CN109379211A - A kind of method for monitoring network and device, server and storage medium - Google Patents

A kind of method for monitoring network and device, server and storage medium Download PDF

Info

Publication number
CN109379211A
CN109379211A CN201811054601.5A CN201811054601A CN109379211A CN 109379211 A CN109379211 A CN 109379211A CN 201811054601 A CN201811054601 A CN 201811054601A CN 109379211 A CN109379211 A CN 109379211A
Authority
CN
China
Prior art keywords
data information
application program
network
information
data
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201811054601.5A
Other languages
Chinese (zh)
Other versions
CN109379211B (en
Inventor
王建明
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Wangsu Science and Technology Co Ltd
Original Assignee
Wangsu Science and Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Wangsu Science and Technology Co Ltd filed Critical Wangsu Science and Technology Co Ltd
Priority to CN201811054601.5A priority Critical patent/CN109379211B/en
Publication of CN109379211A publication Critical patent/CN109379211A/en
Application granted granted Critical
Publication of CN109379211B publication Critical patent/CN109379211B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0631Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0681Configuration of triggering conditions

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The present embodiments relate to Network Monitoring Technology field, a kind of method for monitoring network and device, server and storage medium are disclosed.The method for monitoring network is applied to server, comprising: obtains the data information of application program;According to the data information of application program, judge whether that network failure occurs;If it is determined that network failure occurs, data information is matched with the fault mode prestored, Trouble Report is determined according to matching result;If it is determined that network failure does not occur, early warning judgement is carried out to data information, early warning is determined according to early warning judging result;Wherein, data information includes: flow information, application program running state information and the application program operation consumption resource information of application program.Enable and carry out accident analysis generation Trouble Report automatically when carrying out network monitoring discovery network failure, does not occur to carry out early warning judgement when network failure, realization checks erroneous ideas at the outset.

