CN113542160A - SDN-based method and system for pulling east-west flow in cloud - Google Patents
SDN-based method and system for pulling east-west flow in cloud Download PDFInfo
- Publication number
- CN113542160A CN113542160A CN202110582284.XA CN202110582284A CN113542160A CN 113542160 A CN113542160 A CN 113542160A CN 202110582284 A CN202110582284 A CN 202110582284A CN 113542160 A CN113542160 A CN 113542160A
- Authority
- CN
- China
- Prior art keywords
- flow
- virtual machine
- cloud
- module
- east
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
- 238000000034 method Methods 0.000 title claims abstract description 18
- 230000003993 interaction Effects 0.000 claims description 9
- 238000001914 filtration Methods 0.000 claims description 6
- 230000000007 visual effect Effects 0.000 claims description 4
- 210000001503 joint Anatomy 0.000 claims description 3
- 238000004891 communication Methods 0.000 claims description 2
- 238000013508 migration Methods 0.000 abstract description 5
- 230000005012 migration Effects 0.000 abstract description 5
- 230000010354 integration Effects 0.000 abstract 1
- 238000007726 management method Methods 0.000 description 38
- 230000006870 function Effects 0.000 description 2
- 238000012986 modification Methods 0.000 description 2
- 230000004048 modification Effects 0.000 description 2
- 238000007792 addition Methods 0.000 description 1
- 238000012550 audit Methods 0.000 description 1
- 230000009286 beneficial effect Effects 0.000 description 1
- 238000012217 deletion Methods 0.000 description 1
- 230000037430 deletion Effects 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 238000010586 diagram Methods 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 238000005206 flow analysis Methods 0.000 description 1
- 238000012544 monitoring process Methods 0.000 description 1
- 230000008447 perception Effects 0.000 description 1
- 238000011176 pooling Methods 0.000 description 1
- 239000000523 sample Substances 0.000 description 1
- 230000003068 static effect Effects 0.000 description 1
- 238000006467 substitution reaction Methods 0.000 description 1
- 230000001360 synchronised effect Effects 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L49/00—Packet switching elements
- H04L49/20—Support for services
- H04L49/208—Port mirroring
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/02—Standardisation; Integration
- H04L41/0246—Exchanging or transporting network management information using the Internet; Embedding network management web servers in network elements; Web-services-based protocols
- H04L41/0253—Exchanging or transporting network management information using the Internet; Embedding network management web servers in network elements; Web-services-based protocols using browsers or web-pages for accessing management information
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/08—Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
- H04L43/0876—Network utilisation, e.g. volume of load or congestion level
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/12—Network monitoring probes
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/02—Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/133—Protocols for remote procedure calls [RPC]
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Environmental & Geological Engineering (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
The invention provides an SDN-based method and system for pulling east-west flow in a cloud, which realize integration of flow acquisition and management in the cloud. The system comprises a flow acquisition module, a centralized controller module and a Web management module. The method comprises the steps that a flow acquisition module in the form of a virtual machine is deployed on each host of a cloud platform, a web management module calls a cloud platform open interface to obtain the host and a virtual machine list, the web management module selects a host or a virtual machine needing to be monitored on a page, then the web management module issues a port mirror image strategy to the cloud platform through a rest interface, and the flow of the virtual machine clicked by a user is mirrored to the flow acquisition module deployed in the current host; and collecting and analyzing the flow. According to the invention, the SDN controller is used for managing the acquisition equipment and the cloud platform in a centralized manner, the global view is uniformly scheduled, the migration of the virtual machine is sensed, the east-west flow in the virtual environment can be acquired, the acquisition of unnecessary flow is reduced, and the performance pressure is relieved.
Description
Technical Field
The invention belongs to the technical field of networks, and particularly relates to a cloud east-west flow traction method and system based on an SDN.
Background
Cloud services are occupying a larger and larger area in various industries in China. Since 2017, more than 70% of provinces and cities in China have policies for coming out of the provinces and the cities in sequence, and local enterprises are promoted to be accelerated to go to the cloud. After an enterprise goes to the cloud, the physical machine is not used for deploying services in a large scale, the virtualization technology is mostly used for carrying out uniform pooling management on computing resources, and at the moment, the business interaction east-west flow between different virtual machines of the same physical machine does not pass through a network physical switch any more. The traditional data center has a mature flow collection scheme, but the flow collection realization in the cloud environment faces the following challenges: firstly, as the east-west flow interaction between different virtual machines in the same physical machine does not pass through the physical switch any more, the traditional mode of acquiring the service interaction flow through the mirror image of the physical switch cannot adapt to the flow acquisition between the virtual machines, and the acquisition of the east-west flow in the cloud environment needs to break through the traditional complete bypass non-invasive mirror image mode, so that the acquisition client is deployed on the server. Second, traditional physical traffic collection draws traffic to the collection platform by selective mirroring on the access switch, so its performance is not problematic for a while. However, in a cloud environment, servers are mostly accessed through 10G or 20G high density, and as the switch mirror image can only collect all traffic based on the interface and cannot be filtered, the influence of performance and stability is brought. Thirdly, the static mirror image strategy after the virtual machine migration cannot follow the synchronous migration.
Disclosure of Invention
In view of the above, an object of the present invention is to provide an SDN-based method for pulling east-west traffic in a cloud, which can overcome the problems in the prior art.
One of the purposes of the invention is realized by the following technical scheme:
an SDN-based method for east-west traffic pulling in a cloud, the method comprising the steps of:
step S1: deploying a flow acquisition module in a virtual machine mode, a configuration acquisition network and a management network on each host machine of the cloud platform, deploying a centralized controller module and a web management module, and connecting the management network with the centralized control module in a communication way;
step S2: calling a cloud platform open interface by a web management module to acquire a host machine and a virtual machine list, and displaying in a visual mode; a user selects a host or a virtual machine to be monitored on a page provided by a web management module, then the web management module issues a port mirroring strategy to a cloud platform through a rest interface, and the virtual machine flow clicked by the user is mirrored to a flow acquisition module deployed in the current host;
step S3: and collecting and analyzing the flow.
The web management module has a unique identifier for each host, and when a certain virtual machine is migrated, the cloud platform automatically identifies and copies the original port mirror image strategy to the host, and deletes the original strategy.
Further, in step S4, the web management module stores a unique identifier for each host in the database, and performs query and comparison between the unique identifier of the newly added virtual machine in the host and the unique identifier of the virtual machine already existing in the database; if the matched identifier is not found, judging that the virtual machine is newly added, otherwise, judging that the virtual machine is migrated.
Further, the web management module calls a rest interface of the openanyright software to convert the data into openflow protocol data, and the openflow protocol data is issued to each acquisition device in each acquisition network.
Further, in the VMware-based cloud platform, the mirror image of the virtual machine flow is realized through the self-contained distributed port mirror image of the VMware cloud platform; in the cloud platform based on the OpenStack, the traction of the virtual machine traffic is realized through port mirroring of ovs switches.
Further, in step S2, the policy of port mirroring is: the network card flow of the source virtual machine is copied to a network card of a target virtual machine, the target virtual machine is a flow acquisition module in a virtual machine mode, and the flow of the source virtual machine to be monitored is pulled to the flow acquisition module in a port mirror image mode of a cloud platform.
The second purpose of the invention is realized by the following technical scheme:
an SDN-based in-cloud east-west traffic pulling system, comprising:
the flow acquisition module is deployed on the server in the form of a virtual machine;
the centralized controller module is used for centrally controlling the flow acquisition module through an openflow protocol so as to carry out flow traction, filtering and strategy issuing; and
and the Web management module is in butt joint with the centralized controller module and the cloud platform interface through the rest interface, and provides an operation and display page.
Further, the flow acquisition module is realized by a linux operating system and openvswitch and dpdk software.
Further, the flow acquisition module is packaged into an iso mirror image through a xorriso software linux operating system, openvswitch and dpdk software.
Further, the centralized controller module is realized through openanyright software, the interaction with the web management module is realized through an openanyright software native restful protocol, and the interaction with the traffic collection module is realized through an openflow protocol.
Further, the web management module realizes the acquisition and configuration of data through restful api, and the web management module uses the restful interface of openanyright to realize the issuing of the acquisition policy to the traffic acquisition module and the acquisition of the topology information and the traffic information of the traffic acquisition module.
The invention has the beneficial effects that: the method and the system realize centralized management of the acquisition equipment and the cloud platform through the SDN controller, realize unified strategy issuing, unified acquisition, unified scheduling of global view angles and perception of virtual machine migration; the inside of the server is built in a probe mode through openvswitch, east-west flow in a virtual environment can be collected, and cloud inside-outside virtual integrated collection is achieved; and the traffic is filtered through an openflow protocol, so that the acquisition of unnecessary traffic is reduced, and the performance pressure is relieved.
Additional advantages, objects, and features of the invention will be set forth in part in the description which follows and in part will become apparent to those having ordinary skill in the art upon examination of the following or may be learned from practice of the invention. The objectives and other advantages of the present invention will be realized and attained by the structure particularly pointed out in the written description and claims hereof as well as the appended drawings.
Drawings
In order to make the objects, technical solutions and advantages of the present invention more apparent, the present invention will be further described in detail with reference to the accompanying drawings, in which:
FIG. 1 is a system topology diagram of the present invention.
Detailed Description
Hereinafter, preferred embodiments of the present invention will be described in detail with reference to the accompanying drawings. It should be understood that the preferred embodiments are illustrative of the invention only and are not limiting upon the scope of the invention.
In the description of the present invention, it is to be understood that the terms "longitudinal," "length," "circumferential," "front," "rear," "left," "right," "top," "bottom," "inner," "outer," and the like are used in the orientations and positional relationships indicated in the drawings for the convenience of description and simplicity of description, and do not indicate or imply that the referenced devices or elements must have a particular orientation, be constructed in a particular orientation, and be operated, and thus are not to be construed as limiting the present invention.
In the present invention, unless otherwise expressly stated or limited, the terms "mounted," "connected," "secured," and the like are to be construed broadly and can, for example, be fixedly connected, detachably connected, or integrally formed; can be mechanically connected, electrically connected or can communicate with each other; either directly or indirectly through intervening media, either internally or in any other relationship. The specific meanings of the above terms in the present invention can be understood by those skilled in the art according to specific situations.
Furthermore, the terms "first", "second" and "first" are used for descriptive purposes only and are not to be construed as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of the present invention, "a plurality" means at least two, e.g., two, three, etc., unless specifically limited otherwise.
As shown in the figure, an SDN-based in-cloud east-west traffic pulling system of the present invention includes:
the system comprises a flow acquisition module 1, a flow control module and a flow control module, wherein the flow acquisition module is deployed on a server in a virtual machine mode;
the centralized controller module 2 is used for centrally controlling the flow acquisition module through an openflow protocol so as to carry out flow traction, filtering and strategy issuing; and
and the Web management module 3 is in butt joint with the centralized controller module and the cloud platform interface through a rest interface, and provides an operation and display page.
Deploying a flow acquisition module 1 in a virtual machine form, configuring an acquisition network and a management network on each host of the cloud platform, deploying a centralized controller module 2 and a web management module 3, wherein the management network is accessible to the centralized control module 2 through a network;
the web management module 3 calls a cloud platform open interface to obtain a host machine and a virtual machine list, and the host machine and the virtual machine list are displayed in a visual mode; a user selects a host or a virtual machine to be monitored on a page provided by the web management module 3, and then the web management module 3 issues a port mirroring strategy to the cloud platform through a rest interface, and the virtual machine flow clicked by the user is mirrored to a flow acquisition module deployed in the current host;
specifically, the traffic collection module 1 is composed of a linux operating system, an open-source openvswitch (hereinafter referred to as ovs) and dpdk software, and the whole system and the software can be packaged into an iso image through xorriso software, wherein the image can be directly installed on a server of a cloud platform and is irrelevant to a platform manufacturer and a model.
Cloud platforms on the market today can be roughly divided into two categories: VMware-based architecture and OpenStack-based architecture. In the VMware-based cloud platform, mirroring of virtual machine traffic can be realized through self-contained distributed port mirroring of the VMware cloud platform, and in the OpenStack-based cloud platform, traction of the virtual machine traffic can be realized through port mirroring of the ovs switch.
The strategy of port mirroring is as follows: the flow of the network card of the source virtual machine is copied to the network card of the destination virtual machine, the flow acquisition module 1 is a destination virtual machine, and the flow of the source virtual machine to be monitored is pulled to the virtual machine of the flow acquisition module 1 in a port mirror image mode of different platforms, namely the acquisition of the flow of the virtual machine is completed.
The centralized controller module 2 has a global view, the controller of the centralized controller module is implemented by open-source opendayl light (hereinafter abbreviated as ODL) software, the interaction with the northbound web management module 3 is implemented by an ODL native restful protocol, and the interaction with the southerbound traffic acquisition module 1 is implemented by an openflow protocol.
First, the centralized controller module 2 needs to be accessible to the traffic collection module 1 via a network, and a command is embedded in ovs of the traffic collection module: ovs-vsctl set-controller br0 tcp: x.x.x.x.6633. Wherein, x.x.x is the ip address of controller promptly, can go automatically to connect centralized controller module 2 when flow acquisition module 1 is online like this, and centralized controller module 2 just can manage and control this flow acquisition module 1 through openflow agreement this moment, and its operable function includes: topology discovery, ACL filtering, port flow monitoring, addition, deletion, check and modification of a flow table and the like.
Secondly, the centralized controller module 2 and the web management module 3 are deployed together, the centralized controller module 2 serves as a middle layer, a bottom-layer complex protocol is shielded for upper-layer calling, and the web management module 3 can manage the acquisition module equipment through a standard restful interface to perform visual display.
The web management module 3 is a UI page of the entire system, and requires front-end and back-end programming development. All data acquisition and configuration are realized by calling open restful api, and the front end and the back end are realized by using a main flow framework: vue and java spring boot.
The web management module 3 realizes issuing of an acquisition policy, such as acquiring a specified quintuple message and filtering the message, by calling an ODL restful interface. The web management module acquires collector topology information and flow information by calling an ODL restful interface and displays the collector topology information and the flow information on a page.
The web management module 3 acquires the virtual machine list of each host machine by calling the cloud platform restful open interface, and realizes the port mirror image function by calling the platform API, so that the operation of virtual machine flow mirror image drainage in the whole cloud can be realized only by using the system.
By connecting the cloud platform, the list information of the virtual machines is acquired in real time, whether the virtual machines are migrated or not can be monitored, and if the virtual machines are migrated, the system automatically triggers rule migration (original strategies are copied to the migrated virtual machines, and the original strategies are deleted).
Based on the system, the cloud east-west flow traction method based on the SDN comprises the following steps:
step S1: the method comprises the steps of deploying a flow acquisition module 1 in a virtual machine mode on each host machine of the cloud platform, configuring an acquisition network and a management network, enabling the management network to be accessible to a centralized control module 2 through a network, and then deploying the centralized controller module 2 and a web management module 3.
Step S2, the web management module 3 firstly calls a cloud platform open interface to obtain a host and virtual machine list and visually display the list, a user selects a host or a virtual machine to be monitored through a page, the web management module 3 issues a port mirror image strategy to the cloud platform through a rest interface, the virtual machine flow clicked by the user is mirrored to the flow acquisition module 1 deployed in the current host, and if the corresponding flow acquisition module 1 does not exist, an error is prompted to be reported to the user to install the flow acquisition module 1 on the current host.
The collection policy may be set on the page provided by the web management module 3, such as: collecting a certain quintuple message, only collecting a DNS message and the like, wherein a user can collect flow filtration for each collection device (namely a host machine with a flow collection module 1), a web management module calls a rest interface of an ODL, and the ODL converts the rest data into openflow protocol data and sends the openflow protocol data to the collection device.
The web management module 3 has a unique identifier for each host machine and stores the unique identifier in the database, when a certain virtual machine migrates, the cloud platform automatically identifies and copies the original port mirror image strategy to the host machine and deletes the original strategy.
Step S3: after the flow is collected to the system, the system can be used for analyzing the flow analysis, audit and safety equipment of a user.
Therefore, the system for pulling the flow in the east-west direction of the cloud based on the SDN can integrate flow acquisition and management in the cloud.
Finally, the above embodiments are only intended to illustrate the technical solutions of the present invention and not to limit the present invention, and although the present invention has been described in detail with reference to the preferred embodiments, it will be understood by those skilled in the art that modifications or equivalent substitutions may be made on the technical solutions of the present invention without departing from the spirit and scope of the technical solutions, and all of them should be covered by the claims of the present invention.
Claims (10)
1. An SDN-based method for pulling east-west flow in cloud is characterized in that: the method comprises the following steps:
step S1: deploying a flow acquisition module in a virtual machine mode, a configuration acquisition network and a management network on each host machine of the cloud platform, deploying a centralized controller module and a web management module, and connecting the management network with the centralized control module in a communication way;
step S2: calling a cloud platform open interface by a web management module to acquire a host machine and a virtual machine list, and displaying in a visual mode; a user selects a host or a virtual machine to be monitored on a page provided by a web management module, then the web management module issues a port mirroring strategy to a cloud platform through a rest interface, and the virtual machine flow clicked by the user is mirrored to a flow acquisition module deployed in the current host;
step S3: and collecting and analyzing the flow.
The web management module has a unique identifier for each host, and when a certain virtual machine is migrated, the cloud platform automatically identifies and copies the original port mirror image strategy to the host, and deletes the original strategy.
2. The SDN-based in-cloud east-west traffic pulling method and system according to claim 1, wherein: in step S4, the web management module stores a unique identifier for each host in the database, and performs query and comparison between the unique identifier of the newly added virtual machine in the host and the unique identifier of the virtual machine already existing in the database; if the matched identifier is not found, judging that the virtual machine is newly added, otherwise, judging that the virtual machine is migrated.
3. The SDN-based in-cloud east-west traffic pulling method according to claim 1, wherein: and the web management module calls a rest interface of the openanyright software to convert the data into openflow protocol data, and the openflow protocol data is issued to each acquisition device in each acquisition network.
4. The SDN-based in-cloud east-west traffic pulling method according to claim 1, wherein: in a VMware-based cloud platform, realizing the mirror image of the virtual machine flow through the self-carried distributed port mirror image of the VMware cloud platform; in the cloud platform based on the OpenStack, the traction of the virtual machine traffic is realized through port mirroring of ovs switches.
5. The SDN-based in-cloud east-west traffic pulling method according to claim 1, wherein: in step S2, the policy of port mirroring is: the network card flow of the source virtual machine is copied to a network card of a target virtual machine, the target virtual machine is a flow acquisition module in a virtual machine mode, and the flow of the source virtual machine to be monitored is pulled to the flow acquisition module in a port mirror image mode of a cloud platform.
6. An SDN-based in-cloud east-west traffic traction system is characterized in that: the method comprises the following steps:
the flow acquisition module is deployed on the server in the form of a virtual machine;
the centralized controller module is used for centrally controlling the flow acquisition module through an openflow protocol so as to carry out flow traction, filtering and strategy issuing; and
and the Web management module is in butt joint with the centralized controller module and the cloud platform interface through the rest interface, and provides an operation and display page.
7. The SDN-based in-cloud east-west traffic pulling system of claim 6, wherein: the flow acquisition module is realized by a linux operating system and openvswitch and dpdk software.
8. The SDN-based in-cloud east-west traffic pulling system of claim 6, wherein: and the flow acquisition module is packaged into an iso mirror image through a xorriso software linux operating system, openvswitch and dpdk software.
9. The SDN-based in-cloud east-west traffic pulling system of claim 6, wherein: the centralized controller module is realized through openanyright software, the interaction with the web management module is realized through an openanyright software native restful protocol, and the interaction with the flow acquisition module is realized through an openflow protocol.
10. The SDN-based in-cloud east-west traffic pulling system of claim 6, wherein: the web management module realizes the acquisition and configuration of data through restful api, and the web management module uses a restful interface of openanyright to realize the issuing of an acquisition strategy to the traffic acquisition module and the acquisition of the topology information and the traffic information of the traffic acquisition module.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202110582284.XA CN113542160A (en) | 2021-05-27 | 2021-05-27 | SDN-based method and system for pulling east-west flow in cloud |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202110582284.XA CN113542160A (en) | 2021-05-27 | 2021-05-27 | SDN-based method and system for pulling east-west flow in cloud |
Publications (1)
Publication Number | Publication Date |
---|---|
CN113542160A true CN113542160A (en) | 2021-10-22 |
Family
ID=78124393
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN202110582284.XA Pending CN113542160A (en) | 2021-05-27 | 2021-05-27 | SDN-based method and system for pulling east-west flow in cloud |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN113542160A (en) |
Cited By (7)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN114363035A (en) * | 2021-12-30 | 2022-04-15 | 绿盟科技集团股份有限公司 | Flow traction method and device |
CN114615022A (en) * | 2022-02-17 | 2022-06-10 | 奇安信科技集团股份有限公司 | Cloud internal flow traction method and device |
CN114615174A (en) * | 2022-03-10 | 2022-06-10 | 奇安信科技集团股份有限公司 | Flow monitoring method and device |
CN115695522A (en) * | 2022-09-16 | 2023-02-03 | 中电信数智科技有限公司 | Data packet drainage system based on OVS-DPDK and implementation method thereof |
CN115941558A (en) * | 2022-11-11 | 2023-04-07 | 上海市大数据股份有限公司 | OpenStack traffic monitoring system and method based on cloud platform |
CN115967688A (en) * | 2021-11-04 | 2023-04-14 | 贵州电网有限责任公司 | OpenSwitch-based traffic acquisition performance optimization method |
CN115967657A (en) * | 2022-12-20 | 2023-04-14 | 浪潮云信息技术股份公司 | SDWAN-based cloud platform capacity acquisition method |
Citations (11)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20140337674A1 (en) * | 2013-05-10 | 2014-11-13 | Nec Laboratories America, Inc. | Network Testing |
CN104753951A (en) * | 2015-04-13 | 2015-07-01 | 成都双奥阳科技有限公司 | Network security traffic platform based on software definition |
CN106572120A (en) * | 2016-11-11 | 2017-04-19 | 中国南方电网有限责任公司 | Access control method and system based on mixed cloud |
US20170249177A1 (en) * | 2016-02-26 | 2017-08-31 | Red Hat, Inc. | Extending user interface of a web console |
WO2019060949A1 (en) * | 2017-09-27 | 2019-04-04 | Newsouth Innovations Pty Limited | Process and apparatus for identifying and classifying video-data |
CN110266603A (en) * | 2019-06-27 | 2019-09-20 | 公安部第一研究所 | Authentication business network flow analysis system and method based on http protocol |
CN110912731A (en) * | 2019-10-29 | 2020-03-24 | 广州丰石科技有限公司 | NFV-based system and method for realizing service identification and topology analysis by adopting DPI technology |
CN111224990A (en) * | 2020-01-09 | 2020-06-02 | 武汉思普崚技术有限公司 | Flow traction method and system of distributed micro-isolation network |
CN112437072A (en) * | 2020-11-17 | 2021-03-02 | 广州西麦科技股份有限公司 | Virtual machine flow traction system, method, equipment and medium in cloud platform |
CN112565023A (en) * | 2020-12-28 | 2021-03-26 | 广州西麦科技股份有限公司 | Traffic visualization system and method based on Telemetry traffic acquisition technology |
CN112615811A (en) * | 2020-11-19 | 2021-04-06 | 贵州电网有限责任公司 | Method for automatically analyzing robustness of network boundary strategy in power information |
-
2021
- 2021-05-27 CN CN202110582284.XA patent/CN113542160A/en active Pending
Patent Citations (11)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20140337674A1 (en) * | 2013-05-10 | 2014-11-13 | Nec Laboratories America, Inc. | Network Testing |
CN104753951A (en) * | 2015-04-13 | 2015-07-01 | 成都双奥阳科技有限公司 | Network security traffic platform based on software definition |
US20170249177A1 (en) * | 2016-02-26 | 2017-08-31 | Red Hat, Inc. | Extending user interface of a web console |
CN106572120A (en) * | 2016-11-11 | 2017-04-19 | 中国南方电网有限责任公司 | Access control method and system based on mixed cloud |
WO2019060949A1 (en) * | 2017-09-27 | 2019-04-04 | Newsouth Innovations Pty Limited | Process and apparatus for identifying and classifying video-data |
CN110266603A (en) * | 2019-06-27 | 2019-09-20 | 公安部第一研究所 | Authentication business network flow analysis system and method based on http protocol |
CN110912731A (en) * | 2019-10-29 | 2020-03-24 | 广州丰石科技有限公司 | NFV-based system and method for realizing service identification and topology analysis by adopting DPI technology |
CN111224990A (en) * | 2020-01-09 | 2020-06-02 | 武汉思普崚技术有限公司 | Flow traction method and system of distributed micro-isolation network |
CN112437072A (en) * | 2020-11-17 | 2021-03-02 | 广州西麦科技股份有限公司 | Virtual machine flow traction system, method, equipment and medium in cloud platform |
CN112615811A (en) * | 2020-11-19 | 2021-04-06 | 贵州电网有限责任公司 | Method for automatically analyzing robustness of network boundary strategy in power information |
CN112565023A (en) * | 2020-12-28 | 2021-03-26 | 广州西麦科技股份有限公司 | Traffic visualization system and method based on Telemetry traffic acquisition technology |
Cited By (7)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN115967688A (en) * | 2021-11-04 | 2023-04-14 | 贵州电网有限责任公司 | OpenSwitch-based traffic acquisition performance optimization method |
CN114363035A (en) * | 2021-12-30 | 2022-04-15 | 绿盟科技集团股份有限公司 | Flow traction method and device |
CN114615022A (en) * | 2022-02-17 | 2022-06-10 | 奇安信科技集团股份有限公司 | Cloud internal flow traction method and device |
CN114615174A (en) * | 2022-03-10 | 2022-06-10 | 奇安信科技集团股份有限公司 | Flow monitoring method and device |
CN115695522A (en) * | 2022-09-16 | 2023-02-03 | 中电信数智科技有限公司 | Data packet drainage system based on OVS-DPDK and implementation method thereof |
CN115941558A (en) * | 2022-11-11 | 2023-04-07 | 上海市大数据股份有限公司 | OpenStack traffic monitoring system and method based on cloud platform |
CN115967657A (en) * | 2022-12-20 | 2023-04-14 | 浪潮云信息技术股份公司 | SDWAN-based cloud platform capacity acquisition method |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN113542160A (en) | SDN-based method and system for pulling east-west flow in cloud | |
US9385923B2 (en) | Configuration management method of logical topology in virtual network and management server | |
EP3780502B1 (en) | Underlay-overlay correlation | |
US11444855B2 (en) | System and method for determining a data flow path in an overlay network | |
US8180872B1 (en) | Common data model for heterogeneous SAN components | |
US7275103B1 (en) | Storage path optimization for SANs | |
CN114143203A (en) | Kubernetes container network data packet index acquisition method and system based on dynamic service topological mapping | |
US7685269B1 (en) | Service-level monitoring for storage applications | |
US20140201642A1 (en) | User interface for visualizing resource performance and managing resources in cloud or distributed systems | |
EP2884695A1 (en) | Management server and control method for management server | |
US8060630B1 (en) | Creating and configuring virtual fabrics in storage area networks | |
CN112925646A (en) | Electric power data edge calculation system and calculation method | |
SG193069A1 (en) | Management server and management method | |
CN103475722A (en) | Implement system for business collaboration platform | |
EP3933579A1 (en) | Correlation of virtual network traffic across bare metal servers | |
WO2015192664A1 (en) | Device monitoring method and apparatus | |
EP3934176A1 (en) | Application flow monitoring | |
CN110912731B (en) | NFV-based system and method for realizing service identification and topology analysis by adopting DPI technology | |
CN108845865A (en) | A kind of monitoring service dispositions method, system and storage medium | |
CN107864055A (en) | The management method and platform of virtualization system | |
CN106982244A (en) | The method and apparatus that the message mirror of dynamic flow is realized under cloud network environment | |
CN113542074B (en) | Method and system for visually managing east-west network flow of kubernets cluster | |
CN112068953B (en) | Cloud resource fine management traceability system and method | |
CN116880840A (en) | Service interface generation method, service interface generation device, electronic equipment and medium | |
Cisco | Operations and Management |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
RJ01 | Rejection of invention patent application after publication | ||
RJ01 | Rejection of invention patent application after publication |
Application publication date: 20211022 |