CN107087006B - A kind of agreement shunt method, system and server - Google Patents

A kind of agreement shunt method, system and server Download PDF

Info

Publication number
CN107087006B
CN107087006B CN201710374366.9A CN201710374366A CN107087006B CN 107087006 B CN107087006 B CN 107087006B CN 201710374366 A CN201710374366 A CN 201710374366A CN 107087006 B CN107087006 B CN 107087006B
Authority
CN
China
Prior art keywords
feature
router
feature database
agreement
network
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201710374366.9A
Other languages
Chinese (zh)
Other versions
CN107087006A (en
Inventor
高峰
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Full Message Converged Network Technology (beijing) Co Ltd
Original Assignee
Full Message Converged Network Technology (beijing) Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Full Message Converged Network Technology (beijing) Co Ltd filed Critical Full Message Converged Network Technology (beijing) Co Ltd
Priority to CN201710374366.9A priority Critical patent/CN107087006B/en
Publication of CN107087006A publication Critical patent/CN107087006A/en
Application granted granted Critical
Publication of CN107087006B publication Critical patent/CN107087006B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/16Implementation or adaptation of Internet protocol [IP], of transmission control protocol [TCP] or of user datagram protocol [UDP]
    • H04L69/161Implementation details of TCP/IP or UDP/IP stack architecture; Specification of modified or new header fields
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/52Multiprotocol routers
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/74Address processing for routing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/18Multiprotocol handlers, e.g. single devices capable of handling multiple protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/30Definitions, standards or architectural aspects of layered protocol stacks
    • H04L69/32Architecture of open systems interconnection [OSI] 7-layer type protocol stacks, e.g. the interfaces between the data link level and the physical level
    • H04L69/322Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions
    • H04L69/329Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions in the application layer [OSI layer 7]
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y02TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
    • Y02DCLIMATE CHANGE MITIGATION TECHNOLOGIES IN INFORMATION AND COMMUNICATION TECHNOLOGIES [ICT], I.E. INFORMATION AND COMMUNICATION TECHNOLOGIES AIMING AT THE REDUCTION OF THEIR OWN ENERGY USE
    • Y02D30/00Reducing energy consumption in communication networks
    • Y02D30/50Reducing energy consumption in communication networks in wire-line communication networks, e.g. low power modes or reduced link rate

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention discloses a kind of agreement shunt methods, are applied to server, comprising: summarize the whole characteristic packets provided by router, obtain characteristic packet set;Feature extraction is carried out to the characteristic packet set, obtains feature database;The feature database is periodically sent in the router, when in order to receive the first time handshake request based on TCP connection when the router, application layer protocol type, and the allocation of packets network line sent according to the identified application layer protocol type to client are identified according to the feature database.It realizes and quickly timely carries out agreement shunting again, reduce the power consumption that router is generated by data processing, hence it is evident that improve network speed, network line distribution is balanced, avoids the waste of user bandwidth resource.The invention also discloses a kind of server and a kind of agreement separate systems, have said effect.