Description

A kind of method for monitoring network and device, server and storage medium
Technical field
The present embodiments relate to Network Monitoring Technology field, in particular to a kind of method for monitoring network and device, service Device and storage medium.
Background technique
With the development of internet, network communication has become indispensable communication mode, facing to huge network Flow, network acceleration become critical technology in network communication, and the message forwarding service based on high-performance user state is more next More paid attention to.Therefore the service performance of monitoring server, service quality and network of relation transmission process in network flow It is particularly important, and the existing network equipment faces so huge network flow, corresponding network service is inevitable, such as The number and type of network failure, network flow monitoring etc., current network failure are various, need to accomplish to monitor in time network and It was found that service is abnormal.
At least there are the following problems in the prior art for inventor's discovery: in existing network monitoring, network failure is occurring Later, network failure cannot be analyzed automatically, increases the later period operation maintenance cost of network monitoring;Existing network is accused In alert function, because the data of the application program obtained only indicate the operating status of application program or the use stream of application program Amount cannot monitor out system according to the data information of current application program and run undesirable situation, can not achieve and check erroneous ideas at the outset.
Summary of the invention
Embodiment of the present invention is designed to provide a kind of method for monitoring network and device, server and storage medium, Enable and finds that carrying out accident analysis when network failure automatically generates Trouble Report, does not occur during carrying out network monitoring Early warning judgement is able to carry out when network failure, realization checks erroneous ideas at the outset.
In order to solve the above technical problems, embodiments of the present invention provide a kind of method for monitoring network, it is applied to service Device, comprising:
Obtain the data information of application program;
According to the data information of application program, judge whether that network failure occurs;
If it is determined that network failure occurs, data information is matched with the fault mode prestored, event is determined according to matching result Barrier report;
If it is determined that network failure does not occur, early warning judgement is carried out to data information, early warning is determined according to early warning judging result Prompt;
Wherein, data information includes: flow information, application program running state information and the application program fortune of application program Row consumption resource information.
Embodiments of the present invention additionally provide a kind of network monitoring apparatus, comprising: obtain module, judgment module, failure Analysis module and warning module;
It obtains module to be used for, obtains the data information of application program;
Judgment module is used for, and according to the data information of application program, judges whether that network failure occurs;
Failure analysis module is used for, however, it is determined that network failure occurs, data information is matched with the fault mode prestored, root Trouble Report is determined according to matching result;
Warning module is used for, however, it is determined that network failure does not occur, carries out early warning judgement to data information, is judged according to early warning As a result early warning is determined;
Wherein, data information includes: flow information, application program running state information and the application program fortune of application program Row consumption resource information.
Embodiments of the present invention additionally provide a kind of server, comprising: at least one processor;And at least one The memory of a processor communication connection;Wherein, memory is stored with the instruction that can be executed by least one processor, instructs quilt At least one processor executes, so that at least one processor is able to carry out above-mentioned method for monitoring network.
Embodiments of the present invention additionally provide a kind of computer readable storage medium, are stored with computer program, the meter Calculation machine program realizes above-mentioned method for monitoring network when being executed by processor.
Embodiment of the present invention includes the application program in the data information of application program in terms of existing technologies The resource information of flow information, the application program running state information and application program operation consumption, the data of application program Information is richer to make it possible to be accurately judged to currently whether have generation network failure, further, however, it is determined that network event occurs Barrier, according to the matching of the data information of application program and fault mode determines Trouble Report, can be realized to fault mode from Dynamic analysis, however, it is determined that network failure does not occur, early warning judgement is carried out to data information, is capable of determining that the variation of data information can The influence that can be generated, the system that avoids does not break down but operation maintenance personnel cannot be found in time when network operation situation is bad Phenomenon avoids the occurrence of system crash so that issuing early warning when Network status is bad, realizes and checks erroneous ideas at the outset, and improves system Safety.
In addition, obtaining the data information of application program, comprising: obtain the data letter of the application program shown in shared interface Breath, wherein shared interface is for showing the data information for belonging at least one of a sort application program.
In the embodiment, the data information of same class application program can be got from shared interface, which obtains It takes mode not limited by network quality, and is capable of the data information of the multiple application programs of quick obtaining, improve data acquisition Rate, and then improve the message transmission rate of system.
In addition, before obtaining the data information for sharing the application program shown in interface, method for monitoring network further include: be Application assigned shared drive, and determine the mark of shared drive, mark is used for identification application and application program institute The type of category;The data information of the application program by network transmission is intercepted and captured, and is stored in the corresponding shared drive of application program; According to the determining shared drive for belonging to same type of each application program with application program of mark;It will belong to and same type of respectively answer With the data information transfer in the shared drive of program to same shared interface, and shown.
In the embodiment, setting shared drive directly to read from shared drive when carrying out data information transfer Data, wherein obtain data from shared drive, compared to the mode that network transmission obtains data, can be avoided data information reading The problem of taking out existing network congestion, compared to from hard disk reading manner, data transmission efficiency is higher.
In addition, data information is matched with the fault mode prestored, Trouble Report is determined according to matching result, comprising: will Data information is matched with the data information of the fault mode prestored, exports matching result;Failure is issued according to matching result Report;It wherein, include matching result in Trouble Report.
In the embodiment, Trouble Report is determined by pattern match, enables the maintenance personnel on backstage according to failure Report quickly solves the problems, such as network failure, and possible fault type can be determined by Trouble Report, guarantees background maintenance Personnel can have the solution network failure being directed to.
In addition, carrying out early warning judgement to data information, early warning is determined according to early warning judging result, comprising: extract number It is believed that the warning information for early warning judgement in breath;Judge whether warning information meets early warning Rule of judgment;If satisfied, determining Early warning, wherein include the warning information for meeting early warning Rule of judgment in early warning.
In the embodiment, early warning judgement is carried out to data information when network does not break down, it can be according to warning information The operation conditions of judgement system, issuing warning information can also make background maintenance personnel carry out system dimension according to warning information in time Shield reduces the probability that network failure occurs for system.
In addition, will acquire generation network failure when corresponding data information and the fault mode prestored data information It is matched, exports matching result, comprising: the data information in data information and the fault mode prestored is subjected to data Match, the similarity for determining data information between the fault mode that prestores;Similarity as matching result and is exported.
In addition, the data information in data information and the fault mode prestored is carried out Data Matching, data information is determined With the similarity between the fault mode that prestores, comprising: by data each in data information respectively and in the fault mode that prestores Each data carry out Data Matching, determine the corresponding similarity of each data in data information;Calculate data information In the corresponding similarity of each data sum, using resulting and value as between data information and the fault mode prestored Similarity.
In the embodiment, when determining generation network failure, it can judge according to the similarity for prestoring fault mode The possible fault mode of current network failure enables background maintenance personnel to determine network failure type as early as possible, improves The treatment effeciency of network failure afterwards.
In addition, data information is matched with the fault mode prestored, after determining Trouble Report according to matching result, network Monitoring method further include: saved data information as a kind of fault mode.
In addition, application program operation consumption resource information includes at least: usage amount, the class of network flow of network flow One in the occupancy of type, the occupancy of central processor CPU and memory.
Detailed description of the invention
One or more embodiments are illustrated by the picture in corresponding attached drawing, these exemplary theorys The bright restriction not constituted to embodiment, the element in attached drawing with same reference numbers label are expressed as similar element, remove Non- to have special statement, composition does not limit the figure in attached drawing.
Fig. 1 is the flow chart of method for monitoring network in first embodiment of the invention;
Fig. 2 is the flow chart of method for monitoring network in second embodiment of the invention;
Fig. 3 is the client/server clastotype structure chart that interface is shared in second embodiment of the invention;
Fig. 4 is the structure chart of network monitoring apparatus in third embodiment of the invention;
Fig. 5 is the structure chart of network monitoring apparatus in four embodiment of the invention;
Fig. 6 is the structure chart of server in fifth embodiment of the invention.
Specific embodiment
In order to make the object, technical scheme and advantages of the embodiment of the invention clearer, below in conjunction with attached drawing to the present invention Each embodiment be explained in detail.However, it will be understood by those skilled in the art that in each embodiment party of the present invention In formula, in order to make the reader understand this application better, many technical details are proposed.But even if without these technical details And various changes and modifications based on the following respective embodiments, the application technical solution claimed also may be implemented.
The first embodiment of the present invention is related to a kind of method for monitoring network.Applied to server, detailed process such as Fig. 1 institute Show, includes the following steps:
Step 101: obtaining the data information of application program.
Wherein, which includes: flow information, application program running state information and the application program of application program Operation consumption resource information.
Specifically, the data information memory of application program in server, can directly acquire user device transmissions to clothes The data information of the application program of business device can also obtain the data information of application program by the memory space of reading service device, Herein with no restrictions.
Preferably, the data of application program can be directly read from shared interface when obtaining the data information of application program Information, specific implementation are as follows: obtain the data information of the application program shown in shared interface, wherein shared interface is for showing Belong to it is of a sort at least one application program data information.
It should be noted that shared interface is used to show the data information of a kind of application program, shared interface is directly acquired In data information can be avoided the influence that data are transmitted in Network Abnormal and network congestion, improve data transmission efficiency, And the data information of of a sort application program can be got, reduce power consumption of the system from memory read data.
Specifically, application program operation consumption resource information includes at least: the usage amount of network flow, network flow One in the occupancy of type, the occupancy of central processing unit (Central Processing Unit, CPU) and memory.
Wherein, the data information of application program is applied for judging whether the application program occurs network failure obtaining When the data information of program, not only needs to obtain the flow information of application program and the running state information of application program, also need Resource occupation amount when application program operation is obtained, so that when network failure such as periods of network disruption occurs, it can be according to using journey Resource occupation amount when sort run determine occur network failure the reason of, also improve it is subsequent carry out Analysis of Network Malfunction can By property.
Step 102: according to the data information of application program, judging whether that network failure occurs;If it is, thening follow the steps 103, otherwise, execute step 104.
Specifically, being wrapped in data information when the data information according to application program judges whether to occur network failure The data of different dimensions are included, the occupancy of the CPU such as obtained in network failure is expressed as (X1, X2, X3 ...), different dimensions Indicate the different time, the data of different dimensions are to carry out the data of data information acquisition acquisition, data every preset time Data volume in information is also referred to as matrix of variables, that is, the data square formed according to the data information that the different time obtains Battle array can calculate the variable quantity etc. of the data of interval time acquisition according to the data in the matrix of variables.
It wherein, is only to illustrate to be judged whether that network failure occurs according to the data information of application program herein, specifically The mode that network failure occurs for judgement is not content concerned by this application, herein without concrete restriction and explanation.
Step 103: data information being matched with the fault mode prestored, Trouble Report is determined according to matching result.
Specifically, data information to be carried out to a matched tool with the fault mode prestored after determination is broken down Body is realized are as follows: is matched data information with the data information of the fault mode prestored, is exported matching result;It is tied according to matching Fruit issues Trouble Report.It wherein, include matching result in Trouble Report.
Specifically, matched realization process is, it will be in the data information in application program and the fault mode prestored Data information is matched one by one, carries out the matched specific implementation of network failure are as follows: by data information and the fault mode prestored In data information carry out Data Matching, the similarity for determining data information between the fault mode that prestores;By the similarity As matching result and export.
Wherein, the data information in fault mode is matched with the data in the fault mode prestored, is calculated similar The specific implementation of degree are as follows: data each in data information are subjected to data with each data in the fault mode that prestores respectively Match, determines the corresponding similarity of each data in data information;The each data calculated in data information respectively correspond to Similarity sum, using resulting and value as the similarity between data information and the fault mode prestored.
One in the specific implementation, by the data information in data information when network failure occurs and the fault mode prestored When being matched, the covariance of different data is calculated, by taking the occupancy of CPU as an example, CPU occupancy when network failure occurs Corresponding matrix of variables are as follows: (X1, X2, X3 ...), in the fault mode prestored, the occupancy of the CPU in fault mode 1 are as follows: (Y1, Y2, Y3 ...) calculates the corresponding similarity of each data according to formula 1:
Formula one:
Wherein, PXYThe related coefficient of expression variable X and variable Y is also referred to as the similarity of X and Y, and COV (X, Y) indicates X, Y Covariance, D (X) indicate X variance, D (Y) indicate Y variance, it should be noted that the calculating of covariance and variance with it is known Calculation method it is identical, herein without repeating.
Acquire the similarities of each data such as, similarity PXY1、PXY2 ... according to the similarity calculation phases of each data Like the sum of degree Pmax, wherein Pmax=PXY1+PXY2+…….Pmax indicates network failure mode and the fault mode 1 that prestores Similarity.And so on, the similarity of network failure mode with other fault modes prestored is calculated, and then determine network event The similarity of barrier mode and each fault mode prestored, and provide Trouble Report.
Network failure occurs it should be noted that determining, it, will be current after carrying out Trouble Match and determining Trouble Report Fault mode save, when so that network failure occurs again later as carry out Trouble Match foundation.
Step 104: early warning judgement being carried out to data information, early warning is determined according to early warning judging result.
Specifically, network failure does not occur for determination, the one of early warning is issued after carrying out early warning judgement to data information A specific implementation are as follows: extract the warning information for early warning judgement in data information;Judge whether warning information meets early warning Rule of judgment;If satisfied, determining early warning.It wherein, include the warning information for meeting early warning Rule of judgment in early warning.Example Such as, the EMS memory occupation amount in application program operation consumption resource or the usage amount of CPU can reflect the operation conditions of system, then Can be set in warning information includes EMS memory occupation amount or the usage amount of CPU.It is merely illustrative of herein, in warning information The particular content for being included is herein with no restrictions.
Wherein it is determined that current Network status is judged by early warning Rule of judgment when network does not break down, for example, setting It sets the data that early warning Rule of judgment includes: warning information and is greater than or equal to preset numerical value, and/or, the data of warning information become Change amount is greater than or equal to default variable quantity.Judgement by early warning Rule of judgment to warning data can judge to be likely to occur System operation problem, e.g., EMS memory occupation amount increase suddenly, and leading to EMS memory occupation amount is more than preset numerical value, then issue early warning and mention Show.Issue this implementation of early warning, can be realized and check erroneous ideas at the outset, enable background maintenance personnel according to early warning more The good operation of good maintenance system.
In terms of existing technologies, the flow information in the data information of application program including the application program, this answers With running state of programs information and the application program operation consumption resource information, the data information of application program it is richer so that Can be accurately judged to currently whether have generation network failure, further, however, it is determined that network failure occurs, according to application program Data information and the matching of fault mode determine Trouble Report, can be realized and fault mode is automatically analyzed, however, it is determined that not Network failure occurs, early warning judgement is carried out to data information, the issuable influence of the variation of data information is capable of determining that, keeps away Exempted from system do not break down but operation maintenance personnel the phenomenon that cannot finding in time when network operation situation is bad so that in network Early warning is issued when situation is bad, avoids the occurrence of system crash, realizes and checks erroneous ideas at the outset, and improves the safety of system.
Second embodiment of the present invention is related to a kind of method for monitoring network.Second embodiment is big with first embodiment It causes identical, is in place of the main distinction: in second embodiment of the invention, specifically illustrating and obtain application from shared interface Implementation steps before when the data information of program.Detailed process is as shown in Fig. 2, include the following steps, it should be noted that step Rapid 206 is identical to step 104 as step 102 respectively to step 208, and details are not described herein again.
Step 201: for application assigned shared drive, and determining the mark of shared drive.Wherein, the mark is for marking Know the type of application program and application program.
Step 202: intercepting and capturing the data information of the application program by network transmission, and it is corresponding total to be stored in application program Enjoy memory.
Step 203: according to the determining shared drive for belonging to same type of each application program with application program of mark.
Step 204: by the data information transfer in the shared drive for belonging to same type of each application program to altogether Interface is enjoyed, and is shown.
Step 205: obtaining the data information of the application program shown in shared interface.
It should be noted that particular content and the specific descriptions phase of the step 101 in first embodiment in step 205 Together, details are not described herein again.
Specifically, being one shared drive of each application assigned, and it is identified, wherein each shared drive is only For storing the data information of corresponding application program, multiple processors can read the data wherein stored from shared drive Information.Shared drive identifies the type it can be shown that the application program stored in the shared drive, true will pass through mark The type of application program in the fixed shared drive.
Specifically, ustomer premises access equipment passes the data of corresponding application program in preset time interval in step 202 It is defeated into server, server according to the mark of shared drive by data information memory in corresponding shared drive, so as to it His processor carries out the reading of data.
Specifically, a shared interface is used to show the information of of a sort application program in step 204, e.g., setting is answered It is video processing program with program 1, application program 2, then can shows that application program 1 can be used in a shared interface Application program 2 is shown, in addition, the display main program at shared interface also can according to need the data for showing corresponding application program Information.Further, however, it is determined that network failure occurs, which can also be used to show Trouble Report etc., such as Trouble Report In fault mode similarity.It is only explanation herein, the data of same type of application program has been got in shared interface Information, the data information being particularly shown is herein without limitation.
Wherein, when carrying out network monitoring, the data information of application program is directly acquired from shared interface, is avoided from service Program complexity, power consumption higher problem are executed when obtaining data information in the storage file of device, and once may be used from shared interface The data information for obtaining same type of multiple application programs improves the efficiency of data transmission.
It should be noted that shared interface is arranged on the basis of client/server separation, specific structure such as Fig. 3 institute Show, can be used for showing application program 1, application program 2 and application program 3, the data information of each application program in shared interface It can be obtained from different user equipmenies, can be the acquisition data information from identical user equipment, be also possible to from different Data information is obtained at user equipment, as application program 1 is obtained from user equipment 1, user equipment 2 and user equipment 3 in Fig. 3 Data information;Data information can also be obtained from user equipment 1 and user equipment 2 in application program 2, in addition it can from user Equipment N etc. obtains data information;Application program 3 obtains data information from user equipment N and user equipment M etc..Wherein, Fig. 3 is only It is exemplary illustration, in, shares the data of the application program of interface display and obtain the use of the data information of application program Family number of devices is with no restrictions.
The step of various methods divide above, be intended merely to describe it is clear, when realization can be merged into a step or Certain steps are split, multiple steps are decomposed into, as long as including identical logical relation, all in the protection scope of this patent It is interior;To adding inessential modification in algorithm or in process or introducing inessential design, but its algorithm is not changed Core design with process is all in the protection scope of the patent.
Third embodiment of the invention is related to a kind of network monitoring apparatus, as shown in Figure 4, comprising: obtains module 401, sentences Disconnected module 402, failure analysis module 403 and warning module 404.
It obtains module 401 to be used for, obtains the data information of application program.
Judgment module 402 is used for, and according to the data information of application program, judges whether that network failure occurs.
Failure analysis module 403 is used for, however, it is determined that network failure occurs, by data information and the fault mode prestored Match, Trouble Report is determined according to matching result.
Warning module 404 is used for, however, it is determined that network failure does not occur, early warning judgement is carried out to data information, according to early warning Judging result determines early warning.
Wherein, data information includes: flow information, application program running state information and the application program fortune of application program Row consumption resource information.
It is not difficult to find that present embodiment is system embodiment corresponding with first embodiment, present embodiment can be with First embodiment is worked in coordination implementation.The relevant technical details mentioned in first embodiment still have in the present embodiment Effect, in order to reduce repetition, which is not described herein again.Correspondingly, the relevant technical details mentioned in present embodiment are also applicable in In first embodiment.
It is noted that each module involved in present embodiment is logic module, and in practical applications, one A logic unit can be a physical unit, be also possible to a part of a physical unit, can also be with multiple physics lists The combination of member is realized.In addition, in order to protrude innovative part of the invention, it will not be with solution institute of the present invention in present embodiment The technical issues of proposition, the less close unit of relationship introduced, but this does not indicate that there is no other single in present embodiment Member.
Four embodiment of the invention is related to a kind of network monitoring apparatus.4th embodiment and third embodiment are substantially It is identical, it is in place of the main distinction: in four embodiment of the invention, specifically illustrates and also wrapped in the network monitoring apparatus Include: distribution module 501, interception module 502, determining module 503 and transmission module 504, specific structure is as shown in Figure 5.
It should be noted that only illustrate increased module in present embodiment, in third embodiment it is stated that module It repeats no more.
Distribution module 501 is used for, and is application assigned shared drive, and determine the mark of shared drive, mark is used for Type belonging to identification application and application program;
Interception module 502 is used for, and intercepts and captures the data information of the application program by network transmission, and is stored in application program Corresponding shared drive;
Determining module 503 is used for, and belongs to the shared of same type of each application program with application program according to mark is determining Memory;
Transmission module 504 is used for, by the data information transfer in the shared drive for belonging to same type of each application program To same shared interface, and shown.
Since second embodiment is corresponded to each other with present embodiment, present embodiment can be mutual with second embodiment Match implementation.The relevant technical details mentioned in second embodiment are still effective in the present embodiment, implement second The attainable technical effect of institute similarly may be implemented in the present embodiment in mode, no longer superfluous here in order to reduce repetition It states.Correspondingly, the relevant technical details mentioned in present embodiment are also applicable in second embodiment.
Fifth embodiment of the invention is related to a kind of server, as shown in fig. 6, including at least one processor 601;With And the memory 602 with the communication connection of at least one processor 601.Wherein, be stored with can be by least one for memory 602 The instruction that device 601 executes is managed, instruction is executed by least one processor 601, so that at least one processor 601 is able to carry out net Network monitoring method.
In present embodiment, for processor 601 is with central processing unit (Central Processing Unit, CPU), For memory 602 is with readable and writable memory (Random Access Memory, RAM).Processor 601, memory 602 can be with It is connected by bus or other modes, in Fig. 6 for being connected by bus.Memory 602 is used as a kind of non-volatile meter Calculation machine readable storage medium storing program for executing can be used for storing non-volatile software program, non-volatile computer executable program and module, As realized in the application embodiment, the program of method for monitoring network is stored in memory 602.Processor 601 passes through operation Storage non-volatile software program, instruction and module in the memory 602, thereby executing equipment various function application with And data processing, that is, realize above-mentioned method for monitoring network.
Memory 602 may include storing program area and storage data area, wherein storing program area can store operation system Application program required for system, at least one function;It storage data area can the Save option list etc..In addition, memory can wrap High-speed random access memory is included, can also include nonvolatile memory, for example, at least disk memory, a flash memories Part or other non-volatile solid state memory parts.In some embodiments, it includes relative to processor that memory 602 is optional 601 remotely located memories, these remote memories can pass through network connection to external equipment.The example packet of above-mentioned network Include but be not limited to internet, intranet, local area network, mobile radio communication and combinations thereof.
One or more program module stores in the memory 602, executes when by one or more processor 601 When, execute the method for monitoring network in above-mentioned first or second method implementation.
Method for monitoring network provided by the application embodiment can be performed in the said goods, has the corresponding function of execution method Can module and beneficial effect, the not technical detail of detailed description in the present embodiment, reference can be made to the application embodiment is mentioned The method for monitoring network of confession.
Sixth embodiment of the invention is related to a kind of computer readable storage medium, which is computer Readable storage medium storing program for executing is stored with computer instruction in the computer readable storage medium, which enables a computer to Execute method for monitoring network involved in the application first or second method implementation.
It will be appreciated by those skilled in the art that implementing the method for the above embodiments is that can pass through Program is completed to instruct relevant hardware, which is stored in a storage medium, including some instructions are used so that one A equipment (can be single-chip microcontroller, chip etc.) or processor (processor) execute each embodiment the method for the application All or part of the steps.And storage medium above-mentioned includes: USB flash disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), magnetic or disk etc. are various can store journey The medium of sequence code.
It will be understood by those skilled in the art that the respective embodiments described above are to realize specific embodiments of the present invention, And in practical applications, can to it, various changes can be made in the form and details, without departing from the spirit and scope of the present invention.

Claims (12)

1. a kind of method for monitoring network is applied to server characterized by comprising
Obtain the data information of application program;
According to the data information of the application program, judge whether that network failure occurs;
If it is determined that network failure occurs, the data information is matched with the fault mode prestored, event is determined according to matching result Barrier report;
If it is determined that network failure does not occur, early warning judgement is carried out to the data information, early warning is determined according to early warning judging result Prompt;
Wherein, the data information includes: the flow information of the application program, the application program running state information and institute State application program operation consumption resource information.
2. method for monitoring network according to claim 1, which is characterized in that the data information for obtaining application program, Include:
Obtain the data information of the application program shown in shared interface, wherein the shared interface belongs to for showing The data information of at least one of a sort application program.
3. method for monitoring network according to claim 2, which is characterized in that shown in the shared interface of acquisition described Before the data information of application program, the method for monitoring network further include:
For the application assigned shared drive, and determine the mark of the shared drive, the mark is described for identifying Type belonging to application program and the application program;
The data information of the application program by network transmission is intercepted and captured, and it is corresponding described total to be stored in the application program Enjoy memory;
According to the determining shared drive for belonging to same type of each application program with the application program of the mark;
By the data information transfer in the shared drive for belonging to same type of each application program to same shared interface, and It is shown.
4. method for monitoring network according to claim 1-3, which is characterized in that it is described by the data information with The fault mode matching prestored, determines Trouble Report according to matching result, comprising:
The data information is matched with the data information of the fault mode prestored, exports matching result;
The Trouble Report is issued according to the matching result;
It wherein, include the matching result in the Trouble Report.
5. method for monitoring network according to claim 1-3, which is characterized in that it is described to the data information into Row early warning judgement, determines early warning according to early warning judging result, comprising:
Extract the warning information for early warning judgement in the data information;
Judge whether the warning information meets early warning Rule of judgment;
If satisfied, determining early warning, wherein include the early warning for meeting the early warning Rule of judgment in the early warning Information.
6. method for monitoring network according to claim 4, which is characterized in that described by the generation got the net The corresponding data information is matched with the data information of the fault mode prestored when network failure, exports matching result, packet It includes:
Data information in the data information and the fault mode prestored is subjected to Data Matching, determines the data letter Similarity between breath and the fault mode prestored;
The similarity as matching result and is exported.
7. method for monitoring network according to claim 6, which is characterized in that described to prestore the data information with described Fault mode in data information carry out Data Matching, determine between the data information and the fault mode prestored Similarity, comprising:
Data each in the data information are subjected to Data Matching with each data in the fault mode prestored respectively, Determine the corresponding similarity of each data in the data information;
The sum for calculating the corresponding similarity of each data in the data information regard resulting and value as the data Similarity between information and the fault mode prestored.
8. method for monitoring network according to claim 4, which is characterized in that described by the data information and the event prestored Hinder pattern match, after determining Trouble Report according to matching result, the method for monitoring network further include:
It is saved the data information as a kind of fault mode.
9. method for monitoring network according to claim 1-3, which is characterized in that the application program operation consumption Resource information includes at least: usage amount, the type of network flow, the occupancy of central processor CPU and the storage of network flow One in the occupancy of device.
10. a kind of network monitoring apparatus characterized by comprising obtain module, judgment module, failure analysis module and early warning Module;
The acquisition module is used for, and obtains the data information of application program;
The judgment module is used for, and according to the data information of the application program, judges whether that network failure occurs;
The failure analysis module is used for, however, it is determined that network failure occurs, by the data information and the fault mode prestored Match, Trouble Report is determined according to matching result;
The warning module is used for, however, it is determined that network failure does not occur, early warning judgement is carried out to the data information, according to early warning Judging result determines early warning;
Wherein, the data information includes: the flow information of the application program, the application program running state information and institute State application program operation consumption resource information.
11. a kind of server characterized by comprising
At least one processor;And the memory being connect at least one described processor communication;Wherein, the memory It is stored with the instruction that can be executed by least one described processor, described instruction is executed by least one described processor, so that At least one described processor is able to carry out the method for monitoring network as described in claim 1-9 is any.
12. a kind of computer readable storage medium, is stored with computer program, wherein the computer program is held by processor Claim 1-9 described in any item method for monitoring network are realized when row.
CN201811054601.5A 2018-09-11 2018-09-11 Network monitoring method and device, server and storage medium Active CN109379211B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201811054601.5A CN109379211B (en) 2018-09-11 2018-09-11 Network monitoring method and device, server and storage medium

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201811054601.5A CN109379211B (en) 2018-09-11 2018-09-11 Network monitoring method and device, server and storage medium

Publications (2)

Publication Number Publication Date
CN109379211A true CN109379211A (en) 2019-02-22
CN109379211B CN109379211B (en) 2022-04-01

Family

ID=65404965

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201811054601.5A Active CN109379211B (en) 2018-09-11 2018-09-11 Network monitoring method and device, server and storage medium

Country Status (1)

Country Link
CN (1) CN109379211B (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110262968A (en) * 2019-06-10 2019-09-20 天翼电子商务有限公司 Promote method, system, medium and the electronic equipment of application failure location efficiency

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7051098B2 (en) * 2000-05-25 2006-05-23 United States Of America As Represented By The Secretary Of The Navy System for monitoring and reporting performance of hosts and applications and selectively configuring applications in a resource managed system
CN104917651A (en) * 2015-06-09 2015-09-16 北京齐尔布莱特科技有限公司 Method and device for monitoring network anomalies
CN105204970A (en) * 2014-06-30 2015-12-30 北京金山安全软件有限公司 Method and device for detecting CPU occupancy rate abnormity of APP and mobile terminal
CN105548764A (en) * 2015-12-29 2016-05-04 山东鲁能软件技术有限公司 Electric power equipment fault diagnosis method
CN107018001A (en) * 2016-01-28 2017-08-04 中国移动通信集团贵州有限公司 A kind of application and trouble localization method and device
CN108462897A (en) * 2018-02-09 2018-08-28 北京奇艺世纪科技有限公司 A kind of method of data capture and device of network failure

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7051098B2 (en) * 2000-05-25 2006-05-23 United States Of America As Represented By The Secretary Of The Navy System for monitoring and reporting performance of hosts and applications and selectively configuring applications in a resource managed system
CN105204970A (en) * 2014-06-30 2015-12-30 北京金山安全软件有限公司 Method and device for detecting CPU occupancy rate abnormity of APP and mobile terminal
CN104917651A (en) * 2015-06-09 2015-09-16 北京齐尔布莱特科技有限公司 Method and device for monitoring network anomalies
CN105548764A (en) * 2015-12-29 2016-05-04 山东鲁能软件技术有限公司 Electric power equipment fault diagnosis method
CN107018001A (en) * 2016-01-28 2017-08-04 中国移动通信集团贵州有限公司 A kind of application and trouble localization method and device
CN108462897A (en) * 2018-02-09 2018-08-28 北京奇艺世纪科技有限公司 A kind of method of data capture and device of network failure

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110262968A (en) * 2019-06-10 2019-09-20 天翼电子商务有限公司 Promote method, system, medium and the electronic equipment of application failure location efficiency

Also Published As

Publication number Publication date
CN109379211B (en) 2022-04-01

Similar Documents

Publication Publication Date Title
CN107135093B (en) Internet of things intrusion detection method and detection system based on finite automaton
Yao et al. Energy theft detection with energy privacy preservation in the smart grid
RU2419986C2 (en) Combining multiline protocol accesses
CN111901327B (en) Cloud network vulnerability mining method and device, electronic equipment and medium
Parthasarathy et al. Bloom filter based intrusion detection for smart grid SCADA
CN111092869A (en) Security management and control method for terminal access to office network and authentication server
CN110347501A (en) A kind of service testing method, device, storage medium and electronic equipment
CN111885050B (en) Data storage method and device based on block chain network, related equipment and medium
CN108846603A (en) Logistics retroactive method, user equipment, storage medium and device based on block chain
CN110048907B (en) Global flow control method and device in cluster environment
JP2012150805A (en) Systems and methods for detecting fraud associated with systems application processing
KR102160950B1 (en) Data Distribution System and Its Method for Security Vulnerability Inspection
CN111464525B (en) Session identification method, session identification device, session identification control equipment and storage medium
CN105791286B (en) The abnormality detection and processing method of cloud virtual environment
CN105279614A (en) Business auditing system based on process and method thereof
CN107040405A (en) Passive type various dimensions main frame Fingerprint Model construction method and its device under network environment
CN111273995A (en) Safety scheduling method and system for virtual micro-isolation network
CN114205816B (en) Electric power mobile internet of things information security architecture and application method thereof
CN109525645A (en) A kind of method and system for collecting the log of distributed storage cluster
CN107566334B (en) A kind of distribution terminal safety monitoring method and device realized based on agency
CN110365673B (en) Method, server and system for isolating network attack plane
CN109379211A (en) A kind of method for monitoring network and device, server and storage medium
CN111970112B (en) Ether house deployment method and system based on ZYNQ heterogeneous computing platform
Wang et al. Feature selection for precise anomaly detection in substation automation systems
CN109831335A (en) A kind of data monitoring method, monitor terminal, storage medium and data monitoring system

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant