WO2012106861A1 - 终端分布信息获取方法、数据获取装置以及通信系统 - Google Patents

终端分布信息获取方法、数据获取装置以及通信系统 Download PDF

Info

Publication number
WO2012106861A1
WO2012106861A1 PCT/CN2011/076762 CN2011076762W WO2012106861A1 WO 2012106861 A1 WO2012106861 A1 WO 2012106861A1 CN 2011076762 W CN2011076762 W CN 2011076762W WO 2012106861 A1 WO2012106861 A1 WO 2012106861A1
Authority
WO
WIPO (PCT)
Prior art keywords
data
terminal
protocol
type
data packet
Prior art date
Application number
PCT/CN2011/076762
Other languages
English (en)
French (fr)
Inventor
布丕⋅库马尔⋅杰恩
王绍宇
陈飞
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to PCT/CN2011/076762 priority Critical patent/WO2012106861A1/zh
Priority to CN2011800015266A priority patent/CN102301764A/zh
Publication of WO2012106861A1 publication Critical patent/WO2012106861A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/18Protocol analysers
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0227Filtering policies
    • H04L63/0245Filtering by information in the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W24/00Supervisory, monitoring or testing arrangements
    • H04W24/08Testing, supervising or monitoring using real traffic

Definitions

  • Terminal distribution information acquisition method Terminal distribution information acquisition method, data acquisition device, and communication system
  • the embodiments of the present invention relate to the field of communications technologies, and in particular, to a terminal distribution information acquiring method, a data acquiring device, and a communication system. Background technique
  • DP I Deep Packet Ins pec ti on
  • Ordinary packet detection uses the port number to identify the application type. For example, if the port number is detected as
  • the application is considered to represent a common Internet application.
  • some illegal applications on the current network will use the hidden or fake port number to avoid detection and supervision, and the data stream that causes legitimate packets will erode the network.
  • the ordinary message detection method can't do anything about it.
  • DPI technology is to detect the true application of data packets by detecting the content of data packets in the application stream.
  • the business intelligence (Bus ines s Inte lli gence, hereinafter referred to as BI) technology is a technology that transforms existing data into information and knowledge.
  • the technology is essentially a comprehensive application of data warehousing, online analytical processing and data mining. , can provide enterprises with a real-time data analysis system to help enterprises improve their operational level.
  • the embodiment of the invention provides a terminal distribution information acquisition method, a data acquisition device, a communication system, and a data aggregation device, which are used to improve the statistical efficiency when collecting statistics on terminal distribution information, and improve the accuracy of statistical results.
  • An embodiment of the present invention provides a method for acquiring terminal distribution information, including:
  • the data processing module sends a notification message carrying the protocol parsing data to the data aggregation device, so that the data processing module generates terminal distribution information of each type of terminal according to the protocol parsing data aggregation, where the terminal distribution information includes each type of terminal and its corresponding Traffic statistics for a specific time period.
  • the embodiment of the invention further provides a method for acquiring terminal distribution information, including:
  • a notification message that carries protocol parsing data obtained by parsing the data packet, where the protocol parsing data includes a type identifier of the terminal that sends the data packet, a protocol type of the data packet, and a corresponding Service traffic value of the protocol type;
  • the terminal distribution information of each type of terminal is generated according to the protocol analysis data aggregated by the received data acquisition devices, and the terminal distribution information includes the traffic statistics values of the terminals of the type and the corresponding specific time segments.
  • the embodiment of the invention further provides a data acquisition device, including:
  • a first sending module configured to send a request message carrying a pre-resolved data message to the deep data packet detecting device, where the request message is used to instruct the deep data packet detecting device to perform protocol parsing on the data packet;
  • a first receiving module configured to receive a response message that carries the protocol parsing data returned by the deep packet detecting device, where the protocol parsing data includes a type identifier of a terminal that sends the data packet, and a protocol of the data packet a type and a service traffic value corresponding to the protocol type;
  • a second sending module configured to send, to the data aggregation device, a notification message that carries the protocol parsing data, so that the data processing module aggregates data according to the protocol to generate each type Terminal distribution information of the terminal.
  • the embodiment of the invention further provides a data convergence device, comprising:
  • a second receiving module configured to receive, by the data acquiring device, a notification message that carries the protocol parsing data obtained by parsing the data packet, where the protocol parsing data includes a type identifier of the terminal that sends the data packet, and the data packet The protocol type of the text and the value of the traffic flow corresponding to the protocol type;
  • a second obtaining module configured to generate terminal distribution information of each type of terminal according to the protocol analysis data fed back by each data acquisition device, where the terminal distribution information includes a terminal type and a traffic statistics value in a corresponding specific time period.
  • the embodiment of the invention further provides a communication system comprising a service GRPS support node provided with the above data acquisition device and a business intelligence system provided with the above data aggregation device.
  • the terminal distribution information acquisition method, the data aggregation device, the data acquisition device, and the communication system provided by the foregoing embodiment of the present invention wherein the data acquisition device sends the data message sent by the terminal to the server to the DPI device for protocol analysis, to obtain The type identifier of the terminal that sends the data packet, the protocol type of the data packet, and the service traffic value, etc., by further transmitting the above information to the data aggregation device for aggregation, the types of terminals and their corresponding specificities can be statistically obtained.
  • the traffic statistics in the time period can improve the statistics of the terminal distribution information. The statistical efficiency, while improving the accuracy of statistical results.
  • FIG. 1 is a schematic flowchart of Embodiment 1 of a method for acquiring terminal segment information according to the present invention
  • FIG. 2 is a schematic flowchart of a specific embodiment of the present invention
  • FIG. 3 is a schematic structural diagram of a DPI device according to an embodiment of the present invention.
  • FIG. 5 is a schematic structural diagram of an IMS I according to an embodiment of the present invention.
  • FIG. 6 is a schematic structural diagram of an IME I according to an embodiment of the present invention.
  • FIG. 7 is a schematic flowchart of Embodiment 2 of a method for acquiring terminal distribution information according to the present invention
  • FIG. 8 is a schematic diagram of data aggregation in an embodiment of the present invention
  • FIG. 9 is a schematic structural diagram of an embodiment of a data acquisition apparatus according to the present invention.
  • FIG. 10 is a schematic structural diagram of an embodiment of a data convergence device according to the present invention. detailed description
  • the embodiment of the invention provides a technical solution for acquiring terminal distribution information, and specifically, the data acquisition device and the deep data packet detection device in the communication system can be obtained in real time.
  • the type of the terminal and the size of the corresponding service data stream may be that the device is served on the gateway serving GPRS node GGSN, and then sent to the data aggregation device, and the terminal information is obtained by the data aggregation device.
  • 1 is a schematic flowchart of Embodiment 1 of a method for acquiring terminal segment information according to the present invention. As shown in FIG. 1, the method includes the following steps:
  • Step 101 Deep Packet Inspection (hereinafter referred to as:
  • the DPI is configured to send a request message carrying a pre-resolved data message, where the request message is used to indicate that the DPI device performs protocol parsing on the IP data packet;
  • Step 102 Receive a response message carrying the protocol parsing data returned by the DPI device, where the protocol parsing data includes a type identifier of a terminal that sends the data packet, a protocol type of the data packet, and a corresponding protocol type.
  • the protocol parsing data includes a type identifier of a terminal that sends the data packet, a protocol type of the data packet, and a corresponding protocol type.
  • Business traffic value
  • Step 103 Send a notification message carrying the protocol parsing data to the data aggregation device, so that the data convergence device generates terminal distribution information of each type of terminal according to the protocol parsing data aggregation, where the terminal distribution information includes each type of terminal. And the corresponding traffic statistics in a specific time period.
  • the steps in the foregoing embodiment of the present invention may be specifically performed by a data acquiring device that is configured in the GGSN, and the data acquiring device sends the data packet sent by the terminal to the server to the DPI device for protocol parsing to obtain the data.
  • the type identifier of the terminal of the packet, the protocol type of the data packet, and the service traffic value, etc. by further transmitting the above information to the data aggregation device for aggregation, the various types of terminals and their corresponding specific time segments can be statistically obtained.
  • a complete data packet generated according to the protocol may be divided into multiple data packets, that is, the pre-resolved data packet may be a complete data packet, or Complete data message.
  • the protocol data can be parsed by the deep packet inspection device, and the data packet is a non-complete data packet.
  • the packet can be sent to the DPI device at least twice.
  • a pre-resolved request message for a non-complete data message, and step 102 may be receiving The protocol parsing data obtained by parsing the at least two non-integrity data packets returned by the DPI device.
  • the DPI device In the case of parsing the incomplete data packet, the DPI device detects and obtains the partial protocol parsing data, and encapsulates the parsed data into the context information, and the DPI device returns to carry.
  • the foregoing context information and the response response message indicating that the data detection information needs to be performed again the data acquiring device retransmits the request message carrying the incomplete data message, and further carries the foregoing context information, so that the DPI device is based on the newly obtained incomplete data.
  • the message is further parsed by the protocol, and the protocol parsing data obtained twice before is merged until the complete protocol parsing data can be obtained, otherwise the above process will continue to be executed.
  • the type identifier of the terminal may be the device model approval number in the international mobile device identification code
  • the data obtaining device in the step 102 receives the response message of the bearer protocol parsing data returned by the DPI device.
  • the data acquiring device further performs the following steps: Corresponding to the relationship table, obtaining the corresponding mobile terminal model.
  • the protocol parsing data carried in the notification message sent to the data aggregation device includes a mobile terminal model for transmitting the data packet, a protocol type of the data packet, and a service traffic value corresponding to the protocol type.
  • the data packet sent to the DPI device may be a complete data packet or an incomplete data packet.
  • the data packet is a complete data packet.
  • the situation, as shown in Figure 2, includes the following steps:
  • Step 201 The mobile terminal (Mobile Station, hereinafter referred to as MS) sends an IP data packet (for example, IP Packet 1 and IP Packet2) to the server, and the foregoing IP data packet passes through the GGSN, and each IP data packet is matched and matched on the GGSN. Reorganizing, sorting IP packets on a service flow, and filtering the repeated data packets to obtain TCP packets (TCP Packet1 and TCP Packet2). Further, the GGSN is further provided with the above data acquisition device, The data acquisition device will selectively send the request to the DPI device according to the pre-configured rules.
  • IP data packet for example, IP Packet 1 and IP Packet2
  • the request message carries a pre-resolved data packet (TCP data packet), and requests the DPI device to perform the layer 7 protocol parsing.
  • TCP data packet pre-resolved data packet
  • the GGSN may receive two IP data packets each time.
  • the DPI device sends the request message once, and may also set a time period, for example, sending the request message every minute;
  • Step 202 The DPI device (DPI Parser) performs protocol parsing on the received TCP data packet, and first identifies the 7-layer protocol type before parsing, and determines protocol parsing data that needs to be parsed according to the protocol type, and the foregoing protocol parsing data may be Including one or more of the following information, such as International Mobile Subscriber Identification (IMSI), International Mobile Equipment Identifier (IMEI), and protocol class (protocol category: e.g. P2P, VOIP, etc.), protocol type (protocol, e.g.
  • IMSI International Mobile Subscriber Identification
  • IMEI International Mobile Equipment Identifier
  • protocol class protocol category: e.g. P2P, VOIP, etc.
  • protocol type protocol, e.g.
  • the uplink traffic may be specifically for a specific type of terminal, and the uplink traffic may be specific to a specific type of terminal, and the specific traffic may be specific to a specific type of terminal.
  • the DPI device may include an analysis rule library, a preprocessing module, a parsing module, a post processing module, an intermediate state storage module, and a quintuple management module, where the parsing rule library stores parsing rules.
  • the specific parsing rule may be a parsing policy according to different protocol types, and the TCP packets of different protocol types may be parsed.
  • the pre-processing module After receiving the TCP packet encapsulating one or more IP data packets, the pre-processing module obtains the corresponding parsing rule from the parsing protocol rule base, and sends it to the parsing module for parsing, and obtains the parsing result, which is post-processed.
  • Step 203 The GGSN performs corresponding processing on the received protocol parsing data, and sends the processed protocol parsing data to the data converging device in the server.
  • the data converging device may be specific.
  • the processing herein may include
  • the terminal type identifier is a TAC identifier in the IMET.
  • the mobile terminal model is obtained according to the correspondence between the TAC identifier and the mobile terminal model, and is carried in a notification message and sent to the server.
  • the context information involved in the above step may be sent to the DPI device when the DPI device needs to parse the TCP packet of the same service flow again, and release the relevant context information in the memory when the service flow is released.
  • the GGSN determines whether to send the subsequent TCP data packet to the DPI device for parsing according to the result of the parsing and the configuration of the protocol (in a manner of configuration), which may be specifically performed for the configuration rule involved in step 201, for example, FIG. 2 As shown, the GGSN needs to receive the IP packet (IP Packet3), which is not sent to the DPI for parsing, but is sent directly to the server for processing (server).
  • IP Packet3 IP Packet3
  • Step 301 The steps of step 201 are basically the same. The difference is that the TCP packet sent by the GGSN to the DPI device is a non-complete data packet due to the characteristics of the IP fragment.
  • Step 302 The DPI device parses the received incomplete data packet. Because it is an incomplete data packet, the DPI device cannot obtain complete protocol parsing data through one parsing, and the DPI device needs to parse the incomplete data packet. After caching the necessary information, generate context information.
  • Step 303 The DP I device returns a response message to the GGSN, where the response message carries the indication information that needs to continue to send the TCP packet for parsing, and may also use the foregoing context information. Sent to the GGSN. The GGSN will send the previously received IP packets to the server.
  • Step 304 After receiving the subsequent IP data packet (IP Packet3), the GGSN continues to send the converted TCP data packet to the DPI device, and is parsed by the DPI device, and also sends the context information obtained by the last parsing. Give the DPI device.
  • IP Packet3 IP Packet3
  • Step 305 The DPI device parses the received TCP data packet (TCPPacket3), and combines the parsed information with the foregoing context information. If the complete protocol parsing data has been obtained, the parsing result is returned to the GGSN. , indicating that the parsing is successful, and may also return the context information in the embodiment shown in FIG. 2 to refer to when parsing the TCP packet of the same service flow.
  • TCPPacket3 TCP data packet
  • Step 306 The GGSN sends the complete protocol parsing data obtained by the parsing to the data convergence device in the server.
  • the GGSN also sends IP packets (IP Packet1, IP Packet2, and IP Packet3) sent to the DPI device for analysis to the server.
  • the data structure may be as shown in FIG. 5, including a Mobile Country Code (MCC), and a MCC unique identifier for the mobile subscriber country, which is composed of 3 digits;
  • MCC Mobile Country Code
  • MCC unique identifier for the mobile subscriber country, which is composed of 3 digits
  • the GSM PLMN code that identifies the mobile user is composed of 1 or 3 digits
  • the MNC and the MSIN form a National Mobile Subscriber Identity (hereinafter referred to as: Li SI).
  • Li SI National Mobile Subscriber Identity
  • the structure of the IMEI may be as shown in FIG. 6, which includes the device model approval number TAC indicating the model of the mobile terminal device, the factory assembly code FAC indicating the origin of the terminal device, the serial number SNR indicating the production sequence number, and the check code. SP.
  • FIG. 7 is a schematic flowchart of Embodiment 2 of a method for acquiring terminal distribution information according to the present invention. As shown in FIG. 7, the method includes the following steps:
  • Step 401 Receive a notification message that is sent by the data acquiring apparatus and that carries protocol parsing data obtained by parsing the data packet, where the protocol parsing data includes a terminal that sends the data packet. a type identifier, a protocol type of the data packet, and a service traffic value corresponding to the protocol type.
  • Step 402 Generate, according to the received protocol analysis data fed back by each data acquisition device, terminal distribution information of each type of terminal.
  • the terminal distribution information includes traffic statistics of each type of terminal and its corresponding specific time period.
  • the protocol analysis data fed back by the received data acquisition devices is aggregated, and the terminal distribution information of each type of terminal is obtained, that is, the types of terminals and the traffic statistics in the corresponding specific time period are obtained.
  • the value can improve the statistical efficiency of the distribution information of the terminal and provide the accuracy of the statistical results.
  • the type identifier of the terminal in the protocol parsing data may be a TAC code in the IMEI, or may be a mobile terminal model obtained according to the TAC code.
  • the type identifier of the terminal is TAC code, the present It can be converted to a mobile terminal model in an embodiment.
  • the protocol parsing data sent to the data aggregation device may include an IMS I (ie, a mobile phone number) in addition to the type identifier of the terminal, the protocol type of the data packet, and the service traffic value corresponding to the protocol type.
  • IMS I ie, a mobile phone number
  • the above information may be sent to the data collection module DRM of the BI system in the form of a UDP data packet, the module is part of the data aggregation device, and the DRM will receive Convert the UDP packet to a CSV file, which is a plain text used to store data.
  • the full name is English: Comma Separated Va lues, and written on the hard disk.
  • the "local information" and "user details” can also be obtained by the mobile phone number associated with the carrier's internal business support system, and saved to the hard disk as a CSV file.
  • the CSV file parsing component periodically parses and filters the CSV file data into the buffer table (ETL table), and then places the data from the buffer table (ETL table) into the metadata table according to certain requirements by the memory and the ORACLE stored procedure.
  • the BI system ETL (data processing module) module will read the CSV file on the hard disk and insert the record into the corresponding table in the Orac le backend database.
  • Each original record includes traffic statistics (specifically, uplink traffic information and downstream traffic information), through the terminal class. The type is used to group and summarize the records to obtain the total traffic volume of a certain terminal.
  • the metadata table data is aggregated into the aggregation table, and the distribution statistics report based on various dimensions can be formed in the BI system, and the analysis engine (Ana lys is Eng ine) remotely creates and manages the cube Cube according to requirements.
  • the analyst interacts with the reporting system based on various dimensional information through the HTTP interface.
  • the specific generated distribution statistical report can be as follows
  • the system automatically collects data and generates a report.
  • the data is statistically calculated by using a manual method, and the statistical efficiency of the data is high.
  • the data statistics based on the user's real communication consumption record are high, and the embodiment of the present invention can perform statistics based on the minute, hour, day, week, month, or any time granularity period. It is also possible to obtain the geographical location information according to the IMS I identifier, perform statistics on a specific area, or obtain a home user from the network management system, and perform statistics on belonging to the same user.
  • the data is aggregated according to the federated protocol to generate the distribution information of each type of terminal.
  • the specific one may be:
  • the Ha shMap structure is used to aggregate the metadata in the memory, and the file is read and written to the memory at one time for use by all the aggregators, thereby reducing the operation of the disk 10. And improve processing performance.
  • the detailed records under the same type of terminal (termina l ), the same website (webs i te ), or the same user (subscr i ber) in the buffer table may be taken according to certain rules such as a time field.
  • the union, the data field to and the number of detailed records as a number of accesses are summarized into a record and written into the aggregate table.
  • the minute granularity and the hourly granularity of the large amount of data can be aggregated in the memory, and then the data is converted into a CSV file (CSV file) by the CSV Writer (CSV Wr ter), and then the CSV file is passed.
  • the data inbound module (ETL) is forwarded to the database and stored as minute granularity data and hourly granularity data respectively.
  • the above minute granularity data and hourly granularity data can be further aggregated to form sky granularity data and monthly granularity data, the second time.
  • the aggregation process can be implemented in the database.
  • FIG. 9 is a schematic structural diagram of an embodiment of a data acquisition apparatus according to the present invention.
  • the apparatus includes a first sending module 11, a first receiving module 12, and a second sending module 13, wherein the first sending module 11 is configured to
  • the deep data packet detecting apparatus sends a request message carrying a pre-resolved data message, where the request message is used to instruct the deep data packet detecting apparatus to perform protocol parsing on the data packet;
  • the first receiving module 12 is configured to receive the depth a response message carrying the protocol parsing data returned by the packet detecting device, where the protocol parsing data includes a type identifier of the terminal that sends the data packet, a protocol type of the data packet, and a service traffic value corresponding to the protocol type;
  • the second sending module 13 is configured to send a notification message carrying the protocol parsing data to the data aggregation device, so that the data processing module aggregates terminal distribution information of each type of terminal according to the protocol parsing data aggregation.
  • the data obtaining apparatus can send a request message to the deep packet detecting apparatus to parse the data packet to obtain protocol parsing data, where the protocol parsing data includes a terminal that sends the data packet.
  • Type identification the above data message
  • the protocol type and the service traffic value corresponding to the protocol type, and the foregoing protocol parsing data is sent to the data aggregation device for aggregation to obtain the terminal distribution information of each type of terminal, which can improve the statistical efficiency of the terminal distribution information and obtain accurate Higher statistical results.
  • the data obtaining apparatus in the foregoing embodiment of the present invention may further include a first obtaining module 14 configured to: in the type of the terminal, the type of the terminal is an international mobile device identification code, and the mobile terminal model Corresponding relationship table, obtaining a corresponding mobile terminal model; and the protocol parsing data carried in the notification message sent by the second sending module 13 includes a mobile terminal model for transmitting the data packet, a protocol type of the data packet, and a pair The traffic flow value of the protocol type should be.
  • a first obtaining module 14 configured to: in the type of the terminal, the type of the terminal is an international mobile device identification code, and the mobile terminal model Corresponding relationship table, obtaining a corresponding mobile terminal model; and the protocol parsing data carried in the notification message sent by the second sending module 13 includes a mobile terminal model for transmitting the data packet, a protocol type of the data packet, and a pair The traffic flow value of the protocol type should be.
  • the data obtaining apparatus in the above embodiment of the present invention may be disposed in the GGSN, and the deep packet detecting apparatus therein may be set in the GGSN or in a separately set form.
  • FIG. 10 is a schematic structural diagram of an embodiment of a data convergence device according to the present invention.
  • the device includes a second receiving module 21 and a second obtaining module 22, where
  • the receiving module 21 is configured to receive, by the data acquiring device, a notification message that carries the protocol parsing data obtained by parsing the data packet, where the protocol parsing data includes a type identifier of the terminal that sends the data packet, and the data packet
  • the second obtaining module 22 is configured to generate terminal distribution information of each type of terminal according to the protocol analysis data aggregated by each data acquisition device, where the terminal distribution information includes the terminal type And the corresponding traffic statistics in a specific time period.
  • the data aggregation device generates the terminal distribution information according to the protocol analysis data acquired by each data acquisition device, and obtains the terminal distribution information by manually collecting the method in the prior art.
  • the statistical efficiency of the terminal distribution information can also improve the accuracy of the statistical results.
  • An embodiment of the present invention further provides a communication system, where the communication system includes the foregoing number According to the GGSN of the acquisition device and the business intelligence system in which the above data acquisition device is provided.
  • the deep packet detecting device may be disposed in the GGSN; or the deep packet detecting device may be set in the communication network in an independently set manner.

Description

终端分布信息获取方法、 数据获取装置以及通信系统 技术领域
本发明实施例涉及通信技术领域, 尤其涉及一种终端分布信息获取方 法、 数据获取装置以及通信系统。 背景技术
深度数据包检测 (Deep Packet Ins pec t i on , 以下简称: DP I ) 技 术不仅能够如同普通报文检测一样, 分析出 IP数据包中的源地址、 目的 地址、 源端口、 目的端口以及协议类型, 而且还增加了应用层分析, 能够 高效的识别出网络上的各种应用及其内容,
普通报文检测是通过端口号来识别应用类型的, 如检测到端口号为
80 时, 则认为该应用代表着普通上网应用。 而当前网络上的一些非法应 用会采用隐藏或假冒端口号的方式躱避检测和监管,造成仿冒合法报文的 数据流侵蚀着网络。 此时普通报文检测方法就无能为力了。 DPI技术就是 通过对应用流中的数据报文内容进行探测, 从而确定数据报文的真正应 用。
商业智能 (Bus ines s Inte l l i gence , 以下简称: BI )技术是企业将现 有的数据转化为信息和知识的技术, 该技术实质上是数据仓库、 联机分析 处理和数据挖掘等技术的综合运用, 能够为企业提供一个实时的数据分析 系统, 帮助企业提高运营水平。
例如, 对于通信运营商和手机终端厂商而言, 随着网络技术的不断演 进, 需要统计指定地区当前流行的手机终端设备, 以及该类手机终端设备 的网络使用情况, 也可称为是对终端分布信息进行统计。 现有技术中队上 述信息的统计是由通信运营商从网络管理系统, 业务运营支撑系统 ( Bus ines s & Opera t i on Suppor t Sys tem, 以下简称: BOSS ) 中导出用 户话单, 或者消费记录后进行人工统计分析的方式获取。 现有技术中存在 的对手机等终端的分布信息进行统计的方式普遍存在统计效率低的缺陷, 同时其统计结果的精度也较低。 发明内容
本发明实施例提供一种终端分布信息获取方法、 数据获取装置以及通 信系统, 以及数据汇聚装置, 用以提高对终端分布信息进行统计时的统计 效率, 同时提高统计结果的精度。 本发明实施例提供了一种终端分布信息获取方法, 包括:
向深度数据包检测装置发送携带预解析的数据报文的请求消息, 所述 请求消息用于指示深度数据包检测装置对所述数据报文进行协议解析; 接收所述深度数据包检测装置返回的携带协议解析数据的响应消息, 所述协议解析数据包括发送所述数据报文的终端的类型标识、 所述数据报 文的协议类型以及对应该协议类型的业务流量值;
向数据汇聚装置发送携带所述协议解析数据的通知消息, 以使所述数 据处理模块根据所述协议解析数据汇聚生成各类型终端的终端分布信息, 所述终端分布信息包括各类型终端及其对应的特定时间段内的流量统计 值。
本发明实施例还提供了一种终端分布信息获取方法, 包括:
接收数据获取装置发送的携带对数据报文解析获得的协议解析数据 的通知消息, 所述协议解析数据包括发送所述数据报文的终端的类型标 识、 所述数据报文的协议类型以及对应该协议类型的业务流量值;
根据接收到的各个数据获取装置反馈的所述协议解析数据汇聚生成 各类型终端的终端分布信息, 所述终端分布信息包括各类型终端及其对应 的特定时间段内的流量统计值。 本发明实施例还提供了一种数据获取装置, 包括:
第一发送模块, 用于向深度数据包检测装置发送携带预解析的数据报 文的请求消息, 所述请求消息用于指示深度数据包检测装置对所述数据报 文进行协议解析;
第一接收模块, 用于接收所述深度数据包检测装置返回的携带协议解 析数据的响应消息, 所述协议解析数据包括发送所述数据报文的终端的类 型标识、 所述数据报文的协议类型以及对应该协议类型的业务流量值; 第二发送模块, 用于向数据汇聚装置发送携带所述协议解析数据的通 知消息, 以使所述数据处理模块根据所述协议解析数据汇聚生成各类型终 端的终端分布信息。
本发明实施例还提供了一种数据汇聚装置, 包括:
第二接收模块, 用于接收数据获取装置发送的对数据报文解析获得的 携带协议解析数据的通知消息, 所述协议解析数据包括发送所述数据报文 的终端的类型标识、 所述数据报文的协议类型以及对应该协议类型的业务 流量值;
第二获取模块, 用于根据各个数据获取装置反馈的所述协议解析数据 汇聚生成各类型终端的终端分布信息, 所述终端分布信息包括终端类型及 其对应的特定时间段内的流量统计值。
本发明实施例还提供了一种通信系统, 包括设置有上述的数据获取装 置的服务 GRPS支持节点和设置有上述的数据汇聚装置的商务智能系统。
本发明上述实施例提供的终端分布信息获取方法、 数据汇聚装置、 数 据获取装置以及通信系统, 其中可以由数据获取装置将终端发送给服务器 的数据报文, 发送给 DPI装置进行协议解析, 以获发送数据报文的终端的 类型标识, 数据报文的协议类型, 以及业务流量值等信息, 通过进一步的 将上述信息发送给数据汇聚装置进行汇聚, 即可统计获得各类型终端及其 对应的特定时间段内的流量统计值, 能够提高对终端分布信息进行统计时 的统计效率, 同时提高统计结果的精度。 附图说明
为了更清楚地说明本发明实施例或现有技术中的技术方案, 下面将对实 施例或现有技术描述中所需要使用的附图作一简单地介绍, 显而易见地, 下 面描述中的附图是本发明的一些实施例, 对于本领域普通技术人员来讲, 在 不付出创造性劳动性的前提下, 还可以根据这些附图获得其他的附图。
图 1为本发明终端分部信息获取方法实施例一的流程示意图; 图 2为本发明一具体实施例的流程示意图;
图 3为本发明实施例中 DPI装置的结构示意图;
图 4为本发明另一具体实施例的流程示意图;
图 5为本发明实施例中 IMS I的构成示意图;
图 6为本发明实施例中 IME I的构成示意图;
图 7为本发明终端分布信息获取方法实施例二的流程示意图; 图 8为本发明实施例中数据聚合的示意图;
图 9为本发明数据获取装置实施例的结构示意图;
图 10为本发明数据汇聚装置实施例的结构示意图。 具体实施方式
为使本发明实施例的目的、 技术方案和优点更加清楚, 下面将结合本 发明实施例中的附图, 对本发明实施例中的技术方案进行清楚、 完整地描 述, 显然, 所描述的实施例是本发明一部分实施例, 而不是全部的实施例。 基于本发明中的实施例, 本领域普通技术人员在没有作出创造性劳动前提 下所获得的所有其他实施例, 都属于本发明保护的范围。
本发明实施例提供了一种获取终端分布信息的技术方案, 具体的可以 是通信系统中设置数据获取装置以及深度数据包检测装置, 实时获取各个 类型的终端及其对应的业务数据流的大小, 具体的可以是将上述装置在网 关服务 GPRS节点 GGSN上, 然后将其向数据汇聚装置发送, 由数据汇聚 装置统计获得终端分布信息。 图 1为本发明终端分部信息获取方法实施例 一的流程示意图, 如图 1所示, 包括如下步骤:
步骤 101、 向深度数据包检测 (Deep Packet Inspection, 以下简称:
DPI ) 装置发送携带预解析的数据报文的请求消息, 所述请求消息用于指 示 DPI装置对所述 IP数据包进行协议解析;
步骤 102、 接收所述 DPI装置返回的携带协议解析数据的响应消息, 所述协议解析数据包括发送所述数据报文的终端的类型标识、 所述数据报 文的协议类型以及对应该协议类型的业务流量值;
步骤 103、 向数据汇聚装置发送携带所述协议解析数据的通知消息, 以使所述数据汇聚装置根据所述协议解析数据汇聚生成各类型终端的终 端分布信息, 所述终端分布信息包括各类型终端及其对应的特定时间段内 的流量统计值。
本发明上述实施例中的步骤,具体的可以是由设置在 GGSN中的数据 获取装置执行, 该数据获取装置将终端发送给服务器的数据报文, 发送给 DPI装置进行协议解析, 以获发送数据报文的终端的类型标识, 数据报文 的协议类型, 以及业务流量值等信息, 通过进一步的将上述信息发送给数 据汇聚装置进行汇聚, 即可统计获得各类型终端及其对应的特定时间段内 的流量统计值。
本发明上述实施例中, 由于 IP数据传输的特性, 一个按照协议生成 完整的数据报文可能被分为多个数据包传输, 即上述预解析的数据报文可 能是完整数据报文, 或者是非完整数据报文。 其中对于完整的数据报文, 可以通过深度数据包检测装置一次解析获得协议解析数据, 而对数据报文 是非完整的数据报文的情况,上述步骤 101中可以是至少两次向 DPI装置 发送携带预解析的非完整数据报文的请求消息, 而步骤 102 可以是接收 DPI装置返回的根据至少两个非完整性数据报文进行解析获取的协议解析 数据。 而上述解析非完整数据报文的情况, 具体的可以是在首次向 DPI装 置发送预解析的数据报文后, DPI装置检测获得部分协议解析数据, 将其 封装到上下文信息中, DPI装置返回携带上述上下文信息以及指示需要再 次进行数据检测信息的响应响应消息, 数据获取装置再次发送携带非完整 数据报文的请求消息, 同时还携带上述的上下文信息, 以由 DPI装置根据 新获得的非完整数据报文进一步进行协议解析, 并将前后两次获得的协议 解析数据进行合并, 直到能够获得完整的协议解析数据为止, 否则将持续 执行上述的流程。
另外, 本发明上述实施例中, 对于终端的类型标识可以是国际移动设 备标识码中的设备型号核准号码, 而上述步骤 102中数据获取装置在接收 到 DPI装置返回的携带协议解析数据的响应消息之后,数据获取装置进一 步的执行下述步骤: 对应关系表, 获取对应的移动终端型号。 并且向数据汇聚装置发送的通知 消息中携带的协议解析数据包括发送上述数据报文的移动终端型号、 上述 数据报文的协议类型以及对应该协议类型的业务流量值。
图 2为本发明一具体实施例的流程示意图, 如上所述的, 发送给 DPI 装置的数据报文可以是完整数据报文, 或者是非完整数据报文, 本实施例 中是针对完整数据报文的情况, 如图 2所示, 包括如下步骤:
步骤 201、 移动终端(Mobile Station, 以下简称: MS )向服务器发送 IP数据包(例如 IP Packet 1和 IP Packet2 ) , 上述的 IP数据包经过 GGSN, 且各个 IP数据包在 GGSN上进行流匹配和重组, 对于一个业务流上的 IP 数据包进行排序, 并过滤重复的数据报文,得到 TCP数据包(TCP Packetl 和 TCP Packet2 ) , 进一步的, 该 GGSN上还设置有上述的数据获取装 置, 该数据获取装置会根据预先配置的规则, 选择性的向 DPI装置发送请 求消息, 该请求消息中携带预解析的数据报文(TCP数据包) , 请求 DPI 装置进行 7层协议解析, 具体的本实施例中, 可以是 GGSN每接收到两个 IP数据包,则向 DPI装置发送一次请求消息,另外还可以是设定一时间段, 例如每分钟发送一次请求消息;
步骤 202、 DPI装置( DPI Parser )对接收到的 TCP数据包进行协议解 析, 解析前会先识别出 7层协议类型, 并根据协议类型确定需要解析得到 的协议解析数据, 上述的协议解析数据可以包括如下的信息中的一项或多 项, 例如国际移动用户标识码 ( International Mobile Subscriber Identification IMSI ) 、 国际移动设备标识码 ( International Mobile Equipment I den t i f i ca t i on ,以下简称: IMEI )、协议大类( Protocol Category : 例如 P2P、 VOIP等) 、 协议类型 (Protocol, 例如 BT、 eDonkey ) 、 范围 的 URL名称、 业务流量值(可以包括上行业务流量和下行业务流量) 等 信息, 而上述 IMET 中的 TAC标识是与移动终端型号——对应的, 上行 业务流量可以具体是针对特定类型终端, 在特定协议类上的上行业务流 量, 而下行业务流量也可以具体是针对特定类型终端, 在特定协议类上的 下行业务流量。
具体的, 如图 3所示, DPI装置可以包括解析规则库、 预处理模块、 解析模块、 后处理模块、 中间状态存储模块和五元组管理模块, 上述的解 析规则库中存储有解析规则, 具体的该解析规则可以是依据不同协议类型 的解析策略, 可以保证对不同协议类型的 TCP数据包进行解析。预处理模 块在接收到封装有一个或多个 IP数据包的 TCP数据包后, 同时从解析协 议规则库中获取对应的解析规则, 将其发送给解析模块进行解析, 获得解 析结果, 由后处理模块将解析结果返回给数据获取装置, 并可以将解析得 到的状态信息存储到 DPI装置的中间状态存储模块中, 再次对 IP数据包 进行解析时, 由预处理模块获取并发送给解析模块解析时参考, 另外将上 述的状态信息作为上下文信息携带在响应消息中返回给数据获取装置, 以 由数据获取装置在下一次针对同一业务流进行解析时, 将其携带在请求消 息中发送给 DPI装置, 而上述五元组管理模块负责五元组信息的创建、 老 化、 更新和查询。
步骤 203、 GGSN将接收到的协议解析数据进行相应处理, 并将处理 后的协议解析数据发送给服务器 (server ) 中的数据汇聚装置, 该数据汇 聚装置可以是具体的这里的处理可以包括是在上述的终端类型标识是 IMET中的 TAC标识, 根据 TAC标识与移动终端型号的对应关系, 获取 移动终端型号, 并将其携带在通知消息中发送给服务器。 另外对于上述步 骤中涉及的上下文信息, 可以在需要 DPI 装置再次对同一业务流的 TCP 数据包解析时发送给 DPI装置, 同时在业务流释放时释放内存中的相关上 下文信息。
步骤 204、 GGSN根据解析的结果和协议的特性 (采用配置的方式 ) 来确定是否将后续的 TCP数据包发送给 DPI装置进行解析, 具体的可以 针对步骤 201中涉及的配置规则执行, 例如图 2所示, GGSN对后需接收 到的 IP数据包 ( IP Packet3 ) , 不发送给 DPI进行解析, 而是直接发送给 服务器处理 (server ) 。
上述实施例是针对 TCP数据包为完整数据报文的情况的实施例,而针 对 IP数据包为非完整数据报文的情况, 可如图 4所示, 包括如下的步骤: 步骤 301、 与上述步骤 201的步骤基本相同, 区别在于由于 IP分片的 特性, GGSN发送给 DPI装置的 TCP数据包为非完整数据报文。
步骤 302、 DPI 装置对接收到的非完整数据报文进行解析, 由于是非 完整数据报文,因此 DPI装置无法通过一次解析获得完整的协议解析数据, DPI装置需要进行对非完整数据报文进行解析后緩存必要的信息, 生成上 下文信息。
步骤 303、 DP I装置向 GGSN返回响应消息, 该响应消息中携带需要继 续发送 TCP数据包进行解析的指示信息, 同时还可以将上述的上下文信息 发送给 GGSN。 GGSN会把之前接收到的 IP数据包发送给服务器。 步骤 304、 GGSN在接收到后续的 IP数据包 ( IP Packet3)后, 会继 续将转换得到的 TCP数据包发送给 DPI装置, 由 DPI装置进行解析, 同时 也会将上次解析得到的上下文信息发送给 DPI装置。
步骤 305、 DPI装置对接收到的 TCP数据包(TCPPacket3)进行解析, 同时会将解析得到的信息与上述的上下文信息进行合并, 如果已经获得完 整的协议解析数据, 则会将解析结果返回给 GGSN, 表明解析成功, 同时也 可以返回图 2所示实施例中的上下文信息, 以在解析同一业务流的 TCP数 据包时参考。
步骤 306、 GGSN将解析获得的完整的协议解析数据发送给服务器中的 数据汇聚装置。 另外本实施例中, GGSN也同样会将发送给 DPI装置解析的 IP数据包 ( IP Packetl、 IP Packet2和 IP Packet3 )发送给服务器。
具体的, 针对上述的 IMSI, 其数据结构可以如图 5所示, 包括移动国 家代码 (Mobile Country Code, 以下简称: MCC ) 、 MCC唯一的标识移动 用户所在的国家, 由 3 位组成; MNC 用以标识移动用户有效的 GSM PLMN 代码,由 1或 3位组成; MNC和 MSIN共同组成国家移动用户标识(National Mobile Subscriber Identity, 以下简称: 丽 SI ) 。
IMEI的结构可以如图 6所示,其包括表示移动终端设备的机型的设备 型号核准号码 TAC, 表示终端设备的产地的工厂装配码 FAC, 表示生产顺 序号的串号 SNR, 以及校验码 SP。
在上述的数据获取装置获取协议解析数据后, 将其发送给数据汇聚装 置, 数据汇聚装置根据接收到的各个数据获取装置反馈的协议解析数据生 成各类型终端的终端分布信息。 图 7为本发明终端分布信息获取方法实施 例二的流程示意图, 如图 7所示, 该方法包括如下的步骤:
步骤 401、 接收数据获取装置发送的携带对数据报文解析获得的协议 解析数据的通知消息, 所述协议解析数据包括发送所述数据报文的终端的 类型标识、 所述数据报文的协议类型以及对应该协议类型的业务流量值; 步骤 402、 根据接收到的各个数据获取装置反馈的所述协议解析数据 汇聚生成各类型终端的终端分布信息, 所述终端分布信息包括各类型终端 及其对应的特定时间段内的流量统计值。
本发明上述实施例中, 通过对接收到的各个数据获取装置反馈的协议 解析数据进行汇聚, 获得各类型终端的终端分布信息, 即获取各类型终端 及其在对应的特定时间段内的流量统计值, 能够提高对终端分布信息的统 计效率, 同时提供统计结果的准确性。
具体的上述实施例中, 对于协议解析数据中的终端的类型标识可以是 IMEI中的 TAC码, 也可以是根据 TAC码获取的移动终端型号, 在上述 的终端的类型标识为 TAC码时, 本实施例中可以将其转换为移动终端型 号。
在发送给数据汇聚装置的协议解析数据中, 除可以包括上述的终端的 类型标识、 数据报文的协议类型以及对应该协议类型的业务流量值外, 还 可以包括 IMS I (即手机号码), 或者是包括与上述的数据报文相关的网站 /服务器等内容, 上述的信息可以是以 UDP数据包的形式发送到 BI系统的 数据收集模块 DRM, 该模块是数据汇聚装置的一部分, DRM将收到 UDP数 据包转换为 CSV文件,该 CSV文件为一种用来存储数据的纯文本, 英文全 称为: Comma Separa ted Va lues , 并写在硬盘上。 同时, 对于 "所处地域 信息" 和 "用户详细信息" , 也可以通过手机号码关联到运营商内部业务 支撑系统获得, 以 CSV文件的形式保存到硬盘上。
CSV文件解析组件定时解析过滤 CSV文件数据到緩冲表(ETL表), 再 由内存和 ORACLE存储过程的将数据从緩冲表(ETL表)按照一定要求放置 到元数据表中。 BI系统 ETL (数据处理模块)模块将读取硬盘上的 CSV文 件并将记录插入到 Orac le后台数据库里相应的表中。 每条原始记录包括 流量统计值(具体可以包括上行流量信息和下行流量信息) , 通过终端类 型来对记录进行分组汇总求和, 得出某种终端的总流量大小。
通过汇聚任务对元数据表数据进行汇聚至汇聚表, 即可在 BI 系统中 形成基于各种维度的分布统计报表, 分析引擎 (Ana lys i s Eng ine ) 根据 需求远程创建并管理多维数据集 Cube , 分析师通过 HTTP接口与报表系统 进行基于各种维度信息进行交互, 具体的生成的分布统计报表可以如下所
Figure imgf000013_0001
在本发明实施例中, 由系统将自动采集数据并生成报表, 相对于现有 技术中利用人工方式进行数据统计, 数据的统计效率高。 另外, 本发明实 施例中还是一种基于用户真实通信消费记录的数据统计, 其精确度高, 且 本发明实施例可以基于分钟、 小时、 天、 周、 月或任何时间粒度期限进行 统计, 同时也可以根据 IMS I 标识获取地域位置信息, 实现对特定地区进 行统计, 或者从网络管理系统获取归属用户, 对属于同一用户进行统计。 本发明上述实施例中, 根据反馈的协议解析数据汇聚生成各类型终端的分 布信息, 在针对不同粒度的数据进行汇聚时, 具体的可以是:
根据各个数据获取装置反馈的协议解析数据进行内存聚合, 汇聚生成 分钟粒度的各类型终端的终端分布信息和 /或小时粒度的各类型终端的终 端分布信息; 以及
根据各个数据获取装置反馈的协议解析数据进行数据库聚合, 汇聚生 成天粒度的各类型终端的终端分布信息和 /或月粒度的各类型终端的终端 分布信息。
具体的如图 8所示, 通过读本地文件的方式, 使用 Ha shMap结构在内 存中对元数据进行聚合操作, 将文件一次性读写到内存中, 供所有的聚合 器使用, 减少磁盘 10操作, 并提升处理性能。 对于一次聚合过程, 具体 的可以是将緩冲表中同一类型终端 ( termina l ) 、 同一网站 ( webs i te ) 或同一用户 (subscr i ber ) 下的明细记录, 按照某种规则如时间字段取并 集, 数据字段去和, 明细记录条数作为访问次数等汇总成一条记录并写入 到聚合表中。 具体的可以是将数据量大的分钟粒度和小时粒度聚合在内存 中完成, 后通过 CSV写操作器( CSV Wr i ter )将数据转换为 CSV文件(CSV f i l e ) , 然后将上述的 CSV文件通过数据入库模块 (ETL ) 转发到数据库 中, 分别存储为分钟粒度数据和小时粒度数据, 可将上述的分钟粒度数据 和小时粒度数据进一步的聚合形成天粒度数据和月粒度数据, 第二次的聚 合过程可以在数据库中实现。
图 9为本发明数据获取装置实施例的结构示意图, 如图 9所示, 该装 置包括第一发送模块 11、 第一接收模块 12和第二发送模块 13 , 其中第一 发送模块 11 用于向深度数据包检测装置发送携带预解析的数据报文的请 求消息, 所述请求消息用于指示深度数据包检测装置对所述数据报文进行 协议解析; 第一接收模块 12用于接收所述深度数据包检测装置返回的携 带协议解析数据的响应消息, 所述协议解析数据包括发送所述数据报文的 终端的类型标识、 所述数据报文的协议类型以及对应该协议类型的业务流 量值; 第二发送模块 13 用于向数据汇聚装置发送携带所述协议解析数据 的通知消息, 以使所述数据处理模块根据所述协议解析数据汇聚生成各类 型终端的终端分布信息。
本发明上述实施例中提供的数据获取装置, 能够通过向深度数据包检 测装置发送请求消息, 使其对数据报文进行解析以获取协议解析数据, 该 协议解析数据包括发送上述数据报文的终端的类型标识、 上述数据报文的 协议类型以及对应该协议类型的业务流量值, 并将上述的协议解析数据发 送给数据汇聚装置进行汇聚, 以得到各类型终端的终端分布信息, 能够提 高对终端分布信息的统计效率, 并获得精确度更高的统计结果。 本发明上 述实施例中的数据获取装置,还可以进一步的包括第一获取模块 14 , 该第 —获取模块 14 用于在所述终端的类型标识为国际移动设备标识码中的设 与移动终端型号对应关系表, 获取对应的移动终端型号; 且上述第二发送 模块 13发送的通知消息中携带的协议解析数据包括发送所述数据报文的 移动终端型号、 所述数据报文的协议类型以及对应该协议类型的业务流量 值。
本发明上述实施例中的数据获取装置可以是设置在 GGSN中,而其中 的深度数据包检测装置既可以是设置在 GGSN中,也可以是单独设置的形 式。
本发明实施例还提供了一种数据汇聚装置, 图 10 为本发明数据汇聚 装置实施例的结构示意图, 如图 10所示, 该装置包括第二接收模块 21和 第二获取模块 22, 其中第二接收模块 21用于接收数据获取装置发送的对 数据报文解析获得的携带协议解析数据的通知消息, 所述协议解析数据包 括发送所述数据报文的终端的类型标识、 所述数据报文的协议类型以及对 应该协议类型的业务流量值; 第二获取模块 22用于根据各个数据获取装 置反馈的所述协议解析数据汇聚生成各类型终端的终端分布信息, 所述终 端分布信息包括终端类型及其对应的特定时间段内的流量统计值。
本实施例提供的技术方案中, 其中的数据汇聚装置根据各个数据获取 装置获取到的协议解析数据汇聚生成终端分布信息, 相对于现有技术中通 过人工采集的方式获取终端分布信息, 能够提高对终端分布信息的统计效 率, 同时也能够提高统计结果的精确度。
本发明实施例还提供了一种通信系统, 该通信系统包括设置了上述数 据获取装置的 GGSN 和设置了上述的数据获取装置的商务智能系统。 另 外, 进一步的, 还可以将深度数据包检测装置设置在 GGSN中; 或者独立 设置的方式将深度数据包检测装置设置在通信网络中。
本领域普通技术人员可以理解: 实现上述方法实施例的全部或部分步 骤可以通过程序指令相关的硬件来完成, 前述的程序可以存储于一计算机 可读取存储介质中, 该程序在执行时, 执行包括上述方法实施例的步骤; 而前述的存储介质包括: ROM、 RAM, 磁碟或者光盘等各种可以存储程 序代码的介质。
最后应说明的是: 以上实施例仅用以说明本发明的技术方案, 而非对 其限制; 尽管参照前述实施例对本发明进行了详细的说明, 本领域的普通 技术人员应当理解: 其依然可以对前述各实施例所记载的技术方案进行修 改, 或者对其中部分技术特征进行等同替换; 而这些修改或者替换, 并不 使相应技术方案的本质脱离本发明各实施例技术方案的精神和范围。

Claims

权 利 要 求 书
1、 一种终端分布信息获取方法, 其特征在于, 包括:
向深度数据包检测装置发送携带预解析的数据报文的请求消息, 所述 请求消息用于指示深度数据包检测装置对所述数据报文进行协议解析; 接收所述深度数据包检测装置返回的携带协议解析数据的响应消息, 所述协议解析数据包括发送所述数据报文的终端的类型标识、 所述数据报 文的协议类型以及对应该协议类型的业务流量值;
向数据汇聚装置发送携带所述协议解析数据的通知消息, 以使所述数 据处理模块根据所述协议解析数据汇聚生成各类型终端的终端分布信息, 所述终端分布信息包括各类型终端及其对应的特定时间段内的流量统计 值。
2、 根据权利要求 1所述的终端分布信息获取方法, 其特征在于, 所 述预解析的数据报文为完整数据报文或非完整数据报文, 且在所述预解析 的数据报文为非完整数据报文, 所述向深度数据包检测装置发送携带预解 析的数据报文的请求消息包括:
至少两次向所述深度数据包检测装置发送携带预解析的非完整数据 报文的请求消息;
所述接收所述深度数据包检测装置返回的所述数据报文的协议解析 数据包括:
接收深度数据包检测装置返回的根据至少两个非完整数据报文进行 解析获取的协议解析数据。
3、 根据权利要求 1所述的终端分布信息获取方法, 其特征在于, 所 述终端的类型标识为国际移动设备标识码中的设备型号核准号码, 在接收 所述深度数据包检测装置返回的携带协议解析数据的响应消息之后还包 括: 对应关系表, 获取对应的移动终端型号;
则向数据汇聚装置发送的通知消息中携带的协议解析数据包括发送 所述数据报文的移动终端型号、 所述数据报文的协议类型以及对应该协议 类型的业务流量值。
4、 一种终端分布信息获取方法, 其特征在于, 包括:
接收数据获取装置发送的携带对数据报文解析获得的协议解析数据 的通知消息, 所述协议解析数据包括发送所述数据报文的终端的类型标 识、 所述数据报文的协议类型以及对应该协议类型的业务流量值;
根据接收到的各个数据获取装置反馈的所述协议解析数据汇聚生成 各类型终端的终端分布信息, 所述终端分布信息包括各类型终端及其对应 的特定时间段内的流量统计值。
5、 根据权利要求 4所述的终端分布信息获取方法, 其特征在于, 所 述终端的类型标识为移动终端型号。
6、 根据权利要求 4所述的终端分布信息获取方法, 其特征在于, 所 述根据接收到的各个数据获取装置反馈的协议解析数据汇聚生成各类型 终端的终端分布信息包括:
根据各个数据获取装置反馈的协议解析数据进行内存聚合, 汇聚生成 分钟粒度的各类型终端的终端分布信息和 /或小时粒度的各类型终端的终 端分布信息; 以及
根据各个数据获取装置反馈的协议解析数据进行数据库聚合, 汇聚生 成天粒度的各类型终端的终端分布信息和 /或月粒度的各类型终端的终端 分布信息。
7、 一种数据获取装置, 其特征在于, 包括:
第一发送模块, 用于向深度数据包检测装置发送携带预解析的数据报 文的请求消息, 所述请求消息用于指示深度数据包检测装置对所述数据报 文进行协议解析; 第一接收模块, 用于接收所述深度数据包检测装置返回的携带协议解 析数据的响应消息, 所述协议解析数据包括发送所述数据报文的终端的类 型标识、 所述数据报文的协议类型以及对应该协议类型的业务流量值; 第二发送模块, 用于向数据汇聚装置发送携带所述协议解析数据的通 知消息, 以使所述数据处理模块根据所述协议解析数据汇聚生成各类型终 端的终端分布信息。
8、 根据权利要求 7所述的数据获取装置, 其特征在于, 还包括: 第一获取装置, 用于在所述终端的类型标识为国际移动设备标识码中 号码与移动终端型号对应关系表, 获取对应的移动终端型号;
且所述第二发送模块发送的通知消息中携带的协议解析数据包括发 送所述数据报文的移动终端型号、 所述数据报文的协议类型以及对应该协 议类型的业务流量值。
9、 一种数据汇聚装置, 其特征在于, 包括:
第二接收模块, 用于接收数据获取装置发送的对数据报文解析获得的 携带协议解析数据的通知消息, 所述协议解析数据包括发送所述数据报文 的终端的类型标识、 所述数据报文的协议类型以及对应该协议类型的业务 流量值;
第二获取模块, 用于根据各个数据获取装置反馈的所述协议解析数据 汇聚生成各类型终端的终端分布信息, 所述终端分布信息包括终端类型及 其对应的特定时间段内的流量统计值。
10、 一种通信系统, 其特征在于, 包括设置有权利要求 7或 8所述的 数据获取装置的服务 GRPS支持节点和设置有权利要求 9所述的数据汇聚 装置的商务智能系统。
PCT/CN2011/076762 2011-07-01 2011-07-01 终端分布信息获取方法、数据获取装置以及通信系统 WO2012106861A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PCT/CN2011/076762 WO2012106861A1 (zh) 2011-07-01 2011-07-01 终端分布信息获取方法、数据获取装置以及通信系统
CN2011800015266A CN102301764A (zh) 2011-07-01 2011-07-01 终端分布信息获取方法、数据获取装置以及通信系统

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2011/076762 WO2012106861A1 (zh) 2011-07-01 2011-07-01 终端分布信息获取方法、数据获取装置以及通信系统

Publications (1)

Publication Number Publication Date
WO2012106861A1 true WO2012106861A1 (zh) 2012-08-16

Family

ID=45360545

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2011/076762 WO2012106861A1 (zh) 2011-07-01 2011-07-01 终端分布信息获取方法、数据获取装置以及通信系统

Country Status (2)

Country Link
CN (1) CN102301764A (zh)
WO (1) WO2012106861A1 (zh)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2890168A4 (en) * 2012-08-22 2015-09-09 Huawei Tech Co Ltd METHOD, SYSTEM AND DEVICE FOR SHARING / ACQUIRING PROFIT OF PACKET DEPTH INSPECTION ANALYSIS RESULT
CN112866973A (zh) * 2019-11-28 2021-05-28 上海华为技术有限公司 一种统计终端设备分布情况的方法及相关装置
CN115250297A (zh) * 2022-06-28 2022-10-28 合肥移顺信息技术有限公司 一线通数据解析方法、装置、终端、介质及程序产品

Families Citing this family (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103906094B (zh) * 2012-12-24 2017-10-17 中国电信股份有限公司 Evdo控制信道资源占用获取方法和系统
CN103988543B (zh) * 2013-12-11 2018-09-07 华为技术有限公司 无线局域网中的控制设备、网络系统及业务处理方法
CN103853838B (zh) * 2014-03-17 2017-09-12 中国联合网络通信集团有限公司 一种数据处理方法和装置
US10013414B2 (en) * 2014-08-20 2018-07-03 Futurewei Technologies, Inc. System and method for metadata enhanced inventory management of a communications system
KR102349450B1 (ko) * 2014-12-08 2022-01-10 삼성전자주식회사 무결성 검사 데이터 제공 방법 및 장치
CN107239542A (zh) * 2017-06-02 2017-10-10 福建中金在线信息科技有限公司 一种数据统计方法、装置、服务器及存储介质
CN107864068B (zh) * 2017-10-23 2020-11-24 北京中创信测科技股份有限公司 一种基于dpi技术的应用识别系统及方法
CN107831842A (zh) * 2017-12-10 2018-03-23 夏烬楚 基于大数据的智能信息捕获系统
CN110121175A (zh) * 2019-04-12 2019-08-13 国家计算机网络与信息安全管理中心 一种用于移动物联网智能终端的数据监测方法及系统
CN112838960B (zh) * 2019-11-22 2024-03-12 中兴通讯股份有限公司 通信数据清洗方法、装置、网络设备及存储介质
CN111988271B (zh) * 2020-06-30 2021-11-16 联想(北京)有限公司 一种通信流处理方法及装置
CN112671721A (zh) * 2020-12-11 2021-04-16 浙江万胜智能科技股份有限公司 一种智能电能表的报文解析方法
CN113923716B (zh) * 2021-12-13 2022-05-03 北京赋乐科技有限公司 一种用户信息获取方法、装置和电子设备

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101141418A (zh) * 2006-09-08 2008-03-12 中国电信股份有限公司 基于策略的家庭网络业务识别的系统和方法
CN101715182A (zh) * 2009-11-30 2010-05-26 中国移动通信集团浙江有限公司 一种流量控制方法、系统和设备
CN101925101A (zh) * 2009-06-09 2010-12-22 中兴通讯股份有限公司 一种用户呼叫过程信息采集及统计分析的方法及装置
EP2315392A1 (en) * 2009-10-21 2011-04-27 Nederlandse Organisatie voor toegepast -natuurwetenschappelijk onderzoek TNO Telecommunication quality of service control

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8289864B2 (en) * 2008-08-28 2012-10-16 Alcatel Lucent DPI-triggered application-aware dormancy timer adjustment for mobile data bearers
US8266673B2 (en) * 2009-03-12 2012-09-11 At&T Mobility Ii Llc Policy-based privacy protection in converged communication networks
CN101729308B (zh) * 2009-06-01 2013-08-07 中兴通讯股份有限公司 一种策略控制的方法和装置
KR101171687B1 (ko) * 2009-12-23 2012-08-07 주식회사 케이티 가입자 단말의 서비스 상태 관리 장치 및 그 방법

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101141418A (zh) * 2006-09-08 2008-03-12 中国电信股份有限公司 基于策略的家庭网络业务识别的系统和方法
CN101925101A (zh) * 2009-06-09 2010-12-22 中兴通讯股份有限公司 一种用户呼叫过程信息采集及统计分析的方法及装置
EP2315392A1 (en) * 2009-10-21 2011-04-27 Nederlandse Organisatie voor toegepast -natuurwetenschappelijk onderzoek TNO Telecommunication quality of service control
CN101715182A (zh) * 2009-11-30 2010-05-26 中国移动通信集团浙江有限公司 一种流量控制方法、系统和设备

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2890168A4 (en) * 2012-08-22 2015-09-09 Huawei Tech Co Ltd METHOD, SYSTEM AND DEVICE FOR SHARING / ACQUIRING PROFIT OF PACKET DEPTH INSPECTION ANALYSIS RESULT
CN112866973A (zh) * 2019-11-28 2021-05-28 上海华为技术有限公司 一种统计终端设备分布情况的方法及相关装置
CN112866973B (zh) * 2019-11-28 2022-11-11 上海华为技术有限公司 一种统计终端设备分布情况的方法及相关装置
CN115250297A (zh) * 2022-06-28 2022-10-28 合肥移顺信息技术有限公司 一线通数据解析方法、装置、终端、介质及程序产品

Also Published As

Publication number Publication date
CN102301764A (zh) 2011-12-28

Similar Documents

Publication Publication Date Title
WO2012106861A1 (zh) 终端分布信息获取方法、数据获取装置以及通信系统
CN101754253B (zh) 一种gprs端到端性能分析方法及系统
US9037710B2 (en) Method and apparatus for correlating end to end measurements through control plane monitoring of wireless traffic
CN107634848B (zh) 一种采集分析网络设备信息的系统和方法
CN108337652B (zh) 一种检测流量欺诈的方法及装置
WO2011157064A1 (zh) 一种基于移动通信网络的车险理赔系统及方法
CN1906961A (zh) 用于确定运行无线网络中移动终端性能的方法
CN105828310B (zh) 一种数据业务的计费方法及设备、系统
US8897745B2 (en) Method and apparatus for optimizing delivery of network usage and billing data
CN105681125A (zh) 一种云平台的虚拟机外网流量统计方法
CN1901543A (zh) 用于向中央储存库传送导出呼叫记录的方法和系统
CN108111320A (zh) 一种本地业务计费方法、服务器和计费网关
US9892030B2 (en) Method and apparatus for improving non-uniform memory access
US20120155255A1 (en) Method and apparatus for managing a degree of parallelism of streams
CN109451486A (zh) 基于探测请求帧的WiFi采集系统及WiFi终端探测方法
CN108322354B (zh) 一种偷跑流量账户识别方法及装置
WO2010115358A1 (zh) 业务状态信息获取方法及装置
CN110691007A (zh) 一种精确测量quic连接丢包率的方法
US20120155379A1 (en) Method and apparatus for applying uniform hashing to wireless traffic
WO2013007198A1 (zh) 一种计费方法及装置
US20120155293A1 (en) Method and apparatus for providing a two-layer architecture for processing wireless traffic
CN109286506B (zh) 一种流量计费的方法、系统及装置
CN108616415B (zh) 数据关联方法及装置
JP2023544456A (ja) ボイスオーバーipトラフィックを分類し処理するためのシステム及び方法
CN110972199A (zh) 一种流量拥塞监测方法及装置

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 201180001526.6

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 11858295

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 11858295

Country of ref document: EP

Kind code of ref document: A1