WO2016143066A1 - Information processing device and port mirroring position selection method - Google Patents

Information processing device and port mirroring position selection method Download PDF

Info

Publication number
WO2016143066A1
WO2016143066A1 PCT/JP2015/056983 JP2015056983W WO2016143066A1 WO 2016143066 A1 WO2016143066 A1 WO 2016143066A1 JP 2015056983 W JP2015056983 W JP 2015056983W WO 2016143066 A1 WO2016143066 A1 WO 2016143066A1
Authority
WO
WIPO (PCT)
Prior art keywords
traffic
mirror position
mirror
communication
port
Prior art date
Application number
PCT/JP2015/056983
Other languages
French (fr)
Japanese (ja)
Inventor
貴也 井出
恭宏 相樂
順史 木下
高田 治
Original Assignee
株式会社日立製作所
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 株式会社日立製作所 filed Critical 株式会社日立製作所
Priority to PCT/JP2015/056983 priority Critical patent/WO2016143066A1/en
Publication of WO2016143066A1 publication Critical patent/WO2016143066A1/en

Links

Images

Definitions

  • the present invention relates to an information processing apparatus and a port mirroring position selection method, and is suitable for application to, for example, a communication system of a cloud provider that provides IaaS (Infrastructure As Service).
  • IaaS Intelligent As Service
  • IaaS An increasing number of companies use a service called IaaS that provides a customer with an environment in which a set of computer resources such as a server device, a storage device, and a network necessary for building a business computer system can be used.
  • IT Internet Technology
  • mirroring In order to perform passive performance monitoring, it is necessary to collect the application traffic to be monitored in the analyzer. This can be done by port mirroring (hereinafter referred to simply as mirroring) using a communication device such as a switch or router that constitutes an IaaS physical network, or by connecting a tap to each link on the network to branch the traffic signal. It is realized by doing.
  • target traffic a communication device that performs mirroring settings
  • a mirror position as appropriate
  • Patent Document 1 and Patent Document 2 disclose a technique for selecting a mirror position based on communication path information.
  • Patent Document 1 discloses selecting a mirror position based on physical topology information
  • Patent Document 2 discloses selecting a mirror position based on BGP (Border Gateway Protocol) information in a communication device. Is disclosed.
  • BGP Border Gateway Protocol
  • the mirror position is selected without considering the bandwidth of the output interface of the packet duplicated by mirroring (hereinafter referred to as the mirror port). Yes.
  • the present invention has been made in view of the above points, and will propose an information processing apparatus and a port mirroring position selection method capable of quickly selecting a communication apparatus capable of performing port mirroring without discarding mirrored traffic. It is what.
  • the present invention relates to each of the traffic passing through the communication device in an information processing device for selecting the communication device to be subjected to port mirroring of traffic flowing through a network composed of a plurality of communication devices.
  • a network information analyzing unit for acquiring the predetermined traffic information from each of the communication devices, and identifying each of the communication devices through which each of the traffic flowing through the network passes by analyzing each of the acquired traffic information; Based on the analysis result of the network information analysis unit, the traffic to be subjected to the port mirroring is specified, all the communication devices through which the specified traffic passes are specified, and the port of each specified communication device is specified.
  • Said mirroring A mirror position candidate enumeration unit for enumerating combinations of communication devices; and the port mirroring of the communication device in the communication device constituting the combination among the combinations of the communication devices enumerated by the mirror position candidate enumeration unit And a satisfactory combination selection unit for selecting a combination that does not cause congestion in the mirror port.
  • the information processing apparatus includes: The communication device through which each of the traffic flowing through the network passes by acquiring predetermined traffic information regarding each of the traffic passing through the communication device from each of the communication devices, and analyzing each of the acquired traffic information.
  • a first step of identifying the information and the information processing device identifies the traffic to be subject to the port mirroring based on the analysis result, identifies all the communication devices through which the identified traffic passes, Port on each identified communication device
  • a second step of enumerating the combinations of the communication devices that perform the error ringing, and the information processing apparatus includes the port mirroring of the communication device in the communication device that constitutes the combination among the enumerated combinations of the communication devices.
  • a third step of selecting a combination that does not cause congestion in the mirror port is
  • the present invention it is possible to realize an information processing apparatus and a port mirroring position selection method that can quickly select a mirror position (communication apparatus) that can execute port mirroring without discarding mirrored traffic.
  • (A) is a conceptual diagram which shows the structure of a communication management table
  • (B) is a conceptual diagram which shows the structure of a path
  • FIG. 11 is a sequence diagram showing a flow of a series of processes from when a mirror position request is transmitted from an operation source to a management apparatus until a mirror position response corresponding to the mirror position request is transmitted from the management apparatus to the operation source. It is a flowchart which shows the process sequence of a network information analysis process. It is a conceptual diagram which shows the data format of an IPFIX message. It is a flowchart which shows the process sequence of a mirror position candidate enumeration process. It is a flowchart which shows the process sequence of a candidate search process.
  • (A) to (E) are diagrams for explaining candidate search processing. It is a flowchart which shows the process sequence of a candidate registration process. It is a flowchart which shows the process sequence of a satisfaction combination selection process. It is a figure which shows schematic structure of a mirroring condition display screen. It is a block diagram which shows the whole structure of the communication system by 2nd Embodiment. It is a conceptual diagram which shows the structure of the mirror position request
  • FIG. 1 indicates a communication system according to the present embodiment as a whole.
  • the communication system 1 is connected to a plurality of computers 3 and a plurality of communication devices 4 connected to a data network 2, an aggregation communication device 5 connected to these communication devices 4, and an aggregation communication device 5.
  • the electronic computer 3 is composed of, for example, a server device or a personal computer, and communicates with each other via the data network 2.
  • the communication device 4 includes, for example, a LAN (Local Area Network) switch, a router, and the like, and includes one or a plurality of interfaces (not shown) connected to the data network 2, an interface connected to the control network 7, and aggregation. And one or a plurality of mirror ports MP connected to the communication device 5. Note that the communication device 4 of the present embodiment includes only one mirror port MP.
  • LAN Local Area Network
  • the communication device 4 is equipped with a transfer function 10, a mirroring function 11, and a communication information notification function 12.
  • the transfer function 10 analyzes the traffic received via an arbitrary interface of the communication device 4, and based on information such as a 5-tuple obtained by the analysis, an interface to output the traffic according to a predetermined rule. This function determines and outputs traffic from the determined interface.
  • the 5-tuple refers to a “source IP address” that is an IP (Internet Protocol) address of a communication device (electronic computer 3) that is a transmission source of the traffic, and transmission of traffic from a plurality of programs operated by the communication device.
  • “Sender port number” that specifies the source program
  • "Destination IP address” that is the IP address of the communication device (electronic computer 3) that is the destination of the traffic
  • a plurality of programs that the communication device operates Indicates a “destination port number” that specifies a destination program of traffic and “IP protocol” that indicates the type of IP protocol used when sending / receiving the traffic. Such information can be acquired from the header portion of each packet constituting the traffic.
  • the mirroring function 11 is a function that duplicates traffic designated using information such as a 5-tuple out of traffic passing through the communication device 4 and outputs it from the mirror port MP.
  • the communication information notification function 12 uses predetermined traffic information related to traffic passing through the communication device 4 (information such as accumulated traffic for each traffic and 5 tuples) as the notification information 13, and a predetermined device (the present embodiment). Is a function of transmitting to the management apparatus 8) via the control network 7.
  • the transfer function 10, mirroring function 11, and communication information notification function 12 of the communication device 4 are all based on existing technology.
  • the transfer function 10 includes a LAN switch switching function
  • the mirroring function 11 includes LAN switch access control.
  • IPFIX IP Flow Information Export
  • IPFIX IP Flow Information Export
  • the aggregation communication device 5 is composed of, for example, a network packet broker, and includes a plurality of reception ports RP and one or a plurality of transmission ports TP. Each reception port RP is connected to a mirror port MP of a different communication device 4, and one or more transmission ports TP are connected to an arbitrary analysis device 6. Then, the aggregation communication device 5 transfers the traffic copied (mirrored) by each communication device 4 received via the reception port RP to the corresponding analysis device 6 via the transmission port TP.
  • the analysis device 6 is composed of a passive type performance monitoring device.
  • the analysis device 6 analyzes the traffic transferred from the aggregation communication device 5 to monitor the response performance of the application that transmits and receives the traffic, for example.
  • the management device 8 is, for example, a server device used by a system administrator to manage the communication system 1, and in response to a mirror position request 17 to be described later given from the operation source 9, in the mirror position request 17. Equipped with a function to select the communication device 4 to be the mirror position when analyzing the specified traffic and return the selection result to the operation source 9 as a mirror position response 18 (hereinafter referred to as a mirror position selection function) Has been.
  • the operation source 9 is assumed to be, for example, a client terminal 15 operated by the user 14 or an operation management apparatus 16 installed by a cloud operator who operates the communication system 1.
  • the client terminal 15 uses the traffic to be analyzed by the analysis device 6 (hereinafter referred to as target traffic) and, if necessary, the mirror position of the target traffic.
  • GUI Graphic User Interface
  • the client terminal 15 transmits a request for selecting the mirror position of the target traffic designated by the user 14 to the management apparatus 8 as the above-described mirror position request 17 by using this GUI.
  • the client terminal 15 determines the mirror position of the target traffic selected by the management apparatus 8 that is recognized based on the mirror position response 18. Display in format.
  • the mirror position request 17 includes one or more combinations of communication requirements and mirror position communication device IDs.
  • the communication requirement is a requirement for target traffic, and is composed of information on five tuples of the target traffic (hereinafter referred to as five-tuple information). In this case, the communication requirement does not need to include all of the 5-tuple information, and only a part thereof may be used.
  • a VLAN (Virtual LAN) identifier may be included.
  • the mirror position communication device ID is an identifier (communication device ID) of the communication device 4 to be the mirror position of the target traffic designated by the operation source 9 as described above.
  • the mirror position communication device ID may be empty (that is, the communication device 4 to be the mirror position of the target traffic may not be specified).
  • the mirror position response 18 should be the mirror position selected by the management apparatus 8 in addition to the information (combination of one or more communication requirements and the mirror position communication apparatus ID) included in the corresponding mirror position request 17.
  • the identifier (communication device ID) of the communication device 4 is included.
  • interface information for executing port mirroring is required in addition to mirror position (communication device) information.
  • mirroring can be performed even if only the communication device 4 is specified.
  • port mirroring is activated in advance for all ports of the communication device 4, and any traffic is denied (deny) by access control. After the mirror position is specified, the communication that becomes the mirror position is performed. By permitting the mirroring of the traffic to be mirrored by the access control of the device 4, the interface information becomes unnecessary when performing the port mirroring.
  • the mirror position request 17 and the mirror position response 18 are described in XML (eXtensible Markup Language), for example, and are transmitted and received between the operation source 9 and the management device 8 by HTTP (Hyper Text Transfer Protocol).
  • XML eXtensible Markup Language
  • HTTP Hyper Text Transfer Protocol
  • FIG. 2 shows a configuration example of the data network 2.
  • the configuration of the data network 2 and the traffic flowing through the data network 2 are simplified.
  • the data network is configured by a large number of communication devices, and a large number of traffics are generated on the data network. Flowing.
  • the data network 2 is composed of a plurality of communication devices 4A to 4D having the same functions and configurations as the communication device 4 described above with reference to FIG. 1, and a plurality of electronic computers 3S to 3W are connected to the data network 2. ing.
  • the communication devices 4A to 4D and the electronic computers 3S to 3W do not need to be devices having physical entities, but may be virtual switches or virtual machines implemented by software.
  • the communication devices 4A to 4D and the electronic computers 3S to 3W are connected to each other using a LAN cable.
  • the electronic computer 3S is connected to the communication device 4A
  • the communication device 4A is connected to the communication device 4C and the communication device 4D, respectively.
  • the electronic computer 3T is connected to a communication device 4B
  • this communication device 4B is connected to the communication device 4C and the communication device 4D, respectively.
  • the communication device 4C is connected to the electronic computer 3U
  • the communication device 4D is connected to the electronic computer 3V and the electronic computer 3W.
  • the traffic 19K flows from the electronic computer 3S to the electronic computer 3U via the communication device 4A and the communication device 4C
  • the traffic 19M flows from the electronic computer 3T via the communication device 4B and the communication device 4D
  • traffic 19L flows from the computer 3V via the communication device 4D, the communication device 4B, and the communication device 4C.
  • FIGS. 5 to 8 used in the following description, in the data network 2 having such a configuration, it is desired to mirror the traffic to the electronic computer 3U (the transmission source is not specified) and the traffic from the electronic computer 3T to the electronic computer 3W.
  • the traffic of each traffic is always 800 Mbps, and the bandwidth of the mirror port MP (FIG. 1) of the communication device 4 (hereinafter including 4A to 4D). Is set to 1024 [Mbps]. Under such a situation, when a plurality of traffics are mirrored by the same communication device 4, congestion occurs at the mirror port MP, so that the mirror position needs to be distributed to the plurality of communication devices 4.
  • FIG. 3 shows a simplified hardware configuration of the management device 8.
  • the management device 8 includes a processor 21, a main storage device 22, an external storage device 23, a communication control device 24, and an input / output device 26 connected to each other via an internal bus 20. Configured.
  • the processor 21 is hardware having a function for controlling operation of the entire management apparatus 8.
  • the main storage device 22 is composed of, for example, a semiconductor memory and is used to temporarily hold various programs and control data.
  • the mirror position request management table 34 and the mirror position candidate management table group 35 are also stored and held in the main storage device 22.
  • the external storage device 23 is a storage device having a large storage capacity, and is composed of, for example, a hard disk device or an SSD (Solid State Drive). The external storage device 23 is used for holding various programs and data for a long period of time.
  • the communication control device 24 is hardware having a function of controlling communication with each communication device 4, and is connected to the control network 7 via the interface 27.
  • the input / output device 26 includes an input device such as a keyboard and a mouse for a user to perform various operation inputs, and an output device such as a liquid crystal display for displaying various information.
  • FIG. 4 shows a simple logical configuration of the management device 8.
  • the management device 8 includes a network information analysis unit 40, a mirror position selection unit 41, a mirror position candidate listing unit 42, and a satisfaction combination selection unit 43.
  • the network information analysis unit 40, the mirror position selection unit 41, the mirror position candidate listing unit 42, and the satisfaction combination selection unit 43 are stored in the main storage device 22 (FIG. 3) by the processor 21 (FIG. 3) of the management device 8. This is a function embodied by executing the management program 31 (FIG. 3).
  • the network information analysis unit 40 analyzes the above notification information 13 transmitted from each communication device 4 constituting the data network 2 via the control network 7, and includes 5-tuple information on each traffic flowing through the data network 2, The communication device 4 through which each of the traffic passes and information such as the traffic of the traffic in the communication device 4 are acquired, and processing for storing the acquired information in the communication analysis information table group 33 is executed.
  • the mirror position selection unit 41 executes a process of receiving the mirror position request 17 transmitted from the operation source 9 and newly registering it in the mirror position request management table 34.
  • the mirror position selection unit 41 is the case where the mirror position request 17 is given from the operation source 9 and the 5-tuple information of the target traffic specified in the mirror position request 17 in the mirror position request management table 34. If all the same records already exist, no records are added.
  • the mirror position selection unit 41 notifies the operation source 9 as a mirror position response 18.
  • the mirror position candidate enumeration unit 42 sequentially reads the mirror position request 17 registered in the mirror position request management table 34, and the network topology information table 32 and communication analysis described later for the target traffic specified in the read mirror position request 17.
  • the information table group 33 is used to list one communication device 4 or a combination of a plurality of communication devices 4 that can be mirrored without omission or duplication as mirror position candidates (hereinafter referred to as mirror position candidates), and Is stored in the mirror position candidate management table group 35.
  • the sufficiency combination selecting unit 43 selects all the communication devices 4 constituting the mirror position candidate from the mirror position candidates of the target traffic enumerated by the mirror position candidate listing unit 42 and stored in the mirror position candidate management table group 35. 1, one mirror position candidate whose communication amount of the mirror port MP (FIG. 1) is equal to or less than a mirror port threshold value described later is selected, and this is notified to the mirror position selection unit 41 as a mirror position selection result.
  • a network topology information table 32, a communication analysis information table group 33, a mirror position request management table 34, and a mirror position candidate management table group 35 are stored in the main storage device 22 of the management apparatus 8. ing.
  • the network topology information table 32 is a table used to hold device information of each communication device 4 configuring the data network 2, and as shown in FIG. 5, a communication device ID column 32A, an IP address column 32B, A mirror port bandwidth column 32C and a mirror port threshold column 32D are provided. In the network topology information table 32, one row (record) corresponds to one communication device 4.
  • identifiers (communication device IDs) assigned to the respective communication devices 4 constituting the data network 2 are stored, and in the IP address column 32B, the corresponding communication device 4 receives the above notification.
  • the mirror port bandwidth column 32C stores the maximum bandwidth of the mirror port MP (FIG. 1) of the corresponding communication device 4, and the mirror port threshold value column 32D stores the mirror port of the notification device by a system administrator or the like.
  • a preset threshold value of communication traffic (hereinafter referred to as a mirror port threshold value) is stored.
  • These pieces of information in the network topology information table 32 are set in advance by the system administrator or the like using the input / output device 26 (FIG. 3). However, such information may be set by a system administrator or the like via the control network 7.
  • the communication analysis information table group 33 is a table group for managing information obtained based on the notification information 13 transmitted from each communication device 4 constituting the data network 2, and as shown in FIG. It consists of a communication management table 33A and a route management table 33B.
  • the communication management table 33A is a table used for managing traffic flowing on the data network 2, and as shown in FIG. 6A, a communication ID column 33AA, a transmission source IP address column 33AB, a transmission source port. A number field 33AC, a destination IP address field 33AD, a destination port number field 33AE, and an IP protocol field 33AF are provided. In the communication management table 33A, one row corresponds to one traffic flowing through the data network 2.
  • the communication ID column 33AA stores an identifier (communication ID) unique to the traffic assigned to the corresponding traffic, and includes a source IP address column 33AB, a source port number column 33AC, and a destination IP address column 33AD.
  • a source IP address column 33AB In the destination port number column 33AE and the IP protocol column 33AF, corresponding information (source IP address, source port number, destination IP address, destination port number and IP protocol) of the 5-tuple information of the traffic is stored. Each is stored.
  • These pieces of information stored in the communication management table 33 ⁇ / b> A are information included in the notification information 13.
  • the route management table 33B is a table used for managing various types of information regarding the route of each traffic flowing on the data network 2, and as shown in FIG. 6B, the communication ID column 33BA, the communication device ID.
  • a column 33BB, a traffic column 33BC, a cumulative traffic column 33BD, a reception interface column 33BE, a transmission interface column 33BF, and an acquisition time column 33BG are configured. Also in the route management table 33B, one row corresponds to one traffic flowing through the data network 2.
  • the communication ID column 33BA stores the communication ID of the corresponding traffic
  • the communication device ID column 33BB stores the communication device ID of one of the communication devices 4 through which the corresponding traffic passes.
  • the traffic volume column 33BC stores the data volume (communication volume) per second flowing through the communication device 4 to which the corresponding traffic corresponds
  • the accumulated traffic volume column 33BD stores the corresponding traffic in the corresponding communication device 4. Is stored (hereinafter referred to as the accumulated communication amount).
  • the reception interface column 33BE stores the identifier of the interface that has received the corresponding traffic by the corresponding communication device 4, and the transmission interface column 33BF has transmitted the corresponding traffic by the corresponding communication device 4 to another device. Stores the identifier of the interface. Further, in the acquisition time column 33BG, the time when the management device 8 received the corresponding notification information 13 (more precisely, the time when the corresponding communication device 4 generated the notification information 13 is referred to as the acquisition time. Stored) is stored.
  • the information stored in the communication device ID column 33BB, the accumulated communication amount column 33BD, the reception interface column 33BE, the transmission interface column 33BF, and the acquisition time column 33BG is the corresponding notification.
  • Information acquired from the information 13 and stored in the traffic column 33BC (that is, traffic) is stored in the acquisition time column 33BG and information stored in the cumulative traffic column 33BD (that is, cumulative traffic). It is calculated based on the information (that is, the acquisition time).
  • the mirror position request management table 34 is a table used for holding the mirror position request 17 given from the operation source 9 to the management apparatus 8, and as shown in FIG. A requirement column 34B and a mirror position communication device ID column 34C are provided. In the mirror position request management table 34, one row corresponds to one mirror position request 17.
  • an identifier (request ID) unique to the mirror position request 17 assigned to the mirror position request 17 when the management apparatus 8 receives the corresponding mirror position request 17 is stored.
  • the communication requirement column 34B includes a source IP address column 34BA, a source IP port number column 34BB, a destination IP address column 34BC, a destination port number column 34BD, and an IP protocol column 34BE.
  • the communication device ID of the communication device 4 to be set as the mirror position for the corresponding target traffic specified in the corresponding mirror position request 17 is stored.
