量的目的IP地址。S302. If the traffic label is an inbound traffic label, the traffic detection device determines the destination IP address of the data traffic.

一种示例,若数据流量为入方向数据流量,流量检测装置分析入方向数据流量五元组确定该数据流量的目的IP地址为120.80.100.200,此时的目的IP地址为IDC设备的IP地址。In one example, if the data traffic is inbound data traffic, the traffic detection device analyzes the five-tuple of inbound data traffic to determine that the destination IP address of the data traffic is 120.80.100.200, and the destination IP address at this time is the IP address of the IDC device.

S303、流量检测装置确定目的IP地址是否为备案IP地址。S303. The traffic detection device determines whether the destination IP address is a filing IP address.

结合S302中的示例,在存储单元DU中存储的备案IP地址为120.80.100.0/25,流量检测装置确定数据流量的目的IP地址120.80.100.200不是备案IP地址120.80.100.0/25。若存储单元DU中存储的备案IP地址为120.80.100.200,则流量检测装置确定数据流量的目的IP地址120.80.100.200是备案IP地址120.80.100.200。Referring to the example in S302, the recordation IP address stored in the storage unit DU is 120.80.100.0/25, and the traffic detection device determines that the destination IP address 120.80.100.200 of the data traffic is not the recordation IP address 120.80.100.0/25. If the filing IP address stored in the storage unit DU is 120.80.100.200, the traffic detection device determines that the destination IP address 120.80.100.200 of the data flow is the filing IP address 120.80.100.200.

需要指出的是,入方向数据流量的目的IP地址为IDC设备的IP地址。每个IDC设备在存储单元DU中均预先存储有备案IP地址,备案IP地址用于与流量检测装置确定目的IP地址进行对比,若出现目的IP地址不是备案IP地址的情况,则说明系统出现漏报IP地址的情况,需对漏报的IP地址添加至备案IP地址中,避免出现漏报的情况。It should be noted that the destination IP address of the inbound data traffic is the IP address of the IDC device. Each IDC device has a record IP address stored in the storage unit DU in advance. The record IP address is used for comparison with the destination IP address determined by the traffic detection device. If the destination IP address is not the record IP address, it means that there is a leak in the system. In the case of reporting the IP address, it is necessary to add the missing IP address to the record IP address to avoid the situation of missing reporting.

S304、在流量标签为出方向流量标签的情况下,流量检测装置确定数据流量的源IP地址。S304. If the traffic label is an outbound traffic label, the traffic detection device determines the source IP address of the data traffic.

一种示例,若数据流量为出方向数据流量,流量检测装置分析出方向数据流量五元组确定该数据流量的源IP地址为120.80.100.200,此时的源IP地址为IDC设备的IP地址。In one example, if the data traffic is outbound data traffic, the traffic detection device analyzes the outbound data traffic quintuple to determine that the source IP address of the data traffic is 120.80.100.200, and the source IP address at this time is the IP address of the IDC device.

又一种示例,在数据流量为出方向数据流量,流量检测装置分析出方向数据流量五元组确定该数据流量的目的IP地址为120.80.100.200,此时的目的IP地址为用户端的IP地址;在现有的系统中,120.80.100.200可能为外部业务地址,也可能是用户漏报的业务地址,无法进行判断,因此本申请通过执行单元EU对流量标签进行识别,判断流量标签为入方向流量标签还是出方向流量标签,若为出方向流量标签,且分析五元组后确定的目的IP地址,则目的IP地址120.80.100.200为外网业务地址,不属于用户漏报的情况。In another example, when the data traffic is data traffic in the outgoing direction, the traffic detection device analyzes the quintuple of the outgoing data traffic to determine that the destination IP address of the data traffic is 120.80.100.200, and the destination IP address at this time is the IP address of the client; In the existing system, 120.80.100.200 may be an external business address, or it may be a business address missed by the user, so it cannot be judged. Therefore, this application uses the execution unit EU to identify the traffic label and judge that the traffic label is inbound traffic. The label is still an outbound traffic label. If it is an outbound traffic label and the destination IP address is determined after analyzing the quintuple, the destination IP address 120.80.100.200 is the external network service address, which is not a case of user omission.

S305、流量检测装置确定源IP地址是否为备案IP地址。S305. The traffic detection device determines whether the source IP address is a record IP address.

结合S304中的示例,在存储单元DU中存储的备案IP地址为120.80.100.0/25,流量检测装置确定数据流量的源IP地址120.80.100.200不是备案IP地址120.80.100.0/25。若存储单元DU中存储的备案IP地址为120.80.100.200,则流量检测装置确定数据流量的源IP地址120.80.100.200是备案IP地址120.80.100.200。Referring to the example in S304, the recordation IP address stored in the storage unit DU is 120.80.100.0/25, and the traffic detection device determines that the source IP address 120.80.100.200 of the data traffic is not the recordation IP address 120.80.100.0/25. If the filing IP address stored in the storage unit DU is 120.80.100.200, the traffic detection device determines that the source IP address 120.80.100.200 of the data traffic is the filing IP address 120.80.100.200.

需要指出的是,出方向数据流量的源IP地址为IDC设备的IP地址;出方向数据流量的目的IP地址为用户端的IP地址。每个IDC设备在存储单元DU中均预先存储有备案IP地址,备案IP地址用于与流量检测装置确定源IP地址进行对比,若出现源IP地址不是备案IP地址的情况,则说明系统出现漏报IP地址的情况,需对漏报的IP地址添加至备案IP地址中。It should be pointed out that the source IP address of the outbound data traffic is the IP address of the IDC device; the destination IP address of the outbound data traffic is the IP address of the client. Each IDC device has a record IP address stored in the storage unit DU in advance. The record IP address is used for comparison with the source IP address determined by the traffic detection device. If the source IP address is not the record IP address, it means that there is a leak in the system. In the case of reporting the IP address, the missing IP address needs to be added to the record IP address.

上述实施例提供的技术方案至少带来以下有益效果,相比较于现有技术,本申请实施例提供的流量检测方法,通过流量检测装置识别数据流量的流量标签,若流量标签为入方向流量标签,则确定数据流量的目的IP地址,流量检测装置再确定目的IP地址是否属于备案IP地址,若流量标签为出方向流量标签,则确定数据流量的源IP地址,流量检测装置再确定源IP地址是否属于备案IP地址,能够有效检测IP地址,避免出现告警设备对用户备案地址错报的问题。The technical solutions provided by the above embodiments bring at least the following beneficial effects. Compared with the prior art, the flow detection method provided by the embodiments of the present application uses the flow detection device to identify the flow label of the data flow. If the flow label is an inbound flow label , then determine the destination IP address of the data traffic, the traffic detection device then determines whether the destination IP address belongs to the record IP address, if the traffic label is an outgoing traffic label, then determines the source IP address of the data traffic, and the traffic detection device then determines the source IP address Whether it belongs to the filing IP address can effectively detect the IP address and avoid the problem that the alarm device misreports the user's filing address.

一种可能的实现方式中,结合图2和图3,如图4所示,在上述S301、流量检测装置识别数据流量的流量标签之前,汇聚分流设备需要为数据流量添加标签,具体可以通过以下S401-S402实现,以下进行详细说明:In a possible implementation manner, in combination with Fig. 2 and Fig. 3, as shown in Fig. 4, before the above S301, the traffic detection device identifies the traffic label of the data traffic, the converging and splitting device needs to add a label to the data traffic, specifically through the following The implementation of S401-S402 is described in detail below:

S401、汇聚分流设备获取数据流量。S401. The converging and distributing device acquires data traffic.

一种示例,核心路由器CR在与互联网数据中心IDC设备进行数据流量交换过程中,汇聚分流设备通过分光器获取该交换的数据流量。In one example, when the core router CR exchanges data traffic with the Internet data center IDC equipment, the converging and distributing equipment obtains the exchanged data traffic through the optical splitter.

S402、汇聚分流设备根据预设二层报文策略为数据流量添加的标签。S402. The converging and distributing device adds a label to the data traffic according to a preset Layer 2 packet policy.

一种示例,汇聚分流设备上设备有两个端口,两个端口分别为端口A和端口B。若数据流量为入方向数据流量,则汇聚分流设备通过端口A上的二层报文策略为入方向数据流量添加标签,入方向数据流量的流量标签可以为vlan10,若数据流量为出方向数据流量,则汇聚分流设备通过端口B上的二层报文策略为出方向数据流量添加标签,出方向数据流量的流量标签可以为vlan20。In one example, there are two ports on the convergence and distribution device, and the two ports are port A and port B respectively. If the data traffic is inbound data traffic, the aggregation and distribution device will add a label to the inbound data traffic through the Layer 2 packet policy on port A. The traffic label of the inbound data traffic can be vlan10. If the data traffic is outbound data traffic , the aggregation and distribution device adds a label to the outbound data traffic through the Layer 2 packet policy on port B, and the traffic label of the outbound data traffic can be vlan20.

一种可能的实现方式中,如图3所示,本申请还包括以下告警步骤,具体可以通过S306-S307实现,以下进行详细说明:In a possible implementation manner, as shown in FIG. 3 , the present application further includes the following warning steps, which can be specifically implemented through S306-S307, and are described in detail below:

S306、在目的IP地址或源IP地址不为备案IP地址的情况下,流量检测装置生成告警信息。S306. In the case that the destination IP address or the source IP address is not the registered IP address, the traffic detection device generates alarm information.

结合S303中的示例,目的IP地址120.80.100.200不为备案IP地址120.80.100.0/25,流量检测装置确定告警信息。Referring to the example in S303, the destination IP address 120.80.100.200 is not the filing IP address 120.80.100.0/25, and the traffic detection device determines the alarm information.

结合S305中的示例,源IP地址120.80.100.200不为备案IP地址120.80.100.0/25,流量检测装置确定告警信息。With reference to the example in S305, the source IP address 120.80.100.200 is not the filing IP address 120.80.100.0/25, and the traffic detection device determines the alarm information.

S307、流量检测装置向告警输出设备发送告警信息。S307. The flow detection device sends alarm information to the alarm output device.

本申请实施例可以根据上述方法示例对流量检测装置进行功能模块或者功能单元的划分,例如,可以对应各个功能划分各个功能模块或者功能单元,也可以将两个或两个以上的功能集成在一个处理模块中。上述集成的模块既可以采用硬件的形式实现,也可以采用软件功能模块或者功能单元的形式实现。其中,本申请实施例中对模块或者单元的划分是示意性的,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式。The embodiments of the present application can divide the flow detection device into functional modules or functional units according to the above-mentioned method examples. For example, each functional module or functional unit can be divided corresponding to each function, or two or more functions can be integrated into one processing module. The above-mentioned integrated modules can be implemented not only in the form of hardware, but also in the form of software function modules or functional units. Wherein, the division of modules or units in the embodiment of the present application is schematic, and is only a logical function division, and there may be another division manner in actual implementation.

如图5所示,为本申请实施例提供的一种流量检测装置50的结构示意图,流量检测装置50包括处理单元501。As shown in FIG. 5 , it is a schematic structural diagram of a flow detection device 50 provided in the embodiment of the present application. The flow detection device 50 includes a processing unit 501 .

处理单元501,用于识别数据流量的流量标签;流量标签为入方向流量标签和出方向流量标签中的任一项;在流量标签为入方向流量标签的情况下,处理单元501,还用于确定数据流量的目的IP地址;处理单元501,还用于确定目的IP地址是否为备案IP地址;在流量标签为出方向流量标签的情况下,处理单元501,还用于确定数据流量的源IP地址;处理单元501,还用于确定源IP地址是否为备案IP地址。The processing unit 501 is used to identify the traffic label of the data traffic; the traffic label is any one of the inbound traffic label and the outbound traffic label; when the traffic label is an inbound traffic label, the processing unit 501 is also used for Determine the destination IP address of the data traffic; the processing unit 501 is also used to determine whether the destination IP address is an IP address for record; when the traffic label is an outgoing traffic label, the processing unit 501 is also used to determine the source IP of the data traffic Address; the processing unit 501 is also used to determine whether the source IP address is a filing IP address.

