CN106789703B - SDN architecture-based traffic supervision method - Google Patents

SDN architecture-based traffic supervision method Download PDF

Info

Publication number
CN106789703B
CN106789703B CN201710021501.1A CN201710021501A CN106789703B CN 106789703 B CN106789703 B CN 106789703B CN 201710021501 A CN201710021501 A CN 201710021501A CN 106789703 B CN106789703 B CN 106789703B
Authority
CN
China
Prior art keywords
sdn
flow
supervision
sdn switch
controller
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201710021501.1A
Other languages
Chinese (zh)
Other versions
CN106789703A (en
Inventor
翟跃
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Guangdong Yundong Technology Co.,Ltd.
Original Assignee
Phicomm Shanghai Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Phicomm Shanghai Co Ltd filed Critical Phicomm Shanghai Co Ltd
Priority to CN201710021501.1A priority Critical patent/CN106789703B/en
Publication of CN106789703A publication Critical patent/CN106789703A/en
Application granted granted Critical
Publication of CN106789703B publication Critical patent/CN106789703B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/23Bit dropping
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/24Traffic characterised by specific attributes, e.g. priority or QoS
    • H04L47/2483Traffic characterised by specific attributes, e.g. priority or QoS involving identification of individual flows

Abstract

The invention relates to a flow supervision method based on an SDN framework, which comprises the following steps of S101: a user configures a flow supervision strategy on an SDN controller; s102: the SDN controller receives a message from the SDN switch and analyzes a target IP and a source IP; s103: the SDN controller receives a private extended expermer message from the SDN switch and analyzes the expermer message; s104: and the SDN switch detects the flow rate and reports the flow rate to the SDN controller according to a detection result. Compared with the prior art, the flow monitoring process based on the SDN framework is uniformly calculated and managed by the controller in a centralized mode, all flow monitoring configurations are centralized on the controller, and management and later-stage operation are facilitated.

Description

SDN architecture-based traffic supervision method
Technical Field
The invention belongs to the technical field of network communication, particularly relates to the technical field of network communication traffic supervision, and particularly relates to a traffic supervision method based on an SDN framework.
Background
Network security has always been a hotspot problem in the network field, and network attacks are not flooded in the network at all times. The flow supervision can effectively prevent the impact on the network caused by a large amount of instantaneous data in the network, and ensure the efficient and stable operation of the user network.
Network flow is often supervised in a traditional network, however, monitoring equipment with high price is often adopted, the function is single, high expansibility is not achieved, the flexible and changeable network attack is difficult to adapt, more requirements are brought to safety analysis workers in the equipment, the safety analysis workers need to master the use methods of various equipment besides corresponding safety knowledge storage, and the learning cost is increased by replacing different equipment. In addition, the monitoring equipment follows different technical standards, so that more convenient and faster user-defined setting is difficult to perform, and the flexibility and the expansibility of the equipment are greatly reduced.
Traditional traffic supervision messages will be marked in three colors: green, yellow and red. Carrying out flow statistics on the green messages and re-marking the actions which can be taken on the yellow messages as message priority; the action that can be taken for a red message is to discard it. The flow statistics supports byte statistics or message number statistics, and the supervision condition is convenient to check. The priority re-marking is to search a re-marking priority mapping table according to the original priority of the message to obtain the new message priority. However, the conventional configuration of traffic policing is distributed, and the requirement for an administrator is high on a per forwarding device basis.
SDN (Software Defined Networking) is a novel network technology architecture. Unlike conventional network architectures, it separates the control plane and the data plane of the network. In the data plane, the functions tend to be simpler, and the forwarding can be carried out according to the strategy of the control plane. SDN (Software Defined Networking) control plane is typically handled by a controller, with switches implementing data plane functions. SDN (Software defined networking) is flexible, reliable and safe, and the characteristics meet the requirements of the Internet on expandability, safety and compatibility. The strategy of separating the control plane and the data plane of the software-defined network is very beneficial to the expansion and the upgrade of the communication network.
The invention discloses a method for monitoring flow based on an SDN framework, which is typically applied to monitoring the specification of certain flow entering a network by an SDN controller, limiting the certain flow within a reasonable range, or performing punishment on the excessive flow so as to protect network resources and the benefits of operators. For example, HTTP messages may be limited from occupying more than 50% of the network bandwidth. If the traffic of a certain connection is found to be out of standard, the traffic supervision can choose to discard the message or reset the priority of the message. The SDN controller calculates the flow monitoring process based on the SDN framework in a unified way and manages the flow monitoring process in a centralized way; all flow supervision configurations are centralized on the SDN controller, and management and later-stage operation are facilitated.
Disclosure of Invention
In view of the shortcomings or shortcomings of the prior art, the technical problem to be solved by the present invention is to provide a SDN architecture-based traffic supervision method in which a traffic supervision process is uniformly controlled by an SDN controller.
In order to solve the above technical problems, the present invention has the following configurations:
a traffic supervision method based on an SDN architecture comprises the following steps: s101: a user configures a flow supervision strategy on an SDN controller; s102: the SDN controller receives a message from the SDN switch and analyzes a target IP and a source IP; s103: the SDN controller receives a private extended expermer message from the SDN switch and analyzes the expermer message; s104: and the SDN switch detects the flow rate and reports the flow rate to the SDN controller according to a detection result.
The SDN controller supports SDN-based traffic supervision configuration tasks, and the configuration tasks comprise traffic supervision tables and SDN-based traffic supervision functions; the flow monitoring table comprises flow characteristics and threshold values specified by a user and monitoring states reported by the SDN switch; the SDN-based traffic supervision function is configured to turn on or off the SDN-based traffic supervision function.
The system also comprises a private traffic supervision table which is statically configured or dynamically created by a user, and the priority of the static entry is higher than that of the dynamic entry; the private flow monitoring table comprises a destination IP, a source IP, a green threshold, a yellow threshold and a monitoring state; the destination IP and the source IP are used for specifying flow; comparing the flow rate with a green threshold and a yellow threshold respectively, and reporting the flow rate to an SDN controller after the SDN switch carries out flow statistics; the supervision state represents the marked color of the report reported by the SDN switch.
The format of the private extended expermer message received by the SDN controller from the SDN switch is that the expermer value is 1, which indicates that the message is directed from the SDN switch to the SDN controller, and the expermer value is 255; reporting the private extended Experimenter message to an SDN controller by an SDN switch on a forwarding path; the destination IP and the source IP uniquely determine a stream; the regulatory status indicates what color traffic is marked.
The step S101 is specifically: reporting a message of the unmatched flow table by the SDN switch; the SDN controller issues a flow table based on a flow supervision strategy and a forwarding path; and reporting a flow monitoring result by the SDN switch.
Inquiring a flow supervision table according to the destination IP and the source IP, and if the flow supervision table is hit, obtaining a threshold value and a priority level from the matched entry; then acquiring a message forwarding path, and issuing flow tables to all SDN switches on the forwarding path according to the matched entries; inquiring a flow monitoring table according to the destination IP and the source IP, and if the flow monitoring table is not hit, dynamically generating a new monitoring item; finally, a message forwarding path is obtained, and flow tables are issued to all SDN switches on the forwarding path according to the matched entries; and if the monitoring item is not hit, the SDN controller dynamically generates a new monitoring item, the threshold value is a default value, the priority level is taken from the message, and no change is made.
In step S103, the supervision state of the traffic supervision table is updated according to the Experimenter packet analyzed by the SDN controller.
If the detection rate of the SDN switch is less than or equal to a green threshold value, the flow is marked to be green, and the SDN switch reports the flow to the controller after carrying out flow statistics; the flow statistics comprises byte number and message number statistics; if the detection rate of the SDN switch is larger than a green threshold value and is smaller than or equal to a yellow threshold value, marking the flow into yellow, re-marking the priority of the SDN switch, and reporting the priority to an SDN controller; the priority re-marking processing mode is priority reduction processing; if the snooping rate of the SDN switch is greater than the yellow threshold, the traffic is marked red and reported to the SDN controller.
When the traffic is marked red, the SDN switch performs packet loss processing.
The SDN controller and the SDN switch both support expansion of flow tables; the Match field of the expansion flow table comprises a source IP and a destination IP; the action field of the extended flow table is the rate of the detected flow.
The extended flow table specifically includes: when the detection rate is less than or equal to a green threshold value, the flow is marked to be green, and the SDN switch carries out flow statistics and reports the flow to the controller; when the detection rate is less than or equal to a yellow threshold value, marking the flow as yellow, and the SDN switch carries out priority re-marking and reports the priority re-marking to the SDN controller; and when the detection rate is greater than the yellow threshold value, marking the flow as red, and reporting the packet to an SDN controller by the SDN switch.
Compared with the prior art, the flow supervision process based on the SDN framework is uniformly calculated and managed by the SDN controller, all flow supervision configurations are centralized on the SDN controller, and management and later-stage operation are facilitated; SDN controllers regulate the specification of a certain amount of traffic entering the network, limit it to a reasonable range, or "penalize" the excess traffic to protect network resources and operator benefits.
Drawings
FIG. 1: the invention is a flow supervision method schematic diagram based on an SDN framework;
FIG. 2: the invention is based on a flow supervision flow chart of an SDN framework;
FIG. 3: the invention discloses a flow chart of processing a user message by an SDN controller;
FIG. 4: the invention discloses a flow chart of processing an Experimenter message by an SDN controller;
FIG. 5: the invention relates to a processing flow chart of an SDN switch;
FIG. 6: the test environment of the embodiment of the invention is schematic.
Detailed Description
The conception, the specific structure and the technical effects of the present invention will be further described with reference to the accompanying drawings to fully understand the objects, the features and the effects of the present invention.
As shown in fig. 1, the traffic supervision method based on the SDN architecture of the present invention includes the following steps: s101: a user configures a flow supervision strategy on an SDN controller; s102: the SDN controller receives a message from the SDN switch and analyzes a target IP and a source IP; s103: the SDN controller receives a private extended expermer message from the SDN switch and analyzes the expermer message; s104: and the SDN switch detects the flow rate and reports the flow rate to the SDN controller according to a detection result. The flow monitoring process based on the SDN framework is uniformly calculated and managed by the SDN controller, all flow monitoring configurations are centralized on the SDN controller, and management, operation and maintenance are facilitated.
The specific supervision of the different steps will be specifically described below:
step S101, see fig. 2: and configuring a flow supervision strategy on the SDN controller by a user.
Specifically, the SDN switch reports a message that does not match a flow table; the SDN controller issues a flow table based on a flow supervision strategy and a forwarding path; and reporting a flow monitoring result by the SDN switch.
The SDN controller supports SDN-based traffic supervision configuration tasks including traffic supervision tables and SDN-based traffic supervision functions. The flow monitoring table comprises flow characteristics and threshold values specified by a user and monitoring states reported by the SDN switch. The SDN-based traffic supervision function is configured to turn on or off the SDN-based traffic supervision function.
Step S102, see fig. 3: and the SDN controller receives a message from the SDN switch and analyzes a destination IP and a source IP.
Inquiring a private flow supervision table according to the destination IP and the source IP, and if the private flow supervision table is hit, obtaining a threshold value and a priority level from the matched entry; and then acquiring a message forwarding path, and issuing flow tables to all SDN switches on the forwarding path according to the matched entries.
And inquiring a private flow monitoring table according to the destination IP and the source IP, if the private flow monitoring table is not hit, dynamically generating a new monitoring entry by the SDN controller, wherein the threshold value is a default value, the priority level is taken from the message, and the priority level is not changed. And finally, acquiring a message forwarding path, and issuing flow tables to all SDN switches on the forwarding path according to the matched entries.
The private traffic policing table is statically configured or dynamically created by the user, and static entries have a higher priority than dynamic entries.
The private flow monitoring table comprises a destination IP, a source IP, a green threshold, a yellow threshold and a monitoring state; the destination IP and the source IP are used for specifying flow; comparing the flow rate with a green threshold and a yellow threshold respectively, and reporting the flow rate to an SDN controller after the SDN switch carries out flow statistics; the supervision state represents the marked color of the report reported by the SDN switch.
Step S103, see fig. 4: the SDN controller receives a private extended Experimenter message from the SDN switch, analyzes the Experimenter message, and then updates the monitoring state of the flow monitoring table.
The format of the private extended expermer message received by the SDN controller from the SDN switch is that the expermer value is 1, which indicates that the message is directed from the SDN switch to the SDN controller, and the expermer value is 255; reporting the private extended Experimenter message to an SDN controller by an SDN switch on a forwarding path; the destination IP and the source IP uniquely determine a stream; the regulatory status indicates what color the flow is marked (see description below).
The regulatory status typically indicates that the traffic is labeled in three colors: green, yellow and red, when the traffic is marked as green, the SDN switch performs traffic statistics and reports the traffic statistics to the controller; when the flow is marked to be yellow, the SDN switch carries out priority re-marking and reports to the SDN controller; and when the traffic is marked to be red, the SDN switch carries out packet loss processing and reports the packet loss processing to the SDN controller.
Step S104, see fig. 5: and the SDN switch detects the flow rate and reports the flow rate to the SDN controller according to a detection result.
Specifically, if the detection rate of the SDN switch is less than or equal to a green threshold, the traffic is marked green, and the SDN switch performs traffic statistics and reports the traffic statistics to the controller. The flow statistics comprises byte number and message number statistics.
And if the detection rate of the SDN switch is greater than the green threshold and is less than or equal to the yellow threshold, marking the flow as yellow, and the SDN switch carries out priority re-marking and reports the priority re-marking to the SDN controller. The priority re-marking is processed in a priority reduction mode.
And if the detection rate of the SDN switch is greater than the yellow threshold, marking the flow as red, and reporting the packet loss to the SDN controller by the SDN switch.
With the above different threshold settings, the SDN controller supervises the specification of a certain traffic entering the network, limits it within a reasonable range, or "penalizes" the excess traffic to protect the network resources and the benefit of the operator.
As a further improvement, the SDN controller and the SDN switch both support an extended flow table. The Match field of the augmented flow table includes a source IP and a destination IP. The action field of the extended flow table is the rate of the detected flow.
The augmented flow table is specifically described as: when the detection rate is less than or equal to a green threshold value, the flow is marked to be green, and the SDN switch performs flow statistics (statistics of the number of bytes and the number of messages to be supported) and reports the flow to the controller; when the detection rate is less than or equal to a yellow threshold value, marking the flow as yellow, carrying out priority re-marking (priority reduction) on the SDN switch, and reporting to an SDN controller; and when the detection rate is greater than the yellow threshold, marking the traffic as red, and reporting the SDN controller by the SDN switch when the SDN switch loses the packet.
The SDN-based traffic supervision method according to the present invention will be specifically described below with reference to a specific test environment.
Firstly, as shown in fig. 6, a test environment is established, and a user configures a traffic supervision policy on an SDN controller.
The SDN controller supports SDN-based traffic supervision configuration tasks including traffic supervision tables and SDN-based traffic supervision functions. The flow monitoring table comprises flow characteristics and threshold values specified by a user and monitoring states reported by the SDN switch. The SDN-based traffic supervision function is configured to turn on or off the SDN-based traffic supervision function.
In addition, the SDN controller and SDN switch both support an augmented flow table. The extended flow table comprises a Match field and an action field, the Match field comprises a source IP and a destination IP, and the action field of the extended flow table is the speed of the detection flow.
The augmented flow table is specifically described as: when the detection rate is less than or equal to a green threshold value, the flow is marked to be green, and the SDN switch performs flow statistics (statistics of the number of bytes and the number of messages to be supported) and reports the flow to the controller; when the detection rate is less than or equal to a yellow threshold value, marking the flow as yellow, carrying out priority re-marking (priority reduction) on the SDN switch, and reporting to an SDN controller; and when the detection rate is greater than the yellow threshold, marking the traffic as red, and reporting the SDN controller by the SDN switch when the SDN switch loses the packet.
In the test environment, the green threshold is 100 PPS, the yellow threshold is 200PPS, and the new priority level is 1. The flow from the client C to the server is 50PPS, the flow from the client A to the server is 120 PPS, and the flow from the client B to the server is 220 PPS.
The SDN controller then receives the packet from the SDN switch, parses the destination IP and the source IP, and follows a private traffic policing table. The private traffic supervision table comprises a destination IP, a source IP, a green threshold, a yellow threshold and a supervision state.
The destination IP and the source IP are used for specifying flow; comparing the flow rate with a green threshold and a yellow threshold respectively, and reporting the flow rate to an SDN controller after the SDN switch carries out flow statistics; the supervision state represents a color of the SDN switch reporting message being marked.
The specific comparison result of the flow rate in the test environment is that the flow from the client C to the server is 50PPS, and the value is smaller than the green threshold value of 100 PPS.
The client a traffic to the server is 120 PPS, which is greater than the green threshold and less than the yellow threshold of 200 PPS.
Client B traffic to the server is 220 PPS, which is greater than the yellow threshold of 200 PPS.
Then, the SDN controller receives a private extended Experimenter message from the SDN switch and analyzes the Experimenter message.
The SDN controller receives a private extended expermer message from an SDN switch in a format that the expermer value is 1, the message is from the SDN switch to the SDN controller, and the expermer value is 255 and needs to apply to an ONF organization; reporting the private extended Experimenter message to an SDN controller by an SDN switch on a forwarding path; the destination IP and the source IP uniquely determine a stream; the regulatory status indicates what color the flow is marked, and the regulatory status typically indicates that the flow is marked in three colors, green, yellow, and red.
The steps are as follows:
the client C traffic to the server is marked green.
The client a traffic to the server is marked yellow.
Client B traffic to the server is marked red.
And finally, the SDN switch detects the flow rate and reports the flow rate to the SDN controller according to a detection result.
The specific analysis process is that if the detection rate of the SDN switch is less than or equal to a green threshold value, the flow is marked to be green, and the SDN switch performs flow statistics and reports the flow statistics to the SDN controller. The flow statistics comprises byte number and message number statistics.
And if the detection rate of the SDN switch is greater than the green threshold and is less than or equal to the yellow threshold, marking the flow as yellow, and the SDN switch carries out priority re-marking and reports the priority re-marking to the SDN controller. The priority re-marking is processed in a priority reduction mode.
And if the detection rate of the SDN switch is greater than the yellow threshold, marking the flow as red, and reporting the packet loss to the SDN controller by the SDN switch.
According to the analysis, the flow from the client C to the server is 50PPS < green threshold 100 PPS, the flow is marked as green, and the SDN switch reports the flow to the SDN controller after performing flow statistics (statistics of the number of bytes and the number of messages to be supported).
If the traffic 120 PPS from the client a to the server is greater than the green threshold 100 PPS and is less than the yellow threshold 200PPS, the traffic is marked to be yellow, the SDN switch performs priority re-marking, that is, the priority of the traffic from the client a to the server is modified to be 1 (the priority of 1 is the lowest), and reports the traffic to the SDN controller.
If the traffic 220 PPS from the client B to the server is greater than the yellow threshold 200PPS, the traffic is marked red, directly discarded by S0, and reported to the SDN controller.
Through the setting of the different thresholds, the SDN controller monitors the specification of a certain flow entering the network, and limits the certain flow to a reasonable range, that is, monitors the flows of the client a, the client B and the client C, and "punishes" the partial flow that exceeds the certain flow, that is, directly discards the flow data of the client B and performs degradation processing on the flow data of the client a, so as to protect the network resources and the benefits of the operator.
The SDN controller calculates the flow supervision process based on the SDN framework in a unified mode, the flow supervision process is managed in a centralized mode, all flow supervision configurations are centralized on the SDN controller, management and later-stage operation are facilitated, the supervision effect is obviously superior to that of a traditional working mode, control is more convenient and efficient, and the SDN controller has a very wide market application prospect.
It will be appreciated by those skilled in the art that the drawings are merely schematic representations of one preferred embodiment and that the elements or processes in the drawings are not necessarily required to practice the invention. The above-mentioned serial numbers of the embodiments of the present invention are merely for description and do not represent the merits of the embodiments.
The above embodiments are merely to illustrate the technical solutions of the present invention, not to limit the present invention, and the present invention has been described in detail with reference to the preferred embodiments. It will be understood by those skilled in the art that various modifications and equivalent arrangements may be made without departing from the spirit and scope of the present invention and it is intended to cover the appended claims.

Claims (7)

1. A traffic supervision method based on an SDN architecture is characterized by comprising the following steps:
s101: a user configures a flow supervision strategy on an SDN controller;
the SDN controller supports SDN-based traffic supervision configuration tasks, and the configuration tasks comprise traffic supervision tables and SDN-based traffic supervision functions; the flow monitoring table comprises flow characteristics and threshold values specified by a user and monitoring states reported by the SDN switch; the SDN-based traffic supervision function is used for turning on or off the SDN-based traffic supervision function;
s102: the SDN controller receives a message from the SDN switch and analyzes a target IP and a source IP;
inquiring a private flow supervision table according to the destination IP and the source IP, and if the private flow supervision table is hit, obtaining a threshold value and a priority level from the matched entry; then acquiring a message forwarding path, and issuing flow tables to all SDN switches on the forwarding path according to the matched entries;
inquiring a private flow monitoring table according to a destination IP and a source IP, if the private flow monitoring table is not hit, dynamically generating a new monitoring entry by the SDN controller, wherein a threshold value is a default value, a priority level is taken from a message, and the priority level is not changed;
wherein, the private traffic supervision table is statically configured or dynamically created by a user, and the priority of the static entry is higher than that of the dynamic entry; the private flow monitoring table comprises a destination IP, a source IP, a green threshold, a yellow threshold and a monitoring state; the destination IP and the source IP are used for specifying flow; comparing the flow rate with a green threshold and a yellow threshold respectively, and reporting the flow rate to an SDN controller after the SDN switch carries out flow statistics; the supervision state represents the marked color of the report reported by the SDN switch;
s103: the SDN controller receives a private extended Experimenter message from the SDN switch, analyzes the Experimenter message, and updates the monitoring state of a flow monitoring table;
s104: and the SDN switch detects the flow rate and reports the flow rate to the SDN controller according to a detection result.
2. The SDN architecture-based traffic policing method of claim 1, wherein the SDN controller receives a private extended expermer message from an SDN switch in a format, wherein an expermer value of 1 indicates that the SDN switch is directed to the SDN controller, and wherein the expermer value is 255; reporting the private extended Experimenter message to an SDN controller by an SDN switch on a forwarding path; the destination IP and the source IP uniquely determine a stream; the regulatory status indicates what color traffic is marked.
3. The SDN architecture-based traffic supervision method according to claim 1, wherein the step S101 is specifically:
reporting a message of the unmatched flow table by the SDN switch;
the SDN controller issues a flow table based on a flow supervision strategy and a forwarding path;
and reporting a flow monitoring result by the SDN switch.
4. The SDN architecture-based traffic policing method of claim 1,
if the detection rate of the SDN switch is less than or equal to a green threshold value, the flow is marked to be green, and the SDN switch reports the flow to the controller after carrying out flow statistics;
the flow statistics comprises byte number and message number statistics;
if the detection rate of the SDN switch is larger than a green threshold value and is smaller than or equal to a yellow threshold value, marking the flow into yellow, re-marking the priority of the SDN switch, and reporting the priority to an SDN controller;
the priority re-marking processing mode is priority reduction processing;
if the snooping rate of the SDN switch is greater than the yellow threshold, the traffic is marked red and reported to the SDN controller.
5. The SDN architecture based traffic policing method of claim 4, wherein when the traffic is marked red, the SDN switch will perform packet loss processing.
6. The SDN architecture based traffic policing method of claim 1, wherein the SDN controller and SDN switch each support an augmented flow table; the Match field of the expansion flow table comprises a source IP and a destination IP; the action field of the extended flow table is the rate of the detected flow.
7. The SDN architecture-based traffic policing method of claim 6, wherein the augmented flow table is specifically: when the detection rate is less than or equal to a green threshold value, the flow is marked to be green, and the SDN switch carries out flow statistics and reports the flow to the controller; when the detection rate is less than or equal to a yellow threshold value, marking the flow as yellow, and the SDN switch carries out priority re-marking and reports the priority re-marking to the SDN controller; and when the detection rate is greater than the yellow threshold value, marking the flow as red, and reporting the packet to an SDN controller by the SDN switch.
CN201710021501.1A 2017-01-12 2017-01-12 SDN architecture-based traffic supervision method Active CN106789703B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201710021501.1A CN106789703B (en) 2017-01-12 2017-01-12 SDN architecture-based traffic supervision method

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201710021501.1A CN106789703B (en) 2017-01-12 2017-01-12 SDN architecture-based traffic supervision method

Publications (2)

Publication Number Publication Date
CN106789703A CN106789703A (en) 2017-05-31
CN106789703B true CN106789703B (en) 2020-10-13

Family

ID=58947751

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201710021501.1A Active CN106789703B (en) 2017-01-12 2017-01-12 SDN architecture-based traffic supervision method

Country Status (1)

Country Link
CN (1) CN106789703B (en)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108235804B (en) * 2017-12-27 2021-12-31 达闼机器人有限公司 Network speed limiting method and device and server
CN110351199A (en) * 2018-04-04 2019-10-18 中兴通讯股份有限公司 Flow smoothing method, server and forwarding device
CN112671713B (en) * 2020-11-30 2023-01-20 山东电力工程咨询院有限公司 SDN network data forwarding method, SDN switch, controller and system
CN114500418B (en) * 2022-02-11 2023-10-20 珠海星云智联科技有限公司 Data statistics method and related device

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104601482A (en) * 2013-10-30 2015-05-06 中兴通讯股份有限公司 Traffic cleaning method and device
CN104796344A (en) * 2014-01-16 2015-07-22 中兴通讯股份有限公司 Method, system, Openflow switch and server for realizing message forwarding based on SDN
CN105429886A (en) * 2015-10-30 2016-03-23 南京优速网络科技有限公司 Comprehensive unified flow scheduling system and scheduling method based on SDN

Family Cites Families (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101741603B (en) * 2008-11-11 2013-01-16 中兴通讯股份有限公司 Method and device for supervising traffic based on token bucket
CN101741739B (en) * 2009-12-01 2012-06-13 中兴通讯股份有限公司 Method and device for counting messages of output/input port of exchange equipment
US9729424B2 (en) * 2012-06-11 2017-08-08 Futurewei Technologies, Inc. Defining data flow paths in software-defined networks with application-layer traffic optimization
CN104301251B (en) * 2014-09-22 2018-04-27 新华三技术有限公司 A kind of QoS processing methods, system and equipment
CN105791152B (en) * 2014-12-19 2019-02-19 新华三技术有限公司 A kind of flow control methods, SDN controller and SDN equipment
CN104734994A (en) * 2015-04-13 2015-06-24 上海斐讯数据通信技术有限公司 Traffic label control method based on SDN (software-defined network) frame
CN104967578B (en) * 2015-07-08 2017-11-21 上海斐讯数据通信技术有限公司 SDN controllers and interchanger, flow table management method and message processing method
CN105376158B (en) * 2015-10-12 2018-04-27 上海斐讯数据通信技术有限公司 SDN circulation methods and its device based on EXP values in MPLS messages
CN105827487A (en) * 2016-05-30 2016-08-03 上海斐讯数据通信技术有限公司 SDN network message flow statistics method, SDN network message flow processing method and SDN network system
CN106330625A (en) * 2016-11-25 2017-01-11 国网安徽省电力公司信息通信分公司 SDN-based flow detection method

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104601482A (en) * 2013-10-30 2015-05-06 中兴通讯股份有限公司 Traffic cleaning method and device
CN104796344A (en) * 2014-01-16 2015-07-22 中兴通讯股份有限公司 Method, system, Openflow switch and server for realizing message forwarding based on SDN
CN105429886A (en) * 2015-10-30 2016-03-23 南京优速网络科技有限公司 Comprehensive unified flow scheduling system and scheduling method based on SDN

Also Published As

Publication number Publication date
CN106789703A (en) 2017-05-31

Similar Documents

Publication Publication Date Title
CN106789703B (en) SDN architecture-based traffic supervision method
Hyun et al. Towards knowledge-defined networking using in-band network telemetry
US9929965B1 (en) Traffic-aware sampling rate adjustment within a network device
JP4774357B2 (en) Statistical information collection system and statistical information collection device
US9203645B2 (en) Virtual input-output connections for machine virtualization
US9473456B2 (en) Incremental application of resources to network traffic flows based on heuristics and business policies
EP2933954B1 (en) Network anomaly notification method and apparatus
Hyun et al. Knowledge-defined networking using in-band network telemetry
US20150156086A1 (en) Behavioral network intelligence system and method thereof
CN106790656B (en) SDN-based load balancing device and method thereof
KR20140106235A (en) Open-flow switch and packet manageing method thereof
WO2020083272A1 (en) Processing strategy generation method and system, and storage medium
CN112787959B (en) Flow scheduling method and system
US8693335B2 (en) Method and apparatus for control plane CPU overload protection
CN106059942A (en) Traffic control method based on load prediction in SDN network
CN105100142A (en) Transmission control method and device of software defined network (SDN) protocol message
EP3791543B1 (en) Packet programmable flow telemetry profiling and analytics
Afaq et al. Large flows detection, marking, and mitigation based on sFlow standard in SDN
CN107819602A (en) Customer flow distribution method and system
Kumar et al. Open flow switch with intrusion detection system
CN115484047A (en) Method, device, equipment and storage medium for identifying flooding attack in cloud platform
CN108183864B (en) IDS feedback-based software-defined network flow sampling method and system
KR20180058594A (en) Software Defined Network/Test Access Port Application
Krishnan et al. Behavioral security threat detection strategies for data center switches and routers
CN107241359A (en) A kind of software-oriented defines the lightweight network flow abnormal detecting method of network

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant
TR01 Transfer of patent right

Effective date of registration: 20201023

Address after: 318015 no.2-3167, zone a, Nonggang City, no.2388, Donghuan Avenue, Hongjia street, Jiaojiang District, Taizhou City, Zhejiang Province

Patentee after: Taizhou Jiji Intellectual Property Operation Co.,Ltd.

Address before: 201616 Shanghai city Songjiang District Sixian Road No. 3666

Patentee before: Phicomm (Shanghai) Co.,Ltd.

TR01 Transfer of patent right
TR01 Transfer of patent right

Effective date of registration: 20221025

Address after: Room 2005, Dongjian Building East, No. 501-507, Dongfeng Middle Road, Yuexiu District, Guangzhou, Guangdong 510000

Patentee after: Guangdong Yundong Technology Co.,Ltd.

Address before: 318015 no.2-3167, area a, nonggangcheng, 2388 Donghuan Avenue, Hongjia street, Jiaojiang District, Taizhou City, Zhejiang Province

Patentee before: Taizhou Jiji Intellectual Property Operation Co.,Ltd.

TR01 Transfer of patent right