CN102957571A - Method and system for monitoring network flows - Google Patents

Method and system for monitoring network flows Download PDF

Info

Publication number
CN102957571A
CN102957571A CN2011102416183A CN201110241618A CN102957571A CN 102957571 A CN102957571 A CN 102957571A CN 2011102416183 A CN2011102416183 A CN 2011102416183A CN 201110241618 A CN201110241618 A CN 201110241618A CN 102957571 A CN102957571 A CN 102957571A
Authority
CN
China
Prior art keywords
url
focus
unit
initiatively
protocol
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN2011102416183A
Other languages
Chinese (zh)
Other versions
CN102957571B (en
Inventor
陈旭
宋璇
尹咸阳
张仁卓
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Changshu intellectual property operation center Co.,Ltd.
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to CN201110241618.3A priority Critical patent/CN102957571B/en
Priority to PCT/CN2012/080039 priority patent/WO2013026362A1/en
Publication of CN102957571A publication Critical patent/CN102957571A/en
Application granted granted Critical
Publication of CN102957571B publication Critical patent/CN102957571B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/10Protocols in which an application is distributed across nodes in the network
    • H04L67/104Peer-to-peer [P2P] networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/08Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Environmental & Geological Engineering (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

An embodiment of the invention provides a method and a system for monitoring network flows. The method in the embodiment includes computing requested times of uniform resource locators URL within a preset time so as to determine hot point URLs, actively capturing resources corresponding to the hot point URLs, subjecting the captured resources corresponding to the hot point URLs to protocol restructuring and analyzing content of data subjected to protocol restructuring. The embodiment of the invention further provides the system for monitoring network flows. Load of protocol restructuring and content analysis can be effectively reduced, efficiency of the integral system is improved, and system cost is reduced. Further, distributed P2P (peer to peer) resources can be intelligently restructured and P2P monitoring is supported.

Description

The method and system that is used for network flow monitoring
Technical field
The present invention relates to field, the Internet (Internet), and more specifically, relate to the monitoring of data traffic in the Internet.
Background technology
Along with the fast development of Internet, the Internet becomes the main path of Information Communication carrying.Yet conventional internet lacks supervision, maliciously/information of yellow/personal attack spreads unchecked, even terroristic organization occurred and utilizes the Internet to cultivate the terrorist, organizes the case of the attack of terrorism.In order to tackle this bad mood, adopt technological means the Internet to be supervised the common recognition that becomes national governments and operator.Flux monitoring system arises at the historic moment under such background.Flux monitoring system gathers flow information, reduction raw information, and carry out intellectual analysis according to the feature in the raw information, thereby the leak that in time exists in the discovering network, and make every effort to network attack is accomplished to prevent trouble before it happens.
Traditional flux monitoring method generally is divided into three steps: flow drainage, Protocol reassembling and backstage content analysis.These three steps are finished by three kinds of functional units of correspondence, as shown in Figure 1, are respectively drainage taxon 102, Protocol reassembling unit 104 and backstage content analysis unit 106.Wherein, drainage taxon 102 is given different Protocol reassembling unit 104 according to protocol type with the packet delivery received, Protocol reassembling unit 104 reduction application layer messages (for example, from Simple Mail Transfer protocol (SMTP) message reducing e-mail (Email) information, from the HTML (HTML) of HTML (Hypertext Markup Language) (HTTP) message reduction webpage, then, with the reduction application layer message together with time tag, link informations etc. are sent to backstage content analysis unit 106 and analyze.Backstage content analysis unit 106 is comprised of server cluster, the application layer message of reduction is carried out focus statistics, internet information analysis etc., thereby take certain measure Suppression network to attack.
But, in above-mentioned prior art, the passive drainage of drainage taxon, the data of large flow directly are directed to Protocol reassembling unit and backstage content analysis unit.Along with the growth of flow, the processing cost of the server cluster in Protocol reassembling unit and the backstage content analysis unit can significantly rise.
Secondly, backstage content analysis function is finished behind Protocol reassembling, thereby a large amount of identical contents are repeated restructuring, causes the performance requirement of Protocol reassembling unit very large.
In addition, above-mentioned traditional flux monitoring method is owing to can only obtain the peer-to-peer network (Peer-To-Peer of part, English referred to as P2P) file fragmentation and can't realize other P2P file fragmentation of intelligent interlinking, thus can not process the traffic monitoring of peer-to-peer network.
Summary of the invention
In view of this, an aspect of of the present present invention provides a kind of method for network flow monitoring, described method comprises: in the given time the requested number of times of uniform resource position mark URL (Uniform/Universal ResourceLocator, URL) is added up to determine focus URL; Initiatively grasp resource corresponding to described focus URL; Resource corresponding to described focus URL to initiatively crawl carried out Protocol reassembling; And the data through Protocol reassembling are carried out content analysis.
An aspect of of the present present invention provides a kind of system for network flow monitoring, and described system comprises: the drainage taxon is used for packet is carried out the drainage classification; The focus statistics unit is used in the given time the requested number of times of uniform resource position mark URL being added up to determine focus URL; Initiatively placement unit is used for initiatively grasping resource corresponding to described focus URL; The Protocol reassembling unit is used for the resource corresponding to described focus URL of initiatively crawl carried out Protocol reassembling; And the backstage content analysis unit, be used for the data behind Protocol reassembling are carried out content analysis.
The technical scheme of the embodiment of the invention is added up to determine focus URL the requested number of times of uniform resource position mark URL in the given time, then initiatively grasps resource corresponding to described focus URL and carries out Protocol reassembling and content analysis.Therefore, can reduce the burden of Protocol reassembling and backstage content analysis.In addition, the technical scheme of the embodiment of the invention can initiatively grasp the P2P file fragmentation that is distributed in everywhere for the distributed P 2 P resource, to support the monitoring to the P2P flow.
Description of drawings
Fig. 1 is the schematic diagram of network flow monitoring system traditional in the prior art.
Fig. 2 is an embodiment schematic diagram of network flow monitoring system in the embodiment of the invention.
Fig. 3 is another embodiment schematic diagram of network flow monitoring system in the embodiment of the invention.
Fig. 4 is an embodiment schematic diagram of network flow monitoring method in the embodiment of the invention.
To understand better the detailed description of above summary of the invention and following some embodiment of the present invention when reading by reference to the accompanying drawings.For the purpose of illustrating the invention, show in the drawings some embodiment.Yet, should be appreciated that the layout that the invention is not restricted to show in the accompanying drawing and means.
Embodiment
The detailed description of hereinafter setting forth by reference to the accompanying drawings is intended to illustrate various embodiment of the present invention, only can be embodied as these embodiment but not represent the present invention.Detailed description comprises detail, well understands of the present invention in order to reach.Yet, it will be understood by one of ordinary skill in the art that enforcement of the present invention also can not use these details.In some instances, show each well-known structure and assembly with the form of calcspar, in order to avoid desalination is to explanation of the present invention.
Fig. 2 describes is network flow monitoring system according to an embodiment of the invention.This system comprises: drainage taxon 202, focus statistics unit 204, active placement unit 206, Protocol reassembling unit 208 and backstage content analysis unit 210.Wherein, drainage taxon 202 is used for packet is carried out the drainage classification; Focus statistics unit 204 is used in the given time the requested number of times of uniform resource position mark URL being added up to determine focus URL; Initiatively placement unit 206 is used for initiatively grasping resource corresponding to described focus URL; Protocol reassembling unit 208 is used for the resource corresponding to described focus URL of initiatively crawl carried out Protocol reassembling; Backstage content analysis unit 210 is used for the data behind Protocol reassembling are carried out content analysis.In this network flow monitoring system, obtain first hot point resource, carry out again Protocol reassembling and backstage content analysis, so that same content is only carried out single treatment, thereby reduced the burden of Protocol reassembling unit and backstage content analysis unit, the efficient of whole system is provided.In addition, for the distributed P 2 P resource, can initiatively grasp the P2P file fragmentation that is distributed in everywhere, to support the monitoring to the P2P flow.
Fig. 3 describes is according to another embodiment of the present invention network flow monitoring system.This network flow monitoring system comprises:
Drainage taxon 302 is used for packet is carried out the drainage classification;
Focus statistics unit 304 is used in the given time the requested number of times of uniform resource position mark URL being added up to determine focus URL;
Initiatively placement unit 310 is used for initiatively grasping resource corresponding to described focus URL;
Protocol reassembling unit 312 is used for the resource corresponding to described focus URL of initiatively crawl carried out Protocol reassembling; And
Backstage content analysis unit 314 is used for the data behind Protocol reassembling are carried out content analysis.
Wherein, focus statistics unit 304 further comprises hierarchical statistics unit 306 and judging unit 308.Wherein, hierarchical statistics unit 306, be used for setting up resource table to the requested number of times of described URL hierarchical statistics to determine that whether every grade of URL is as focus URL.Resource table will be stored every grade of URL in the given time requested number of times and predetermined threshold value.Judging unit 308 is used for determining that this URL is focus URL when the requested number of times of a certain URL in the scheduled time surpasses predetermined threshold value.The resource that focus URL is corresponding can be webpage, also can be the P2P file fragmentation.
Fig. 4 has showed a kind of method flow diagram for network flow monitoring.This method can reduce the burden of Protocol reassembling unit and backstage content analysis unit, improves the efficient of whole system and reduces cost; Secondly, for the distributed P 2 P resource, can initiatively grasp the P2P file fragmentation that is distributed in everywhere, support the monitoring to the P2P flow.
The method of network flow monitoring shown in Figure 4 comprises:
402: the drainage taxon is carried out the drainage classification to packet;
According to the present embodiment, according to the protocol type under the packet of catching packet is carried out the drainage classification.
If the protocol type under the packet is HTTP, then only request header is sent to the focus statistics unit.Set up in the process of request at HTTP, the request header in the HTTP request message comprises the request row, and the request row comprises requesting method, and requesting method can be GET or POST.GET generally is used for obtaining/query resource information, and POST generally is used for upgrading resource information.When client will read document from server, use the GET requesting method.The GET requesting method requires server that the resource of URL location is placed on the data division loopback of response message to client.Adopt the GET requesting method herein.The URL that also comprises hyperlink request in the GET request row.
404: the focus statistics unit adds up to determine focus URL to the requested number of times of uniform resource position mark URL;
Alternatively, when requesting method is GET, in the given time the requested number of times of the URL(uniform resource locator) in the HTTP request header (URL) is added up.Usually can be made as 10 days the scheduled time.In 10 days, sort from high to low by the requested number of times of URL, regularly remove the URL after ordering is leaned on.When the requested number of times of a certain URL in the scheduled time surpasses predetermined threshold, determine that then this URL is focus URL, trigger initiatively grasping movement of initiatively placement unit execution.
406: initiatively placement unit initiatively grasps resource corresponding to described focus URL;
After having determined focus URL, initiatively placement unit initiatively grasps resource corresponding to focus URL.This resource can be webpage corresponding to focus URL with and other webpage of being linked to; The resource that this focus URL is corresponding can also be to be distributed in the file fragmentation on the different nodes in the peer-to-peer network (P2P).
408: the Protocol reassembling unit carries out Protocol reassembling to the resource corresponding to described focus URL of initiatively crawl;
410: the backstage content analysis unit is carried out content analysis to the data through Protocol reassembling.
For ease of understanding, the below introduces two concrete application scenarioss.
One, network public-opinion monitoring
Network public-opinion refers to the focus focal issue of the public to being concerned about most in the actual life that produces in the network.These problems of being shown great attention to are mainly propagated by approach such as forum, blog, microbloggings.Because the fast propagation of network, some hot issues will get out of hand in the very short time after occuring.Network public-opinion is monitored, can in time be tackled the public accident of network burst and grasp social situation and people's will comprehensively.
In this application scene, the focus statistics unit is by determining focus URL to the requested number of times of the URL in the statistics HTTP/GET request in the given time, then the active placement unit grasps other webpages of webpage corresponding to this focus URL and link thereof, can reach the purpose of public sentiment monitoring.
In certain embodiments, the focus statistics unit receives whenever that in the given time HTTP/GET message note does once record.Can adopt the form of resource table that URL is carried out hierarchical statistics.The degree of depth of statistics is determined according to the requirement of monitoring.What it will be appreciated by those skilled in the art that is that a rank divided in each division sign (/) among the URL.Such as, for the URL of www.xxx.com/sport/football/fifa2012/index.html, the statistics degree of depth can be made as 3.The first order is www.xxx.com; The second level is www.xxx.com/sport; 3rd level is www.xxx.com/sport/football.Data and the predetermined threshold of statistics gained all are stored in the resource table.
Need to prove, arranging of threshold value is common with reference to empirical value.If empirical value was arranged low, then can cause a large amount of content cachings in this locality, arrange and too highly can cause failing to report of part hot information again.Empirical value can be according to the definition of monitoring focus, the memory capacity of system are rationally arranged.The setting of predetermined threshold can be used with the client System Dependent.For example, at the dried net of Chinese state, threshold value can be made as several ten thousand; At provinces and cities' outlet net, then can be made as several thousand.Following table 1 is showed the signal resource table that focus URL is added up:
Table 1
Wherein, in the given time, the request number of times 10000 of www.xxx.com has surpassed threshold value 8000, determines that then this URL is focus URL.In certain embodiments, can adopt the mode of Hash table that resource table is stored on the data file, the index stores of resource table is in internal memory.Find hashed value according to URL, find index by hashed value again, directly navigate to data file according to index point.
After focus URL is determined in the focus statistics unit, initiatively placement unit initiatively grasp webpage corresponding to focus URL with and other webpage of being linked to.If the A webpage is the focus webpage, the A webpage covers the link of B webpage, and the B webpage covers the link of C webpage.In the situation that excavating depth is 3, A, B, C webpage are initiatively grabbed this locality.Excavating depth concrete in the practical application is by manual setting, and excavating depth is the 5 grades of needs that can finish monitoring under normal conditions.
For example, if www.xxx.com is confirmed as focus URL, then initiatively placement unit sends HTTP/GET and asks www.xxx.com, at this moment usually directly returns Index.html.Analyze the link on the Index.html, do the crawl of range or the degree of depth.Usually homepage of Index Web page representative begins to grasp step by step web page contents at different levels by homepage.What degree of depth crawl was adopted is that recurrence grasps the hyperlink that all run into, until recurrence meets the requirements of the crawl rank.The range crawl then is whole hyperlinks of a webpage of retrieval, sends respectively HTTP and asks to grasp full content, and then step by step deeply until the crawl rank that requires.
The resource that grabs is analyzed for the backstage after by Protocol reassembling, can recognize independent IP (Internet Protocol, procotol, the IP) data such as address flow, Website page flow, isolated user flow, new customer flow, thus realization is to the monitoring of public sentiment.
Two, peer-to-peer network (P2P)
P2P, namely Peer-To-Peer is known by people as the synonym of peer-to-peer network.The P2P network can simply be defined as by direct exchange and realize resource-sharing between the different system.In the P2P network environment, be seen as the participant of equality by the computer of Internet connection, their status is reciprocity each other, each node that participates in communication is called a Peer.Under the P2P pattern, the boundary between the server and client side has been cancelled.Because data storage, processing and the network bandwidth etc. all are to move with a kind of fully dispersion, asynchronous mode, various loads just can obtain fully reasonably balanced.The characteristics of the application model of P2P are exactly that the people who downloads is more, and the bandwidth that provides is also wider, and seed also can get more and more, and the speed of download is more and more faster.
In P2P uses, the P2P node is downloaded the seed file that needs to the website by browser, then therefrom obtain the address of Tracker server and be attached thereto, the Track server will return the information of other node (neighbor node) of downloading same resource file after the successful connection.Requesting node obtains backward these neighbor nodes of this information and initiates a message and connect, and carries out the download of resource, thereby realizes shared resource and service between the peer node in network.Wherein, seed file is " index " that is downloaded file, and the index information of each piece of download file and Hash identifying code write seed file.The Tracker server is the server of collecting download person, and this information is offered other download person, makes download person's the transmission of data that is connected with each other.
This shows, download person wants the download file content, at first needs to obtain corresponding seed file, then resolves the address that seed file obtains the Tracker server, connects the Tracker server.Download person other download person's of acquisition (neighbor node) from the receiveing the response of Tracker server IP address connects other download person and finishes sharing of data and resource.In this process, the file that download is divided into several file fragmentations, and it is stored in respectively in the middle of the different nodes, and the Tracker server can be known the IP address of the different nodes that each file fragmentation is stored.
Communicating by letter based on http protocol between node and the Tracker server.That is to say, node connects the Tracker server and needs at first to send the HTTP/GET request to this Tracker server, and the URL that comprises in this request is the address of the Tracker server that records in the seed file.
In certain embodiments, the requested number of times of the URL during ask to Tracker server transmission HTTP/GET in the given time to the P2P node focus statistics unit is added up.When in the given time the request number of times of certain URL being surpassed predetermined threshold, this URL is defined as focus URL.The IP address of the node stored to each file fragmentation of Tracker request download file corresponding to this focus URL of handling module initiatively, then obtain different file fragmentations from different nodes, these bursts are reconfigured be original contents, analyze for the backstage content analysis unit.Can make to be understood that the similar P2P node of the active placement unit here.
One of ordinary skill in the art will appreciate that all or part of step that realizes in above-described embodiment method is to come the relevant hardware of instruction to finish by program, this program can be stored in a kind of computer-readable recording medium, the above-mentioned storage medium of mentioning can be read-only memory, disk or CD etc.
Various illustrative logical blocks in conjunction with embodiment elaboration disclosed herein, the unit, circuit, element and/or assembly can pass through general processor, digital signal processor (Digital Signal Processing, DSP), application specific integrated circuit (Application Specific Integrated Circuit, ASIC), field programmable gate array (Field-Programmable Gate Array, FPGA) or other programmable logic components, discrete gate or transistor logic, discrete hardware components, or be designed for its any combination of carrying out function described herein and implement or carry out.General processor can be microprocessor, but another is chosen as, and processor also can be any conventional processors, controller, microcontroller or state machine.Processor also can be embodied as the combination of computation module, the combination of for example combination of the combination of DSP and microprocessor, multi-microprocessor, one or more microprocessor and DSP core or any other this configuration.
Embodiments of the invention are added up to determine focus URL the requested number of times of uniform resource position mark URL in the given time, then initiatively grasp resource corresponding to described focus URL and carry out Protocol reassembling and content analysis.Therefore, can reduce the burden of Protocol reassembling unit and backstage content analysis unit.In addition, the technical scheme of the embodiment of the invention can initiatively grasp the P2P file fragmentation that is distributed in everywhere for the distributed P 2 P resource, to support the monitoring to the P2P flow.
Above method and system for network flow monitoring provided by the present invention is described in detail, for one of ordinary skill in the art, thought according to the embodiment of the invention, all will change in specific embodiments and applications, therefore, this description should not be construed as limitation of the present invention.

Claims (8)

1. a method that is used for network flow monitoring is characterized in that, described method comprises:
Packet is carried out the drainage classification;
In the given time the requested number of times of uniform resource position mark URL is added up to determine focus URL;
Initiatively grasp resource corresponding to described focus URL;
Resource corresponding to described focus URL to initiatively crawl carried out Protocol reassembling; And
Data through Protocol reassembling are carried out content analysis.
2. method according to claim 1 is characterized in that,
In the given time the requested number of times of URL is added up to determine that focus URL comprises: to the requested number of times of described URL hierarchical statistics to determine that whether every grade of URL is as focus URL.
3. method according to claim 1 and 2 is characterized in that, wherein,
Resource corresponding to described focus URL comprises: webpage or Peer-to-Peer Network P2P file fragmentation.
4. each described method according to claim 1-3, it is characterized in that, in the given time the requested number of times of URL is added up to determine that focus URL comprises: as certain URL when requested number of times surpasses predetermined threshold in the given time, then this URL is defined as described focus URL.
5. a system that is used for network flow monitoring is characterized in that, described system comprises:
The drainage taxon is used for packet is carried out the drainage classification;
The focus statistics unit is used in the given time the requested number of times of uniform resource position mark URL being added up to determine focus URL;
Initiatively placement unit is used for initiatively grasping resource corresponding to described focus URL;
The Protocol reassembling unit is used for the resource corresponding to described focus URL of initiatively crawl carried out Protocol reassembling; And
The backstage content analysis unit is used for the data behind Protocol reassembling are carried out content analysis.
6. system according to claim 5 is characterized in that, described focus statistics unit further comprises the hierarchical statistics unit, and described hierarchical statistics unit is used for described URL hierarchical statistics request number of times to determine that whether every grade of URL is as focus URL.
7. according to claim 5 or 6 described systems, it is characterized in that,
Resource corresponding to described focus URL comprises: webpage or Peer-to-Peer Network P2P file fragmentation.
8. each described system according to claim 5-7, it is characterized in that, described focus statistics unit further comprises judging unit, and described judging unit is used for then this URL being defined as focus URL as certain URL when requested number of times is above predetermined threshold in the given time.
CN201110241618.3A 2011-08-22 2011-08-22 Method and system for monitoring network flows Active CN102957571B (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN201110241618.3A CN102957571B (en) 2011-08-22 2011-08-22 Method and system for monitoring network flows
PCT/CN2012/080039 WO2013026362A1 (en) 2011-08-22 2012-08-13 Method and system for monitoring network traffic

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201110241618.3A CN102957571B (en) 2011-08-22 2011-08-22 Method and system for monitoring network flows

Publications (2)

Publication Number Publication Date
CN102957571A true CN102957571A (en) 2013-03-06
CN102957571B CN102957571B (en) 2015-04-29

Family

ID=47745932

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201110241618.3A Active CN102957571B (en) 2011-08-22 2011-08-22 Method and system for monitoring network flows

Country Status (2)

Country Link
CN (1) CN102957571B (en)
WO (1) WO2013026362A1 (en)

Cited By (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103281367A (en) * 2013-05-22 2013-09-04 北京蓝汛通信技术有限责任公司 Load balance method and device
CN103338249A (en) * 2013-06-26 2013-10-02 优视科技有限公司 Cache method and device
CN103593446A (en) * 2013-11-18 2014-02-19 北京国双科技有限公司 Flow quality analyzing method and device
CN104092620A (en) * 2014-07-04 2014-10-08 浪潮(北京)电子信息产业有限公司 Method and device for achieving adjustment of network bandwidth
CN105119764A (en) * 2015-09-29 2015-12-02 百度在线网络技术(北京)有限公司 Method and device for monitoring flow
CN106161433A (en) * 2016-06-27 2016-11-23 安徽科成信息科技有限公司 A kind of network monitoring apparatus ensureing Web vector graphic safety
CN106209985A (en) * 2016-06-27 2016-12-07 安徽科成信息科技有限公司 A kind of safety monitoring device
CN106209796A (en) * 2016-06-27 2016-12-07 安徽科成信息科技有限公司 A kind of safe network monitoring apparatus
CN109429262A (en) * 2017-09-04 2019-03-05 ***通信有限公司研究院 A kind of detection method of hot spot, the network equipment and computer readable storage medium
CN111026942A (en) * 2019-11-01 2020-04-17 平安科技(深圳)有限公司 Hot word extraction method, device, terminal and medium based on web crawler

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110020263B (en) 2018-08-30 2021-10-22 京东方科技集团股份有限公司 Monitoring method and device of closed system and monitoring equipment
CN109376797B (en) * 2018-11-20 2023-05-16 大连理工大学 Network traffic classification method based on binary encoder and multi-hash table
CN113556260B (en) * 2020-04-24 2022-12-09 北京三快在线科技有限公司 Flow monitoring method and device, storage medium and electronic equipment
CN113094621B (en) * 2021-04-23 2023-08-08 中南大学 Internet public opinion cloud platform

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101437030A (en) * 2008-11-29 2009-05-20 成都市华为赛门铁克科技有限公司 Method for preventing server from being attacked, detection device and monitoring device
US7661136B1 (en) * 2005-12-13 2010-02-09 At&T Intellectual Property Ii, L.P. Detecting anomalous web proxy activity
CN101753341A (en) * 2008-12-16 2010-06-23 上海冰峰计算机网络技术有限公司 Monitoring method of computer network
CN101902365A (en) * 2009-05-26 2010-12-01 北京启明星辰信息技术股份有限公司 Method for monitoring P2P traffic of wide area network and system thereof

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7661136B1 (en) * 2005-12-13 2010-02-09 At&T Intellectual Property Ii, L.P. Detecting anomalous web proxy activity
CN101437030A (en) * 2008-11-29 2009-05-20 成都市华为赛门铁克科技有限公司 Method for preventing server from being attacked, detection device and monitoring device
CN101753341A (en) * 2008-12-16 2010-06-23 上海冰峰计算机网络技术有限公司 Monitoring method of computer network
CN101902365A (en) * 2009-05-26 2010-12-01 北京启明星辰信息技术股份有限公司 Method for monitoring P2P traffic of wide area network and system thereof

Cited By (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103281367B (en) * 2013-05-22 2016-03-02 北京蓝汛通信技术有限责任公司 A kind of load-balancing method and device
CN103281367A (en) * 2013-05-22 2013-09-04 北京蓝汛通信技术有限责任公司 Load balance method and device
CN103338249A (en) * 2013-06-26 2013-10-02 优视科技有限公司 Cache method and device
CN103338249B (en) * 2013-06-26 2018-05-25 优视科技有限公司 Caching method and device
CN103593446A (en) * 2013-11-18 2014-02-19 北京国双科技有限公司 Flow quality analyzing method and device
WO2015070735A1 (en) * 2013-11-18 2015-05-21 北京国双科技有限公司 Traffic quality analysis method and device
CN104092620A (en) * 2014-07-04 2014-10-08 浪潮(北京)电子信息产业有限公司 Method and device for achieving adjustment of network bandwidth
CN105119764A (en) * 2015-09-29 2015-12-02 百度在线网络技术(北京)有限公司 Method and device for monitoring flow
CN105119764B (en) * 2015-09-29 2019-06-28 百度在线网络技术(北京)有限公司 Method and apparatus for traffic monitoring
CN106161433A (en) * 2016-06-27 2016-11-23 安徽科成信息科技有限公司 A kind of network monitoring apparatus ensureing Web vector graphic safety
CN106209985A (en) * 2016-06-27 2016-12-07 安徽科成信息科技有限公司 A kind of safety monitoring device
CN106209796A (en) * 2016-06-27 2016-12-07 安徽科成信息科技有限公司 A kind of safe network monitoring apparatus
CN109429262A (en) * 2017-09-04 2019-03-05 ***通信有限公司研究院 A kind of detection method of hot spot, the network equipment and computer readable storage medium
CN111026942A (en) * 2019-11-01 2020-04-17 平安科技(深圳)有限公司 Hot word extraction method, device, terminal and medium based on web crawler
CN111026942B (en) * 2019-11-01 2024-04-16 平安科技(深圳)有限公司 Hot vocabulary extraction method, device, terminal and medium based on web crawlers

Also Published As

Publication number Publication date
WO2013026362A1 (en) 2013-02-28
CN102957571B (en) 2015-04-29

Similar Documents

Publication Publication Date Title
CN102957571B (en) Method and system for monitoring network flows
US8346753B2 (en) System and method for searching for internet-accessible content
Maggi et al. Two years of short urls internet measurement: security threats and countermeasures
CN104301161B (en) Computational methods, computing device and the communication system of quality of service index
CN103179132A (en) Method and device for detecting and defending CC (challenge collapsar)
WO2017025052A1 (en) Resource caching method and device
CN101826110B (en) Method for crawling BitTorrent torrent files
CN102968591B (en) Malicious-software characteristic clustering analysis method and system based on behavior segment sharing
US11281730B1 (en) Direct leg access for proxy web scraping
US10862995B2 (en) Internet-wide scheduling of transactions
CN106331172A (en) Method and device for detecting resources for content distribution network
Pham et al. Understanding website behavior based on user agent
Hurst et al. Social streams blog crawler
WO2018149479A1 (en) Distributed meta messaging computing
Chow et al. BTM-An automated rule-based BT monitoring system for piracy detection
Feng et al. An efficient caching mechanism for network-based url filtering by multi-level counting bloom filters
EP4227829A1 (en) Web scraping through use of proxies, and applications thereof
Akyol et al. A context aware notification architecture based on distributed focused crawling in the big data era
Kamiyama et al. Investigating structure of modern Web traffic
Shen et al. Freeweb: P2p-assisted collaborative censorship-resistant web browsing
Yuan et al. Evidence Collection Agent Model Design for Big Data Forensic Analysis
Pujol Gil Web content delivery, monetization, and search
Pujol Gil Web content delivery, monetization, and search: back-office and advertisement traffic on the Internet
Chen et al. A peer-to-peer based passive web crawling system
Sahoo et al. Machine Learning Based Architecture for Rule Establishment of Web Proxy Server

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
TR01 Transfer of patent right

Effective date of registration: 20201119

Address after: Unit 2414-2416, main building, no.371, Wushan Road, Tianhe District, Guangzhou City, Guangdong Province

Patentee after: GUANGDONG GAOHANG INTELLECTUAL PROPERTY OPERATION Co.,Ltd.

Address before: 518129 Bantian HUAWEI headquarters office building, Longgang District, Guangdong, Shenzhen

Patentee before: HUAWEI TECHNOLOGIES Co.,Ltd.

Effective date of registration: 20201119

Address after: 215500 No.13, Caotang Road, Changshu, Suzhou, Jiangsu Province

Patentee after: Changshu intellectual property operation center Co.,Ltd.

Address before: Unit 2414-2416, main building, no.371, Wushan Road, Tianhe District, Guangzhou City, Guangdong Province

Patentee before: GUANGDONG GAOHANG INTELLECTUAL PROPERTY OPERATION Co.,Ltd.

TR01 Transfer of patent right
CP02 Change in the address of a patent holder

Address after: 215500 5th floor, building 4, 68 Lianfeng Road, Changfu street, Changshu City, Suzhou City, Jiangsu Province

Patentee after: Changshu intellectual property operation center Co.,Ltd.

Address before: No.13 caodang Road, Changshu City, Suzhou City, Jiangsu Province

Patentee before: Changshu intellectual property operation center Co.,Ltd.

CP02 Change in the address of a patent holder