EP2165462A2 - Procédé de télésurveillance d'une pluralité de réseaux locaux, a travers un réseau de communication externe - Google Patents
Procédé de télésurveillance d'une pluralité de réseaux locaux, a travers un réseau de communication externeInfo
- Publication number
- EP2165462A2 EP2165462A2 EP08826356A EP08826356A EP2165462A2 EP 2165462 A2 EP2165462 A2 EP 2165462A2 EP 08826356 A EP08826356 A EP 08826356A EP 08826356 A EP08826356 A EP 08826356A EP 2165462 A2 EP2165462 A2 EP 2165462A2
- Authority
- EP
- European Patent Office
- Prior art keywords
- network
- local
- entity
- external
- address
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04M—TELEPHONIC COMMUNICATION
- H04M11/00—Telephonic communication systems specially adapted for combination with other electrical systems
- H04M11/007—Telephonic communication systems specially adapted for combination with other electrical systems with remote control systems
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
- H04L12/2803—Home automation networks
- H04L12/2823—Reporting information sensed by appliance or service execution status of appliance services in a home automation network
- H04L12/2825—Reporting to a device located outside the home and the home network
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/08—Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
- H04L43/0805—Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters by checking availability
- H04L43/0811—Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters by checking availability by checking connectivity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/08—Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
- H04L43/0805—Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters by checking availability
- H04L43/0817—Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters by checking availability by checking functioning
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/09—Mapping addresses
- H04L61/25—Mapping addresses of the same type
- H04L61/2503—Translation of Internet protocol [IP] addresses
- H04L61/2514—Translation of Internet protocol [IP] addresses between local and global IP addresses
Definitions
- the present invention relates to a method and a remote monitoring system of a plurality of local networks, such as home networks, comprising a local gateway for connection to an IP network (for Internet Protocol in English).
- a local gateway for connection to an IP network (for Internet Protocol in English).
- Domestic remote monitoring systems are known primarily for medical applications, to remotely monitor a patient, or secure, to detect intrusions into a home.
- Such systems include sensors that monitor a specific activity, for example the cardiac activity of a patient, the opening of a door or window of a home or the presence of an intruder in this home .
- These sensors are connected to a local communication module capable of signaling to a remote remote monitoring center alarms in the event of problems detected, generally via a telephone line of a PSTN network (for Public Telephone Network).
- PSTN network for Public Telephone Network
- These home network monitoring systems actually provide an alarm notification service from a home network to a remote monitoring center. If the communication chain between the home network and the remote monitoring center is working, the solution is satisfactory. However, if an element of the chain is not operational, for example because of a failure, the system no longer performs its function. In addition, such remote monitoring systems are not suitable for proactively monitoring home networks.
- local network monitoring systems such as enterprise networks, including a monitoring server for monitoring a relatively large number of devices, possibly through aggregation entities.
- SNMP Simple Network Managment Protocol
- the object of the invention is to propose a remote monitoring method through an external telecommunications network, such as a WAN (for WideArea Network in English) or ADSL (for Asymnrtric Digîal Suscriber Line in English), of a plurality local networks, each local network being connected to the external network via a gateway with network address translation (NAT) means for mapping local internal network addresses to external addresses of the external network, which allows these local networks to be monitored proactively .
- NAT network address translation
- the invention relates to a remote monitoring method of a plurality of local networks, through an external communication network, a local network comprising means for translating addresses to correspond to an internal address in the local network.
- an external address in the external network which comprises: a regular sending from a LAN monitoring entity of a status report on said local network to an aggregation entity of the external network, with a transmission frequency adapted to maintain "alive a correspondence between an internal address of the monitoring entity of the local network and an external address in the external network by the address translation means, - in case of detection of an anomaly in the local network, the establishment of a communication between a remote monitoring platform and the local network monitoring entity, through the external network, at the i nitiative of the remote monitoring platform, according to said correspondence. Keeping alive a correspondence between an internal address and an external address of a local network monitoring entity makes it possible, in case of detection of an anomaly, to communicate directly with this monitoring entity.
- the address translation means are of NAT type (for Network Address Translation).
- the remote monitoring method according to the invention applies more particularly to networks implementing a NAT type address translation mechanism according to which, for an observer external to the local network, any request resulting from this network seems to come from the gateway between the local network and the external network and not an entity behind this gateway.
- the state report on said local network is contained in a UDP (User Datagram Protocol) type packet.
- UDP packets have the advantage of being very small in size. This makes it possible to ensure the remote monitoring of a very large number of local networks while limiting the load of the external network and that of the aggregation entity.
- the status report on said local network and / or the correspondence between an internal address of the monitoring entity of the local network and an external address in the external network are saved in a database.
- the database further comprises the synthesis of the status reports of at least two local networks.
