FIELD: computing systems.
SUBSTANCE: systems for analyzing data networks, namely methods for balancing while maintaining the integrity of data flows, taking into account the membership of TCP/UDP protocol sessions. The technical result is achieved by proposing a balancing method while preserving the integrity of data streams, in which the fields of packets are allocated in the form of a bit vector - descriptor, the body of the packet is stored in SRAM memory for the duration of processing, then a 5-tuple session hash is constructed from the generated vector of packet headers, which is supplied as an address to the DDR memory of the session store. The data received from memory is the saved session parameters, if it is noted that the session has already been encountered, then the output used the previous time is reused, and if the output interface for the session in the parameters received from the DDR memory of the session store is not defined or the session timeout has passed - a new output for the session is determined. At the same time, session parameters are recorded/updated in the DDR session storage. The output of the balancing table is the number of the output interface for the session, on which the packet body is retrieved from the packet buffer and issued to the selected output interface.
EFFECT: ensuring the functioning of traffic pre-processing devices with packet balancing without breaking sessions when balancing parameters change.
2 cl, 4 dwg
Title | Year | Author | Number |
---|---|---|---|
A WAY TO TRACK FRAGMENTS OF PACKETS IN NETWORK TRAFFIC | 2022 |
|
RU2778462C1 |
METHOD FOR ENSURING BALANCING IDENTITY FOR BIDIRECTIONAL NETWORK SESSION DATA FLOW | 2022 |
|
RU2786629C1 |
METHOD FOR TRACKING SESSIONS IN NETWORK TRAFFIC | 2022 |
|
RU2786178C1 |
METHOD FOR DYNAMIC FILTERING OF NETWORK PACKETS BY SESSIONS | 2022 |
|
RU2779135C1 |
METHOD FOR FILTERING A PART OF PACKETS IN A NETWORK SESSION | 2022 |
|
RU2790635C1 |
METHOD FOR DETECTING DUPLICATE PACKETS IN A NETWORK TRAFFIC FLOW | 2022 |
|
RU2790636C1 |
METHOD FOR FILTERING NETWORK TRAFFIC BASED ON RULES WITH A MASK DURING PACKET SWITCHING | 2022 |
|
RU2795295C1 |
METHOD FOR SECURITY GATEWAY CLUSTER OPERATION | 2021 |
|
RU2757297C1 |
METHOD OF MANAGING CONNECTIONS IN FIREWALL | 2012 |
|
RU2517411C1 |
METHOD OF OPERATING A FIREWALL | 2017 |
|
RU2667805C1 |
Authors
Dates
2023-11-21—Published
2023-08-31—Filed