WO2016086755A1 - Packet processing method and transparent proxy server - Google Patents
Packet processing method and transparent proxy server Download PDFInfo
- Publication number
- WO2016086755A1 WO2016086755A1 PCT/CN2015/094131 CN2015094131W WO2016086755A1 WO 2016086755 A1 WO2016086755 A1 WO 2016086755A1 CN 2015094131 W CN2015094131 W CN 2015094131W WO 2016086755 A1 WO2016086755 A1 WO 2016086755A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- web server
- server
- address
- transparent proxy
- domain name
- Prior art date
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
Definitions
- the present invention relates to the field of communications technologies, and in particular, to a packet processing method and a transparent proxy server.
- VAS Value Added Servers
- the transparent proxy server is located between the client and the World Wide Web (WEB) server, and the client initiates the domain name to the Domain Name System (DNS). Parsing the request to obtain the IP address of the WEB server, the transparent proxy server constructs a connection between the client and the WEB server, and the client sends the service packet to the WEB server by using the IP address of the WEB service as the destination IP address.
- the transparent proxy server identifies the service type of the service packet by using deep packet inspection (DPI), and determines a VAS server for processing the service packet according to the service type, and then the transparent proxy server is disconnected.
- DPI deep packet inspection
- the transparent proxy server needs to identify the service packet sent by the user through the DPI to determine the VAS server, so that the data packet cannot be obtained in time. Processing affects the user experience.
- the embodiment of the invention provides a method for processing a message, which can shorten the length of time for the transparent proxy server to determine the VAS server, and enable the service packet exchanged between the user and the WEB server to obtain the processing of the VAS server in time, and improve the user. Experience.
- a first aspect of the embodiments of the present invention provides a packet processing method, including:
- the transparent proxy server obtains the handshake message sent by the client to the WEB server.
- the transparent proxy server determines the target VAS server according to the destination IP address and the corresponding relationship, and the corresponding relationship is VAS. Correspondence between the server and the IP address of the target WEB server;
- the transparent proxy server constructs a connection between the user end, the target VAS server, and the WEB server, where the target VAS server is configured to process a service packet exchanged between the user end and the WEB server.
- the transparent proxy server determines that the destination IP address of the handshake packet is a preset target WEB server.
- the IP address further includes: the transparent proxy server acquiring an IP address of the target WEB server.
- the transparent proxy server acquiring the IP address of the target WEB server includes:
- the transparent proxy server saves the IP address of the target WEB server.
- the transparent proxy server determines that the domain name of the target WEB server includes:
- the domain name of the first WEB server is the domain name of the target WEB server.
- the obtaining, by the transparent proxy server, the IP address of the target WEB server includes:
- the transparent proxy server determines a first number of times that the user sends the first service packet to the first web server, and a second number of times that the second service packet is sent to the second web server, where the first number of times is greater than
- the second service packet includes a first destination IP address, and the second service packet includes a second destination IP address.
- the first destination IP address is an IP address of the target WEB server
- the transparent proxy server saves the IP address of the target WEB server.
- the determining, by the transparent proxy server, the target VAS server further includes: the transparent proxy server acquiring the corresponding relationship according to the destination IP address and the corresponding relationship.
- a second aspect of the embodiments of the present invention provides a packet processing method, including:
- the transparent proxy server obtains the handshake message sent by the user to the WEB server, where the destination IP address in the handshake message is the IP address of the WEB server;
- the transparent proxy server Determining, by the transparent proxy server, the domain name of the WEB server according to the destination IP address and the first correspondence, where the first correspondence is a correspondence between a domain name of the WEB server and an IP address of the WEB server;
- the transparent proxy server determines the target VAS server according to the domain name and the second correspondence of the WEB server, and the second correspondence is VAS. Correspondence between the server and the domain name of the preset target WEB server;
- the transparent proxy server constructs a connection between the user end, the target VAS server, and the WEB server, where the target VAS server is configured to process a service packet exchanged between the user end and the WEB server.
- the transparent proxy server determines that the domain name of the WEB server is the domain name of the preset target WEB server.
- the method includes: the transparent proxy server acquiring a domain name of the target server.
- the obtaining, by the transparent proxy server, the domain name of the target WEB server includes:
- the transparent proxy server determines an IP address of the target WEB server
- the transparent proxy server saves the domain name of the target WEB server.
- the transparent proxy server determines that the IP address of the target WEB server includes:
- the transparent proxy server determines a first number of times that the user sends the first service packet to the first web server, and a second number of times that the second service packet is sent to the second web server, where the first number of times is greater than
- the second service packet includes a first destination IP address, and the second service packet includes a second destination IP address.
- the obtaining, by the transparent proxy server, the domain name of the target WEB server includes:
- the domain name of the first WEB server is the domain name of the target WEB server
- the transparent proxy server saves the domain name of the target WEB server.
- the transparent proxy server before the transparent proxy server determines the domain name of the WEB server according to the destination IP address and the first correspondence, the transparent proxy server further includes: the transparent proxy server acquiring the location The first correspondence is described.
- the transparent proxy server further includes: before the target VAS server is determined according to the domain name and the second correspondence of the WEB server. The transparent proxy server acquires the second correspondence.
- a third aspect of the embodiments of the present invention provides a transparent proxy server, including:
- An obtaining unit configured to obtain a handshake message sent by the client to the WEB server
- a determining unit configured to determine a target VAS server according to the destination IP address and the corresponding relationship when determining that the destination IP address in the handshake packet is an IP address of a preset target WEB server, where the correspondence is VAS Correspondence between the server and the IP address of the target WEB server;
- a building unit configured to construct a connection between the user end, the target VAS server, and the WEB server, where the target VAS server is configured to process a service packet exchanged between the user end and the WEB server .
- the acquiring unit is further configured to acquire an IP address of the target WEB server.
- the acquiring unit is specifically configured to determine a domain name of the target WEB server
- the acquiring unit is specifically configured to determine that the user end uses the first WEB server.
- the first number of times the domain name is parsed and the second number of times the domain name of the second WEB server is used for parsing, the first number of times being greater than the second number of times;
- the domain name of the first WEB server is the domain name of the target WEB server.
- the acquiring unit is specifically configured to determine that the user end sends the information to the first WEB server.
- the first number of times of the first service packet and the second number of times the second service packet is sent to the second WEB server, where the first number of times is greater than the second number of times, and the first service packet includes the first destination IP address An address, where the second service packet includes a second destination IP address;
- the first number of times is greater than or equal to a preset ratio of the sum of the first number of times and the second number of times, determining that the first destination IP address is an IP address of the target WEB server, and saving the The IP address of the target WEB server.
- the acquiring unit is further configured to obtain The corresponding relationship.
- a fourth aspect of the embodiments of the present invention provides a transparent proxy server, including:
- An obtaining unit configured to obtain a handshake message sent by the user to the WEB server, where the destination IP address in the handshake message is an IP address of the WEB server;
- a determining unit configured to determine a domain name of the WEB server according to the destination IP address and the first correspondence, where the first correspondence is a correspondence between a domain name of the WEB server and an IP address of the WEB server;
- the determining unit is further configured to: when determining that the domain name of the WEB server is the domain name of the preset target WEB server, determine the target VAS server according to the domain name and the second correspondence of the WEB server, and the second corresponding The relationship is a correspondence between the VAS server and the domain name of the preset target WEB server;
- a building unit configured to construct a connection between the user end, the target VAS server, and the WEB server, where the target VAS server is configured to process a service packet exchanged between the user end and the WEB server .
- the acquiring unit is further configured to acquire a domain name of the target server.
- the acquiring unit is specifically configured to determine an IP address of the target WEB server
- the acquiring unit is specifically configured to determine that the user end sends the information to the first WEB server.
- the first number of times of the first service packet and the second number of times the second service packet is sent to the second WEB server, where the first number of times is greater than the second number of times, and the first service packet includes the first destination IP address An address, where the second service packet includes a second destination IP address;
- the obtaining unit is specifically configured to determine a first number of times that the user end uses the domain name of the first WEB server for parsing, and a second number that is parsed by using the domain name of the second WEB server, The first number of times is greater than the second number of times;
- the domain name of the first WEB server is the domain name of the target WEB server
- the acquiring unit is further configured to use the first correspondence.
- the acquiring unit is further configured to acquire the second correspondence.
- a fifth aspect of the embodiments of the present invention provides a transparent proxy server, including a processor, a memory, a bus, and a communication interface.
- the memory is configured to store computer execution instructions
- the processor is coupled to the memory via the bus, and when the mobility management entity is running, the processor executes the computer execution instructions stored by the memory, A method of causing the mobility management entity to perform the message processing according to any one of claims 1 to 13.
- the transparent proxy server When the user establishes a connection with the WEB server, the transparent proxy server obtains the handshake message sent by the user to the WEB server, and determines the destination IP address of the handshake message according to the VAS server when determining the destination IP address of the handshake message. Corresponding relationship with the IP address of the target WEB server determines the VAS server. Compared with the prior art, the VAS server can be determined and the user end interacts with the WEB server without establishing a connection between the UE and the WEB server. The service packets are processed in time by the VAS server to improve the user experience.
- FIG. 1 is a schematic diagram of an embodiment of a packet processing method according to Embodiment 1 of the present invention.
- FIG. 2 is a schematic diagram of an embodiment of a packet processing method according to Embodiment 2 of the present invention.
- FIG. 3 is a schematic diagram of an embodiment of a packet processing method according to Embodiment 3 of the present invention.
- FIG. 4 is a schematic diagram of an embodiment of a packet processing method according to Embodiment 4 of the present invention.
- FIG. 5 is a schematic diagram of an embodiment of a packet processing method according to Embodiment 5 of the present invention.
- FIG. 6 is a schematic diagram of an embodiment of a transparent proxy server according to Embodiment 6 and Embodiment 7 of the present invention.
- FIG. 7 is a schematic diagram of an embodiment of a transparent proxy server according to Embodiment 8 of the present invention.
- a packet processing method in Embodiment 1 of the present invention includes:
- the transparent proxy server obtains a handshake message sent by the client to the WEB server.
- the transparent proxy server works in the transparent proxy mode and is located between the client and the WEB server.
- the client interacts with the WEB server
- the data packet generated by the client passes through the transparent proxy server.
- the TCP/IP protocol uses a three-way handshake to establish a connection.
- the client sends a handshake packet to the WEB server.
- the proxy server can obtain the handshake message, and the transparent proxy server can identify the destination IP address in the handshake message.
- the transparent proxy server determines the target VAS server according to the destination IP address and the corresponding relationship, and the corresponding relationship The correspondence between the VAS server and the IP address of the target WEB server.
- the IP address of the target WEB server is preset in the transparent proxy server, and the transparent proxy server can identify the destination IP address from the handshake message and the IP address of the preset target WEB service.
- the transparent proxy server may be configured according to the destination IP address, the VAS server, and the target WEB. The correspondence between the IP addresses of the servers determines the target VAS server.
- the transparent proxy server constructs a connection between the user end, the target VAS server, and the WEB server, where the target VAS server is configured to process data exchanged between the user end and the WEB server. Message.
- a specific VAS server is configured to process data packets of one or more service types, and when the data message sent by the user to the WEB server is obtained, the transparent proxy server may The data message is forwarded to the target VAS server, and the target VAS server performs corresponding value-added service processing on the received data packet, and sends the data packet to the WEB server, and the WEB server feeds back to the user end.
- the data message can also be processed by the VAS server.
- the transparent proxy server When the user establishes a connection with the WEB server, the transparent proxy server obtains the handshake message sent by the user to the WEB server, and determines the destination IP address of the handshake message according to the VAS server when determining the destination IP address of the handshake message. Corresponding relationship with the IP address of the target WEB server determines the VAS server. Compared with the prior art, the VAS server can be determined and the user end interacts with the WEB server without establishing a connection between the UE and the WEB server. The service packets are processed in time by the VAS server to improve the user experience.
- the IP of the target WEB server may be configured in a transparent proxy server or may be obtained by the transparent proxy server.
- the transparent proxy server obtains the IP address of the target WEB server, which may be in multiple manners, as follows:
- the transparent proxy server obtains the IP address of the target WEB server, specifically: the transparent proxy server determines the domain name of the target WEB server; and the transparent proxy server determines the domain according to the domain name of the target WEB server.
- the IP address of the target WEB server; the transparent proxy server saves the IP address of the target WEB server.
- a method for processing a message according to Embodiment 2 of the present invention includes:
- the transparent proxy server obtains a handshake message sent by the client to the WEB server.
- the transparent proxy server works in a transparent proxy mode, and the transparent proxy server is deployed between the client and the WEB server, and is a proxy server that is not perceived by the client and the WEB server, and the client and the WEB server.
- the data packets generated during the interaction will pass through the transparent proxy server, for example, in the PCC architecture, and the transparent proxy server is PCEF/TDF.
- the handshake message generated between the user end and the WEB server passes through the transparent proxy server, and the transparent proxy server can obtain the handshake message and identify the handshake message.
- the destination IP address in the handshake packet for example, in the TCP/IP protocol.
- the three-way handshake is used to establish a connection.
- the user sends a synchronous (syn) handshake message to the WEB server.
- the transparent proxy server can obtain the syn handshake packet.
- the transparent proxy server can identify the destination IP address in the syn handshake message.
- the user terminal may be a mobile terminal such as a mobile phone or a tablet computer, or a device that can access the network, such as a notebook computer, and is not limited herein.
- 202 and 203 are further included after 201 in this embodiment.
- the transparent proxy server determines a domain name of the target WEB server, and determines an IP address of the target WEB server according to the domain name of the target WEB server, and saves an IP address of the target WEB server.
- the client before the user sends a service packet to the WEB server, the client usually sends the domain name of the WEB server to the DNS server for domain name resolution. After the DNS server is parsed, the user is sent to the user through the transparent proxy server. The end feedback contains the query result of the WEB server IP address.
- the manner in which the transparent proxy server determines the IP address of the target WEB server may be specifically: the domain name sent by the client is used as the domain name of the target WEB server, and the DNS server is parsed and then sent to the client.
- the IP address included in the feedback result is used as the IP address of the target WEB server; or the transparent proxy server may determine the IP address of the target WEB server by recording the number of times the user uses the WEB server domain name for resolution, such as transparent
- the proxy server records a first number of times that the user end uses the domain name of the first WEB server for parsing and a second number that is parsed by using the second domain name of the second WEB server, when the first number of times is greater than or equal to the first number
- the transparent proxy server may use the domain name of the first WEB server as the domain name of the target WEB server, and determine according to the query result fed back by the DNS server, when the preset ratio of the number of times and the second number of times is the same.
- the IP address corresponding to the domain name of the target WEB server that is, the IP address of the target WEB server.
- the preset ratio in the embodiment is 90%. In actual applications, the preset ratio may be set according to actual needs, which is not limited herein.
- the transparent proxy server determines the IP address of the target WEB server by using the query result fed back by the DNS server.
- the transparent proxy server may also pass the WEB server.
- the mapping between the domain name and the IP address of the WEB server determines the IP address of the target WEB server, which is not limited herein.
- the mapping between the domain name of the WEB server and the IP address of the WEB server may be pre-configured in the transparent proxy server, or may be the IP address corresponding to the domain name fed back by the transparent proxy server through the domain name and the DNS.
- the construction is not limited herein.
- the transparent proxy server acquires a correspondence between the VAS server and an IP address of the target WEB server.
- the transparent proxy server can generate the corresponding relationship by sampling the data packet of the user to the target WEB server, specifically: the transparent proxy server passes the deep packet inspection (Deep Packet Inspection). , DPI) analyzes the destination IP address in the sampled data message, that is, the IP address of the target WEB server, and tracks the VAS server through which the data message passes, the transparent proxy server according to the IP address of the target WEB server Corresponding to the VAS server through which the data packet passes, and the corresponding relationship is saved.
- DPI deep packet inspection
- the corresponding relationship may be obtained by the transparent proxy server, or may be configured in the transparent proxy server after the other device obtains the corresponding relationship, which is not limited herein.
- the VAS server is configured to process a specific type of data packet, such as a virus filtering, a page adaptation, a video optimization, and the like.
- the user sends a data packet to the WEB server through a Transmission Control Protocol (TCP) or other protocol, which is not limited herein.
- TCP Transmission Control Protocol
- the transparent proxy server determines whether the destination IP address in the handshake message is an IP address of a preset target WEB server. If not, step 205 is performed, and if yes, step 206 is performed.
- the transparent proxy server can parse the destination IP address in the handshake packet, and compare the parsed destination IP address with the IP address of the target WEB server to determine the destination IP address in the target data packet. Whether the address is the IP address of the target WEB server.
- the transparent proxy server establishes a connection between the client and the WEB server.
- the transparent proxy server determines that the destination IP address in the target data packet is not the IP address of the target WEB server, the transparent proxy server establishes a connection between the client and the WEB server.
- the transparent proxy server determines the target VAS server according to the destination IP address and the corresponding relationship, where the correspondence relationship is a correspondence between the VAS server and the IP address of the target WEB server.
- the target VAS server is determined according to the correspondence between the VAS server and the IP address of the target WEB server.
- the transparent proxy server constructs a connection between the user end, the VAS server, and the target WEB server, where the target VAS server is configured to process data exchanged between the user end and the WEB server. Message.
- the VAS server can provide value-added service processing for data packets of a specific service type, for example, a video optimization server is used to process data packets of a service type of video services, and a hypertext transfer protocol (HTTP).
- the content type of the video service request report includes: video/mp4, video/x-flv, video/x-f4v, etc.; the page adaptation server is configured to process data packets whose service type is page adaptation service.
- the content types of the page adaptation data message include: text/html, application/vnd.wap.xhtml, application/xhtml+xml, ext/vnd.wap.wml, application/vnd.wap.
- the content insertion server is configured to process a data packet whose service type is a content insertion service.
- the content type of the content insertion data packet includes: /html, application/vnd.wap.xhtml, application/xhtml+xml, etc.
- the VAS server can process one or more data packets at the same time.
- the VAS server can process the video data packet and the page adaptation data packet at the same time, which is not limited herein.
- the transparent proxy server includes a port for connecting with the client, a port for connecting with the VAS server, and a port for connecting to the WEB server, and determining a VAS server according to the handshake message, where the transparent proxy server can be
- the port connected by the client establishes a communication channel with the port connected to the VAS server, thereby implementing a connection between the client, the target VAS server, and the target WEB server.
- the target VAS server may process the data used by the target VAS server to process interaction between the client and the WEB server. Message.
- the transparent proxy server uses the domain name with the proportion of the number of domain name resolutions greater than or equal to 90% as the domain name of the target WEB server, and then determines the target WEB server according to the domain name of the target WEB server.
- the IP address that is, the frequency of the IP address of the target WEB server used by the client is high. Therefore, according to the correspondence between the IP address of the target server and the VAS server, the success rate of determining the target VAS server can be improved.
- the transparent proxy server obtains the IP address of the target WEB server, where the transparent proxy server determines that the user sends the first data packet to the WEB server for the first time and sends the first data packet.
- the second number of times of the second data packet the first number of times is greater than the second number of times, the first data packet includes a first destination IP address, and the second data packet includes a second destination IP address;
- the transparent proxy The server saves the IP address of the target WEB server.
- a method for processing a message according to Embodiment 3 of the present invention includes:
- the transparent proxy server obtains a handshake message sent by the user end to the WEB server.
- the transparent proxy server works in a transparent proxy mode, and the transparent proxy server is deployed between the client and the WEB server, and is a proxy server that is not perceived by the client and the WEB server, and the client and the WEB server.
- the data packets generated during the interaction will pass through the transparent proxy server, for example, in the PCC architecture, and the transparent proxy server is PCEF/TDF.
- the handshake message generated between the user end and the WEB server passes through the transparent proxy server, and the transparent proxy server can obtain the handshake message and identify the handshake message.
- the destination IP address in the handshake packet for example, in the TCP/IP protocol, the three-way handshake is used to establish a connection.
- the client sends a synchronous (syn) handshake to the WEB server.
- the message, the transparent proxy server can obtain the syn handshake packet, and the transparent proxy server can identify the destination IP address in the syn handshake packet.
- the user terminal may be a mobile terminal such as a mobile phone or a tablet computer, or a device that can access the network, such as a notebook computer, and is not limited herein.
- step 301 after step 301, 302, 303, and 304 are further included.
- the transparent proxy server determines a first time that the user sends the first data packet to the WEB server, and a second number of times that the second data packet is sent, where the first number is greater than the first
- the second data packet includes a first destination IP address, and the second data packet includes a second destination IP address.
- the transparent proxy server may obtain the data packet sent by the client to the WEB server, and record that the client sends the data packet to the WEB server. The number of times of the data packet, the transparent proxy server may further analyze the obtained data packet to obtain a destination IP address in the data packet, such as the The transparent proxy server records the first number of times that the user sends the first data packet to the first WEB server, and sends the second data packet to the second WEB server for the second time, and analyzes the first data. The first destination IP address in the packet and the second destination IP address in the second data packet.
- the transparent proxy server determines that the first destination IP address is the target WEB server. IP address and save the IP address of the target WEB server.
- the transparent proxy server can compare whether the first number of times is greater than the second number, and determine whether the first number of times is greater than or equal to a sum of the first number and the second number of times Proportion, when the transparent proxy server determines that the first number of times is greater than the second number, and the first number of times is greater than or equal to a preset ratio of the sum of the first number of times and the second number of times,
- the first destination IP address is used as the IP address of the target WEB server, and the IP address of the target WEB server is saved in the transparent proxy server.
- the preset ratio in the embodiment is 90%. In actual applications, the preset ratio may be set according to actual needs, which is not limited herein.
- the transparent proxy server acquires a correspondence between the VAS server and an IP address of the target WEB server.
- the transparent proxy server determines whether the destination IP address in the handshake message is an IP address of a preset target WEB server. If not, step 306 is performed, and if yes, step 307 is performed.
- the transparent proxy server establishes a connection between the client and the WEB server.
- the transparent proxy server determines, according to the destination IP address and the corresponding relationship, a target VAS server, where the correspondence relationship is a correspondence between the VAS server and an IP address of the target WEB server.
- the transparent proxy server constructs a connection between the user end, the VAS server, and the target WEB server, where the target VAS server is configured to process data exchanged between the user end and the WEB server. Message.
- the transparent proxy server determines that the service number of the client is greater than or equal to 90%, and uses the destination IP address in the service packet as the target WEB server.
- the IP address that is, the IP address of the target WEB server is high, so that the success rate of the target VAS server can be improved according to the correspondence between the IP address of the target server and the VAS server.
- the transparent proxy server pre- The IP address of the target WEB server is set.
- the domain name of the target WEB server can also be preset in the transparent proxy server.
- a method for processing a packet according to Embodiment 4 of the present invention includes:
- the transparent proxy server obtains a handshake message sent by the user to the WEB server, where the IP address of the handshake message is an IP address of the WEB server.
- the transparent proxy server works in a transparent proxy mode, and the transparent proxy server is deployed between the client and the WEB server, and is a proxy server that is not perceived by the client and the WEB server, and the client and the WEB server.
- the data packets generated during the interaction will pass through the transparent proxy server, for example, in the PCC architecture, and the transparent proxy server is PCEF/TDF.
- the handshake message generated between the user end and the WEB server passes through the transparent proxy server, and the transparent proxy server can obtain the handshake message and identify the handshake message.
- the destination IP address in the handshake packet for example, in the TCP/IP protocol, the three-way handshake is used to establish a connection.
- the client sends a synchronous (syn) handshake to the WEB server.
- the message, the transparent proxy server can obtain the syn handshake packet, and the transparent proxy server can identify the destination IP address in the syn handshake packet.
- the user terminal may be a mobile terminal such as a mobile phone or a tablet computer, or a device that can access the network, such as a notebook computer, and is not limited herein.
- the transparent proxy server determines the domain name of the WEB server according to the destination IP address and the first correspondence, where the first correspondence is a correspondence between a domain name of the WEB server and an IP address of the WEB server.
- the transparent proxy server obtains the destination IP address from the obtained handshake packet, and the destination IP address is the IP address of the WEB server, and the WEB may be determined according to the correspondence between the domain name of the WEB server and the IP address of the WEB server.
- the IP address of the server is the IP address of the WEB server.
- the transparent proxy server determines the service type of the target data packet according to the domain name and the first correspondence of the WEB server.
- the first correspondence is a correspondence between a VAS server and a domain name of the target WEB server.
- the transparent proxy server can determine whether the domain name of the WEB server is the domain name of the target WEB server preset in the transparent proxy server, and determine that the domain name of the WEB server is When the domain name of the target WEB service preset in the transparent proxy server is described, the target VAS server is determined according to the correspondence between the VAS server and the domain name of the target server.
- the transparent proxy server constructs a connection between the user end, the target VAS server, and the WEB server, where the target VAS server is configured to process data exchanged between the user end and the WEB server. Message.
- a specific VAS server is configured to process data packets of one or more service types, and when the data message sent by the user to the WEB server is obtained, the transparent proxy server may The data message is forwarded to the target VAS server, and the target VAS server performs corresponding value-added service processing on the received data packet, and sends the data packet to the WEB server, and the WEB server feeds back to the user end.
- the data message can also be processed by the VAS server.
- the transparent proxy server determines the domain name of the WEB server corresponding to the destination IP address of the data packet according to the IP address of the WEB server and the first correspondence, and determines that the domain name of the WEB server is a preset target.
- the domain name of the WEB server is determined according to the domain name and the second correspondence of the WEB server, so that the length of the target VAS server is determined by the transparent proxy server, and the service packet is processed by the VAS server in time to improve the user experience.
- the transparent proxy server determines the target VAS server according to the domain name and the second correspondence of the WEB server.
- the second correspondence may be pre-configured in the transparent
- the proxy server may also be obtained by the transparent proxy server. The following describes the second proxy relationship obtained by the transparent proxy server:
- a method for processing a packet according to Embodiment 5 of the present invention includes:
- the transparent proxy server obtains a handshake message sent by the user to the WEB server, where the IP address in the handshake message is an IP address of the WEB server.
- the transparent proxy server works in a transparent proxy mode, and the transparent proxy server is deployed between the client and the WEB server, and is a proxy server that is not perceived by the client and the WEB server, and the client and the WEB server.
- the data packets generated during the interaction will pass through the transparent proxy server, for example, in the PCC architecture, and the transparent proxy server is PCEF/TDF.
- the handshake message generated between the user end and the WEB server passes through the transparent proxy server, and the transparent proxy server can obtain the handshake message and identify the handshake message.
- the destination IP address in the handshake packet for example, in the TCP/IP protocol.
- the three-way handshake is used to establish a connection.
- the user sends a synchronous (syn) handshake message to the WEB server.
- the transparent proxy server can obtain the syn handshake packet.
- the transparent proxy server can identify the destination IP address in the syn handshake message.
- the user terminal may be a mobile terminal such as a mobile phone or a tablet computer, or a device that can access the network, such as a notebook computer, and is not limited herein.
- steps 502, 503, and 504 are further included.
- the transparent proxy server acquires a correspondence between a domain name of the WEB server and an IP address of the WEB server.
- the client before the user sends a service packet to the WEB server, the client usually sends the domain name of the WEB server to the DNS server for domain name resolution. After the DNS server is parsed, the user is sent to the user through the transparent proxy server. The end-feedback includes the query result of the IP address of the WEB server. At this time, the transparent proxy server may determine the domain name of the WEB server and the WEB server according to the query result fed back by the DNS server and the domain name sent by the client. Correspondence of IP addresses.
- the transparent proxy server acquires a domain name of the target WEB server.
- the manner in which the transparent proxy server obtains the domain name of the target WEB server includes at least the following two types:
- the transparent proxy server determines the IP address of the target WEB server, and determines the domain name of the target WEB server according to the IP address of the target WEB server, and saves the domain name of the target WEB server.
- the manner in which the transparent proxy server determines the IP address of the target WEB server is specifically: the transparent proxy server records the number of times the user sends a service packet to the WEB server, and The destination IP address in the service packet with the highest number of times of transmission is used as the IP address of the target WEB server. For example, the transparent proxy server records the first number and the first time that the user sends the first service packet to the first WEB server.
- the second number of times that the second WEB server sends the second service packet if the first number of times is greater than the second number of times, and the first number of times is greater than or equal to the sum of the first number of times and the second number of times 90%, the first destination IP address in the first service packet is used as the IP address of the target WEB server.
- the transparent proxy server may directly send the obtained client.
- the IP address in the service message, as the IP address of the target WEB server, or the transparent proxy server can be determined by other means.
- the IP address of the target WEB server is not limited herein.
- the transparent proxy server determines that the service number of the client is greater than or equal to 90%, and the destination IP address in the service packet is the IP address of the target WEB server, that is, The frequency of the IP address of the target WEB server is high, and the domain name of the target WEB server is determined according to the correspondence between the IP address of the server and the domain name of the server, that is, the domain name of the target WEB server is used by the client.
- the high frequency and the corresponding relationship of the VAS server can improve the success rate of determining the target VAS server.
- the ratio of the first number of times to the sum of the first number of times and the second number of times may be set according to actual needs, and the preset ratio in this embodiment is 90%, specifically Not limited.
- the manner in which the transparent proxy server determines the domain name of the target WEB server according to the IP address of the target WEB server is specifically: the transparent proxy server according to the IP address of the target WEB server and the domain name of the WEB server The mapping of the IP address of the WEB server determines the domain name of the target WEB server.
- the transparent proxy server may be determined according to other manners, which is not limited herein.
- the transparent proxy server performs the number of times of parsing according to the domain name of the WEB server by the client, and uses the domain name with a high proportion of domain name resolution as the domain name of the target server.
- the transparent proxy server determines a first number of times the client uses the domain name of the first WEB server for parsing and a second number of times that the domain name of the second WEB server is used for parsing, if the first number of times When the first number of times is greater than or equal to a preset ratio of the sum of the first number and the second number, the domain name of the first WEB server is used as the embodiment of the present invention.
- the transparent proxy server uses the domain name with the proportion of the number of domain name resolutions greater than or equal to 90% as the domain name of the target WEB server, that is, the domain name of the target WEB server used by the client is high, so according to the target server
- the correspondence between the domain name and the VAS server can improve the success rate of determining the target VAS server.
- the proportion of the number of times of domain name resolution can be set according to actual needs, and the proportion of the number of domain name resolutions in this embodiment is 90%, which is not limited herein.
- the transparent proxy server acquires a correspondence between a VAS server and a domain name of the preset target WEB server.
- the transparent proxy server when the transparent proxy server obtains the service packet sent by the client to the WEB server, the transparent proxy server can analyze the destination IP address of the service packet by using the DPI, and the proxy server can Determining the destination IP address and the first correspondence Determining the domain name of the WEB server, and tracking the VAS server through which the data packet passes, the transparent proxy server generating the corresponding according to the IP address of the target WEB server and the VAS server through which the data packet passes Relationship and save the correspondence.
- the corresponding relationship may be obtained by the transparent proxy server, or may be configured in the transparent proxy server after the other device obtains the corresponding relationship, which is not limited herein.
- the transparent proxy server determines a domain name of the WEB server according to the destination IP address of the handshake packet and the first correspondence.
- the transparent proxy server is capable of parsing the destination IP address in the handshake packet, and determining the domain name of the WEB server according to the correspondence between the obtained domain name of the WEB server and the IP address of the WEB server.
- step 506. Determine whether the domain name of the WEB server is the domain name of the preset target WEB server. If yes, go to step 507. If yes, go to step 508.
- the transparent proxy server can compare the domain name of the WEB server with the domain name of the target WEB service, so as to determine whether the domain name of the WEB server is the domain name of the preset target WEB server.
- the transparent proxy server establishes a connection between the client and the WEB server.
- the transparent proxy server determines, according to the destination IP address and the corresponding relationship, a target VAS server, where the correspondence relationship is a correspondence between the VAS server and an IP address of the target WEB server.
- the target VAS server is determined according to the correspondence between the VAS server and the IP address of the target WEB server.
- the transparent proxy server constructs a connection between the user end, the VAS server, and the target WEB server, where the target VAS server is configured to process data exchanged between the user end and the WEB server. Message.
- 509 in this embodiment may adopt the same method as that in Embodiment 2, and details are not described herein again.
- the transparent proxy server determines the domain name of the WEB server corresponding to the destination IP address of the data packet according to the IP address of the WEB server and the first correspondence, and determines that the domain name of the WEB server is a preset target.
- the VAS server is determined according to the domain name and the second correspondence relationship of the WEB server, thereby shortening the transparent proxy server determination.
- the duration of the target VAS server enables the service packets to be processed by the VAS server in time to improve the user experience.
- the transparent proxy server provided in Embodiment 6 of the present invention includes:
- the obtaining unit 601 is configured to obtain a handshake message sent by the UE to the WEB server.
- the obtaining unit 601 is further configured to acquire an IP address of the target WEB server.
- the manner in which the obtaining unit 601 obtains the IP address of the target WEB server includes at least the following two types:
- the obtaining unit 601 determines the domain name of the target WEB server, determines the IP address of the target WEB server according to the domain name of the target WEB server, and then saves the IP address of the target WEB server.
- the obtaining unit 601 determines the domain name of the target WEB server, which may be determined by determining the first time that the user end uses the domain name of the first WEB server for parsing and the domain name of using the second WEB server. The second number of times, the first number of times is greater than the second number, and if the first number of times is greater than or equal to a preset ratio of the sum of the first number and the second number, determining the first
- the domain name of a WEB server is the domain name of the target WEB server.
- the preset ratio is the sum of the number and the second number
- the first destination IP address is determined to be the IP address of the target WEB server, and then the IP address of the target WEB server is saved.
- the obtaining unit 601 is further configured to acquire the correspondence.
- the determining unit 602 is configured to determine, according to the destination IP address and the corresponding relationship, a target VAS server, when the destination IP address in the handshake message is an IP address of a preset target WEB server, where the corresponding relationship is Correspondence between the VAS server and the IP address of the target WEB server.
- a building unit 603 configured to construct a connection between the user end, the target VAS server, and the WEB server, where the target VAS server is configured to process a service report between the user end and the WEB server. Text.
- the transparent proxy server passes the IP address and the IP address of the preset target WEB server. Match the destination IP address obtained in the handshake packet, and determine the target VAS server by using the mapping between the IP address of the preset target WEB server and the VAS server.
- the transparent proxy server can also be preset. The correspondence between the domain name of the target WEB server and the VAS server, thereby determining the target VAS server.
- Embodiment 7 of the present invention which specifically includes:
- the obtaining unit 601 is configured to obtain a handshake message sent by the UE to the WEB server, where the destination IP address in the handshake message is an IP address of the WEB server.
- the obtaining unit 601 is further configured to acquire a domain name of the target server.
- the manner in which the obtaining unit 601 is further configured to acquire the domain name of the target server includes at least the following two types:
- the obtaining unit 601 determines the domain name of the target WEB server according to the IP address of the target WEB server, and saves the domain name of the target WEB server according to the IP address of the target WEB server.
- the obtaining unit 601 determines that the IP address of the target WEB server may be sent to the second WEB server by determining the first time that the user sends the first service packet to the first WEB server.
- the second number of times of the second service packet the first number of times is greater than the second number, the first service packet includes a first destination IP address, and the second service packet includes a second destination IP address;
- the first number of times is greater than or equal to a preset ratio of the sum of the first number and the second number, determining that the first destination IP address is an IP address of the target WEB server.
- the obtaining unit 601 may determine the first number of times that the user end uses the domain name of the first WEB server for parsing and the second time that is parsed by using the domain name of the second WEB server, where the first number of times is greater than a second number of times; if the first number of times is greater than or equal to a preset ratio of the sum of the first number of times and the second number of times, determining that the domain name of the first WEB server is the domain name of the target WEB server And then save the domain name of the target WEB server.
- the obtaining unit 601 is further configured to acquire the first correspondence.
- the obtaining unit 601 is further configured to acquire the second correspondence.
- the determining unit 602 is configured to determine a domain name of the WEB server according to the destination IP address and the first correspondence, where the first correspondence is a correspondence between a domain name of the WEB server and an IP address of the WEB server;
- the determining unit 602 is further configured to: when determining that the domain name of the WEB server is a preset target Determining, by the domain name of the WEB server, the target VAS server according to the domain name and the second correspondence of the WEB server, where the second correspondence is a correspondence between the VAS server and the domain name of the preset target WEB server;
- a building unit 603 configured to construct a connection between the user end, the target VAS server, and the WEB server, where the target VAS server is configured to process a service report between the user end and the WEB server. Text.
- the transparent proxy server obtains the destination IP address in the handshake packet through the obtaining unit 601, and when the determining unit 602 determines that the destination IP address is the IP address of the WEB server, according to the IP address of the WEB server.
- the first corresponding relationship determines the domain name of the WEB server corresponding to the destination IP address of the data packet, and when determining that the domain name of the WEB server is the domain name of the preset target WEB server, according to the domain name and the second domain of the WEB server
- the VAS server is determined, and the connection between the client, the target VAS server and the WEB server is constructed by using the constructing unit 603, so that the VAS server processes between the client and the WEB server.
- the service packets are exchanged, so that the length of the target VAS server is determined by the transparent proxy server, so that the service packets are processed by the VAS server in time to improve the user experience.
- FIG. 7 is a transparent proxy server according to Embodiment 8 of the present invention.
- the transparent proxy server 700 may include:
- the processor 701, the memory 702, and the communication interface 705 are connected by a bus 704 and complete communication with each other.
- Processor 701 may be a single core or multi-core central processing unit, or a particular integrated circuit, or one or more integrated circuits configured to implement embodiments of the present invention.
- the memory 702 may be a high speed RAM memory or a non-volatile memory such as at least one disk memory.
- Memory 702 is used by computer to execute instructions 703.
- the computer execution instructions 703 may include program code.
- the processor 701 runs the computer execution instruction 703, and can execute the message processing method described in the method embodiment corresponding to any one of FIG. 1 to FIG.
- the disclosed system, device and method The law can be implemented in other ways.
- the device embodiments described above are merely illustrative.
- the division of the unit is only a logical function division.
- there may be another division manner for example, multiple units or components may be combined or Can be integrated into another system, or some features can be ignored or not executed.
- the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, and may be in an electrical, mechanical or other form.
- the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of the embodiment.
- each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
- the above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
- the integrated unit if implemented in the form of a software functional unit and sold or used as a standalone product, may be stored in a computer readable storage medium.
- the technical solution of the present invention which is essential or contributes to the prior art, or all or part of the technical solution, may be embodied in the form of a software product stored in a storage medium.
- a number of instructions are included to cause a computer device (which may be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present invention.
- the foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and the like. .
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Abstract
Disclosed in an embodiment of the present invention is a packet processing method for shortening a duration of the time taken by a transparent proxy server to determine a VAS server, such that a service packet from the interaction between a user terminal and a WEB server is processed in time by the VAS server, thus improving user experience. The method comprises: the transparent proxy server acquires a handshake packet transmitted by the user terminal to the WEB server; when a target IP address of the handshake packet is determined to be an IP address of a preset target WEB server, the transparent proxy server determines a service type of a target service request packet according to a first corresponding relationship of the target IP address, the first corresponding relationship being a corresponding relationship between the VAS server and the IP address of the target WEB server. Also provided in the embodiment of the present invention is a transparent proxy server for shortening a duration of the time taken by the transparent proxy server to determine the VAS server, such that the service packet from the interaction between a user terminal and a WEB server is processed in time by the VAS server, thus improving user experience.
Description
本申请要求于2014年12月04日提交中国专利局、申请号为201410733682.7、发明名称为“一种报文处理的方法和透明代理服务器”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。This application claims priority to Chinese Patent Application No. 201410733682.7, entitled "Method for Processing Messages and Transparent Proxy Server", filed on December 4, 2014, the entire contents of which are incorporated by reference. In this application.
本发明涉及通信技术领域,尤其涉及一种报文处理的方法以及透明代理服务器。The present invention relates to the field of communications technologies, and in particular, to a packet processing method and a transparent proxy server.
随着网络的发展,运营商开始为用户端提供增值服务。举例来说,典型的增值服务包括:病毒过滤、页面适配、视频优化等。不同的增值业务服务器(Value Added Server,VAS)提供不同业务类型的增值服务。With the development of the network, operators began to provide value-added services to the client. For example, typical value-added services include: virus filtering, page adaptation, video optimization, and the like. Different Value Added Servers (VAS) provide value-added services for different types of services.
在策略计费控制(Policy and Charging Control,PCC)架构中,透明代理服务器位于用户端与目的万维网(World Wide Web,WEB)服务器之间,用户端向域名服务器(Domain Name System,DNS)发起域名解析请求,以获取WEB服务器的IP地址,该透明代理服务器构建该用户端和该WEB服务器之间的连接,该用户端将该WEB服务的IP地址作为目的IP地址向该WEB服务器发送业务报文,该透明代理服务器通过深度数据包检测(Deep Packet Inspection,DPI)识别出该业务报文的业务类型,并根据该业务类型确定用于处理该业务报文的VAS服务器,然后该透明代理服务器断开该用户端与WEB服务器之间的连接,并建立用户端和该VAS服务器之间的连接,以及该VAS服务器和WEB服务器之间的连接,以使该VAS服务器处理该用户端与该WEB服务器之间的交互的业务报文,从而实现为用户端提供相应的增值服务。In the Policy and Charging Control (PCC) architecture, the transparent proxy server is located between the client and the World Wide Web (WEB) server, and the client initiates the domain name to the Domain Name System (DNS). Parsing the request to obtain the IP address of the WEB server, the transparent proxy server constructs a connection between the client and the WEB server, and the client sends the service packet to the WEB server by using the IP address of the WEB service as the destination IP address. The transparent proxy server identifies the service type of the service packet by using deep packet inspection (DPI), and determines a VAS server for processing the service packet according to the service type, and then the transparent proxy server is disconnected. Opening a connection between the client and the WEB server, establishing a connection between the client and the VAS server, and a connection between the VAS server and the WEB server, so that the VAS server processes the client and the WEB server The interaction between the business messages, thereby providing the corresponding value-added services for the client.
然而,现有技术中,透明代理服务器需要在用户端与WEB服务器之间建立连接之后,通过DPI对用户端发送的业务报文进行识别,才能确定VAS服务器,使数据报文无法及时得到VAS服务器的处理,影响用户体验。However, in the prior art, after the connection between the client and the WEB server is established, the transparent proxy server needs to identify the service packet sent by the user through the DPI to determine the VAS server, so that the data packet cannot be obtained in time. Processing affects the user experience.
发明内容Summary of the invention
本发明实施例提供了一种报文处理的方法,可起到缩短该透明代理服务器确定VAS服务器的时长,使用户端与该WEB服务器交互的业务报文及时得到该VAS服务器的处理,提升用户体验。
The embodiment of the invention provides a method for processing a message, which can shorten the length of time for the transparent proxy server to determine the VAS server, and enable the service packet exchanged between the user and the WEB server to obtain the processing of the VAS server in time, and improve the user. Experience.
本发明实施例第一方面提供一种报文处理的方法,包括:A first aspect of the embodiments of the present invention provides a packet processing method, including:
透明代理服务器获取用户端向WEB服务器发送的握手报文;The transparent proxy server obtains the handshake message sent by the client to the WEB server.
当确定所述握手报文中的目的IP地址为预置的目标WEB服务器的IP地址时,所述透明代理服务器根据所述目的IP地址和对应关系,确定目标VAS服务器,所述对应关系为VAS服务器与所述目标WEB服务器的IP地址的对应关系;When it is determined that the destination IP address in the handshake message is the IP address of the preset target WEB server, the transparent proxy server determines the target VAS server according to the destination IP address and the corresponding relationship, and the corresponding relationship is VAS. Correspondence between the server and the IP address of the target WEB server;
所述透明代理服务器构建所述用户端、所述目标VAS服务器和所述WEB服务器之间的连接,所述目标VAS服务器用于处理所述用户端与所述WEB服务器之间交互的业务报文。The transparent proxy server constructs a connection between the user end, the target VAS server, and the WEB server, where the target VAS server is configured to process a service packet exchanged between the user end and the WEB server. .
结合本发明实施例的第一方面,在本发明实施例第一方面的第一种实现方式中,在所述透明代理服务器确定所述握手报文的目的IP地址为预置的目标WEB服务器的IP地址之前还包括:所述透明代理服务器获取所述目标WEB服务器的IP地址。With reference to the first aspect of the embodiments of the present invention, in a first implementation manner of the first aspect of the embodiments, the transparent proxy server determines that the destination IP address of the handshake packet is a preset target WEB server. The IP address further includes: the transparent proxy server acquiring an IP address of the target WEB server.
结合本发明实施例的第一方面的第一种实现方式,在本发明实施例第一方面的第二种实现方式中,所述透明代理服务器获取所述目标WEB服务器的IP地址包括:With reference to the first implementation manner of the first aspect of the embodiment of the present invention, in the second implementation manner of the first aspect of the embodiment, the transparent proxy server acquiring the IP address of the target WEB server includes:
所述透明代理服务器确定所述目标WEB服务器的域名;Determining, by the transparent proxy server, a domain name of the target WEB server;
所述透明代理服务器根据所述目标WEB服务器的域名,确定所述目标WEB服务器的IP地址;Determining, by the transparent proxy server, an IP address of the target WEB server according to the domain name of the target WEB server;
所述透明代理服务器保存所述目标WEB服务器的IP地址。The transparent proxy server saves the IP address of the target WEB server.
结合本发明实施例的第一方面的第二种实现方式,在本发明实施例第一方面的第三种实现方式中,所述透明代理服务器确定目标WEB服务器的域名包括:With reference to the second implementation manner of the first aspect of the embodiment of the present invention, in the third implementation manner of the first aspect of the embodiment, the transparent proxy server determines that the domain name of the target WEB server includes:
所述透明代理服务器确定所述用户端使用第一WEB服务器的域名进行解析的第一次数和使用第二WEB服务器的域名进行解析的第二次数,所述第一次数大于第二次数;Determining, by the transparent proxy server, a first number of times that the user end uses the domain name of the first WEB server for parsing and a second time that is parsed by using the domain name of the second WEB server, where the first number of times is greater than the second number of times;
若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一WEB服务器的域名为所述目标WEB服务器的域名。If the first number of times is greater than or equal to a preset ratio of the sum of the first number of times and the second number of times, determining that the domain name of the first WEB server is the domain name of the target WEB server.
结合本发明实施例的第一方面的第一种实现方式,在本发明实施例第一方面的第四种实现方式中,所述透明代理服务器获取所述目标WEB服务器的IP地址包括:
With reference to the first implementation manner of the first aspect of the embodiment of the present invention, in the fourth implementation manner of the first aspect of the embodiment, the obtaining, by the transparent proxy server, the IP address of the target WEB server includes:
所述透明代理服务器确定所述用户端向第一WEB服务器发送第一业务报文的第一次数和向第二WEB服务器发送第二业务报文的第二次数,所述第一次数大于第二次数,所述第一业务报文包括第一目的IP地址,所述第二业务报文包括第二目的IP地址;The transparent proxy server determines a first number of times that the user sends the first service packet to the first web server, and a second number of times that the second service packet is sent to the second web server, where the first number of times is greater than The second service packet includes a first destination IP address, and the second service packet includes a second destination IP address.
若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一目的IP地址为所述目标WEB服务器的IP地址;If the first number of times is greater than or equal to a preset ratio of the sum of the first number of times and the second number of times, determining that the first destination IP address is an IP address of the target WEB server;
所述透明代理服务器保存所述目标WEB服务器的IP地址。The transparent proxy server saves the IP address of the target WEB server.
结合本发明实施例的第一方面或第一方面的第一种实现方式或第一方面的第二种实现方式或第一方面的第三种实现方式或第一方面的第四种实现方式,在本发明实施例第一方面的第五种实现方式中,所述透明代理服务器根据所述目的IP地址和对应关系,确定目标VAS服务器之前还包括:所述透明代理服务器获取所述对应关系。With reference to the first aspect of the embodiments of the present invention or the first implementation of the first aspect or the second implementation of the first aspect or the third implementation of the first aspect or the fourth implementation of the first aspect, In a fifth implementation manner of the first aspect of the embodiments of the present disclosure, the determining, by the transparent proxy server, the target VAS server further includes: the transparent proxy server acquiring the corresponding relationship according to the destination IP address and the corresponding relationship.
本发明实施例第二方面提供一种报文处理的方法,包括:A second aspect of the embodiments of the present invention provides a packet processing method, including:
透明代理服务器获取用户端向WEB服务器发送的握手报文,所述握手报文中的目的IP地址为所述WEB服务器的IP地址;The transparent proxy server obtains the handshake message sent by the user to the WEB server, where the destination IP address in the handshake message is the IP address of the WEB server;
所述透明代理服务器根据所述目的IP地址和第一对应关系,确定所述WEB服务器的域名,所述第一对应关系为WEB服务器的域名与WEB服务器的IP地址的对应关系;Determining, by the transparent proxy server, the domain name of the WEB server according to the destination IP address and the first correspondence, where the first correspondence is a correspondence between a domain name of the WEB server and an IP address of the WEB server;
当确定所述WEB服务器的域名为预置的目标WEB服务器的域名时,所述透明代理服务器根据所述WEB服务器的域名和第二对应关系,确定目标VAS服务器,所述第二对应关系为VAS服务器与所述预置的目标WEB服务器的域名的对应关系;When the domain name of the WEB server is determined to be the domain name of the preset target WEB server, the transparent proxy server determines the target VAS server according to the domain name and the second correspondence of the WEB server, and the second correspondence is VAS. Correspondence between the server and the domain name of the preset target WEB server;
所述透明代理服务器构建所述用户端、所述目标VAS服务器和所述WEB服务器之间的连接,所述目标VAS服务器用于处理所述用户端与所述WEB服务器之间交互的业务报文。The transparent proxy server constructs a connection between the user end, the target VAS server, and the WEB server, where the target VAS server is configured to process a service packet exchanged between the user end and the WEB server. .
结合本发明实施例的第二方面,在本发明实施例第二方面的第一种实现方式中,在所述透明代理服务器确定所述WEB服务器的域名为预置的目标WEB服务器的域名之前还包括:所述透明代理服务器获取所述目标服务器的域名。With reference to the second aspect of the embodiments of the present invention, in a first implementation manner of the second aspect of the embodiment of the present invention, before the transparent proxy server determines that the domain name of the WEB server is the domain name of the preset target WEB server, The method includes: the transparent proxy server acquiring a domain name of the target server.
结合本发明实施例的第二方面的第一种实现方式,在本发明实施例第二方面的第二种实现方式中,所述透明代理服务器获取所述目标WEB服务器的域名包括:
With reference to the first implementation manner of the second aspect of the embodiment of the present invention, in the second implementation manner of the second aspect of the embodiment of the present disclosure, the obtaining, by the transparent proxy server, the domain name of the target WEB server includes:
所述透明代理服务器确定所述目标WEB服务器的IP地址;The transparent proxy server determines an IP address of the target WEB server;
所述透明代理服务器根据所述目标WEB服务器的IP地址,确定所述目标WEB服务器的域名;Determining, by the transparent proxy server, a domain name of the target WEB server according to an IP address of the target WEB server;
所述透明代理服务器保存所述目标WEB服务器的域名。The transparent proxy server saves the domain name of the target WEB server.
结合本发明实施例的第二方面的第二种实现方式,在本发明实施例第二方面的第三种实现方式中,所述透明代理服务器确定所述目标WEB服务器的IP地址包括:With reference to the second implementation manner of the second aspect of the embodiment of the present invention, in a third implementation manner of the second aspect of the embodiment, the transparent proxy server determines that the IP address of the target WEB server includes:
所述透明代理服务器确定所述用户端向第一WEB服务器发送第一业务报文的第一次数和向第二WEB服务器发送第二业务报文的第二次数,所述第一次数大于第二次数,所述第一业务报文包括第一目的IP地址,所述第二业务报文包括第二目的IP地址;The transparent proxy server determines a first number of times that the user sends the first service packet to the first web server, and a second number of times that the second service packet is sent to the second web server, where the first number of times is greater than The second service packet includes a first destination IP address, and the second service packet includes a second destination IP address.
若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一目的IP地址为所述目标WEB服务器的IP地址。And determining, when the first number of times is greater than or equal to a preset ratio of the sum of the first number and the second number, determining that the first destination IP address is an IP address of the target WEB server.
结合本发明实施例的第二方面的第一种实现方式,在本发明实施例第二方面的第四种实现方式中,所述透明代理服务器获取所述目标WEB服务器的域名包括:With reference to the first implementation manner of the second aspect of the embodiment of the present invention, in a fourth implementation manner of the second aspect of the embodiment of the present disclosure, the obtaining, by the transparent proxy server, the domain name of the target WEB server includes:
所述透明代理服务器确定所述用户端使用第一WEB服务器的域名进行解析的第一次数和使用第二WEB服务器的域名进行解析的第二次数,所述第一次数大于第二次数;Determining, by the transparent proxy server, a first number of times that the user end uses the domain name of the first WEB server for parsing and a second time that is parsed by using the domain name of the second WEB server, where the first number of times is greater than the second number of times;
若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一WEB服务器的域名为所述目标WEB服务器的域名;If the first number of times is greater than or equal to a preset ratio of the sum of the first number of times and the second number of times, determining that the domain name of the first WEB server is the domain name of the target WEB server;
所述透明代理服务器保存所述目标WEB服务器的域名。The transparent proxy server saves the domain name of the target WEB server.
结合本发明实施例的第二方面或第二方面的第一种实现方式或第二方面的第二种实现方式或第二方面的第三种实现方式或第二方面的第四种实现方式,在本发明实施例第二方面的第五种实现方式中,在所述透明代理服务器根据所述目的IP地址和第一对应关系,确定WEB服务器的域名之前还包括:所述透明代理服务器获取所述第一对应关系。The second implementation of the second aspect or the second aspect of the embodiment of the present invention or the second implementation manner of the second aspect or the third implementation manner of the second aspect or the fourth implementation manner of the second aspect, In a fifth implementation manner of the second aspect of the embodiment of the present invention, before the transparent proxy server determines the domain name of the WEB server according to the destination IP address and the first correspondence, the transparent proxy server further includes: the transparent proxy server acquiring the location The first correspondence is described.
结合本发明实施例的第二方面或第二方面的第一种实现方式或第二方面的第二种实现方式或第二方面的第三种实现方式或第二方面的第四种实现方式,在本发明实施例第二方面的第六种实现方式中,在所述透明代理服务器根据所述WEB服务器的域名和第二对应关系,确定目标VAS服务器之前还包括:所
述透明代理服务器获取所述第二对应关系。The second implementation of the second aspect or the second aspect of the embodiment of the present invention or the second implementation manner of the second aspect or the third implementation manner of the second aspect or the fourth implementation manner of the second aspect, In a sixth implementation manner of the second aspect of the embodiment, the transparent proxy server further includes: before the target VAS server is determined according to the domain name and the second correspondence of the WEB server.
The transparent proxy server acquires the second correspondence.
本发明实施例第三方面提供一种透明代理服务器,包括:A third aspect of the embodiments of the present invention provides a transparent proxy server, including:
获取单元,用于获取用户端向WEB服务器发送的握手报文;An obtaining unit, configured to obtain a handshake message sent by the client to the WEB server;
确定单元,用于当确定所述握手报文中的目的IP地址为预置的目标WEB服务器的IP地址时,根据所述目的IP地址和对应关系,确定目标VAS服务器,所述对应关系为VAS服务器与所述目标WEB服务器的IP地址的对应关系;a determining unit, configured to determine a target VAS server according to the destination IP address and the corresponding relationship when determining that the destination IP address in the handshake packet is an IP address of a preset target WEB server, where the correspondence is VAS Correspondence between the server and the IP address of the target WEB server;
构建单元,用于构建所述用户端、所述目标VAS服务器和所述WEB服务器之间的连接,所述目标VAS服务器用于处理所述用户端与所述WEB服务器之间交互的业务报文。a building unit, configured to construct a connection between the user end, the target VAS server, and the WEB server, where the target VAS server is configured to process a service packet exchanged between the user end and the WEB server .
结合本发明实施例的第三方面,在本发明实施例第三方面的第一种实现方式中,所述获取单元还用于获取所述目标WEB服务器的IP地址。With reference to the third aspect of the embodiments of the present invention, in a first implementation manner of the third aspect, the acquiring unit is further configured to acquire an IP address of the target WEB server.
结合本发明实施例的第三方面的第一种实现方式,在本发明实施例第三方面的第二种实现方式中,所述获取单元具体用于确定所述目标WEB服务器的域名;With reference to the first implementation manner of the third aspect of the embodiment of the present invention, in a second implementation manner of the third aspect of the embodiment, the acquiring unit is specifically configured to determine a domain name of the target WEB server;
根据所述目标WEB服务器的域名,确定所述目标WEB服务器的IP地址;Determining an IP address of the target WEB server according to the domain name of the target WEB server;
保存所述目标WEB服务器的IP地址。Save the IP address of the target WEB server.
结合本发明实施例的第三方面的第二种实现方式,在本发明实施例第三方面的第三种实现方式中,所述获取单元具体用于确定所述用户端使用第一WEB服务器的域名进行解析的第一次数和使用第二WEB服务器的域名进行解析的第二次数,所述第一次数大于第二次数;With reference to the second implementation manner of the third aspect of the embodiment of the present invention, in a third implementation manner of the third aspect of the embodiment, the acquiring unit is specifically configured to determine that the user end uses the first WEB server. The first number of times the domain name is parsed and the second number of times the domain name of the second WEB server is used for parsing, the first number of times being greater than the second number of times;
若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一WEB服务器的域名为所述目标WEB服务器的域名。If the first number of times is greater than or equal to a preset ratio of the sum of the first number of times and the second number of times, determining that the domain name of the first WEB server is the domain name of the target WEB server.
结合本发明实施例的第三方面的第一种实现方式,在本发明实施例第三方面的第四种实现方式中,所述获取单元具体用于确定所述用户端向第一WEB服务器发送第一业务报文的第一次数和向第二WEB服务器发送第二业务报文的第二次数,所述第一次数大于第二次数,所述第一业务报文包括第一目的IP地址,所述第二业务报文包括第二目的IP地址;With reference to the first implementation manner of the third aspect of the embodiment of the present invention, in a fourth implementation manner of the third aspect of the embodiment, the acquiring unit is specifically configured to determine that the user end sends the information to the first WEB server. The first number of times of the first service packet and the second number of times the second service packet is sent to the second WEB server, where the first number of times is greater than the second number of times, and the first service packet includes the first destination IP address An address, where the second service packet includes a second destination IP address;
若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一目的IP地址为所述目标WEB服务器的IP地址,保存所述目标WEB服务器的IP地址。If the first number of times is greater than or equal to a preset ratio of the sum of the first number of times and the second number of times, determining that the first destination IP address is an IP address of the target WEB server, and saving the The IP address of the target WEB server.
结合本发明实施例的第三方面或第三方面的第一种实现方式或第三方面的
第二种实现方式或第三方面的第三种实现方式或第三方面的第四种实现方式,在本发明实施例第三方面的第五种实现方式中,所述获取单元还用于获取所述对应关系。Combining the third or third aspect of the embodiments of the present invention with the first implementation or the third aspect
The second implementation manner, or the third implementation manner of the third aspect, or the fourth implementation manner of the third aspect, in the fifth implementation manner of the third aspect of the embodiment, the acquiring unit is further configured to obtain The corresponding relationship.
本发明实施例第四方面提供一种透明代理服务器,包括:A fourth aspect of the embodiments of the present invention provides a transparent proxy server, including:
获取单元,用于获取用户端向WEB服务器发送的握手报文,所述握手报文中的目的IP地址为所述WEB服务器的IP地址;An obtaining unit, configured to obtain a handshake message sent by the user to the WEB server, where the destination IP address in the handshake message is an IP address of the WEB server;
确定单元,用于根据所述目的IP地址和第一对应关系,确定所述WEB服务器的域名,所述第一对应关系为WEB服务器的域名与WEB服务器的IP地址的对应关系;a determining unit, configured to determine a domain name of the WEB server according to the destination IP address and the first correspondence, where the first correspondence is a correspondence between a domain name of the WEB server and an IP address of the WEB server;
所述确定单元,还用于当确定所述WEB服务器的域名为预置的目标WEB服务器的域名时,根据所述WEB服务器的域名和第二对应关系,确定目标VAS服务器,所述第二对应关系为VAS服务器与所述预置的目标WEB服务器的域名的对应关系;The determining unit is further configured to: when determining that the domain name of the WEB server is the domain name of the preset target WEB server, determine the target VAS server according to the domain name and the second correspondence of the WEB server, and the second corresponding The relationship is a correspondence between the VAS server and the domain name of the preset target WEB server;
构建单元,用于构建所述用户端、所述目标VAS服务器和所述WEB服务器之间的连接,所述目标VAS服务器用于处理所述用户端与所述WEB服务器之间交互的业务报文。a building unit, configured to construct a connection between the user end, the target VAS server, and the WEB server, where the target VAS server is configured to process a service packet exchanged between the user end and the WEB server .
结合本发明实施例的第四方面,在本发明实施例第四方面的第一种实现方式中,所述获取单元,还用于获取所述目标服务器的域名。With reference to the fourth aspect of the embodiments of the present invention, in a first implementation manner of the fourth aspect, the acquiring unit is further configured to acquire a domain name of the target server.
结合本发明实施例的第四方面的第一种实现方式,在本发明实施例第四方面的第二种实现方式中,所述获取单元具体用于确定所述目标WEB服务器的IP地址;With reference to the first implementation manner of the fourth aspect of the embodiment of the present invention, in a second implementation manner of the fourth aspect of the embodiment, the acquiring unit is specifically configured to determine an IP address of the target WEB server;
根据所述目标WEB服务器的IP地址,确定所述目标WEB服务器的域名;Determining, according to an IP address of the target WEB server, a domain name of the target WEB server;
保存所述目标WEB服务器的域名。Save the domain name of the target WEB server.
结合本发明实施例的第四方面的第二种实现方式,在本发明实施例第四方面的第三种实现方式中,所述获取单元具体用于确定所述用户端向第一WEB服务器发送第一业务报文的第一次数和向第二WEB服务器发送第二业务报文的第二次数,所述第一次数大于第二次数,所述第一业务报文包括第一目的IP地址,所述第二业务报文包括第二目的IP地址;With reference to the second implementation manner of the fourth aspect of the embodiments of the present invention, in a third implementation manner of the fourth aspect of the embodiments, the acquiring unit is specifically configured to determine that the user end sends the information to the first WEB server. The first number of times of the first service packet and the second number of times the second service packet is sent to the second WEB server, where the first number of times is greater than the second number of times, and the first service packet includes the first destination IP address An address, where the second service packet includes a second destination IP address;
若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一目的IP地址为所述目标WEB服务器的IP地址。And determining, when the first number of times is greater than or equal to a preset ratio of the sum of the first number and the second number, determining that the first destination IP address is an IP address of the target WEB server.
结合本发明实施例的第四方面的第一种实现方式,在本发明实施例第四方
面的第四种实现方式中,所述获取单元具体用于确定所述用户端使用第一WEB服务器的域名进行解析的第一次数和使用第二WEB服务器的域名进行解析的第二次数,所述第一次数大于第二次数;In conjunction with the first implementation of the fourth aspect of the embodiments of the present invention, in the fourth aspect of the embodiment of the present invention
In a fourth implementation manner, the obtaining unit is specifically configured to determine a first number of times that the user end uses the domain name of the first WEB server for parsing, and a second number that is parsed by using the domain name of the second WEB server, The first number of times is greater than the second number of times;
若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一WEB服务器的域名为所述目标WEB服务器的域名;If the first number of times is greater than or equal to a preset ratio of the sum of the first number of times and the second number of times, determining that the domain name of the first WEB server is the domain name of the target WEB server;
保存所述目标WEB服务器的域名。Save the domain name of the target WEB server.
结合本发明实施例的第四方面或第四方面的第一种实现方式或第四方面的第二种实现方式或第四方面的第三种实现方式或第四方面的第四种实现方式,在本发明实施例第四方面的第五种实现方式中,所述获取单元还用于所述第一对应关系。With reference to the fourth aspect of the embodiment of the present invention or the first implementation manner of the fourth aspect or the second implementation manner of the fourth aspect, or the third implementation manner of the fourth aspect, or the fourth implementation manner of the fourth aspect, In a fifth implementation manner of the fourth aspect of the embodiment, the acquiring unit is further configured to use the first correspondence.
结合本发明实施例的第四方面或第四方面的第一种实现方式或第四方面的第二种实现方式或第四方面的第三种实现方式或第四方面的第四种实现方式,在本发明实施例第四方面的第六种实现方式中,所述获取单元还用于获取所述第二对应关系。With reference to the fourth aspect of the embodiment of the present invention or the first implementation manner of the fourth aspect or the second implementation manner of the fourth aspect, or the third implementation manner of the fourth aspect, or the fourth implementation manner of the fourth aspect, In a sixth implementation manner of the fourth aspect of the embodiment, the acquiring unit is further configured to acquire the second correspondence.
本发明实施例第五方面提供一种透明代理服务器,包括处理器、存储器、总线和通信接口;A fifth aspect of the embodiments of the present invention provides a transparent proxy server, including a processor, a memory, a bus, and a communication interface.
所述存储器用于存储计算机执行指令,所述处理器与所述存储器通过所述总线连接,当所述移动性管理实体运行时,所述处理器执行所述存储器存储的所述计算机执行指令,以使所述移动性管理实体执行如权利要求1至13中任一项所述的报文处理的方法。The memory is configured to store computer execution instructions, the processor is coupled to the memory via the bus, and when the mobility management entity is running, the processor executes the computer execution instructions stored by the memory, A method of causing the mobility management entity to perform the message processing according to any one of claims 1 to 13.
本发明实施例具体如下优点:The embodiments of the present invention specifically have the following advantages:
透明代理服务器在用户端与WEB服务器建立连接时,获取用户端向该WEB服务器发送的握手报文,并在确定握手报文的目的IP地址为预置目标WEB服务器的IP地址时,根据VAS服务器与所述目标WEB服务器的IP地址的对应关系确定VAS服务器,相对于现有技术来讲,无需用户端与该WEB服务器建立连接,即可确定VAS服务器,使用户端与该WEB服务器之间交互的业务报文及时得到VAS服务器的处理,提升用户体验。When the user establishes a connection with the WEB server, the transparent proxy server obtains the handshake message sent by the user to the WEB server, and determines the destination IP address of the handshake message according to the VAS server when determining the destination IP address of the handshake message. Corresponding relationship with the IP address of the target WEB server determines the VAS server. Compared with the prior art, the VAS server can be determined and the user end interacts with the WEB server without establishing a connection between the UE and the WEB server. The service packets are processed in time by the VAS server to improve the user experience.
图1为本发明实施例一提供的一种报文处理方法的实施例示意图;1 is a schematic diagram of an embodiment of a packet processing method according to Embodiment 1 of the present invention;
图2为本发明实施例二提供的一种报文处理方法的实施例示意图;2 is a schematic diagram of an embodiment of a packet processing method according to Embodiment 2 of the present invention;
图3为本发明实施例三提供的一种报文处理方法的实施例示意图;
FIG. 3 is a schematic diagram of an embodiment of a packet processing method according to Embodiment 3 of the present invention; FIG.
图4为本发明实施例四提供的一种报文处理方法的实施例示意图;4 is a schematic diagram of an embodiment of a packet processing method according to Embodiment 4 of the present invention;
图5为本发明实施例五提供的一种报文处理方法的实施例示意图;FIG. 5 is a schematic diagram of an embodiment of a packet processing method according to Embodiment 5 of the present invention; FIG.
图6为本发明实施例六和实施例七提供的一种透明代理服务器的实施例示意图;6 is a schematic diagram of an embodiment of a transparent proxy server according to Embodiment 6 and Embodiment 7 of the present invention;
图7为本发明实施例八提供的一种透明代理服务器的实施例示意图。FIG. 7 is a schematic diagram of an embodiment of a transparent proxy server according to Embodiment 8 of the present invention.
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。The technical solutions in the embodiments of the present invention are clearly and completely described in the following with reference to the accompanying drawings in the embodiments of the present invention. It is obvious that the described embodiments are only a part of the embodiments of the present invention, but not all embodiments. All other embodiments obtained by a person skilled in the art based on the embodiments of the present invention without creative efforts are within the scope of the present invention.
请参阅图1,本发明实施例一中的一种报文处理方法包括:Referring to FIG. 1, a packet processing method in Embodiment 1 of the present invention includes:
101、透明代理服务器获取用户端向WEB服务器发送的握手报文。101. The transparent proxy server obtains a handshake message sent by the client to the WEB server.
可以理解的是,透明代理服务器工作在透明代理模式下,位于用户端和WEB服务器之间,当用户端与WEB服务器进行交互时产生的数据报文,都会经过所述透明代理服务器,当所述用户端需要与WEB服务器需要建立连接时,由于在TCP/IP协议中,采用三次握手建立连接的方式,在第一次握手时,所述用户端会向WEB服务器发送握手报文,此时透明代理服务器可以获取该握手报文,并且所述透明代理服务器能够识别握手报文中的目的IP地址。It can be understood that the transparent proxy server works in the transparent proxy mode and is located between the client and the WEB server. When the client interacts with the WEB server, the data packet generated by the client passes through the transparent proxy server. When the user needs to establish a connection with the WEB server, the TCP/IP protocol uses a three-way handshake to establish a connection. When the first handshake is performed, the client sends a handshake packet to the WEB server. The proxy server can obtain the handshake message, and the transparent proxy server can identify the destination IP address in the handshake message.
102、当确定所述握手报文中的目的IP地址为预置的目标WEB服务器的IP地址时,所述透明代理服务器根据所述目的IP地址和对应关系,确定目标VAS服务器,所述对应关系为VAS服务器与所述目标WEB服务器的IP地址的对应关系。102. When it is determined that the destination IP address in the handshake message is the IP address of the preset target WEB server, the transparent proxy server determines the target VAS server according to the destination IP address and the corresponding relationship, and the corresponding relationship The correspondence between the VAS server and the IP address of the target WEB server.
可以理解的是,在所述透明代理服务器中预先设置有目标WEB服务器的IP地址,所述透明代理服务器能够将从握手报文中识别出的目的IP地址和预置的目标WEB服务的IP地址进行比对,当判断出所述目的IP地址为所述透明代理服务器中预置的目标WEB服务的IP地址时,所述透明代理服务器可以根据所述目的IP地址、VAS服务器和所述目标WEB服务器的IP地址的对应关系,确定目标VAS服务器。It can be understood that the IP address of the target WEB server is preset in the transparent proxy server, and the transparent proxy server can identify the destination IP address from the handshake message and the IP address of the preset target WEB service. Performing an alignment, when determining that the destination IP address is an IP address of a target WEB service preset in the transparent proxy server, the transparent proxy server may be configured according to the destination IP address, the VAS server, and the target WEB. The correspondence between the IP addresses of the servers determines the target VAS server.
103、所述透明代理服务器构建所述用户端、所述目标VAS服务器和所述WEB服务器之间的连接,所述目标VAS服务器用于处理所述用户端与所述WEB服务器之间交互的数据报文。
103. The transparent proxy server constructs a connection between the user end, the target VAS server, and the WEB server, where the target VAS server is configured to process data exchanged between the user end and the WEB server. Message.
可以理解的是,特定的VAS服务器用于处理一种或多种业务类型的数据报文,当获取到用户端向所述WEB服务器发送的数据报文时,所述透明代理服务器可以将所述数据报文转发至所述目标VAS服务器,使所述目标VAS服务器对接收到的数据报文进行相应的增值业务处理,并发送给所述WEB服务器,所述WEB服务器向所述用户端反馈的所述数据报文也可以经过所述VAS服务器进行处理。It can be understood that a specific VAS server is configured to process data packets of one or more service types, and when the data message sent by the user to the WEB server is obtained, the transparent proxy server may The data message is forwarded to the target VAS server, and the target VAS server performs corresponding value-added service processing on the received data packet, and sends the data packet to the WEB server, and the WEB server feeds back to the user end. The data message can also be processed by the VAS server.
本发明实施例中,In the embodiment of the present invention,
透明代理服务器在用户端与WEB服务器建立连接时,获取用户端向该WEB服务器发送的握手报文,并在确定握手报文的目的IP地址为预置目标WEB服务器的IP地址时,根据VAS服务器与所述目标WEB服务器的IP地址的对应关系确定VAS服务器,相对于现有技术来讲,无需用户端与该WEB服务器建立连接,即可确定VAS服务器,使用户端与该WEB服务器之间交互的业务报文及时得到VAS服务器的处理,提升用户体验。When the user establishes a connection with the WEB server, the transparent proxy server obtains the handshake message sent by the user to the WEB server, and determines the destination IP address of the handshake message according to the VAS server when determining the destination IP address of the handshake message. Corresponding relationship with the IP address of the target WEB server determines the VAS server. Compared with the prior art, the VAS server can be determined and the user end interacts with the WEB server without establishing a connection between the UE and the WEB server. The service packets are processed in time by the VAS server to improve the user experience.
在实施例一描述的一种报文处理方法中,当确定所述握手报文中的目的IP地址为预置的目标WEB服务器的IP地址时,在实际应用中,所述目标WEB服务器的IP地址可以是配置在透明代理服务器中的,也可以是所述透明代理服务器获取到的。其中,所述透明代理服务器获取所述目标WEB服务器的IP地址,可以为多种方式,具体如下:In a message processing method described in the first embodiment, when it is determined that the destination IP address in the handshake message is the IP address of the preset target WEB server, in actual application, the IP of the target WEB server The address may be configured in a transparent proxy server or may be obtained by the transparent proxy server. The transparent proxy server obtains the IP address of the target WEB server, which may be in multiple manners, as follows:
一、所述透明代理服务器获取所述目标WEB服务器的IP地址,具体为:所述透明代理服务器确定所述目标WEB服务器的域名;所述透明代理服务器根据所述目标WEB服务器的域名,确定所述目标WEB服务器的IP地址;所述透明代理服务器保存所述目标WEB服务器的IP地址。The transparent proxy server obtains the IP address of the target WEB server, specifically: the transparent proxy server determines the domain name of the target WEB server; and the transparent proxy server determines the domain according to the domain name of the target WEB server. The IP address of the target WEB server; the transparent proxy server saves the IP address of the target WEB server.
请参阅图2,本发明实施例二中的一种报文处理的方法包括:Referring to FIG. 2, a method for processing a message according to Embodiment 2 of the present invention includes:
201、透明代理服务器获取用户端向WEB服务器发送的握手报文。201. The transparent proxy server obtains a handshake message sent by the client to the WEB server.
可以理解的是,所述透明代理服务器工作在透明代理模式下,所述透明代理服务器部署在用户端和WEB服务器之间,为用户端和WEB服务器都不感知的代理服务器,用户端与WEB服务器进行交互时产生的数据报文,都会经过所述透明代理服务器,比如在PCC架构中,所述透明代理服务器为PCEF/TDF。It can be understood that the transparent proxy server works in a transparent proxy mode, and the transparent proxy server is deployed between the client and the WEB server, and is a proxy server that is not perceived by the client and the WEB server, and the client and the WEB server. The data packets generated during the interaction will pass through the transparent proxy server, for example, in the PCC architecture, and the transparent proxy server is PCEF/TDF.
当所述用户端需要与WEB服务器进行初始建连时,所述用户端与所述WEB服务器之间产生的握手报文将经过透明代理服务器,此时透明代理服务器可以获取握手报文,并识别出该握手报文中的目的IP地址,比如在TCP/IP协
议中,采用三次握手建立连接的方式,在第一次握手时,所述用户端会向WEB服务器发送同步(synchronous,syn)握手报文,此时透明代理服务器可以获取该syn握手报文,并且所述透明代理服务器能够识别出该syn握手报文中的目的IP地址。When the user needs to establish an initial connection with the WEB server, the handshake message generated between the user end and the WEB server passes through the transparent proxy server, and the transparent proxy server can obtain the handshake message and identify the handshake message. The destination IP address in the handshake packet, for example, in the TCP/IP protocol.
In the discussion, the three-way handshake is used to establish a connection. In the first handshake, the user sends a synchronous (syn) handshake message to the WEB server. The transparent proxy server can obtain the syn handshake packet. And the transparent proxy server can identify the destination IP address in the syn handshake message.
用户端可以是手机、平板电脑等移动终端,也可以是笔记本电脑等可以接入网络的设备,具体此处不作限定。The user terminal may be a mobile terminal such as a mobile phone or a tablet computer, or a device that can access the network, such as a notebook computer, and is not limited herein.
可选地,在本实施例中的201之后还包括202和203。Optionally, 202 and 203 are further included after 201 in this embodiment.
202、所述透明代理服务器确定所述目标WEB服务器的域名,并根据所述目标WEB服务器的域名确定所述目标WEB服务器的IP地址,保存所述目标WEB服务器的IP地址。202. The transparent proxy server determines a domain name of the target WEB server, and determines an IP address of the target WEB server according to the domain name of the target WEB server, and saves an IP address of the target WEB server.
可以理解的是,在用户端向WEB服务器发送业务报文之前,该用户端通常会将WEB服务器的域名发送给DNS服务器进行域名解析,该DNS服务器经解析后,经所述透明代理服务器向用户端反馈包含WEB服务器IP地址的查询结果。其中,所述透明代理服务器确定所述目标WEB服务器的IP地址的方式具体可以为:将所述用户端发送给的域名作为目标WEB服务器的域名,将所述DNS服务器经解析后,向用户端反馈的查询结果中包含的IP地址作为所述目标WEB服务器的IP地址;或者,该透明代理服务器还可以通过记录用户端使用WEB服务器域名进行解析的次数,确定目标WEB服务器的IP地址,比如透明代理服务器记录用户端使用第一WEB服务器的域名进行解析的第一次数和使用第二WEB服务器的第二域名进行解析的第二次数,当所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,所述透明代理服务器可以将所述第一WEB服务器的域名作为所述目标WEB服务器的域名,并根据所述DNS服务器反馈的查询结果,确定所述目标WEB服务器的域名对应的IP地址,即目标WEB服务器的IP地址。It can be understood that, before the user sends a service packet to the WEB server, the client usually sends the domain name of the WEB server to the DNS server for domain name resolution. After the DNS server is parsed, the user is sent to the user through the transparent proxy server. The end feedback contains the query result of the WEB server IP address. The manner in which the transparent proxy server determines the IP address of the target WEB server may be specifically: the domain name sent by the client is used as the domain name of the target WEB server, and the DNS server is parsed and then sent to the client. The IP address included in the feedback result is used as the IP address of the target WEB server; or the transparent proxy server may determine the IP address of the target WEB server by recording the number of times the user uses the WEB server domain name for resolution, such as transparent The proxy server records a first number of times that the user end uses the domain name of the first WEB server for parsing and a second number that is parsed by using the second domain name of the second WEB server, when the first number of times is greater than or equal to the first number The transparent proxy server may use the domain name of the first WEB server as the domain name of the target WEB server, and determine according to the query result fed back by the DNS server, when the preset ratio of the number of times and the second number of times is the same. The IP address corresponding to the domain name of the target WEB server, that is, the IP address of the target WEB server.
需要说明的是,本实施例中的所述预置比例为90%,在实际应用中,所述预置比例可以根据实际需要进行设定,具体此处不作限定。It should be noted that the preset ratio in the embodiment is 90%. In actual applications, the preset ratio may be set according to actual needs, which is not limited herein.
本实施例中,所述透明代理服务器在确定目标WEB服务器的域名之后,通过DNS服务器反馈的查询结果确定所述目标WEB服务器IP地址,在实际应用中,所述透明代理服务器还可以通过WEB服务器的域名与所述WEB服务器的IP地址的对应关系,确定所述目标WEB服务器的IP地址,具体此处不作限定。
In this embodiment, after determining the domain name of the target WEB server, the transparent proxy server determines the IP address of the target WEB server by using the query result fed back by the DNS server. In actual applications, the transparent proxy server may also pass the WEB server. The mapping between the domain name and the IP address of the WEB server determines the IP address of the target WEB server, which is not limited herein.
所述WEB服务器的域名与所述WEB服务器的IP地址的对应关系可以是预先配置在所述透明代理服务器中的,也可是所述透明代理服务器通过域名和DNS反馈的所述域名对应的IP地址构建的,具体此处不作限定。The mapping between the domain name of the WEB server and the IP address of the WEB server may be pre-configured in the transparent proxy server, or may be the IP address corresponding to the domain name fed back by the transparent proxy server through the domain name and the DNS. The construction is not limited herein.
203、所述透明代理服务器获取VAS服务器与所述目标WEB服务器的IP地址的对应关系。203. The transparent proxy server acquires a correspondence between the VAS server and an IP address of the target WEB server.
可以理解的是,所述透明代理服务器可以通过对用户端向目标WEB服务器的数据报文进行抽样检测,生成所述对应关系,具体为:所述透明代理服务器通过深度数据包检测(Deep Packet Inspection,DPI)分析出抽样数据报文中的目的IP地址,即目标WEB服务器的IP地址,并跟踪记录所述数据报文经过的VAS服务器,所述透明代理服务器根据所述目标WEB服务器的IP地址和所述数据报文经过的VAS服务器,生成所述对应关系,并将所述对应关系进行保存。It can be understood that the transparent proxy server can generate the corresponding relationship by sampling the data packet of the user to the target WEB server, specifically: the transparent proxy server passes the deep packet inspection (Deep Packet Inspection). , DPI) analyzes the destination IP address in the sampled data message, that is, the IP address of the target WEB server, and tracks the VAS server through which the data message passes, the transparent proxy server according to the IP address of the target WEB server Corresponding to the VAS server through which the data packet passes, and the corresponding relationship is saved.
需要说明的是,所述对应关系可以是所述透明代理服务器获取的,也可以是其他设备获取到所述对应关系后,预先配置在所述透明代理服务器中的,具体此处不作限定。It should be noted that the corresponding relationship may be obtained by the transparent proxy server, or may be configured in the transparent proxy server after the other device obtains the corresponding relationship, which is not limited herein.
所述VAS服务器用于处理特定类型的数据报文,比如病毒过滤、页面适配、视频优化等,具体此处不作限定。The VAS server is configured to process a specific type of data packet, such as a virus filtering, a page adaptation, a video optimization, and the like.
用户端通过传输控制协议(Transmission Control Protocol,TCP)或者其他协议向WEB服务器发送数据报文,具体此处不作限定。The user sends a data packet to the WEB server through a Transmission Control Protocol (TCP) or other protocol, which is not limited herein.
204、所述透明代理服务器判断所述握手报文中的目的IP地址是否为预置的目标WEB服务器的IP地址,若否,则执行步骤205,若是,则执行步骤206。204. The transparent proxy server determines whether the destination IP address in the handshake message is an IP address of a preset target WEB server. If not, step 205 is performed, and if yes, step 206 is performed.
所述透明代理服务器能够解析出所述握手报文中的目的IP地址,并将解析得到的目的IP地址与目标WEB服务器的IP地址进行比对,从而判断所述目标数据报文中的目的IP地址是否为目标WEB服务器的IP地址。The transparent proxy server can parse the destination IP address in the handshake packet, and compare the parsed destination IP address with the IP address of the target WEB server to determine the destination IP address in the target data packet. Whether the address is the IP address of the target WEB server.
205、所述透明代理服务器建立所述用户端和WEB服务器之间的连接。205. The transparent proxy server establishes a connection between the client and the WEB server.
当透明代理服务器判断出所述目标数据报文中的目的IP地址不是目标WEB服务器的IP地址时,所述透明代理服务器建立所述用户端和WEB服务器之间的连接。When the transparent proxy server determines that the destination IP address in the target data packet is not the IP address of the target WEB server, the transparent proxy server establishes a connection between the client and the WEB server.
206、所述透明代理服务器根据所述目的IP地址和对应关系,确定目标VAS服务器,所述对应关系为VAS服务器与所述目标WEB服务器的IP地址的对应关系。
The transparent proxy server determines the target VAS server according to the destination IP address and the corresponding relationship, where the correspondence relationship is a correspondence between the VAS server and the IP address of the target WEB server.
在所述透明代理服务器确定所述目的IP地址为目标WEB服务器的IP地址时,根据所述VAS服务器与所述目标WEB服务器的IP地址的对应关系,确定目标VAS服务器。When the transparent proxy server determines that the destination IP address is the IP address of the target WEB server, the target VAS server is determined according to the correspondence between the VAS server and the IP address of the target WEB server.
207、所述透明代理服务器构建所述用户端、所述VAS服务器和所述目标WEB服务器之间的连接,所述目标VAS服务器用于处理所述用户端与所述WEB服务器之间交互的数据报文。207. The transparent proxy server constructs a connection between the user end, the VAS server, and the target WEB server, where the target VAS server is configured to process data exchanged between the user end and the WEB server. Message.
可以理解的是,VAS服务器可以为特定的业务类型的数据报文提供增值服务处理,比如视频优化服务器用于处理业务类型为视频业务的数据报文,在超文本传送协议(Hypertext transfer protocol,HTTP)中,所述视频业务请求报的内容类型包括:video/mp4、video/x-flv、video/x-f4v等;页面适配服务器用于处理业务类型为页面适配业务的数据报文,在HTTP协议中,所述页面适配数据报文的内容类型包括:text/html、application/vnd.wap.xhtml、application/xhtml+xml、ext/vnd.wap.wml、application/vnd.wap.wmlc、image/jpeg、image/gif、image/png等;内容插入服务器用于处理业务类型为内容插入业务的数据报文,在HTTP协议中,所述内容插入数据报文的内容类型包括:text/html、application/vnd.wap.xhtml、application/xhtml+xml等。It can be understood that the VAS server can provide value-added service processing for data packets of a specific service type, for example, a video optimization server is used to process data packets of a service type of video services, and a hypertext transfer protocol (HTTP). The content type of the video service request report includes: video/mp4, video/x-flv, video/x-f4v, etc.; the page adaptation server is configured to process data packets whose service type is page adaptation service. In the HTTP protocol, the content types of the page adaptation data message include: text/html, application/vnd.wap.xhtml, application/xhtml+xml, ext/vnd.wap.wml, application/vnd.wap. Wmlc, image/jpeg, image/gif, image/png, etc.; the content insertion server is configured to process a data packet whose service type is a content insertion service. In the HTTP protocol, the content type of the content insertion data packet includes: /html, application/vnd.wap.xhtml, application/xhtml+xml, etc.
需要说明的是,所述VAS服务器可以同时处理一种或多种数据报文,比如VAS服务器可以同时处理视频数据报文和页面适配数据报文,具体此处不作限定。It should be noted that the VAS server can process one or more data packets at the same time. For example, the VAS server can process the video data packet and the page adaptation data packet at the same time, which is not limited herein.
所述透明代理服务器中包括用于与用户端连接的端口、用于与VAS服务器连接的端口和用于与WEB服务器的端口,在根据握手报文确定VAS服务器,所述透明代理服务器可以根据所述用户端连接的端口与所述VAS服务器连接的端口建立通信通道,从而实现构建用户端、目标VAS服务器和目标WEB服务器之间的连接。在所述透明代理服务器建立所述用户端与所述VAS服务器之间连接之后,所述目标VAS服务器可以处理所述目标VAS服务器用于处理所述用户端与所述WEB服务器之间交互的数据报文。The transparent proxy server includes a port for connecting with the client, a port for connecting with the VAS server, and a port for connecting to the WEB server, and determining a VAS server according to the handshake message, where the transparent proxy server can be The port connected by the client establishes a communication channel with the port connected to the VAS server, thereby implementing a connection between the client, the target VAS server, and the target WEB server. After the transparent proxy server establishes a connection between the client and the VAS server, the target VAS server may process the data used by the target VAS server to process interaction between the client and the WEB server. Message.
本发明实施例中,所述透明代理服务器将域名解析的次数的占比大于或等于90%的域名作为目标WEB服务器的域名,再根据所述目标WEB服务器的域名可以确定出所述目标WEB服务器的IP地址,也就是说,用户端使用该目标WEB服务器的IP地址频率高,因此根据该目标服务器的IP地址和VAS服务器的对应关系,可以提高确定目标VAS服务器的成功率高。
In the embodiment of the present invention, the transparent proxy server uses the domain name with the proportion of the number of domain name resolutions greater than or equal to 90% as the domain name of the target WEB server, and then determines the target WEB server according to the domain name of the target WEB server. The IP address, that is, the frequency of the IP address of the target WEB server used by the client is high. Therefore, according to the correspondence between the IP address of the target server and the VAS server, the success rate of determining the target VAS server can be improved.
二、所述透明代理服务器获取所述目标WEB服务器的IP地址,具体为:所述透明代理服务器确定所述用户端向所述WEB服务器发送所述第一数据报文的第一次数和发送第二数据报文的第二次数,所述第一次数大于第二次数,所述第一数据报文包括第一目的IP地址,所述第二数据报文包括第二目的IP地址;若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一目的IP地址为所述目标WEB服务器的IP地址;所述透明代理服务器保存所述目标WEB服务器的IP地址。The transparent proxy server obtains the IP address of the target WEB server, where the transparent proxy server determines that the user sends the first data packet to the WEB server for the first time and sends the first data packet. The second number of times of the second data packet, the first number of times is greater than the second number of times, the first data packet includes a first destination IP address, and the second data packet includes a second destination IP address; When the first number of times is greater than or equal to a preset ratio of the sum of the first number and the second number, determining that the first destination IP address is an IP address of the target WEB server; the transparent proxy The server saves the IP address of the target WEB server.
请参阅图3,本发明实施例三提供的一种报文处理的方法包括:Referring to FIG. 3, a method for processing a message according to Embodiment 3 of the present invention includes:
301、透明代理服务器获取用户端向WEB服务器发送的握手报文。301. The transparent proxy server obtains a handshake message sent by the user end to the WEB server.
可以理解的是,所述透明代理服务器工作在透明代理模式下,所述透明代理服务器部署在用户端和WEB服务器之间,为用户端和WEB服务器都不感知的代理服务器,用户端与WEB服务器进行交互时产生的数据报文,都会经过所述透明代理服务器,比如在PCC架构中,所述透明代理服务器为PCEF/TDF。It can be understood that the transparent proxy server works in a transparent proxy mode, and the transparent proxy server is deployed between the client and the WEB server, and is a proxy server that is not perceived by the client and the WEB server, and the client and the WEB server. The data packets generated during the interaction will pass through the transparent proxy server, for example, in the PCC architecture, and the transparent proxy server is PCEF/TDF.
当所述用户端需要与WEB服务器进行初始建连时,所述用户端与所述WEB服务器之间产生的握手报文将经过透明代理服务器,此时透明代理服务器可以获取握手报文,并识别出该握手报文中的目的IP地址,比如在TCP/IP协议中,采用三次握手建立连接的方式,在第一次握手时,所述用户端会向WEB服务器发送同步(synchronous,syn)握手报文,此时透明代理服务器可以获取该syn握手报文,并且所述透明代理服务器能够识别出该syn握手报文中的目的IP地址。When the user needs to establish an initial connection with the WEB server, the handshake message generated between the user end and the WEB server passes through the transparent proxy server, and the transparent proxy server can obtain the handshake message and identify the handshake message. The destination IP address in the handshake packet, for example, in the TCP/IP protocol, the three-way handshake is used to establish a connection. When the first handshake is performed, the client sends a synchronous (syn) handshake to the WEB server. The message, the transparent proxy server can obtain the syn handshake packet, and the transparent proxy server can identify the destination IP address in the syn handshake packet.
用户端可以是手机、平板电脑等移动终端,也可以是笔记本电脑等可以接入网络的设备,具体此处不作限定。The user terminal may be a mobile terminal such as a mobile phone or a tablet computer, or a device that can access the network, such as a notebook computer, and is not limited herein.
可选地,在步骤301之后,还包括302、303和304。Optionally, after step 301, 302, 303, and 304 are further included.
302、所述透明代理服务器确定所述用户端向所述WEB服务器发送所述第一数据报文的第一次数和发送第二数据报文的第二次数,所述第一次数大于第二次数,所述第一数据报文包括第一目的IP地址,所述第二数据报文包括第二目的IP地址。302. The transparent proxy server determines a first time that the user sends the first data packet to the WEB server, and a second number of times that the second data packet is sent, where the first number is greater than the first The second data packet includes a first destination IP address, and the second data packet includes a second destination IP address.
可以理解的是,在用户端向所述WEB服务器发送数据报文时,所述透明代理服务器可以获取所述用户端向WEB服务器发送数据报文,并记录所述用户端向所述WEB服务器发送数据报文的次数,所述透明代理服务器还可以对获取到的数据报文进行分析,以获取所述数据报文中的目的IP地址,比如所述
透明代理服务器记录所述用户端向第一WEB服务器发送第一数据报文的第一次数,以及向第二WEB服务器发送第二数据报文的第二次数,并分析出所述第一数据报文中的第一目的IP地址和第二数据报文中的第二目的IP地址。It can be understood that, when the user sends a data packet to the WEB server, the transparent proxy server may obtain the data packet sent by the client to the WEB server, and record that the client sends the data packet to the WEB server. The number of times of the data packet, the transparent proxy server may further analyze the obtained data packet to obtain a destination IP address in the data packet, such as the
The transparent proxy server records the first number of times that the user sends the first data packet to the first WEB server, and sends the second data packet to the second WEB server for the second time, and analyzes the first data. The first destination IP address in the packet and the second destination IP address in the second data packet.
303、若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,所述透明代理服务器确定所述第一目的IP地址为所述目标WEB服务器的IP地址,并保存所述目标WEB服务器的IP地址。303. If the first number of times is greater than or equal to a preset ratio of the sum of the first number and the second number, the transparent proxy server determines that the first destination IP address is the target WEB server. IP address and save the IP address of the target WEB server.
可以理解的是,所述透明代理服务器可以比较所述第一次数是否大于第二次数,并且判断所述第一次数是否大于或等于所述第一次数与第二次数之和的预置比例,当所述透明代理服务器判断出所述第一次数大于第二次数,并且所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,将所述第一目的IP地址作为目标WEB服务器的IP地址,并将所述目标WEB服务器的IP地址保存在所述透明代理服务器中。It can be understood that the transparent proxy server can compare whether the first number of times is greater than the second number, and determine whether the first number of times is greater than or equal to a sum of the first number and the second number of times Proportion, when the transparent proxy server determines that the first number of times is greater than the second number, and the first number of times is greater than or equal to a preset ratio of the sum of the first number of times and the second number of times, The first destination IP address is used as the IP address of the target WEB server, and the IP address of the target WEB server is saved in the transparent proxy server.
需要说明的是,本实施例中的所述预置比例为90%,在实际应用中,所述预置比例可以根据实际需要进行设定,具体此处不作限定。It should be noted that the preset ratio in the embodiment is 90%. In actual applications, the preset ratio may be set according to actual needs, which is not limited herein.
304、所述透明代理服务器获取VAS服务器与所述目标WEB服务器的IP地址的对应关系。304. The transparent proxy server acquires a correspondence between the VAS server and an IP address of the target WEB server.
305、所述透明代理服务器判断所述握手报文中的目的IP地址是否为预置的目标WEB服务器的IP地址,若否,则执行步骤306,若是,则执行步骤307。305. The transparent proxy server determines whether the destination IP address in the handshake message is an IP address of a preset target WEB server. If not, step 306 is performed, and if yes, step 307 is performed.
306、所述透明代理服务器建立所述用户端和WEB服务器之间的连接。306. The transparent proxy server establishes a connection between the client and the WEB server.
307、所述透明代理服务器根据所述目的IP地址和对应关系,确定目标VAS服务器,所述对应关系为VAS服务器与所述目标WEB服务器的IP地址的对应关系。307. The transparent proxy server determines, according to the destination IP address and the corresponding relationship, a target VAS server, where the correspondence relationship is a correspondence between the VAS server and an IP address of the target WEB server.
308、所述透明代理服务器构建所述用户端、所述VAS服务器和所述目标WEB服务器之间的连接,所述目标VAS服务器用于处理所述用户端与所述WEB服务器之间交互的数据报文。308. The transparent proxy server constructs a connection between the user end, the VAS server, and the target WEB server, where the target VAS server is configured to process data exchanged between the user end and the WEB server. Message.
本发明实施例中,本发明实施例中,所述透明代理服务器确定出用户端发送次数占比大于或等于90%的业务报文,并将该业务报文中的目的IP地址作为目标WEB服务器的IP地址,也就是说,该用户端使用该目标WEB服务器的IP地址频率高,因此根据该目标服务器的IP地址和VAS服务器的对应关系,可以提高确定出目标VAS服务器的成功率。In the embodiment of the present invention, in the embodiment of the present invention, the transparent proxy server determines that the service number of the client is greater than or equal to 90%, and uses the destination IP address in the service packet as the target WEB server. The IP address, that is, the IP address of the target WEB server is high, so that the success rate of the target VAS server can be improved according to the correspondence between the IP address of the target server and the VAS server.
上面实施例中所描述的一种报文处理的方法中,所述透明代理服务器中预
置目标WEB服务器的IP地址,在实际应用中,所述透明代理服务器中也可以预置目标WEB服务器的域名,下面对本发明实施例中的另外一种报文处理方法进行描述:In the method for processing a message described in the above embodiment, the transparent proxy server pre-
The IP address of the target WEB server is set. In the actual application, the domain name of the target WEB server can also be preset in the transparent proxy server. The following describes another packet processing method in the embodiment of the present invention:
请参阅图4,本发明实施例四提供的一种报文处理的方法包括:Referring to FIG. 4, a method for processing a packet according to Embodiment 4 of the present invention includes:
401、透明代理服务器获取用户端向WEB服务器发送的握手报文,所述握手报文中IP地址为所述WEB服务器的IP地址。401. The transparent proxy server obtains a handshake message sent by the user to the WEB server, where the IP address of the handshake message is an IP address of the WEB server.
可以理解的是,所述透明代理服务器工作在透明代理模式下,所述透明代理服务器部署在用户端和WEB服务器之间,为用户端和WEB服务器都不感知的代理服务器,用户端与WEB服务器进行交互时产生的数据报文,都会经过所述透明代理服务器,比如在PCC架构中,所述透明代理服务器为PCEF/TDF。It can be understood that the transparent proxy server works in a transparent proxy mode, and the transparent proxy server is deployed between the client and the WEB server, and is a proxy server that is not perceived by the client and the WEB server, and the client and the WEB server. The data packets generated during the interaction will pass through the transparent proxy server, for example, in the PCC architecture, and the transparent proxy server is PCEF/TDF.
当所述用户端需要与WEB服务器进行初始建连时,所述用户端与所述WEB服务器之间产生的握手报文将经过透明代理服务器,此时透明代理服务器可以获取握手报文,并识别出该握手报文中的目的IP地址,比如在TCP/IP协议中,采用三次握手建立连接的方式,在第一次握手时,所述用户端会向WEB服务器发送同步(synchronous,syn)握手报文,此时透明代理服务器可以获取该syn握手报文,并且所述透明代理服务器能够识别出该syn握手报文中的目的IP地址。When the user needs to establish an initial connection with the WEB server, the handshake message generated between the user end and the WEB server passes through the transparent proxy server, and the transparent proxy server can obtain the handshake message and identify the handshake message. The destination IP address in the handshake packet, for example, in the TCP/IP protocol, the three-way handshake is used to establish a connection. When the first handshake is performed, the client sends a synchronous (syn) handshake to the WEB server. The message, the transparent proxy server can obtain the syn handshake packet, and the transparent proxy server can identify the destination IP address in the syn handshake packet.
用户端可以是手机、平板电脑等移动终端,也可以是笔记本电脑等可以接入网络的设备,具体此处不作限定。The user terminal may be a mobile terminal such as a mobile phone or a tablet computer, or a device that can access the network, such as a notebook computer, and is not limited herein.
402、所述透明代理服务器根据所述目的IP地址和第一对应关系,确定WEB服务器的域名,所述第一对应关系为WEB服务器的域名与WEB服务器的IP地址的对应关系。The transparent proxy server determines the domain name of the WEB server according to the destination IP address and the first correspondence, where the first correspondence is a correspondence between a domain name of the WEB server and an IP address of the WEB server.
所述透明代理服务器从获取到的握手报文中获取目的IP地址,所述目的IP地址为WEB服务器的IP地址,根据WEB服务器的域名与WEB服务器的IP地址的对应关系,可确定所述WEB服务器的IP地址。The transparent proxy server obtains the destination IP address from the obtained handshake packet, and the destination IP address is the IP address of the WEB server, and the WEB may be determined according to the correspondence between the domain name of the WEB server and the IP address of the WEB server. The IP address of the server.
403、当确定所述WEB服务器的域名为预置的目标WEB服务器的域名时,所述透明代理服务器根据所述WEB服务器的域名和第一对应关系,确定所述目标数据报文的业务类型,所述第一对应关系为VAS服务器与所述目标WEB服务器的域名的对应关系。403. When it is determined that the domain name of the WEB server is the domain name of the preset target WEB server, the transparent proxy server determines the service type of the target data packet according to the domain name and the first correspondence of the WEB server. The first correspondence is a correspondence between a VAS server and a domain name of the target WEB server.
所述透明代理服务器能够判断WEB服务器的域名是否为所述透明代理服务器中预置的目标WEB服务器的域名,当判断出所述WEB服务器的域名为所
述透明代理服务器中预置的目标WEB服务的域名时,根据VAS服务器与所述目标服务器的域名的对应关系,确定目标VAS服务器。The transparent proxy server can determine whether the domain name of the WEB server is the domain name of the target WEB server preset in the transparent proxy server, and determine that the domain name of the WEB server is
When the domain name of the target WEB service preset in the transparent proxy server is described, the target VAS server is determined according to the correspondence between the VAS server and the domain name of the target server.
404、所述透明代理服务器构建所述用户端、所述目标VAS服务器和所述WEB服务器之间的连接,所述目标VAS服务器用于处理所述用户端与所述WEB服务器之间交互的数据报文。404. The transparent proxy server constructs a connection between the user end, the target VAS server, and the WEB server, where the target VAS server is configured to process data exchanged between the user end and the WEB server. Message.
可以理解的是,特定的VAS服务器用于处理一种或多种业务类型的数据报文,当获取到用户端向所述WEB服务器发送的数据报文时,所述透明代理服务器可以将所述数据报文转发至所述目标VAS服务器,使所述目标VAS服务器对接收到的数据报文进行相应的增值业务处理,并发送给所述WEB服务器,所述WEB服务器向所述用户端反馈的所述数据报文也可以经过所述VAS服务器进行处理。It can be understood that a specific VAS server is configured to process data packets of one or more service types, and when the data message sent by the user to the WEB server is obtained, the transparent proxy server may The data message is forwarded to the target VAS server, and the target VAS server performs corresponding value-added service processing on the received data packet, and sends the data packet to the WEB server, and the WEB server feeds back to the user end. The data message can also be processed by the VAS server.
本发明实施例中,透明代理服务器根据WEB服务器的IP地址和第一对应关系,确定数据报文的目的IP地址对应的WEB服务器的域名,当判断出所述WEB服务器的域名为预置的目标WEB服务器的域名时,根据所述WEB服务器的域名和第二对应关系,确定VAS服务器,从而缩短该透明代理服务器确定目标VAS服务器的时长,使业务报文及时得到VAS服务器的处理,提升用户体验。In the embodiment of the present invention, the transparent proxy server determines the domain name of the WEB server corresponding to the destination IP address of the data packet according to the IP address of the WEB server and the first correspondence, and determines that the domain name of the WEB server is a preset target. The domain name of the WEB server is determined according to the domain name and the second correspondence of the WEB server, so that the length of the target VAS server is determined by the transparent proxy server, and the service packet is processed by the VAS server in time to improve the user experience. .
上述实施例四中,所述透明代理服务器根据所述WEB服务器的域名和第二对应关系,确定所述目标VAS服务器,在实际应用中,所述第二对应关系可以为预先配置在所述透明代理服务器中的,也可以为所述透明代理服务器获取到的,下面对所述透明代理服务器获取所述第二对应关系进行详细描述:In the fourth embodiment, the transparent proxy server determines the target VAS server according to the domain name and the second correspondence of the WEB server. In an actual application, the second correspondence may be pre-configured in the transparent The proxy server may also be obtained by the transparent proxy server. The following describes the second proxy relationship obtained by the transparent proxy server:
请参阅图5,本发明实施例五提供的一种报文处理的方法包括:Referring to FIG. 5, a method for processing a packet according to Embodiment 5 of the present invention includes:
501、透明代理服务器获取用户端向WEB服务器发送的握手报文,所述握手报文中IP地址为所述WEB服务器的IP地址。501. The transparent proxy server obtains a handshake message sent by the user to the WEB server, where the IP address in the handshake message is an IP address of the WEB server.
可以理解的是,所述透明代理服务器工作在透明代理模式下,所述透明代理服务器部署在用户端和WEB服务器之间,为用户端和WEB服务器都不感知的代理服务器,用户端与WEB服务器进行交互时产生的数据报文,都会经过所述透明代理服务器,比如在PCC架构中,所述透明代理服务器为PCEF/TDF。It can be understood that the transparent proxy server works in a transparent proxy mode, and the transparent proxy server is deployed between the client and the WEB server, and is a proxy server that is not perceived by the client and the WEB server, and the client and the WEB server. The data packets generated during the interaction will pass through the transparent proxy server, for example, in the PCC architecture, and the transparent proxy server is PCEF/TDF.
当所述用户端需要与WEB服务器进行初始建连时,所述用户端与所述WEB服务器之间产生的握手报文将经过透明代理服务器,此时透明代理服务器可以获取握手报文,并识别出该握手报文中的目的IP地址,比如在TCP/IP协
议中,采用三次握手建立连接的方式,在第一次握手时,所述用户端会向WEB服务器发送同步(synchronous,syn)握手报文,此时透明代理服务器可以获取该syn握手报文,并且所述透明代理服务器能够识别出该syn握手报文中的目的IP地址。When the user needs to establish an initial connection with the WEB server, the handshake message generated between the user end and the WEB server passes through the transparent proxy server, and the transparent proxy server can obtain the handshake message and identify the handshake message. The destination IP address in the handshake packet, for example, in the TCP/IP protocol.
In the discussion, the three-way handshake is used to establish a connection. In the first handshake, the user sends a synchronous (syn) handshake message to the WEB server. The transparent proxy server can obtain the syn handshake packet. And the transparent proxy server can identify the destination IP address in the syn handshake message.
用户端可以是手机、平板电脑等移动终端,也可以是笔记本电脑等可以接入网络的设备,具体此处不作限定。The user terminal may be a mobile terminal such as a mobile phone or a tablet computer, or a device that can access the network, such as a notebook computer, and is not limited herein.
可选地,在步骤501之后,还包括步骤502、503和504。Optionally, after step 501, steps 502, 503, and 504 are further included.
502、所述透明代理服务器获取WEB服务器的域名与WEB服务器的IP地址的对应关系。502. The transparent proxy server acquires a correspondence between a domain name of the WEB server and an IP address of the WEB server.
可以理解的是,在用户端向WEB服务器发送业务报文之前,该用户端通常会将WEB服务器的域名发送给DNS服务器进行域名解析,该DNS服务器经解析后,经所述透明代理服务器向用户端反馈包含WEB服务器IP地址的查询结果,此时,所述透明代理服务器可以根据所述DNS服务器反馈的查询结果和所述用户端发送的域名,确定所述WEB服务器的域名与所述WEB服务器的IP地址的对应关系。It can be understood that, before the user sends a service packet to the WEB server, the client usually sends the domain name of the WEB server to the DNS server for domain name resolution. After the DNS server is parsed, the user is sent to the user through the transparent proxy server. The end-feedback includes the query result of the IP address of the WEB server. At this time, the transparent proxy server may determine the domain name of the WEB server and the WEB server according to the query result fed back by the DNS server and the domain name sent by the client. Correspondence of IP addresses.
503、所述透明代理服务器获取所述目标WEB服务器的域名。503. The transparent proxy server acquires a domain name of the target WEB server.
所述透明代理服务器获取所述目标WEB服务器的域名的方式至少包括如下两种:The manner in which the transparent proxy server obtains the domain name of the target WEB server includes at least the following two types:
一、所述透明代理服务器确定所述目标WEB服务器的IP地址,并根据所述目标WEB服务器的IP地址,确定所述目标WEB服务器的域名,保存所述目标WEB服务器的域名。The transparent proxy server determines the IP address of the target WEB server, and determines the domain name of the target WEB server according to the IP address of the target WEB server, and saves the domain name of the target WEB server.
需要说明的是,本实施例中,所述透明代理服务器确定所述目标WEB服务器的IP地址的方式具体为:所述透明代理服务器记录所述用户端向WEB服务器发送业务报文的次数,并将发送次数较多的业务报文中的目的IP地址,作为目标WEB服务器的IP地址,比如所述透明代理服务器记录用户端向第一WEB服务器发送第一业务报文的第一次数和向第二WEB服务器发送第二业务报文的第二次数,若所述第一次数大于第二次数,并且所述第一次数大于或等于所述第一次数与第二次数之和的90%时,则将所述第一业务报文中的第一目的IP地址作为目标WEB服务器的IP地址,在实际应用中,所述透明代理服务器还可以直接将获取到的所述用户端发送的业务报文中的IP地址,作为目标WEB服务器的IP地址,或者,所述透明代理服务器还可以通过其他方式确定
所述目标WEB服务器的IP地址,具体此处不作限定。It should be noted that, in this embodiment, the manner in which the transparent proxy server determines the IP address of the target WEB server is specifically: the transparent proxy server records the number of times the user sends a service packet to the WEB server, and The destination IP address in the service packet with the highest number of times of transmission is used as the IP address of the target WEB server. For example, the transparent proxy server records the first number and the first time that the user sends the first service packet to the first WEB server. The second number of times that the second WEB server sends the second service packet, if the first number of times is greater than the second number of times, and the first number of times is greater than or equal to the sum of the first number of times and the second number of times 90%, the first destination IP address in the first service packet is used as the IP address of the target WEB server. In an actual application, the transparent proxy server may directly send the obtained client. The IP address in the service message, as the IP address of the target WEB server, or the transparent proxy server can be determined by other means.
The IP address of the target WEB server is not limited herein.
本发明实施例中所述透明代理服务器确定出用户端发送次数占比大于或等于90%的业务报文,并将该业务报文中的目的IP地址作为目标WEB服务器的IP地址,也就是说,该用户端使用该目标WEB服务器的IP地址频率高,根据该服务器的IP地址和所述服务器域名的对应关系确定的目标WEB服务器的域名,也就说,用户端使用该目标WEB服务器的域名频率高,VAS服务器的对应关系,可以提高确定目标VAS服务器的成功率高。In the embodiment of the present invention, the transparent proxy server determines that the service number of the client is greater than or equal to 90%, and the destination IP address in the service packet is the IP address of the target WEB server, that is, The frequency of the IP address of the target WEB server is high, and the domain name of the target WEB server is determined according to the correspondence between the IP address of the server and the domain name of the server, that is, the domain name of the target WEB server is used by the client. The high frequency and the corresponding relationship of the VAS server can improve the success rate of determining the target VAS server.
需要说明的是,所述第一次数与所述第一次数和第二次数之和的占比可以根据实际需要进行设定,本实施例中的预置比例为90%,具体此处不作限定。It should be noted that the ratio of the first number of times to the sum of the first number of times and the second number of times may be set according to actual needs, and the preset ratio in this embodiment is 90%, specifically Not limited.
所述透明代理服务器根据所述目标WEB服务器的IP地址,确定所述目标WEB服务器的域名的方式具体为:所述透明代理服务器根据所述目标WEB服务器的IP地址和所述WEB服务器的域名与所述WEB服务器的IP地址的对应关系,确定所述目标WEB服务器的域名,在实际应用中,所述透明代理服务器还可以根据其他方式进行确定,具体此处不作限定。The manner in which the transparent proxy server determines the domain name of the target WEB server according to the IP address of the target WEB server is specifically: the transparent proxy server according to the IP address of the target WEB server and the domain name of the WEB server The mapping of the IP address of the WEB server determines the domain name of the target WEB server. In an actual application, the transparent proxy server may be determined according to other manners, which is not limited herein.
二、所述透明代理服务器根据用户端使用WEB服务器的域名进行解析的次数,并将域名解析次数占比高的域名作为目标服务器的域名。2. The transparent proxy server performs the number of times of parsing according to the domain name of the WEB server by the client, and uses the domain name with a high proportion of domain name resolution as the domain name of the target server.
举例来说,所述透明代理服务器确定所述用户端使用第一WEB服务器的域名进行解析的第一次数和使用第二WEB服务器的域名进行解析的第二次数,若所述第一次数大于第二次数,并且所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则将所述第一WEB服务器的域名作为所述本发明实施例中,所述透明代理服务器将域名解析的次数的占比大于或等于90%的域名作为目标WEB服务器的域名,也就是说,用户端使用该目标WEB服务器的域名频率高,因此根据该目标服务器的域名和VAS服务器的对应关系,可以提高确定出目标VAS服务器的成功率。For example, the transparent proxy server determines a first number of times the client uses the domain name of the first WEB server for parsing and a second number of times that the domain name of the second WEB server is used for parsing, if the first number of times When the first number of times is greater than or equal to a preset ratio of the sum of the first number and the second number, the domain name of the first WEB server is used as the embodiment of the present invention. The transparent proxy server uses the domain name with the proportion of the number of domain name resolutions greater than or equal to 90% as the domain name of the target WEB server, that is, the domain name of the target WEB server used by the client is high, so according to the target server The correspondence between the domain name and the VAS server can improve the success rate of determining the target VAS server.
需要说明的是,域名解析的次数的占比可以根据实际需要进行设定,本实施例中的域名解析的次数的占比为90%,具体此处不作限定。It should be noted that the proportion of the number of times of domain name resolution can be set according to actual needs, and the proportion of the number of domain name resolutions in this embodiment is 90%, which is not limited herein.
504、所述透明代理服务器获取VAS服务器与所述预置的目标WEB服务器的域名的对应关系。504. The transparent proxy server acquires a correspondence between a VAS server and a domain name of the preset target WEB server.
可以理解的是,所述透明代理服务器在获取用户端向WEB服务器发送的业务报文时,所述透明代理服务器能够通过DPI分析出所述业务报文的目的IP地址,所述代理服务器能够根据所述目的IP地址和所述第一对应关系,从而确
定所述WEB服务器的域名,并跟踪记录所述数据报文经过的VAS服务器,所述透明代理服务器根据所述目标WEB服务器的IP地址和所述数据报文经过的VAS服务器,生成所述对应关系,并将所述对应关系进行保存。It can be understood that, when the transparent proxy server obtains the service packet sent by the client to the WEB server, the transparent proxy server can analyze the destination IP address of the service packet by using the DPI, and the proxy server can Determining the destination IP address and the first correspondence
Determining the domain name of the WEB server, and tracking the VAS server through which the data packet passes, the transparent proxy server generating the corresponding according to the IP address of the target WEB server and the VAS server through which the data packet passes Relationship and save the correspondence.
需要说明的是,所述对应关系可以是所述透明代理服务器获取的,也可以是其他设备获取到所述对应关系后,预先配置在所述透明代理服务器中的,具体此处不作限定。It should be noted that the corresponding relationship may be obtained by the transparent proxy server, or may be configured in the transparent proxy server after the other device obtains the corresponding relationship, which is not limited herein.
505、所述透明代理服务器根据所述握手报文的目的IP地址和第一对应关系,确定所述WEB服务器的域名。505. The transparent proxy server determines a domain name of the WEB server according to the destination IP address of the handshake packet and the first correspondence.
所述透明代理服务器能耐解析出握手报文中的目的IP地址,并根据获取到的WEB服务器的域名与WEB服务器的IP地址的对应关系,确定所述WEB服务器的域名。The transparent proxy server is capable of parsing the destination IP address in the handshake packet, and determining the domain name of the WEB server according to the correspondence between the obtained domain name of the WEB server and the IP address of the WEB server.
506、判断所述WEB服务器的域名是否为预置的目标WEB服务器的域名,若是,则执行步骤507,若是,则执行步骤508。506. Determine whether the domain name of the WEB server is the domain name of the preset target WEB server. If yes, go to step 507. If yes, go to step 508.
所述透明代理服务器能够将WEB服务器的域名与目标WEB服务的域名进行比对,从而判断所述WEB服务器的域名是否为预置的目标WEB服务器的域名。The transparent proxy server can compare the domain name of the WEB server with the domain name of the target WEB service, so as to determine whether the domain name of the WEB server is the domain name of the preset target WEB server.
507、所述透明代理服务器建立所述用户端和WEB服务器之间的连接。507. The transparent proxy server establishes a connection between the client and the WEB server.
508、所述透明代理服务器根据所述目的IP地址和对应关系,确定目标VAS服务器,所述对应关系为VAS服务器与所述目标WEB服务器的IP地址的对应关系。508. The transparent proxy server determines, according to the destination IP address and the corresponding relationship, a target VAS server, where the correspondence relationship is a correspondence between the VAS server and an IP address of the target WEB server.
在所述透明代理服务器确定所述目的IP地址为目标WEB服务器的IP地址时,根据所述VAS服务器与所述目标WEB服务器的IP地址的对应关系,确定目标VAS服务器。When the transparent proxy server determines that the destination IP address is the IP address of the target WEB server, the target VAS server is determined according to the correspondence between the VAS server and the IP address of the target WEB server.
509、所述透明代理服务器构建所述用户端、所述VAS服务器和所述目标WEB服务器之间的连接,所述目标VAS服务器用于处理所述用户端与所述WEB服务器之间交互的数据报文。509. The transparent proxy server constructs a connection between the user end, the VAS server, and the target WEB server, where the target VAS server is configured to process data exchanged between the user end and the WEB server. Message.
本实施例中的509可采用与实施例二相同的方法,此处不再赘述。509 in this embodiment may adopt the same method as that in Embodiment 2, and details are not described herein again.
本发明实施例中,透明代理服务器根据WEB服务器的IP地址和第一对应关系,确定数据报文的目的IP地址对应的WEB服务器的域名,当判断出所述WEB服务器的域名为预置的目标WEB服务器的域名时,根据所述WEB服务器的域名和第二对应关系,确定VAS服务器,从而缩短该透明代理服务器确定
目标VAS服务器的时长,使业务报文及时得到VAS服务器的处理,提升用户体验。In the embodiment of the present invention, the transparent proxy server determines the domain name of the WEB server corresponding to the destination IP address of the data packet according to the IP address of the WEB server and the first correspondence, and determines that the domain name of the WEB server is a preset target. When the domain name of the WEB server is used, the VAS server is determined according to the domain name and the second correspondence relationship of the WEB server, thereby shortening the transparent proxy server determination.
The duration of the target VAS server enables the service packets to be processed by the VAS server in time to improve the user experience.
上面对本发明实施例的方法部分进行了描述,下面对本发明实施例的装置部分进行描述,请参阅图6,本发明实施例六提供的透明代理服务器包括:The method part of the embodiment of the present invention is described above. The device part of the embodiment of the present invention is described below. Referring to FIG. 6, the transparent proxy server provided in Embodiment 6 of the present invention includes:
获取单元601,用于获取用户端向WEB服务器发送的握手报文。The obtaining unit 601 is configured to obtain a handshake message sent by the UE to the WEB server.
可选地,所述获取单元601还用于获取所述目标WEB服务器的IP地址。Optionally, the obtaining unit 601 is further configured to acquire an IP address of the target WEB server.
其中,所述获取单元601获取所述目标WEB服务器的IP地址的方式包括至少如下两种:The manner in which the obtaining unit 601 obtains the IP address of the target WEB server includes at least the following two types:
一、所述获取单元601通过确定所述目标WEB服务器的域名,并根据所述目标WEB服务器的域名,确定所述目标WEB服务器的IP地址,然后再保存所述目标WEB服务器的IP地址。1. The obtaining unit 601 determines the domain name of the target WEB server, determines the IP address of the target WEB server according to the domain name of the target WEB server, and then saves the IP address of the target WEB server.
需要说明的是,所述获取单元601确定所述目标WEB服务器的域名,具体可以通过确定所述用户端使用第一WEB服务器的域名进行解析的第一次数和使用第二WEB服务器的域名进行解析的第二次数,所述第一次数大于第二次数,若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一WEB服务器的域名为所述目标WEB服务器的域名。It is to be noted that the obtaining unit 601 determines the domain name of the target WEB server, which may be determined by determining the first time that the user end uses the domain name of the first WEB server for parsing and the domain name of using the second WEB server. The second number of times, the first number of times is greater than the second number, and if the first number of times is greater than or equal to a preset ratio of the sum of the first number and the second number, determining the first The domain name of a WEB server is the domain name of the target WEB server.
二、所述获取单元601通过确定所述用户端向第一WEB服务器发送第一业务报文的第一次数和向第二WEB服务器发送第二业务报文的第二次数,所述第一次数大于第二次数,所述第一业务报文包括第一目的IP地址,所述第二业务报文包括第二目的IP地址;若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一目的IP地址为所述目标WEB服务器的IP地址,然后保存所述目标WEB服务器的IP地址。The first obtaining, by the acquiring unit 601, the first number of times that the user sends the first service packet to the first web server, and the second number of times that the second service packet is sent to the second web server, the first The number of times is greater than the second number, the first service packet includes a first destination IP address, and the second service packet includes a second destination IP address; if the first number of times is greater than or equal to the first time When the preset ratio is the sum of the number and the second number, the first destination IP address is determined to be the IP address of the target WEB server, and then the IP address of the target WEB server is saved.
可选地,所述获取单元601还用于获取所述对应关系。Optionally, the obtaining unit 601 is further configured to acquire the correspondence.
确定单元602,用于当确定所述握手报文中的目的IP地址为预置的目标WEB服务器的IP地址时,根据所述目的IP地址和对应关系,确定目标VAS服务器,所述对应关系为VAS服务器与所述目标WEB服务器的IP地址的对应关系。The determining unit 602 is configured to determine, according to the destination IP address and the corresponding relationship, a target VAS server, when the destination IP address in the handshake message is an IP address of a preset target WEB server, where the corresponding relationship is Correspondence between the VAS server and the IP address of the target WEB server.
构建单元603,用于构建所述用户端、所述目标VAS服务器和所述WEB服务器之间的连接,所述目标VAS服务器用于处理所述用户端与所述WEB服务器之间交互的业务报文。a building unit 603, configured to construct a connection between the user end, the target VAS server, and the WEB server, where the target VAS server is configured to process a service report between the user end and the WEB server. Text.
实施例六中,透明代理服务器通过预置的目标WEB服务器的IP地址与从
握手报文中获取到的目的IP地址进行匹配,并利用预置的目标WEB服务器的IP地址与VAS服务器的对应关系确定目标VAS服务器,在实际应用中,所述透明代理服务器还可以通过预置的目标WEB服务器的域名与VAS服务器的对应关系,从而确定目标VAS服务器。In the sixth embodiment, the transparent proxy server passes the IP address and the IP address of the preset target WEB server.
Match the destination IP address obtained in the handshake packet, and determine the target VAS server by using the mapping between the IP address of the preset target WEB server and the VAS server. In actual applications, the transparent proxy server can also be preset. The correspondence between the domain name of the target WEB server and the VAS server, thereby determining the target VAS server.
下面请继续参阅图6,对本发明实施例七提供的一种透明代理服务器进行描述,具体包括:The following is a description of a transparent proxy server according to Embodiment 7 of the present invention, which specifically includes:
获取单元601,用于获取用户端向WEB服务器发送的握手报文,所述握手报文中的目的IP地址为所述WEB服务器的IP地址.The obtaining unit 601 is configured to obtain a handshake message sent by the UE to the WEB server, where the destination IP address in the handshake message is an IP address of the WEB server.
可选地,所述获取单元601还用于获取所述目标服务器的域名。Optionally, the obtaining unit 601 is further configured to acquire a domain name of the target server.
其中,所述获取单元601还用于获取所述目标服务器的域名的方式包括至少如下两种:The manner in which the obtaining unit 601 is further configured to acquire the domain name of the target server includes at least the following two types:
一、所述获取单元601通过确定所述目标WEB服务器的IP地址,并根据所述目标WEB服务器的IP地址,确定所述目标WEB服务器的域名,再将所述目标WEB服务器的域名进行保存。1. The obtaining unit 601 determines the domain name of the target WEB server according to the IP address of the target WEB server, and saves the domain name of the target WEB server according to the IP address of the target WEB server.
需要说明的是,所述获取单元601确定所述目标WEB服务器的IP地址具体可以通过确定所述用户端向第一WEB服务器发送第一业务报文的第一次数和向第二WEB服务器发送第二业务报文的第二次数,所述第一次数大于第二次数,所述第一业务报文包括第一目的IP地址,所述第二业务报文包括第二目的IP地址;若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一目的IP地址为所述目标WEB服务器的IP地址。It is to be noted that the obtaining unit 601 determines that the IP address of the target WEB server may be sent to the second WEB server by determining the first time that the user sends the first service packet to the first WEB server. The second number of times of the second service packet, the first number of times is greater than the second number, the first service packet includes a first destination IP address, and the second service packet includes a second destination IP address; When the first number of times is greater than or equal to a preset ratio of the sum of the first number and the second number, determining that the first destination IP address is an IP address of the target WEB server.
二、所述获取单元601可以通过确定所述用户端使用第一WEB服务器的域名进行解析的第一次数和使用第二WEB服务器的域名进行解析的第二次数,所述第一次数大于第二次数;若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一WEB服务器的域名为所述目标WEB服务器的域名,然后将所述目标WEB服务器的域名进行保存。The obtaining unit 601 may determine the first number of times that the user end uses the domain name of the first WEB server for parsing and the second time that is parsed by using the domain name of the second WEB server, where the first number of times is greater than a second number of times; if the first number of times is greater than or equal to a preset ratio of the sum of the first number of times and the second number of times, determining that the domain name of the first WEB server is the domain name of the target WEB server And then save the domain name of the target WEB server.
可选地,所述获取单元601还用于获取所述第一对应关系。Optionally, the obtaining unit 601 is further configured to acquire the first correspondence.
可选地,所述获取单元601,还用于获取所述第二对应关系。Optionally, the obtaining unit 601 is further configured to acquire the second correspondence.
确定单元602,用于根据所述目的IP地址和第一对应关系,确定所述WEB服务器的域名,所述第一对应关系为WEB服务器的域名与WEB服务器的IP地址的对应关系;The determining unit 602 is configured to determine a domain name of the WEB server according to the destination IP address and the first correspondence, where the first correspondence is a correspondence between a domain name of the WEB server and an IP address of the WEB server;
所述确定单元602,还用于当确定所述WEB服务器的域名为预置的目标
WEB服务器的域名时,根据所述WEB服务器的域名和第二对应关系,确定目标VAS服务器,所述第二对应关系为VAS服务器与所述预置的目标WEB服务器的域名的对应关系;The determining unit 602 is further configured to: when determining that the domain name of the WEB server is a preset target
Determining, by the domain name of the WEB server, the target VAS server according to the domain name and the second correspondence of the WEB server, where the second correspondence is a correspondence between the VAS server and the domain name of the preset target WEB server;
构建单元603,用于构建所述用户端、所述目标VAS服务器和所述WEB服务器之间的连接,所述目标VAS服务器用于处理所述用户端与所述WEB服务器之间交互的业务报文。a building unit 603, configured to construct a connection between the user end, the target VAS server, and the WEB server, where the target VAS server is configured to process a service report between the user end and the WEB server. Text.
本发明实施例中,透明代理服务器通过获取单元601,获取握手报文中的目的IP地址,并在确定单元602确定所述目的IP地址为WEB服务器的IP地址时,根据WEB服务器的IP地址和第一对应关系,确定数据报文的目的IP地址对应的WEB服务器的域名,当判断出所述WEB服务器的域名为预置的目标WEB服务器的域名时,根据所述WEB服务器的域名和第二对应关系,确定VAS服务器,再利用构建单元603构建所述用户端、所述目标VAS服务器和所述WEB服务器之间的连接,使所述VAS服务器处理所述用户端与所述WEB服务器之间交互的业务报文,从而缩短该透明代理服务器确定目标VAS服务器的时长,使业务报文及时得到VAS服务器的处理,提升用户体验。In the embodiment of the present invention, the transparent proxy server obtains the destination IP address in the handshake packet through the obtaining unit 601, and when the determining unit 602 determines that the destination IP address is the IP address of the WEB server, according to the IP address of the WEB server. The first corresponding relationship determines the domain name of the WEB server corresponding to the destination IP address of the data packet, and when determining that the domain name of the WEB server is the domain name of the preset target WEB server, according to the domain name and the second domain of the WEB server Correspondingly, the VAS server is determined, and the connection between the client, the target VAS server and the WEB server is constructed by using the constructing unit 603, so that the VAS server processes between the client and the WEB server. The service packets are exchanged, so that the length of the target VAS server is determined by the transparent proxy server, so that the service packets are processed by the VAS server in time to improve the user experience.
如图7,为本发明实施例八提供的一种透明代理服务器,所述透明代理服务器700可以包括:FIG. 7 is a transparent proxy server according to Embodiment 8 of the present invention. The transparent proxy server 700 may include:
处理器701、存储器702、总线704和通信接口705。处理器701、存储器702和通信接口705之间通过总线704连接并完成相互间的通信。 Processor 701, memory 702, bus 704, and communication interface 705. The processor 701, the memory 702, and the communication interface 705 are connected by a bus 704 and complete communication with each other.
处理器701可能为单核或多核中央处理单元,或者为特定集成电路,或者为被配置成实施本发明实施例的一个或多个集成电路。 Processor 701 may be a single core or multi-core central processing unit, or a particular integrated circuit, or one or more integrated circuits configured to implement embodiments of the present invention.
存储器702可以为高速RAM存储器,也可以为非易失性存储器(non-volatile memory),例如至少一个磁盘存储器。The memory 702 may be a high speed RAM memory or a non-volatile memory such as at least one disk memory.
存储器702用于计算机执行指令703。具体的,计算机执行指令703中可以包括程序代码。Memory 702 is used by computer to execute instructions 703. Specifically, the computer execution instructions 703 may include program code.
当所述装置运行时,处理器701运行计算机执行指令703,可以执行图1至图5任意之一对应的方法实施例所述的报文处理方法。When the device is running, the processor 701 runs the computer execution instruction 703, and can execute the message processing method described in the method embodiment corresponding to any one of FIG. 1 to FIG.
所属领域的技术人员可以清楚地了解到,为描述的方便和简洁,上述描述的系统,装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。A person skilled in the art can clearly understand that for the convenience and brevity of the description, the specific working process of the system, the device and the unit described above can refer to the corresponding process in the foregoing method embodiment, and details are not described herein again.
在本申请所提供的几个实施例中,应该理解到,所揭露的系统,装置和方
法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。In the several embodiments provided by the present application, it should be understood that the disclosed system, device and method
The law can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the unit is only a logical function division. In actual implementation, there may be another division manner, for example, multiple units or components may be combined or Can be integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, and may be in an electrical, mechanical or other form.
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of the embodiment.
另外,在本发明各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
所述集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本发明的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本发明各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、磁碟或者光盘等各种可以存储程序代码的介质。The integrated unit, if implemented in the form of a software functional unit and sold or used as a standalone product, may be stored in a computer readable storage medium. Based on such understanding, the technical solution of the present invention, which is essential or contributes to the prior art, or all or part of the technical solution, may be embodied in the form of a software product stored in a storage medium. A number of instructions are included to cause a computer device (which may be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and the like. .
以上所述,以上实施例仅用以说明本发明的技术方案,而非对其限制;尽管参照前述实施例对本发明进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本发明各实施例技术方案的精神和范围。
The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to be limiting; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art will understand that The technical solutions described in the embodiments are modified, or the equivalents of the technical features are replaced by the equivalents of the technical solutions of the embodiments of the present invention.
Claims (27)
- 一种报文处理的方法,其特征在于,包括:A method for processing a message, comprising:透明代理服务器获取用户设备向WEB服务器发送的握手报文;The transparent proxy server obtains the handshake message sent by the user equipment to the WEB server;当确定所述握手报文中的目的IP地址为预置的目标WEB服务器的IP地址时,所述透明代理服务器根据所述目的IP地址和对应关系,确定目标VAS服务器,所述对应关系为VAS服务器与所述目标WEB服务器的IP地址的对应关系;When it is determined that the destination IP address in the handshake message is the IP address of the preset target WEB server, the transparent proxy server determines the target VAS server according to the destination IP address and the corresponding relationship, and the corresponding relationship is VAS. Correspondence between the server and the IP address of the target WEB server;所述透明代理服务器分别建立与所述用户设备、所述目标VAS服务器和所述WEB服务器之间的连接,将所述用户设备与所述WEB服务器之间交互的业务报文发给所述目标VAS服务器处理。The transparent proxy server establishes a connection with the user equipment, the target VAS server, and the WEB server, and sends a service packet exchanged between the user equipment and the WEB server to the target. VAS server processing.
- 根据权利要求1所述的方法,其特征在于,在所述透明代理服务器确定所述握手报文的目的IP地址为预置的目标WEB服务器的IP地址之前还包括:所述透明代理服务器获取所述目标WEB服务器的IP地址。The method according to claim 1, wherein before the transparent proxy server determines that the destination IP address of the handshake message is an IP address of the preset target WEB server, the method further includes: the transparent proxy server acquiring the location The IP address of the target WEB server.
- 根据权利要求2所述的方法,其特征在于,所述透明代理服务器获取所述目标WEB服务器的IP地址包括:The method according to claim 2, wherein the obtaining, by the transparent proxy server, the IP address of the target WEB server comprises:所述透明代理服务器确定所述目标WEB服务器的域名;Determining, by the transparent proxy server, a domain name of the target WEB server;所述透明代理服务器根据所述目标WEB服务器的域名,确定所述目标WEB服务器的IP地址;Determining, by the transparent proxy server, an IP address of the target WEB server according to the domain name of the target WEB server;所述透明代理服务器保存所述目标WEB服务器的IP地址。The transparent proxy server saves the IP address of the target WEB server.
- 根据权利要求3所述的方法,其特征在于,所述透明代理服务器确定目标WEB服务器的域名包括:The method according to claim 3, wherein the transparent proxy server determines that the domain name of the target WEB server comprises:所述透明代理服务器确定所述用户设备使用第一WEB服务器的域名进行解析的第一次数和使用第二WEB服务器的域名进行解析的第二次数,所述第一次数大于第二次数;The transparent proxy server determines a first number of times that the user equipment uses the domain name of the first WEB server for parsing and a second number that is parsed by using the domain name of the second WEB server, where the first number of times is greater than the second number of times;若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一WEB服务器的域名为所述目标WEB服务器的域名。If the first number of times is greater than or equal to a preset ratio of the sum of the first number of times and the second number of times, determining that the domain name of the first WEB server is the domain name of the target WEB server.
- 根据权利要求2所述的方法,其特征在于,所述透明代理服务器获取所述目标WEB服务器的IP地址包括:The method according to claim 2, wherein the obtaining, by the transparent proxy server, the IP address of the target WEB server comprises:所述透明代理服务器确定所述用户设备向第一WEB服务器发送第一业务报文的第一次数和向第二WEB服务器发送第二业务报文的第二次数,所述第一次数大于第二次数,所述第一业务报文包括第一目的IP地址,所述第二业务 报文包括第二目的IP地址;The transparent proxy server determines a first number of times that the user equipment sends the first service packet to the first WEB server and a second number of times that the second service packet is sent to the second WEB server, where the first number of times is greater than The second service, the first service packet includes a first destination IP address, and the second service The message includes a second destination IP address;若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一目的IP地址为所述目标WEB服务器的IP地址;If the first number of times is greater than or equal to a preset ratio of the sum of the first number of times and the second number of times, determining that the first destination IP address is an IP address of the target WEB server;所述透明代理服务器保存所述目标WEB服务器的IP地址。The transparent proxy server saves the IP address of the target WEB server.
- 根据权利要求1至5中任一项所述的方法,其特征在于,在所述透明代理服务器根据所述目的IP地址和对应关系,确定目标VAS服务器之前还包括:所述透明代理服务器获取所述对应关系。The method according to any one of claims 1 to 5, wherein before the determining, by the transparent proxy server, the target VAS server according to the destination IP address and the correspondence, the transparent proxy server further comprises: the transparent proxy server acquiring the location Represent the correspondence.
- 一种报文处理的方法,其特征在于,包括:A method for processing a message, comprising:透明代理服务器获取用户设备向WEB服务器发送的握手报文,所述握手报文中的目的IP地址为所述WEB服务器的IP地址;The transparent proxy server obtains the handshake message sent by the user equipment to the WEB server, where the destination IP address in the handshake message is the IP address of the WEB server;所述透明代理服务器根据所述目的IP地址和第一对应关系,确定所述WEB服务器的域名,所述第一对应关系为WEB服务器的域名与WEB服务器的IP地址的对应关系;Determining, by the transparent proxy server, the domain name of the WEB server according to the destination IP address and the first correspondence, where the first correspondence is a correspondence between a domain name of the WEB server and an IP address of the WEB server;当确定所述WEB服务器的域名为预置的目标WEB服务器的域名时,所述透明代理服务器根据所述WEB服务器的域名和第二对应关系,确定目标VAS服务器,所述第二对应关系为VAS服务器与所述预置的目标WEB服务器的域名的对应关系;When the domain name of the WEB server is determined to be the domain name of the preset target WEB server, the transparent proxy server determines the target VAS server according to the domain name and the second correspondence of the WEB server, and the second correspondence is VAS. Correspondence between the server and the domain name of the preset target WEB server;所述透明代理服务器分别建立与所述用户设备、所述目标VAS服务器和所述WEB服务器之间的连接,将所述用户端与所述WEB服务器之间交互的业务报文发送给所述目标VAS服务器处理。The transparent proxy server establishes a connection with the user equipment, the target VAS server, and the WEB server, and sends a service packet exchanged between the user end and the WEB server to the target. VAS server processing.
- 根据权利要求7所述的方法,其特征在于,在所述透明代理服务器确定所述WEB服务器的域名为预置的目标WEB服务器的域名之前还包括:所述透明代理服务器获取所述目标服务器的域名。The method according to claim 7, wherein before the transparent proxy server determines that the domain name of the WEB server is the domain name of the preset target WEB server, the method further includes: the transparent proxy server acquiring the target server domain name.
- 根据权利要求8所述的方法,其特征在于,所述透明代理服务器获取所述目标WEB服务器的域名包括:The method according to claim 8, wherein the obtaining, by the transparent proxy server, the domain name of the target WEB server comprises:所述透明代理服务器确定所述目标WEB服务器的IP地址;The transparent proxy server determines an IP address of the target WEB server;所述透明代理服务器根据所述目标WEB服务器的IP地址,确定所述目标WEB服务器的域名;Determining, by the transparent proxy server, a domain name of the target WEB server according to an IP address of the target WEB server;所述透明代理服务器保存所述目标WEB服务器的域名。The transparent proxy server saves the domain name of the target WEB server.
- 根据权利要求9所述的方法,其特征在于,所述透明代理服务器确定所述目标WEB服务器的IP地址包括: The method according to claim 9, wherein the transparent proxy server determines that the IP address of the target WEB server comprises:所述透明代理服务器确定所述用户端向第一WEB服务器发送第一业务报文的第一次数和向第二WEB服务器发送第二业务报文的第二次数,所述第一次数大于第二次数,所述第一业务报文包括第一目的IP地址,所述第二业务报文包括第二目的IP地址;The transparent proxy server determines a first number of times that the user sends the first service packet to the first web server, and a second number of times that the second service packet is sent to the second web server, where the first number of times is greater than The second service packet includes a first destination IP address, and the second service packet includes a second destination IP address.若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一目的IP地址为所述目标WEB服务器的IP地址。And determining, when the first number of times is greater than or equal to a preset ratio of the sum of the first number and the second number, determining that the first destination IP address is an IP address of the target WEB server.
- 根据权利要求8所述的方法,其特征在于,所述透明代理服务器获取所述目标WEB服务器的域名包括:The method according to claim 8, wherein the obtaining, by the transparent proxy server, the domain name of the target WEB server comprises:所述透明代理服务器确定所述用户端使用第一WEB服务器的域名进行解析的第一次数和使用第二WEB服务器的域名进行解析的第二次数,所述第一次数大于第二次数;Determining, by the transparent proxy server, a first number of times that the user end uses the domain name of the first WEB server for parsing and a second time that is parsed by using the domain name of the second WEB server, where the first number of times is greater than the second number of times;若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一WEB服务器的域名为所述目标WEB服务器的域名;If the first number of times is greater than or equal to a preset ratio of the sum of the first number of times and the second number of times, determining that the domain name of the first WEB server is the domain name of the target WEB server;所述透明代理服务器保存所述目标WEB服务器的域名。The transparent proxy server saves the domain name of the target WEB server.
- 根据权利要求7至11中任一项所述的方法,其特征在于,在所述透明代理服务器根据所述目的IP地址和第一对应关系,确定WEB服务器的域名之前还包括:所述透明代理服务器获取所述第一对应关系。The method according to any one of claims 7 to 11, wherein before the transparent proxy server determines the domain name of the WEB server according to the destination IP address and the first correspondence, the transparent proxy server further includes: the transparent proxy The server acquires the first correspondence.
- 根据权利要求7至11中任一项所述的方法,其特征在于,在所述透明代理服务器根据所述WEB服务器的域名和第二对应关系,确定目标VAS服务器之前还包括:所述透明代理服务器获取所述第二对应关系。The method according to any one of claims 7 to 11, wherein before the determining, by the transparent proxy server, the target VAS server according to the domain name and the second correspondence of the WEB server, the transparent proxy further comprises: the transparent proxy The server acquires the second correspondence.
- 一种透明代理服务器,其特征在于,包括:A transparent proxy server, comprising:获取单元,用于获取用户设备向WEB服务器发送的握手报文;An obtaining unit, configured to obtain a handshake message sent by the user equipment to the WEB server;确定单元,用于当确定所述握手报文中的目的IP地址为预置的目标WEB服务器的IP地址时,根据所述目的IP地址和对应关系,确定目标VAS服务器,所述对应关系为VAS服务器与所述目标WEB服务器的IP地址的对应关系;a determining unit, configured to determine a target VAS server according to the destination IP address and the corresponding relationship when determining that the destination IP address in the handshake packet is an IP address of a preset target WEB server, where the correspondence is VAS Correspondence between the server and the IP address of the target WEB server;构建单元,用于分别建立与所述用户端、所述目标VAS服务器和所述WEB服务器之间的连接,将所述用户端与所述WEB服务器之间交互的业务报文发送给所述目标VAS服务器处理。a building unit, configured to separately establish a connection with the user end, the target VAS server, and the WEB server, and send a service packet exchanged between the user end and the WEB server to the target VAS server processing.
- 根据权利要求14所述的透明代理服务器,其特征在于,所述获取单元还用于获取所述目标WEB服务器的IP地址。The transparent proxy server according to claim 14, wherein the obtaining unit is further configured to acquire an IP address of the target WEB server.
- 根据权利要求15所述的透明代理服务器,其特征在于,所述获取单元 具体用于确定所述目标WEB服务器的域名;The transparent proxy server according to claim 15, wherein said obtaining unit Specifically, the domain name of the target WEB server is determined;根据所述目标WEB服务器的域名,确定所述目标WEB服务器的IP地址;Determining an IP address of the target WEB server according to the domain name of the target WEB server;保存所述目标WEB服务器的IP地址。Save the IP address of the target WEB server.
- 根据权利要求16所述的透明代理服务器,其特征在于,所述获取单元具体用于确定所述用户设备使用第一WEB服务器的域名进行解析的第一次数和使用第二WEB服务器的域名进行解析的第二次数,所述第一次数大于第二次数;The transparent proxy server according to claim 16, wherein the obtaining unit is specifically configured to determine a first time that the user equipment uses the domain name of the first WEB server for parsing and a domain name of the second WEB server. a second number of times of parsing, the first number of times being greater than the second number of times;若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一WEB服务器的域名为所述目标WEB服务器的域名。If the first number of times is greater than or equal to a preset ratio of the sum of the first number of times and the second number of times, determining that the domain name of the first WEB server is the domain name of the target WEB server.
- 根据权利要求15所述的透明代理服务器,其特征在于,所述获取单元具体用于确定所述用户设备向第一WEB服务器发送第一业务报文的第一次数和向第二WEB服务器发送第二业务报文的第二次数,所述第一次数大于第二次数,所述第一业务报文包括第一目的IP地址,所述第二业务报文包括第二目的IP地址;The transparent proxy server according to claim 15, wherein the obtaining unit is specifically configured to determine a first time that the user equipment sends a first service packet to the first WEB server and send the first service packet to the second WEB server. The second number of times of the second service packet, the first number of times is greater than the second number of times, the first service packet includes a first destination IP address, and the second service packet includes a second destination IP address;若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一目的IP地址为所述目标WEB服务器的IP地址,保存所述目标WEB服务器的IP地址。If the first number of times is greater than or equal to a preset ratio of the sum of the first number of times and the second number of times, determining that the first destination IP address is an IP address of the target WEB server, and saving the The IP address of the target WEB server.
- 根据权利要求14至18中任一项所述的透明代理服务器,其特征在于,所述获取单元还用于获取所述对应关系。The transparent proxy server according to any one of claims 14 to 18, wherein the obtaining unit is further configured to acquire the correspondence.
- 一种透明代理服务器,其特征在于,包括:A transparent proxy server, comprising:获取单元,用于获取用户设备向WEB服务器发送的握手报文,所述握手报文中的目的IP地址为所述WEB服务器的IP地址;An obtaining unit, configured to obtain a handshake message sent by the user equipment to the WEB server, where the destination IP address in the handshake message is an IP address of the WEB server;确定单元,用于根据所述目的IP地址和第一对应关系,确定所述WEB服务器的域名,所述第一对应关系为WEB服务器的域名与WEB服务器的IP地址的对应关系;a determining unit, configured to determine a domain name of the WEB server according to the destination IP address and the first correspondence, where the first correspondence is a correspondence between a domain name of the WEB server and an IP address of the WEB server;所述确定单元,还用于当确定所述WEB服务器的域名为预置的目标WEB服务器的域名时,根据所述WEB服务器的域名和第二对应关系,确定目标VAS服务器,所述第二对应关系为VAS服务器与所述预置的目标WEB服务器的域名的对应关系;The determining unit is further configured to: when determining that the domain name of the WEB server is the domain name of the preset target WEB server, determine the target VAS server according to the domain name and the second correspondence of the WEB server, and the second corresponding The relationship is a correspondence between the VAS server and the domain name of the preset target WEB server;构建单元,用于分别建立与所述用户端、所述目标VAS服务器和所述WEB服务器之间的连接,将所述用户端与所述WEB服务器之间交互的业务报文发 送给所述目标VAS服务器处理。a building unit, configured to establish a connection with the user end, the target VAS server, and the WEB server, and send a service packet exchanged between the user end and the WEB server Send to the target VAS server for processing.
- 根据权利要求20所述的透明代理服务器,其特征在于,所述获取单元,还用于获取所述目标服务器的域名。The transparent proxy server according to claim 20, wherein the obtaining unit is further configured to acquire a domain name of the target server.
- 根据权利要求21所述的透明代理服务器,其特征在于,所述获取单元具体用于确定所述目标WEB服务器的IP地址;The transparent proxy server according to claim 21, wherein the obtaining unit is specifically configured to determine an IP address of the target WEB server;根据所述目标WEB服务器的IP地址,确定所述目标WEB服务器的域名;Determining, according to an IP address of the target WEB server, a domain name of the target WEB server;保存所述目标WEB服务器的域名。Save the domain name of the target WEB server.
- 根据权利要求22所述的透明代理服务器,其特征在于,所述获取单元具体用于确定所述用户设备向第一WEB服务器发送第一业务报文的第一次数和向第二WEB服务器发送第二业务报文的第二次数,所述第一次数大于第二次数,所述第一业务报文包括第一目的IP地址,所述第二业务报文包括第二目的IP地址;The transparent proxy server according to claim 22, wherein the obtaining unit is configured to determine a first time that the user equipment sends a first service packet to the first WEB server and send the first service packet to the second WEB server. The second number of times of the second service packet, the first number of times is greater than the second number of times, the first service packet includes a first destination IP address, and the second service packet includes a second destination IP address;若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一目的IP地址为所述目标WEB服务器的IP地址。And determining, when the first number of times is greater than or equal to a preset ratio of the sum of the first number and the second number, determining that the first destination IP address is an IP address of the target WEB server.
- 根据权利要求21所述的透明代理服务器,其特征在于,所述获取单元具体用于确定所述用户设备使用第一WEB服务器的域名进行解析的第一次数和使用第二WEB服务器的域名进行解析的第二次数,所述第一次数大于第二次数;The transparent proxy server according to claim 21, wherein the obtaining unit is specifically configured to determine a first time that the user equipment uses the domain name of the first WEB server for parsing and a domain name of the second WEB server. a second number of times of parsing, the first number of times being greater than the second number of times;若所述第一次数大于或等于所述第一次数与第二次数之和的预置比例时,则确定所述第一WEB服务器的域名为所述目标WEB服务器的域名;If the first number of times is greater than or equal to a preset ratio of the sum of the first number of times and the second number of times, determining that the domain name of the first WEB server is the domain name of the target WEB server;保存所述目标WEB服务器的域名。Save the domain name of the target WEB server.
- 根据权利要求20至24中任一项所述的透明代理服务器,其特征在于,所述获取单元还用于所述第一对应关系。The transparent proxy server according to any one of claims 20 to 24, wherein the obtaining unit is further used for the first correspondence.
- 根据权利要求20至24中任一项所述的透明代理服务器,其特征在于,所述获取单元还用于获取所述第二对应关系。The transparent proxy server according to any one of claims 20 to 24, wherein the obtaining unit is further configured to acquire the second correspondence.
- 一种透明代理服务器,其特征在于,包括处理器、存储器、总线和通信接口;A transparent proxy server, comprising: a processor, a memory, a bus, and a communication interface;所述存储器用于存储计算机执行指令,所述处理器与所述存储器通过所述总线连接,当所述移动性管理实体运行时,所述处理器执行所述存储器存储的所述计算机执行指令,以使所述移动性管理实体执行如权利要求1至13中任一项所述的报文处理的方法。 The memory is configured to store computer execution instructions, the processor is coupled to the memory via the bus, and when the mobility management entity is running, the processor executes the computer execution instructions stored by the memory, A method of causing the mobility management entity to perform the message processing according to any one of claims 1 to 13.
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201410733682.7A CN104518968B (en) | 2014-12-04 | 2014-12-04 | The method and Transparent proxy server of a kind of Message processing |
CN201410733682.7 | 2014-12-04 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2016086755A1 true WO2016086755A1 (en) | 2016-06-09 |
Family
ID=52793716
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/CN2015/094131 WO2016086755A1 (en) | 2014-12-04 | 2015-11-09 | Packet processing method and transparent proxy server |
Country Status (2)
Country | Link |
---|---|
CN (1) | CN104518968B (en) |
WO (1) | WO2016086755A1 (en) |
Families Citing this family (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN104518968B (en) * | 2014-12-04 | 2018-07-03 | 华为技术有限公司 | The method and Transparent proxy server of a kind of Message processing |
CN104994137B (en) * | 2015-05-27 | 2019-01-22 | 四川卫士通信息安全平台技术有限公司 | A kind of method of network readezvous point agency |
CN105119982B (en) * | 2015-07-23 | 2019-02-22 | 中国联合网络通信集团有限公司 | The method and device of increment processing |
JP6579884B2 (en) * | 2015-09-24 | 2019-09-25 | キヤノン株式会社 | Communication device, control method, and program |
CN113726915A (en) * | 2020-05-25 | 2021-11-30 | 华为技术有限公司 | Network system, message transmission method therein and related device |
CN112954683B (en) * | 2021-05-13 | 2021-08-17 | 中兴通讯股份有限公司 | Domain name resolution method, domain name resolution device, electronic equipment and storage medium |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2010049940A1 (en) * | 2008-10-31 | 2010-05-06 | Onmobile Global Limited | Method and system of providing vas in a communication network |
CN102256348A (en) * | 2010-05-21 | 2011-11-23 | 华为技术有限公司 | Routing method, device and system for uplink message |
CN103931162A (en) * | 2014-01-20 | 2014-07-16 | 华为技术有限公司 | Method for processing service and network equipment |
CN104518968A (en) * | 2014-12-04 | 2015-04-15 | 华为技术有限公司 | Message processing method and transparent proxy server |
-
2014
- 2014-12-04 CN CN201410733682.7A patent/CN104518968B/en active Active
-
2015
- 2015-11-09 WO PCT/CN2015/094131 patent/WO2016086755A1/en active Application Filing
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2010049940A1 (en) * | 2008-10-31 | 2010-05-06 | Onmobile Global Limited | Method and system of providing vas in a communication network |
CN102256348A (en) * | 2010-05-21 | 2011-11-23 | 华为技术有限公司 | Routing method, device and system for uplink message |
CN103931162A (en) * | 2014-01-20 | 2014-07-16 | 华为技术有限公司 | Method for processing service and network equipment |
CN104518968A (en) * | 2014-12-04 | 2015-04-15 | 华为技术有限公司 | Message processing method and transparent proxy server |
Also Published As
Publication number | Publication date |
---|---|
CN104518968A (en) | 2015-04-15 |
CN104518968B (en) | 2018-07-03 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
WO2016086755A1 (en) | Packet processing method and transparent proxy server | |
US10659354B2 (en) | Processing data packets using a policy based network path | |
US10587544B2 (en) | Message processing method, processing server, terminal, and storage medium | |
EP3275162B1 (en) | Systems and techniques for web communication | |
US10392823B2 (en) | Synthetic client | |
US9722806B2 (en) | Service discovery across different networks | |
US20150229669A1 (en) | Method and device for detecting distributed denial of service attack | |
US9554276B2 (en) | System and method for on the fly protocol conversion in obtaining policy enforcement information | |
US10034057B2 (en) | Message processing method, device, gateway, STB and IPTV | |
WO2015158064A1 (en) | Communication protocol conversion method, device and storage media | |
WO2016082371A1 (en) | Ssh protocol-based session parsing method and system | |
KR20180004093A (en) | Transmitting media content during instant messaging | |
EP3331213A1 (en) | Access to data on a remote device | |
WO2014101661A1 (en) | Service flow mirroring method and mirroring device | |
EP3668043A1 (en) | Method for identifying encrypted data stream, device, storage medium, and system | |
CN103401946A (en) | HTTP (hyper text transfer protocol) uploading acceleration method and system | |
WO2023103318A1 (en) | Media streaming method and system | |
WO2019001562A1 (en) | Model loading method and apparatus, storage medium, and computer device | |
CN104079629A (en) | HTTP request message monitoring method and gateway based on cookie information | |
CN106789413A (en) | A kind of method and apparatus for detecting proxy surfing | |
US10129320B2 (en) | QoS improvement method, apparatus, and system | |
WO2013044483A1 (en) | Access processing method, apparatus and system | |
WO2016106557A1 (en) | Method and apparatus for sending video | |
EP3176986A1 (en) | Method, device and system for remote desktop protocol gateway to conduct routing and switching | |
WO2014101095A1 (en) | Redirection method and network device |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 15865726 Country of ref document: EP Kind code of ref document: A1 |
|
NENP | Non-entry into the national phase |
Ref country code: DE |
|
122 | Ep: pct application non-entry in european phase |
Ref document number: 15865726 Country of ref document: EP Kind code of ref document: A1 |