CN107787003A - A kind of method and apparatus of flow detection - Google Patents

A kind of method and apparatus of flow detection Download PDF

Info

Publication number
CN107787003A
CN107787003A CN201610712704.0A CN201610712704A CN107787003A CN 107787003 A CN107787003 A CN 107787003A CN 201610712704 A CN201610712704 A CN 201610712704A CN 107787003 A CN107787003 A CN 107787003A
Authority
CN
China
Prior art keywords
address
flow
wechat
api
server
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201610712704.0A
Other languages
Chinese (zh)
Inventor
宋科
李华光
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
ZTE Corp
Original Assignee
ZTE Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by ZTE Corp filed Critical ZTE Corp
Priority to CN201610712704.0A priority Critical patent/CN107787003A/en
Publication of CN107787003A publication Critical patent/CN107787003A/en
Pending legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W24/00Supervisory, monitoring or testing arrangements
    • H04W24/08Testing, supervising or monitoring using real traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/08Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
    • H04L43/0876Network utilisation, e.g. volume of load or congestion level

Abstract

The invention discloses a kind of flow rate testing methods, including:Internet-ip address list is periodically obtained from wechat server according to preset parameter;The IP address of the wechat server is obtained according to the IP address list;The IP address is loaded into deep message detection DPI feature databases and the flow of the wechat server is identified according to the IP address.Know method for distinguishing so as to carry out flow using wechat server IP address is dynamically loaded into DPI feature databases, solve when wechat edition upgrading protocol characteristic changes situation, the renewal of DPI feature databases causes wechat flow to leak the problem of identifying or misidentifying not in time;Also solve due to network environment destabilizing factor, the problem of leading to not identify some imperfect wechat flows.

Description

A kind of method and apparatus of flow detection
Technical field
The present invention relates to the communications field, in particular to a kind of method and apparatus of flow detection.
Background technology
In packet domain mobile communication network, telecom operators generally set in gateway device or independent network traffic analysis Standby middle deployment DPI (Deep Packet Inspection, deep message detection) function, is interconnected using DPI identification of function user The agreement of net flow/service application classification situation, operator are directed to DPI recognition result, can export application class statistics report Table, application layer QoS (Quality of Service, service quality) strategies, application layer blocks or speed limit, application layer content charging Etc. function.
DPI technologies are telecom operators' intelligent pipeline, the important foundation technology of flow operation.It is right in some application scenarios DPI recognition accuracies require high, for example carry out content charging to wechat flow, if DPI identifications are inaccurate, are likely to occur Two kinds of situations:One kind is not identify whole wechat flows, then operator can collect customer charge less, cause business revenue Loss;Another kind is to misidentify other application flow into wechat, then operator can collect customer charge more, may cause to use Family is complained, and causes operator's prestige to decline.
Common DPI technologies, including based on configuration of IP (Internet Protocol, Internet protocol) address or TCP/ UDP (Transmission Control Protocol/User Datagram Protocol, transmission control protocol/user's report Agreement) the shallow-layer detection methods of port numbers, the deep layer detection method based on agreement or key characteristics, the detection side based on single current Method, the Heuristic detection method based on the strong incidence relation of multithread, the Heuristic detection method of weak rigidity relation based on event, base In detection method of net bag statistical nature etc..These detection methods, otherwise renewal be present not in time, may verification and measurement ratio or existing It is unable to reach 100% accurate or situation about may misidentify.
In mobile communication network, instant messaging service platform, if wechat is a kind of very important applied business.For There are very high expectation in the recognition capability of wechat, telecom operators.Existing DPI technologies, the protocol characteristic after wechat edition upgrading When changing, DPI feature databases may update not in time, so as to cause the leakage of wechat flow to identify or misidentify;In addition, may be used Can be because network environment destabilizing factor, wechat can produce some incomplete flows (typically, such as only up TCP SYN Message amount in bag, or a stream is less than the quantity that DPI features place is expected), existing DPI technologies may also None- identified. For these situations, prior art there is no solution.
The content of the invention
The invention provides a kind of flow rate testing methods and device, at least to solve accurately know in existing DPI technologies The problem of other wechat flow.
According to an aspect of the invention, there is provided a kind of flow rate testing methods, including:According to preset parameter from wechat Server periodically obtains internet-ip address list;The IP of the wechat server is obtained according to the IP address list Location;The IP address is loaded into deep message detection DPI feature databases and the wechat server is identified according to the IP address Flow.
According to an aspect of the present invention, a kind of flow detector is additionally provided, including:
First acquisition module, for periodically obtaining internet-ip address row from wechat server according to preset parameter Table;
Second acquisition module, for according to the IP address list, obtaining the IP address of the wechat server;
DPI functional modules, for the IP address to be loaded into DPI feature databases and identified according to the IP address described micro- The flow of telecommunications services device.
Beneficial effect:Using wechat server IP address is dynamically loaded into DPI feature databases so as to carry out flow identification Method, solve when wechat edition upgrading protocol characteristic changes situation, the renewal of DPI feature databases causes wechat flow not in time The problem of leakage identification or misrecognition;Also solve due to network environment destabilizing factor, lead to not identify that some are imperfect micro- The problem of letter flow amount.
Brief description of the drawings
Accompanying drawing described herein is used for providing a further understanding of the present invention, forms the part of the application, this hair Bright schematic description and description is used to explain the present invention, does not form inappropriate limitation of the present invention.In the accompanying drawings:
Fig. 1 is a kind of flow rate testing methods flow chart according to embodiments of the present invention;
Fig. 2 is a kind of flow rate testing methods signaling interaction diagram according to embodiments of the present invention;
Fig. 3 is a kind of flow detector block diagram according to embodiments of the present invention;
Fig. 4 is a kind of flow detection device block diagram according to embodiments of the present invention.
Embodiment
It should be noted that in the case where not conflicting, the feature in embodiment and embodiment in the application can phase Mutually combination.Describe the present invention in detail below with reference to the accompanying drawings and in conjunction with the embodiments.It should be strongly noted that hereinafter to carry To " first, second " do not form limitation to the embodiment of the present invention, it is only for difference is convenient and uses.
The embodiments of the invention provide a kind of flow rate testing methods, Fig. 1 is a kind of flow inspection according to embodiments of the present invention Survey method, as shown in figure 1, including the steps:
S102. internet-ip address list is periodically obtained from wechat server according to preset parameter;
S104. the IP address of the wechat server is obtained according to the IP address list;
S106. the IP address is loaded into deep message detection DPI feature databases and according to IP address identification The flow of wechat server.
Wherein, optionally, S102 includes, and the API for obtaining access token is used for according to the preset parametric configuration (Application Programming Interface, application programming interface) network address and for obtaining IP address list API network address;According to the API websites periodicity timing acquisition internet-ip address list.
The preset parameter, including application unique mark, using key, API, API network address template, fixed Shi Shichang.
S106 is specifically included when the IP address matches with from the destination address of user-to-network directional flow, then will described in IP packet labelings corresponding to flow are wechat;Or when the IP address and from network to the source address of user's directional flow Match somebody with somebody, be then wechat by IP packet labelings corresponding to the flow.
Wechat server IP address is dynamically loaded into DPI feature databases so as to carry out flow knowledge method for distinguishing using above-mentioned, Solve when wechat edition upgrading protocol characteristic changes situation, the renewal of DPI feature databases causes the leakage of wechat flow to know not in time The problem of not or misidentifying;Also solve due to network environment destabilizing factor, lead to not identify some imperfect wechat streams The problem of amount.
In order that technical scheme and implementation method are clearer, below in conjunction with preferred embodiment in fact Existing process is described in detail.
As shown in Fig. 2 the implementation to technical scheme is described in further detail below in conjunction with the accompanying drawings:
As shown in Fig. 2 a kind of flow rate testing methods step is provided in one embodiment of the present of invention, including:
S200. the call parameter of preset flow detection, such as:Wechat public number application unique mark, wechat public number application Key, the API network address templates of access token are obtained for constructing, for the timing length of periodicity timing acquisition access token, The API network address templates of IP address list are obtained for constructing, for the timing length of periodicity timing acquisition IP address list, with And other relevant parameters.
For example wechat public number application unique mark may be shaped like:wx0123456789abcdef.Wechat public number application Key may be shaped like:01234567890abcdef01234567890abcdef.The API network address of access token is obtained for constructing Template may be shaped like:https://api.weixin.qq.com/cgi-bin/tokenGrant_type=client_ Credential&appid=<Using unique mark>&secret=<Using key>.Reacquire and visit for periodically timing Ask that the timing length of token may be shaped like:7200 seconds.The API network address template that IP address list is obtained for constructing may be shaped like: https://api.weixin.qq.com/cgi-bin/getcallbackipAccess_token=<Access token>.For Periodically timing reacquire the timing length of IP address list may be shaped like:3600 seconds.
S202. periodically aforementioned configuration parameters are read in timing, by the way that unique mark and application key will be applied to substitute into and obtain The API network address templates of access token, construct the API network address for obtaining access token.
By foregoing citing, after substitution generation obtain the API network address of access token may be shaped like:
https://api.weixin.qq.com/cgi-bin/tokenGrant_type=client_ Credential&appid=wx0123456789abcdef&secret= 01234567890abcdef01234567890abcdef。
Periodically timing initiates HTTP request to the API network address of the acquisition access token of previous constructions generation, so as to obtain Corresponding http response, access token is extracted from the response.
In http response, along with access token, the term of validity duration of the access token is likely present, typically, It is probably 7200 seconds.Preferably, the term of validity duration is extracted, takes a duration for being slightly less than the value, such as 7000 seconds, dynamically more In new system periodicity timing reacquire access token timing length, so as to subsequently can access token fail before and When reacquire.
If effective time in foregoing http response be present, the effective time is preferentially taken.If do not deposited in http response In effective time, then the timing length of aforementioned arrangements is taken.
Periodically aforementioned arrangements are read in timing, and the API nets of IP address list are obtained by the way that newest access token is substituted into Location template, construct the API network address for obtaining IP address list.
After substitution generation obtain the API network address of IP address list may be shaped like:
https://api.weixin.qq.com/cgi-bin/getcallbackipAccess_token=_ Ak5m7......GAKUI, wherein ellipsis represent largely similar character, and typically, access token might have individual word more than 100 Symbol.
The periodically timing API network address for obtaining IP address list successful to previous constructions initiates HTTP request, to obtain Corresponding http response, then extract IP address list from the response.In http response, the IP address list of return may Comprising tens of or up to a hundred or more IP address/IP address network segment record, wherein the IP address network segment may be presented as mask shape Formula or other forms.Typically, may be shaped like:
{"ip_list":[
"101.226.62.77","101.226.62.78","101.226.62.79",
……
"180.163.15.168","180.163.15.169","101.226.103.0\/25",
……
"58.247.206.128\/25","103.7.30.21","103.7.30.64\/26"]}
IP address list includes a large amount of IP address of wechat server.By these IP address or the IP address network segment, dynamic Ground is added in the feature database of DPI functions, and it is come into force.
S204. using the wechat server IP address after renewal, wechat flow is identified:
Based on the DPI methods used by the matching of IP messages, for the flow from user-to-network direction, to its destination address Matched;For, to the flow in user direction, being matched from network to its source address.If with foregoing wechat server IP Address matches, then corresponding IP messages are marked as wechat, then uses or exports for DPI functions.
Based on the DPI methods using TCP/UDP stream matchings, as long as generally first message or preceding several of stream where matching Message, for the flow from user-to-network direction, its destination address is matched;For from network to the stream in user direction Amount, is matched to its source address.If matched with foregoing wechat server IP address, corresponding IP messages are marked as micro- Letter, while TCP/UDP where the IP messages is failed to be sold at auction and is designated as wechat, then use or export for DPI functions.
As shown in figure 3, the embodiments of the invention provide a kind of flow detector, including:
First acquisition module 300, for according to preset parameter from wechat server periodicity timing acquisition internet ip Address list;
Second acquisition module 302, for according to the IP address list, obtaining the IP address of the wechat server;
DPI functional modules 304, for the IP address to be loaded into DPI feature databases and identifies institute according to the IP address State the flow of wechat server.
Optionally, the preset parameter of this programme includes:Wechat public number application unique mark, wechat public number is using close Key, the API network address templates of access token are obtained for constructing, for when periodically timing reacquires the timing of access token It is long, the API network address templates of IP address list are obtained for constructing, the timing of IP address list is reacquired for periodically timing Duration, and other relevant parameters.
Wherein 300 and 302 be specifically used for periodically timing read configuration module parameter, by will apply unique mark and The API network address templates for obtaining access token are substituted into using key, construct the API network address for obtaining access token.
Periodically timing initiates HTTP request to the API network address of the acquisition access token of previous constructions generation, so as to obtain Corresponding http response, access token is extracted from the response.Periodically aforementioned arrangements are read in timing, by by newest access Token substitutes into the API network address templates for obtaining IP address list, constructs the API network address for obtaining IP address list.Periodically timing The API network address for obtaining IP address list successful to previous constructions initiates HTTP request, to obtain corresponding http response, then IP address list is extracted from the response.
Wherein 304 specifically include, for based on using the DPI methods by the matching of IP messages, for from user-to-network side To flow, its destination address is matched;For, to the flow in user direction, being matched from network to its source address. If matched with foregoing wechat server IP address, corresponding IP messages are marked as wechat, then for DPI functions use or Output.
For based on using TCP/UDP stream matching DPI methods, as long as generally matching where stream first message or preceding Several messages, for the flow from user-to-network direction, its destination address is matched;For from network to user direction Flow, its source address is matched.If matched with foregoing wechat server IP address, corresponding IP messages are labeled For wechat, while TCP/UDP where the IP messages is failed to be sold at auction and is designated as wechat, then used or export for DPI functions.
It should be noted that the content described in device embodiment corresponds to above-mentioned embodiment of the method, it is specific real Existing process had carried out detailed description in embodiment of the method, will not be repeated here.
In summary, wechat server IP address is dynamically loaded into DPI feature databases according to the abovementioned embodiments of the present invention Know method for distinguishing so as to carry out flow, solve when wechat edition upgrading protocol characteristic changes situation, the renewal of DPI feature databases The problem of causing wechat flow leakage identification or misrecognition not in time;Also solve due to network environment destabilizing factor, cause nothing Method identifies the problem of some imperfect wechat flows.
The embodiment of the method that the embodiment of the present application is provided can be held in terminal or similar arithmetic unit OK.Exemplified by running on computer terminals, Fig. 4 is the hardware of the terminal of the flow rate testing methods of the embodiment of the present invention Structured flowchart.As shown in figure 4, terminal 40 can include one or more (one is only shown in Fig. 4) processors 402, Memory 404 for data storage.It will appreciated by the skilled person that the structure shown in Fig. 4 is only to illustrate, it is simultaneously The structure of above-mentioned electronic installation is not caused to limit.For example, terminal 40 may also include than shown in Fig. 4 more or more Few component, or there is the configuration different from shown in Fig. 4.
Memory 404 can be used for the software program and module of storage application software, such as the flow in the embodiment of the present invention Programmed instruction/module corresponding to detection method, processor 402 by operation be stored in software program in memory 404 and Module, so as to perform various function application and data processing, that is, realize above-mentioned method.Memory 104 may include at a high speed with Machine memory, may also include nonvolatile memory, as one or more magnetic storage device, flash memory or other it is non-easily The property lost solid-state memory.
Obviously, those skilled in the art should be understood that above-mentioned each module of the invention or each step can be with general Computing device realize that they can be concentrated on single computing device, or be distributed in multiple computing devices and formed Network on, alternatively, they can be realized with the program code that computing device can perform, it is thus possible to they are stored Performed in storage medium by computing device, either they are fabricated to respectively each integrated circuit modules or by they In multiple modules or step be fabricated to single integrated circuit module to realize.So, the present invention is not restricted to any specific Hardware and software combines.
The preferred embodiments of the present invention are the foregoing is only, are not intended to limit the invention, for the skill of this area For art personnel, the present invention can have various modifications and variations.Within the spirit and principles of the invention, that is made any repaiies Change, equivalent substitution, improvement etc., should be included in the scope of the protection.

Claims (8)

  1. A kind of 1. flow rate testing methods, it is characterised in that including:
    Internet-ip address list is periodically obtained from wechat server according to preset parameter;
    The IP address of the wechat server is obtained according to the IP address list;
    The IP address is loaded into deep message detection DPI feature databases and the wechat server is identified according to the IP address Flow.
  2. 2. flow rate testing methods according to claim 1, it is characterised in that it is described according to preset parameter from wechat service Device, which periodically obtains internet-ip address list, to be included,
    It is used to obtain the application programming interface API network address of access token and for obtaining according to the preset parametric configuration The API network address of IP address list;
    Internet-ip address list is periodically obtained according to the API network address.
  3. 3. flow rate testing methods according to claim 1 or 2, it is characterised in that the preset parameter includes application only One identifies, using key, API, API network address template, timing length.
  4. 4. flow rate testing methods according to claim 1, it is characterised in that described described micro- according to IP address identification The flow of telecommunications services device includes:
    When the IP address matches with from terminal to the destination address of server directional flow, then IP corresponding to the flow is reported Text marks;Or
    When the IP address and from server to the source address matches of terminal directional flow, then by IP messages corresponding to the flow Labeled as wechat.
  5. A kind of 5. flow detector, it is characterised in that including:
    First acquisition module, for periodically obtaining internet-ip address list from wechat server according to preset parameter;
    Second acquisition module, for according to the IP address list, obtaining the IP address of the wechat server;
    DPI functional modules, for the IP address to be loaded into DPI feature databases and identifies that the wechat takes according to the IP address The flow of business device.
  6. 6. device according to claim 5, it is characterised in that first acquisition module is additionally operable to,
    The API network address for obtaining access token and the API for obtaining IP address list are used for according to the preset parametric configuration Network address;According to the API network address periodicity timing acquisition internet-ip address list.
  7. 7. the device according to claim 5 or 6, it is characterised in that the preset parameter, including application unique mark, Using key, API API network address template, timing length.
  8. 8. device according to claim 5, it is characterised in that the identification module is additionally operable to:
    When the IP address matches with from terminal to the destination address of server directional flow, then IP corresponding to the flow is reported Text marks;Or
    When the IP address and from server to the source address matches of terminal directional flow, then by IP messages corresponding to the flow Labeled as wechat.
CN201610712704.0A 2016-08-24 2016-08-24 A kind of method and apparatus of flow detection Pending CN107787003A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201610712704.0A CN107787003A (en) 2016-08-24 2016-08-24 A kind of method and apparatus of flow detection

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201610712704.0A CN107787003A (en) 2016-08-24 2016-08-24 A kind of method and apparatus of flow detection

Publications (1)

Publication Number Publication Date
CN107787003A true CN107787003A (en) 2018-03-09

Family

ID=61388144

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201610712704.0A Pending CN107787003A (en) 2016-08-24 2016-08-24 A kind of method and apparatus of flow detection

Country Status (1)

Country Link
CN (1) CN107787003A (en)

Citations (25)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070001723A1 (en) * 2005-07-01 2007-01-04 Via Technologies, Inc. Clock and data recovery circuit and method thereof
CN101184000A (en) * 2007-12-14 2008-05-21 北京交通大学 Packet sampling and application signature based internet application flux identifying method
CN101202652A (en) * 2006-12-15 2008-06-18 北京大学 Device for classifying and recognizing network application flow quantity and method thereof
CN101321097A (en) * 2008-05-27 2008-12-10 南京邮电大学 Tencent network living broadcast business recognition method based on payload depth detection
CN101442541A (en) * 2008-12-30 2009-05-27 北京畅讯信通科技有限公司 Method for recognizing P2P application encipher flux
EP2092765A2 (en) * 2006-12-07 2009-08-26 Starent Networks Corporation Providing interaction management for communication networks
WO2009107117A2 (en) * 2008-02-28 2009-09-03 Alcatel Lucent Compressed ip flow recognition for in-line integrated mobile dpi
CN101540772A (en) * 2009-04-15 2009-09-23 成都市华为赛门铁克科技有限公司 DPI (deep packet inspection) equipment and communication method thereof
CN101668035A (en) * 2009-09-28 2010-03-10 中国人民解放军理工大学指挥自动化学院 Method for recognizing various P2P-TV application video flows in real time
CN102347870A (en) * 2010-07-29 2012-02-08 中国电信股份有限公司 Flow rate security detection method, equipment and system
CN102710504A (en) * 2012-05-16 2012-10-03 华为技术有限公司 Application identification method and application identification device
CN103297270A (en) * 2013-05-24 2013-09-11 华为技术有限公司 Application type recognition method and network equipment
WO2014025225A1 (en) * 2012-08-10 2014-02-13 주식회사 아이디어웨어 Apparatus for detecting application packet data pattern
CN103618792A (en) * 2013-11-29 2014-03-05 华为技术有限公司 Data stream identification method and device
CN103873356A (en) * 2012-12-11 2014-06-18 中国电信股份有限公司 Household gateway based application identification method and system, and household gateway
WO2014093900A1 (en) * 2012-12-13 2014-06-19 Huawei Technologies Co., Ltd. Content based traffic engineering in software defined information centric networks
CN102325061B (en) * 2011-09-16 2014-07-02 北京星网锐捷网络技术有限公司 Network monitoring method, equipment and system
CN104219339A (en) * 2014-09-17 2014-12-17 北京金山安全软件有限公司 Method and device for detecting address resolution protocol attack in local area network
CN104639391A (en) * 2015-01-04 2015-05-20 中国联合网络通信集团有限公司 Method for generating network flow record and corresponding flow detection equipment
CN104796406A (en) * 2015-03-20 2015-07-22 杭州华三通信技术有限公司 Method and device for identifying application
CN105357082A (en) * 2014-12-22 2016-02-24 成都科来软件有限公司 Method and device for identifying network flow
WO2016054179A1 (en) * 2014-09-30 2016-04-07 Convida Wireless, Llc Dynamic policy control
CN105592449A (en) * 2014-10-20 2016-05-18 中国电信股份有限公司 Service identification method and system
CN105790960A (en) * 2014-12-24 2016-07-20 中国电信股份有限公司 Traffic identification method and system and traffic gateway
CN105792265A (en) * 2014-12-23 2016-07-20 中国电信股份有限公司 Malicious traffic detection method and system and monitoring platform

Patent Citations (25)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070001723A1 (en) * 2005-07-01 2007-01-04 Via Technologies, Inc. Clock and data recovery circuit and method thereof
EP2092765A2 (en) * 2006-12-07 2009-08-26 Starent Networks Corporation Providing interaction management for communication networks
CN101202652A (en) * 2006-12-15 2008-06-18 北京大学 Device for classifying and recognizing network application flow quantity and method thereof
CN101184000A (en) * 2007-12-14 2008-05-21 北京交通大学 Packet sampling and application signature based internet application flux identifying method
WO2009107117A2 (en) * 2008-02-28 2009-09-03 Alcatel Lucent Compressed ip flow recognition for in-line integrated mobile dpi
CN101321097A (en) * 2008-05-27 2008-12-10 南京邮电大学 Tencent network living broadcast business recognition method based on payload depth detection
CN101442541A (en) * 2008-12-30 2009-05-27 北京畅讯信通科技有限公司 Method for recognizing P2P application encipher flux
CN101540772A (en) * 2009-04-15 2009-09-23 成都市华为赛门铁克科技有限公司 DPI (deep packet inspection) equipment and communication method thereof
CN101668035A (en) * 2009-09-28 2010-03-10 中国人民解放军理工大学指挥自动化学院 Method for recognizing various P2P-TV application video flows in real time
CN102347870A (en) * 2010-07-29 2012-02-08 中国电信股份有限公司 Flow rate security detection method, equipment and system
CN102325061B (en) * 2011-09-16 2014-07-02 北京星网锐捷网络技术有限公司 Network monitoring method, equipment and system
CN102710504A (en) * 2012-05-16 2012-10-03 华为技术有限公司 Application identification method and application identification device
WO2014025225A1 (en) * 2012-08-10 2014-02-13 주식회사 아이디어웨어 Apparatus for detecting application packet data pattern
CN103873356A (en) * 2012-12-11 2014-06-18 中国电信股份有限公司 Household gateway based application identification method and system, and household gateway
WO2014093900A1 (en) * 2012-12-13 2014-06-19 Huawei Technologies Co., Ltd. Content based traffic engineering in software defined information centric networks
CN103297270A (en) * 2013-05-24 2013-09-11 华为技术有限公司 Application type recognition method and network equipment
CN103618792A (en) * 2013-11-29 2014-03-05 华为技术有限公司 Data stream identification method and device
CN104219339A (en) * 2014-09-17 2014-12-17 北京金山安全软件有限公司 Method and device for detecting address resolution protocol attack in local area network
WO2016054179A1 (en) * 2014-09-30 2016-04-07 Convida Wireless, Llc Dynamic policy control
CN105592449A (en) * 2014-10-20 2016-05-18 中国电信股份有限公司 Service identification method and system
CN105357082A (en) * 2014-12-22 2016-02-24 成都科来软件有限公司 Method and device for identifying network flow
CN105792265A (en) * 2014-12-23 2016-07-20 中国电信股份有限公司 Malicious traffic detection method and system and monitoring platform
CN105790960A (en) * 2014-12-24 2016-07-20 中国电信股份有限公司 Traffic identification method and system and traffic gateway
CN104639391A (en) * 2015-01-04 2015-05-20 中国联合网络通信集团有限公司 Method for generating network flow record and corresponding flow detection equipment
CN104796406A (en) * 2015-03-20 2015-07-22 杭州华三通信技术有限公司 Method and device for identifying application

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
陆晨: "基于流量采集IP定位及查询应用系统的设计与实现", 《中国优秀硕士学位论文库》 *

Similar Documents

Publication Publication Date Title
CN110113345A (en) A method of the assets based on Internet of Things flow are found automatically
CN107547310B (en) User behavior correlation analysis method and system based on bypass audit equipment
CN102958152B (en) Realize WLAN localization method and the location-server of third party location
CN104995891B (en) The method, apparatus and gateway of processing business message
CN110300065B (en) Application flow identification method and system based on software defined network
CN110245273B (en) Method for acquiring APP service feature library and corresponding device
CN101188505B (en) content type recognition method and device
CN103581881B (en) Comprehensive number-obtaining device as well as system and method for obtaining cell phone number of user on network side
CN104113598A (en) Three-layer auditing method for database
CN112580730B (en) Terminal type identification method and device
WO2016119420A1 (en) Method, apparatus and communication gateway for detecting malicious access to network resources
CN104333538B (en) A kind of network equipment access method
US8224933B2 (en) Method and apparatus for case-based service composition
CN109286506B (en) Method, system and device for charging flow
CN113438332B (en) DoH service identification method and device
CN104980409A (en) Internet behavior management method and device
CN107592299B (en) Proxy internet access identification method, computer device and computer readable storage medium
CN110545335A (en) Internet protocol address acquisition method, server and system
CN105744002B (en) A method of realizing the push page to Client Policy
CN109361618B (en) Data flow marking method and device, computer equipment and storage medium
CN102395117B (en) Method and device for identifying content type
CN107787003A (en) A kind of method and apparatus of flow detection
CN105591842A (en) Method and device for obtaining version of mobile terminal operating system
US20230037602A1 (en) Information processing method and apparatus, node device, server and storage medium
CN114629823A (en) Server testing and monitoring method and device, terminal equipment and storage medium

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication
RJ01 Rejection of invention patent application after publication

Application publication date: 20180309