CN103546343B - The network traffics methods of exhibiting of network traffic analysis system and system - Google Patents

The network traffics methods of exhibiting of network traffic analysis system and system Download PDF

Info

Publication number
CN103546343B
CN103546343B CN201310493586.5A CN201310493586A CN103546343B CN 103546343 B CN103546343 B CN 103546343B CN 201310493586 A CN201310493586 A CN 201310493586A CN 103546343 B CN103546343 B CN 103546343B
Authority
CN
China
Prior art keywords
analysis system
network traffic
data
traffic analysis
network
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Expired - Fee Related
Application number
CN201310493586.5A
Other languages
Chinese (zh)
Other versions
CN103546343A (en
Inventor
张思拓
吴柳
谢尧
杨俊权
洪丹轲
魏畅
李昭桦
卓越
程小蓉
李阳
张宇清
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Southern Power Grid Co Ltd
China Energy Engineering Group Guangdong Electric Power Design Institute Co Ltd
Original Assignee
China Southern Power Grid Co Ltd
China Energy Engineering Group Guangdong Electric Power Design Institute Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Southern Power Grid Co Ltd, China Energy Engineering Group Guangdong Electric Power Design Institute Co Ltd filed Critical China Southern Power Grid Co Ltd
Priority to CN201310493586.5A priority Critical patent/CN103546343B/en
Publication of CN103546343A publication Critical patent/CN103546343A/en
Application granted granted Critical
Publication of CN103546343B publication Critical patent/CN103546343B/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Abstract

A kind of network traffics methods of exhibiting and system of network traffic analysis system, wherein method include step:The analytical data of each network traffic analysis system is obtained, different identification of the same analytical data in heterogeneous networks flow analysis system is converted to into same mark, generate the mapped file of each network traffic analysis system;Obtain the unit type data in network traffic analysis system to be converted;Data acquisition modes are judged with the model data list for prestoring according to the unit type data of the acquisition;Analytical data in network traffic analysis system to be converted is obtained according to the acquisition mode, and the analytical data in the network traffic analysis system to be converted is carried out by protocol conversion according to the unit type data, the acquisition mode and the mapped file, obtain transformational analysis data;The transformational analysis data are shown.By present invention achieves while showing the analytical data of different system output.

Description

The network traffics methods of exhibiting of network traffic analysis system and system
Technical field
The present invention relates to the network traffics displaying side of technical field of network communication, more particularly to network traffic analysis system Method and system.
Background technology
As the continuous development of information age, network size day by day increase, the application of network is intricate, network speed and flow Grow at top speed, need by reliable, effective network traffic analysis system, all kinds of business carried to network and network are entered Timely, the accurate flow of row and flow direction analysis.
In conventional art, network traffic analysis system includes three parts, the network equipment, flow collection equipment, flow point Analysis system.Handling process:Packet enters the network equipment;The network equipment passes through dividing technology, there is provided a shunting link is to stream Amount collecting device.Shunting link can realize using beam splitter that the link segmentation that two switches are connected by beam splitter is a part of Light source gives third party's access device, to provide the data acquisition of other analytical equipments, and ensure that the data of original link Transmission;Mirror port can also be adopted, for the network equipment of Support Port Mirroring, flow collection equipment can be received from mirror port Collection network traffic information.Packet is sent to flow analysis system by flow collection equipment, is analyzed, and exports analytical data.
However, each network traffic analysis system often carries out analysis of network using special form, it is due to system difference, defeated Go out result different.Such as, large enterprise often disposes multiple network traffic analysis systems, the output of heterogeneous networks flow analysis system Analytical data cannot be shown simultaneously.
The content of the invention
Based on this, it is necessary to for the problem that the analytical data of different system output cannot be shown simultaneously, there is provided one Plant the network traffics methods of exhibiting and system of network traffic analysis system.
A kind of network traffics methods of exhibiting of network traffic analysis system, including step:
The analytical data of each network traffic analysis system is obtained, by same analytical data in heterogeneous networks flow analysis system In different identification be converted to same mark, generate the mapped file of each network traffic analysis system;
Obtain the unit type data in network traffic analysis system to be converted;
Data acquisition modes are judged with the model data list for prestoring according to the unit type data of the acquisition, wherein, Acquisition mode includes proprietary protocol acquisition mode, file transfer protocol (FTP) acquisition mode, Web Service agreement acquisition modes, type The model data of each network traffic analysis system and the mapping relations of acquisition mode are recorded in number list;
Analytical data in network traffic analysis system to be converted is obtained according to the acquisition mode, and according to the equipment Analytical data in the network traffic analysis system to be converted is entered by model data, the acquisition mode and the mapped file Row protocol conversion, obtains transformational analysis data;
The transformational analysis data are shown.
A kind of network traffics display systems of network traffic analysis system, including:
Mapped file generation module, for obtaining the analytical data of each network traffic analysis system, by same analytical data Different identification in heterogeneous networks flow analysis system is converted to same mark, generates the mapping of each network traffic analysis system File;
Acquisition module, for obtaining the unit type data in network traffic analysis system to be converted;
Judge module, for judging that data are adopted according to the unit type data of the acquisition and the model data list for prestoring Mode set, wherein, acquisition mode includes proprietary protocol acquisition mode, file transfer protocol (FTP) acquisition mode, Web Service agreements Acquisition mode, the mapping of model data and acquisition mode that each network traffic analysis system is recorded in model data list are closed System;
Acquisition module, is additionally operable to the analysis number in network traffic analysis system to be converted is obtained according to the acquisition mode According to;
First modular converter, for according to the unit type data, the acquisition mode and the mapped file by institute Stating the analytical data in network traffic analysis system to be converted carries out protocol conversion, obtains transformational analysis data;
Display module, for the transformational analysis data are shown.
The network traffics methods of exhibiting and system of above-mentioned network traffic analysis system, by first by same analytical data not Same mark is converted to the different identification in network traffic analysis system, the mapping text of each network traffic analysis system is generated Part.Then, the unit type data in network traffic analysis system to be converted are obtained, acquisition mode is determined, collection analysises data, Then the analytical data for treating switching network flow analysis system further according to mapped file carries out protocol conversion and shows.The present invention By proprietary protocol acquisition mode, file transfer protocol (FTP) acquisition mode, Web Service agreements three kinds of acquisition modes of acquisition mode Analytical data is changed by collection analysises data by mapped file, is converted to unified form, is realized while showing not The analytical data of homologous ray output, so as to reduce the maintenance work amoun of user, improves the network operation efficiency of management, while being easy to prison Control analytical data.
Description of the drawings
Schematic flow sheets of the Fig. 1 for the network traffics methods of exhibiting embodiment of inventive network flow analysis system;
Schematic flow sheets of the Fig. 2 for the network traffics display systems embodiment of inventive network flow analysis system.
Specific embodiment
Carry out below for each embodiment of the network traffics methods of exhibiting and system of inventive network flow analysis system Detailed description.
As shown in figure 1, the flow process for the network traffics methods of exhibiting embodiment of inventive network flow analysis system is illustrated Figure, including:
Step S101:The analytical data of each network traffic analysis system is obtained, by same analytical data in heterogeneous networks stream Different identification in amount analysis system is converted to same mark, generates the mapped file of each network traffic analysis system;Wherein, divide Analysis data refer to the analysis result that network traffic analysis system is obtained after being analyzed to network traffics, the such as bit error rate, network Response delay, number of dropped packets etc..Same analytical data mark often in heterogeneous networks flow analysis system is different, this step Purpose is to unify to be same mark by all same analysis data corresponding different identification, generates each network traffic analysis system Mapped file.Mapped file can be that each network traffic analysis system is distinguished one, or divides each network traffics The mapped file of analysis system assembles a total mapped file, equivalent to a protocol conversion dictionary.
For example, wherein in one embodiment, by proprietary protocol, file transfer protocol (FTP), three kinds of Web Service agreements Acquisition mode obtains the analytical data of each network traffic analysis system;
Different identification is converted to into same mark, wherein different identification is same analytical data in heterogeneous networks flow analysis Mark in system;
The mapped file of each network traffic analysis system is generated according to transformational relation.
Step S102:Obtain the unit type data in network traffic analysis system to be converted;
Step S103:Data acquisition modes are judged according to the unit type data for obtaining and the model data list for prestoring, Wherein, acquisition mode includes proprietary protocol acquisition mode, file transfer protocol (FTP) acquisition mode, Web Service agreements collection side Formula, records the model data of each network traffic analysis system and the mapping relations of acquisition mode in model data list;
Step S104:Analytical data in network traffic analysis system to be converted is obtained according to acquisition mode;
Wherein, acquisition mode can include proprietary protocol acquisition mode, file transfer protocol (FTP) acquisition mode, Web Service agreement acquisition modes.FTP(File Transfer Protocal)During i.e. file transfer protocol (FTP) is ICP/IP protocol group One of agreement, be the basis of Internet files transmission, it is made up of a series of specification documents, and target is to improve file Sharing, there is provided non-immediate use remote computer, make storage medium transparent to user and reliably and effectively transmit data. Web service are network, distributed modular assemblies, and it is outwardly provided one and can be adjusted by Web API, can obtain the information of needs by calling this API.Web Services mainly utilize HTTP and soap protocol Business data is made to transmit on Web, SOAP calls business object to perform remote functionality by HTTP and calls, and Web user can make The method called by Web with SOAP and HTTP is calling remote object.WSDL is the description language of Web Service, is one IDL is planted, for describing interface message of Web Service etc..
Wherein, can be included using proprietary protocol acquisition mode gathered data step:
In one traffic analyzer of network traffic analysis system deployment, the program can make regular check on database file renewal Situation.
After traffic analyzer finds that database file updates, initiated more to data acquisition process by socket communication New command.
When data acquisition process receives more new command, it will startup file download instruction, by data from network traffics point The data base of analysis system derives,
Data acquisition process carries out text resolution.Finally insert data in data base, realize collection.
Wherein, can be included using file transfer protocol (FTP) acquisition mode gathered data step:
Network traffic analysis system generates data file according to the interface rules timing for defining, and uploads to what is specified Ftp server catalogue.
Agent programs are according to FTP Client by ftp server IP, user name, code entry to ftp server timing Poll ftp server file update status.
After agent programs find that ftp server file updates, will be downloaded the file into by FTP Client is locally carried out Parsing.
Agent programs carry out protocol conversion to the data downloaded, and parsing is sent to after becoming satisfactory data form Data base.
Delete after the completion of loading on ftp server and downloaded the file for completing.
This mode belongs to the form of question-response.
Wherein, can be included using Web Service agreement acquisition mode gathered data steps:
Network traffic analysis system releases news the Web service interfaces of inquiry, and provides corresponding WSDL (Web Service description languages).
Web service_agent programs describe document according to WSDL, generate a SOAP request message and issue network flow Amount analysis system.
Network traffic analysis system produces response message according to solicited message and returns to Web service_agent.
Web service_agent are parsed to the response message for obtaining, and carry out protocol conversion, and parsing becomes and conforms to Data base is sent to after the data form asked.
This mode falls within the form of question-response.
Step S105:According to unit type data, acquisition mode and mapped file by network traffic analysis system to be converted In analytical data carry out protocol conversion, obtain transformational analysis data;Wherein, mapped file includes the collection side of analytical data Formula, can also include unit type data certainly, therefore can be according to unit type data, acquisition mode correspondence in mapped file In find matching identification and changed.
Step S106:Transformational analysis data are shown.
Wherein, step S101 can be not limited in first step between any step before step S105.
Wherein in one embodiment, obtain transformational analysis data after, by transformational analysis data be shown step it Before, also include:Transformational analysis data are classified and traffic statistics class list, performance statisticses class list is generated, flow is united Meter class list, performance statisticses class list are stored.Wherein, traffic statistics class list includes the traffic statistics of probe physical interface Table, probe physical interface flow and error statistic table, application traffic statistics table, communication to traffic statistics table, performance statisticses Class list is included based on the communication under concrete application to response delay table statistical table, using response delay table statistical table, based on tool Server response delay table statistical table under body application, based on the response sample distribution table statistical table of concrete application, based on concrete Using network transfer delay table statistical table, based on application Fault Distribution table statistical table.By these change datas are carried out After sorting out storage, facilitate subsequent query and displaying, while being easy to monitoring data.
Wherein in one embodiment, obtain unit type data step in network traffic analysis system to be converted it Afterwards, also include:
Attribute information, interface message according to unit type data acquisition network traffic analysis system;
The device signal data of network traffic analysis system, attribute information, interface message are stored;
The device signal data of network traffic analysis system, attribute information, interface message are shown.
Wherein in one embodiment, to the various error message feedback error results run in processing procedure.Such as, when When obtaining the unit type data failure in network traffic analysis system to be converted, response correspondence failure information;Such as access Network traffic analysis system is not identified, and the equipment of access is not that network traffic analysis system or access device are not powered on Deng.
And/or
When analytical data in network traffic analysis system to be converted is obtained fails, response correspondence failure information;Such as The reason for failing in gatherer process etc..
And/or
When analytical data protocol conversion fails, response correspondence failure information.
By feedback error result, the reason for displaying fails can be clearly understood that and corresponding solution is carried out.
In a concrete application example, in order to realize the unified management and displaying of heterogeneous networks flow analysis system, this The model of invention automatic identification network traffic analysis system, is stored in the probe management class table of present invention definition, needed for collection Technical parameter, through the mapped file of the invention, realize each collection skill of the network traffic analysis system manufacturers of main flow The parsing of art parameter, is stored in the list of traffic statistics class and performance statisticses class list of present invention definition, realizes flow analysis The unification of index is regular, then carries out unifying to show by the content of the list of traffic statistics class and performance statisticses class list.So that adopting Can unify to show specific acquisition technique parametric results with the network traffic analysis system of different specialized protocols.
The method for converting protocol is realized according to " proprietary protocol ", " FTP interfaces ", three kinds of modes of " Web service " interface The access of the statistical index data of different flow analysis producer, then carries out that data are regular, it is most regular at last after data provide Show interface to unified.
According to definition and identification means of the mainstream network flow analysis system to different analytical data, work out through arrangement A mapped file, from identification any one network traffic analysis system in gathered data, by collection data mark Translation is converted to the unified mark of correspondence.Concrete steps can be as follows:
S1:Initially set up mapped file.The analytical data of each network traffic analysis system is obtained, same analytical data is existed Different identification in heterogeneous networks flow analysis system is converted to same mark, generates the mapping text of each network traffic analysis system Part.
S2:Collection is polled to each network traffic analysis system, by snmp protocol with the network flow that connected Amount analysis system is interacted, and determines the model of system.It is if successfully recognizing the model of network traffic analysis system, into S3, no S8 is entered then;
S3:The model of identification network traffic analysis system, by relevant information write probe management class table;
S4:The model of the network traffic analysis system preserved according to probe management category, is defined as network traffic analysis system The acquisition mode of system gathered data, is divided into " proprietary protocol ", " FTP interfaces ", three kinds of modes of " Web service " interface, realizes The access of the analytical data of different flow analysis system;
S5:Judge whether data acquisition is successful, by " proprietary protocol ", " FTP interfaces ", " Web service " interface three After any one mode of the mode of kind is acquired, such as gather successfully, into S6, otherwise into S8;
S6:The data of parsing collection, with reference to specific model and specific acquisition mode, by the mapped file for having woven Parsed, such as successfully parse, the data for having parsed are saved in the list of traffic statistics class and performance statisticses class list, it is regular Data, into S7;S8 is entered otherwise;
S7:Unified display data, according to the information for being stored in the list of traffic statistics class and performance statisticses class list, is receiving The lower output corresponding data of instruction, can both be many index of same branded network flow analysis system, it is also possible to which contrast is different The index identical with one or more of branded network flow analysis system;If displaying is unsuccessful, into S8;
S8:Process various error messages, feedback error result.
From the error message of step S2 transmission, the reason for feedback polling is failed, the network traffic analysis system for such as accessing It is not identified, the equipment of access is not network traffic analysis system, or access device is not started shooting etc..
From the error message of step S5 transmission, by the reason for feedback data collection failure.
From the error message of step S6 transmission, by the reason for feedback data parsing failure.
From the error message of step S7 transmission, feedback data is shown into the reason for failing.
Wherein, as shown in table 1, traffic statistics class list can include:" Link_overtime tables ", " Link_ Snapshot tables ", " topapp_overtime tables " and " topalconv_overtime tables ".
Table 1
Data table name Description Remarks
Link_overtime The traffic statistics of probe physical interface Statistics granularity:1 minute
Link_snapshot Probe physical interface flow and error statistic Statistics granularity:15 minutes
Topapp_overtime The traffic statistics of top N applications Statistics granularity:1 minute
Topalconv_overtime top N IP communication to traffic statistics Statistics granularity:15 minutes
1.1 Link_overtime tables of table
1.2 Link_snapshot tables of table
1.3 Topapp_overtime tables of table
1.4 Topalconv_overtime tables of table
As shown in table 2, performance statisticses class list can include " Appflows_overtime tables ", " Allapp_ Overtime tables ", " Allserver_overtime tables ", " Resptimedist_overtime tables ", " Flighttot_ Overtime tables " and " Errordistot_overtime tables ".
Table 2
Data table name Description Remarks
Appflows_overtime Based on the communication under concrete application to response delay table Statistics granularity:15 minutes
Allapp_overtime Using response delay table Statistics granularity:15 minutes
Allserver_overtime Based on the server response delay table under concrete application Statistics granularity:15 minutes
Resptimedist_overtime Response delay distribution table based on concrete application Statistics granularity:15 minutes
Flighttot_overtime Network transfer delay table based on concrete application Statistics granularity:15 minutes
Errordistot_overtime Fault Distribution table based on application Statistics granularity:15 minutes
2.1 Appflows_overtime tables of table
2.2 Allapp_overtime tables of table
2.3 Allappserver_overtime tables of table
2.4 Resptimedist_overtime tables of table
2.5 Flighttot_overtime tables of table
2.6 ErrorDistOt_overtime tables of table
As shown in table 3, probe management class table can be:
3.1 Probe_management of table manages table
Id Major key, is incremented by automatically
Probe_vender_id Probe producer indicates
Probe_server_name Probe manages server name
Probe_name Probe title
Probe_server_area Probe manages server zone title
Probe_area Probe area title
Probe_server_ip Probe manages server ip address
Probe_ip Probe I P address
Probe_physical The physics packet capturing interface of probe
Probe_logic The logic packet capturing interface of probe
Onlinestatus Equipment on-line state
Probe_server_user Probe management software logins account
Probe_server_pwd Probe management software logins password
create_time Creation time
Contact Contact person
Contact_way Telephone number
The present invention program designs a kind of methods of exhibiting, there is provided the unified management and displaying of heterogeneous networks flow analysis system, The maintenance work amoun of user is reduced, the network operation efficiency of management is improved
According to said method, the present invention also provides a kind of network traffics display systems of network traffic analysis system, such as Fig. 2 It is shown, it is the structural representation of the network traffics display systems embodiment of inventive network flow analysis system, including:
Mapped file generation module 201, for obtaining the analytical data of each network traffic analysis system, by same analysis number Same mark is converted to according to the different identification in heterogeneous networks flow analysis system, reflecting for each network traffic analysis system is generated Penetrate file;
Acquisition module 202, for obtaining the unit type data in network traffic analysis system to be converted;
Judge module 203, for judging that data are adopted according to the unit type data for obtaining and the model data list for prestoring Mode set, wherein, acquisition mode includes proprietary protocol acquisition mode, file transfer protocol (FTP) acquisition mode, Web Service agreements Acquisition mode, the mapping of model data and acquisition mode that each network traffic analysis system is recorded in model data list are closed System;
Acquisition module 202, is additionally operable to the analytical data in network traffic analysis system to be converted is obtained according to acquisition mode;
First modular converter 204, for according to unit type data, acquisition mode and mapped file by network flow to be converted Analytical data in amount analysis system carries out protocol conversion, obtains transformational analysis data;
Display module 205, for transformational analysis data are shown.
Wherein in one embodiment, mapped file generation module includes:
Acquisition module, for being adopted by proprietary protocol, file transfer protocol (FTP), three kinds of acquisition modes of Web Service agreements Collect the analytical data of each network traffic analysis system;
Second modular converter, for different identification is converted to same mark, wherein different identification is same analytical data Mark in heterogeneous networks flow analysis system;
Generation module, for the mapped file of each network traffic analysis system is generated according to transformational relation.
Wherein in one embodiment, also including memory module, for transformational analysis data are classified and stream is generated Amount statistics class list, performance statisticses class list, traffic statistics class list, performance statisticses class list are stored,
Wherein, traffic statistics class list includes traffic statistics table, probe physical interface flow and the difference of probe physical interface Wrong statistical table, the traffic statistics table of application, communication to traffic statistics table, performance statisticses class list includes based under concrete application Communication to response delay table statistical table, using response delay table statistical table, based on the server response delay under concrete application Table statistical table, based on concrete application response sample distribution table statistical table, based on concrete application network transfer delay table count Table, the Fault Distribution table statistical table based on application.
Wherein in one embodiment, also including feedback information module, it is used for:
When the unit type data failure in acquisition network traffic analysis system to be converted, response correspondence failure information;
And/or
When analytical data in network traffic analysis system to be converted is obtained fails, response correspondence failure information;
And/or
When analytical data protocol conversion fails, response correspondence failure information.
The network traffics display systems of the network traffic analysis system of the present invention and network traffic analysis system of the invention Network traffics methods of exhibiting be one-to-one, in the network traffics methods of exhibiting embodiment of above-mentioned network traffic analysis system Correlation technique feature and its technique effect suitable for the network traffics display systems embodiment of network traffic analysis system, Will not be described here.
Embodiment described above only expresses the several embodiments of the present invention, and its description is more concrete and detailed, but and Therefore the restriction to the scope of the claims of the present invention can not be interpreted as.It should be pointed out that for one of ordinary skill in the art For, without departing from the inventive concept of the premise, some deformations and improvement can also be made, these belong to the guarantor of the present invention Shield scope.Therefore, the protection domain of patent of the present invention should be defined by claims.

Claims (10)

1. a kind of network traffics methods of exhibiting of network traffic analysis system, it is characterised in that including step:
The analytical data of each network traffic analysis system is obtained, by same analytical data in heterogeneous networks flow analysis system Different identification is converted to same mark, generates the mapped file of each network traffic analysis system;
Obtain the unit type data in network traffic analysis system to be converted;
Data acquisition modes are judged with the model data list for prestoring according to the unit type data of the acquisition, wherein, collection Mode includes proprietary protocol acquisition mode, file transfer protocol (FTP) acquisition mode, Web Service agreement acquisition modes, model number According to the model data of each network traffic analysis system and the mapping relations of acquisition mode are recorded in list;
Analytical data in network traffic analysis system to be converted is obtained according to the acquisition mode, and according to the unit type Analytical data in the network traffic analysis system to be converted is assisted by data, the acquisition mode and the mapped file View conversion, obtains transformational analysis data;
The transformational analysis data are shown.
2. the network traffics methods of exhibiting of network traffic analysis system according to claim 1, it is characterised in that described to obtain The analytical data of each network traffic analysis system is taken, the different marks by same analytical data in heterogeneous networks flow analysis system Knowledge is converted to same mark, generates the mapped file step of each network traffic analysis system, including:
Each network traffic analysis system is obtained by proprietary protocol, file transfer protocol (FTP), three kinds of acquisition modes of Web Service agreements The analytical data of system;
Different identification is converted to into same mark, wherein different identification is same analytical data in heterogeneous networks flow analysis system In mark;
The mapped file of each network traffic analysis system is generated according to transformational relation.
3. the network traffics methods of exhibiting of network traffic analysis system according to claim 1, it is characterised in that it is described will Before the transformational analysis data are shown step, also include:The transformational analysis data are classified and generated flow Statistics class list, performance statisticses class list, traffic statistics class list, performance statisticses class list are stored.
4. the network traffics methods of exhibiting of network traffic analysis system according to claim 3, it is characterised in that
The traffic statistics class list includes traffic statistics table, probe physical interface flow and the error statistic of probe physical interface Table, the traffic statistics table of application, communication to traffic statistics table, the performance statisticses class list includes based under concrete application Communication is to response delay table statistical table, using response delay table statistical table, based on the server response delay table under concrete application Statistical table, based on concrete application response sample distribution table statistical table, based on the network transfer delay table statistical table of concrete application, Fault Distribution table statistical table based on application.
5. the network traffics methods of exhibiting of network traffic analysis system as claimed in any of claims 1 to 4, which is special Levy and be,
After the unit type data step obtained in network traffic analysis system to be converted, also include:
Attribute information, interface message according to unit type data acquisition network traffic analysis system;
The device signal data of network traffic analysis system, attribute information, interface message are stored;
The device signal data of network traffic analysis system, attribute information, interface message are shown.
6. the network traffics methods of exhibiting of network traffic analysis system as claimed in any of claims 1 to 4, which is special Levy and be,
When the unit type data failure in acquisition network traffic analysis system to be converted, response correspondence failure information;
And/or
When analytical data in network traffic analysis system to be converted is obtained fails, response correspondence failure information;
And/or
When analytical data protocol conversion fails, response correspondence failure information.
7. a kind of network traffics display systems of network traffic analysis system, it is characterised in that include:
Mapped file generation module, for obtaining the analytical data of each network traffic analysis system, by same analytical data not Same mark is converted to the different identification in network traffic analysis system, the mapping text of each network traffic analysis system is generated Part;
Acquisition module, for obtaining the unit type data in network traffic analysis system to be converted;
Judge module, for judging data acquisition side according to the unit type data of the acquisition and the model data list for prestoring Formula, wherein, acquisition mode includes proprietary protocol acquisition mode, file transfer protocol (FTP) acquisition mode, the collection of Web Service agreements Mode, records the model data of each network traffic analysis system and the mapping relations of acquisition mode in model data list;
Acquisition module, is additionally operable to the analytical data in network traffic analysis system to be converted is obtained according to the acquisition mode;
First modular converter, for being treated described according to the unit type data, the acquisition mode and the mapped file Analytical data in switching network flow analysis system carries out protocol conversion, obtains transformational analysis data;
Display module, for the transformational analysis data are shown.
8. network traffics display systems of network traffic analysis system according to claim 7, it is characterised in that described to reflect Penetrating file generating module includes:
Acquisition module, for each by proprietary protocol, file transfer protocol (FTP), the three kinds of acquisition mode collections of Web Service agreements The analytical data of network traffic analysis system;
Second modular converter, for different identification is converted to same mark, wherein different identification is same analytical data not With the mark in network traffic analysis system;
Generation module, for the mapped file of each network traffic analysis system is generated according to transformational relation.
9. network traffics display systems of network traffic analysis system according to claim 7, it is characterised in that also include Memory module, for the transformational analysis data are classified and traffic statistics class list, performance statisticses class list is generated, will Traffic statistics class list, performance statisticses class list are stored,
Wherein, the traffic statistics class list includes traffic statistics table, probe physical interface flow and the difference of probe physical interface Wrong statistical table, the traffic statistics table of application, communication to traffic statistics table, the performance statisticses class list includes based on specifically should Communication with is responded to response delay table statistical table, using response delay table statistical table, based on the server under concrete application Time delay table statistical table, based on concrete application response sample distribution table statistical table, the network transfer delay table based on concrete application Statistical table, the Fault Distribution table statistical table based on application.
10. network traffics display systems of the network traffic analysis system according to any one in claim 7 to 9, its It is characterised by, also including feedback information module, is used for:
When the unit type data failure in acquisition network traffic analysis system to be converted, response correspondence failure information;
And/or
When analytical data in network traffic analysis system to be converted is obtained fails, response correspondence failure information;
And/or
When analytical data protocol conversion fails, response correspondence failure information.
CN201310493586.5A 2013-10-18 2013-10-18 The network traffics methods of exhibiting of network traffic analysis system and system Expired - Fee Related CN103546343B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201310493586.5A CN103546343B (en) 2013-10-18 2013-10-18 The network traffics methods of exhibiting of network traffic analysis system and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201310493586.5A CN103546343B (en) 2013-10-18 2013-10-18 The network traffics methods of exhibiting of network traffic analysis system and system

Publications (2)

Publication Number Publication Date
CN103546343A CN103546343A (en) 2014-01-29
CN103546343B true CN103546343B (en) 2017-03-29

Family

ID=49969418

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201310493586.5A Expired - Fee Related CN103546343B (en) 2013-10-18 2013-10-18 The network traffics methods of exhibiting of network traffic analysis system and system

Country Status (1)

Country Link
CN (1) CN103546343B (en)

Families Citing this family (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104869026B (en) * 2014-02-24 2019-08-23 大唐软件技术股份有限公司 Method, access device and gateway for the detection of local area network background traffic
CN105490865A (en) * 2014-09-17 2016-04-13 中兴通讯股份有限公司 Method and device for implementing flow analysis
CN107508721B (en) * 2017-08-01 2018-11-02 南京云利来软件科技有限公司 A kind of collecting method based on metadata
CN107634848B (en) * 2017-08-07 2020-10-27 上海天旦网络科技发展有限公司 System and method for collecting and analyzing network equipment information
CN107846460B (en) * 2017-10-30 2020-09-25 中国人民解放军战略支援部队航天工程大学 System and method for reproducing information flow of military information system
CN108156051A (en) * 2017-12-12 2018-06-12 上海天旦网络科技发展有限公司 Analyzing network data information shows method and system
CN109584668A (en) * 2018-12-29 2019-04-05 中铁工程装备集团有限公司 A kind of rock tunnel(ling) machine training platform based on virtual reality and big data
CN110913287A (en) * 2019-12-23 2020-03-24 北京首都在线科技股份有限公司 Signal processing method and system and light splitting equipment applied to method and system
CN112350882A (en) * 2020-09-28 2021-02-09 广东电力信息科技有限公司 Distributed network traffic analysis system and method
CN112333020B (en) * 2020-11-03 2023-07-21 广东电网有限责任公司 Network security monitoring and data message analysis system based on quintuple
CN115277477B (en) * 2022-07-24 2024-03-01 杭州迪普科技股份有限公司 Flow detection method and device based on simple object access protocol
CN115278737B (en) * 2022-07-29 2023-03-14 深圳市深玛网络科技有限公司 Data acquisition method of 5G network

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102422596A (en) * 2009-05-07 2012-04-18 意法半导体(格勒诺布尔2)公司 Method and device for analyzing transaction propagation in a multiprotocol network of a system on chip
CN102638378A (en) * 2012-02-22 2012-08-15 中国人民解放军国防科学技术大学 Mass storage system monitoring method integrating heterogeneous storage devices
CN103095498A (en) * 2013-01-17 2013-05-08 河南省电力通信自动化公司 Method and system of phone bill collection

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102422596A (en) * 2009-05-07 2012-04-18 意法半导体(格勒诺布尔2)公司 Method and device for analyzing transaction propagation in a multiprotocol network of a system on chip
CN102638378A (en) * 2012-02-22 2012-08-15 中国人民解放军国防科学技术大学 Mass storage system monitoring method integrating heterogeneous storage devices
CN103095498A (en) * 2013-01-17 2013-05-08 河南省电力通信自动化公司 Method and system of phone bill collection

Also Published As

Publication number Publication date
CN103546343A (en) 2014-01-29

Similar Documents

Publication Publication Date Title
CN103546343B (en) The network traffics methods of exhibiting of network traffic analysis system and system
US9712409B2 (en) Agile information technology infrastructure management system
CN101582807B (en) Method and system based on northbound interface to realize network management
US7525422B2 (en) Method and system for providing alarm reporting in a managed network services environment
CN103403707B (en) The system and method exchanged for database proxy request
US8892737B2 (en) Network sniffer for performing service level management
US20110029657A1 (en) Tracking high-level network transactions
CN108667725A (en) A kind of industrial AnyRouter and implementation method based on a variety of accesses and edge calculations
US20110016528A1 (en) Method and Device for Intrusion Detection
CN101933003A (en) Automated application dependency mapping
CN104092755B (en) A kind of method and device for capturing of cloud service origination data
CN113055421B (en) Service grid management method and system
CN105119757A (en) Method and system for operation and maintenance automation of enterprise servers
CN106888106A (en) The extensive detecting system of IT assets in intelligent grid
CN108900374B (en) Data processing method and device applied to DPI equipment
CN103152352A (en) Perfect information security and forensics monitoring method and system based on cloud computing environment
CN102820984A (en) Automatic network topology detection and modeling
CN101099345A (en) Interpreting an application message at a network element using sampling and heuristics
CN110855493B (en) Application topological graph drawing device for mixed environment
CN103248512A (en) Method and system for generating topological structure of application layer in communication network
CN105052076B (en) Network element management system and network element management method based on cloud computing
CN109923847A (en) Call discovery method, apparatus, equipment and the storage medium of link
CN110209518A (en) A kind of multi-data source daily record data, which is concentrated, collects storage method and device
CN107463490B (en) Cluster log centralized collection method applied to platform development
CN101667932B (en) Method of network element equipment log management and device

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
C53 Correction of patent for invention or patent application
CB02 Change of applicant information

Address after: 510623 Guangdong city in Guangzhou Province, the Pearl River Metro Chinese Sui Road No. 6

Applicant after: China Southern Power Grid Co., Ltd.

Applicant after: Company limited of China Energy Engineering Group Guangdong Electric Power Design Institute

Applicant after: Shenzhen Peng Tai communication apparatus Co., Ltd

Address before: 510623 Guangdong city in Guangzhou Province, the Pearl River Metro Chinese Sui Road No. 6

Applicant before: China Southern Power Grid Co., Ltd.

Applicant before: Guangdong Electric Power Design Institute of CEEC

Applicant before: Shenzhen Peng Tai communication apparatus Co., Ltd

COR Change of bibliographic data

Free format text: CORRECT: APPLICANT; FROM: CHINA ENERGY ENGINEERING GROUP GUANGDONG ELECTRIC POWER DESIGN INSTITUTE SHENZHEN PENGTAI WIRELESS CO., LTD. TO: CHINA ENERGY ENGINEERING GROUP GUANGDONG ELECTRIC POWER DESIGN INSTITUTE CO., LTD. SHENZHEN PENGTAI WIRELESS CO., LTD.

C41 Transfer of patent application or patent right or utility model
TA01 Transfer of patent application right

Effective date of registration: 20170221

Address after: 510623 Guangdong Province, Guangzhou city Whampoa District Science City Kexiang Road No. 11

Applicant after: China Southern Power Grid Co., Ltd.

Applicant after: Company limited of China Energy Engineering Group Guangdong Electric Power Design Institute

Address before: 510623 Guangdong city in Guangzhou Province, the Pearl River Metro Chinese Sui Road No. 6

Applicant before: China Southern Power Grid Co., Ltd.

Applicant before: Company limited of China Energy Engineering Group Guangdong Electric Power Design Institute

Applicant before: Shenzhen Peng Tai communication apparatus Co., Ltd

GR01 Patent grant
GR01 Patent grant
CF01 Termination of patent right due to non-payment of annual fee
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20170329

Termination date: 20191018