CN1983955A - Method and system for monitoring illegal message - Google Patents

Method and system for monitoring illegal message Download PDF

Info

Publication number
CN1983955A
CN1983955A CN 200610035386 CN200610035386A CN1983955A CN 1983955 A CN1983955 A CN 1983955A CN 200610035386 CN200610035386 CN 200610035386 CN 200610035386 A CN200610035386 A CN 200610035386A CN 1983955 A CN1983955 A CN 1983955A
Authority
CN
China
Prior art keywords
invalid packet
message
monitoring
monitoring rule
invalid
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN 200610035386
Other languages
Chinese (zh)
Inventor
宋端智
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to CN 200610035386 priority Critical patent/CN1983955A/en
Publication of CN1983955A publication Critical patent/CN1983955A/en
Pending legal-status Critical Current

Links

Images

Abstract

This invention discloses a monitoring way and relating system about the illegal Packet. According to the classification about the illegal Packet in the net, this method is used to search the relating monitoring rule and action. Without the influence on the transmitting, certain illegal packet is disposed or saved and sent, as the result, the vindicator of the net equipment may find it easy to maintain the equipment, understand the new net condition, and supply the help for the future net plan through the analysis about these packets.

Description

Method for supervising and supervisory control system to invalid packet
Technical field
The present invention relates to a kind of monitoring messages technical field, be specifically related in a kind of digital communications network method for supervising and supervisory control system invalid packet.
Background technology
Because popularizing of computer technology and digital communications network; network has become an indispensable part in people's life; continuous increase along with demand; the structure and the level of network become increasingly complex; the message information stream that transmits in network also is more and more intensive; owing to technology or artificial reason; in the network usually invalid packet can appear; the invalid packet of indication of the present invention generally is meant the mistake that the network equipment can be distinguished; attack message; or the equipment message that can't discern and transmit; this type of message may be caused by client, also may be because intermediate equipment is handled wrong the generation.
Have in the network equipment of firewall functionality at some, the message that often detects its forwarding belongs to certain outside rogue attacks, so with this packet loss.For this situation, the network planning and researcher wish which type rogue attacks message current on the awareness network has, and where derives from, and purpose is again where to wait information.
After some message enters the network equipment, owing to some reasons (existing mistake, equipment can't discern this message or because the problem that exists on the equipment disposition etc.) as message itself, message is usually abandoned by equipment, may be presented as network failure in this case, also cause losing of information simultaneously.To this situation, the network maintenance staff wishes to locate the concrete place of the network equipment that breaks down, and wishes further to locate the concrete reason that breaks down, thereby finds the way of dealing with problems.
Summary of the invention
The technical problem that the present invention solves provides a kind of method for supervising and supervisory control system to invalid packet that is applicable in computer network or the digital communications network, thinks that the research of invalid packet in the maintenance, network of the network equipment provides effective means.
For addressing the above problem, the present invention is to the method for supervising of invalid packet, and this method mainly comprises:
(1) invalid packet is classified;
(2) the monitoring rule of all kinds of invalid packets that set in advance on the requester network equipment, and to the invalid packet that hits monitoring rule according to its monitoring of hitting rule corresponding processing action carry out corresponding operating.
Wherein, classification is to classify according to the type of the error message that occurs in the message transmission procedure to invalid packet in the described step (1).
Further, described invalid packet classification is a message classification of pressing the header field errors, or by the message classification that does not have forwarding-table item.
Wherein, described monitoring rule is the matching relationship between invalid packet class categories and the processing action.
Further, described monitoring rule is to send to the order line of the network equipment or by the webmaster static configuration by webmaster, or carries out dynamically issuing of rule by the situation that the upper level network equipment detects according to current invalid packet.
Wherein, the corresponding processing action of the rule of the monitoring described in the step (3) comprises:
A1, the port of the direct slave unit of message is sent; Or
A2, message content is kept on the local storage medium; Or
A3, in the new network information of header encapsulation one deck, normally transmit then, send to far-end server.
Wherein, described in the step (3) operation of hitting regular invalid packet is comprised:
B1, be above-mentioned a1, then on this port, connect a terminal and carry out the reception of message if handle action; Or
B2, be above-mentioned a2, then carry out checking of original message by directly reading or downloading if handle action; Or
B3, be above-mentioned a3, then message recombinated and extraction sends on the far-end server if handle action.
Correspondingly, a kind of supervisory control system of the present invention to invalid packet, this system mainly comprises:
Monitor the rale store unit, be used to store the monitoring rule of all types of invalid packet correspondences;
The invalid packet taxon is used for invalid packet is classified, to determine the type of invalid packet;
Monitoring rule query unit is used for inquiring about the regular storage element of described monitoring according to the type of described invalid packet and whether has the monitoring rule corresponding with described invalid packet;
Invalid packet is handled operating unit, when described monitoring rule query unit Query Result is when having the monitoring rule corresponding with described invalid packet, moves according to the corresponding processing of the monitoring rule of this invalid packet correspondence this invalid packet is handled accordingly.
Wherein, classification is to classify according to the type of the error message that occurs in the message transmission procedure to described invalid packet taxon to invalid packet.
Further, described invalid packet taxon is classified to invalid packet can press the message classification of header field errors, or by the message classification that does not have forwarding-table item.
Wherein, the monitoring rule of described monitoring rale store unit storage is the matching relationship between invalid packet class categories and the processing action.
Wherein, the monitoring rule of described monitoring rale store unit storage is to send to the order line of the network equipment or by the webmaster static configuration by webmaster, or carries out dynamically issuing of rule by the situation that the upper level network equipment detects according to current invalid packet.
Wherein, the corresponding processing action of the monitoring rule of described monitoring rale store unit storage comprises:
A1, the port of the direct slave unit of message is sent; Or
A2, message content is kept on the local storage medium; Or
A3, in the new network information of header encapsulation one deck, normally transmit then, send to far-end server.
Wherein, described invalid packet processing operating unit is handled accordingly described invalid packet and is comprised:
B1, be A1, then on this port, connect a terminal and carry out the reception of message if handle action; Or
B2, be A2, then carry out checking of original message by directly reading or downloading if handle action; Or
B3, be A3, then message recombinated and extraction sends on the far-end server if handle action.
Compared with prior art, the present invention has following beneficial effect:
The present invention has changed the practice that directly invalid packet is abandoned in the prior art, after classifying to invalid packet, employing does comparatively reasonably to handle, optimized the Network Transmission environment, realized under the precondition that does not influence forwarding performance of equipment, certain type message is preserved or sent out,, can alleviate the maintenance difficulties of the network equipment by analysis to these messages, also can therefrom understand current network condition, the follow-up network planning is offered help.
Description of drawings
Fig. 1 is the schematic flow sheet of the present invention to a kind of embodiment of the method for supervising of invalid packet;
Fig. 2 is the composition schematic diagram of the present invention to a kind of embodiment of the supervisory control system of invalid packet.
Embodiment
Below in conjunction with accompanying drawing the present invention is elaborated.
With reference to figure 1, this figure is the schematic flow sheet of the present invention to a kind of embodiment of the method for supervising of invalid packet, and the present embodiment idiographic flow comprises:
Step 100: at first preset the monitoring rule, described monitoring rule can be the matching relationship between invalid packet classification type and the processing action.
Step 101: invalid packet is classified, and this classification can be classified according to the normal error message type that occurs in the message transmission procedure, also can adopt other modes, mode classification can be according to the desired precision setting of equipment, in general, it is careful more to classify, and precision is high more.
Step 102: according to the corresponding monitoring rule of classification type inquiry of invalid packet.
Step 103: judge whether invalid packet hits the monitoring rule,, then enter step 105,, then enter step 104 if judged result is not promptly hit the monitoring rule for not if judged result is promptly hit the monitoring rule for being.
Step 104: do not process, or direct dropping packets, the end process process; Also can adopt other processing modes during specific implementation, repeat no more here.
