CN1746859A - Alarming system and method for intelligent platform event - Google Patents

Alarming system and method for intelligent platform event Download PDF

Info

Publication number
CN1746859A
CN1746859A CN 200410074628 CN200410074628A CN1746859A CN 1746859 A CN1746859 A CN 1746859A CN 200410074628 CN200410074628 CN 200410074628 CN 200410074628 A CN200410074628 A CN 200410074628A CN 1746859 A CN1746859 A CN 1746859A
Authority
CN
China
Prior art keywords
event
information
platform
event information
address
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN 200410074628
Other languages
Chinese (zh)
Other versions
CN100371903C (en
Inventor
刘文涵
宋建福
崔佳
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Inventec Corp
Original Assignee
Inventec Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Inventec Corp filed Critical Inventec Corp
Priority to CNB2004100746282A priority Critical patent/CN100371903C/en
Publication of CN1746859A publication Critical patent/CN1746859A/en
Application granted granted Critical
Publication of CN100371903C publication Critical patent/CN100371903C/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Debugging And Monitoring (AREA)
  • Information Transfer Between Computers (AREA)

Abstract

An event alarm system of intelligent platform comprises event detection module and information transmitting module. It features that corresponding event information is picked up from event information storage module when platform event is detected by event detection module and event information is transmitted to relevant address by information transmitting module according to address information in event information.

Description

A kind of intelligent platform event warning system and method thereof
Technical field
The present invention relates to a kind of platform events warning system and method, particularly relate to a kind of intelligent platform event warning system and method thereof.
Background technology
Platform events (Platform Event) is meant that the hardware element of the firmware (as BIOS) of platform or platform is (as ASIC, chipset, microcontroller or chip etc.) incident that directly produces, these incidents are independent of operating system (OS) or the system management software and hardware, are that a kind of alarm or particular condition need timely reporting system administrative unit.
Existing platform events management method is that these information are sent to the network management software, with the particular event that takes place on the informing network Administrator system.In the reciprocal process of keeper and operating system, after system occurred unusually, hardware was notified OS by driver, and OS notifies the keeper in the mail mode or is recorded in the daily record and checks for the keeper.The keeper further processes after learning unusually.
See also Fig. 1, be the synoptic diagram of existing event notification mechanism.As shown in the figure, the platform 20 in the server (Sever) 10 reports to operating system 30 by mechanism (B) with platform events, and operating system 30 reports to keeper 40 by mechanism (A) with platform events.The mechanism here (B) is generally the driver of hardware; Mechanism (A) is generally mail or log.
Clearly,, for example cause the driver cisco unity malfunction unusually, can not give OS with exception reporting just driver has problems because hardware produces if mechanism (B) has produced problem.And cause the unusual incident of hardware generation can show identical phenomenon, this driver on the upper strata can't accurately be located and be produced unusual position, final result or can not notify the keeper, that perhaps sends notifies inaccurate or even wrong information.If latter's (causing hardware to produce unusual incident), the keeper can rule of thumb in time take to save action at least, excludes partial fault, if the former (hardware produces unusual), then the keeper still is not apprised of after machine produces serious problems, and this is a danger close.
In addition, will inevitably cause the loss of system resource owing to the intervention of operating system 30 in the event notice process.For example the keeper to analyze and solve unusual measure only be will have to insert the hot-pluggable hard disk of getting well not insert again, only whole process is without closing server 10, the service that is providing on the server is not provided, but traditional mechanism will inevitably produce a large amount of journal files or send many mails and be used for notifying the keeper, this has just taken the resource of Server, if and the keeper goes to visit the daily record of these higher priorities, also will inevitably take the resource of this machine, this has just caused the problem that can steadily solve originally, the shake that has produced system resource in the process that solves is not accomplished and operating system independent.
And, if system closedown then use the keeper of traditional approach management to can not receive any mail from the quilt Server that manages, and the Server startup is consuming time very long, if produce anomalous event in the meantime, also has no idea to allow the keeper know.This solves this type of problem with regard to pressing for a kind of scheme that has nothing to do with OS.
In sum, the Notification Method of the incident that adopts is at present as can be known also existing a lot of shortcomings aspect promptness, accuracy, the utilization of resources and the operating system correlativity.
Summary of the invention
Technical matters to be solved by this invention is to provide a kind of intelligent platform event warning system and method thereof, the intervention that need not operating system also can be informed the keeper with the platform events that detects, in conserve system resources, improve the promptness and the accuracy of notice.
To achieve these goals, the invention provides a kind of intelligent platform event warning system, its characteristics are, need not by operating system, platform events information can be sent to the keeper, comprising: an event checking module, and it is in order to the detection platform incident; One event information memory module is in order to store pre-configured event information; And an information sending module, it links to each other with this event checking module; Wherein, when this event checking module detects platform events, in this event information memory module, extract this corresponding event information, and, this event information is sent to appropriate address by this information sending module according to the address information in this event information.
Above-mentioned intelligent platform event warning system, its characteristics are that this event information comprises tactful number, set of strategies number, keyword, address information and explains character string.
Above-mentioned intelligent platform event warning system, its characteristics are, described information sending module also comprises the platform information that sends the generation incident, comprises the entity and the event data of time, event type, seriousness, generation incident.
The present invention also provides a kind of intelligent platform event alarm method, and its characteristics are, need not by operating system, platform events information can be sent to the keeper, and this method comprises the steps: state detector detection platform incident; According to this platform events, in the event information memory module, extract corresponding event information; Extract the address information in this event information; And, this event information is sent to appropriate address by network interface card according to this address information.
Above-mentioned intelligent platform event alarm method, its characteristics are that this event information comprises tactful number, set of strategies number, keyword, address information and explains character string.
Above-mentioned intelligent platform event alarm method, its characteristics are, the step that this sends event information also comprises the platform information that sends the generation incident, comprises the entity and the event data of time, event type, seriousness, generation incident.
Above-mentioned intelligent platform event alarm method, its characteristics are that this sends the step of event information, if this address information is a plurality of, then send respectively according to this address information.
The present invention also provides a kind of intelligent platform event warning device, and its characteristics are, need not by operating system, platform events information can be sent to the keeper, comprising: a storage element, and it is in order to store pre-configured platform events information; One state sensor, it is used for the state of detection hardware element, the receiving platform incident; One baseboard management controller, it is in order to collect this platform events; And a network interface card, it is in order to extracting the address information in this event information, and according to this address information, this event information is taken place to the keeper; Wherein, this storage element, this state sensor and this network interface card all are positioned on the mainboard, and link to each other with this baseboard management controller, and this baseboard management controller is according to this platform events of collecting, in this storage element, search for corresponding event information, and this event information is transferred to this network interface card.
Above-mentioned intelligent platform event warning device, its characteristics are that this baseboard management controller also includes a driver element, and it sets up being connected of this baseboard management controller and this operating system, and the parameter of this baseboard management controller is provided with and obtains.
Above-mentioned intelligent platform event warning device, its characteristics are that this network interface card links to each other with this baseboard management controller by data bus.
Above-mentioned intelligent platform event warning device, its characteristics be, this storage element is one can electricly wipe the formula electricallyalterablereadonlymemory off.
Effect of the present invention, be to have realized in time by the PET standard, accurately, solution with the upper strata operating system independent, by on mainboard, placing the phylogenetic anomalous event of BMC detection hardware, anomalous event is sent to the address that has configured by network interface card, and the address that will send, information such as the content of carrying are that configured in advance leaves (as EPROM) in the erasable internal memory well in, and organize inquiry when sending by certain strategy, like this, because BMC oneself has processing power, so be independent of OS work, solved the shortcoming of classic method, have in time, accurately, the advantage that OS is irrelevant, even under the OS closed condition, as long as main board power supply just can send the message of anomalous event, it is unusual to allow the keeper but can not learn which has appearred in the server of being monitored the very first time at the scene, so that in time take measures.
Describe the present invention below in conjunction with the drawings and specific embodiments, but not as a limitation of the invention.
Description of drawings
Fig. 1 is the synoptic diagram of existing event notification mechanism;
Fig. 2 is the modular structure figure of intelligent platform event warning system of the present invention;
Fig. 3 is the process flow diagram of intelligent platform event alarm method of the present invention;
Fig. 4 is the synoptic diagram of event notification mechanism of the present invention;
Fig. 5 is a platform events warning device synoptic diagram of the present invention; And
The process flow diagram that Fig. 6 sends for embodiment of the invention strategy.
Wherein, Reference numeral:
The 10-server, 20-platform, 30-operating system
The 40-keeper, 50-BMC, 60-BMC driver element
The 70-mainboard, 80-state sensor, 90-EEPROM
The 100-network interface card
The 11-software layer, the 12-hardware layer
The 210-event checking module, 220-event information memory module
The 230-information sending module
Step 310-state detector detection platform incident
Step 320-extracts corresponding event information according to this platform events in the event information memory module
Step 330-extracts the address information in this event information
Step 340-is sent to appropriate address with this event information by network interface card according to this address information
Step 610-detects platform events
Does step 620-determine the corresponding strategies of this incident by keyword or set of strategies number?
Step 631-parses policy number
Step 641-collects the All Policies that is complementary with the set of strategies number in All Policies
Step 632-resolves this keyword
Step 642-collects the All Policies that is complementary with keyword in All Policies
Step 650-is according to relevant information stuff event information
The destination address that step 660-is sent to this incident in the strategy to be comprised
Does step 670-judge whether that last incident sends successfully?
The all incidents of step 680-all successfully send
Embodiment
At first, please refer to Fig. 2, the modular structure figure for the intelligent platform event warning system that the present invention carried is described as follows: event checking module 210, it is in order to the detection platform incident.Event information memory module 220, in order to store pre-configured event information, wherein said event information comprises tactful number, set of strategies number, keyword, address information and explains character string.Information sending module 230, it links to each other with this event checking module 210.This information sending module 230 also comprises the platform information that sends the generation incident, comprises the entity and the event data of time, event type, seriousness, generation incident.Wherein, when this event checking module 210 detects platform events, in this event information memory module 220, extract this corresponding event information, and, this event information is sent to appropriate address by this information sending module 230 according to the address information in this event information.
Then, by Fig. 3 flow process of the present invention is described, this figure is the operation workflow figure of the intelligent platform event alarm method that the present invention carried.At first, step 310, state detector detection platform incident; Step 320 then according to this platform events, is extracted corresponding event information in the event information memory module, wherein event information comprises tactful number, set of strategies number, keyword, address information and explains character string.Step 330 is extracted the address information in this event information again; Step 340 at last according to this address information, is sent to appropriate address with this event information by network interface card, also comprises the platform information that sends the generation incident, comprises the entity and the event data of time, event type, seriousness, generation incident.
See also Fig. 4, be the synoptic diagram of event notification mechanism of the present invention.The BMC50 that is positioned at hardware layer 12 is mounted in the microcontroller chip on the mainboard, is used for detecting anomalous event, and BMC50 directly mails to the address that configures with detected anomalous event information.The OS30 that BMC50 has walked around position software layer 11 directly sends event message, is independent of OS30, and BMC50 self has processing power, does not take the resource of system; BMC is directly known the duty of hardware on the mainboard (temperature sensor, voltage sensor etc.) by system bus (Bus), network interface card (NIC), and the information that obtains in time, accurately.
See also Fig. 5, be platform events warning device synoptic diagram of the present invention.Include BMC50 and the EEPROM90 that is attached thereto, state sensor 80, network interface card 100 and BMC driver element 60.Carry out the processing of data by the microcontroller BMC50 that is installed on the mainboard 70, use EEPROM90 as memory device, all information outwards sends by network interface card 100.Wherein BMC50 is a microprocessor, and it is responsible for deal with data; EEPRom90 is a memory module, and many configuration informations are deposited in wherein; State sensor 80 is distributed on the mainboard 70, is used for the state of detection hardware element, as cpu temperature, rotation speed of the fan; Network interface card 100 is connected with BMC50 by bus, and BMC50 can send data to network interface card 100 by bus and send; BMC driver element 60 is being got in touch OS30 and BMC50, uses KCS interface accessing BMC50, and the order of the normalized definition of use IPMI1.5 is provided with and obtains all multiparameters of BMC, comprising:
(A) communication mechanism of expression BMC and EEPRom
(B) expression OS is by the communication mechanism of driving with BMC
(C) expression BMC is by the communication mechanism of BUS and network interface card
(D) communication mechanism of expression Sensor and BMC
In PET, a strategy (Policy) just becomes a kind of rule, and the combination of strategy is called set of strategies (Policy Set).Strategy comprises the number (Policy Number) of strategy, the number of set of strategies (SetNumber).In some strategies, need the needed keyword of rapid positioning strategy (Key), the IP address that send (Destination Address), the fix information that carries (Alert String) etc.The information that typical strategy comprises is as shown in table 1 below:
Policy?Number 1
Policy?Set?Number 1
Key 1
Destination?Address 10.190.5.179
Alert?String “Emergency?voltage?error”
Table 1
4 Policy are arranged, entrained information such as following table 2 in the present embodiment:
Policy Number 1 ? 2 ? 3 ? 4 ?
Policy?Set Number 1 ? 2 ? 1 ? 1 ?
Key (keyword) Voltage Unspecified Voltage Voltage
Destination Address 10.190.5.179 ? 192.168.0.1 ? 10.190.5.180 ? 10.190.5.181 ?
Alert String ? ?“Emergency ?voltage ?error” ?“Unspecified” ? ? “Voltage too?high” ? “Voltage too?low” ?
Table 2
Wherein:
● Policy Number is used as unique numbering and identifies this Policy;
● some Policy that Policy Set Number is identical are set.For example, all can be generalized into a set with the relevant system mistake of voltage, are convenient to management, in the set of this voltage mistake, the Policy of expression dangerous voltage mistake is arranged, the Policy that represents the overtension mistake is arranged, the Policy of expression brownout mistake is arranged.In the table 2, Policy Number is that 1,3,4 Policy belongs to a set simultaneously, because their Policy Set Number is 1;
● Key is as keyword, can search the Policy with certain querying condition coupling in some Policy, such as, as keyword query, then can find Policy Number is 1,3,4 Policy with " Voltage ";
● Destination Address decision PET is sent to incident where;
● Alert String is used as the explanation character string relevant with such incident.
This strategy is deposited among the EEPRom90, can carry out the IPMI standard commands from OS30 by BMC driver element 60 and set, and also can set up Session by network and carry out the IPMI standard commands then and set.
When sending, the details of incident will be formed a Trap package temporarily, and the form of package is by IPMI Platform Event Trap Format Specification v 1.0 definition.Mainly comprised type, the seriousness of some information, time, the incident of the platform of the incident of generation, the entity (Entity) of generation incident, and a series of information such as event data.Form the complete SNMP Trap package of lattice according to certain coded format, send through the address in the top strategy.If one incident BMC has collected a lot of strategies relevant with this incident, can send according to following several " sending strategy ":
1.Trap be sent to each destination address.
2. if article one Trap sends successfully, next bar will be sent to the different address in this set of strategies.
In a single day 3. successfully sent a Trap, then stopped sending.
See also Fig. 6, be the process flow diagram of embodiment of the invention strategy transmission.Step 610 detects platform events; Step 620 afterwards, is judged the corresponding strategies of determining this incident by keyword or set of strategies number; Step 631, if select by the set of strategies number, then countermeasure summary number is resolved; Step 641 is collected the All Policies that is complementary with the set of strategies number in All Policies; Step 632 is then resolved this keyword if select by the keyword collection strategy; Step 642 is collected the All Policies that is complementary with keyword in All Policies.Step 650 is then according to relevant information (comprise the detected information of state detector and the fix information that carries etc.) stuff event information; Step 660, the destination address that is sent to this incident in the strategy again to be comprised.Does step 670 judge whether that last incident sends successfully then? if last incident sends successfully, step 680 shows that then all incidents all successfully send.
Certainly; the present invention also can have other various embodiments; under the situation that does not deviate from spirit of the present invention and essence thereof; those of ordinary skill in the art can make various corresponding changes and distortion according to the present invention, but these corresponding changes and distortion all should belong to the protection domain of claim of the present invention.

Claims (11)

1, a kind of intelligent platform event warning system is characterized in that, need not by operating system, platform events information can be sent to the keeper, comprising:
One event checking module, it is in order to the detection platform incident;
One event information memory module is in order to store pre-configured event information; And
One information sending module, it links to each other with this event checking module;
Wherein, when this event checking module detects platform events, in this event information memory module, extract this corresponding event information, and, this event information is sent to appropriate address by this information sending module according to the address information in this event information.
2, intelligent platform event warning system according to claim 1 is characterized in that, this event information comprises tactful number, set of strategies number, keyword, address information and explains character string.
3, intelligent platform event warning system according to claim 1 is characterized in that, described information sending module also comprises the platform information that sends the generation incident, comprises the entity and the event data of time, event type, seriousness, generation incident.
4, a kind of intelligent platform event alarm method is characterized in that, need not by operating system, platform events information can be sent to the keeper, and this method comprises the steps:
State detector detection platform incident;
According to this platform events, in the event information memory module, extract corresponding event information;
Extract the address information in this event information; And
According to this address information, this event information is sent to appropriate address by network interface card.
5, intelligent platform event alarm method according to claim 4 is characterized in that, this event information comprises tactful number, set of strategies number, keyword, address information and explains character string.
6, intelligent platform event alarm method according to claim 4, it is characterized in that, the step that this sends event information also comprises the platform information that sends the generation incident, comprises the entity and the event data of time, event type, seriousness, generation incident.
7, intelligent platform event alarm method according to claim 4 is characterized in that, this sends the step of event information, if this address information is a plurality of, then sends respectively according to this address information.
8, a kind of intelligent platform event warning device is characterized in that, need not by operating system, platform events information can be sent to the keeper, comprising:
One storage element, it is in order to store pre-configured platform events information;
One state sensor, it is used for the state of detection hardware element, the receiving platform incident;
One baseboard management controller, it is in order to collect this platform events; And
One network interface card, it is in order to extracting the address information in this event information, and according to this address information, this event information is taken place to the keeper;
Wherein, this storage element, this state sensor and this network interface card all are positioned on the mainboard, and link to each other with this baseboard management controller, and this baseboard management controller is according to this platform events of collecting, in this storage element, search for corresponding event information, and this event information is transferred to this network interface card.
9, intelligent platform event warning device according to claim 8, it is characterized in that, this baseboard management controller also includes a driver element, and it sets up being connected of this baseboard management controller and this operating system, and the parameter of this baseboard management controller is provided with and obtains.
10, intelligent platform event warning device according to claim 8 is characterized in that, this network interface card links to each other with this baseboard management controller by data bus.
11, intelligent platform event warning device according to claim 8 is characterized in that, this storage element is one can electricly wipe the formula electricallyalterablereadonlymemory off.
CNB2004100746282A 2004-09-09 2004-09-09 Alarming system and method for intelligent platform event Expired - Fee Related CN100371903C (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CNB2004100746282A CN100371903C (en) 2004-09-09 2004-09-09 Alarming system and method for intelligent platform event

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CNB2004100746282A CN100371903C (en) 2004-09-09 2004-09-09 Alarming system and method for intelligent platform event

Publications (2)

Publication Number Publication Date
CN1746859A true CN1746859A (en) 2006-03-15
CN100371903C CN100371903C (en) 2008-02-27

Family

ID=36166403

Family Applications (1)

Application Number Title Priority Date Filing Date
CNB2004100746282A Expired - Fee Related CN100371903C (en) 2004-09-09 2004-09-09 Alarming system and method for intelligent platform event

Country Status (1)

Country Link
CN (1) CN100371903C (en)

Cited By (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101997932A (en) * 2009-08-28 2011-03-30 联想(北京)有限公司 Computer, network card and data exchange method
CN102055615A (en) * 2009-10-28 2011-05-11 英业达股份有限公司 Server monitoring method
CN101741654B (en) * 2008-11-27 2012-01-18 英业达股份有限公司 Monitoring device and method of operating system
CN102467425A (en) * 2010-11-05 2012-05-23 英业达股份有限公司 Method for acquiring storage device failure signal by utilizing baseboard management controller
WO2013032438A1 (en) 2011-08-29 2013-03-07 Intel Corporation Device, system and method of processing a received alert
CN103200050A (en) * 2013-04-12 2013-07-10 北京百度网讯科技有限公司 Server hardware state monitoring method and server hardware state monitoring system
CN103684817A (en) * 2012-09-06 2014-03-26 百度在线网络技术(北京)有限公司 Monitoring method and system for data center
CN103905566A (en) * 2014-04-22 2014-07-02 浪潮电子信息产业股份有限公司 Server starting information remote checking and leading-out method
CN104010007A (en) * 2013-02-21 2014-08-27 中兴通讯股份有限公司 Server remote monitoring method and system
WO2015039598A1 (en) * 2013-09-17 2015-03-26 华为技术有限公司 Fault locating method and device

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5984178A (en) * 1996-11-29 1999-11-16 Diebold, Incorporated Fault monitoring and notification system for automated banking machines
US5968189A (en) * 1997-04-08 1999-10-19 International Business Machines Corporation System of reporting errors by a hardware element of a distributed computer system
US6178528B1 (en) * 1997-09-18 2001-01-23 Intel Corporation Method and apparatus for reporting malfunctioning computer system
US6772376B1 (en) * 2000-11-02 2004-08-03 Dell Products L.P. System and method for reporting detected errors in a computer system
US6823482B2 (en) * 2001-03-08 2004-11-23 International Business Machines Corporation System and method for reporting platform errors in partitioned systems
CN1519747A (en) * 2003-01-24 2004-08-11 英保达股份有限公司 Method and device for sending out information in time sequence

Cited By (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101741654B (en) * 2008-11-27 2012-01-18 英业达股份有限公司 Monitoring device and method of operating system
CN101997932A (en) * 2009-08-28 2011-03-30 联想(北京)有限公司 Computer, network card and data exchange method
CN101997932B (en) * 2009-08-28 2014-08-27 联想(北京)有限公司 Computer, network card and data exchange method
CN102055615A (en) * 2009-10-28 2011-05-11 英业达股份有限公司 Server monitoring method
CN102055615B (en) * 2009-10-28 2013-05-01 英业达股份有限公司 Server monitoring method
CN102467425A (en) * 2010-11-05 2012-05-23 英业达股份有限公司 Method for acquiring storage device failure signal by utilizing baseboard management controller
EP2751795A1 (en) * 2011-08-29 2014-07-09 Intel Corporation Device, system and method of processing a received alert
WO2013032438A1 (en) 2011-08-29 2013-03-07 Intel Corporation Device, system and method of processing a received alert
EP2751795A4 (en) * 2011-08-29 2015-04-01 Intel Corp Device, system and method of processing a received alert
CN103684817A (en) * 2012-09-06 2014-03-26 百度在线网络技术(北京)有限公司 Monitoring method and system for data center
CN104010007A (en) * 2013-02-21 2014-08-27 中兴通讯股份有限公司 Server remote monitoring method and system
WO2014127614A1 (en) * 2013-02-21 2014-08-28 中兴通讯股份有限公司 Remote monitoring method and system for server
CN103200050A (en) * 2013-04-12 2013-07-10 北京百度网讯科技有限公司 Server hardware state monitoring method and server hardware state monitoring system
WO2015039598A1 (en) * 2013-09-17 2015-03-26 华为技术有限公司 Fault locating method and device
CN103905566A (en) * 2014-04-22 2014-07-02 浪潮电子信息产业股份有限公司 Server starting information remote checking and leading-out method

Also Published As

Publication number Publication date
CN100371903C (en) 2008-02-27

Similar Documents

Publication Publication Date Title
CN103152352B (en) A kind of perfect information security forensics monitor method based on cloud computing environment and system
RU2417417C2 (en) Real-time identification of resource model and resource categorisation for assistance in protecting computer network
CA2629279C (en) Log collection, structuring and processing
Roschke et al. An extensible and virtualization-compatible IDS management architecture
CN1655518A (en) Network security system and method
CN1746859A (en) Alarming system and method for intelligent platform event
CN1642104A (en) Method and device for realizing system journal
CN104574219A (en) System and method for monitoring and early warning of operation conditions of power grid service information system
CN1901568A (en) Method for realizing historical property collection in net managing system
CN101034974A (en) Associative attack analysis and detection method and device based on the time sequence and event sequence
CN1741526A (en) Method and system for detecting exception flow of network
CN105119915A (en) Malicious domain detection method and device based on intelligence analysis
CN105072120A (en) Method and device for malicious domain name detection based on domain name service state analysis
CN1175621C (en) Method of detecting and monitoring malicious user host machine attack
CN1722682A (en) Network monitoring system
CN105072119A (en) Domain name resolution conversation mode analysis-based method and device for detecting malicious domain name
CN1756257A (en) Host performance collection proxy in large-scale network
CN1832417A (en) Data collecting method and system
CN101076174A (en) Method for processing warn windstorm
CN1175352C (en) Automatic WINDOWS NT course protecting system
CN108833442A (en) A kind of distributed network security monitoring device and its method
KR100846835B1 (en) Method and apparatus for Security Event Correlation Analysis based on Context Language
CN1968148A (en) Network management system for integrative supervision and management of application software system and host resource
CN1921419A (en) Topology method for network physical arrangement
US8949669B1 (en) Error detection, correction and triage of a storage array errors

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
C17 Cessation of patent right
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20080227

Termination date: 20100909