- the method is applicable to more than one local network. Establishing a summary of the status reports of the local networks considered makes it possible to limit the data processing load.
- data contained in the database is transmitted to the remote monitoring platform by the aggregation entity.
- the remote monitoring platform has data enabling it to monitor the local network.
- This data is transmitted by the aggregation entity either on the initiative of the latter or on request of the remote monitoring platform.
- a fault in the local network corresponds to the absence of sending the status report on said local network by a monitoring entity of the local network for a duration greater than a predefined limit duration.
- the detection of anomaly by not sending the status report on the local network makes it possible to ensure proactive remote monitoring of the local network.
- the invention also relates to an aggregation entity in an external communication network through which remote monitoring of a plurality of local area networks is provided, a local area network comprising address translation means for matching an internal address in the local network an external address in the external network, which comprises means for recording data in a database, the data forming part of the set:
- the aggregation entity includes a database in which it records data for remote monitoring of at least one local area network. According to a preferred feature, the aggregation entity includes means for transmitting to a remote monitoring platform data stored in the database.
- the aggregation entity can transmit data making it possible to ensure remote monitoring of the local network, in particular to a remote monitoring platform of the local network.
- the invention also relates to a remote monitoring platform in an external communication network through which the remote monitoring of a plurality of local area networks is ensured, a local area network comprising address translation means for matching an internal address in the network.
- local network an external address in the external network, characterized in that it comprises means for establishing a communication between the remote monitoring platform and a monitoring entity of a local network when a data analysis transmitted by a Aggregation entity leads to detect an anomaly at the local network monitoring entity.
- the remote monitoring platform By analyzing data transmitted by the aggregation entity, the remote monitoring platform detects anomalies in the local network.
- the invention also relates to a computer program product that includes instructions for implementing communication establishment operations between a remote monitoring platform and a monitoring entity of a local network, through a network. external, at the initiative of the remote monitoring platform, when an analysis of data transmitted by an aggregation entity leads to detect an anomaly at the monitoring entity of the local network, when these operations are executed by a computer .
- FIG. Figure 2 shows a more detailed view of the system but with a single LAN.
- FIG. 1 shows a plurality of local home networks HOME1,..., HOME99999, and a remote monitoring platform server 1.
- Local networks HOME1,..., HOME9999 are connected to the remote monitoring platform 1 by via an external telecommunications network 3, such as Wide Area Network (WAN) or ADSL.
- WAN Wide Area Network
- ADSL Advanced Digital Subscriber Service
- a home network for example HOME1, here comprises a set of detection devices 2, such as smoke, gas and / or presence sensors.
- the detection devices 2 are connected to a local surveillance entity 4, which is itself connected to a communication gateway 5 between the home network HOME1 and the external telecommunications network 3.
- the HOME 1 LAN uses a wireless communication technique, such as ZigBee.
- the gateway 5 comprises a broadband modem and a NAT module 6 for translating addresses making it possible to correspond to an internal address of the local network an external address in the external network 3.
- This module NAT 6 establishes a correspondence table between addresses 3. Specifically, the NAT module matches a pair (internal address / internal port of gateway 5) with a pair (external address / external port of gateway 5). With this NAT table, the NAT module 6 is able to determine which element of the local network is intended for an incoming packet and to which address of the external network an outgoing packet is to be sent.
- the system further comprises an aggregation entity
- the remote monitoring system operates as follows.
- the local monitoring entity of a local network 4 collects information from detection devices 2 of the local network, as represented by the arrow El. This collection can be carried out in "push” mode. ie spontaneous sending of information from the devices 2, or in "pull” mode, that is to say at the request of the local monitoring entity 4.
- the local monitoring entity 4 periodically sends a summary report on the state of the network to an aggregation entity 7 of the external network 3, as represented by the arrow E2.
- This report is here contained in a simple UDP packet (for User Data ⁇ am Protocol). It indicates here a state for each device 2 of the network, for example
- This report is transmitted to the aggregation entity 7 via the gateway 5.
- the NAT 6 of the gateway 5 creates a correspondence between the internal address in the local network HOME1 of the communication entity.
- the sending frequency of this status report of the local network 3 is adapted to keep alive this correspondence.
- the aggregation entity 7 registers in a database the regularly received reports as well as the information relating to the correspondence between the internal address in the local network local 1 HOME 1 of the local monitoring entity 4 and an external address in the network 3.
- the aggregation entity 7 transmits to the remote monitoring platform 1 the information relating to the correspondence between the internal address in the local network LOC of the local monitoring entity 4 and an external address in the network 3, as well as reports regularly received, during a step E3.
- the remote monitoring platform 1 sends a request to the aggregation entity 7 to request the transmission of the information relating to the correspondence between the internal address in the local network HOME1 of the communication entity.
- the entity 7 records in a database syntheses on the reports received from a plurality of local networks for transmission to the remote monitoring platform 1 either on the initiative of the aggregation entity 7 at the request of the remote monitoring platform 1.
- the remote monitoring platform 1 analyzes the status reports of the network HOME 1 received in order to detect a possible anomaly.
- An anomaly may for example correspond to a state of malfunction reported for a device 2 HOMEl network or the detection of a problem (smoke, gas, intrusion, etc.).
- the remote monitoring platform 1 takes the initiative of establishing a communication with the local surveillance entity 4 in order to carry out a detailed monitoring of the state of the network HOMEl, during a step E4.
- the establishment of this proactive communication, on the initiative of the platform 1, is made possible by the fact that the correspondence between the internal address of the local entity 4 and an external address in the external network 3 is kept alive. by regularly sending the network status report HOME 1 from the local entity 4 to the aggregation entity 7, through the gateway 5.
- the monitoring platform 1 detects that there is an anomaly and informs another platform service, in this case a support platform, the problem.
- This service platform can for example inform the customer user of the local network considered, in this case HOME l, the problem, by sending an SMS, per call, etc..
- the monitoring platform 1 may attempt to establish a communication with the local monitoring entity 4, as in the case of detection of an anomaly in the reports received.
- the system may comprise several aggregation entities 7.
- the number of local networks to be monitored is relatively small, it could be envisaged that they send their status reports directly to the remote monitoring platform 1 which integrates the aggregation entity 7.
- the aggregation entity 7 comprises means for recording data in a database.
- the recorded data includes status reports of at least one local network (HOME1, ..., HOME 99999) regularly transmitted by the local monitoring entity 4 of the local area network.
- the recorded data may include the synthesis of status reports from at least two local area networks.
- the recorded data may, furthermore, include information relating to the correspondence between the internal address in the local network considered of the local monitoring entity 4 and an external address in the external network 3.
- the aggregation entity 7 comprises means for transmitting data to the remote monitoring platform 1.
- the transmitted data correspond to data recorded in the database.
- the means for recording data in a database and the data transmission means to the remote monitoring platform 1 may be software modules forming a computer program.
- the invention therefore also relates to a computer program comprising software instructions for the execution of data recording operations in a database and data transmission to the remote monitoring platform 1 when these operations are performed by the aggregation entity 7.
- Software modules may be stored in or transmitted by a data carrier. This may be a hardware storage medium, for example a CD-ROM, a magnetic diskette or a hard disk, or a transmissible medium such as an electrical signal, optical or radio.
- the remote monitoring platform 1 comprises means for receiving data transmitted by the aggregation entity 7. According to one variant, the remote monitoring platform 1 comprises means for sending a request to the aggregation entity 7.
- the remote monitoring platform 1 comprises data analysis means transmitted by the aggregation entity 7 either at the initiative of the latter or at the request of the remote monitoring platform 1.
- the remote monitoring platform 1 also comprises means for establishing a call that establishes a communication between the remote monitoring platform 1 and the local monitoring entity 4 when the data analysis by the analysis means of the platform monitoring 1 has led to detect an anomaly at the level of the local monitoring entity 4.
- the means for receiving data and the means for sending a request by the remote monitoring platform 1 may be software modules forming a computer program.
- the invention therefore also relates to a computer program comprising software instructions for executing data reception and sending a request operations when these operations are performed by the remote monitoring platform 1.
- the means of data analysis by the remote monitoring platform 1 may be software modules forming a computer program.
- the invention therefore also relates to a computer program comprising software instructions for the execution of the data analysis operations when these operations are carried out by the remote monitoring platform 1.
- the means of establishing a communication by the remote monitoring platform 1 may be software modules forming a computer program.
- the invention therefore also relates to a computer program comprising software instructions for carrying out the establishment of a communication operations when these operations are performed by the remote monitoring platform 1.
- the software modules can be stored in or transmitted by a data carrier.
- a data carrier This may be a hardware storage medium, for example a CD-ROM, a magnetic diskette or a hard disk, or a transmissible medium such as an electrical signal, optical or radio.
Landscapes
- Engineering & Computer Science (AREA)
- Signal Processing (AREA)
- Automation & Control Theory (AREA)
- Computer Networks & Wireless Communication (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Small-Scale Networks (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR0756219 | 2007-07-02 | ||
| PCT/FR2008/051208 WO2009010669A2 (fr) | 2007-07-02 | 2008-06-30 | Procédé de télésurveillance d'une pluralité de réseaux locaux, a travers un réseau de communication externe |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP2165462A2 true EP2165462A2 (fr) | 2010-03-24 |
Family
ID=40260139
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP08826356A Withdrawn EP2165462A2 (fr) | 2007-07-02 | 2008-06-30 | Procédé de télésurveillance d'une pluralité de réseaux locaux, a travers un réseau de communication externe |
Country Status (2)
| Country | Link |
|---|---|
| EP (1) | EP2165462A2 (fr) |
| WO (1) | WO2009010669A2 (fr) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN111541791A (zh) * | 2020-03-16 | 2020-08-14 | 武汉猎鹰网安科技有限公司 | 网络安全中平台的流量压力测试系统 |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6108782A (en) * | 1996-12-13 | 2000-08-22 | 3Com Corporation | Distributed remote monitoring (dRMON) for networks |
| US20030174070A1 (en) * | 2002-03-13 | 2003-09-18 | Garrod J. Kelly | Wireless supervisory control and data acquisition |
| KR100600734B1 (ko) * | 2004-02-25 | 2006-07-14 | 엘지전자 주식회사 | 홈네트워크 시스템 및 그 제어 방법 |
-
2008
- 2008-06-30 WO PCT/FR2008/051208 patent/WO2009010669A2/fr not_active Ceased
- 2008-06-30 EP EP08826356A patent/EP2165462A2/fr not_active Withdrawn
Non-Patent Citations (1)
| Title |
|---|
| BROADBAND FORUM: "TR-069 CPE WAN Management Protocol v1.1 Issue 1 Amentment 1", BROADBAND FORUM TECHNICAL REPORT,, no. ISSUE 1 AMENDMENT 1, 30 November 2006 (2006-11-30), pages 1 - 138, XP002550467 * |
Also Published As
| Publication number | Publication date |
|---|---|
| WO2009010669A2 (fr) | 2009-01-22 |
| WO2009010669A3 (fr) | 2009-06-25 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12200001B2 (en) | Behavior based profiling | |
| US10771396B2 (en) | Communications network failure detection and remediation | |
| US11171875B2 (en) | Systems and methods of communications network failure detection and remediation utilizing link probes | |
| US9736174B2 (en) | Method and apparatus for machine to machine network security monitoring in a communications network | |
| US8626210B2 (en) | Methods, systems, and products for security systems | |
| US20070090944A1 (en) | Home-monitoring system | |
| US7441429B1 (en) | SIP-based VoIP traffic behavior profiling | |
| US11722378B2 (en) | Internet of things management through self-describing objects | |
| US8937658B2 (en) | Methods, systems, and products for security services | |
| FR2868643A1 (fr) | Methode de decouverte d'appareils connectes a un reseau ip et appareil implementant la methode | |
| EP3917108A1 (fr) | Procede de configuration d'un equipement pare-feu dans un reseau de communication, procede de mise a jour d'une configuration d'un equipement pare-feu, dispositif, equipement d'acces, equipement pare-feu et programmes d'ordinateur correspondants | |
| KR100947211B1 (ko) | 능동형 보안 감사 시스템 | |
| JP4570652B2 (ja) | 不正アクセス監視装置およびその方法 | |
| NO313067B1 (no) | Arrangement og styrer ved overvåkning | |
| EP2165462A2 (fr) | Procédé de télésurveillance d'une pluralité de réseaux locaux, a travers un réseau de communication externe | |
| FR3024809A1 (fr) | Dispositif domotique a liaison de communication alternative avec un serveur informatique distant | |
| WO2009138721A2 (fr) | Gestion de caméras en réseau | |
| EP2883341A1 (fr) | Dispositif et procede de mise a disposition de services dans un reseau de communication | |
| FR3105486A1 (fr) | Procédé de détection d’un comportement malveillant dans un réseau de communication, dispositif, équipement d’accès audit réseau, procédé de détection d’une attaque distribuée dans ledit réseau, dispositif, équipement nœud et programmes d’ordinateur correspondants | |
| JP2008538470A (ja) | 未承諾の音声情報の送信に対抗する方法 | |
| EP3510713A1 (fr) | Procede de detection de reemission d'une trame | |
| US12407705B1 (en) | Prediction of network vulnerability of a user's network-connected smart device using crowdsourced vulnerability profiles | |
| US20190158312A1 (en) | VoIP Countersurveillance System | |
| US12301608B1 (en) | Identification of one or more services for a user's network-connected smart device using a smart device fingerprint of the network-connected smart device | |
| Chan et al. | Analyzing Internet Background Radiation with Reflective Network Telescopes |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20100126 |
|
| AK | Designated contracting states |
Kind code of ref document: A2 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MT NL NO PL PT RO SE SI SK TR |
|
| AX | Request for extension of the european patent |
Extension state: AL BA MK RS |
|
| 17Q | First examination report despatched |
Effective date: 20100624 |
|
| DAX | Request for extension of the european patent (deleted) | ||
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| RIC1 | Information provided on ipc code assigned before grant |
Ipc: H04L 12/28 20060101AFI20130111BHEP Ipc: H04M 11/00 20060101ALI20130111BHEP |
|
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: ORANGE |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20130618 |