Step 105: the message that hits the monitoring rule is analyzed, determined the processing action of its correspondence, during specific implementation, it handles action can be execution in step 106a, 106b, 106c or 106d, wherein
If corresponding processing action is step 106a: i.e. action is transmitted for local, and then enter step 107a: message sends from local port;
If corresponding processing action is step 106b: i.e. action is local storage, and then enter step 107b: message is stored in local storage medium;
If corresponding processing action is step 106c: i.e. action is transmitted for far-end, then enters step 107c: message increases packaging information and transmits former end server;
If corresponding processing action is for other monitoring rule and handle the defined action of action, then enter step 106d, handle according to the corresponding method of define action, so far, present embodiment is finished the method for supervising handling process of invalid packet.
Be elaborated with the monitoring to invalid packet in the message forwarding processing procedure in the network equipment below.
After message entered the network equipment, equipment had problems as if discovery message itself in processing procedure, or because some restriction can't be transmitted processing normally to message, then is defined as invalid packet, and this message is handled in preparation.
According to the information that obtains in the message processing procedure, at first invalid packet is classified.Concrete mode classification can be determined according to actual needs.For example, the message of certain field errors of head can be divided into a class; Maybe will there be the message of forwarding-table item to be divided into another kind of.
At the type of invalid packet classification, monitoring rule that can pre-configured correspondence and handle action:
The monitoring rule can be the matching relationship between illegal message classification type and the processing action among the present invention, dividing time-like can be a certain class or a few class invalid packet, it also can be the combination of illegal type of message and other rules, other classification can be the conditions at message content or message forwarding path setting, as message five-tuple information etc., the five-tuple information of IP message is meant source IP address, purpose IP address, source port number, destination slogan and protocol number herein.Such as, some network worm virus have certain feature (fixing as the destination slogan), and the network equipment can directly abandon detected viral message, and this is a kind of type that abandons.A corresponding monitoring rule can be set, will send out, infect this kind virus so that observe which terminal owing to the message that this reason abandons.Further, if only wish to understand in certain enterprise that this equipment inserts below should virus infection conditions, can on the basis of previous monitoring rule,, construct corresponding new monitoring rule in conjunction with other conditions (as the network segment of IP address).
The monitoring rule can issue or the webmaster static configuration by order line among the present invention, also can be that the situation that the network equipment detects according to current invalid packet is monitored dynamically issuing of rule.
In addition, for each processing action of monitoring regular invalid packet of coupling including but not limited to following several: a, certain port of the direct slave unit of original message is sent; B, message content is kept on the local storage medium; C, in the new network information (as new IP head) of original message head encapsulation one deck, normally transmit then, send to far-end server.
The data forwarding layer is according to the type of current invalid packet, and inquiry is regular and action with the monitoring of its coupling, and the miss message of monitoring rule is directly abandoned; The message that hits the monitoring rule carries out corresponding next step processing according to the action of configuration;
Specifically, the invalid packet basis of hitting the monitoring rule is handled accordingly with the action of its coupling:
If, then connecting a terminal for sending to certain local port on this port, action carries out the reception of message;
If action is for being saved in local storage medium, then can carry out checking of original message by directly reading or downloading;
If action is that message is delivered on the far-end server, then need on server, move corresponding receiving software, original message is recombinated and extracted.
In addition, detecting and monitor issuing of rule and action, can be to be finished alone by the network equipment, also can be finished by the network equipment and the combination of other equipment.As the network equipment can with the virus detection server combination, exist when sending viral that message propagates when server detects on the network, can preserve the association message of this viroid by informing network equipment, so that analyze viral source and distribution thereof.
Below by a concrete example technical solution of the present invention is done the example explanation.
For example: the P of enterprise that the network equipment R by the T of operator inserts certain network worm virus at present spreads unchecked, in order to prevent that this virus spread is to whole carrier network, according to this viral feature (TCP message destination slogan is 4444), the network maintenance staff of T is provided with ACL (Access-list on equipment R, Access Control List (ACL)), this type of message with device forwards all abandons.
This moment, the P of enterprise currently infected viral terminal in order to find those, so that take certain treatment measures at these terminals.According to this enterprise IP address characteristic distributions (using network segment X.Y.0.0/16), on equipment R, be provided with as follows:
1) rule:
Abandon type: ACL
+ IP message source address belongs to network segment X.Y.0.0/16
+ IP message protocol number=TCP
+ TCP destination slogan=4444
2) action:
Slave unit R port N sends
Under port N, connect a PC then, carry out message by the software on the PC and grasp, can be easy to analyze current those terminals and infect virus.
The following describes invalid packet supervisory control system of the present invention.
With reference to figure 2, illegal supervisory control system of the present invention includes: monitoring rale store unit 10, invalid packet taxon 11, monitoring rule query unit 12 and invalid packet are handled operating unit 13, describe in detail below.
Monitoring rale store unit 10, the monitoring rale store unit 10 described in the present invention are mainly used in all types of non-corresponding monitoring rules of literary composition of transmitting messages of storage.With reference to above stated specification, monitoring rule described here is the matching relationship between invalid packet class categories and the processing action, in specific embodiment, described monitoring rule is pre-configured, and can issue by the order line that webmaster sends to the network equipment or, or dynamically issue according to the situation that current invalid packet detects by the upper level network equipment by the webmaster static configuration.
Invalid packet taxon 11, the invalid packet taxon 11 described in the present invention is mainly used in classifies to invalid packet, to determine the type of invalid packet.In the specific implementation, concrete mode classification can be determined according to actual needs.For example, can classify according to the type of the error message that occurs in the message transmission procedure, when further segmenting, can also be the message classification of pressing the header field errors, or by the message classification that does not have forwarding-table item.
Monitoring rule query unit 12, the monitoring rule query unit 12 described in the present invention is mainly used in according to the type of described invalid packet to inquire about whether there be the monitoring rule corresponding with described invalid packet in the regular storage element of described monitoring.
Invalid packet is handled operating unit 13, invalid packet described in the present invention handle operating unit 13 be mainly used in when described monitoring rule query unit Query Result when existing the monitoring corresponding regular with described invalid packet, according to the processing action that the monitoring rule of invalid packet correspondence is corresponding this invalid packet is handled accordingly, in addition, according to actual conditions, it is when not having the monitoring rule corresponding with described invalid packet at described monitoring rule query Query Result that described invalid packet is handled operating unit 13, also described invalid packet directly can be abandoned and finish monitoring and handle or adopt other processing modes, here repeat no more, with reference to above stated specification, the corresponding processing action of the monitoring rule described in the present invention can comprise in addition:
A1, the port of the direct slave unit of message is sent; Or
A2, message content is kept on the local storage medium; Or
A3, in the new network information of header encapsulation one deck, normally transmit then, send to far-end server.Described invalid packet handled then accordingly comprises:
B1, be A1, then on this port, connect a terminal and carry out the reception of message if handle action; Or
B2, be A2, then carry out checking of original message by directly reading or downloading if handle action; Or
B3, be A3, then message recombinated and extraction sends on the far-end server if handle action.
To sum up, the present invention is under the precondition that does not influence forwarding performance of equipment, invalid packet is classified, and monitor rule according to the invalid packet correspondence of the type and carry out respective handling, for example message is preserved or sent out,, can alleviate the maintenance difficulties of the network equipment by analysis to these messages, also can therefrom understand current network condition, the follow-up network planning is offered help.
The above only is a preferred implementation of the present invention; should be pointed out that for those skilled in the art, under the prerequisite that does not break away from the principle of the invention; can also make some improvements and modifications, these improvements and modifications also should be considered as protection scope of the present invention.

Claims (14)

1, a kind of method for supervising to invalid packet is characterized in that, comprising:
(1) invalid packet is classified;
(2) the monitoring rule of all kinds of invalid packets that set in advance on the requester network equipment, and to the invalid packet that hits monitoring rule according to its monitoring of hitting rule corresponding processing action carry out corresponding operating.
2, the method for supervising to invalid packet as claimed in claim 1 is characterized in that, described invalid packet is classified is that type according to the error message that occurs in the message transmission procedure is classified.
3, the method for supervising to invalid packet as claimed in claim 2 is characterized in that, described invalid packet is classified is the message classification of pressing the header field errors, or by the message classification that does not have forwarding-table item.
4, the method for supervising to invalid packet as claimed in claim 1 is characterized in that, described monitoring rule is the matching relationship between invalid packet class categories and the processing action.
5, as each described method for supervising of claim 1-4 to invalid packet, it is characterized in that, described monitoring rule is to send to the order line of the network equipment or by the webmaster static configuration by webmaster, or carries out dynamically issuing of rule by the situation that the upper level network equipment detects according to current invalid packet.
6, the method for supervising of stating as claim 5 to invalid packet is characterized in that, the corresponding processing action of the monitoring rule described in the step (3) comprises:
A1, the port of the direct slave unit of message is sent; Or
A2, message content is kept on the local storage medium; Or
A3, in the new network information of header encapsulation one deck, normally transmit then, send to far-end server.
7, the method for supervising to invalid packet as claimed in claim 6 is characterized in that, described in the step (3) operation of hitting the regular invalid packet of monitoring is comprised:
B1, be a1, then on this port, connect a terminal and carry out the reception of message if handle action; Or
B2, be a2, then carry out checking of original message by directly reading or downloading if handle action; Or b3, be a3 if handle action, then message is recombinated and extraction sends on the far-end server.
8, a kind of supervisory control system to invalid packet is characterized in that, comprising:
Monitor the rale store unit, be used to store the monitoring rule of all types of invalid packet correspondences;
The invalid packet taxon is used for invalid packet is classified, to determine the type of invalid packet;
Monitoring rule query unit is used for inquiring about described monitoring rale store unit according to the type of described invalid packet and whether has the monitoring rule corresponding with described invalid packet;
Invalid packet is handled operating unit, be used for when described monitoring rule query unit Query Result when having the monitoring rule corresponding with described invalid packet, move according to the corresponding processing of the monitoring rule of this invalid packet correspondence this invalid packet handled accordingly.
9, the supervisory control system to invalid packet as claimed in claim 8 is characterized in that, classification is to classify according to the type of the error message that occurs in the message transmission procedure to described invalid packet taxon to invalid packet.
10, the supervisory control system to invalid packet as claimed in claim 9 is characterized in that, classification is a message classification of pressing the header field errors to described invalid packet taxon to invalid packet, or by the message classification that does not have forwarding-table item.
11, the supervisory control system to invalid packet as claimed in claim 8 is characterized in that, the monitoring rule of described monitoring rale store unit storage is the matching relationship between invalid packet class categories and the processing action.
12, as claim 8 or 11 described supervisory control systems to invalid packet, it is characterized in that, the monitoring rule of described monitoring rale store unit storage is to send to the order line of the network equipment or by the webmaster static configuration by webmaster, or carries out dynamically issuing of rule by the situation that the upper level network equipment detects according to current invalid packet.
13, the supervisory control system to invalid packet as claimed in claim 11 is characterized in that, the corresponding processing action of the monitoring rule of described monitoring rale store unit storage comprises:
A1, the port of the direct slave unit of message is sent; Or
A2, message content is kept on the local storage medium; Or
A3, in the new network information of header encapsulation one deck, normally transmit then, send to far-end server.
14, the supervisory control system to invalid packet as claimed in claim 13 is characterized in that, described invalid packet processing operating unit is handled accordingly described invalid packet and comprised:
B1, be A1, then on this port, connect a terminal and carry out the reception of message if handle action; Or
B2, be A2, then carry out checking of original message by directly reading or downloading if handle action; Or
B3, be A3, then message recombinated and extraction sends on the far-end server if handle action.
CN 200610035386 2006-05-09 2006-05-09 Method and system for monitoring illegal message Pending CN1983955A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN 200610035386 CN1983955A (en) 2006-05-09 2006-05-09 Method and system for monitoring illegal message

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN 200610035386 CN1983955A (en) 2006-05-09 2006-05-09 Method and system for monitoring illegal message

Publications (1)

Publication Number Publication Date
CN1983955A true CN1983955A (en) 2007-06-20

Family

ID=38166210

Family Applications (1)

Application Number Title Priority Date Filing Date
CN 200610035386 Pending CN1983955A (en) 2006-05-09 2006-05-09 Method and system for monitoring illegal message

Country Status (1)

Country Link
CN (1) CN1983955A (en)

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101355503B (en) * 2008-09-03 2011-01-05 中兴通讯股份有限公司 System and method for automatic mirror-image of packet
WO2012142868A1 (en) * 2011-04-18 2012-10-26 中兴通讯股份有限公司 Method, system and device for monitoring network information
CN102932202A (en) * 2012-10-25 2013-02-13 北京星网锐捷网络技术有限公司 Outgoing information auditing method and device
CN105939220A (en) * 2016-04-18 2016-09-14 杭州迪普科技有限公司 Remote port mirroring realization method and device
CN106899419A (en) * 2015-12-17 2017-06-27 北京网御星云信息技术有限公司 A kind of method for realizing abnormality processing, device and request end
CN107317834A (en) * 2009-01-28 2017-11-03 海德沃特研究有限责任公司 Adaptive environment is serviced
WO2022193196A1 (en) * 2021-03-17 2022-09-22 华为技术有限公司 Network message handling device and method, and electronic device

Cited By (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101355503B (en) * 2008-09-03 2011-01-05 中兴通讯股份有限公司 System and method for automatic mirror-image of packet
CN107317834A (en) * 2009-01-28 2017-11-03 海德沃特研究有限责任公司 Adaptive environment is serviced
CN107317834B (en) * 2009-01-28 2021-11-02 海德沃特研究有限责任公司 Adaptive environmental services
WO2012142868A1 (en) * 2011-04-18 2012-10-26 中兴通讯股份有限公司 Method, system and device for monitoring network information
CN102932202A (en) * 2012-10-25 2013-02-13 北京星网锐捷网络技术有限公司 Outgoing information auditing method and device
CN102932202B (en) * 2012-10-25 2015-08-19 北京星网锐捷网络技术有限公司 The method of audit outgoing messages and device
CN106899419A (en) * 2015-12-17 2017-06-27 北京网御星云信息技术有限公司 A kind of method for realizing abnormality processing, device and request end
CN106899419B (en) * 2015-12-17 2020-11-10 北京网御星云信息技术有限公司 Method, device and request terminal for realizing exception handling
CN105939220A (en) * 2016-04-18 2016-09-14 杭州迪普科技有限公司 Remote port mirroring realization method and device
WO2022193196A1 (en) * 2021-03-17 2022-09-22 华为技术有限公司 Network message handling device and method, and electronic device

Similar Documents

Publication Publication Date Title
CN108040057B (en) Working method of SDN system suitable for guaranteeing network security and network communication quality
CN101175078B (en) Identification of potential network threats using a distributed threshold random walk
US7703138B2 (en) Use of application signature to identify trusted traffic
US20070022468A1 (en) Packet transmission equipment and packet transmission system
US7832010B2 (en) Unauthorized access program monitoring method, unauthorized access program detecting apparatus, and unauthorized access program control apparatus
US6895432B2 (en) IP network system having unauthorized intrusion safeguard function
CN101399711B (en) Network monitoring system and network monitoring method
CN1983955A (en) Method and system for monitoring illegal message
US7684339B2 (en) Communication control system
JP2005506736A (en) A method and apparatus for providing node security in a router of a packet network.
JP2011151514A (en) Traffic volume monitoring system
US8064454B2 (en) Protocol incompatibility detection
KR100733830B1 (en) DDoS Detection and Packet Filtering Scheme
US20110141899A1 (en) Network access apparatus and method for monitoring and controlling traffic using operation, administration, and maintenance (oam) packet in internet protocol (ip) network
JP2007259223A (en) Defense system and method against illegal access on network, and program therefor
EP3787240B1 (en) Device for anomaly detection, method and program for anomaly detection
CN111641659A (en) Method, device, equipment and storage medium for preventing central processing unit of switch from being attacked
CN108206828B (en) Dual-monitoring safety control method and system
JP2009005122A (en) Illegal access detection apparatus, and security management device and illegal access detection system using the device
JP2003348113A (en) Switch and lan
KR20100048105A (en) Network management apparatus and method thereof, user terminal for managing network and recoding medium thereof
JP2008135871A (en) Network monitoring system, network monitoring method, and network monitoring program
KR101424504B1 (en) Integrated security control system using positive way
JP6063340B2 (en) Command source specifying device, command source specifying method, and command source specifying program
JP2008199675A (en) Device, method and program for monitoring network, and recording medium with network monitoring program stored therein

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C12 Rejection of a patent application after its publication
RJ01 Rejection of invention patent application after publication