Summary of the invention
In view of this, main purpose of the present invention is to provide a kind of, to reduce the discovery of application layer topological structure, generation and maintenance cost.
Technical scheme of the present invention is achieved in that
A generation method for application layer topological structure in communication network, comprising:
By analyzing message or gathering the communication communicated by the machine to become a partner relation by analyzing transmission control protocol TCP state table on node device in a communication network, described each communication relation of becoming a partner comprises source address, destination address and destination slogan;
Application layer topological structure is generated according to gathered communication relationship analysis of becoming a partner, concrete analysis generative process comprises: each different source address correspondence of becoming a partner in relation for described communication draws source node, the each different destination address of becoming a partner in relation for described communication adds destination slogan correspondence and draws destination node, and according to described communication become a partner relation source to object requesting party to draw from source node to the requesting party of corresponding destination node to.
A generation system for application layer topological structure in communication network, comprising:
Harvester, arrange on node device in a communication network, for on node device by analyzing message or gathering the communication communicated by the machine to become a partner relation report analysis generating apparatus by analyzing transmission control protocol TCP state table, described each communication relation of becoming a partner comprises source address, destination address and destination slogan;
Analyze generating apparatus, for becoming a partner according to gathered communication, relationship analysis generates application layer topological structure, concrete analysis generative process comprises: each different source address correspondence of becoming a partner in relation for described communication draws source node, the each different destination address of becoming a partner in relation for described communication adds destination slogan correspondence and draws destination node, and according to described communication become a partner relation source to object requesting party to draw from source node to the requesting party of corresponding destination node to.
Compared with prior art, the data basis that the present invention generates described application layer topological structure is not that the topology theory that developer writes describes document, the relation but the objective communication in the communication network actual motion that can automatically gather is become a partner, each communication relation of becoming a partner comprises source address, destination address and destination slogan, port numbers is wherein exactly the service label of application software, therefore the present invention also can based on these relations of becoming a partner that communicates, automatic analysis generates the application layer topological structure of communication network, and do not need artificial too much intervention, relative to prior art, the present invention finds and generate application layer topological structure does not need at substantial manpower, reduce the cost finding and generate application layer topological structure, simultaneously, described communication is become a partner the correspondence in relation real embodiment communication network between current various application software, therefore when safeguarding described application layer topological structure, only need Resurvey and analyze to generate current application layer topological structure, do not need at substantial manpower, reduce the cost of maintenance application etale topology structure yet.
Embodiment
Below in conjunction with drawings and the specific embodiments, the present invention is further described in more detail.
Fig. 1 is the main flow figure of the generation method of application layer topological structure in communication network of the present invention.See Fig. 1, the method comprises:
Step 101, node device (as the machinery equipment such as computer, router) be in a communication network upper to be gathered the communication communicated by the machine (namely by this node device) and to become a partner relation, and described each communication relation of becoming a partner comprises source address, destination address and destination slogan.In an embodiment of the present invention, described source address, destination address specifically refer to source IP address, object IP address.
Step 102, relationship analysis of becoming a partner according to gathered communication generate application layer topological structure, concrete analysis generative process comprises: each different source address correspondence of becoming a partner in relation for described communication draws source node, the each different destination address of becoming a partner in relation for described communication adds destination slogan correspondence and draws destination node, and according to described communication become a partner relation source to object requesting party to draw from source node to the requesting party of corresponding destination node to.
Fig. 2 is the main composition schematic diagram of the generation system of application layer topological structure in communication network of the present invention.See Fig. 2, this system comprises harvester and analyzes generating apparatus:
Described harvester arranges on node device in a communication network, to become a partner relation report analysis generating apparatus for gathering the communication communicated by the machine on node device, described each communication relation of becoming a partner comprises source address, destination address and destination slogan.
Although there is concrete annexation between node device, because the present invention does not limit the actual annexation between described communication network interior joint equipment, the annexation therefore clearly do not drawn between node device in Fig. 2.
Described analysis generating apparatus can be arranged on node device for network management as management server, for becoming a partner according to gathered communication, relationship analysis generates application layer topological structure, concrete analysis generative process comprises: each different source address correspondence of becoming a partner in relation for described communication draws source node, the each different destination address of becoming a partner in relation for described communication adds destination slogan correspondence and draws destination node, and according to described communication become a partner relation source to object requesting party to draw from source node to the requesting party of corresponding destination node to.
In step 101, described harvester gathers the communication relation of becoming a partner communicated by the machine on node device can comprise two kinds of concrete execution modes, one is by analyzing message collection, another kind is by analyzing the collection of transmission control protocol (TCP, TransmissionControlProtocol) state table.
Describedly gather the described communication relation of becoming a partner be specially by analyzing message: the passing message gathering described node device the machine network interface card, specifically comprise the message sent from the machine network interface card and the message received by the machine network interface card, extract source address, destination address and the destination slogan in the message gathered, the source address of a message, destination address and destination slogan are carried out record as the relation of becoming a partner that communicates.Herein can timing acquiring, the time also can specified according to described management server gathers.
Describedly gather the described communication relation of becoming a partner by tcp state table and be specially: the tcp state table inquiring about the native operating system of described node device, this tcp state table gives tacit consent to generation in operating system is as WINDOWS operating system and LINUX operating system, such as, can utilize this tcp state table of netstat command calls in LINUX operating system.The state recording that many represent network service is recorded in described tcp state table, the source address of this network service in every bar state record, destination address and destination slogan, described harvester extracts corresponding source address, destination address and destination slogan from the every bar state record this tcp state table, and the source address of a bar state record, destination address and destination slogan are carried out record as the relation of becoming a partner that communicates.
In the present invention, can find and generate the whole application layer topological structure of certain designated communication network of specifying, also can find and generate the application layer topological structure of local corresponding to the one or more node device of specifying in certain communication network.In communication network management such as IDC machine room, application layer topological structure can be generated to the communication network of whole IDC machine room, also can find for one or several node device in IDC machine room and generate corresponding topical application etale topology structure.
In one embodiment, in order to find and generate the whole application layer topological structure of certain communication network, be specifically as follows in a step 101 and each node device in this communication network (communication network as an IDC machine room) gather the communication communicated by the machine and to become a partner relation, in a step 102, gather communication that each node device gathers to become a partner relation, analyze the whole application layer topological structure generating communication network.
In another embodiment, in order to find and generate application layer topological structure corresponding to one or more node device that in certain communication network, (in the communication network as IDC machine room) specifies, in a step 101 concrete specified node equipment in the communications network can gather the communication being undertaken communicating by this node device to become a partner relation, described specified command can be sent by described analysis generating apparatus.
Fig. 3 a is that collection communication is become a partner a kind of schematic diagram of relation on the node device of specifying.See Fig. 3 a, described analysis generating apparatus can comprise capture setting module 301, this capture setting module 301 is for according to user instruction, collection communication is needed to become a partner the node device of relation in designated communication network, different node devices has different marks, specific node device can be specified by mark, after appointment, acquisition instructions be sent to the described harvester of described specified node equipment (specifying the relation of becoming a partner that communicates of acquisition node equipment 1 and node device 2 in such as this figure); Described harvester to be further used for after receiving described acquisition instructions just gathering on this node device the communication communicated by the machine and to become a partner relation, and reports analysis generating apparatus.The communication that can realize gathering specified node equipment is like this become a partner relation, analyzes the application layer topological structure that the application layer topological structure generated is these specified node equipment.
In another embodiment, in order to find and generate application layer topological structure corresponding to one or more node device that in certain communication network, (in the communication network as IDC machine room) specifies, step 101 each node device in the communications network can be gathered the communication communicated by the machine and to become a partner relation; In a step 102, become a partner after relation collecting communication from node device, can unify to be input in database, then the node device that need generate application layer topological structure is specified according to user instruction, such as can specified node equipment 1 and node device 2, determine the address of described specified node equipment afterwards, check that the communication gathered in database is become a partner source address in relation and destination address, the communication extracted containing described specified node device address is become a partner relation; The communication that follow-up basis contains described specified node device address relationship analysis of becoming a partner generates the application layer topological structure of described specified node equipment.
Fig. 3 b is a kind of schematic diagram of relation of being become a partner by the communication analyzing generating apparatus analysis specified node equipment, see Fig. 3 b, the gathered communication relation of becoming a partner communicated by the machine is reported and gathers to described analysis generating apparatus by the harvester on described each node device; Described analysis generating apparatus comprises analysis and arranges module 302, for specifying the node device that need generate application layer topological structure according to user instruction, determine the address of described specified node equipment, check that described communication is become a partner source address in relation and destination address, the communication extracted containing described specified node device address is become a partner relation; Follow-up described analysis generating apparatus only generates the application layer topological structure of described specified node equipment according to the relationship analysis of becoming a partner of the communication containing described specified node device address.
Communication that a large amount of content repeats may to be had in relation to become a partner relation because the described communication gathered in node device is become a partner, such as may have the source address of one or more, the relation of becoming a partner that communicates that destination address is all identical with destination slogan, therefore in an embodiment of the present invention, can also further before relationship analysis of becoming a partner according to gathered communication generates application layer topological structure, convergence process is carried out to the gathered communication relation of becoming a partner, that is: become a partner in relation in gathered communication, same source will be had, destination address converges one with the relation of becoming a partner that communicates of one or more of destination slogan and has this source address, the relation of becoming a partner that communicates of destination address and destination slogan.If such as there is the relation of becoming a partner that communicates that the source address of one or more, destination address and destination slogan are all identical, only retain a relation of becoming a partner that communicates containing this source address, destination address and destination slogan, delete the relation of becoming a partner that communicates that all the other have same source, destination address and destination slogan.
Described convergence process can perform in the harvester in each node device, such as in one embodiment, described harvester comprises convergence module, for before collecting described communication and becoming a partner after relation, report described analysis generating apparatus, becoming a partner in relation in gathered communication, converging having same source, destination address and the relation of becoming a partner that communicates of one or more of destination slogan the relation of becoming a partner that communicates that has this source address, destination address and destination slogan.
Described convergence process also can perform in described analysis generating apparatus, such as in one embodiment, described analysis generating apparatus comprises convergence module, the communication reported for receiving harvester becomes a partner after relation, start concrete analysis generative process before, becoming a partner in relation in gathered communication, converging having same source, destination address and the relation of becoming a partner that communicates of one or more of destination slogan the relation of becoming a partner that communicates that has this source address, destination address and destination slogan.
After described convergence process, the every bar communication relation of becoming a partner gathered is all unique, and its content is not identical.As followsly to become a partner the data content of relation for a kind of communication of obtaining after convergence process:
0A00A8C0->0C00A8C00050
0A00A8C0->1500A8C00050
0A00A8C0->7200A8C00050
0A00A8C0->8600A8C00050
0A00A8C0->9700A8C00050
0A00A8C0->9800A8C00050
0A00A8C0->DB00A8C00050
0A00A8C0->DC00A8C00050
0A00A8C0->E800A8C00050
Above-mentioned each row of data represents that a communication is become a partner relation, and its data content 16 systems represent, need to convert 10 systems to during generation application layer topological structure to be analyzed.Arrow wherein represents the direction of this communication request, is wherein source IP address on the left of arrow, IP address for the purpose of on the right side of arrow, port numbers for the purpose of the right side of object IP address.
Become a partner due to gathered communication and there is the IP address of outer net (this communication network is as the network outside IDC machine room) in relation, in one embodiment, in order to more accurately give birth to the application layer topological structure of cost communications network, not by the data influence of external communication network, can before relationship analysis of becoming a partner according to gathered communication generates application layer topological structure, the communication filtering out non-communication network is further become a partner relation, detailed process is: the address information determining this communication network (as this IDC machine room communication network), the address information of described communication network comprises: the address of the machine, with the address of the machine same network segment, and in the address pool of this communication network registered address, check that gathered communication is become a partner source address in relation and destination address afterwards, by the communication of the address containing this communication network, relation of becoming a partner retains, remaining communication relation of becoming a partner is deleted, again the retained described communication relation of becoming a partner is analyzed to the application layer topological structure of raw cost communications network afterwards.
In order to realize above-mentioned functions, described harvester comprises filtering module, for before collecting described communication and becoming a partner after relation, report described analysis generating apparatus, determine the address information of this communication network, check that gathered communication is become a partner source address in relation and destination address, by the communication of the address containing this communication network, relation of becoming a partner retains, and remaining communication relation of becoming a partner is deleted, the communication relation of becoming a partner of reservation is reported described analysis generating apparatus.
In a step 102, describedly generate application layer topological structure existing directed graph production process specifically can be utilized to analyze described communication to become a partner relation information according to gathered communication relationship analysis of becoming a partner, and generating corresponding directed graph, the directed graph generated is exactly the schematic diagram of corresponding application layer topological structure.Described directed graph production process can be such as existing grahpviz program, or existing gephi program etc.But before utilizing described directed graph production process analysis generation application layer topological structure, the inputted data format of the directed graph production process needing the Data Format Transform of further gathered communication being become a partner relation to become to specify, and the communication relation of becoming a partner after conversion is input to described directed graph production process of specifying, described directed graph production process performs concrete analysis generative process and exports application layer topological structure.
When specifying the directed graph production process of use for grahpviz, the inputted data format of grahpviz is dot language format, needs the data structure of relation of first described communication being become a partner to be converted to dot language format and inputs grahpviz again.When specifying the directed graph production process used to be gephi, it is excel table format that the one that gehpi supports can input data format, therefore needs the Data Format Transform of relation of described communication being become a partner in advance to become excel table format to input gehpi again.
Corresponding, described analysis generating apparatus comprises data format conversion module and directed graph production process, wherein: the Data Format Transform that described data format conversion module is used for relation of gathered communication being become a partner becomes the inputted data format of described directed graph production process, and the communication relation of becoming a partner after conversion is input to described directed graph production process; Described directed graph production process performs described concrete analysis generative process and exports application layer topological structure.
Fig. 4 is the composition schematic diagram of a kind of specific embodiment of the generation system of application layer topological structure in communication network of the present invention, see Fig. 4, gather the communication communicated by the machine in described harvester to become a partner relation, and utilize convergence module wherein to carry out convergence process to the communication relation of becoming a partner after acquisition, remove the communication that content repeats to become a partner relation, report described analysis generating apparatus afterwards.The unified warehouse-in of relation of in described analysis generating apparatus, the communication that each harvester reports being become a partner, utilize to analyze and the node device that module appointment need generate application layer topological structure is set, determine the address of described specified node equipment, check that reported communication is become a partner source address in relation and destination address, the communication extracted containing described specified node device address is become a partner relation; Become the inputted data format of described directed graph production process by the described communication extracted the to be become a partner Data Format Transform of relation of described data conversion module afterwards, and the communication relation of becoming a partner after conversion is input to described directed graph production process; Described directed graph production process performs described concrete analysis generative process and exports application layer topological structure.
Fig. 5 is the schematic diagram of the application layer topological structure that a kind of the present invention of utilization finally generates.See Fig. 5, it is relation between 192.168.2.7 and 192.168.2.5 two node devices and application software thereof that this application layer topological structure describes IP address.Wherein, the starting point of arrow is the requesting party of communication request, i.e. source node, this source node is identified by source IP address, the direction of arrow be requesting party to, the terminal of arrow is asked application service, i.e. destination node, this destination node adds destination slogan to identify by object IP address.Wherein the starting point of arrow does not have port numbers, and the terminal of arrow is with port numbers.
Compared with prior art, the data basis that the present invention generates described application layer topological structure is not that the topology theory that developer writes describes document, the relation but the objective communication in the communication network actual motion that can automatically gather is become a partner, each communication relation of becoming a partner comprises source address, destination address and destination slogan, port numbers is wherein exactly the service label of application software, therefore the present invention also can based on these relations of becoming a partner that communicates, automatic analysis generates the application layer topological structure of communication network, and do not need artificial too much intervention, relative to prior art, the present invention finds and generate application layer topological structure does not need at substantial manpower, reduce the cost finding and generate application layer topological structure, simultaneously, described communication is become a partner the correspondence in relation real embodiment communication network between current various application software, therefore when safeguarding described application layer topological structure, only need Resurvey and analyze to generate current application layer topological structure, do not need at substantial manpower, reduce the cost of maintenance application etale topology structure yet.
In addition, the accuracy of the application layer topological structure that the manual drawing scheme of prior art generates is not high, just describe inaccurate because the topology theory of some application software describes document when developing, along with the renewal of application software but the topology theory of correspondence describes document does not upgrade after service operation a period of time, cause the accuracy on the data basis of drawing application layer topological structure not high, error rate when adding artificial drafting is higher, and the accuracy of the application layer topological structure of therefore prior art drafting generation is not high.But, the data basis that the present invention generates described application layer topological structure is not that the topology theory that developer writes describes document, the relation but the objective communication in communication network actual motion is become a partner, these communication relations of becoming a partner can correspondence in actual response communication network between current various application software, not only consistent with practical application traffic model, and real-time is high, therefore the accuracy of the application layer topological structure of communication network that generates of the present invention is higher.
The foregoing is only preferred embodiment of the present invention, not in order to limit the present invention, within the spirit and principles in the present invention all, any amendment made, equivalent replacement, improvement etc., all should be included within the scope of protection of the invention.