CN103078766B - The auditing method of network traffics, device and the network equipment - Google Patents

The auditing method of network traffics, device and the network equipment Download PDF

Info

Publication number
CN103078766B
CN103078766B CN201210591000.4A CN201210591000A CN103078766B CN 103078766 B CN103078766 B CN 103078766B CN 201210591000 A CN201210591000 A CN 201210591000A CN 103078766 B CN103078766 B CN 103078766B
Authority
CN
China
Prior art keywords
audit
traffic information
network traffic
memory space
cycle
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201210591000.4A
Other languages
Chinese (zh)
Other versions
CN103078766A (en
Inventor
魏逢一
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Star Net Ruijie Networks Co Ltd
Original Assignee
Beijing Star Net Ruijie Networks Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Star Net Ruijie Networks Co Ltd filed Critical Beijing Star Net Ruijie Networks Co Ltd
Priority to CN201210591000.4A priority Critical patent/CN103078766B/en
Publication of CN103078766A publication Critical patent/CN103078766A/en
Application granted granted Critical
Publication of CN103078766B publication Critical patent/CN103078766B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Abstract

The invention discloses a kind of auditing method of network traffics, device and the network equipment, according to the method, in current predetermined audit cycle, the size of the memory space needed for the network traffic information of predetermined each audit target of storage, when judging to obtain idle memory space and be more than or equal to the memory space sum needed for the network traffic information of each audit target determined, add up the network traffic information that each audit target produces in a upper audit cycle successively, and store the network traffic information added up and obtain; Can before carrying out network traffics audit, just judge according to the situation of idle storage space in memory space, whether current have enough memory spaces to store the network traffic information of auditing and obtaining, thus can avoid the problem that in prior art, network audit flow information is lost.

