CN105827522A - Gateway equipment for processing log files - Google Patents

Gateway equipment for processing log files Download PDF

Info

Publication number
CN105827522A
CN105827522A CN201510762850.XA CN201510762850A CN105827522A CN 105827522 A CN105827522 A CN 105827522A CN 201510762850 A CN201510762850 A CN 201510762850A CN 105827522 A CN105827522 A CN 105827522A
Authority
CN
China
Prior art keywords
module
journal file
information
name
domain
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201510762850.XA
Other languages
Chinese (zh)
Inventor
张力锴
熊远雄
李毅洪
李幼庭
郭凯
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Guangdong Eshore Technology Co Ltd
Original Assignee
Guangdong Eshore Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Guangdong Eshore Technology Co Ltd filed Critical Guangdong Eshore Technology Co Ltd
Priority to CN201510762850.XA priority Critical patent/CN105827522A/en
Publication of CN105827522A publication Critical patent/CN105827522A/en
Pending legal-status Critical Current

Links

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention discloses gateway equipment for processing log files. The equipment comprises a log file creation module for creating a log file and storing the log file in the same directory; an acquisition module for acquiring data packets in access requests sent from all user equipment to the external network; a domain name extraction module for extracting the initial domain name information out of each data packet in the application layer of the gateway equipment, wherein the initial domain name information contains the protocol field information; a judgment module for judging whether the protocol field information contains the HTTP protocol or not and whether the protocol field information contains the HTTPs protocol or not; a log file storage module for storing data packets compatible with the HTTP protocol/HTTPs protocol in the log file, and a filtering module for filtering data packets not compatible with the HTTP protocol and the HTTPs protocol. According to the technical scheme of the invention, the network behaviors of all user equipment can be recorded in the log file. Meanwhile, the processing efficiency of a server is improved through simplifying the log file.

Description

Process the gateway device of journal file
Technical field
The present invention relates to network and communication technical field, particularly relate to a kind of gateway processing journal file and set Standby.
Background technology
The WiFi equipment provided for operator, public security department proposes safety standard requirements.Additionally, public security Goal operator can help to demand the bad network behavior of some individuals.
In order to be monitored the network behavior that some are bad, Chinese invention patent CN104702424A discloses The method and device of monitoring " a kind of network behavior ", this invention by network access equipment read subscriber equipment to The packet that carries in the data access request that network side sends, then network access equipment by packet with pre- The unlawful data of definition is compared, if predefined unlawful data comprises packet, network access equipment pair Data access request intercepts.Described packet is the URL that user sends to network side URL and the access moment of user.This invention for user side access behavior, intercept its URL and timestamp, And determine whether unauthorized access according to URL and timestamp.If unauthorized access then intercepts this access behavior. Therefore, will realize this technical scheme, this device needs possess a huge knowledge base coupling access behavior Packet, judges this access legitimacy of behavior with this.Therefore, complexity and the cost of this device are added. If additionally, this knowledge base is little, it is easy to accessing the interception causing mistake, reduce the Experience Degree of user.If This knowledge base is big, adds the workload of coupling, reduces the process performance of device and reduce the body of user Degree of testing.
In order to be monitored the network behavior that some are bad, Chinese invention patent CN104639387A discloses " a kind of user network behavior tracking method and apparatus ".This user network behavior tracking method includes walking as follows Rapid: to monitor user's login behavior by equipment, generate user name and identify, then upload server, real The behavior tracking now user accessed.This invention is logged in by account number cipher just for user or anonymous login Situation conducts interviews behavior tracking.Therefore, this invention fails access behavior comprehensive to user and is tracked. Additionally, the process of tracking needs a large amount of detective and coupling work, both invaded the network privacy of user, also reduced The treatment effeciency of this equipment, have impact on the Experience Degree of user.
In sum, no matter it is that network access equipment is according to the packet received and predefined unlawful data Matching result judge that whether the network behavior of subscriber equipment is the technical scheme of bad network behavior, or The technical scheme that the network behavior of user logged in is tracked by server, all exist network access equipment or The workload of service end is big, so that the problem that treatment effect is low and user experience is low.Therefore, how to promote Network access equipment or the treatment effeciency of server and user experience, be technical problem the most urgently to be resolved hurrily.
Summary of the invention
In view of this, being necessary in fact to provide a kind of gateway device, this gateway device passes through journal file record institute There is the network behavior of user.And this gateway device is to sending after simplifying in journal file to processing equipment (example As: server), reduce the workload of server, to promote treatment effect and the user experience of this server.
A kind of gateway device processing journal file, gateway device includes journal file creation module, obtains mould Block, domain name extraction module, judge module, journal file memory module and filtering module.Journal file creates Module, is used for creating journal file, and journal file is positioned under same catalogue.Acquisition module, is used for obtaining institute Packet in the access request that some subscriber equipment external network send.Domain name extraction module, is used for The application layer of gateway device extracts the initial domain-name information in each packet, and initial domain-name information includes association View field information.Judge module, is used for judging whether protocol fields information is http agreement and judges agreement word Whether segment information is https agreement.Journal file memory module, if being http agreement for protocol fields information If or protocol fields information is https agreement, the packet corresponding with protocol fields information is stored to daily record literary composition Part.Filtering module, if for protocol fields information non-http agreement and protocol fields information non-https agreement, Filter the packet corresponding with protocol fields information.
Preferably, gateway device also includes that domain name simplifies module and discard processing module.Domain name simplifies module, For by the initial domain name information reduction in all packets in journal file for simplifying domain-name information.Judge For judgement, module, simplifies whether domain-name information comprises network name, domain name main body and domain suffix.Abandon place Reason module, if any one for simplify that domain-name information do not comprises in network name, domain name main body or domain suffix Xiang Shi, carries out discard processing by the packet corresponding with simplifying domain-name information.
Preferably, gateway device also includes MAC Address extraction module, timestamp extraction module and removes molality Block.MAC Address extraction module, for the packet from journal file of the data link layer at gateway device Middle extraction terminal MAC address information.Timestamp extraction module, for the physical layer at gateway device from day Extraction time stamp information in packet in will file.Judge module, is used for judging whether to meet duplicate removal Two packets of condition, duplicate removal condition is: two packets have identical simplifies domain-name information, has phase With interlude section between terminal MAC address information and both timestamp informations preset time period with In.Deduplication module, if meet two packets of duplicate removal condition for existing, remove wherein with a little later The packet that timestamp information is corresponding.
Preferably, gateway device also includes naming module.Name module, for generating the file of journal file Name information, file name information includes temporal information, reference number of a document and suffix.
Preferably, gateway device also includes arranging module.Module is set, for arranging log file size Higher limit.
Preferably, journal file creation module, if the size being additionally operable to journal file reaches higher limit, wound Building new journal file, new journal file is stored under catalogue.Name module, for generating new daily record The new file name information of file, file name information includes temporal information, reference number of a document+1 and suffix.
Preferably, gateway device also includes receiver module, upper transmission module, detection module and cleaning module.Connect Receive module, be additionally operable to receive the request uploading journal file that external network sends.Upper transmission module, for Pass all of journal file.Detection module, is used for being spaced preset time period, detects whether to receive extranets The feedback information that the journal file that network sends has been uploaded.Cleaning module, if for receiving feedback information, All of journal file under the catalogue of journal file is deposited in cleaning.
The present invention have recorded the packet of the network behavior of all users by journal file, and filters out Protocol fields information non-http agreement and the packet of protocol fields information non-https agreement, so that daily record is civilian Part only saves useful packet.When journal file sends to server, improve server according to being somebody's turn to do Packet demands the speed of bad network behavior.
Accompanying drawing explanation
Fig. 1 is the block diagram that the present invention processes a kind of embodiment of gateway device of journal file.
Fig. 2 is the block diagram that the present invention processes the gateway device another kind embodiment of journal file.
Fig. 3 is that the present invention processes the gateway device of journal file block diagram of embodiment in another.
Detailed description of the invention
In order to make the purpose of the present invention, technical scheme and advantage clearer, below in conjunction with accompanying drawing and reality Execute example, the present invention is further elaborated.Only should be appreciated that specific embodiment described herein Only in order to explain the present invention, it is not used to limit the present invention.
Fig. 1 illustrates a kind of embodiment that the present invention processes the gateway device of journal file.In the present embodiment, The gateway device (such as: router) of this process journal file, including journal file creation module 100, life Name module 101, arrange module 102, acquisition module 103, domain name extraction module 104, judge module 105, Journal file memory module 106, filtering module 107, receiver module 108, upper transmission module 109, detection Module 110 and cleaning module 111.
Wherein, journal file creation module 100, it is used for creating journal file, this journal file is positioned at same Under catalogue.So-called journal file, is that gateway device is by intercepting and capturing all of user equipment access external network Access request, and use the record information extracted in ad hoc fashion packet from this access request. So-called catalogue is Log Directory (such as :/etc_ro/log), and the most all of journal file is all stored in this day In will catalogue.It should be noted that after the Log Directory in the present embodiment is stored in gateway device power-off, should The particular disk subregion that journal file under Log Directory will not lack.Such as: the flash subarea of router. Name module 101, for generating the file name information of journal file, file name information includes that the time believes Breath, reference number of a document and suffix.Such as: journal file is named with this form: date (such as " 2014-10-29 ") + reference number of a document (such as " _ 1 ")+suffix (such as " .log ") is finally constituted file name information: “2014-10-29_1.log”.Module 102 is set, for arranging the higher limit of log file size.Such as: The higher limit of the size arranging journal file is 4M.If the size of journal file exceedes higher limit (4M). Journal file creation module 100, for creating new journal file, new journal file is still stored in same Under catalogue.That is, new journal file is still stored in Log Directory (such as :/etc_ro/log).Name module 101, For generating the new file name information of new journal file, new file name information include temporal information, Reference number of a document+1 and suffix.That is: the reference number of a document of new journal file is on the basis of previous journal file On add 1.
Wherein, acquisition module 103, the access sent for obtaining all of subscriber equipment external network please Packet in asking.Domain name extraction module 104, extracts each data for the application layer at gateway device Initial domain-name information in bag, initial domain-name information includes protocol fields information.So-called initial domain-name information is The detailed network address provided during user equipment access external network, i.e. uniform resource position mark URL.Such as: Assume that initial domain-name information when user accesses Baidu is: Https: //www.baidu.com/?Tn=06008006_2_pg.So-called protocol fields information includes: http-is super civilian HTML (Hypertext Markup Language), ftp-file that this host-host protocol resource, https-transmit by security socket layer pass The search of transmission protocol, mailto-e-mail address, ldap-Lightweight Directory Access Protocol, file-locality electricity Brain or the file shared on the net, news-Usenet newsgroup, gopher-Gopher agreement and telnet- Telnet agreement etc..Judge module 105, is used for judging whether protocol fields information is http agreement and judgement Whether protocol fields information is https agreement.Journal file memory module 106, if for protocol fields information If being http agreement or protocol fields information being https agreement, the packet corresponding with protocol fields information is deposited Storage is to journal file.I.e. in journal file, only storage protocol fields information is http agreement or protocol fields information For the packet of https agreement, decrease the quantity of packet in journal file, therefore, work as journal file When transmission is to server, reduces the process workload of server, improve the treatment effect of server.This Outward, filtering module 107, if for protocol fields information non-http agreement and the non-https of protocol fields information Agreement, filters the packet corresponding with protocol fields information.The number that so-called filtration is corresponding with protocol fields information According to bag, this packet is not stored to journal file.
Wherein, receiver module 108, it is additionally operable to receive the request uploading journal file that external network sends. I.e. server sends and uploads the request of journal file to gateway device.Upper transmission module 109, is used for uploading all Journal file.Detection module 110, is used for being spaced preset time period, detects whether to receive external network The feedback information that the journal file sent has been uploaded.So-called preset time period is the time that program is arranged, Such as: 60s.The process that so-called external network sends feedback information is: gateway device uploads all of daily record literary composition Part, to server, after server detects all of journal file of acquisition, will send one entitled " done " File should store to Log Directory by " done " file to gateway device, gateway device.When detection mould When block 110 detects this " done " file under Log Directory, clear up module 111, deposit for cleaning All of journal file under the catalogue of journal file.That is: cleaning module 111 is to all literary compositions under Log Directory Part is cleared up, and discharges the space of this Log Directory.
Fig. 2 illustrates a kind of embodiment that the present invention processes the gateway device of journal file.The merit of the present embodiment Energy module is the most identical with the above embodiments, and the present embodiment is with the above embodiments difference, this The gateway device of embodiment also includes that domain name simplifies module 112 and discard processing module 113.Wherein, domain name Simplify module 112, be used for the initial domain name information reduction in all packets in journal file as simplifying Domain-name information.Such as: assume that initial domain-name information isHttps: //www.baidu.com/?Tn=06008006_2_pg, then domain name simplifies module 112 to this initial domain name Information becomes after simplifying:www.baidu.com.Wherein, the entitled www of network.Domain name main body is baidu. Domain suffix is.com.For judgement, judge module 105, simplifies whether domain-name information comprises network name, territory Name main body and domain suffix.When judge module judge simplify domain-name information do not comprise network name, domain name main body and In domain suffix arbitrary one, i.e. simplify domain-name information for sky.Or when judge module judges to simplify domain name letter Breath only comprises in network name, domain name main body and domain suffix arbitrary one, such as:.com.Or when judging Module judges that simplifying domain-name information only comprises in network name, domain name main body and domain suffix arbitrary two, such as:www.baidu.When there is in above-mentioned three kinds of situations any, discard processing module 113, for will be with essence The packet that letter domain-name information is corresponding carries out discard processing.That is, discard processing module 113 will with simplify domain name Packet corresponding to information is deleted from journal file.The present embodiment is by the packet in journal file Quantity is simplified further, has reached the effect of the treatment effect promoting server further.
Fig. 3 illustrates a kind of embodiment that the present invention processes the gateway device of journal file.The merit of the present embodiment Energy module is the most identical with the above embodiments, and the present embodiment is with the above embodiments difference, this The gateway device of embodiment also includes MAC Address extraction module, timestamp extraction module and deduplication module. Wherein, MAC Address extraction module, for the data from journal file of the data link layer at gateway device Bag extracts terminal MAC address information.So-called mac address information is used for identifying each user.Typically Form be two hexadecimal numbers be one group, six groups altogether, middle separate with colon.Such as: 3c:97:0e:d2:f6:67.Timestamp extraction module, for the physical layer at gateway device from journal file Extraction time stamp information in packet.Timestamp information is the time at that time of user equipment access external network Information.When this timestamp information information includes, three fields of minute, second.Such as: 11:05:43.Judge module 105, for judging whether to meet two packets of duplicate removal condition, duplicate removal condition is: two packets Have identical simplify domain-name information, have same terminal mac address information and both timestamp informations it Between interlude section within preset time period.So-called preset time period is the time period that program is arranged, Such as: 3 minutes.That is: assuming to there are two packets, the domain-name information of simplifying of a packet iswww.baidu.com, terminal MAC address information is 3c:97:0e:d2:f6:67, and timestamp information information is 11:05:43.The domain-name information of simplifying of another packet iswww.baidu.com, terminal MAC address is believed Breath is 3c:97:0e:d2:f6:67, and timestamp information is 11:07:43.Therefore, illustrate that terminal MAC address is believed Breath have accessed two within 3 minutes simplify domain-name information for 3c:97:0e:d2:f6:67www.baidu.com External network, in this case, deduplication module, for remove wherein with timestamp information a little later Corresponding packet.I.e. deduplication module, simplifying domain-name information in deletion journal file iswww.baidu.com, Terminal MAC address information is 3c:97:0e:d2:f6:67, and timestamp information is the packet of 11:07:43, reaches To simplifying the technique effect of journal file further, and promote the skill of the treatment effeciency of server further Art effect.
Being described in detail the detailed description of the invention of invention above, but it is only used as example, the present invention is also It is not intended to and specific embodiments described above.For a person skilled in the art, any to this The bright equivalent modifications carried out or replacement are the most all among scope of the invention, therefore, without departing from the present invention's The impartial conversion made under spirit and spirit and amendment, improvement etc., all should contain in the scope of the present invention In.

Claims (7)

1. the gateway device processing journal file, it is characterised in that described gateway device includes daily record literary composition Part creation module, acquisition module, domain name extraction module, judge module, journal file memory module and filtration Module;Described journal file creation module, is used for creating journal file, and described journal file is positioned at same mesh Under record;Described acquisition module, for obtaining in the access request that all of subscriber equipment external network sends Packet;Domain name extraction module, extracts described in each for the application layer at described gateway device Initial domain-name information in packet, described initial domain-name information includes protocol fields information;Described judgement mould Block, is used for judging whether described protocol fields information is http agreement and whether judges described protocol fields information For https agreement;Described journal file memory module, if being described http for described protocol fields information If agreement or described protocol fields information are described https agreements, by the number corresponding with described protocol fields information Store to described journal file according to bag;Described filtering module, if for the non-described http of described protocol fields information Agreement and the non-described https agreement of described protocol fields information, filter the number corresponding with described protocol fields information According to bag.
The gateway device of process journal file the most according to claim 1, it is characterised in that described net Pass equipment also includes that domain name simplifies module and discard processing module;Domain name simplifies module, for by described Initial domain name information reduction in all packets in journal file is for simplifying domain-name information;Described judgement mould Block, be used for judging described in simplify whether domain-name information comprises network name, domain name main body and domain suffix;Described Discard processing module, if simplify described in Yong Yu domain-name information do not comprise described network name, domain name main body or During any one in domain name suffix, will abandon with the described packet simplifying domain-name information corresponding Process.
The gateway device of process journal file the most according to claim 2, it is characterised in that described net Pass equipment also includes MAC Address extraction module, timestamp extraction module and deduplication module;Described MAC Address extraction module, for the packet from described journal file of the data link layer at described gateway device Middle extraction terminal MAC address information;Described timestamp extraction module, for the thing at described gateway device Extraction time stamp information in reason layer packet from described journal file;Described judge module, is used for judging Existence meets two described packets of duplicate removal condition, and described duplicate removal condition is: two packets have Simplify domain-name information described in identical, there is identical described terminal MAC address information and both timestamps letter Between breath, interlude section is within preset time period;Described deduplication module, if meeting described for existence Two described packets of duplicate removal condition, remove wherein corresponding with timestamp information a little later packet.
The gateway device of process journal file the most according to claim 1, it is characterised in that described net Pass equipment also includes naming module;Described name module, for generating the file name letter of described journal file Breath, described file name information includes temporal information, reference number of a document and suffix.
The gateway device of process journal file the most according to claim 1, it is characterised in that described net Pass equipment also includes arranging module;Described module is set, for arranging the higher limit of described log file size.
The gateway device of process journal file the most according to claim 5, it is characterised in that described day Will file creation module, if the size being additionally operable to described journal file reaches described higher limit, creates new Journal file, described new journal file is stored under described catalogue;Described name module, is used for generating institute Stating the new file name information of new journal file, described file name information includes temporal information, file Numbering+1 and suffix.
The gateway device of process journal file the most according to claim 1, it is characterised in that described net Pass equipment also includes receiver module, upper transmission module, detection module and cleaning module;Described receiver module, also For receiving the request uploading journal file that external network sends;Described upper transmission module, is used for uploading all Journal file;Described detection module, is used for being spaced preset time period, detects whether to receive external network The feedback information that the journal file sent has been uploaded;Described cleaning module, if for detecting described feedback Information, clears up all of journal file under the catalogue depositing journal file.
CN201510762850.XA 2015-11-10 2015-11-10 Gateway equipment for processing log files Pending CN105827522A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201510762850.XA CN105827522A (en) 2015-11-10 2015-11-10 Gateway equipment for processing log files

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201510762850.XA CN105827522A (en) 2015-11-10 2015-11-10 Gateway equipment for processing log files

Publications (1)

Publication Number Publication Date
CN105827522A true CN105827522A (en) 2016-08-03

Family

ID=56514569

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201510762850.XA Pending CN105827522A (en) 2015-11-10 2015-11-10 Gateway equipment for processing log files

Country Status (1)

Country Link
CN (1) CN105827522A (en)

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107517261A (en) * 2017-08-31 2017-12-26 深圳市中兴物联科技有限公司 Gateway, server, method, apparatus, storage medium and Internet of things system
CN109600418A (en) * 2018-11-05 2019-04-09 阿里巴巴集团控股有限公司 Track method, apparatus, equipment and the system of application access
CN109600254A (en) * 2018-11-29 2019-04-09 恒生电子股份有限公司 The generation method and related system of full link log
CN111488320A (en) * 2020-04-17 2020-08-04 上海思询信息科技有限公司 Method for cleaning service application program log in Kubernetes
CN112073258A (en) * 2020-08-06 2020-12-11 深信服科技股份有限公司 Method for identifying user, electronic equipment and storage medium

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101964795A (en) * 2010-09-30 2011-02-02 北京世纪互联工程技术服务有限公司 Log collecting system, log collection method and log recycling server
CN102750326A (en) * 2012-05-30 2012-10-24 浪潮电子信息产业股份有限公司 Log management optimization method of cluster system based on downsizing strategy
CN103118007A (en) * 2013-01-06 2013-05-22 瑞斯康达科技发展股份有限公司 Method and system of acquiring user access behavior
CN103354518A (en) * 2013-07-24 2013-10-16 江苏晓山信息产业股份有限公司 Web log mining-based intelligent household gateway and web log mining-based intelligent household system
US20140047543A1 (en) * 2012-08-07 2014-02-13 Electronics And Telecommunications Research Institute Apparatus and method for detecting http botnet based on densities of web transactions

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101964795A (en) * 2010-09-30 2011-02-02 北京世纪互联工程技术服务有限公司 Log collecting system, log collection method and log recycling server
CN102750326A (en) * 2012-05-30 2012-10-24 浪潮电子信息产业股份有限公司 Log management optimization method of cluster system based on downsizing strategy
US20140047543A1 (en) * 2012-08-07 2014-02-13 Electronics And Telecommunications Research Institute Apparatus and method for detecting http botnet based on densities of web transactions
CN103118007A (en) * 2013-01-06 2013-05-22 瑞斯康达科技发展股份有限公司 Method and system of acquiring user access behavior
CN103354518A (en) * 2013-07-24 2013-10-16 江苏晓山信息产业股份有限公司 Web log mining-based intelligent household gateway and web log mining-based intelligent household system

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107517261A (en) * 2017-08-31 2017-12-26 深圳市中兴物联科技有限公司 Gateway, server, method, apparatus, storage medium and Internet of things system
CN109600418A (en) * 2018-11-05 2019-04-09 阿里巴巴集团控股有限公司 Track method, apparatus, equipment and the system of application access
CN109600418B (en) * 2018-11-05 2021-04-20 创新先进技术有限公司 Method, device, equipment and system for tracking application access
CN109600254A (en) * 2018-11-29 2019-04-09 恒生电子股份有限公司 The generation method and related system of full link log
CN111488320A (en) * 2020-04-17 2020-08-04 上海思询信息科技有限公司 Method for cleaning service application program log in Kubernetes
CN112073258A (en) * 2020-08-06 2020-12-11 深信服科技股份有限公司 Method for identifying user, electronic equipment and storage medium
CN112073258B (en) * 2020-08-06 2022-09-30 深信服科技股份有限公司 Method for identifying user, electronic equipment and storage medium

Similar Documents

Publication Publication Date Title
CN105827522A (en) Gateway equipment for processing log files
CN114097207B (en) Intelligent agent switcher
CN101924757B (en) Method and system for reviewing Botnet
Padmanabhan et al. Reasons dynamic addresses change
KR101047997B1 (en) A detecting system and a management method for terminals sharing by analyzing network packets and a method of service
US7996912B2 (en) Method and system for monitoring online computer network behavior and creating online behavior profiles
He et al. Next stop, the cloud: Understanding modern web service deployment in ec2 and azure
CN105516165B (en) A kind of method illegally acted on behalf of, equipment and the system of identification charging fraud
CN102761449B (en) Method and device for web service performance analysis
US10263868B1 (en) User-specific policy enforcement based on network traffic fingerprinting
JP2004507908A5 (en)
CN100362805C (en) Multifunctional management system for detecting erotic images and unhealthy information in network
KR101230500B1 (en) Network resource management system and method
US10285038B2 (en) Method and system for discovering user equipment in a network
CN101483676A (en) Method for securing special line user access network
CN109617753A (en) A kind of platform management method, system and electronic equipment and storage medium
CN106411819A (en) Method and apparatus for recognizing proxy Internet protocol address
US20120047248A1 (en) Method and System for Monitoring Flows in Network Traffic
CN101729310B (en) Method and system for realizing business monitor and information acquisition equipment
CN109600395A (en) A kind of device and implementation method of terminal network access control system
CN1558612A (en) Method for realizing network monitoring
CN104065766B (en) One kind bypass caching domain name analytic method
CN114124512B (en) WeChat small program supervision method, system and equipment based on flow behavior analysis
CN106161048A (en) Audit terminal and the wireless auditing system with this audit terminal
Wang et al. Towards comprehensive analysis of tor hidden service access behavior identification under obfs4 scenario

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication

Application publication date: 20160803

RJ01 Rejection of invention patent application after publication