CN103312562B - A kind of method and device that detects P2P flow - Google Patents

A kind of method and device that detects P2P flow Download PDF

Info

Publication number
CN103312562B
CN103312562B CN201310228333.5A CN201310228333A CN103312562B CN 103312562 B CN103312562 B CN 103312562B CN 201310228333 A CN201310228333 A CN 201310228333A CN 103312562 B CN103312562 B CN 103312562B
Authority
CN
China
Prior art keywords
source host
session
host
source
active
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201310228333.5A
Other languages
Chinese (zh)
Other versions
CN103312562A (en
Inventor
陈强
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Topsec Technology Co Ltd
Original Assignee
Beijing Topsec Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Topsec Technology Co Ltd filed Critical Beijing Topsec Technology Co Ltd
Priority to CN201310228333.5A priority Critical patent/CN103312562B/en
Publication of CN103312562A publication Critical patent/CN103312562A/en
Application granted granted Critical
Publication of CN103312562B publication Critical patent/CN103312562B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Abstract

The method and the device that the invention discloses a kind of P2P of detection flow, the method comprises: source host is monitored, and on the quantity of the destination host connecting according to source host and source host, the quantity of active session, judges whether source host possesses P2P feature. This device comprises: monitoring modular and judge module. The present invention, compared with the existing type of service recognition methods based on DFI detection means, realizes simply, can, with less detection index, reach identical even higher accuracy of detection, thereby mention the detection efficiency of P2P flow, has shortened detection time. The technical scheme of combination DPI detection means of the present invention, can also further improve the accuracy of identification of P2P flow, than merely using DPI detection means recognition efficiency to improve 70-80%, only needs the extremely short time just can identify to more active application.

Description

A kind of method and device that detects P2P flow
Technical field
The present invention relates to network security technology field, relate in particular to a kind of P2P(Peer-to-Peer of detection, it is right to putPoint) method and the device of flow.
Background technology
Types of applications based on P2P agreement is more and more extensive, but brings simultaneously easily,Develop into gradually the killer of the network bandwidth, easily cause network congestion, have a strong impact on network service quality. At presentMain by DPI(DeepPacketInspection, deep-packet detection) and DFI(Deep/DynamicFlowInspection, the degree of depth/dynamic flow detects) two kinds of detection means combine P2P flow are identified. DiscriminationAspect is each has something to recommend him, due to DPI adopt packet-by-packet analyze, keyword match technology, can in flowConcrete application type and the agreement known accomplish to identify more accurately, but detection speed is slower; DFIThat traffic behavior is detected to analysis, to all known or unknown application systems that meet P2P discharge modelOne is identified as P2P flow, and accuracy of detection is not high.
A kind of method that has occurred at present identification services type based on DFI detection means, comprises the business of obtainingTraffic characteristic, it is one of following that this traffic characteristic comprises: the size of the real part of the effective data packets of business, industryThe ratio of the uplink and downlink packet of the data flow of business, according to the type of service of this traffic characteristic identification services.The defect of the method is: 1, detect index too much, efficiency is too low; 2, detection time long, need to be longer timeBetween could identify; 3, identification error rate is higher.
Therefore, how to improve the recognition efficiency to P2P flow, become this area technical problem urgently to be resolved hurrily.
Summary of the invention
The technical problem to be solved in the present invention is to provide a kind of method and device of the P2P of detection flow, raisingTo the recognition efficiency of P2P flow.
The technical solution used in the present invention is that the method for described detection P2P flow, comprising:
Source host is monitored, active on the quantity of the destination host connecting according to source host and source hostThe quantity of session, judges whether source host possesses P2P feature.
The acquisition process of the quantity of the destination host that further, described source host connects is as follows:
The IP address of the destination host by Statistic Source host access, determines the destination host that source host connectsQuantity;
On described source host, the acquisition process of the quantity of active session is as follows:
Connection state information based on preserving on source host is determined the active degree of session corresponding to each connection;
When the active degree of session higher than set the first threshold values time, described session is judged to be to active session,Count the quantity of active session on source host.
Further, the described connection state information based on source host is determined session corresponding to each connectionActive degree, specifically comprises:
The active degree initial value of the session of timer, each connection correspondence is set;
For arbitrary session, whenever time of timer then, judge whether described session exists transfer of data,If so, active degree current described session is increased to a unit amount, otherwise deduct a unitsValue.
Further, active session on the quantity of the described destination host connecting according to source host and source hostQuantity, judge that whether source host possesses P2P feature, specifically comprises:
A1, is included into monitoring list by source host to be monitored;
A2, judges whether the quantity of the destination host of source host connection meets the Second Threshold of setting, if so,Perform step A3, otherwise repeated execution of steps A2 is to process the next source host in monitoring list;
A3, judges whether the quantity of active session on source host meets the 3rd threshold values of setting, and if so, willDescribed source host is judged to be to possess the main frame of P2P feature, otherwise repeated execution of steps A2 is to process monitoring listIn next source host.
Further, described method also comprises:
In the time judging that source host possesses P2P feature, the connection state information based on preserving on source host filters outWith the packet of each join dependency, adopt DPI detection method to carry out type of service identification to packet.
The present invention also provides a kind of device of the P2P of detection flow, comprising:
Monitoring modular, for source host is monitored, obtain source host connect destination host quantity withAnd the quantity of active session on source host;
Judge module, for active session on the quantity of destination host that connects according to source host and source hostQuantity, judge whether source host possesses P2P feature.
Further, in the time obtaining the quantity of destination host of source host connection, described monitoring modular is specifically usedIn:
The IP address of the destination host by Statistic Source host access, determines the destination host that source host connectsQuantity;
In the time obtaining the quantity of active session on source host, described monitoring modular specifically for:
Connection state information based on preserving on source host is determined the active degree of session corresponding to each connection;
When the active degree of session higher than set the first threshold values time, described session is judged to be to active session,Count the quantity of active session on source host.
Further, in the time determining the active degree of session corresponding to each connection, also tool of described monitoring modularBody is used for:
The active degree initial value of the session of timer, each connection correspondence is set;
For arbitrary session, whenever time of timer then, judge whether described session exists transfer of data,If so, active degree current described session is increased to a unit amount, otherwise deduct a unitsValue.
Further, described monitoring modular, also for: source host to be monitored is included into monitoring list;
Described judge module, specifically comprises:
First judges submodule, sets for judging that whether the quantity of the destination host that source host connects meetSecond Threshold, if so, second judges submodule, otherwise repeats to call the first judgement submodule to process prisonSurvey the next source host in list;
Second judges submodule, whether meets the 3rd of setting for the quantity that judges active session on source hostThreshold values, if so, is judged to be described source host to possess the main frame of P2P feature, otherwise repeats to call firstJudge that submodule is to process the next source host in monitoring list.
Further, described judge module also for:
In the time judging that source host possesses P2P feature, the connection state information based on preserving on source host filters outWith the packet of each join dependency, adopt DPI detection method to carry out type of service identification to packet.
Adopt technique scheme, the present invention at least has following advantages:
Method and the device of detection P2P flow of the present invention, with the existing industry based on DFI detection meansBusiness kind identification method is compared, and realizes simply, can be with less detection index, reach identical even higherAccuracy of detection, thereby mentioned the detection efficiency of P2P flow, shortened detection time.
The technical scheme of combination DPI detection means of the present invention, the identification that can also further improve P2P flowPrecision, than merely being used DPI detection means recognition efficiency to improve 70-80%, to more active application onlyNeed the extremely short time just can identify.
Brief description of the drawings
Fig. 1 is the method flow diagram of the detection P2P flow of first embodiment of the invention;
Fig. 2 is the acquisition process schematic diagram of the quantity of active session on the source host of first embodiment of the invention;
Fig. 3 is the judgement implementation process signal for multiple source hosts to be monitored in first embodiment of the inventionFigure;
Fig. 4 is the installation composition schematic diagram of the detection P2P flow of second embodiment of the invention;
Fig. 5 is that the device of the detection P2P flow of second embodiment of the invention forms schematic diagram in detail;
Fig. 6 is the session active degree calculated examples schematic diagram of application example of the present invention.
Detailed description of the invention
Technological means and effect of taking for reaching predetermined object for further setting forth the present invention, below knotClose accompanying drawing and preferred embodiment, the present invention is described in detail as after.
First embodiment of the invention, a kind of method that detects P2P flow, as shown in Figure 1, comprises following toolBody step:
Step S101, monitors source host, obtains quantity and the source of the destination host of source host connectionThe quantity of active session on main frame. When source host access destination host, initiate connection request to destination host,Destination host is for providing the main frame of downloaded resources.
Concrete, the acquisition process of the quantity of the destination host that source host connects is as follows:
The IP address of the destination host by Statistic Source host access, determines the destination host that source host connectsQuantity;
As shown in Figure 2, on source host, the acquisition process of the quantity of active session is as follows:
S1, the connection state information based on preserving on source host is determined the journey of enlivening of session corresponding to each connectionDegree. In the time that source host and destination host connect, on source host, conventionally can preserve connection state information,Such as, preserve every with the form of session table and connect related five-tuple information: source IP address, orderIP address, source port, destination interface and protocol information, this is the known technology of this area, soPlace is not described in detail. Step S1 specifically comprises:
S11: the active degree initial value that the session of timer, each connection correspondence is set;
S12: for arbitrary session, whenever time of timer then, judge whether described session exists dataTransmission, if so, increases a unit amount by active degree current described session, otherwise deducts oneUnit amount. The size of unit amount can arrange as required flexibly.
S2, when the active degree of session higher than set the first threshold values time, described session is judged to be to active meetingTalk about, count the quantity of active session on source host.
Step S102, the number of active session on the quantity of the destination host connecting according to source host and source hostAmount, judges whether source host possesses P2P feature.
Preferably, as shown in Figure 3, for multiple source hosts to be monitored, method is also wrapped described in the present embodimentDraw together as the implementation process that judges:
A1, is included into monitoring list by source host to be monitored;
A2, judges whether the quantity of the destination host of source host connection meets the Second Threshold of setting, if so,Perform step A3, otherwise repeated execution of steps A2 is to process the next source host in monitoring list;
A3, judges whether the quantity of active session on source host meets the 3rd threshold values of setting, and if so, willDescribed source host is judged to be to possess the main frame of P2P feature, otherwise repeated execution of steps A2 is to process monitoring listIn next source host.
Preferably, method described in the present embodiment also comprises after step S102:
In the time judging that source host possesses P2P feature, the connection state information based on preserving on source host filters outWith the packet of each join dependency, adopt DPI detection method to carry out type of service identification to packet, follow-upCan carry out corresponding strategy to the P2P flow identifying.
Second embodiment of the invention, a kind of device that detects P2P flow, as shown in Figure 4, comprises following groupBecome part:
Monitoring modular 100, for source host is monitored, obtains the quantity of the destination host of source host connectionAnd the quantity of active session on source host; When source host access destination host, initiate to connect to destination hostRequest, destination host is for providing the main frame of downloaded resources.
Judge module 200, for active meeting on the quantity of destination host that connects according to source host and source hostThe quantity of words, judges whether source host possesses P2P feature.
Concrete, in the time obtaining the quantity of the destination host that source host connects, monitoring modular 100 specifically for:
The IP address of the destination host by Statistic Source host access, determines the destination host that source host connectsQuantity;
In the time obtaining the quantity of active session on source host, monitoring modular 100 specifically for:
Connection state information based on preserving on source host is determined the active degree of session corresponding to each connection.In the time that source host and destination host connect, on source host, conventionally can preserve connection state information; ThisThe known technology of this area, so locate not describe in detail.
When the active degree of session higher than set the first threshold values time, described session is judged to be to active session,Count the quantity of active session on source host.
Further, in the time determining the active degree of session corresponding to each connection, also tool of monitoring modular 100Body is used for:
The active degree initial value of the session of timer, each connection correspondence is set;
For arbitrary session, whenever time of timer then, judge whether described session exists transfer of data,If so, active degree current described session is increased to a unit amount, otherwise deduct a unitsValue.
Preferably, as shown in Figure 5, for multiple source hosts to be monitored, that installs described in the present embodiment is eachModule also comprises following function and implementation:
Monitoring modular 100, also for: source host to be monitored is included into monitoring list;
Judge module 200, specifically comprises:
Whether first judges submodule 201, meet and set for the quantity that judges the destination host that source host connectsSecond Threshold, if so, second judge submodule, otherwise repeat to call the first judgement submodule to processNext source host in monitoring list;
Second judges submodule 202, for judge the quantity of active session on source host whether meet set theThree threshold values, if so, are judged to be described source host to possess the main frame of P2P feature, otherwise repeat to callOne judges that submodule is to process the next source host in monitoring list.
It should be noted that, in the embodiment of the present invention, quantity and the source host of the destination host that source host connectsThe quantity of upper active session is two features that must judge, the present invention does not limit these two featuresJudgement order, that is to say, is not limited to the quantity of the destination host that first judges source host connection, also can be firstJudge the quantity of active session on source host.
Preferably, described in the present embodiment device in, described judge module also for:
In the time judging that source host possesses P2P feature, the connection state information based on preserving on source host filters outWith the packet of each join dependency, adopt DPI detection method to carry out type of service identification (to knowing to packetThe P2P flow not going out is carried out corresponding strategy).
Based on above-described embodiment, introduce an application example of the present invention below:
Application example of the present invention is that some behavioural characteristic values of network traffics are added up, according to the knot of statisticsFruit judges whether to possess P2P feature. The behavioural characteristic of statistics comprises following two aspects:
Feature 1: certain source host connects destination host quantity;
Feature 2: the quantity of the current active session of certain source host;
When feature 1 and feature 2 all reach the threshold values of setting, this main frame is considered to possess the master of P2P featureMachine.
Active session refers to that transmission data are than session more frequently, and the time of transmitting is continuously longer, active degreeHigher. The active degree of session, is defined as follows:
The initial value of session active degree is set as 0;
In a given timer time interval T, if session has transfer of data, at timer time TWhen end, the active degree value of this session adds 1, otherwise subtracts 1, and active degree value is minimum reduces to 0;
If the active degree value of session is greater than the first given threshold values, this session is exactly active session; FirstThe scope of threshold values can be 3~5, and preferred, the first threshold values is 4.
Fig. 6 is session active degree calculated examples schematic diagram, and as shown in Figure 6, arrow is illustrated in two timesIn point, (being in a time interval T of timer) has flow process, in T0, T1, T2, T3 moment,The active degree of session is respectively:
The active degree of session A is (0,1,2,3)
The active degree of session B is (0,1,0,1)
The active degree of session C is (0,1,0,0)
The thinking of application example of the present invention is mainly from flow, to extract feature, and traffic characteristic comprises that source host connectsThe quantity of the destination host connecing, the quantity of the active session of source host. Adopt DFI and DPI function synergic pairThe scheme that P2P flow is identified, and the main frame that possesses P2P feature to identifying proposed solution,Specifically comprise following process:
Step 1, user sets the source host scope that needs monitoring;
Step 2, arranges a timer, completes once to all monitored source hosts every a time cycleScanning, scanning process is as follows:
B21, detects the destination host number being connected with source host and whether is greater than the first specified threshold, if be greater than,Proceed scanning process below, otherwise, next main frame is scanned; The first specified threshold canThink 32-64, preferably 48.
B22, to source host, all sessions are carried out the calculating of active degree and are judged active session, if activeNumber of sessions is greater than the source host of the second specified threshold, is identified as the main frame that possesses P2P feature; SecondSpecified threshold can be 10~29, preferably 16.
Step 3, the session table of main frame based on possessing P2P feature filters out the data with each join dependencyBag, carries out type of service identification by DPI detection means to packet, if determine its type of service,Take corresponding strategy to process, if can not determine type of service, show the company at this packet placeIt is undesired to connect, and blocks this connection.
In the step 2 of this application example, mention timing, the time interval of monitoring is set, this time interval canWith with statistics session active degree time timer used the time interval identical, it is same fixed to adoptTime device. The number range in the time interval of this timer is 5~10 seconds, preferred, between the time of this timerBe divided into 8 seconds.
Application example of the present invention, the technical scheme that adopts DFI to combine with DPI, can fine identification P2PFlow, has improved 70-80% than the recognition efficiency that merely uses DPI detection means, should to relatively more activeJust can identify with the time cycle that only needs several timers.
By the explanation of detailed description of the invention, the technology that should take for reaching predetermined object the present inventionMeans and effect are able to more deeply and concrete understanding, but appended diagram is only to provide with reference to explanationWith, be not used for the present invention to be limited.

Claims (8)

1. a method that detects P2P flow, is characterized in that, comprising:
Source host is monitored, active on the quantity of the destination host connecting according to source host and source hostThe quantity of session, judges whether source host possesses P2P feature;
On described source host, the acquisition process of the quantity of active session is as follows:
Connection state information based on preserving on source host is determined the active degree of session corresponding to each connection;
When the active degree of session higher than set the first threshold values time, described session is judged to be to active session,Count the quantity of active session on source host;
The described connection state information based on source host is determined the active degree of session corresponding to each connection,Specifically comprise:
The active degree initial value of the session of timer, each connection correspondence is set;
For arbitrary session, whenever time of timer then, judge whether described session exists transfer of data,If so, active degree current described session is increased to a unit amount, otherwise deduct a unitsValue.
2. the method for detection P2P flow according to claim 1, is characterized in that described source hostThe acquisition process of the quantity of the destination host connecting is as follows:
The IP address of the destination host by Statistic Source host access, determines the destination host that source host connectsQuantity.
3. the method for detection P2P flow according to claim 1, is characterized in that, described according to sourceThe quantity of active session on the quantity of destination host that main frame connects and source host, judges whether tool of source hostStandby P2P feature, specifically comprises:
A1, is included into monitoring list by source host to be monitored;
A2, judges whether the quantity of the destination host of source host connection meets the Second Threshold of setting, if so,Perform step A3, otherwise repeated execution of steps A2 is to process the next source host in monitoring list;
A3, judges whether the quantity of active session on source host meets the 3rd threshold values of setting, and if so, willDescribed source host is judged to be to possess the main frame of P2P feature, otherwise repeated execution of steps A2 is to process monitoring listIn next source host.
4. according to the method for the detection P2P flow described in any one in claim 1~3, it is characterized in that,Described method also comprises:
In the time judging that source host possesses P2P feature, the connection state information based on preserving on source host filters outWith the packet of each join dependency, adopt DPI detection method to carry out type of service identification to packet.
5. a device that detects P2P flow, is characterized in that, comprising:
Monitoring modular, for source host is monitored, obtain source host connect destination host quantity withAnd the quantity of active session on source host;
Judge module, for active session on the quantity of destination host that connects according to source host and source hostQuantity, judge whether source host possesses P2P feature;
In the time obtaining the quantity of active session on source host, described monitoring modular specifically for:
Connection state information based on preserving on source host is determined the active degree of session corresponding to each connection;
When the active degree of session higher than set the first threshold values time, described session is judged to be to active session,Count the quantity of active session on source host;
In the time determining the active degree of session corresponding to each connection, described monitoring modular also specifically for:
The active degree initial value of the session of timer, each connection correspondence is set;
For arbitrary session, whenever time of timer then, judge whether described session exists transfer of data,If so, active degree current described session is increased to a unit amount, otherwise deduct a unitsValue.
6. the device of detection P2P flow according to claim 5, is characterized in that, is obtaining source masterWhen the quantity of destination host that machine connects, described monitoring modular specifically for:
The IP address of the destination host by Statistic Source host access, determines the destination host that source host connectsQuantity.
7. the device of detection P2P flow according to claim 5, is characterized in that described monitoring mouldPiece, also for: source host to be monitored is included into monitoring list;
Described judge module, specifically comprises:
First judges submodule, sets for judging that whether the quantity of the destination host that source host connects meetSecond Threshold, if so, second judges submodule, otherwise repeats to call the first judgement submodule to process prisonSurvey the next source host in list;
Second judges submodule, whether meets the 3rd of setting for the quantity that judges active session on source hostThreshold values, if so, is judged to be described source host to possess the main frame of P2P feature, otherwise repeats to call firstJudge that submodule is to process the next source host in monitoring list.
8. according to the device of the detection P2P flow described in any one in claim 5~7, it is characterized in that,Described judge module also for:
In the time judging that source host possesses P2P feature, the connection state information based on preserving on source host filters outWith the packet of each join dependency, adopt DPI detection method to carry out type of service identification to packet.
CN201310228333.5A 2013-06-08 2013-06-08 A kind of method and device that detects P2P flow Active CN103312562B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201310228333.5A CN103312562B (en) 2013-06-08 2013-06-08 A kind of method and device that detects P2P flow

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201310228333.5A CN103312562B (en) 2013-06-08 2013-06-08 A kind of method and device that detects P2P flow

Publications (2)

Publication Number Publication Date
CN103312562A CN103312562A (en) 2013-09-18
CN103312562B true CN103312562B (en) 2016-05-11

Family

ID=49137363

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201310228333.5A Active CN103312562B (en) 2013-06-08 2013-06-08 A kind of method and device that detects P2P flow

Country Status (1)

Country Link
CN (1) CN103312562B (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113729622A (en) * 2020-05-29 2021-12-03 芯海科技(深圳)股份有限公司 Biological index measuring method, biological index measuring device, biological index measuring apparatus, and storage medium

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1863154A (en) * 2005-10-18 2006-11-15 华为技术有限公司 Method for limiting current for point to point application
CN1889475A (en) * 2006-07-31 2007-01-03 南京信风软件有限公司 Method for real-time monitoring P2P application consumed bandwidth
CN101051997A (en) * 2006-11-20 2007-10-10 深圳市深信服电子科技有限公司 P2P flow identifying control method based on network application
CN101645803A (en) * 2008-08-05 2010-02-10 中兴通讯股份有限公司 P2P service identification method and Internet service identification system

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8819244B2 (en) * 2010-04-07 2014-08-26 Apple Inc. Apparatus and method for establishing and utilizing backup communication channels

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1863154A (en) * 2005-10-18 2006-11-15 华为技术有限公司 Method for limiting current for point to point application
CN1889475A (en) * 2006-07-31 2007-01-03 南京信风软件有限公司 Method for real-time monitoring P2P application consumed bandwidth
CN101051997A (en) * 2006-11-20 2007-10-10 深圳市深信服电子科技有限公司 P2P flow identifying control method based on network application
CN101645803A (en) * 2008-08-05 2010-02-10 中兴通讯股份有限公司 P2P service identification method and Internet service identification system

Also Published As

Publication number Publication date
CN103312562A (en) 2013-09-18

Similar Documents

Publication Publication Date Title
US10469364B2 (en) System and method for real-time load balancing of network packets
CN110324210B (en) Detection method and device for covert channel communication based on ICMP (Internet control protocol)
CN106303751B (en) Method and system for realizing directional flow packet
EP2210370B1 (en) Method and monitoring component for network traffic monitoring
CN106487605B (en) Packet loss rate detection method and device
CN104243237A (en) P2P flow detection method and device
CN113411260A (en) Method and device for sending data message in IPv6 network
JP5916877B2 (en) Method, system, and computer program for testing a DIAMETER routing node
CN110248379B (en) Performance test method and device for base station in wireless local area network
CN103312562B (en) A kind of method and device that detects P2P flow
CN107222403A (en) A kind of data transmission method, system and electronic equipment
FI124815B (en) Processing of call data records
CN105704088A (en) Multi-user shared Internet access detection method and device
CN106230741A (en) A kind of method and apparatus that message is carried out speed limit
CN101447934A (en) Business flow-recognizing method and system thereof and business flow charging method and system thereof
CN106921534A (en) Data traffic monitoring and managing method and device
CN101753372B (en) Detection method and device of bearer network router equipment
CN111224891A (en) Traffic application identification system and method based on dynamic learning triples
CN104253712B (en) A kind of method that P2P Network Recognitions are carried out using deep packet inspection technical
CN102340532B (en) P2P application identification method and device as well as P2P flow management method and device
CN106612241A (en) Service control method and service control device
CN105515896B (en) A kind of judgment method and device of mobile terminal network obstruction
CN102136952B (en) Condition code failure detection method and system
CN110098982B (en) Link state providing method, device, router and computer readable storage medium
CN108011939B (en) Method and device for restoring network session

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C53 Correction of patent for invention or patent application
CB02 Change of applicant information

Address after: 100085 Beijing, East Road, No. 1, building on the north side of the building, Room 301, room 3

Applicant after: BEIJING TOPSEC TECHNOLOGY CO., LTD.

Address before: 100085 Beijing, East Road, No. 1, building on the north side of the building, Room 301, room 3

Applicant before: Beijing heaven melts letter Science Technologies Co., Ltd.

COR Change of bibliographic data

Free format text: CORRECT: APPLICANT; FROM: BEIJING HEAVEN MELTS LETTER SCIENCE TECHNOLOGIES CO., LTD. TO: BEIJING TOPSEC TECHNOLOGY CO., LTD.

C53 Correction of patent for invention or patent application
CB02 Change of applicant information

Address after: 100085 Beijing, East Road, No. 1, building on the north side of the building, Room 301, room 3

Applicant after: Beijing heaven melts letter Science Technologies Co., Ltd.

Address before: 100085 Beijing, East Road, No. 1, building on the north side of the building, Room 301, room 3

Applicant before: BEIJING TOPSEC TECHNOLOGY CO., LTD.

COR Change of bibliographic data

Free format text: CORRECT: APPLICANT; FROM: BEIJING TOPSEC TECHNOLOGY CO., LTD. TO: BEIJING HEAVEN MELTS LETTER SCIENCE TECHNOLOGIES CO., LTD.

CB02 Change of applicant information

Address after: 100085 Beijing, East Road, No. 1, building on the north side of the building, Room 301, room 3

Applicant after: BEIJING TOPSEC TECHNOLOGY CO., LTD.

Address before: 100085 Beijing, East Road, No. 1, building on the north side of the building, Room 301, room 3

Applicant before: Beijing heaven melts letter Science Technologies Co., Ltd.

COR Change of bibliographic data
C14 Grant of patent or utility model
GR01 Patent grant
C56 Change in the name or address of the patentee
CP01 Change in the name or title of a patent holder

Address after: 100085 Beijing, East Road, No. 1, building on the north side of the building, Room 301, room 3

Patentee after: Beijing heaven melts letter Science Technologies Co., Ltd.

Address before: 100085 Beijing, East Road, No. 1, building on the north side of the building, Room 301, room 3

Patentee before: BEIJING TOPSEC TECHNOLOGY CO., LTD.