CN109639592A - A kind of rapid data analysis method and device based on ten thousand megastream amounts - Google Patents

A kind of rapid data analysis method and device based on ten thousand megastream amounts Download PDF

Info

Publication number
CN109639592A
CN109639592A CN201811510530.5A CN201811510530A CN109639592A CN 109639592 A CN109639592 A CN 109639592A CN 201811510530 A CN201811510530 A CN 201811510530A CN 109639592 A CN109639592 A CN 109639592A
Authority
CN
China
Prior art keywords
data
stream
packet
packet capturing
module
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201811510530.5A
Other languages
Chinese (zh)
Other versions
CN109639592B (en
Inventor
段晓飞
吕洋
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Wuhan Austrian Information Technology Co Ltd
Original Assignee
Wuhan Austrian Information Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Wuhan Austrian Information Technology Co Ltd filed Critical Wuhan Austrian Information Technology Co Ltd
Priority to CN201811510530.5A priority Critical patent/CN109639592B/en
Publication of CN109639592A publication Critical patent/CN109639592A/en
Application granted granted Critical
Publication of CN109639592B publication Critical patent/CN109639592B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/24Traffic characterised by specific attributes, e.g. priority or QoS
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/12Avoiding congestion; Recovering from congestion
    • H04L47/125Avoiding congestion; Recovering from congestion by balancing the load, e.g. traffic engineering
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/24Traffic characterised by specific attributes, e.g. priority or QoS
    • H04L47/2441Traffic characterised by specific attributes, e.g. priority or QoS relying on flow classification, e.g. using integrated services [IntServ]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0227Filtering policies
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/22Parsing or analysis of headers

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The present invention relates to a kind of rapid data analysis method and device based on ten thousand megastream amounts, method includes: to import the high-performance data that undertaking range of flow is 0~10000M after the data in the region that will need to audit converge to acquire network interface card;The data in network interface card are acquired to high-performance data by Filter module to be filtered, and filtered data are transferred to cache module;Load balancing is carried out to the data in cache module, data are referred in different stream according to different session attributes;Packet capturing is carried out to data in stream and dissection process, each packet capturing parsing module correspond to the processing of data packet in single stream;Data after parsing are transferred to cluster server to be stored and integrated, and carry out the classification displaying of data on administration interface.The present invention realizes safety auditing system and effectively imports big flow business datum, earlier filtering invalid data and grab according to the attribute balancing flow of session to different stream parallel execution of data packets and the purpose of fast resolving.

