CN101483553A - Audit apparatus and method for customer network behavior - Google Patents

Audit apparatus and method for customer network behavior Download PDF

Info

Publication number
CN101483553A
CN101483553A CNA2009100783072A CN200910078307A CN101483553A CN 101483553 A CN101483553 A CN 101483553A CN A2009100783072 A CNA2009100783072 A CN A2009100783072A CN 200910078307 A CN200910078307 A CN 200910078307A CN 101483553 A CN101483553 A CN 101483553A
Authority
CN
China
Prior art keywords
log
audit
types
target journaling
record
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CNA2009100783072A
Other languages
Chinese (zh)
Other versions
CN101483553B (en
Inventor
华振兴
周峰
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
ZTE Corp
Original Assignee
ZTE Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by ZTE Corp filed Critical ZTE Corp
Priority to CN2009100783072A priority Critical patent/CN101483553B/en
Publication of CN101483553A publication Critical patent/CN101483553A/en
Application granted granted Critical
Publication of CN101483553B publication Critical patent/CN101483553B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Abstract

The present invention discloses a device for auditing user network action, wherein the device comprises the following components: a setting module which is used for respectively setting a corresponding auditing field set for each log style and the link field between log styles, a filtering module which is used for obtaining the log record of each device and filtering the log record of each device, an input module and an inquiring module. The invention simultaneously discloses a method for auditing user network action, wherein the method comprises the following steps: setting a corresponding auditing field set beforehand for each log style; beforehand setting the link field between log styles; obtaining the log record of each device; filtering and storing the log record of each device according to the auditing field set; inputting inquiring condition; and inquiring each auditing log according to the inquiring condition and the set link filed between log styles for obtaining the network logging-on information to be inquired. The device and the method according to the invention can realize the automatic inquiring of network logging-on information.