可选的,流量标签为汇聚分流设备获取到数据流量之后,根据预设二层报文策略为数据流量添加的标签。Optionally, the traffic label is a label added to the data traffic according to a preset Layer 2 packet policy after the convergence and distribution device obtains the data traffic.

可选的,该流量检测装置50还包括:通信单元502;在目的IP地址或源IP地址不为备案IP地址的情况下,处理单元501,还用于生成告警信息;通信单元502,用于向告警输出设备发送告警信息。Optionally, the traffic detection device 50 also includes: a communication unit 502; when the destination IP address or the source IP address is not a filing IP address, the processing unit 501 is also used to generate alarm information; the communication unit 502 is used to Send alarm information to the alarm output device.

在通过硬件实现时,本申请实施例中的通信单元502可以集成在通信接口上,处理单元501可以集成在处理器上。具体实现方式如图6所示。When implemented by hardware, the communication unit 502 in the embodiment of the present application may be integrated on a communication interface, and the processing unit 501 may be integrated on a processor. The specific implementation is shown in Figure 6.

图6示出了上述实施例中所涉及的流量检测装置的又一种可能的结构示意图。该流量检测装置包括:处理器602和通信接口603。处理器602用于对流量检测装置的动作进行控制管理,例如,执行上述处理单元501执行的步骤,和/或用于执行本文所描述的技术的其它过程。通信接口603用于支持流量检测装置与其他网络实体的通信,例如,执行上述通信单元502执行的步骤。流量检测装置还可以包括存储器601和总线604,存储器601用于存储流量检测装置的程序代码和数据。Fig. 6 shows another possible structural schematic diagram of the flow detection device involved in the above embodiment. The flow detection device includes: a processor 602 and a communication interface 603 . The processor 602 is used to control and manage the actions of the flow detection device, for example, to execute the steps executed by the processing unit 501 above, and/or to execute other processes of the technologies described herein. The communication interface 603 is used to support communication between the flow detection device and other network entities, for example, to perform the steps performed by the communication unit 502 above. The flow detection device may also include a memory 601 and a bus 604, and the memory 601 is used to store program codes and data of the flow detection device.

其中,存储器601可以是流量检测装置中的存储器等,该存储器可以包括易失性存储器,例如随机存取存储器;该存储器也可以包括非易失性存储器,例如只读存储器,快闪存储器,硬盘或固态硬盘;该存储器还可以包括上述种类的存储器的组合。Wherein, the memory 601 can be a memory in the flow detection device, etc., and the memory can include a volatile memory, such as a random access memory; the memory can also include a non-volatile memory, such as a read-only memory, a flash memory, a hard disk or a solid-state hard disk; the storage may also include a combination of the above-mentioned types of storage.

上述处理器602可以是实现或执行结合本申请公开内容所描述的各种示例性的逻辑方框,模块和电路。该处理器可以是中央处理器,通用处理器,数字信号处理器,专用集成电路,现场可编程门阵列或者其他可编程逻辑器件、晶体管逻辑器件、硬件部件或者其任意组合。其可以实现或执行结合本申请公开内容所描述的各种示例性的逻辑方框,模块和电路。该处理器也可以是实现计算功能的组合,例如包含一个或多个微处理器组合,DSP和微处理器的组合等。The above-mentioned processor 602 may realize or execute various exemplary logic blocks, modules and circuits described in conjunction with the disclosure of this application. The processor may be a central processing unit, a general purpose processor, a digital signal processor, an application specific integrated circuit, a field programmable gate array or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. It can implement or execute the various illustrative logical blocks, modules and circuits described in connection with the present disclosure. The processor may also be a combination of computing functions, for example, a combination of one or more microprocessors, a combination of DSP and a microprocessor, and the like.