  • the mirror position candidate management table group 35 is a table group for holding the mirror position candidates listed by the mirror position candidate listing unit 42 (FIG. 4). As shown in FIG. The candidate position management table 35B is used.
  • the candidate management table 35A is a table used for managing the correspondence between the mirror position request 17 and a candidate ID described later, and as shown in FIG. 8A, the request ID column 35AA and the candidate ID column 35AB. It is configured with.
  • the request ID column 35AA stores a request ID unique to the mirror position request 17 assigned to the mirror position request 17 received by the management apparatus 8, and the candidate ID column 35AB stores a candidate ID described later. Is done.
  • one row corresponds to one candidate ID.
  • the candidate position management table 35B is a table used for managing the mirror position candidates listed by the mirror position candidate listing unit 42. As shown in FIG. 8B, the candidate position management table 35B includes a candidate ID column 35BA, a communication device, and the like. An ID column 35BB and a traffic volume column 35BC are provided.
  • identifiers (candidate IDs) assigned to the respective mirror position candidates enumerated by the mirror position candidate enumeration unit 42 with respect to one mirror position request 17 are stored.
  • different candidate IDs are assigned to these mirror position candidates.
  • the communication device ID column 35BB stores the communication device ID of one communication device 4 constituting the mirror position candidate. Accordingly, when the mirror position candidate is configured by a combination of a plurality of communication devices 4, these communication devices 4 are registered in different rows of the candidate position management table 35B.
  • the traffic volume column 35BC when the corresponding communication device 4 is set as the mirror position of the target traffic, the traffic volume of the target traffic flowing through the mirror port MP (FIG. 1) of the communication device 4 (the mirror port MP) Is stored).
  • FIG. 9 shows the state after the mirror position request 17 is transmitted from the operation source 9 to the management device 8 The flow of a series of processes until the mirror position response 18 corresponding to the mirror position request 17 is transmitted from the management apparatus 8 to the operation source 9 is shown.
  • the management device 8 When the mirror position request 17 designating the 5-tuple of the target traffic and the communication device 4 to be the mirror position as necessary is transmitted from the operation source 9 to the management device 8 (SP1), first, the management device 8 The mirror position selection unit 41 extracts the 5-tuple information of the target traffic included in the mirror position request 17 and the communication device ID of the communication device 4 to be the mirror position from the mirror position request 17, and obtains these pieces of information. It is registered in the mirror position request management table 34 (SP2).
  • the mirror position selection unit 41 thereafter issues a request to enumerate mirror position candidates corresponding to the mirror position request 17 at a predetermined timing (hereinafter referred to as a mirror position candidate enumeration request).
  • the position candidate enumeration unit 42 is given (SP3).
  • the mirror position candidate enumeration unit 42 When the mirror position candidate enumeration unit 42 receives the above-described mirror position candidate enumeration request from the mirror position selection unit 41, the mirror position candidate enumeration unit 42 performs communication analysis information table group 33 for each mirror position request 17 registered in the mirror position request management table 34. Referring to the communication management table 33A (FIG. 6A) and the path management table 33B (FIG. 6B), all the mirror position candidates corresponding to the mirror position request 17 are listed (SP4).
  • the mirror position candidate enumeration unit 42 obtains necessary information regarding the enumerated mirror position candidates from the candidate management table 35A (FIG. 8A) and the candidate position management table 35B (FIG. 8) of the mirror position candidate management table group 35. (B)) is registered (SP5).
  • the mirror position candidate enumeration unit 42 then requests that one mirror position candidate should be selected as a mirror position from these mirror position candidates at a predetermined timing (hereinafter, this is referred to as a satisfaction combination selection request).
  • SP6 To the satisfaction combination selection unit 43 (SP6).
  • the satisfaction combination selection section 43 configures the mirror position candidates from the mirror position candidates registered in the mirror position candidate management table group 35. For all the communication devices 4 that perform this, one mirror position candidate is selected at which the traffic of the mirror port MP (FIG. 1) is equal to or less than the mirror port threshold (SP7). The sufficiency combination selection unit 43 selects one such mirror position candidate for each mirror position request 17. Then, the satisfaction combination selection unit 43 notifies the mirror position selection unit 41 of the mirror position selection result for each mirror position request 17 obtained in this way (SP8).
  • the mirror position selection unit 41 is notified from the satisfaction combination selection unit 43 of a mirror position selection result (a set of request ID 34A (FIG. 7) and a plurality of communication device IDs 32A (FIG. 5)) for each mirror position request 17 described above. Then, the communication requirement 34B corresponding to the request ID 34 included in the mirror position selection result is obtained by referring to the mirror position request management table 34, and the communication device ID 32A corresponding to the obtained communication requirement 34B and the mirror position selection result is obtained. Is created (SP9), and the created mirror position response 18 is transmitted to the operation source 9 (SP10).
  • FIG. 10 shows notification information transmitted from each communication device 4 constituting the data network 2 13 shows the specific processing contents of processing (hereinafter referred to as network information analysis processing) executed by the network information analysis unit 40 (FIG. 4) that has received 13 (FIG. 1).
  • network information analysis processing executed by the network information analysis unit 40 (FIG. 4) that has received 13 (FIG. 1).
  • the network information analysis unit 40 analyzes the notification information 13 in accordance with the processing procedure shown in FIG. 10 and stores necessary information in the communication analysis information table group 33.
  • IPFIX is applied as the communication information notification function 12 (FIG. 1) of the communication device 4 as described above, and the description will be made on the assumption that the notification information 13 is an IPFIX message.
  • the IPFIX message is a message having the data structure shown in FIG. That is, the IPFIX message 50 includes an IP header 50A, a UDP header 50B, an IPFIX header 50C, and a payload portion 50D.
  • the payload portion 50D is associated with each traffic passing through the communication device that is the source of the IPFIX message 50.
  • the 5-tuple information (source IP address, destination IP address, source port number, destination port number and IP protocol) of the traffic and the identifier (“input physical IF” and the physical interface for inputting / outputting the traffic)
  • a data set 51 including information such as “output physical IF”) and cumulative communication amount (“cumulative communication amount”) is stored.
  • the network information analysis unit 40 When the network information analysis unit 40 receives the notification information 13 as described above transmitted from any one of the communication devices 4 constituting the data network 2, the network information analysis unit 40 starts the network information analysis process shown in FIG.
  • the source IP address included in the IP header 50A (FIG. 11) of the notification information 13 is compared with the IP address 32B of the network topology information table 32 (FIG. 5), and the communication device 4 that is the source of the notification information
  • the communication device ID is acquired (SP20). Further, the network information analysis unit 40 acquires the Unix time (“Unix (registered trademark) Secs”) stored in the IPFIX header 50C (FIG. 11) of the notification information 13 as the acquisition time of the notification information 13 (SP21). .
  • Unix time (“Unix (registered trademark) Secs”
  • the network information analysis unit 40 extracts one data set 51 (FIG. 11) from the payload portion 50D (FIG. 11) of the notification information 13 (SP22), and the 5-tuple information included in the acquired data set 51. It is determined whether or not a record having the same 5-tuple information exists in the communication management table 33A (FIG. 6A) of the communication analysis information table group 33 (SP23).
  • the network information analysis unit 40 assigns a unique communication ID to the traffic corresponding to the data set 51 extracted in step SP22, and includes the communication ID and 5 included in the data set 51.
  • the tuple information is newly registered in the communication management table 33A (SP24).
  • the network information analysis unit 40 stores the communication ID assigned to the traffic in the communication ID column 33AA of the new row in the communication management table 33A, and the source IP address column 33AB, source port of the row.
  • the number field 33AC, the destination IP address field 33AD, the destination port number field 33AE, and the IP protocol field 33AF corresponding information of the 5-tuple information included in the data set 51 extracted in step SP22 is stored.
  • the network information analysis unit 40 thereafter registers the traffic route corresponding to the data set 51 extracted in step SP22 in the route management table 33B (FIG. 6B) (SP25).
  • the network information analysis unit 40 stores the communication ID assigned to the traffic at step SP24 in the communication ID column 33BA of the new line in the route management table 33B, and steps into the communication device ID column 33BB of the row. Stores the communication device ID acquired in SP20.
  • the network information analyzing unit 40 adds corresponding information of the identifier of the reception physical interface and the identifier of the transmission physical interface included in the data set 51 extracted in step SP22 to the reception interface column 33BE and the transmission interface column 33BF of the row. And the acquisition time of the communication information acquired in step SP21 is stored in the acquisition time column 33BG of the row. Furthermore, the network information analysis unit 40 stores the accumulated communication amount included in the data set 51 extracted in step SP22 in the communication amount column 33BC and the accumulated communication amount column 33BD of the row.
  • step SP25 the process proceeds to step SP29.
  • obtaining a negative result in the determination at step SP23 means that the traffic corresponding to the data set 51 extracted at step SP22 has already been registered in the communication analysis information table group 33.
  • the network information analysis unit 40 acquires the communication ID of the traffic already registered in the communication analysis information table group 33 from the communication management table 33A (FIG. 6A) (SP26).
  • the network information analysis unit 40 matches the communication ID stored in the communication ID column 33BA in the record of the route management table 33B (FIG. 6B) with the communication ID acquired in step SP26 and the communication device ID. It is determined whether there is a record in which the communication device ID stored in the column 33BB matches the communication device ID acquired in step SP20 (SP27).
  • step SP27 registers the new route of the traffic in the route management table as described above, and then proceeds to step SP29.
  • obtaining a positive result in the determination at step SP27 means that the traffic has already been registered in the communication analysis information table group 33 and there is no change in the route.
  • the network information analysis unit 40 updates the traffic volume stored in the traffic volume column 33BC of the line corresponding to the traffic in the route management table 33B (SP28).
  • the network information analysis unit 40 uses CCV1 as the cumulative communication amount included in the data set 51 extracted at step SP22, T1 as the generation time of the notification information 13 acquired at step SP21, and the corresponding record detected at step SP26.
  • CCV2 is the cumulative communication amount stored in the cumulative communication amount column 33BD
  • T2 is the time stored in the acquisition time column 33BG of the record
  • the traffic stored in the column 33BC is expressed as Is updated to the communication amount CV calculated by.
  • the network information analysis unit 40 determines whether or not the processing of step SP23 to step SP28 has been executed for all the data sets 51 stored in the payload portion 50D (FIG. 11) of the notification information 13 received at that time. (SP29). If the network information analysis unit 40 obtains a negative result in this determination, it returns to step SP22, and thereafter, the data set 51 selected in step SP22 is sequentially switched to another unprocessed data set 51 while step SP22 to step SP22. The processing of SP29 is repeated.
  • the network information analysis unit 40 eventually obtains a positive result at step SP29 by completing the processing of step SP23 to step SP28 for all the data sets 51 stored in the payload portion 50D of the notification information 13 received at that time. And this network information analysis processing is complete
  • FIG. 12 is executed by the mirror position candidate enumeration unit 42 (FIG. 4) to which the mirror position candidate enumeration request is given from the mirror position selection unit 41 (FIG. 4).
  • the specific processing content of the processing (the processing of step SP4 in FIG. 9 and hereinafter referred to as mirror position candidate enumeration processing) is shown.
  • the mirror position candidate enumeration unit 42 for each mirror position request 17 registered in the mirror position request management table 34 (FIG. 7), in accordance with the processing procedure shown in FIG. All the position candidates are detected (enumerated), and each mirror position candidate for each detected mirror position request 17 is registered in the mirror position candidate management table group 35 (FIG. 4).
  • the mirror position candidate enumeration unit 42 when receiving the mirror position candidate enumeration request 42, the mirror position candidate enumeration unit 42 starts the mirror position candidate enumeration process shown in FIG.
  • One record (mirror position request 17) is selected, and its contents are stored as record R (SP30).
  • the mirror position candidate listing unit 42 obtains a traffic set T that satisfies the communication requirements of the record R (SP31). Specifically, the mirror position candidate listing unit 42 sets the communication requirement of the record R selected in step SP30 among the records of the communication management table 33A (FIG. 6B) of the communication analysis information table group 33 (FIG. 6). Each communication ID stored in the communication ID column 33AA (FIG. 6A) of each record to be satisfied is acquired, and these acquired communication IDs are stored as a set T.
  • the record R is a record corresponding to the mirror position request 17 “req2” in FIG. 7 (record on the second line from the top in FIG. 7), this is indicated in the communication management table 33A (FIG. 6A). Since the record satisfying the communication requirement of the record R is a record corresponding to the traffic of the communication ID “trM” (record on the third line from the top in FIG. 6A), the mirror position candidate enumeration unit 42 The communication ID “trM” is stored as a set T.
  • the record R corresponds to the mirror position request 17 “req1” in FIG. 7 (this is a mirror position request for requesting the mirror position for all traffic input to the computer 3 whose IP address is “10.2.0.50”).
  • the record satisfying the communication requirement of the record R in the communication management table 33A is a record corresponding to the traffic with the communication ID “trK” (record on the first line from the top in FIG. 6A).
  • “TrL” is a record corresponding to the traffic of the communication ID “trL” (record on the second line from the top in FIG. 6A), the mirror position candidate enumeration unit 42 “trK” which is the communication ID of these traffics.
  • “trL” is stored as a set T.
  • the mirror position candidate listing unit 42 selects a set P of records corresponding to each traffic obtained in step SP31 from the records in the route management table 33B (FIG. 6B) of the communication analysis information table group 33. Obtain (SP32). Specifically, the mirror position candidate enumeration unit 42 selects any one of the records in the path management table 33B whose communication ID stored in the communication ID column 33BA (FIG. 6B) belongs to the set T obtained in step SP31. A record matching the communication ID is detected, and a set of the records is set as a set P.
  • the mirror position candidate listing unit 42 determines whether or not the number of elements of the set P obtained in step SP32 is greater than 0 (SP33).
  • Obtaining a negative result in this determination means that there is no traffic that satisfies the communication request of the mirror position request 17 corresponding to the record R selected in step SP30 or there is no route of the traffic (for example, the record R is the first line in FIG. 7). In other words, the traffic having “10.2.0.50” as the destination IP address or the route of the traffic does not exist).
  • the mirror position candidate listing unit 42 transmits an error notification to the mirror position selection unit 41 (SP38), and then proceeds to step SP44.
  • the mirror position selection unit 41 receives the error notification from the mirror position candidate listing unit 42 and transmits the mirror position response 18 corresponding thereto to the operation source 9.
  • obtaining a positive result in the determination in step SP33 means that there is traffic or a route of the traffic that satisfies the communication request of the mirror position request 17 corresponding to the record R selected in step SP30.
  • the mirror position candidate listing unit 42 determines whether the communication device ID of any communication device is stored in the mirror position communication device ID column 34C (FIG. 7) of the record R selected in step SP40 (step S40). It is determined whether or not the communication device 4 to be the mirror position is specified in the mirror position request 17 corresponding to the record R selected in SP30 (SP34).
  • the mirror position candidate listing unit 42 is stored in the mirror position communication device ID column 34C of the record R selected in step SP30 from the records belonging to the set P in the route management table 33B. All the records whose communication device IDs are stored in the communication device ID column 33BB (FIG. 6B) are extracted, and the extracted record group is stored as a set F (SP35).
  • the mirror position candidate listing unit 42 determines whether or not the number of elements of the set F obtained in step SP35 is greater than 0 (SP36).
  • the target traffic specified in the mirror position request 17 corresponding to the record R selected in step SP30 passes through the communication device 4 specified as the mirror position in the mirror position request 17. Means no.
  • the mirror position candidate listing unit 42 transmits an error notification to the mirror position selection unit 41 (SP38), and then proceeds to step SP44.
  • obtaining a positive result in the determination at step SP36 means that the traffic specified in the mirror position request 17 corresponding to the record R selected in step SP30 is the communication specified as the mirror position in the mirror position request 17. This means that the device 4 is being routed.
  • the mirror position candidate listing unit 42 selects the communication device 4 specified in the mirror position request 17 as a mirror position candidate corresponding to the mirror position request 17 corresponding to the record R selected in step SP30.
  • the candidate registration process mentioned later is performed (SP37). Further, after completing the candidate registration process, the mirror position candidate listing unit 42 proceeds to step SP44.
  • the mirror position candidate listing unit 42 uses the record set P of the route management table 33B (FIG. 6B) obtained at step SP32 as the record set for each traffic. Classify into P1 to Pn (SP39). Specifically, the mirror position candidate enumeration unit 42 uses the records P having the same communication ID stored in the communication ID column 33BA (FIG. 6B) as the set P of the records in the route management table 33B obtained in step SP32. Into sets P1 to Pn.
  • the communication device IDs of all the communication devices 4 through which the traffic passes are obtained as a set Si. .
  • the mirror position candidate listing unit 42 executes a candidate search process to be described later in order to search for a mirror position candidate corresponding to the mirror position request 17 corresponding to the record R selected in step SP30 (SP41).
  • the mirror position candidate listing unit 42 stores necessary information of all candidates Ui obtained by the candidate search process in step SP41 (more precisely, all sets Vi converted in step SP42) in the mirror position candidate management table group 35.
  • a candidate registration process for registration is executed (SP43).
  • the mirror position candidate listing unit 42 performs the processing of steps SP31 to SP43 for all the records in the mirror position request management table 34 (FIG. 7) (for all mirror position requests 17 registered in the mirror position request management table 34). It is determined whether or not the execution of the process has been completed (SP44).
  • the mirror position candidate listing unit 42 When the mirror position candidate listing unit 42 obtains a negative result in this determination, it returns to step SP30, and then sequentially switches the record R selected in step SP30 to another record that has not been processed, and then performs the processing in steps SP30 to SP44. repeat.
  • the mirror position candidate enumeration unit 42 executes the processing of steps SP31 to SP43 for all the records in the mirror position request management table 34 (for all the mirror position requests 17 registered in the mirror position request management table 34). If a positive result is obtained in step SP44 by finishing, this mirror position candidate enumeration process is terminated.
  • the mirror position candidate enumeration unit 42 proceeds to step SP41 of the mirror position candidate enumeration process, the mirror position candidate enumeration unit 42 starts the candidate search process shown in FIG. 13, and first selects one communication device ID included in each of the sets S1 to Sn. A set C1 including each of them is created (SP50).
  • step SP50 the unit 42 collects all kinds of elements of the sets S1 to S4 so as not to overlap, which is 7 A, B, C, D, E, F, G.
  • a set C1 having one communication device ID as an element is created.
  • the mirror position candidate listing unit 42 creates a power set of the set C1 created in step SP50, and removes the remaining elements (excluding the empty set and two sets having the same value as C1 from the power set. That is, zero or more sets including the heel set) are set as sets C2 to Cp, respectively (SP51).
  • sets C2 to Cp which are two smaller than the number of elements in the set of sets C1, are created.
  • the mirror position candidate enumeration unit 42 extracts from the sets C1 to Cp a set in which the number of elements in the common part with each set of the sets S1 to Sn is all 1, and sets these as candidates U1 to Uq. (SP52). For example, as shown in FIG. 14 (D), a set C9 having two communication device IDs A and B as elements has two common part elements in the set S1, and therefore may be a candidate Ui. However, the set C13 having two communication device IDs A and F as elements is extracted as a candidate because there is one common element in all of the sets S1 to S4.
  • the purpose of the SP 42 is to calculate a combination of mirror positions for mirroring a plurality of traffics that are simultaneously mirrored to satisfy the mirror position request 17 without collection omission or duplication.
  • each of the sets S1 to Sn represents a communication path as a communication device ID of the communication device 4 for each set of traffic, in order to mirror Si without collection omission or duplication, an element of the set Si is used.
  • the one or more communication device IDs exactly one communication device ID may be selected as the mirror position (when 0, traffic is not collected, and when there are 2 or more, one traffic is duplicated) And mirror it).
  • a set of communication device IDs that select exactly one communication device ID from each set as a mirror position is a set of communication devices ID for which all sets S1 to Sn represent communication paths. Represents a combination of mirror positions where collection omissions and duplication do not occur even when mirroring at the same time.
  • the number of elements in the common part is used to determine whether the set Ck has just selected one communication device ID among the elements of the set Si.
  • the mirror position candidate listing unit 42 ends this candidate search process, and uses the candidates U1 to Uq as shown in FIG. 14E obtained in step SP52 of this candidate search process, as shown in FIG. Step SP41 of the mirror position candidate enumeration process described above is executed.
  • FIG. 15 shows specific contents of the candidate registration process executed by the mirror position candidate enumeration unit 42 in step SP37 or step SP43 of the mirror position candidate enumeration process (FIG. 12).
  • the mirror position candidate enumeration unit 42 starts this candidate registration process.
  • the unique candidate to be given to the mirror position candidate to be registered at that time An ID is generated, and the generated candidate ID is assigned to the request ID column 34A (in the record (record R) of the mirror position request management table 34 (FIG. 7) selected in step SP30 of the mirror position candidate enumeration process (FIG. 12) ( It is registered in the candidate management table 35A (FIG. 8A) of the mirror position candidate management table group 35 (FIG. 8) in association with the request ID stored in FIG. 7 (SP60).
  • the mirror position candidate listing unit 42 in the case of step SP37 of the mirror position candidate listing process, in the corresponding record in the route management table 33B (FIG. 6B) of the communication analysis information table group 33 (FIG. 6). Records belonging to the record set F, records belonging to the record set V1 to Vm in the case of step SP43), and those having the same communication device ID stored in the communication device ID column 33BB (FIG. 6B) The records are grouped together, and the record groups having the same communication device ID obtained by the classification are set as sets X1 to Xp, respectively (SP61).
  • the mirror position candidate listing unit 42 associates the total communication amount calculated in step SP63 and the communication device ID corresponding to the selected record group Xi with the candidate ID generated in step SP60, and the mirror position candidate management table group 35.
  • the candidate position management table 35B (FIG. 8B) (FIG. 8B) of FIG. 8 is registered (SP64). Thereafter, the processing of steps SP63 to SP64 is performed for all sets X1 to Xp obtained by the classification of step SP61. It is determined whether or not the execution has been completed (SP65).
  • step SP62 When the mirror position candidate listing unit 42 obtains a negative result in this determination, it returns to step SP62, and then sequentially switches the set Xi selected in step SP62 to another set Xi that has not been processed, and then proceeds from step SP62 to step SP65. Repeat the process.
  • FIG. 16 shows processing executed by the satisfaction combination selection unit 43 that has received the combination search request from the mirror position candidate listing unit 42 (in the process of step SP7 in FIG. 9). Yes, this is hereinafter referred to as a satisfaction combination selection process).
  • the sufficiency combination selection unit 43 follows the processing procedure shown in FIG. 16 for each mirror position request 17 and selects one mirror from the mirror position candidates enumerated by the mirror position candidate enumeration unit 42. A position candidate is selected, and the selected mirror position candidate is notified to the mirror position selection unit 41 as a mirror position selection result.
  • the satisfaction combination selection unit 43 when the satisfaction combination selection unit 43 receives such a combination search request, the satisfaction combination selection unit 43 starts the satisfaction combination selection process shown in FIG. 16, and first, a candidate management table 35A (FIG. 8) configuring the mirror position candidate management table group 35.
  • a set of candidate IDs C1 to Cn is generated by classifying the candidate IDs stored in the candidate ID column 35AB (FIG. 8A) of each record of (A)) for each requirement ID (SP70). Accordingly, the sets C1 to Cn correspond to different requirement IDs.
  • the sufficiency combination selection unit 43 extracts candidate IDs one by one from the sets C1 to Cn generated in step SP70 and stores them as a set of candidate IDs Sk. As many sets Sk as the number of combinations of candidate IDs that are unique are created and stored as candidate ID sets S1 to Sp (SP71).
  • the sufficiency combination selection unit 43 sets the variable k to 1 (SP72), and corresponds to each candidate ID included in the candidate ID group Sk among the records of the candidate position management table 35B (FIG. 8B).
  • Each of the records that is, each record in which any candidate ID included in the candidate ID group Sk is stored in the candidate ID column 35BA (FIG. 8B)
  • the total value of the stored traffic is calculated for each communication device ID (SP73).
  • the sufficiency combination selection unit 43 refers to the network topology information table 32 (FIG. 5), and in all the communication devices 4 respectively corresponding to the respective communication device IDs for which the total value of the communication amount has been calculated in step SP73. Then, it is determined whether or not the total value is less than or equal to the mirror port threshold (SP74).
  • the satisfaction combination selection unit 43 determines whether or not the value of the variable k is equal to or greater than the number of candidate ID groups S1 to Sp described above (SP75). If the satisfaction combination selection unit 43 obtains a negative result in this determination, it increments (increases by 1) the value of the variable k (SP76), returns to step SP73, and thereafter gives a positive result in step SP74 or step SP75. Steps SP73 to SP76 are repeated until it is obtained.
  • the sufficiency combination selecting unit 43 eventually selects a candidate ID group Sk in which the total amount of traffic in all the communication devices 4 from the candidate ID groups S1 to Sp enumerated in step SP71 is less than or equal to the mirror port threshold of the communication device 4.
  • a positive result is obtained in step SP74 by first detecting the ID, the requirement ID indicated by the candidate included in the candidate ID group Sk and the correspondence relationship between the communication device IDs are selected as mirror positions (SP78). Then, the satisfaction combination selection process is terminated.
  • the sufficiency combination selecting unit 43 can detect a candidate ID group Sk in which the total value of the communication amount is less than or equal to the mirror port threshold value of the communication device 4 among the candidate ID groups Sk listed in step SP71. If a positive result is obtained in step SP75, a predetermined error notification is transmitted to the mirror position selection unit 41 (SP77), and then the satisfaction combination selection process is terminated.
  • FIG. 17 shows a mirroring status display screen 60 that can be displayed on the client terminal 15 (FIG. 1) or the operation management apparatus 16 (FIG. 1) of the operation source 9 by a predetermined operation.
  • the mirroring status display screen 60 displays the mirroring status of traffic that has a mirror position set in the traffic flowing through the data network 2, and the traffic on the mirror port MP of the traffic in each communication device 4 that is set to the mirror position. Is a screen for presenting to the user.
  • the mirroring status display screen 60 includes a mirror acquisition status display area 61 and a mirror port traffic display area 62.
  • the mirror acquisition status display area 61 is an area for displaying the mirroring acquisition status in the data network 2
  • the mirror port traffic display area 62 is a mirror of the communication device 4 set as the mirror position in the data network 2. This is an area for displaying the traffic of the port MP.
  • one or more communication device icons 70 are displayed in correspondence with the communication devices 4 constituting the data network 2.
  • the target traffic line 71 represents a path of traffic (target traffic) that is mirrored, and the mirror position icon 72 corresponds to the communication device icon 70 of the communication device 4 that is mirroring the target traffic. Is displayed.
  • the target traffic line 71 is displayed in a different color or line type (solid line or broken line) for each mirror position request 17 (request ID), and the correspondence between the target traffic and the target traffic line 71 is displayed in the legend 73.
  • two-dimensional coordinates 80 are displayed with the traffic volume on the vertical axis and the time on the horizontal axis.
  • a specific communication device icon 70 communication device icon 70 corresponding to the communication device 4 set at the mirror position
  • the communication device corresponding to the communication device icon 70 is displayed.
  • One or a plurality of graphs 81 each representing the traffic amount of each target traffic in the four mirror ports MP are displayed in a two-dimensional coordinate 80 in a stacked graph format.
  • a threshold line 82 indicating the threshold of the traffic amount of the mirror port MP is also displayed.
  • the graph 81 for each target traffic in the two-dimensional coordinate 80 is a traffic volume column 33BC in the row corresponding to the communication device 4 of the target traffic in the path management table 33B described above with reference to FIG. 6B (FIG. 6B).
  • the threshold line 82 is generated based on the mirror port threshold value of the communication device 4 registered in the network topology information table 32 described above with reference to FIG.
  • the mirror position candidate enumeration unit 42 identifies and identifies all the communication devices 4 through which the target traffic passes. All combinations of these communication devices 4 are listed as mirror position candidates, and thereafter, in the satisfaction combination selection unit 43, the mirror position candidates are configured from the mirror position candidates listed by the mirror position candidate listing unit 42. For all the communication devices 4, one mirror position candidate whose communication amount of the mirror port MP is equal to or less than a mirror port threshold value to be described later is selected, and this is notified to the mirror position selection unit 41 as a mirror position selection result.
  • the communication device 4 that does not cause congestion in the mirror port MP can be selected as the mirror position, and thus the mirror position (where the mirrored traffic can be executed without discarding the mirrored traffic) The communication device 4) can be selected quickly.
  • FIG. 18 which shows the same reference numerals corresponding to FIGS. 1 to 4, shows a logical configuration of a communication system 90 according to the second embodiment.
  • This communication system 90 performs the reselection of the mirror position when the free bandwidth of the mirror port MP (FIG. 1) of the communication device 91 is below a certain amount, and when the reselection of the mirror position is unnecessary. It is characterized in that a user or the like can be set so as not to perform such reselection.
  • the hardware configuration and other functions of the communication system 90 according to the present embodiment are the same as those of the communication system 1 according to the first embodiment, and a description thereof will be omitted here.
  • a band information output function 92 is installed in the communication device 91.
  • This band information output function 92 uses the current use band of the mirror port MP of the communication device 91 (hereinafter referred to as the mirror port use band) as mirror port band information 93 at a predetermined time interval set as a control network.
  • 7 is a function of transmitting to the management apparatus 94 via 7.
  • Such a function is publicly known, and for example, a function of an SNNP (Simple Network Management Protocol) agent provided in a general communication apparatus can be applied.
  • SNNP Simple Network Management Protocol
  • the management device 94 is the same as that of the first embodiment except that the mirror port bandwidth monitoring unit 100 is provided, the function of the mirror position selection unit 101 is different, and the configuration of the mirror position request management table 102 is different.
  • the configuration is the same as that of the management device 8.
  • the mirror port bandwidth monitoring unit 100 and the mirror position selection unit 101 according to the present embodiment execute the management program 103 (FIG. 3) of the present embodiment stored in the main storage device 22 by the processor of the management device 8. It is a function that is embodied.
  • the mirror port bandwidth monitoring unit 100 performs processing for monitoring the mirror port usage bandwidth of each communication device 91 based on the above-described mirror port bandwidth information 93 transmitted from each communication device 91 constituting the data network 2. Execute.
  • the mirror port bandwidth monitoring unit 100 refers to the network topology information table 32 (FIG. 5) and the mirror port bandwidth information 93. Is specified in the communication device ID column 32A (FIG. 5), and the mirror port threshold column 32D (FIG. 5) of the record is specified. From this, the mirror port threshold value of the communication device 91 is acquired.
  • the mirror port bandwidth monitoring unit 100 compares the acquired mirror port threshold value with the current mirror port usage bandwidth stored in the mirror port bandwidth information 93, and the mirror port usage bandwidth is greater than the mirror port threshold value. In this case, a mirror position reselection request is given to the mirror position selection unit 101.
  • the mirror position request 103 transmitted from the operation source 9 to the management apparatus 94 is fixed to the mirror position in addition to one or more combinations of communication requirements and mirror position communication apparatus ID. It differs from the communication system 1 of the first embodiment in that a flag is included.
  • the mirror position fixing flag is a Boolean value indicating whether the mirror position of the target traffic can be changed from the communication apparatus 91 once set to another communication apparatus 91, and is “true (cannot be changed)” or “false (changeable). ) ”.
  • the mirror position request management table 102 of the present embodiment has a request ID column 34A and a communication requirement column 34B of the mirror position request management table 34 of the first embodiment described above with reference to FIG.
  • a mirror position fixing flag column 102D is provided in addition to the request ID column 102A, the communication requirement column 102B, and the mirror position communication device ID column 102C having the same function and configuration as the mirror position communication device ID column 34C.
  • the mirror position fixing flag included in the mirror position request 103 received by the selection unit 101 is stored and managed in this mirror position fixing flag column 102D.
  • the mirror position selection unit 101 has a mirror position fixing flag included in the mirror position request 103 of “false”. If the mirror port bandwidth monitoring unit 100 gives the above-described mirror position reselection request, the function for re-selecting the mirror position is executed. It is equipped with functions.
  • the mirror position selection unit 101 registers this in the mirror position request management table 102 as in the case of the mirror position selection unit 41 of the first embodiment.
  • a mirror position candidate enumeration request is given to the mirror position candidate enumeration unit 42 at a predetermined timing.
  • the request included in this notification (mirror position selection result) on the mirror position request management table 102.
  • a record in which the same request ID as the ID is stored in the request ID column 102A (FIG. 19) is searched, and the mirror position fixing flag stored in the mirror position fixing flag column 102D (FIG. 19) of the record detected by this search is acquired. To do.
  • the mirror position selection unit 101 stores the record of the candidate position management table 35B (FIG. 8B) in the mirror position candidate management table group 35.
  • a record in which the same candidate ID as the candidate ID included in the mirror position selection result is stored in the candidate ID column 35BA (FIG. 8B) is detected, and the communication device ID column 35BB (FIG. 8) of the record is detected.
  • the communication device ID stored in (B)) (hereinafter referred to as a candidate communication device ID) is acquired.
  • the mirror position selection unit 101 has the same request ID as the request ID included in the mirror position selection result given from the satisfaction combination selection unit 43 among the records in the mirror position request management table 102.
  • the record stored in FIG. 19) is detected, and the candidate communication device ID acquired as described above is stored in the mirror position communication device ID column 102C (FIG. 19) of the record.
  • the mirror position selection unit 101 does not update the value.
  • the other processes are the same as the processes after step SP9 in FIG. 9 described above for the first embodiment.
  • the mirror position selection unit 101 performs the same processing as the mirror position selection unit 41 (FIG. 4) of the first embodiment. I do.
  • the mirror position selection unit 101 executes the same process as when the mirror position request 103 is given from the operation source 9 described above.
  • the mirror position is automatically reselected when the mirror port bandwidth of the communication device 91 exceeds the threshold value (mirror port threshold value) set for the mirror port MP.
  • the result is notified to the operation source 9 as a mirror position response 18.
  • the mirror port use band of the communication device 91 exceeds a predetermined mirror port threshold (that is, the empty band of the mirror port MP is less than a certain amount).
  • a predetermined mirror port threshold that is, the empty band of the mirror port MP is less than a certain amount.
  • the mirror position is reselected, so that it is possible to prevent the occurrence of a situation in which the mirror port congestion occurs in the communication device 4 set at the mirror position and the mirrored traffic is discarded. it can.
  • the mirror position can be fixed by setting the mirror position fixing flag to “true” in the mirror position request. Therefore, the mirror position is changed for important traffic. It is possible to prevent a momentary interruption of traffic collection.
  • the network information analysis unit 40 the mirror position selection unit 41, the mirror position candidate listing unit 42, and the satisfaction combination of the management devices 8 and 94 are provided.
  • the selection unit 43 and the mirror port bandwidth monitoring unit 100 are configured as software has been described, the present invention is not limited to this, and some or all of these may be configured as hardware.
  • the mirroring status display screen 60 described above with reference to FIG. 17 among the traffic flowing through the data network 2, the status of mirroring of the traffic whose mirror position is set, and the mirror
  • the present invention is not limited to this, for example, the mirroring status display screen 60 May be used to add traffic that is being mirrored, specify a mirror position, and perform access control for each user.
  • the table format is applied as the format for holding information such as communication analysis information and network topology information
  • the present invention is not limited to this.
  • various other formats can be widely applied.
  • the present invention is not limited to this, and a dedicated device may be provided separately from the management device used by the system administrator for managing the data network 2, and such a mirror position selection function may be installed in the dedicated device.
  • the present invention can be widely applied to various communication systems.

Abstract

[Problem] To enable a quick selection of a communication device capable of executing port mirroring without discarding mirrored traffic. [Solution] At the time of selecting a communication device for conducting port mirroring of a traffic flowing through a network constituted by a plurality of communication devices, communication devices through which traffics flowing through the network pass are determined; a traffic that is to be port-mirrored is determined; all communication devices through which the determined traffic passes are determined; combinations of the communication devices for conducting port mirroring among the determined communication devices are listed; and, from among the listed combinations of the communication devices, a combination such that, in the communication devices constituting the combinations, no congestion will occur at the mirror port of the communication devices for conducting port mirroring is selected.

Description

情報処理装置及びポートミラーリング位置選定方法Information processing apparatus and port mirroring position selection method
 本発明は、情報処理装置及びポートミラーリング位置選定方法に関し、例えば、IaaS(Infrastructure As A Service)を提供するクラウド事業者の通信システムに適用して好適なものである。 The present invention relates to an information processing apparatus and a port mirroring position selection method, and is suitable for application to, for example, a communication system of a cloud provider that provides IaaS (Infrastructure As Service).
 業務用コンピュータシステムの構築に必要なサーバ装置、ストレージ装置及びネットワークといったコンピュータ資源一式が利用できる環境を、ネットワークを介して顧客に提供するIaaSと呼ばれるサービスを利用する企業が増えてきている。IaaSの顧客は、提要されたコンピュータ資源を用いてウェブアプリケーションなどのIT(Internet Technology)システムを構築する。 An increasing number of companies use a service called IaaS that provides a customer with an environment in which a set of computer resources such as a server device, a storage device, and a network necessary for building a business computer system can be used. An IaaS customer constructs an IT (Internet Technology) system such as a web application using the provided computer resources.
 近年、IaaS上の顧客アプリケーションも信頼性が求められるようになったことを受け、IaaSを提供するクラウド事業者に対して、アプリケーション性能の監視サービスを提供する期待が高まっている。 In recent years, as customer applications on IaaS have also been required to be reliable, there is an increasing expectation that cloud service providers that provide IaaS will provide application performance monitoring services.
 しかしながら、アプリケーション性能が監視する際、IaaSを提供するクラウド事業者が顧客により様々なアプリケーション実行基盤に対して監視ソフトウェアを一律に適用することは困難である。よって、IaaS上でアプリケーション性能の監視サービスを行う手法としては、アプリケーションのトラヒックを基に応答時間などを解析するパッシブ型の性能監視が適している。 However, when the application performance is monitored, it is difficult for the cloud provider providing IaaS to uniformly apply the monitoring software to various application execution platforms by customers. Therefore, as a technique for performing application performance monitoring service on IaaS, passive performance monitoring that analyzes response time based on application traffic is suitable.
 パッシブ型の性能監視を行うには、監視対象のアプリケーションのトラヒックを解析装置に集める必要がある。これは、IaaSの物理ネットワークを構成するスイッチやルータといった通信装置でポートミラーリング(以下、これを単にミラーリングと呼ぶ)を行うか、又はネットワーク上の各リンクにタップを接続してトラヒックの信号を分岐することで実現される。 In order to perform passive performance monitoring, it is necessary to collect the application traffic to be monitored in the analyzer. This can be done by port mirroring (hereinafter referred to simply as mirroring) using a communication device such as a switch or router that constitutes an IaaS physical network, or by connecting a tap to each link on the network to branch the traffic signal. It is realized by doing.
 この場合、タップは無条件でパケットを複製するため、多数の通信が流れるクラウド環境では、複製したパケットを解析装置まで配送するためのネットワークや解析装置に負荷がかかる。よって、クラウド環境でパケットを収集する際は、性能監視を行いたいアプリケーションのトラヒックのみに絞ってパケットを収集できるミラーリングを使うことが望ましい。 In this case, since the tap duplicates the packet unconditionally, in a cloud environment where a large number of communications flow, a load is imposed on the network and the analysis device for delivering the duplicated packet to the analysis device. Therefore, when collecting packets in a cloud environment, it is desirable to use mirroring that can collect packets only for the traffic of the application whose performance is to be monitored.
 しかしながら、多数の通信装置からなる環境で、特定のトラヒック(以下、これを対象トラヒックと呼ぶ)をミラーリングするためには、ミラーリング設定を行う通信装置(以下、適宜、これをミラー位置と呼ぶ)を迅速に選定する必要がある。 However, in order to mirror specific traffic (hereinafter referred to as target traffic) in an environment including a large number of communication devices, a communication device that performs mirroring settings (hereinafter referred to as a mirror position as appropriate) is used. It is necessary to select quickly.
 以上の課題を解決するための方法として、特許文献1及び特許文献2には、通信の経路情報を基にミラー位置を選定する技術が開示されている。例えば、特許文献1には、物理トポロジ情報に基づいてミラー位置を選定することが開示され、特許文献2には、通信装置内のBGP(Border Gateway Protocol)情報に基づいてミラー位置を選定することが開示されている。 As a method for solving the above problems, Patent Document 1 and Patent Document 2 disclose a technique for selecting a mirror position based on communication path information. For example, Patent Document 1 discloses selecting a mirror position based on physical topology information, and Patent Document 2 discloses selecting a mirror position based on BGP (Border Gateway Protocol) information in a communication device. Is disclosed.
特開2010-245710号公報JP 2010-245710 A 特開2008-92520号公報JP 2008-92520 A
 ところで、前述の特許内でミラー位置を選定する際に用いられる手法では、ミラーリングで複製したパケットの出力インタフェース(以下、これをミラーポートと呼ぶ)の帯域を考慮せずにミラー位置を選定している。 By the way, in the technique used when selecting the mirror position in the above-mentioned patent, the mirror position is selected without considering the bandwidth of the output interface of the packet duplicated by mirroring (hereinafter referred to as the mirror port). Yes.
 通常、通信装置のミラーポートとして設定可能なインタフェースは1~2個であるため、ミラーポートの帯域を考慮してミラー位置を選定しなければ、性能監視を希望するアプリケーションが多数存在する環境では、ミラーポートが輻輳し、収集対象のトラヒックが破棄されるおそれがある。 Normally, there are 1 to 2 interfaces that can be set as the mirror port of the communication device. Therefore, in an environment where there are many applications that require performance monitoring unless the mirror position is selected in consideration of the mirror port bandwidth, There is a possibility that the mirror port is congested and the traffic to be collected is discarded.
 本発明は以上の点を考慮してなされたもので、ミラーリングしたトラフィックが破棄されることなくポートミラーリングを実行可能な通信装置を迅速に選定し得る情報処理装置及びポートミラーリング位置選定方法を提案しようとするものである。 The present invention has been made in view of the above points, and will propose an information processing apparatus and a port mirroring position selection method capable of quickly selecting a communication apparatus capable of performing port mirroring without discarding mirrored traffic. It is what.
 かかる課題を解決するため本発明においては、複数の通信装置から構成されるネットワークを流れるトラヒックのポートミラーリングを行うべき前記通信装置を選定する情報処理装置において、前記通信装置を通過する各前記トラヒックに関する所定のトラヒック情報を各前記通信装置からそれぞれ取得し、取得した各前記トラヒック情報をそれぞれ解析することにより、前記ネットワークを流れる各前記トラヒックがそれぞれ通過する前記通信装置を特定するネットワーク情報解析部と、前記ネットワーク情報解析部の解析結果に基づいて、前記ポートミラーリングの対象とすべき前記トラヒックを特定し、特定した当該トラフィックが通過するすべての前記通信装置を特定し、特定した各前記通信装置でポートミラーリングを行う前記通信装置の組合せを列挙するミラー位置候補列挙部と、前記ミラー位置候補列挙部により列挙された前記通信装置の組合せの中から、当該組合せを構成する前記通信装置において、当該通信装置の前記ポートミラーリングを行うミラーポートにおいて輻輳が発生しない組合せを選定する充足組合せ選定部とを設ける。 In order to solve this problem, the present invention relates to each of the traffic passing through the communication device in an information processing device for selecting the communication device to be subjected to port mirroring of traffic flowing through a network composed of a plurality of communication devices. A network information analyzing unit for acquiring the predetermined traffic information from each of the communication devices, and identifying each of the communication devices through which each of the traffic flowing through the network passes by analyzing each of the acquired traffic information; Based on the analysis result of the network information analysis unit, the traffic to be subjected to the port mirroring is specified, all the communication devices through which the specified traffic passes are specified, and the port of each specified communication device is specified. Said mirroring A mirror position candidate enumeration unit for enumerating combinations of communication devices; and the port mirroring of the communication device in the communication device constituting the combination among the combinations of the communication devices enumerated by the mirror position candidate enumeration unit And a satisfactory combination selection unit for selecting a combination that does not cause congestion in the mirror port.
 また本発明においては、複数の通信装置から構成されるネットワークを流れるトラヒックのポートミラーリングを行うべき前記通信装置を選定する情報処理装置により実行されるポートミラーリング位置選定方法において、情報処理装置が、前記通信装置を通過する各前記トラヒックに関する所定のトラヒック情報を各前記通信装置からそれぞれ取得し、取得した各前記トラヒック情報をそれぞれ解析することにより、前記ネットワークを流れる各前記トラヒックがそれぞれ通過する前記通信装置を特定する第1のステップと、情報処理装置が、解析結果に基づいて、前記ポートミラーリングの対象とすべき前記トラヒックを特定し、特定した当該トラフィックが通過するすべての前記通信装置を特定し、特定した各前記通信装置でポートミラーリングを行う前記通信装置の組合せを列挙する第2のステップと、情報処理装置が、列挙した前記通信装置の組合せの中から、当該組合せを構成する前記通信装置において、当該通信装置の前記ポートミラーリングを行うミラーポートにおいて輻輳が発生しない組合せを選定する第3のステップとを設ける。 Further, in the present invention, in the port mirroring position selection method executed by the information processing apparatus that selects the communication apparatus that should perform port mirroring of traffic flowing through a network composed of a plurality of communication apparatuses, the information processing apparatus includes: The communication device through which each of the traffic flowing through the network passes by acquiring predetermined traffic information regarding each of the traffic passing through the communication device from each of the communication devices, and analyzing each of the acquired traffic information. A first step of identifying the information, and the information processing device identifies the traffic to be subject to the port mirroring based on the analysis result, identifies all the communication devices through which the identified traffic passes, Port on each identified communication device A second step of enumerating the combinations of the communication devices that perform the error ringing, and the information processing apparatus includes the port mirroring of the communication device in the communication device that constitutes the combination among the enumerated combinations of the communication devices. And a third step of selecting a combination that does not cause congestion in the mirror port.
 本発明によれば、ミラーリングしたトラフィックが破棄されることなくポートミラーリングを実行可能なミラー位置(通信装置)を迅速に選定し得る情報処理装置及びポートミラーリング位置選定方法を実現できる。 According to the present invention, it is possible to realize an information processing apparatus and a port mirroring position selection method that can quickly select a mirror position (communication apparatus) that can execute port mirroring without discarding mirrored traffic.
第1の実施の形態による通信システムの全体構成を示すブロック図である。It is a block diagram which shows the whole structure of the communication system by 1st Embodiment. データネットワークの構成例を示すブロック図である。It is a block diagram which shows the structural example of a data network. 管理装置のハードウェア構成を示すブロック図である。It is a block diagram which shows the hardware constitutions of a management apparatus. 管理装置の論理構成を示すブロック図である。It is a block diagram which shows the logical structure of a management apparatus. ネットワークトポロジ情報テーブルの構成を示す概念図である。It is a conceptual diagram which shows the structure of a network topology information table. (A)は通信管理テーブルの構成を示す概念図であり、(B)は経路管理テーブルの構成を示す概念図である。(A) is a conceptual diagram which shows the structure of a communication management table, (B) is a conceptual diagram which shows the structure of a path | route management table. ミラー位置要求管理テーブルの構成を示す概念図である。It is a conceptual diagram which shows the structure of a mirror position request | requirement management table. (A)は候補管理テーブルの構成を示す概念図であり、(B)は候補位置管理テーブルの構成を示す概念図である。(A) is a conceptual diagram which shows the structure of a candidate management table, (B) is a conceptual diagram which shows the structure of a candidate position management table. 操作元から管理装置にミラー位置要求が送信された後、当該ミラー位置要求に対応するミラー位置応答が管理装置からその操作元に送信されるまでの一連の処理の流れを示すシーケンス図である。FIG. 11 is a sequence diagram showing a flow of a series of processes from when a mirror position request is transmitted from an operation source to a management apparatus until a mirror position response corresponding to the mirror position request is transmitted from the management apparatus to the operation source. ネットワーク情報解析処理の処理手順を示すフローチャートである。It is a flowchart which shows the process sequence of a network information analysis process. IPFIXメッセージのデータフォーマットを示す概念図である。It is a conceptual diagram which shows the data format of an IPFIX message. ミラー位置候補列挙処理の処理手順を示すフローチャートである。It is a flowchart which shows the process sequence of a mirror position candidate enumeration process. 候補探索処理の処理手順を示すフローチャートである。It is a flowchart which shows the process sequence of a candidate search process. (A)~(E)は候補探索処理の説明に供する図である。(A) to (E) are diagrams for explaining candidate search processing. 候補登録処理の処理手順を示すフローチャートである。It is a flowchart which shows the process sequence of a candidate registration process. 充足組合せ選定処理の処理手順を示すフローチャートである。It is a flowchart which shows the process sequence of a satisfaction combination selection process. ミラーリング状況表示画面の概略構成を示す図である。It is a figure which shows schematic structure of a mirroring condition display screen. 第2の実施の形態による通信システムの全体構成を示すブロック図である。It is a block diagram which shows the whole structure of the communication system by 2nd Embodiment. 第2の実施の形態によるミラー位置要求管理テーブルの構成を示す概念図である。It is a conceptual diagram which shows the structure of the mirror position request | requirement management table by 2nd Embodiment.
 以下図面について、本発明の一実施の形態を詳述する。 Hereinafter, an embodiment of the present invention will be described in detail with reference to the drawings.
(1)第1の実施の形態
(1-1)本実施の形態による通信システムの構成
 図1において、1は全体として本実施の形態による通信システムを示す。この通信システム1は、データネットワーク2に接続された複数の電子計算機3及び複数の通信装置4と、これらの通信装置4と接続された集約用通信装置5と、集約用通信装置5と接続された解析装置6と、各通信装置4と制御ネットワーク7を介して接続された管理装置8と、管理装置8と接続された操作元9とを備えて構成される。
(1) First Embodiment (1-1) Configuration of Communication System According to the Present Embodiment In FIG. 1, 1 indicates a communication system according to the present embodiment as a whole. The communication system 1 is connected to a plurality of computers 3 and a plurality of communication devices 4 connected to a data network 2, an aggregation communication device 5 connected to these communication devices 4, and an aggregation communication device 5. Analysis device 6, management device 8 connected to each communication device 4 via control network 7, and operation source 9 connected to management device 8.
 電子計算機3は、例えば、サーバ装置やパーソナルコンピュータなどから構成され、データネットワーク2を介して相互に通信を行う。 The electronic computer 3 is composed of, for example, a server device or a personal computer, and communicates with each other via the data network 2.
 通信装置4は、例えばLAN(Local Area Network)スイッチやルータなどから構成され、データネットワーク2に接続された1又は複数のインタフェース(図示せず)と、制御ネットワーク7に接続されたインタフェースと、集約用通信装置5に接続された1又は複数のミラーポートMPとを備えて構成される。なお、本実施の形態の通信装置4は、ミラーポートMPを1つのみ備えるものとする。 The communication device 4 includes, for example, a LAN (Local Area Network) switch, a router, and the like, and includes one or a plurality of interfaces (not shown) connected to the data network 2, an interface connected to the control network 7, and aggregation. And one or a plurality of mirror ports MP connected to the communication device 5. Note that the communication device 4 of the present embodiment includes only one mirror port MP.
 通信装置4には、転送機能10、ミラーリング機能11及び通信情報通知機能12が搭載されている。転送機能10は、通信装置4の任意のインタフェースを介して受信したトラヒックを解析し、解析により得られた5タプルなどの情報に基づいて、予め定められた規則に従って当該トラヒックを出力すべきインタフェースを決定し、決定したインタフェースからトラヒックを出力する機能である。 The communication device 4 is equipped with a transfer function 10, a mirroring function 11, and a communication information notification function 12. The transfer function 10 analyzes the traffic received via an arbitrary interface of the communication device 4, and based on information such as a 5-tuple obtained by the analysis, an interface to output the traffic according to a predetermined rule. This function determines and outputs traffic from the determined interface.
 ここで、5タプルとは、そのトラヒックの送信元の通信機器(電子計算機3)のIP(Internet Protocol)アドレスである「送信元IPアドレス」と、通信機器が稼動させる複数のプログラムからトラフィックの送信元となるプログラムを指定する「送信元ポート番号」と、そのトラヒックの送信先の通信機器(電子計算機3)のIPアドレスである「送信先IPアドレス」と、その通信機器が稼動させる複数のプログラムからトラフィックの宛先となるプログラムを指定する「宛先ポート番号」と、そのトラヒックを送受する際のIPプロトコルの種類を表す「IPプロトコル」を指す。これらの情報は、トラヒックを構成する各パケットのヘッダ部から取得することができる。 Here, the 5-tuple refers to a “source IP address” that is an IP (Internet Protocol) address of a communication device (electronic computer 3) that is a transmission source of the traffic, and transmission of traffic from a plurality of programs operated by the communication device. "Sender port number" that specifies the source program, "Destination IP address" that is the IP address of the communication device (electronic computer 3) that is the destination of the traffic, and a plurality of programs that the communication device operates Indicates a “destination port number” that specifies a destination program of traffic and “IP protocol” that indicates the type of IP protocol used when sending / receiving the traffic. Such information can be acquired from the header portion of each packet constituting the traffic.
 またミラーリング機能11は、通信装置4を経由するトラヒックのうち、5タプルなどの情報を用いて指定されたトラヒックを複製し、ミラーポートMPから出力する機能である。さらに通信情報通知機能12は、通信装置4を通過するトラヒックに関する所定のトラヒック情報(トラヒックごとの累積通信量及び5タプルなどの情報)を通知情報13として、予め定められた機器(本実施の形態においては管理装置8)に制御ネットワーク7を介して送信する機能である。 Also, the mirroring function 11 is a function that duplicates traffic designated using information such as a 5-tuple out of traffic passing through the communication device 4 and outputs it from the mirror port MP. Further, the communication information notification function 12 uses predetermined traffic information related to traffic passing through the communication device 4 (information such as accumulated traffic for each traffic and 5 tuples) as the notification information 13, and a predetermined device (the present embodiment). Is a function of transmitting to the management apparatus 8) via the control network 7.
 通信装置4のこれら転送機能10、ミラーリング機能11及び通信情報通知機能12はいずれも既存技術によるものであり、例えば、転送機能10としてLANスイッチのスイッチング機能、ミラーリング機能11としてLANスイッチのアクセス制御付きポートミラーリング機能、通信情報通知機能12としてIPFIX(IP Flow Information Export)をそれぞれ適用することができる。なお、以下においては、通信情報通知機能12としてIPFIXを適用した場合を想定し、通知情報13はIPFIXメッセージであるものとする。 The transfer function 10, mirroring function 11, and communication information notification function 12 of the communication device 4 are all based on existing technology. For example, the transfer function 10 includes a LAN switch switching function, and the mirroring function 11 includes LAN switch access control. As the port mirroring function and the communication information notification function 12, IPFIX (IP Flow Information Export) can be applied. In the following, it is assumed that IPFIX is applied as the communication information notification function 12, and the notification information 13 is an IPFIX message.
 集約用通信装置5は、例えばネットワークパケットブローカから構成され、複数の受信ポートRPと、1又は複数の送信ポートTPとを備える。各受信ポートRPは、それぞれ異なる通信装置4のミラーポートMPと接続され、1つ以上の送信ポートTPは、それぞれ任意の解析装置6と接続される。そして集約用通信装置5は、受信ポートRPを介して受信した各通信装置4が複製(ミラーリング)したトラヒックを送信ポートTPを介して対応する解析装置6に転送する。 The aggregation communication device 5 is composed of, for example, a network packet broker, and includes a plurality of reception ports RP and one or a plurality of transmission ports TP. Each reception port RP is connected to a mirror port MP of a different communication device 4, and one or more transmission ports TP are connected to an arbitrary analysis device 6. Then, the aggregation communication device 5 transfers the traffic copied (mirrored) by each communication device 4 received via the reception port RP to the corresponding analysis device 6 via the transmission port TP.
 解析装置6は、パッシブ型の性能監視装置から構成される。解析装置6は、集約用通信装置5から転送されたトラヒックを解析することにより、例えば、そのトラヒックを送受するアプリケーションの応答性能を監視する。 The analysis device 6 is composed of a passive type performance monitoring device. The analysis device 6 analyzes the traffic transferred from the aggregation communication device 5 to monitor the response performance of the application that transmits and receives the traffic, for example.
 管理装置8は、例えば、システム管理者が本通信システム1を管理するために利用されるサーバ装置であり、操作元9から与えられる後述のミラー位置要求17に応じて、当該ミラー位置要求17において指定されたトラヒックを解析する際にミラー位置とすべき通信装置4を選定し、選定結果をミラー位置応答18として操作元9に返信する機能(以下、これをミラー位置選定機能と呼ぶ)が搭載されている。 The management device 8 is, for example, a server device used by a system administrator to manage the communication system 1, and in response to a mirror position request 17 to be described later given from the operation source 9, in the mirror position request 17. Equipped with a function to select the communication device 4 to be the mirror position when analyzing the specified traffic and return the selection result to the operation source 9 as a mirror position response 18 (hereinafter referred to as a mirror position selection function) Has been.
 操作元9は、例えば利用者14が操作するクライアント端末15や、本通信システム1の運用を行うクラウド事業者が設置した運用管理装置16などを想定する。操作元9がクライアント端末15の場合、クライアント端末15は、解析装置6の解析対象とすべきトラヒック(以下、これを対象トラヒックと呼ぶ)と、必要に応じてその対象トラヒックのミラー位置とを利用者が指定するためのGUI(Graphical User Interface)を表示する。そしてクライアント端末15、このGUIを利用して利用者14により指定された対象トラヒックのミラー位置を選定すべき旨の要求を上述のミラー位置要求17として管理装置8に送信する。またクライアント端末15は、このミラー位置要求17に対するミラー位置応答18が管理装置8から与えられると、当該ミラー位置応答18に基づき認識される、管理装置8により選定された対象トラヒックのミラー位置を所定形式で表示する。 The operation source 9 is assumed to be, for example, a client terminal 15 operated by the user 14 or an operation management apparatus 16 installed by a cloud operator who operates the communication system 1. When the operation source 9 is the client terminal 15, the client terminal 15 uses the traffic to be analyzed by the analysis device 6 (hereinafter referred to as target traffic) and, if necessary, the mirror position of the target traffic. GUI (Graphical User Interface) for the user to specify is displayed. Then, the client terminal 15 transmits a request for selecting the mirror position of the target traffic designated by the user 14 to the management apparatus 8 as the above-described mirror position request 17 by using this GUI. In addition, when a mirror position response 18 to the mirror position request 17 is given from the management apparatus 8, the client terminal 15 determines the mirror position of the target traffic selected by the management apparatus 8 that is recognized based on the mirror position response 18. Display in format.
 なお本実施の形態の場合、ミラー位置要求17は、通信要件及びミラー位置通信装置IDの組合せを1つ以上含む。通信要件は、対象トラヒックの要件であり、当該対象トラヒックの5タプルの情報(以下、これを5タプル情報と呼ぶ)から構成される。この場合、通信要件は、5タプル情報のすべてを含む必要はなく、その一部だけでも良い。また5タプル情報に加えて、VLAN(Virtual LAN)の識別子を含ませるようにしても良い。ミラー位置通信装置IDは、上述のように操作元9により指定された対象トラヒックのミラー位置とすべき通信装置4の識別子(通信装置ID)である。このミラー位置通信装置IDは、空であっても良い(つまり対象トラヒックのミラー位置とすべき通信装置4が指定されていなくても良い)。 In the present embodiment, the mirror position request 17 includes one or more combinations of communication requirements and mirror position communication device IDs. The communication requirement is a requirement for target traffic, and is composed of information on five tuples of the target traffic (hereinafter referred to as five-tuple information). In this case, the communication requirement does not need to include all of the 5-tuple information, and only a part thereof may be used. In addition to the 5-tuple information, a VLAN (Virtual LAN) identifier may be included. The mirror position communication device ID is an identifier (communication device ID) of the communication device 4 to be the mirror position of the target traffic designated by the operation source 9 as described above. The mirror position communication device ID may be empty (that is, the communication device 4 to be the mirror position of the target traffic may not be specified).
 またミラー位置応答18は、対応するミラー位置要求17に含まれていた情報(1つ以上の通信要件及びミラー位置通信装置IDの組合せ)に加えて、管理装置8が選定したミラー位置とすべき通信装置4の識別子(通信装置ID)を含む。なお通常、ポートミラーリングを行うには、ミラー位置(通信装置)情報以外にポートミラーリングを実行するインタフェース情報も必要となるが、アクセス制御付きポートミラーリングを用いる場合は通信装置4のみの指定でもミラーリングを実施できる。具体的には、予め通信装置4の全ポートでポートミラーリングを稼動させ、かつアクセス制御であらゆる(any)トラフィックのミラーリングを拒否(deny)した状態にし、ミラー位置特定の後に、ミラー位置となる通信装置4のアクセス制御でミラー対象となるトラヒックのミラーリングを許可(permit)することで、ポートミラーリング実施の際に、インタフェース情報が不要となる。 The mirror position response 18 should be the mirror position selected by the management apparatus 8 in addition to the information (combination of one or more communication requirements and the mirror position communication apparatus ID) included in the corresponding mirror position request 17. The identifier (communication device ID) of the communication device 4 is included. Normally, in order to perform port mirroring, interface information for executing port mirroring is required in addition to mirror position (communication device) information. However, when port mirroring with access control is used, mirroring can be performed even if only the communication device 4 is specified. Can be implemented. Specifically, port mirroring is activated in advance for all ports of the communication device 4, and any traffic is denied (deny) by access control. After the mirror position is specified, the communication that becomes the mirror position is performed. By permitting the mirroring of the traffic to be mirrored by the access control of the device 4, the interface information becomes unnecessary when performing the port mirroring.
 ミラー位置要求17及びミラー位置応答18は、例えばXML(eXtensible Markup Language)で記述され、HTTP(Hyper Text Transfer Protocol)により操作元9及び管理装置8間で送受信される。 The mirror position request 17 and the mirror position response 18 are described in XML (eXtensible Markup Language), for example, and are transmitted and received between the operation source 9 and the management device 8 by HTTP (Hyper Text Transfer Protocol).
 図2は、データネットワーク2の構成例を示す。図2では、データネットワーク2の構成や、当該データネットワーク2を流れるトラヒックは単純化されているが、実際の環境では多数の通信装置によりデータネットワークが構成され、当該データネットワーク上を多数のトラヒックが流れている。 FIG. 2 shows a configuration example of the data network 2. In FIG. 2, the configuration of the data network 2 and the traffic flowing through the data network 2 are simplified. However, in an actual environment, the data network is configured by a large number of communication devices, and a large number of traffics are generated on the data network. Flowing.