Description

A kind of user network behavior audit device and method
Technical field
The present invention relates to the network audit technology, relate in particular to a kind of user network behavior audit device and method.
Background technology
User network behavior audit is the internet information by the log acquisition user of each equipment in the network, and then user's application behavior carried out monitor audit, wherein, the application behavior comprises access websites and browsing page, receiving and dispatching mail, uploads and download, instant messaging, chat, forum, remote terminal visit Telnet etc.; Internet information comprises outer net information, Intranet information, authentication information and user profile four category informations.
At present, each equipment can only write down and the relevant internet information of equipment self operation in the network, there is not the equipment of can recording user once using the complete internet information of behavior, for example, the IP/ATM netting index that is used for user bandwidth is according to the BAS Broadband Access Server (BRAS that inserts, Broadband Remote AccessServer) only can write down the BRAS daily record that belongs to outer net information, be used to distribute dynamic host allocation protocol (DHCP, the Dynamic Host Configuration Protocol) equipment of client TCP/IP only can write down the DHCP daily record that belongs to Intranet information; Like this, once use the part internet information of behavior when the network manager known users, the known internet information of this part belongs to the class in outer net information, Intranet information, authentication information and the user profile, when needing part or all of remaining internet information of this time of inquiring user internet behavior, if the internet information of required inquiry and known internet information belong to same category information, the equipment of this category information of query note gets final product; If but the internet information of required inquiry and known internet information do not belong to same category information, then personnel query need carry out following operation:
Step 1, determine information type under the Given information, and on the equipment of this category information of record, import Given information, obtain to comprise the log record of Given information; Determine the equipment of the affiliated information type of required inquiry internet information and record the type information;
Step 2, determine the described log record that comprises Given information field with whether contain same field in the field of daily record of definite equipment, if contain, execution in step 3; If do not contain, execution in step 4;
Step 3, with the element on the same field described in the described log record that comprises Given information as condition of contact, and in the definite equipment of institute, import described condition of contact, obtain the log record that comprises described condition of contact, promptly obtain required inquiry internet information, finish current flow process;
Step 4, determine and the described log record that comprises Given information and the daily record of definite equipment the information type of same field is all arranged, and the same field of the information type that will determine and the described log record that comprises Given information is as first field, element in the described log record that comprises Given information on first field is as first condition of contact, in the equipment of the definite information type information of record institute, import first condition of contact, obtain the log record that comprises first condition of contact;
Step 5, the information type that will determine with the same field of daily record of definite equipment as second field, with the element on second field in the described log record that comprises first condition of contact as second condition of contact, described second condition of contact of input in the definite equipment of institute, obtain the log record that comprises described second condition of contact, promptly obtain required inquiry internet information;
If required inquiry internet information comprises the information of a plurality of information types, need repeat the operation of step 2~5, each information type is inquired about respectively, also need to be connected with two or more records of time common factor then, and the identical entry in the merge record, and then obtain required inquiry internet information.
Above-mentioned whole operation process is very numerous and diverse, and by manually finishing, workload is very big, very wastes time and energy, when especially needing in the short time to finish the inquiry of a large amount of internet informations, because the restriction of factors such as personnel query time, muscle power is difficult to guarantee the inquiry quality.
Summary of the invention
In view of this, main purpose of the present invention is to provide a kind of user network behavior audit device and method, can realize the automatic inquiry of internet information.
For achieving the above object, technical scheme of the present invention is achieved in that
A kind of user network behavior audit device, this device comprises:
Module is set, is used for being respectively in advance each Log Types corresponding auditing field set is set; And be used to set in advance link field between each Log Types;
Filtering module is used to obtain out the log record of each equipment; And be used for filtering this log record according to the auditing field set of Log Types correspondence under the obtaining log record, obtain audit log and write down and be stored in the audit log of this log record corresponding device correspondence;
Input module is used for the input inquiry condition;
Enquiry module is used for inquiring about each described audit log according to the link field between described querying condition and set each Log Types, obtains the internet information of required inquiry.
Further, this device further comprises:
Index module, the audit log that is used to be respectively each equipment is provided with index and is stored in the audit log of this equipment correspondence that sets in advance.
Further, described querying condition comprises the Log Types under known audit information, the known audit information, and the target journaling set of types;
Accordingly, described enquiry module comprises:
Administration module is used for determining whether the target journaling set of types exists the target journaling type of not taking out; And take out the target journaling type of not taking out in the target journaling set of types when being used to the target journaling type that existence do not take out and be sent to first determination module, when not having the target journaling type of not taking out order connect merge module exist the audit log record that occurs simultaneously to connect to each outcome record centralized recording time and and close;
First determination module, whether with take out target journaling type identical, and be used for determining that the audit log that the result orders the inquiry of first enquiry module to comprise known audit information when being identical writes down, determines that the result is by not ordering second determination module to determine the Log Types that known audit information is affiliated simultaneously and being taken out whether there is link field between the target journaling type if being used for the affiliated Log Types of definite known audit information;
First enquiry module, be used for inquiring about the audit log record that Log Types institute each audit log of correspondence under the known audit information comprises known audit information, obtain the pairing outcome record collection of the target journaling type of taking out, and the notice administration module determine whether there is the target journaling type of not taking out in the target journaling set of types;
Second determination module is used to inquire about the link field between each set Log Types, determine under the known audit information Log Types and take out whether there is link field between the target journaling type; And be used for determining the result be order second inquiry comprises known audit information when having link field audit log record, determine the result order when not having link field the 3rd determination module determine with the affiliated Log Types of known audit information and all have the Log Types of link field between the taking-up target journaling type;
Second enquiry module, be used for inquiring about the audit log record that Log Types institute each audit log of correspondence under the known audit information comprises known audit information, and be used for writing down and existing link field according to the described audit log that comprises known audit information, inquiry institute's target journaling type of taking out each audit log of correspondence, obtain the pairing outcome record collection of the target journaling type of taking out, and the notice administration module determine whether there is the target journaling type of not taking out in the target journaling set of types;
The 3rd determination module is used to inquire about the link field between each set Log Types, determines Log Types and the take out Log Types that target journaling type between all have link field affiliated with known audit information;
