CN106533722A - Network monitoring method and network monitoring device - Google Patents
Network monitoring method and network monitoring device Download PDFInfo
- Publication number
- CN106533722A CN106533722A CN201510580034.7A CN201510580034A CN106533722A CN 106533722 A CN106533722 A CN 106533722A CN 201510580034 A CN201510580034 A CN 201510580034A CN 106533722 A CN106533722 A CN 106533722A
- Authority
- CN
- China
- Prior art keywords
- address
- network node
- packet loss
- abnormal
- api
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/08—Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Environmental & Geological Engineering (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
The invention discloses a network monitoring method and a network monitoring device. The network monitoring method comprises steps that API addresses of IP addresses used for querying network nodes are acquired; an IP address set is acquired by using a plurality of IP address of the API addresses; whether the service performance of the network node corresponding to every IP address of the IP address set is normal is detected; when the service performance of the network node corresponding to the corresponding IP address is abnormal, the abnormal IP address and corresponding abnormal information are transmitted to a monitoring terminal, and the abnormal IP address and the corresponding abnormal information are displayed by a monitoring terminal. A technical problem of a prior art of inability of knowing the abnormity of the network nodes timely is solved.
Description
Technical field
The application is related to internet arena, in particular to a kind of network monitoring method and device.
Background technology
Content distributing network (Content Delivery Network, referred to as CDN) node is usually one dynamic
Node group, after the flow switch of website is to CDN, the monitoring of network traffics and maintenance work Dou Shi CDN manufacturers complete.
However, the service monitoring of network node is not open to website operator, this causes website operator timely
Solution CDN node abnormal conditions, this can cause website operator carry out trouble shooting to website in time, cause net
Stand flow loss.
For above-mentioned problem, effective solution is not yet proposed at present.
The content of the invention
The embodiment of the present application provides a kind of network monitoring method and device, so that at least solve cannot be timely in prior art
Know the technical problem of the abnormal conditions of network node.
According to the one side of the embodiment of the present application, there is provided a kind of network monitoring method, including:Obtain for inquiring about
The API addresses of the IP address of network node;Using the multiple IP address of the API address acquisitions, IP address collection is obtained;
Detect that the IP address concentrates the service performance of the corresponding network node of each IP address whether abnormal;And in inspection
When measuring the service performance appearance exception of the corresponding network node of IP address, abnormal IP address and its correspondence is will appear from
Abnormal information send to monitor terminal so that the monitor terminal shows described abnormal IP address and its correspondence occur
Abnormal information.
According to the another aspect of the embodiment of the present application, a kind of network monitor device is additionally provided, including:First obtains single
Unit, for obtaining the API addresses for inquiring about the IP address of network node;Second acquisition unit, it is described for utilizing
The multiple IP address of API address acquisitions, obtain IP address collection;Detector unit, for detecting that it is every that the IP address is concentrated
Whether the service performance of the corresponding network node of one IP address is abnormal;And first transmitting element, for detecting
When the service performance of the corresponding network node of IP address occurs abnormal, abnormal IP address and its corresponding exception is will appear from
Information is sent to monitor terminal, so that the monitor terminal shows the IP address and its corresponding exception for exception occur
Information.
According to the embodiment of the present application, by obtaining the API addresses for inquiring about the IP address of network node, using API
The multiple IP address of address acquisition, obtain IP address collection, and detection IP address concentrates the corresponding network section of each IP address
Whether the service performance of point is abnormal, when the service performance for detecting the corresponding network node of IP address occurs abnormal, will
There is abnormal IP address and its corresponding abnormal information is sent to monitor terminal, so that monitor terminal shows exception occurs
IP address and its corresponding abnormal information, website staff can check trouble point in time, and checked and located
Reason, in terms of existing technologies, need not carry out secondary data inquiry, cannot know net in time in solving prior art
The technical problem of the abnormal conditions of network node, has reached the effect of the trouble point of timely prompting staff's network node.
Description of the drawings
Accompanying drawing described herein is used for providing further understanding of the present application, constitutes the part of the application, this Shen
Schematic description and description please does not constitute the improper restriction to the application for explaining the application.In accompanying drawing
In:
Fig. 1 is the flow chart of the network monitoring method according to the embodiment of the present application;
Fig. 2 is the schematic diagram of the network monitor device according to the embodiment of the present application.
Specific embodiment
In order that those skilled in the art more fully understand application scheme, below in conjunction with the embodiment of the present application
Accompanying drawing, is clearly and completely described to the technical scheme in the embodiment of the present application, it is clear that described embodiment
The only embodiment of the application part, rather than the embodiment of whole.Based on the embodiment in the application, ability
The every other embodiment obtained under the premise of creative work is not made by domain those of ordinary skill, should all belong to
The scope of the application protection.
It should be noted that the description and claims of this application and the term " first " in above-mentioned accompanying drawing, " second "
Etc. being for distinguishing similar object, without for describing specific order or precedence.It should be appreciated that so making
Data can be exchanged in the appropriate case, so that embodiments herein described herein can be with except here
Order beyond those of diagram or description is implemented.Additionally, term " comprising " and " having " and their any deformation,
Be intended to cover it is non-exclusive include, for example, contain the process of series of steps or unit, method, system,
Product or equipment are not necessarily limited to those steps clearly listed or unit, but may include clearly not list or
Other intrinsic for these processes, method, product or equipment step or unit.
According to the embodiment of the present application, there is provided a kind of embodiment of the method for network monitoring method, it should be noted that
The step of flow process of accompanying drawing is illustrated can be performed in the such as computer system of one group of computer executable instructions, and
And, although show logical order in flow charts, but in some cases, can be with different from order herein
Perform shown or described step.
Fig. 1 is the flow chart of the network monitoring method according to the embodiment of the present application, as shown in figure 1, the method include as
Lower step:
Step S102, obtains the API addresses for inquiring about the IP address of network node.
In CDN, each network node one server of correspondence, the IP address of network node is the server
IP address.Address can for application programming interface (Application Programming Interface, referred to as API)
To be provided by CDN service business, IP address collection is that is to say for inquiring about dynamic CDN parsing IP ponds.
Step S104, using the multiple IP address of API address acquisitions, obtains IP address collection.
After API addresses are got, using the multiple IP address of API address acquisitions, parsed so as to obtain up till now
The IP address of the server in pond, forms IP address collection.Specifically, using API address acquisitions IP address can be
To send request, receive and return message, then from the form of extracting IP address in message is returned obtaining.
Step S106, detects that IP address concentrates the service performance of the corresponding network node of each IP address whether abnormal.
Step S108, when the service performance for detecting the corresponding network node of IP address occurs abnormal, will appear from different
Normal IP address and its corresponding abnormal information are sent to monitor terminal, so that monitor terminal shows abnormal IP occurs
Address and its corresponding abnormal information.
After getting IP address collection, the service performance of each IP address corresponding network node is concentrated to IP address
Detected, judge whether the corresponding network node of each IP address exception occurs in parsing pond at present, and record different
Normal information.When abnormal network node is detected, the IP address of the network node and its corresponding abnormal information are sent out
Monitor terminal is delivered to, can be sent in the way of note or mail.The presentation of information for receiving is existed by monitor terminal
On display, trouble point is checked in time in order to website staff, is checked in time and is processed.
According to the embodiment of the present application, by obtaining the API addresses for inquiring about the IP address of network node, using API
The multiple IP address of address acquisition, obtain IP address collection, and detection IP address concentrates the corresponding network section of each IP address
Whether the service performance of point is abnormal, when the service performance for detecting the corresponding network node of IP address occurs abnormal, will
There is abnormal IP address and its corresponding abnormal information is sent to monitor terminal, so that monitor terminal shows exception occurs
IP address and its corresponding abnormal information, website staff can check trouble point in time, and checked and located
Reason, in terms of existing technologies, need not carry out secondary data inquiry, cannot know in time in solving prior art
The technical problem of the abnormal conditions of network node, has reached the effect of the trouble point of timely prompting staff's network node.
Preferably, detect that IP address concentrates whether the service performance of the corresponding network node of each IP address wraps extremely
Include:Probe requests thereby is sent to the corresponding network node of each IP address, the total duration of probe requests thereby is recorded, judges total
Whether duration exceedes Preset Time;And/or, the net of preset times is sent to the corresponding network node of each IP address
Network is tested, and is recorded the packet loss number of times of network test, is calculated each IP address using preset times and packet loss number of times corresponding
Network node network test packet loss, judge that whether packet loss exceedes predetermined threshold value;Judging that total duration is super
When Preset Time or packet loss is crossed more than predetermined threshold value, determine that total duration exceedes Preset Time or packet loss exceedes in advance
If the service performance of the corresponding network node of the IP address of threshold value occurs abnormal.
Above-mentioned middle network test, can be such as ping test, below for the ease of understanding the application, use ping
Test citing.
Can have various ways to the detection of the service performance of network node, the preferred probe requests thereby of the embodiment of the present application and/
Or the mode of ping test is detected, in the present embodiment, can be detected using one of which, it is also possible to two kinds
The form that mode is combined is detected.Now both modes are described respectively:
For the mode of probe requests thereby, when detecting to each IP address, first to the corresponding network of IP address
Node sends probe requests thereby, records the total duration of probe requests thereby, and the total duration is started until this from transmission probe requests thereby
The time that probe requests thereby response terminates, domain name system (Domain Name System, referred to as DNS) can be included
The parsing time, build connection time, download time etc..When the total duration of probe requests thereby is obtained, judge that the total duration is
It is no more than preset duration, if it is, it is abnormal to determine that the corresponding network node of corresponding IP address occurs.Wherein, remember
The abnormal information of record can be the duration of probe requests thereby links and total duration.
Further, one sub- thread of multithreading module creation first by python, this sub-line journey:Call python
Pycurl modules (pycurl is that a python language is write, detect web services quality python modules,
Advantage is can finely to customize HTTP request, and detects detailed http response performance information, the method for operation be
The module is called in the order line of python, or in python programs are write quotes module.In the present embodiment,
The module is detected for HTTP request, can collect the links response time in detection process, such as the DNS times,
TCP builds connection time, download time etc.), main thread is circulated first with for, is grouped as every height in IP address
Thread takes out a detection IP, and pycurl sends probe requests thereby, the corresponding temporal information of each link obtained by detection process
It is stored in predefined variable.Take out the total duration of probe requests thereby again from predefined variable, judged, it is determined that
Whether the corresponding network node of each IP address is abnormal.
For ping test, probe command can be write in advance, to send the ping test of preset times to IP address,
The packet loss number of times of record ping test, calculates packet loss further according to packet loss number of times and preset times, specifically, packet loss
Number obtains packet loss divided by preset times.Judge whether packet loss exceedes and predetermined threshold value, if it is, determining corresponding
The corresponding network node of IP address occur it is abnormal.
Further, ping test is carried out to the IP address of network node, probe command ping f c1000 can be preset,
1000 ping tests are quickly sent, and packet loss are obtained with packet loss number of times/1000.Again packet loss is judged,
Determine whether exception.
According in the embodiment of the present application, network node is examined by way of using probe requests thereby and/or ping test
Survey, detection process is quickly succinct, improves the efficiency of detection.
Alternatively, detect that IP address concentrates whether the service performance of the corresponding network node of each IP address wraps extremely
Include:Step A:Obtain the IP address that IP address is concentrated;Step B:To the corresponding network node of IP address for obtaining
Probe requests thereby is sent, the total duration of probe requests thereby is recorded, judges whether total duration exceedes Preset Time;And/or, to obtaining
The corresponding network node of IP address for taking sends the ping test of preset times, records the packet loss number of times of ping test,
The packet loss of the ping test of the corresponding network node of each IP address is calculated using preset times and packet loss number of times,
Judge whether packet loss exceedes predetermined threshold value;Step C:Judging that total duration exceedes Preset Time or packet loss is super
When crossing predetermined threshold value, frequency of abnormity adds 1;Step D:Judge whether frequency of abnormity reaches preset times;Abnormal secondary
When number is not up to preset times, execution step B is returned;When frequency of abnormity reaches preset times, it is determined that the IP for obtaining
The service performance of the corresponding network node in address occurs abnormal.
Whether in order to reduce rate of false alarm, in the embodiment of the present application, increasing frequency of abnormity carrying out uncertain network node is
It is abnormal.It is wherein, identical for the mode mode as the aforementioned of the corresponding network node abnormality detection of each IP address, i.e.
Detected by the way of probe requests thereby, ping test or its combination each time, repeated no more here.
During being detected, if it is abnormal to detect that network node occurs, but frequency of abnormity is not up to default secondary
Number, then can be with dormancy Preset Time after, again the network node is detected, is sentenced further according to testing result
It is disconnected.If exception occurs in detection number network node, and frequency of abnormity reaches preset times, then show that the network node goes out
It is now abnormal.In the embodiment, if it is determined that abnormal, then to detect last time abnormal information occurs in network node
Give monitor terminal.
According to the embodiment of the present application, by increasing the judgement of frequency of abnormity, so as to avoid the network section of accidental sexual abnormality
Point is reported as abnormal nodes, reduces rate of false alarm.
Preferably, before the API addresses for the IP address for inquiring about network node are obtained, method also includes:To domain
Name system sends the inquiry request to target domain name;The Query Result that domain name system is returned is received, is carried from Query Result
Take the corresponding canonical name of target domain name;It is corresponding that canonical name is inquired about in default reference table using canonical name
The information of CDN service business and the API addresses for inquiring about the IP address of network node, wherein, will appear from exception
IP address and its corresponding abnormal information while send to monitor terminal, by the information of CDN service business send to
Monitor terminal.
During the application is implemented, in advance by the information of CDN service business, website canonical name (CNAME) and CDN
The API addresses of service provider's offer are corresponding to be stored in reference table, and wherein, the information of CDN service business can include
CDN abbreviations, service calls of CDN service business etc..When needing that the corresponding network node of target domain name is examined
During survey, first the inquiry request for carrying target domain name can be sent to domain name system, domain name system is entered to target domain name
Row parsing, and return analysis result as Query Result, as such, it is possible to extract target from the Query Result for returning
The canonical name of domain name, then using canonical name as the key word of inquiry, canonical name is inquired about from reference table corresponding
The information of CDN service business and the API addresses for inquiring about the IP address of network node, in order to detect network
When node is abnormal, the information of CDN service business is sent to into monitor terminal in the lump.
As a example by using www.gridsum.com as aiming field name, inquiry request is sent to DNS first, by DNS's
The CNAME fields of return information are taken out, such as DNS query result:
www.gridsum.com CNAME gridsum.com.ccgslb.com.cn
Obtain CNAME:gridsum.com.ccgslb.com.cn;With the CNAME, in reference table, (program is ordered in advance
The CDN abbreviations that make, CNAME, parsing inquiry API, the synopsis of service calls) in take out CDN referred to as,
As the title of CDN service business;Continue to take out parsing inquiry API addresses in reference table with the CNAME,
The API is that CDN service business provides, and for inquiring about dynamic CDN parsing IP ponds, the API addresses has been deposited
Come;Continue to take out " service calls " etc. in reference table with the CNAME.
Preferably, using the multiple IP address of API address acquisitions, obtaining IP address collection includes:To API addresses correspondence
Server send HTTP connection requests so that the corresponding server in API addresses returns the IP for including network node
The html file of address;The html file that the corresponding server in API addresses is returned is received, using regular expressions
The IP address of the network node that formula is included in obtaining html file, obtains IP address collection.
For the acquisition of IP address collection, in the present embodiment, by sending HTTP connection requests to API addresses, should
After the corresponding server in API addresses receives the request, a html file is returned, in this document, includes mesh
The IP address of the network node in front parsing pond.As html file has the text formatting of its own, this enforcement
In example, data in the html file are matched using regular expression, so as to extract the IP for wherein including
Address, forms IP address collection.
Specifically, the text style of one html file of return can be:
<td>10.1.1.1</td>
<td>10.1.1.2</td>
<td>10.1.1.3</td>
Matching treatment is carried out with regular expression, each IP is taken out and is appended in list, finally give list
[‘10.1.1.1’,’10.1.1.2’,’10.1.1.3’…..]
IP in list is the IP address for parsing the network node in pond at present.
According to the embodiment of the present application, by rapidly extracting IP address from html file using regular expression,
Improve the extraction efficiency of IP address.
The embodiment of the present application additionally provides a kind of network monitor device, and the device can be used for performing the embodiment of the present application
Network monitoring method, as shown in Fig. 2 the device includes:First acquisition unit 10, second acquisition unit 20, inspection
Survey unit 30 and the first transmitting element 40.
First acquisition unit 10 is used for obtaining the API addresses for inquiring about the IP address of network node.
In CDN, each network node one server of correspondence, the IP address of network node is the server
IP address.Address can for application programming interface (Application Programming Interface, referred to as API)
To there is CDN service business to provide, IP address collection is that is to say for inquiring about dynamic CDN parsing IP ponds.
Second acquisition unit 20 is used for using the multiple IP address of API address acquisitions, obtains IP address collection.
After API addresses are got, using the multiple IP address of API address acquisitions, parsed so as to obtain up till now
The IP address of the server in pond, forms IP address collection.Specifically, using API address acquisitions IP address can be
To send request, receive and return message, then from the form of extracting IP address in message is returned obtaining.
Detector unit 30 is used for detecting whether IP address concentrates the service performance of the corresponding network node of each IP address
It is abnormal.
When first transmitting element 40 is for occurring abnormal in the service performance for detecting the corresponding network node of IP address,
Will appear from abnormal IP address and its corresponding abnormal information is sent to monitor terminal, so that monitor terminal shows that appearance is different
Normal IP address and its corresponding abnormal information.
After getting IP address collection, the service performance of each IP address corresponding network node is concentrated to IP address
Detected, judge whether the corresponding network node of each IP address exception occurs in parsing pond at present, and record different
Normal information.When abnormal network node is detected, the IP address of the network node and its corresponding abnormal information are sent out
Monitor terminal is delivered to, can be sent in the way of note or mail.The presentation of information for receiving is existed by monitor terminal
On display, trouble point is checked in time in order to website staff, is checked in time and is processed.
According to the embodiment of the present application, by obtaining the API addresses for inquiring about the IP address of network node, using API
The multiple IP address of address acquisition, obtain IP address collection, and detection IP address concentrates the corresponding network section of each IP address
Whether the service performance of point is abnormal, when the service performance for detecting the corresponding network node of IP address occurs abnormal, will
There is abnormal IP address and its corresponding abnormal information is sent to monitor terminal, so that monitor terminal shows exception occurs
IP address and its corresponding abnormal information, website staff can check trouble point in time, and checked and located
Reason, in terms of existing technologies, need not carry out secondary data inquiry, cannot know net in time in solving prior art
The technical problem of the abnormal conditions of network node, has reached the effect of the trouble point of timely prompting staff's network node.
Preferably, detector unit includes:First judge module, for sending out to the corresponding network node of each IP address
Probe requests thereby is sent, the total duration of probe requests thereby is recorded, judges whether total duration exceedes Preset Time;And/or, to each
The corresponding network node of individual IP address sends the ping test of preset times, records the packet loss number of times of ping test, profit
The packet loss of the ping test of the corresponding network node of each IP address is calculated with preset times and packet loss number of times, is sentenced
Whether disconnected packet loss exceedes predetermined threshold value;First determining module, for judge total duration exceed Preset Time or
When packet loss exceedes predetermined threshold value, determine that total duration exceedes the IP address that Preset Time or packet loss exceed predetermined threshold value
The service performance of corresponding network node occurs abnormal.
Can have various ways to the detection of the service performance of network node, the preferred probe requests thereby of the embodiment of the present application and/
Or the mode of ping test is detected, in the present embodiment, can be detected using one of which, it is also possible to two kinds
The form that mode is combined is detected.Now both modes are described respectively:
For the mode of probe requests thereby, when detecting to each IP address, first to the corresponding network of IP address
Node sends probe requests thereby, records the total duration of probe requests thereby, and the total duration is started until this from transmission probe requests thereby
The time that probe requests thereby response terminates, domain name system (Domain Name System, referred to as DNS) can be included
The parsing time, build connection time, download time etc..When the total duration of probe requests thereby is obtained, judge that the total duration is
It is no more than preset duration, if it is, it is abnormal to determine that the corresponding network node of corresponding IP address occurs.Wherein, remember
The abnormal information of record can be the duration of probe requests thereby links and total duration.
Further, one sub- thread of multithreading module creation first by python, this sub-line journey:Call python
Pycurl modules (Pycurl is that a python language is write, detect web services quality python modules,
Advantage is can finely to customize HTTP request, and detects detailed http response performance information, the method for operation be
The module is called in the order line of python, or in python programs are write quotes module.In the present embodiment,
The module is detected for HTTP request, can collect the links response time in detection process, such as the DNS times,
TCP builds connection time, download time etc.), main thread is circulated first with for, is grouped as every height in IP address
Thread takes out a detection IP, and pycurl sends probe requests thereby, the corresponding temporal information of each link obtained by detection process
It is stored in predefined variable.Take out the total duration of probe requests thereby again from predefined variable, judged, it is determined that
Whether the corresponding network node of each IP address is abnormal.
For ping test, probe command can be write in advance, to send the ping test of preset times to IP address,
The packet loss number of times of record ping test, calculates packet loss further according to packet loss number of times and preset times, specifically, packet loss
Number obtains packet loss divided by preset times.Judge whether packet loss exceedes and predetermined threshold value, if it is, determining corresponding
The corresponding network node of IP address occur it is abnormal.
Further, ping test is carried out to the IP address of network node, probe command ping f c1000 can be preset,
1000 ping tests are quickly sent, and packet loss are obtained with packet loss number of times/1000.Again packet loss is judged,
Determine whether exception.
According in the embodiment of the present application, network node is examined by way of using probe requests thereby and/or ping test
Survey, detection process is quickly succinct, improves the efficiency of detection.
Alternatively, detector unit includes:Acquisition module, for obtaining the IP address of IP address concentration;Second judges
Module, for sending probe requests thereby to the corresponding network node of IP address for obtaining, records the total duration of probe requests thereby,
Judge whether total duration exceedes Preset Time;And/or, the corresponding network node of the IP address to obtaining sends default time
Several network tests, records the packet loss number of times of network test, calculates each IP ground using preset times and packet loss number of times
The packet loss of the network test of the corresponding network node in location, judges whether packet loss exceedes predetermined threshold value;Accumulator module,
For when judging that total duration exceedes Preset Time or packet loss more than predetermined threshold value, frequency of abnormity adds 1;3rd
Judge module, for judging whether frequency of abnormity reaches preset times;Second determining module, for reaching in frequency of abnormity
During to preset times, it is determined that there is exception, wherein, second in the service performance of the corresponding network node of IP address for obtaining
When frequency of abnormity is not up to preset times, the IP address to obtaining is detected judge module again.
Above-mentioned middle network test, can be such as ping test, below for the ease of understanding the application, use ping
Test is enumerated.
Whether in order to reduce rate of false alarm, in the embodiment of the present application, increasing frequency of abnormity carrying out uncertain network node is
It is abnormal.It is wherein, identical for the mode mode as the aforementioned of the corresponding network node abnormality detection of each IP address, i.e.
Detected by the way of probe requests thereby, ping test or its combination each time, repeated no more here.
During being detected, if it is abnormal to detect that network node occurs, but frequency of abnormity is not up to default secondary
Number, then can be with dormancy Preset Time after, again the network node is detected, is sentenced further according to testing result
It is disconnected.If exception occurs in detection number network node, and frequency of abnormity reaches preset times, then show that the network node goes out
It is now abnormal.In the embodiment, if it is determined that abnormal, then to detect last time abnormal information occurs in network node
Give monitor terminal.
According to the embodiment of the present application, by increasing the judgement of frequency of abnormity, so as to avoid the network section of accidental sexual abnormality
Point is reported as abnormal nodes, reduces rate of false alarm.
Preferably, device also includes:Second transmitting element, for obtaining the IP address for inquiring about network node
Before API addresses, the inquiry request to target domain name is sent to domain name system;Extraction unit, for receiving domain name system
The Query Result that system is returned, extracts the corresponding canonical name of target domain name from Query Result;Query unit, for profit
The information of the corresponding CDN service business of canonical name is inquired about in default reference table and for inquiring about net with canonical name
The API addresses of the IP address of network node, wherein, the first transmitting element be additionally operable to will appear from abnormal IP address and
While its corresponding abnormal information is sent to monitor terminal, the information of CDN service business is sent to monitor terminal.
During the application is implemented, in advance by the information of CDN service business, website canonical name (CNAME) and CDN
The API addresses of service provider's offer are corresponding to be stored in reference table, and wherein, the information of CDN service business can include
CDN abbreviations, service calls of CDN service business etc..When needing that the corresponding network node of target domain name is examined
During survey, first the inquiry request for carrying target domain name can be sent to domain name system, domain name system is entered to target domain name
Row parsing, and return analysis result as Query Result, as such, it is possible to extract target from the Query Result for returning
The canonical name of domain name, then using canonical name as the key word of inquiry, canonical name is inquired about from reference table corresponding
The information of CDN service business and the API addresses for inquiring about the IP address of network node, in order to detect network
When node is abnormal, the information of CDN service business is sent to into monitor terminal in the lump.
As a example by using www.gridsum.com as aiming field name, inquiry request is sent to DNS first, by DNS's
The CNAME fields of return information are taken out, such as DNS query result:
www.gridsum.com CNAME gridsum.com.ccgslb.com.cn
Obtain CNAME:gridsum.com.ccgslb.com.cn;With the CNAME, in reference table, (program is ordered in advance
The CDN abbreviations that make, CNAME, parsing inquiry API, the synopsis of service calls) in take out CDN referred to as,
As the title of CDN service business;Continue to take out parsing inquiry API addresses in reference table with the CNAME,
The API is that CDN service business provides, and for inquiring about dynamic CDN parsing IP ponds, the API addresses has been deposited
Come;Continue to take out " service calls " etc. in reference table with the CNAME.
Preferably, second acquisition unit includes:Sending module, for sending HTTP to the corresponding server in API addresses
Connection request, so that the corresponding server in API addresses returns the html file of the IP address for including network node;
Receiver module, for receiving the html file that the corresponding server in API addresses is returned, is obtained using regular expression
The IP address of the network node included in html file, obtains IP address collection.
For the acquisition of IP address collection, in the present embodiment, by sending HTTP connection requests to API addresses, should
After the corresponding server in API addresses receives the request, a html file is returned, in this document, includes mesh
The IP address of the network node in front parsing pond.As html file has the text formatting of its own, this enforcement
In example, data in the html file are matched using regular expression, so as to extract the IP for wherein including
Address, forms IP address collection.
Specifically, the text style of one html file of return can be:
<td>10.1.1.1</td>
<td>10.1.1.2</td>
<td>10.1.1.3</td>
Matching treatment is carried out with regular expression, each IP is taken out and is appended in list, finally give list
[‘10.1.1.1’,’10.1.1.2’,’10.1.1.3’…..]
IP in list is the IP address for parsing the network node in pond at present.
According to the embodiment of the present application, by rapidly extracting IP address from html file using regular expression,
Improve the extraction efficiency of IP address.
The application is described below by a preferred embodiment.In this embodiment, it is main to include identification
Module, IP address generation module, detecting module and alarm module.Wherein, identification module is equivalent to the embodiment of the present application
In the second transmitting element, extraction unit and query unit, IP address generation module equivalent to second acquisition unit, detection
, equivalent to detector unit, alarm module is equivalent to the first transmitting element for module.Specifically:
Identification module is for, before detection is started, sending a monitoring inquiry of the domain name to DNS first and asking, and general
The CNAME fields of the return information of DNS are taken out, and obtain CNAME and carry out CDN service business distinguishing.
For example, DNS query result is:www.gridsum.com CNAME gridsum.com.ccgslb.com.cn
Obtain CNAME:gridsum.com.ccgslb.com.cn;
With the CNAME reference table (program in advance customized good CDN abbreviation, CNAME, parsing inquire about API,
The synopsis of service calls) middle taking-up CDN abbreviations, in case by the referred to as addition warning during alarm module generation warning
In " CDN service business's name " item of information;Continue to take out parsing inquiry API addresses in reference table with the CNAME,
The API is that CDN service business provides, and for inquiring about dynamic CDN parsing IP ponds, the API addresses is stored away,
Use for following IP address list generation module;Continue to take out " service calls " in reference table with the CNAME.
For sending HTTP connection requests to the API, the API returns a HTML text to IP address generation module
Part, has some IP address in file, text style is similar to:
<td>10.1.1.1</td>
<td>10.1.1.2</td>
<td>10.1.1.3</td>
Matching treatment is carried out with regular expression, each is taken out and is appended in list, finally give list [' 10.1.1.1 ', '
10.1.1.2’,’10.1.1.3’…..]
IP in list is the IP address for parsing the server in pond at present.This list is preserved, for detecting mould
Block is fixed IP and is detected.
Detecting module for after the IP address list that IP address generation module is sent is received, first by python's
One sub- thread of multithreading module creation, this sub-line journey are adopted and are detected in two ways:
The first:Call python pycurl modules (this module dedicated for HTTP request detect, can collect
Links response time in detection process, such as DNS times, TCP build connection time, download time etc.), it is main
Thread is circulated first with for, in IP lists takes out a detection IP for each sub-line journey, and pycurl sends detection
Request, the corresponding temporal information of each link obtained by detection process are stored in predefined variable;
Second:Carry out ping test to the IP address of network node, probe command ping f c 1000, i.e., quickly
1000 ping tests are sent, and packet loss are obtained with packet loss number of times/1000.
Detecting module is additionally operable to the alarm decision to network node, specifically, if the total duration of this probe requests thereby is not
More than 10 seconds and ping packet loss be less than 10%, then terminate the detection process of the sub-line journey;In the event of detection
Any one situation during 10 seconds time-out or packet loss are asked more than 10%, then " frequency of failure "+1, judges " frequency of failure "
Whether more than 3 times, if also not less than 3 times, this is " doubtful warning " extremely, this thread dormancy 10 seconds, again
Detected;If " frequency of failure " is more than 3 times, this is " true to report to the police " extremely, and detecting module is with pycurl
The information variable of the last time test that test process retains, ping packet loss, generate a dictionary, the form of dictionary
It is exemplified below:
{‘IP’:’10.1.1.1’,’CDN’:’chinacache’,’ping_lost’:' 0% ', ' time_totle ':’11s’,’time_dns’:’1s
’,’time_connect’:’10s’…}
In the dictionary, most contents can be used for the detection details content in next step generation warning message.
Alarm module is then have IP address to detect continuous 3 situations more than 10 seconds, the IP services when being triggered
Can there may be exception, need report to website operator, first the dictionary that previous step is generated is read out, is reported
Alert IP, CDN title, detection time details, then call " nali " tool detection this IP ownership place in shell,
Next start to arrange form, the exquisiteness that identification module and detecting module are obtained is organized into into one section of bell character(BEL) string, word
Symbol string citing:
[IP:10.1.1.1 state:Report to the police]
Ownership place:China-Beijing
CDN service business:chinacache
Detection details:
time_totle:11s
time_dns:1s
time_connect:10s
time_download:0s
ping_lost:0%
Service calls:010-******
Alarm module calls monitored module in shell, and this character string is sent to monitor terminal, the monitoring end
End is configurable in configuration file.
Above-mentioned the embodiment of the present application sequence number is for illustration only, does not represent the quality of embodiment.
In above-described embodiment of the application, the description to each embodiment all emphasizes particularly on different fields, and does not have in certain embodiment
The part of detailed description, may refer to the associated description of other embodiment.
In several embodiments provided herein, it should be understood that disclosed technology contents, other can be passed through
Mode realize.Wherein, device embodiment described above is only schematic, such as division of described unit,
Can be a kind of division of logic function, when actually realizing, can have other dividing mode, such as multiple units or component
Can with reference to or be desirably integrated into another system, or some features can be ignored, or not perform.It is another, institute
The coupling each other for showing or discussing or direct-coupling or communication connection can be by some interfaces, unit or mould
The INDIRECT COUPLING of block or communication connection, can be electrical or other forms.
The unit as separating component explanation can be or may not be it is physically separate, it is aobvious as unit
The part for showing can be or may not be physical location, you can local to be located at one, or can also be distributed to
On multiple units.Some or all of unit therein can be selected according to the actual needs to realize this embodiment scheme
Purpose.
In addition, each functional unit in the application each embodiment can be integrated in a processing unit, it is also possible to
It is that unit is individually physically present, it is also possible to which two or more units are integrated in a unit.It is above-mentioned integrated
Unit both can be realized in the form of hardware, it would however also be possible to employ the form of SFU software functional unit is realized.
If the integrated unit realized using in the form of SFU software functional unit and as independent production marketing or use when,
Can be stored in a computer read/write memory medium.Based on such understanding, the technical scheme essence of the application
On all or part of part that in other words prior art is contributed or the technical scheme can be with software product
Form is embodied, and the computer software product is stored in a storage medium, is used so that one including some instructions
Platform computer equipment (can be personal computer, server or network equipment etc.) performs each embodiment institute of the application
State all or part of step of method.And aforesaid storage medium includes:USB flash disk, read only memory (ROM, Read-Only
Memory), random access memory (RAM, Random Access Memory), portable hard drive, magnetic disc or
CD etc. is various can be with the medium of store program codes.
The above is only the preferred implementation of the application, it is noted that for the ordinary skill people of the art
For member, on the premise of without departing from the application principle, some improvements and modifications can also be made, these improve and moisten
Decorations also should be regarded as the protection domain of the application.
Claims (10)
1. a kind of network monitoring method, it is characterised in that include:
Obtain the API addresses for inquiring about the IP address of network node;
Using the multiple IP address of the API address acquisitions, IP address collection is obtained;
Detect that the IP address concentrates the service performance of the corresponding network node of each IP address whether abnormal;
And
When the service performance for detecting the corresponding network node of IP address occurs abnormal, abnormal IP is will appear from
Address and its corresponding abnormal information are sent to monitor terminal, so that the monitor terminal shows that the appearance is abnormal
IP address and its corresponding abnormal information.
2. method according to claim 1, it is characterised in that the detection IP address concentrates each IP address
Whether the service performance of corresponding network node includes extremely:
Probe requests thereby is sent to the corresponding network node of each IP address, the total duration of the probe requests thereby is recorded,
Judge whether the total duration exceedes Preset Time;And/or, the corresponding network node of each IP address is sent out
The network test of preset times is sent, the packet loss number of times of the network test is recorded, using the preset times and institute
State the packet loss that packet loss number of times calculates the network test of the corresponding network node of each IP address, judge described in lose
Whether bag rate exceedes predetermined threshold value;
When judging that the total duration exceedes the Preset Time or the packet loss more than the predetermined threshold value,
Determine that total duration exceedes the IP address correspondence that the Preset Time or the packet loss exceed the predetermined threshold value
Network node service performance occur it is abnormal.
3. method according to claim 1, it is characterised in that the detection IP address concentrates each IP address
Whether the service performance of corresponding network node includes extremely:
Step A:Obtain the IP address that the IP address is concentrated;
Step B:Probe requests thereby is sent to the corresponding network node of IP address for obtaining, the probe requests thereby is recorded
Total duration, judge that whether the total duration exceedes Preset Time;And/or, the IP address to obtaining is corresponding
Network node sends the network test of preset times, records the packet loss number of times of the network test, using described pre-
If number of times and the packet loss number of times calculate the packet loss of the network test of the corresponding network node of each IP address,
Judge whether the packet loss exceedes predetermined threshold value;
Step C:Judging that it is described pre- that the total duration exceedes more than the Preset Time or the packet loss
If during threshold value, frequency of abnormity adds 1;
Step D:Judge whether frequency of abnormity reaches preset times;
When frequency of abnormity is not up to the preset times, returns and perform step B;
When frequency of abnormity reaches the preset times, the corresponding network node of IP address of the acquisition is determined
Service performance occurs abnormal.
4. method according to claim 1, it is characterised in that obtaining the IP address for inquiring about network node
Before API addresses, methods described also includes:
The inquiry request to target domain name is sent to domain name system;
The Query Result that domain name system is returned is received, the target domain name is extracted from the Query Result corresponding
Canonical name;
The corresponding CDN service business of the canonical name is inquired about in default reference table using the canonical name
Information and the API addresses for inquiring about the IP address of network node,
Wherein, while will appear from abnormal IP address and its corresponding abnormal information sends to monitor terminal,
The information of the CDN service business is sent to the monitor terminal.
5. method according to claim 1, it is characterised in that using the multiple IP address of the API address acquisitions,
Obtaining IP address collection includes:
HTTP connection requests are sent to the corresponding server in the API addresses, so that the corresponding clothes in API addresses
Business device returns the html file of the IP address for including network node;
The html file that the corresponding server in the API addresses is returned is received, is obtained using regular expression
The IP address of the network node included in html file, obtains the IP address collection.
6. a kind of network monitor device, it is characterised in that include:
First acquisition unit, for obtaining the API addresses for inquiring about the IP address of network node;
Second acquisition unit, for using the multiple IP address of the API address acquisitions, obtaining IP address collection;
Detector unit, for detecting that the IP address concentrates the service of the corresponding network node of each IP address
Whether performance is abnormal;And
First transmitting element, during for occurring abnormal in the service performance for detecting the corresponding network node of IP address,
Will appear from abnormal IP address and its corresponding abnormal information is sent to monitor terminal, so that the monitor terminal is aobvious
Show the IP address and its corresponding abnormal information for exception occur.
7. device according to claim 6, it is characterised in that the detector unit includes:
First judge module, for sending probe requests thereby to the corresponding network node of each IP address, records institute
The total duration of probe requests thereby is stated, judges whether the total duration exceedes Preset Time;And/or, to each IP
The corresponding network node in address sends the network test of preset times, records the packet loss number of times of the network test,
The network that the corresponding network node of each IP address is calculated using the preset times and the packet loss number of times is surveyed
The packet loss of examination, judges whether the packet loss exceedes predetermined threshold value;
First determining module, for judging the total duration more than the Preset Time or the packet loss
During more than the predetermined threshold value, determine that total duration exceedes the Preset Time or the packet loss more than described pre-
If the service performance of the corresponding network node of the IP address of threshold value occurs abnormal.
8. device according to claim 6, it is characterised in that the detector unit includes:
Acquisition module, for obtaining the IP address that the IP address is concentrated;
Second judge module, for sending probe requests thereby to the corresponding network node of IP address for obtaining, records institute
The total duration of probe requests thereby is stated, judges whether the total duration exceedes Preset Time;And/or, to the IP for obtaining
The corresponding network node in address sends the network test of preset times, records the packet loss number of times of the network test,
The ping that the corresponding network node of each IP address is calculated using the preset times and the packet loss number of times is surveyed
The packet loss of examination, judges whether the packet loss exceedes predetermined threshold value;
Accumulator module, for judging that the total duration exceedes the Preset Time or the packet loss exceedes
During the predetermined threshold value, frequency of abnormity adds 1;
3rd judge module, for judging whether frequency of abnormity reaches preset times;
Second determining module, for when frequency of abnormity reaches the preset times, determining the IP ground of the acquisition
There is exception in the service performance of the corresponding network node in location,
Wherein, the second judge module frequency of abnormity be not up to the preset times when, again to obtain IP ground
Detected location.
9. device according to claim 6, it is characterised in that described device also includes:
Second transmitting element, for before the API addresses for the IP address of inquiring about network node are obtained, to
Domain name system sends the inquiry request to target domain name;
Extraction unit, for receiving the Query Result of domain name system return, extracts described from the Query Result
The corresponding canonical name of target domain name;
Query unit, for inquiring about the canonical name correspondence using the canonical name in default reference table
CDN service business information and the API addresses for inquiring about the IP address of network node,
Wherein, first transmitting element is additionally operable to will appear from abnormal IP address and its corresponding abnormal information
While transmission to monitor terminal, the information of the CDN service business is sent to the monitor terminal.
10. device according to claim 6, it is characterised in that the second acquisition unit includes:
Sending module, for sending HTTP connection requests to the corresponding server in the API addresses, so that API
The corresponding server in address returns the html file of the IP address for including network node;
Receiver module, for receiving the html file that the corresponding server in the API addresses is returned, using just
Then the IP address of the network node that expression formula is included in obtaining html file, obtains the IP address collection.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201510580034.7A CN106533722B (en) | 2015-09-11 | 2015-09-11 | Network monitoring method and device |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201510580034.7A CN106533722B (en) | 2015-09-11 | 2015-09-11 | Network monitoring method and device |
Publications (2)
Publication Number | Publication Date |
---|---|
CN106533722A true CN106533722A (en) | 2017-03-22 |
CN106533722B CN106533722B (en) | 2019-06-21 |
Family
ID=58348105
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201510580034.7A Active CN106533722B (en) | 2015-09-11 | 2015-09-11 | Network monitoring method and device |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN106533722B (en) |
Cited By (29)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN107294780A (en) * | 2017-06-29 | 2017-10-24 | 重庆邮电大学 | Resources-type internet source of trouble localization method based on network monitoring |
CN107506298A (en) * | 2017-07-28 | 2017-12-22 | 杭州销冠网络科技有限公司 | A kind of monitoring method and system for business on line |
CN107682174A (en) * | 2017-08-24 | 2018-02-09 | 郑州云海信息技术有限公司 | A kind of network equipment supports the collection method of data |
CN107769957A (en) * | 2017-08-30 | 2018-03-06 | 贵州白山云科技有限公司 | A kind of domain name system failure cause analysis method and device |
CN107894950A (en) * | 2017-10-30 | 2018-04-10 | 北京奇虎科技有限公司 | A kind of equipment detection method, device, server and storage medium |
CN108400907A (en) * | 2018-02-08 | 2018-08-14 | 安徽农业大学 | A kind of link packet drop rate inference method under uncertain network environment |
CN108696555A (en) * | 2017-04-11 | 2018-10-23 | 贵州白山云科技有限公司 | A kind of equipment detection method and device |
CN108759920A (en) * | 2018-06-04 | 2018-11-06 | 深圳源广安智能科技有限公司 | A kind of depot safety monitoring system based on Internet of Things |
CN108924005A (en) * | 2018-06-29 | 2018-11-30 | 优刻得科技股份有限公司 | Network detecting method, network detection device, medium and equipment |
CN109245955A (en) * | 2017-07-10 | 2019-01-18 | 阿里巴巴集团控股有限公司 | A kind of data processing method, device and server |
CN109450699A (en) * | 2018-12-06 | 2019-03-08 | 合肥海诺恒信息科技有限公司 | Integration firm IT operation management system and method |
CN109614340A (en) * | 2018-12-28 | 2019-04-12 | 北京微播视界科技有限公司 | Exploitation adjustment method, device, electronic equipment and the storage medium of application program |
CN109728920A (en) * | 2017-10-27 | 2019-05-07 | 贵州白山云科技股份有限公司 | A kind of method and device for the service quality improving web service product |
CN110557304A (en) * | 2019-09-20 | 2019-12-10 | 腾讯科技(深圳)有限公司 | Address detection method and device and computer readable storage medium |
CN111224959A (en) * | 2019-12-29 | 2020-06-02 | 西安天互通信有限公司 | Server port automatic detection and forwarding defense system and defense method |
CN111327592A (en) * | 2020-01-19 | 2020-06-23 | 深圳市博威创盛科技有限公司 | Network monitoring method and related device |
CN111371826A (en) * | 2018-12-26 | 2020-07-03 | 北京奇虎科技有限公司 | CDN node performance detection method, device and system |
CN111385244A (en) * | 2018-12-27 | 2020-07-07 | 中国移动通信集团四川有限公司 | Abnormal flow identification method, device, equipment, system and medium |
CN111885145A (en) * | 2020-07-20 | 2020-11-03 | 北京百度网讯科技有限公司 | Switching method, device, equipment and computer storage medium |
CN112751745A (en) * | 2020-12-28 | 2021-05-04 | 上海蓝云网络科技有限公司 | Message reminding method and device |
CN113472607A (en) * | 2021-06-29 | 2021-10-01 | 未鲲(上海)科技服务有限公司 | Application program network environment detection method, device, equipment and storage medium |
CN113691420A (en) * | 2021-08-26 | 2021-11-23 | 北京基调网络股份有限公司 | Method for monitoring CDN quality, electronic equipment, server and storage medium |
CN113783755A (en) * | 2021-09-15 | 2021-12-10 | 云茂互联智能科技(厦门)有限公司 | Network monitoring method, network monitoring device, storage medium and electronic device |
CN114285763A (en) * | 2021-11-26 | 2022-04-05 | 中国联合网络通信集团有限公司 | Data acquisition method, data acquisition device and computer-readable storage medium |
CN114615310A (en) * | 2022-03-01 | 2022-06-10 | 天翼安全科技有限公司 | Method and device for maintaining TCP connection and electronic equipment |
CN114629824A (en) * | 2022-03-24 | 2022-06-14 | 阿里巴巴(中国)有限公司 | Packet loss positioning method, device, computing equipment and medium |
CN115190045A (en) * | 2022-07-06 | 2022-10-14 | 南京云柜网络科技有限公司 | Express cabinet system service monitoring method and device, electronic equipment and storage medium |
CN115361358A (en) * | 2022-08-19 | 2022-11-18 | 山石网科通信技术股份有限公司 | IP extraction method, device, storage medium and electronic device |
CN116170294A (en) * | 2023-02-21 | 2023-05-26 | 北京志凌海纳科技有限公司 | Network anomaly detection method and system for distributed system |
Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101741643A (en) * | 2009-12-24 | 2010-06-16 | 北京世纪互联宽带数据中心有限公司 | Content delivery network node detecting method and system |
CN102932204A (en) * | 2012-11-09 | 2013-02-13 | 北京奇虎科技有限公司 | Monitoring method and monitoring system of content delivery network |
CN102938709A (en) * | 2012-11-09 | 2013-02-20 | 北京奇虎科技有限公司 | Monitoring method and monitoring server for content delivery network (CDN) |
CN103428011A (en) * | 2012-05-16 | 2013-12-04 | 深圳市腾讯计算机系统有限公司 | Node state detection method, system and device used in distributed system |
US20150046593A1 (en) * | 2013-08-08 | 2015-02-12 | Level 3 Communications, Llc | Content delivery methods and systems |
-
2015
- 2015-09-11 CN CN201510580034.7A patent/CN106533722B/en active Active
Patent Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101741643A (en) * | 2009-12-24 | 2010-06-16 | 北京世纪互联宽带数据中心有限公司 | Content delivery network node detecting method and system |
CN103428011A (en) * | 2012-05-16 | 2013-12-04 | 深圳市腾讯计算机系统有限公司 | Node state detection method, system and device used in distributed system |
CN102932204A (en) * | 2012-11-09 | 2013-02-13 | 北京奇虎科技有限公司 | Monitoring method and monitoring system of content delivery network |
CN102938709A (en) * | 2012-11-09 | 2013-02-20 | 北京奇虎科技有限公司 | Monitoring method and monitoring server for content delivery network (CDN) |
US20150046593A1 (en) * | 2013-08-08 | 2015-02-12 | Level 3 Communications, Llc | Content delivery methods and systems |
Cited By (43)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN108696555A (en) * | 2017-04-11 | 2018-10-23 | 贵州白山云科技有限公司 | A kind of equipment detection method and device |
CN107294780A (en) * | 2017-06-29 | 2017-10-24 | 重庆邮电大学 | Resources-type internet source of trouble localization method based on network monitoring |
CN109245955A (en) * | 2017-07-10 | 2019-01-18 | 阿里巴巴集团控股有限公司 | A kind of data processing method, device and server |
CN109245955B (en) * | 2017-07-10 | 2022-12-09 | 阿里巴巴集团控股有限公司 | Data processing method and device and server |
CN107506298A (en) * | 2017-07-28 | 2017-12-22 | 杭州销冠网络科技有限公司 | A kind of monitoring method and system for business on line |
CN107682174A (en) * | 2017-08-24 | 2018-02-09 | 郑州云海信息技术有限公司 | A kind of network equipment supports the collection method of data |
CN107682174B (en) * | 2017-08-24 | 2021-06-01 | 郑州云海信息技术有限公司 | Method for collecting network equipment support data |
CN107769957A (en) * | 2017-08-30 | 2018-03-06 | 贵州白山云科技有限公司 | A kind of domain name system failure cause analysis method and device |
CN109728920A (en) * | 2017-10-27 | 2019-05-07 | 贵州白山云科技股份有限公司 | A kind of method and device for the service quality improving web service product |
CN109728920B (en) * | 2017-10-27 | 2020-08-21 | 贵州白山云科技股份有限公司 | Method and device for improving service quality of network service product |
CN107894950A (en) * | 2017-10-30 | 2018-04-10 | 北京奇虎科技有限公司 | A kind of equipment detection method, device, server and storage medium |
CN108400907A (en) * | 2018-02-08 | 2018-08-14 | 安徽农业大学 | A kind of link packet drop rate inference method under uncertain network environment |
CN108400907B (en) * | 2018-02-08 | 2021-06-01 | 安徽农业大学 | Link packet loss rate reasoning method under uncertain network environment |
CN108759920B (en) * | 2018-06-04 | 2021-08-27 | 深圳源广安智能科技有限公司 | Warehouse safety monitoring system based on thing networking |
CN108759920A (en) * | 2018-06-04 | 2018-11-06 | 深圳源广安智能科技有限公司 | A kind of depot safety monitoring system based on Internet of Things |
CN108924005B (en) * | 2018-06-29 | 2020-05-12 | 优刻得科技股份有限公司 | Network detection method, network detection apparatus, medium, and device |
CN108924005A (en) * | 2018-06-29 | 2018-11-30 | 优刻得科技股份有限公司 | Network detecting method, network detection device, medium and equipment |
CN109450699A (en) * | 2018-12-06 | 2019-03-08 | 合肥海诺恒信息科技有限公司 | Integration firm IT operation management system and method |
CN111371826B (en) * | 2018-12-26 | 2024-04-09 | 三六零科技集团有限公司 | CDN node performance detection method, device and system |
CN111371826A (en) * | 2018-12-26 | 2020-07-03 | 北京奇虎科技有限公司 | CDN node performance detection method, device and system |
CN111385244A (en) * | 2018-12-27 | 2020-07-07 | 中国移动通信集团四川有限公司 | Abnormal flow identification method, device, equipment, system and medium |
CN109614340A (en) * | 2018-12-28 | 2019-04-12 | 北京微播视界科技有限公司 | Exploitation adjustment method, device, electronic equipment and the storage medium of application program |
CN110557304A (en) * | 2019-09-20 | 2019-12-10 | 腾讯科技(深圳)有限公司 | Address detection method and device and computer readable storage medium |
CN111224959A (en) * | 2019-12-29 | 2020-06-02 | 西安天互通信有限公司 | Server port automatic detection and forwarding defense system and defense method |
CN111327592A (en) * | 2020-01-19 | 2020-06-23 | 深圳市博威创盛科技有限公司 | Network monitoring method and related device |
CN111327592B (en) * | 2020-01-19 | 2022-11-18 | 陈建慧 | Network monitoring method and related device |
CN111885145A (en) * | 2020-07-20 | 2020-11-03 | 北京百度网讯科技有限公司 | Switching method, device, equipment and computer storage medium |
CN112751745A (en) * | 2020-12-28 | 2021-05-04 | 上海蓝云网络科技有限公司 | Message reminding method and device |
CN113472607A (en) * | 2021-06-29 | 2021-10-01 | 未鲲(上海)科技服务有限公司 | Application program network environment detection method, device, equipment and storage medium |
CN113472607B (en) * | 2021-06-29 | 2023-05-02 | 未鲲(上海)科技服务有限公司 | Application program network environment detection method, device, equipment and storage medium |
CN113691420A (en) * | 2021-08-26 | 2021-11-23 | 北京基调网络股份有限公司 | Method for monitoring CDN quality, electronic equipment, server and storage medium |
CN113783755A (en) * | 2021-09-15 | 2021-12-10 | 云茂互联智能科技(厦门)有限公司 | Network monitoring method, network monitoring device, storage medium and electronic device |
CN114285763B (en) * | 2021-11-26 | 2023-05-30 | 中国联合网络通信集团有限公司 | Data acquisition method, device and computer readable storage medium |
CN114285763A (en) * | 2021-11-26 | 2022-04-05 | 中国联合网络通信集团有限公司 | Data acquisition method, data acquisition device and computer-readable storage medium |
CN114615310A (en) * | 2022-03-01 | 2022-06-10 | 天翼安全科技有限公司 | Method and device for maintaining TCP connection and electronic equipment |
CN114629824A (en) * | 2022-03-24 | 2022-06-14 | 阿里巴巴(中国)有限公司 | Packet loss positioning method, device, computing equipment and medium |
CN114629824B (en) * | 2022-03-24 | 2024-03-19 | 阿里巴巴(中国)有限公司 | Packet loss positioning method, device, computing equipment and medium |
CN115190045A (en) * | 2022-07-06 | 2022-10-14 | 南京云柜网络科技有限公司 | Express cabinet system service monitoring method and device, electronic equipment and storage medium |
CN115190045B (en) * | 2022-07-06 | 2024-04-09 | 南京云柜网络科技有限公司 | Monitoring method and device for express cabinet system service, electronic equipment and storage medium |
CN115361358B (en) * | 2022-08-19 | 2024-02-06 | 山石网科通信技术股份有限公司 | IP extraction method and device, storage medium and electronic device |
CN115361358A (en) * | 2022-08-19 | 2022-11-18 | 山石网科通信技术股份有限公司 | IP extraction method, device, storage medium and electronic device |
CN116170294B (en) * | 2023-02-21 | 2023-07-11 | 北京志凌海纳科技有限公司 | Network anomaly detection method and system for distributed system |
CN116170294A (en) * | 2023-02-21 | 2023-05-26 | 北京志凌海纳科技有限公司 | Network anomaly detection method and system for distributed system |
Also Published As
Publication number | Publication date |
---|---|
CN106533722B (en) | 2019-06-21 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN106533722A (en) | Network monitoring method and network monitoring device | |
CN104219670B (en) | Identify method, client and the system of falseness wifi | |
CN112491611B (en) | Fault location system, method, apparatus, electronic device, and computer readable medium | |
CN105335271A (en) | State monitoring apparatus and comprehensive monitoring system and method | |
CN108768753B (en) | Method and device for positioning warning source, storage medium and electronic device | |
CN109861878B (en) | Method for monitoring topic data of kafka cluster and related equipment | |
CN108170580A (en) | A kind of rule-based log alarming method, apparatus and system | |
CN104052832B (en) | Method and device for setting IP address of domain name resolution server and server | |
CN105868256A (en) | Method and system for processing user behavior data | |
CN108182783A (en) | A kind of method and apparatus of data sampling and processing | |
CN106685984A (en) | Network threat analysis system and method based on data pocket capture technology | |
CN110706030A (en) | Advertisement putting method, device, system and storage medium | |
CN109413017B (en) | Method and system for managing heterogeneous firewall | |
CN107147546A (en) | Double net heartbeat inspecting method and system | |
CN107528817A (en) | The detection method and device of Domain Hijacking | |
CN109905262A (en) | A kind of monitoring system and monitoring method of CDN device service | |
CN106161443A (en) | A kind of monitoring method and device of game service | |
CN107995066A (en) | A kind of method and apparatus of automatic test network interface card | |
CN108269116A (en) | A kind of advertisement safety monitoring method and device | |
CN106230775A (en) | Prevent from attacking method and the device of URL rule base | |
US20130041716A1 (en) | Method for notifying a sales person of a sales prospect | |
CN107483350A (en) | A kind of gateway distribution method and device | |
CN111526109A (en) | Method and device for automatically detecting running state of web threat recognition defense system | |
CN106571971A (en) | Empty shell website detection method, device and system | |
CN117312098A (en) | Log abnormity alarm method and device |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
CB02 | Change of applicant information |
Address after: 100083 No. 401, 4th Floor, Haitai Building, 229 North Fourth Ring Road, Haidian District, Beijing Applicant after: Beijing Guoshuang Technology Co.,Ltd. Address before: 100086 Cuigong Hotel, 76 Zhichun Road, Shuangyushu District, Haidian District, Beijing Applicant before: Beijing Guoshuang Technology Co.,Ltd. |
|
CB02 | Change of applicant information | ||
GR01 | Patent grant | ||
GR01 | Patent grant |