 図2において、データネットワーク2は、図1について上述した通信装置4と同じ機能及び構成を有する複数の通信装置4A~4Dから構成され、このデータネットワーク2に複数の電子計算機3S~3Wが接続されている。なお、これらの通信装置4A~4D及び電子計算機3S~3Wは、物理的な実体を有する機器である必要はなく、ソフトウェアで実現される仮想スイッチや仮想マシンであっても良い。 2, the data network 2 is composed of a plurality of communication devices 4A to 4D having the same functions and configurations as the communication device 4 described above with reference to FIG. 1, and a plurality of electronic computers 3S to 3W are connected to the data network 2. ing. Note that the communication devices 4A to 4D and the electronic computers 3S to 3W do not need to be devices having physical entities, but may be virtual switches or virtual machines implemented by software.
 これらの通信装置4A~4D及び電子計算機3S~3Wは、LANケーブルを用いて相互に接続されている。具体的には、電子計算機3Sは通信装置4Aと接続され、この通信装置4Aは通信装置4C及び通信装置4Dとそれぞれ接続されている。また電子計算機3Tは通信装置4Bと接続され、この通信装置4Bは通信装置4C及び通信装置4Dとそれぞれ接続されている。さらに通信装置4Cは電子計算機3Uと接続され、通信装置4Dは電子計算機3V及び電子計算機3Wと接続されている。 The communication devices 4A to 4D and the electronic computers 3S to 3W are connected to each other using a LAN cable. Specifically, the electronic computer 3S is connected to the communication device 4A, and the communication device 4A is connected to the communication device 4C and the communication device 4D, respectively. The electronic computer 3T is connected to a communication device 4B, and this communication device 4B is connected to the communication device 4C and the communication device 4D, respectively. Further, the communication device 4C is connected to the electronic computer 3U, and the communication device 4D is connected to the electronic computer 3V and the electronic computer 3W.
 そして図2は、電子計算機3Sから通信装置4A及び通信装置4Cを経由して電子計算機3Uにトラヒック19Kが流れ、電子計算機3Tから通信装置4B及び通信装置4Dを経由してトラヒック19Mが流れ、電子計算機3Vから通信装置4D、通信装置4B及び通信装置4Cを経由してトラヒック19Lが流れている例を示している。 In FIG. 2, the traffic 19K flows from the electronic computer 3S to the electronic computer 3U via the communication device 4A and the communication device 4C, and the traffic 19M flows from the electronic computer 3T via the communication device 4B and the communication device 4D. In this example, traffic 19L flows from the computer 3V via the communication device 4D, the communication device 4B, and the communication device 4C.
 以下の説明に用いる図5~図8では、かかる構成を有するデータネットワーク2において、電子計算機3Uへのトラヒック(送信元は特定しない)及び電子計算機3Tから電子計算機3Wへのトラヒックをミラーリングしたいというミラー位置要求17が操作元9から管理装置8に与えられた場合についての例を示している。但し、図5~図8において、全情報を記載するとテーブルの行数が多くなる場合は、代表的な数行のみをテーブルに記載するものとする。また図5~図8では、説明の単純化のため、各トラヒックの通信量を常に800〔Mbps〕とし、通信装置4(以下、4A~4Dを含む)のミラーポートMP(図1)の帯域を1024〔Mbps〕としている。このような状況のもとでは、複数のトラヒックを同一の通信装置4でミラーリングするとミラーポートMPで輻輳が発生するため、ミラー位置を複数の通信装置4に分散させる必要がある。 In FIGS. 5 to 8 used in the following description, in the data network 2 having such a configuration, it is desired to mirror the traffic to the electronic computer 3U (the transmission source is not specified) and the traffic from the electronic computer 3T to the electronic computer 3W. An example in which the position request 17 is given from the operation source 9 to the management device 8 is shown. However, in FIG. 5 to FIG. 8, if all the information is written and the number of rows in the table increases, only a few representative rows are listed in the table. 5 to 8, for simplification of description, the traffic of each traffic is always 800 Mbps, and the bandwidth of the mirror port MP (FIG. 1) of the communication device 4 (hereinafter including 4A to 4D). Is set to 1024 [Mbps]. Under such a situation, when a plurality of traffics are mirrored by the same communication device 4, congestion occurs at the mirror port MP, so that the mirror position needs to be distributed to the plurality of communication devices 4.
 図3は、管理装置8の簡略的なハードウェア構成を示す。管理装置8は、この図3からも明らかなように、内部バス20を介して相互に接続されたプロセッサ21、主記憶装置22、外部記憶装置23、通信制御装置24及び入出力装置26を備えて構成される。 FIG. 3 shows a simplified hardware configuration of the management device 8. As is apparent from FIG. 3, the management device 8 includes a processor 21, a main storage device 22, an external storage device 23, a communication control device 24, and an input / output device 26 connected to each other via an internal bus 20. Configured.
 プロセッサ21は、管理装置8全体の動作制御を司る機能を有するハードウェアである。また主記憶装置22は、例えば半導体メモリから構成され、各種プログラムや制御データを一時的に保持するために利用される。主記憶装置22には、各通信装置4から送信されてくる通知情報を一時的に保持するための通知情報スタック30のほか、後述する管理プログラム31、ネットワークトポロジ情報テーブル32、通信解析情報テーブル群33、ミラー位置要求管理テーブル34及びミラー位置候補管理テーブル群35もこの主記憶装置22に格納されて保持される。 The processor 21 is hardware having a function for controlling operation of the entire management apparatus 8. The main storage device 22 is composed of, for example, a semiconductor memory and is used to temporarily hold various programs and control data. In the main storage device 22, in addition to a notification information stack 30 for temporarily storing notification information transmitted from each communication device 4, a management program 31, a network topology information table 32, and a communication analysis information table group to be described later 33, the mirror position request management table 34 and the mirror position candidate management table group 35 are also stored and held in the main storage device 22.
 外部記憶装置23は、大容量の記憶容量を有する記憶装置であり、例えばハードディスク装置やSSD(Solid State Drive)などから構成される。外部記憶装置23は、各種プログラムやデータを長期間保持するために利用される。また通信制御装置24は、各通信装置4との通信を制御する機能を有するハードウェアであり、インタフェース27を介して制御ネットワーク7に接続される。入出力装置26は、ユーザが各種操作入力を行うためのキーボードやマウスなどの入力装置と、各種情報を表示するための液晶ディスプレイなどの出力装置とから構成される。 The external storage device 23 is a storage device having a large storage capacity, and is composed of, for example, a hard disk device or an SSD (Solid State Drive). The external storage device 23 is used for holding various programs and data for a long period of time. The communication control device 24 is hardware having a function of controlling communication with each communication device 4, and is connected to the control network 7 via the interface 27. The input / output device 26 includes an input device such as a keyboard and a mouse for a user to perform various operation inputs, and an output device such as a liquid crystal display for displaying various information.
 図4は、管理装置8の簡略的な論理構成を示す。この図4に示すように、管理装置8は、ネットワーク情報解析部40、ミラー位置選定部41、ミラー位置候補列挙部42及び充足組合せ選定部43を備えて構成される。これらネットワーク情報解析部40、ミラー位置選定部41、ミラー位置候補列挙部42及び充足組合せ選定部43は、管理装置8のプロセッサ21(図3)が主記憶装置22(図3)に格納された管理プログラム31(図3)を実行することにより具現化される機能である。 FIG. 4 shows a simple logical configuration of the management device 8. As shown in FIG. 4, the management device 8 includes a network information analysis unit 40, a mirror position selection unit 41, a mirror position candidate listing unit 42, and a satisfaction combination selection unit 43. The network information analysis unit 40, the mirror position selection unit 41, the mirror position candidate listing unit 42, and the satisfaction combination selection unit 43 are stored in the main storage device 22 (FIG. 3) by the processor 21 (FIG. 3) of the management device 8. This is a function embodied by executing the management program 31 (FIG. 3).
 ネットワーク情報解析部40は、データネットワーク2を構成する各通信装置4から制御ネットワーク7を介してそれぞれ送信される上述の通知情報13を解析し、データネットワーク2を流れる各トラヒックの5タプル情報や、これらトラヒックがそれぞれ経由する通信装置4及び当該通信装置4におけるこれらトラヒックの通信量などの情報を取得すると共に、取得したこれらの情報を通信解析情報テーブル群33に格納する処理を実行する。 The network information analysis unit 40 analyzes the above notification information 13 transmitted from each communication device 4 constituting the data network 2 via the control network 7, and includes 5-tuple information on each traffic flowing through the data network 2, The communication device 4 through which each of the traffic passes and information such as the traffic of the traffic in the communication device 4 are acquired, and processing for storing the acquired information in the communication analysis information table group 33 is executed.
 またミラー位置選定部41は、操作元9から送信されるミラー位置要求17を受信してミラー位置要求管理テーブル34に新規に登録する処理を実行する。ただし、ミラー位置選定部41は、操作元9からミラー位置要求17が与えられた場合であって、ミラー位置要求管理テーブル34内に、そのミラー位置要求17において指定された対象トラヒックの5タプル情報がすべて同じレコードが既に存在する場合には、レコードを追加しない。またミラー位置選定部41は、後述のように充足組合せ選定部43からミラー位置の選定結果が与えられると、これをミラー位置応答18として操作元9に通知する。 Further, the mirror position selection unit 41 executes a process of receiving the mirror position request 17 transmitted from the operation source 9 and newly registering it in the mirror position request management table 34. However, the mirror position selection unit 41 is the case where the mirror position request 17 is given from the operation source 9 and the 5-tuple information of the target traffic specified in the mirror position request 17 in the mirror position request management table 34. If all the same records already exist, no records are added. In addition, when the mirror position selection result is given from the sufficiency combination selection unit 43 as described later, the mirror position selection unit 41 notifies the operation source 9 as a mirror position response 18.
 ミラー位置候補列挙部42は、ミラー位置要求管理テーブル34に登録されたミラー位置要求17を順次読み出し、読み出したミラー位置要求17において指定された対象トラヒックについて、後述するネットワークトポロジ情報テーブル32や通信解析情報テーブル群33を利用して、漏れや重複なくミラーリング可能な1つの通信装置4又は複数の通信装置4の組合せをミラー位置の候補(以下、これをミラー位置候補と呼ぶ)として列挙し、これらをミラー位置候補管理テーブル群35に格納する処理を実行する。 The mirror position candidate enumeration unit 42 sequentially reads the mirror position request 17 registered in the mirror position request management table 34, and the network topology information table 32 and communication analysis described later for the target traffic specified in the read mirror position request 17. The information table group 33 is used to list one communication device 4 or a combination of a plurality of communication devices 4 that can be mirrored without omission or duplication as mirror position candidates (hereinafter referred to as mirror position candidates), and Is stored in the mirror position candidate management table group 35.
 充足組合せ選定部43は、ミラー位置候補列挙部42により列挙されてミラー位置候補管理テーブル群35に格納された対象トラヒックのミラー位置候補の中から、そのミラー位置候補を構成するすべての通信装置4について、ミラーポートMP(図1)の通信量が後述するミラーポート閾値以下となるミラー位置候補を1つ選択し、これをミラー位置の選定結果としてミラー位置選定部41に通知する。 The sufficiency combination selecting unit 43 selects all the communication devices 4 constituting the mirror position candidate from the mirror position candidates of the target traffic enumerated by the mirror position candidate listing unit 42 and stored in the mirror position candidate management table group 35. 1, one mirror position candidate whose communication amount of the mirror port MP (FIG. 1) is equal to or less than a mirror port threshold value described later is selected, and this is notified to the mirror position selection unit 41 as a mirror position selection result.
 一方、管理装置8の主記憶装置22には、図3に示すように、ネットワークトポロジ情報テーブル32、通信解析情報テーブル群33、ミラー位置要求管理テーブル34及びミラー位置候補管理テーブル群35が格納されている。 On the other hand, as shown in FIG. 3, a network topology information table 32, a communication analysis information table group 33, a mirror position request management table 34, and a mirror position candidate management table group 35 are stored in the main storage device 22 of the management apparatus 8. ing.
 ネットワークトポロジ情報テーブル32は、データネットワーク2を構成する各通信装置4の機器情報を保持するために利用されるテーブルであり、図5に示すように、通信装置ID欄32A、IPアドレス欄32B、ミラーポート帯域欄32C及びミラーポート閾値欄32Dを備えて構成される。ネットワークトポロジ情報テーブル32では、1つの行(レコード)が1つの通信装置4に対応する。 The network topology information table 32 is a table used to hold device information of each communication device 4 configuring the data network 2, and as shown in FIG. 5, a communication device ID column 32A, an IP address column 32B, A mirror port bandwidth column 32C and a mirror port threshold column 32D are provided. In the network topology information table 32, one row (record) corresponds to one communication device 4.
 そして通信装置ID欄32Aには、データネットワーク2を構成する各通信装置4にそれぞれ付与された識別子(通信装置ID)が格納され、IPアドレス欄32Bには、対応する通信装置4が上述の通知情報13(図1)を管理装置8に送信する際に送信元IPアドレスとして使用するIPアドレスが格納される。 In the communication device ID column 32A, identifiers (communication device IDs) assigned to the respective communication devices 4 constituting the data network 2 are stored, and in the IP address column 32B, the corresponding communication device 4 receives the above notification. An IP address used as a transmission source IP address when the information 13 (FIG. 1) is transmitted to the management device 8 is stored.
 またミラーポート帯域欄32Cには、対応する通信装置4のミラーポートMP(図1)の最大帯域が格納され、ミラーポート閾値欄32Dには、その通知装置のそのミラーポートについてシステム管理者等により予め設定された通信量の閾値(以下、これをミラーポート閾値と呼ぶ)が格納される。 The mirror port bandwidth column 32C stores the maximum bandwidth of the mirror port MP (FIG. 1) of the corresponding communication device 4, and the mirror port threshold value column 32D stores the mirror port of the notification device by a system administrator or the like. A preset threshold value of communication traffic (hereinafter referred to as a mirror port threshold value) is stored.
 ネットワークトポロジ情報テーブル32におけるこれらの情報は、システム管理者等が入出力装置26(図3)を利用して予め設定する。ただし、これらの情報を制御ネットワーク7を介してシステム管理者等が設定できるようにしても良い。 These pieces of information in the network topology information table 32 are set in advance by the system administrator or the like using the input / output device 26 (FIG. 3). However, such information may be set by a system administrator or the like via the control network 7.
 通信解析情報テーブル群33は、データネットワーク2を構成する各通信装置4からそれぞれ送信されてきた通知情報13に基づき得られた情報を管理するためのテーブル群であり、図6に示すように、通信管理テーブル33A及び経路管理テーブル33Bから構成される。 The communication analysis information table group 33 is a table group for managing information obtained based on the notification information 13 transmitted from each communication device 4 constituting the data network 2, and as shown in FIG. It consists of a communication management table 33A and a route management table 33B.
 通信管理テーブル33Aは、データネットワーク2上を流れるトラヒックを管理するために利用されるテーブルであり、図6(A)に示すように、通信ID欄33AA、送信元IPアドレス欄33AB、送信元ポート番号欄33AC、宛先IPアドレス欄33AD、宛先ポート番号欄33AE及びIPプロトコル欄33AFを備えて構成される。通信管理テーブル33Aでは、1つの行がデータネットワーク2を流れる1つのトラヒックに対応する。 The communication management table 33A is a table used for managing traffic flowing on the data network 2, and as shown in FIG. 6A, a communication ID column 33AA, a transmission source IP address column 33AB, a transmission source port. A number field 33AC, a destination IP address field 33AD, a destination port number field 33AE, and an IP protocol field 33AF are provided. In the communication management table 33A, one row corresponds to one traffic flowing through the data network 2.
 そして通信ID欄33AAには、対応するトラヒックに対して付与されたそのトラヒックに固有の識別子(通信ID)が格納され、送信元IPアドレス欄33AB、送信元ポート番号欄33AC、宛先IPアドレス欄33AD、宛先ポート番号欄33AE及びIPプロトコル欄33AFには、それぞれそのトラヒックの5タプル情報のうちの対応する情報(送信元IPアドレス、送信元ポート番号、宛先IPアドレス、宛先ポート番号及びIPプロトコル)がそれぞれ格納される。通信管理テーブル33Aに格納されるこれらの情報は、通知情報13に含まれていた情報である。 The communication ID column 33AA stores an identifier (communication ID) unique to the traffic assigned to the corresponding traffic, and includes a source IP address column 33AB, a source port number column 33AC, and a destination IP address column 33AD. In the destination port number column 33AE and the IP protocol column 33AF, corresponding information (source IP address, source port number, destination IP address, destination port number and IP protocol) of the 5-tuple information of the traffic is stored. Each is stored. These pieces of information stored in the communication management table 33 </ b> A are information included in the notification information 13.
 また経路管理テーブル33Bは、データネットワーク2上を流れる各トラヒックの経路に関する各種情報を管理するために利用されるテーブルであり、図6(B)に示すように、通信ID欄33BA、通信装置ID欄33BB、通信量欄33BC、累積通信量欄33BD、受信インタフェース欄33BE、送信インタフェース欄33BF及び取得時間欄33BGを備えて構成される。経路管理テーブル33Bにおいても、1つの行がデータネットワーク2を流れる1つのトラヒックに対応する。 The route management table 33B is a table used for managing various types of information regarding the route of each traffic flowing on the data network 2, and as shown in FIG. 6B, the communication ID column 33BA, the communication device ID. A column 33BB, a traffic column 33BC, a cumulative traffic column 33BD, a reception interface column 33BE, a transmission interface column 33BF, and an acquisition time column 33BG are configured. Also in the route management table 33B, one row corresponds to one traffic flowing through the data network 2.
 そして通信ID欄33BAには、対応するトラヒックの通信IDが格納され、通信装置ID欄33BBには、対応するトラヒックが経由する通信装置4のうちの1つの通信装置4の通信装置IDが格納される。また通信量欄33BCには、対応するトラヒックが対応する通信装置4を流れる1秒当たりのデータ量(通信量)が格納され、累積通信量欄33BDには、対応する通信装置4における対応するトラヒックの通信量の累積値(以下、これを累積通信量と呼ぶ)が格納される。 The communication ID column 33BA stores the communication ID of the corresponding traffic, and the communication device ID column 33BB stores the communication device ID of one of the communication devices 4 through which the corresponding traffic passes. The The traffic volume column 33BC stores the data volume (communication volume) per second flowing through the communication device 4 to which the corresponding traffic corresponds, and the accumulated traffic volume column 33BD stores the corresponding traffic in the corresponding communication device 4. Is stored (hereinafter referred to as the accumulated communication amount).
 さらに受信インタフェース欄33BEには、対応する通信装置4が対応するトラヒックを受信したインタフェースの識別子が格納され、送信インタフェース欄33BFには、対応する通信装置4が対応するトラヒックを他の機器に送信したインタフェースの識別子が格納される。さらに取得時間欄33BGには、対応する通知情報13を管理装置8が受信した時間(正確には、対応する通信装置4がその通知情報13を生成した時間であり、以下、これを取得時間と呼ぶ)が格納される。 Further, the reception interface column 33BE stores the identifier of the interface that has received the corresponding traffic by the corresponding communication device 4, and the transmission interface column 33BF has transmitted the corresponding traffic by the corresponding communication device 4 to another device. Stores the identifier of the interface. Further, in the acquisition time column 33BG, the time when the management device 8 received the corresponding notification information 13 (more precisely, the time when the corresponding communication device 4 generated the notification information 13 is referred to as the acquisition time. Stored) is stored.
 経路管理テーブル33Bに格納されるこれらの情報のうち、通信装置ID欄33BB、累積通信量欄33BD、受信インタフェース欄33BE、送信インタフェース欄33BF及び取得時間欄33BGに格納される情報は、対応する通知情報13から取得したものであり、通信量欄33BCに格納される情報(つまり通信量)は、累積通信量欄33BDに格納された情報(つまり累積通信量)と、取得時間欄33BGに格納された情報(つまり取得時間)とに基づいて算出されたものである。 Among these pieces of information stored in the path management table 33B, the information stored in the communication device ID column 33BB, the accumulated communication amount column 33BD, the reception interface column 33BE, the transmission interface column 33BF, and the acquisition time column 33BG is the corresponding notification. Information acquired from the information 13 and stored in the traffic column 33BC (that is, traffic) is stored in the acquisition time column 33BG and information stored in the cumulative traffic column 33BD (that is, cumulative traffic). It is calculated based on the information (that is, the acquisition time).
 一方、ミラー位置要求管理テーブル34は、操作元9から管理装置8に与えられたミラー位置要求17を保持するために利用されるテーブルであり、図7に示すように、要求ID欄34A、通信要件欄34B及びミラー位置通信装置ID欄34Cを備えて構成される。ミラー位置要求管理テーブル34では、1つの行が1つのミラー位置要求17に対応する。 On the other hand, the mirror position request management table 34 is a table used for holding the mirror position request 17 given from the operation source 9 to the management apparatus 8, and as shown in FIG. A requirement column 34B and a mirror position communication device ID column 34C are provided. In the mirror position request management table 34, one row corresponds to one mirror position request 17.
 そして要求ID欄34Aには、対応するミラー位置要求17を管理装置8が受信したときに当該ミラー位置要求17に対して付与したそのミラー位置要求17に固有の識別子(要求ID)が格納される。 In the request ID column 34A, an identifier (request ID) unique to the mirror position request 17 assigned to the mirror position request 17 when the management apparatus 8 receives the corresponding mirror position request 17 is stored. .
 また通信要件欄34Bは、送信元IPアドレス欄34BA、送信元IPポート番号欄34BB、宛先IPアドレス欄34BC、宛先ポート番号欄34BD及びIPプロトコル欄34BEから構成され、これら送信元IPアドレス欄34BA、送信元IPポート番号欄34BB、宛先IPアドレス欄34BC、宛先ポート番号欄34BD及びIPプロトコル欄34BEに、対応するミラー位置要求17から取得した5タプル情報のうちの対応する情報(送信元IPアドレス、送信元ポート番号、宛先IPアドレス、宛先ポート番号又はIPプロトコル)がそれぞれ格納される。 The communication requirement column 34B includes a source IP address column 34BA, a source IP port number column 34BB, a destination IP address column 34BC, a destination port number column 34BD, and an IP protocol column 34BE. These source IP address column 34BA, In the source IP port number column 34BB, the destination IP address column 34BC, the destination port number column 34BD, and the IP protocol column 34BE, corresponding information (source IP address, Source port number, destination IP address, destination port number or IP protocol) are stored.
 さらにミラー位置通信装置ID欄34Cには、対応するミラー位置要求17において指定された、対応する対象トラヒックについてミラー位置とすべき通信装置4の通信装置IDが格納される。 Further, in the mirror position communication device ID column 34C, the communication device ID of the communication device 4 to be set as the mirror position for the corresponding target traffic specified in the corresponding mirror position request 17 is stored.
 他方、ミラー位置候補管理テーブル群35は、ミラー位置候補列挙部42(図4)により列挙されたミラー位置候補を保持するためのテーブル群であり、図8に示すように、候補管理テーブル35A及び候補位置管理テーブル35Bから構成される。 On the other hand, the mirror position candidate management table group 35 is a table group for holding the mirror position candidates listed by the mirror position candidate listing unit 42 (FIG. 4). As shown in FIG. The candidate position management table 35B is used.
 候補管理テーブル35Aは、ミラー位置要求17と後述する候補IDとの対応関係を管理するために利用されるテーブルであり、図8(A)に示すように、要求ID欄35AA及び候補ID欄35ABを備えて構成される。そして要求ID欄35AAには、管理装置8が受信したミラー位置要求17に対して付与したそのミラー位置要求17に固有の要求IDが格納され、候補ID欄35ABには、後述の候補IDが格納される。候補管理テーブル35Aでは、1つの行が1つの候補IDと対応する。 The candidate management table 35A is a table used for managing the correspondence between the mirror position request 17 and a candidate ID described later, and as shown in FIG. 8A, the request ID column 35AA and the candidate ID column 35AB. It is configured with. The request ID column 35AA stores a request ID unique to the mirror position request 17 assigned to the mirror position request 17 received by the management apparatus 8, and the candidate ID column 35AB stores a candidate ID described later. Is done. In the candidate management table 35A, one row corresponds to one candidate ID.
 また候補位置管理テーブル35Bは、ミラー位置候補列挙部42により列挙されたミラー位置候補を管理するために利用されるテーブルであり、図8(B)に示すように、候補ID欄35BA、通信装置ID欄35BB及び通信量欄35BCを備えて構成される。 The candidate position management table 35B is a table used for managing the mirror position candidates listed by the mirror position candidate listing unit 42. As shown in FIG. 8B, the candidate position management table 35B includes a candidate ID column 35BA, a communication device, and the like. An ID column 35BB and a traffic volume column 35BC are provided.
 そして候補ID欄35BAには、1つのミラー位置要求17に対してミラー位置候補列挙部42が列挙した各ミラー位置候補に対してそれぞれ付与した識別子(候補ID)が格納される。なお、1つのミラー位置要求17に対してミラー位置候補列挙部42により列挙されたミラー位置候補が複数ある場合には、これらのミラー位置候補にそれぞれ異なる候補IDが付与される。 In the candidate ID column 35BA, identifiers (candidate IDs) assigned to the respective mirror position candidates enumerated by the mirror position candidate enumeration unit 42 with respect to one mirror position request 17 are stored. In addition, when there are a plurality of mirror position candidates listed by the mirror position candidate listing unit 42 for one mirror position request 17, different candidate IDs are assigned to these mirror position candidates.
 また通信装置ID欄35BBには、そのミラー位置候補を構成する1つの通信装置4の通信装置IDが格納される。従って、ミラー位置候補が複数の通信装置4の組合せにより構成される場合、これらの通信装置4はそれぞれ候補位置管理テーブル35Bの異なる行に登録されることになる。 Further, the communication device ID column 35BB stores the communication device ID of one communication device 4 constituting the mirror position candidate. Accordingly, when the mirror position candidate is configured by a combination of a plurality of communication devices 4, these communication devices 4 are registered in different rows of the candidate position management table 35B.
 さらに通信量欄35BCには、対応する通信装置4を対象トラヒックのミラー位置として設定した場合に、その通信装置4のミラーポートMP(図1)を流れる当該対象トラヒックの通信量(そのミラーポートMPに要求される帯域)が格納される。 Further, in the traffic volume column 35BC, when the corresponding communication device 4 is set as the mirror position of the target traffic, the traffic volume of the target traffic flowing through the mirror port MP (FIG. 1) of the communication device 4 (the mirror port MP) Is stored).
(1-2)ミラー位置選定機能に関連する各種処理
(1-2-1)ミラー位置選定機能に関する処理の流れ
 図9は、操作元9から管理装置8にミラー位置要求17が送信された後、当該ミラー位置要求17に対応するミラー位置応答18が管理装置8からその操作元9に送信されるまでの一連の処理の流れを示す。
(1-2) Various Processes Related to the Mirror Position Selection Function (1-2-1) Flow of Processes Related to the Mirror Position Selection Function FIG. 9 shows the state after the mirror position request 17 is transmitted from the operation source 9 to the management device 8 The flow of a series of processes until the mirror position response 18 corresponding to the mirror position request 17 is transmitted from the management apparatus 8 to the operation source 9 is shown.
 操作元9から対象トラヒックの5タプルと、必要に応じてミラー位置とすべき通信装置4とを指定したミラー位置要求17が管理装置8に送信されると(SP1)、まず、管理装置8のミラー位置選定部41が、そのミラー位置要求17に含まれる対象トラヒックの5タプル情報と、ミラー位置とすべき通信装置4の通信装置IDとを当該ミラー位置要求17から抽出し、これらの情報をミラー位置要求管理テーブル34に登録する(SP2)。 When the mirror position request 17 designating the 5-tuple of the target traffic and the communication device 4 to be the mirror position as necessary is transmitted from the operation source 9 to the management device 8 (SP1), first, the management device 8 The mirror position selection unit 41 extracts the 5-tuple information of the target traffic included in the mirror position request 17 and the communication device ID of the communication device 4 to be the mirror position from the mirror position request 17, and obtains these pieces of information. It is registered in the mirror position request management table 34 (SP2).
 またミラー位置選定部41は、この後、所定のタイミングで、そのミラー位置要求17に対応するミラー位置候補の列挙を行うべき旨の要求(以下、これをミラー位置候補列挙要求と呼ぶ)をミラー位置候補列挙部42に与える(SP3)。 Further, the mirror position selection unit 41 thereafter issues a request to enumerate mirror position candidates corresponding to the mirror position request 17 at a predetermined timing (hereinafter referred to as a mirror position candidate enumeration request). The position candidate enumeration unit 42 is given (SP3).
 ミラー位置候補列挙部42は、ミラー位置選定部41から上述のミラー位置候補列挙要求が与えられると、ミラー位置要求管理テーブル34に登録されている各ミラー位置要求17について、通信解析情報テーブル群33の通信管理テーブル33A(図6(A))及び経路管理テーブル33B(図6(B))を参照して、そのミラー位置要求17に応じたすべてのミラー位置候補を列挙する(SP4)。 When the mirror position candidate enumeration unit 42 receives the above-described mirror position candidate enumeration request from the mirror position selection unit 41, the mirror position candidate enumeration unit 42 performs communication analysis information table group 33 for each mirror position request 17 registered in the mirror position request management table 34. Referring to the communication management table 33A (FIG. 6A) and the path management table 33B (FIG. 6B), all the mirror position candidates corresponding to the mirror position request 17 are listed (SP4).
 またミラー位置候補列挙部42は、列挙したこれらのミラー位置候補に関する必要な情報を、ミラー位置候補管理テーブル群35の候補管理テーブル35A(図8(A))及び候補位置管理テーブル35B(図8(B))にそれぞれ登録する(SP5)。そしてミラー位置候補列挙部42は、この後、所定のタイミングで、これらのミラー位置候補の中から1つのミラー位置候補をミラー位置として選定すべき旨の要求(以下、これを充足組合せ選定要求と呼ぶ)を充足組合せ選定部43に与える(SP6)。 Further, the mirror position candidate enumeration unit 42 obtains necessary information regarding the enumerated mirror position candidates from the candidate management table 35A (FIG. 8A) and the candidate position management table 35B (FIG. 8) of the mirror position candidate management table group 35. (B)) is registered (SP5). The mirror position candidate enumeration unit 42 then requests that one mirror position candidate should be selected as a mirror position from these mirror position candidates at a predetermined timing (hereinafter, this is referred to as a satisfaction combination selection request). To the satisfaction combination selection unit 43 (SP6).
 充足組合せ選定部43は、ミラー位置候補列挙部42から上述の充足組合せ選定要求が与えられると、ミラー位置候補管理テーブル群35に登録されているミラー位置候補の中から、そのミラー位置候補を構成するすべての通信装置4について、ミラーポートMP(図1)の通信量がミラーポート閾値以下となるミラー位置候補を1つ選定する(SP7)。充足組合せ選定部43は、このような1つのミラー位置候補の選定を、ミラー位置要求17ごとに行う。そして充足組合せ選定部43は、このようにして得られたミラー位置要求17ごとのミラー位置の選定結果を、ミラー位置選定部41に通知する(SP8)。 When the above-mentioned satisfaction combination selection request is given from the mirror position candidate listing section 42, the satisfaction combination selection section 43 configures the mirror position candidates from the mirror position candidates registered in the mirror position candidate management table group 35. For all the communication devices 4 that perform this, one mirror position candidate is selected at which the traffic of the mirror port MP (FIG. 1) is equal to or less than the mirror port threshold (SP7). The sufficiency combination selection unit 43 selects one such mirror position candidate for each mirror position request 17. Then, the satisfaction combination selection unit 43 notifies the mirror position selection unit 41 of the mirror position selection result for each mirror position request 17 obtained in this way (SP8).
 ミラー位置選定部41は、上述のミラー位置要求17ごとのミラー位置の選定結果(要求ID34A(図7)と複数の通信装置ID32A(図5)の組)が充足組合せ選定部43から通知されると、ミラー位置要求管理テーブル34を参照し、ミラー位置の選定結果に含まれる要求ID34に対応した通信要件34Bを入手し、入手した通信要件34Bとミラー位置の選定結果のうち対応した通信装置ID32Aを組みとしたミラー位置応答18を作成し(SP9)、作成したミラー位置応答18を操作元9に送信する(SP10)。 The mirror position selection unit 41 is notified from the satisfaction combination selection unit 43 of a mirror position selection result (a set of request ID 34A (FIG. 7) and a plurality of communication device IDs 32A (FIG. 5)) for each mirror position request 17 described above. Then, the communication requirement 34B corresponding to the request ID 34 included in the mirror position selection result is obtained by referring to the mirror position request management table 34, and the communication device ID 32A corresponding to the obtained communication requirement 34B and the mirror position selection result is obtained. Is created (SP9), and the created mirror position response 18 is transmitted to the operation source 9 (SP10).
(1-2-2)ミラー位置選定機能に関する具体的な処理内容
(1-2-2-1)ネットワーク情報解析処理
 図10は、データネットワーク2を構成する各通信装置4から送信される通知情報13(図1)を受信したネットワーク情報解析部40(図4)により実行される処理(以下、これをネットワーク情報解析処理と呼ぶ)の具体的な処理内容を示す。ネットワーク情報解析部40は、かかる通知情報13を受信すると、この図10に示す処理手順に従って当該通知情報13を解析し、必要な情報を通信解析情報テーブル群33に格納する。
(1-2-2) Specific Processing Contents Related to Mirror Position Selection Function (1-2-2-1) Network Information Analysis Processing FIG. 10 shows notification information transmitted from each communication device 4 constituting the data network 2 13 shows the specific processing contents of processing (hereinafter referred to as network information analysis processing) executed by the network information analysis unit 40 (FIG. 4) that has received 13 (FIG. 1). When receiving the notification information 13, the network information analysis unit 40 analyzes the notification information 13 in accordance with the processing procedure shown in FIG. 10 and stores necessary information in the communication analysis information table group 33.
 なお以下においては、上述のように通信装置4の通信情報通知機能12(図1)としてIPFIXを適用した場合を想定しており、通知情報13がIPFIXメッセージであることを前提に説明を進める。因みに、IPFIXメッセージは、図11に示すデータ構成を有するメッセージである。すなわちIPFIXメッセージ50は、IPヘッダ50A、UDPヘッダ50B、IPFIXヘッダ50C及びペイロード部50Dから構成され、ペイロード部50Dには、そのIPFIXメッセージ50の送信元の通信装置を通過する各トラヒックにそれぞれ対応させて、そのトラヒックの5タプル情報(送信元IPアドレス、宛先IPアドレス、送信元ポート番号、宛先ポート番号及びIPプロトコル)と、そのトラヒックを入出力する各物理インタフェースの識別子(「入力物理IF」及び「出力物理IF」)と、累積通信量(「累積通信量」)となどの情報からなるデータセット51が格納される。 In the following description, it is assumed that IPFIX is applied as the communication information notification function 12 (FIG. 1) of the communication device 4 as described above, and the description will be made on the assumption that the notification information 13 is an IPFIX message. Incidentally, the IPFIX message is a message having the data structure shown in FIG. That is, the IPFIX message 50 includes an IP header 50A, a UDP header 50B, an IPFIX header 50C, and a payload portion 50D. The payload portion 50D is associated with each traffic passing through the communication device that is the source of the IPFIX message 50. The 5-tuple information (source IP address, destination IP address, source port number, destination port number and IP protocol) of the traffic and the identifier (“input physical IF” and the physical interface for inputting / outputting the traffic) A data set 51 including information such as “output physical IF”) and cumulative communication amount (“cumulative communication amount”) is stored.
 そしてネットワーク情報解析部40は、データネットワーク2を構成するいずれかの通信装置4から送信された上述のような通知情報13を受信すると、この図10に示すネットワーク情報解析処理を開始し、まず、その通知情報13のIPヘッダ50A(図11)に含まれる送信元IPアドレスと、ネットワークトポロジ情報テーブル32(図5)のIPアドレス32Bとを照らし合わせ、当該通知情報の送信元となる通信装置4の通信装置IDを取得する(SP20)。またネットワーク情報解析部40は、その通知情報13のIPFIXヘッダ50C(図11)に格納されたユニックス時間(「Unix(登録商標)Secs」)を当該通知情報13の取得時間として取得する(SP21)。 When the network information analysis unit 40 receives the notification information 13 as described above transmitted from any one of the communication devices 4 constituting the data network 2, the network information analysis unit 40 starts the network information analysis process shown in FIG. The source IP address included in the IP header 50A (FIG. 11) of the notification information 13 is compared with the IP address 32B of the network topology information table 32 (FIG. 5), and the communication device 4 that is the source of the notification information The communication device ID is acquired (SP20). Further, the network information analysis unit 40 acquires the Unix time (“Unix (registered trademark) Secs”) stored in the IPFIX header 50C (FIG. 11) of the notification information 13 as the acquisition time of the notification information 13 (SP21). .
 続いて、ネットワーク情報解析部40は、その通知情報13のペイロード部50D(図11)から1つのデータセット51(図11)を抽出し(SP22)、取得したデータセット51に含まれる5タプル情報と同一の5タプル情報を有するレコードが通信解析情報テーブル群33の通信管理テーブル33A(図6(A))に存在するか否かを判断する(SP23)。 Subsequently, the network information analysis unit 40 extracts one data set 51 (FIG. 11) from the payload portion 50D (FIG. 11) of the notification information 13 (SP22), and the 5-tuple information included in the acquired data set 51. It is determined whether or not a record having the same 5-tuple information exists in the communication management table 33A (FIG. 6A) of the communication analysis information table group 33 (SP23).
 この判断で否定結果を得ることは、ステップSP22で抽出したデータセット51に対応するトラヒックが未だ通信解析情報テーブル群33に登録されていないことを意味する。かくして、このときネットワーク情報解析部40は、ステップSP22で抽出したデータセット51に対応するトラヒックに対してそのトラヒックに固有の通信IDを付与し、当該通信IDと、当該データセット51に含まれる5タプル情報とを通信管理テーブル33Aに新規に登録する(SP24)。 Obtaining a negative result in this determination means that the traffic corresponding to the data set 51 extracted in step SP22 is not yet registered in the communication analysis information table group 33. Thus, at this time, the network information analysis unit 40 assigns a unique communication ID to the traffic corresponding to the data set 51 extracted in step SP22, and includes the communication ID and 5 included in the data set 51. The tuple information is newly registered in the communication management table 33A (SP24).
 具体的に、ネットワーク情報解析部40は、そのトラヒックに付与した通信IDを通信管理テーブル33Aにおける新規の行の通信ID欄33AAに格納すると共に、その行の送信元IPアドレス欄33AB、送信元ポート番号欄33AC、宛先IPアドレス欄33AD、宛先ポート番号欄33AE及びIPプロトコル欄33AFに、ステップSP22で抽出したデータセット51に含まれる5タプル情報のうちの対応する情報をそれぞれ格納する。 Specifically, the network information analysis unit 40 stores the communication ID assigned to the traffic in the communication ID column 33AA of the new row in the communication management table 33A, and the source IP address column 33AB, source port of the row. In the number field 33AC, the destination IP address field 33AD, the destination port number field 33AE, and the IP protocol field 33AF, corresponding information of the 5-tuple information included in the data set 51 extracted in step SP22 is stored.
 さらにネットワーク情報解析部40は、この後、ステップSP22で抽出したデータセット51に対応するトラヒックの経路を経路管理テーブル33B(図6(B))に登録する(SP25)。 Further, the network information analysis unit 40 thereafter registers the traffic route corresponding to the data set 51 extracted in step SP22 in the route management table 33B (FIG. 6B) (SP25).
 具体的に、ネットワーク情報解析部40は、ステップSP24でそのトラヒックに付与した通信IDを経路管理テーブル33Bにおける新規の行の通信ID欄33BAに格納すると共に、その行の通信装置ID欄33BBにステップSP20で取得した通信装置IDを格納する。 Specifically, the network information analysis unit 40 stores the communication ID assigned to the traffic at step SP24 in the communication ID column 33BA of the new line in the route management table 33B, and steps into the communication device ID column 33BB of the row. Stores the communication device ID acquired in SP20.
 またネットワーク情報解析部40は、その行の受信インタフェース欄33BE及び送信インタフェース欄33BFに、ステップSP22で抽出したデータセット51に含まれる受信物理インタフェースの識別子及び送信物理インタフェースの識別子のうちの対応する情報をそれぞれ格納し、さらにその行の取得時間欄33BGに、ステップSP21で取得したその通信情報の取得時間を格納する。さらにネットワーク情報解析部40は、その行の通信量欄33BC及び累積通信量欄33BDに、ステップSP22で抽出したデータセット51に含まれる累積通信量をそれぞれ格納する。 Further, the network information analyzing unit 40 adds corresponding information of the identifier of the reception physical interface and the identifier of the transmission physical interface included in the data set 51 extracted in step SP22 to the reception interface column 33BE and the transmission interface column 33BF of the row. And the acquisition time of the communication information acquired in step SP21 is stored in the acquisition time column 33BG of the row. Furthermore, the network information analysis unit 40 stores the accumulated communication amount included in the data set 51 extracted in step SP22 in the communication amount column 33BC and the accumulated communication amount column 33BD of the row.
 そしてネットワーク情報解析部40は、この後、このステップSP25の処理を終了すると、ステップSP29に進む。 Then, when the network information analyzing unit 40 ends the process of step SP25, the process proceeds to step SP29.
 一方、ステップSP23の判断で否定結果を得ることは、ステップSP22で抽出したデータセット51に対応するトラヒックが既に通信解析情報テーブル群33に登録されていることを意味する。かくして、このときネットワーク情報解析部40は、既に通信解析情報テーブル群33に登録されているそのトラヒックの通信IDを通信管理テーブル33A(図6(A))から取得する(SP26)。 On the other hand, obtaining a negative result in the determination at step SP23 means that the traffic corresponding to the data set 51 extracted at step SP22 has already been registered in the communication analysis information table group 33. Thus, at this time, the network information analysis unit 40 acquires the communication ID of the traffic already registered in the communication analysis information table group 33 from the communication management table 33A (FIG. 6A) (SP26).
