Summary of the invention
For solving the problem existing for above-mentioned prior art, the present invention proposes a kind of performance optimization based on Router Simulation
Method, including:
Virtual router is set between true main frame and fictitious host computer, the data from network simulation operation platform are entered
Row processes, and transfers to destination host, and the message being sent out by fictitious host computer is packaged into Frame and is sent to described network
Simulation run platform.
Preferably, described virtual router farther includes NIU, data processing unit, route planning unit
With data transfer unit, described NIU is used for receiving and sending message;Data processing unit is used for data detection, mistake
Difference controls, ip packet filter, packet loss and Delay computing, wherein data detection includes, successively the verification of inspection IP packet header with, whether
For error message and whether be multicast message;Error control includes, processes message mistake occur, sends message to source host
Report reason of makeing mistakes, it is achieved query message and Discrepancy Report message;Ip packet filter includes, realizes the mistake to IP bag for broadcast packet
Filter, packet loss and Delay computing are used for calculating message and are often transferring it through a router, produced delay, and router
Before the delay that should calculate, and the packet loss in link;Described route planning unit utilizes IP bag to realize route planning and calculates
Method, thus realize route planning, and routing table is safeguarded and updates, described data transfer unit is according to purpose IP ground
Virtual routing tables is searched in location, determines to which virtual router to send.
Preferably, described fictitious host computer transfers to fictitious host computer data and the void of distance host reception for virtual router
Intend main frame and access data;Described fictitious host computer is divided into NIU, communication unit, thread units and document handling unit,
Wherein fictitious host computer passes through NIU, receives message that is that route platform catches and that transferred, described line by router
The service thread of Cheng Danyuan, starts service emulation script and sets up communication, and service thread is as accessed file, then by file process
The file system agent of unit performs to access operation;When fictitious host computer accesses distance host, system is by activating thread list
The active threads of unit, is started network communication software by active threads, injects seizure program;Start network communication software, catch and pass
Send data, transmit data and be processed as the data of fictitious host computer through active threads, then loaded fictitious host computer feature by communication unit, it
After give virtual router process, finally sent data by platform.
Preferably, self after operation, is first initialized by described network simulation operation platform;Platform is adjusted to
Ready state, waits the operation of user;The service that virtual network device provides realizes by writing script, passes through script interpretation
The initial work of device completes the reading to script interpreter configuration file, it is thus achieved that the catalogue at all kinds of script interpreter places, supplies
Perform to call during script;Analyze feature database file, by loading feature database emulation several operation systems and identifying that remote access is main
The operating system of machine;Loading the network equipment feature templates preset, described feature templates also can be during building the network operation
Add, during for configuration device attribute;Opening journal file, write data in file, this journal file is used for network row
For monitoring and analysis;Initialize the interface of platform and external network, for the seizure of message with transfer;One is distributed for cache pool
Fixed memory headroom keeps in the message of transmitting-receiving, postpones for virtual network;The statistics queue of initialization data amount, the statistical unit time
Inside flow through the message flow of platform and virtual network device, including receiving flow and transmitted traffic;After initialization completes, user
Select to be loaded into the network having built up or a newly-built network, complete the configuration to device attribute, corresponding parameter is set, it is intended that
Interface corresponding to this equipment also initializes, and connects each equipment by the network topology being pre-designed, to the logic of network just
Really property is tested, the most correct including IP address format, if there is identical IP, and network connects the most correct, if configuration
Incorrect, then error message is fed back to user and makes it reconfigure, after simulation process terminates, platform cleaning rubbish, close and beat
The interface opened and pipeline, the memory headroom that release platform is opened up, preserve network topological diagram simultaneously.
The present invention compared to existing technology, has the advantage that
The present invention proposes a kind of performance optimization method based on Router Simulation, does not change agreement overall architecture, autonomous structure
Establishing network and configuration parameter, the analysis for network attack and defence provides good environment.
Detailed description of the invention
Hereafter provide retouching in detail one or more embodiment of the present invention together with the accompanying drawing of the diagram principle of the invention
State.Describe the present invention in conjunction with such embodiment, but the invention is not restricted to any embodiment.The scope of the present invention is only by right
Claim limits, and the present invention contains many replacements, amendment and equivalent.Illustrate in the following description many details with
Thorough understanding of the present invention is just provided.These details are provided for exemplary purposes, and without in these details
Some or all details can also realize the present invention according to claims.
An aspect of of the present present invention provides a kind of performance optimization method based on Router Simulation.Fig. 1 is real according to the present invention
Execute the performance optimization method flow chart based on Router Simulation of example.
The present invention, based on network simulation operation platform, simulates various operating system and service leak.With a physics master
On the basis of machine realizes live network Dynamic simulation, the small scale network that multiple stage physical host emulates is connected into fairly large
Network, and be each network equipments configuration equipment feature.For general user, platform as a kind of network struction instrument,
The display unit observation that platform provides flows through the flow of platform and the network equipment.For developer, platform provides development interface,
Exploitation meets the functional device of needs.
Whole platform is divided into four layers: key-course, mechanical floor, program layer and communication layers.The function of each layer is introduced respectively
As follows:
(1) control to functional device during key-course is responsible for platform and the initialization of functional device and running, and provide
User interface.Including three subelements: device control cell, network configuration element and user interface section.Device control cell
It is responsible for the concrete network equipment is configured, including setting operation system, file system and open port;Network configuration list
Unit is responsible for generation and the configuration of input router of network topology;User interface section is for the interface mutual with emulator.
(2) mechanical floor is used for the operating various network equipments of analog network, including main frame, server, fire wall, route
Device, hub device.Wherein main frame and server have two types, and a kind of is the network equipment emulated, and one is integrated into very
Physical equipment in real network.
(3) the file system needed for program layer is responsible on the network equipment program run and service and operation program and service
System, it is made up of service routine, signal procedure and file interface.Service routine includes simulation scenario or Console program, is used for
The various network services run on virtual network device.Signal procedure refers to the application software with network communicating function, by joining
Put, using these application softwaries as on the network equipment application program run so that the network equipment in an active manner with other
Main frame communicates.File interface is used for the file system of fictitious host computer, provides file operation service to thread and reflects institute's mould
The feature of the operating system intended, including tissue and operation two parts of file of file.
(4) communication layers is responsible for the communication work of the network equipment, including protocol characteristic storehouse, ICP/IP protocol stack, network interface
With display interface.Protocol characteristic storehouse comprises the protocol stack characteristic information of various operating system, for the behaviour of virtual network device
Make system loads protocol stack feature, identify the operating system of remote access host.ICP/IP protocol stack is for managing in platform
All connections, it is ensured that being correctly completed of equipment communication.The agreement of platform processes has link layer protocol, ARP, IP, TCP, UDP association
View, application layer protocol is then given application program and is realized.This subelement achieves the encapsulation to TCP/IP protocol suite, provides a user with
Protocol data package interface at all levels.These interfaces can be used for encapsulation needs the message of transmission, it is also possible to utilize this
A little interfaces extract field interested in message and are analyzed.Network interface is used for being linked in live network platform, and
During platform runs, network data is caught.Platform catch data have both of which, be respectively user model and
Kernel mode, can only operate in the transport layer of ICP/IP protocol under user model, it is impossible to directly data intercept link-layer frame and net
Network layers message, and kernel mode can obtain the frame of link layer, it is achieved intermediate drivers level catches, including message seizure, message
Injection, network monitoring and storage are to disk, and network interface is that user carries out Network application and development and research provides unified letter
Number interface, utilizes these interfaces, and user can carry out secondary development to platform, loads functional device.Display interface provides for upper strata
The explicit function of some necessity.Mechanical floor calls display interface, display interface interchange system explicit function or self-defined display letter
Number.
Each layer protocol uses modularized design, and every kind of agreement has the protocol header of oneself to define, and provides protocol header
Analyze and encapsulation operation.For analyzing operation, when platform receives Frame, the every layer data comprised is located accordingly
Reason, by repeatedly solving the operation that frame unpacks, checks each tab character in header, determines the upper strata association receiving data
View, finally consigns to application program by the application layer data in frame.For encapsulation operation, when application layer data needs to pass through platform
During transmission, needing to be packaged data by protocol stack, encapsulation will increase frame head letter on the basis of receiving data every time
Breath, eventually forms the Frame that can transmit over ethernet.
After platform captures Frame by network interface, according to the type field of frame judge be adress analysis message or
IP message, if adress analysis message is then directly responded by platform, abandons the adress analysis message that the machine sends, otherwise
Transferring to virtual network device to process, the message processed is sent by platform.
The entrance entering virtual network at message arranges input router, in order to be given at input router by message
Reason, defines the cache pool between platform and input router, and the message processed is sent into cache pool by platform, and message is at cache pool
In store in the way of dynamic link table, if cache pool is full, abandon new bag.Virtual network device processes the flow process tool of message
Body includes:
Input router reads message from cache pool, and first message carries out pretreatment, checks length and the verification of bag
Code, then analysis purpose address and data from message, send the data to destination host finally according to routing table.Host process
After completing, before message is sent to gateway route, in addition it is also necessary to be packaged, load predetermined feature so that it is meet configuration
Operating system features, last message is stored in cache pool through input router.
The network equipment may used when building the network of emulation has main frame, router, fire wall, hub etc..This
Router and the main frame of emulation are illustrated by inventive embodiment.Virtual router is that network environment is carried out with fictitious host computer
The bridge of communication, therefore virtual router not only has data and transfers function, provides simultaneously and carries out connecing of data interaction with platform
Mouthful.Router is divided into four unit, respectively NIU, data processing unit, route planning unit and data turn
Send unit.Function and the design realization of each unit are described below:
The function of NIU is to receive and send message.From the angle of router access network, router is divided into
Two classes: input router and ordinary router.Input router is the road being joined directly together with true main frame place network in logic
By device, ordinary router is directly or indirectly connected with input router.Input router enters virtual network as data and runs
Entrance, need the data from platform are processed, and transfer to destination host;Ingress router is also required to empty simultaneously
The message that plan main frame is sent out is packaged into Frame and gives platform.
Data processing unit is responsible for data detection, error control, ip packet filter, packet loss and Delay computing.Data detection bag
Include inspection IP packet header successively verification and, whether be error message and whether be multicast message;Error control includes processing
The message of mistake occurs, sends message to source host and report reason of makeing mistakes, it is achieved that two kinds of messages, are query message and mistake respectively
Difference report message;Ip packet filter realizes the filtration to IP bag, is directed to broadcast packet;Message often through a router, all can
Producing corresponding delay, router is before transferring, it should calculate delay, and link also has certain packet loss, packet loss simultaneously
This function can be completed with Delay computing.
Route planning unit utilizes IP bag to realize route planning algorithm, thus realizes route planning.Can also be responsible for satisfying the need
By maintenance and the renewal of table.
Transfer unit, according to purpose IP address search virtual routing tables, determines to which virtual router to send.
The method of platform access network has multiple, and the present embodiment uses following methods virtual network to be run and accesses true net
Network.Assume the true main frame that B is platform place, access Internet, V by router A1-VnFor the n of emulation on true main frame
Platform main frame.If within the scope of visitor is positioned at the LAN at fictitious host computer place.When visitor attempts and fictitious host computer ViCommunication
Time, wherein 1≤i≤n, find fictitious host computer ViBe positioned at the same network segment with it, then it can first look for the adress analysis of oneself
Caching.If there being fictitious host computer V in Huan CuniMAC Address, then message directly transmits away;Without fictitious host computer Vi's
MAC Address, then send adress analysis bag and ask fictitious host computer ViMAC Address, obtain fictitious host computer ViMAC Address after again
Send data.As fictitious host computer ViWhen receiving, by the Internet, the message that a remote access person sends, router A connects
While receiving message and begin attempt to be sent out this bag.Router is retrieved by routing table, and determines this ViBag
Where it is sent to.If route points to Vi, then this router then can abandon current message;The message that router A will receive
It is transferred to other router;If there is V in the LAN at router placei, ViThen can receive the bag transmitted by router A.Will
VIData stream transmitting to the process of true host B use one of following two mode: true host B is by sending fictitious host computer Vi
Route entrance set.In this way, message then can be transferred on fictitious host computer then directly transmit by router
To true main frame.In the situation of the router without special outfit, router can use the instruction of Address Resolution Protocol to inquire about
The hardware address of fictitious host computer.But being because the fictitious host computer not having to respond, the query statement analyzing agreement will not obtain
To response.Now respond above-mentioned query statement with the hardware address of true main frame.Allow router by ViMessage transmit the most pure virginity
Real main frame.Under increasingly complex special network environment, or the address space that a section idle is connected by routed encapsulation
To true main frame.
Virtual router transfers the function spy simulating router in terms of three from data process, route planning and data
Property, in terms of data detection, error control, ip packet filter, packet loss and delay five, embody control mechanism and the chain of router
Road characteristic, it is possible to meet the requirement of router emulation.
For the emulation of main frame, constitute from the network of operating system and start with, fictitious host computer is divided into following four unit, its
Consist of NIU, communication unit, thread units and document handling unit.
Fictitious host computer is for processing the data in two sources: virtual router transfers to fictitious host computer data, and remotely leads
The fictitious host computer that machine receives accesses data.The mode processing both data is: main frame passes through NIU, receives route
The message transferred by router that platform catches.The service thread of thread units, service thread starts service emulation script also
Setting up communication, service thread then is performed to access operation by the file system agent of document handling unit as accessed file;
When fictitious host computer accesses distance host, system, by activating the active threads of thread units, is started network service by active threads
Software, injects seizure program.Then, network communication software starts, and catches it and transmits data.Transmit data to process through active threads
For the data of fictitious host computer, then loaded fictitious host computer feature by communication unit, give virtual router afterwards and process, finally by putting down
Platform sends data.Function and the design realization of fictitious host computer unit make introductions all round as follows:
NIU: main frame is uniquely identified by IP address in a computer network.Transmission between computer
Data are sent by virtual router and receive, and fictitious host computer must connect virtual router could access network.Empty
Intending main frame uses IP address to identify, and uses the MAC Address of input router to carry out network service.Fictitious host computer is by receiving road
The Receive message transferred by device is sent to the data of self.
Communication unit: realize sending the encapsulation of data and to receiving data classification and decapsulation.Protocol characteristic storehouse by
Realize in the built-in feature storehouse of existing scanning software.
Thread units: the service thread in main frame emulation accesses fictitious host computer for other main frame and provides service, passes through
External script or Console program realize, and startup optimization the most when accessed.Service thread with emulation script it
Between use pipeline communicate;Active threads in main frame emulation refers to the thread in operating system with network communicating function,
It can actively initiate connect and set up communication to distance host.Active threads leads to for active situation and the network of simulation thread
Letter situation.
Document handling unit: file system is for providing file operation service to thread, and it includes tissue and the literary composition of file
The operation of part.The tissue of file uses data in magnetic disk organized formats to be saved as a file, and this document is divided into four parts: first
Part is reserved area, records basic input/output argument block;Part II is file allocation table, for log file system space
Use distribution condition;Part III is file directory, for storing the information such as the length of file, address, date;Part IV
It is data field, deposits for file.
After the network simulation operation platform of the present invention runs, first self is initialized.Initialization procedure is by platform
It is adjusted to ready state, waits the operation of user.The service that virtual network device provides all realizes by writing script,
The reading to script interpreter configuration file is completed, it is thus achieved that all kinds of script interpreter institutes by the initial work of script interpreter
Catalogue, for perform script time call.Analyze feature database file, by loading feature database emulation several operation systems and identification
The operating system of remote access host.Loading the network equipment feature templates preset, feature templates also can build the network operation
During add, for configuration device attribute time.Open journal file, in file, write data.Journal file is used for net
The monitoring of network behavior and analysis.Initialize the interface of platform and external network, for the seizure of message with transfer.Divide for cache pool
Join certain memory headroom and keep in the message of transmitting-receiving, postpone for virtual network.The statistics queue of initialization data amount, statistical unit
The message flow of platform and virtual network device is flowed through, including receiving flow and transmitted traffic in time.
User selects to be loaded into the network having built up, or a newly-built network, needs the interpolation network equipment according to test,
And connect each equipment by the network topology being pre-designed, form complete network analog.Add network equipment process actually
Complete the configuration to device attribute, corresponding parameter is set, it is intended that interface corresponding to this equipment is also initialized.User is complete
In pairs after the configuration of network, the logical correctness of network is tested, the most correct including IP address format, if to there is phase
Same IP, network connects the most correct.If improperly-configured, then error message is fed back to use with the form of dialog box by platform
Family, in order to network is reconfigured by user according to feedback information, until network configuration is correct.After ready, platform is i.e.
Start working according to predefined program, until experiment terminates.During this period, user can be with the state of real-time monitored network, also
The network operation can be suspended to check ruuning situation, recover the operation of network the most again, it is also possible to directly stop the network operation.
After simulation process terminates, platform cleaning rubbish, close the interface and pipeline, the internal memory that release platform is opened up opened
Space, preserves network topological diagram simultaneously.
In sum, the present invention proposes a kind of performance optimization method based on Router Simulation, does not change agreement integrated stand
Structure, autonomous structure network and configuration parameter, the analysis for network attack and defence provides good environment.
Obviously, it should be appreciated by those skilled in the art, each unit of the above-mentioned present invention or each step can be with general
Calculating system realize, they can concentrate in single calculating system, or be distributed in multiple calculating system and formed
Network on, alternatively, they can realize with the executable program code of calculating system, it is thus possible to by they store
Performed by calculating system within the storage system.So, the present invention is not restricted to the combination of any specific hardware and software.
It should be appreciated that the above-mentioned detailed description of the invention of the present invention is used only for exemplary illustration or explains the present invention's
Principle, and be not construed as limiting the invention.Therefore, that is done in the case of without departing from the spirit and scope of the present invention is any
Amendment, equivalent, improvement etc., should be included within the scope of the present invention.Additionally, claims purport of the present invention
Whole within containing the equivalents falling into scope and border or this scope and border change and repair
Change example.