Description

The auditing method of network traffics, device and the network equipment
Technical field
The present invention relates to network communication technology field, particularly, relate to a kind of auditing method of network traffics, device and the network equipment.
Background technology
Along with the high speed development of network, network size is also increasing, and the application carried in network and business are also more and more diversified.In the face of day by day complicated network, attendant wishes the traffic conditions of business and each business carried in awareness network usually, and Intranet user and traffic conditions thereof, and the ruuning situation of awareness network accordingly, whether reasonable to judge network bandwidth distribution that is whether sufficient, the network bandwidth.When there is Network Abnormal, can for location, dealing with problems provides enough foundations.Because network traffics audit has become the indispensable function of the network equipment one.
Network traffics audit can be divided into the network traffics of real-time network traffics audit and history to audit two kinds usually.Representated by wherein real-time network traffics audit is the current traffic conditions of network, and attendant can judge current network operation situation accordingly and carry out the track and localization of network failure; And be network traffic conditions and the network traffics tendency of the past period representated by the network traffics audit of history, be generally used for the network failure analysis of causes afterwards.Two kinds of network traffics audits have different application scenarios, and network operation situation and fault location are responsible for different responsibilities, are all that the network equipment is necessary usually.
Usually web-based history network auditing system is carried out by two kinds of methods in prior art.
Method one: the length first setting a sampling period, such as 10 minutes, then the data traffic size that the various audit targets (as each business, each user, user's group etc.) that sample devices forwards within each cycle produce, and be these dimensions generation network auditing system record, preserve in write into Databasce.Suppose that we need to audit the historical traffic information of Intranet each user, then the information record of periodic sampling is as shown in table 1, which includes the uplink traffic of user 1 ~ user 3 respectively within two sampling periods and downlink traffic.
Table 1
User name Uplink traffic (byte) Downlink traffic (byte) Time
User 1 100113 2340234 2012-8-3014:10:00~2012-8-3014:20:00
User 2 230543 323023 2012-8-3014:10:00~2012-8-3014:20:00
User 3 3232 432045024 2012-8-3014:10:00~2012-8-3014:20:00
User 1 234242 242424254 2012-8-3014:20:00~2012-8-3014:30:00
User 2 324563 423023 2012-8-3014:20:00~2012-8-3014:30:00
User 3 32322 23045024 2012-8-3014:20:00~2012-8-3014:30:00
In reality is implemented, attendant can need the field information of audit according to actual conditions additions and deletions, such as uplink packet number, downstream packets number etc.According to the audit information got, attendant just knows the average traffic rate of each user in each cycle, also can know the integrated flow situation of each user at the appointed time in scope.But in the method, because the sampling period is fixing, and under normal circumstances, the business number of the number of users in network and the network carrying all may change along with the change of network, if the same cycle needs the amount of information of record of the audit too many, when causing exceeding equipment audit handling property, just may there is network traffics audit information and lose, finally make the network traffics information provided of auditing become unreliable, final network traffics audit also just loses actual meaning.
Method two, on the basis of method one, performance according to the network equipment adjusts the sampling period automatically, adjustment mode is are contrasted in this processing time and the sampling period of presetting, if this processing time is greater than the default sampling period, then tune up the sampling period, otherwise turn the sampling period down, to make the network equipment can audit with the sampling period corresponding to the data traffic of reality, with the problem avoiding the audit information of network traffics to lose.But the method adjusted the duration in the sampling period of next cycle according to the handling duration in a upper sampling period, belonged to and adjusted, and had certain hysteresis quality afterwards, the loss of network auditing system information still may caused in some cases.
Visible, lack in prior art and effectively can solve the technical scheme that network traffics audit information loses problem.
Summary of the invention
In view of this, embodiments provide a kind of auditing method of network traffics, device and the network equipment, in order to solve in prior art in the process of network audit, to the problem that the audit information of network traffics is lost.
Embodiment of the present invention technical scheme is as follows:
A kind of auditing method of network traffics, comprise: in current predetermined audit cycle, the size of the memory space needed for the network traffic information of predetermined each audit target of storage, judges whether idle memory space is more than or equal to the memory space sum needed for network traffic information of each audit target determined; When judging to obtain idle memory space and be more than or equal to the memory space sum needed for the network traffic information of each audit target determined, add up the network traffic information that each audit target produces in a upper audit cycle successively, and store the network traffic information added up and obtain; When judging to obtain idle memory space and be less than the memory space sum needed for the network traffic information of each audit target determined, wait for predetermined latent period, when to wait for after this predetermined latent period then and the memory space of free time be more than or equal to each audit target determined network traffic information needed for memory space sum, add up the network traffic information that each audit target produces in a upper audit cycle and in latent period successively, and store the network traffic information added up and obtain.
An audit device for network traffics, comprising: determination module, for predefined each audit target of storage network traffic information needed for the size of memory space; Judge module, for in current predetermined audit cycle, the size of the memory space needed for the network traffic information of each audit target of storage determined according to described determination module, judges whether idle memory space is more than or equal to the memory space sum needed for network traffic information of each audit target that described determination module is determined; Audit Module, for judging that at described judge module obtaining idle memory space is more than or equal to determined memory space sum needed for the network traffic information of each audit target, add up the network traffic information that each audit target produces in a upper audit cycle successively; When described judge module judges to obtain the memory space sum needed for network traffic information that idle memory space is less than each audit target determined, wait for predetermined latent period, when to wait for after predetermined latent period then and the memory space of free time be more than or equal to each audit target determined network traffic information needed for memory space sum, add up the network traffic information that each audit target produces in a upper audit cycle successively; Memory module, adds up for storing described Audit Module the network traffic information obtained.
A kind of network equipment, comprises the audit device of network traffics as above.
In the technical scheme of the embodiment of the present invention, in current predetermined audit cycle, the size of the memory space needed for the network traffic information of predetermined each audit target of storage, judge whether idle memory space is more than or equal to the memory space sum needed for network traffic information of each audit target determined, when judging to obtain idle memory space and be more than or equal to the memory space sum needed for the network traffic information of each audit target determined, add up the network traffic information that each audit target produces in a upper audit cycle successively, and store the network traffic information added up and obtain, when judging to obtain idle memory space and be less than the memory space sum needed for the network traffic information of each audit target determined, wait for predetermined latent period, when to wait for after predetermined latent period then and the memory space of free time be more than or equal to each audit target determined network traffic information needed for memory space sum, add up the network traffic information that each audit target produces in a upper audit cycle and in latent period successively, and store the network traffic information added up and obtain, can before carrying out network traffics audit, just judge according to the situation of idle storage space in memory space, whether current have enough memory spaces to store the network traffic information of auditing and obtaining, thus can avoid the loss of network audit flow information in prior art.
Other features and advantages of the present invention will be set forth in the following description, and, partly become apparent from specification, or understand by implementing the present invention.Object of the present invention and other advantages realize by structure specifically noted in write specification, claims and accompanying drawing and obtain.
Accompanying drawing explanation
The workflow diagram of the auditing method of the network traffics that Fig. 1 provides for the embodiment of the present invention;
The structured flowchart of the audit device of the network traffics that Fig. 2 provides for the embodiment of the present invention;
Fig. 3 is the preferred structure block diagram of Fig. 2 shown device.
Embodiment
Below in conjunction with accompanying drawing, embodiments of the invention are described, should be appreciated that embodiment described herein is only for instruction and explanation of the present invention, is not intended to limit the present invention.
For in prior art in the process of network audit, to the problem that the audit information of network traffics is lost, embodiments provide a kind of auditing method of network traffics, device and the network equipment, to solve this problem.
Fig. 1 shows the auditing method of the network traffics that the embodiment of the present invention provides, and comprising:
Step 101, at current predetermined audit cycle (such as T n) in, the size of the memory space needed for the network traffic information of predetermined each audit target of storage, judges whether idle memory space is more than or equal to the memory space sum needed for network traffic information of each audit target determined;
Wherein, pre-determine the operation of the size of the memory space needed for network traffic information storing each audit target, specifically comprise: the storage size information needed for the network traffic information that the storage that acquisition distributes for each audit target in advance is once added up; Or, determine in several audit cycles before the current audit cycle respectively, the memory space shared by the network traffic information of each audit target with value average;
Preferably, idle memory space is the memory space of the free time in buffer memory; Idle memory space also can be the memory space in database, but be directly stored in database by adding up the data obtained, due to by data write into Databasce time, the operation of the data directory of the data that the establishment that usually also can walk abreast writes, the efficiency of storage operation will be affected like this, so data are preferably stored in buffer memory by the embodiment of the present invention;
Wherein, the audit target can comprise audit interface, business and/or user;
Step 102, when judging to obtain idle memory space (S) and be more than or equal to memory space sum (N) needed for the network traffic information of each audit target determined (i.e. S>=N), add up each audit target successively at a upper audit cycle (T n-1) the interior network traffic information (or being called audit information) produced, and store the network traffic information added up and obtain; Preferably, be stored in buffer memory by adding up the network traffic information obtained;
Step 103, when judging to obtain idle memory space and be less than the memory space sum needed for the network traffic information of each audit target determined (i.e. S < N), wait for predetermined latent period (U), after waiting for that predetermined latent period then, and the memory space of free time is when being more than or equal to the memory space sum needed for network traffic information of each audit target determined (i.e. S >=N), add up the network traffic information that each audit target produces in a upper audit cycle and in latent period successively, and store the network traffic information added up and obtain, preferably, be stored in buffer memory by adding up the network traffic information obtained,
Particularly, if after waiting for that a latent period then, idle memory space is still less than the memory space sum needed for network traffic information of each audit target determined, then continue to wait at least one latent period, until the memory space of free time is more than or equal to the memory space sum needed for network traffic information of each audit target determined.
Particularly, the process of the network traffic information that the statistics audit target produces in a upper audit cycle, specifically comprise: according to the initial time of last statistical operation and the initial time of this statistical operation, the network traffic information that the statistics audit target produces in a upper audit cycle, or, the statistics audit target, at a upper audit cycle and the network traffic information that produces in latent period, namely adds up the network traffic information that the audit target produces between the initial time and the initial time of this statistical operation of upper once statistical operation.
Wherein, the time span of predetermined audit cycle and the time span of predetermined latent period are all determined according to concrete application scenarios, and in follow-up method optimizing process, can also adjust the time span of audit cycle and the time span of latent period according to the situation of concrete enforcement and effect, obtain the time span value of ideal audit cycle and the time span value of latent period;
The network traffic information that the audit target produces comprises the network traffic information of the audit network traffic information of interface, the network traffic information of business and/or user, and network traffic information is by including but not limited to: the mark of the audit target, the sampling time in each audit cycle, uplink traffic, downlink traffic, converting flow and/or abandon flow.When uplink traffic or the downlink traffic of each audit target of concrete statistics, the length of the uplink message audit target produced in a upper audit cycle is carried out adding up and maybe the length of the downlink message of generation is added up.In like manner, converting flow and the process abandoning flow are also similar to this.
And, after storing added up network traffic information in the buffer, the quantity of memory space idle in buffer memory is deducted the memory space shared by network traffic information of the stored audit target, obtain the size of the memory space of the free time of next audit cycle.In follow-up process, after the network traffic information in buffer memory being imported to the audit statement in database, the memory space in buffer memory is discharged.
By above-mentioned processing procedure, can before carrying out network traffics audit, just judge according to the situation of idle storage space in memory space, whether current have enough memory spaces to store the network traffic information of auditing and obtaining, when having enough memory spaces, the network traffic information that the audit target generates is added up and stored, when not having enough memory spaces, dynamically adjust the cycle (namely waiting for predetermined latent period on the basis in current audit cycle) of statistical operation, until when there is enough memory spaces, just the network traffic information that the audit target generates is added up and stored, thus the loss of network audit flow information in prior art can be avoided.
Adding up and storing after after the network traffic information of the audit target, the network traffic information stored should derived and generate audit statement, audit statement is stored in more stable Database Systems in buffer memory.Particularly, according to audit cycle (T n) with predetermined report generation cycle (V n) corresponding relation, be stored into adding up the network traffic information that obtains in the audit statement in the report generation cycle corresponding with the current audit cycle.Report generation cycle (V n) can be the time span determined according to actual needs, such as 1 hour, 1 day, 1 week or 1 month, this time span also can adjust according to the situation of concrete enforcement and effect, generates an audit statement in each report generation cycle.Such as, audit cycle is 10 minutes, the report generation cycle is 1 day (namely 1440 minutes), then, report generation cycle corresponding 144 audit cycles, when being stored into the network traffic information of each audit target stored in buffer memory in database at every turn, can store according to the predetermined memory cycle, within such as 10 minutes, store once, then, the network traffic information added up in 144 audit cycles corresponding in 1 day time is all stored in the audit statement of this day in database.
Network traffic information is being imported (or being called write) in the process of the audit statement in database, usual meeting is in order to improve the performance of data query, it can be the data creation index of write into Databasce, but, if set up data directory while write data, the performance writing data will be caused sharply to decline, and especially when data volume is larger, the performance of write data can decline more obvious; And the embodiment of the present invention for network traffic information to write requirement of real-time higher, if write data performance significantly decline, with regard to likely cause the network traffic information in database to be written because etc. overabundance of data to be written cause block and lose.
For this problem, the embodiment of the present invention, after a report generation end cycle, generates the data directory of the network traffic information in the audit statement in this report generation cycle.Each being imported to by network traffic information in database so just can be avoided to create data directory while audit statement, significantly can promote the performance of preserving audit statement.Particularly, when judging that the current report generation cycle is a new cycle initial, for the network traffic information in the audit statement in the upper report generation cycle creates data directory, and create the audit statement in a current report generation cycle in a database, in during the current report generation cycle, to add up in the audit cycle corresponding current report generation cycle successively and the network traffic information stored in the buffer imports in this audit statement, and discharge corresponding memory space in buffer memory.
Further, the embodiment of the present invention also generates the chart of the network traffic information of each audit target in preserved audit statement, and this chart of preservation (can be preserved separately in a database separately, also can carry out preserving separately in the network equipment of auditing), so that directly read when inquiring about the network traffic information of the audit target and show the chart of this audit target, avoid directly inquiring about from database and reading the network traffic information of the audit target and gather, the processing load making paired data storehouse increases the weight of, affects the problem of query performance.Preferably, the chart of the network traffic information of the audit target can be generated when the network equipment is comparatively idle.
Based on identical inventive concept, the embodiment of the present invention additionally provides a kind of audit device of network traffics.
Fig. 2 shows the structured flowchart of the audit device of the network traffics that the embodiment of the present invention provides, and this device comprises:
Determination module 20, for predefined each audit target of storage network traffic information needed for the size of memory space;
Particularly, determination module 20 obtains the storage size information needed for the network traffic information once added up of storage of distributing for each audit target in advance; Or, determine in several audit cycles before the current audit cycle respectively, the memory space shared by the network traffic information of each audit target with value average;
Judge module 21, be connected to determination module 20, for in current predetermined audit cycle, the size of the memory space needed for the network traffic information of each audit target of storage determined according to determination module 20, judges whether idle memory space is more than or equal to the memory space sum needed for network traffic information of each audit target that determination module 20 is determined;
Audit Module 22, be connected to judge module 21, for judging that at described judge module 21 obtaining idle memory space is more than or equal to determined memory space sum needed for the network traffic information of each audit target, add up the network traffic information that each audit target produces in a upper audit cycle successively; When described judge module 21 judges that obtaining idle memory space is less than determined memory space sum needed for the network traffic information of each audit target, wait for predetermined latent period, when the latent period that wait is predetermined is then rear and the memory space of free time is more than or equal to determined memory space sum needed for the network traffic information of each audit target, add up the network traffic information that each audit target produces in a upper audit cycle successively;
Particularly, the initial time of Audit Module 22 according to last statistical operation and the initial time of this statistical operation, the network traffic information that the statistics audit target produces in a upper audit cycle, or the statistics audit target is at a upper audit cycle and the network traffic information that produces in latent period;
Memory module 23, is connected to Audit Module 22, adds up for storing described Audit Module 22 network traffic information obtained.
Function and the method shown in above-mentioned Fig. 1 of Fig. 2 shown device are similar, repeat no more here.
By device as shown in Figure 2, also can before carrying out network traffics audit, just judge according to the situation of idle storage space in memory space, whether current have enough memory spaces to store the network traffic information of auditing and obtaining, thus can avoid the loss of network audit flow information in prior art.
Preferably, as shown in Figure 3, on the basis of device as shown in Figure 2, the audit device of the network traffics that the embodiment of the present invention provides can further include: index generation module 24 and chart generating module 25;
Further, memory module 23, also for according to audit cycle and the corresponding relation in predetermined report generation cycle, is stored into adding up the network traffic information obtained in the audit statement in the report generation cycle corresponding with the current audit cycle
Index generation module 24, is connected to memory module 23, for after a report generation end cycle, generates the data directory of the network traffic information in the audit statement in this report generation cycle;
Chart generating module 25, is connected to memory module 23, for generating the chart of the network traffic information of each audit target in audit statement that described memory module 23 stores, and preserves this chart.
The function of Fig. 3 shown device is described above, repeats no more here.
Based on identical inventive concept, the embodiment of the present invention additionally provides a kind of network equipment, and this network equipment comprises device as shown in Figure 2 or Figure 3, and preferably, this network equipment can be router, switch or gateway device.
In sum, in the technical scheme of the embodiment of the present invention, in current predetermined audit cycle, the size of the memory space needed for the network traffic information of predetermined each audit target of storage, judge whether idle memory space is more than or equal to the memory space sum needed for network traffic information of each audit target determined, when judging to obtain idle memory space and be more than or equal to the memory space sum needed for the network traffic information of each audit target determined, add up the network traffic information that each audit target produces in a upper audit cycle successively, and store the network traffic information added up and obtain, when judging to obtain idle memory space and be less than the memory space sum needed for the network traffic information of each audit target determined, wait for predetermined latent period, when to wait for after predetermined latent period then and the memory space of free time be more than or equal to each audit target determined network traffic information needed for memory space sum, add up the network traffic information that each audit target produces in a upper audit cycle and in latent period successively, and store the network traffic information added up and obtain, can before carrying out network traffics audit, just judge according to the situation of idle storage space in memory space, whether current have enough memory spaces to store the network traffic information of auditing and obtaining, thus can avoid the loss of network audit flow information in prior art.
One of ordinary skill in the art will appreciate that realizing all or part of step that above-described embodiment method carries is that the hardware that can carry out instruction relevant by program completes, described program can be stored in a kind of computer-readable recording medium, this program perform time, step comprising embodiment of the method one or a combination set of.
In addition, each functional unit in each embodiment of the present invention can be integrated in a processing module, also can be that the independent physics of unit exists, also can be integrated in a module by two or more unit.Above-mentioned integrated module both can adopt the form of hardware to realize, and the form of software function module also can be adopted to realize.If described integrated module using the form of software function module realize and as independently production marketing or use time, also can be stored in a computer read/write memory medium.
Those skilled in the art should understand, embodiments of the invention can be provided as method, system or computer program.Therefore, the present invention can adopt the form of complete hardware embodiment, completely software implementation or the embodiment in conjunction with software and hardware aspect.And the present invention can adopt in one or more form wherein including the upper computer program implemented of computer-usable storage medium (including but not limited to magnetic disc store and optical memory etc.) of computer usable program code.
The present invention describes with reference to according to the flow chart of the method for the embodiment of the present invention, equipment (system) and computer program and/or block diagram.Should understand can by the combination of the flow process in each flow process in computer program instructions realization flow figure and/or block diagram and/or square frame and flow chart and/or block diagram and/or square frame.These computer program instructions can being provided to the processor of all-purpose computer, special-purpose computer, Embedded Processor or other programmable data processing device to produce a machine, making the instruction performed by the processor of computer or other programmable data processing device produce device for realizing the function of specifying in flow chart flow process or multiple flow process and/or block diagram square frame or multiple square frame.
These computer program instructions also can be stored in can in the computer-readable memory that works in a specific way of vectoring computer or other programmable data processing device, the instruction making to be stored in this computer-readable memory produces the manufacture comprising command device, and this command device realizes the function of specifying in flow chart flow process or multiple flow process and/or block diagram square frame or multiple square frame.
These computer program instructions also can be loaded in computer or other programmable data processing device, make on computer or other programmable devices, to perform sequence of operations step to produce computer implemented process, thus the instruction performed on computer or other programmable devices is provided for the step realizing the function of specifying in flow chart flow process or multiple flow process and/or block diagram square frame or multiple square frame.
Obviously, those skilled in the art can carry out various change and modification to the present invention and not depart from the spirit and scope of the present invention.Like this, if these amendments of the present invention and modification belong within the scope of the claims in the present invention and equivalent technologies thereof, then the present invention is also intended to comprise these change and modification.

Claims (11)

1. an auditing method for network traffics, is characterized in that, comprising:
In current predetermined audit cycle, the size of the memory space needed for the network traffic information of predetermined each audit target of storage, judges whether idle memory space is more than or equal to the memory space sum needed for network traffic information of each audit target determined;
When judging to obtain idle memory space and be more than or equal to the memory space sum needed for the network traffic information of each audit target determined, add up the network traffic information that each audit target produces in a upper audit cycle successively, and store the network traffic information added up and obtain;
When judging to obtain idle memory space and be less than the memory space sum needed for the network traffic information of each audit target determined, wait for predetermined latent period, when to wait for after this predetermined latent period then and the memory space of free time be more than or equal to each audit target determined network traffic information needed for memory space sum, add up the network traffic information that each audit target produces in a upper audit cycle and in latent period successively, and store the network traffic information added up and obtain;
Wherein, the memory space of described free time is the memory space of the free time in buffer memory;
Pre-determine the size of the memory space needed for network traffic information storing each audit target, specifically comprise: the storage size information needed for the network traffic information that the storage that acquisition distributes for each audit target in advance is once added up; Or, determine in several audit cycles before the current audit cycle respectively, the memory space shared by the network traffic information of each audit target with value average.
2. method according to claim 1, it is characterized in that, the network traffic information that the statistics audit target produces in a upper audit cycle, specifically comprise: according to the initial time of last statistical operation and the initial time of this statistical operation, the network traffic information that the statistics audit target produces in a upper audit cycle;
The network traffic information that the statistics audit target produces in a upper audit cycle and in latent period, specifically comprise: according to the initial time of last statistical operation and the initial time of this statistical operation, the statistics audit target is at a upper audit cycle and the network traffic information that produces in latent period.
3. method according to claim 1, is characterized in that, stores the network traffic information added up and obtain, specifically comprises:
According to audit cycle and the corresponding relation in predetermined report generation cycle, be stored into adding up the network traffic information obtained in the audit statement in the report generation cycle corresponding with the current audit cycle.
4. method according to claim 3, is characterized in that, described method also comprises:
After a report generation end cycle, generate the data directory of the network traffic information in the audit statement in this report generation cycle.
5. method according to claim 3, is characterized in that, described method also comprises:
Generate the chart of the network traffic information of each audit target in audit statement, and preserve this chart.
6. an audit device for network traffics, is characterized in that, comprising:
Determination module, for predefined each audit target of storage network traffic information needed for the size of memory space; Be specially the storage size information needed for the network traffic information once added up of storage that acquisition distributes for each audit target in advance; Or, determine in several audit cycles before the current audit cycle respectively, the memory space shared by the network traffic information of each audit target with value average;
Judge module, for in current predetermined audit cycle, the size of the memory space needed for the network traffic information of each audit target of storage determined according to described determination module, judges whether idle memory space is more than or equal to the memory space sum needed for network traffic information of each audit target that described determination module is determined;
Audit Module, for judging that at described judge module obtaining idle memory space is more than or equal to determined memory space sum needed for the network traffic information of each audit target, add up the network traffic information that each audit target produces in a upper audit cycle successively; When described judge module judges to obtain the memory space sum needed for network traffic information that idle memory space is less than each audit target determined, wait for predetermined latent period, when to wait for after predetermined latent period then and the memory space of free time be more than or equal to each audit target determined network traffic information needed for memory space sum, add up the network traffic information that each audit target produces in a upper audit cycle successively;
Memory module, adds up for storing described Audit Module the network traffic information obtained;
Wherein, the memory space of described free time is memory space idle in buffer memory.
7. device according to claim 6, is characterized in that, described Audit Module, specifically for:
According to the initial time of last statistical operation and the initial time of this statistical operation, the network traffic information that the statistics audit target produces in a upper audit cycle, or the statistics audit target is at a upper audit cycle and the network traffic information that produces in latent period.
8. device according to claim 6, is characterized in that, described memory module, specifically for:
According to audit cycle and the corresponding relation in predetermined report generation cycle, be stored into adding up the network traffic information obtained in the audit statement in the report generation cycle corresponding with the current audit cycle.
9. device according to claim 8, is characterized in that, described device also comprises:
Index generation module, after a report generation end cycle, generates the data directory of the network traffic information in the audit statement in this report generation cycle.
10. device according to claim 8, is characterized in that, described device also comprises:
Chart generating module, for generating the chart of the network traffic information of each audit target in audit statement that described memory module stores, and preserves this chart.
11. 1 kinds of network equipments, is characterized in that, comprise the device according to any one of claim 6 ~ 10.
CN201210591000.4A 2012-12-31 2012-12-31 The auditing method of network traffics, device and the network equipment Active CN103078766B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201210591000.4A CN103078766B (en) 2012-12-31 2012-12-31 The auditing method of network traffics, device and the network equipment

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201210591000.4A CN103078766B (en) 2012-12-31 2012-12-31 The auditing method of network traffics, device and the network equipment

Publications (2)

Publication Number Publication Date
CN103078766A CN103078766A (en) 2013-05-01
CN103078766B true CN103078766B (en) 2015-11-25

Family

ID=48155176

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201210591000.4A Active CN103078766B (en) 2012-12-31 2012-12-31 The auditing method of network traffics, device and the network equipment

Country Status (1)

Country Link
CN (1) CN103078766B (en)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105978706A (en) * 2016-04-14 2016-09-28 丽水市睿鼎知识产权咨询有限公司 Network traffic linkage auditing equipment and method
CN110991880B (en) * 2019-12-03 2020-12-01 乐清市风杰电子科技有限公司 Household power auditing system and method based on big data
CN112671922B (en) * 2020-12-29 2022-05-27 北京明朝万达科技股份有限公司 Industrial internet data processing system and method

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7346929B1 (en) * 1999-07-29 2008-03-18 International Business Machines Corporation Method and apparatus for auditing network security
CN102143071A (en) * 2011-03-09 2011-08-03 中兴通讯股份有限公司 Method and device for determining network flow as well as network equipment
CN102752774A (en) * 2012-07-06 2012-10-24 大唐移动通信设备有限公司 Non-real-time service flow monitoring time setting method and system

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6813731B2 (en) * 2001-02-26 2004-11-02 Emc Corporation Methods and apparatus for accessing trace data
US7143006B2 (en) * 2005-03-23 2006-11-28 Cisco Technology, Inc. Policy-based approach for managing the export of network flow statistical data

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7346929B1 (en) * 1999-07-29 2008-03-18 International Business Machines Corporation Method and apparatus for auditing network security
CN102143071A (en) * 2011-03-09 2011-08-03 中兴通讯股份有限公司 Method and device for determining network flow as well as network equipment
CN102752774A (en) * 2012-07-06 2012-10-24 大唐移动通信设备有限公司 Non-real-time service flow monitoring time setting method and system

Also Published As

Publication number Publication date
CN103078766A (en) 2013-05-01

Similar Documents

Publication Publication Date Title
CN109726016A (en) A kind of link tracing methods, devices and systems for distributed system
CN104601736A (en) Method and device for realizing short uniform resource locator (URL) service
CN105242983A (en) Data storage method and data storage management server
CN102916854A (en) Traffic statistical method and device and proxy server
CN103078766B (en) The auditing method of network traffics, device and the network equipment
CN104580018A (en) Bandwidth adjustment method and device in software-defined network
CN101763433A (en) Data storage system and method
CN109274777A (en) A kind of method, apparatus, equipment and readable storage medium storing program for executing exporting configuration file
CN103530335A (en) In-stockroom operation method and device of electric power measurement acquisition system
CN102404760A (en) Method and device for real-time measurement of system performance
CN104754521A (en) Message transmitting method, wireless access point, wireless controller and system
CN103026671B (en) A kind of method and apparatus of traffic shaping
US9641440B2 (en) Method and apparatus for maintaining token
CN102739531B (en) Flow shaping method and traffic shaping device
CN102710502A (en) Network speed-limiting method and device based on time wasting
CN101478495A (en) Flow limitation method and apparatus
CN103905335A (en) Flow control method and device
JP6257773B2 (en) Wireless body area network data processing method and apparatus
CN101753527A (en) Method, system and device for transmitting bandwidth distribution information in transport network
CN104104597B (en) A kind of data transmission method, Apparatus and system
CN104636397A (en) Resource allocation method, computation speedup method and device for distributed computation
CN103024715B (en) A kind of method that business datum flow based on tariff period is added up and device
CN107465629A (en) Method for limiting speed and device
CN102695154A (en) Base station straight-through architecture-based method, device and system for charging process
CN101777999A (en) Uploading method, system and server of network element historical performance data

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant