WO2010127525A1 - 深度报文检测设备联动策略生成系统及方法 - Google Patents

深度报文检测设备联动策略生成系统及方法 Download PDF

Info

Publication number
WO2010127525A1
WO2010127525A1 PCT/CN2009/073660 CN2009073660W WO2010127525A1 WO 2010127525 A1 WO2010127525 A1 WO 2010127525A1 CN 2009073660 W CN2009073660 W CN 2009073660W WO 2010127525 A1 WO2010127525 A1 WO 2010127525A1
Authority
WO
WIPO (PCT)
Prior art keywords
policy
information
dpi
module
linkage
Prior art date
Application number
PCT/CN2009/073660
Other languages
English (en)
French (fr)
Inventor
宋晓丽
杨波
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2010127525A1 publication Critical patent/WO2010127525A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/14Network analysis or design
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control

Definitions

  • the present invention relates to a deep packet detection technology, and in particular, to a deep packet detection device linkage policy generation system and method.
  • BACKGROUND With the rapid growth of Internet services, the realization of controllable and controllable services based on various services is a problem that is of great concern in all aspects of the industry chain. However, the primary condition for implementing the control of various services based on various services is to identify corresponding ones. Applications, using Deep Packet Inspection (DPI) technology, are undoubtedly the best choice for business identification. DPI technology is an application layer-based traffic detection and control technology. It is compared with the analysis level of common packets.
  • DPI Deep Packet Inspection
  • DPI Downlink Packet Data Protocol
  • TCP Transmission Control Protocol
  • UDP User Datagram Protocol
  • DPI technology works in the transport layer to application layer of the Open System Interconnect (OSI) model. It has high data stream processing capability, can identify and manage traffic carried by the network, and can be deployed on the network. Backbone network, city i or network and enterprise network. However, due to the decentralized deployment of DPI devices and the independence of management, it is highly probable that DPI devices will handle unbalanced traffic. In addition, failure of a DPI device may cause local service processing to fail. In the related art, a scheme for centrally managing each DPI device and corresponding information distributed in the network has not been proposed.
  • OSI Open System Interconnect
  • the main object of the present invention is to provide a deep message detection device linkage strategy generation system and method, so as to implement centralized management and analysis of distributed DPI devices and information.
  • a deep message detecting device linkage policy generating system includes: a deep packet detecting DPI executing mechanism, a DPI linkage information control center, and a policy decision module;
  • the DPI executing agency is used to identify and control the service traffic, and is also used to provide information of each DPI device to the DPI linkage information control center; the DPI linkage information control center is configured to collect information of each DPI device, and collect the collected information.
  • the information classification is provided to the policy decision module; the policy decision module is configured to collect the information of the DPI device from the DPI linkage information control center, and generate an executable application policy according to the collected information, and then send the generated application policy to the DPI executive agency.
  • the policy decision module includes a DPI device linkage policy management sub-module and a policy generation sub-module; wherein the DPI device linkage policy management sub-module is configured to receive an application policy reported by the policy generation sub-module, according to the reported Applying an application to generate an executable application policy and delivering a DPI execution mechanism; the policy generation sub-module is configured to receive various DPI device information reported by the DPI linkage information control center, and generate various policies according to the received DPI device information, The generated policy is provided to the DPI device linkage policy management sub-module.
  • the information of the DPI device includes, but is not limited to, routing information of the DPI device, status information of the DPI device, identification result information of the DPI device, traffic information of the DPI device, and association information of the DPI device;
  • the module includes any one or more of an association identification control policy decision sub-module, a traffic sharing linkage policy decision sub-module, and a fault processing linkage policy decision sub-module.
  • the policy generation sub-module includes an association identification control policy decision sub-module, a traffic sharing linkage policy decision sub-module, and a fault processing linkage policy decision sub-module;
  • the association identification control policy decision sub-module is used for linkage from DPI Information Control Center acquires associations of DPI devices Information, according to the obtained associated information, the corresponding control decision is made, and the control strategy generated by itself is connected to the DPI device linkage policy management sub-module;
  • the traffic sharing linkage strategy decision sub-module is used to obtain from the DPI linkage information control center.
  • the traffic information of the DPI device is used to perform the traffic sharing policy decision based on the obtained traffic information, and the traffic sharing policy generated by the DPI device is reported to the DPI device linkage policy management sub-module; the fault processing linkage policy decision sub-module is used for the DPI linkage information.
  • the control center obtains the status information of the DPI device, and then performs the fault handling policy decision according to the obtained state information, and reports the fault processing policy generated by itself to the DPI device linkage policy management sub-module.
  • the system further includes a centralized policy management module for coordinating and managing one or more of the linkage policy generation systems, generating and delivering a corresponding management policy to a policy decision module within its jurisdiction; correspondingly, the DPI device linkage policy management sub-module further The method is configured to receive a policy delivered by the centralized policy management module, and then generate an executable application policy according to the received policy analysis.
  • the system further includes an external management and decision system for generating a policy for managing the DPI device, and providing the generated policy to the policy decision module; correspondingly, the DPI device linkage policy management sub-module is further configured to receive the external management And the decision-making system editing and import/export strategy; then, combined with the received various policy information analysis to generate an executable application strategy.
  • a method for generating a linkage message detection device linkage policy includes: acquiring information of each DPI device, determining different application policies according to the acquired information, and then determining the determined one.
  • the above application strategy generates an executable application policy and delivers it.
  • the information about obtaining the DPI devices is: the information of each DPI device is classified and reported to each policy decision sub-module in the policy decision module; correspondingly, the different application policies are determined according to the acquired information.
  • each policy decision sub-module generates its own application policy according to the received information, and associates the generated application policy with the DPI device in the policy decision module, and associates the policy management sub-module;
  • the DPI device linkage policy management sub-module generates the executed application policy according to the application strategy of the previous application and delivers the DPI execution organization.
  • a method for generating a deep message detecting device linkage policy includes: acquiring information of each DPI device, determining different application policies according to the acquired information, and then determining more than one determined according to the obtained information.
  • the application policy is combined with the policy information provided by the centralized policy management module and/or the external management and decision system to generate an executable application policy and deliver the policy.
  • the information about obtaining the DPI devices is: the information of each DPI device is classified and reported to each policy decision sub-module in the policy decision module; correspondingly, the different application policies are determined according to the acquired information.
  • each policy decision sub-module generates its own application policy according to the received information, and associates the generated application policy with the DPI device in the policy decision module, and associates the policy management sub-module;
  • the DPI device linkage policy management sub-module analyzes the generated application policy and delivers the DPI execution according to the reported application policy, the policy information delivered by the centralized policy management module, and/or the policy generated by the external management and decision system. mechanism.
  • the system and method for generating a linkage strategy for a depth 4 ⁇ detection device obtains various types of information of each DPI device, and initially determines different application strategies according to the obtained various types of information, and then determines a plurality of applications that are initially determined.
  • the strategy is comprehensively analyzed to generate the final executable application strategy and deliver it.
  • the entire system can adjust the application policy according to the state change of all the DPI devices, such as: traffic sharing, fault processing, etc., and formulate a linkage policy according to the information of each DPI device, so as to implement the DPI devices distributed in the network.
  • the purpose of centralized management is used to adjust the application policy according to the state change of all the DPI devices, such as: traffic sharing, fault processing, etc.
  • the invention adopts a two-level application strategy determination mechanism when formulating an application strategy, and firstly, each module that specifically processes a certain type of information generates its own application strategy, and then the policy decision module comprehensively analyzes all the received application strategies to generate a final Executable application strategy.
  • the invention can effectively realize the traffic optimization of the DPI device deployed in the network, and the transfer of the traffic under the fault condition, thereby realizing the coordinated and reliable cooperation between the DPI devices.
  • the policy decision module of the present invention may also combine the application policy of each policy decision sub-module with the application policy delivered by the centralized policy management module, And/or external management and decision-making system to comprehensively analyze and judge the application strategy provided by it, and generate a more applicable executable application strategy, so that the traffic management of each DPI device in the network can be better optimized, which can better Coordinate work between DPI devices.
  • FIG. 1 is a schematic structural diagram of a DPI linkage policy generation system according to an embodiment of the present invention
  • FIG. 2 is a detailed structural diagram of a DPI linkage policy generation system according to an embodiment of the present invention; Schematic diagram of the implementation process of the DPI linkage strategy generation method.
  • the basic idea of the deep packet detection device linkage strategy generation scheme provided by the embodiment of the present invention is: acquiring various types of information of each DPI device, and initially determining different application strategies according to the obtained various types of information, and then The final executable application policy is generated and delivered according to a plurality of initially determined application policies. Further, the solution may also take a preliminary determination of multiple application strategies, and combine the application policies issued by the centralized policy management module and/or the application policies provided by the external management and decision system to analyze and judge, and generate more Applicable executable application strategy.
  • the deep packet detection device linkage policy generation system mainly includes: DPI execution mechanism 11, DPI linkage information control Center 12 and policy decision module 13; wherein
  • the DPI executor 11 is a DPI linkage device group, which is used to specifically identify and control service traffic, and is also used to provide information about each DPI device to the DPI linkage information control center 12;
  • the application strategy performs control operations on the DPI device.
  • the information may include routing information of the DPI device, status information of the DPI device, identification result information of the DPI device, traffic information of the DPI device, association information of the DPI device, and the like.
  • the performing the control operation on the DPI device may be The transfer of data traffic, for example: transferring data transmitted by the faulty device to one or more devices that are working normally and having a small load; transferring a portion of the data on the device with a large load to one or more devices having a small load transmission.
  • the DPI linkage information control center 12 is configured to manage device registration, device information collection and maintenance in the DPI device group, and provide the collected DPI device information to the policy generation sub-module in the policy decision module.
  • the DPI linkage policy decision making and the most critical module are the policy decision module 13
  • the policy decision module 13 is configured to collect various types of information of the DPI device from the DPI linkage information control center 12 , and The executable application policy is generated according to the collected information, and the generated application policy is sent to the DPI executing organization 11.
  • the policy decision module 13 can be integrated into the network management device as a function module, or can be used as a separate network device, for example, as a policy decision server.
  • the policy decision module 13 is composed of a DPI device linkage policy management submodule 131 and a policy generation submodule 130.
  • the DPI device linkage policy management sub-module 131 is a center for the final decision and release of the executable application policy, and the sub-module is specifically configured to complete the following functions:
  • the receiving from the policy generation sub-module 130 generates the DPI device information according to the collected types.
  • the comprehensive analysis may be to determine and compare different received application policies, and determine an optimal application policy as a final executable according to the degree of association, overlap, and conflict between the application policies.
  • Application strategy may be to determine and compare different received application policies, and determine an optimal application policy as a final executable according to the degree of association, overlap, and conflict between the application policies.
  • the sub-module can also be used to prioritize the application policy, and select the application policy with high priority as the final executable application policy. Accordingly, the application policy issued by the DPI executing organization 11 is finally generated and prioritized. Adjusted application strategy.
  • the policy generation sub-module 130 is configured to receive various types reported by the DPI linkage information control center 12
  • the DPI device information generates various policies according to the received DPI device information, and provides the generated policy to the DPI device linkage policy management sub-module 131.
  • the policy generation sub-module 130 may include an association identification control policy decision sub-module 132, Any one or more of the traffic sharing linkage policy decision sub-module 133 and the fault handling linkage policy decision sub-module 134. That is, the policy generation sub-module 130 may be any one of the three sub-modules: the association identification control policy decision sub-module 132, the traffic-sharing linkage policy decision sub-module 133, the fault-processing linkage policy decision sub-module 134, or any two sub-modules A combination of modules, or a combination of three submodules.
  • the DPI linkage information control center 12 provides the collected information classification to the corresponding policy decision sub-module in the policy decision module.
  • the classification refers to distinguishing all the received information according to different categories, for example: identification result information of the DPI device, routing information of the DPI device, status information of the DPI device, traffic information of the DPI device, and DPI device Associated information and so on, then different types of information can be used to different policy decision sub-modules.
  • a certain type of information can be given only to a corresponding policy decision sub-module, for example: 4) the status information is used, and the fault processing strategy decision sub-module is also used;
  • the relevance of the policy module is to report certain types of information to the same policy decision sub-module, for example: report routing information and status information to the fault handling policy decision sub-module;
  • Correlation report a certain type of information to multiple policy decision sub-modules, for example: report routing information to the traffic sharing linkage policy decision sub-module, and fault handling policy decision sub-module.
  • the DPI device linkage policy management sub-module 131 receives various generation policies from the association identification control policy decision sub-module 132, the traffic sharing linkage policy decision sub-module 133, and the fault-processing linkage policy decision sub-module 134.
  • the association and identification control policy decision sub-module 132 is configured to obtain, from the DPI linkage information control center 12, association information obtained by different DPI devices for service identification needs, and perform corresponding control decisions according to the acquired association information, and The generated control policy is reported to the DPI device linkage policy management sub-module 131, and the DPI device linkage policy management sub-module 131 finally applies the policy decision.
  • the traffic sharing collaboration policy decision sub-module 133 is configured to obtain the traffic information of the DPI device from the DPI collaboration information control center 12, and then perform the traffic sharing policy decision according to the obtained traffic information, and report the traffic sharing policy generated by the DPI device to the DPI device.
  • the policy management sub-module 131 is linked by the DPI device to the policy management sub-module 13 so that the policy decision is finally applied.
  • the principle of the traffic sharing policy decision is to optimize the traffic balance between the application layers at each application layer.
  • the fault processing linkage policy decision sub-module 134 is configured to obtain status information of the DPI device from the DPI linkage information control center 12, and then perform fault processing policy decision according to the acquired state information, and generate a fault processing strategy by itself.
  • the device linkage policy management sub-module 131 is linked to the policy management sub-module 131 by the DPI device, so that the policy decision is finally applied.
  • the purpose of this sub-module is to avoid equipment risks and timely handle service interruptions and related problems caused by equipment failures.
  • the sub-module can also receive DPI device information such as routing information, and generate its own fault handling strategy in combination with various types of information received when making policy decisions.
  • the status information it can be determined which DPI device is faulty, and the traffic load condition of each DPI device can be known according to the routing information, then according to the load situation, it can be determined which to transfer the data stream transmitted on the faulty DPI device, or which The DPI device is more suitable, which can ensure the normal transmission of the data stream and optimize the traffic balance.
  • the linkage policy generation system is composed of the dynamic information control center 12 and the policy decision module 13. Then, in order to coordinate and manage a plurality of such linkage strategy generation systems, the centralized policy management module 15 and the connection policy decision module 13 may be further included in FIG.
  • the system shown in FIG. 1 may further include an external management and decision system 14 for an external decision management system for generating a policy for managing the DPI device, and providing the generated policy to the policy decision module 13 .
  • the DPI device linkage policy management sub-module 131 is further configured to receive various policies delivered by the centralized policy management module 15, and / or used to process the policies from the external management and decision system 14 editing and import / export; then combined with the various strategies received to conduct a comprehensive analysis to generate the final executable application strategy.
  • various policy information for comprehensive analysis includes policies from the policy decision module 13 , policies from the centralized policy management module 15 , and/or policies from the external management and decision system 14 .
  • the comprehensive analysis of the various policies received by the combination may be: the policy decision module 13 formulates a corresponding policy according to the information acquired by the DPI linkage information control center 12; and the policy decision module 13 receives the centralized policy management module 15 The corresponding policy is given; after that, the policy decision module 13 compares and analyzes the policy formulated by itself and the received policy to determine the final executable application strategy.
  • the policy decision module 13 formulates the following strategies: A certain application traffic of a DPI device, such as VOIP traffic, should be controlled at 10 Mbps; and the centralized policy management module 15 formulates a policy to limit the VOIP traffic of all DPI devices under it. At 5 Mbps, the policy priority of the centralized policy management module 15 is high, because the policy formulated by the centralized policy management module may involve multiple global linkage strategy generation systems; The priority of the centralized management module 15 is 5 Mbps applied to the corresponding DPI device. In the embodiment of the present invention, the policy decision is mainly for the linkage strategy.
  • the identification and control strategy for the service may be performed according to the information provided by the external management and decision system 14, or may be formulated by the external management and decision system 14
  • the corresponding identification and control strategy selects the policy of the policy decision module 13 or the policy of the external management and decision system 14 according to the priority.
  • 2 is a schematic structural diagram of a DPI linkage policy generation system according to an embodiment of the present invention.
  • the policy generation sub-module 130 includes an association identification control policy decision sub-module 132, a traffic sharing linkage policy decision sub-module 133, and a fault processing.
  • Linkage policy decision sub-module 134 three Submodule.
  • different types of information are represented by different filling methods.
  • the DPI linkage information control center 12 to the association identification control strategy decision there are three types of information, which are respectively represented by black filling, oblique filling, and blank filling; correspondingly, the DPI linkage information control center 12 to the association identification control strategy decision
  • the solid line of the module 132 indicates that the black filled data stream is transmitted;
  • the dotted line of the DPI linkage information control center 12 to the flow sharing linkage policy decision sub-module 133 indicates the data stream filled with the oblique line filling;
  • the dotted line of decision sub-module 134 represents the transmission of a blank filled data stream. As shown in FIG.
  • the DPI linkage information control center 12 obtains the information of the DPI device from the DPI executing unit 11, and classifies the acquired information into the corresponding policy decision sub-module in the policy decision module 13 respectively: Association identification control policy decision The module 132, the traffic sharing linkage policy decision sub-module 133, the fault processing linkage policy decision sub-module 134, each policy decision sub-module generates its own application policy according to the received corresponding information, and the application strategy generated by itself 1
  • the DPI device linkage policy management sub-module 131, the DPI device linkage policy management module 131 comprehensively analyzes the policy decision information received from each policy decision sub-module, and finally determines that an executable application policy is generated and sent to the DPI execution organization 11, After receiving the applicable application policy, the DPI executing mechanism 11 performs control operations on the DPI device according to the delivered application policy, such as transferring data traffic, sharing data traffic, and the like.
  • the comprehensive analysis means that the DPI device linkage policy management module 131 combines the policy information from each policy sub-module to analyze and obtain an executable application policy. For example, the DPI device linkage policy management module 131 receives the policy from the traffic sharing linkage policy decision sub-module 133 and the fault processing linkage policy decision sub-module 134, wherein the policy of the traffic sharing linkage policy decision sub-module 133 gives the current normal operation. The network topology of each node device, the policy of the fault processing linkage policy decision sub-module 134 gives the current faulty node device and indicates that the bypass path needs to be taken. Then, the DPI device linkage policy management module 131 receives the two policies.
  • the comprehensive analysis combines the strategic information from various aspects to arrive at the final application strategy; or, from several similar strategies, select the higher priority, or better, or the most suitable strategy for the current operating environment.
  • the final executable application strategy The following examples are combined with specific applications.
  • DPI 1 There are four DPI devices in the network: DPI 1, DPI2, DPI3, and DPI4. Among them, four DPI devices support P2P ten, and DPI 1 and DPI2 and DPB are connected, DPI2 and DPB are connected to DPI4, and data stream transmitted from DPI1 to DPI4 is transmitted via DPI2.
  • the DPI linkage information control center 12 acquires the information of the DPI device from the DPI executing unit 11: DPI1 ⁇ DPI4 support P2P ten-party negotiation; DPI1 is connected with DPI2, DPB, DPI2, DPB is connected with DPI4, and DPI1 transmits data to DPI4 through DPI2; DPI4 fails.
  • the DPI linkage information control center 12 classifies the information into three categories: DPI 1 ⁇ DPI4 both support the P2P protocol belonging to the recognition result information; DPI 1, DPI2, DPB, DPI4 connection relationship, and DPI1 to DPI4
  • the path taken by the transmission data belongs to the routing information; the failure of DPI4 belongs to the status information.
  • the DPI linkage information control center 12 reports the identification result information to the association identification control policy decision sub-module 132; the routing information is reported to the traffic distribution linkage policy decision sub-module 133 and the fault processing linkage policy decision sub-module 134; The fault handling linkage policy decision sub-module 134.
  • the association identification control policy decision sub-module 132, the traffic sharing linkage policy decision sub-module 133, and the fault-processing linkage policy decision sub-module 134 each generate an application policy according to the received information; wherein the fault-processing linkage policy decision sub-module 134 receives After the routing information and the status information, the policy decision is generated according to the status information and the routing information: The data transmitted by DPI1 to DPI4 via DPI2 is transferred to the DPI4 via the DPB. Finally, the fault handling linkage policy decision sub-module 134 determines the policy decision generated by itself.
  • the DPI device linkage policy management module 131 and the DPI device linkage policy management module 131 perform comprehensive analysis.
  • the DPI1 transmits data to the DPI4 via the DPB as the final executable application policy, and delivers the jt ⁇ application policy to the DPI execution organization.
  • the DPI executing agency 11 controls the DPI 1 ⁇ DPI4 according to the received application policy, and transmits the data of the DPI 1 sent by the DPI 1 via the DPB.
  • the method embodiment is based on the foregoing system, and the embodiment of the present invention further provides a method for generating a linkage policy of a deep packet detection device. The specific processing procedure of the method is as shown in FIG.
  • Step 301 The DPI linkage information control center obtains the information of each DPI device from the DPI executing organization, and reports the policy generation sub-module of the policy decision module.
  • the policy generation sub-module includes multiple policy decision sub-modules, for example: including association identification
  • the control policy decision sub-module, the traffic sharing linkage policy decision sub-module, and the fault-processing linkage policy decision sub-module classifies the DPI device information, and reports each policy decision sub-module in the policy generation sub-module.
  • the information of the DPI device may be routing information of the DPI device, and/or status information of the DPI device, and/or identification result information of the DPI device, and/or traffic information of the DPI device, and/or DPI device.
  • the policy generation sub-module is Each of the policy decision sub-modules is configured to generate a self-application policy according to the received information, and report the DPI device linkage policy management sub-module.
  • Step 303 The DPI device linkage policy management sub-module comprehensively analyzes the received various application policies, and finally forms an executable application policy, which is sent to the DPI executing organization.
  • the DPI device linkage policy management sub-module is also connected to the centralized policy The management module, and/or the external management and decision-making system; then, the final executable application strategy is: one or more application policies determined according to the determination, combined with the policy information delivered by the centralized policy management module, and/or The policy information provided by the external management and decision making system generates the final executable application strategy.
  • Step 304 The DPI executing unit performs corresponding control operations on each DPI device according to the finally executable application policy delivered by the policy decision module.
  • Step 304 is optional for the DPI device linkage policy generation method. It can be seen from the above process that the method provided by the embodiment of the present invention can effectively integrate the DPI device information and service status deployed in the network, and formulate corresponding policy decisions, thereby effectively realizing the DPI device to identify the service traffic. Optimize equalization and transfer of data traffic in the event of a single DPI device failure.
  • a computer readable medium having stored thereon computer executable instructions for causing a computer or processor to perform, for example, when executed by a computer or processor
  • the processing from step 301 to step 304 shown in FIG. 3, may Perform one or more of the above-described embodiments.
  • the implementation of the present invention does not modify the system architecture and the current processing flow, is easy to implement, facilitates promotion in the technical field, and has strong industrial applicability.
  • the above description is only for the preferred embodiment of the present invention, and is not intended to limit the scope of the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included. Within the scope of protection of the present invention.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Description

深度 4艮文检测设备联动策略生成系统及方法 技术领域 本发明涉及深度报文检测技术,尤其是涉及一种深度报文检测设备联动 策略生成系统及方法。 背景技术 随着互联网业务的急剧增长,实现基于各种业务的可管可控是产业链各 环节都比较关心的问题, 但是, 要实现基于各种业务的疏导管控的首要条件 就是识别相应的各种应用 , 使用深度艮文检测 ( Deep Packet Inspection, 筒称 为 DPI ) 技术无疑是作为业务识别功能的最佳选择。 DPI技术是一种基于应用层的流量检测和控制技术,是与普通报文的分 析层次相比较而言的, 一般情况下 , 普通报文检测仅分析 IP数据包层以下的 内容, 包括: 源地址、 目的地址、 源端口、 目的端口以及协议类型; 而 DPI 除了对前面的层次进行分析外, 还增加了对应用层的分析, 可识别各种应用 甚至其内容。 实现 DPI技术的设备称为 DPI设备, 是具备业务数据流识别、 业务数 据流控制能力的设备。 当 IP数据包、 传输控制协议( TCP )或用户数据包协 议(UDP ) 的数据流通过 DPI设备时, 该设备通过深入读取 IP数据包载荷 的内容来分析 TCP/IP 十办议中的应用层信息, 从而识别出真正的应用类型和 特征。 因此, 利用 DPI技术在 IP网络中部署 DPI系统, 可实现网络运营中 的业务识别、 业务控制和业务统计等功能。 DPI 技术工作在开放系统互连 ( Open System Interconnect, 筒称为 OSI )模型的传输层到应用层, 具有高 数据流处理能力, 能够对网络所承载的业务进行识别和流量管理, 可部署在 网络骨干网、 城 i或网和企业网内部。 但是, 由于当前 DPI 设备部署的分散性以及管理的独立性, 极有可能 出现 DPI设备处理业务流量不均衡的现象; 另夕卜, 某台 DPI设备发生故障也 会导致局部业务处理失败。 在相关技术中, 尚未提出对分散部署于网络中各 DPI设备及相应信息进行集中管理的方案。 发明内容 有鉴于此,本发明的主要目的在于提供一种深度报文检测设备联动策略 生成系统及方法, 以实现对分散的 DPI设备及信息进行集中管理与分析。 为达到上述目的, 根据本发明的一个方面, 提供了一种深度报文检测设 备联动策略生成系统。 根据本发明的深度报文检测设备联动策略生成系统包括:深度报文检测 DPI执行机构、 DPI联动信息控制中心以及策略决策模块; 其中,
DPI执行机构 , 用于对业务流量进行识别与控制 , 还用于向 DPI联动信 息控制中心提供各 DPI设备的信息; DPI联动信息控制中心, 用于收集各 DPI设备的信息, 并将收集到的信 息分类提供给策略决策模块; 策略决策模块, 用于从 DPI联动信息控制中心收集 DPI设备的信息, 并才艮据收集的信息生成可执行的应用策略 , 再将所生成的应用策略下发给 DPI执行机构。 上述方案中, 所述策略决策模块包括 DPI设备联动策略管理子模块、 策略生成子模块; 其中, 所述 DPI设备联动策略管理子模块, 用于接收策略 生成子模块上报的应用策略, 根据上报的应用策略生成可执行的应用策略并 下发 DPI执行机构; 所述策略生成子模块, 用于接收 DPI联动信息控制中心 上报的各种 DPI设备信息, 根据收到的 DPI设备信息生成各种策略, 并将生 成的策略提供给 DPI设备联动策略管理子模块。 上述方案中 , 所述 DPI设备的信息包括但不限于 DPI设备的路由信息、 DPI设备的状态信息、 DPI设备的识别结果信息、 DPI设备的流量信息、 DPI 设备的关联信息; 所述策略生成子模块包括关联识别控制策略决策子模块、流量分担联动 策略决策子模块、 故障处理联动策略决策子模块中的任意一个或多个。 上述方案中, 所述策略生成子模块包括关联识别控制策略决策子模块、 流量分担联动策略决策子模块和故障处理联动策略决策子模块; 所述关联识 别控制策略决策子模块, 用于从 DPI联动信息控制中心获取 DPI设备的关联 信息, 根据获取的关联信息进行相应控制决策, 并将自身生成的控制策略上 •t艮 DPI设备联动策略管理子模块; 所述流量分担联动策略决策子模块, 用于 从 DPI联动信息控制中心获取 DPI设备的流量信息,根据获取的流量信息进 行流量分担策略决策, 并将自身产生的流量分担策略上报 DPI设备联动策略 管理子模块; 所述故障处理联动策略决策子模块, 用于从 DPI联动信息控制 中心获取 DPI设备的状态信息,才艮据获取的状态信息进行故障处理策略决策, 并将自身产生的故障处理策略上报 DPI设备联动策略管理子模块。 该系统进一步包括集中策略管理模块,用于协调管理一个以上所述联动 策略生成系统, 生成并下发相应管理策略给其管辖范围内的策略决策模块; 相应的, DPI设备联动策略管理子模块还用于接收集中策略管理模块下发的 策略; 之后结合所收到的策略分析生成可执行的应用策略。 该系统进一步包括外部管理及决策系统, 用于生成对 DPI 设备进行管 理的策略, 并将所生成的策略提供给策略决策模块; 相应的, DPI设备联动 策略管理子模块还用于接收来自外部管理及决策系统编辑和导入 /导出的策 略; 之后结合所收到的各种策略信息分析生成可执行的应用策略。 根据本发明的另一个方面,提供了一种深度报文检测设备联动策略生成 方法, 包括: 获取各 DPI设备的信息, 根据所获取的信息确定不同的应用策略, 之 后再才艮据确定的一个以上应用策略生成可执行的应用策略并下发。 上述方案中, 所述获取各 DPI设备的信息为: 将获取的各 DPI设备的 信息分类上报策略决策模块中的各策略决策子模块; 相应的, 所述根据所获 取的信息确定不同的应用策略为: 各策略决策子模块根据收到的信息生成自 身的应用策略, 并将生成的应用策略上 4艮策略决策模块中的 DPI设备联动策 略管理子模块; 所述生成可执行的应用策略并下发为: DPI设备联动策略管 理子模块才艮据上 4艮的应用策略生成执行的应用策略并下发 DPI执行机构。 根据本发明的另一个方面,提供了一种深度报文检测设备联动策略生成 方法, 包括: 获取各 DPI设备的信息, 根据所获取的信息确定不同的应用策略, 之 后才艮据确定的一个以上应用策略, 并结合集中策略管理模块、 和 /或外部管理 及决策系统提供的策略信息生成可执行的应用策略并下发。 上述方案中, 所述获取各 DPI设备的信息为: 将获取的各 DPI设备的 信息分类上报策略决策模块中的各策略决策子模块; 相应的, 所述根据所获 取的信息确定不同的应用策略为: 各策略决策子模块根据收到的信息生成自 身的应用策略, 并将生成的应用策略上 4艮策略决策模块中的 DPI设备联动策 略管理子模块; 所述生成可执行的应用策略并下发为: DPI设备联动策略管 理子模块根据上报的应用策略、集中策略管理模块下发的策略信息和 /或外部 管理及决策系统生成的策略, 分析生成可执行的应用策略, 并下发 DPI执行 机构。 本发明所提供的深度 4艮文检测设备联动策略生成系统及方法,通过获取 各个 DPI设备的各类信息 ,根据所获取的各类信息初步确定不同的应用策略 , 之后将初步确定的多个应用策略进行综合分析, 生成最终可执行的应用策略 并下发。 如此, 整个系统可以根据所有 DPI设备的状态变化, 及时调整应用 策略, 比如: 流量分担、 故障处理等等, 依据各 DPI设备的信息制定联动策 略, 达到对分散部署于网络中的各 DPI设备进行集中管理的目的。 本发明在制定应用策略时采用两级应用策略确定机制,先由专门针对某 类信息进行处理的模块各自生成自身的应用策略, 再由策略决策模块对收到 的所有应用策略综合分析, 生成最终可执行的应用策略。 通过本发明可以有 效实现对部署于网络中的 DPI设备进行流量优化、 以及故障情况下流量的转 移等等, 进而实现各 DPI设备之间协调、 可靠的配合工作。 进一步的, 本发明的策略决策模块、 具体为策略决策模块中的 DPI设 备联动策略管理子模块还可以将各个策略决策子模块上 4艮的应用策略, 结合 集中策略管理模块下发的应用策略、和 /或外部管理及决策系统为其提供的应 用策略进行综合分析判断, 生成更适用的可执行应用策略, 如此, 能够更好 地对网络中各 DPI设备的流量管理进行优化 , 能更好地协调各 DPI设备之间 的工作。 附图说明 图 1为根据本发明实施例的 DPI联动策略生成系统的组成结构示意图; 图 2为根据本发明实施例的 DPI联动策略生成系统的详细结构示意图; 图 3为根据本发明实施例的 DPI联动策略生成方法的实现流程示意图。 具体实施方式 功能相克述 本发明实施例提供的深度报文检测设备联动策略生成方案的基本思想 是: 获取各个 DPI设备的各类信息, 根据所获取的各类信息初步确定不同的 应用策略, 之后才艮据初步确定的多个应用策略生成最终可执行的应用策略并 下发。 进一步的, 该方案还可以 ^夺初步确定的多个应用策略, 与集中策略管理 模块下发的应用策略、和 /或外部管理及决策系统为其提供的应用策略结合起 来进行分析判断, 生成更适用的可执行应用策略。 系统实施例 图 1是根据本发明实施例的 DPI联动策略生成系统的组成结构示意图 , 如图 1所示, 该深度报文检测设备联动策略生成系统主要包括: DPI执行机 构 11、 DPI联动信息控制中心 12以及策略决策模块 13; 其中,
DPI执行机构 11是一个 DPI联动设备组, 用于具体实现对业务流量的 识别与控制 ,还用于向 DPI联动信息控制中心 12提供各个 DPI设备的信息; 并可才艮据策略决策模块下发的应用策略对 DPI设备执行控制操作。 其中 , 所述信息可以包括 DPI设备的路由信息、 DPI设备的状态信息、 DPI设备的识别结果信息、 DPI设备的流量信息、 DPI设备的关联信息等等; 所述对 DPI设备执行控制操作可以是数据流量的转移, 比如: 将故障设备传 输的数据转由正常工作且负荷量小的一个或多个设备传输; 将负荷量大的设 备上的一部分数据转由负荷量小的一个或多个设备传输。
DPI联动信息控制中心 12, 用于管理 DPI设备组中设备的注册、 设备 信息的收集与维护, 并将收集到的 DPI设备信息提供给策略决策模块中的策 略生成子模块。 在图 1 所示的系统中, 完成 DPI联动策略决策制定与下发最关键的模 块为策略决策模块 13 , 策略决策模块 13用于从 DPI联动信息控制中心 12 收集 DPI设备的各类信息, 并根据收集的信息生成可执行的应用策略, 再将 所生成的应用策略下发给 DPI执行机构 11。 在实际应用中 , 所述策略决策模块 13可以作为功能模块集成于网管设 备中, 也可以作为单独的网络设备, 比如: 单独作为策略决策服务器。 具体 的, 该策略决策模块 13由 DPI设备联动策略管理子模块 131、 以及策略生成 子模块 130组成。 其中, DPI设备联动策略管理子模块 131是可执行的应用 策略最终决定与发布的中心, 该子模块具体用于完成以下功能: 接收来自策 略生成子模块 130根据收集到的各类 DPI设备信息生成的各种策略, 再综合 分析接收到的各种策略, 产生可执行的应用策略; 对 DPI执行机构 11发布 识别模版以及最终产生的应用策略。 其中, 所述综合分析可以是对收到的不同应用策略进行判断、 比较, 根 据各个应用策略之间的关联度、 是否重叠、 是否有冲突等等条件, 确定最优 的应用策略为最终可执行的应用策略。 该子模块还可用于对应用策略进行优先级的调整,选择优先级高的应用 策略作为最终可执行的应用策略; 相应的, 对 DPI执行机构 11发布的应用 策略即为最终产生且经过优先级调整的应用策略。 策略生成子模块 130, 用于接收 DPI联动信息控制中心 12上报的各种
DPI设备信息, 根据收到的 DPI设备信息生成各种策略, 并将生成的策略提 供给 DPI设备联动策略管理子模块 131; 所述策略生成子模块 130可以包括关联识别控制策略决策子模块 132、 流量分担联动策略决策子模块 133、 故障处理联动策略决策子模块 134 中的 任意一个或多个。 也就是说, 策略生成子模块 130可以是关联识别控制策略 决策子模块 132、 流量分担联动策略决策子模块 133、 故障处理联动策略决 策子模块 134三者中任意一个子模块、 或是任意两个子模块的组合、 或是三 个子模块的组合。 相应的, DPI联动信息控制中心 12将收集到的信息分类提供给策略决 策模块中相应的策略决策子模块。 其中, 所述分类是指将收到的所有信息按 不同类别区分, 比如: 分为 DPI设备的识别结果信息、 DPI设备的路由信息、 DPI设备的状态信息、 DPI设备的流量信息、 DPI设备的关联信息等等, 那 么, 可将不同类别的信息上 4艮不同的策略决策子模块。 实际应用中, 可将某一类信息仅上 4艮给一个对应的策略决策子模块, 比 如: 将状态信息上 4艮故障处理策略决策子模块等; 也可以才艮据信息与策略决 策子模块的相关性, 将某几类信息上报同一个策略决策子模块, 比如: 将路 由信息、 状态信息都上报至故障处理策略决策子模块; 还可以才艮据信息与策 略决策子模块的相关性, 将某一类信息上报多个策略决策子模块, 比如: 将 路由信息上报流量分担联动策略决策子模块、 故障处理策略决策子模块。 这种情况下, DPI设备联动策略管理子模块 131接收来自关联识别控制 策略决策子模块 132、 流量分担联动策略决策子模块 133、 故障处理联动策 略决策子模块 134的各种生成策略。 具体的, 关联识别控制策略决策子模块 132, 用于从 DPI联动信息控制 中心 12获取在不同 DPI设备间因业务识别需要而得到的关联信息, 根据获 取的关联信息进行相应控制决策, 并将自身生成的控制策略上报 DPI设备联 动策略管理子模块 131 , 由 DPI设备联动策略管理子模块 131 ^故最终应用策 略决策。 比如: 同一业务数据通过不同 DPI设备传输时, 可通过对不同 DPI 设备信息的识别确定为同一业务数据, 进而制定相应的处理策略。 流量分担联动策略决策子模块 133 , 用于从 DPI联动信息控制中心 12 获取 DPI设备的流量信息, 才艮据获取的流量信息进行流量分担策略决策, 并 将自身产生的流量分担策略上报 DPI设备联动策略管理子模块 131 , 由 DPI 设备联动策略管理子模块 13 故最终应用策略决策。 这里, 进行流量分担策 略决策的原则是使各个 DPI设备之间在应用层的流量平衡优化。 故障处理联动策略决策子模块 134 , 用于从 DPI联动信息控制中心 12 获取 DPI设备的状态信息, 才艮据获取的状态信息进行故障处理策略决策, 并 将自身产生的故障处理策略上 4艮 DPI设备联动策略管理子模块 131 , 由 DPI 设备联动策略管理子模块 131 ^故最终应用策略决策。 本子模块的目的是规避设备风险,及时处理设备故障带来的业务中断及 相关问题。 实际应用中, 该子模块也可以接收路由信息等 DPI设备信息, 在 进行策略决策时结合所收到的各类信息生成自身的故障处理策略。 比如: 根 据状态信息可确定是哪个 DPI设备发生故障,根据路由信息可获知各 DPI设 备的流量负荷情况, 那么根据该负荷情况就可以确定将故障 DPI设备上传输 的数据流转移到哪个、或哪些 DPI设备比较合适,既能保证数据流正常传输, 又能达到流量均衡优化。 在实际应用中, 如果网络中同时存在多个由 DPI执行机构 11、 DPI联 动信息控制中心 12和策略决策模块 13组成的联动策略生成系统, 那么, 为 了协调管理多个这样的联动策略生成系统, 图 1中可进一步包括集中策略管 理模块 15 , 连接策略决策模块 13 , 用于协调管理一个以上所述联动策略生 成系统, 生成并下发相应的管理策略给其管辖范围内的策略决策模块 13。 在实际应用中, 图 1 所示的系统还可以包括外部管理及决策系统 14, 为外部决策管理系统, 用于生成对 DPI设备进行管理的策略, 并将所生成的 策略提供给策略决策模块 13。 对于增加集中策略管理模块 15、 和 /或外部管理及决策系统 14的情况, 相应的, DPI设备联动策略管理子模块 131 , 还用于接收来自集中策略管理 模块 15下发的各种策略,和 /或用于处理来自外部管理及决策系统 14编辑和 导入 /导出的策略; 之后结合所收到的各种策略进行综合分析, 生成最终可执 行的应用策略。 其中, 进行综合分析的各种策略信息包括来自策略决策模块 13的策略、 来自集中策略管理模块 15的策略和 /或来自外部管理及决策系统 14的策略。 其中, 所述结合所收到的各种策略进行综合分析具体可以是: 策略决策 模块 13根据 DPI联动信息控制中心 12所获取的信息制定相应策略; 同时策 略决策模块 13接收集中策略管理模块 15发给的相应策略; 之后, 策略决策 模块 13 会对自身制定的策略与接收到的策略进行比较分析, 确定最终可执 行的应用策略。 艮如, 策略决策模块 13制定的策略为: 对某台 DPI设备的 某种应用流量如 VOIP流量应控制在 10Mbps; 而集中策略管理模块 15所制 定的策略是限制其下所有 DPI设备的 VOIP流量在 5Mbps , 且集中策略管理 模块 15 的策略优先级高, 其原因是集中策略管理模块制定的策略可能会涉 及到全局多个联动策略生成系统; 则策略决策模块 13 综合分析后, 才艮据决 策的优先级将集中策略管理模块 15制定的 5Mbps应用于相应 DPI设备。 本发明实施例中, 策略决策主要针对联动策略而言, 因此, 对于业务的 识别及控制策略可以才艮据外部管理及决策系统 14 所提供的信息执行, 也可 以由外部管理及决策系统 14 制定相应的识别与控制的策略, 才艮据优先级选 用策略决策模块 13的策略或外部管理及决策系统 14的策略。 图 2为根据本发明实施例的 DPI联动策略生成系统的详细结构示意图, 本实施例中, 策略生成子模块 130 包括关联识别控制策略决策子模块 132、 流量分担联动策略决策子模块 133、 故障处理联动策略决策子模块 134三个 子模块。 图 2中用不同填充方式表示不同类别的信息, 本实施例中共有三类 信息, 分别用黑色填充、 斜线填充以及空白填充表示; 相应的, DPI联动信 息控制中心 12到关联识别控制策略决策子模块 132的实线表示传输黑色填 充的数据流; DPI联动信息控制中心 12到流量分担联动策略决策子模块 133 的虚线表示传输斜线填充的数据流; DPI联动信息控制中心 12到故障处理联 动策略决策子模块 134的点划线表示传输空白填充的数据流。 如图 2所示, DPI联动信息控制中心 12从 DPI执行机构 11获取 DPI 设备的信息, 并将所获取的信息分类后分别上报策略决策模块 13 中相应策 略决策子模块: 关联识别控制策略决策子模块 132、 流量分担联动策略决策 子模块 133、 故障处理联动策略决策子模块 134 , 各个策略决策子模块才艮据 收到的相应信息生成自身的应用策略, 并^1自身生成的应用策略上 4艮 DPI设 备联动策略管理子模块 131 , DPI设备联动策略管理模块 131对来自各个策 略决策子模块接收的策略决策信息进行综合分析, 并最终决定产生可执行的 应用策略下发至 DPI执行机构 11 , DPI执行机构 11收到可执行的应用策略 后, 根据下发的应用策略对 DPI设备进行控制操作, 比如转移数据流量、 分 担数据流量等。 其中, 所述综合分析是指 DPI设备联动策略管理模块 131要结合来自 各个策略子模块的策略信息, 分析得出可执行的应用策略。 比如: DPI设备 联动策略管理模块 131收到来自流量分担联动策略决策子模块 133、 故障处 理联动策略决策子模块 134的策略,其中,流量分担联动策略决策子模块 133 的策略给出当前正常工作的各节点设备的网络拓朴结构, 故障处理联动策略 决策子模块 134 的策略给出当前出现故障的节点设备并指出需要走迂回路 径, 那么, DPI设备联动策略管理模块 131收到这两个策略后, 先根据故障 处理联动策略决策子模块 134的策略确定哪个节点设备发生故障, 再才艮据流 量分担联动策略决策子模块 133的策略确定与该故障节点设备连接的上下游 各节点设备、 以及该上下游各节点设备之间连接的所有节点设备, 之后根据 路径选择算法从中选出合适的替换故障节点设备的节点设备。 可见, 综合分 析是结合来自各方面的策略信息才得出最终的应用策略; 或是, 从几种同类 策略中选出优先级高的、 或较佳的、 或最适合当前运行环境的策略作为最终 可执行的应用策略。 以下结合具体应用进行举例说明 , 1设网络中有 DPI 1、 DPI2、 DPI3、 DPI4四个 DPI设备 , 其中, 四个 DPI设备均支持 P2P十办议 , 且 DPI 1分别与 DPI2、 DPB相连, DPI2、 DPB均连接 DPI4, 从 DPIl传输至 DPI4的数据 流经由 DPI2传输。 当 DPI2发生故障时, 首先, DPI联动信息控制中心 12从 DPI执行机 构 11获取 DPI设备的信息: DPIl ~ DPI4均支持 P2P十办议; DPI1与 DPI2、 DPB相连, DPI2、 DPB与 DPI4相连,且 DPI1通过 DPI2向 DPI4传输数据; DPI4发生故障。 然后, DPI联动信息控制中心 12获得上述信息后, 将这些信息分为三 类: DPI 1 ~ DPI4均支持 P2P协议属于识别结果信息; DPI 1、 DPI2、 DPB、 DPI4的连接关系, 以及 DPI1 向 DPI4传输数据所走的路径属于路由信息; DPI4发生故障属于状态信息。 之后, DPI联动信息控制中心 12将识别结果信息上报关联识别控制策 略决策子模块 132; 将路由信息上报流量分担联动策略决策子模块 133和故 障处理联动策略决策子模块 134; 将状态信息上 4艮故障处理联动策略决策子 模块 134。 关联识别控制策略决策子模块 132、 流量分担联动策略决策子模块 133 和故障处理联动策略决策子模块 134各自根据收到的信息生成自身的应用策 略; 其中, 故障处理联动策略决策子模块 134收到路由信息和状态信息后, 根据状态信息和路由信息生成自身的策略决策: 将 DPI1经由 DPI2向 DPI4 传输的数据, 转移至经由 DPB向 DPI4传输。 最后, 故障处理联动策略决策子模块 134 将自身生成的策略决策上 4艮
DPI设备联动策略管理模块 131 , DPI设备联动策略管理模块 131经过综合 分析, 对于故障处理, 将 DPI1经由 DPB传输数据至 DPI4作为最终可执行 的应用策略, 并下发 jt匕应用策略给 DPI执行机构 11 , DPI执行机构 11才艮据 收到的应用策略对 DPI 1 ~ DPI4进行控制处理, 将 DPI 1发送 DPI4的数据经 由 DPB传输。 方法实施例 基于上述系统,本发明实施例还提供了一种深度报文检测设备联动策略 生成方法,该方法的具体处理过程如图 3所示,包括以下步骤 301至步骤 304 的处理: 步骤 301 : DPI联动信息控制中心从 DPI执行机构获取各个 DPI设备的 信息, 上报策略决策模块的策略生成子模块; 这里, 如果策略生成子模块中包括多个策略决策子模块, 例如: 包括关 联识别控制策略决策子模块、 流量分担联动策略决策子模块、 故障处理联动 策略决策子模块, 则 DPI联动信息控制中心会将 DPI设备信息分类后, 上报 策略生成子模块中的各个策略决策子模块。 其中, 所述 DPI设备的信息可为 DPI设备的路由信息、 和 /或 DPI设备的状态信息、 和 /或 DPI设备的识别结 果信息、 和 /或 DPI设备的流量信息、 和 /或 DPI设备的关联信息。 步骤 302: 策略生成子模块根据收到的相应信息生成各种应用策略, 并 将生成的应用策略上 4艮策略决策模块中的 DPI设备联动策略管理子模块; 这里, 如果策略生成子模块由多个策略决策子模块组成, 则各策略决策 子模块各自根据收到的相应信息生成自身的应用策略, 上报 DPI设备联动策 略管理子模块。 步骤 303: DPI设备联动策略管理子模块综合分析收到的各种应用策略, 并最终形成可执行的应用策略, 下发至 DPI执行机构; 这里, 如果 DPI设备联动策略管理子模块还连接集中策略管理模块、 和 /或外部管理及决策系统; 那么, 所述最终形成可执行的应用策略为: 才艮据 确定的一个以上应用策略, 并结合集中策略管理模块下发的策略信息、 和 / 或外部管理及决策系统提供的策略信息生成最终可执行的应用策略。 步骤 304: DPI执行机构根据策略决策模块下发的最终可执行的应用策 略, 对各个 DPI设备执行相应控制操作。 步骤 304对于 DPI设备联动策略生成方法来说是可选的。 由上述处理过程可以看出: 采用本发明实施例所提供的方法, 可以有效 综合网络中部署的 DPI设备信息以及业务状态等,进行相应策略决策的制定, 进而有效的实现 DPI设备识别业务流量的优化均衡, 以及单个 DPI设备故障 情况下数据流量的转移等功能。 才艮据本发明实施例, 还提供了一种计算机可读介质, 该计算机可读介质 上存储有计算机可执行的指令, 当该指令被计算机或处理器执行时, 使得计 算机或处理器执行如图 3所示的步骤 301至步骤 304的处理, 优选地, 可以 执行上述的实施例中的一个或多个。 另外 ,本发明的实现没有对系统架构和目前的处理流程修改,易于实现, 便于在技术领域中进行推广, 具有较强的工业适用性。 以上所述, 仅为本发明的较佳实施例而已, 并非用于限定本发明的保护 范围, 凡在本发明的精神和原则之内所作的任何修改、 等同替换和改进等, 均应包含在本发明的保护范围之内。

Claims

权 利 要 求 书 一种深度报文检测设备联动策略生成系统, 其特征在于, 该系统包括: 深度报文检测 DPI执行机构、 DPI联动信息控制中心以及策略决策模 块; 其中,
DPI执行机构, 用于对业务流量进行识别与控制, 还用于向 DPI 联动信息控制中心提供各 DPI设备的信息;
DPI联动信息控制中心, 用于收集各 DPI设备的信息, 并将收集 到的信息分类提供给策略决策模块;
策略决策模块,用于从 DPI联动信息控制中心收集 DPI设备的信 息, 并才艮据收集的信息生成可执行的应用策略, 再将所生成的应用策 略下发给 DPI执行机构。 根据权利要求 1所述的深度报文检测设备联动策略生成系统, 其特征 在于, 所述策略决策模块包括 DPI设备联动策略管理子模块、 策略生 成子模块;
其中, 所述 DPI设备联动策略管理子模块, 用于接收策略生成子 模块上报的应用策略, 根据上报的应用策略生成可执行的应用策略并 下发 DPI执行机构;
所述策略生成子模块,用于接收 DPI联动信息控制中心上报的各 种 DPI设备信息, 根据收到的 DPI设备信息生成各种策略, 并将生成 的策略提供给 DPI设备联动策略管理子模块。 根据权利要求 2所述的深度报文检测设备联动策略生成系统, 其特征 在于 , 所述 DPI设备的信息包括但不限于 DPI设备的路由信息、 DPI 设备的状态信息、 DPI设备的识别结果信息、 DPI设备的流量信息、 DPI设备的关联信息;
所述策略生成子模块包括关联识别控制策略决策子模块、 流量分 担联动策略决策子模块、 故障处理联动策略决策子模块中的任意一个 或多个。
4. 根据权利要求 2所述的深度报文检测设备联动策略生成系统, 其特征 在于, 所述策略生成子模块包括关联识别控制策略决策子模块、 流量 分担联动策略决策子模块和故障处理联动策略决策子模块;
所述关联识别控制策略决策子模块,用于从 DPI联动信息控制中 心获取 DPI设备的关联信息,根据获取的关联信息进行相应控制决策, 并将自身生成的控制策略上报 DPI设备联动策略管理子模块;
所述流量分担联动策略决策子模块,用于从 DPI联动信息控制中 心获取 DPI设备的流量信息, 根据获取的流量信息进行流量分担策略 决策 , 并将自身产生的流量分担策略上报 DPI设备联动策略管理子模 块;
所述故障处理联动策略决策子模块,用于从 DPI联动信息控制中 心获取 DPI设备的状态信息, 才艮据获取的状态信息进行故障处理策略 决策, 并将自身产生的故障处理策略上 DPI设备联动策略管理子模 块。
5. 根据权利要求 4所述的深度报文检测设备联动策略生成系统 , 其特征 在于, 该系统进一步包括集中策略管理模块, 用于协调管理一个以上 所述联动策略生成系统, 生成并下发相应管理策略给其管辖范围内的 策略决策模块;
相应的, DPI设备联动策略管理子模块还用于接收集中策略管理 模块下发的策略;之后结合所收到的策略分析生成可执行的应用策略。
6. 根据权利要求 4或 5所述的深度报文检测设备联动策略生成系统, 其 特征在于, 该系统进一步包括外部管理及决策系统, 用于生成对 DPI 设备进行管理的策略, 并将所生成的策略提供给策略决策模块;
相应的, DPI设备联动策略管理子模块还用于接收来自外部管理 及决策系统编辑和导入 /导出的策略; 之后结合所收到的策略分析生成 可执行的应用策略。
7. 一种深度报文检测设备联动策略生成方法, 其特征在于, 该方法包括: 获取各 DPI 设备的信息, 根据所获取的信息确定不同的应用策 略 , 之后再才艮据确定的一个以上应用策略生成可执行的应用策略并下 发。
8. 根据权利要求 7所述的深度报文检测设备联动策略生成方法, 其特征 在于, 所述获取各 DPI设备的信息为: 将获取的各 DPI设备的信息分 类上报策略决策模块中的各策略决策子模块;
相应的, 所述根据所获取的信息确定不同的应用策略为: 各策略 决策子模块才艮据收到的信息生成自身的应用策略, 并将生成的应用策 略上 4艮策略决策模块中的 DPI设备联动策略管理子模块;
所述生成可执行的应用策略并下发为: DPI设备联动策略管理子 模块才艮据上 4艮的应用策略生成执行的应用策略并下发 DPI执行机构。
9. 根据权利要求 7或 8所述的深度报文检测设备联动策略生成方法, 其 特征在于, 所述 DPI设备的信息包括但不限于 DPI设备的路由信息、 DPI设备的状态信息、 DPI设备的识别结果信息、 DPI设备的流量信息、 DPI设备的关联信息。
10. 一种深度报文检测设备联动策略生成方法, 其特征在于, 该方法包括: 获取各 DPI 设备的信息, 根据所获取的信息确定不同的应用策 略, 之后才艮据确定的一个以上应用策略, 并结合集中策略管理模块、 和 /或外部管理及决策系统提供的策略信息生成可执行的应用策略并 下发。
11. 根据权利要求 10所述的深度报文检测设备联动策略生成方法,其特征 在于, 所述获取各 DPI设备的信息为: 将获取的各 DPI设备的信息分 类上报策略决策模块中的各策略决策子模块;
相应的, 所述根据所获取的信息确定不同的应用策略为: 各策略 决策子模块才艮据收到的信息生成自身的应用策略, 并将生成的应用策 略上 4艮策略决策模块中的 DPI设备联动策略管理子模块;
所述生成可执行的应用策略并下发为: DPI设备联动策略管理子 模块根据上报的应用策略、 集中策略管理模块下发的策略信息和 /或外 部管理及决策系统生成的策略, 分析生成可执行的应用策略, 并下发 DPI执行机构。
12. 根据权利要求 10或 11所述的深度报文检测设备联动策略生成方法, 其特征在于,所述 DPI设备的信息包括但不限于 DPI设备的路由信息、 DPI设备的状态信息、 DPI设备的识别结果信息、 DPI设备的流量信息、 DPI设备的关联信息。
PCT/CN2009/073660 2009-05-05 2009-09-01 深度报文检测设备联动策略生成系统及方法 WO2010127525A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN200910083189.4A CN101883016B (zh) 2009-05-05 2009-05-05 一种深度报文检测设备联动策略生成系统及方法
CN200910083189.4 2009-05-05

Publications (1)

Publication Number Publication Date
WO2010127525A1 true WO2010127525A1 (zh) 2010-11-11

Family

ID=43049936

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2009/073660 WO2010127525A1 (zh) 2009-05-05 2009-09-01 深度报文检测设备联动策略生成系统及方法

Country Status (2)

Country Link
CN (1) CN101883016B (zh)
WO (1) WO2010127525A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2024208298A1 (zh) * 2023-04-04 2024-10-10 中国移动通信有限公司研究院 一种策略管理方法、系统及可读存储介质

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102752384B (zh) * 2012-06-29 2015-03-04 安科智慧城市技术(中国)有限公司 一种设备信息联动处理方法及装置
CN103888307B (zh) * 2012-12-20 2017-11-17 中国电信股份有限公司 用于优化深度包检测的方法、用户侧板卡和宽带接入网关
CN107645502B (zh) * 2017-09-20 2021-01-22 新华三信息安全技术有限公司 一种报文检测方法及装置
CN112187498B (zh) * 2019-07-03 2022-09-06 中国电信股份有限公司 旁路保护方法及其装置、系统和深度报文检测dpi系统
CN111355610A (zh) * 2020-02-25 2020-06-30 网宿科技股份有限公司 一种基于边缘网络的异常处理方法及装置
CN116055423A (zh) * 2022-12-26 2023-05-02 南京中孚信息技术有限公司 一种基于策略控制的流量并行分发装置

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101286937A (zh) * 2008-05-16 2008-10-15 华为技术有限公司 一种网络流量控制方法、装置及系统
CN101399749A (zh) * 2007-09-27 2009-04-01 华为技术有限公司 一种报文过滤的方法、系统和设备
CN101420367A (zh) * 2007-10-24 2009-04-29 中国电信股份有限公司 P2p流量控制系统及方法

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101350781A (zh) * 2008-07-31 2009-01-21 成都市华为赛门铁克科技有限公司 一种流量监控的方法、设备和系统

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101399749A (zh) * 2007-09-27 2009-04-01 华为技术有限公司 一种报文过滤的方法、系统和设备
CN101420367A (zh) * 2007-10-24 2009-04-29 中国电信股份有限公司 P2p流量控制系统及方法
CN101286937A (zh) * 2008-05-16 2008-10-15 华为技术有限公司 一种网络流量控制方法、装置及系统

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2024208298A1 (zh) * 2023-04-04 2024-10-10 中国移动通信有限公司研究院 一种策略管理方法、系统及可读存储介质

Also Published As

Publication number Publication date
CN101883016B (zh) 2014-11-05
CN101883016A (zh) 2010-11-10

Similar Documents

Publication Publication Date Title
WO2010127525A1 (zh) 深度报文检测设备联动策略生成系统及方法
Sarhan et al. Data Inspection in SDN Network
JP4510777B2 (ja) リンクアグリゲーショングループのリンク内でフレームを分配するための方法、ネットワーク要素及び論理装置
US8848522B2 (en) Telecommunications system and server apparatus
CN100512215C (zh) 使用分布式网络处理的数据交换设备和方法
CN103825823B (zh) 基于不同优先级的软件定义网络中数据转发方法
CN103618677B (zh) 一种网络流量调整方法及系统
CN105052113B (zh) 提供针对网络设备的共同代理框架的方法、设备及介质
CN107852365A (zh) 具有加密和流量工程解析的动态vpn策略模型
Abbasi et al. Traffic engineering in software defined networks: a survey
JP4510776B2 (ja) リンクアグリゲーショングループのリンク内でカンバセーションを再配分するための方法、ネットワーク要素及び論理装置
CN103067291B (zh) 一种上下行链路关联的方法和装置
JP2006295935A (ja) リンクアグリゲーショングループ内で通信を移行するための方法、ネットワーク要素及び論理装置
JP2015519823A (ja) パケットデータネットワーキングにおける輻輳制御
CN106656905A (zh) 防火墙集群实现方法及装置
WO2014000399A1 (zh) 链路选择方法和装置
JP4823156B2 (ja) リモートトラフィック監視方法
EP3756317A1 (en) Method and system for interfacing communication networks
CN108540559A (zh) 一种支持IPSec VPN负载均衡的SDN控制器
US11240140B2 (en) Method and system for interfacing communication networks
Ouamri et al. Request delay and survivability optimization for software defined‐wide area networking (SD‐WAN) using multi‐agent deep reinforcement learning
JP2007228217A (ja) トラフィック判定装置、トラフィック判定方法、及びそのプログラム
Chaturvedi et al. Comparative Analysis of Traditional Virtual-LAN with Hybrid Software Defined Networking Enabled Network
CN101958843A (zh) 基于流量分析和节点信任度的智能路由选择方法
WO2010127524A1 (zh) 基于深度报文检测设备的业务识别网络的管理方法与系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09844277

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 09844277

Country of ref document: EP

Kind code of ref document: A1