总线604可以是扩展工业标准结构(Extended Industry StandardArchitecture,EISA)总线等。总线604可以分为地址总线、数据总线、控制总线等。为便于表示,图6中仅用一条粗线表示,但并不表示仅有一根总线或一种类型的总线。The bus 604 may be an Extended Industry Standard Architecture (Extended Industry Standard Architecture, EISA) bus or the like. The bus 604 can be divided into address bus, data bus, control bus and so on. For ease of representation, only one thick line is used in FIG. 6 , but it does not mean that there is only one bus or one type of bus.

通过以上的实施方式的描述,所属领域的技术人员可以清楚地了解到,为描述的方便和简洁,仅以上述各功能模块的划分进行举例说明,实际应用中,可以根据需要而将上述功能分配由不同的功能模块完成,即将装置的内部结构划分成不同的功能模块,以完成以上描述的全部或者部分功能。上述描述的系统,装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。Through the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and brevity of the description, only the division of the above-mentioned functional modules is used as an example for illustration. In practical applications, the above-mentioned functions can be allocated according to needs It is completed by different functional modules, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. For the specific working process of the above-described system, device, and unit, reference may be made to the corresponding process in the foregoing method embodiments, and details are not repeated here.

本申请实施例提供一种包含指令的计算机程序产品,当该计算机程序产品在计算机上运行时,使得该计算机执行上述方法实施例中的流量检测方法。An embodiment of the present application provides a computer program product containing instructions, and when the computer program product is run on a computer, the computer is made to execute the traffic detection method in the above method embodiment.

本申请实施例还提供一种计算机可读存储介质,计算机可读存储介质中存储有指令,当该指令在计算机上运行时,使得该计算机执行上述方法实施例所示的方法流程中的流量检测方法。The embodiment of the present application also provides a computer-readable storage medium, and instructions are stored in the computer-readable storage medium, and when the instructions are run on a computer, the computer is made to perform flow detection in the method flow shown in the above method embodiments method.

其中,计算机可读存储介质,例如可以是但不限于电、磁、光、电磁、红外线、或半导体的系统、装置或器件,或者任意以上的组合。计算机可读存储介质的更具体的例子(非穷举的列表)包括:具有一个或多个导线的电连接、便携式计算机磁盘、硬盘、随机存取存储器(Random Access Memory,RAM)、只读存储器(Read-Only Memory,ROM)、可擦式可编程只读存储器(Erasable Programmable Read Only Memory,EPROM)、寄存器、硬盘、光纤、便携式紧凑磁盘只读存储器(Compact Disc Read-Only Memory,CD-ROM)、光存储器件、磁存储器件、或者上述的任意合适的组合、或者本领域熟知的任何其它形式的计算机可读存储介质。一种示例性的存储介质耦合至处理器,从而使处理器能够从该存储介质读取信息,且可向该存储介质写入信息。当然,存储介质也可以是处理器的组成部分。处理器和存储介质可以位于特定用途集成电路(Application Specific Integrated Circuit,ASIC)中。在本申请实施例中,计算机可读存储介质可以是任何包含或存储程序的有形介质,该程序可以被指令执行系统、装置或者器件使用或者与其结合使用。Wherein, the computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any combination thereof. More specific examples (non-exhaustive list) of computer-readable storage media include: electrical connections with one or more conductors, portable computer disks, hard disks, Random Access Memory (RAM), read-only memory (Read-Only Memory, ROM), Erasable Programmable Read-Only Memory (Erasable Programmable Read Only Memory, EPROM), Registers, Hard Disk, Optical Fiber, Portable Compact Disk Read-Only Memory (Compact Disc Read-Only Memory, CD-ROM ), an optical storage device, a magnetic storage device, or any suitable combination of the above, or any other form of computer-readable storage medium known in the art. An exemplary storage medium is coupled to the processor such the processor can read information from, and write information to, the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may be located in an application specific integrated circuit (Application Specific Integrated Circuit, ASIC). In the embodiments of the present application, a computer-readable storage medium may be any tangible medium containing or storing a program, and the program may be used by or in combination with an instruction execution system, device, or device.

由于本发明的实施例中的流量检测装置、计算机可读存储介质、计算机程序产品可以应用于上述方法,因此,其所能获得的技术效果也可参考上述方法实施例,本发明实施例在此不再赘述。Since the flow detection device, computer-readable storage medium, and computer program product in the embodiments of the present invention can be applied to the above methods, the technical effects that can be obtained can also refer to the above method embodiments, and the embodiments of the present invention are hereby No longer.

在本申请所提供的几个实施例中,应该理解到,所揭露的系统、设备和方法,可以通过其它的方式实现。例如,以上所描述的设备实施例仅仅是示意性的,例如,单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,设备或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods may be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated. to another system, or some features may be ignored, or not implemented. In another point, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces, and the indirect coupling or communication connection of devices or units may be in electrical, mechanical or other forms.

作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。A unit described as a separate component may or may not be physically separated, and a component displayed as a unit may or may not be a physical unit, that is, it may be located in one place, or may be distributed to multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

另外,在本申请各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, each unit may exist separately physically, or two or more units may be integrated into one unit.

以上,仅为本申请的具体实施方式,但本申请的保护范围并不局限于此,任何在本申请揭露的技术范围内的变化或替换,都应涵盖在本申请的保护范围之内。因此,本申请的保护范围应该以权利要求的保护范围为准。The above are only specific implementation methods of this application, but the protection scope of this application is not limited thereto. Any changes or replacements within the technical scope disclosed in this application shall be covered within the protection scope of this application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims (10)

1.一种流量检测系统,其特征在于,所述系统包括:1. A flow detection system, characterized in that the system comprises: 核心路由器CR、互联网数据中心IDC设备、汇聚分流设备、以及执行单元EU;所述CR和所述IDC设备通过通信链路连接并通过所述通信链路互相转发数据;所述汇聚分流设备通过分光器接入所述CR和所述IDC设备之间的通信链路;Core router CR, Internet data center IDC equipment, aggregation and distribution equipment, and execution unit EU; the CR and the IDC equipment are connected through a communication link and transmit data to each other through the communication link; the aggregation and distribution equipment transmits data through optical splitting A device accesses the communication link between the CR and the IDC device; 所述汇聚分流设备,被配置为:获取所述CR和所述IDC设备之间转发的第一数据流量;根据预设二层报文策略为所述第一数据流量添加标签,生成第二数据流量,向所述执行单元EU发送所述第二数据流量;The converging and distributing device is configured to: obtain the first data flow forwarded between the CR and the IDC device; add a label to the first data flow according to a preset Layer 2 message policy, and generate a second data flow traffic, sending the second data traffic to the execution unit EU; 所述执行单元EU,被配置为:接收所述第二数据流量,确定所述第二数据流量的流量标签;所述流量标签为入方向流量标签和出方向流量标签中的任一项;在所述流量标签为入方向流量标签的情况下,确定所述数据流量的目的IP地址;确定所述目的IP地址是否为备案IP地址;在所述流量标签为出方向流量标签的情况下,确定所述数据流量的源IP地址;确定所述源IP地址是否为备案IP地址。The execution unit EU is configured to: receive the second data flow, and determine a flow label of the second data flow; the flow label is any one of an inbound flow label and an outbound flow label; When the flow label is an incoming flow label, determine the destination IP address of the data flow; determine whether the destination IP address is an IP address for record; if the flow label is an outgoing flow label, determine The source IP address of the data traffic; determine whether the source IP address is a filing IP address. 2.根据权利要求1所述的系统,其特征在于,所述系统还包括:告警输出设备;2. The system according to claim 1, further comprising: an alarm output device; 所述EU,还被配置为:在所述目的IP地址或源IP地址不为备案IP地址的情况下,生成告警信息;向所述告警输出设备发送所述告警信息;The EU is further configured to: generate alarm information when the destination IP address or the source IP address is not the filing IP address; send the alarm information to the alarm output device; 所述告警输出设备,还被配置为:输出所述告警信息。The alarm output device is further configured to: output the alarm information. 3.一种流量检测方法,其特征在于,所述方法包括:3. A flow detection method, characterized in that the method comprises: 识别数据流量的流量标签;所述流量标签为入方向流量标签和出方向流量标签中的任一项;A traffic label for identifying data traffic; the traffic label is any one of an inbound traffic label and an outbound traffic label; 在所述流量标签为入方向流量标签的情况下,确定所述数据流量的目的IP地址;In the case where the traffic label is an inbound traffic label, determine the destination IP address of the data traffic; 确定所述目的IP地址是否为备案IP地址;Determine whether the destination IP address is a filing IP address; 在所述流量标签为出方向流量标签的情况下,确定所述数据流量的源IP地址;In the case where the traffic label is an outgoing traffic label, determine the source IP address of the data traffic; 确定所述源IP地址是否为备案IP地址。Determine whether the source IP address is a filing IP address. 4.根据权利要求3所述的方法,其特征在于,所述流量标签为汇聚分流设备获取到所述数据流量之后,根据预设二层报文策略为所述数据流量添加的标签。4. The method according to claim 3, wherein the traffic label is a label added to the data traffic according to a preset Layer 2 packet policy after the convergence and distribution device obtains the data traffic. 5.根据权利要求3所述的方法,其特征在于,所述方法还包括:5. The method according to claim 3, wherein the method further comprises: 在所述目的IP地址或所述源IP地址不为备案IP地址的情况下,生成告警信息;When the destination IP address or the source IP address is not an IP address for filing, generate a warning message; 向告警输出设备发送所述告警信息。Send the alarm information to an alarm output device. 6.一种流量检测装置,其特征在于,所述装置包括:处理单元;6. A flow detection device, characterized in that the device comprises: a processing unit; 所述处理单元,用于识别数据流量的流量标签;所述流量标签为入方向流量标签和出方向流量标签中的任一项;The processing unit is configured to identify a traffic label of data traffic; the traffic label is any one of an inbound traffic label and an outbound traffic label; 在所述流量标签为入方向流量标签的情况下,所述处理单元,还用于确定所述数据流量的目的IP地址;In the case where the traffic label is an inbound traffic label, the processing unit is further configured to determine a destination IP address of the data traffic; 所述处理单元,还用于确定所述目的IP地址是否为备案IP地址;The processing unit is also used to determine whether the destination IP address is a filing IP address; 在所述流量标签为出方向流量标签的情况下,所述处理单元,还用于确定所述数据流量的源IP地址;In the case where the traffic label is an outbound traffic label, the processing unit is further configured to determine the source IP address of the data traffic; 所述处理单元,还用于确定所述源IP地址是否为备案IP地址。The processing unit is further configured to determine whether the source IP address is a filing IP address. 7.根据权利要求6所述的装置,其特征在于,所述流量标签为汇聚分流设备获取到所述数据流量之后,根据预设二层报文策略为所述数据流量添加的标签。7 . The device according to claim 6 , wherein the traffic label is a label added to the data traffic according to a preset Layer 2 packet policy after the convergence and distribution device acquires the data traffic. 7 . 8.根据权利要求6所述的装置,其特征在于,所述装置还包括:通信单元;8. The device according to claim 6, further comprising: a communication unit; 在所述目的IP地址或所述源IP地址不为备案IP地址的情况下,所述处理单元,还用于生成告警信息;In the case where the destination IP address or the source IP address is not a filing IP address, the processing unit is further configured to generate alarm information; 所述通信单元,用于向告警输出设备发送所述告警信息。The communication unit is configured to send the alarm information to an alarm output device. 9.一种流量检测装置,其特征在于,包括:处理器和通信接口;所述通信接口和所述处理器耦合,所述处理器用于运行计算机程序或指令,以实现如权利要求3-5任一项中所述的流量检测方法。9. A flow detection device, characterized in that it comprises: a processor and a communication interface; the communication interface is coupled to the processor, and the processor is used to run computer programs or instructions to achieve the requirements of claims 3-5. The flow detection method described in any one. 10.一种计算机可读存储介质,所述计算机可读存储介质中存储有指令,其特征在于,当计算机执行该指令时,该计算机执行上述权利要求3-5任一项中所述的流量检测方法。10. A computer-readable storage medium, with instructions stored in the computer-readable storage medium, characterized in that, when a computer executes the instructions, the computer executes the flow described in any one of claims 3-5 Detection method.
CN202211572525.3A 2022-12-08 2022-12-08 Flow detection system, method, device and storage medium thereof Pending CN116248471A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202211572525.3A CN116248471A (en) 2022-12-08 2022-12-08 Flow detection system, method, device and storage medium thereof

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202211572525.3A CN116248471A (en) 2022-12-08 2022-12-08 Flow detection system, method, device and storage medium thereof

Publications (1)

Publication Number Publication Date
CN116248471A true CN116248471A (en) 2023-06-09

Family

ID=86626621

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202211572525.3A Pending CN116248471A (en) 2022-12-08 2022-12-08 Flow detection system, method, device and storage medium thereof

Country Status (1)

Country Link
CN (1) CN116248471A (en)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110505248A (en) * 2019-09-29 2019-11-26 国家计算机网络与信息安全管理中心 A kind of localization method and system of Intranet NAT flow
WO2021008028A1 (en) * 2019-07-18 2021-01-21 平安科技(深圳)有限公司 Network attack source tracing and protection method, electronic device and computer storage medium
CN113923189A (en) * 2020-07-07 2022-01-11 中国联合网络通信集团有限公司 Data flow-based IP address filing information verification method and device

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2021008028A1 (en) * 2019-07-18 2021-01-21 平安科技(深圳)有限公司 Network attack source tracing and protection method, electronic device and computer storage medium
CN110505248A (en) * 2019-09-29 2019-11-26 国家计算机网络与信息安全管理中心 A kind of localization method and system of Intranet NAT flow
CN113923189A (en) * 2020-07-07 2022-01-11 中国联合网络通信集团有限公司 Data flow-based IP address filing information verification method and device

Similar Documents

Publication Publication Date Title
US12375447B2 (en) Efficient packet capture for cyber threat analysis
CN107241186B (en) Network device and method for network communication
CN108701187B (en) Apparatus and method for hybrid hardware-software distributed threat analysis
US9064121B2 (en) Network data transmission analysis
US8416709B1 (en) Network data transmission analysis management
US8555383B1 (en) Network data transmission auditing
JP2021528749A (en) Automatic packetless network reachability analysis
CN105282169B (en) Ddos attack method for early warning based on SDN controller threshold values and its system
WO2014085952A1 (en) Policy processing method and network device
US12095741B1 (en) Secure proxy service
CN110311927B (en) Data processing method and device, electronic device and medium
US20160248652A1 (en) System and method for classifying and managing applications over compressed or encrypted traffic
CN104702618B (en) The method and apparatus for determining network access information
KR101017015B1 (en) Network based high performance content security system and method
US10229459B1 (en) Method and apparatus for routing in transaction management systems
CN116248471A (en) Flow detection system, method, device and storage medium thereof
CN118827826A (en) Method, device, electronic device and storage medium for determining SRv6 message processing instance
CN116318849A (en) Asset identification method, device and readable storage medium
CN115567546A (en) Monitoring data transmission method and device, electronic equipment and storage medium
Jeuk et al. Universal cloud classification (ucc) and its evaluation in a data center environment
CN115150106A (en) A security protection method for a physical machine and a network node device
CN117439824B (en) AI-based smart city evaluation method, system, device and storage medium
CN115118473B (en) Data processing method, device, equipment and storage medium
CN114338438B (en) Internet surfing behavior management method, system storage medium and equipment
CN120263436A (en) A collection method, device and system

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination