TW201105065A - IP network information error checking and analyzing system - Google Patents

IP network information error checking and analyzing system Download PDF

Info

Publication number
TW201105065A
TW201105065A TW98125298A TW98125298A TW201105065A TW 201105065 A TW201105065 A TW 201105065A TW 98125298 A TW98125298 A TW 98125298A TW 98125298 A TW98125298 A TW 98125298A TW 201105065 A TW201105065 A TW 201105065A
Authority
TW
Taiwan
Prior art keywords
network
traffic
analysis
information
module
Prior art date
Application number
TW98125298A
Other languages
Chinese (zh)
Other versions
TWI389504B (en
Inventor
Yi Xiao
jing-li Liu
Wei-Ting Lin
Zheng-Ru You
Original Assignee
Chunghwa Telecom Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Chunghwa Telecom Co Ltd filed Critical Chunghwa Telecom Co Ltd
Priority to TW98125298A priority Critical patent/TWI389504B/en
Publication of TW201105065A publication Critical patent/TW201105065A/en
Application granted granted Critical
Publication of TWI389504B publication Critical patent/TWI389504B/en

Links

Abstract

An Internet protocol (IP) network information error checking and analyzing system includes two sub-systems, which are a distributed probe (DP) and a server host group, respectively responsible for the functions of collection and detection of information between any two nodes in the network, deep analysis and man-machine interface. The distributed probe (DP) is constructed on various nodes of each IP backbone. The server host group is connected to one of the nodes of the IP backbone network via network, thereby achieving the function of centrally controlling, managing and analyzing the information of each IP backbone network. The server host group includes: a website server, a database server, a real-time information duplication system (RIDS), an information analyzing apparatus module and a reporting form server module. The present invention makes use of the cloud computing architecture, so that, when being collected by distributed probe (DP) sub-system and introduced into the RIDS apparatus, the IP network information can be further introduced into various information analyzing apparatus modules for respectively analyzing and detecting information data, such asP2P (Peer-to-Peer) information, DDoS (Distributed Denial of Service) attack, VoIP (Voice over Internet Protocol) information, L7 (layer 7) communication protocol and information QoS (Quality of Service), in real time.

Description

201105065 六、發明說明: 【發明所屬之技術領域】 本發明係關於-種IP網路訊務查錯與分析线,特別為一種運用 Cloud Computing架構達成集令控管與分析各jp骨幹網路的訊務之功能。 【先前技術】 目前傳統_路的訊務查錯與分析,主要使用aiem Se而模式,需 要各種不@雜的Client設触搭@&之Sefvei·。其缺錢雜要5種以上訊 務查錯與分析功能,每個模組再有配合5種以上軟體執行即需要Μ種以 上client訊務送至25個以上Server上,現階段若不整合,則屬不可行之模 式。 本案發明人鑑於上述制技術所触之各項缺點,乃亟思加以改良創 新,並經多年苦心孤言旨潛心研究後,終於成功研發完成本案ιρ網路訊務查 錯與分析錢。係湘ClGud CGmputing的「分散枝算」(&滅糾 mputmg)概念’將龐大運算作業拆成千百她小作業,在相 '多部飼 服器上同時動作。 【發明内容】 、本發明目的是在提供IP網路訊務分散式佈點、集中管控錢務查錯盘 分析系統,能夠分別針對P2P訊務、DD()S攻擊、驗訊務、U通訊協定^ 與訊務QoS等贿㈣作個聊時分析與檢測。 可達成上秘明目狀IP網_務查顺分析魏,此魏包含分散 式探測器(DP)翻服器主機群等兩大子錢所組成。傭器主機群包含 201105065 網站舰ϋ、f料庫舰$、即_瞒複製魏概器(RIDS)、訊務分析 設備模組與報表舰器模組。即時訊務複製重現键器(rids)與訊務分 析設備模組,運用Cloud Computing的架構,# jp網職務*分散式探測 器(DP)子系統收集,並導入咖5設備後,可進一步導入多種訊務分析 設備模組,分別能夠針對P2P贿、DD〇s攻擊、營訊務、L7通訊協定、 與訊務QoS _务資料作個別即時分析與檢測。每一模組之分析設備分別 疋由3 5台不同的訊務分析設備組成;將訊務資料分析過後,分別傳送到 各模組之專用報表伺服器。針對5種不同的訊務分析,使用不_訊務分 析設備模組’搭配模組化㈣處觀務之倾⑺種)進行訊務查錯與分 析。 【實施方式】 >閱圖為本發明1p網路訊務查錯與分析系統之系統架構圖,由 圖中可知,本發明是由分散式探· (Dp) U油㈣主麟U等兩大 子系統所組成,分別負責網路上各個節點之間訊務的錢檢測深層分析 與人機界轉功能。其巾分散式_器(Dp) u絲設於各IP骨幹網路(正 backbone)上各㈣點’蝴m麟12則透過網料㈣骨幹網路上 的其中個即點’ ^成集中控管與分析各ιρ骨幹網路的訊務之功能。 θ之刀月欠式探測器u,在硬體部分需採用與一般商用pc架構同 等之擴充穩疋度須更為可靠,足以應付長時間不停機工作要求之電腦 平台;妹體部分需採用具有操作穩定、_允許多人多工上線與相對比 較不耗資源的作辈 '' 目剮分散式探測器11主要的功能為即時網路訊務 皿!’、操取H通常纽胁_的麟路由器㈤ge r。咖)或客 201105065 戶終端(CustomerEnd),透過路由(或交換)器的複製埠(Mirr〇rp〇rt)或 網路分接器(Tap)來達到訊務擷取與監測之目的。201105065 VI. Description of the Invention: [Technical Fields of the Invention] The present invention relates to an IP network traffic error detection and analysis line, in particular to a cloud computing architecture to achieve collective control and analysis of various jp backbone networks. The function of the service. [Prior Art] At present, the traditional _ road traffic error detection and analysis, mainly using aiem Se mode, requires a variety of non-complex client settings to touch @& Sefvei. It lacks more than 5 kinds of traffic troubleshooting and analysis functions. Each module can be sent to more than 25 servers with more than 5 software implementations. If it is not integrated at this stage, It is not a viable model. In view of the shortcomings of the above-mentioned system technology, the inventor of the present invention has improved and innovated, and after years of painstaking research, he finally succeeded in research and development and completed the investigation and analysis of the money. Xiang Xiang ClGud CGmputing's "Distributed Branch" (& mumpmg) concept has taken a huge computational work into thousands of her small assignments, and simultaneously operated on the phase 'multiple feeders. SUMMARY OF THE INVENTION The purpose of the present invention is to provide an IP network traffic distributed arrangement, centralized control and money checking and disc analysis system, which can respectively target P2P communication, DD () S attack, verification service, U communication protocol. ^ Analysis and testing when discussing bribes (4) with QoS. Can achieve the secret IP network _ _ _ _ analysis of Wei, this Wei contains a distributed detector (DP) overturned host group and other two major money. The servant host group includes 201105065 website ship f, f library ship $, ie _瞒 copy Wei general device (RIDS), traffic analysis device module and report ship module. Instant messaging replication replays (rids) and traffic analysis device modules, using Cloud Computing architecture, #jpnet job* decentralized detector (DP) subsystem collection, and importing coffee 5 devices, further Import a variety of traffic analysis device modules, which can be used for individual analysis and detection of P2P bribes, DD〇s attacks, camping services, L7 communication protocols, and traffic QoS data. The analysis equipment of each module is composed of 35 different traffic analysis devices; after analyzing the traffic data, it is transmitted to the dedicated report server of each module. For five different traffic analysis, use the non-traffic analysis device module ‘with the modular (4) view of the service (7) for traffic troubleshooting and analysis. [Embodiment] > Reading is a system architecture diagram of the 1p network traffic error detection and analysis system of the present invention. As can be seen from the figure, the present invention is composed of a distributed probe (Dp) U oil (four) main Lin U and the like. The large subsystems are responsible for the deep analysis of the money detection and the human-machine boundary function of the communication between the nodes on the network. The towel dispersing _ device (Dp) u wire is set on each IP backbone network (positive backbone) at each (four) point 'butter m lin 12 through the net material (four) one of the backbone network 'points' into a centralized control And the function of analyzing the traffic of each ιρ backbone network. The θ 刀 月 月 detector u, in the hardware part, needs to be the same as the general commercial pc architecture, the expansion stability must be more reliable, enough to meet the long-term non-stop work requirements of the computer platform; the sister part needs to have Stable operation, _ allows multi-person multiplexes to go online and relatively less resource-intensive generations''. The main function of the distributed detector 11 is the instant network server! ', the operation of the usual N threat _ Lin router (five) ge r. Coffee) or customer 201105065 CustomerEnd (CustomerEnd), through the routing (or exchange) copy 埠 (Mirr〇rp〇rt) or network tap (Tap) to achieve the purpose of traffic retrieval and monitoring.

本發明之伺服器主機群12 ’係由網站伺服器13、資科庫伺服器14與 即時訊務複製魏舰H (RIDS) 15、訊務分析設備模組(AS) 16以及報 表伺服器模組17所組成。其中該_舰器13,主要提供人機操作界面以 便檢視分散_· U狀態、奴並㈣碰設備峨讀ιρ鱗訊務之 第四層至第七層資訊。資料庫伺㈣14則貞贿存封包触f料。沿仍Μ 則將資料庫魏器14之封包資料導人多種訊務分析設備模組Μ,能夠 同步的快速分_路訊務並針對制定·絲啟動告警。而報表伺服器模 組17則負責輸出各訊務分析賴模組16最後所產生的檢測結果,包括網 路的各類封包分析報表,内容包含p2p訊務、DD〇s攻擊聊訊務、口 通訊協定、與訊務QoS之分析與查錯等。 請參閱圖二,為本發明„>網路訊務查錯與分析系統之分散式探測器與 伺服器主機群間的功能架構圖,_中可知,其中該分散式探測器η,藉 (Network Monitoringj 資料’並可利用FTP (File T_fer p咖】)協定方式傳回伺服器主機群 12。負責人機界面的_舰器13_rap(Hyp_prepr_)小制 以及Java程式語言來撰寫動態網頁,並利用權 RIDS 15以及訊務分析設備模組16功能之人員、 表資料的人員進行控管。 限管理機制,將具備設定 線上查詢人員以及輸出報 請參閱圖三,為本發明IP網】 丨路訊務查錯與分析系統之主_試模組測 圖,中可知,包含針管理如8 (即是伺職主細)及 201105065 幹娜各節點之分散式探測器11二個部分。其中該針管理系統 集嫩式探·11所轉彻,输咖丨5核心元件產 生複製備瞒紳,並即時分配傳送到各訊務分析賴模組I6加以分 析,並將結果岭分析設備的報她獅Π,回報咖者端,可依 據收到的喃資贼期產生報表。❹卜提供客戶端轉使时介面,可隨 =進入系統觀察網路狀況;該分散式探測器U可即時收集客戶端的IP流 量’並將訊務軸送™s 15核心元件,賴分配至織備模組, 作即時性的網路訊務分析與查錯。 4閱圖四為本發明IP網路訊務查錯與分析系統之孤S與訊務分 析設備模組整合__,由财可知,個㈤C。亭㈣的架構, 其中該訊務分析設備模組16包含p2PAna㈣微儀s An_模組、 alyzer杈組、L7 Protocol Anaiyzer模組及網路Q〇s編㈣模組等5 種刀析模,i,》別針對P2p訊務、DDgS攻擊、替訊務、口通訊協定、 與網路⑽等訊務資料作分析與查錯。每一模組分別是由η台不同的訊 務刀析π備19組成,將訊務資料分析過後,分別傳送到各模組之專用報表 伺服器20。本發明可針對不同的訊務,使用不同的訊務分析設備,予以即 ^處理分析。當網路訊務產生異敎_,能夠針對各雜進行同步 刀析並偵綱題的所在,並傳送警告訊息至報表销mG,可幫助使用者 在不同的錢與不同的網路條件τ,酬應雌式的效能。當報表伺服器 0接收到超過網路安全臨界標準值時,便即時傳送異常回報資訊至網管中 〇 本發明之訊務分析設備模組16,包含p2p Analyzer模組、DD沾 201105065The server host group 12' of the present invention is composed of a website server 13, a sine server 14 and an instant message copy Wei ship H (RIDS) 15, a traffic analysis device module (AS) 16 and a report server module. Group 17 consists of. Among them, the _the ship 13 mainly provides a man-machine operation interface to view the scattered _· U state, the slave (4) touch device, and the fourth layer to the seventh layer information of the ιρ scale message. The database is (four) 14 and the bribes are stored in the package. Along the still, the packet data of the database Wei 14 is introduced into a plurality of traffic analysis device modules, which can synchronously divide the traffic and generate alarms for the development of the wire. The report server module 17 is responsible for outputting the final detection result generated by each traffic analysis module 16, including various packet analysis reports of the network, including p2p communication, DD〇s attack chat service, and port. Communication protocols, analysis and troubleshooting of traffic QoS. Please refer to FIG. 2 , which is a functional architecture diagram of the decentralized detector and the server host group of the network traffic error detection and analysis system of the present invention, wherein the distributed detector η, The Network Monitoringj data can be transmitted back to the server host group 12 using the FTP (File T_fer p) protocol. It is responsible for the man-machine interface _ship 13_rap (Hyp_prepr_) and the Java programming language to write dynamic web pages and utilize them. The RIDS 15 and the personnel of the traffic analysis equipment module 16 function, the personnel of the table data are controlled. The limited management mechanism will have the set online inquiry personnel and the output report, please refer to Figure 3, which is the IP network of the invention] The main module of the error detection and analysis system, the test module, can be seen, including the needle management such as 8 (that is, the main task) and the 201105065 Ganna node of the distributed detector 11 two parts. The system gathers the tender type 11 and turns it through, and the 5 core components of the coffee crepe are re-prepared, and the instant distribution is transmitted to each traffic analysis module I6 for analysis, and the result of the analysis of the equipment is reported to her. ,return The reporter can generate a report according to the received thief period. The client provides the client transfer interface, and can enter the system to observe the network status; the distributed detector U can collect the client's IP traffic immediately. 'And send the traffic axis to the core components of TMs 15 and distribute it to the weaving module for real-time network traffic analysis and troubleshooting. 4See Figure 4 for IP network traffic troubleshooting and analysis of the present invention. The solitary S of the system is integrated with the traffic analysis device module __, and the structure of the (five) C. kiosk (four), wherein the traffic analysis device module 16 includes a p2PAna (four) micro-meter s An_ module, alyzer 杈 group, L7 Protocol Anaiyzer module and network Q〇s (4) module and other five kinds of knife analysis, i, "Do not target P2p services, DDgS attacks, service, port protocol, and network (10) and other traffic information For analysis and error checking, each module is composed of n different servo blades, and the traffic data is analyzed and transmitted to the dedicated report server 20 of each module. The present invention can be directed to Different traffic, using different traffic analysis devices, to analyze and analyze the network. It can generate different _ _, can be synchronized with each other and analyze the location of the problem, and send a warning message to the report pin mG, which can help users in different money and different network conditions τ, remunerate female When the report server 0 receives the critical value of the network security critical value, it immediately transmits the abnormal return information to the traffic analysis device module 16 of the present invention in the network management, including the p2p Analyzer module, DD dip 201105065

Analyzer 模組 ' VoIP Analyzer 模組、[7 Protocol Analyzer模組及網路 Q〇SAnalyzer Module ' VoIP Analyzer Module, [7 Protocol Analyzer Module and Network Q〇S

Analyzer模_ 5種分析模組,其巾p2p Αη&ι^模組能夠針對w訊務 進仃珠層》析’並且監測網路訊務中的p2p應用程式或p2p祕協議佔用 夕>、頻見不僅幫助管理人貞對整體網路流量的傳輸情況進行了解,也對 訊務進行統計分析。透過聰15,訊射以針定應舰務、特定網路 協定作上鏈路或下鏈路的訊務麵行進一步的p2p深層分析。 而該DDoS Analyzer 4莫組,能夠針對D〇s攻擊的手法,包括tcp (Transmission Control Protocol) Do8 . UDP ( User Datagram Protocol)Analyzer module _ 5 kinds of analysis modules, the towel p2p Αη & ι ^ module can be used to analyze the 'p2p application or p2p secret protocol in the network traffic> Frequently, it not only helps the administrator to understand the transmission of the overall network traffic, but also statistical analysis of the traffic. Through Cong 15, the signal is used to determine the SHIPPING and the specific network protocol for the uplink or downlink of the traffic surface for further p2p deep analysis. The DDoS Analyzer 4 can be used for D〇s attacks, including tcp (Transmission Control Protocol) Do8. UDP (User Datagram Protocol)

Flood DoS 攻擊、DDoS 攻擊、以及 ICMp( Int_t c〇mr〇1 M⑽辟 pr〇_Flood DoS attack, DDoS attack, and ICMp ( Int_t c〇mr〇1 M(10) pr〇_

DoS攻擊等’同步即時監控區域網路中的封包數量是否異常,並配合動態 封包過渡,續達麻禦DgS攻擊的目的。#攻擊發生畴_警告訊息 透過回報伺服器回傳至網路管理者。 A VoIP Analyzer » iUHi SIP( Session Initiation Protocol) > H.232DoS attacks and other 'synchronous real-time monitoring of the number of packets in the regional network is abnormal, and with the dynamic packet transition, the purpose of the Mugget DgS attack is continued. #攻出域_Warning message Returned to the network administrator through the reward server. A VoIP Analyzer » iUHi SIP ( Session Initiation Protocol) > H.232

MGCP (驗Gateway CG咖iPfQt_丨)物_歧彳爾,並可針對MGCP (check Gateway CG coffee iPfQt_丨) _ 彳 彳 尔, and can target

VoIP語音與視蝴汉量㈣。替分析馳__剛進行詳細的 統計分析’ _路維護者可以掌_路巾替通訊的品質。 該L7Pr〇t0colAnalyzer模組,為第七層網路分析工具,利用「深度封 , (Deep Packet Inspection, DPI) , 即時檢測並加以分類;並將鱗的Q()S參數實際透過_、_ _路 效能參數值表現出來,以及結合報表概器2〇達成告警動作;精細的編 數據則會_報表倾摘騎上細奴整、相侧路録。透劍 表的顯示,可以清楚了解網路訊務的程式分布練,讓網路維護扣 201105065 便仏測網崎境的各制題,並且綱未絲娜服務的規辦需要的趨 勢。 該網路QoS Analyzer模組,乃提供網路品質狀況的即時伽,主要針 對封包遺失,傳送延遲,封包傳送順序,以及其他錯誤的㈣監控。例如, 當網路餘而造成傳送延敎幅增加,或者發生封包大量遺失等狀況時, 本刀析核組可以細彳此鋪魏況。本分補_報抽腳如整合後, 可將各類QgS訊息傳送至管理者端,並且在超過異常臨界值之前預先發出 1。可即W握網路的qgS狀態。此外’透過本模組也可以檢視長期的 網路流量@表’進而加时析轉估未來流量的趨勢。 本發明所提供之ip麟訊魅贿分m與其他龍麟相互比 較時,更具備下列優點: 1. 運用本發明之IP網路訊務查錯與分析系統,具有即時檢測功能, 能夠檢視、量測、收集IP網路之穩定性及可靠性等相關數據,作 為目前網路效能檢測、診斷、模擬、以及未來流量成長的預測等 之依據。 2. 本發明之IP網路訊務查錯與分析系統,可提供圯網路各類型檢 測服務,如企業網路安全與效能健檢等。 3. 擷取流經網路上的封包記錄及應用程序的資料交換情形,用來模 擬建構真實網路流量’並加以分析診斷祕層,層間的程序 活動。 4. 自行整合多合一功能的標準型探測器之量測設備(Dp)與即時訊 務複製重現伺服器(RIDS),大幅降低建置服務成本。 201105065 5. 6. 本發明之 a〇ud CGmputing麟實作Ip __分散式佈 集中s控之訊務查錯與分析系統也適用於ip'網路無人機房, 配合網管彡統,_卩_運。也可配合觀咖吻VoIP voice and video volume (four). For the analysis of Chi __ just carried out detailed statistical analysis _ road maintainers can palm _ road towel for the quality of communication. The L7Pr〇t0colAnalyzer module is a Layer 7 network analysis tool that uses “Deep Packet Inspection (DPI), instant detection and classification; and the Q()S parameter of the scale is actually transmitted through _, _ _ The road performance parameter value is displayed, and the alarm action is achieved in combination with the report generalizer 2; the detailed data is _ report dumping on the fine slave, the side road recording. The display of the sword table can clearly understand the network The distribution of the program of the service, let the network maintenance deduction 201105065 will test the various problems of the network, and the trend of the program is not required. The network QoS Analyzer module provides network quality. The status of the real-time gamma, mainly for packet loss, transmission delay, packet transmission order, and other erroneous (four) monitoring. For example, when the network causes the transmission delay to increase, or a large number of packets are lost, this analysis The nuclear group can fine-tune the situation of this shop. After the integration, the various types of QgS messages can be sent to the manager, and before the abnormal threshold is exceeded, the network can be pre-issued. qgS In addition, 'this module can also view the long-term network traffic @表' and then analyze the trend of future traffic.) The ip linxue bribes provided by the present invention are compared with other Longlin. It has the following advantages: 1. Using the IP network traffic error detection and analysis system of the present invention, with instant detection function, capable of viewing, measuring, and collecting related data such as stability and reliability of the IP network, as the current network The basis of road performance detection, diagnosis, simulation, and prediction of future traffic growth. 2. The IP network traffic error detection and analysis system of the present invention can provide various types of network detection services, such as enterprise network security and Performance check, etc. 3. Capture the packet records flowing through the network and the data exchange situation of the application, used to simulate the construction of real network traffic' and analyze the diagnostic secret layer, the program activity between the layers. The measurement device (Dp) and the Instant Messaging Reproducing Server (RIDS) of the standard detector of the unified function greatly reduce the cost of the installation service. 201105065 5. 6. The a〇ud CGmputing of the present invention麟实作Ip __Distributed cloth Centralized s control traffic error detection and analysis system is also applicable to ip' network unmanned computer room, with network management system, _ _ _ transport. Also can match the view of the kiss

Operating Center)魏’達_路訊務即時分析與查錯。 本發明可分別針對P2P訊務、DDqS攻擊、替訊務、U通訊 協定、與訊務⑽等訊務資料作__分析與檢測。Operating Center) Wei's _ road traffic analysis and troubleshooting. The invention can separately analyze and detect the traffic data such as P2P communication, DDqS attack, relay service, U communication protocol, and traffic (10).

上列詳細說明係針對本發明之一可行實施例之具體說明,惟該實施例 並非用以關本㈣之專利細,凡未麟本發藝精神所為之等效實 施或變更’均應包含於本案之專利範圍中。 所述本案不但在技術思想上確屬創新,並能較習用物品增進上 述多項功效’應以充分符合新紐及進步性之法定發明專利要件,麦依法 提出申請’騎树料物帛,糊_,康便。 【圖式簡單說明】 • _一為本發明正網路訊務查錯與分析系統之系統架麵; 圖二為職網路訊務查錯與分析系統之分散式探測器與舰器主機群 間的功能架構圖; 圖三為該1p晴1瞒查錯與分析錢之主_試測試架構圖; 圖為《亥IP鹏β瞒查錯與分析系統之即時訊務複製重現飼服器與訊 務分析設備整合測試架構圖。 【主要元件符號說明】 11分散式探測器 201105065 12伺服器主機群 13網站伺服器 14資料庫伺服器 15即時訊務複製重現伺服器 16訊務分析設備模組 17報表伺服器模組 18集中管理系統 19訊務分析設備 20報表伺服器The detailed description above is a detailed description of one of the possible embodiments of the present invention, but the embodiment is not intended to be used in the context of the patent (b), and the equivalent implementation or modification of the spirit of the present invention should be included in The patent scope of this case. The case is not only innovative in terms of technical thinking, but also able to enhance the above-mentioned multiple functions compared with conventional articles. 'It should be in full compliance with the new and progressive statutory invention patents, and Mai applied to apply for 'ride tree materials, paste _ Kang will be. [Simple diagram of the diagram] • _1 is the system frame of the positive network traffic error detection and analysis system of the present invention; Figure 2 is the distributed detector and the host group of the network communication error detection and analysis system. The functional architecture diagram between the two; Figure 3 is the 1p clear 1 瞒 check and analysis of the main _ test structure diagram of the money; The picture shows the "Hi IP 瞒 瞒 瞒 瞒 与 与 与 与 与 即时 即时 即时 即时 即时 即时Integrate the test architecture diagram with the traffic analysis device. [Main component symbol description] 11 distributed detector 201105065 12 server host group 13 website server 14 database server 15 instant message replication reproduction server 16 traffic analysis device module 17 report server module 18 centralized Management system 19 traffic analysis device 20 report server

Claims (1)

201105065 七、申請專利範圍: 1· 一種1p網路訊務查錯與分析系統,至少包含: 一分散式探測器⑽ributed Probe,DP)子系統,包含複數個分散式 探測器,分別架設於各IP骨幹網路(IPbackb〇ne)上各㈣點主要 係負責網路上糊節點之間訊務·集檢測、深層分析與人機界面等 功能; ,站魏H ’提供人機猶界面,讀視分散編齡態、設定 並控制整體設備以分析IP網路訊務資料; 一資料庫健器’藉由網站舰器連接IP骨幹網路上的其中一個節 占,以储存分散式探測器擷取之訊務資料; ’時訊務複製重現伺㈣(刪),將f料庫健㈣存之訊務資 料產生複製備份資料’麟時分轉送到各簡分析設備模組; ^訊務分析設備·,包含不_務諸的分析設備,與即時訊務201105065 VII. Patent application scope: 1. A 1p network traffic error detection and analysis system, comprising at least: a distributed detector (10) ributed probe, DP) subsystem, comprising a plurality of distributed detectors, respectively erected on each IP The (4) points on the backbone network (IPbackb〇ne) are mainly responsible for the functions of traffic, set detection, deep analysis and human-machine interface between the paste nodes on the network; the station Wei H' provides the human-machine interface, and the reading is scattered. Ageing, setting and controlling the overall device to analyze IP network traffic data; a database health device's connection to one of the nodes on the IP backbone network by the website ship to store the scattered detectors Business information; 'Time communication copy reproduces (4) (deleted), f material library health (four) stored information data to generate copy backup data 'Lin time points transferred to each analysis device module; ^ traffic analysis equipment · , including not-to-do analysis devices, and instant messaging 2. 製重現伺服器以cloud computing的架構連接可個別即時分析與 測不同的訊務資料; —報表伺腳,包含分概接訊務分析設職组之各分析設備 報表輸出設備,可分別輸出不同的訊務資料之分析與查錯報表。 如申請專利範圍第i項所述之IP網路訊務查錯與分析系統,其中該 散式探測II子系統,魏置於鱗的邊緣路由器(Edge ^ 戶終端伽_Γ叫透過路由(或交換)器的嬉㈤贿加 或網路分接器(Tap)來達到訊務擷取與監敬目的,並可利用 協定方式將收集到之即時網路聰料傳吻庫伺服器錯存。 11 201105065 3·如申請專利範圍第丄項所述之IP網給瞒查錯與分析系統,其中該訊 務分析設備辦且,分析之訊務資料,可包含p2p訊務、DD〇s攻擊、 VoIP訊務、L7通訊協定、與網路qoS等訊務資料。 4·如申請專利範圍第w所述之^網路訊務查錯與分析系統其中該訊 務分析设備模組之分析設備’可包含P2P Analyzer模組、DD〇s A响⑽ 模組、VoIP AnaiyZer 模組、L7 Protocol Analyzer 模組、與網路 Q〇s Analyzer模組等分析設備。 5. 如申請專利範圍第4項所狀m網路訊務查錯與分析系統,其中該 P2P Analyzer模組,可監測網路訊務中的p2p應用程式或p2p網路協 議佔用多少頻寬,以及透過RIDS,可以針對特定顧服務、特定網路 協定作上鏈路或下鏈路的訊務P2P深層分析。 6. 如申請專利範圍第4項所述之IP網路訊務查錯與分析系統,其中該 DDoS Analyzer模組,可以透過分析設備上多個網路監控程式,同步即 時監控區域網路中的封包數量是否異常,並配合動態封包過濾功能, 來防禦DoS的攻擊。 7_如申請專利範圍第6項所述之π>網路訊務查錯與分析系統,其中該 DoS 攻擊可包括 TCP (Transmission Control Protocol) DoS 攻擊、UDP (User Datagram Protocol) Flood DoS 攻擊、DDoS 攻擊、以及 ICMP (Internet Control Message Protocol) DoS 攻擊等。 8.如申請專利範圍第4項所述之IP網路訊務查錯與分析系統,其中該 VoIP Analyzer模組’可針對SIP、H.232、MGCp等多種協定進行分析, 以及對VoIP語音與視訊進行定量測量。 12 201105065 9·如申請專利範圍第4項所述之IP網路訊務查錯與分析系統,其中該 L7 Protocol Analyzer模組’係利用深度封包檢測(Dpi)技術針對欲分 析之網路流量,執行即時檢測並加以分類;能夠將網路的Q〇s參數實 際透過Dday、Jitter等網路效能參數值表現出來,以清楚了綱路訊 務的應用程式分布狀態。 1 〇·如中請專利細第4項所述之IP網路訊務查錯與分析系統,其中該網 路QOS偏yzer模組,係提供網路品質狀況的即時侧功能,主要係 針對封包遺失,傳送延遲,封包傳送鱗,以及其他錯誤來即時監控, 可即時掌握網路的QoS狀態。 二 132. The re-creation server is connected to the cloud computing architecture to analyze and measure different traffic data in a timely manner; - the report server, including the analysis device report output device of the service analysis group. Output analysis and error reporting of different traffic data. For example, the IP network traffic error detection and analysis system described in claim i, wherein the scattered detection II subsystem, Wei placed on the scale edge router (Edge ^ terminal gamma Γ 透过 through routing (or The exchange of the device (5) bribes or network taps (Tap) to achieve the purpose of traffic capture and homage, and the use of the agreement to collect the instant network of cheats to kiss the library server. 11 201105065 3. The IP network for error detection and analysis system as described in the scope of the patent application scope, wherein the traffic analysis device can analyze and analyze the traffic information, which may include p2p traffic, DD〇s attacks, VoIP services, L7 communication protocols, and network qoS and other traffic information. 4. The network traffic error detection and analysis system described in Patent Application No. w, wherein the analysis device of the traffic analysis device module 'Can include P2P Analyzer module, DD〇s A ring (10) module, VoIP AnaiyZer module, L7 Protocol Analyzer module, and network Q〇s Analyzer module. 5. If you apply for patent scope 4 M network traffic error detection and analysis system, wherein the P2P Analyzer module It can monitor the bandwidth of the p2p application or the p2p network protocol in the network traffic, and the deep P2P analysis of the traffic on the uplink or the downlink for specific services and specific network protocols through RIDS. 6. The IP network traffic error detection and analysis system described in claim 4, wherein the DDoS Analyzer module can synchronize the real-time monitoring area network by analyzing multiple network monitoring programs on the device. Whether the number of packets is abnormal and cooperates with the dynamic packet filtering function to defend against DoS attacks. 7_ As described in claim 6 of the scope of the patent, the network traffic error detection and analysis system, wherein the DoS attack may include TCP (Transmission Control Protocol) DoS attack, UDP (User Datagram Protocol) Flood DoS attack, DDoS attack, and ICMP (Internet Control Message Protocol) DoS attack, etc. 8. IP network traffic as described in claim 4 Error detection and analysis system, where the VoIP Analyzer module can analyze various protocols such as SIP, H.232, MGCp, and quantitatively measure VoIP voice and video. 12 201105065 9 · The IP network traffic error detection and analysis system described in claim 4, wherein the L7 Protocol Analyzer module utilizes deep packet inspection (Dpi) technology for network traffic to be analyzed. Perform real-time detection and classification; the Q〇s parameters of the network can be actually expressed through the network performance parameter values such as Dday and Jitter, so as to clear the distribution status of the application of the road traffic. 1 〇 · The IP network traffic error detection and analysis system described in the fourth paragraph of the patent, wherein the network QOS partial yzer module provides the instant side function of the network quality status, mainly for the packet Loss, transmission delay, packet transmission scale, and other errors for immediate monitoring, instant access to the QoS status of the network. Two 13
TW98125298A 2009-07-28 2009-07-28 IP network traffic error detection and analysis system TWI389504B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW98125298A TWI389504B (en) 2009-07-28 2009-07-28 IP network traffic error detection and analysis system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW98125298A TWI389504B (en) 2009-07-28 2009-07-28 IP network traffic error detection and analysis system

Publications (2)

Publication Number Publication Date
TW201105065A true TW201105065A (en) 2011-02-01
TWI389504B TWI389504B (en) 2013-03-11

Family

ID=44813867

Family Applications (1)

Application Number Title Priority Date Filing Date
TW98125298A TWI389504B (en) 2009-07-28 2009-07-28 IP network traffic error detection and analysis system

Country Status (1)

Country Link
TW (1) TWI389504B (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI457774B (en) * 2012-06-08 2014-10-21
TWI466494B (en) * 2012-07-02 2014-12-21
TWI473468B (en) * 2012-06-06 2015-02-11

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI473468B (en) * 2012-06-06 2015-02-11
TWI457774B (en) * 2012-06-08 2014-10-21
TWI466494B (en) * 2012-07-02 2014-12-21

Also Published As

Publication number Publication date
TWI389504B (en) 2013-03-11

Similar Documents

Publication Publication Date Title
US11601356B2 (en) Emulating packet flows to assess network links for SD-WAN
US20160337200A1 (en) Method and Apparatus for Visualized Network Operation and Maintenance
US7804787B2 (en) Methods and apparatus for analyzing and management of application traffic on networks
TWI361595B (en) Pool-based network diagnostic systems and methods
US20080177874A1 (en) Method and System for Visualizing Network Performance Characteristics
US20070171827A1 (en) Network flow analysis method and system
KR20020089400A (en) Server monitoring using virtual points of presence
CN107295010A (en) A kind of enterprise network security management cloud service platform system and its implementation
CN105471620A (en) Broadband intelligent terminal embedded network analysis and diagnosis device and method thereof
US20150012647A1 (en) Router-based end-user performance monitoring
CN112333020A (en) Network security monitoring and data message analyzing system based on quintuple
CN105530137B (en) Data on flows analysis method and data on flows analysis system
TW201105065A (en) IP network information error checking and analyzing system
CN107168844A (en) A kind of method and device of performance monitoring
Sperotto et al. Anomaly characterization in flow-based traffic time series
CN105025006B (en) A kind of positive information safety operation and maintenance platform
TW201038009A (en) Real-time traffic measurement system of IP network centralized network management and distributed nodes
TW200924428A (en) An inside tracing method of the network attacking detection
JP2004193816A (en) Network evaluation system
Viipuri Traffic analysis and modeling of IP core networks
Eittenberger et al. Atheris: A First Step Towards a Uni? ed Peer-to-Peer Traf? c Measurement Framework
CN108566288A (en) A kind of computer network cloud activation system
Deng et al. Measuring broadband performance using M-Lab: Why averages tell a poor tale
Zseby et al. Packet tracking in planetlab europe–a use case
Shawky et al. Characterization and modeling of network traffic

Legal Events

Date Code Title Description
MM4A Annulment or lapse of patent due to non-payment of fees