The 3rd inquiry module is used for inquiring about the audit log record that Log Types institute each audit log of correspondence under the known audit information comprises known audit information, obtains first Query Result; Be used for the link field according to the Log Types under first Query Result and institute definite Log Types and the known audit information, the definite Log Types of inquiry institute each audit log of correspondence obtains second Query Result; And be used for link field according to second Query Result and institute definite Log Types and the target journaling type of taking out, inquiry institute's target journaling type of taking out each audit log of correspondence, obtain the pairing outcome record collection of the target journaling type of taking out, and the notice administration module determine whether there is the target journaling type of not taking out in the target journaling set of types;
Connect and merge module, be used for audit log record with each outcome record collection, element on the link field between each Log Types is a tie point, there is the described audit log record that occurs simultaneously in the linkage record time, and merge the same field that connects in the audit log record that obtains, obtain the internet information and the output of required inquiry.
The present invention also provides a kind of user network behavior auditing method, and this method comprises:
Be respectively each Log Types in advance corresponding auditing field set is set; And set in advance link field between each Log Types;
Obtain out the log record of each equipment; Auditing field set according to Log Types correspondence under the obtaining log record is filtered this log record, obtains audit log and writes down and be stored in the audit log of this log record corresponding device correspondence;
The input inquiry condition; According to the link field between described querying condition and set each Log Types, inquire about each described audit log, obtain the internet information of required inquiry.
Further, this method further comprises:
The audit log that is respectively each equipment is provided with index and is stored in the audit log of this equipment correspondence that sets in advance.
Further, described querying condition comprises the Log Types under known audit information, the known audit information, and the target journaling set of types;
Accordingly, the described inquiry audit log record that meets described querying condition comprises:
A, by taking out a target journaling type, execution in step B in the input target journaling set of types;
B, determine whether the Log Types under the known audit information is identical with taking-up target journaling type, if it is identical, inquire about the audit log record that comprises known audit information in Log Types institute each audit log of correspondence under the known audit information, obtain the pairing outcome record collection of the target journaling type of taking out, execution in step F; Otherwise, execution in step C;
Link field between C, set each Log Types of inquiry determines Log Types and the institute under the known audit information takes out whether there is link field between the target journaling type, if existence, execution in step D; Otherwise, execution in step E;
The audit log record that comprises known audit information in D, inquiry Log Types institute each audit log of correspondence under the known audit information, and according to described audit log record and the existing link field that comprises known audit information, inquiry institute's target journaling type of taking out each audit log of correspondence, obtain the pairing outcome record collection of the target journaling type of taking out, execution in step F;
Link field between E, set each Log Types of inquiry is determined Log Types and the take out Log Types that target journaling type between all have link field affiliated with known audit information; Inquire about the audit log record that comprises known audit information in Log Types institute each audit log of correspondence under the known audit information, obtain first Query Result, and according to first Query Result and the link field of the Log Types under definite Log Types and the known audit information, corresponding each audit log of definite Log Types institute of inquiry institute obtains second Query Result; According to the link field of second Query Result and institute definite Log Types and the target journaling type of taking out, inquire about the target journaling type of taking out each audit log of correspondence, obtain the pairing outcome record collection of the target journaling type of taking out, execution in step F;
F, determine whether there is the target journaling type of not taking out in the target journaling set of types, if there is no, in the audit log record with each outcome record collection, element on the link field between each Log Types is a tie point, and merging connects the same field in the audit log record that obtains, promptly obtain the internet information of required inquiry, finish this flow process; If exist, take out the target journaling type of not taking out in the target journaling set of types, return step B.
Further, describedly be for the audit log of each equipment is provided with index:
A, set up the sequencing table of the value of each field of audit log respectively, and each value storage of corresponding field comprises the recording mechanism that the audit log of this value writes down, obtain the index file of this field;
B, repeating step a are up to for the audit log of each equipment index being set.
Further, the audit log that comprises known audit information in the institute of the Log Types under the known audit information of described inquiry each audit log of correspondence is recorded as:
Determine in affiliated corresponding each audit log of Log Types institute of known audit information the index file of field under the described known audit information; Inquire about known audit information in the sequencing table in determined index file, obtain the recording mechanism of known audit information correspondence; In corresponding each audit log of the institute of the Log Types under the known audit information, the audit log record of inquiry resulting records correspondence promptly obtains the described audit log record that comprises known audit information.
Further, described according to described audit log record and the existing link field that comprises known audit information, the inquiry institute target journaling type of taking out each audit log of correspondence be:
With the value of existing link field in the described audit log record that comprises known audit information as condition of contact; Determine institute's target journaling type of taking out in each audit log of correspondence, the index file of described link field; Inquire about condition of contact in the sequencing table in determined index file, obtain the recording mechanism of condition of contact correspondence; In corresponding each audit log of taking-up target journaling type institute, the audit log record of inquiry resulting records correspondence.
Further, described link field according to the Log Types under first Query Result and institute definite Log Types and the known audit information, inquiry institute definite Log Types each audit log of correspondence is:
With in described first Query Result the value of link field of the Log Types under definite Log Types and the known audit information as first condition of contact; Determine in corresponding each audit log of definite Log Types institute of institute the index file of the link field of the Log Types that definite Log Types of institute and known audit information are affiliated; Inquire about first condition of contact in the sequencing table in determined index file, obtain the recording mechanism of the first condition of contact correspondence; In corresponding each audit log of definite Log Types institute of institute, inquire about the audit log record of described first condition of contact institute corresponding record correspondence;
Accordingly, described link field according to second Query Result and institute definite Log Types and the target journaling type of taking out, inquire about the target journaling type of taking out each audit log of correspondence be:
With in described second Query Result the value of link field of definite Log Types and the target journaling type of taking out as second condition of contact; Determine in the target journaling type of taking out institute of institute each audit log of correspondence, the index file of definite Log Types and the link field of target journaling type of taking out; Inquire about second condition of contact in the sequencing table in determined index file, obtain the recording mechanism of the second condition of contact correspondence; In corresponding each audit log of taking-up target journaling type institute, inquire about the audit log record of described second condition of contact institute corresponding record correspondence.
User network behavior audit device provided by the present invention and method, the complete audit log by storing each equipment and set in advance link field between each Log Types is realized the automatic inquiry of internet information.The present invention also has following advantage and characteristics:
1) by auditing field set according to each the Log Types correspondence that sets in advance, in the filtering network in the log record of each equipment with the irrelevant information of audit after store, simplified log information, storage and search efficiency have been improved, and standardization the storage format of each Log Types, help expanding new equipment;
2) device type that adopts according to each network environment for each network environment is provided with link field between each Log Types, makes the present invention can realize the automatic inquiry of user's internet information in the diverse network;
