WO2021093510A1 - 网络业务的处理方法、系统和网关设备 - Google Patents

网络业务的处理方法、系统和网关设备 Download PDF

Info

Publication number
WO2021093510A1
WO2021093510A1 PCT/CN2020/121251 CN2020121251W WO2021093510A1 WO 2021093510 A1 WO2021093510 A1 WO 2021093510A1 CN 2020121251 W CN2020121251 W CN 2020121251W WO 2021093510 A1 WO2021093510 A1 WO 2021093510A1
Authority
WO
WIPO (PCT)
Prior art keywords
intranet
software package
gateway device
intranet device
gateway
Prior art date
Application number
PCT/CN2020/121251
Other languages
English (en)
French (fr)
Inventor
蒋武
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to CA3157038A priority Critical patent/CA3157038A1/en
Priority to EP20888021.1A priority patent/EP4047885A4/en
Priority to MX2022005625A priority patent/MX2022005625A/es
Priority to JP2022526740A priority patent/JP7383145B2/ja
Publication of WO2021093510A1 publication Critical patent/WO2021093510A1/zh
Priority to US17/742,341 priority patent/US11843518B2/en
Priority to US18/511,806 priority patent/US20240089178A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/12Avoiding congestion; Recovering from congestion
    • H04L47/125Avoiding congestion; Recovering from congestion by balancing the load, e.g. traffic engineering
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/66Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F8/00Arrangements for software engineering
    • G06F8/60Software deployment
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0803Configuration setting
    • H04L41/0806Configuration setting for initial configuration or provisioning, e.g. plug-and-play
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0894Policy-based network configuration management
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/20Network management software packages
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/50Network service management, e.g. ensuring proper service fulfilment according to agreements
    • H04L41/5003Managing SLA; Interaction between SLA and QoS
    • H04L41/5006Creating or negotiating SLA contracts, guarantees or penalties
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/50Network service management, e.g. ensuring proper service fulfilment according to agreements
    • H04L41/5003Managing SLA; Interaction between SLA and QoS
    • H04L41/5009Determining service level performance parameters or violations of service level contracts, e.g. violations of agreed response time or mean time between failures [MTBF]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/74Address processing for routing
    • H04L45/745Address table lookup; Address filtering
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/34Network arrangements or protocols for supporting network services or applications involving the movement of software or configuration parameters 
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/50Network services
    • H04L67/56Provisioning of proxy services
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/50Network service management, e.g. ensuring proper service fulfilment according to agreements
    • H04L41/5041Network service management, e.g. ensuring proper service fulfilment according to agreements characterised by the time relationship between creation and deployment of a service

Definitions

  • This application relates to the field of computer and communication technology, and in particular to a network service processing method, a network service processing system, and a gateway device.
  • Gateway (Gateway) equipment is used to connect two networks. It is an important type of basic equipment for many organizations such as enterprises, campuses, and homes to build a local area network. Various types of local area networks are connected to the Internet through gateway devices. The basic function of a gateway device is to forward packets between two networks. For user needs and cost considerations, in many scenarios, gateway devices often need to integrate multiple additional functions, such as firewall functions, security sandbox functions, or network caching (also known as "net disk”) functions, and so on.
  • the gateway device is restricted by its own hardware resources, and it is difficult to support more additional functions. Integrating a variety of additional functions will often significantly reduce the performance of the gateway device, thereby affecting the normal operation of the entire LAN system. How to solve this contradiction has become an urgent problem to be solved.
  • the embodiment of the present application provides a method for processing network services to alleviate the problem that the gateway device cannot meet more and more requirements for additional functions.
  • a method for processing network services is provided.
  • the gateway device identifies the type of the first intranet device, and the first intranet device belongs to the internal network to which the gateway device is connected.
  • the gateway device obtains a first software package according to the type of the first intranet device, where the first software package is used to implement the first additional function.
  • the gateway device sends a first instruction message and the first software package to the first intranet device, where the first instruction message is used to instruct the first intranet device to install the first software package and execute the The first additional function.
  • the gateway device acts as the main body of management and control that implements additional functions, and according to the type of the intranet device, controls the appropriate intranet device to install a software package to implement the additional function.
  • the processing burden of the gateway device is reduced, the processing resources and storage resources of the gateway device are saved, and a low-cost implementation of gateway device addition is provided Functional scheme.
  • the solution uses the idle resources of the intranet equipment to implement additional functions, which improves the utilization of intranet resources.
  • the gateway device determines the software package to be installed on the intranet device according to the performance of the intranet device.
  • the gateway device obtains the first software package in the following manner.
  • the gateway device determines the performance of the first intranet device according to the type of the first intranet device, the performance includes software capabilities and hardware capabilities, the software capabilities include whether to support the installation of software packages, and the hardware capabilities include Processor performance value and/or storage space size.
  • the gateway device obtains the first software package according to the performance of the first intranet device, and the performance of the first intranet device meets the installation performance requirements of the first software package. Using the performance of the intranet device to determine the software package to be installed on the intranet device will greatly improve the implementation effect and performance of additional functions.
  • the gateway device saves the corresponding relationship between the software package and the installation performance requirements, so that the gateway device can find the first in the corresponding relationship between the software package and the installation performance requirements according to the performance of the first intranet device.
  • Software package
  • the gateway device obtains the first software package in the following manner. According to the performance of the first intranet device, the gateway device finds the identifier of the first software package in the corresponding relationship between the identifier of the software package and the installation performance requirement. The gateway device sends the identifier of the first software package to the server, and receives the first software package returned by the server according to the identifier of the first software package.
  • the function of matching a suitable software package according to the performance of the intranet device may also be shared by the server.
  • the gateway device obtains the first software package in the following manner.
  • the gateway device sends the performance of the first intranet device to the server.
  • the gateway device receives the first software package returned by the server according to the performance of the first internal and external devices.
  • the steps of querying the installation performance requirements according to the type of the first intranet device and the steps of obtaining the first software package according to the performance are all performed by the server.
  • the gateway device obtains the first software package in the following manner.
  • the gateway device sends the type of the first intranet device to the server.
  • the gateway device receives the first software package returned by the server according to the type of the first internal and external device.
  • the gateway device in the case where the first software package determined for two or more different intranet devices is the same software package, there may be multiple Intranet devices perform the same additional function after installing the same software package, which may cause waste of intranet device resources or conflicts in the implementation of additional functions.
  • the gateway device before the gateway device sends the first indication message and the first software package to the first intranet device, the gateway device identifies the type of the second intranet device, and the second intranet device The device belongs to the internal network. The gateway device determines the performance of the second intranet device according to the type of the second intranet device.
  • the gateway device finds the second software package in the corresponding relationship between the software package and the installation performance requirements according to the performance of the second intranet device, and the performance of the second intranet device meets the requirements of the second software package. Installation performance requirements; if the first software package and the second software package are the same software package, the gateway device selects the first intranet device from the first intranet device and the second intranet device An intranet device is used to install the first software package.
  • the gateway device can select the first intranet device from the first intranet device and the second intranet device in a variety of ways, for example, randomly selected or selected according to a strategy. For example, the gateway device selects from the first intranet device and the second intranet device according to the performance of the first intranet device and the performance of the second intranet device according to a predetermined selection strategy The first intranet device is used to install the first software package.
  • the gateway device in order to facilitate the subsequent correct forwarding of the data stream to be executed with the first additional function (that is, the target data stream), so as to correctly execute the first additional function, After the gateway device sends the first indication message and the first software package to the first intranet device, it saves the correspondence between the identifier of the first intranet device and the first additional function.
  • the gateway device obtains a target data stream, where the target data stream is a data stream for which the first additional function is to be executed.
  • the gateway device sends the target data stream to the first intranet device according to the correspondence between the identifier of the first intranet device and the first additional function, and receives a pair of the first intranet device The processing result of the target data stream.
  • the gateway device After receiving the processing result of the target data stream by the first intranet device, the gateway device performs an action corresponding to the processing result on the target data stream according to the processing result, and the action includes Forward, alert or block.
  • the gateway device in order to facilitate the subsequent correct forwarding of the data stream to be executed with the first additional function (that is, the target data stream), so as to correctly execute the first additional function, After the gateway device sends the first indication message and the first software package to the first intranet device, it saves the correspondence between the identifier of the first intranet device and the first additional function.
  • the gateway device obtains a target data stream, where the target data stream is a data stream for which the first additional function is to be executed.
  • the gateway device determines description information, and the description information is used to describe the target data flow.
  • the gateway device sends the description information to the first intranet device according to the correspondence between the identifier of the first intranet device and the first additional function, and receives the first intranet device’s response to the Describe the processing result of the description information.
  • the gateway device sends description information to the first intranet device instead of the target data stream, which can reduce the amount of data sent by the gateway device to the intranet device that performs additional functions.
  • the gateway device After receiving the processing result of the description information by the first intranet device, the gateway device performs an action corresponding to the processing result on the target data stream according to the processing result, and the action includes forwarding , Alarm or block.
  • the gateway device before the gateway device sends the first indication message and the first software package to the first intranet device, Output prompt information.
  • the prompt information includes the corresponding relationship between the identifier of the first intranet device and the first additional function, and the prompt information is used to prompt the first intranet device to be capable of executing the first additional function. Capability of additional functions; receiving input confirmation information, where the confirmation information is used to indicate that the first intranet device is allowed to perform the first additional function.
  • the gateway device recognizes the type of the first intranet device through multiple possible implementation manners. In the actual application process, one or more of these identification methods can be selected according to different needs.
  • One way is to identify the type of the first intranet device from the forwarded traffic.
  • the gateway device intercepts the characteristic message sent by the first intranet device, the characteristic message carries a first characteristic field, and the content of the first characteristic field is used to indicate the operating system type of the sender or a predetermined website domain name .
  • the gateway device queries the first device type corresponding to the content of the first feature field in the feature database, and the feature database saves the correspondence between the content of the first feature field and the first device type; the gateway device determines The device type of the first intranet device is the first device type.
  • the second way is to identify based on the MAC address.
  • the gateway device obtains the MAC address of the first intranet device; the gateway device queries the device information database for the first device type corresponding to the MAC address of the first intranet device, and the device information database stores the Correspondence between the MAC address of the first intranet device and the first device type; the gateway device determines that the device type of the first intranet device is the first device type.
  • the third method is active scanning detection.
  • the gateway device sends a detection message to the first intranet device; the gateway device receives a response message corresponding to the detection message sent by the first intranet device; the gateway device according to the response message Obtain the first identification fingerprint; the gateway device queries the fingerprint database for the first device type corresponding to the first identification fingerprint, and the fingerprint database saves the correspondence between the first identification fingerprint and the first device type The gateway device determines that the device type of the first intranet device is the first device type.
  • the first additional function is a data stream security detection function, a network cache function, or a security sandbox function.
  • the target data stream is a data stream to be detected.
  • the target data stream is a data stream carrying content to be cached.
  • the target data stream is a data stream carrying the content of the file to be detected.
  • a gateway device in a second aspect, includes a network interface, a memory, and a processor connected to the memory.
  • the memory is used to store instructions; the processor is used to execute the instructions, so that the gateway device executes the method in the first aspect or any one of the possible implementations of the first aspect. For details, refer to the detailed description above , I won’t repeat it here.
  • a network service processing device has the function of implementing the method described in the first aspect or any one of the possible implementation manners of the foregoing aspects.
  • the function can be realized by hardware, or by hardware executing corresponding software.
  • the hardware or software includes one or more modules corresponding to the above-mentioned functions.
  • an embodiment of the present application provides a computer storage medium for storing computer software instructions used by the above-mentioned gateway device, which includes instructions for executing the above-mentioned first aspect or any one of the possible implementations of the above-mentioned aspects. Designed procedures.
  • another aspect of the present application provides a computer program product containing instructions, which when run on a computer, causes the computer to execute the methods described in the foregoing aspects.
  • an embodiment of the present application provides a chip including a memory and a processor, the memory is used to store computer instructions, and the processor is used to call and run the computer instructions from the memory to execute the first aspect and its first The method in any possible implementation of the aspect.
  • FIG. 1 is a schematic diagram of an application scenario of a network service processing solution provided by an embodiment of the present application
  • FIG. 2 is a flowchart of a network service processing method provided by an embodiment of the present application.
  • FIG. 3 is a flowchart of the first method of identifying the type of intranet device provided by an embodiment of the present application
  • FIG. 4 is a flowchart of a second method of identifying the type of an intranet device provided by an embodiment of the present application
  • FIG. 5 is a flowchart of a third method of identifying the type of an intranet device provided by an embodiment of the present application.
  • FIG. 6 is a flowchart of a method for selecting a software package installed by an intranet device based on the performance of an intranet device according to an embodiment of the present application;
  • FIG. 7 is a flowchart of another network service processing method provided by an embodiment of the present application.
  • FIG. 8 is a flowchart of obtaining the first software package according to the performance of the first intranet device in the distributed storage solution 1 provided by the embodiment of the present application;
  • FIG. 9 is a flowchart of the gateway device acquiring the first software package according to the performance of the first intranet device in the distributed storage solution 2 provided by the embodiment of the present application;
  • FIG. 10 is a flowchart of the gateway device acquiring the first software package according to the performance of the first intranet device in the distributed storage solution 3 provided by the embodiment of the present application;
  • FIG. 11 is a flowchart of another network service processing method provided by an embodiment of the present application.
  • FIG. 12 is a flowchart of another network service processing method provided by an embodiment of the present application.
  • FIG. 13 is a schematic structural diagram of a gateway device provided by an embodiment of the present application.
  • FIG. 14 is a schematic structural diagram of a network service processing apparatus provided by an embodiment of the present application.
  • Integrating more additional functions on the gateway device not only provides convenience to users, but also makes the gateway device easy to become a performance bottleneck. Especially in scenarios where there are a large number of hosts in the corporate LAN to which the gateway device is connected, or in scenarios where the home router itself used as a home LAN gateway has low performance, it is often difficult for the gateway device to support the integration of more and more add-ons.
  • the embodiments of the present application provide a method for processing network services. Based on this method, under the management and control of the gateway equipment, the internal network equipment in the internal network connected by the gateway equipment performs certain additional functions, and part of the burden of the gateway equipment performing additional functions is transferred to the internal network equipment, thereby reducing
  • the processing burden of the gateway device provides a low-cost solution for implementing additional functions of the gateway device.
  • the gateway device first identifies the type of the internal network device in the connected internal network, and further sends a suitable software package for implementing certain additional functions to the internal network device according to the type of the internal network device. After installing the software package, the intranet device realizes the corresponding additional functions.
  • Fig. 1 is a schematic diagram of an application scenario of a network service processing solution provided by an embodiment of the present application.
  • This application scenario includes two networks, an external network 100 and an internal network 200, respectively.
  • the gateway device 300 is used to connect the external network and the internal network 200.
  • the external network is the Internet
  • the internal network is a local area network established by organizations such as enterprises, campuses, and families, or a campus network (Campus network, CAN) composed of multiple local area networks.
  • organizations such as enterprises, campuses, and families, or a campus network (Campus network, CAN) composed of multiple local area networks.
  • CAN campus network
  • the internal network 200 includes several internal network devices, which are denoted as the internal network device 201 to the internal network device 20n, where n is a natural number greater than 1.
  • the number of intranet devices is limited by the address space of the internal network, and the embodiment of the present application does not specifically limit the number of intranet devices.
  • Intranet devices include but are not limited to personal computers, servers, laptops, virtual machines, wearable devices, mobile phones, smart screen TVs, sweeping robots, projectors, tablets, switches, and wireless access point (AP) devices And so on with computing power and network connection capabilities.
  • the gateway device 300 in the embodiment of the present application includes devices such as routers, firewalls, and Layer 3 switches. Routers further include access routers (such as home routers), enterprise-level routers, backbone-level routers, and so on.
  • access routers such as home routers
  • enterprise-level routers such as enterprise-level routers
  • backbone-level routers such as backbone-level routers
  • the network service processing system provided by the embodiment of the present application includes the gateway device 300 in FIG. 1 and at least one intranet device among the intranet device 201 to the intranet device 20n.
  • the gateway device 300 is used to identify the type of the first intranet device.
  • the first intranet device is one of the intranet devices 201 to 20n in FIG. 1; according to the type of the first intranet device, Obtain a first software package, the first software package is used to implement a first additional function; send a first indication message and the first software package to the first intranet device, the first indication message is used to indicate The first intranet device installs the first software package and executes the first additional function.
  • the type of internal network equipment refers to the category obtained by classifying internal network equipment according to factors such as functions and usage characteristics.
  • the types of intranet devices include: personal computers, servers, mobile terminals, printers, smart home devices, and so on. The aforementioned laptops, mobile phones, and tablet computers belong to mobile terminals, and smart screen TVs, sweeping robots, and projectors belong to smart home devices.
  • the additional functions in the embodiments of the present application include, but are not limited to: a data stream security detection function, a network cache function, a security sandbox function, etc., taking the firewall function as an example.
  • the firewall function includes filtering forwarded packets between the LAN and the Internet according to a predetermined rule set
  • the security sandbox function includes running unknown specific types of content in a virtual operating environment, such as files, web pages, etc.
  • network caching functions Including cache files that meet the conditions, such as video files and audio files that exceed a predetermined size.
  • the intranet device is configured to receive the first instruction message and the first software package sent by the gateway device, and execute the first additional function after installing the first software package according to the first instruction message.
  • the gateway device 300 selects a suitable software package for the intranet devices to implement additional functions based on the respective performances of different types of intranet devices.
  • the gateway device 300 stores various software packages used to implement different additional functions, and the installation performance requirements corresponding to each software package (for example, the need to support the installation of software packages, the requirements for the CPU processing rate value, or the requirements for the size of storage space. and many more).
  • the gateway device 300 first determines the performance of the first intranet device according to the type of the first intranet device. Including software capabilities and hardware capabilities, the software capabilities include whether to support the installation of software packages, and the hardware capabilities include processor performance values and/or storage space sizes.
  • the software capabilities also include whether necessary supporting software has been installed, the version of the current operating system, and so on.
  • the gateway device 300 obtains the first software package according to the performance of the first intranet device, and the performance of the first intranet device meets the installation performance requirements of the first software package. For example, the gateway device 300 finds the first software package in the corresponding relationship between the software package and the installation performance requirements according to the performance of the first intranet device.
  • the gateway device 300 may be able to identify the types of at least two internal network devices. In this case, the gateway device 300 selects one of the internal network devices for use. To install the first package. Specifically, the gateway device 300 recognizes the types of at least two intranet devices, and obtains the performance of each of the at least two intranet devices. If there are at least two intranet devices, for example, the performance of the first intranet device and the performance of the second intranet device both meet the installation performance requirements of the first software package, the gateway device 300 selects from the at least two intranet devices Select an intranet device, such as the first intranet device, to install the first software package.
  • the gateway device 300 may select an intranet device to install the first software package according to multiple selection strategies.
  • the gateway device 300 randomly selects an intranet device from the first intranet device and the second intranet device to install the first software package, or the gateway device 300 selects from the first intranet device and the second intranet device
  • the intranet device with higher performance is selected among the two intranet devices to install the first software package, or the gateway device 300 according to the internal network topology, selects the second intranet device from the first intranet device and the second intranet device.
  • an intranet device with a shorter distance from the gateway device 300 is selected to install the first software package. Due to space limitations, the selection strategies will not be listed here.
  • the target data flow refers to the first additional function to be executed
  • the description information of the data stream and/or the target data stream is sent to the first intranet device that implements the first additional function, and the gateway device 300 also needs to record the correspondence between the identifier of the first intranet device and the first additional function.
  • the gateway device 300 sends the target data stream and/or the above description information to the first intranet device according to the correspondence between the identifier of the first intranet device and the first additional function, it further includes receiving the first intranet device.
  • the processing result returned by the device is further configured to perform an action corresponding to the processing result on the target data stream according to the processing result, and the action includes forwarding, warning, or blocking.
  • the gateway device 300 recognizes the type of the first intranet device through one of multiple methods or a combination of two or more methods. For example, the gateway device 300 determines the type of the intranet device according to a configuration table, where the corresponding relationship between the identifier of each intranet device and the type of the device is stored in the configuration table, and the configuration table is generated based on the data input by the administrator. In addition, the gateway device 300 can also recognize the type of the first intranet device in real time through other active or passive means.
  • Method 1 to obtain the type of the first intranet device from the characteristic message
  • Method 2 to identify the first intranet device based on the Media Access Control (MAC) address of the first intranet device
  • the type of the internal network device to identify the type of the first internal network device.
  • Method 3 the type of the first internal network device is determined through active detection and scanning.
  • the above-mentioned software package may be stored in a server (as shown in the server 101 in FIG. 1) instead of being stored in the gateway device 300. That is, the gateway device 300 does not need to save the correspondence between the software package and the installation performance requirements, but saves the correspondence between the identification of the software package and the installation performance requirements.
  • the gateway device 300 finds the identification of the first software package in the correspondence between the identification of the software package and the installation performance requirements, sends the identification of the first software package to the server 101, and receives the identification of the first software package.
  • the server corresponds to the returned first software package.
  • the server 101 is configured to send the stored first software package to the gateway device 300 according to the received identifier of the first software package.
  • the above-mentioned step of obtaining the first software package according to the performance of the first intranet device may be performed by the server 101 in FIG. 1.
  • the gateway device 300 sends the performance of the first intranet device to the server, and the gateway device 300 receives the first software package correspondingly returned by the server 101.
  • the server 101 saves the correspondence between the software package and the installation performance requirements, receives the performance of the first intranet device sent by the gateway device 300, finds the first software package in the correspondence between the software package and the installation performance requirements, and sends it to The gateway device 300 sends the queried first software package.
  • the above-mentioned step of querying the installation performance requirements according to the type of the first intranet device may also be executed by the server 101 in FIG. 1.
  • the gateway device 300 recognizes the type of the first intranet device, it sends the type of the first intranet device to the server; and receives the first software package correspondingly returned by the server.
  • the server 101 determines the performance of the first intranet device according to the type of the first intranet device, and then obtains the first software package according to the performance of the first intranet device. For example, the first software package is found in the corresponding relationship between the software package and the installation performance requirements.
  • the server 101 sends the acquired first software package to the gateway device 300.
  • the server 101 may be deployed in the internal network 200 (not shown in FIG. 1); alternatively, the server 101 may also be deployed in the external network 100 (as shown in FIG. 1).
  • the server 101 can support multiple different internal networks to implement the network service processing solution provided in the embodiment of the present application, and the server 101 is also referred to as a "cloud server".
  • the owner of the cloud server is an operator or a third-party organization other than the operator and the owner of the internal network, and the customers of the cloud server are several internal networks 200.
  • the cloud server is managed by the operator or a third-party organization other than the operator and the internal network owner, and provides support services for multiple different internal networks through open dedicated ports. After passing the registration authentication, the internal network 200 communicates and interacts with the cloud server through a general protocol or a private protocol.
  • Fig. 2 is a flowchart of a network service processing method provided by an embodiment of the application.
  • the network service processing method is executed by a gateway device, such as the gateway device 300 in FIG. 1.
  • the network service processing method provided in the embodiment of the present application includes the following steps.
  • Step 210 The gateway device identifies the type of the first intranet device. It should be noted that the "first” and “second” in the “first intranet device” and the subsequent “second intranet device” do not indicate a sequence relationship, but are used to distinguish different intranet devices. The first, second, etc. appearing in the following description are also used to distinguish different information or messages.
  • the first internal network device belongs to the internal network to which the gateway device is connected.
  • the first internal network device is the internal network device 201 in FIG. 1.
  • the gateway device can roughly determine whether the intranet device is suitable for performing additional functions and has the ability to perform additional functions. For example, if an intranet device is a mobile terminal, since the location of the mobile terminal often changes, the intranet device is not suitable for performing additional functions. If a mobile terminal is designated to perform an additional function, when the mobile terminal is taken away from the internal network by the user, the additional function performed by the mobile terminal will be unavailable, which will cause the instability of the additional function. For another example, if an intranet device is a printer, due to the limited storage and processing performance of the printer, it is not suitable to perform additional functions that consume more storage resources and processing resources, and it is relatively more suitable to perform additional functions that consume more storage resources and processing resources. Additional features.
  • the gateway device uses one or more methods to identify the type of the intranet device, including but not limited to the following.
  • the gateway device prefers one of the methods to identify the type of an intranet device, and when the type of the intranet device cannot be successfully identified, it tries to identify the type of the intranet device through other methods.
  • Method 0 Determine the type of intranet device based on the saved configuration table.
  • the gateway device generates a configuration table according to the data input by the administrator, and the configuration table stores the corresponding relationship between the identification of each intranet device (such as the Internet Protocol (IP) address of the intranet device) and the type of the device.
  • IP Internet Protocol
  • the administrator uses the input device connected to the input and output interface of the gateway device to input related data of an intranet device through the command line interface of the gateway device, or other application software such as the network management software interface, and these data include the intranet
  • the IP address of the device, and the type of the intranet device, and further information such as the manufacturer and specific model of the intranet device can be input.
  • the gateway device generates an entry corresponding to the intranet device in the configuration table according to the above data, and the entry includes the IP address of the intranet device and the type of the intranet device.
  • the gateway device When the gateway device subsequently needs to determine the type of an intranet device, according to the IP address of the intranet device, it queries the entry containing the IP address in the configuration table, and obtains the type of the intranet device from the searched entry.
  • Manner 1 Obtain the type of the first intranet device from the forwarded characteristic message.
  • Fig. 3 is a flowchart of the first method of identifying the type of intranet device provided by an embodiment of the present application.
  • Step 300 The gateway device intercepts the characteristic message sent by the first intranet device from the forwarded network traffic, the characteristic message carries a first characteristic field, and the content of the first characteristic field is used to indicate the operating system of the sender Type or reserved website domain name.
  • the predetermined website domain name includes the domain name of the device upgrade website.
  • Step 320 The gateway device queries the feature database for the first device type corresponding to the content of the first feature field in the feature message, and the feature database saves the content of the first feature field and the first device type. Correspondence of types.
  • Step 340 The gateway device determines that the type of the first intranet device is the first device type.
  • the characteristic message is a Hypertext Transfer Protocol (HTTP) message carrying a User-Agent (User-Agent) field sent by an intranet device.
  • HTTP Hypertext Transfer Protocol
  • User-Agent User-Agent
  • Intranet devices will send HTTP messages carrying the User-Agent field during Portal authentication.
  • Example 1 the content of the User-Agent field is "Android 8.0.0; VTR-L09Build/HUAWEIVTR-L09".
  • the content of the User-Agent field in the HTTP message sent by the mobile phone model HUAWEI P10 during Portal authentication includes "Android 8.0.0; VTR-L09 Build/HUAWEIVTR-L09".
  • Example 2 the content of the User-Agent field is "Windows NT 6.1; Win64; x64".
  • the content of the User-Agent field in the HTTP message sent by the personal computer during the Portal authentication process includes "Windows NT 6.1; Win64; x64".
  • the corresponding relationship between "Android 8.0.0; VTR-L09 Build/HUAWEIVTR-L09” and the device type "mobile terminal” is pre-stored in the feature library of the gateway device, and "Windows NT 6.1; Win64; x64" and the device type "personal computer "The corresponding relationship.
  • the gateway device parses the content of the User-Agent field from the feature message sent by the first intranet device, it compares the content of the User-Agent field obtained by the analysis with the feature fields in the feature library.
  • the content of the User-Agent field includes "Android 8.0.0; VTR-L09 Build/HUAWEIVTR-L09", it is determined that the type of the first intranet device is a mobile terminal, if the content of the User-Agent field obtained by analysis includes "Windows NT 6.1; Win64; x64", then confirm that the type of the first intranet device is a personal computer.
  • the characteristic message may also be a DHCP message carrying an option (Option) field sent by an intranet device.
  • Contents of the requested parameter list field (i.e. Option 55), vendor id field (i.e. Option 60 field), and host name (host name) field (i.e. Option 12 field) in the Option field It can also be used to identify the type of the intranet device that sends the DHCP message carrying the option (Option) field.
  • the characteristic message may also be a Probe Request (Probe Request) message and/or an Association Request (Association Request) message sent by the intranet device to the AP.
  • Probe Request Probe Request
  • Association Request Association Request
  • the above signature database is pre-configured by the administrator, and can also be obtained from a public website, such as https://fingerbank.inverse.ca.
  • Method 2 Identify based on MAC address.
  • Fig. 4 is a flowchart of a second method of identifying the type of an intranet device provided by an embodiment of the present application.
  • Step 400 The gateway device obtains the MAC address of the first intranet device. For example, the gateway device obtains the MAC address of the first intranet device from the header of the forwarded IP packet, or the gateway device sends an ARP request to the first intranet device and obtains it from the corresponding address resolution protocol (Address Resolution Protocol). , ARP) response to obtain the MAC address of the first intranet device.
  • ARP Address Resolution Protocol
  • Step 420 The gateway device queries a device information database for the first device type corresponding to the MAC address of the first intranet device.
  • the device information database stores the MAC address of the first intranet device and the first device type. Correspondence of device types.
  • the device information database is pre-saved. For example, when the gateway device administrator adds a new device to the internal network, when configuring network parameters for the new internal network device, the MAC address of the new internal network device and the device type of the new internal network device Enter the gateway device through the input device connected to the gateway device and save it. Or, the device information database is downloaded by the gateway device from the manufacturer's support website of the intranet device.
  • Step 440 The gateway device determines that the type of the first intranet device is the first device type.
  • the first 3 bytes of the MAC address are the MAC organization unique identifier (OUI).
  • MAC OUI is the Institute of Electrical and Electronics Engineers (IEEE) uniformly assigned to various equipment manufacturers, and can be used to identify companies disclosed by IEEE. There is a corresponding relationship between equipment manufacturers and equipment types. For example, some manufacturers only produce printer devices, some manufacturers only produce mobile terminal devices, and so on.
  • the above-mentioned equipment information rule database can be established manually, or it can be established by referring to the public information on the website of some manufacturer organizations. For example, you can refer to the IEEE MAC OUI rule base http://standards-oui.ieee.ory/oui/oui.txt.
  • Method 3 identification is carried out through active detection and scanning.
  • the gateway device sends a detection message to the first intranet device to identify the type of the first intranet device according to the corresponding response message.
  • Fig. 5 is a flowchart of a third method of identifying the type of an intranet device provided by an embodiment of the present application.
  • Step 500 The gateway device sends a detection message to the first intranet device.
  • Step 520 The gateway device receives a response message corresponding to the detection message sent by the first intranet device.
  • Step 540 The gateway device obtains a first identification fingerprint according to the response message.
  • Step 560 The gateway device queries the fingerprint database for the first device type corresponding to the first identification fingerprint, and the fingerprint database saves the correspondence between the first identification fingerprint and the first device type.
  • Step 580 The gateway device determines that the type of the first intranet device is the first device type.
  • one or more scanner software is pre-installed in the gateway device.
  • the scanner software includes, but is not limited to, the vulnerability scanner NESSUS launched by Tenable, the open source scanning tool Nmap, the network tool netcat of the Unix operating system platform, and so on.
  • the gateway device actively sends a detection message to the intranet device by running the above-mentioned scanner software, and obtains an identification fingerprint from the corresponding response message, and identifies the type of the intranet device as the scanning target according to the identification fingerprint.
  • a gateway device uses Nmap to scan an intranet device, it sends multiple specially constructed detection messages.
  • the gateway device receives the response message corresponding to the internal network device, and generates an identification fingerprint according to the following field values in the response message.
  • the field used to generate the identification fingerprint in the response message includes one or more of the following combinations: SEQ, OPS, WIN, T1-T7, IE, ECN, U1.
  • the gateway device uses the generated identification fingerprint as an index to query the corresponding device type in the fingerprint database.
  • the fingerprint library provided by Nmap with the version number of 7.70 contains 5652 fingerprints stored in plain text. These fingerprints correspond to 28 device types.
  • step 220 is executed.
  • Step 220 The gateway device obtains a first software package according to the type of the first intranet device, where the first software package is used to implement the first additional function.
  • the gateway device stores the correspondence between the type of the intranet device and the software package, as shown in Table 1. After the gateway device recognizes the type of the first intranet device, it queries the software package corresponding to the type of the first intranet device from the correspondence shown in Table 1.
  • a software package refers to a program or a group of programs that have specific functions and are used to complete specific tasks.
  • a character string with a suffix is used to represent a software package
  • a character string without a suffix is used to represent the identification (name of the software package) of the software package.
  • "Firewall.exe” represents a software package used to implement additional security detection functions using a firewall as an example
  • Firewall represents the identification of the software package.
  • the corresponding relationship between the type of the intranet device and the software package may be stored in a variety of possible storage formats. For example, what is actually stored is the correspondence between the type of the intranet device and the storage location of the software package in the file system of the gateway device, or the correspondence between the type of the intranet device and the identifier of the software package.
  • the storage location includes but is not limited to the path in the file system. If what is saved is the correspondence between the type of the intranet device and the storage location of the software package in the file system of the gateway device, the gateway device finds the storage location of the corresponding first software package according to the type of the first intranet device, The first software package is obtained at the storage location.
  • the gateway device finds the identification of the corresponding first software package according to the type of the first internal network device, and then finds the first software package in the file system of the gateway device. A software package.
  • the correspondence shown in Table 1 can also be replaced with the correspondence between the type of the intranet device and the additional function.
  • the gateway device After the gateway device recognizes the type of the first intranet device, it queries the corresponding relationship between the type of the intranet device and the additional function to find the additional function corresponding to the type of the first intranet device, and then further obtains the implementation.
  • the corresponding relationship shown in Table 1 may also include the software package and the additional functions corresponding to the software package.
  • Step 230 The gateway device sends a first indication message and a first software package to the first intranet device.
  • the first instruction message is used to instruct the first intranet device to install the first software package and execute the first additional function.
  • the first instruction message includes an identifier and an operator of the first software package, and the operator corresponds to an installation operation and a running operation.
  • the identifier of the first software package includes the name of the first software package, the hash value of the first software package, and so on.
  • the gateway device informs the administrator that the first intranet device can execute The first additional function.
  • the gateway device executes step 230.
  • notification methods include but are not limited to: prompting the administrator through the connected output device of the gateway device, sending a short message to the mobile phone used by the administrator, sending an email to the administrator, and using WeChat, MSN (The Microsoft Network) as Examples of instant messaging software to send messages to the administrator and so on.
  • the gateway device serves as the main body of management and control that implements additional functions.
  • the gateway device first identifies the type of the intranet device, and according to the type of the intranet device, sends a software package for implementing appropriate additional functions to the intranet device, and instructs the intranet device to successfully install the software package to implement the additional functions.
  • the processing burden of the gateway device is reduced, the processing resources and storage resources of the gateway device are saved, and a low-cost implementation of gateway device addition is provided Functional scheme.
  • the solution uses the idle resources of the intranet equipment to implement additional functions, which improves the utilization of intranet resources.
  • each additional function corresponds to an independent software package, and each time an additional function is added, only the corresponding software package needs to be developed. Performing new additional functions does not significantly increase the burden on the gateway device, so it also has better scalability.
  • step 220 the gateway device obtains the first software package based on the correspondence between the type of the intranet device and the software package shown in Table 1, which is quick and effective.
  • the method in step 220 can only achieve the difference between the intranet device and the software package (or additional functions). Coarse-grained matching. In the specific implementation process, there may be problems such as the failure of the software package installation or the poor implementation of additional functions.
  • the performance of the intranet device is actually difficult to meet the requirements for implementing additional functions and the software package installation fails, or the performance of the intranet device is too low, which causes the software package to run too slowly after the installation is completed, and the effect of implementing additional functions is poor. .
  • the type of the first intranet device is a server
  • the type of the second intranet device is a personal computer
  • both the first intranet device and the second intranet device can support an additional device that consumes more storage resources and processing resources.
  • the performance of the first intranet device is significantly higher than that of the second intranet device, for example, the first intranet device has a larger memory capacity and processor speed, and the execution of the first intranet device consumes more storage resources and processing resources. More additional functions can get better results.
  • the embodiment of the present application provides a method for selecting the software package installed by the intranet device based on the performance of the intranet device, as shown in FIG. 6.
  • the process shown in FIG. 6 is an alternative method of performing step 220 in FIG. 2 "the gateway device obtains the first software package according to the type of the first intranet device".
  • Step 610 The gateway device determines the performance of the first intranet device according to the type of the first intranet device. Among them, performance includes software capabilities and hardware capabilities, the software capabilities include whether to support the installation of software packages, and the hardware capabilities include processor performance values, storage space sizes, and so on.
  • the corresponding relationship between the type and performance of the intranet device is stored in the gateway device, as shown in Table 2.
  • the gateway device After the gateway device recognizes the type of the first intranet device, it can query the performance of the first intranet device in the corresponding relationship between the type and performance of the intranet device shown in Table 2.
  • the type of the intranet device further includes the manufacturer and/or model information of the intranet device, which is equivalent to further subdividing the type of the intranet device.
  • the gateway device After the gateway device identifies the type of the first intranet device containing manufacturer and/or model information in step 220 in FIG. 2, it can query the corresponding relationship between the type and performance of the intranet device shown in Table 2. To more precise performance.
  • Step 620 The gateway device obtains the first software package according to the performance of the first intranet device. Wherein, the performance of the first intranet device meets the installation performance requirement of the first software package.
  • the installation performance requirements corresponding to each software package are stored in the gateway device, as shown in Table 3.
  • the gateway device obtains the performance of the first intranet device, it compares the performance of the first intranet device with the installation performance requirements of each software package. If the main performance of the first intranet device is higher than the installation performance of the first software package Performance requirements, it is determined that the performance of the first intranet device meets the installation performance requirements of the first software package.
  • the performance of the first intranet device meets the installation performance requirements of the software packages networkstorage.exe and Firewall.exe, but does not meet the software package Websandbox.exe The installation performance requirements.
  • the first software package is a software package named networkstorage.exe or a software package named Firewall.exe.
  • the performance of the first intranet device meets the installation performance requirements of the software packages networkstorage.exe, Firewall.exe, and Websandbox.exe.
  • the first software package is a software package named networkstorage.exe, a software package named Firewall.exe, or a software package named Websandbox.exe.
  • the gateway device in the embodiment of the present application recognizes the type of the first intranet device, it obtains the performance of the first intranet device according to the type of the first intranet device, and then compares the performance of the first intranet device with the installation performance of the software package. A comparison is required to ensure that the performance of the first intranet device meets the installation performance requirements of the selected first software package. In this way, the failure rate of installing the software package or running the software package on the first intranet device can be reduced, and the success rate of installing the software package on the first intranet device can be improved, thereby improving the effect of implementing additional functions.
  • the gateway device 300 recognizes the types of multiple intranet devices in parallel. After recognizing the types of multiple intranet devices, the method shown in Figure 2 or Figure 6 may be used for two or more different internal devices. Network equipment, the first software package determined to be the same software package. At this time, if the gateway device 300 sends the same software package to two or more intranet devices, these intranet devices will perform the same additional function after installing the same software package, which may result in waste of intranet device resources, or Conflict problems in the implementation of additional functions. In order to avoid this possible problem, when the first software package determined by the gateway device 300 is the same software package for multiple different intranet devices, the gateway device 300 needs to select from the multiple intranet devices An intranet device.
  • the gateway device 300 sends the first software package to the selected intranet device to avoid sending the same software package to multiple intranet devices at the same time. That is, in the method shown in FIG. 2, before step 230, the method further includes: the gateway device 300 determines to obtain the first software package according to the type of the second intranet device; the gateway device 300 obtains the first software package from the first intranet device and The first intranet device is selected from the second intranet device, and the first instruction message and the first software package are sent to the first intranet device, but the first instruction message and the first software package are not sent to the second intranet device.
  • the first software package is determined to be the same software package for two or more different intranet devices, it can also be based on the two For the performance of the internal network equipment, select one of the internal network equipment for subsequent installation of the first software package.
  • the processing method of the network service in this case is shown in Figure 7.
  • a network service processing method shown in FIG. 7 includes the following steps.
  • steps 210, 610, 620, and 230 please refer to FIG. 6 and related descriptions, and will not be repeated here.
  • the method further includes:
  • Step 710 The gateway device identifies the type of the second intranet device, and the second intranet device belongs to the internal network to which the network management device is connected.
  • Step 720 The gateway device determines the performance of the second intranet device according to the type of the second intranet device.
  • the gateway device finds the second software package in the corresponding relationship between the software package and the installation performance requirements according to the performance of the second intranet device, and the performance of the second intranet device meets the second The installation performance requirements of the software package.
  • step 710 to step 730 are respectively similar to step 210 in FIG. 2 and steps 610 and 620 in FIG. 6, and will not be repeated here.
  • step 240 the gateway device determines whether the first software package and the second software package are the same software package, and if the first software package and the second software package are different software packages, step 230 and step 231 are executed.
  • Step 231 The gateway device sends a second instruction message and a second software package to a second intranet device, where the second instruction message is used to instruct the second intranet device to install the second software package and execute the second software package. Two additional functions.
  • step 250 is executed.
  • Step 250 According to the performance of the first intranet device and the performance of the second intranet device, the gateway device selects the first intranet device from the first intranet device and the second intranet device according to a predetermined selection strategy. Install the first software package. Step 230 is executed.
  • the predetermined selection strategy includes selecting an intranet device with better performance.
  • the gateway device 300 recognizes the types of the intranet device 201 and the intranet device 202, it executes the method shown in FIG. 6 for the intranet device 201 and the intranet device 202 respectively, and determines that the intranet device 201 is used to install Firewall.exe, The intranet device 201 is also used to install Firewall.exe.
  • the gateway device 300 selects the intranet device 201 from the intranet device 201 and the intranet device 202, and the gateway device 300 sends an instruction message to the intranet device 201.
  • the message includes the Firewall.exe software package, which is used to instruct the intranet device 201 to install the Firewall.exe software package and execute the corresponding firewall function.
  • the gateway device taking the gateway device 300 in FIG. 1 as an example is the main body that controls each intranet device to perform additional functions, and executes the network service processing method shown in FIG. 2, FIG. 2 or FIG. 7.
  • the above-mentioned multiple software packages used to perform various additional functions can be stored centrally or distributed.
  • Centralized storage means that the above-mentioned multiple software packages used to perform various additional functions are stored in the memory of the gateway device.
  • Distributed storage means that all or part of the above-mentioned multiple software packages used to perform various additional functions are stored in other network devices that are accessible by the gateway device.
  • these network devices used to store all or part of the software packages may be deployed in the internal network 200 or the external network 100.
  • only the "cloud server" solution shown in FIG. 1 is taken as an example to describe the situation of distributed storage.
  • the embodiments of the present application provide three specific implementations of distributed storage.
  • Each software package is stored in a cloud server as shown in the server 101 in FIG. 1, instead of being stored in the gateway device 300.
  • the gateway device 300 does not need to save the correspondence between the software package and the installation performance requirements, but saves the correspondence between the identification of the software package and the installation performance requirements.
  • the implementation process of step 220 in FIG. 6 is shown in FIG. 8.
  • FIG. 8 describes the process of the gateway device acquiring the first software package according to the performance of the first intranet device.
  • the gateway device executes step 610 in FIG. 6, and after determining the performance of the first intranet device according to the type of the first intranet device, it cooperates with the server to execute step 810 to step 840 in FIG. 8 instead of the drawings. Step 620 in 6.
  • the gateway device obtains the identifier of the first software package from the corresponding relationship between the identifier of the software package and the installation performance requirement according to the performance of the first intranet device. Wherein, the performance of the first intranet device meets the installation performance requirements corresponding to the identifier of the first software package.
  • Step 820 The gateway device sends the identifier of the first software package to the server.
  • Step 830 The server obtains the stored first software package according to the received identifier of the first software package.
  • Step 840 The server sends the obtained first software package to the gateway device.
  • the gateway device receives the first software package correspondingly returned by the server.
  • the first intranet device is an intranet device 201
  • the type of the intranet device 201 is a personal computer and the model is H-TG01.
  • the gateway device 300 locally stores the corresponding relationship between the identifier of the stored software package and the installation performance requirement, as shown in Table 4.
  • the gateway device 300 determines that the performance of the first intranet device meets the installation performance requirements of the software package named Firewall.
  • the gateway device 300 sends the identifier “Firewall” of the first software package to the server 101, and after receiving the software package Firewall.exe returned by the server 101, sends the first instruction message and the software package Firewall.exe to the intranet device 201.
  • the separate storage solution provided by the embodiment of the present application can save the storage resources of the gateway device 300.
  • Each software package is stored in a cloud server as shown in the server 101 in FIG. 1, instead of being stored in the gateway device 300.
  • the gateway device 300 does not need to save the correspondence between the software package and the installation performance requirements, nor does it need to save the correspondence between the identification of the software package and the installation performance requirements. It only needs to save the correspondence between the type and performance of the intranet device shown in Table 2. .
  • the server 101 not only saves each software package, but also needs to save the corresponding relationship between the software package and the installation performance requirements as shown in Table 3. In this case, the implementation process of step 220 in FIG. 6 is shown in FIG. 9.
  • Fig. 9 depicts the flow of the gateway device acquiring the first software package according to the performance of the first intranet device.
  • the gateway device performs step 610 in FIG. 6, and after determining the performance of the first intranet device according to the type of the first intranet device, it cooperates with the server to perform step 910 to step 930 instead of the steps in FIG. 6 620.
  • Step 910 The gateway device sends the performance of the first intranet device to the server.
  • Step 920 The server obtains the first software package from the correspondence relationship between the software package and the installation performance requirement according to the received performance of the first intranet device. Wherein, the performance of the first intranet device meets the installation performance requirements corresponding to the identifier of the first software package.
  • the server saves the corresponding relationship between the software packages shown in Table 3 and the installation performance requirements.
  • the server After receiving the performance of the first intranet device sent by the gateway device, the server compares the performance of the first intranet device with the corresponding software packages. The installation performance requirements are compared, and if the main performance of the first intranet device is higher than the installation performance requirements of the first software package, it is determined that the performance of the first intranet device meets the installation performance requirements of the first software package.
  • the server saves the software package and the installation performance requirements shown in Table 3, but the correspondence between the identifier of the server saves the software package and the installation performance requirements shown in Table 4.
  • the server After the server receives the performance of the first intranet device, it compares the performance of the first intranet device with the installation performance requirements corresponding to the identification of each software package. If the main performance of the first intranet device is higher than that of the first software According to the installation performance requirement corresponding to the package identifier, it is determined that the performance of the first intranet device meets the installation performance requirement of the first software package. The server then finds the corresponding first software package according to the identifier of the first software package.
  • Step 930 The server sends the first software package to the gateway device.
  • the gateway device receives the first software package correspondingly returned by the server, and then sends the first software package and the first instruction message to the first intranet device.
  • the first intranet device is an intranet device 201
  • the type of the intranet device 201 is a personal computer and the model is H-TG01.
  • the gateway device 300 determines according to Table 2 that the performance of the intranet device 201 includes "CPU: 2GHz; memory: 512MB; hard disk capacity: 256GB".
  • the gateway device 300 sends the performance of the intranet device 201 "CPU: 2GHz; memory: 512MB; hard disk capacity: 256GB" to the server 101.
  • the server 101 will receive the received performance "CPU: 2GHz; memory: 512MB; hard disk capacity: 256GB" with the saved software package shown in Table 3 and the corresponding relationship between the installation performance requirements, or the server saved software package shown in Table 4 The entries in the corresponding relationship between the identification and the installation performance requirements are compared.
  • the performance of the internal network device 201 of the server 101 meets the installation performance requirements of the software package Firewall.exe.
  • the server 101 sends the software package Firewall.exe to the gateway device 300.
  • the separate storage solution provided by the embodiments of the present application can further save the storage resources of the gateway device on the one hand, and on the other hand, since the step of obtaining the first software package is executed by the server according to performance, it also saves the processing resources of the gateway device.
  • Each software package is stored in a cloud server as shown in the server 101 in FIG. 1, instead of being stored in the gateway device 300.
  • the gateway device 300 not only does not need to save the correspondence between the software package and the installation performance requirements, nor does it need to save the correspondence between the identification of the software package and the installation performance requirements, and does not need to save the information about the type and performance of the intranet devices shown in Table 2.
  • the server 101 not only saves each software package, but also needs to save the corresponding relationship between the software package and the installation performance requirements shown in Table 3, and further needs to save the corresponding relationship between the type and performance of the intranet device shown in Table 2.
  • the implementation process of step 220 in FIG. 2 is shown in FIG. 10.
  • Fig. 10 depicts the flow of the gateway device acquiring the first software package according to the performance of the first intranet device.
  • the gateway device executes step 210 in Figure 2 or Figure 6, after identifying the type of the first intranet device, and cooperates with the server to perform steps 110 to 130 to replace step 220 in Figure 2 or to replace step 220 in Figure 6 ⁇ steps 610-620.
  • Step 110 The gateway device sends the type of the first intranet device to the server.
  • Step 120 After receiving the type of the first intranet device sent by the gateway device, the server queries the performance of the first intranet device from the correspondence between the type and performance of the intranet device shown in Table 2.
  • step 130 the server finds the first software package in the corresponding relationship between the software package and the installation performance requirement according to the queried performance of the first intranet device. Wherein, the performance of the first intranet device meets the installation performance requirements corresponding to the identifier of the first software package.
  • the server saves the corresponding relationship between the software packages shown in Table 3 and the installation performance requirements. After the server finds the performance of the first intranet device, it compares the performance of the first intranet device with the installation performance requirements corresponding to each software package. By comparison, if the main performance of the first intranet device is higher than the installation performance requirement of the first software package, it is determined that the performance of the first intranet device meets the installation performance requirement of the first software package.
  • the server finds the performance of the first intranet device, it compares the performance of the first intranet device with the installation performance requirements corresponding to the identification of each software package. If the main performance of the first intranet device is higher than that of the first software According to the installation performance requirement corresponding to the package identifier, it is determined that the performance of the first intranet device meets the installation performance requirement of the first software package. The server then finds the corresponding first software package according to the identifier of the first software package.
  • step 120 and step 130 can be directly simplified as: the server queries the software package corresponding to the type of the first device according to the received type of the intranet device and the correspondence between the type of the intranet device and the software package.
  • step 220 is basically similar, except that the execution subject is different, and will not be detailed here.
  • Step 140 The server sends the first software package to the gateway device.
  • the gateway device receives the first software package correspondingly returned by the server, and then sends the first software package and the first instruction message to the first intranet device.
  • step 130 is similar to step 920 in FIG. 9, and the execution process of step 140 is similar to step 930 in FIG. 9, and the description is not repeated here.
  • the first intranet device is an intranet device 201
  • the type of the intranet device 201 is a personal computer and the model is H-TG01.
  • the gateway device 300 sends the type of the intranet device 201 "personal computer, H-TG01" to the server 101.
  • the server 101 receives the type "personal computer, H-TG01" of the intranet device 201, it queries the type "personal computer, H-TG01" corresponding to the type and performance of the intranet device shown in Table 2
  • the performance is "CPU: 2GHz; memory: 512MB; hard disk capacity: 256GB”.
  • the server 101 further compares the performance "CPU: 2GHz; memory: 512MB; hard disk capacity: 256GB” with the corresponding relationship between the software package shown in Table 3 and the installation performance requirements, or the identification of the software package saved by the server shown in Table 4
  • the table items in the corresponding relationship of the installation performance requirements are compared to determine that the performance "CPU: 2GHz; memory: 512MB; hard disk capacity: 256GB" meets the installation performance requirements of the software package Firewall.exe.
  • the server 101 sends the software package Firewall.exe to the gateway device 300.
  • the separate storage solution provided by the embodiments of the present application can further save the storage resources of the gateway device on the one hand, and on the other hand, because of the step of querying the installation performance requirements according to the type of the first intranet device, and obtaining the first software package according to the performance
  • the steps are all executed by the server, which further saves the processing resources of the gateway device.
  • the gateway device sends the first indication message and the first software package to the first intranet device, in order to facilitate subsequent changes to the target
  • the data stream, and/or the description information used to describe the target data stream is sent to the first intranet device that implements the first additional function, and the gateway device also needs to record the correspondence between the identifier of the first intranet device and the first additional function relationship.
  • the target data stream refers to the data stream of the first additional function to be executed.
  • the purpose of the gateway device to record the correspondence between the identifier of the first intranet device and the first additional function is to correctly forward the target data stream subsequently, so as to correctly execute the first additional function.
  • the gateway device subsequently sends the target data stream and/or description information used to describe the target data stream to the device that implements the first additional function according to the correspondence between the identifier of the first intranet device and the first additional function.
  • the first intranet device and receives the processing result corresponding to the first intranet device.
  • the gateway device performs an action corresponding to the processing result on the target data flow in the traffic to be forwarded according to the received processing result, and the action includes forwarding, warning, or blocking.
  • the specific implementation process is shown in FIG. 11 and FIG. 12.
  • FIG. 11 is a flowchart of a method for processing a network service provided by an embodiment of the present application.
  • the gateway device 300 in FIG. 1 the gateway device sends the first indication message and the first instruction message to the first intranet device in the network service processing method described in FIG. 2 and FIG. 6 to FIG.
  • the steps shown in FIG. 11 are also executed.
  • Step 111 The gateway device saves the corresponding relationship between the identifier of the first intranet device and the first additional function.
  • the gateway device after the gateway device sends the first indication message and the first software package to the first intranet device, it waits to receive that the first intranet device returns after the installation of the first software package is completed. Confirmation message. After the gateway device receives the confirmation message from the first intranet device, the gateway device saves the corresponding relationship between the identifier of the first intranet device and the first additional function.
  • Step 112 The gateway device obtains the traffic to be forwarded, and obtains a target data stream from the traffic to be forwarded, where the target data stream refers to a data stream for which the first additional function is to be executed.
  • Which data flow is the target data flow is related to specific additional functions. For example, if the first additional function is a data stream security detection function, then the target data stream is the traffic to be detected that conforms to the predetermined policy.
  • the predetermined strategy is set according to the network scenario in advance, and can be all two-way traffic, or one-way traffic sent from the external network to the internal network, and so on.
  • the target data stream is a data stream carrying the content to be cached.
  • the type of content to be cached is preset, for example, the content to be cached is multimedia content and so on.
  • the target data stream is a data stream carrying the content of the file to be detected.
  • the format type of the file to be detected is preset, such as a portable document format (Portable Document Format, pdf) file, or an executable (executable file, exe) file, a portable executable (Portable Executable, PE) file, and so on.
  • the gateway device can analyze some of the packets in the data stream to be forwarded, such as a small number of packets in the initial stage of session establishment, to determine whether the data stream to which these packets belong is the target data stream. For example, protocol analysis is performed on a small number of messages in the initial stage of session establishment to obtain the file header data carried in the message, and the content type carried by the session is obtained from the file header data.
  • Step 113 The gateway device sends the target data stream to the first intranet device according to the correspondence between the identifier of the first intranet device and the first additional function.
  • Step 114 The gateway device receives the processing result of the target data stream by the first intranet device.
  • the first intranet device is the intranet device 201 in FIG. 1, and the gateway device is the gateway device 300 in FIG. 1.
  • the gateway device 300 sends the first indication message and the software package networkstorage.exe to the intranet device 201.
  • the intranet device 201 executes the network caching function.
  • the gateway device 300 records the correspondence between the intranet device 201 and the network cache function.
  • the predetermined policy configured in the gateway device 300 is to cache video files exceeding 50M. That is, the target data stream is a data stream that carries video files exceeding 50M.
  • the gateway device 300 After the gateway device 300 subsequently receives a data stream carrying a video file of more than 50M through a network interface, in addition to executing the original forwarding process, it also sends the data stream to the intranet device 201.
  • the gateway device 300 receives the caching result of this part of the data stream by the intranet device 201, for example, the caching result indicates that the video file is cached successfully or the caching result indicates that the video file has failed to cache.
  • the gateway device further executes step 115.
  • Step 115 The gateway device performs an action corresponding to the processing result on the target data stream according to the processing result, and the action includes forwarding, warning, or blocking.
  • the first intranet device is the intranet device 201 in FIG. 1, and the gateway device is the gateway device 300 in FIG. 1.
  • the first instruction message and software package Firewall.exe sent by the gateway device 300 to the intranet device 201.
  • the intranet device 201 executes the data stream security detection function using the firewall as an example.
  • the gateway device 300 records the correspondence between the intranet device 201 and the data stream security detection function.
  • the predetermined policy configured in the gateway device 300 is to perform security detection on the one-way traffic sent from the external network to the internal network.
  • the target data flow to be detected is the one-way flow sent from the external network to the internal network.
  • the gateway device 300 After the gateway device 300 subsequently receives the data stream sent by the external network 100 to the internal network 200 through the network interface, it sends the data stream to the internal network device 201.
  • the gateway device 300 receives the security detection result of the internal network device 201 on the target data stream, if the security detection result indicates that the target data stream does not contain data that violates firewall rules, the gateway device 300 forwards the target data to the internal network 200 through the network interface Stream; if the security detection result indicates that the target data stream contains data that violates firewall rules, the gateway device 300 blocks the target data stream and prohibits forwarding the target data stream to the internal network 200 through the network interface.
  • the gateway device in order to reduce the amount of data sent by the gateway device to the intranet device that performs additional functions, the gateway device first parses, analyzes, extracts or counts the target data stream to obtain Descriptive information used to describe the target data stream.
  • Descriptive information is also called metadata.
  • Metadata is data describing data (data about data), mainly information describing data properties, used to support functions such as indicating storage locations, historical data, resource search, and file recording.
  • there are multiple ways and formats for generating description information including formats supported by standard organizations and existing mainstream vendors, or formats customized by administrators. For example, the IP data flow information output (IP Flow Information Export, IPFIX) protocol format, NetFlow format, sflow format, etc. defined by the Internet Engineering Task Force (IETF).
  • IPFIX IP Flow Information Export
  • IETF Internet Engineering Task Force
  • Fig. 12 is a processing method of a network service provided by an embodiment of the present application. Taking the gateway device 300 in FIG. 1 as an example, the gateway device sends the first indication message and the first instruction message to the first intranet device in the network service processing method described in FIG. 2 and FIG. 6 to FIG. After the steps of the software package, the steps shown in FIG. 12 are also executed.
  • Step 121 The gateway device saves the correspondence between the identifier of the first intranet device and the first additional function.
  • Step 122 The gateway device obtains the traffic to be forwarded, and obtains a target data stream from the traffic to be forwarded, where the target data stream refers to a data stream on which the first additional function is to be executed.
  • Step 121 and step 122 in FIG. 12 are similar to step 111 and step 112 in FIG. 11, respectively, and the description will not be repeated here.
  • Step 123 The gateway device determines description information, where the description information is used to describe the target data stream.
  • Step 124 The gateway device sends description information to the first intranet device according to the correspondence between the identifier of the first intranet device and the first additional function.
  • Step 125 The gateway device receives the processing result of the description information by the first intranet device.
  • Step 126 The gateway device performs an action corresponding to the processing result on the target data stream according to the processing result of the description information by the first intranet device, and the action includes forwarding, warning, or blocking.
  • the first intranet device is the intranet device 201 in FIG. 1, and the gateway device is the gateway device 300 in FIG. 1.
  • the gateway device 300 sends the first instruction message and the software package Firewall.exe to the intranet device 201. After completing the installation of the software package Firewall.exe according to the first instruction message, the intranet device 201 executes the data stream security detection function using the firewall as an example.
  • the gateway device 300 records the correspondence between the intranet device 201 and the data stream security detection function.
  • the predetermined policy configured in the gateway device 300 is to perform security detection on the one-way traffic sent from the external network to the internal network. That is, the target data flow is the one-way flow sent from the external network to the internal network.
  • the gateway device 300 After the gateway device 300 subsequently receives the data stream (that is, the target data stream) sent by the external network 100 to the internal network 200 through the network interface, it extracts the description information of the target data stream.
  • the description information includes 5-tuple information consisting of a source address, a source port number, a destination address, a destination port number, and a protocol type. Optionally, the description information also includes the contents of some designated fields in the message header, and so on.
  • the gateway device 300 sends description information to the intranet device 201.
  • the gateway device 300 After the gateway device 300 receives the security detection result of the internal network device 201 on the description information, if the security detection result indicates that the description information does not contain data that violates firewall rules, the gateway device 300 forwards the target data stream to the internal network 200 through the network interface; If the security detection result indicates that the description information contains data that violates the firewall rules, the gateway device 300 blocks the target data flow and prohibits forwarding the target data flow to the internal network 200 through the network interface.
  • FIG. 13 is a schematic structural diagram of a gateway device provided by an embodiment of the present application.
  • the gateway device shown in FIG. 13 is the gateway device 300 in the application scenario shown in FIG. 1 and the gateway device in the processes shown in FIG. 2 and FIG. 6 to FIG. 12.
  • the gateway device includes a processor 131, a memory 132, and a network interface 133.
  • the processor 131 may be one or more CPUs, and the CPU may be a single-core CPU or a multi-core CPU.
  • the memory 132 includes but is not limited to random access memory (RAM), read only memory (ROM), erasable programmable read-only memory, EPROM or flash Memory), flash memory, or optical memory, etc.
  • RAM random access memory
  • ROM read only memory
  • EPROM erasable programmable read-only memory
  • flash memory or optical memory, etc.
  • the code of the operating system is stored in the memory 132.
  • the network interface 133 may be a wired interface, such as a Fiber Distributed Data Interface (FDDI) or a Gigabit Ethernet (GE) interface; the network interface 63 may also be a wireless interface.
  • the network interface 133 is used to receive data streams from the internal network and/or external network, communicate with the internal network device in the internal network according to the instruction of the processor 131, and communicate with the server in the external network.
  • FDDI Fiber Distributed Data Interface
  • GE Gigabit Ethernet
  • the processor 131 implements the method in the foregoing embodiment by reading instructions stored in the memory 132, or the processor 131 may also implement the method in the foregoing embodiment by using internally stored instructions.
  • the processor 131 implements the method in the foregoing embodiment by reading the instructions stored in the memory 132
  • the memory 132 stores the instruction to implement the method provided in the foregoing embodiment of the present application.
  • the gateway device executes the following operations: identifying the type of the first intranet device, the first intranet device belonging to the internal network connected to the gateway device; the gateway device according to For the type of the first intranet device, a first software package is obtained, and the first software package is used to implement a first additional function; and a first instruction message and a first instruction message are sent to the first intranet device through the network interface 133 For the first software package, the first instruction message is used to instruct the first intranet device to install the first software package and execute the first additional function.
  • the at least one processor 131 further executes the network service processing method described in the above method embodiment according to several correspondence tables (such as Table 1, Table 2, Table 3, and Table 4 in the previous embodiment) stored in the memory 132 .
  • Table 1, Table 2, Table 3, and Table 4 in the previous embodiment stored in the memory 132 .
  • the gateway device further includes a bus 134, and the aforementioned processor 131 and memory 132 are usually connected to each other through the bus 134, and may also be connected to each other in other ways.
  • the gateway device further includes an input and output interface 135, which is used to connect to an output device and output a prompt message to the administrator to notify the administrator that the first intranet device can perform the first additional function, and where appropriate Under the condition of, output alarms and so on according to the processing results of the internal network equipment.
  • Output devices include but are not limited to displays, printers, etc.
  • the input and output interface 135 is also used to connect with an input device, and receive a confirmation message returned by the administrator in response to the prompt message.
  • Input devices include but are not limited to keyboards, touch screens, microphones, Bluetooth modules, and so on.
  • gateway device shown in FIG. 13 For other additional functions that can be implemented by the gateway device shown in FIG. 13 and the interaction process with other network element devices (such as an intranet device or a server), please refer to the description of the gateway device in the method embodiment, which will not be repeated here.
  • the gateway device provided in the embodiment of the present application is used to execute the network service processing method provided in the foregoing method embodiments.
  • the gateway device itself does not need to perform additional functions, but as a management and control body that implements additional functions, and controls appropriate intranet devices to share the task of implementing additional functions.
  • the main function of the gateway device is to identify the type of the internal network device, and according to the type of the internal network device, send a software package for implementing appropriate additional functions to the internal network device, and instruct the internal network device to implement additional functions after the software package is successfully installed.
  • FIG. 14 is a schematic structural diagram of a network service processing apparatus provided by an embodiment of the present application.
  • the processing device 14 includes a processing module 141 and a sending module 142.
  • the processing device 14 is coupled to the gateway device in the foregoing method embodiments, for example, is integrated in the gateway device, and is a software or hardware component in the gateway device.
  • the processing device shown in FIG. 14 is applied to the scenario shown in FIG. 1 of the method embodiment to realize the function of the gateway device therein.
  • the processing module 141 is configured to identify the type of the first intranet device, which belongs to the internal network connected to the gateway device; obtain the first software according to the identified type of the first intranet device The first software package is used to implement the first additional function.
  • the sending module 142 is configured to send a first instruction message and the first software package to the first intranet device, where the first instruction message is used to instruct the first intranet device to install the first software package And execute the first additional function.
  • the processing module 141 obtains the first software package according to the type of the first intranet device, including: determining the performance of the first intranet device according to the type of the first intranet device, the Performance includes software capabilities and hardware capabilities.
  • the software capabilities include whether to support the installation of software packages, and the hardware capabilities include processor performance values and/or storage space sizes; according to the performance of the first intranet device, the first intranet device is obtained.
  • a software package, and the performance of the first intranet device meets the installation performance requirements of the first software package.
  • the processing module 141 is further configured to identify the type of the second intranet device.
  • the internal network device belongs to the internal network.
  • the processing module 141 determines the performance of the second intranet device according to the type of the second intranet device; obtains a second software package, and the performance of the second intranet device meets the installation performance of the second software package Claim. If the first software package and the second software package are the same software package, the gateway device selects the first intranet device from the first intranet device and the second intranet device Used to install the first software package.
  • the device further includes a receiving module 143.
  • the processing module 142 After the sending module 142 sends the first indication message and the first software package to the first intranet device, the processing module 142 saves the correspondence between the identifier of the first intranet device and the first additional function .
  • the processing module 141 obtains a target data stream from the traffic to be forwarded received by the receiving module 143, where the target data stream is a data stream for which the first additional function is to be executed.
  • the processing module 142 sends the target data stream to the first intranet device through the sending module 142 according to the correspondence between the identifier of the first intranet device and the first additional function, and receives the target data stream via the receiving module 143.
  • processing module 141 For additional functions that can be implemented by the processing module 141, the sending module 142, and the receiving module 143, and for more details of implementing the above-mentioned functions, please refer to the descriptions in the previous method embodiments, and will not be repeated here.
  • the device embodiment described in FIG. 14 is only illustrative.
  • the division of the modules is only a logical function division, and there may be other divisions in actual implementation, for example, multiple modules or components may be combined or It can be integrated into another system, or some features can be ignored or not implemented.
  • the functional modules in the various embodiments of the present application may be integrated into one processing module, or each module may exist alone physically, or two or more modules may be integrated into one module.
  • the above-mentioned modules in FIG. 14 can be implemented in the form of hardware or software functional units.
  • the processing module 141, the sending module 142, and the receiving module 143 may be implemented by software functional modules generated after the processor 131 in FIG. 13 reads the program code stored in the memory.
  • the above-mentioned modules in FIG. 14 can also be implemented by different hardware in the gateway device.
  • the sending module 142 and the receiving module 143 are implemented by the network interface 133 in FIG. 13, and the processing module 141 is implemented by the processor 133 in FIG.
  • Part of the processing resources may be implemented using programmable devices such as Field-Programmable Gate Array (FPGA) or coprocessor.
  • FPGA Field-Programmable Gate Array
  • the above functional modules can also be implemented by a combination of software and hardware.
  • the sending module 142 and the receiving module 143 are implemented by the network interface 133
  • the processing module 141 is a software functional module generated after the CPU reads instructions stored in the memory. .
  • the embodiment of the present application also provides a network service processing system, which includes a gateway device and at least one intranet device.
  • the gateway device is used to connect the external network and the internal network.
  • the at least one internal network device belongs to the internal network.
  • the processing system further includes a server, and the server is deployed in an internal network or an external network.
  • a computer program product refers to computer-readable instructions stored in a computer-readable medium.
  • the computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium.
  • Computer-readable storage media include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, equipment or devices, or any appropriate combination of the foregoing.
  • the computer-readable storage medium is Random Access Memory (RAM), Read Only Memory (ROM), Erasable Programmable Read Only Memory (EPROM) or portable only memory.
  • RAM Random Access Memory
  • ROM Read Only Memory
  • EPROM Erasable Programmable Read Only Memory
  • CD-ROM Compact Disc Read-Only Memory

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Computer And Data Communications (AREA)
  • Stored Programmes (AREA)
  • Information Transfer Between Computers (AREA)

Abstract

本申请公开了一种网络业务的处理方法、网络业务的处理系统及一种网关设备,用以缓解网关设备无法满足越来越多的附加功能需求的问题。网关设备识别第一内网设备的类型,所述第一内网设备属于所述网关设备连接的内部网络。网关设备根据所述第一内网设备的类型,获得第一软件包,所述第一软件包用于实现第一附加功能。网关设备向所述第一内网设备发送第一指示消息和所述第一软件包,所述第一指示消息用于指示所述第一内网设备安装所述第一软件包并执行所述第一附加功能。

Description

网络业务的处理方法、系统和网关设备
本申请要求于2019年11月11日提交中国国家知识产权局、申请号为201911097192.1、申请名称为“网络业务的处理方法、系统和网关设备”的中国专利申请的优先权,以及要求于2019年11月19日提交中国国家知识产权局、申请号为201911134443.9、申请名称为“网络业务的处理方法、系统和网关设备”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及计算机及通信技术领域,尤其涉及一种网络业务的处理方法、网络业务的处理系统及一种网关设备。
背景技术
网关(Gateway)设备是用于连接两个网络的设备,是企业、校园、家庭等许多机构构建局域网时重要的一类基础设备。各种类型的局域网通过网关设备与互联网相连。网关设备的基本功能是转发两个网络之间的报文。出于用户需求和成本的考虑,在许多场景下,网关设备往往需要集成多种附加功能,例如防火墙功能、安全沙箱功能、或者网络缓存(也被称为“网盘”)功能等等。
然而,网关设备受自身硬件资源的制约,难以支持更多附加功能。集成多种附加功能往往会显著降低网关设备的性能,进而影响整个局域网系统的正常工作。如何解决这一矛盾成为一个亟待解决的问题。
发明内容
本申请实施例提供一种网络业务的处理方法,用以缓解网关设备无法满足越来越多的附加功能需求的问题。
第一方面,提供了一种网络业务的处理方法。在该方法中网关设备识别第一内网设备的类型,所述第一内网设备属于所述网关设备连接的内部网络。网关设备根据所述第一内网设备的类型,获得第一软件包,所述第一软件包用于实现第一附加功能。网关设备向所述第一内网设备发送第一指示消息和所述第一软件包,所述第一指示消息用于指示所述第一内网设备安装所述第一软件包并执行所述第一附加功能。
基于该方法,网关设备作为实现附加功能的管理控制主体,根据内网设备的类型,控制合适的内网设备安装软件包以实现附加功能。由于将执行附加功能的部分负担从网关设备转移到内网设备上,从而减轻了网关设备的处理负担,节约了网关设备的处理资源和存储资源,提供了一种较低代价的实现网关设备附加功能的方案。同时,该方案利用内网设备的闲置资源实现附加功能,提高了内网资源的利用率。
可选地,为了提高内网设备与软件包(或附加功能)之间匹配的精确性,网关设备根据内网设备的性能确定内网设备待安装的软件包。在第一方面的一种可能的实现方式中, 网关设备采用以下方式获得第一软件包。网关设备根据所述第一内网设备的类型,确定所述第一内网设备的性能,所述性能包括软件能力和硬件能力,所述软件能力包括是否支持安装软件包,所述硬件能力包括处理器性能值和/或存储空间大小。所述网关设备根据所述第一内网设备的性能,获取所述第一软件包,所述第一内网设备的性能符合所述第一软件包的安装性能要求。通过内网设备的性能确定内网设备待安装的软件包,将有可能较大提升附加功能的实现效果和性能。
可选地,网关设备保存有软件包与安装性能要求的对应关系,以便于网关设备根据所述第一内网设备的性能,在软件包与安装性能要求的对应关系中查找到所述第一软件包。
可选地,为了节省网关设备的存储资源,上述用以执行各个附加功能的多个软件包被分布保存在以服务器为例的其他设备中。在第一方面的一种可能的实现方式中,网关设备采用以下方式获得第一软件包。所述网关设备根据第一内网设备的性能,在软件包的标识与安装性能要求的对应关系中查找到所述第一软件包的标识。网关设备向服务器发送所述第一软件包的标识,并接收所述服务器根据所述第一软件包的标识返回的所述第一软件包。
可选地,为了节省网关设备的存储资源和处理资源,根据内网设备的性能匹配合适软件包的功能也可以由服务器分担。在第一方面的一种可能的实现方式中,网关设备采用以下方式获得第一软件包。网关设备向服务器发送所述第一内网设备的性能。所述网关设备接收所述服务器根据所述第一内外设备的性能返回的所述第一软件包。
可选地,为了进一步节省网关设备的存储资源和处理资源,根据第一内网设备的类型查询安装性能要求的步骤、以及根据性能,获取所述第一软件包的步骤均由服务器执行。在第一方面的一种可能的实现方式中,网关设备采用以下方式获得第一软件包。所述网关设备向服务器发送所述第一内网设备的类型。所述网关设备接收所述服务器根据所述第一内外设备的类型返回的所述第一软件包。
可选地,在第一方面的一种可能的实现方式中,在针对两个或两个以上不同的内网设备,确定出的第一软件包为同一软件包的情况下,可能出现多个内网设备分别安装同一软件包后执行同一附加功能,这有可能导致内网设备资源浪费、或者附加功能实现过程中的冲突问题。为了避免这种可能出现的问题,网关设备向所述第一内网设备发送第一指示消息和所述第一软件包之前,网关设备识别第二内网设备的类型,所述第二内网设备属于所述内部网络。所述网关设备根据所述第二内网设备的类型,确定所述第二内网设备的性能。所述网关设备根据第二内网设备的性能,在软件包与安装性能要求的对应关系中查找到所述第二软件包,所述第二内网设备的性能符合所述第二软件包的安装性能要求;如果所述第一软件包和所述第二软件包为同一软件包,则所述网关设备从所述第一内网设备和所述第二内网设备中选择出所述第一内网设备用以安装所述第一软件包。网关设备可以选用多种方式从所述第一内网设备和所述第二内网设备中选择出所述第一内网设备,例如随机选取,或者按照策略选取。例如,网关设备根据所述第一内网设备的性能和所述第二内网设备的性能,按照预定的选择策略,从所述第一内网设备和所述第二内网设备中选择出所述第一内网设备用以安装所述第一软件包。
可选地,在第一方面的一种可能的实现方式中,为了便于后续对待执行第一附加功能的数据流(即目标数据流)进行正确转发,以便于正确地执行第一附加功能,所述网关设备向所述第一内网设备发送第一指示消息和所述第一软件包之后,保存所述第一内网设备 的标识与所述第一附加功能的对应关系。所述网关设备获取目标数据流,所述目标数据流为待执行所述第一附加功能的数据流。所述网关设备根据所述第一内网设备的标识与所述第一附加功能的对应关系,向所述第一内网设备发送所述目标数据流,并接收所述第一内网设备对所述目标数据流的处理结果。
进一步地,接收所述第一内网设备对所述目标数据流的处理结果之后,网关设备根据所述处理结果,对所述目标数据流执行与所述处理结果对应的动作,所述动作包括转发、告警或者阻断。
可选地,在第一方面的一种可能的实现方式中,为了便于后续对待执行第一附加功能的数据流(即目标数据流)进行正确转发,以便于正确地执行第一附加功能,所述网关设备向所述第一内网设备发送第一指示消息和所述第一软件包之后,保存所述第一内网设备的标识与所述第一附加功能的对应关系。所述网关设备获取目标数据流,所述目标数据流为待执行所述第一附加功能的数据流。所述网关设备确定描述信息,所述描述信息用于描述所述目标数据流。所述网关设备根据所述第一内网设备的标识与所述第一附加功能的对应关系,向所述第一内网设备发送所述描述信息,并接收所述第一内网设备对所述描述信息的处理结果。网关设备向第一内网设备发送描述信息而不是目标数据流,可以减少网关设备向执行附加功能的内网设备发送的数据量。
进一步地,接收所述第一内网设备对所述描述信息的处理结果之后,网关设备根据所述处理结果,对所述目标数据流执行与所述处理结果对应的动作,所述动作包括转发、告警或者阻断。
可选地,为了提升用户的使用感受,在第一方面的一种可能的实现方式中,所述网关设备向所述第一内网设备发送第一指示消息和所述第一软件包之前,输出提示信息,所述提示信息中包括所述第一内网设备的标识与所述第一附加功能的对应关系,所述提示信息用于提示所述第一内网设备具备执行所述第一附加功能的能力;接收输入的确认信息,所述确认信息用于表示允许所述第一内网设备执行所述第一附加功能。
可选地,网关设备通过多种可能的实现方式识别第一内网设备的类型。在实际应用过程中,可以根据不同需求选择其中一种或多种识别方式。一种方式是从转发的流量中识别第一内网设备的类型。网关设备截获所述第一内网设备发送的特征报文,所述特征报文中携带第一特征字段,其中所述第一特征字段的内容用于指示发送方的操作系统类型或者预定网站域名。网关设备在特征库中查询所述第一特征字段的内容对应的第一设备类型,所述特征库中保存所述第一特征字段的内容与所述第一设备类型的对应关系;网关设备确定所述第一内网设备的设备类型为所述第一设备类型。
第二种方式是基于MAC地址进行识别。网关设备获取所述第一内网设备的MAC地址;所述网关设备在设备信息库中查询所述第一内网设备的MAC地址对应的第一设备类型,所述设备信息库中保存所述第一内网设备的MAC地址与所述第一设备类型的对应关系;所述网关设备确定所述第一内网设备的设备类型为所述第一设备类型。
第三种方式是主动扫描探测。网关设备向所述第一内网设备发送探测报文;所述网关设备接收所述第一内网设备发送的对应所述探测报文的响应报文;所述网关设备根据所述响应报文获取第一识别指纹;所述网关设备在指纹库中查询所述第一识别指纹对应的第一设备类型,所述指纹库中保存所述第一识别指纹与所述第一设备类型的对应关系;所述网关设备确定所述第一内网设备的设备类型为所述第一设备类型。
可选地,在第一方面、或者第一方面的任意一种可能的实现方式中,第一附加功能为数据流安全检测功能、网络缓存功能、或者安全沙箱功能。在第一附加功能为数据流安全检测功能的情况下,所述目标数据流为待检测的数据流。在第一附加功能为网络缓存功能的情况下,所述目标数据流为承载待缓存内容的数据流。在第一附加功能为安全沙箱功能的情况下,所述目标数据流为承载待检测文件内容的数据流。
第二方面,提供了网关设备,该网关设备包括网络接口、存储器和与所述存储器连接的处理器。所述存储器用于存储指令;所述处理器用于执行所述指令,以使所述网关设备执行第一方面或第一方面的任意一种可能的实现方式中的方法,具体参见上面的详细描述,此处不再赘述。
第三方面,提供了一种网络业务的处理装置,该装置具有实现上述第一方面所述方法或上述方面的任意一种可能的实现方式的功能。所述功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功能相对应的模块。
第四方面,本申请实施例提供了一种计算机存储介质,用于储存为上述网关设备所用的计算机软件指令,其包含用于执行上述第一方面或上述方面的任意一种可能的实现方式所设计的程序。
第五方面,本申请的又一方面提供了一种包含指令的计算机程序产品,当其在计算机上运行时,使得计算机执行上述各方面所述的方法。
第六方面,本申请实施例提供了一种芯片,包括存储器和处理器,存储器用于存储计算机指令,处理器用于从存储器中调用并运行该计算机指令,以执行上述第一方面及其第一方面任意可能的实现方式中的方法。
附图说明
为了更清楚地说明本申请实施例的技术方案,下面将对实施例中所需要使用的附图作一简单地介绍,显而易见地,下面描述中的附图是本申请的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1是本申请实施例提供的网络业务的处理方案的应用场景示意图;
图2是本申请实施例提供的网络业务处理方法的流程图;
图3是本申请实施例提供的第一种识别内网设备类型的方式的流程图;
图4是本申请实施例提供的第二种识别内网设备的类型的方式流程图;
图5是本申请实施例提供的第三种识别内网设备类型的方式的流程图;
图6是本申请实施例提供的一种基于内网设备的性能选择内网设备安装的软件包的方法的流程图;
图7是本申请实施例提供的另一种网络业务处理方法的流程图;
图8是本申请实施例提供的分布存储方案1中网关设备根据第一内网设备的性能,获取所述第一软件包的流程图;
图9是本申请实施例提供的分布存储方案2中网关设备根据第一内网设备的性能,获取所述第一软件包的流程图;
图10是本申请实施例提供的分布存储方案3中网关设备根据第一内网设备的性能,获取所述第一软件包的流程图;
图11是本申请实施例提供的另一种网络业务处理方法的流程图;
图12是本申请实施例提供的另一种网络业务处理方法的流程图;
图13是本申请实施例提供的网关设备的结构示意图;
图14是本申请实施例提供的一种网络业务的处理装置的结构示意图。
具体实施方式
在网关设备上集成更多附加功能在为用户提供便利的同时,也使得网关设备容易成为性能瓶颈。特别是在网关设备连接的企业局域网中包含的主机数量较多的场景下,或者在作为家庭局域网网关使用的家用路由器本身性能较低的场景下,网关设备往往难以支持集成越来越多的附加功能。
针对以上现状,本申请实施例提供了一种网络业务的处理方法。基于该方法,在网关设备的管理和控制下,由网关设备所连接的内部网络中的内网设备执行一定附加功能,将网关设备执行附加功能的部分负担转移到内网设备上,从而减轻了网关设备的处理负担,提供了一种较低代价的实现网关设备附加功能的方案。具体地,网关设备首先识别所连接的内部网络中的内网设备的类型,进一步根据内网设备的类型,向内网设备发送合适的、用于实现一定附加功能的软件包。内网设备安装软件包后实现相应的附加功能。
下面结合各个附图对本发明实施例技术方案的主要实现原理、具体实施方式及其对应能够达到的有益效果进行详细的阐述。
附图1是本申请实施例提供的网络业务的处理方案的应用场景示意图。该应用场景中包括两个网络,分别为外部网络100和内部网络200。网关设备300用于连接外部网络和内部网络200。可选地,外部网络是互联网,内部网络是由企业、校园、家庭等组织建立的局域网、或者由多个局域网组成的园区网络(Campus network,CAN)。
内部网络200中包括若干内网设备,记为内网设备201~内网设备20n,其中n为大于1的自然数。内网设备的数量受内部网络地址空间的限制,本申请实施例对内网设备的数量不进行特别限制。内网设备包括但不限于个人计算机、服务器、笔记本电脑、虚拟机、可穿戴设备、手机、智慧屏电视、扫地机器人、投影仪、平板电脑、交换机、无线接入点(access point,AP)设备等等具备计算能力和网络连接能力的设备。
可选地,本申请实施例中的网关设备300包括路由器、防火墙、三层交换机等设备。路由器进一步包括接入路由器(如家用路由器)、企业级路由器、骨干级路由器等等。
本申请实施例提供的网络业务的处理系统包括附图1中的网关设备300和内网设备201~内网设备20n中的至少一个内网设备。
网关设备300用于识别第一内网设备的类型,第一内网设备为附图1内网设备201~内网设备20n中的一个内网设备;根据所述第一内网设备的类型,获得第一软件包,所述第一软件包用于实现第一附加功能;向所述第一内网设备发送第一指示消息和所述第一软件包,所述第一指示消息用于指示所述第一内网设备安装所述第一软件包并执行所述第一附加功能。内网设备的类型是指按照功能、使用特点等因素对内网设备进行分类后得到的类别。内网设备的类型包括:个人计算机、服务器、移动终端、打印机、智能家居设备等等。前面提及的笔记本电脑、手机、平板电脑等所属的类型为移动终端,智慧屏电视、扫地机器人、投影仪所属的类型为智能家居设备。
本申请实施例中的附加功能包括但不限于:以防火墙功能为例的数据流安全检测功能、网络缓存功能、安全沙箱功能等等。其中,防火墙功能包括根据预定规则集过滤所转发的局域网和互联网之间的报文,安全沙箱功能包括在虚拟运行环境中运行未知的特定类型的内容,如文件、网页等等,网络缓存功能包括缓存符合条件的文件,如超过预定大小的视频文件、音频文件。
内网设备,用于接收所述网关设备发送的所述第一指示消息和所述第一软件包,并根据所述第一指示消息安装所述第一软件包后执行第一附加功能。
可选地,网关设备300基于不同类型的内网设备分别对应的性能,为内网设备选择合适的软件包以实现附加功能。具体地,网关设备300保存有用于实现不同附加功能的各个软件包、以及每个软件包对应的安装性能要求(例如需要支持安装软件包,对CPU处理速率值的要求、或者存储空间大小的需求等等)。网关设备300在根据所述第一内网设备的类型,获得第一软件包的过程中,首先根据所述第一内网设备的类型,确定所述第一内网设备的性能,所述性能包括软件能力和硬件能力,所述软件能力包括是否支持安装软件包,所述硬件能力包括处理器性能值和/或存储空间大小。可选地,软件能力还包括是否已安装必要的支持软件,以及当前操作系统的版本等等。网关设备300根据第一内网设备的性能,获取所述第一软件包,所述第一内网设备的性能符合所述第一软件包的安装性能要求。例如,网关设备300根据第一内网设备的性能,在软件包与安装性能要求的对应关系中查找到所述第一软件包。
可选地,在内部网络中包括多个内网设备的场景下,网关设备300存在能够识别至少两个内网设备的类型的情况,在这种情况下网关设备300选择其中一个内网设备用以安装第一软件包。具体地,网关设备300识别至少两个内网设备的类型,并获得所述至少两个内网设备中每个内网设备的性能。如果存在至少两个内网设备,如第一内网设备的性能和第二内网设备的性能均符合所述第一软件包的安装性能要求,则网关设备300从至少两个内网设备中选择一个内网设备,如第一内网设备,用以安装所述第一软件包。在这种情况下,网关设备300可以按照多种选择策略选择一个内网设备用以安装所述第一软件包。可选地,网关设备300随机地从第一内网设备和第二内网设备中选择一个内网设备用以安装所述第一软件包,或者网关设备300从第一内网设备和第二内网设备二者中选择性能较高的一个内网设备用以安装所述第一软件包,又或者网关设备300按照内部网络的拓扑结构,从第一内网设备和第二内网设备二者中选择与网关设备300距离较短的一个内网设备用以安装所述第一软件包,篇幅所限,在这里不再一一列举选择策略。
可选地,在网关设备300向所述第一内网设备发送第一指示消息和所述第一软件包之后,为了便于后续将目标数据流,目标数据流是指待执行第一附加功能的数据流,和/或目标数据流的描述信息发送到实现第一附加功能的第一内网设备,网关设备300还需要记录第一内网设备的标识与所述第一附加功能的对应关系。进一步地,网关设备300根据第一内网设备的标识与所述第一附加功能的对应关系,向第一内网设备发送目标数据流和/或上述描述信息后,还包括接收第一内网设备返回的处理结果。可选地,对于某些附加功能,网关设备300还用于根据处理结果,对所述目标数据流执行与所述处理结果对应的动作,所述动作包括转发、告警或者阻断。
可选地,网关设备300通过多种方式中的一种或者两种以上方式的组合来识别第一内网设备的类型。例如,网关设备300根据配置表确定内网设备的类型,其中配置表中保存 有各内网设备的标识与设备的类型的对应关系,配置表是根据管理员输入的数据生成的。此外,网关设备300还可以通过其他主动或被动的方式实时地识别第一内网设备的类型。这些方式包括但不限于:方式1,从特征报文中获得第一内网设备的类型;方式2,基于第一内网设备的媒体接入控制(Media Access Control Address,MAC)地址识别第一内网设备的类型;方式3,通过主动探测扫描确定第一内网设备的类型。
可选地,为了节省网关设备300的存储资源,上述软件包可以保存在一个服务器(如附图1中服务器101所示)中,而不是保存在网关设备300中。即网关设备300不需要保存软件包与安装性能要求的对应关系,而是保存软件包的标识与安装性能要求的对应关系。在这种情况下,网关设备300在软件包的标识与安装性能要求的对应关系中查找到所述第一软件包的标识,向服务器101发送所述第一软件包的标识,并接收所述服务器对应返回的所述第一软件包。服务器101用于根据接收到的第一软件包的标识,向网关设备300发送存储的第一软件包。
可选地,为了再一步降低占用的网关设备300的处理资源,上述根据第一内网设备的性能,获取所述第一软件包的步骤可以由附图1中服务器101执行。在这种情况下,网关设备300向服务器发送所述第一内网设备的性能,网关设备300接收所述服务器101对应返回的所述第一软件包。服务器101保存软件包与安装性能要求的对应关系,接收到网关设备300发送的第一内网设备的性能,在软件包与安装性能要求的对应关系中查找到所述第一软件包,并向网关设备300发送查询到的第一软件包。
可选地,为了再一步降低占用的网关设备300的处理资源,上述根据第一内网设备的类型查询安装性能要求的步骤也可以由附图1中服务器101执行。在这种情况下,网关设备300识别出第一内网设备的类型后,向服务器发送所述第一内网设备的类型;接收所述服务器对应返回的所述第一软件包。服务器101根据所述第一内网设备的类型,确定所述第一内网设备的性能,然后根据第一内网设备的性能,获取所述第一软件包。例如在软件包与安装性能要求的对应关系中查找到所述第一软件包。服务器101向网关设备300发送获取到的第一软件包。
可选地,服务器101可以部署在内部网络200中(图1中未示出);可替换地,服务器101也可以部署在外部网络100(如图1所示)。在服务器101部署在外部网络100中的情况下,服务器101能够支持多个不同内部网络实现本申请实施例提供的网络业务的处理方案,服务器101也被称为“云服务器”。云服务器的所有者为运营商或者除运营商和内部网络所有者之外的第三方机构,云服务器的客户为若干个内部网络200。云服务器由运营商或者除运营商和内部网络所有者之外的第三方机构管理,通过开放专用端口为多个不同内部网络提供支持服务。内部网络200在通过注册认证后,通过通用协议或者私有协议与云服务器进行通信交互。
附图2为本申请实施例提供的网络业务处理方法的流程图。该网络业务处理方法由网关设备执行,如附图1中的网关设备300。本申请实施例提供的网络业务处理方法包括以下步骤。
步骤210,网关设备识别第一内网设备的类型。需要说明的是,“第一内网设备”和后面出现的“第二内网设备”中的“第一”和“第二”并不是表示顺序关系,而是为了区别不同的内网设备。后面描述中出现的第一、第二等也是为了区别不同的信息或消息等。
第一内网设备属于网关设备连接的内部网络,如第一内网设备是附图1中的内网设备 201。
根据一个内网设备的类型,网关设备可以大致确定出该内网设备是否适宜执行附加功能,以及具备执行哪些附加功能的能力。例如,如果一个内网设备为移动终端,由于移动终端的位置经常变化,则该内网设备不太适宜执行附加功能。如果指定移动终端执行某一附加功能,那么当移动终端被使用者带离内部网络范围时,该移动终端执行的附加功能将不可用,这将导致附加功能的不稳定性。又例如,如果一个内网设备为打印机,由于通常打印机的存储和处理性能有限,不太适宜执行消耗存储资源和处理资源较多的附加功能,相对更适宜执行消耗存储资源和处理资源较少的附加功能。
可选地,网关设备采用一种或多种方式来识别内网设备的类型,包括但不限于以下几种。例如网关设备优选其中一种方式来识别某一内网设备的类型,当无法成功识别出该内网设备的类型时,再尝试通过其他方式识别该内网设备的类型。
方式0,基于保存的配置表确定内网设备的类型。
网关设备根据管理员输入的数据生成配置表,其中配置表中保存有各内网设备的标识(如内网设备的互联网协议(Internet Protocol,IP)地址)与设备的类型的对应关系。可选地,管理员使用网关设备的输入输出接口所连接的输入设备,通过网关设备的命令行界面、或者其他应用软件如网管软件界面输入一个内网设备的相关数据,这些数据包括该内网设备的IP地址,以及该内网设备的类型,进一步的还可以输入该内网设备的厂商、具体型号等信息。网关设备根据上述数据在配置表中生成一个内网设备对应的表项,该表项中包括该内网设备的IP地址,以及该内网设备的类型。
网关设备后续需要确定一个内网设备的类型时,根据该内网设备的IP地址,在配置表中查询包含该IP地址的表项,从查找到的表项中获取该内网设备的类型。
方式1,从转发的特征报文中获得第一内网设备的类型。附图3是本申请实施例提供的第一种识别内网设备类型的方式的流程图。
步骤300,网关设备从转发的网络流量截获第一内网设备发送的特征报文,所述特征报文中携带第一特征字段,所述第一特征字段的内容用于指示发送方的操作系统类型或者预定网站域名。可选地,所述预定网站域名包括设备升级网站的域名。
步骤320,网关设备在特征库中查询所述特征报文中的第一特征字段的内容对应的第一设备类型,所述特征库中保存所述第一特征字段的内容与所述第一设备类型的对应关系。
步骤340,网关设备确定所述第一内网设备的类型为所述第一设备类型。
例如,特征报文是内网设备发送的携带用户-代理(User-Agent)字段的超文本传输协议(Hypertext Transfer Protocol,HTTP)报文。内网设备在进行门户网站(Portal)认证过程中会发送携带User-Agent字段的HTTP报文。
下面给出了两个特征字段的具体内容的具体例子。
例1,User-Agent字段内容为“Android 8.0.0;VTR-L09Build/HUAWEIVTR-L09”。型号为HUAWEI P10的手机在进行Portal认证过程中发送的HTTP报文中的User-Agent字段内容包括“Android 8.0.0;VTR-L09 Build/HUAWEIVTR-L09”。
例2,User-Agent字段内容为“Windows NT 6.1;Win64;x64”。个人计算机在进行Portal认证过程中发送的HTTP报文中的User-Agent字段内容包括“Windows NT 6.1;Win64;x64”。
网关设备的特征库中预先保存“Android 8.0.0;VTR-L09 Build/HUAWEIVTR-L09”与设备类型“移动终端”的对应关系,以及“Windows NT 6.1;Win64;x64”与设备类型“个人计算机”的对应关系。当网关设备从第一内网设备发送的特征报文中解析出User-Agent字段的内容后,将解析得到的User-Agent字段的内容与特征库中的各特征字段进行比较,如果解析得到的User-Agent字段的内容包括“Android 8.0.0;VTR-L09 Build/HUAWEIVTR-L09”,则确定第一内网设备的类型为移动终端,如果解析得到的User-Agent字段的内容包括“Windows NT 6.1;Win64;x64”,则确定第一内网设备的类型为个人计算机。
特征报文也可以是内网设备发送的携带选项(Option)字段的DHCP报文。Option字段中的请求参数列表(requested parameter list)字段(即Option 55字段)、厂商标识(vendor id)字段(即Option 60字段)、主机名(host name)字段(即Option 12字段)中的内容也可以用于识别发送该携带选项(Option)字段的DHCP报文的内网设备的类型。
特征报文还可以是内网设备向AP发送的探测请求(Probe Request)报文和/或关联请求(Association Request)报文。
其他的特征报文在这里不再一一列举。
上述特征库是管理员预先配置的,也可以从公开网站中获取,例如https://fingerbank.inverse.ca。
方式2,基于MAC地址进行识别。附图4是本申请实施例提供的第二种识别内网设备的类型的方式流程图。
步骤400,网关设备获取第一内网设备的MAC地址。例如网关设备从转发的IP报文的报文头中获得第一内网设备的MAC地址,又或者网关设备通过向第一内网设备发送ARP请求,并从对应的地址解析协议(Address Resolution Protocol,ARP)响应中获得第一内网设备的MAC地址。
步骤420,网关设备在设备信息库中查询所述第一内网设备的MAC地址对应的第一设备类型,所述设备信息库中保存所述第一内网设备的MAC地址与所述第一设备类型的对应关系。设备信息库是预先保存的。例如,网关设备管理员在内部网络中增加新的设备时,在为这个新的内网设备配置网络等参数时,将该新的内网设备的MAC地址和该新的内网设备的设备类型通过网关设备连接的输入设备输入网关设备并保存。或者,设备信息库是网关设备从内网设备的制造商支持网站上下载的。
步骤440,网关设备确定所述第一内网设备的类型为所述第一设备类型。
例如,MAC地址的前3个字节是MAC组织唯一标识符(Organizationally unique identifier,OUI)。MAC OUI是电气和电子工程师协会(Institute of Electrical and Electronics Engineers,IEEE)统一分配给各个设备厂商,可用于识别IEEE公开的公司。设备厂商与设备的类型存在对应关系,例如有些厂商只生产打印机设备、有的厂商只生成移动终端设备等等。
上述设备信息规则库可以人工建立,也可以参考一些厂商组织网站上的公开信息建立。例如,可以参考IEEE的MAC OUI规则库http://standards-oui.ieee.ory/oui/oui.txt。
方式3,通过主动探测扫描进行识别。网关设备向第一内网设备发送探测报文,从根据对应的响应报文识别第一内网设备的类型。附图5是本申请实施例提供的第三种识别内 网设备类型的方式的流程图。
步骤500,网关设备向第一内网设备发送探测报文。
步骤520,网关设备接收所述第一内网设备发送的对应所述探测报文的响应报文。
步骤540,网关设备根据所述响应报文获取第一识别指纹。
步骤560,网关设备在指纹库中查询所述第一识别指纹对应的第一设备类型,所述指纹库中保存所述第一识别指纹与所述第一设备类型的对应关系。
步骤580,网关设备确定所述第一内网设备的类型为所述第一设备类型。
例如,网关设备中预先安装一个或多个扫描器软件,扫描器软件包括但不限于Tenable公司推出的漏洞扫描器NESSUS、开源扫描工具Nmap、Unix操作系统平台的网络工具netcat等等。网关设备通过运行上述扫描器软件主动地向内网设备发送探测报文,并从对应的响应报文获得识别指纹,根据识别指纹识别作为扫描对象的内网设备的类型。
例如,网关设备使用Nmap对一个内网设备进行扫描时,发送多个特殊构造的探测报文。网关设备接收内网设备对应的响应报文,并根据响应报文中的下列字段值生成识别指纹。响应报文中用于生成识别指纹的字段包括以下一个或多个的组合:SEQ、OPS、WIN、T1-T7、IE、ECN、U1。然后网关设备以生成的识别指纹为索引,在指纹库中查询对应的设备类型。
版本号为7.70的Nmap提供的指纹库中包含明文存储的5652个指纹。这些指纹对应28个设备类型。
回到附图2所示的流程中,网关设备在步骤210中识别出第一内网设备的类型后,执行步骤220。
步骤220,网关设备根据所述第一内网设备的类型,获得第一软件包,所述第一软件包用于实现第一附加功能。
可选地,网关设备保存有内网设备的类型与软件包的对应关系,如表1所示。网关设备识别出第一内网设备的类型后,从表1所示的对应关系中查询到第一内网设备的类型对应的软件包。
软件包是指是指具有特定的功能,用来完成特定任务的一个程序或一组程序。为了描述简便且具有区别性,在本申请实施例中,用带有后缀的字符串表示软件包,而用不带后缀的字符串表示软件包的标识(软件包的名称)。例如,“Firewall.exe”表示用于实现以防火墙为例的安全检测附加功能的软件包,Firewall表示该软件包的标识。
表1
Figure PCTCN2020121251-appb-000001
可选地,内网设备的类型与软件包的对应关系在具体存储时,有多种可能的保存形式。 例如,实际保存的是内网设备的类型与软件包在网关设备的文件系统中的存储位置的对应关系、或者内网设备的类型与软件包的标识的对应关系。其中存储位置包括但不限于文件系统中的路径。如果保存的是内网设备的类型与软件包在网关设备的文件系统中的存储位置的对应关系,网关设备在根据第一内网设备的类型查找到对应的第一软件包的存储位置后,在该存储位置上获取到第一软件包。如果保存的是内网设备的类型与软件包的标识的对应关系,网关设备根据第一内网设备的类型查找到对应的第一软件包的标识后,在网关设备的文件系统中查找到第一软件包。
可选地,由于在通常情况下,软件包与附加功能有一一对应的关系,表1所示的对应关系也可以替换为内网设备的类型与附加功能的对应关系。在这种情况下,网关设备识别出第一内网设备的类型后,从内网设备的类型与附加功能的对应关系中查询到第一内网设备的类型对应的附加功能,再进一步获取实现该附加功能的软件包。或者表1所示的对应关系中也可以同时包括软件包和软件包对应的附加功能。
步骤230,网关设备向第一内网设备发送第一指示消息和第一软件包。其中,第一指示消息用于指示所述第一内网设备安装所述第一软件包并执行所述第一附加功能。例如,第一指示消息中包括第一软件包的标识和操作符,操作符对应安装操作和运行操作。第一软件包的标识包括第一软件包的名称、第一软件包的哈希值等等。
可选地,为了提升用户的使用感受,保证用户的知情权,网关设备向第一内网设备发送第一软件包和第一指示消息之前,通过网关设备通知管理员第一内网设备能够执行第一附加功能。网关设备在接收到管理员的确认指示后,执行步骤230。可选地,通知方式包括但不限于:通过网关设备的连接的输出设备提示管理员、向管理员使用的手机发送短信、向管理员发送电子邮件、通过以微信,MSN(The Microsoft Network)为例的即时通讯软件向管理员发送消息等等。
根据本申请实施例提供的网络业务处理方法,网关设备作为实现附加功能的管理控制主体。网关设备首先识别内网设备的类型,根据内网设备的类型,向内网设备发送用于实现适宜附加功能的软件包,指示内网设备成功安装软件包后实现附加功能。由于将执行附加功能的部分负担从网关设备转移到内网设备上,从而减轻了网关设备的处理负担,节约了网关设备的处理资源和存储资源,提供了一种较低代价的实现网关设备附加功能的方案。同时,该方案利用内网设备的闲置资源实现附加功能,提高了内网资源的利用率。此外,该方案中,每项附加功能都对应独立的软件包,每次增加附加功能时,只需要开发对应的软件包即可。执行新的附加功能并不会显著增加网关设备的负担,因此还具备较佳的可扩展性。
在附图2所示的网络业务的处理方法中,在步骤220中网关设备基于表1所示的内网设备的类型与软件包的对应关系获得第一软件包,该方式快捷有效。然而在实际实施场景中,往往存在多种类型的内网设备,而这些内网设备的性能有较大差异,步骤220的方法只能实现内网设备与软件包(或附加功能)之间的粗粒度匹配。在具体实施过程中可能存在软件包安装失败、或者附加功能实现效果不佳的问题。例如,内网设备的性能实际上难以满足实现附加功能的需求而导致的软件包安装失败,或者因内网设备的性能过低导致软件包安装完成之后运行速度过慢,附加功能实现效果较差。
如果能够提高内网设备与软件包(或附加功能)之间匹配的精确性,将有可能较大提升附加功能的实现效果和性能。例如,有第一内网设备的类型为服务器、第二内网设备的 类型为个人计算机,虽然第一内网设备和第二内网设备均能支持一个消耗存储资源和处理资源较多的附加功能。然而由于第一内网设备的性能显著高于第二内网设备,例如第一内网设备具有更大的存储器容量和处理器速率,由第一内网设备来执行消耗存储资源和处理资源较多的附加功能能够获得更佳的效果。因此,本申请实施例提供了一种基于内网设备的性能选择内网设备安装的软件包的方法,如附图6所示。附图6所示的过程是执行附图2中步骤220“网关设备根据所述第一内网设备的类型,获得第一软件包”的一种替代方法。
步骤610,网关设备根据所述第一内网设备的类型,确定所述第一内网设备的性能。其中,性能包括软件能力和硬件能力,所述软件能力包括是否支持安装软件包,所述硬件能力包括处理器性能值、存储空间大小等等。
可选地,网关设备中保存有内网设备的类型与性能的对应关系,如表2所示。网关设备识别出第一内网设备的类型后,可以在表2所示的内网设备的类型与性能的对应关系中查询到第一内网设备的性能。
可选地,内网设备的类型进一步还包含内网设备的生产商、和/或型号信息,相当于对内网设备的类型进一步进行了细分。网关设备在图2中的步骤220中识别出包含生产商、和/或型号信息的第一内网设备的类型后,可以在表2所示的内网设备的类型与性能的对应关系中查询到更为精确的性能。
表2
Figure PCTCN2020121251-appb-000002
步骤620,网关设备根据第一内网设备的性能,获取所述第一软件包。其中,所述第一内网设备的性能符合所述第一软件包的安装性能要求。
可选地,网关设备中存储每个软件包对应的安装性能要求,如表3所示。网关设备获得第一内网设备的性能后,将第一内网设备的性能与各软件包对应的安装性能要求进行比对,如果第一内网设备的主要性能高于第一软件包的安装性能要求,则确定第一内网设备的性能符合所述第一软件包的安装性能要求。
表3
Figure PCTCN2020121251-appb-000003
例如,假设第一内网设备的类型是个人计算机、型号为H-TG01,则第一内网设备的性能符合软件包networkstorage.exe和Firewall.exe的安装性能要求,不符合软件包Websandbox.exe的安装性能要求。在这种情况下,第一软件包是名为networkstorage.exe的软件包或名为Firewall.exe的软件包。
假设第一内网设备的类型是服务器、型号为D-R7,则第一内网设备的性能符合软件包networkstorage.exe、Firewall.exe和Websandbox.exe的安装性能要求。在这种情况下,第一软件包是名为networkstorage.exe的软件包、名为Firewall.exe的软件包或名为Websandbox.exe的软件包。
本申请实施例中网关设备识别出第一内网设备的类型后,根据第一内网设备的类型获取第一内网设备的性能,再将第一内网设备的性能与软件包的安装性能要求进行比对,从而确保第一内网设备的性能符合选择出的第一软件包的安装性能要求。这样可以降低第一内网设备安装软件包、或者运行软件包的失败率,提升第一内网设备安装软件包的成功率,从而提高附加功能的实现效果。
可选地,当附图1中的内部网络200中包含多个内网设备时。网关设备300并行地识别多个内网设备的类型,在识别出多个内网设备的类型后,采用附图2或者附图6所示的方法可能出现针对两个或两个以上不同的内网设备,确定出的第一软件包为同一软件包的情况。这时,如果网关设备300向两个或两个以上内网设备发送同一软件包,那么这些内网设备分别安装同一软件包后将执行同一附加功能,这有可能导致内网设备资源浪费、或者附加功能实现过程中的冲突问题。为了避免这种可能出现的问题,在针对多个不同的内网设备,网关设备300确定出的第一软件包为同一软件包的情况下,网关设备300需要从多个内网设备中选择出一个内网设备。网关设备300向选择出的内网设备发送第一软件包,避免同时向多个内网设备发送同一软件包。即,在附图2所示的方法中,步骤230之前,还包括:网关设备300确定根据第二内网设备的类型,获得所述第一软件包;网关设备300从第一内网设备和第二内网设备中选择出第一内网设备,向第一内网设备发送第一指示消息和第一软件包,而不向第二内网设备发送第一指示消息和第一软件包。
类似地,在附图6所示的网络业务的处理方法,如果出现针对两个或两个以上不同的内网设备,确定出的第一软件包为同一软件包的情况,还可以根据两个内网设备的性能,选择出其中一个内网设备用于后续安装第一软件包。这种情况下的网络业务的处理方法,如图7所示。
附图7所示的一种网络业务的处理方法包括以下步骤。
步骤210、610、620、230请参考附图6及相关描述,在这里不再重复。
在步骤230之前,所述方法还包括:
步骤710,网关设备识别第二内网设备的类型,所述第二内网设备属于所述网管设备连接的内部网络。
步骤720,网关设备根据所述第二内网设备的类型,确定所述第二内网设备的性能。
步骤730,所述网关设备根据第二内网设备的性能,在软件包与安装性能要求的对应关系中查找到所述第二软件包,所述第二内网设备的性能符合所述第二软件包的安装性能要求。
步骤710~步骤730的实现原理分别与附图2中步骤210以及附图6中的步骤610、620类似,在这里不再重复。
步骤240,网关设备判断所述第一软件包和所述第二软件包是否为同一软件包,如果第一软件包和第二软件包为不同软件包,则执行步骤230和步骤231。步骤231,网关设备向第二内网设备发送第二指示消息和第二软件包,所述第二指示消息用于指示所述第二内网设备安装所述第二软件包并执行所述第二附加功能。
如果第一软件包和第二软件包为同一软件包,则执行步骤250。
步骤250,网关设备根据第一内网设备的性能和第二内网设备的性能,按照预定的选择策略,从第一内网设备和第二内网设备中选择出第一内网设备用以安装第一软件包。执行步骤230。
可选地,预定的选择策略包括选择性能更佳的内网设备。
假设第一内网设备为附图1中的内网设备201,内网设备201的类型为个人计算机、型号为H-TG01。假设第二内网设备为附图1中的内网设备202,内网设备202的类型为个人计算机、型号为D-VOSTRO。网关设备300识别出内网设备201和内网设备202的类型后,分别针对内网设备201和内网设备202执行附图6所示的方法,确定内网设备201用以安装Firewall.exe、内网设备201也用以安装Firewall.exe。由于内网设备201的性能优于内网设备201,因此网关设备300从内网设备201和内网设备202中选择出内网设备201,网关设备300向内网设备201发送指示消息,该指示消息中包括Firewall.exe软件包,用以指示内网设备201安装Firewall.exe软件包并执行对应的防火墙功能。
可选地,以附图1中网关设备300为例的网关设备作为控制各个内网设备执行附加功能的主体,执行附图2、附图2或附图7所示的网络业务的处理方法。上述用以执行各个附加功能的多个软件包可以集中存储也可以分布存储。集中存储是指上述用以执行各个附加功能的多个软件包被保存在网关设备的存储器中。分布存储是指上述用以执行各个附加功能的多个软件包中的全部或者部分软件包存储在网关设备可访问的、其他网络设备中。可选地,这些用于存储全部或者部分软件包的网络设备可以部署在内部网络200中,也可以部署在外部网络100。这里仅以附图1所示的“云服务器”的方案为例,对分布存储的情况进行描述。本申请实施例给出了三种分布存储的具体实现方式。
分布存储方案1
各个软件包保存在如附图1中服务器101所示云服务器中,而不是保存在网关设备300中。网关设备300不需要保存软件包与安装性能要求的对应关系,而是保存软件包的标识与安装性能要求的对应关系。在这种情况下,附图6中步骤220的实现过程如图8所示。
附图8描述了网关设备根据第一内网设备的性能,获取所述第一软件包的流程。
网关设备执行附图6中步骤610,根据所述第一内网设备的类型,确定所述第一内网设备的性能后,与服务器配合执行附图8中步骤810~步骤840以替代附图6中的步骤620。
步骤810,网关设备根据第一内网设备的性能,在软件包的标识与安装性能要求的对应关系中获取到第一软件包的标识。其中,第一内网设备的性能符合所述第一软件包的标识对应的安装性能要求。
步骤820,网关设备向服务器发送所述第一软件包的标识。
步骤830,服务器根据接收到的第一软件包的标识,获取到保存的第一软件包。
步骤840,服务器向网关设备发送获取的第一软件包。网关设备接收所述服务器对应返回的所述第一软件包。
例如,假设第一内网设备为内网设备201,内网设备201的类型是个人计算机、型号为H-TG01。网关设备300本地保存有保存软件包的标识与安装性能要求的对应关系,如表4所示。
表4
Figure PCTCN2020121251-appb-000004
网关设备300确定第一内网设备的性能符合名为Firewall的软件包的安装性能要求。网关设备300向服务器101发送第一软件包的标识“Firewall”,接收服务器101返回的软件包Firewall.exe后,向内网设备201发送第一指示消息和软件包Firewall.exe。
本申请实施例提供的分离存储方案能够节省网关设备300的存储资源。
分布存储方案2
各个软件包保存在如附图1中服务器101所示云服务器中,而不是保存在网关设备300中。网关设备300不需要保存软件包与安装性能要求的对应关系,也不需要保存软件包的标识与安装性能要求的对应关系,只需要保存表2所示的内网设备的类型与性能的对应关系。服务器101不仅保存各个软件包,还需要保存如表3所示的软件包与安装性能要求的对应关系。在这种情况下,附图6中步骤220的实现过程如图9所示。
附图9描述了网关设备根据第一内网设备的性能,获取所述第一软件包的流程。
网关设备执行附图6中步骤610,根据所述第一内网设备的类型,确定所述第一内网设备的性能后,与服务器配合执行步骤910~步骤930以替代附图6中的步骤620。
步骤910,网关设备向服务器发送所述第一内网设备的性能。
步骤920,服务器根据接收到的第一内网设备的性能,在软件包与安装性能要求的对应关系中获取到所述第一软件包。其中,第一内网设备的性能符合所述第一软件包的标识对应的安装性能要求。
例如,服务器保存表3所示的软件包与安装性能要求的对应关系,服务器在接收到网关设备发送的第一内网设备的性能后,将第一内网设备的性能与各软件包对应的安装性能要求进行比对,如果第一内网设备的主要性能高于第一软件包的安装性能要求,则确定第一内网设备的性能符合所述第一软件包的安装性能要求。
可替代地,服务器保存的不是表3所示的软件包与安装性能要求的对应关系,而是表4所示的服务器保存软件包的标识与安装性能要求的对应关系。服务器接收到的第一内网设备的性能后,将第一内网设备的性能与各软件包的标识对应的安装性能要求进行比对,如果第一内网设备的主要性能高于第一软件包的标识对应的安装性能要求,则确定第一内网设备的性能符合所述第一软件包的安装性能要求。服务器再根据第一软件包的标识查找到对应的第一软件包。
步骤930,服务器向网关设备发送第一软件包。相应地,所述网关设备接收所述服务器对应返回的所述第一软件包,再将第一软件包和第一指示消息发送给第一内网设备。
例如,假设第一内网设备为内网设备201,内网设备201的类型是个人计算机、型号为H-TG01。网关设备300根据表2确定出内网设备201的性能包括“CPU:2GHz;内存:512MB;硬盘容量:256GB”。网关设备300向服务器101发送内网设备201的性能“CPU:2GHz;内存:512MB;硬盘容量:256GB”。服务器101将接收到的性能“CPU:2GHz;内存:512MB;硬盘容量:256GB”与保存的表3所示的软件包与安装性能要求的对应关系,或者表4所示的服务器保存软件包的标识与安装性能要求的对应关系中的各表项进行比对。服务器101内网设备201的性能符合软件包Firewall.exe的安装性能要求。服务器101向网关设备300发送软件包Firewall.exe。
本申请实施例提供的分离存储方案一方面能够进一步节省网关设备的存储资源,另一方面由于根据性能,获取所述第一软件包的步骤由服务器执行,也节省了网关设备的处理资源。
分布存储方案3
各个软件包保存在如附图1中服务器101所示云服务器中,而不是保存在网关设备300中。网关设备300不仅不需要保存软件包与安装性能要求的对应关系,也不需要保存软件包的标识与安装性能要求的对应关系,还不需要保存表2所示的内网设备的类型与性能的对应关系。服务器101不仅保存各个软件包,还需要保存如表3所示的软件包与安装性能要求的对应关系,进一步还需要保存表2所示的内网设备的类型与性能的对应关系。在这种情况下,附图2中步骤220的实现过程如图10所示。
附图10描述了网关设备根据第一内网设备的性能,获取所述第一软件包的流程。
网关设备执行附图2、或者附图6中步骤210,识别第一内网设备的类型之后,与服务器配合执行步骤110~步骤130以替代附图2中的步骤220,或者替代附图6中的步骤610~620。
步骤110,网关设备向服务器发送所述第一内网设备的类型。
步骤120,服务器接收到网关设备发送的第一内网设备的类型后,在表2所示的内网设备的类型与性能的对应关系中查询到第一内网设备的性能。
步骤130,服务器根据查询到的第一内网设备的性能,在软件包与安装性能要求的对应关系中查找到所述第一软件包。其中,第一内网设备的性能符合所述第一软件包的标识对应的安装性能要求。
例如,服务器保存表3所示的软件包与安装性能要求的对应关系,服务器在查询到第一内网设备的性能后,将第一内网设备的性能与各软件包对应的安装性能要求进行比对,如果第一内网设备的主要性能高于第一软件包的安装性能要求,则确定第一内网设备的性能符合所述第一软件包的安装性能要求。
可替代地,服务器保存的不是表3所示的软件包与安装性能要求的对应关系,而是表4所示的服务器保存软件包的标识与安装性能要求的对应关系。服务器在查询到第一内网设备的性能后,将第一内网设备的性能与各软件包的标识对应的安装性能要求进行比对,如果第一内网设备的主要性能高于第一软件包的标识对应的安装性能要求,则确定第一内网设备的性能符合所述第一软件包的安装性能要求。服务器再根据第一软件包的标识查找到对应的第一软件包。
可替代地,服务器保存的不是表3所示的软件包与安装性能要求的对应关系或表4所示的服务器保存软件包的标识与安装性能要求的对应关系,而是表1所示的内网设备的类型与软件包的对应关系。这种情况下,步骤120和步骤130可以直接简化为,服务器根据接收到的内网设备的类型,在内网设备的类型与软件包的对应关系查询到第一设备的类型对应的软件包。如步骤220基本类似,只是执行主体不同,在这里不再展开详述。
步骤140,服务器向网关设备发送第一软件包。相应地,所述网关设备接收所述服务器对应返回的所述第一软件包,再将第一软件包和第一指示消息发送给第一内网设备。
步骤130的执行过程与附图9中的步骤920类似,步骤140的执行过程与附图9中的步骤930类似,在这里不再展开描述。
例如,假设第一内网设备为内网设备201,内网设备201的类型是个人计算机、型号为H-TG01。网关设备300向服务器101发送内网设备201的类型“个人计算机、H-TG01”。服务器101接收到内网设备201的类型“个人计算机、H-TG01”后,在表2所示的内网设备的类型与性能的对应关系中,查询到类型“个人计算机、H-TG01”对应的性能为“CPU:2GHz;内存:512MB;硬盘容量:256GB”。服务器101进一步将性能“CPU:2GHz;内存:512MB;硬盘容量:256GB”与保存的表3所示的软件包与安装性能要求的对应关系,或者表4所示的服务器保存软件包的标识与安装性能要求的对应关系中的各表项进行比对,确定性能“CPU:2GHz;内存:512MB;硬盘容量:256GB”符合软件包Firewall.exe的安装性能要求。服务器101向网关设备300发送软件包Firewall.exe。
本申请实施例提供的分离存储方案一方面能够进一步节省网关设备的存储资源,另一方面由于根据第一内网设备的类型查询安装性能要求的步骤、以及根据性能,获取所述第一软件包的步骤均由服务器执行,也进一步节省了网关设备的处理资源。
可选地,根据附图2、附图6~附图10所述的网络业务的处理方法,网关设备向第一内网设备发送第一指示消息和第一软件包之后,为了便于后续将目标数据流,和/或用于描述目标数据流的描述信息发送到实现第一附加功能的第一内网设备,网关设备还需要记录第一内网设备的标识与所述第一附加功能的对应关系。其中目标数据流是指待执行第一附加功能的数据流。网关设备记录第一内网设备的标识与所述第一附加功能的对应关系的目的是为了后续对目标数据流进行正确转发,以便于正确地执行第一附加功能。例如,网 关设备根据第一内网设备的标识与所述第一附加功能的对应关系,后续将目标数据流,和/或用于描述目标数据流的描述信息,发送到实现第一附加功能的第一内网设备,并接收第一内网设备对应的处理结果。可选地,对于一些附加功能,网关设备根据接收到的处理结果,对待转发流量中的目标数据流执行与所述处理结果对应的动作,所述动作包括转发、告警或者阻断。具体实现过程如附图11和附图12所示。
基于本申请前面各个实施例提供的网络业务的处理方法,本申请实施例又提供了一种网络业务的处理方法,如附图11所示。附图11是本申请实施例提供的网络业务的处理方法的流程图。以附图1中网关设备300为例的网关设备在执行附图2、附图6~附图10所述的网络业务的处理方法中的向第一内网设备发送第一指示消息和第一软件包的步骤之后,还执行附图11所示的各步骤。
步骤111,网关设备保存第一内网设备的标识与第一附加功能的对应关系。
可选地,为了保证第一附加功能的实现效果,网关设备向第一内网设备发送第一指示消息和第一软件包之后,等待接收第一内网设备在第一软件包安装完成之后返回的确认消息。网关设备接收到来自于第一内网设备的确认消息后,网关设备再保存第一内网设备的标识与第一附加功能的对应关系。
步骤112,网关设备获取待转发的流量,并从待转发的流量中获取目标数据流,所述目标数据流是指待执行第一附加功能的数据流。
哪些数据流是目标数据流是与具体的附加功能相关的。例如如果第一附加功能是数据流安全检测功能,那么目标数据流是符合预定策略的待检测的流量。预定策略是根据预先根据网络场景设置的,可以是全部双向流量、也可以是外部网络向内部网络发送的单向流量等等。
例如,如果第一附加功能是网络缓存功能,那么目标数据流为承载待缓存内容的数据流。待缓存内容的类型是预先设置的,例如待缓存内容是多媒体内容等等。
例如,如果第一附加功能为安全沙箱功能,那么目标数据流为承载待检测文件内容的数据流。待检测文件的格式类型是预先设置的,例如便携式文档格式(Portable Document Format,pdf)文件、或者可执行(executable file,exe)文件、可移植可执行(Portable Executable,PE)文件等等。网关设备可以对待转发数据流中的部分报文,例如会话建立初始阶段的少量报文,进行解析从而确定这些报文所属的数据流是否是目标数据流。例如对会话建立初始阶段的少量报文进行协议解析获得报文中承载的文件头数据,从文件头数据中获取会话承载的内容类型。
步骤113,网关设备根据所述第一内网设备的标识与第一附加功能的对应关系,向第一内网设备发送目标数据流。
步骤114,网关设备接收第一内网设备对目标数据流的处理结果。
可选地,以第一附加功能为网络缓存功能为例。第一内网设备为附图1中的内网设备201,网关设备为附图1中网关设备300。网关设备300向内网设备201发送第一指示消息和软件包networkstorage.exe。内网设备201根据第一指示消息安装软件包Firewall.exe完成后,执行网络缓存功能。网关设备300记录内网设备201与网络缓存功能的对应关系。网关设备300中被配置的预定策略为对超过50M的视频文件进行缓存。即目标数据流为承载超过50M的视频文件的数据流。网关设备300通过网络接口后续接收承载超过50M的视频文件的数据流后,除了执行原有转发流程,还向内网设备201发送该数据流。网关设备 300接收到内网设备201对这部分数据流的缓存结果,如缓存结果指示视频文件缓存成功或者缓存结果指示视频文件缓存失败。
可选地,对于某些附加功能,在步骤114之后,网关设备还执行步骤115。
步骤115,网关设备根据所述处理结果,对目标数据流执行与所述处理结果对应的动作,所述动作包括转发、告警或者阻断。
可选地,以第一附加功能为数据流安全检测功能为例。第一内网设备为附图1中的内网设备201,网关设备为附图1中网关设备300。网关设备300向内网设备201发送的第一指示消息和软件包Firewall.exe。内网设备201根据第一指示消息安装软件包Firewall.exe完成后,执行以防火墙为例的数据流安全检测功能。网关设备300记录内网设备201与数据流安全检测功能的对应关系。网关设备300中被配置的预定策略为对外部网络向内部网络发送的单向流量进行安全检测。即待检测的目标数据流为外部网络向内部网络发送的单向流量。网关设备300通过网络接口后续接收到外部网络100向内部网络200发送的数据流后,向内网设备201发送该数据流。网关设备300接收到内网设备201对目标数据流的安全检测结果后,如果安全检测结果指示目标数据流不含违反防火墙规则的数据,则网关设备300通过网络接口向内部网络200转发该目标数据流;如果安全检测结果指示目标数据流含有违反防火墙规则的数据,则网关设备300阻断目标数据流,禁止通过网络接口向内部网络200转发目标数据流。
基于附图11所示的处理方法,在一些应用场景下,为了减少网关设备向执行附加功能的内网设备发送的数据量,网关设备先对目标数据流进行解析、分析、提取或统计,获得用于描述目标数据流的描述信息。描述信息也被称为元数据(metadata)。元数据为描述数据的数据(data about data),主要是描述数据属性(property)的信息,用来支持如指示存储位置、历史数据、资源查找、文件记录等功能。可选地,描述信息的生成方式和格式有多种,包括标准组织和现有主流厂商支持的格式,或者是管理员自定义的格式。例如互联网工程任务组(Internet Engineering Task Force,IETF)定义的IP数据流信息输出(IP Flow Information Export,IPFIX)协议格式,NetFlow格式,sflow格式等等。
网关设备向执行附加功能的内网设备发送的是描述信息而不是目标数据流本身,从而减少网关设备与内网设备之间传输的数据量。具体实现过程如附图12所示。
附图12是本申请实施例提供的网络业务的处理方法。以附图1中网关设备300为例的网关设备在执行附图2、附图6~附图10所述的网络业务的处理方法中的向第一内网设备发送第一指示消息和第一软件包的步骤之后,还执行附图12所示的各步骤。
步骤121,网关设备保存第一内网设备的标识与第一附加功能的对应关系。
步骤122,网关设备获取待转发的流量,并从待转发的流量中获取目标数据流,所述目标数据流是指待执行所述第一附加功能的数据流。
附图12中的步骤121和步骤122分别与附图11中的步骤111和步骤112类似,在这里不重复描述。
步骤123,网关设备确定描述信息,所述描述信息用于描述目标数据流。
步骤124,网关设备根据所述第一内网设备的标识与第一附加功能的对应关系,向第一内网设备发送描述信息。
步骤125,网关设备接收第一内网设备对描述信息的处理结果。
步骤126,网关设备根据第一内网设备对描述信息的处理结果,对目标数据流执行与所述处理结果对应的动作,所述动作包括转发、告警或者阻断。
可选地,以第一附加功能为数据流安全检测功能为例。第一内网设备为附图1中的内网设备201,网关设备为附图1中网关设备300。网关设备300向内网设备201发送第一指示消息和软件包Firewall.exe。内网设备201根据第一指示消息安装软件包Firewall.exe完成后,执行以防火墙为例的数据流安全检测功能。网关设备300记录内网设备201与数据流安全检测功能的对应关系。网关设备300中被配置的预定策略为对外部网络向内部网络发送的单向流量进行安全检测。即目标数据流为外部网络向内部网络发送的单向流量。网关设备300通过网络接口后续接收到外部网络100向内部网络200发送的数据流(即目标数据流)后,提取目标数据流的描述信息。描述信息包括由源地址、源端口号、目的地址、目的端口号和协议类型组成的五元组信息,可选地,描述信息还包括报文头中部分指定字段的内容等等。网关设备300向内网设备201发送描述信息。网关设备300接收到内网设备201对描述信息的安全检测结果后,如果安全检测结果指示描述信息中不含违反防火墙规则的数据,则网关设备300通过网络接口向内部网络200转发目标数据流;如果安全检测结果指示描述信息中含有违反防火墙规则的数据,则网关设备300阻断这目标数据流,禁止通过网络接口向内部网络200转发这目标数据流。
相应地,本申请实施例提供了一种网关设备,用以执行上述各个实施例提供的网络业务的处理方法。图13是本申请实施例提供的网关设备的结构示意图。可选地,图13所示的网关设备是图1所示应用场景中的网关设备300、图2、图6~附图12所示流程中的网关设备。网关设备包括处理器131、存储器132和网络接口133。
处理器131可以是一个或多个CPU,该CPU可以是单核CPU,也可以是多核CPU。
存储器132包括但不限于是随机存取存储器(random access memory,RAM)、只读存储器(Read only Memory,ROM)、可擦除可编程只读存储器(erasable programmable read-only memory,EPROM或者快闪存储器)、快闪存储器、或光存储器等。存储器132中保存有操作系统的代码。
网络接口133可以是有线接口,例如光纤分布式数据接口(Fiber Distributed Data Interface,FDDI)、千兆以太网(Gigabit Ethernet,GE)接口;网络接口63也可以是无线接口。网络接口133用于接收来自于内部网络和/或外部网络的数据流,根据处理器131的指示与内部网络中的内网设备进行通信,以及与外部网络中的服务器进行通信。
可选地,处理器131通过读取存储器132中保存的指令实现上述实施例中的方法,或者,处理器131也可以通过内部存储的指令实现上述实施例中的方法。在处理器131通过读取存储器132中保存的指令实现上述实施例中的方法的情况下,存储器132中保存实现本申请上述实施例提供的方法的指令。
处理器131执行存储器132中存储的指令后,使得网关设备执行以下操作:识别第一内网设备的类型,所述第一内网设备属于所述网关设备连接的内部网络;所述网关设备根据所述第一内网设备的类型,获得第一软件包,所述第一软件包用于实现第一附加功能;通过所述网络接口133向所述第一内网设备发送第一指示消息和所述第一软件包,所述第一指示消息用于指示所述第一内网设备安装所述第一软件包并执行所述第一附加功能。
所述至少一个处理器131进一步根据存储器132保存的若干对应关系表(如前面实施例中的表1、表2、表3、表4)来执行上述方法实施例所描述的网络业务的处理方法。处 理器131实现上述功能的更多细节请参考前面各个方法实施例中的描述,在这里不再重复。
可选地,网关设备还包括总线134,上述处理器131、存储器132通常通过总线134相互连接,也可以采用其他方式相互连接。
可选地,网关设备还包括输入输出接口135,输入输出接口135用于与输出设备连接,向管理员输出提示消息,以通知管理员第一内网设备能够执行第一附加功能,以及在合适的条件下,根据内网设备的处理结果输出告警等等。输出设备包括但不限于显示器、打印机等等。
输入输出接口135还用于与输入设备连接,接收管理员针对提示消息返回的确认消息。输入设备包括但不限于键盘、触摸屏、麦克风、蓝牙模块等等。
附图13所示的网关设备可以实现的其他附加功能、以及与其他网元设备(如内网设备或者服务器)的交互过程,请参照方法实施例中对网关设备的描述,在这里不再赘述
本申请实施例提供的网关设备用于执行上述各个方法实施例提供的网络业务的处理方法。该网关设备本身无需执行附加功能,而是作为实现附加功能的管理控制主体,控制适宜的内网设备分担实现附加功能的任务。该网关设备的主要功能是识别内网设备的类型,根据内网设备的类型,向内网设备发送用于实现适宜附加功能的软件包,指示内网设备成功安装软件包后实现附加功能。
图14是本申请实施例提供的一种网络业务的处理装置的结构示意图。该处理装置14包括处理模块141和发送模块142。该处理装置14与上述各个方法实施例中的网关设备耦合连接,例如集成在网关设备中,是网关设备中的一个软件或硬件组件。附图14所示的处理装置应用于方法实施例附图1所示的场景中,实现其中网关设备的功能。
处理模块141,用于识别第一内网设备的类型,所述第一内网设备属于所述网关设备连接的内部网络;根据识别出的所述第一内网设备的类型,获得第一软件包,所述第一软件包用于实现第一附加功能。
发送模块142,用于向所述第一内网设备发送第一指示消息和所述第一软件包,所述第一指示消息用于指示所述第一内网设备安装所述第一软件包并执行所述第一附加功能。
可选地,处理模块141根据所述第一内网设备的类型,获得第一软件包,包括:根据所述第一内网设备的类型,确定所述第一内网设备的性能,所述性能包括软件能力和硬件能力,所述软件能力包括是否支持安装软件包,所述硬件能力包括处理器性能值和/或存储空间大小;根据所述第一内网设备的性能,获取所述第一软件包,所述第一内网设备的性能符合所述第一软件包的安装性能要求。
可选地,发送模块142向所述第一内网设备发送第一指示消息和所述第一软件包之前,所述处理模块141还用于识别第二内网设备的类型,所述第二内网设备属于所述内部网络。处理模块141根据所述第二内网设备的类型,确定所述第二内网设备的性能;获取第二软件包,所述第二内网设备的性能符合所述第二软件包的安装性能要求。如果所述第一软件包和所述第二软件包为同一软件包,则所述网关设备从所述第一内网设备和所述第二内网设备中选择出所述第一内网设备用以安装所述第一软件包。
可选地,所述装置还包括接收模块143。
发送模块142向所述第一内网设备发送第一指示消息和所述第一软件包之后,所述处理模块142保存所述第一内网设备的标识与所述第一附加功能的对应关系。
处理模块141从接收模块143接收的待转发流量中获取目标数据流,所述目标数据流 为待执行所述第一附加功能的数据流。处理模块142根据所述第一内网设备的标识与所述第一附加功能的对应关系,通过发送模块142向所述第一内网设备发送所述目标数据流,并通过接收模块143接收所述第一内网设备对所述目标数据流的处理结果。
处理模块141、发送模块142和接收模块143能够实现的附加功能、实现上述功能的更多细节请参考前面各个方法实施例中的描述,在这里不再重复。
附图14所描述的装置实施例仅仅是示意性的,例如,所述模块的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个模块或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。在本申请各个实施例中的各功能模块可以集成在一个处理模块中,也可以是各个模块单独物理存在,也可以两个或两个以上模块集成在一个模块中。附图14中上述各个模块既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。例如,采用软件实现时,处理模块141、发送模块142和接收模块143可以是由附图13中的处理器131读取存储器中存储的程序代码后,生成的软件功能模块来实现。图14中上述各个模块也可以由网关设备中的不同硬件分别实现,例如发送模块142和接收模块143由附图13中的网络接口133实现,而处理模块141由附图13中处理器133中的部分处理资源(例如多核处理器中的其他核),或者采用现场可编程门阵列(Field-Programmable Gate Array,FPGA)、或协处理器等可编程器件来完成。显然上述功能模块也可以采用软件硬件相结合的方式来实现,例如发送模块142和接收模块143由网络接口133实现,而处理模块141是由CPU读取存储器中存储的指令后生成的软件功能模块。
附图14中装置可以实现的其他附加功能、与其他网元设备(例如内网设备、或者服务器)的交互过程、以及能够实现的技术效果、以及识别模块141、获取模块142和发送模块143实现上述功能的更多细节请参考前面各个方法实施例中对于网关设备的描述,在这里不再赘述。
本申请实施例还提供了一种网络业务的处理系统,该处理系统包括网关设备和至少一个内网设备。网关设备用于连接外部网络和内部网络。所述至少一个内网设备属于所述内部网络。可选地,当软件包采用分布式存储方式时,该处理系统还包括服务器,服务器部署于内部网络或外部网络中。该处理系统中网关设备、内网设备和服务器实现各自功能的更多细节、以及相互之间的交互过程的更多细节请参考前面各个方法实施例中对于网关设备的描述,在这里不再赘述。
本说明书中的各个实施例均采用递进的方式描述,各个实施例之间相同相似的部分互相参见即可,每个实施例重点说明的都是与其他实施例的不同之处。尤其,对于系统实施例而言,由于其基本相似于方法实施例,所以描述的比较简单,相关之处参见方法实施例的部分说明即可。
本领域普通技术人员将会理解,当使用软件实现本申请实施例的各个方面、或各个方面的可能实现方式时,上述各个方面、或各个方面的可能实现方式可以全部或部分地以计算机程序产品的形式实现。计算机程序产品是指存储在计算机可读介质中的计算机可读指令。在计算机上加载和执行所述计算机指令时,全部或部分地产生按照本申请实施例所述的流程或功能。
计算机可读介质可以是计算机可读信号介质或者计算机可读存储介质。计算机可读存储介质包括但不限于电子、磁性、光学、电磁、红外或半导体系统、设备或者装置,或 者前述的任意适当组合。如计算机可读存储介质为随机存取存储器(Random Access Memory,RAM)、只读存储器(read only memory,ROM)、可擦除可编程只读存储器(Erasable Programmable Read Only Memory,EPROM)或便携式只读存储器(Compact Disc Read-Only Memory,CD-ROM)。
显然,本领域的技术人员可以对本发明进行各种改动和变型而不脱离本发明的范围。这样,倘若本申请的这些修改和变型属于本发明权利要求的范围之内,则本发明也意图包括这些改动和变型在内。

Claims (31)

  1. 一种网络业务的处理方法,其特征在于,包括:
    网关设备识别第一内网设备的类型,所述第一内网设备属于所述网关设备连接的内部网络;
    所述网关设备根据所述第一内网设备的类型,获得第一软件包,所述第一软件包用于实现第一附加功能;
    所述网关设备向所述第一内网设备发送第一指示消息和所述第一软件包,所述第一指示消息用于指示所述第一内网设备安装所述第一软件包并执行所述第一附加功能。
  2. 根据权利要求1所述的处理方法,其特征在于,所述网关设备根据所述第一内网设备的类型,获得第一软件包,包括:
    所述网关设备根据所述第一内网设备的类型,确定所述第一内网设备的性能,所述性能包括软件能力和硬件能力,所述软件能力包括是否支持安装软件包,所述硬件能力包括处理器性能值和/或存储空间大小;
    所述网关设备根据所述第一内网设备的性能,获取所述第一软件包,所述第一内网设备的性能符合所述第一软件包的安装性能要求。
  3. 根据权利要求2所述的处理方法,其特征在于,所述网关设备根据所述第一内网设备的性能,获取所述第一软件包,包括:
    所述网关设备根据所述第一内网设备的性能,在软件包与安装性能要求的对应关系中查找到所述第一软件包。
  4. 根据权利要求2所述的处理方法,其特征在于,所述网关设备根据所述第一内网设备的性能,获取所述第一软件包,包括:
    所述网关设备根据第一内网设备的性能,在软件包的标识与安装性能要求的对应关系中查找到所述第一软件包的标识;
    所述网关设备向服务器发送所述第一软件包的标识,并接收所述服务器根据所述第一软件包的标识返回的所述第一软件包。
  5. 根据权利要求2所述的处理方法,其特征在于,所述网关设备根据所述第一内网设备的性能,获取所述第一软件包,包括:
    所述网关设备向服务器发送所述第一内网设备的性能;
    所述网关设备接收所述服务器根据所述第一内外设备的性能返回的所述第一软件包。
  6. 根据权利要求1所述的处理方法,其特征在于,所述网关设备根据所述第一内网设备的类型,获得第一软件包,包括:
    所述网关设备向服务器发送所述第一内网设备的类型;
    所述网关设备接收所述服务器根据所述第一内外设备的类型返回的所述第一软件包。
  7. 根据权利要求2所述的处理方法,其特征在于,所述网关设备向所述第一内网设备发送第一指示消息和所述第一软件包之前,所述方法还包括:
    所述网关设备识别第二内网设备的类型,所述第二内网设备属于所述内部网络;
    所述网关设备根据所述第二内网设备的类型,确定所述第二内网设备的性能;
    所述网关设备根据第二内网设备的性能,在软件包与安装性能要求的对应关系中查找到所述第二软件包,所述第二内网设备的性能符合所述第二软件包的安装性能要求;
    如果所述第一软件包和所述第二软件包为同一软件包,则所述网关设备从所述第一内网设备和所述第二内网设备中选择出所述第一内网设备用以安装所述第一软件包。
  8. 根据权利要求7所述的处理方法,其特征在于,所述网关设备从所述第一内网设备和所述第二内网设备中选择出所述第一内网设备用以安装所述第一软件包,包括:
    所述网关设备根据所述第一内网设备的性能和所述第二内网设备的性能,按照预定的选择策略,从所述第一内网设备和所述第二内网设备中选择出所述第一内网设备用以安装所述第一软件包。
  9. 根据权利要求1-8任一所述的方法,其特征在于,所述网关设备向所述第一内网设备发送第一指示消息和所述第一软件包之后,所述方法还包括:
    所述网关设备保存所述第一内网设备的标识与所述第一附加功能的对应关系;
    所述网关设备获取目标数据流,所述目标数据流为待执行所述第一附加功能的数据流;
    所述网关设备根据所述第一内网设备的标识与所述第一附加功能的对应关系,向所述第一内网设备发送所述目标数据流,并接收所述第一内网设备对所述目标数据流的处理结果。
  10. 根据权利要求9所述的方法,其特征在于,所述接收所述第一内网设备对所述目标数据流的处理结果之后,还包括:
    所述网关设备根据所述处理结果,对所述目标数据流执行与所述处理结果对应的动作,所述动作包括转发、告警或者阻断。
  11. 根据权利要求1或2所述的方法,其特征在于,所述网关设备向所述第一内网设备发送第一指示消息和所述第一软件包之后,所述方法还包括:
    所述网关设备保存所述第一内网设备的标识与所述第一附加功能的对应关系;
    所述网关设备获取目标数据流,所述目标数据流为待执行所述第一附加功能的数据流;
    所述网关设备确定描述信息,所述描述信息用于描述所述目标数据流;
    所述网关设备根据所述第一内网设备的标识与所述第一附加功能的对应关系,向所述第一内网设备发送所述描述信息,并接收所述第一内网设备对所述描述信息的处理结果。
  12. 根据权利要求11所述的方法,其特征在于,所述接收所述第一内网设备对所述描述信息的处理结果之后,还包括:
    所述网关设备根据所述处理结果,对所述目标数据流执行与所述处理结果对应的动作,所述动作包括转发、告警或者阻断。
  13. 根据权利要求9-12所述的方法,其特征在于,所述第一附加功能为数据流安全检测功能,所述目标数据流为待检测的数据流。
  14. 根据权利要求9-12任一所述的方法,其特征在于,所述第一附加功能为网络缓存功能,所述目标数据流为承载待缓存内容的数据流。
  15. 根据权利要求9-12任一所述的方法,其特征在于,所述第一附加功能为安全沙箱功能,所述目标数据流为承载待检测文件内容的数据流。
  16. 根据权利要求1-15任一所述的方法,其特征在于,所述网关设备向所述第一内网设备发送第一指示消息和所述第一软件包之前,所述方法还包括:
    输出提示信息,所述提示信息中包括所述第一内网设备的标识与所述第一附加功能的 对应关系,所述提示信息用于提示所述第一内网设备具备执行所述第一附加功能的能力;
    接收输入的确认信息,所述确认信息用于表示允许所述第一内网设备执行所述第一附加功能。
  17. 根据权利要求1-16任一所述的方法,其特征在于,所述网关设备识别第一内网设备的类型,包括:
    所述网关设备截获所述第一内网设备发送的特征报文,所述特征报文中携带第一特征字段,所述第一特征字段的内容用于指示发送方的操作系统类型或者预定网站域名;
    所述网关设备在特征库中查询所述第一特征字段的内容对应的第一设备类型,所述特征库中保存所述第一特征字段的内容与所述第一设备类型的对应关系;
    所述网关设备确定所述第一内网设备的设备类型为所述第一设备类型。
  18. 根据权利要求1-16任一所述的方法,其特征在于,所述网关设备识别第一内网设备的类型,包括:
    所述网关设备获取所述第一内网设备的MAC地址;
    所述网关设备在设备信息库中查询所述第一内网设备的MAC地址对应的第一设备类型,所述设备信息库中保存所述第一内网设备的MAC地址与所述第一设备类型的对应关系;
    所述网关设备确定所述第一内网设备的设备类型为所述第一设备类型。
  19. 根据权利要求1-16任一所述的方法,其特征在于,所述网关设备识别第一内网设备的类型,包括:
    所述网关设备向所述第一内网设备发送探测报文;
    所述网关设备接收所述第一内网设备发送的对应所述探测报文的响应报文;
    所述网关设备根据所述响应报文获取第一识别指纹;
    所述网关设备在指纹库中查询所述第一识别指纹对应的第一设备类型,所述指纹库中保存所述第一识别指纹与所述第一设备类型的对应关系;
    所述网关设备确定所述第一内网设备的设备类型为所述第一设备类型。
  20. 一种网关设备,其特征在于,包括网络接口、存储器和与所述存储器连接的处理器,
    所述存储器用于存储指令;
    所述处理器用于执行所述指令,以使所述网关设备执行以下操作:
    识别第一内网设备的类型,所述第一内网设备属于所述网关设备连接的内部网络;
    根据所述第一内网设备的类型,获得第一软件包,所述第一软件包用于实现第一附加功能;
    通过所述网络接口向所述第一内网设备发送第一指示消息和所述第一软件包,所述第一指示消息用于指示所述第一内网设备安装所述第一软件包并执行所述第一附加功能。
  21. 根据权利要求20所述的网关设备,其特征在于,
    所述处理器,用于根据所述第一内网设备的类型,确定所述第一内网设备的性能,所述性能包括软件能力和硬件能力,所述软件能力包括是否支持安装软件包,所述硬件能力包括处理器性能值和/或存储空间大小;根据所述第一内网设备的性能,获取所述第一软件包,所述第一内网设备的性能符合所述第一软件包的安装性能要求。
  22. 根据权利要求21所述的网关设备,其特征在于,
    所述处理器根据第一内网设备的性能,在软件包的标识与安装性能要求的对应关系中 查找到所述第一软件包的标识;
    通过所述网络接口向服务器发送所述第一软件包的标识,并通过所述网络接口接收所述服务器根据所述第一软件包的标识返回的所述第一软件包。
  23. 根据权利要求21所述的网关设备,其特征在于,
    所述处理器通过所述网络接口向服务器发送所述第一内网设备的性能,并通过所述网络接口接收所述服务器根据所述第一内外设备的性能返回的所述第一软件包。
  24. 根据权利要求20所述的网关设备,其特征在于,
    所述处理器通过所述网络接口向服务器发送所述第一内网设备的类型,并通过所述网络接口接收所述服务器根据所述第一内外设备的类型返回的所述第一软件包。
  25. 根据权利要求21所述的网关设备,其特征在于,通过所述网络接口向所述第一内网设备发送第一指示消息和所述第一软件包之前,
    所述处理器还用于识别第二内网设备的类型,所述第二内网设备属于所述内部网络;根据所述第二内网设备的类型,确定所述第二内网设备的性能;根据第二内网设备的性能,在软件包与安装性能要求的对应关系中查找到所述第二软件包,所述第二内网设备的性能符合所述第二软件包的安装性能要求;如果所述第一软件包和所述第二软件包为同一软件包,则从所述第一内网设备和所述第二内网设备中选择出所述第一内网设备用以安装所述第一软件包。
  26. 根据权利要求20-25任一所述的网关设备,其特征在于,通过网络接口向所述第一内网设备发送第一指示消息和所述第一软件包之后,
    所述处理器还用于保存所述第一内网设备的标识与所述第一附加功能的对应关系;
    获取目标数据流,所述目标数据流为待执行所述第一附加功能的数据流;
    根据所述第一内网设备的标识与所述第一附加功能的对应关系,通过所述网络接口向所述第一内网设备发送所述目标数据流,并通过所述网络接口接收所述第一内网设备对所述目标数据流的处理结果。
  27. 根据权利要求26所述的网关设备,其特征在于,
    所述处理器还用于根据所述处理结果,对所述目标数据流执行与所述处理结果对应的动作,所述动作包括转发、告警或者阻断。
  28. 根据权利要求20-25任一所述的网关设备,其特征在于,通过网络接口向所述第一内网设备发送第一指示消息和所述第一软件包之后,
    所述处理器还用于保存所述第一内网设备的标识与所述第一附加功能的对应关系;获取目标数据流,所述目标数据流为待执行所述第一附加功能的数据流;
    确定描述信息,所述描述信息用于描述所述目标数据流;
    根据所述第一内网设备的标识与所述第一附加功能的对应关系,通过所述网络接口向所述第一内网设备发送所述描述信息,并通过所述网络接口接收所述第一内网设备对所述描述信息的处理结果。
  29. 根据权利要求28所述的网关设备,其特征在于,
    所述处理器,还用于根据所述处理结果,对所述目标数据流执行与所述处理结果对应的动作,所述动作包括转发、告警或者阻断。
  30. 一种网络业务的处理装置,其特征在于,所述处理装置与网关设备连接,包括:
    处理模块,用于识别第一内网设备的类型,所述第一内网设备属于所述网关设备连接 的内部网络;根据所述第一内网设备的类型,获得第一软件包,所述第一软件包用于实现第一附加功能;
    发送模块,用于向所述第一内网设备发送第一指示消息和所述第一软件包,所述第一指示消息用于指示所述第一内网设备安装所述第一软件包并执行所述第一附加功能。
  31. 一种网络业务的处理系统,其特征在于,包括:
    网关设备和第一内网设备,所述第一内网设备属于所述网关设备连接的内部网络;
    所述网关设备,用于执行如权利要求1-19任一所述的方法;
    所述第一内网设备,用于接收所述网关设备发送的所述第一指示消息和所述第一软件包,根据所述第一指示消息安装所述第一软件包后执行所述第一附加功能。
PCT/CN2020/121251 2019-11-11 2020-10-15 网络业务的处理方法、系统和网关设备 WO2021093510A1 (zh)

Priority Applications (6)

Application Number Priority Date Filing Date Title
CA3157038A CA3157038A1 (en) 2019-11-11 2020-10-15 Network service processing method, system, and gateway device
EP20888021.1A EP4047885A4 (en) 2019-11-11 2020-10-15 METHOD AND SYSTEM FOR PROCESSING A NETWORK SERVICE AND GATEWAY
MX2022005625A MX2022005625A (es) 2019-11-11 2020-10-15 Metodo de procesamiento de servicio de red, sistema y dispositivo de puerta de enlace.
JP2022526740A JP7383145B2 (ja) 2019-11-11 2020-10-15 ネットワークサービス処理方法、システム及びゲートウェイデバイス
US17/742,341 US11843518B2 (en) 2019-11-11 2022-05-11 Network service processing method, system, and gateway device
US18/511,806 US20240089178A1 (en) 2019-11-11 2023-11-16 Network service processing method, system, and gateway device

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
CN201911097192.1 2019-11-11
CN201911097192 2019-11-11
CN201911134443.9A CN112787947B (zh) 2019-11-11 2019-11-19 网络业务的处理方法、系统和网关设备
CN201911134443.9 2019-11-19

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US17/742,341 Continuation US11843518B2 (en) 2019-11-11 2022-05-11 Network service processing method, system, and gateway device

Publications (1)

Publication Number Publication Date
WO2021093510A1 true WO2021093510A1 (zh) 2021-05-20

Family

ID=75749939

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2020/121251 WO2021093510A1 (zh) 2019-11-11 2020-10-15 网络业务的处理方法、系统和网关设备

Country Status (7)

Country Link
US (2) US11843518B2 (zh)
EP (1) EP4047885A4 (zh)
JP (1) JP7383145B2 (zh)
CN (3) CN116032762A (zh)
CA (1) CA3157038A1 (zh)
MX (1) MX2022005625A (zh)
WO (1) WO2021093510A1 (zh)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114760279A (zh) * 2022-03-10 2022-07-15 深圳市联洲国际技术有限公司 识别设备类型的方法、服务端与计算机可读存储介质

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101141360A (zh) * 2007-09-14 2008-03-12 四川长虹电器股份有限公司 家庭网络中设备管理和控制的方法
CN101340497A (zh) * 2008-08-11 2009-01-07 中兴通讯股份有限公司 一种降低VoIP媒体网关设备功耗的方法及装置
CN101931592A (zh) * 2010-08-26 2010-12-29 北京科技大学 一种基于wsn的矿下安全监控系统网关设备
WO2016169218A1 (zh) * 2015-04-22 2016-10-27 中兴通讯股份有限公司 一种网关虚拟化方法、系统及计算机存储介质
CN108377222A (zh) * 2018-01-15 2018-08-07 顺丰科技有限公司 基于软件的负载均衡实现方法、装置、设备及存储介质

Family Cites Families (21)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2001222500A (ja) * 1999-12-01 2001-08-17 Sharp Corp ネットワークゲートウェイにおけるプログラムの配布方法
KR100541942B1 (ko) * 2003-08-11 2006-01-10 삼성전자주식회사 홈네트워크의 홈디바이스원격관리장치 및 그 방법
CN103135999A (zh) * 2011-11-24 2013-06-05 成绵广 软件加载方法
CN102638460B (zh) * 2012-03-26 2016-08-10 华为终端有限公司 家庭网关、云服务器及两者之间进行通信的方法
CN102938718B (zh) * 2012-10-19 2016-03-30 中兴通讯股份有限公司 一种家庭网关与智能终端综合系统及其通信方法
CN103650424B (zh) * 2013-08-20 2018-02-02 华为技术有限公司 一种家庭网关服务功能的实现方法和服务器
JP2015090570A (ja) * 2013-11-06 2015-05-11 ソニー株式会社 情報処理装置および制御方法
CN103677899B (zh) * 2013-11-15 2017-08-01 小米科技有限责任公司 安装应用程序的方法及设备
CN103944815A (zh) * 2014-04-29 2014-07-23 中国联合网络通信集团有限公司 基于容量卡实现家庭网关的方法、装置及路由器
US10122660B2 (en) * 2015-03-27 2018-11-06 MINDBODY, Inc. Contextual mobile communication platform
CN104821911B (zh) * 2015-05-04 2018-10-02 南京邮电大学 基于网络功能虚拟化的家庭网关系统
WO2017075781A1 (zh) * 2015-11-05 2017-05-11 华为技术有限公司 一种数据报文的处理方法、装置及系统
CN105577496B (zh) 2016-03-03 2018-06-15 烽火通信科技股份有限公司 一种家庭网关利用云平台识别接入设备类型的系统
CN106897058A (zh) * 2017-01-24 2017-06-27 北京奇虎科技有限公司 业务对象安装包的融合方法与装置
CN107347025A (zh) * 2017-06-14 2017-11-14 云丁网络技术(北京)有限公司 数据处理方法、装置、服务器及系统
US20190090158A1 (en) * 2017-09-20 2019-03-21 Qualcomm Incorporated Enhanced network-assisted services
US10938663B2 (en) * 2018-05-07 2021-03-02 Servicenow, Inc. Discovery and management of devices
CN109302461B (zh) * 2018-09-13 2021-08-31 网易有道信息技术(杭州)有限公司 信息展示、处理方法、介质、系统和计算设备
US20210044579A1 (en) * 2018-12-04 2021-02-11 Viakoo, Inc. Systems and Methods of Remotely Updating a Multitude of IP Connected Devices
CN110099074B (zh) 2019-05-28 2021-06-29 创新先进技术有限公司 一种物联网设备的异常检测方法、系统及电子设备
US11432167B2 (en) * 2020-01-22 2022-08-30 Abl Ip Holding Llc Selective updating of nodes of a nodal wireless network

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101141360A (zh) * 2007-09-14 2008-03-12 四川长虹电器股份有限公司 家庭网络中设备管理和控制的方法
CN101340497A (zh) * 2008-08-11 2009-01-07 中兴通讯股份有限公司 一种降低VoIP媒体网关设备功耗的方法及装置
CN101931592A (zh) * 2010-08-26 2010-12-29 北京科技大学 一种基于wsn的矿下安全监控系统网关设备
WO2016169218A1 (zh) * 2015-04-22 2016-10-27 中兴通讯股份有限公司 一种网关虚拟化方法、系统及计算机存储介质
CN108377222A (zh) * 2018-01-15 2018-08-07 顺丰科技有限公司 基于软件的负载均衡实现方法、装置、设备及存储介质

Also Published As

Publication number Publication date
CN112787947A (zh) 2021-05-11
EP4047885A4 (en) 2022-11-16
US20220272003A1 (en) 2022-08-25
MX2022005625A (es) 2022-06-14
CN112787947B (zh) 2022-12-13
JP2023500958A (ja) 2023-01-11
CN116032763A (zh) 2023-04-28
CN116032762A (zh) 2023-04-28
US11843518B2 (en) 2023-12-12
CA3157038A1 (en) 2021-05-20
JP7383145B2 (ja) 2023-11-17
EP4047885A1 (en) 2022-08-24
US20240089178A1 (en) 2024-03-14

Similar Documents

Publication Publication Date Title
US10616077B2 (en) System architecture and methods for controlling and managing networking devices and expediting new service delivery in a subscriber's home network using micro-domains
CN108616490B (zh) 一种网络访问控制方法、装置及系统
CN110311929B (zh) 一种访问控制方法、装置及电子设备和存储介质
US11336696B2 (en) Control access to domains, servers, and content
RU2562438C2 (ru) Сетевая система и способ управления сетью
WO2018028606A1 (zh) 转发策略配置
US10701582B2 (en) Dynamic application QoS profile provisioning
US20150156079A1 (en) Methods and Apparatus to Dynamically Provide Network Policies
WO2018137384A1 (zh) 一种调整转发路径的方法、装置及系统
WO2011032321A1 (zh) 一种数据转发方法、数据处理方法、系统以及相关设备
EP2814217B1 (en) Access control method for wifi device and wifi device thereof
KR20190029486A (ko) 탄력적 허니넷 시스템 및 그 동작 방법
US20240089178A1 (en) Network service processing method, system, and gateway device
WO2022214019A1 (zh) 一种部署网络设备的方法、装置、设备、系统及存储介质
US11533335B2 (en) Fast internetwork reconnaissance engine
US10657093B2 (en) Managing actions of a network device based on policy settings corresponding to a removable wireless communication device
JP6044020B2 (ja) データパケット処理の方法、システム、およびデバイス
US9467932B2 (en) Access control method for WiFi device and WiFi device
KR20210016802A (ko) 소프트웨어 정의 네트워킹 환경에서 서버-클라이언트 기반의 네트워크 서비스를 위한 플로우 테이블을 최적화하는 방법 및 이를 위한 sdn 스위치
WO2013159591A1 (zh) 一种区分无线终端的方法及装置
JP2013126219A (ja) 転送サーバおよび転送プログラム
JP5622088B2 (ja) 認証システム、認証方法
Frank et al. Securing smart homes with openflow
WO2012155584A1 (zh) 一种网元设备鉴权管理的方法及系统
JP4638513B2 (ja) 通信制御装置及び通信制御方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 20888021

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 3157038

Country of ref document: CA

ENP Entry into the national phase

Ref document number: 2022526740

Country of ref document: JP

Kind code of ref document: A

ENP Entry into the national phase

Ref document number: 2020888021

Country of ref document: EP

Effective date: 20220520

NENP Non-entry into the national phase

Ref country code: DE