CN109379211A - A kind of method for monitoring network and device, server and storage medium - Google Patents
A kind of method for monitoring network and device, server and storage medium Download PDFInfo
- Publication number
- CN109379211A CN109379211A CN201811054601.5A CN201811054601A CN109379211A CN 109379211 A CN109379211 A CN 109379211A CN 201811054601 A CN201811054601 A CN 201811054601A CN 109379211 A CN109379211 A CN 109379211A
- Authority
- CN
- China
- Prior art keywords
- data information
- application program
- network
- information
- data
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
- H04L41/0631—Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
- H04L41/0681—Configuration of triggering conditions
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
The present embodiments relate to Network Monitoring Technology field, a kind of method for monitoring network and device, server and storage medium are disclosed.The method for monitoring network is applied to server, comprising: obtains the data information of application program;According to the data information of application program, judge whether that network failure occurs;If it is determined that network failure occurs, data information is matched with the fault mode prestored, Trouble Report is determined according to matching result;If it is determined that network failure does not occur, early warning judgement is carried out to data information, early warning is determined according to early warning judging result;Wherein, data information includes: flow information, application program running state information and the application program operation consumption resource information of application program.Enable and carry out accident analysis generation Trouble Report automatically when carrying out network monitoring discovery network failure, does not occur to carry out early warning judgement when network failure, realization checks erroneous ideas at the outset.
Description
Technical field
The present embodiments relate to Network Monitoring Technology field, in particular to a kind of method for monitoring network and device, service
Device and storage medium.
Background technique
With the development of internet, network communication has become indispensable communication mode, facing to huge network
Flow, network acceleration become critical technology in network communication, and the message forwarding service based on high-performance user state is more next
More paid attention to.Therefore the service performance of monitoring server, service quality and network of relation transmission process in network flow
It is particularly important, and the existing network equipment faces so huge network flow, corresponding network service is inevitable, such as
The number and type of network failure, network flow monitoring etc., current network failure are various, need to accomplish to monitor in time network and
It was found that service is abnormal.
At least there are the following problems in the prior art for inventor's discovery: in existing network monitoring, network failure is occurring
Later, network failure cannot be analyzed automatically, increases the later period operation maintenance cost of network monitoring;Existing network is accused
In alert function, because the data of the application program obtained only indicate the operating status of application program or the use stream of application program
Amount cannot monitor out system according to the data information of current application program and run undesirable situation, can not achieve and check erroneous ideas at the outset.
Summary of the invention
Embodiment of the present invention is designed to provide a kind of method for monitoring network and device, server and storage medium,
Enable and finds that carrying out accident analysis when network failure automatically generates Trouble Report, does not occur during carrying out network monitoring
Early warning judgement is able to carry out when network failure, realization checks erroneous ideas at the outset.
In order to solve the above technical problems, embodiments of the present invention provide a kind of method for monitoring network, it is applied to service
Device, comprising:
Obtain the data information of application program;
According to the data information of application program, judge whether that network failure occurs;
If it is determined that network failure occurs, data information is matched with the fault mode prestored, event is determined according to matching result
Barrier report;
If it is determined that network failure does not occur, early warning judgement is carried out to data information, early warning is determined according to early warning judging result
Prompt;
Wherein, data information includes: flow information, application program running state information and the application program fortune of application program
Row consumption resource information.
Embodiments of the present invention additionally provide a kind of network monitoring apparatus, comprising: obtain module, judgment module, failure
Analysis module and warning module;
It obtains module to be used for, obtains the data information of application program;
Judgment module is used for, and according to the data information of application program, judges whether that network failure occurs;
Failure analysis module is used for, however, it is determined that network failure occurs, data information is matched with the fault mode prestored, root
Trouble Report is determined according to matching result;
Warning module is used for, however, it is determined that network failure does not occur, carries out early warning judgement to data information, is judged according to early warning
As a result early warning is determined;
Wherein, data information includes: flow information, application program running state information and the application program fortune of application program
Row consumption resource information.
Embodiments of the present invention additionally provide a kind of server, comprising: at least one processor;And at least one
The memory of a processor communication connection;Wherein, memory is stored with the instruction that can be executed by least one processor, instructs quilt
At least one processor executes, so that at least one processor is able to carry out above-mentioned method for monitoring network.
Embodiments of the present invention additionally provide a kind of computer readable storage medium, are stored with computer program, the meter
Calculation machine program realizes above-mentioned method for monitoring network when being executed by processor.