3) connect and merge by the audit log record that each outcome record of being inquired is concentrated, can provide complete internet information that the user uses behavior to network manager.
Description of drawings
Fig. 1 is the structural representation of embodiment of the invention user network behavior audit device;
Fig. 2 is the enquiry module structural representation of embodiment of the invention user network behavior audit device;
Fig. 3 realizes the flow chart of user network behavior audit for adopting user network behavior audit device of the present invention.
Embodiment
Basic thought of the present invention is: user network behavior audit device of the present invention is according to the auditing field set of each the Log Types correspondence that sets in advance, store after the information that has nothing to do with audit in the log record of each equipment in the filtering network, like this, in user network behavior audit device of the present invention, promptly stored the complete audit log of each equipment; And according to the link field that sets in advance between each Log Types, Log Types under automatically definite known audit information and the link field between the target journaling type, or the Log Types and the Log Types that all has link field between the target journaling type that takes out under definite automatically and the known audit information, and the Log Types under the known audit information and the target journaling type of taking out respectively with the link field of definite Log Types, and then, inquire the pairing outcome record collection of each target journaling type in the target journaling set of types by known audit information according to determined link field.
Adopt user network behavior audit device of the present invention, after the personnel query input inquiry information, whole query script is finished automatically by user network behavior audit device of the present invention, has alleviated the work that personnel query is inquired about greatly, and can draw Query Result quickly and accurately.
The structure of embodiment of the invention user network behavior audit device comprises: module filtering module, input module and enquiry module are set as shown in Figure 1; Wherein,
The described module that is provided with is used for being respectively in advance each Log Types corresponding auditing field set is set, for each equipment is provided with corresponding audit log; And be used to set in advance the audit log of each equipment correspondence, and be used to set in advance the link field between each Log Types; Here, for each Log Types is provided with the storage format that corresponding auditing field set can each Log Types of standardization, help expanding new equipment, and when helping to inquire about internet information automatically, the determining and connection and merging that each outcome record is concentrated the audit log record of link field;
Wherein, described Log Types comprises: network address translation (NAT, Network AddressTranslation) daily record, BRAS daily record, DHCP daily record, Certificate Authority and note are taken (AAA) daily record etc.;
Described NAT daily record and BRAS daily record belong to outer net information, the auditing field set of NAT daily record correspondence is { time, event id, purpose IP, destination interface, outer net IP, outer net port, Intranet IP, Intranet port, an agreement }, and the auditing field set of BRAS daily record correspondence is { time, event id, purpose IP, destination interface, outer net IP, outer net port, Intranet IP, Intranet port, agreement, an account }; The DHCP daily record belongs to Intranet information, and the auditing field set of DHCP daily record correspondence is { time, event id, Intranet IP, MAC Address, a host name }; The AAA daily record comprises aaa authentication daily record and AAA user journal, the aaa authentication daily record belongs to authentication information, the AAA user journal belongs to user profile, the auditing field set of aaa authentication daily record correspondence is { time started of authentication, the concluding time of authentication, Intranet IP, MAC Address, a number of the account }, and the auditing field set of AAA user journal correspondence is { number of the account, name, identification card number, phone, address }.
Here, described link field is the same field in the auditing field set of each Log Types correspondence, wherein, Time And Event ID is generally as link field, that is, and and between different Log Types, except that Time And Event ID, be present in two kinds of fields in the daily record simultaneously and can be used as link field.
The device type difference that different network environments adopts, the Log Types difference of recording user internet information, this is provided with the device type that module adopts according to each network environment, for each network environment is provided with link field between each Log Types, make the present invention can realize the automatic inquiry of user's internet information in the diverse network, for example:
In the network environment of NAT, BRAS and DHCP mixed networking, the link field between each Log Types is as shown in table 1:
Log Types 1 Log Types 2 Condition of contact
The BRAS daily record The DHCP daily record Intranet IP
The BRAS daily record The aaa authentication daily record Intranet IP or number of the account
The BRAS daily record The AAA user journal Number of the account
The NAT daily record The DHCP daily record Intranet IP
The NAT daily record The aaa authentication daily record Intranet IP
The DHCP daily record The aaa authentication daily record Intranet IP or MAC Address
The aaa authentication daily record The AAA user journal Number of the account
Table 1
Be in the network environment of public network IP at Intranet IP, do not have NAT device, the link field between each Log Types is as shown in table 2:
Log Types 1 Log Types 2 Condition of contact
The BRAS daily record The DHCP daily record Intranet IP
The BRAS daily record The aaa authentication daily record Intranet IP or number of the account
The BRAS daily record The AAA user journal Number of the account
The DHCP daily record The aaa authentication daily record Intranet IP or MAC Address
The aaa authentication daily record The AAA user journal Number of the account
Table 2
Use in the network environment of static IP, do not have DHCP equipment, the link field between each Log Types is as shown in table 3:
Log Types 1 Log Types 2 Condition of contact
The BRAS daily record The aaa authentication daily record Intranet IP or number of the account
The BRAS daily record The AAA user journal Number of the account
The NAT daily record The aaa authentication daily record Intranet IP
The aaa authentication daily record The AAA user journal Number of the account
Table 3
Described filtering module is used to obtain the log record of each equipment; And be used for filtering this log record according to the auditing field set of Log Types correspondence under the obtaining log record, obtain audit log and write down and be stored in the audit log of this log record corresponding device correspondence;
Wherein, concrete filter method is:
Element with the auditing field set of each Log Types correspondence, the field that audit log comprised as each equipment correspondence under this Log Types daily record, remove this equipment in the log record of each equipment that obtains in the corresponding audit log the value of non-existent field, promptly obtain the audit log record of this equipment;
Here, filtered out the information beyond the field corresponding element of auditing field set in the log record, simplified log information, improved storage and search efficiency by filtering module.
Described input module is used for the input inquiry condition; Here, described querying condition comprises the Log Types under known audit information, the known audit information, and the target journaling set of types;
Described enquiry module is used for inquiring about each described audit log according to the link field between described querying condition and set each Log Types, obtains the internet information of required inquiry;
This device further comprises:
Index module, the audit log that is used to be respectively each equipment is provided with index and is stored in the audit log of this equipment correspondence; Here, can be with the combination of each field or field in the auditing field set of each audit log correspondence all as the index of this audit log, to improve search efficiency.
Wherein, the audit log that is specially each equipment is provided with index and is:
Step a, set up the sequencing table of the value of each field of audit log respectively, and each value storage of corresponding field comprises the recording mechanism that the audit log of this value writes down, obtain the index file of this field;
Step b, repeating step a are up to for the audit log of each equipment index being set.
For example, set up the sequencing table of the value of Intranet IP, outer net IP respectively, and each value storage of corresponding Intranet IP comprises the recording mechanism of the audit log record of this value, promptly obtain this Intranet IP index file, each value storage of corresponding outer net IP comprises the recording mechanism that the audit log of this value writes down, promptly obtain this outer net IP index file.
During inquiry, at first determine the index file of the affiliated field correspondence of known audit information; Then this known audit information of inquiry in determined index file, and the recording mechanism of this known audit information correspondence; The last pairing audit log record of the recording mechanism that is inquired that in audit log, finds; Wherein, audit log comprises a plurality of audit log record sheets, the corresponding table number of each record sheet, and write down the table number that deposits the priority in the table and the table that deposits in according to audit log and write down the recording mechanism that is assigned correspondence for each audit log;
Here, the value of field is orderly in the sequencing table of the value of field, and recording mechanism also is orderly in each audit log record sheet, therefore, during inquiry, can obtain the audit log record that will inquire about very soon, makes that whole inquiry is very fast.
Wherein, the structure of described enquiry module comprises as shown in Figure 2: administration module, first determination module, first enquiry module, second determination module, second enquiry module, the 3rd determination module, the 3rd inquiry module merge module with being connected; Wherein,
Administration module is used for determining whether the target journaling set of types exists the target journaling type of not taking out; And be used for determining the result take out the target journaling type that a target journaling set of types do not take out when having the target journaling type of not taking out and be sent to first determination module, determine the result be when not having the target journaling type of not taking out order connect merge module exist the audit log record that occurs simultaneously to connect to each outcome record centralized recording time and and close;
First determination module is used for determining whether the Log Types under the known audit information is identical with taking-up target journaling type; And be used for determining that the audit log that the result orders the inquiry of first enquiry module to comprise known audit information when being identical writes down, determines that the result is by not ordering second determination module to determine the Log Types that known audit information is affiliated simultaneously and being taken out whether there is link field between the target journaling type;
First enquiry module, be used for inquiring about the audit log record that Log Types institute each audit log of correspondence under the known audit information comprises known audit information, obtain the pairing outcome record collection of the target journaling type of taking out, and the notice administration module determine whether there is the target journaling type of not taking out in the target journaling set of types; Corresponding each audit log of described Log Types institute, that is, and the audit log of each equipment correspondence under this Log Types daily record;
Wherein, the audit log record that inquiry comprises known audit information is specially: determine in affiliated corresponding each audit log of Log Types institute of known audit information the index file of field under the described known audit information; Inquire about known audit information in the sequencing table in determined index file, obtain the recording mechanism of known audit information correspondence; In corresponding each audit log of the institute of the Log Types under the known audit information, the audit log record of inquiry resulting records correspondence promptly obtains the described audit log record that comprises known audit information;
Second determination module is used to inquire about the link field between each set Log Types, determine under the known audit information Log Types and take out whether there is link field between the target journaling type; And be used for determining the result be order second inquiry comprises known audit information when having link field audit log record, determine the result order when not having link field the 3rd determination module determine with the affiliated Log Types of known audit information and all have the Log Types of link field between the taking-up target journaling type;
Second enquiry module, be used for inquiring about the audit log record that Log Types institute each audit log of correspondence under the known audit information comprises known audit information, and be used for writing down and existing link field according to the described audit log that comprises known audit information, inquiry institute's target journaling type of taking out each audit log of correspondence, obtain the pairing outcome record collection of the target journaling type of taking out, and the notice administration module determine whether there is the target journaling type of not taking out in the target journaling set of types;
Wherein, described according to described audit log record and the existing link field that comprises known audit information, the inquiry institute target journaling type of taking out each audit log of correspondence be specially: the value of existing link field was as condition of contact during the described audit log that comprises known audit information was write down; Determine institute's target journaling type of taking out in each audit log of correspondence, the index file of described link field; Inquire about condition of contact in the sequencing table in determined index file, obtain the recording mechanism of condition of contact correspondence; In corresponding each audit log of taking-up target journaling type institute, the audit log record of inquiry resulting records correspondence;
The 3rd determination module is used to inquire about the link field between each set Log Types, determines Log Types and the take out Log Types that target journaling type between all have link field affiliated with known audit information;
The 3rd inquiry module is used for inquiring about the audit log record that Log Types institute each audit log of correspondence under the known audit information comprises known audit information, obtains first Query Result; Be used for the link field according to the Log Types under first Query Result and institute definite Log Types and the known audit information, the definite Log Types of inquiry institute each audit log of correspondence obtains second Query Result; And be used for link field according to second Query Result and institute definite Log Types and the target journaling type of taking out, inquiry institute's target journaling type of taking out each audit log of correspondence, obtain the pairing outcome record collection of the target journaling type of taking out, and the notice administration module determine whether there is the target journaling type of not taking out in the target journaling set of types;
Wherein, described link field according to the Log Types under first Query Result and institute definite Log Types and the known audit information, inquiry definite Log Types each audit log of correspondence be specially: with in described first Query Result the value of link field of the affiliated Log Types of definite Log Types and known audit information as first condition of contact; Determine in corresponding each audit log of definite Log Types institute of institute the index file of the link field of the Log Types that definite Log Types of institute and known audit information are affiliated; Inquire about first condition of contact in the sequencing table in determined index file, obtain the recording mechanism of the first condition of contact correspondence; In corresponding each audit log of definite Log Types institute of institute, the audit log record of inquiry resulting records correspondence;
Described link field according to second Query Result and institute definite Log Types and the target journaling type of taking out, inquire about the target journaling type of taking out each audit log of correspondence be specially: with in described second Query Result the value of link field of definite Log Types and the target journaling type of taking out as second condition of contact; Determine in the target journaling type of taking out institute of institute each audit log of correspondence, the index file of definite Log Types and the link field of target journaling type of taking out; Inquire about second condition of contact in the sequencing table in determined index file, obtain the recording mechanism of the second condition of contact correspondence; In corresponding each audit log of taking-up target journaling type institute, the audit log record of inquiry resulting records correspondence;
Connect and merge module, be used for audit log record with each outcome record collection, element on the link field between each Log Types is a tie point, there is the described audit log record that occurs simultaneously in the linkage record time, and merge the same field that connects in the audit log record that obtains, promptly obtain the internet information and the output of required inquiry.
Adopt flow process that user network behavior audit device of the present invention realizes user network behavior audit as shown in Figure 3, may further comprise the steps:
Step 301: be respectively each Log Types in advance corresponding auditing field set is set; And set in advance link field between each Log Types.
Step 302: the log record that obtains out each equipment; Auditing field set according to Log Types correspondence under the obtaining log record is filtered this log record, obtains audit log and writes down and be stored in the audit log of this log record corresponding device correspondence.
Step 303: the audit log that is respectively each equipment is provided with index and is stored in the audit log of this equipment correspondence that sets in advance.
Wherein, the method that the index of each audit log specifically is set is:
Step a, set up the sequencing table of the value of each field of audit log respectively, and each value storage of corresponding field comprises the recording mechanism that the audit log of this value writes down, obtain the index file of this field;
Step b, repeating step a are up to for the audit log of each equipment index being set.
For example, set up the sequencing table of the value of Intranet IP, outer net IP respectively, and each value storage of corresponding Intranet IP comprises the recording mechanism of the audit log record of this value, promptly obtain this Intranet IP index file, each value storage of corresponding outer net IP comprises the recording mechanism that the audit log of this value writes down, promptly obtain this outer net IP index file.
Step 304: input inquiry condition; Here, described querying condition comprises the Log Types under known audit information, the known audit information, and the target journaling set of types.
Step 305: according to the link field between described querying condition and set each Log Types, inquire about described audit log, obtain the internet information of required inquiry.
Here, the described inquiry audit log record that meets described querying condition specifically comprises:
Steps A, by taking out a target journaling type, execution in step B in the input target journaling set of types;
Step B, determine whether the Log Types under the known audit information is identical with taking-up target journaling type, if it is identical, inquire about the audit log record that comprises known audit information in Log Types institute each audit log of correspondence under the known audit information, obtain the pairing outcome record collection of the target journaling type of taking out, execution in step F, promptly, when the Log Types under the known audit information is identical with takes out target journaling type, only need inquire about the affiliated Log Types of known audit information can obtain the pairing outcome record collection of the target journaling type of taking out; Otherwise, execution in step C.
Link field between step C, set each Log Types of inquiry determines Log Types and the institute under the known audit information takes out whether there is link field between the target journaling type, if existence, execution in step D; Otherwise, execution in step E;
Wherein, the audit log record that inquiry comprises known audit information is specially: determine in affiliated corresponding each audit log of Log Types institute of known audit information the index file of field under the described known audit information; Inquire about known audit information in the sequencing table in determined index file, obtain the recording mechanism of known audit information correspondence; In corresponding each audit log of the institute of the Log Types under the known audit information, the audit log record of inquiry resulting records correspondence promptly obtains the described audit log record that comprises known audit information;
The audit log record that comprises known audit information in step D, inquiry Log Types institute each audit log of correspondence under the known audit information, and according to described audit log record and the existing link field that comprises known audit information, inquiry institute's target journaling type of taking out each audit log of correspondence, obtain the pairing outcome record collection of the target journaling type of taking out, execution in step F;
Wherein, described according to described audit log record and the existing link field that comprises known audit information, the inquiry institute target journaling type of taking out each audit log of correspondence be specially: the value of existing link field was as condition of contact during the described audit log that comprises known audit information was write down; Determine institute's target journaling type of taking out in each audit log of correspondence, the index file of described link field; Inquire about condition of contact in the sequencing table in determined index file, obtain the recording mechanism of condition of contact correspondence; In corresponding each audit log of taking-up target journaling type institute, the audit log record of inquiry resulting records correspondence;
By step C, D as seen, Log Types under the known audit information is identical with taking-up target journaling type, but when between two Log Types link field being arranged, need the affiliated Log Types of the known audit information of inquiry, and according to Query Result and this link field inquiry institute target journaling type of taking out each audit log of correspondence, just can obtain the pairing outcome record collection of the target journaling type of taking out;
Link field between step e, set each Log Types of inquiry is determined Log Types and the take out Log Types that target journaling type between all have link field affiliated with known audit information; Inquire about the audit log record that comprises known audit information in Log Types institute each audit log of correspondence under the known audit information, obtain first Query Result, and according to first Query Result and the link field of the Log Types under definite Log Types and the known audit information, corresponding each audit log of definite Log Types institute of inquiry institute obtains second Query Result; According to the link field of second Query Result and institute definite Log Types and the target journaling type of taking out, inquire about the target journaling type of taking out each audit log of correspondence, obtain the pairing outcome record collection of the target journaling type of taking out, execution in step F;
Wherein, described link field according to the Log Types under first Query Result and institute definite Log Types and the known audit information, inquiry definite Log Types each audit log of correspondence be specially: with in described first Query Result the value of link field of the affiliated Log Types of definite Log Types and known audit information as first condition of contact; Determine in corresponding each audit log of definite Log Types institute of institute the index file of the link field of the Log Types that definite Log Types of institute and known audit information are affiliated; Inquire about first condition of contact in the sequencing table in determined index file, obtain the recording mechanism of the first condition of contact correspondence; In corresponding each audit log of definite Log Types institute of institute, inquire about the audit log record of described first condition of contact institute corresponding record correspondence;
Described link field according to second Query Result and institute definite Log Types and the target journaling type of taking out, inquire about the target journaling type of taking out each audit log of correspondence be specially: with in described second Query Result the value of link field of definite Log Types and the target journaling type of taking out as second condition of contact; Determine in the target journaling type of taking out institute of institute each audit log of correspondence, the index file of definite Log Types and the link field of target journaling type of taking out; Inquire about second condition of contact in the sequencing table in determined index file, obtain the recording mechanism of the second condition of contact correspondence; In corresponding each audit log of taking-up target journaling type institute, inquire about the audit log record of described second condition of contact institute corresponding record correspondence;
By step C, E as seen, Log Types under the known audit information is identical with taking-up target journaling type, but when not having link field between two Log Types, need the Log Types and the Log Types that all has link field between the target journaling type that takes out definite and that known audit information is affiliated, inquire about the affiliated Log Types of known audit information, and according to the Log Types under Query Result and the known audit information with corresponding each audit log of the definite Log Types of link field inquiry institute of definite Log Types, and according to the definite Log Types of described inquiry institute the Query Result of each audit log of correspondence, and the target journaling type of taking out respectively with the link field of definite Log Types, inquiry institute's target journaling type of taking out each audit log of correspondence, just can obtain the pairing outcome record collection of the target journaling type of taking out;
Step F, determine whether there is the target journaling type of not taking out in the target journaling set of types, if there is no, in the audit log record with each outcome record collection, element on the link field between each Log Types is a tie point, there is the described audit log record that occurs simultaneously in the linkage record time, and merge the same field that connects in the audit log record that obtains, and promptly obtain the internet information of required inquiry, finish this flow process; If exist, take out the target journaling type of not taking out in the target journaling set of types, return step B;
In this step,,, promptly can provide complete internet information that the user uses behavior to network manager by the described audit log record that the described linkage record time exist to occur simultaneously if comprised the whole Log Types in the network in the target journaling set of types; And merge the same field that connects in the audit log record that obtains, then can merge the duplicate message in the audit log record.
The above is preferred embodiment of the present invention only, is not to be used to limit protection scope of the present invention.

Claims (10)

1, a kind of user network behavior audit device is characterized in that this device comprises:
Module is set, is used for being respectively in advance each Log Types corresponding auditing field set is set; And be used to set in advance link field between each Log Types;
Filtering module is used to obtain out the log record of each equipment; And be used for filtering this log record according to the auditing field set of Log Types correspondence under the obtaining log record, obtain audit log and write down and be stored in the audit log of this log record corresponding device correspondence;
Input module is used for the input inquiry condition;
Enquiry module is used for inquiring about each described audit log according to the link field between described querying condition and set each Log Types, obtains the internet information of required inquiry.
2, user network behavior audit device according to claim 1 is characterized in that this device further comprises:
Index module, the audit log that is used to be respectively each equipment is provided with index and is stored in the audit log of this equipment correspondence that sets in advance.
3, user network behavior audit device according to claim 1 and 2 is characterized in that, described querying condition comprises the Log Types under known audit information, the known audit information, and the target journaling set of types;
Accordingly, described enquiry module comprises:
Administration module is used for determining whether the target journaling set of types exists the target journaling type of not taking out; And take out the target journaling type of not taking out in the target journaling set of types when being used to the target journaling type that existence do not take out and be sent to first determination module, when not having the target journaling type of not taking out order connect merge module exist the audit log record that occurs simultaneously to connect to each outcome record centralized recording time and and close;
First determination module, whether with take out target journaling type identical, and be used for determining that the audit log that the result orders the inquiry of first enquiry module to comprise known audit information when being identical writes down, determines that the result is by not ordering second determination module to determine the Log Types that known audit information is affiliated simultaneously and being taken out whether there is link field between the target journaling type if being used for the affiliated Log Types of definite known audit information;
First enquiry module, be used for inquiring about the audit log record that Log Types institute each audit log of correspondence under the known audit information comprises known audit information, obtain the pairing outcome record collection of the target journaling type of taking out, and the notice administration module determine whether there is the target journaling type of not taking out in the target journaling set of types;
Second determination module is used to inquire about the link field between each set Log Types, determine under the known audit information Log Types and take out whether there is link field between the target journaling type; And be used for determining the result be order second inquiry comprises known audit information when having link field audit log record, determine the result order when not having link field the 3rd determination module determine with the affiliated Log Types of known audit information and all have the Log Types of link field between the taking-up target journaling type;
Second enquiry module, be used for inquiring about the audit log record that Log Types institute each audit log of correspondence under the known audit information comprises known audit information, and be used for writing down and existing link field according to the described audit log that comprises known audit information, inquiry institute's target journaling type of taking out each audit log of correspondence, obtain the pairing outcome record collection of the target journaling type of taking out, and the notice administration module determine whether there is the target journaling type of not taking out in the target journaling set of types;
The 3rd determination module is used to inquire about the link field between each set Log Types, determines Log Types and the take out Log Types that target journaling type between all have link field affiliated with known audit information;
The 3rd inquiry module is used for inquiring about the audit log record that Log Types institute each audit log of correspondence under the known audit information comprises known audit information, obtains first Query Result; Be used for the link field according to the Log Types under first Query Result and institute definite Log Types and the known audit information, the definite Log Types of inquiry institute each audit log of correspondence obtains second Query Result; And be used for link field according to second Query Result and institute definite Log Types and the target journaling type of taking out, inquiry institute's target journaling type of taking out each audit log of correspondence, obtain the pairing outcome record collection of the target journaling type of taking out, and the notice administration module determine whether there is the target journaling type of not taking out in the target journaling set of types;
Connect and merge module, be used for audit log record with each outcome record collection, element on the link field between each Log Types is a tie point, there is the described audit log record that occurs simultaneously in the linkage record time, and merge the same field that connects in the audit log record that obtains, obtain the internet information and the output of required inquiry.
4, a kind of user network behavior auditing method is characterized in that this method comprises:
Be respectively each Log Types in advance corresponding auditing field set is set; And set in advance link field between each Log Types;
Obtain out the log record of each equipment; Auditing field set according to Log Types correspondence under the obtaining log record is filtered this log record, obtains audit log and writes down and be stored in the audit log of this log record corresponding device correspondence;
The input inquiry condition; According to the link field between described querying condition and set each Log Types, inquire about each described audit log, obtain the internet information of required inquiry.
5, user network behavior auditing method according to claim 4 is characterized in that this method further comprises:
The audit log that is respectively each equipment is provided with index and is stored in the audit log of this equipment correspondence that sets in advance.
According to claim 4 or 5 described user network behavior auditing methods, it is characterized in that 6, described querying condition comprises the Log Types under known audit information, the known audit information, and the target journaling set of types;
Accordingly, the described inquiry audit log record that meets described querying condition comprises:
A, by taking out a target journaling type, execution in step B in the input target journaling set of types;
B, determine whether the Log Types under the known audit information is identical with taking-up target journaling type, if it is identical, inquire about the audit log record that comprises known audit information in Log Types institute each audit log of correspondence under the known audit information, obtain the pairing outcome record collection of the target journaling type of taking out, execution in step F; Otherwise, execution in step C;
Link field between C, set each Log Types of inquiry determines Log Types and the institute under the known audit information takes out whether there is link field between the target journaling type, if existence, execution in step D; Otherwise, execution in step E;
The audit log record that comprises known audit information in D, inquiry Log Types institute each audit log of correspondence under the known audit information, and according to described audit log record and the existing link field that comprises known audit information, inquiry institute's target journaling type of taking out each audit log of correspondence, obtain the pairing outcome record collection of the target journaling type of taking out, execution in step F;
Link field between E, set each Log Types of inquiry is determined Log Types and the take out Log Types that target journaling type between all have link field affiliated with known audit information; Inquire about the audit log record that comprises known audit information in Log Types institute each audit log of correspondence under the known audit information, obtain first Query Result, and according to first Query Result and the link field of the Log Types under definite Log Types and the known audit information, corresponding each audit log of definite Log Types institute of inquiry institute obtains second Query Result; According to the link field of second Query Result and institute definite Log Types and the target journaling type of taking out, inquire about the target journaling type of taking out each audit log of correspondence, obtain the pairing outcome record collection of the target journaling type of taking out, execution in step F;
F, determine whether there is the target journaling type of not taking out in the target journaling set of types, if there is no, in the audit log record with each outcome record collection, element on the link field between each Log Types is a tie point, and merging connects the same field in the audit log record that obtains, promptly obtain the internet information of required inquiry, finish this flow process; If exist, take out the target journaling type of not taking out in the target journaling set of types, return step B.
7, user network behavior auditing method according to claim 5 is characterized in that, describedly for the audit log of each equipment is provided with index is:
A, set up the sequencing table of the value of each field of audit log respectively, and each value storage of corresponding field comprises the recording mechanism that the audit log of this value writes down, obtain the index file of this field;
B, repeating step a are up to for the audit log of each equipment index being set.
8, user network behavior auditing method according to claim 7 is characterized in that, the audit log that comprises known audit information in Log Types institute each audit log of correspondence under the known audit information of described inquiry is recorded as:
Determine in affiliated corresponding each audit log of Log Types institute of known audit information the index file of field under the described known audit information; Inquire about known audit information in the sequencing table in determined index file, obtain the recording mechanism of known audit information correspondence; In corresponding each audit log of the institute of the Log Types under the known audit information, the audit log record of inquiry resulting records correspondence promptly obtains the described audit log record that comprises known audit information.
9, user network behavior auditing method according to claim 7 is characterized in that, and is described according to described audit log record and the existing link field that comprises known audit information, the inquiry institute target journaling type of taking out each audit log of correspondence be:
With the value of existing link field in the described audit log record that comprises known audit information as condition of contact; Determine institute's target journaling type of taking out in each audit log of correspondence, the index file of described link field; Inquire about condition of contact in the sequencing table in determined index file, obtain the recording mechanism of condition of contact correspondence; In corresponding each audit log of taking-up target journaling type institute, the audit log record of inquiry resulting records correspondence.
10, user network behavior auditing method according to claim 7, it is characterized in that, described link field according to the Log Types under first Query Result and institute definite Log Types and the known audit information, inquiry institute definite Log Types each audit log of correspondence is:
With in described first Query Result the value of link field of the Log Types under definite Log Types and the known audit information as first condition of contact; Determine in corresponding each audit log of definite Log Types institute of institute the index file of the link field of the Log Types that definite Log Types of institute and known audit information are affiliated; Inquire about first condition of contact in the sequencing table in determined index file, obtain the recording mechanism of the first condition of contact correspondence; In corresponding each audit log of definite Log Types institute of institute, inquire about the audit log record of described first condition of contact institute corresponding record correspondence;
Accordingly, described link field according to second Query Result and institute definite Log Types and the target journaling type of taking out, inquire about the target journaling type of taking out each audit log of correspondence be:
With in described second Query Result the value of link field of definite Log Types and the target journaling type of taking out as second condition of contact; Determine in the target journaling type of taking out institute of institute each audit log of correspondence, the index file of definite Log Types and the link field of target journaling type of taking out; Inquire about second condition of contact in the sequencing table in determined index file, obtain the recording mechanism of the second condition of contact correspondence; In corresponding each audit log of taking-up target journaling type institute, inquire about the audit log record of described second condition of contact institute corresponding record correspondence.
CN2009100783072A 2009-02-24 2009-02-24 Audit apparatus and method for customer network behavior Active CN101483553B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN2009100783072A CN101483553B (en) 2009-02-24 2009-02-24 Audit apparatus and method for customer network behavior

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN2009100783072A CN101483553B (en) 2009-02-24 2009-02-24 Audit apparatus and method for customer network behavior

Publications (2)

Publication Number Publication Date
CN101483553A true CN101483553A (en) 2009-07-15
CN101483553B CN101483553B (en) 2011-09-21

Family

ID=40880495

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2009100783072A Active CN101483553B (en) 2009-02-24 2009-02-24 Audit apparatus and method for customer network behavior

Country Status (1)

Country Link
CN (1) CN101483553B (en)

Cited By (17)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101931557A (en) * 2010-08-13 2010-12-29 杭州迪普科技有限公司 User behaviour auditing method and system
CN102377828A (en) * 2010-08-06 2012-03-14 中兴通讯股份有限公司 System and method for user traceablility in NAT environment
CN102932492A (en) * 2011-09-12 2013-02-13 微软公司 Correlation of users to ip address lease events
CN103793479A (en) * 2014-01-14 2014-05-14 上海上讯信息技术股份有限公司 Log management method and log management system
CN106815125A (en) * 2015-12-02 2017-06-09 阿里巴巴集团控股有限公司 A kind of log audit method and platform
CN106897465A (en) * 2017-03-31 2017-06-27 联想(北京)有限公司 A kind of document audit method and system
CN107025233A (en) * 2016-01-29 2017-08-08 苏宁云商集团股份有限公司 A kind of processing method and processing device of data characteristics
CN107305521A (en) * 2016-04-20 2017-10-31 百度在线网络技术(北京)有限公司 Log recording method and device
CN107645542A (en) * 2017-09-03 2018-01-30 中国南方电网有限责任公司 A kind of data acquisition device applied to cloud auditing system
CN107656973A (en) * 2017-09-03 2018-02-02 中国南方电网有限责任公司 A kind of log audit subsystem applied to cloud auditing system
CN107688624A (en) * 2017-08-18 2018-02-13 杭州迪普科技股份有限公司 A kind of daily record index structuring method and device
CN108021458A (en) * 2017-12-01 2018-05-11 天津麒麟信息技术有限公司 A kind of multi-tenant audit indexing means based on message trigger
CN108111435A (en) * 2017-12-15 2018-06-01 北京星河星云信息技术有限公司 A kind of mass data auditing method and auditing system
CN108616415A (en) * 2018-03-16 2018-10-02 新华三大数据技术有限公司 data correlation method and device
CN109033813A (en) * 2018-07-09 2018-12-18 携程旅游信息技术(上海)有限公司 The auditing system and method for Linux operation log
CN110061993A (en) * 2019-04-23 2019-07-26 新华三技术有限公司 A kind of log generation method, device and access device comprising public network exit address
CN112346938A (en) * 2019-08-08 2021-02-09 腾讯科技(深圳)有限公司 Operation auditing method and device, server and computer readable storage medium

Cited By (23)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102377828A (en) * 2010-08-06 2012-03-14 中兴通讯股份有限公司 System and method for user traceablility in NAT environment
CN102377828B (en) * 2010-08-06 2015-09-16 中兴通讯股份有限公司 A kind of System and method for of tracing to the source for user under network address translation environment
CN101931557A (en) * 2010-08-13 2010-12-29 杭州迪普科技有限公司 User behaviour auditing method and system
CN101931557B (en) * 2010-08-13 2013-01-30 杭州迪普科技有限公司 User behaviour auditing method and system
CN102932492A (en) * 2011-09-12 2013-02-13 微软公司 Correlation of users to ip address lease events
CN103793479A (en) * 2014-01-14 2014-05-14 上海上讯信息技术股份有限公司 Log management method and log management system
CN106815125A (en) * 2015-12-02 2017-06-09 阿里巴巴集团控股有限公司 A kind of log audit method and platform
CN107025233A (en) * 2016-01-29 2017-08-08 苏宁云商集团股份有限公司 A kind of processing method and processing device of data characteristics
CN107025233B (en) * 2016-01-29 2020-04-28 苏宁云计算有限公司 Data feature processing method and device
CN107305521A (en) * 2016-04-20 2017-10-31 百度在线网络技术(北京)有限公司 Log recording method and device
CN106897465A (en) * 2017-03-31 2017-06-27 联想(北京)有限公司 A kind of document audit method and system
CN107688624B (en) * 2017-08-18 2020-12-29 杭州迪普科技股份有限公司 Log index construction method and device
CN107688624A (en) * 2017-08-18 2018-02-13 杭州迪普科技股份有限公司 A kind of daily record index structuring method and device
CN107645542A (en) * 2017-09-03 2018-01-30 中国南方电网有限责任公司 A kind of data acquisition device applied to cloud auditing system
CN107656973A (en) * 2017-09-03 2018-02-02 中国南方电网有限责任公司 A kind of log audit subsystem applied to cloud auditing system
CN108021458A (en) * 2017-12-01 2018-05-11 天津麒麟信息技术有限公司 A kind of multi-tenant audit indexing means based on message trigger
CN108111435A (en) * 2017-12-15 2018-06-01 北京星河星云信息技术有限公司 A kind of mass data auditing method and auditing system
CN108616415A (en) * 2018-03-16 2018-10-02 新华三大数据技术有限公司 data correlation method and device
CN109033813A (en) * 2018-07-09 2018-12-18 携程旅游信息技术(上海)有限公司 The auditing system and method for Linux operation log
CN109033813B (en) * 2018-07-09 2020-10-16 携程旅游信息技术(上海)有限公司 Linux operation log auditing system and method
CN110061993A (en) * 2019-04-23 2019-07-26 新华三技术有限公司 A kind of log generation method, device and access device comprising public network exit address
CN110061993B (en) * 2019-04-23 2022-06-24 新华三技术有限公司 Log generation method and device containing public network exit address and access equipment
CN112346938A (en) * 2019-08-08 2021-02-09 腾讯科技(深圳)有限公司 Operation auditing method and device, server and computer readable storage medium

Also Published As

Publication number Publication date
CN101483553B (en) 2011-09-21

Similar Documents

Publication Publication Date Title
CN101483553B (en) Audit apparatus and method for customer network behavior
CN103312836B (en) A kind of large-scale local network ip address management method
US20130067062A1 (en) Correlation of Users to IP Address Lease Events
DE102013108714B3 (en) Support decryption of encrypted data
CN106878483A (en) A kind of IP address distribution method and device
DE102008024798A1 (en) Method for over-the-air personalization of smart cards in telecommunications
CN107465617A (en) The message transmission control method and communication network device of communication network device
CN103200281A (en) Method, device and system for accessing intranet server
CN105228140A (en) A kind of data access method and device
CN101159758A (en) Classification associated dynamic host machine configuring protocol option distribution method and device
CN102394948B (en) DHCP (dynamic host configuration protocol) address distribution method and DHCP server
WO2012146120A1 (en) Method for forwarding response packet from dhcp server, forwarding device and system
CN102739812B (en) A kind of method of commending friends and device
CN105978748A (en) Terminal equipment information counting method and terminal equipment information counting device based on Hash node
CN103532796B (en) Large ISP interconnection port statistical system and method
CN104243209A (en) IP address content provider label coverage statistics method
CN101184099A (en) Second IP address assignment method based on dynamic host machine configuration protocol access authentication
CN102891901A (en) Dynamic domain name resolution method, server and domain name service system
CN102685265A (en) IP (Internet Protocol) address managing method, equipment and system
CN107547523A (en) Message processing method, device, the network equipment and machinable medium
EP4075356A1 (en) System and method for sending mail
CN104683491B (en) A kind of method and system for the Internet Protocol address for obtaining virtual machine
CN111654452B (en) Message processing method and device
CN104717176A (en) Access control method, access control system, and server
CN104113462B (en) PPPOE agreements multi-operator accesses shared link method

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant