CN103618641A - Data packet detecting and monitoring system based on multiple-core network processor and capable of being deployed fast - Google Patents

Data packet detecting and monitoring system based on multiple-core network processor and capable of being deployed fast Download PDF

Info

Publication number
CN103618641A
CN103618641A CN201310598644.0A CN201310598644A CN103618641A CN 103618641 A CN103618641 A CN 103618641A CN 201310598644 A CN201310598644 A CN 201310598644A CN 103618641 A CN103618641 A CN 103618641A
Authority
CN
China
Prior art keywords
message
packet
many nuclear
network processor
nuclear network
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201310598644.0A
Other languages
Chinese (zh)
Other versions
CN103618641B (en
Inventor
周锋
王方驰
李小勇
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing University of Posts and Telecommunications
Original Assignee
Beijing University of Posts and Telecommunications
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing University of Posts and Telecommunications filed Critical Beijing University of Posts and Telecommunications
Priority to CN201310598644.0A priority Critical patent/CN103618641B/en
Publication of CN103618641A publication Critical patent/CN103618641A/en
Application granted granted Critical
Publication of CN103618641B publication Critical patent/CN103618641B/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention provides a data packet detecting and monitoring system based on a multiple-core network processor and capable of being deployed fast. The system is composed of a deploying unit and a multiple-core network processor unit, wherein the deploying unit has program configuring, compiling and loading functions and a processor unit monitoring function, and the multiple cores in the multiple-core network processor are divided into different working groups which include a control management group, a message processing and forwarding group, a message regrouping group and a local control group. The control management group comprises a timer processing module, a remote interaction interface module and a control core module. The message processing and forwarding group comprises a data packet pre-processing module, a data packet detecting and analyzing module and a data packet forwarding module. The message regrouping group comprises a data message regrouping module. The local control group comprises a local interface module and a control core module. The data packet detecting and monitoring system based on the multiple-core network processor and capable of being deployed fast can be configured and deployed to live fast and automatically, can meet data packet detection requirements of networks with large handling capacity in operation, and has a flexible configuring function.

Description

A kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment
Technical field
The present invention relates to network packet depth detection field, proposed a kind of based on many nuclear network processor architectural frameworks, can rapid deployment packet Inspection and monitoring system.
Background technology
Current, in network, exist some flames, network environment has been caused to certain pollution.For this situation, need effective regulatory measure.And carry out Deep content detection for packet in network, it is one of necessary method.By the content of packet in network is resolved, can monitor the data traffic in network and user's internet behavior, stop in time the circulation of the flame in network, source is traced in location fast, prevents the generation of event in violation of rules and regulations.
Owing to packet being carried out to the content detection of the degree of depth, need to partly carry out keyword matching detection to the data payload of packet.With respect to being only the detection system of protocol header information that detects the protocol layer of packet, carry out the detection of depth data bag and need more time and resource, and at present at a high speed, the net environment of large flow, packet detection system also needs to adopt specific architecture, guarantee to detect performance and user's communication quality, otherwise, be positioned at the packet detection system of network key node, to become the bottleneck of network traffics, affect the performance of whole network.Meanwhile, for meeting day by day changeable network environment and structure, detection system should provide abundant administration configuration interface, is easy to rapid deployment; For different demands, should provide different content detection, package forward filtering policys.
Accordingly, the present invention proposes a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, this system is used the network processing unit of many nuclear system frameworks, a large amount of cores in processor are divided into different work for the treatment of groups, numerous core concurrent workings, and make full use of hardware cell in network processing unit, meet the performance requirement of network.Meanwhile, the deployment unit of the Inspection and monitoring system that the present invention proposes, can meet the demand that detection system rapid deployment is reached the standard grade, and can use administration configuration interface, meets different detection monitoring demands.
Summary of the invention
It is a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment that the present invention proposes, comprises deployment unit and many nuclear network processor units.
The deployment unit of this system, runs on the program on many nuclear network processor units and monitors many nuclear network processor unit running statuses for configuring, compile, disposing, and deployment unit is comprised of following assembly:
Operating system;
Program compilation environment;
Application configuration file;
Program deployment interface;
Condition monitoring and management interface.
Many nuclear network processor units of this system, as the processors with a large amount of processing cores and dedicated hardware units, be responsible for carrying out deep message detection and taking different message repeating strategies according to testing result flowing into the packet of this unit, many nuclear network processors are with special-purpose hardware pattern matching DFA unit and timer units, the former is for carrying out rapidly sensitive information matching detection, and the latter is for realizing the filtration based on stream of native system and based on monitoring function end to end.
Numerous processing core works of many core processing units, in different working groups, are carried out different work-based logics, comprising:
Control and management group, is responsible for carrying out alternately, further comprising timer processing module, remote interaction interface module and control core module with remote management terminal;
Message processing forward group, be responsible for packet to carry out deep message content detection, further comprise packet pretreatment module, packet detects analysis module and package forward module, wherein except sensitive content filtering function, also comprise filtration based on stream and based on monitoring function end to end;
Message restructuring group, is responsible for the message of burst to recombinate, and comprises data message recombination module;
Local control group, is responsible for carrying out alternately, further comprising local interface module and control core module with local serial ports.
The invention has the beneficial effects as follows:
System provided by the invention can be configured rapid automatizedly and dispose and reach the standard grade, and is in operation and makes full use of many core parallel processing functions of many nuclear network processors, and the packet that can meet high speed, large throughput network detects demand.Meanwhile, native system, except sensitive content filtering function, also comprises filtration based on stream and based on monitoring function and IP fragmentation and reassembly function end to end, and has configuration feature flexibly, can meet the demand of complicated content detection strategy.
Accompanying drawing explanation
Fig. 1 is many core parallel data bag Inspection and monitoring system structure charts that the present invention proposes;
Fig. 2 is the filtration based on stream and based on monitoring function flow chart end to end in the system that proposes of the present invention.
Embodiment
Below in conjunction with accompanying drawing, the present invention is further described specifically.
As shown in Figure 1, of the present invention a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, comprising:
1, deployment unit (1), runs on the program on many nuclear network processor units and monitors many nuclear network processor unit running statuses for configuring, compile, disposing, and comprising:
Operating system (2), supports the operation of translation and compiling environment and all kinds of configuration, deployment and management tool;
Program compilation environment (3), provides compiler, load libraries, third party's instrument etc., supports compiling to obtain running on the program on many nuclear network processors;
Application configuration file (4), comprises that setting parameter file and match pattern expression formula set a file.Setting parameter file is for the operating state of setting program initial launch, with the form of key-value pair, preserve the settings of parameters, when program compilation, compilation tool is according to the settings in this document, the setup code of setting program, it is set that assurance program when operation relevant parameter initial value is configuration file.Match pattern expression formula is set a file and is contained predefined set of modes, regular expression rule of every behavior, and the forwarding strategy of the data message flowing into will be judged in many-core processor unit according to these set of modes;
Program deployment interface (5), automation tools is provided, automatically program compiling being completed is correctly written into many nuclear network processor units and makes many nuclear network processor units start operation, and after this instrument is carried out, many nuclear network processors normally start and start normal operation.
Condition monitoring and management interface (6), automation tools is provided, automatically obtain alternately the running state information of many nuclear network processor units with many nuclear network processor units, and can correctly catch the mistake that the operation of many nuclear network processor units occurs, caller deployment interface many nuclear network processor units of resetting automatically when many nuclear network processor units make a mistake.
2, another functional unit of native system is many nuclear network processor units (7), as the special network processor with a large amount of cores, be responsible for carrying out deep message detection and taking different message repeating strategies according to testing result flowing into the packet of this unit, in many nuclear network processor units, numerous processing core works are in different working groups (12), carry out different work-based logics, comprising:
2-1 message processing forward group (8), is responsible for collecting the data message of inflow system and carries out the detection of depth data bag, according to testing result, takes different forwarding strategies that message is sent.Comprise:
Packet pretreatment module: be responsible for receiving the packet of inflow system, and the UDP message with special control format is sent to control and management group, fragment message is sent to message restructuring group, common IP message is sent to packet and detects analysis module;
Packet detection analysis module: be responsible for packet to deliver the hardware pattern matching unit DFA(13 on many nuclear network processors) carry out matching check, analytical model matching check operating operation result, and analysis conclusion is delivered to package forward module, its conclusion comprises:
1) hit filtration: this packet hits in pattern matching;
2) same flow hits: this packet does not hit in pattern matching, but before this packet inflow system in a period of time, flow into system, with the packet of same source IP address and source port number, there is pattern matching with this packet and hit;
3) same end-to-end hitting: this packet hits at pattern matching meta, but before this packet inflow system in a period of time, flow into system, with the packet of same source IP address and same object IP address, there is pattern matching with this packet and hit;
4) miss: this packet does not hit in pattern matching, and before this packet inflow system in a period of time, inflow system, with the packet of same source IP address and source port number, there is not pattern matching with this packet and hit, and before this packet inflow system in a period of time, flow into system, with the packet of same source IP address and object IP address, there is not pattern matching with this packet and hit;
Package forward module: be responsible for detecting according to packet the analysis conclusion of analysis module, corresponding packet is taked to different forwarding strategies, comprising:
1) hit filtration: by package forward to predefined filtration port, setting message flow and the end-to-end information table of message, and set timer and send to control and management group;
2) same flow hits: by package forward to predefined filtration port;
3) same end-to-end hitting: packet is forwarded to predefined normal forwarding port and predefined filtration port simultaneously;
4) miss: by package forward to predefined normal forwarding port.
In message processing forward group, there is a large amount of processing cores, the concurrent working of all processing cores, when having new message to arrive system, idle core will be collected new message and start and process, thereby make numerous messages parallel processed in numerous cores, thereby guaranteed the message processing speed performance requirement of system.
2-2 control and management group (11), by timer processing module and remote interaction interface module, formed, timer processing module is wherein responsible in receiving system the then report of a plurality of timers of being set by message processing forward group, and according to timer information then, remove the record in the end-to-end information table of corresponding message flow and message.
Remote interaction interface module, be responsible for accepting the UDP message of specific format, the loading section of this type of message is with relevant control information, this type of control information is comprised of a command word and several parameter values, according to different command words and parameter value, call the control operation of control core module completion system.
The local control group (9) of 2-3, comprise local interface module and the control core module shared with Long-distance Control group, local interface module receives local input command by serial equipment, calls the control operation of kernel control module completion system, and by serial equipment outputs command executing result.
The control core module that above-mentioned control and management group and local control group all share, this module is the nucleus module of the operations such as actual complete sorts of systems parameter setting, system mode feedback, and can be called by other modules.
2-4 message restructuring group (10), receives the IP message of burst, and will belong to a plurality of IP fragmentation and reassemblies of same IP message, and the message after restructuring is submitted to message processing forward group.
Numerous cores of many nuclear network processors lay respectively in above-mentioned different working group, and can in the configuration file of deployment unit, assign the working group of each core, simultaneously, when system is moved, also can each core be shifted in different operating group by condition monitoring and the management interface of deployment unit, dynamically adjust core amounts in each working group, meet different network condition demands.
Above-mentioned message processing forward group and control and management group, can share the end-to-end information table of message flow and message, and message processing forward group can be used timer (14) and control and management group mutual.Message flow information table, record be the combination of source IP and source port, represented certain Network that a certain main frame sends; The end-to-end information table of message, record be the combination of source IP and object IP, represented the communication of two main frames in network.Shown in Fig. 2 is that system is utilized the above-mentioned end-to-end information table of message flow information table, message and timer, the filtration based on stream of realization and the function based on monitoring end to end.After some packet generation sensitive information couplings, for the follow-up flow in a period of time, system can be tackled the flow that filters the consolidated network business that all and same source host sensitive information packet send, forward simultaneously and monitor produce sensitive information communication two main frames between the flow of all-network business; The time of setting then after, control and management group is responsible for the relative recording in clear two information tables, in order to avoid affect subsequent network flow.

Claims (9)

1. based on many nuclear network processors a packet Inspection and monitoring system that can rapid deployment, comprising:
Deployment unit, runs on the program on many nuclear network processor units and monitors many nuclear network processor unit running statuses for configuring, compile, disposing;
Many nuclear network processor units, as the network processing unit with a plurality of cores, are responsible for carrying out deep message detection and taking different message repeating strategies according to testing result flowing into the packet of this unit;
Wherein, described deployment unit comprises:
Operating system, supports the operation of translation and compiling environment and all kinds of configuration, deployment and management tool;
Program compilation environment, provides compiler, load libraries, third party's instrument etc., supports compiling to obtain running on the program on many nuclear network processors;
Application configuration file, comprise that setting parameter file and pattern expression formula to be detected set a file, setting parameter file is for the operating state of setting program initial launch, pattern expression formula to be detected is set a file and is contained predefined set of modes, and many nuclear network processor units will be judged the forwarding strategy of the data message flowing into according to these set of modes;
Program deployment interface, provides related tool to help executable program be loaded into the program loading position of many nuclear network processor units and start many nuclear network processor units;
Condition monitoring and management interface, provide running status that related tool helps the many nuclear network processor units of monitoring, configuration management many-core processor unit many nuclear network processor units of resetting when many nuclear network processor units are made mistakes when information, operation while obtaining operation;
In described many nuclear network processor units, a plurality of core works, in different working groups, are carried out different work-based logics, comprising:
Control and management group, is responsible for the control message of receiving remote and makes corresponding management action according to message content;
Message processing forward group, is responsible for collecting the data message of inflow system and carries out the detection of depth data bag, according to testing result, takes different forwarding strategies that message is sent;
Message restructuring group, is responsible for collecting the message that burst appears in network layer, by after a plurality of IP fragmentation and reassemblies of same message, then carries out packet check and forwarding;
Local control group, receives control command by processor serial port parts, and takes different control actions according to different command;
Hardware pattern matching DFA unit, for carrying out rapidly sensitive information matching detection;
Timer units, for realizing filtration based on stream and based on monitoring function end to end.
2. according to claim 1 a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, it is characterized in that, the application configuration file of described deployment unit, with the form of key-value pair, preserve the settings of parameters, when program compilation, compilation tool is according to the settings in this document, the setup code of setting program, and during the operation of assurance program, to be configuration file set for relevant parameter initial value.
3. according to claim 1 a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, it is characterized in that, the program deployment interface of deployment unit can provide automation tools, automatically program compiling being completed is correctly written into many nuclear network processor units and makes many nuclear network processor units start operation, after this instrument is carried out, many nuclear network processors normally start and start normal operation.
4. according to claim 1 a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, it is characterized in that, condition monitoring and the management interface of deployment unit provide automation tools, automatically obtain alternately the running state information of many nuclear network processor units with many nuclear network processor units, and can correctly catch the mistake that the operation of many nuclear network processor units occurs, caller deployment interface many nuclear network processor units of resetting automatically when many nuclear network processor units make a mistake.
5. according to claim 1 a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, it is characterized in that, control and management group and the public message flow record sheet of message processing forward group and the end-to-end record sheet of message of many nuclear network processor units, in message flow record sheet, record be occur coupling message with source IP address and the combination of source port number; In the end-to-end record sheet of message, record be occur coupling message with source IP address and the combination of object IP address.
6. according to claim 1 a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, it is characterized in that, many nuclear network processor units comprise control and management group and local control group, Management Unit as unit, wherein, control and management group comprises timer processing module, the then report of a plurality of timers of being set by message processing forward group in responsible receiving system, and according to timer information then, remove the record in the end-to-end information table of corresponding message flow and message.Control and management group also comprises remote interaction interface module, be responsible for accepting the UDP message of specific format, the loading section of this type of message is with relevant control information, this type of control information is comprised of a command word and several parameter values, according to different command words and parameter value, call the control operation of control core module completion system.
The local interface module of local control group receives local input command by serial equipment, calls the control operation of kernel control module completion system, and by serial equipment outputs command executing result.
7. according to claim 1 a kind ofly it is characterized in that based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, the message processing forward group of many nuclear network processor units comprises:
Packet pretreatment module: be responsible for receiving the packet of inflow system, and the UDP message with special control format is sent to control and management group, fragment message is sent to message restructuring group, common IP message is sent to packet and detects analysis module;
Packet detects analysis module: the pattern matching hardware cell of being responsible for packet to deliver on many nuclear network processors carries out matching check, analytical model matching check operating operation result, and analysis conclusion is delivered to package forward module, its conclusion comprises:
(1) hit filtration: this packet hits in pattern matching;
(2) same flow hits: this packet does not hit in pattern matching, but before this packet inflow system in a period of time, flow into system, with the packet of same source IP address and source port number, there is pattern matching with this packet and hit;
(3) same end-to-end hitting: this packet hits at pattern matching meta, but before this packet inflow system in a period of time, flow into system, with the packet of same source IP address and same object IP address, there is pattern matching with this packet and hit;
(4) miss: this packet does not hit in pattern matching, and before this packet inflow system in a period of time, inflow system, with the packet of same source IP address and source port number, there is not pattern matching with this packet and hit, and before this packet inflow system in a period of time, flow into system, with the packet of same source IP address and object IP address, there is not pattern matching with this packet and hit;
Package forward module: be responsible for detecting according to packet the analysis conclusion of analysis module, corresponding packet is taked to different forwarding strategies, comprising:
(1) hit filtration: package forward, to predefined filtration port, is set to message flow and the end-to-end information table of message, and set timer;
(2) same flow hits: by package forward to predefined filtration port;
(3) same end-to-end hitting: packet is forwarded to predefined normal forwarding port and predefined filtration port simultaneously;
(4) miss: by package forward to predefined normal forwarding port.
8. according to claim 1 a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, it is characterized in that, the message restructuring group of many nuclear network processor units can receive the IP message of burst, and a plurality of IP fragmentation and reassemblies of same IP message will be belonged to, and the message after restructuring is submitted to message processing forward group.
9. according to claim 1 a kind of based on many nuclear network processors packet Inspection and monitoring system that can rapid deployment, it is characterized in that, numerous cores of many nuclear network processor units lay respectively in different working groups, and can in the configuration file of deployment unit, assign the working group of each core, simultaneously, when system is moved, also can each core be shifted in different operating group by condition monitoring and the management interface of deployment unit, dynamically adjust core amounts in each working group.
CN201310598644.0A 2013-11-25 2013-11-25 Data packet detecting and monitoring system based on multiple-core network processor and capable of being deployed fast Expired - Fee Related CN103618641B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201310598644.0A CN103618641B (en) 2013-11-25 2013-11-25 Data packet detecting and monitoring system based on multiple-core network processor and capable of being deployed fast

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201310598644.0A CN103618641B (en) 2013-11-25 2013-11-25 Data packet detecting and monitoring system based on multiple-core network processor and capable of being deployed fast

Publications (2)

Publication Number Publication Date
CN103618641A true CN103618641A (en) 2014-03-05
CN103618641B CN103618641B (en) 2017-01-11

Family

ID=50169345

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201310598644.0A Expired - Fee Related CN103618641B (en) 2013-11-25 2013-11-25 Data packet detecting and monitoring system based on multiple-core network processor and capable of being deployed fast

Country Status (1)

Country Link
CN (1) CN103618641B (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104375868A (en) * 2014-11-26 2015-02-25 浪潮(北京)电子信息产业有限公司 Method and device suitable for rapid deployment of mass storage system
CN104102579B (en) * 2014-06-30 2017-07-28 重庆邮电大学 A kind of network measuring system and method based on multinuclear or many-core embeded processor
CN107241305A (en) * 2016-12-28 2017-10-10 神州灵云(北京)科技有限公司 A kind of network protocol analysis system and its analysis method based on polycaryon processor

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101488946A (en) * 2008-01-16 2009-07-22 华为技术有限公司 Packet detection method and system
US20100172257A1 (en) * 2009-01-05 2010-07-08 Shaohua Yu Internet Real-Time Deep Packet Inspection and Control Device and Method
CN102497297A (en) * 2011-12-13 2012-06-13 曙光信息产业(北京)有限公司 System and method for realizing deep packet inspection technology based on multi-core and multi-thread
CN103281158A (en) * 2013-05-13 2013-09-04 昊优明镝(天津)科技有限公司 Method for detecting communication granularity of deep web and detection equipment thereof

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101488946A (en) * 2008-01-16 2009-07-22 华为技术有限公司 Packet detection method and system
US20100172257A1 (en) * 2009-01-05 2010-07-08 Shaohua Yu Internet Real-Time Deep Packet Inspection and Control Device and Method
CN102497297A (en) * 2011-12-13 2012-06-13 曙光信息产业(北京)有限公司 System and method for realizing deep packet inspection technology based on multi-core and multi-thread
CN103281158A (en) * 2013-05-13 2013-09-04 昊优明镝(天津)科技有限公司 Method for detecting communication granularity of deep web and detection equipment thereof

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
万志涛等: "基于多核处理器的深度包检测的实现和性能评估", 《2009年信息通信网络技术委员会年会征文》 *

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104102579B (en) * 2014-06-30 2017-07-28 重庆邮电大学 A kind of network measuring system and method based on multinuclear or many-core embeded processor
CN104375868A (en) * 2014-11-26 2015-02-25 浪潮(北京)电子信息产业有限公司 Method and device suitable for rapid deployment of mass storage system
CN104375868B (en) * 2014-11-26 2018-05-18 浪潮(北京)电子信息产业有限公司 A kind of method and apparatus suitable for mass storage system (MSS) rapid deployment
CN107241305A (en) * 2016-12-28 2017-10-10 神州灵云(北京)科技有限公司 A kind of network protocol analysis system and its analysis method based on polycaryon processor

Also Published As

Publication number Publication date
CN103618641B (en) 2017-01-11

Similar Documents

Publication Publication Date Title
CN100471139C (en) System and method for network test
CN110401581B (en) Industrial control protocol fuzzy test case generation method based on flow tracing
CN109271793B (en) Internet of things cloud platform equipment category identification method and system
CN102638453B (en) A kind of voice data kernel retransmission method based on Linux system server
CN1750485A (en) Network simulation detection system and method
CN103491575A (en) Session-aware gtpv1 load balancing
CN100466563C (en) Central monitoring method of the data service system without network management interface
CN105989539A (en) Financial trading condition acquisition system and method
CN103067218B (en) A kind of express network packet content analytical equipment
WO2011134739A1 (en) Method for searching for message sequences, protocol analysis engine and protocol analyzer
CN107947994B (en) Network topology self-discovery method and device, network equipment and computer storage medium
CN103200190A (en) Physical accessing method facing QualNet network semi-physical simulation
CN102469045B (en) Method for improving concurrency of WEB security gateway
CN102387045A (en) Embedded point to point (P2P) flow monitoring system and method thereof
CN104539483A (en) Network testing system
CN103078791A (en) Method, device and system for processing operation, administration and maintenance (OAM) message
CN106411863A (en) Virtualization platform for processing network traffic of virtual switches in real time
CN104243230A (en) Method and device for obtaining monitoring data of Linux server
CN103618641A (en) Data packet detecting and monitoring system based on multiple-core network processor and capable of being deployed fast
CN101753456B (en) Method and system for detecting flow of peer-to-peer network
CN102104609B (en) Method for analyzing safety defect of network protocol
CN110708209B (en) Virtual machine flow acquisition method and device, electronic equipment and storage medium
CN107317810A (en) A kind of data interception method and device
CN101753372B (en) Detection method and device of bearer network router equipment
CN107483308A (en) A kind of ethernet communication method based on timeslice token mechanism

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20170111