Description

A kind of agreement shunt method, system and server
Technical field
The present invention relates to field of network data transmission, in particular to a kind of application layer protocol shunt method further relates to one kind Server further relates to a kind of agreement separate system.
Background technique
Currently, being built by TCP (the Transmission Control Protocol) transmission control protocol in transport layer Connection between vertical end and end, guarantees reliable, sequence (data packet is received with the sequence sent) and will not duplicate number According to transmission.Agreement shunting refers to that data packet can be transmitted according to specified protocol in given line under multi-thread environment, In, the agreement in agreement shunting refers to application layer protocol.
In the prior art, agreement shunts inaccurate reason and is that first three message of Transmission Control Protocol is not carry application layer Data also can not just judge application layer protocol type so that deep message identification can not be carried out, can not be according to application layer protocol Type is accurately shunted, and there is no carry out network line point according to affiliated application layer protocol type for final different data packet Match, causes the waste of user bandwidth resource, network line distributes unbalanced and slow network speed problem.
Therefore, how to carry out agreement shunting in time and accurately is that those skilled in the art's urgent need technology to be solved is asked Topic.
Summary of the invention
In view of this, in time and effectively raising the standard that agreement shunts the present invention provides a kind of agreement shunt method True property, and then it is slow to solve the problems, such as that the waste of user bandwidth resource, network line distribute unbalanced and network speed.
To achieve the above object, the present invention provides a kind of agreement shunt methods, are applied to server, comprising:
The whole characteristic packets provided by router are provided, characteristic packet set is obtained;
Feature extraction is carried out to the characteristic packet set, obtains feature database;
The feature database is periodically sent in the router, in order to be based on TCP connection when the router receives First time handshake request when, application layer protocol type is identified according to the feature database, and according to the identified application layer The allocation of packets network line that protocol type sends client.
Optionally, in above-mentioned agreement shunt method, the router adds the data packet that the client is sent special Sign, obtains characteristic packet, comprising:
The router adds network layer feature and/or transport layer characteristics to the data packet that the client is sent, and obtains Network layer feature and/or transport layer characteristics data packet.
Optionally, in above-mentioned agreement shunt method, feature extraction is carried out to the characteristic packet set, obtains feature Library, comprising:
The network layer feature in the characteristic packet set is extracted, the network layer feature database is formed;
Confidence level calculating is carried out to the network layer feature, obtains sample data;
The sample data is filtered according to the confidence level, data pressure is carried out to the filtered sample data Contracting, obtains transport layer characteristics library.
The present invention also provides a kind of servers, comprising:
Collection modules obtain characteristic packet set for summarizing the whole characteristic packets provided by router;
Extraction module obtains feature database for carrying out feature extraction to the characteristic packet set;
Sending module, for the feature database to be periodically sent in the router, in order to be connect when the router When receiving first time handshake request based on TCP connection, application layer protocol type is identified according to the feature database, and according to having identified The application layer protocol type distribute network line.
Optionally, in above-mentioned server, the extraction module includes:
First unit forms the network layer for extracting the network layer feature in the characteristic packet set Feature database;
Second unit obtains sample data for carrying out confidence level calculating to the network layer feature;
Third unit, for being filtered according to the confidence level to the sample data, to the filtered sample Data carry out data compression, obtain transport layer characteristics library.
The present invention also provides a kind of agreement separate systems, including server as described in any one of the above embodiments.
Optionally, in above-mentioned agreement separate system, further includes:
Router when for receiving the first time handshake request based on TCP connection, identifies application layer according to the feature database Protocol type, and the allocation of packets network line that client is sent according to the identified application layer protocol type.
The present invention by adopting the above technical scheme, has the advantages that in the present solution, server summarizes a large amount of routers offers Characteristic packet set, and to characteristic packet set carry out data processing, obtain the feature database periodically obtained by router. When client or server end initiate the connection request with router, i.e., first when establishing with client based on TCP connection When secondary handshake request, router realizes the identification of the application layer protocol type of data packet according to feature database, without waiting for client Or server end sends data packet to router after establishing TCP connection and then carries out the identification of application layer protocol type, It realizes and quickly timely carries out agreement shunting again, reduce the power consumption that router is generated by data processing, hence it is evident that mention Network speed is risen, network line distribution is balanced, avoids the waste of user bandwidth resource.
Above-mentioned general introduction is merely to illustrate that the purpose of book, it is not intended to be limited in any way.Except foregoing description Schematical aspect, except embodiment and feature, by reference to attached drawing and the following detailed description, the present invention is further Aspect, embodiment and feature, which will be, to be readily apparent that.
Detailed description of the invention
In the accompanying drawings, unless specified otherwise herein, otherwise indicate the same or similar through the identical appended drawing reference of multiple attached drawings Component or element.What these attached drawings were not necessarily to scale.It should be understood that these attached drawings depict only according to the present invention Disclosed some embodiments, and should not serve to limit the scope of the present invention.
Fig. 1 is a kind of agreement shunt method flow diagram provided in an embodiment of the present invention;
Fig. 2 is a kind of server architecture schematic diagram provided in an embodiment of the present invention;
Fig. 3 is a kind of schematic diagram of agreement separate system provided in an embodiment of the present invention.
Specific embodiment
Hereinafter, certain exemplary embodiments are simply just described.As one skilled in the art will recognize that Like that, without departing from the spirit or scope of the present invention, described embodiment can be modified by various different modes. Therefore, attached drawing and description are considered essentially illustrative rather than restrictive.
When the first time carried out when establishing TCP connection between client and router shakes hands, i.e., client sends SYN (SEQ =x) message to router when, agreement shunting have occurred and that, after three-way handshake, agreement shunting can not be carried out again, work as client When sending data to router, router can only carry out data transmission according to the application layer protocol type after having shunted.For example, Router application layer protocol type according to belonging to the data that local specimen discerning client is sent, application layer protocol type are fixed It is constant, after next number is sent to router according to packet, no matter application layer protocol type belonging to this data packet whether with it is silent The application layer protocol type recognized is identical, is identified according to default application layer protocol type.Application layer protocol type is caused to be known It is not inaccurate, and then cause router that can not accurately carry out agreement shunting, there is no according to affiliated for final different data packet Application layer protocol carry out network line distribution, cause user bandwidth resource waste, network line distribution it is unbalanced and The slow problem of network speed.
For timely and accurate progress agreement shunting, speed and accuracy that agreement shunts are improved, the present invention is based on The data of SynProxy are transmitted, and a kind of embodiment is provided, it is therefore an objective to establish TCP connection in client 002 and router 001 For the first time when shaking hands, i.e., when client 002 also to router 001 does not send data packet, the just identification of progress application layer protocol.
A kind of agreement shunt method is present embodiments provided, server is applied to, as shown in FIG. 1, FIG. 1 is the present invention to implement A kind of agreement shunt method flow diagram that example provides, this method comprises:
Step S100: the whole characteristic packets provided by router 001 are provided, characteristic packet set is obtained;
Wherein, in daily data transmission procedure, there is a large amount of data packet by client 002 by 001 turn of router It is sent to server 003, router 001 adds feature, such as network layer feature, transport layer characteristics etc. in data packet, obtains spy Data packet is levied, characteristic packet is forwarded in server 003 by router 001 later, and whole remittances is carried out by server 003 Always.
Step S200: feature extraction is carried out to the characteristic packet set, obtains feature database;
Wherein, server 003 receives the characteristic packet that a large amount of router 001 is sent, to all characteristic packets Carry out statistics and feature extraction carried out according to custom algorithm to form feature database, feature database is divided into network according to characteristic type Layer feature database and transport layer characteristics library.By establishing feature database, in the case where no data passes through router 001, in advance in visitor Application layer protocol type is known according to feature database in advance when family end 002 or 003 end of server initiate the connection request;Due to feature database It constantly updates, router 001 need to periodically obtain the feature database of the offer of server 003, in order to more accurately carry out application layer The identification of protocol type;The foundation of feature database so that the replacement of server 003 will not influence the identification of application layer protocol type, So that even if replacement server 003 after, also can a successful connection;In addition, the foundation of feature database, so that no matter from client 002, which initiates the connection still 003 end of server, initiates the connection, and may be employed the identification of layer protocol type.
Step S300: the feature database is periodically sent in the router 001, in order to work as the router 001 When receiving first time handshake request based on TCP connection, application layer protocol type is identified according to the feature database, and according to having known The allocation of packets network line that other application layer protocol type sends client 002.
Wherein, have between the network layer feature and/or transport layer characteristics and application layer protocol type in feature database corresponding Relationship, therefore, the first time based on TCP connection that router 001 receives the client 002 or the server 003 is sent When handshake request, router 001 is identified in time according to the network layer feature and/or transport layer characteristics of corresponding relationship and acquisition and is answered With layer protocol type, and then to the allocation of packets network line that client 002 is sent.
In the present solution, server 003 summarizes the characteristic packet set that a large amount of routers provide, and to characteristic packet collection It closes and carries out data processing, obtain the feature database periodically obtained by router 001.When client 002 or server 003 initiate with The connection request of router 001, i.e., with client 002 establish based on TCP connection when first time handshake request when, router 001 realizes the identification of the application layer protocol type of data packet according to feature database, without waiting for client 002 or server 003 Data packet is sent after establishing TCP connection to router 001 and then carries out the identification of application layer protocol type, is realized quickly Agreement shunting is timely carried out again, reduces the power consumption that router is generated by data processing, hence it is evident that improves network speed Degree, network line distribution is balanced, avoids the waste of user bandwidth resource.
Further, on the basis of above-mentioned agreement shunt method, summarize the whole characteristic packets provided by router, Before obtaining characteristic packet set, further includes:
The router 001 adds network layer feature to the data packet that the client 002 is sent and/or transport layer is special Sign, obtains network layer feature and/or transport layer characteristics data packet.
Specifically, router 001 receives the mass data packet of the transmission of client 002, network is carried out to mass data packet Layer analysis adds source address, destination address, source port number, destination slogan and the IP protocol type network of such as data packet Layer feature, carries out transmission layer analysis, adds such as transport layer protocol type, network flow characteristic sequence transport layer characteristics, obtains spy Levy data packet.It is emphasized that the characteristic packet each with network layer feature and/or transport layer characteristics corresponds to one kind and answers With layer protocol type.
On the basis of the above embodiments, feature extraction is carried out to the characteristic packet set, obtains feature database, wrapped It includes:
Step S221: the network layer feature in the characteristic packet set is extracted, the network layer feature is formed Library.
Wherein, net is formed by the network layer feature for being identified as certain application traffic by router 001 that routing end is submitted Network layers feature database, network layer feature include gwid routing label, addr IP address, port port numbers, proto protocol-identifier, Priority priority, appid application numbers and stamp timestamp, gwid are submitted in a manner of filename, other to pass through text The mode of part content is submitted.With filename 20170501-000123_dpi_1_ee534f694c2438b390cdadb80 B53e432_28.2_iYNkaL.gzw is sample, and ee534f694c2438b390cdadb80b53e432 is gwid routing label, File content is as shown in the table:
Addr Port proto priority appid stamp
20.141.226.101 8102 6 100 6015724 1485874399
151.44.221.27 80 6 200 6015724 1485874399
225.194.147.119 8000 17 100 6015724 1485874399
Step S222: confidence level calculating is carried out to the network layer feature, obtains sample data.
Wherein, by being processed to network layer feature, if erasing time stabs, routing label is added and removal repeats to remember Record, data sample after processing: ee534f694c2438b390cdadb80b53e43220.141.226.101 8,102 6 100 6015724.It is divided into three kinds of data: 17dpi data, i.e. the unique data that obtains after above-mentioned processing of network layer characteristic, It is also sample initial data;14dpi data remove the data of routing label, such as 20.141.226.101 8,102 6 100 6015724;Tuple group data, i.e. network layer identify application numbers by IP address, port numbers, protocol number trinary data Data, such as 20.141.226.101 8,102 6.
The preferable data of accuracy rate in order to obtain carry out confidence level calculating to above-mentioned network layer feature.It is calculated in confidence level Before, statistics routing number, such as the routing number of statistics submission 14dpi data first, as a result may be 20.141.226.101 8102 6 100 6,015,724 1, wherein last column data 1 is the routing number for submitting current 14dpi data line;Then it is counted According to filtering, in order to improve the accuracy of sample data, need to set sample data certain filter condition, such as minimum preferential Grade, the sample initial data lower than this priority is not used, or at least routes number, lower than the number of the 14dpi of this routing number According to not being used, so far all data are text data, are handled by C, shell, awk completion;Finally confidence level is calculated again, It is designed by algorithmWherein, AiBe application i in some tuple group can Reliability;I ... ..m, using i to using m;J ... ..n, using priority j ... the .. priority n of i;P is numerical priority value;R is road By number;MAX is that (priority X routing number) peak is taken to correspond to tuple as calculation basis using i.The description as described in algorithm: (1) A is appliediThere may be multiple priority in certain tuple group, the corresponding routing number of each priority calculates its product simultaneously Summation;(2) maximum value is taken out as molecule;(3) certain tuple group may be identified as multiple applications, be calculated according to step (1) Each application and value;(4) summation for all applications that certain tuple group identifies is as denominator;(5) molecule and denominator ratio hundred Divide than being to apply confidence level of the i in some tuple group;Load and packet aggregation operation of the above process by mysql It completes.
Step S223: the sample data is filtered according to the confidence level, to the filtered sample data Data compression is carried out, transport layer characteristics library is obtained.
Wherein, specific application is obtained at some after specified conditions filter in whole samples of network layer feature database submission The characteristic of confidence level forms transport layer characteristics library in tuple group.Transport layer characteristics data include: addr IP address, port Port numbers, proto protocol-identifier, priority priority, appid application numbers and percent confidence level, sample such as following table It is shown:
Addr Port proto priority appid percent
344842853 8102 6 100 6015724 90
2536299803 80 6 200 6015724 85
3787625335 8000 17 100 6015724 80
Specifically, to network layer feature database submit whole sample datas process: data filtering, such as according to it is minimum can Reliability is filtered, and the data lower than this confidence level are not used;Data compression, data are by protobuf data compression Reason, ultimately generates binary file.
Further, in order to improve the accuracy of the characteristic in transport layer data library, transport layer data library is according to net Combination of the network layers database by way of following one or several kinds is extended processing.At times, according to stamp field to certain Period data is analyzed and processed;Provinces or municipalities, according to IP address and information bank to the Data Analysis Services of specific provinces and cities;Divide and answers With can be analyzed and processed to tuple group data according to application-specific data.
Based on above-mentioned agreement shunt method, the embodiment of the invention also provides a kind of server 003, server 003 with it is upper It is corresponding to state agreement shunt method, as shown in Fig. 2, Fig. 2 is a kind of server architecture schematic diagram provided in an embodiment of the present invention, institute State server 003, comprising:
Collection modules 31 obtain characteristic packet set for summarizing the whole characteristic packets provided by router;
Extraction module 32 obtains feature database for carrying out feature extraction to the characteristic packet set;
Sending module 33, for the feature database to be periodically sent in the router, in order to work as the router When receiving first time handshake request based on TCP connection, application layer protocol type is identified according to the feature database, and according to having known Other application layer protocol type distributes network line.
Further, on the basis of above-mentioned server 003, the extraction module 32 includes:
First unit forms the network layer for extracting the network layer feature in the characteristic packet set Feature database;
Second unit obtains sample data for carrying out confidence level calculating to the network layer feature;Third unit is used In being filtered according to the confidence level to the sample data, data compression is carried out to the filtered sample data, is obtained To transport layer characteristics library.
Based on above-mentioned agreement shunt method, the embodiment of the invention also provides a kind of agreement separate systems, as shown in figure 3, Fig. 3 is a kind of agreement separate system structural schematic diagram provided in an embodiment of the present invention.
Agreement separate system includes the router 001 that client 002, server 003 and any of the above-described embodiment provide. Wherein, the client 002 in agreement separate system is for establishing and the connection of the router 001, and to the router 001 Send data packet;Router 001 is for establishing the data packet progress sent to the client 002 with the connection of client 002 Application-level protocol identification determines the network line of the data packet according to identified application layer protocol, according to the grid line Transmit the other functions and effect that the data packet includes into server 003 and above-described embodiment in road;Server 003 is used In the data packet that receiving router 001 is sent.
Server 003 is used to provide feature database to the router 001, and the feature database is that the server 003 passes through The network layer feature database and/or transport layer that characteristic extracts and processes are carried out to all characteristic packets summarized Feature database.
It should be pointed out that server 003 can be cloud server or local server, in protection scope.
The above description is merely a specific embodiment, but scope of protection of the present invention is not limited thereto, any Those familiar with the art in the technical scope disclosed by the present invention, can readily occur in its various change or replacement, These should be covered by the protection scope of the present invention.Therefore, protection scope of the present invention should be with the guarantor of the claim It protects subject to range.

Claims (7)

1. a kind of agreement shunt method is applied to server characterized by comprising
The whole characteristic packets provided by router are provided, characteristic packet set is obtained;
Feature extraction is carried out to the characteristic packet set, obtains feature database;Network layer feature in the feature database and/or Transport layer characteristics and application layer protocol type have corresponding relationship;
The feature database is periodically sent in the router, in order to receive the based on TCP connection when the router When handshake request, application layer protocol type is identified according to the feature database, and according to the identified application layer protocol The allocation of packets network line that type sends client.
2. agreement shunt method as described in claim 1, which is characterized in that the number that the router sends the client Feature is added according to packet, obtains characteristic packet, comprising:
The router adds network layer feature and/or transport layer characteristics to the data packet that the client is sent, and obtains network Layer feature and/or transport layer characteristics data packet.
3. agreement shunt method as claimed in claim 2, which is characterized in that carry out feature to the characteristic packet set and mention It takes, obtains feature database, comprising:
The network layer feature in the characteristic packet set is extracted, the network layer feature database is formed;
Confidence level calculating is carried out to the network layer feature, obtains sample data;
The sample data is filtered according to the confidence level, data compression is carried out to the filtered sample data, Obtain transport layer characteristics library.
4. a kind of server characterized by comprising
Collection modules obtain characteristic packet set for summarizing the whole characteristic packets provided by router;
Extraction module obtains feature database for carrying out feature extraction to the characteristic packet set;Net in the feature database Network layers feature and/or transport layer characteristics and application layer protocol type have corresponding relationship;
Sending module, for the feature database to be periodically sent in the router, in order to receive base when the router When the first time handshake request of TCP connection, application layer protocol type is identified according to the feature database, and according to identified institute State application layer protocol type distribution network line.
5. server as claimed in claim 4, which is characterized in that the extraction module includes:
First unit forms the network layer feature for extracting the network layer feature in the characteristic packet set Library;
Second unit obtains sample data for carrying out confidence level calculating to the network layer feature;
Third unit, for being filtered according to the confidence level to the sample data, to the filtered sample data Data compression is carried out, transport layer characteristics library is obtained.
6. a kind of agreement separate system, which is characterized in that including server as described in claim 4 or 5.
7. agreement separate system as claimed in claim 6, which is characterized in that further include:
Router when for receiving the first time handshake request based on TCP connection, identifies application layer protocol according to the feature database Type, and the allocation of packets network line that client is sent according to the identified application layer protocol type.
CN201710374366.9A 2017-05-24 2017-05-24 A kind of agreement shunt method, system and server Active CN107087006B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201710374366.9A CN107087006B (en) 2017-05-24 2017-05-24 A kind of agreement shunt method, system and server

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201710374366.9A CN107087006B (en) 2017-05-24 2017-05-24 A kind of agreement shunt method, system and server

Publications (2)

Publication Number Publication Date
CN107087006A CN107087006A (en) 2017-08-22
CN107087006B true CN107087006B (en) 2019-08-16

Family

ID=59607621

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201710374366.9A Active CN107087006B (en) 2017-05-24 2017-05-24 A kind of agreement shunt method, system and server

Country Status (1)

Country Link
CN (1) CN107087006B (en)

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107948061B (en) * 2017-11-23 2021-11-12 成都智蜂网科技有限责任公司 Bridge-based distributable hot standby dual-routing system and control method thereof
CN108400910A (en) * 2018-02-24 2018-08-14 上海康斐信息技术有限公司 A kind of router realizes the method and system of network protocol analysis
CN111224878B (en) * 2019-12-31 2022-05-13 中移(杭州)信息技术有限公司 Route forwarding method and device, electronic equipment and storage medium
CN112636974B (en) * 2020-12-22 2022-08-02 安徽飞凯电子技术有限公司 Communication equipment intelligent supervision system based on big data
CN113645256B (en) * 2021-10-13 2021-12-28 成都数默科技有限公司 Aggregation method without reducing TCP session data value density
CN115913893B (en) * 2022-10-14 2023-12-26 江苏未来网络集团有限公司 Enhanced training method and system for artificial intelligent network management module

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101827083A (en) * 2010-02-09 2010-09-08 蓝盾信息安全技术股份有限公司 Method and system for realizing unified threat management in heterogeneous network
CN102158414A (en) * 2011-04-12 2011-08-17 中兴通讯股份有限公司 Protocol processing method for intermediate device and device thereof
CN102394827A (en) * 2011-11-09 2012-03-28 浙江万里学院 Hierarchical classification method for internet flow
US8275875B2 (en) * 2000-05-12 2012-09-25 Niksun, Inc. Security camera for a network
CN102916896A (en) * 2011-08-01 2013-02-06 赛尔网络有限公司 Method and device for distributing multi-channel port mirroring mixed data stream
CN104734993A (en) * 2013-12-24 2015-06-24 杭州华为数字技术有限公司 Data distribution method and distributor

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8275875B2 (en) * 2000-05-12 2012-09-25 Niksun, Inc. Security camera for a network
CN101827083A (en) * 2010-02-09 2010-09-08 蓝盾信息安全技术股份有限公司 Method and system for realizing unified threat management in heterogeneous network
CN102158414A (en) * 2011-04-12 2011-08-17 中兴通讯股份有限公司 Protocol processing method for intermediate device and device thereof
CN102916896A (en) * 2011-08-01 2013-02-06 赛尔网络有限公司 Method and device for distributing multi-channel port mirroring mixed data stream
CN102394827A (en) * 2011-11-09 2012-03-28 浙江万里学院 Hierarchical classification method for internet flow
CN104734993A (en) * 2013-12-24 2015-06-24 杭州华为数字技术有限公司 Data distribution method and distributor

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
一种基于协议分析技术的混合型入侵检测系统的研究;袁卫华;《中国优秀硕士学位论文全文数据库信息科技辑》;20061130;全文

Also Published As

Publication number Publication date
CN107087006A (en) 2017-08-22

Similar Documents

Publication Publication Date Title
CN107087006B (en) A kind of agreement shunt method, system and server
CN101510841B (en) Method and system for recognizing end-to-end flux
WO2009151739A3 (en) Methods for collecting and analyzing network performance data
CN111930700A (en) Distributed log processing method, server, system and computing equipment
CN109474718B (en) Domain name resolution method and device
CN108809749A (en) It is checked based on sample rate to execute the upper layer of stream
CN106781434A (en) Share-car method and system based on traffic route information
CN111432247B (en) Traffic scheduling method, traffic scheduling device, server and storage medium
CN108270699B (en) Message processing method, shunt switch and aggregation network
CN102056212B (en) Method for detecting internet speed and network side equipment
CN108833281A (en) A kind of message forwarding method and the network equipment
CN102209019B (en) A kind of load-balancing method based on message payload and load-balancing device
CN104092588B (en) A kind of exception flow of network detection method combined based on SNMP with NetFlow
CN111404768A (en) DPI recognition realization method and equipment
CN106209840A (en) A kind of network packet De-weight method and device
CN104916127A (en) Internet of vehicles distributed real-time traffic condition analysis method and system
CN102055620B (en) Method and system for monitoring user experience
CN107508827A (en) A kind of message parsing method and device
CN1853369A (en) Method and apparatus for providing separable billing services
US8224771B2 (en) Resource sharing for document production
CN106612241B (en) Service control method and device
US20050172324A1 (en) Method and system for embedding messages within HTTP
CN113014555A (en) Method and device for determining attack event, electronic equipment and storage medium
CN112866275A (en) Flow sampling method, device and computer readable storage medium
JP2005057755A5 (en)

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant