CN103731482A - Cluster load balancing system and achieving method thereof - Google Patents

Cluster load balancing system and achieving method thereof Download PDF

Info

Publication number
CN103731482A
CN103731482A CN201310720350.0A CN201310720350A CN103731482A CN 103731482 A CN103731482 A CN 103731482A CN 201310720350 A CN201310720350 A CN 201310720350A CN 103731482 A CN103731482 A CN 103731482A
Authority
CN
China
Prior art keywords
request
load
cluster
condition code
http
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201310720350.0A
Other languages
Chinese (zh)
Inventor
戴纯兴
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Inspur Electronic Information Industry Co Ltd
Original Assignee
Inspur Electronic Information Industry Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Inspur Electronic Information Industry Co Ltd filed Critical Inspur Electronic Information Industry Co Ltd
Priority to CN201310720350.0A priority Critical patent/CN103731482A/en
Publication of CN103731482A publication Critical patent/CN103731482A/en
Pending legal-status Critical Current

Links

Images

Abstract

The invention relates to a load balancing method, in particular to a load balancing method under the condition that safety of an HTTP request is ensured after rule matching. The invention particularly relates to a cluster load balancing system and an achieving method thereof. By means of a clustering manner, safe detection and filtering are carried out on the HTTP request and responding content. The safety of the HTTP request is ensured after rule matching.

Description

A kind of cluster SiteServer LBS and its implementation
Technical field
The present invention relates to a kind of load-balancing method, particularly a kind ofly guarantee that HTTP asks the load-balancing method safe in the situation that, specifically provides a kind of cluster SiteServer LBS and its implementation after by rule match.
Background technology
Along with the continuous progress of network technology, Web network service and user's quantity is with explosive growth.To such an extent as to the visit capacity of Web website and data traffic are constantly challenged the performance of server.The disposal ability of single server and computing capability cannot be born this challenge under many circumstances.Therefore proposed the scheme of load balancing, by load-balancing technique, making many Web servers be combined into an organic whole unification externally provides Web service, has effectively guaranteed stability and the high efficiency of Web website.
Just because of the continuous progress of network technology, the threshold that enters this field is constantly reduced, a large amount of technical staff constantly pours in such field.A large amount of Web application systems is accepted and by them, carries out network browsing and obtain various information and the various article of network payment purchase.The various aspects of people's life can satisfy the demands by the form of network.Thing followed network security problem is also more and more outstanding.Therefore there is Web safety detection technology, for guaranteeing the safe and effective of Web service.
But the Web safety detection based on application has also produced huge challenge to device processes ability and computing capability, in order to guarantee the effective and stable of Web safety detection, can tackle the deployment way of backstage Web cluster.Web safety detection technology based on load balancing becomes a developing direction of load-balancing device.
Summary of the invention
In order to solve the problem of prior art, the invention provides a kind of cluster SiteServer LBS and its implementation, its mode by cluster is to HTTP request and response contents safety detection and filtration, by guaranteeing HTTP request safety after rule match.
The technical solution adopted in the present invention is as follows:
A cluster SiteServer LBS, comprising:
Virtual Networking System, for different load-balancing devices being invented to an equipment, externally provides service;
Request dissemination system, for HTTP request being distributed to corresponding load-balancing device according to the difference of each load-balancing device current performance, comprises that condition code is calculated, request distribution, request receiving;
Delivery of services system, is distributed to rear end real server by consistency HASH algorithm by request for the condition code according to based on IP and COOKIE, comprises consistency HASH algorithm, TCP/IP request distribution and safety detection.
Virtual Networking System, the mode the network interface card of distinct device by network interface card polymerization invents same network interface card, and by their, receives and send HTTP and ask.
Request dissemination system has adopted condition code computing technique, by the different performance parameter of load-balancing device, by certain algorithm, is converted into a metric.
Request dissemination system has adopted request distribution technology, for HTTP is asked according to the difference of condition code, is directly assigned on specific load-balancing device.
Request dissemination system has adopted request receiving technology, and the HTTP sending on this load-balancing device by other load-balancing device is asked, and converts to from this equipment and receives.
Delivery of services system has adopted the consistency hash algorithm based on COOKIE and IP, for guaranteeing to send to the session consistency of the HTTP request of rear end real server cluster.
Delivery of services system has adopted TCP/IP request distribution technology, for the HTTP request by 7 layers of load balancing, sends to rear end real server.
Delivery of services system has adopted safety detection technology, realizes information filtering and attack detecting function with response to HTTP request.
An implementation method for cluster SiteServer LBS, comprises the realization of the realization of Virtual Networking System, the realization of request dissemination system and service dissemination system:
Wherein, the implementation method of Virtual Networking System is: load equalizer cluster is that the mode of disposing with bypass is linked in network environment, deployment way between load-balanced server cluster is that the network port of different loads equalizer is pooled to same virtual network port; Exchanges data between load equalizer completes by trusted port separately; Separate unit load equalizer also can be realized local port and converge; But when many load equalizers are disposed, local load balancing device is by invalid;
Ask the implementation method of dissemination system specifically:
First system derives three processes after starting, and is responsible for respectively condition code and calculates, trusted port data receiver, virtual port data receiver;
Wherein condition code is calculated and is adopted cpu busy percentage, memory usage and network throughput weighted average to obtain, and is saved in condition code storehouse;
Credible network interface card monitor process is responsible for synchronous to condition code storehouse and other load-balancing devices is sent to the HTTP request of this equipment, is treated to from this equipment Microsoft Loopback Adapter and receives, and be forwarded in delivery of services system;
Microsoft Loopback Adapter monitor process is for receiving HTTP request, and to calculate current request be by this device processes or being forwarded to miscellaneous equipment processes according to condition code;
The implementation method of delivery of services system is specifically: the HTTP request that receptivity dissemination system sends, and safety detection is carried out in request to HTTP, if detect by; by IP and COOKIE consistency HASH algorithm, select back-end server, and Forward-reques; If, by safety detection, directly do not return to the wrong page, and close TCP connection; Detect the data of back-end server response simultaneously, after detecting, return to client, not by the wrong page that returns detecting.
The beneficial effect that technical scheme provided by the invention is brought is:
1, the SiteServer LBS of realizing by the method is load balancing checkout equipment independently.Its whole system running environment can be that a platform independent operation also can form cluster synthetic operation by multiple devices;
2, in single device operation, possesses local port aggregation feature.A plurality of network interface cards are pooled and have an IP, and the virtual network port of a MAC Address, externally provides service jointly;
3, in multiple devices operation, possess network port aggregation feature, local port aggregation feature is no longer enabled.Certain network interface card of distinct device is pooled and has an IP, and the virtual network port of a MAC Address, externally provides service jointly;
4, the principal character of Virtual Networking System is trunking.By this system, can realize fast interpolation and the deletion of load equalizer.Simultaneously can be to newly adding the load equalizer synchronization policy of cluster to;
5, the principal character of request dissemination system is that the HTTP request from Virtual Networking System reception is carried out to cluster distribution processor.Be responsible for the load-balancing device in cluster to carry out feature collection and keep its consistency; Load is distributed according to condition code the HTTP request receiving, and is distributed on different load-balancing devices; Be responsible for other load-balancing device in cluster to send over HTTP request, process, allow delivery of services system think that this HTTP request receives from local port; Be responsible for, to being distributed to the HTTP request of the machine, uploading to delivery of services system.Wherein condition code is calculated and has mainly been adopted cpu busy percentage, and memory usage and network throughput are weighted, and during delivery of services, with minimum value principle, distribute;
6, the principal character of delivery of services system is to receive HTTP request, and safety detection is carried out in request to HTTP, to not conforming to the HTTP request of rule, directly return to the wrong page, and interrupting TCP connects.The HTTP request of involutory rule calculates the rear end that will forward by the consistency hash algorithm based on IP and cookie, is forwarded to back-end server.For the http response receiving from back-end server, detect its response contents, close directly response of rule, do not conform to rule and return to the wrong page;
7, the principal character of safety detection is, can detect the agreement compliance of HTTP request, request header, request row, request body, can inject SQL, and network sweep, wooden horse is attacked, and common Web attacks and protects, and records attack logs.
In sum, a kind of cluster SiteServer LBS of the present invention and its implementation can provide load balancing service and intrusion detection service for back-end server.
Accompanying drawing explanation
The network site schematic diagram of Fig. 1 load equalizer of the present invention;
Network port when Fig. 2 is many load equalizer clusters of the present invention converges schematic diagram;
Local port when Fig. 3 is separate unit load equalizer deployment of the present invention converges schematic diagram;
Fig. 4 is the workflow diagram of request dissemination system of the present invention;
Fig. 5 is the workflow diagram of delivery of services system of the present invention;
Fig. 6 is the workflow diagram of safety detection mechanism of the present invention;
Fig. 7 is the consistency HASH algorithm schematic diagram based on IP and COOKIE.
Embodiment
For making the object, technical solutions and advantages of the present invention clearer, below in conjunction with accompanying drawing, embodiment of the present invention is described further in detail.
Embodiment mono-
As shown in Figure 1, load equalizer cluster is that the mode of disposing with bypass is linked in network environment.During deployment, must allow the HTTP of back-end server is asked, be forwarded to load equalizer, and have load equalizer that HTTP request is forwarded to rear end Web server.
As shown in Figure 2, the deployment way between load-balanced server cluster, is that the network port of different loads equalizer is pooled to same virtual network port.Exchanges data between load equalizer completes by trusted port separately.Separate unit load equalizer also can be realized local port and converge (accompanying drawing 3).But when many load equalizers are disposed, local load balancing device is by invalid.
Load equalizer forms cluster to be completed by Virtual Service system.Between Virtual Service system, by trust data port, communicate swap data; Can add automatically cluster or delete from cluster according to user's configuration.Thereby reach the object that expands flexibly cluster; Can pass through networks converge port, a Microsoft Loopback Adapter is externally provided, receive HTTP request.
A kind of cluster SiteServer LBS of the present embodiment, comprising:
Virtual Networking System, for different load-balancing devices being invented to an equipment, externally provides service;
Request dissemination system, for HTTP request being distributed to corresponding load-balancing device according to the difference of each load-balancing device current performance, comprises that condition code is calculated, request distribution, request receiving;
Delivery of services system, is distributed to rear end real server by consistency HASH algorithm by request for the condition code according to based on IP and COOKIE, comprises consistency HASH algorithm, TCP/IP request distribution and safety detection.
Its implementation is as accompanying drawing 4-6, and request dissemination system receives the data that Microsoft Loopback Adapter is received, can reach average load to being distributed on different load equalizers of the HTTP request dynamic receiving, and the object of load equalizer performance is provided; Can upload to service to the HTTP request being assigned on this load equalizer; Can be according to cpu utilance, memory usage and network throughput weighted calculation go out the minimum load equalizer of load, and when the machine load reaches certain condition, the HTTP request by receiving, is forwarded on the minimum load equalizer of load; The HTTP request that other load equalizer sends over, is treated to from the machine and receives, and upload to delivery of services system.
First system derives three processes after starting, and is responsible for respectively condition code and calculates, trusted port data receiver, virtual port data receiver.
Wherein condition code is calculated and is adopted cpu busy percentage, memory usage and network throughput weighted average to obtain.And be saved in condition code storehouse.
Condition code be synchronously this condition code from last time condition code when having setting different, just carry out synchronous.When this condition code and last time signature update value while being more or less the same, will not carry out signature update.
Credible network interface card monitor process is responsible for synchronous to condition code storehouse and other load-balancing devices is sent to the HTTP request of this equipment, is treated to from this equipment Microsoft Loopback Adapter and receives, and be forwarded in delivery of services system.Microsoft Loopback Adapter monitor process is for receiving HTTP request, and to calculate current request be by this device processes or being forwarded to miscellaneous equipment processes according to condition code.As being directly forwarded to delivery of services system by this device processes.If any miscellaneous equipment, process and will after request packing, according to condition code minimum value principle, be forwarded to miscellaneous equipment.
The HTTP request that delivery of services system (accompanying drawing 5) receptivity dissemination system sends.And safety detection is carried out in request to HTTP, passes through if detected, and selects back-end server by IP and COOKIE consistency HASH algorithm, and Forward-reques.If, by safety detection, directly do not return to the wrong page, and close TCP connection.Detect the data of back-end server response simultaneously, after detecting, return to client, not by the wrong page that returns detecting.
Safety detection engine detects data for (accompanying drawing 6), whether investigation meets http protocol standard, whether there is sensitive content, whether be the behaviors such as DDOS attack, Cc attack, SQL injection attacks, cross-site attack, common Web attack, network sweep, and judge whether Forward-reques according to investigation result, and to thering is the request msg of attack, return to testing result log.
The foregoing is only preferred embodiment of the present invention, in order to limit the present invention, within the spirit and principles in the present invention not all, any modification of doing, be equal to replacement, improvement etc., within all should being included in protection scope of the present invention.

Claims (7)

1. a cluster SiteServer LBS, comprises Virtual Networking System, request dissemination system and service dissemination system, wherein,
Virtual Networking System, for different load-balancing devices being invented to an equipment, externally provides service;
Request dissemination system, for HTTP request being distributed to corresponding load-balancing device according to the difference of each load-balancing device current performance, comprises that condition code is calculated, request distribution, request receiving;
Delivery of services system, is distributed to rear end real server by consistency HASH algorithm by request for the condition code according to based on IP and COOKIE, comprises consistency HASH algorithm, TCP/IP request distribution and safety detection.
2. a kind of cluster SiteServer LBS according to claim 1, is characterized in that, described Virtual Networking System for the mode by network interface card polymerization invents same network interface card the network interface card of distinct device, and receives and sends HTTP by their and ask.
3. a kind of cluster SiteServer LBS according to claim 1, is characterized in that, the condition code of described request dissemination system is calculated and referred to the different performance parameter of load-balancing device, by certain algorithm, is converted into a metric.
4. a kind of cluster SiteServer LBS according to claim 1, is characterized in that, the request distribution of described request dissemination system refers to asks HTTP according to the difference of condition code, is directly assigned on specific load-balancing device.
5. a kind of cluster SiteServer LBS according to claim 1, it is characterized in that, the request receiving of described request dissemination system refers to asks the HTTP sending on this load-balancing device by other load-balancing device, converts to from this equipment and receives.
6. a kind of cluster SiteServer LBS according to claim 1, is characterized in that, the TCP/IP request distribution of described delivery of services system refers to that the HTTP request by 7 layers of load balancing sends to rear end real server.
7. an implementation method for cluster SiteServer LBS, comprises that the realization of Virtual Networking System is, the realization of the realization of request dissemination system and service dissemination system:
Wherein, the implementation method of Virtual Networking System is: load equalizer cluster is that the mode of disposing with bypass is linked in network environment, deployment way between load-balanced server cluster is that the network port of different loads equalizer is pooled to same virtual network port; Exchanges data between load equalizer completes by trusted port separately; Separate unit load equalizer also can be realized local port and converge; But when many load equalizers are disposed, local load balancing device is by invalid;
Ask the implementation method of dissemination system specifically:
First system derives three processes after starting, and is responsible for respectively condition code and calculates, trusted port data receiver, virtual port data receiver;
Wherein condition code is calculated and is adopted cpu busy percentage, memory usage and network throughput weighted average to obtain, and is saved in condition code storehouse;
Credible network interface card monitor process is responsible for synchronous to condition code storehouse and other load-balancing devices is sent to the HTTP request of this equipment, is treated to from this equipment Microsoft Loopback Adapter and receives, and be forwarded in delivery of services system;
Microsoft Loopback Adapter monitor process is for receiving HTTP request, and to calculate current request be by this device processes or being forwarded to miscellaneous equipment processes according to condition code;
The implementation method of delivery of services system is specifically: the HTTP request that receptivity dissemination system sends, and safety detection is carried out in request to HTTP, if detect by; by IP and COOKIE consistency HASH algorithm, select back-end server, and Forward-reques; If, by safety detection, directly do not return to the wrong page, and close TCP connection; Detect the data of back-end server response simultaneously, after detecting, return to client, not by the wrong page that returns detecting.
CN201310720350.0A 2013-12-24 2013-12-24 Cluster load balancing system and achieving method thereof Pending CN103731482A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201310720350.0A CN103731482A (en) 2013-12-24 2013-12-24 Cluster load balancing system and achieving method thereof

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201310720350.0A CN103731482A (en) 2013-12-24 2013-12-24 Cluster load balancing system and achieving method thereof

Publications (1)

Publication Number Publication Date
CN103731482A true CN103731482A (en) 2014-04-16

Family

ID=50455404

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201310720350.0A Pending CN103731482A (en) 2013-12-24 2013-12-24 Cluster load balancing system and achieving method thereof

Country Status (1)

Country Link
CN (1) CN103731482A (en)

Cited By (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104113586A (en) * 2014-06-17 2014-10-22 上海地面通信息网络有限公司 Control device of load balancer bypassing data center switch
CN104202409A (en) * 2014-09-12 2014-12-10 成都卫士通信息产业股份有限公司 Balanced load SSL VPN (security socket layer, virtual private network) device cluster system and operating method thereof
CN104394163A (en) * 2014-12-05 2015-03-04 浪潮电子信息产业股份有限公司 Security detection method based on Web application
CN104539645A (en) * 2014-11-28 2015-04-22 百度在线网络技术(北京)有限公司 Method and equipment for processing http request
CN105282045A (en) * 2015-11-17 2016-01-27 高新兴科技集团股份有限公司 Distributed calculating and storage method based on consistent Hash algorithm
CN108134810A (en) * 2016-12-01 2018-06-08 中国移动通信有限公司研究院 A kind of method and its system of determining scheduling of resource component
CN110324282A (en) * 2018-03-29 2019-10-11 华耀(中国)科技有限公司 The load-balancing method and its system of SSL/TLS visualization flow
CN110417903A (en) * 2019-08-01 2019-11-05 广州知弘科技有限公司 A kind of information processing method and system based on cloud computing
CN113190607A (en) * 2021-05-21 2021-07-30 上海申铁信息工程有限公司 HTTP request-based database load balancing method, device and medium
CN114500340A (en) * 2021-12-23 2022-05-13 天翼云科技有限公司 Intelligent scheduling distributed path calculation method and system

Cited By (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104113586A (en) * 2014-06-17 2014-10-22 上海地面通信息网络有限公司 Control device of load balancer bypassing data center switch
CN104202409A (en) * 2014-09-12 2014-12-10 成都卫士通信息产业股份有限公司 Balanced load SSL VPN (security socket layer, virtual private network) device cluster system and operating method thereof
CN104202409B (en) * 2014-09-12 2017-09-15 成都卫士通信息产业股份有限公司 The SSL VPN devices group system and its method of work of a kind of load balancing
CN104539645A (en) * 2014-11-28 2015-04-22 百度在线网络技术(北京)有限公司 Method and equipment for processing http request
CN104394163A (en) * 2014-12-05 2015-03-04 浪潮电子信息产业股份有限公司 Security detection method based on Web application
CN105282045B (en) * 2015-11-17 2018-11-16 高新兴科技集团股份有限公司 A kind of distributed computing and storage method based on consistency hash algorithm
CN105282045A (en) * 2015-11-17 2016-01-27 高新兴科技集团股份有限公司 Distributed calculating and storage method based on consistent Hash algorithm
CN108134810A (en) * 2016-12-01 2018-06-08 中国移动通信有限公司研究院 A kind of method and its system of determining scheduling of resource component
CN108134810B (en) * 2016-12-01 2020-01-07 中国移动通信有限公司研究院 Method and system for determining resource scheduling component
CN110324282A (en) * 2018-03-29 2019-10-11 华耀(中国)科技有限公司 The load-balancing method and its system of SSL/TLS visualization flow
CN110417903A (en) * 2019-08-01 2019-11-05 广州知弘科技有限公司 A kind of information processing method and system based on cloud computing
CN113190607A (en) * 2021-05-21 2021-07-30 上海申铁信息工程有限公司 HTTP request-based database load balancing method, device and medium
CN113190607B (en) * 2021-05-21 2024-04-16 上海申铁信息工程有限公司 HTTP request-based database load balancing method, device and medium
CN114500340A (en) * 2021-12-23 2022-05-13 天翼云科技有限公司 Intelligent scheduling distributed path calculation method and system
CN114500340B (en) * 2021-12-23 2023-08-04 天翼云科技有限公司 Intelligent scheduling distributed path calculation method and system

Similar Documents

Publication Publication Date Title
CN103731482A (en) Cluster load balancing system and achieving method thereof
US11122067B2 (en) Methods for detecting and mitigating malicious network behavior and devices thereof
US10122740B1 (en) Methods for establishing anomaly detection configurations and identifying anomalous network traffic and devices thereof
CN107426206A (en) A kind of protector and method to web server
CN105991412B (en) Information push method and device
US20150244678A1 (en) Network traffic filtering and routing for threat analysis
CN107819891A (en) Data processing method, device, computer equipment and storage medium
CN102932391A (en) Method and device for processing data in peer to server/peer (P2SP) system, and P2SP system
CN108092940B (en) DNS protection method and related equipment
CN107733867B (en) Botnet discovery and protection method, system and storage medium
CN110798459B (en) Multi-safety-node linkage defense method based on safety function virtualization
CN104408182A (en) Method and device for processing web crawler data on distributed system
CN103067359A (en) System and method based on connection multiplexing and capable of improving server concurrent processing capacity
CN109889451A (en) The system and method and server of network speed limit
CN110557289A (en) Network architecture supporting configuration and service response method
KR101200906B1 (en) High Performance System and Method for Blocking Harmful Sites Access on the basis of Network
CN102708325A (en) Method and system for killing viruses of virtual desktop environment file
CN104506552B (en) A kind of information system security monitoring and access control method
CN112383573B (en) Security intrusion playback equipment based on multiple attack stages
CN111600929B (en) Transmission line detection method, routing strategy generation method and proxy server
JP6117345B2 (en) Message system that avoids degradation of processing performance
Lei et al. Integrating consortium blockchain into edge server to defense against ransomware attack
CN110545268A (en) multidimensional mimicry voting method based on process elements
US10992702B2 (en) Detecting malware on SPDY connections
CN103973744A (en) Distributed file progressive storage technology

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
WD01 Invention patent application deemed withdrawn after publication
WD01 Invention patent application deemed withdrawn after publication

Application publication date: 20140416