Embodiment of the present invention includes the application program in the data information of application program in terms of existing technologies
The resource information of flow information, the application program running state information and application program operation consumption, the data of application program
Information is richer to make it possible to be accurately judged to currently whether have generation network failure, further, however, it is determined that network event occurs
Barrier, according to the matching of the data information of application program and fault mode determines Trouble Report, can be realized to fault mode from
Dynamic analysis, however, it is determined that network failure does not occur, early warning judgement is carried out to data information, is capable of determining that the variation of data information can
The influence that can be generated, the system that avoids does not break down but operation maintenance personnel cannot be found in time when network operation situation is bad
Phenomenon avoids the occurrence of system crash so that issuing early warning when Network status is bad, realizes and checks erroneous ideas at the outset, and improves system
Safety.
In addition, obtaining the data information of application program, comprising: obtain the data letter of the application program shown in shared interface
Breath, wherein shared interface is for showing the data information for belonging at least one of a sort application program.
In the embodiment, the data information of same class application program can be got from shared interface, which obtains
It takes mode not limited by network quality, and is capable of the data information of the multiple application programs of quick obtaining, improve data acquisition
Rate, and then improve the message transmission rate of system.
In addition, before obtaining the data information for sharing the application program shown in interface, method for monitoring network further include: be
Application assigned shared drive, and determine the mark of shared drive, mark is used for identification application and application program institute
The type of category;The data information of the application program by network transmission is intercepted and captured, and is stored in the corresponding shared drive of application program;
According to the determining shared drive for belonging to same type of each application program with application program of mark;It will belong to and same type of respectively answer
With the data information transfer in the shared drive of program to same shared interface, and shown.
In the embodiment, setting shared drive directly to read from shared drive when carrying out data information transfer
Data, wherein obtain data from shared drive, compared to the mode that network transmission obtains data, can be avoided data information reading
The problem of taking out existing network congestion, compared to from hard disk reading manner, data transmission efficiency is higher.
In addition, data information is matched with the fault mode prestored, Trouble Report is determined according to matching result, comprising: will
Data information is matched with the data information of the fault mode prestored, exports matching result;Failure is issued according to matching result
Report;It wherein, include matching result in Trouble Report.
In the embodiment, Trouble Report is determined by pattern match, enables the maintenance personnel on backstage according to failure
Report quickly solves the problems, such as network failure, and possible fault type can be determined by Trouble Report, guarantees background maintenance
Personnel can have the solution network failure being directed to.
In addition, carrying out early warning judgement to data information, early warning is determined according to early warning judging result, comprising: extract number
It is believed that the warning information for early warning judgement in breath;Judge whether warning information meets early warning Rule of judgment;If satisfied, determining
Early warning, wherein include the warning information for meeting early warning Rule of judgment in early warning.
In the embodiment, early warning judgement is carried out to data information when network does not break down, it can be according to warning information
The operation conditions of judgement system, issuing warning information can also make background maintenance personnel carry out system dimension according to warning information in time
Shield reduces the probability that network failure occurs for system.
In addition, will acquire generation network failure when corresponding data information and the fault mode prestored data information
It is matched, exports matching result, comprising: the data information in data information and the fault mode prestored is subjected to data
Match, the similarity for determining data information between the fault mode that prestores;Similarity as matching result and is exported.
In addition, the data information in data information and the fault mode prestored is carried out Data Matching, data information is determined
With the similarity between the fault mode that prestores, comprising: by data each in data information respectively and in the fault mode that prestores
Each data carry out Data Matching, determine the corresponding similarity of each data in data information;Calculate data information
In the corresponding similarity of each data sum, using resulting and value as between data information and the fault mode prestored
Similarity.
In the embodiment, when determining generation network failure, it can judge according to the similarity for prestoring fault mode
The possible fault mode of current network failure enables background maintenance personnel to determine network failure type as early as possible, improves
The treatment effeciency of network failure afterwards.
In addition, data information is matched with the fault mode prestored, after determining Trouble Report according to matching result, network
Monitoring method further include: saved data information as a kind of fault mode.
In addition, application program operation consumption resource information includes at least: usage amount, the class of network flow of network flow
One in the occupancy of type, the occupancy of central processor CPU and memory.
Detailed description of the invention
One or more embodiments are illustrated by the picture in corresponding attached drawing, these exemplary theorys
The bright restriction not constituted to embodiment, the element in attached drawing with same reference numbers label are expressed as similar element, remove
Non- to have special statement, composition does not limit the figure in attached drawing.
Fig. 1 is the flow chart of method for monitoring network in first embodiment of the invention;
Fig. 2 is the flow chart of method for monitoring network in second embodiment of the invention;
Fig. 3 is the client/server clastotype structure chart that interface is shared in second embodiment of the invention;
Fig. 4 is the structure chart of network monitoring apparatus in third embodiment of the invention;
Fig. 5 is the structure chart of network monitoring apparatus in four embodiment of the invention;
Fig. 6 is the structure chart of server in fifth embodiment of the invention.
Specific embodiment
In order to make the object, technical scheme and advantages of the embodiment of the invention clearer, below in conjunction with attached drawing to the present invention
Each embodiment be explained in detail.However, it will be understood by those skilled in the art that in each embodiment party of the present invention
In formula, in order to make the reader understand this application better, many technical details are proposed.But even if without these technical details
And various changes and modifications based on the following respective embodiments, the application technical solution claimed also may be implemented.
The first embodiment of the present invention is related to a kind of method for monitoring network.Applied to server, detailed process such as Fig. 1 institute
Show, includes the following steps:
Step 101: obtaining the data information of application program.
Wherein, which includes: flow information, application program running state information and the application program of application program
Operation consumption resource information.
Specifically, the data information memory of application program in server, can directly acquire user device transmissions to clothes
The data information of the application program of business device can also obtain the data information of application program by the memory space of reading service device,
Herein with no restrictions.
Preferably, the data of application program can be directly read from shared interface when obtaining the data information of application program
Information, specific implementation are as follows: obtain the data information of the application program shown in shared interface, wherein shared interface is for showing
Belong to it is of a sort at least one application program data information.
It should be noted that shared interface is used to show the data information of a kind of application program, shared interface is directly acquired
In data information can be avoided the influence that data are transmitted in Network Abnormal and network congestion, improve data transmission efficiency,
And the data information of of a sort application program can be got, reduce power consumption of the system from memory read data.
Specifically, application program operation consumption resource information includes at least: the usage amount of network flow, network flow
One in the occupancy of type, the occupancy of central processing unit (Central Processing Unit, CPU) and memory.
Wherein, the data information of application program is applied for judging whether the application program occurs network failure obtaining
When the data information of program, not only needs to obtain the flow information of application program and the running state information of application program, also need
Resource occupation amount when application program operation is obtained, so that when network failure such as periods of network disruption occurs, it can be according to using journey
Resource occupation amount when sort run determine occur network failure the reason of, also improve it is subsequent carry out Analysis of Network Malfunction can
By property.
Step 102: according to the data information of application program, judging whether that network failure occurs;If it is, thening follow the steps
103, otherwise, execute step 104.
Specifically, being wrapped in data information when the data information according to application program judges whether to occur network failure
The data of different dimensions are included, the occupancy of the CPU such as obtained in network failure is expressed as (X1, X2, X3 ...), different dimensions
Indicate the different time, the data of different dimensions are to carry out the data of data information acquisition acquisition, data every preset time
Data volume in information is also referred to as matrix of variables, that is, the data square formed according to the data information that the different time obtains
Battle array can calculate the variable quantity etc. of the data of interval time acquisition according to the data in the matrix of variables.
It wherein, is only to illustrate to be judged whether that network failure occurs according to the data information of application program herein, specifically
The mode that network failure occurs for judgement is not content concerned by this application, herein without concrete restriction and explanation.
Step 103: data information being matched with the fault mode prestored, Trouble Report is determined according to matching result.
Specifically, data information to be carried out to a matched tool with the fault mode prestored after determination is broken down
Body is realized are as follows: is matched data information with the data information of the fault mode prestored, is exported matching result;It is tied according to matching
Fruit issues Trouble Report.It wherein, include matching result in Trouble Report.
Specifically, matched realization process is, it will be in the data information in application program and the fault mode prestored
Data information is matched one by one, carries out the matched specific implementation of network failure are as follows: by data information and the fault mode prestored
In data information carry out Data Matching, the similarity for determining data information between the fault mode that prestores;By the similarity
As matching result and export.
Wherein, the data information in fault mode is matched with the data in the fault mode prestored, is calculated similar
The specific implementation of degree are as follows: data each in data information are subjected to data with each data in the fault mode that prestores respectively
Match, determines the corresponding similarity of each data in data information;The each data calculated in data information respectively correspond to
Similarity sum, using resulting and value as the similarity between data information and the fault mode prestored.
One in the specific implementation, by the data information in data information when network failure occurs and the fault mode prestored
When being matched, the covariance of different data is calculated, by taking the occupancy of CPU as an example, CPU occupancy when network failure occurs
Corresponding matrix of variables are as follows: (X1, X2, X3 ...), in the fault mode prestored, the occupancy of the CPU in fault mode 1 are as follows:
(Y1, Y2, Y3 ...) calculates the corresponding similarity of each data according to formula 1:
Formula one:
Wherein, PXYThe related coefficient of expression variable X and variable Y is also referred to as the similarity of X and Y, and COV (X, Y) indicates X, Y
Covariance, D (X) indicate X variance, D (Y) indicate Y variance, it should be noted that the calculating of covariance and variance with it is known
Calculation method it is identical, herein without repeating.
Acquire the similarities of each data such as, similarity PXY1、PXY2 ... according to the similarity calculation phases of each data
Like the sum of degree Pmax, wherein Pmax=PXY1+PXY2+…….Pmax indicates network failure mode and the fault mode 1 that prestores
Similarity.And so on, the similarity of network failure mode with other fault modes prestored is calculated, and then determine network event
The similarity of barrier mode and each fault mode prestored, and provide Trouble Report.
Network failure occurs it should be noted that determining, it, will be current after carrying out Trouble Match and determining Trouble Report
Fault mode save, when so that network failure occurs again later as carry out Trouble Match foundation.
Step 104: early warning judgement being carried out to data information, early warning is determined according to early warning judging result.
Specifically, network failure does not occur for determination, the one of early warning is issued after carrying out early warning judgement to data information
A specific implementation are as follows: extract the warning information for early warning judgement in data information;Judge whether warning information meets early warning
Rule of judgment;If satisfied, determining early warning.It wherein, include the warning information for meeting early warning Rule of judgment in early warning.Example
Such as, the EMS memory occupation amount in application program operation consumption resource or the usage amount of CPU can reflect the operation conditions of system, then
Can be set in warning information includes EMS memory occupation amount or the usage amount of CPU.It is merely illustrative of herein, in warning information
The particular content for being included is herein with no restrictions.
Wherein it is determined that current Network status is judged by early warning Rule of judgment when network does not break down, for example, setting
It sets the data that early warning Rule of judgment includes: warning information and is greater than or equal to preset numerical value, and/or, the data of warning information become
Change amount is greater than or equal to default variable quantity.Judgement by early warning Rule of judgment to warning data can judge to be likely to occur
System operation problem, e.g., EMS memory occupation amount increase suddenly, and leading to EMS memory occupation amount is more than preset numerical value, then issue early warning and mention
Show.Issue this implementation of early warning, can be realized and check erroneous ideas at the outset, enable background maintenance personnel according to early warning more
The good operation of good maintenance system.
In terms of existing technologies, the flow information in the data information of application program including the application program, this answers
With running state of programs information and the application program operation consumption resource information, the data information of application program it is richer so that
Can be accurately judged to currently whether have generation network failure, further, however, it is determined that network failure occurs, according to application program
Data information and the matching of fault mode determine Trouble Report, can be realized and fault mode is automatically analyzed, however, it is determined that not
Network failure occurs, early warning judgement is carried out to data information, the issuable influence of the variation of data information is capable of determining that, keeps away
Exempted from system do not break down but operation maintenance personnel the phenomenon that cannot finding in time when network operation situation is bad so that in network
Early warning is issued when situation is bad, avoids the occurrence of system crash, realizes and checks erroneous ideas at the outset, and improves the safety of system.
Second embodiment of the present invention is related to a kind of method for monitoring network.Second embodiment is big with first embodiment
It causes identical, is in place of the main distinction: in second embodiment of the invention, specifically illustrating and obtain application from shared interface
Implementation steps before when the data information of program.Detailed process is as shown in Fig. 2, include the following steps, it should be noted that step
Rapid 206 is identical to step 104 as step 102 respectively to step 208, and details are not described herein again.
Step 201: for application assigned shared drive, and determining the mark of shared drive.Wherein, the mark is for marking
Know the type of application program and application program.
Step 202: intercepting and capturing the data information of the application program by network transmission, and it is corresponding total to be stored in application program
Enjoy memory.
Step 203: according to the determining shared drive for belonging to same type of each application program with application program of mark.
Step 204: by the data information transfer in the shared drive for belonging to same type of each application program to altogether
Interface is enjoyed, and is shown.
Step 205: obtaining the data information of the application program shown in shared interface.
It should be noted that particular content and the specific descriptions phase of the step 101 in first embodiment in step 205
Together, details are not described herein again.
Specifically, being one shared drive of each application assigned, and it is identified, wherein each shared drive is only
For storing the data information of corresponding application program, multiple processors can read the data wherein stored from shared drive
Information.Shared drive identifies the type it can be shown that the application program stored in the shared drive, true will pass through mark
The type of application program in the fixed shared drive.
Specifically, ustomer premises access equipment passes the data of corresponding application program in preset time interval in step 202
It is defeated into server, server according to the mark of shared drive by data information memory in corresponding shared drive, so as to it
His processor carries out the reading of data.
Specifically, a shared interface is used to show the information of of a sort application program in step 204, e.g., setting is answered
It is video processing program with program 1, application program 2, then can shows that application program 1 can be used in a shared interface
Application program 2 is shown, in addition, the display main program at shared interface also can according to need the data for showing corresponding application program
Information.Further, however, it is determined that network failure occurs, which can also be used to show Trouble Report etc., such as Trouble Report
In fault mode similarity.It is only explanation herein, the data of same type of application program has been got in shared interface
Information, the data information being particularly shown is herein without limitation.
Wherein, when carrying out network monitoring, the data information of application program is directly acquired from shared interface, is avoided from service
Program complexity, power consumption higher problem are executed when obtaining data information in the storage file of device, and once may be used from shared interface
The data information for obtaining same type of multiple application programs improves the efficiency of data transmission.
It should be noted that shared interface is arranged on the basis of client/server separation, specific structure such as Fig. 3 institute
Show, can be used for showing application program 1, application program 2 and application program 3, the data information of each application program in shared interface
It can be obtained from different user equipmenies, can be the acquisition data information from identical user equipment, be also possible to from different
Data information is obtained at user equipment, as application program 1 is obtained from user equipment 1, user equipment 2 and user equipment 3 in Fig. 3
Data information;Data information can also be obtained from user equipment 1 and user equipment 2 in application program 2, in addition it can from user
Equipment N etc. obtains data information;Application program 3 obtains data information from user equipment N and user equipment M etc..Wherein, Fig. 3 is only
It is exemplary illustration, in, shares the data of the application program of interface display and obtain the use of the data information of application program
Family number of devices is with no restrictions.
The step of various methods divide above, be intended merely to describe it is clear, when realization can be merged into a step or
Certain steps are split, multiple steps are decomposed into, as long as including identical logical relation, all in the protection scope of this patent
It is interior;To adding inessential modification in algorithm or in process or introducing inessential design, but its algorithm is not changed
Core design with process is all in the protection scope of the patent.
Third embodiment of the invention is related to a kind of network monitoring apparatus, as shown in Figure 4, comprising: obtains module 401, sentences
Disconnected module 402, failure analysis module 403 and warning module 404.
It obtains module 401 to be used for, obtains the data information of application program.
Judgment module 402 is used for, and according to the data information of application program, judges whether that network failure occurs.
Failure analysis module 403 is used for, however, it is determined that network failure occurs, by data information and the fault mode prestored
Match, Trouble Report is determined according to matching result.
Warning module 404 is used for, however, it is determined that network failure does not occur, early warning judgement is carried out to data information, according to early warning
Judging result determines early warning.
Wherein, data information includes: flow information, application program running state information and the application program fortune of application program
Row consumption resource information.
It is not difficult to find that present embodiment is system embodiment corresponding with first embodiment, present embodiment can be with
First embodiment is worked in coordination implementation.The relevant technical details mentioned in first embodiment still have in the present embodiment
Effect, in order to reduce repetition, which is not described herein again.Correspondingly, the relevant technical details mentioned in present embodiment are also applicable in
In first embodiment.
It is noted that each module involved in present embodiment is logic module, and in practical applications, one
A logic unit can be a physical unit, be also possible to a part of a physical unit, can also be with multiple physics lists
The combination of member is realized.In addition, in order to protrude innovative part of the invention, it will not be with solution institute of the present invention in present embodiment
The technical issues of proposition, the less close unit of relationship introduced, but this does not indicate that there is no other single in present embodiment
Member.
Four embodiment of the invention is related to a kind of network monitoring apparatus.4th embodiment and third embodiment are substantially
It is identical, it is in place of the main distinction: in four embodiment of the invention, specifically illustrates and also wrapped in the network monitoring apparatus
Include: distribution module 501, interception module 502, determining module 503 and transmission module 504, specific structure is as shown in Figure 5.
It should be noted that only illustrate increased module in present embodiment, in third embodiment it is stated that module
It repeats no more.
Distribution module 501 is used for, and is application assigned shared drive, and determine the mark of shared drive, mark is used for
Type belonging to identification application and application program;
Interception module 502 is used for, and intercepts and captures the data information of the application program by network transmission, and is stored in application program
Corresponding shared drive;
Determining module 503 is used for, and belongs to the shared of same type of each application program with application program according to mark is determining
Memory;
Transmission module 504 is used for, by the data information transfer in the shared drive for belonging to same type of each application program
To same shared interface, and shown.
Since second embodiment is corresponded to each other with present embodiment, present embodiment can be mutual with second embodiment
Match implementation.The relevant technical details mentioned in second embodiment are still effective in the present embodiment, implement second
The attainable technical effect of institute similarly may be implemented in the present embodiment in mode, no longer superfluous here in order to reduce repetition
It states.Correspondingly, the relevant technical details mentioned in present embodiment are also applicable in second embodiment.
Fifth embodiment of the invention is related to a kind of server, as shown in fig. 6, including at least one processor 601;With
And the memory 602 with the communication connection of at least one processor 601.Wherein, be stored with can be by least one for memory 602
The instruction that device 601 executes is managed, instruction is executed by least one processor 601, so that at least one processor 601 is able to carry out net
Network monitoring method.
In present embodiment, for processor 601 is with central processing unit (Central Processing Unit, CPU),
For memory 602 is with readable and writable memory (Random Access Memory, RAM).Processor 601, memory 602 can be with
It is connected by bus or other modes, in Fig. 6 for being connected by bus.Memory 602 is used as a kind of non-volatile meter
Calculation machine readable storage medium storing program for executing can be used for storing non-volatile software program, non-volatile computer executable program and module,
As realized in the application embodiment, the program of method for monitoring network is stored in memory 602.Processor 601 passes through operation
Storage non-volatile software program, instruction and module in the memory 602, thereby executing equipment various function application with
And data processing, that is, realize above-mentioned method for monitoring network.
Memory 602 may include storing program area and storage data area, wherein storing program area can store operation system
Application program required for system, at least one function;It storage data area can the Save option list etc..In addition, memory can wrap
High-speed random access memory is included, can also include nonvolatile memory, for example, at least disk memory, a flash memories
Part or other non-volatile solid state memory parts.In some embodiments, it includes relative to processor that memory 602 is optional
601 remotely located memories, these remote memories can pass through network connection to external equipment.The example packet of above-mentioned network
Include but be not limited to internet, intranet, local area network, mobile radio communication and combinations thereof.
One or more program module stores in the memory 602, executes when by one or more processor 601
When, execute the method for monitoring network in above-mentioned first or second method implementation.
Method for monitoring network provided by the application embodiment can be performed in the said goods, has the corresponding function of execution method
Can module and beneficial effect, the not technical detail of detailed description in the present embodiment, reference can be made to the application embodiment is mentioned
The method for monitoring network of confession.
Sixth embodiment of the invention is related to a kind of computer readable storage medium, which is computer
Readable storage medium storing program for executing is stored with computer instruction in the computer readable storage medium, which enables a computer to
Execute method for monitoring network involved in the application first or second method implementation.
It will be appreciated by those skilled in the art that implementing the method for the above embodiments is that can pass through
Program is completed to instruct relevant hardware, which is stored in a storage medium, including some instructions are used so that one
A equipment (can be single-chip microcontroller, chip etc.) or processor (processor) execute each embodiment the method for the application
All or part of the steps.And storage medium above-mentioned includes: USB flash disk, mobile hard disk, read-only memory (ROM, Read-Only
Memory), random access memory (RAM, Random Access Memory), magnetic or disk etc. are various can store journey
The medium of sequence code.
It will be understood by those skilled in the art that the respective embodiments described above are to realize specific embodiments of the present invention,
And in practical applications, can to it, various changes can be made in the form and details, without departing from the spirit and scope of the present invention.
Claims (12)
1. a kind of method for monitoring network is applied to server characterized by comprising
Obtain the data information of application program;
According to the data information of the application program, judge whether that network failure occurs;
If it is determined that network failure occurs, the data information is matched with the fault mode prestored, event is determined according to matching result
Barrier report;
If it is determined that network failure does not occur, early warning judgement is carried out to the data information, early warning is determined according to early warning judging result
Prompt;
Wherein, the data information includes: the flow information of the application program, the application program running state information and institute
State application program operation consumption resource information.
2. method for monitoring network according to claim 1, which is characterized in that the data information for obtaining application program,
Include:
Obtain the data information of the application program shown in shared interface, wherein the shared interface belongs to for showing
The data information of at least one of a sort application program.
3. method for monitoring network according to claim 2, which is characterized in that shown in the shared interface of acquisition described
Before the data information of application program, the method for monitoring network further include:
For the application assigned shared drive, and determine the mark of the shared drive, the mark is described for identifying
Type belonging to application program and the application program;
The data information of the application program by network transmission is intercepted and captured, and it is corresponding described total to be stored in the application program
Enjoy memory;
According to the determining shared drive for belonging to same type of each application program with the application program of the mark;
By the data information transfer in the shared drive for belonging to same type of each application program to same shared interface, and
It is shown.
4. method for monitoring network according to claim 1-3, which is characterized in that it is described by the data information with
The fault mode matching prestored, determines Trouble Report according to matching result, comprising:
The data information is matched with the data information of the fault mode prestored, exports matching result;
The Trouble Report is issued according to the matching result;
It wherein, include the matching result in the Trouble Report.
5. method for monitoring network according to claim 1-3, which is characterized in that it is described to the data information into
Row early warning judgement, determines early warning according to early warning judging result, comprising:
Extract the warning information for early warning judgement in the data information;
Judge whether the warning information meets early warning Rule of judgment;
If satisfied, determining early warning, wherein include the early warning for meeting the early warning Rule of judgment in the early warning
Information.
6. method for monitoring network according to claim 4, which is characterized in that described by the generation got the net
The corresponding data information is matched with the data information of the fault mode prestored when network failure, exports matching result, packet
It includes:
Data information in the data information and the fault mode prestored is subjected to Data Matching, determines the data letter
Similarity between breath and the fault mode prestored;
The similarity as matching result and is exported.
7. method for monitoring network according to claim 6, which is characterized in that described to prestore the data information with described
Fault mode in data information carry out Data Matching, determine between the data information and the fault mode prestored
Similarity, comprising:
Data each in the data information are subjected to Data Matching with each data in the fault mode prestored respectively,
Determine the corresponding similarity of each data in the data information;
The sum for calculating the corresponding similarity of each data in the data information regard resulting and value as the data
Similarity between information and the fault mode prestored.
8. method for monitoring network according to claim 4, which is characterized in that described by the data information and the event prestored
Hinder pattern match, after determining Trouble Report according to matching result, the method for monitoring network further include:
It is saved the data information as a kind of fault mode.
9. method for monitoring network according to claim 1-3, which is characterized in that the application program operation consumption
Resource information includes at least: usage amount, the type of network flow, the occupancy of central processor CPU and the storage of network flow
One in the occupancy of device.
10. a kind of network monitoring apparatus characterized by comprising obtain module, judgment module, failure analysis module and early warning
Module;
The acquisition module is used for, and obtains the data information of application program;
The judgment module is used for, and according to the data information of the application program, judges whether that network failure occurs;
The failure analysis module is used for, however, it is determined that network failure occurs, by the data information and the fault mode prestored
Match, Trouble Report is determined according to matching result;
The warning module is used for, however, it is determined that network failure does not occur, early warning judgement is carried out to the data information, according to early warning
Judging result determines early warning;
Wherein, the data information includes: the flow information of the application program, the application program running state information and institute
State application program operation consumption resource information.
11. a kind of server characterized by comprising
At least one processor;And the memory being connect at least one described processor communication;Wherein, the memory
It is stored with the instruction that can be executed by least one described processor, described instruction is executed by least one described processor, so that
At least one described processor is able to carry out the method for monitoring network as described in claim 1-9 is any.
12. a kind of computer readable storage medium, is stored with computer program, wherein the computer program is held by processor
Claim 1-9 described in any item method for monitoring network are realized when row.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201811054601.5A CN109379211B (en) | 2018-09-11 | 2018-09-11 | Network monitoring method and device, server and storage medium |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201811054601.5A CN109379211B (en) | 2018-09-11 | 2018-09-11 | Network monitoring method and device, server and storage medium |
Publications (2)
Publication Number | Publication Date |
---|---|
CN109379211A true CN109379211A (en) | 2019-02-22 |
CN109379211B CN109379211B (en) | 2022-04-01 |
Family
ID=65404965
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201811054601.5A Active CN109379211B (en) | 2018-09-11 | 2018-09-11 | Network monitoring method and device, server and storage medium |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN109379211B (en) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN110262968A (en) * | 2019-06-10 | 2019-09-20 | 天翼电子商务有限公司 | Promote method, system, medium and the electronic equipment of application failure location efficiency |
Citations (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US7051098B2 (en) * | 2000-05-25 | 2006-05-23 | United States Of America As Represented By The Secretary Of The Navy | System for monitoring and reporting performance of hosts and applications and selectively configuring applications in a resource managed system |
CN104917651A (en) * | 2015-06-09 | 2015-09-16 | 北京齐尔布莱特科技有限公司 | Method and device for monitoring network anomalies |
CN105204970A (en) * | 2014-06-30 | 2015-12-30 | 北京金山安全软件有限公司 | Method and device for detecting CPU occupancy rate abnormity of APP and mobile terminal |
CN105548764A (en) * | 2015-12-29 | 2016-05-04 | 山东鲁能软件技术有限公司 | Electric power equipment fault diagnosis method |
CN107018001A (en) * | 2016-01-28 | 2017-08-04 | 中国移动通信集团贵州有限公司 | A kind of application and trouble localization method and device |
CN108462897A (en) * | 2018-02-09 | 2018-08-28 | 北京奇艺世纪科技有限公司 | A kind of method of data capture and device of network failure |
-
2018
- 2018-09-11 CN CN201811054601.5A patent/CN109379211B/en active Active
Patent Citations (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US7051098B2 (en) * | 2000-05-25 | 2006-05-23 | United States Of America As Represented By The Secretary Of The Navy | System for monitoring and reporting performance of hosts and applications and selectively configuring applications in a resource managed system |
CN105204970A (en) * | 2014-06-30 | 2015-12-30 | 北京金山安全软件有限公司 | Method and device for detecting CPU occupancy rate abnormity of APP and mobile terminal |
CN104917651A (en) * | 2015-06-09 | 2015-09-16 | 北京齐尔布莱特科技有限公司 | Method and device for monitoring network anomalies |
CN105548764A (en) * | 2015-12-29 | 2016-05-04 | 山东鲁能软件技术有限公司 | Electric power equipment fault diagnosis method |
CN107018001A (en) * | 2016-01-28 | 2017-08-04 | 中国移动通信集团贵州有限公司 | A kind of application and trouble localization method and device |
CN108462897A (en) * | 2018-02-09 | 2018-08-28 | 北京奇艺世纪科技有限公司 | A kind of method of data capture and device of network failure |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN110262968A (en) * | 2019-06-10 | 2019-09-20 | 天翼电子商务有限公司 | Promote method, system, medium and the electronic equipment of application failure location efficiency |
Also Published As
Publication number | Publication date |
---|---|
CN109379211B (en) | 2022-04-01 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN107135093B (en) | Internet of things intrusion detection method and detection system based on finite automaton | |
Yao et al. | Energy theft detection with energy privacy preservation in the smart grid | |
RU2419986C2 (en) | Combining multiline protocol accesses | |
CN111901327B (en) | Cloud network vulnerability mining method and device, electronic equipment and medium | |
Parthasarathy et al. | Bloom filter based intrusion detection for smart grid SCADA | |
CN111092869A (en) | Security management and control method for terminal access to office network and authentication server | |
CN110347501A (en) | A kind of service testing method, device, storage medium and electronic equipment | |
CN111885050B (en) | Data storage method and device based on block chain network, related equipment and medium | |
CN108846603A (en) | Logistics retroactive method, user equipment, storage medium and device based on block chain | |
CN110048907B (en) | Global flow control method and device in cluster environment | |
JP2012150805A (en) | Systems and methods for detecting fraud associated with systems application processing | |
KR102160950B1 (en) | Data Distribution System and Its Method for Security Vulnerability Inspection | |
CN111464525B (en) | Session identification method, session identification device, session identification control equipment and storage medium | |
CN105791286B (en) | The abnormality detection and processing method of cloud virtual environment | |
CN105279614A (en) | Business auditing system based on process and method thereof | |
CN107040405A (en) | Passive type various dimensions main frame Fingerprint Model construction method and its device under network environment | |
CN111273995A (en) | Safety scheduling method and system for virtual micro-isolation network | |
CN114205816B (en) | Electric power mobile internet of things information security architecture and application method thereof | |
CN109525645A (en) | A kind of method and system for collecting the log of distributed storage cluster | |
CN107566334B (en) | A kind of distribution terminal safety monitoring method and device realized based on agency | |
CN110365673B (en) | Method, server and system for isolating network attack plane | |
CN109379211A (en) | A kind of method for monitoring network and device, server and storage medium | |
CN111970112B (en) | Ether house deployment method and system based on ZYNQ heterogeneous computing platform | |
Wang et al. | Feature selection for precise anomaly detection in substation automation systems | |
CN109831335A (en) | A kind of data monitoring method, monitor terminal, storage medium and data monitoring system |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
GR01 | Patent grant | ||
GR01 | Patent grant |