A kind of icmp packet matching system and method
Technical field
The present invention relates to network data exchange field, more particularly to a kind of icmp packet matching system and method.
Background technology
ICMP(Internet Control Message Protocol)Internet Control Message Protocol is TCP/IP associations
A sub-protocol of race is discussed, for transmitting control message between IP main frames, router.Including network it is unobstructed, main frame is reachable, road
Internet message is waited by available.Although not transmitting user data, the transmission for user data plays an important role.
In specific topological network, the treatment plan of possible in store thousands of each protocol massages of bar of switching equipment
Slightly.When specified packet is reached, it is necessary to carry out five-tuple matching so that it is determined that the port numbers position of the strategy taken, wherein ICMP becomes
Into TYPE types and CODE types, according to general TCP or udp protocol same strategy matching method, storage can be increased
Tactful bar number, so as to storage redundancy can be increased, reduces strategy matching efficiency.
The content of the invention
In order to solve the above technical problems, the present invention is for TYPE similar properties in ICMP strategies and message, it is proposed that one
Plant icmp packet matching system.
The technical solution adopted in the present invention is:
A kind of icmp packet matching system,
Including strategy analyzing module, packet parsing module, Hash operation module, clash handle module, policy store module and ratio
Compared with matching module;
Wherein,
Strategy analyzing module, processes strategy, by the strategy after parsing for receiving and parsing through the icmp packet that front stage circuits are issued
Data is activation is to the Hash operation module and policy store module;
Packet parsing module, the icmp packet of automatic network is carried out for receiving and parsing through, and the message data after parsing is sent to Kazakhstan
Uncommon computing module and comparison match module;
Hash operation module, policy data or message data for receiving input, Kazakhstan is mapped out by certain hash function
Uncommon result, through output end access interference processing module and the high address input of policy store module;
Clash handle module, for recording or inquiring about number of times and the corresponding policy store module that identical Hash output result occurs
Low order address;
Policy store module, exports public for policy data storage to be arrived by the output of Hash operation module and clash handle module
In the address specified;
Comparison match module, for message data and policy data to be carried out into matching comparing, and result is exported.
Policy data after parsing includes legal icmp packet source IP address, legal purpose IP address, legal
Icmp packet TYPE types, legal icmp packet direction, icmp packet processing mode.
Legal icmp packet TYPE types are represented that each position one represents bag in strategy by the bit data form of 11
Containing corresponding TYPE types.
Message data after parsing includes icmp packet source IP address, icmp packet purpose IP address, icmp packet TYPE
Type;
Icmp packet TYPE types after parsing are represented that a certain position one represents that the message is phase by the bit data form of 11
The TYPE types answered;
The invention also discloses a kind of icmp packet matching process, comprise the following steps,
(1)Front stage circuits issue legal icmp packet treatment strategy to strategy analyzing module;
(2)The legal icmp packet source IP address that to parse, legal purpose IP address, the icmp packet of 11 full zero setting
TYPE types carry out Hash operation, and result is carried out into clash handle;
(3)Legal icmp packet TYPE types, legal icmp packet direction, the icmp packet treatment that step 2 is parsed
Mode is stored in the policy store module's address constituted with Hash result and clash handle result;
(4)Icmp packet is reached, and is parsed through packet parsing module;
(5)The source IP address that parses, purpose IP address, the icmp packet TYPE types of 11 full zero setting are through Hash operation and punching
Prominent treatment obtains the policy store module's address that need to be inquired about;
(6)The TYPE types of the icmp packet of arrival are carried out into step-by-step and computing with the TYPE types for reading, if result is not 0,
Then show to have matched legal policy, and then carry out subsequent packet treatment;Otherwise show not matching legal policy, to message not
Deal with or carry out default process.
The beneficial effects of the invention are as follows
Hash treatment is carried out by using segment message parameter, segment message parameter is stored, and it is right that icmp packet is only needed when matching
TYPE types compare.On the premise of the accuracy of strategy matching is ensured, message protocol policy store cost is reduced, improve
Message matching efficiency, is that other protocol strategy storages leave domain amount.
Brief description of the drawings
Fig. 1 is electrical block diagram of the invention.
Specific embodiment
More detailed elaboration is carried out to present disclosure below:
As shown in figure 1, a kind of icmp packet match circuit of the invention, including:Strategy analyzing module, packet parsing module, Kazakhstan
Uncommon computing module, clash handle module, policy store module and comparison match module.
The strategy analyzing module, strategy is processed for receiving and parsing through the icmp packet that front stage circuits are issued, and will be parsed
Policy data afterwards is sent to the Hash operation module and the policy store module.The packet parsing module, for connecing
The icmp packet for carrying out automatic network is received and parsed, the message data after parsing is sent to the Hash operation module and the comparing
Matching module.
The Hash operation module, policy data or message data for receiving input, by certain hash function
Hash result is mapped out, according to preferred for this invention, Hash operation is carried out from CRC32 algorithms.Accessed through output end described
The 11 bit address input high of clash handle module and policy store module.
The clash handle module, for recording or inquiring about number of times that identical Hash output result occurs and corresponding described
Low four bit address of policy store module.The policy store module, for policy data storage to be arrived by Hash operation mould
Block is exported and clash handle module is exported in the public address specified.
The comparison match module, for message data and policy data to be carried out into matching comparing, and result is exported.If
The message of arrival policy store module's address after Hash operation and clash handle is effective, then the icmp packet that will be parsed
TYPE types carry out step-by-step with operation with the TYPE types of the corresponding positions read out from policy store module.If wrapped in strategy
Containing corresponding TYPE types, then corresponding positions can put one, and the two step-by-step has certain position one with operating result, then show to match
Legal strategy.
Policy data after the parsing includes legal icmp packet source IP address, legal purpose IP address, legal
Icmp packet TYPE types, legal icmp packet direction, icmp packet processing mode etc.;Message data bag after the parsing
Include icmp packet source IP address, icmp packet purpose IP address, icmp packet TYPE types etc..
The legal icmp packet TYPE types are represented that each position one represents strategy by the bit data form of 11
It is interior comprising corresponding TYPE types;Icmp packet TYPE types after the parsing represent by the bit data form of 11, certain
One position one represents that the message is corresponding TYPE types.
(1)Front stage circuits issue legal icmp packet treatment strategy to strategy analyzing module;
(2)The legal icmp packet source IP address that to parse, legal purpose IP address, the icmp packet of 11 full zero setting
TYPE types carry out Hash operation, and result is carried out into clash handle;
(3)Legal icmp packet TYPE types, legal icmp packet direction, the icmp packet treatment that step 2 is parsed
Mode etc. is stored in the policy store module's address constituted with Hash result and clash handle result;
(4)Icmp packet is reached, and is parsed through packet parsing module;
(5)The source IP address that parses, purpose IP address, the icmp packet TYPE types of 11 full zero setting are through Hash operation and punching
Prominent treatment obtains the policy store module's address that need to be inquired about;
(6)The TYPE types of the icmp packet of arrival are carried out into step-by-step and computing with the TYPE types for reading, if result is not 0,
Then show to have matched legal policy, and then carry out subsequent packet treatment;Otherwise show not matching legal policy, to message not
Deal with or carry out default process.