Embodiment
The present invention is further described in more detail below in conjunction with drawings and the specific embodiments.
Fig. 1 is the main flow chart of the generation method of application layer topological structure in the communication network of the present invention.Referring to Fig. 1, this method comprises:
Step 101, the node device in communication network (as machinery equipments such as computer, routers) are gathered the communication relation of becoming a partner by this machine (namely by this node device) communication, and described each communication relation of becoming a partner comprises source address, destination address and destination slogan.In an embodiment of the present invention, described source address, destination address specifically refer to source IP address, purpose IP address.
Step 102, generate the application layer topological structure according to the communication of the gathering relationship analysis of becoming a partner, the concrete analysis generative process comprises: be the corresponding source node of drawing of each the different source address in the described communication relation of becoming a partner, for each the different destination address in the described communication relation of becoming a partner adds the corresponding destination node of drawing of destination slogan, and according to the source of the described communication relation of becoming a partner to the requesting party of purpose to draw from source node to corresponding destination node the requesting party to.
Fig. 2 is the main composition schematic diagram of the generation system of application layer topological structure in the communication network of the present invention.Referring to Fig. 2, this system comprises harvester and analyzes generating apparatus:
Described harvester is arranged on the node device in the communication network, for gathering by the communication of this machine communication relation of becoming a partner at node device and reporting the analysis generating apparatus, described each communication relation of becoming a partner comprises source address, destination address and destination slogan.
Though concrete annexation is arranged between the node device, because the present invention do not limit the actual annexation between the node device in the described communication network, so the annexation between the node device of clearly not drawing among Fig. 2.
Described analysis generating apparatus can be arranged on node device such as the management server for network management, generate the application layer topological structure for the relationship analysis of becoming a partner according to the communication of gathering, the concrete analysis generative process comprises: be the corresponding source node of drawing of each the different source address in the described communication relation of becoming a partner, for each the different destination address in the described communication relation of becoming a partner adds the corresponding destination node of drawing of destination slogan, and according to the source of the described communication relation of becoming a partner to the requesting party of purpose to draw from source node to corresponding destination node the requesting party to.
In the step 101, described harvester is gathered by the communication of this machine communication relation of becoming a partner at node device can comprise two kinds of concrete execution modes, a kind of for passing through to analyze the message collection, another kind is by analyzing transmission control protocol (TCP, Transmission Control Protocol) state table collection.
Describedly gather the described communication relation of becoming a partner and be specially by analyzing message: the passing message of gathering described this machine of node device network interface card, specifically comprise the message that sends from this machine network interface card and the message of receiving by this machine network interface card, extract source address, destination address and destination slogan in the message gather, source address, destination address and the destination slogan of a message carried out record as the relation of becoming a partner of communicating by letter.Herein can timing acquiring, also can gather according to the time of described management server appointment.
Described by the tcp state table gather described communication become a partner the relation be specially: the tcp state table of inquiring about the in-local system of described node device, this tcp state table is given tacit consent to generation in operating system such as WINDOWS operating system and LINUX operating system, for example can utilize this tcp state table of netstat command calls in LINUX operating system.Record the state recording of many expression network services in the described tcp state table, source address, destination address and the destination slogan of this network service in every bar state record, extract corresponding source address, destination address and destination slogan in every bar state record of described harvester from this tcp state table, source address, destination address and destination slogan that a bar state is recorded carry out record as the relation of becoming a partner of communicating by letter.
Among the present invention, can find and generate the whole application layer topological structure of certain designated communication network of appointment, also can find and generate the application layer topological structure of part of the one or more node device correspondence of the appointment in certain communication network.For example in the communication network management for the IDC machine room, can generate the application layer topological structure to the communication network of entire I DC machine room, also can find and generate corresponding topical application etale topology structure at one or several node device in the IDC machine room.
In one embodiment, in order to find and generate the whole application layer topological structure of certain communication network, each node device that is specifically as follows in step 101 in this communication network (as the communication network of an IDC machine room) is gathered by the communication of this machine communication relation of becoming a partner, in step 102, gather the communication relation of becoming a partner that each node device is gathered, analyze the whole application layer topological structure that generates communication network.
In another embodiment, in order to find and generate the application layer topological structure of the one or more node device correspondence of (in the communication network as the IDC machine room) appointment in certain communication network, can be in step 101 specifically the specified node equipment in this communication network gather the communication relation of becoming a partner that communicates by this node device, described specified command can be sent by described analysis generating apparatus.
Fig. 3 a is a kind of schematic diagram of the relation of becoming a partner of collection communication on the node device of appointment.Referring to Fig. 3 a, described analysis generating apparatus can comprise that collection arranges module 301, this collection arranges module 301 and is used for according to user instruction, need the node device of the collection communication relation of becoming a partner in the designated communication network, different node devices has different signs, can after specifying acquisition instructions be sent to the described harvester (for example specifying acquisition node equipment 1 and communicating by letter of node device 2 relation of becoming a partner among this figure) of described specified node equipment by identifying to specify specific node device; Described harvester is further used for just gathering by the communication of this machine communication relation of becoming a partner at this node device after receiving described acquisition instructions, and reports the analysis generating apparatus.Can realize gathering the communication relation of becoming a partner of specified node equipment like this, analyzing the application layer topological structure that generates is the application layer topological structure of these specified node equipment.
In another embodiment, in order to find and generate the application layer topological structure of the one or more node device correspondence of (in the communication network as the IDC machine room) appointment in certain communication network, step 101 can be gathered by the communication of this machine communication relation of becoming a partner by each node device in this communication network; In step 102, after from node device, collecting the communication relation of becoming a partner, can unify to be input in the database, specify the node device that needs to generate the application layer topological structure according to user instruction then, for example can specified node equipment 1 and node device 2, determine the address of described specified node equipment afterwards, check source address and destination address in the communication of gathering in the database relation of becoming a partner, extract the communication relation of becoming a partner that contains described specified node device address; The communication that follow-up basis the contains described specified node device address relationship analysis of becoming a partner generates the application layer topological structure of described specified node equipment.
Fig. 3 b serves as reasons and analyzes a kind of schematic diagram that generating apparatus is analyzed the communication of the specified node equipment relation of becoming a partner, referring to Fig. 3 b, the harvester on described each node device reports the communication of passing through the communication of this machine of the gathering relation of becoming a partner and gathers to described analysis generating apparatus; Described analysis generating apparatus comprises that analysis arranges module 302, be used for specifying the node device that needs to generate the application layer topological structure according to user instruction, determine the address of described specified node equipment, check source address and destination address in the described communication relation of becoming a partner, extract the communication relation of becoming a partner that contains described specified node device address; Follow-up described analysis generating apparatus only generates the application layer topological structure of described specified node equipment according to the communication that the contains described specified node device address relationship analysis of becoming a partner.
Owing to may have the communication relation of becoming a partner that a large amount of contents repeat in the described communication of in node device, the gathering relation of becoming a partner, for example may have the source address of one or more, destination address and destination slogan be the identical relation of becoming a partner of communicating by letter all, therefore in an embodiment of the present invention, can also be further before the relationship analysis of becoming a partner according to the communication of gathering generates the application layer topological structure, the communication of the gathering relation of becoming a partner is carried out convergence process, that is: in the communication of the gathering relation of becoming a partner, will have same source, the relation of becoming a partner of communicating by letter of one or more of destination address and destination slogan converges one and has this source address, destination address and communicating by letter of the destination slogan relation of becoming a partner.If source address, destination address and destination slogan that one or more is for example arranged be the identical relation of becoming a partner of communicating by letter all, only keep one and contain this source address, destination address and communicating by letter of the destination slogan relation of becoming a partner, delete all the other and have same source, destination address and communicating by letter of the destination slogan relation of becoming a partner.
Described convergence process can be carried out in the harvester in each node device, for example in one embodiment, described harvester comprises the convergence module, before being used for after collecting the described communication relation of becoming a partner, reporting described analysis generating apparatus, in the communication of the gathering relation of becoming a partner, one or more the relation of becoming a partner of communicating by letter that will have same source, destination address and destination slogan converges one and has this source address, destination address and communicating by letter of the destination slogan relation of becoming a partner.
Described convergence process also can be carried out in described analysis generating apparatus, for example in one embodiment, comprise the convergence module in the described analysis generating apparatus, before the analysis generative process that be used for receiving after the communication relation of becoming a partner that harvester reports, beginning is concrete, in the communication of the gathering relation of becoming a partner, one or more the relation of becoming a partner of communicating by letter that will have same source, destination address and destination slogan converges one and has this source address, destination address and communicating by letter of the destination slogan relation of becoming a partner.
Through after the described convergence process, every communication of gathering relation of becoming a partner all is unique, and its content is all inequality.Data content for becoming a partner and concern through a kind of communication that obtains after the convergence process as follows:
0A00A8C0->0C00A8C00050
0A00A8C0->1500A8C00050
0A00A8C0->7200A8C00050
0A00A8C0->8600A8C00050
0A00A8C0->9700A8C00050
0A00A8C0->9800A8C00050
0A00A8C0->DB00A8C00050
0A00A8C0->DC00A8C00050
0A00A8C0->E800A8C00050
Above-mentioned each row of data is represented a communication relation of becoming a partner, and its data content represents with 16 systems, need convert 10 systems to during generation application layer topological structure to be analyzed.Arrow wherein represents the direction of this communication request, and wherein the arrow left side is source IP address, and the arrow right side is purpose IP address, and the right side of purpose IP address is the destination slogan.
Owing to there is the IP address of outer net (this communication network is as the network outside the IDC machine room) in the communication of the gathering relation of becoming a partner, in one embodiment, in order more accurately to generate the application layer topological structure of this communication network, be not subjected to the data influence of external communication network, can be before the relationship analysis of becoming a partner according to the communication of gathering generates the application layer topological structure, further filter out the communication relation of becoming a partner of non-communication network, detailed process is: determine the address information of this communication network (as this IDC machine room communication network), the address information of described communication network comprises: the address of this machine, address with this machine same network segment, and the address of in the address pool of this communication network, registering; Check source address and destination address in the communication of the gathering relation of becoming a partner afterwards, the communication relation of becoming a partner that will contain the address of this communication network keeps, remaining communication relation of becoming a partner is deleted, the more described communication that the keeps relation of becoming a partner is analyzed the application layer topological structure that generates this communication network afterwards.
In order to realize above-mentioned functions, described harvester comprises filtering module, before being used for after collecting the described communication relation of becoming a partner, reporting described analysis generating apparatus, determine the address information of this communication network, check source address and destination address in the communication of the gathering relation of becoming a partner, the communication relation of becoming a partner that will contain the address of this communication network keeps, and remaining communication relation of becoming a partner is deleted, and the communication that the keeps relation of becoming a partner is reported described analysis generating apparatus.
In step 102, describedly generate the application layer topological structure and specifically can utilize existing directed graph production process to analyze the described communication relation information of becoming a partner according to the communication of the gathering relationship analysis of becoming a partner, and generating corresponding directed graph, the directed graph that generates is exactly the schematic diagram of the application layer topological structure of correspondence.Described directed graph production process for example can be existing grahpviz program, or existing gephi program etc.But before utilizing described directed graph production process analysis generation application layer topological structure, the Data Format Transform of the relation of need further the communication of gathering being become a partner becomes the data format imported of the directed graph production process of appointment, and the relation of becoming a partner of the communication after will changing is input to the directed graph production process of described appointment, and described directed graph production process is carried out concrete analysis generative process and also exported the application layer topological structure.
When specifying the directed graph production process uses as grahpviz, the data format imported of grahpviz is the dot language format, needs earlier described communication the data structure of the relation of becoming a partner to be converted to the dot language format and imports grahpviz again.When specifying the directed graph production process of using to be gephi, a kind of data format of importing that gehpi supports is the excel table format, therefore needs the Data Format Transform of the relation of in advance described communication being become a partner to become the excel table format to import gehpi again.
Corresponding, comprise Data Format Transform module and directed graph production process in the described analysis generating apparatus, wherein: described Data Format Transform module is used for the Data Format Transform of the communication of the gathering relation of becoming a partner is become the data format imported of described directed graph production process, and the relation of becoming a partner of the communication after will changing is input to described directed graph production process; Described directed graph production process is carried out described concrete analysis generative process and is exported the application layer topological structure.
Fig. 4 is the composition schematic diagram of a kind of specific embodiment of the generation system of application layer topological structure in the communication network of the present invention, referring to Fig. 4, gather by the communication of this machine communication relation of becoming a partner in the described harvester, and after collection, utilize convergence module wherein that the communication relation of becoming a partner is carried out convergence process, remove the communication relation of becoming a partner that content repeats, report described analysis generating apparatus afterwards.The unified warehouse-in of the communication that in the described analysis generating apparatus each harvester the is reported relation of becoming a partner, utilize to analyze the node device that module is specified needs to generate the application layer topological structure is set, determine the address of described specified node equipment, check source address and destination address in the communication that the reports relation of becoming a partner, extract the communication relation of becoming a partner that contains described specified node device address; The Data Format Transform of the relation of becoming a partner of the described communication that will be extracted by described data conversion module afterwards becomes the data format imported of described directed graph production process, and the relation of becoming a partner of the communication after will changing is input to described directed graph production process; Described directed graph production process is carried out described concrete analysis generative process and is exported the application layer topological structure.
Fig. 5 is a kind of schematic diagram that utilizes the final application layer topological structure that generates of the present invention.Referring to Fig. 5, it is relation between 192.168.2.7 and two node devices of 192.168.2.5 and the application software thereof that this application layer topological structure has been described the IP address.Wherein, the starting point of arrow is the requesting party of communication request, i.e. source node, this source node identifies by source IP address, the direction of arrow be the requesting party to, the terminal point of arrow is the application service of asking, be destination node, this destination node adds the destination slogan by purpose IP address and identifies.Wherein the starting point of arrow does not have port numbers, and the terminal point of arrow has port numbers.
Compared with prior art, the data basis that the present invention generates described application layer topological structure is not that the topology theory that the developer writes is described document, but the objective communication relation of becoming a partner in the communication network actual motion that can gather automatically, each communication relation of becoming a partner comprises source address, destination address and destination slogan, port numbers wherein is exactly the service label of application software, therefore the present invention also can be based on these communication relation of becoming a partner, automatically analyze the application layer topological structure that generates communication network, and do not need artificial too much intervention, with respect to prior art, the present invention finds and generate the application layer topological structure not to be needed to expend a large amount of manpowers, has reduced the cost of finding and generate the application layer topological structure; Simultaneously, the become a partner correspondence between the current various application software in the communication network that concerned real embodiment of described communication, therefore when safeguarding described application layer topological structure, only need gather and analyze the current application layer topological structure of generation again gets final product, do not need to expend a large amount of manpowers yet, reduced the cost of maintenance application etale topology structure.
In addition, the accuracy of the application layer topological structure that the manual drawing scheme of prior art generates is not high, when exploitation, just describe inaccurately because the topology theory of some application software is described document, service operation after a period of time along with the renewal of application software but corresponding topology theory describe document and do not upgrade, the accuracy on data basis that causes drawing the application layer topological structure is not high, error rate when adding artificial drafting is higher, thus prior art to draw the accuracy of the application layer topological structure that generates not high.But, the data basis that the present invention generates described application layer topological structure is not that the topology theory that the developer writes is described document, but the objective communication relation of becoming a partner in the communication network actual motion, these communications relation of becoming a partner can the actual response communication network in correspondence between the current various application software, not only consistent with the practical application traffic model, and the real-time height, so the accuracy of the application layer topological structure of the communication network that generates of the present invention is higher.
The above only is preferred embodiment of the present invention, and is in order to limit the present invention, within the spirit and principles in the present invention not all, any modification of making, is equal to replacement, improvement etc., all should be included within the scope of protection of the invention.