CN103618641A - Data packet detecting and monitoring system based on multiple-core network processor and capable of being deployed fast - Google Patents
Data packet detecting and monitoring system based on multiple-core network processor and capable of being deployed fast Download PDFInfo
- Publication number
- CN103618641A CN103618641A CN201310598644.0A CN201310598644A CN103618641A CN 103618641 A CN103618641 A CN 103618641A CN 201310598644 A CN201310598644 A CN 201310598644A CN 103618641 A CN103618641 A CN 103618641A
- Authority
- CN
- China
- Prior art keywords
- message
- packet
- many nuclear
- network processor
- nuclear network
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
- 238000012544 monitoring process Methods 0.000 title claims abstract description 34
- 238000012545 processing Methods 0.000 claims abstract description 30
- 238000001514 detection method Methods 0.000 claims abstract description 23
- 230000003993 interaction Effects 0.000 claims abstract description 5
- 238000001914 filtration Methods 0.000 claims description 19
- 238000007689 inspection Methods 0.000 claims description 16
- 238000012360 testing method Methods 0.000 claims description 5
- 238000013467 fragmentation Methods 0.000 claims description 4
- 238000006062 fragmentation reaction Methods 0.000 claims description 4
- 230000008878 coupling Effects 0.000 claims description 3
- 238000010168 coupling process Methods 0.000 claims description 3
- 238000005859 coupling reaction Methods 0.000 claims description 3
- 239000012634 fragment Substances 0.000 claims description 2
- 238000013519 translation Methods 0.000 claims description 2
- 238000007781 pre-processing Methods 0.000 abstract 1
- 238000004891 communication Methods 0.000 description 3
- 238000000034 method Methods 0.000 description 2
- 101000911390 Homo sapiens Coagulation factor VIII Proteins 0.000 description 1
- 230000009286 beneficial effect Effects 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 102000057593 human F8 Human genes 0.000 description 1
- 229940047431 recombinate Drugs 0.000 description 1
- 230000006798 recombination Effects 0.000 description 1
- 238000005215 recombination Methods 0.000 description 1
- 230000001105 regulatory effect Effects 0.000 description 1
- 230000003245 working effect Effects 0.000 description 1
Images
Landscapes
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
The invention provides a data packet detecting and monitoring system based on a multiple-core network processor and capable of being deployed fast. The system is composed of a deploying unit and a multiple-core network processor unit, wherein the deploying unit has program configuring, compiling and loading functions and a processor unit monitoring function, and the multiple cores in the multiple-core network processor are divided into different working groups which include a control management group, a message processing and forwarding group, a message regrouping group and a local control group. The control management group comprises a timer processing module, a remote interaction interface module and a control core module. The message processing and forwarding group comprises a data packet pre-processing module, a data packet detecting and analyzing module and a data packet forwarding module. The message regrouping group comprises a data message regrouping module. The local control group comprises a local interface module and a control core module. The data packet detecting and monitoring system based on the multiple-core network processor and capable of being deployed fast can be configured and deployed to live fast and automatically, can meet data packet detection requirements of networks with large handling capacity in operation, and has a flexible configuring function.
Description
Technical field
The present invention relates to network packet depth detection field, proposed a kind of based on many nuclear network processor architectural frameworks, can rapid deployment packet Inspection and monitoring system.
Background technology
Current, in network, exist some flames, network environment has been caused to certain pollution.For this situation, need effective regulatory measure.And carry out Deep content detection for packet in network, it is one of necessary method.By the content of packet in network is resolved, can monitor the data traffic in network and user's internet behavior, stop in time the circulation of the flame in network, source is traced in location fast, prevents the generation of event in violation of rules and regulations.
Owing to packet being carried out to the content detection of the degree of depth, need to partly carry out keyword matching detection to the data payload of packet.With respect to being only the detection system of protocol header information that detects the protocol layer of packet, carry out the detection of depth data bag and need more time and resource, and at present at a high speed, the net environment of large flow, packet detection system also needs to adopt specific architecture, guarantee to detect performance and user's communication quality, otherwise, be positioned at the packet detection system of network key node, to become the bottleneck of network traffics, affect the performance of whole network.Meanwhile, for meeting day by day changeable network environment and structure, detection system should provide abundant administration configuration interface, is easy to rapid deployment; For different demands, should provide different content detection, package forward filtering policys.
Accordingly, the present invention proposes a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, this system is used the network processing unit of many nuclear system frameworks, a large amount of cores in processor are divided into different work for the treatment of groups, numerous core concurrent workings, and make full use of hardware cell in network processing unit, meet the performance requirement of network.Meanwhile, the deployment unit of the Inspection and monitoring system that the present invention proposes, can meet the demand that detection system rapid deployment is reached the standard grade, and can use administration configuration interface, meets different detection monitoring demands.
Summary of the invention
It is a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment that the present invention proposes, comprises deployment unit and many nuclear network processor units.
The deployment unit of this system, runs on the program on many nuclear network processor units and monitors many nuclear network processor unit running statuses for configuring, compile, disposing, and deployment unit is comprised of following assembly:
Operating system;
Program compilation environment;
Application configuration file;
Program deployment interface;
Condition monitoring and management interface.
Many nuclear network processor units of this system, as the processors with a large amount of processing cores and dedicated hardware units, be responsible for carrying out deep message detection and taking different message repeating strategies according to testing result flowing into the packet of this unit, many nuclear network processors are with special-purpose hardware pattern matching DFA unit and timer units, the former is for carrying out rapidly sensitive information matching detection, and the latter is for realizing the filtration based on stream of native system and based on monitoring function end to end.
Numerous processing core works of many core processing units, in different working groups, are carried out different work-based logics, comprising:
Control and management group, is responsible for carrying out alternately, further comprising timer processing module, remote interaction interface module and control core module with remote management terminal;
Message processing forward group, be responsible for packet to carry out deep message content detection, further comprise packet pretreatment module, packet detects analysis module and package forward module, wherein except sensitive content filtering function, also comprise filtration based on stream and based on monitoring function end to end;
Message restructuring group, is responsible for the message of burst to recombinate, and comprises data message recombination module;
Local control group, is responsible for carrying out alternately, further comprising local interface module and control core module with local serial ports.
The invention has the beneficial effects as follows:
System provided by the invention can be configured rapid automatizedly and dispose and reach the standard grade, and is in operation and makes full use of many core parallel processing functions of many nuclear network processors, and the packet that can meet high speed, large throughput network detects demand.Meanwhile, native system, except sensitive content filtering function, also comprises filtration based on stream and based on monitoring function and IP fragmentation and reassembly function end to end, and has configuration feature flexibly, can meet the demand of complicated content detection strategy.
Accompanying drawing explanation
Fig. 1 is many core parallel data bag Inspection and monitoring system structure charts that the present invention proposes;
Fig. 2 is the filtration based on stream and based on monitoring function flow chart end to end in the system that proposes of the present invention.
Embodiment
Below in conjunction with accompanying drawing, the present invention is further described specifically.
As shown in Figure 1, of the present invention a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, comprising:
1, deployment unit (1), runs on the program on many nuclear network processor units and monitors many nuclear network processor unit running statuses for configuring, compile, disposing, and comprising:
Operating system (2), supports the operation of translation and compiling environment and all kinds of configuration, deployment and management tool;
Program compilation environment (3), provides compiler, load libraries, third party's instrument etc., supports compiling to obtain running on the program on many nuclear network processors;
Application configuration file (4), comprises that setting parameter file and match pattern expression formula set a file.Setting parameter file is for the operating state of setting program initial launch, with the form of key-value pair, preserve the settings of parameters, when program compilation, compilation tool is according to the settings in this document, the setup code of setting program, it is set that assurance program when operation relevant parameter initial value is configuration file.Match pattern expression formula is set a file and is contained predefined set of modes, regular expression rule of every behavior, and the forwarding strategy of the data message flowing into will be judged in many-core processor unit according to these set of modes;
Program deployment interface (5), automation tools is provided, automatically program compiling being completed is correctly written into many nuclear network processor units and makes many nuclear network processor units start operation, and after this instrument is carried out, many nuclear network processors normally start and start normal operation.
Condition monitoring and management interface (6), automation tools is provided, automatically obtain alternately the running state information of many nuclear network processor units with many nuclear network processor units, and can correctly catch the mistake that the operation of many nuclear network processor units occurs, caller deployment interface many nuclear network processor units of resetting automatically when many nuclear network processor units make a mistake.
2, another functional unit of native system is many nuclear network processor units (7), as the special network processor with a large amount of cores, be responsible for carrying out deep message detection and taking different message repeating strategies according to testing result flowing into the packet of this unit, in many nuclear network processor units, numerous processing core works are in different working groups (12), carry out different work-based logics, comprising:
2-1 message processing forward group (8), is responsible for collecting the data message of inflow system and carries out the detection of depth data bag, according to testing result, takes different forwarding strategies that message is sent.Comprise:
Packet pretreatment module: be responsible for receiving the packet of inflow system, and the UDP message with special control format is sent to control and management group, fragment message is sent to message restructuring group, common IP message is sent to packet and detects analysis module;
Packet detection analysis module: be responsible for packet to deliver the hardware pattern matching unit DFA(13 on many nuclear network processors) carry out matching check, analytical model matching check operating operation result, and analysis conclusion is delivered to package forward module, its conclusion comprises:
1) hit filtration: this packet hits in pattern matching;
2) same flow hits: this packet does not hit in pattern matching, but before this packet inflow system in a period of time, flow into system, with the packet of same source IP address and source port number, there is pattern matching with this packet and hit;
3) same end-to-end hitting: this packet hits at pattern matching meta, but before this packet inflow system in a period of time, flow into system, with the packet of same source IP address and same object IP address, there is pattern matching with this packet and hit;
4) miss: this packet does not hit in pattern matching, and before this packet inflow system in a period of time, inflow system, with the packet of same source IP address and source port number, there is not pattern matching with this packet and hit, and before this packet inflow system in a period of time, flow into system, with the packet of same source IP address and object IP address, there is not pattern matching with this packet and hit;
Package forward module: be responsible for detecting according to packet the analysis conclusion of analysis module, corresponding packet is taked to different forwarding strategies, comprising:
1) hit filtration: by package forward to predefined filtration port, setting message flow and the end-to-end information table of message, and set timer and send to control and management group;
2) same flow hits: by package forward to predefined filtration port;
3) same end-to-end hitting: packet is forwarded to predefined normal forwarding port and predefined filtration port simultaneously;
4) miss: by package forward to predefined normal forwarding port.
In message processing forward group, there is a large amount of processing cores, the concurrent working of all processing cores, when having new message to arrive system, idle core will be collected new message and start and process, thereby make numerous messages parallel processed in numerous cores, thereby guaranteed the message processing speed performance requirement of system.
2-2 control and management group (11), by timer processing module and remote interaction interface module, formed, timer processing module is wherein responsible in receiving system the then report of a plurality of timers of being set by message processing forward group, and according to timer information then, remove the record in the end-to-end information table of corresponding message flow and message.
Remote interaction interface module, be responsible for accepting the UDP message of specific format, the loading section of this type of message is with relevant control information, this type of control information is comprised of a command word and several parameter values, according to different command words and parameter value, call the control operation of control core module completion system.
The local control group (9) of 2-3, comprise local interface module and the control core module shared with Long-distance Control group, local interface module receives local input command by serial equipment, calls the control operation of kernel control module completion system, and by serial equipment outputs command executing result.
The control core module that above-mentioned control and management group and local control group all share, this module is the nucleus module of the operations such as actual complete sorts of systems parameter setting, system mode feedback, and can be called by other modules.
2-4 message restructuring group (10), receives the IP message of burst, and will belong to a plurality of IP fragmentation and reassemblies of same IP message, and the message after restructuring is submitted to message processing forward group.
Numerous cores of many nuclear network processors lay respectively in above-mentioned different working group, and can in the configuration file of deployment unit, assign the working group of each core, simultaneously, when system is moved, also can each core be shifted in different operating group by condition monitoring and the management interface of deployment unit, dynamically adjust core amounts in each working group, meet different network condition demands.
Above-mentioned message processing forward group and control and management group, can share the end-to-end information table of message flow and message, and message processing forward group can be used timer (14) and control and management group mutual.Message flow information table, record be the combination of source IP and source port, represented certain Network that a certain main frame sends; The end-to-end information table of message, record be the combination of source IP and object IP, represented the communication of two main frames in network.Shown in Fig. 2 is that system is utilized the above-mentioned end-to-end information table of message flow information table, message and timer, the filtration based on stream of realization and the function based on monitoring end to end.After some packet generation sensitive information couplings, for the follow-up flow in a period of time, system can be tackled the flow that filters the consolidated network business that all and same source host sensitive information packet send, forward simultaneously and monitor produce sensitive information communication two main frames between the flow of all-network business; The time of setting then after, control and management group is responsible for the relative recording in clear two information tables, in order to avoid affect subsequent network flow.
Claims (9)
1. based on many nuclear network processors a packet Inspection and monitoring system that can rapid deployment, comprising:
Deployment unit, runs on the program on many nuclear network processor units and monitors many nuclear network processor unit running statuses for configuring, compile, disposing;
Many nuclear network processor units, as the network processing unit with a plurality of cores, are responsible for carrying out deep message detection and taking different message repeating strategies according to testing result flowing into the packet of this unit;
Wherein, described deployment unit comprises:
Operating system, supports the operation of translation and compiling environment and all kinds of configuration, deployment and management tool;
Program compilation environment, provides compiler, load libraries, third party's instrument etc., supports compiling to obtain running on the program on many nuclear network processors;
Application configuration file, comprise that setting parameter file and pattern expression formula to be detected set a file, setting parameter file is for the operating state of setting program initial launch, pattern expression formula to be detected is set a file and is contained predefined set of modes, and many nuclear network processor units will be judged the forwarding strategy of the data message flowing into according to these set of modes;
Program deployment interface, provides related tool to help executable program be loaded into the program loading position of many nuclear network processor units and start many nuclear network processor units;
Condition monitoring and management interface, provide running status that related tool helps the many nuclear network processor units of monitoring, configuration management many-core processor unit many nuclear network processor units of resetting when many nuclear network processor units are made mistakes when information, operation while obtaining operation;
In described many nuclear network processor units, a plurality of core works, in different working groups, are carried out different work-based logics, comprising:
Control and management group, is responsible for the control message of receiving remote and makes corresponding management action according to message content;
Message processing forward group, is responsible for collecting the data message of inflow system and carries out the detection of depth data bag, according to testing result, takes different forwarding strategies that message is sent;
Message restructuring group, is responsible for collecting the message that burst appears in network layer, by after a plurality of IP fragmentation and reassemblies of same message, then carries out packet check and forwarding;
Local control group, receives control command by processor serial port parts, and takes different control actions according to different command;
Hardware pattern matching DFA unit, for carrying out rapidly sensitive information matching detection;
Timer units, for realizing filtration based on stream and based on monitoring function end to end.
2. according to claim 1 a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, it is characterized in that, the application configuration file of described deployment unit, with the form of key-value pair, preserve the settings of parameters, when program compilation, compilation tool is according to the settings in this document, the setup code of setting program, and during the operation of assurance program, to be configuration file set for relevant parameter initial value.
3. according to claim 1 a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, it is characterized in that, the program deployment interface of deployment unit can provide automation tools, automatically program compiling being completed is correctly written into many nuclear network processor units and makes many nuclear network processor units start operation, after this instrument is carried out, many nuclear network processors normally start and start normal operation.
4. according to claim 1 a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, it is characterized in that, condition monitoring and the management interface of deployment unit provide automation tools, automatically obtain alternately the running state information of many nuclear network processor units with many nuclear network processor units, and can correctly catch the mistake that the operation of many nuclear network processor units occurs, caller deployment interface many nuclear network processor units of resetting automatically when many nuclear network processor units make a mistake.
5. according to claim 1 a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, it is characterized in that, control and management group and the public message flow record sheet of message processing forward group and the end-to-end record sheet of message of many nuclear network processor units, in message flow record sheet, record be occur coupling message with source IP address and the combination of source port number; In the end-to-end record sheet of message, record be occur coupling message with source IP address and the combination of object IP address.
6. according to claim 1 a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, it is characterized in that, many nuclear network processor units comprise control and management group and local control group, Management Unit as unit, wherein, control and management group comprises timer processing module, the then report of a plurality of timers of being set by message processing forward group in responsible receiving system, and according to timer information then, remove the record in the end-to-end information table of corresponding message flow and message.Control and management group also comprises remote interaction interface module, be responsible for accepting the UDP message of specific format, the loading section of this type of message is with relevant control information, this type of control information is comprised of a command word and several parameter values, according to different command words and parameter value, call the control operation of control core module completion system.
The local interface module of local control group receives local input command by serial equipment, calls the control operation of kernel control module completion system, and by serial equipment outputs command executing result.
7. according to claim 1 a kind ofly it is characterized in that based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, the message processing forward group of many nuclear network processor units comprises:
Packet pretreatment module: be responsible for receiving the packet of inflow system, and the UDP message with special control format is sent to control and management group, fragment message is sent to message restructuring group, common IP message is sent to packet and detects analysis module;
Packet detects analysis module: the pattern matching hardware cell of being responsible for packet to deliver on many nuclear network processors carries out matching check, analytical model matching check operating operation result, and analysis conclusion is delivered to package forward module, its conclusion comprises:
(1) hit filtration: this packet hits in pattern matching;
(2) same flow hits: this packet does not hit in pattern matching, but before this packet inflow system in a period of time, flow into system, with the packet of same source IP address and source port number, there is pattern matching with this packet and hit;
(3) same end-to-end hitting: this packet hits at pattern matching meta, but before this packet inflow system in a period of time, flow into system, with the packet of same source IP address and same object IP address, there is pattern matching with this packet and hit;
(4) miss: this packet does not hit in pattern matching, and before this packet inflow system in a period of time, inflow system, with the packet of same source IP address and source port number, there is not pattern matching with this packet and hit, and before this packet inflow system in a period of time, flow into system, with the packet of same source IP address and object IP address, there is not pattern matching with this packet and hit;
Package forward module: be responsible for detecting according to packet the analysis conclusion of analysis module, corresponding packet is taked to different forwarding strategies, comprising:
(1) hit filtration: package forward, to predefined filtration port, is set to message flow and the end-to-end information table of message, and set timer;
(2) same flow hits: by package forward to predefined filtration port;
(3) same end-to-end hitting: packet is forwarded to predefined normal forwarding port and predefined filtration port simultaneously;
(4) miss: by package forward to predefined normal forwarding port.
8. according to claim 1 a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, it is characterized in that, the message restructuring group of many nuclear network processor units can receive the IP message of burst, and a plurality of IP fragmentation and reassemblies of same IP message will be belonged to, and the message after restructuring is submitted to message processing forward group.
9. according to claim 1 a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, it is characterized in that, numerous cores of many nuclear network processor units lay respectively in different working groups, and can in the configuration file of deployment unit, assign the working group of each core, simultaneously, when system is moved, also can each core be shifted in different operating group by condition monitoring and the management interface of deployment unit, dynamically adjust core amounts in each working group.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201310598644.0A CN103618641B (en) | 2013-11-25 | 2013-11-25 | Data packet detecting and monitoring system based on multiple-core network processor and capable of being deployed fast |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201310598644.0A CN103618641B (en) | 2013-11-25 | 2013-11-25 | Data packet detecting and monitoring system based on multiple-core network processor and capable of being deployed fast |
Publications (2)
Publication Number | Publication Date |
---|---|
CN103618641A true CN103618641A (en) | 2014-03-05 |
CN103618641B CN103618641B (en) | 2017-01-11 |
Family
ID=50169345
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201310598644.0A Expired - Fee Related CN103618641B (en) | 2013-11-25 | 2013-11-25 | Data packet detecting and monitoring system based on multiple-core network processor and capable of being deployed fast |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN103618641B (en) |
Cited By (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN104375868A (en) * | 2014-11-26 | 2015-02-25 | 浪潮(北京)电子信息产业有限公司 | Method and device suitable for rapid deployment of mass storage system |
CN104102579B (en) * | 2014-06-30 | 2017-07-28 | 重庆邮电大学 | A kind of network measuring system and method based on multinuclear or many-core embeded processor |
CN107241305A (en) * | 2016-12-28 | 2017-10-10 | 神州灵云(北京)科技有限公司 | A kind of network protocol analysis system and its analysis method based on polycaryon processor |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101488946A (en) * | 2008-01-16 | 2009-07-22 | 华为技术有限公司 | Packet detection method and system |
US20100172257A1 (en) * | 2009-01-05 | 2010-07-08 | Shaohua Yu | Internet Real-Time Deep Packet Inspection and Control Device and Method |
CN102497297A (en) * | 2011-12-13 | 2012-06-13 | 曙光信息产业(北京)有限公司 | System and method for realizing deep packet inspection technology based on multi-core and multi-thread |
CN103281158A (en) * | 2013-05-13 | 2013-09-04 | 昊优明镝(天津)科技有限公司 | Method for detecting communication granularity of deep web and detection equipment thereof |
-
2013
- 2013-11-25 CN CN201310598644.0A patent/CN103618641B/en not_active Expired - Fee Related
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101488946A (en) * | 2008-01-16 | 2009-07-22 | 华为技术有限公司 | Packet detection method and system |
US20100172257A1 (en) * | 2009-01-05 | 2010-07-08 | Shaohua Yu | Internet Real-Time Deep Packet Inspection and Control Device and Method |
CN102497297A (en) * | 2011-12-13 | 2012-06-13 | 曙光信息产业(北京)有限公司 | System and method for realizing deep packet inspection technology based on multi-core and multi-thread |
CN103281158A (en) * | 2013-05-13 | 2013-09-04 | 昊优明镝(天津)科技有限公司 | Method for detecting communication granularity of deep web and detection equipment thereof |
Non-Patent Citations (1)
Title |
---|
万志涛等: "基于多核处理器的深度包检测的实现和性能评估", 《2009年信息通信网络技术委员会年会征文》 * |
Cited By (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN104102579B (en) * | 2014-06-30 | 2017-07-28 | 重庆邮电大学 | A kind of network measuring system and method based on multinuclear or many-core embeded processor |
CN104375868A (en) * | 2014-11-26 | 2015-02-25 | 浪潮(北京)电子信息产业有限公司 | Method and device suitable for rapid deployment of mass storage system |
CN104375868B (en) * | 2014-11-26 | 2018-05-18 | 浪潮(北京)电子信息产业有限公司 | A kind of method and apparatus suitable for mass storage system (MSS) rapid deployment |
CN107241305A (en) * | 2016-12-28 | 2017-10-10 | 神州灵云(北京)科技有限公司 | A kind of network protocol analysis system and its analysis method based on polycaryon processor |
Also Published As
Publication number | Publication date |
---|---|
CN103618641B (en) | 2017-01-11 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN100471139C (en) | System and method for network test | |
CN110401581B (en) | Industrial control protocol fuzzy test case generation method based on flow tracing | |
CN109271793B (en) | Internet of things cloud platform equipment category identification method and system | |
CN102638453B (en) | A kind of voice data kernel retransmission method based on Linux system server | |
CN1750485A (en) | Network simulation detection system and method | |
CN103491575A (en) | Session-aware gtpv1 load balancing | |
CN100466563C (en) | Central monitoring method of the data service system without network management interface | |
CN105989539A (en) | Financial trading condition acquisition system and method | |
CN103067218B (en) | A kind of express network packet content analytical equipment | |
WO2011134739A1 (en) | Method for searching for message sequences, protocol analysis engine and protocol analyzer | |
CN107947994B (en) | Network topology self-discovery method and device, network equipment and computer storage medium | |
CN103200190A (en) | Physical accessing method facing QualNet network semi-physical simulation | |
CN102469045B (en) | Method for improving concurrency of WEB security gateway | |
CN102387045A (en) | Embedded point to point (P2P) flow monitoring system and method thereof | |
CN104539483A (en) | Network testing system | |
CN103078791A (en) | Method, device and system for processing operation, administration and maintenance (OAM) message | |
CN106411863A (en) | Virtualization platform for processing network traffic of virtual switches in real time | |
CN104243230A (en) | Method and device for obtaining monitoring data of Linux server | |
CN103618641A (en) | Data packet detecting and monitoring system based on multiple-core network processor and capable of being deployed fast | |
CN101753456B (en) | Method and system for detecting flow of peer-to-peer network | |
CN102104609B (en) | Method for analyzing safety defect of network protocol | |
CN110708209B (en) | Virtual machine flow acquisition method and device, electronic equipment and storage medium | |
CN107317810A (en) | A kind of data interception method and device | |
CN101753372B (en) | Detection method and device of bearer network router equipment | |
CN107483308A (en) | A kind of ethernet communication method based on timeslice token mechanism |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
CF01 | Termination of patent right due to non-payment of annual fee |
Granted publication date: 20170111 |