Summary of the invention
In view of this, the object of the invention is to provide a kind of message mirror-image method, to realize long-range message mirror, solves the dependence problem of existing message mirror technology to hardware chip simultaneously.
In addition, another purpose of the present invention is to provide a kind of network equipment of supporting remote message mirror, and it can be used said method and carry out the interior remote message mirror of wide area network.
In order to achieve the above object, the invention provides a kind of message mirror-image method, it comprises the following steps:
Step S1, the network equipment carry out image copying to the service message that satisfies predetermined conditions mirror and obtain described copy packet being loaded corresponding Mirror Info after the corresponding copy packet;
Step S2, the described network equipment utilize the described copy packet that is loaded with Mirror Info of procotol encapsulation, obtain the mirror image message of described service message; Wherein, described procotol includes User Datagram Protoco (UDP), and whether by source port and/or destination interface field in the UDP head in the UDP message of described User Datagram Protoco (UDP) encapsulation generation, being used for identifying described UDP message is mirror image message;
Step S3, according to the destination address in the described mirror image message, the described network equipment sends it to the respective remote main frame.
For above-mentioned message mirror-image method, preferably, described Mirror Info includes: by the numbering of mirror port, be used to write down described mirror image message correspondence by the logical number of mirror port; Type of message, being used to indicate described mirror image message is the physical layer mirror image message, perhaps is IP layer mirror image message; The message direction is used to indicate described mirror image message corresponding service message to be exported by mirror port from described, is perhaps imported by mirror port by described.
For above-mentioned message mirror-image method, preferably, described procotol include Internet protocol (Internet Protocol, IP); And,, be used for representing the designated mirror purpose IP address of described mirror image message by the purpose IP address field in the IP head in the IP message of described Internet protocol encapsulation generation.
For above-mentioned message mirror-image method, preferably, after described step S3, also include step S4, described distance host receives described mirror image message, and it is resolved identification, carries out analyzing and processing to reduce the raw information of described service message for the analyst.
In order to reach above-mentioned another purpose, the present invention also provides a kind of network equipment of supporting remote message mirror, and it comprises the mirror image unit that is used for generating according to the service message that satisfies predetermined conditions mirror mirror image message, and described mirror image unit specifically includes:
The image copying module is used to receive the service message that satisfies predetermined conditions mirror, and described service message is carried out image copying, obtains corresponding copy packet;
Package module is used to receive the described copy packet that the image copying module is exported, and described copy packet is loaded corresponding Mirror Info, and according to procotol it is encapsulated, and obtains corresponding mirror image message; Wherein, described procotol includes User Datagram Protoco (UDP), and whether by source port and/or destination interface field in the UDP head in the UDP message of described User Datagram Protoco (UDP) encapsulation generation, being used for identifying described UDP message is mirror image message;
Forwarding module is used to receive the described mirror image message of described package module output, and sends it to the mirror image destination address of appointment by network.
For the network equipment of above-mentioned support remote message mirror, wherein, described Mirror Info includes: by the numbering of mirror port, be used to write down described mirror image message correspondence by the logical number of mirror port; Type of message, being used to indicate described mirror image message is the physical layer mirror image message, perhaps is IP layer mirror image message; The message direction is used to indicate described mirror image message corresponding service message to be exported by mirror port from described, is perhaps imported by mirror port by described.
For the network equipment of above-mentioned support remote message mirror, wherein, described procotol includes Internet protocol; And,, be used for representing the designated mirror purpose IP address of described mirror image message by the purpose IP address field in the IP head in the IP message of described Internet protocol encapsulation generation.
For the network equipment of above-mentioned support remote message mirror, preferably, described package module further includes:
Mirror image message head packed part is connected with described image copying module, is used for loading corresponding Mirror Info toward described copy packet;
The network protocol header packed part is connected with described forwarding module with described mirror image message head packed part, is used to utilize the described copy packet that is loaded with Mirror Info of procotol encapsulation, to obtain corresponding described mirror image message.
By above-mentioned introduction as can be known, after the service message of predetermined conditions mirror is satisfied in image copying, it is carried out corresponding Mirror Info loads and the procotol encapsulation, the feasible mirror image message that finally obtains can be sent to the respective remote main frame according to purpose IP address wherein.
In other words, by mirror image message being carried out processing such as Mirror Info loading and procotol encapsulation, the present invention has realized a kind of extendible message mirror mechanism, the remote message mirror that it is applicable to various kinds of interfaces, efficiently solve existing message mirror technology when using on hardware condition limited problem.
Embodiment
See also Fig. 4, core concept of the present invention is: the service message 600 that satisfies predetermined conditions mirror in the network equipment 420 is carried out certain mirror image encapsulation process, obtain the mirror image message corresponding with it 700; Subsequently, according to the purpose IP address in the described mirror image message 700, send it to long-range analysis main frame 430 by network 410.
Need to prove, though among Fig. 4 the described network equipment 420 is illustrated as router, but those skilled in the art will be understood that other network equipments (such as, Ethernet switch) that have a similar message relay forwarding capability with described router and all can be used to implement the present invention.
As shown in Figure 4, the described network equipment 420 is responsible for generating and sending described mirror image message 700 as client; Described analysis main frame 430 is responsible for resolving the described mirror image message 700 of identification as server end, and the raw information of described mirror image message 700 corresponding service messages 600 of being used for reducing is carried out corresponding analyzing and processing for the analyst.
To at first introduce technical scheme provided by the present invention in detail respectively in operation below, also promptly introduce the concrete enforcement of message mirror-image method provided by the present invention in detail in described client (network equipment 420) and described server end (analyzing main frame 430) execution with reference to Fig. 5.
As shown in Figure 5, be the boundary with the dotted line, dotted line is the operation in described client executing toward top, mainly includes the following step:
Step S_B, the network equipment shown in Fig. 4 420 receives service message 600, and the described service message 600 that wherein satisfies predetermined conditions mirror is carried out image copying, obtains the copy packet of described service message 600.
Step S1, subsequently, the described network equipment 420 loads corresponding Mirror Info in described copy packet;
Step S2, then, the described network equipment 420 utilizes suitable procotol that the described copy packet that is loaded with Mirror Info is encapsulated according to concrete network application environment;
Step S3, last, the described network equipment 420 is sent to long-range analysis main frame 430 according to the purpose IP address in the described mirror image message with described mirror image message.
Wherein, above-mentioned steps S_B is as using the preparation process that the present invention carries out mirror image message 700 encapsulation process, and main purpose is to generate the image copying of described service message.And described image copying can be the constant simple copy of duplicating described service message of former state, also can be that selective feature extraction of duplicating useful information in the described service message is duplicated.
That is to say, need not the concrete operations details of described image copying is limited technology focus of the present invention is the copy packet how encapsulation process produces via described image copying, make that the mirror image message 700 that finally obtains can be by remote transmission.Therefore, will introduce above-mentioned steps S1 and the above-mentioned steps S2 that is used for the described copy packet of encapsulation process below.
At first, for above-mentioned steps S1, generally speaking described Mirror Info includes at least: by the numbering of mirror port, be used to write down described mirror image message 700 correspondences by the logical number of mirror port; Type of message is used to indicate described mirror image message 700 to be the physical layer mirror image message, perhaps is IP layer mirror image message; The message direction is used to indicate described mirror image message 700 corresponding service messages 600 to be exported by mirror port from described, is perhaps imported by mirror port by described.
Simultaneously, the form that above-mentioned various Mirror Infos can also the mirror image message head loads, and Fig. 6 has provided the concrete data structure of mirror image message head 720 described in the one embodiment of the invention.As shown in Figure 6, be packaged with in the described mirror image message head 720:
By the numbering of mirror port (Int-Number) 721, account for 1 byte, be used to write down described mirror image message 700 correspondences by the logical number of mirror port.Those skilled in the art will be understood that described logical number set according to actual application environment by the user herein, and technical solution of the present invention does not have any specific (special) requirements to described setting.
Type of message (Mir-Type) 722 accounts for 1 byte, is used to indicate described mirror image message 700 to be the physical layer mirror image message, perhaps is IP layer mirror image message.Specific explanations it, equal 1 indication described mirror image message 700 such as described type of message 722 and be the physical layer mirror image message, the image copying operation that also promptly produces described mirror image message 700 occurs in physical layer; And described type of message 722 to equal the described mirror image message of 2 expressions be IP layer mirror image message, the image copying operation that also promptly produces described mirror image message 700 occurs in the IP layer.
Message direction (Mir-Direction) 723 accounts for 1 byte, is used to indicate 600 pairs of described mirror image message 700 corresponding service messages described by the I/O direction of mirror port.Specific explanations it, such as described message direction 723 equal 1 the expression described service message 600 exported by mirror port from described, and equal 2 the expression its imported by mirror port from described.
Proprietary protocol number (Protocol) 724, account for 1 byte, be used to indicate the protocol type under the message (also being described copy packet) of mirror image message head 720 back described in the described mirror image message 700, and described protocol type 724 specifically may be atm (encapsulation of aal5 form) message, ppP message, hdlc message, fr message, x.25 message, Ethernet message, ip message, clear data message, lapb message, sdlc message etc.
Message total length (Total-Len) 725 accounts for 2 bytes, is used to represent the length of described copy packet.
Sequence of message number (Sequence) 726 accounts for 2 bytes, is used to represent the sequence number of described copy packet.
Burst skew (Offset) 727 accounts for 1 byte, is unit with the burst number, is used to represent the burst side-play amount of described copy packet (also being described mirror image message 700).
Need to prove that the usefulness of only using the data structure definition of the described mirror image message head 720 that lays down a definition shown in Figure 6 there is no any intention that is used for limiting protection range of the present invention.Those skilled in the art are when handling the needs described mirror image message head 720 of definition flexibly according to practical business on the basis of understanding above-mentioned explanation.
Continue, for above-mentioned steps S2, wherein said procotol generally included Internet protocol (Internet Protocol, IP).And,, can be used to represent the designated mirror purpose IP address of described mirror image message 700 by the purpose IP address field in the IP head in the IP message of described Internet protocol encapsulation generation.
In one embodiment of the invention, for utilizing the described described IP message that generates behind the copy packet of Mirror Info that is loaded with of Internet protocol encapsulation, IP head wherein is packaged with:
Source IP address is used to indicate the source address of described IP message, be assigned in embodiments of the present invention complete 0, to represent that the interface that described mirror image message 700 sends can be any interface;
Purpose IP address is used to indicate the destination address of described IP message, is assigned the designated mirror purpose IP address of described mirror image message 700 in embodiments of the present invention, can correctly be sent to corresponding analysis main frame 430 to guarantee described mirror image message 700;
Protocol number is used to indicate the type of message under the message of back, such as, be assigned 17 in embodiments of the present invention, be UDP (User Datagram Protocol, User Datagram Protoco (UDP)) message with the message of representing IP back described in the described IP message.
Rise time, (Time to Live TTL), was used for defining described IP message in the time-to-live of Network Transmission, whenever will subtract 1 through its numerical value behind the router; It can be assigned 255 in embodiments of the present invention, makes described IP message (also being described mirror image message 700) have the maximum time-to-live;
(Tape of Service TOS), is used for define grid and transmits spies such as described IP priority of messages, delay, throughput and reliability COS; It can be assigned 0 in embodiments of the present invention, makes described IP message (also being described mirror image message 700) have common priority.
Simultaneously, described procotol also include usually User Datagram Protoco (UDP) (User DatagramProtocol, UDP).And whether by source port (Source Port) and/or destination interface (Destination Port) field in the UDP head in the UDP message of described User Datagram Protoco (UDP) encapsulation generation, can be used to identify described UDP message is mirror image message.Such as,
Such as, in one embodiment of the invention, be 6000 with described source port in the UDP head in the described UDP message and described destination interface field while assignment, be a mirror image message 700 to identify described UDP message.
Like this, execute after above-mentioned steps S1 and the step S2, the encapsulation format of the described mirror image message 700 that finally obtains can be consulted Fig. 7.As shown in Figure 7, described mirror image message 700 also includes the mirror image message head 720 that carries corresponding Mirror Info, can identify it and be UDP of mirror image message 730 and the IP 740 that makes things convenient for Network Transmission except the copy packet 710 that includes the described service message 600 of image copying.
Then, the described network equipment 420 is then carried out above-mentioned steps S3, just according to the purpose IP address field in the IP head in the described mirror image message 700, by network 410 described mirror image message is sent to respective remote and analyzes main frame 430.
So far, technical solution of the present invention has been introduced in the concrete enforcement of client (network equipment 420) and has been finished.Under request in person and consult Fig. 5 once more, as shown in Figure 5, dotted line be in the operation of the present invention in server end (analyzing main frame 430) execution toward the lower part, mainly includes the following step:
Step S4, described analysis main frame 430 receives after the message, according to field assignment in the UDP head wherein (such as, source port and destination interface field are 60000) determine that it is mirror image message 700 after, it is peeled off IP head, UDP head, the first-class dissection process of mirror image message, restore raw information with this mirror image message 700 corresponding service messages 600;
Step S_E, based on described raw information, the analyst carries out corresponding analyzing and processing, such as network flow statistic, equipment fault eliminating etc.
So far, message mirror-image method provided by the present invention is explained in detail and is finished as above.And in sum as can be known, the present invention is by carrying out processing such as Mirror Info loading and procotol encapsulation to mirror image message, realized being applicable to the remote message mirror of various kinds of interfaces, it is limited effectively to have broken away from the use of existing message mirror technology on hardware condition.
Simultaneously, the present invention also provides a sharp network equipment of supporting remote message mirror, and it can be used above-mentioned message mirror-image method and carry out the interior remote message mirror of wide area network.The described network equipment comprises the mirror image unit that is used for generating according to the service message that satisfies predetermined conditions mirror mirror image message, and Fig. 8 has provided the structural representation of one of described mirror image unit embodiment.
In conjunction with message mirror-image method flow chart provided by the present invention shown in Figure 5, the structure of introducing described mirror image unit 500 shown in Figure 8 in detail is composed as follows.As shown in Figure 8, described mirror image unit 500 includes:
Image copying module 510 is mainly used in and carries out step S_B shown in Figure 5, also promptly after receiving the service message that satisfies predetermined conditions mirror, described service message is carried out image copying, obtains corresponding copy packet;
Package module 520, link to each other with described image copying module 510, be mainly used in and carry out step S1 shown in Figure 5 and step S2, also promptly after the described copy packet that receives 510 outputs of image copying module, it is carried out processing such as corresponding Mirror Info loading and procotol encapsulation, obtain corresponding mirror image message;
Forwarding module 530 links to each other with described package module 520, is mainly used in to carry out step S3 shown in Figure 5, also promptly after the described mirror image message that receives described package module 520 outputs, sends it to the mirror image destination address of appointment by network.
Wherein, as shown in Figure 8, described package module 520 further includes again
Mirror image message head packed part 521, link to each other with described image copying module 510, be mainly used in and carry out step S1 shown in Figure 5, the also i.e. corresponding Mirror Info of loading in the described copy packet, and can carry out as the form of heading by encapsulating mirror when specifically loading described Mirror Info;
Network protocol header packed part 522, link to each other with described forwarding module 530 with described mirror image message head packed part 521, main execution step S2 shown in Figure 5 also promptly utilizes the suitable described copy packet that is loaded with Mirror Info of procotol encapsulation, obtains corresponding described mirror image message.
The network equipment for support remote message mirror shown in Figure 8, wherein, the described Mirror Info that described package module 520 (comprising described mirror image message head packed part 521 and/or described network protocol header packed part 522) relates to when specifically carrying out step S1 shown in Figure 5 and/or S2, mirror image message head, procotol etc., all with aforementioned relevant introduce similar, so do not repeat them here.
What need statement is that foregoing invention content and embodiment are intended to prove the practical application of technical scheme provided by the present invention, should not be construed as the qualification to protection range of the present invention.Those skilled in the art are in spirit of the present invention and principle, when doing various modifications, being equal to and replacing or improve.Protection scope of the present invention is as the criterion with appended claims.