Description

A kind of rapid data analysis method and device based on ten thousand megastream amounts
Technical field
The present invention relates to network security audit fields, and in particular to a kind of rapid data analytic method based on ten thousand megastream amounts And device.
Background technique
The practical maximum stream flow that current safety auditing system is capable of handling generally only has 100,000,000, and maximum is no more than gigabit (1G).Security audit can only be carried out for the data service of single object (personal or room), can not solve to be directed to group of objects The security audit demand of (for example cell, school, garden, feature are that data business volume is huge).
Summary of the invention
In order to solve the above technical problems, the present invention provides a kind of rapid data analytic method and dress based on ten thousand megastream amounts It sets, massive dataflow is imported by high-speed interface, capture data are analyzed by rapid data collection and analytic method, are discriminated Not, it and then is supplied to background program and does depth integration and displaying, technical scheme is as follows:
As the first aspect of the present invention, a kind of rapid data analytic method based on ten thousand megastream amounts, the method are provided Include:
High-performance data acquisition network interface card will be imported after the data convergence in the region for needing to audit, the data include a variety of kinds The session attribute of class;
By Filter module according to the good filtering rule of configured in advance to high-performance data acquire network interface card in data into Row filtering, the session attribute that clearance security audit concern needs, and filtered data are transferred to cache module;
Load balancing is carried out to the data in cache module, data are referred to difference according to different session attributes Stream in, realize the balanced of data and shunt;
Packet capturing and dissection process are carried out to data in stream by packet capturing parsing module, each packet capturing parsing module is corresponding The processing of data packet in single stream.
Further, method is stated further include:
Data after parsing are transferred to cluster server to be stored and integrated, and carry out data on administration interface Classification is shown.
Further, described that data progress packet capturing and dissection process in stream are specifically wrapped by packet capturing parsing module It includes:
Packet capturing parsing module receives data from corresponding stream by its matched data receiver API in time;
The data received are subjected to tcp group packet according to the sequence number parameter carried in message, are incorporated to tcp_connect Queue saves;
When receiving end message, then the complete session flow data that sequence, group packet is completed is subjected to dissection process.
Further, the end message is time_out, reset or fin message.
Further, the method also includes:
When a session is not received by end message within a preset time, then it is actively inserted into end message, triggering is current Overtime conversation end is transferred to the movement of next step dissection process.
As another aspect of the present invention, a kind of rapid data resolver based on ten thousand megastream amounts, described device are provided Including network convergence device, high-performance data acquisition network interface card, Filter module, load balancing and multiple stream stream and multiple grab The undertaking range of flow of Packet analyzing module, the high-performance data acquisition network interface card is 0~10000M;
The network convergence device, for importing the data in the region for needing to audit in a mirror-image fashion after convergence It accepts the high-performance data that range of flow is 0~10000M and acquires network interface card, the data include the session attribute of a variety of types;
The Filter module, for acquiring the number in network interface card to high-performance data according to the good filtering rule of configured in advance According to being filtered, clearance security audit pays close attention to the session attribute needed, and filtered data are transferred to cache module;
The load balancing module, in cache module data carry out load balancing, to by data according to different Session attribute is referred in different stream, is realized the balanced of data and is shunted;
The packet capturing parsing module, for carrying out packet capturing and dissection process to data in stream, each packet capturing parses mould Block corresponds to the processing of data packet in single stream.
Further, described device further includes cluster server, and the cluster server is used to receive the data after parsing, Data after parsing are stored and integrated, and carry out the classification displaying of data on administration interface.
Further, the packet capturing parsing module includes packet capturing unit and resolution unit;
The packet capturing unit is used to receive data in time from corresponding stream by its matched data receiver API, The data received are subjected to tcp group packet according to the sequence number parameter carried in message, are incorporated to tcp_connect queue preservation, When receiving end message, then the complete session Stream Data Transmission of sequence, group packet will be completed to resolution unit;
The resolution unit, for carrying out dissection process to the data from packet capturing unit received.
Further, the packet capturing parsing module further includes overtime unit;
The time-out unit is actively inserted into one for being not received by end message within a preset time when a session A end message gives packet capturing unit, triggers current overtime conversation end, is transferred to the movement of next step dissection process.
Beneficial effects of the present invention:
1. the present invention abandons common high speed Internet access card, using high-performance data capture card, region is realized by high-speed interface The docking of massive dataflow business can accept 10000M flow.
2. combining the data classification of security audit concern, filtering rule is added, realizes and intercepts nothing in capture card access level Business datum is imitated, the purpose for useful business datum of only letting pass avoids the unnecessary processing of upper layer software (applications).
3. using and configuring more stream modes, equilibrium assignment data packet to be processed to different stream.Packet capturing parsing Unify program by multi-process mode, each process matches the processing that a stream independently carries out complete session data packet, becomes It is serially parallel, to improve data parsing rate.
4. data packet crawl process flow and resolve packet process flow are organically blended, changing two is one, shape At the program of unification processing.
Detailed description of the invention
Fig. 1 is flow chart of data processing schematic diagram provided in an embodiment of the present invention;
Fig. 2 is the rapid data resolver structural schematic diagram provided in an embodiment of the present invention based on ten thousand megastream amounts.
Specific embodiment
Following will be combined with the drawings in the embodiments of the present invention, and technical solution in the embodiment of the present invention carries out clear, complete Site preparation description, it is clear that described embodiment is only present invention a part, instead of all the embodiments.Based on the present invention In embodiment, all other implementation obtained by those of ordinary skill in the art without making creative efforts Example, shall fall within the protection scope of the present invention.
As shown in Figure 1, as the first aspect of the present invention, providing a kind of rapid data parsing side based on ten thousand megastream amounts Method, which comprises
The data in the region audited will be needed to import in a mirror-image fashion after network convergence device converges and accept flow The high-performance data that range is 0~10000M acquires network interface card, and the data include the session attribute of a variety of types;
By Filter module according to the good filtering rule of configured in advance to high-performance data acquire network interface card in data into Row filtering, the session attribute that clearance security audit concern needs, and filtered data are transferred to cache module;
Load balancing is carried out to the data in cache module, data are referred to difference according to different session attributes Stream in, realize the balanced of data and shunt;
Packet capturing and dissection process are carried out to data in stream by packet capturing parsing module, each packet capturing parsing module is corresponding The processing of data packet in single stream;
Data after parsing are transferred to cluster server to be stored and integrated, and carry out data on administration interface Classification is shown.
In above-described embodiment, the present invention first converges the area data flow for needing to audit by network convergence device, Flow after convergence imports the high speed acquisition mouth of high-performance data acquisition network interface card, the high-performance data acquisition in a mirror-image fashion The range of flow that network interface card is accepted is 0~10000M (10G), in the actual environment, since the data of inflow include a variety of types Session attribute, such as HTTP, HTTPS, mail, multimedia, FTP, UDP, file etc., for security audit, not all class The data of type require to pay close attention to, if the multi-medium data of UDP type is there is no need to pay close attention to, in order to filter unnecessary classification number According to the present invention filtering rule good according to configured in advance by Filter module carries out the filtering of different business classification data, only The useful data type of clearance security audit concern, can also be transferred to data by this measure to avoid invalid classification data Process layer drags slow treatment effeciency to waste unnecessary process resource;Then the data in cache module load Weighing apparatus, data are referred in different stream according to different session attributes, are realized the balanced of business datum and are shunted, after being Continuous parallel, quick processing is prepared.It can be according to the quantity of the stream of configuration, starting pair after packet capturing parsing fusion program starting The packet capturing parsing process answered, each process are responsible for corresponding to the processing of data packet in single stream;Finally by the data after parsing It is transferred to cluster server to be stored and integrated, and carries out the classification displaying of data on administration interface.
The mechanism of the mating processing of multi-process is corresponded to, due to devising more stream so as to realize from serially one by one Handle session data to it is concurrent a batch one batch processing session data transformation, data packet capturing, parsing processing speed obtained pole Big to be promoted, for configuring 5 stream, test data processing speed is promoted to original 4 times.
Preferably, described that data progress packet capturing and dissection process in stream are specifically included by packet capturing parsing module:
Packet capturing parsing module receives data from corresponding stream by its matched data receiver API in time;It will connect The data received carry out tcp group packet according to the sequence number parameter carried in message, are incorporated to tcp_connect queue preservation;When connecing End message is received, then the complete session flow data that sequence, group packet is completed is subjected to dissection process;Data after parsing pass through The mode of socket communication is transmitted to cluster server and is stored, further integrated, and is finally divided on administration interface The displaying of class data is checked convenient for user, concludes and is analyzed.
Wherein, the end message is the end messages such as time_out, reset or fin.
Due to consideration that system operation will appear due to individual sessions do not have for a long time time_out, reset or The end messages such as fin arrive, and the data dissection process movement of next step can not be triggered, to cause EMS memory occupation to rise violently, system Fluctuation of service problem, devises timeout mechanism, and when a session is not received by end message within a preset time, active is inserted Enter an end message as timeout packet, triggers current overtime conversation end, be transferred to the movement of next step dissection process, and then release The memory source not discharged is occupied for a long time before putting, and both ensure that session data can be handled quickly, and had been also ensured system Stable operation.
As shown in Fig. 2, providing a kind of rapid data parsing dress based on ten thousand megastream amounts as another aspect of the present invention It sets, described device includes network convergence device, high-performance data acquisition network interface card, Filter module, load balancing and multiple The undertaking range of flow of stream stream and multiple packet capturing parsing modules, the high-performance data acquisition network interface card is 0~10000M;
The network convergence device, for importing the data in the region for needing to audit in a mirror-image fashion after convergence It accepts the high-performance data that range of flow is 0~10000M and acquires network interface card, the data include the session attribute of a variety of types;
The Filter module, for acquiring the number in network interface card to high-performance data according to the good filtering rule of configured in advance According to being filtered, clearance security audit pays close attention to the session attribute needed, and filtered data are transferred to cache module;
The load balancing module, in cache module data carry out load balancing, to by data according to different Session attribute is referred in different stream, is realized the balanced of data and is shunted;
The packet capturing parsing module, for carrying out packet capturing and dissection process to data in stream, each packet capturing parses mould Block corresponds to the processing of data packet in single stream;
Preferably, described device further includes cluster server, and the cluster server is used to receive the data after parsing, right Data after parsing are stored and are integrated, and the classification displaying of data is carried out on administration interface.
Wherein, the packet capturing parsing module includes packet capturing unit and resolution unit;
The packet capturing unit is used to receive data in time from corresponding stream by its matched data receiver API, The data received are subjected to tcp group packet according to the sequence number parameter carried in message, are incorporated to tcp_connect queue preservation, When receiving end message, then the complete session Stream Data Transmission of sequence, group packet will be completed to resolution unit;
The resolution unit, for carrying out dissection process to the data from packet capturing unit received.
Preferably, the packet capturing parsing module further includes overtime unit;
The time-out unit is actively inserted into one for being not received by end message within a preset time when a session A end message gives packet capturing unit, triggers current overtime conversation end, is transferred to the movement of next step dissection process.
The foregoing is merely presently preferred embodiments of the present invention, is not intended to limit the invention, it is all in spirit of the invention and Within principle, any modification, equivalent replacement, improvement and so on be should all be included in the protection scope of the present invention.

Claims (9)

1. a kind of rapid data analytic method based on ten thousand megastream amounts, which is characterized in that the described method includes:
High-performance data acquisition network interface card will be imported after the data convergence in the region for needing to audit, the data include a variety of types Session attribute;
The data in network interface card are acquired to high-performance data according to the good filtering rule of configured in advance by Filter module to carry out Filter, the session attribute that clearance security audit concern needs, and filtered data are transferred to cache module;
Load balancing is carried out to the data in cache module, it is different to be referred to data according to different session attributes In stream, realizes the balanced of data and shunt;
Packet capturing and dissection process are carried out to data in stream by packet capturing parsing module, each packet capturing parsing module is corresponding single The processing of data packet in stream.
2. the rapid data analytic method according to claim 1 based on ten thousand megastream amounts, which is characterized in that the method is also Include:
Data after parsing are transferred to cluster server to be stored and integrated, and carry out the classification of data on administration interface It shows.
3. the rapid data analytic method according to claim 1 based on ten thousand megastream amounts, which is characterized in that described by grabbing Packet analyzing module carries out packet capturing to data in stream and dissection process specifically includes:
Packet capturing parsing module receives data from corresponding stream by its matched data receiver API in time;
The data received are subjected to tcp group packet according to the sequence number parameter carried in message, are incorporated to tcp_connect queue guarantor It deposits;
When receiving end message, then the complete session flow data that sequence, group packet is completed is subjected to dissection process.
4. the rapid data analytic method according to claim 3 based on ten thousand megastream amounts, which is characterized in that the end report Text is time_out, reset or fin message.
5. the rapid data analytic method according to claim 3 based on ten thousand megastream amounts, which is characterized in that the method is also Include:
When a session is not received by end message within a preset time, then it is actively inserted into end message, triggers current time-out Conversation end is transferred to the movement of next step dissection process.
6. a kind of rapid data resolver based on ten thousand megastream amounts, which is characterized in that described device include network convergence device, High-performance data acquires network interface card, Filter module, load balancing and multiple stream stream and multiple packet capturing parsing modules, the height The undertaking range of flow of performance data collection network interface card is 0~10000M;
The network convergence device, the data in the region for that will need to audit import in a mirror-image fashion after convergence to be accepted The high-performance data that range of flow is 0~10000M acquires network interface card, and the data include the session attribute of a variety of types;
The Filter module, for according to the good filtering rule of configured in advance to high-performance data acquisition network interface card in data into Row filtering, the session attribute that clearance security audit concern needs, and filtered data are transferred to cache module;
The load balancing module, in cache module data carry out load balancing, to by data according to different sessions Attribute is referred in different stream, is realized the balanced of data and is shunted;
The packet capturing parsing module, for carrying out packet capturing and dissection process, each packet capturing parsing module pair to data in stream Answer the processing of data packet in single stream.
7. the rapid data resolver according to claim 6 based on ten thousand megastream amounts, which is characterized in that described device is also Including cluster server, the cluster server be used for receives parsing after data, to the data after parsing carry out storage with it is whole It closes, and carries out the classification displaying of data on administration interface.
8. the rapid data resolver according to claim 6 based on ten thousand megastream amounts, which is characterized in that the packet capturing solution Analysing module includes packet capturing unit and resolution unit;
The packet capturing unit is used to receive data in time from corresponding stream by its matched data receiver API, will connect The data received carry out tcp group packet according to the sequence number parameter that carries in message, are incorporated to tcp_connect queue and save, when connecing End message is received, then the complete session Stream Data Transmission of sequence, group packet will be completed to resolution unit;
The resolution unit, for carrying out dissection process to the data from packet capturing unit received.
9. the rapid data resolver according to claim 6 based on ten thousand megastream amounts, which is characterized in that the packet capturing solution Analysing module further includes overtime unit;
The time-out unit is actively inserted into a knot for being not received by end message within a preset time when a session Beam message gives packet capturing unit, triggers current overtime conversation end, is transferred to the movement of next step dissection process.
CN201811510530.5A 2018-12-11 2018-12-11 Rapid data analysis method and device based on ten-gigabit traffic Active CN109639592B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201811510530.5A CN109639592B (en) 2018-12-11 2018-12-11 Rapid data analysis method and device based on ten-gigabit traffic

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201811510530.5A CN109639592B (en) 2018-12-11 2018-12-11 Rapid data analysis method and device based on ten-gigabit traffic

Publications (2)

Publication Number Publication Date
CN109639592A true CN109639592A (en) 2019-04-16
CN109639592B CN109639592B (en) 2023-01-06

Family

ID=66072824

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201811510530.5A Active CN109639592B (en) 2018-12-11 2018-12-11 Rapid data analysis method and device based on ten-gigabit traffic

Country Status (1)

Country Link
CN (1) CN109639592B (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111614786A (en) * 2020-06-05 2020-09-01 易盼红 System and method for processing data at high speed by remote server based on block chain
CN112508513A (en) * 2020-11-27 2021-03-16 中国大唐集团科学技术研究院有限公司 Network centralized control auditing method and centralized control auditing center for industrial control system of unmanned hydropower station
CN113055493A (en) * 2021-03-26 2021-06-29 广州虎牙科技有限公司 Data packet processing method, device, system, scheduling device and storage medium

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1564547A (en) * 2004-03-25 2005-01-12 上海复旦光华信息科技股份有限公司 High speed filtering and stream dividing method for keeping connection features
CN106161098A (en) * 2016-07-21 2016-11-23 四川无声信息技术有限公司 A kind of network behavior detection method and device
CN106445667A (en) * 2016-09-27 2017-02-22 西安交大捷普网络科技有限公司 Method for improving auditing framework CPU load balancing
CN107592303A (en) * 2017-08-28 2018-01-16 北京明朝万达科技股份有限公司 A kind of high speed mirror is as the extracting method and device of outgoing document in network traffics
CN206962832U (en) * 2017-06-26 2018-02-02 杭州创谐信息技术股份有限公司 Network data auditing system based on FPGA high-performance capture cards
CN107689958A (en) * 2017-09-03 2018-02-13 中国南方电网有限责任公司 A kind of network audit subsystem applied to cloud auditing system

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1564547A (en) * 2004-03-25 2005-01-12 上海复旦光华信息科技股份有限公司 High speed filtering and stream dividing method for keeping connection features
CN106161098A (en) * 2016-07-21 2016-11-23 四川无声信息技术有限公司 A kind of network behavior detection method and device
CN106445667A (en) * 2016-09-27 2017-02-22 西安交大捷普网络科技有限公司 Method for improving auditing framework CPU load balancing
CN206962832U (en) * 2017-06-26 2018-02-02 杭州创谐信息技术股份有限公司 Network data auditing system based on FPGA high-performance capture cards
CN107592303A (en) * 2017-08-28 2018-01-16 北京明朝万达科技股份有限公司 A kind of high speed mirror is as the extracting method and device of outgoing document in network traffics
CN107689958A (en) * 2017-09-03 2018-02-13 中国南方电网有限责任公司 A kind of network audit subsystem applied to cloud auditing system

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111614786A (en) * 2020-06-05 2020-09-01 易盼红 System and method for processing data at high speed by remote server based on block chain
CN112508513A (en) * 2020-11-27 2021-03-16 中国大唐集团科学技术研究院有限公司 Network centralized control auditing method and centralized control auditing center for industrial control system of unmanned hydropower station
CN113055493A (en) * 2021-03-26 2021-06-29 广州虎牙科技有限公司 Data packet processing method, device, system, scheduling device and storage medium

Also Published As

Publication number Publication date
CN109639592B (en) 2023-01-06

Similar Documents

Publication Publication Date Title
CN109639592A (en) A kind of rapid data analysis method and device based on ten thousand megastream amounts
US10218598B2 (en) Automatic parsing of binary-based application protocols using network traffic
CN103516710B (en) Session perceives GTPv2 load balances
CN102045363B (en) Establishment, identification control method and device for network flow characteristic identification rule
CN103379002B (en) The adaptive monitoring of telecommunication network
JP3769999B2 (en) Service distribution device
CN105024872B (en) The method and device of applied in network performance test
CN102315974A (en) Stratification characteristic analysis-based method and apparatus thereof for on-line identification for TCP, UDP flows
CN109885684B (en) Cluster-like processing method and device
EP3364601A1 (en) Testing method, device and system
CN111222019B (en) Feature extraction method and device
EP2632083A1 (en) Intelligent and scalable network monitoring using a hierarchy of devices
Wu et al. On the growth of Internet application flows: A complex network perspective
CN107967488A (en) The sorting technique and categorizing system of a kind of server
CN109889558A (en) Data transmission method, middleware and the system of internet of things oriented application
AU2022265712A1 (en) System and method for netflow aggregation of data streams
CN108184008A (en) A kind of terminal Communication Performance Evaluation method and apparatus
Pásztor Accurate active measurement in the Internet and its applications
CN104618878B (en) Short Message Service Gateway
CN111767215A (en) Block chain continuous integration test method, device and system
CN104125105B (en) The method and apparatus classified to the Internet, applications place
CN108259528A (en) A kind of resource caching method and device
CN109040040B (en) Information sending method and device, storage medium and electronic device
CN112929231A (en) Real-time voice recognition service pressure measurement method
CN111506469A (en) Method, system and storage medium for monitoring key area based on communication XDR

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant