CN107018043A - A kind of detection method and device of shared verification - Google Patents

A kind of detection method and device of shared verification Download PDF

Info

Publication number
CN107018043A
CN107018043A CN201710271419.4A CN201710271419A CN107018043A CN 107018043 A CN107018043 A CN 107018043A CN 201710271419 A CN201710271419 A CN 201710271419A CN 107018043 A CN107018043 A CN 107018043A
Authority
CN
China
Prior art keywords
address
node
terminal
timestamp value
source
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201710271419.4A
Other languages
Chinese (zh)
Inventor
曾祥禄
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing An Polytron Technologies Inc
Original Assignee
Beijing An Polytron Technologies Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing An Polytron Technologies Inc filed Critical Beijing An Polytron Technologies Inc
Priority to CN201710271419.4A priority Critical patent/CN107018043A/en
Publication of CN107018043A publication Critical patent/CN107018043A/en
Pending legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/08Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters

Landscapes

  • Engineering & Computer Science (AREA)
  • Environmental & Geological Engineering (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention discloses a kind of detection method and device of shared verification, the detection method includes:In default detection duration, the source IP address and timestamp value of the message received, and current system time are obtained;Determine the corresponding IP address node of the source IP address;It is determined that with the IP address node and send the corresponding terminal node of user terminal of the message, store the timestamp value is corresponding with system time into the terminal node;In the default detection duration of metering, the quantity of the timestamp value stored in each terminal node determines whether the corresponding user terminal of the terminal node is effective terminal according to the result of metering;In the default detection duration of metering, the quantity of the corresponding effective terminal of each IP address node determines the quantity of the user terminal by the corresponding source IP address shared verification of the IP address node according to the result of metering.The detection method, can accurately determine the quantity of the user terminal of shared verification, detect more accurate.

Description

A kind of detection method and device of shared verification
Technical field
The present invention relates to Internet communication technology field, more particularly to a kind of detection method and device of shared verification.
Background technology
Generally, user, can be in a collective (such as school or enterprise) in order to save cost and protection internal network Portion sets up a LAN, is surfed the Net in LAN by the way of shared verification, i.e., multiple Intranet (LAN) users pass through Routing device is carried out after network address translation, (is interconnected using same public network IP between Internet Protocol, network Agreement) address connection outer net (wide area network).And consideration of the operator for interests and management aspect of outer net Connection Service is provided, Shared verification can be controlled, wherein, it is necessary first to shared verification is detected.
In the prior art, outer net manager generally sets shared verification between the LAN and outer net for needing to be managed Detection means, is detected to the shared verification of user.TCP (Transmission Control Protocol, transmission control Agreement) timestamp detection method is a kind of conventional shared verification detection method, mainly each user terminal is respectively provided with one Individual timestamp clock, the timestamp clock takes linear increase after an initial value after the unlatching of relative users terminal, therefore often The timestamp that the TCP message that individual user terminal is sent is carried is different, and thus user terminal can be made a distinction.
For TCP timestamp detection methods, it is typically only capable to detect in certain time period, if there are the feelings of shared verification Condition, and can not specifically detect in each LAN, how many user terminals are had in shared verification, i.e. by the party Method, it is impossible to detect in each LAN, the particular number of the user terminal of shared verification.
The content of the invention
The invention provides a kind of detection method and device of shared verification, to solve existing TCP timestamps detection side Method, it is impossible to the problem of detecting the particular number of user terminal of shared verification.
In a first aspect, the invention provides a kind of detection method of shared verification, the detection method includes:In default detection In duration, the source IP address and timestamp value of the message received, and current system time are obtained;Determine the source IP address Corresponding IP address node;It is determined that with the IP address node and sending the corresponding terminal section of user terminal of the message Point, is stored the timestamp value is corresponding with the system time into the terminal node;Measure in the default detection duration, The quantity of the timestamp value stored in each terminal node, the corresponding user terminal of the terminal node is determined according to the result of metering Whether it is effective terminal;Measure in the default detection duration, the quantity of the corresponding effective terminal of each IP address node, according to The result of metering determines the quantity of the user terminal by the corresponding source IP address shared verification of the IP address node.
Further, it is determined that with the IP address node and sending the corresponding terminal node of user terminal of the message, By the timestamp value process stored into the terminal node corresponding with the system time, specifically include:Judge the IP Whether be stored with timestamp value t in addressed nodesi, the timestamp value tiFollowing relational expressions are met with the timestamp value;(t- ti)*10≈(p-pi)*1000;Wherein, t represents the timestamp value, and p represents the system time, piRepresent and the time Timestamp value tiThe system time of correspondence storage, i takes positive integer, ti< t, pi< p;If it is, by timestamp value tiCorresponding terminal Node is as the corresponding terminal node of user terminal with the IP address node and the transmission message, by the timestamp Value is corresponding with the system time to be stored into the terminal node;Or, if it is not, then set up and institute in the IP address node State IP address node and send the corresponding terminal node of user terminal of the message, by the timestamp value and the system Time correspondence is stored into the terminal node.
Further, the process of the corresponding IP address node of the source IP address is determined, is specifically included:Judge all of storage In the corresponding IP address of IP address node, if exist and the source IP address identical target ip address;If it is, by institute The corresponding IP address node of target ip address is stated as the corresponding IP address node of the source IP address;Or, if it is not, then set up The corresponding IP address node of the source IP address, is stored source IP address IP address node corresponding with its is corresponding.
Further, measure in the default detection duration, the quantity of the timestamp value stored in each terminal node, according to The result of metering determine the corresponding user terminal of the terminal node whether be effective terminal process, specifically include:Metering is described In default detection duration, the quantity of the timestamp value stored in each terminal node, if the time stored in the terminal node The quantity of timestamp value is more than predetermined number, and the corresponding user terminal of the terminal node is defined as into effective terminal;Or, if the terminal The quantity of the timestamp value stored in node is less than or equal to the predetermined number, and the corresponding user terminal of the terminal node is true It is set to inactive terminals.
Further, before the quantity of the timestamp value stored in measuring each terminal node, the detection method also includes: Delete the timestamp value that storage time in each terminal node exceedes preset time threshold.
Second aspect, present invention also offers a kind of detection means of shared verification, the detection means includes:Message information Acquisition module, in default detection duration, obtaining the source IP address and timestamp value of the message received, and current be The system time;IP address node determining module, for determining the corresponding IP address node of the source IP address;Terminal node determines mould Block, the corresponding terminal node of user terminal for determining with the IP address node and sending the message, when will be described Between timestamp value is corresponding with the system time stores into the terminal node;First metering module, for measuring the default detection In duration, the quantity of the timestamp value stored in each terminal node determines that the terminal node is corresponding according to the result of metering Whether user terminal is effective terminal;Second metering module, for measuring in the default detection duration, each IP address node The quantity of corresponding effective terminal, determines to pass through the corresponding source IP address shared verification of the IP address node according to the result of metering User terminal quantity.
Further, the terminal node determining module specifically for:When judging whether to be stored with the IP address node Between timestamp value ti, the timestamp value tiFollowing relational expressions are met with the timestamp value;(t-ti)*10≈(p-pi)*1000;Its In, t represents the timestamp value, and p represents the system time, piRepresent and the timestamp value tiDuring the system of correspondence storage Between, i takes positive integer, ti< t, pi< p;If it is, by timestamp value tiCorresponding terminal node as with the IP address section Point and the corresponding terminal node of user terminal of the message is sent, deposited the timestamp value is corresponding with the system time Storage is into the terminal node;Or, if it is not, then set up described with the IP address node and transmission in the IP address node The corresponding terminal node of the user terminal of message, is stored the timestamp value is corresponding with the system time to the terminal section Point in.
Further, the IP address node determining module specifically for:Judge that all IP address nodes of storage are corresponding In IP address, if exist and the source IP address identical target ip address;If it is, the target ip address is corresponding IP address node be used as the corresponding IP address node of the source IP address;Or, if it is not, then set up the source IP address correspondence IP address node, stored source IP address IP address node corresponding with its is corresponding.
Further, first metering module specifically for:Measure in the default detection duration, in each terminal node The quantity of the timestamp value of storage, if the quantity of the timestamp value stored in the terminal node is more than predetermined number, by the end The corresponding user terminal of end node is defined as effective terminal;Or, if the quantity of the timestamp value stored in the terminal node is small In or equal to the predetermined number, the corresponding user terminal of the terminal node is defined as inactive terminals.
Further, the detection means also includes:Removing module, exceedes in advance for deleting storage time in each terminal node If the timestamp value of time threshold.
Technical scheme provided in an embodiment of the present invention can include the following benefits:Shared the invention provides one kind The detection method and device of net, the detection method is parsed by each message sent to user terminal, gets this The source IP address and timestamp value of message, and by setting IP address node in detection means, and in each IP address User terminal corresponding terminal node with transmission message is set in node, by the source IP address of each message and IP Location node is corresponded to, and the timestamp value of the message is recorded into the IP address node into the user terminal with sending the message In corresponding terminal node, afterwards by counting the quantity of the corresponding effective terminal of each IP address node, you can clear true Make the quantity for the user terminal that shared verification is carried out by the corresponding source IP address of the IP address node, the detection of shared verification More accurate, applicability is more preferable.
Brief description of the drawings
In order to illustrate more clearly of the technical scheme of the application, letter will be made to the required accompanying drawing used in embodiment below Singly introduce, it should be apparent that, for those of ordinary skills, without having to pay creative labor, Other accompanying drawings can also be obtained according to these accompanying drawings.
Fig. 1 is a kind of schematic flow sheet of the detection method of shared verification provided in an embodiment of the present invention;
Fig. 2 is a kind of structured flowchart of the detection means of shared verification provided in an embodiment of the present invention.
Embodiment
With reference to background technology understand, Virtual network operator in order to in some LAN shared verification situation carry out detection and The detection means for detecting shared verification is arranged in management, network that can be between the LAN and outer net, using the detection Device is detected and managed to the shared verification situation in the LAN.Based on this, the inspection of shared verification that the present invention is provided In survey method, by the detection means for detecting shared verification, using bypass or serial manner, the target of detection is wanted in access In communication network between LAN and outer net, so, the user terminal of any one in target LAN sends appointing to outer net One message of meaning, can first be sent to the detection means, be sent afterwards by the detection means to outer net.Wherein, target office The quantity of domain net can be one, or multiple, you can to use the detection means simultaneously to one or more targets office The situation of shared verification is detected in the net of domain.
When carrying out shared verification detection to any one target LAN, typically in one section of duration, the target The situation of shared verification is detected in LAN, therefore, and the situation of shared verification is detected in the target LAN Before, it will usually pre-set a default detection duration, the default detection duration can arbitrarily be set according to actual needs Calmly, the situation of shared verification is detected in default detection duration to the target LAN;Or, can also be with default inspection A length of cycle during survey, persistently the situation to shared verification in the target LAN detect.When below with a default detection Exemplified by length, the specific embodiment of the detection method for the shared verification that the present invention is provided is discussed in detail.
Referring to Fig. 1, Fig. 1 is illustrated that a kind of flow signal of the detection method of shared verification provided in an embodiment of the present invention Figure.Understand that the detection method includes with reference to Fig. 1:
Step 101, in default detection duration, obtain the source IP address and timestamp value of the message received, and currently System time.
, can in target LAN during the situation of shared verification in specific implementation process, it is desirable to detect in some period In detection means, will detect that the time started is set to the initial time of the period, default detection duration is set to this The duration of period.After detection starts, detection means is received after any one message of any one user terminal transmission, right The message is parsed, by parsing the IP header informations of the message, parses the source IP address of the message, and pass through parsing The TCP header information of the message, parses the timestamp value of the message, and records current system time.
Step 102, determine the corresponding IP address node of the source IP address.
Initial in detection, detection means receives first message, and gets after the source IP address of the message, can set up One IP address node corresponding with the source IP address of the message, and by the source IP address of the message and corresponding IP address Node correspondence is stored.Detection means often receives a message after first message is received, later, and gets After the source IP address of the message, in the corresponding IP address of all IP address nodes that can first judge storage, if exist with being somebody's turn to do The source IP address identical target ip address of message, if storage the corresponding IP address of all IP address nodes in, exist with The source IP address identical target ip address of the message, then regard the corresponding IP address node of the target ip address as the message The corresponding IP address node of source IP address;Or, if storage the corresponding IP address of all IP address nodes in, in the absence of with this The source IP address identical target ip address of message, then newly-built IP address node corresponding with the source IP address of the message, and will The source IP address of message IP address node corresponding with its is corresponding to be stored.
Step 103, the corresponding terminal node of user terminal for determining with the IP address node and sending the message, Store the timestamp value is corresponding with the system time into the terminal node.
Understood with reference to foregoing, initial in detection, detection means receives first message, and gets the source IP of the message Behind address, an IP address node corresponding with the source IP address of the message can be set up, and by the source IP address of the message and with Its corresponding IP address node correspondence is stored.In addition, detection means is after the message is received, the message can be also obtained Timestamp value and current system time, and in IP address node corresponding with the source IP address of the message, set up one with The IP address node and the corresponding terminal node of user terminal for sending the message, afterwards, can be by the timestamp value of the message Corresponding stored with the corresponding system time got together with the timestamp value into the terminal node.
Detection means is after first message is received, and any one message received for after is getting this The timestamp value t of message and system time p corresponding with the timestamp value t of the message, and the source IP of the message is determined After the corresponding IP address node in location, the message can be judged first according to the timestamp value t of the message and corresponding system time p Whether whether corresponding with some terminal node stored in the IP address node, that is, it is from the IP address section to judge the message Sent in point in the stored corresponding user terminal of some terminal node.Specific implementation process is:Judge the IP address section Whether be stored with timestamp value t in pointi, timestamp value tiFollowing relational expressions (1) are met with the timestamp value t of the message;
(t-ti)*10≈(p-pi)*1000 (1)
In relational expression (1), t represents the timestamp value of the message, and p represents to receive after the message, acquisition with the message The corresponding system times of timestamp value t, piRepresent and timestamp value tiThe system time of correspondence storage, i takes positive integer;ti< T, pi< p;As (t-ti) * 10 value and (p-pi) * 1000 value between difference 30000ns (nanosecond)~80000ns (nanosecond) When, such as between the two difference 60000ns (nanosecond), it is believed that both meet relational expression (1).
If in the corresponding IP address node of the source IP address of the message, being stored with and meeting the time of above-mentioned relation formula (1) Timestamp value ti, then the timestamp value t of above-mentioned relation formula (1) will be metiCorresponding terminal node as with the IP address node and transmission The corresponding terminal node of the user terminal of the message, and obtained by the timestamp value t of the message and together with timestamp value t Corresponding system time p correspondence store into the terminal node;Or, if the corresponding IP address section of the source IP address of the message There is no storage to meet the timestamp value t of above-mentioned relation formula (1) in pointi, then in the corresponding IP address section of source IP address of the message The corresponding terminal node of user terminal with the IP address node and transmission message is set up in point, and by the time of the message The timestamp value t and corresponding system time p obtained together with timestamp value t is corresponding stores to the terminal node.
In step 104, the metering default detection duration, the quantity of the timestamp value stored in each terminal node, root Determine whether the corresponding user terminal of the terminal node is effective terminal according to the result of metering.
Since detection, after the period of default detection duration, detection means can be measured in each terminal node The quantity of the timestamp value of storage, if the quantity of the timestamp value stored in the terminal node is more than predetermined number, by the end The corresponding user terminal of end node is defined as effective terminal, and the terminal node is labeled as into effective terminal node;Or, if should The quantity of the timestamp value stored in terminal node is less than or equal to predetermined number, and the corresponding user terminal of the terminal node is true It is set to inactive terminals, and the terminal node is labeled as inactive terminals node.Wherein, predetermined number can according to actual needs with Meaning setting, for example, could be arranged to 200.
It is more accurate for the testing result of shared verification in some optional embodiments, measuring each terminal Before the quantity of the timestamp value stored in node, it can also delete storage time in each terminal node and exceed preset time threshold The timestamp value of value.Wherein, preset time threshold can also arbitrarily be set according to actual needs, for example, being set to half Hour.When it is implemented, the storage of the timestamp value can be judged according to the system time of storage corresponding with each timestamp value Whether the time exceedes preset time threshold.
Step 105, measure in the default detection duration, the quantity of the corresponding effective terminal of each IP address node, root The quantity of the user terminal by the corresponding source IP address shared verification of the IP address node is determined according to the result of metering.
Since detection, after the period of default detection duration, detection means is determining each terminal node After whether corresponding user terminal is effective terminal, by measuring the quantity of the corresponding effective terminal of each IP address node, i.e., By the quantity for measuring the effective terminal node included in each IP address node, you can determine since detection, inspection is preset Survey in the duration corresponding period, the number of the user terminal of shared verification is carried out by the corresponding source IP address of the IP address node Amount.For example, since detection, after the period of default detection duration, detection means metering obtains some IP address node The quantity of corresponding effective terminal is N, then can determine to carry out shared verification by the corresponding source IP address of the IP address node User terminal quantity be N.
The detection method of shared verification provided in an embodiment of the present invention, is entered by each message sent to user terminal Row parsing, gets the source IP address and timestamp value of the message, and by setting IP address node in detection means, with And terminal node corresponding with the user terminal for sending message is set in each IP address node, by the source IP of each message Address is corresponding with an IP address node progress, and the timestamp value of the message is recorded into the IP address node with sending this In the corresponding terminal node of user terminal of message, afterwards by counting the number of the corresponding effective terminal of each IP address node Amount, you can clearly determine the quantity for the user terminal that shared verification is carried out by the corresponding source IP address of the IP address node, The detection of shared verification is more accurate, and applicability is more preferable.
Detection method with above-mentioned shared verification is corresponding, and present invention also offers a kind of detection means of shared verification.
Referring to Fig. 2, Fig. 2 is illustrated that a kind of structural frames of the detection means of shared verification provided in an embodiment of the present invention Figure.Understand that the detection means includes with reference to Fig. 2:Message information acquisition module 201, in default detection duration, acquisition to connect The source IP address and timestamp value of the message of receipts, and current system time;IP address node determining module 202, for true Determine the corresponding IP address node of the source IP address;Terminal node determining module 203, for determine with the IP address node and Send the corresponding terminal node of user terminal of the message, by the timestamp value it is corresponding with the system time store to In the terminal node;First metering module 204, for measuring in the default detection duration, is stored in each terminal node The quantity of timestamp value, determines whether the corresponding user terminal of the terminal node is effective terminal according to the result of metering;Second Metering module 205, for measuring in the default detection duration, the quantity of the corresponding effective terminal of each IP address node, root The quantity of the user terminal by the corresponding source IP address shared verification of the IP address node is determined according to the result of metering.
Further, the terminal node determining module 203 specifically for:Judge whether be stored with the IP address node Timestamp value ti, the timestamp value tiFollowing relational expressions are met with the timestamp value;(t-ti)*10≈(p-pi)*1000; Wherein, t represents the timestamp value, and p represents the system time, piRepresent and the timestamp value tiThe system of correspondence storage Time, i takes positive integer, ti< t, pi< p;If it is, by timestamp value tiCorresponding terminal node as with the IP address Node and the corresponding terminal node of user terminal for sending the message, the timestamp value is corresponding with the system time Store into the terminal node;Or, if it is not, then set up in the IP address node and the IP address node and transmission institute The corresponding terminal node of user terminal of message is stated, is stored the timestamp value is corresponding with the system time to the terminal In node.
Further, the IP address node determining module 202 specifically for:Judge all IP address nodes correspondence of storage IP address in, if exist and the source IP address identical target ip address;If it is, by the target ip address pair The IP address node answered is used as the corresponding IP address node of the source IP address;Or, if it is not, then set up the source IP address pair The IP address node answered, is stored source IP address IP address node corresponding with its is corresponding.
Further, first metering module 204 specifically for:Measure in the default detection duration, each terminal section The quantity of the timestamp value stored in point, will if the quantity of the timestamp value stored in the terminal node is more than predetermined number The corresponding user terminal of the terminal node is defined as effective terminal;Or, if the number of the timestamp value stored in the terminal node Amount is less than or equal to the predetermined number, and the corresponding user terminal of the terminal node is defined as into inactive terminals.
Further, the detection means also includes:Removing module 206, surpasses for deleting storage time in each terminal node Cross the timestamp value of preset time threshold.
The detection means of shared verification provided in an embodiment of the present invention, it is possible to implement the detection method of above-mentioned shared verification Each specific steps, is parsed by each message sent to user terminal, gets the source IP address of the message And timestamp value, and set by internally setting IP address node, and in each IP address node with sending message The corresponding terminal node of user terminal, the source IP address of each message is corresponding with an IP address node progress, and will The timestamp value of the message is recorded into the IP address node in terminal node corresponding with the user terminal for sending the message, it Afterwards by counting the quantity of the corresponding effective terminal of each IP address node, you can clearly determine by the IP address node Corresponding source IP address carries out the quantity of the user terminal of shared verification, and the detection of shared verification is more accurate, and applicability is more preferable.
In the specific implementation, the present invention also provides a kind of computer-readable storage medium, wherein, the computer-readable storage medium can be stored There is program, the program may include the part or complete in each embodiment of the detection method for the shared verification that the present invention is provided when performing Portion's step.Described storage medium can be magnetic disc, CD, read-only memory (English:Read-only memory, referred to as: ROM) or random access memory (English:Random access memory, referred to as:RAM) etc..
It is required that those skilled in the art can be understood that the technology in the embodiment of the present invention can add by software The mode of general hardware platform realize.Understood based on such, the technical scheme in the embodiment of the present invention substantially or Say that the part contributed to prior art can be embodied in the form of software product, the computer software product can be deposited Storage is in storage medium, such as ROM/RAM, magnetic disc, CD, including some instructions are to cause a computer equipment (can be with It is personal computer, server, or network equipment etc.) perform some part institutes of each of the invention embodiment or embodiment The method stated.
Between the embodiment of each in this specification identical similar part mutually referring to.Especially for shared verification Detection means embodiment for, because it is substantially similar to embodiment of the method, so description is fairly simple, related part is joined The explanation seen in embodiment of the method.
Invention described above embodiment is not intended to limit the scope of the present invention..

Claims (10)

1. a kind of detection method of shared verification, it is characterised in that including:
In default detection duration, the source IP address and timestamp value of the message received, and current system time are obtained;
Determine the corresponding IP address node of the source IP address;
It is determined that with the IP address node and the corresponding terminal node of user terminal of the message is sent, by the timestamp Value is corresponding with the system time to be stored into the terminal node;
Measure in the default detection duration, the quantity of the timestamp value stored in each terminal node, according to the result of metering Whether determine the corresponding user terminal of the terminal node is effective terminal;
Measure in the default detection duration, the quantity of the corresponding effective terminal of each IP address node, according to the result of metering It is determined that the quantity of the user terminal by the corresponding source IP address shared verification of the IP address node.
2. detection method as claimed in claim 1, it is characterised in that it is determined that with the IP address node and sending the message The corresponding terminal node of user terminal, store the timestamp value is corresponding with the system time into the terminal node Process, specifically include:
Judge the timestamp value t that whether is stored with the IP address nodei, the timestamp value tiMet with the timestamp value Following relational expressions;
(t-ti)*10≈(p-pi)*1000;
Wherein, t represents the timestamp value, and p represents the system time, piRepresent and the timestamp value tiCorrespondence storage System time, i takes positive integer, ti< t, pi< p;
If it is, by timestamp value tiCorresponding terminal node is used as the use with the IP address node and the transmission message The corresponding terminal node of family terminal, is stored the timestamp value is corresponding with the system time into the terminal node;Or,
If it is not, then foundation and the user terminal of the IP address node and the transmission message are equal in the IP address node Corresponding terminal node, is stored the timestamp value is corresponding with the system time into the terminal node.
3. detection method as claimed in claim 1, it is characterised in that determine the corresponding IP address node of the source IP address Process, is specifically included:
In the corresponding IP address of all IP address nodes for judging storage, if exist and the source IP address identical Target IP Address;
If it is, regarding the corresponding IP address node of the target ip address as the corresponding IP address section of the source IP address Point;Or,
If it is not, then the corresponding IP address node of the source IP address is set up, by source IP address IP address corresponding with its Node correspondence is stored.
4. detection method as claimed in claim 1, it is characterised in that in the metering default detection duration, each terminal section The quantity of the timestamp value stored in point, determines whether the corresponding user terminal of the terminal node is effective according to the result of metering The process of terminal, is specifically included:
Measure in the default detection duration, the quantity of the timestamp value stored in each terminal node, if the terminal node The quantity of the timestamp value of middle storage is more than predetermined number, and the corresponding user terminal of the terminal node is defined as into effective terminal; Or, if the quantity of the timestamp value stored in the terminal node is less than or equal to the predetermined number, by the terminal node pair The user terminal answered is defined as inactive terminals.
5. detection method as claimed in claim 1, it is characterised in that the timestamp value stored in each terminal node is measured Quantity before, the detection method also includes:
Delete the timestamp value that storage time in each terminal node exceedes preset time threshold.
6. a kind of detection means of shared verification, it is characterised in that including:
Message information acquisition module, in default detection duration, obtaining the source IP address and timestamp value of the message received, And current system time;
IP address node determining module, for determining the corresponding IP address node of the source IP address;
Terminal node determining module, it is corresponding with the user terminal of the IP address node and the transmission message for determining Terminal node, is stored the timestamp value is corresponding with the system time into the terminal node;
First metering module, for measuring in the default detection duration, the number of the timestamp value stored in each terminal node Amount, determines whether the corresponding user terminal of the terminal node is effective terminal according to the result of metering;
Second metering module, for measuring in the default detection duration, the number of the corresponding effective terminal of each IP address node Amount, the quantity of the user terminal by the corresponding source IP address shared verification of the IP address node is determined according to the result of metering.
7. detection means as claimed in claim 6, it is characterised in that the terminal node determining module specifically for:
Judge the timestamp value t that whether is stored with the IP address nodei, the timestamp value tiMet with the timestamp value Following relational expressions;
(t-ti)*10≈(p-pi)*1000;
Wherein, t represents the timestamp value, and p represents the system time, piRepresent and the timestamp value tiCorrespondence storage System time, i takes positive integer, ti< t, pi< p;
If it is, by timestamp value tiCorresponding terminal node is used as the use with the IP address node and the transmission message The corresponding terminal node of family terminal, is stored the timestamp value is corresponding with the system time into the terminal node;Or,
If it is not, then foundation and the user terminal of the IP address node and the transmission message are equal in the IP address node Corresponding terminal node, is stored the timestamp value is corresponding with the system time into the terminal node.
8. detection means as claimed in claim 6, it is characterised in that the IP address node determining module specifically for:
In the corresponding IP address of all IP address nodes for judging storage, if exist and the source IP address identical Target IP Address;
If it is, regarding the corresponding IP address node of the target ip address as the corresponding IP address section of the source IP address Point;Or,
If it is not, then the corresponding IP address node of the source IP address is set up, by source IP address IP address corresponding with its Node correspondence is stored.
9. detection means as claimed in claim 6, it is characterised in that first metering module specifically for:
Measure in the default detection duration, the quantity of the timestamp value stored in each terminal node, if the terminal node The quantity of the timestamp value of middle storage is more than predetermined number, and the corresponding user terminal of the terminal node is defined as into effective terminal; Or, if the quantity of the timestamp value stored in the terminal node is less than or equal to the predetermined number, by the terminal node pair The user terminal answered is defined as inactive terminals.
10. detection means as claimed in claim 6, it is characterised in that the detection means also includes:
Removing module, the timestamp value of preset time threshold is exceeded for deleting storage time in each terminal node.
CN201710271419.4A 2017-04-24 2017-04-24 A kind of detection method and device of shared verification Pending CN107018043A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201710271419.4A CN107018043A (en) 2017-04-24 2017-04-24 A kind of detection method and device of shared verification

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201710271419.4A CN107018043A (en) 2017-04-24 2017-04-24 A kind of detection method and device of shared verification

Publications (1)

Publication Number Publication Date
CN107018043A true CN107018043A (en) 2017-08-04

Family

ID=59447489

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201710271419.4A Pending CN107018043A (en) 2017-04-24 2017-04-24 A kind of detection method and device of shared verification

Country Status (1)

Country Link
CN (1) CN107018043A (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114285769A (en) * 2021-12-16 2022-04-05 南京中孚信息技术有限公司 Shared internet access detection method, device, equipment and storage medium

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1852182A (en) * 2006-03-15 2006-10-25 华为技术有限公司 Method and apparatus for detecting number of mobile host computers
CN102523263A (en) * 2011-12-06 2012-06-27 中国联合网络通信集团有限公司 Sharing access host quantity monitoring method, device thereof and system thereof
CN105704088A (en) * 2014-11-25 2016-06-22 中兴通讯股份有限公司 Multi-user shared Internet access detection method and device
CN105703962A (en) * 2014-11-25 2016-06-22 中兴通讯股份有限公司 Internet access user detection method and device

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1852182A (en) * 2006-03-15 2006-10-25 华为技术有限公司 Method and apparatus for detecting number of mobile host computers
CN102523263A (en) * 2011-12-06 2012-06-27 中国联合网络通信集团有限公司 Sharing access host quantity monitoring method, device thereof and system thereof
CN105704088A (en) * 2014-11-25 2016-06-22 中兴通讯股份有限公司 Multi-user shared Internet access detection method and device
CN105703962A (en) * 2014-11-25 2016-06-22 中兴通讯股份有限公司 Internet access user detection method and device

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114285769A (en) * 2021-12-16 2022-04-05 南京中孚信息技术有限公司 Shared internet access detection method, device, equipment and storage medium
CN114285769B (en) * 2021-12-16 2024-03-22 南京中孚信息技术有限公司 Shared internet surfing detection method, device, equipment and storage medium

Similar Documents

Publication Publication Date Title
US8880604B2 (en) Determination of a spammer through social network characterization
US20030229695A1 (en) System for use in determining network operational characteristics
CN101166122B (en) A method for locating network failure between communication terminals
CN103532774A (en) Intelligent speed measurement client-terminal and intelligent speed measurement method thereof
CN1937541A (en) Network performance test method
WO2017032133A1 (en) Packet loss rate detection method and apparatus
US20120173712A1 (en) Method and device for identifying p2p application connections
CN110365698A (en) Methods of risk assessment and device
CN112016030B (en) Message pushing method, device, server and computer storage medium
CN109831429A (en) A kind of Webshell detection method and device
WO2011144041A2 (en) Method for detecting quality of service, management and control server, monitoring probe and system thereof
EP0522211A1 (en) Testing a packet-based network
CN108206769A (en) Method, apparatus, equipment and the medium of screen quality alarm
CN115102747B (en) Internet management platform based on digital twinning
CN105743732A (en) Method and system for recording transmission paths and distribution conditions of files in local area network
CN108335165A (en) Interest tags determine method and apparatus
CN103995901B (en) A kind of method for determining back end failure
CN107018043A (en) A kind of detection method and device of shared verification
CN107579981A (en) A kind of network flow monitoring method and system
EP1684458A1 (en) A method of calculating broadband access server dhcp user's on-line time
CN110138682A (en) A kind of method for recognizing flux and device
CN109327349B (en) Method, medium, device and system for limiting block chain account during creation
CN106533847A (en) Method and device for detecting UDP communication quality, and UDP communication system
Millí et al. Application of the analysis of self-similar teletraffic with long-range dependence (LRD) at the network layer level
CN115150901B (en) Method, device and storage medium for determining quality difference cell in communication network

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication
RJ01 Rejection of invention patent application after publication

Application publication date: 20170804