CN101521630B - Analysis method and equipment of network flow - Google Patents

Analysis method and equipment of network flow Download PDF

Info

Publication number
CN101521630B
CN101521630B CN2009101312194A CN200910131219A CN101521630B CN 101521630 B CN101521630 B CN 101521630B CN 2009101312194 A CN2009101312194 A CN 2009101312194A CN 200910131219 A CN200910131219 A CN 200910131219A CN 101521630 B CN101521630 B CN 101521630B
Authority
CN
China
Prior art keywords
message
sample rate
flow
module
network traffics
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN2009101312194A
Other languages
Chinese (zh)
Other versions
CN101521630A (en
Inventor
汪洪远
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
New H3C Technologies Co Ltd
Original Assignee
Hangzhou H3C Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hangzhou H3C Technologies Co Ltd filed Critical Hangzhou H3C Technologies Co Ltd
Priority to CN2009101312194A priority Critical patent/CN101521630B/en
Publication of CN101521630A publication Critical patent/CN101521630A/en
Application granted granted Critical
Publication of CN101521630B publication Critical patent/CN101521630B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention discloses an analysis method and equipment of network flow. The method is applied to network flow output equipment and comprises the steps of sampling and sending flow to be analyzed according to a set sampling rate, analyzing the sampled flow and reverting the analyzed result according to the set sampling rate. The invention selectively samples the flow to be analyzed according to the set sampling rate and reverts the analyzed result according to the set sampling rate, thereby effectively enhancing the data stream analyzing performance of the network equipment through improving the network traffic collecting mode.

Description

A kind of analytical method of network traffics and equipment
Technical field
The present invention relates to communication field, relate in particular to a kind of analytical method and equipment of network traffics.
Background technology
Along with the continuous evolution of network technology, the explosivity development of scale; Internet, applications has extended to the every aspect of contemporary society's life gradually from scientific research field originally; More and more based on network key businesses are surging forward, and network becomes the new motive force that the mankind increased productivity, promoted quality of life.
Simultaneously; Continuous development along with network technology; Data traffic in the network also constantly increases, and provides network management services easily also to become one of direction that network equipment provider greatly develops thereupon, and NetStream (network traffics analysis) technology is a kind of statistics and distribution technology of stream information Network Based; It can add up and issue the traffic in the network and resource operating position, to the network management personnel accessing communication amount details is provided.
NetStream has defined a kind of method of adding up the network traffics data of router/switch output; The data flow creation of value in the network capable of using, and can under the prerequisite that reduces to greatest extent router/switch performance influence, detailed data stream statistics information be provided.As shown in Figure 1; A typical case of existing NetStream technology realizes that framework comprises: NTE (NetTraffic Exporter; The network traffics output equipment), NTC (NetTraffic Collector; The network traffics collecting device) and NTP (NetTraffic Processor, network traffics analytical equipment).Wherein, NTE is responsible for the collection and the transmission of flow, is used for the IP packet through router/switch is gathered and added up, and the packet of gathering and statistics are sent to NTC with the form of NetStream daily record.NTC is responsible for collecting and store packet and the statistical information that NTE sends, and offers NTP.After packet that NTP collects NTC and statistical information are analyzed processing, be that the network planning, the network optimization, network monitoring, traffic trends analysis, abnormality detection etc. provide direct data foundation with mode such as chart, form intuitively.
Wherein, NTE can further be divided into two parts again, and a part is pure exchange route function module, is responsible for the forwarding of data traffic; Another part is NSM (NetStream Module, the module of a support NetStream function) functional module, is responsible for flow is carried out the traffic classification statistics and statistics is sent to NTC.
As shown in Figure 2, be the structural representation of NTE equipment in the prior art, wherein, the exchange route function module of NTE equipment has image feature, and the data flow replication that needs are analyzed is a to the NSM functional module; The NSM functional module receives the data flow of sending from the exchange route function module; According to certain characteristic data stream is carried out analytic statistics; And be assembled into the NetStream daily record, be sent to NTC with UDP (User Datagram Protocol, UDP) message format.
The problem that exists in the prior art is; In the exchange route function module of a NTE, there is the data flow of a plurality of image source ports need be sent under the situation that the NSM functional module analyzes; The flow of event data stream is bigger; Then receive the restriction of port bandwidth, can't be sent to the NSM functional module to the message of all image sources and handle.In this case, have only the data flow that needs analysis through further increase NSM functional module quantity or minimizing, can guarantee that just flow to be analyzed can arrive the NSM functional module.
Summary of the invention
The present invention provides a kind of analytical method and equipment of network traffics, is used under the bigger situation of the flow of data flow, and the acquisition mode through improving network traffics is to promote the data-flow analysis performance of the network equipment.
The invention provides a kind of analytical method of network traffics, be applied to the network traffics output equipment, comprising:
The exchange route function module of NTE is sampled flow to be analyzed according to the sample rate that is provided with and is sent to the module NSM of the network enabled flow analysis function of NTE;
NSM analyzes said sampling flow, and according to the sample rate of said setting said analysis result is reduced.
Wherein, said flow to be analyzed sampled and send according to the sample rate that is provided with before, also comprise:
The employed sample rate of sampling is held consultation, and sample rate is set according to said negotiation result.
Wherein, said sample rate according to setting is sampled flow to be analyzed and send and comprises:
According to the sample rate that is provided with, select message to identify according to said sample rate to the message in the flow to be analyzed; When sample rate is N, from the message of the said flow to be analyzed of N, select a message to identify;
The message of said sign is duplicated the back transmission, as sampling flow.
Wherein, send after said message with said sign duplicates and comprise:
The message of said sign is duplicated directly transmission of back; Or
After the message of said sign duplicated, ACL discerned through access control lists, and the message after the identification is sent through central processing unit CPU; Or
After the message of said sign duplicated, send through the loopback port of equipment.
Wherein, said said sampling flow is analyzed, and according to the sample rate of said setting said analysis result is reduced and to comprise:
Said sampling flow is analyzed, obtained the packet counting statistical information;
According to the sample rate of said setting, said packet counting statistical information is reduced according to said sample rate; When the packet counting statistical information is M, when sample rate is N, said packet counting statistical information is reduced to N * M.
The present invention also provides a kind of network traffics output equipment, comprises exchange routing module and network traffics analysis module, wherein:
The exchange route function module that said exchange routing module is NTE is used for flow to be analyzed is sampled and sending to said network traffics analysis module according to the sample rate that is provided with;
Said network traffics analysis module is the NSM of NTE, is used for the sampling flow that said exchange routing module sends is analyzed, and according to the sample rate of said setting said analysis result is reduced.
Wherein, said network traffics analysis module comprises that first sampling consults submodule, is used for sending agreement request to said exchange routing module, and replys according to the negotiation that said exchange routing module sends the employed sample rate of sampling is set;
Said exchange routing module comprises the second sampling negotiation submodule, is used to receive the agreement request that said network traffics analysis module sends, and sends the negotiation of carrying the employed sample rate of sampling and reply.
Wherein, said exchange routing module also comprises:
The message identification submodule is used for according to the sample rate that is provided with, and selects message to identify the message in the flow to be analyzed according to said sample rate; When sample rate is N, from the message of the said flow to be analyzed of N, select a message to identify;
Message duplicates the transmission submodule, is used for the message of said message identification submodule sign is duplicated the back to said network traffics analysis module transmission, as sampling flow.
Wherein, said message duplicates and sends submodule and specifically be used for:
Directly send after the message of said message identification submodule sign duplicated to said network traffics analysis module; Or
After the message of said message identification submodule sign duplicated, ACL discerned through access control lists, and the message after the identification is sent to said network traffics analysis module through central processing unit CPU; Or
After the message of said message identification submodule sign duplicated, send to said network traffics analysis module through the loopback port of equipment.
Wherein, said network traffics analysis module also comprises:
Analysis result obtains submodule, is used for said sampling flow is analyzed, and obtains the packet counting statistical information;
Analysis result reduction submodule is used for the sample rate according to said setting, said analysis result is obtained the packet counting statistical information that submodule obtains reduce according to said sample rate; When the packet counting statistical information is M, when sample rate is N, said packet counting statistical information is reduced to N * M.
Compared with prior art, the present invention has the following advantages:
Sample rate is set among the present invention flow to be analyzed is selectively sampled, and analysis result is reduced according to the sample rate that is provided with, thereby effectively promoted the data-flow analysis performance of the network equipment through the acquisition mode that improves network traffics.
Description of drawings
In order to be illustrated more clearly in the embodiment of the invention or technical scheme of the prior art; To do to introduce simply to the accompanying drawing of required use in embodiment or the description of the Prior Art below; Obviously, the accompanying drawing in describing below only is some embodiments of the present invention, for those of ordinary skills; Under the prerequisite of not paying creative work property, can also obtain other accompanying drawing according to these accompanying drawings.
Fig. 1 is that a typical case of NetStream technology realizes configuration diagram in the prior art;
Fig. 2 is the structural representation of NTE equipment in the prior art;
Fig. 3 is the flow chart of the analytical method of network traffics among the present invention;
Fig. 4 is the flow chart of the analytical method of network traffics in the application scenarios of the present invention;
Fig. 5 is the structural representation of network traffics output equipment among the present invention;
Fig. 6 is another structural representation of network traffics output equipment among the present invention.
Embodiment
To combine the accompanying drawing in the embodiment of the invention below, the technical scheme in the embodiment of the invention is carried out clear, intactly description, obviously, described embodiment only is the present invention's part embodiment, rather than whole embodiment.Based on the embodiment among the present invention, those of ordinary skills are not making the every other embodiment that is obtained under the creative work prerequisite, all belong to the scope of the present invention's protection.
The invention provides a kind of analytical method of network traffics, be applied to the network traffics output equipment, as shown in Figure 3, comprising:
Step s301, flow to be analyzed is sampled and send according to the sample rate that is provided with.
Step s302, sampling flow is analyzed, and analysis result is reduced according to the sample rate that is provided with.
The method that the application of the invention provides; Sample rate is set selectively samples to flow to be analyzed; And analysis result reduced according to the sample rate that is provided with, thereby effectively promoted the data-flow analysis performance of the network equipment through the acquisition mode that improves network traffics.
Below in conjunction with a concrete application scenarios embodiment of network flow analysis method among the present invention is described.This method is applied to can be known by present NTE structure among the network traffics output equipment NTE that NTE is made up of exchange route function module and NSM functional module two parts.Among the present invention through sample rate is set; Make the exchange route function module be sent to the NSM module to the flow of needs analysis according to sample rate; The NSM module becomes original data to the counting messages information reverting according to the sample rate that is provided with in advance, and is sent to NTC after analyzing according to the flow that receives.
Concrete, as shown in Figure 4, should comprise with the network flow analysis method in the scene:
Step s401, NSM module are sent agreement request to the exchange route function module.
Concrete; Among the present invention; Can between exchange route function module and NSM module, define a kind of simple interaction protocol; Send agreement request to the exchange route function module behind the NSM module connecting system, consult the sample rate that the exchange route function module is adopted when flow to be analyzed is sampled.The NSM module need be known this sample rate equally, after analyzing at the sampling flow that the exchange route function module is sent, according to the sample rate that is provided with analysis result is reduced.
In of the present invention one concrete the realization, the form that the form of protocol massages can be as shown in table 1 below:
Table 1, be used to consult the message format of sample rate
DMAC SMAC Protocol Type Rate
When using the message of structure as shown in table 1, for the message of negotiation request that the NSM module is sent to the exchange route function module, the purpose MAC in the message (DMAC) fixes the address, for the agreement agreed address (like 01-0F-E2-00-00-99.For target MAC (Media Access Control) address is the message of agreed address, when source MAC is the MAC of NSM module, this message is forwarded to the exchange route function module; When source MAC is the MAC Address of exchange route function module, this message is forwarded to the NSM module); Source MAC (SMAC) address is the MAC Address (for the negotiation response message that the exchange route function module is sent to the NSM module, source MAC is the MAC Address of exchange route function module) of NSM module; Protocol type Protocol is self-defined (like 0x8809); Type has two kinds: a kind of is agreement request (0x01); Another kind of for consulting to reply (0x02), for the agreement request that the NSM module is sent to the exchange route function module, its Type is 0x01; Negotiation for the exchange route function module is sent to the NSM module is replied, and its Type is 0x02; Rate is the sampling ratio, and the NSM module is in the agreement request that the exchange route function module is sent, and the value of Rate can default to 1.
Step s402, exchange route function module are sent to the NSM module and are consulted to reply, and the NSM module obtains sample rate.
Concrete, after the exchange route function module is received this agreement request, to send and consult to reply, when using the message of structure as shown in table 1, Type is 0x02, Rate is the pre-configured sample rate of user.If the user does not have pre-configured sample rate, then the exchange route function module can not handled this agreement request and directly abandons, and the NSM module does not receive negotiation that the exchange route function module sends when replying in the preset stand-by period, adopt default sample rate.The exchange route function module also can be in the negotiation of sending to the NSM module be replied, and the value of carrying Rate is 1.
Step s403, exchange route function module identify the message in the flow to be analyzed according to the sample rate of consulting.
Concrete, the exchange route function module selects message to identify the message in the flow to be analyzed according to sample rate according to the sample rate of consulting.When for example sample rate is N (N=1,2,3...),, from every N message, select 1 message to identify for the message in the flow to be analyzed.
Step s404, exchange route function module are duplicated the message of sign, and the message after duplicating is sent to the NSM module.
Concrete, can adopt following send mode: the message after (1) will duplicate directly sends to the NSM module; Or (2) can not be directly with the message after duplicating when the NSM module is sent; With the message after duplicating; Through ACL (Access Control List; Access control lists) is redirected, the message after the identification is sent to the NSM module through CPU (Central Processing Unit, CPU); Or (3) can not be directly with the message after duplicating when the NSM module is sent, the message that duplicates is sent to the loopback port (can dispose loopback by user port forms) of equipment, be forwarded to the NSM module again after getting into by the loopback port.
Step s405, NSM module are analyzed the sampling flow that receives, and obtain the packet counting statistical information.
Concrete, the NSM module is analyzed the message in the sampling flow that receives according to the packet counting statistical method that is provided with in advance one by one, obtains the packet counting statistical information.
Step s406, NSM module be according to the sample rate that is provided with, to the packet counting statistical information according to reducing.
Concrete, when sample rate is N (N=1,2,3...),, reduce according to sample rate for the data such as packet counting in the packet counting statistical information.For example, when the DHCP message amount in the packet counting statistical information is M, the DHCP message amount is reduced to N*M.Afterwards, the NSM module is sent the packet counting statistical information to NTC.
Need to prove in addition,, can also preestablish fixing sample rate at exchange routing module and NSM module except using above-mentioned method through message interaction negotiation sample rate; Also can be through more existing agreements are replenished; As at SNMP (Simple Network Management Protocol; Simple Network Management Protocol) increases relevant MIB (Management Information Base in the agreement; Management information bank) item is accomplished the sample rate of exchange routing module and NSM module and is consulted.
In the said method provided by the invention; Sample rate is set selectively samples to flow to be analyzed; And analysis result reduced according to the sample rate that is provided with, thereby effectively promoted the data-flow analysis performance of the network equipment through the acquisition mode that improves network traffics.
The present invention also provides a kind of network traffics output equipment, and is as shown in Figure 5, comprises exchange routing module 10 and network traffics analysis module 20:
Exchange routing module 10 is used for flow to be analyzed is sampled and sending to network traffics analysis module 20 according to the sample rate that is provided with;
Network traffics analysis module 20 is used for the sampling flow that exchange routing module 10 sends is analyzed, and according to the sample rate that is provided with analysis result is reduced.
In the network traffics output equipment provided by the invention, as shown in Figure 6, concrete:
Exchange routing module 10 may further include:
Submodule 11 is consulted in second sampling, is used to receive the agreement request that network traffics analysis module 20 sends, and sends the negotiation of carrying the employed sample rate of sampling and reply.
Message identification submodule 12 is used for according to the sample rate that is provided with, and selects message to identify the message in the flow to be analyzed according to sample rate; When sample rate is N, from the message of the said flow to be analyzed of N, select a message to identify;
Message duplicates and sends submodule 13, is used for the message of message identification submodule 12 signs is duplicated the back to 20 transmissions of network traffics analysis module, as sampling flow.Specifically be used for: directly send after the message of message identification submodule 12 sign is duplicated to network traffics analysis module 20; Or after the message of message identification submodule 12 sign duplicated, ACL discerned through access control lists, and the message after the identification is sent to network traffics analysis module 20 through central processing unit CPU; Or after the message of message identification submodule 12 sign duplicated, send to network traffics analysis module 20 through the loopback port of equipment.
Network traffics analysis module 20 may further include:
Submodule 21 is consulted in first sampling, is used for sending agreement request to exchange routing module 10, and replys according to the negotiation that exchange routing module 10 sends the employed sample rate of sampling is set;
Analysis result obtains submodule 22, is used for sampling flow is analyzed, and obtains the packet counting statistical information;
Analysis result reduction submodule 23 is used for according to the sample rate that is provided with, and analysis result is obtained the packet counting statistical information that submodule 22 obtains reduce according to sample rate; When the packet counting statistical information is M, when sample rate is N, said packet counting statistical information is reduced to N * M.
In the said equipment provided by the invention; Sample rate is set selectively samples to flow to be analyzed; And analysis result reduced according to the sample rate that is provided with, thereby effectively promoted the data-flow analysis performance of the network equipment through the acquisition mode that improves network traffics.
Through the description of above execution mode, those skilled in the art can be well understood to the present invention and can realize through hardware, also can realize by the mode that software adds necessary general hardware platform.Based on such understanding; Technical scheme of the present invention can be come out with the embodied of software product, this software product can be stored in a non-volatile memory medium (can be CD-ROM, USB flash disk; Portable hard drive etc.) in; Comprise some instructions with so that computer equipment (can be personal computer, server, the perhaps network equipment etc.) carry out the described method of each embodiment of the present invention.
It will be appreciated by those skilled in the art that accompanying drawing is the sketch map of a preferred embodiment, unit in the accompanying drawing or flow process might not be that embodiment of the present invention is necessary.
It will be appreciated by those skilled in the art that the unit in the device among the embodiment can be distributed in the device of embodiment according to the embodiment description, also can carry out respective change and be arranged in the one or more devices that are different from present embodiment.A unit can be merged in the unit of the foregoing description, also can further split into a plurality of subelements.
The invention described above embodiment sequence number is not represented the quality of embodiment just to description.

Claims (10)

1. the analytical method of network traffics is applied to network traffics output equipment NTE, it is characterized in that, comprising:
The exchange route function module of NTE is sampled flow to be analyzed according to the sample rate that is provided with and is sent to the module NSM of the network enabled flow analysis function of NTE;
NSM analyzes said sampling flow, and according to the sample rate of said setting said analysis result is reduced.
2. the method for claim 1 is characterized in that, said flow to be analyzed sampled and send according to the sample rate that is provided with before, also comprise:
The employed sample rate of sampling is held consultation, and sample rate is set according to said negotiation result.
3. the method for claim 1 is characterized in that, said sample rate according to setting is sampled flow to be analyzed and send and comprises:
According to the sample rate that is provided with, select message to identify according to said sample rate to the message in the flow to be analyzed; When sample rate is N, from the message of the said flow to be analyzed of N, select a message to identify;
The message of said sign is duplicated the back transmission, as sampling flow.
4. method as claimed in claim 3 is characterized in that, said message with said sign duplicates the back transmission and comprises:
The message of said sign is duplicated directly transmission of back; Or
After the message of said sign duplicated, ACL discerned through access control lists, and the message after the identification is sent through central processing unit CPU; Or
After the message of said sign duplicated, send through the loopback port of equipment.
5. the method for claim 1 is characterized in that, said said sampling flow is analyzed, and according to the sample rate of said setting said analysis result is reduced and to comprise:
Said sampling flow is analyzed, obtained the packet counting statistical information;
According to the sample rate of said setting, said packet counting statistical information is reduced according to said sample rate: when the packet counting statistical information is M, when sample rate is N, said packet counting statistical information is reduced to N * M.
6. a network traffics output equipment is characterized in that, comprises exchange routing module and network traffics analysis module, wherein:
The exchange route function module that said exchange routing module is NTE is used for flow to be analyzed is sampled and sending to said network traffics analysis module according to the sample rate that is provided with;
The module of the network enabled flow analysis function that said network traffics analysis module is NTE is used for the sampling flow that said exchange routing module sends is analyzed, and according to the sample rate of said setting said analysis result is reduced.
7. network traffics output equipment as claimed in claim 6 is characterized in that,
Said network traffics analysis module comprises that first sampling consults submodule, is used for sending agreement request to said exchange routing module, and replys according to the negotiation that said exchange routing module sends the employed sample rate of sampling is set;
Said exchange routing module comprises the second sampling negotiation submodule, is used to receive the agreement request that said network traffics analysis module sends, and sends the negotiation of carrying the employed sample rate of sampling and reply.
8. like claim 6 or 7 described network traffics output equipments, it is characterized in that said exchange routing module also comprises:
The message identification submodule is used for according to the sample rate that is provided with, and selects message to identify the message in the flow to be analyzed according to said sample rate; When sample rate is N, from the message of the said flow to be analyzed of N, select a message to identify;
Message duplicates the transmission submodule, is used for the message of said message identification submodule sign is duplicated the back to said network traffics analysis module transmission, as sampling flow.
9. network traffics output equipment as claimed in claim 8 is characterized in that, said message duplicates the transmission submodule and specifically is used for:
Directly send after the message of said message identification submodule sign duplicated to said network traffics analysis module; Or
After the message of said message identification submodule sign duplicated, ACL discerned through access control lists, and the message after the identification is sent to said network traffics analysis module through central processing unit CPU; Or
After the message of said message identification submodule sign duplicated, send to said network traffics analysis module through the loopback port of equipment.
10. like claim 6 or 7 described network traffics output equipments, it is characterized in that said network traffics analysis module also comprises:
Analysis result obtains submodule, is used for said sampling flow is analyzed, and obtains the packet counting statistical information;
Analysis result reduction submodule; Be used for sample rate according to said setting; Said analysis result is obtained the packet counting statistical information that submodule obtains to reduce according to said sample rate: when the packet counting statistical information is M, when sample rate is N, said packet counting statistical information is reduced to N * M.
CN2009101312194A 2009-04-09 2009-04-09 Analysis method and equipment of network flow Active CN101521630B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN2009101312194A CN101521630B (en) 2009-04-09 2009-04-09 Analysis method and equipment of network flow

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN2009101312194A CN101521630B (en) 2009-04-09 2009-04-09 Analysis method and equipment of network flow

Publications (2)

Publication Number Publication Date
CN101521630A CN101521630A (en) 2009-09-02
CN101521630B true CN101521630B (en) 2012-07-11

Family

ID=41082013

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2009101312194A Active CN101521630B (en) 2009-04-09 2009-04-09 Analysis method and equipment of network flow

Country Status (1)

Country Link
CN (1) CN101521630B (en)

Families Citing this family (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101707554B (en) * 2009-11-18 2012-01-25 华为技术有限公司 Method and device for obtaining flow distribution of network
CN102130789A (en) * 2011-04-15 2011-07-20 北京网御星云信息技术有限公司 Method, device and system for measuring and sampling streams based on application groups
CN102404231A (en) * 2011-12-19 2012-04-04 曙光信息产业(北京)有限公司 System and method for dynamically adjusting message sampling rate by combining software with hardware
CN103368775B (en) * 2013-07-09 2016-08-17 杭州华三通信技术有限公司 flow backup method and core switching device
US9203711B2 (en) * 2013-09-24 2015-12-01 International Business Machines Corporation Port mirroring for sampling measurement of network flows
CN106603440A (en) * 2016-12-30 2017-04-26 盛科网络(苏州)有限公司 Switch unit and method for realizing multi-destination message mirroring
CN110913287A (en) * 2019-12-23 2020-03-24 北京首都在线科技股份有限公司 Signal processing method and system and light splitting equipment applied to method and system
CN115514686A (en) * 2021-06-23 2022-12-23 深信服科技股份有限公司 Flow acquisition method and device, electronic equipment and storage medium

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101051952A (en) * 2007-04-18 2007-10-10 东南大学 Self adaption sampling stream measuring method under high speed multilink logic channel environment
CN101267349A (en) * 2008-04-29 2008-09-17 杭州华三通信技术有限公司 Network traffic analysis method and device

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101051952A (en) * 2007-04-18 2007-10-10 东南大学 Self adaption sampling stream measuring method under high speed multilink logic channel environment
CN101267349A (en) * 2008-04-29 2008-09-17 杭州华三通信技术有限公司 Network traffic analysis method and device

Also Published As

Publication number Publication date
CN101521630A (en) 2009-09-02

Similar Documents

Publication Publication Date Title
CN101521630B (en) Analysis method and equipment of network flow
US6546420B1 (en) Aggregating information about network message flows
US10021116B2 (en) Network segmentation
CN101176305B (en) Distributed communication service system and method for analyzing communication service flow
EP2240854B1 (en) Method of resolving network address to host names in network flows for network device
US6483812B1 (en) Token ring network topology discovery and display
US20080002697A1 (en) Method, appratus, and system for capturing traffic statistics between two sites of mpls based vpn
US20070288579A1 (en) Network asset tracker for identifying users of networked computers
US9787581B2 (en) Secure data flow open information analytics
Willinger et al. A pragmatic approach to dealing with high-variability in network measurements
US10469326B1 (en) Discovering a computer network topology for an executing application
CN107347062A (en) A kind of method, electronic equipment and the readable storage medium storing program for executing of daily record data processing
EP4012980A1 (en) Application identification method and apparatus, and storage medium
CN100583830C (en) Method and apparatus for gathering and analyzing flux
CN113746654A (en) IPv6 address management and flow analysis method and device
CN101309220A (en) Flow control method and apparatus
CN114338471A (en) Analysis method based on ICP record combination netflow
Qian et al. Characterization of 3g data-plane traffic and application towards centralized control and management for software defined networking
CN108809795B (en) Transparent shunting method and device in local area network environment
Caporuscio et al. An experience in evaluating publish/subscribe services in a wireless network
Grubesic et al. Approximating the geographical characteristics of Internet activity
KR100779080B1 (en) Transmission apparatus with plural network interface and transmission method of using the same
Clegg et al. Challenges in the capture and dissemination of measurements from high-speed networks
Deri et al. Realtime MicroCloud-based flow aggregation for fixed and mobile networks
Riikonen Mobile internet usage-network traffic measurements

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CP03 Change of name, title or address
CP03 Change of name, title or address

Address after: 310052 Binjiang District Changhe Road, Zhejiang, China, No. 466, No.

Patentee after: Xinhua three Technology Co., Ltd.

Address before: 310053 Hangzhou hi tech Industrial Development Zone, Zhejiang province science and Technology Industrial Park, No. 310 and No. six road, HUAWEI, Hangzhou production base

Patentee before: Huasan Communication Technology Co., Ltd.