 またネットワーク情報解析部40は、経路管理テーブル33B(図6(B))のレコードのうち、通信ID欄33BAに格納された通信IDがステップSP26で取得した通信IDと一致し、かつ通信装置ID欄33BBに格納された通信装置IDがステップSP20で取得した通信装置IDと一致するレコードが存在するか否かを判断する(SP27)。 Further, the network information analysis unit 40 matches the communication ID stored in the communication ID column 33BA in the record of the route management table 33B (FIG. 6B) with the communication ID acquired in step SP26 and the communication device ID. It is determined whether there is a record in which the communication device ID stored in the column 33BB matches the communication device ID acquired in step SP20 (SP27).
 この判断で否定結果を得ることは、既に通信解析情報テーブル群33に登録されているトラヒックの通信経路が変更されたことを意味する。かくして、このときネットワーク情報解析部40は、ステップSP27に進んでそのトラヒックの新たな経路を上述のように経路管理テーブルに登録した後、ステップSP29に進む。 Obtaining a negative result in this determination means that the traffic communication path already registered in the communication analysis information table group 33 has been changed. Thus, at this time, the network information analyzing unit 40 proceeds to step SP27, registers the new route of the traffic in the route management table as described above, and then proceeds to step SP29.
 これに対してステップSP27の判断で肯定結果を得ることは、そのトラヒックは既に通信解析情報テーブル群33に登録されており、経路の変更もないことを意味する。かくして、このときネットワーク情報解析部40は、経路管理テーブル33Bにおけるそのトラヒックに対応する行の通信量欄33BCに格納された通信量を更新する(SP28)。 On the other hand, obtaining a positive result in the determination at step SP27 means that the traffic has already been registered in the communication analysis information table group 33 and there is no change in the route. Thus, at this time, the network information analysis unit 40 updates the traffic volume stored in the traffic volume column 33BC of the line corresponding to the traffic in the route management table 33B (SP28).
 具体的に、ネットワーク情報解析部40は、ステップSP22で抽出したデータセット51に含まれる累積通信量をCCV1、ステップSP21で取得した通知情報13の生成時間をT1、ステップSP26で検出した対応するレコードの累積通信量欄33BDに格納されている累積通信量をCCV2、当該レコードの取得時間欄33BGに格納されている時間をT2として、経路管理テーブル33BにおけるステップSP26で検出した対応するレコードの通信量欄33BCに格納されている通信量を、次式
Figure JPOXMLDOC01-appb-M000001
により算出される通信量CVに更新する。
Specifically, the network information analysis unit 40 uses CCV1 as the cumulative communication amount included in the data set 51 extracted at step SP22, T1 as the generation time of the notification information 13 acquired at step SP21, and the corresponding record detected at step SP26. CCV2 is the cumulative communication amount stored in the cumulative communication amount column 33BD, and T2 is the time stored in the acquisition time column 33BG of the record, and the communication amount of the corresponding record detected in step SP26 in the route management table 33B. The traffic stored in the column 33BC is expressed as
Figure JPOXMLDOC01-appb-M000001
Is updated to the communication amount CV calculated by.
 次いで、ネットワーク情報解析部40は、そのとき受信した通知情報13のペイロード部50D(図11)に格納されたすべてのデータセット51についてステップSP23~ステップSP28の処理を実行し終えたか否かを判断する(SP29)。そしてネットワーク情報解析部40は、この判断で否定結果を得るとステップSP22に戻り、この後、ステップSP22で選択するデータセット51を未処理の他のデータセット51に順次切り替えながら、ステップSP22~ステップSP29の処理を繰り返す。 Next, the network information analysis unit 40 determines whether or not the processing of step SP23 to step SP28 has been executed for all the data sets 51 stored in the payload portion 50D (FIG. 11) of the notification information 13 received at that time. (SP29). If the network information analysis unit 40 obtains a negative result in this determination, it returns to step SP22, and thereafter, the data set 51 selected in step SP22 is sequentially switched to another unprocessed data set 51 while step SP22 to step SP22. The processing of SP29 is repeated.
 そしてネットワーク情報解析部40は、やがてそのとき受信した通知情報13のペイロード部50Dに格納されたすべてのデータセット51についてステップSP23~ステップSP28の処理を実行し終えることによりステップSP29で肯定結果を得ると、このネットワーク情報解析処理を終了する。 Then, the network information analysis unit 40 eventually obtains a positive result at step SP29 by completing the processing of step SP23 to step SP28 for all the data sets 51 stored in the payload portion 50D of the notification information 13 received at that time. And this network information analysis processing is complete | finished.
(1-2-2-2)ミラー位置候補列挙処理
 図12は、ミラー位置選定部41(図4)からミラー位置候補列挙要求が与えられたミラー位置候補列挙部42(図4)により実行される処理(図9のステップSP4の処理であり、以下、これをミラー位置候補列挙処理と呼ぶ)の具体的な処理内容を示す。ミラー位置候補列挙部42は、かかるミラー位置候補列挙要求を受信すると、この図12に示す処理手順に従って、ミラー位置要求管理テーブル34(図7)に登録されているミラー位置要求17ごとに、ミラー位置候補をそれぞれすべて検出(列挙)し、検出したミラー位置要求17ごとの各ミラー位置候補をそれぞれミラー位置候補管理テーブル群35(図4)に登録する。
(1-2-2-2) Mirror position candidate enumeration process FIG. 12 is executed by the mirror position candidate enumeration unit 42 (FIG. 4) to which the mirror position candidate enumeration request is given from the mirror position selection unit 41 (FIG. 4). The specific processing content of the processing (the processing of step SP4 in FIG. 9 and hereinafter referred to as mirror position candidate enumeration processing) is shown. When receiving the mirror position candidate enumeration request 42, the mirror position candidate enumeration unit 42, for each mirror position request 17 registered in the mirror position request management table 34 (FIG. 7), in accordance with the processing procedure shown in FIG. All the position candidates are detected (enumerated), and each mirror position candidate for each detected mirror position request 17 is registered in the mirror position candidate management table group 35 (FIG. 4).
 実際上、ミラー位置候補列挙部42は、かかるミラー位置候補列挙要求を受信すると、この図12に示すミラー位置候補列挙処理を開始し、まず、ミラー位置要求管理テーブル34の中から未処理の1つのレコード(ミラー位置要求17)を選択し、その内容をレコードRとして記憶する(SP30)。 In practice, when receiving the mirror position candidate enumeration request 42, the mirror position candidate enumeration unit 42 starts the mirror position candidate enumeration process shown in FIG. One record (mirror position request 17) is selected, and its contents are stored as record R (SP30).
 続いて、ミラー位置候補列挙部42は、レコードRの通信要件を満たすトラヒックの集合Tを求める(SP31)。具体的に、ミラー位置候補列挙部42は、通信解析情報テーブル群33(図6)の通信管理テーブル33A(図6(B))のレコードのうち、ステップSP30で選択したレコードRの通信要件を満たす各レコードの通信ID欄33AA(図6(A))に格納されている通信IDをそれぞれ取得し、取得したこれらの通信IDを集合Tとして記憶する。 Subsequently, the mirror position candidate listing unit 42 obtains a traffic set T that satisfies the communication requirements of the record R (SP31). Specifically, the mirror position candidate listing unit 42 sets the communication requirement of the record R selected in step SP30 among the records of the communication management table 33A (FIG. 6B) of the communication analysis information table group 33 (FIG. 6). Each communication ID stored in the communication ID column 33AA (FIG. 6A) of each record to be satisfied is acquired, and these acquired communication IDs are stored as a set T.
 例えば、レコードRが図7の「req2」というミラー位置要求17に対応するレコード(図7の上から2行目のレコード)であった場合、通信管理テーブル33A(図6(A))においてこのレコードRの通信要件を満たすレコードは「trM」という通信IDのトラヒックに対応するレコード(図6(A)の上から3行目のレコード)であるため、ミラー位置候補列挙部42はこのトラヒックの通信IDである「trM」を集合Tとして記憶する。 For example, if the record R is a record corresponding to the mirror position request 17 “req2” in FIG. 7 (record on the second line from the top in FIG. 7), this is indicated in the communication management table 33A (FIG. 6A). Since the record satisfying the communication requirement of the record R is a record corresponding to the traffic of the communication ID “trM” (record on the third line from the top in FIG. 6A), the mirror position candidate enumeration unit 42 The communication ID “trM” is stored as a set T.
 またレコードRが図7の「req1」というミラー位置要求17(これはIPアドレスが「10.2.0.50」という電子計算機3に入力するすべてのトラヒックについてのミラー位置を要求するミラー位置要求)に対応するレコードであった場合、通信管理テーブル33AにおいてこのレコードRの通信要件を満たすレコードは、「trK」という通信IDのトラヒックに対応するレコード(図6(A)の上から1行目のレコード)と、「trL」という通信IDのトラヒックに対応するレコード(図6(A)の上から2行目のレコード)とであるため、ミラー位置候補列挙部42はこれらトラヒックの通信IDである「trK」及び「trL」を集合Tとして記憶する。 Further, the record R corresponds to the mirror position request 17 “req1” in FIG. 7 (this is a mirror position request for requesting the mirror position for all traffic input to the computer 3 whose IP address is “10.2.0.50”). If the record is a record, the record satisfying the communication requirement of the record R in the communication management table 33A is a record corresponding to the traffic with the communication ID “trK” (record on the first line from the top in FIG. 6A). , “TrL” is a record corresponding to the traffic of the communication ID “trL” (record on the second line from the top in FIG. 6A), the mirror position candidate enumeration unit 42 “trK” which is the communication ID of these traffics. And “trL” is stored as a set T.
 次いで、ミラー位置候補列挙部42は、通信解析情報テーブル群33の経路管理テーブル33B(図6(B))のレコードの中から、ステップSP31で求めた各トラヒックにそれぞれ対応するレコードの集合Pを求める(SP32)。具体的に、ミラー位置候補列挙部42は、経路管理テーブル33Bのレコードのうち、通信ID欄33BA(図6(B))に格納された通信IDがステップSP31で求めた集合Tに属するいずれかの通信IDと一致するレコードを検出し、そのレコードの集合を集合Pとする。 Next, the mirror position candidate listing unit 42 selects a set P of records corresponding to each traffic obtained in step SP31 from the records in the route management table 33B (FIG. 6B) of the communication analysis information table group 33. Obtain (SP32). Specifically, the mirror position candidate enumeration unit 42 selects any one of the records in the path management table 33B whose communication ID stored in the communication ID column 33BA (FIG. 6B) belongs to the set T obtained in step SP31. A record matching the communication ID is detected, and a set of the records is set as a set P.
 この後、ミラー位置候補列挙部42は、ステップSP32で求めた集合Pの要素数が0よりも大きいか否かを判断する(SP33)。 Thereafter, the mirror position candidate listing unit 42 determines whether or not the number of elements of the set P obtained in step SP32 is greater than 0 (SP33).
 この判断で否定結果を得ることは、ステップSP30で選択したレコードRに対応するミラー位置要求17の通信要求を満たすトラヒック又は当該トラヒックの経路が存在しない(例えば、レコードRが図7の1行目のレコードであった場合に、「10.2.0.50」を宛先IPアドレスとするトラヒック又は当該トラヒックの経路が存在しない)ことを意味する。かくして、このときミラー位置候補列挙部42は、エラー通知をミラー位置選定部41に送信し(SP38)、この後、ステップSP44に進む。かくして、このときミラー位置選定部41は、ミラー位置候補列挙部42からのエラー通知を受けて、これに応じたミラー位置応答18を操作元9に送信することになる。 Obtaining a negative result in this determination means that there is no traffic that satisfies the communication request of the mirror position request 17 corresponding to the record R selected in step SP30 or there is no route of the traffic (for example, the record R is the first line in FIG. 7). In other words, the traffic having “10.2.0.50” as the destination IP address or the route of the traffic does not exist). Thus, at this time, the mirror position candidate listing unit 42 transmits an error notification to the mirror position selection unit 41 (SP38), and then proceeds to step SP44. Thus, at this time, the mirror position selection unit 41 receives the error notification from the mirror position candidate listing unit 42 and transmits the mirror position response 18 corresponding thereto to the operation source 9.
 これに対して、ステップSP33の判断で肯定結果を得ることは、ステップSP30で選択したレコードRに対応するミラー位置要求17の通信要求を満たすトラヒック又は当該トラヒックの経路が存在することを意味する。かくして、このときミラー位置候補列挙部42は、ステップSP40で選択したレコードRのミラー位置通信装置ID欄34C(図7)にいずれかの通信装置の通信装置IDが格納されているか否か(ステップSP30で選択したレコードRに対応するミラー位置要求17においてミラー位置とすべき通信装置4が指定されているか否か)を判断する(SP34)。 On the other hand, obtaining a positive result in the determination in step SP33 means that there is traffic or a route of the traffic that satisfies the communication request of the mirror position request 17 corresponding to the record R selected in step SP30. Thus, at this time, the mirror position candidate listing unit 42 determines whether the communication device ID of any communication device is stored in the mirror position communication device ID column 34C (FIG. 7) of the record R selected in step SP40 (step S40). It is determined whether or not the communication device 4 to be the mirror position is specified in the mirror position request 17 corresponding to the record R selected in SP30 (SP34).
 ミラー位置候補列挙部42は、この判断で肯定結果を得た場合、経路管理テーブル33Bにおいて集合Pに属するレコードの中から、ステップSP30で選択したレコードRのミラー位置通信装置ID欄34Cに格納された通信装置IDが通信装置ID欄33BB(図6(B))に格納されたレコードをすべて抽出し、抽出したレコード群を集合Fとして記憶する(SP35)。 If a positive result is obtained in this determination, the mirror position candidate listing unit 42 is stored in the mirror position communication device ID column 34C of the record R selected in step SP30 from the records belonging to the set P in the route management table 33B. All the records whose communication device IDs are stored in the communication device ID column 33BB (FIG. 6B) are extracted, and the extracted record group is stored as a set F (SP35).
 またミラー位置候補列挙部42は、ステップSP35で求めた集合Fの要素数が0よりも大きいか否かを判断する(SP36)。 Also, the mirror position candidate listing unit 42 determines whether or not the number of elements of the set F obtained in step SP35 is greater than 0 (SP36).
 この判断で否定結果を得ることは、ステップSP30で選択したレコードRに対応するミラー位置要求17において指定された対象トラヒックが当該ミラー位置要求17においてミラー位置として指定された通信装置4を経由していないことを意味する。かくして、このときミラー位置候補列挙部42は、エラー通知をミラー位置選定部41に送信し(SP38)、この後、ステップSP44に進む。 To obtain a negative result in this determination is that the target traffic specified in the mirror position request 17 corresponding to the record R selected in step SP30 passes through the communication device 4 specified as the mirror position in the mirror position request 17. Means no. Thus, at this time, the mirror position candidate listing unit 42 transmits an error notification to the mirror position selection unit 41 (SP38), and then proceeds to step SP44.
 これに対してステップSP36の判断で肯定結果を得ることは、ステップSP30で選択したレコードRに対応するミラー位置要求17において指定された対象トラヒックが当該ミラー位置要求17においてミラー位置として指定された通信装置4を経由していることを意味する。かくして、このときミラー位置候補列挙部42は、ステップSP30で選択したレコードRに対応するミラー位置要求17に対応するミラー位置候補として、当該ミラー位置要求17において指定された通信装置4をミラー位置候補管理テーブル群35(図8)に登録するため、後述する候補登録処理を実行する(SP37)。またミラー位置候補列挙部42は、この候補登録処理を終了すると、ステップSP44に進む。 On the other hand, obtaining a positive result in the determination at step SP36 means that the traffic specified in the mirror position request 17 corresponding to the record R selected in step SP30 is the communication specified as the mirror position in the mirror position request 17. This means that the device 4 is being routed. Thus, at this time, the mirror position candidate listing unit 42 selects the communication device 4 specified in the mirror position request 17 as a mirror position candidate corresponding to the mirror position request 17 corresponding to the record R selected in step SP30. In order to register in the management table group 35 (FIG. 8), the candidate registration process mentioned later is performed (SP37). Further, after completing the candidate registration process, the mirror position candidate listing unit 42 proceeds to step SP44.
 一方、ミラー位置候補列挙部42は、ステップSP34の判断で否定結果を得た場合、ステップSP32で求めた経路管理テーブル33B(図6(B))のレコードの集合Pをトラヒックごとのレコードの集合P1~Pnに分類する(SP39)。具体的に、ミラー位置候補列挙部42は、ステップSP32で求めた経路管理テーブル33Bのレコードの集合Pを、その通信ID欄33BA(図6(B))に格納された通信IDが同じレコード同士の集合P1~Pnに分類する。 On the other hand, when the mirror position candidate listing unit 42 obtains a negative result in the determination at step SP34, the mirror position candidate listing unit 42 uses the record set P of the route management table 33B (FIG. 6B) obtained at step SP32 as the record set for each traffic. Classify into P1 to Pn (SP39). Specifically, the mirror position candidate enumeration unit 42 uses the records P having the same communication ID stored in the communication ID column 33BA (FIG. 6B) as the set P of the records in the route management table 33B obtained in step SP32. Into sets P1 to Pn.
 続いて、ミラー位置候補列挙部42は、集合Pi(i=1,2,……,n)ごとに、その集合Piに属するレコードの通信装置ID欄33BB(図6(B))に格納されている通信装置IDの集合Si(i=1,2,……,n)をそれぞれ求める(SP40)。これにより、ステップSP30で選択したレコードRに対応するミラー位置要求17の通信要件を満たすトラヒックごとに、そのトラヒックが経由するすべての通信装置4の通信装置IDがそれぞれ集合Siとして求められることになる。 Subsequently, the mirror position candidate enumeration unit 42 stores each set Pi (i = 1, 2,..., N) in the communication device ID column 33BB (FIG. 6B) of the records belonging to the set Pi. Each set of communication device IDs Si (i = 1, 2,..., N) is obtained (SP40). As a result, for each traffic satisfying the communication requirements of the mirror position request 17 corresponding to the record R selected in step SP30, the communication device IDs of all the communication devices 4 through which the traffic passes are obtained as a set Si. .
 次いで、ミラー位置候補列挙部42は、ステップSP30で選択したレコードRに対応するミラー位置要求17に対応するミラー位置候補を探索するため、後述する候補探索処理を実行する(SP41)。この候補探索処理により、ミラー位置となり得る通信装置4の通信装置IDの組合せがそれぞれ候補Ui(i=1,2,……,m)として求められる。すなわち、所望する解析を行うためには、1つの通信装置4においてのみミラーリングを行えば良い場合のみならず、複数の通信装置4においてミラーリングを行う必要がある場合もある。このため候補Uiは、1つの通信装置4の通信装置IDのみを要素とする場合のみならず、複数の通信装置4の通信装置IDを要素とする場合もある。 Next, the mirror position candidate listing unit 42 executes a candidate search process to be described later in order to search for a mirror position candidate corresponding to the mirror position request 17 corresponding to the record R selected in step SP30 (SP41). By this candidate search process, combinations of communication device IDs of communication devices 4 that can be mirror positions are obtained as candidates Ui (i = 1, 2,..., M), respectively. That is, in order to perform a desired analysis, not only the mirroring only needs to be performed in one communication device 4 but also the mirroring may be required in a plurality of communication devices 4. Therefore, the candidate Ui may include not only the communication device ID of one communication device 4 as an element but also the communication device IDs of a plurality of communication devices 4 as an element.
 この後、ミラー位置候補列挙部42は、上述の候補探索処理により得られた候補Uiごとに、経路管理テーブル33B(図6(B))のレコードの中から、その候補Uiの要素と同じ通信装置IDが通信装置ID欄33BB(図6(B))に格納されたすべてのレコードを抽出し、抽出したレコードの集合をそれぞれ集合Vi(i=1,2,……,m)として記憶する(SP42)。 Thereafter, the mirror position candidate enumeration unit 42 performs the same communication as the element of the candidate Ui from the records of the route management table 33B (FIG. 6B) for each candidate Ui obtained by the above-described candidate search process. All records whose device IDs are stored in the communication device ID column 33BB (FIG. 6B) are extracted, and the sets of extracted records are stored as sets Vi (i = 1, 2,..., M), respectively. (SP42).
 さらにミラー位置候補列挙部42は、ステップSP41の候補探索処理により得られたすべての候補Ui(正確にはステップSP42で変換したすべての集合Vi)の必要な情報をミラー位置候補管理テーブル群35に登録する候補登録処理を実行する(SP43)。 Further, the mirror position candidate listing unit 42 stores necessary information of all candidates Ui obtained by the candidate search process in step SP41 (more precisely, all sets Vi converted in step SP42) in the mirror position candidate management table group 35. A candidate registration process for registration is executed (SP43).
 そしてミラー位置候補列挙部42は、ミラー位置要求管理テーブル34(図7)のすべてのレコードについて(ミラー位置要求管理テーブル34に登録されたすべてのミラー位置要求17について)ステップSP31~ステップSP43の処理を実行し終えたか否かを判断する(SP44)。 Then, the mirror position candidate listing unit 42 performs the processing of steps SP31 to SP43 for all the records in the mirror position request management table 34 (FIG. 7) (for all mirror position requests 17 registered in the mirror position request management table 34). It is determined whether or not the execution of the process has been completed (SP44).
 ミラー位置候補列挙部42は、この判断で否定結果を得るとステップSP30に戻り、この後、ステップSP30で選択するレコードRを未処理の他のレコードに順次切り替えながら、ステップSP30~ステップSP44の処理を繰り返す。 When the mirror position candidate listing unit 42 obtains a negative result in this determination, it returns to step SP30, and then sequentially switches the record R selected in step SP30 to another record that has not been processed, and then performs the processing in steps SP30 to SP44. repeat.
 そしてミラー位置候補列挙部42は、やがてミラー位置要求管理テーブル34のすべてのレコードについて(ミラー位置要求管理テーブル34に登録されたすべてのミラー位置要求17について)ステップSP31~ステップSP43の処理を実行し終えることによりステップSP44で肯定結果を得ると、このミラー位置候補列挙処理を終了する。 Then, the mirror position candidate enumeration unit 42 executes the processing of steps SP31 to SP43 for all the records in the mirror position request management table 34 (for all the mirror position requests 17 registered in the mirror position request management table 34). If a positive result is obtained in step SP44 by finishing, this mirror position candidate enumeration process is terminated.
 なお、上述のミラー位置候補列挙処理のステップSP41においてミラー位置候補列挙部42により実行される候補探索処理の具体的内容を図13に示す。 The specific contents of the candidate search process executed by the mirror position candidate enumeration unit 42 in step SP41 of the mirror position candidate enumeration process described above are shown in FIG.
 ミラー位置候補列挙部42は、ミラー位置候補列挙処理のステップSP41に進むと、この図13に示す候補探索処理を開始し、まず、集合S1~Snにそれぞれ含まれる通信装置IDを全種類1つずつ含む集合C1を作成する(SP50)。 When the mirror position candidate enumeration unit 42 proceeds to step SP41 of the mirror position candidate enumeration process, the mirror position candidate enumeration unit 42 starts the candidate search process shown in FIG. 13, and first selects one communication device ID included in each of the sets S1 to Sn. A set C1 including each of them is created (SP50).
 例えば、集合Siとして、図14(A)に示すように、A,B,Cという3つの通信装置IDを要素とする集合S1と、A,D,Cという3つの通信装置IDを要素とする集合S2と、C,F,Gという3つの通信装置IDを要素とする集合S3と、B,E,Fという3つの通信装置IDを要素とする集合S4とが存在する場合、ミラー位置候補列挙部42は、このステップSP50において、図14(B)に示すように、これら集合S1~S4の要素を重複しないように全種類集めたA,B,C,D,E,F,Gという7つの通信装置IDを要素とする集合C1を作成する。 For example, as set Si, as shown in FIG. 14A, set S1 having three communication device IDs A, B, and C as elements and three communication device IDs A, D, and C as elements. When there is a set S2, a set S3 having three communication device IDs C, F, and G as elements, and a set S4 having three communication device IDs B, E, and F as elements, mirror position candidate enumeration In step SP50, as shown in FIG. 14B, the unit 42 collects all kinds of elements of the sets S1 to S4 so as not to overlap, which is 7 A, B, C, D, E, F, G. A set C1 having one communication device ID as an element is created.
 続いて、ミラー位置候補列挙部42は、ステップSP50で作成した集合C1の冪集合を作成し、当該冪集合から空集合及びC1と全く同じ値を持つ集合の二つを除いた残りの要素(すなわち冪集合をが含む0個以上の集合)をそれぞれ集合C2~Cpとする(SP51)。この処理により、図14(C)に示すように、集合C1の冪集合の要素数より2つ少ない数の集合C2~Cpが作成される。 Subsequently, the mirror position candidate listing unit 42 creates a power set of the set C1 created in step SP50, and removes the remaining elements (excluding the empty set and two sets having the same value as C1 from the power set. That is, zero or more sets including the heel set) are set as sets C2 to Cp, respectively (SP51). As a result of this processing, as shown in FIG. 14C, sets C2 to Cp, which are two smaller than the number of elements in the set of sets C1, are created.
 次いで、ミラー位置候補列挙部42は、集合C1~Cpの中から、集合S1~Snのそれぞれの集合との共通部分の要素数が全て1となる集合を抽出し、これらを候補U1~Uqとする(SP52)。例えば、図14(D)に示すように、A及びBという2つの通信装置IDを要素とする集合C9は、集合S1において2つの共通部分の要素をもつことになるため候補Uiとすることができないが、A及びFという2つの通信装置IDを要素とする集合C13は、集合S1~集合S4のすべてにおいて共通部分の要素が1つであるため候補として抽出されることになる。SP42の目的は、ミラー位置要求17を満たすために同時にミラーリングを行う複数トラフィックを収集漏れや重複なくミラーリングするためのミラー位置の組合せを算出することである。ここで、集合S1~Snはそれぞれの集合が一つのトラヒックが通信経路を通信装置4の通信装置IDとして表しているため、Siを収集漏れや重複なくミラーリングを行うには、集合Siの要素である1個以上の通信装置IDのうち、丁度1個の通信装置IDがミラー位置として選定されればよい(0個の場合、トラヒックの収集漏れとなり、2個以上の場合は1つのトラヒックを重複してミラーリングをすることになる)。このため、集合S1~Snの全ての集合に対し、それぞれの集合から丁度1個の通信装置IDをミラー位置として選定する通信装置IDの集合は、集合S1~Snが通信経路を表すトラヒックを全て同時にミラーリングしても収集漏れや重複が起きないミラー位置の組合せを表す。SP42では、集合Ckが集合Siの要素のうち、丁度1個の通信装置IDを選定しているかの判定として、共通部分の要素数を用いている。 Next, the mirror position candidate enumeration unit 42 extracts from the sets C1 to Cp a set in which the number of elements in the common part with each set of the sets S1 to Sn is all 1, and sets these as candidates U1 to Uq. (SP52). For example, as shown in FIG. 14 (D), a set C9 having two communication device IDs A and B as elements has two common part elements in the set S1, and therefore may be a candidate Ui. However, the set C13 having two communication device IDs A and F as elements is extracted as a candidate because there is one common element in all of the sets S1 to S4. The purpose of the SP 42 is to calculate a combination of mirror positions for mirroring a plurality of traffics that are simultaneously mirrored to satisfy the mirror position request 17 without collection omission or duplication. Here, since each of the sets S1 to Sn represents a communication path as a communication device ID of the communication device 4 for each set of traffic, in order to mirror Si without collection omission or duplication, an element of the set Si is used. Of the one or more communication device IDs, exactly one communication device ID may be selected as the mirror position (when 0, traffic is not collected, and when there are 2 or more, one traffic is duplicated) And mirror it). For this reason, for all sets S1 to Sn, a set of communication device IDs that select exactly one communication device ID from each set as a mirror position is a set of communication devices ID for which all sets S1 to Sn represent communication paths. Represents a combination of mirror positions where collection omissions and duplication do not occur even when mirroring at the same time. In SP42, the number of elements in the common part is used to determine whether the set Ck has just selected one communication device ID among the elements of the set Si.
 そしてミラー位置候補列挙部42は、この後、この候補探索処理を終了し、この候補探索処理のステップSP52において得られた図14(E)に示すような候補U1~Uqを利用して図12について上述したミラー位置候補列挙処理のステップSP41を実行する。 Then, the mirror position candidate listing unit 42 ends this candidate search process, and uses the candidates U1 to Uq as shown in FIG. 14E obtained in step SP52 of this candidate search process, as shown in FIG. Step SP41 of the mirror position candidate enumeration process described above is executed.
 一方、図15は、上述のミラー位置候補列挙処理(図12)のステップSP37又はステップSP43においてミラー位置候補列挙部42により実行される候補登録処理の具体的内容を示す。 On the other hand, FIG. 15 shows specific contents of the candidate registration process executed by the mirror position candidate enumeration unit 42 in step SP37 or step SP43 of the mirror position candidate enumeration process (FIG. 12).
 ミラー位置候補列挙部42は、ミラー位置候補列挙処理のステップSP37又はステップSP43に進むと、この候補登録処理を開始し、まず、そのとき登録しようとするミラー位置候補に対して付与する固有の候補IDを生成し、生成した候補IDを、そのときミラー位置候補列挙処理(図12)のステップSP30で選択したミラー位置要求管理テーブル34(図7)のレコード(レコードR)の要求ID欄34A(図7)に格納されている要求IDと対応付けてミラー位置候補管理テーブル群35(図8)の候補管理テーブル35A(図8(A))に登録する(SP60)。 When the mirror position candidate enumeration unit 42 proceeds to step SP37 or step SP43 of the mirror position candidate enumeration process, the mirror position candidate enumeration unit 42 starts this candidate registration process. First, the unique candidate to be given to the mirror position candidate to be registered at that time An ID is generated, and the generated candidate ID is assigned to the request ID column 34A (in the record (record R) of the mirror position request management table 34 (FIG. 7) selected in step SP30 of the mirror position candidate enumeration process (FIG. 12) ( It is registered in the candidate management table 35A (FIG. 8A) of the mirror position candidate management table group 35 (FIG. 8) in association with the request ID stored in FIG. 7 (SP60).
 続いて、ミラー位置候補列挙部42は、通信解析情報テーブル群33(図6)の経路管理テーブル33B(図6(B))における対応するレコード(ミラー位置候補列挙処理のステップSP37の場合にはレコードの集合Fに属するレコード、ステップSP43の場合にはレコードの集合V1~Vmに属するレコード)を、通信装置ID欄33BB(図6(B))に格納された通信装置IDが同じもの同士をまとめるように分類し、当該分類により得られた通信装置IDが同じレコード群をそれぞれ集合X1~Xpとする(SP61)。 Subsequently, the mirror position candidate listing unit 42, in the case of step SP37 of the mirror position candidate listing process, in the corresponding record in the route management table 33B (FIG. 6B) of the communication analysis information table group 33 (FIG. 6). Records belonging to the record set F, records belonging to the record set V1 to Vm in the case of step SP43), and those having the same communication device ID stored in the communication device ID column 33BB (FIG. 6B) The records are grouped together, and the record groups having the same communication device ID obtained by the classification are set as sets X1 to Xp, respectively (SP61).
 次いで、ミラー位置候補列挙部42は、ステップSP61の分類により得られた集合X1~Xpの中から未処理の1つの集合Xi(i=1,2,……,p)を選択し(SP62)、選択した集合Xi(以下、これを選択レコード群Xiと呼ぶ)に属する各レコードの通信量欄33BC(図6(B))にそれぞれ格納されている通信量を合計した合計通信量を算出する(SP63)。 Next, the mirror position candidate enumeration unit 42 selects one unprocessed set Xi (i = 1, 2,..., P) from the sets X1 to Xp obtained by the classification in step SP61 (SP62). Then, the total communication amount is calculated by adding the communication amounts stored in the communication amount column 33BC (FIG. 6B) of each record belonging to the selected set Xi (hereinafter referred to as the selected record group Xi). (SP63).
 さらにミラー位置候補列挙部42は、ステップSP63で算出した合計通信量と、その選択レコード群Xiに対応する通信装置IDとをステップSP60で生成した候補IDと対応付けてミラー位置候補管理テーブル群35(図8)の候補位置管理テーブル35B(図8(B))に登録し(SP64)、この後、ステップSP61の分類により得られたすべての集合X1~XpについてステップSP63~ステップSP64の処理を実行し終えたか否かを判断する(SP65)。 Further, the mirror position candidate listing unit 42 associates the total communication amount calculated in step SP63 and the communication device ID corresponding to the selected record group Xi with the candidate ID generated in step SP60, and the mirror position candidate management table group 35. The candidate position management table 35B (FIG. 8B) (FIG. 8B) of FIG. 8 is registered (SP64). Thereafter, the processing of steps SP63 to SP64 is performed for all sets X1 to Xp obtained by the classification of step SP61. It is determined whether or not the execution has been completed (SP65).
 ミラー位置候補列挙部42は、この判断で否定結果を得るとステップSP62に戻り、この後、ステップSP62で選択する集合Xiを未処理の他の集合Xiに順次切り替えながら、ステップSP62~ステップSP65の処理を繰り返す。 When the mirror position candidate listing unit 42 obtains a negative result in this determination, it returns to step SP62, and then sequentially switches the set Xi selected in step SP62 to another set Xi that has not been processed, and then proceeds from step SP62 to step SP65. Repeat the process.
 そしてミラー位置候補列挙部42は、やがてステップSP61の分類により得られたすべての集合X1~Xpをミラー位置候補管理テーブル群35に登録し終えることによりステップSP65で肯定結果を得ると、この候補登録処理を終了する。 When the mirror position candidate listing unit 42 finally registers all the sets X1 to Xp obtained by the classification in step SP61 in the mirror position candidate management table group 35 and obtains a positive result in step SP65, this candidate registration The process ends.
(1-2-2-3)充足組合せ選定処理
 図16は、ミラー位置候補列挙部42からの組合せ探索要求を受信した充足組合せ選定部43により実行される処理(図9のステップSP7の処理であり、以下、これを充足組合せ選定処理と呼ぶ)の具体的な処理内容を示す。充足組合せ選定部43は、かかる組合せ探索要求を受信すると、この図16に示す処理手順に従って、ミラー位置要求17ごとに、ミラー位置候補列挙部42により列挙されたミラー位置候補の中から1つのミラー位置候補を選定し、選定したミラー位置候補をミラー位置の選定結果としてミラー位置選定部41に通知する。
(1-2-2-3) Satisfaction Combination Selection Processing FIG. 16 shows processing executed by the satisfaction combination selection unit 43 that has received the combination search request from the mirror position candidate listing unit 42 (in the process of step SP7 in FIG. 9). Yes, this is hereinafter referred to as a satisfaction combination selection process). Upon receiving such a combination search request, the sufficiency combination selection unit 43 follows the processing procedure shown in FIG. 16 for each mirror position request 17 and selects one mirror from the mirror position candidates enumerated by the mirror position candidate enumeration unit 42. A position candidate is selected, and the selected mirror position candidate is notified to the mirror position selection unit 41 as a mirror position selection result.
 実際上、充足組合せ選定部43は、かかる組合せ探索要求を受信すると、この図16に示す充足組合せ選定処理を開始し、まず、ミラー位置候補管理テーブル群35を構成する候補管理テーブル35A(図8(A))の各レコードの候補ID欄35AB(図8(A))に格納されている候補IDを要件IDごとに分類することにより、候補IDの集合C1~Cnを生成する(SP70)。従って、集合C1~Cnは、それぞれ異なる要件IDに対応する。 In practice, when the satisfaction combination selection unit 43 receives such a combination search request, the satisfaction combination selection unit 43 starts the satisfaction combination selection process shown in FIG. 16, and first, a candidate management table 35A (FIG. 8) configuring the mirror position candidate management table group 35. A set of candidate IDs C1 to Cn is generated by classifying the candidate IDs stored in the candidate ID column 35AB (FIG. 8A) of each record of (A)) for each requirement ID (SP70). Accordingly, the sets C1 to Cn correspond to different requirement IDs.
 続いて、充足組合せ選定部43は、ステップSP70で生成した集合C1~Cnからそれぞれ候補IDを1つずつ抽出して候補IDの集合Skとして記憶する。集合Skは、候補IDの組合せが一意となるすべての組合せの数だけ作成し、候補IDの集合S1~Spとして記憶する(SP71)。 Subsequently, the sufficiency combination selection unit 43 extracts candidate IDs one by one from the sets C1 to Cn generated in step SP70 and stores them as a set of candidate IDs Sk. As many sets Sk as the number of combinations of candidate IDs that are unique are created and stored as candidate ID sets S1 to Sp (SP71).
 次いで、充足組合せ選定部43は、変数kを1にセットし(SP72)、候補位置管理テーブル35B(図8(B))のレコードのうち、候補ID群Skに含まれる各候補IDに対応した各レコード(つまり、候補ID群Skに含まれるいずれかの候補IDが候補ID欄35BA(図8(B))に格納された各レコード)の通信量欄35BC(図8(B))にそれぞれ格納されている通信量の合計値を通信装置IDごとにそれぞれ算出する(SP73)。 Next, the sufficiency combination selection unit 43 sets the variable k to 1 (SP72), and corresponds to each candidate ID included in the candidate ID group Sk among the records of the candidate position management table 35B (FIG. 8B). Each of the records (that is, each record in which any candidate ID included in the candidate ID group Sk is stored in the candidate ID column 35BA (FIG. 8B)) is stored in the communication amount column 35BC (FIG. 8B). The total value of the stored traffic is calculated for each communication device ID (SP73).
 この後、充足組合せ選定部43は、ネットワークトポロジ情報テーブル32(図5)を参照して、ステップSP73で通信量の合計値をそれぞれ算出した各通信装置IDにそれぞれ対応するすべての通信装置4において、当該合計値がミラーポート閾値以下であるか否かを判断する(SP74)。 Thereafter, the sufficiency combination selection unit 43 refers to the network topology information table 32 (FIG. 5), and in all the communication devices 4 respectively corresponding to the respective communication device IDs for which the total value of the communication amount has been calculated in step SP73. Then, it is determined whether or not the total value is less than or equal to the mirror port threshold (SP74).
 充足組合せ選定部43は、この判断で否定結果を得ると、変数kの値が上述の候補ID群S1~Spの数以上となったか否かを判断する(SP75)。そして充足組合せ選定部43は、この判断で否定結果を得ると変数kの値をインクリメント(1だけ増加)した後(SP76)、ステップSP73に戻り、この後、ステップSP74又はステップSP75で肯定結果を得るまでステップSP73~ステップSP76の処理を繰り返す。 If the satisfaction combination selection unit 43 obtains a negative result in this determination, it determines whether or not the value of the variable k is equal to or greater than the number of candidate ID groups S1 to Sp described above (SP75). If the satisfaction combination selection unit 43 obtains a negative result in this determination, it increments (increases by 1) the value of the variable k (SP76), returns to step SP73, and thereafter gives a positive result in step SP74 or step SP75. Steps SP73 to SP76 are repeated until it is obtained.
 そして充足組合せ選定部43は、やがてステップSP71で列挙した候補ID群S1~Spの中からすべての通信装置4で通信量の合計値がその通信装置4のミラーポート閾値以下となる候補ID群Skが最初に検出されることによりステップSP74において肯定結果を得ると、その候補ID群Skに含まれる候補が示す要件IDと、通信装置IDの対応関係とをミラー位置として選定し(SP78)、この後、この充足組合せ選定処理を終了する。 Then, the sufficiency combination selecting unit 43 eventually selects a candidate ID group Sk in which the total amount of traffic in all the communication devices 4 from the candidate ID groups S1 to Sp enumerated in step SP71 is less than or equal to the mirror port threshold of the communication device 4. When a positive result is obtained in step SP74 by first detecting the ID, the requirement ID indicated by the candidate included in the candidate ID group Sk and the correspondence relationship between the communication device IDs are selected as mirror positions (SP78). Then, the satisfaction combination selection process is terminated.
 また充足組合せ選定部43は、ステップSP71で列挙した候補ID群Skの中からすべての通信装置4で通信量の合計値がその通信装置4のミラーポート閾値以下となる候補ID群Skを検出できずにステップSP75で肯定結果を得ると、所定のエラー通知をミラー位置選定部41に送信し(SP77)、この後、この充足組合せ選定処理を終了する。 Further, the sufficiency combination selecting unit 43 can detect a candidate ID group Sk in which the total value of the communication amount is less than or equal to the mirror port threshold value of the communication device 4 among the candidate ID groups Sk listed in step SP71. If a positive result is obtained in step SP75, a predetermined error notification is transmitted to the mirror position selection unit 41 (SP77), and then the satisfaction combination selection process is terminated.
(1-3)ミラーリング状況表示画面
 図17は、所定操作により操作元9のクライアント端末15(図1)や運用管理装置16(図1)に表示可能なミラーリング状況表示画面60を示す。このミラーリング状況表示画面60は、データネットワーク2を流れるトラヒックのうち、ミラー位置が設定されたトラヒックのミラーリングの状況と、ミラー位置に設定された各通信装置4におけるそのトラヒックのミラーポートMPにおける通信量とをユーザに提示するための画面である。
(1-3) Mirroring Status Display Screen FIG. 17 shows a mirroring status display screen 60 that can be displayed on the client terminal 15 (FIG. 1) or the operation management apparatus 16 (FIG. 1) of the operation source 9 by a predetermined operation. The mirroring status display screen 60 displays the mirroring status of traffic that has a mirror position set in the traffic flowing through the data network 2, and the traffic on the mirror port MP of the traffic in each communication device 4 that is set to the mirror position. Is a screen for presenting to the user.
 このミラーリング状況表示画面60は、ミラー取得状況表示領域61及びミラーポート通信量表示領域62から構成される。ミラー取得状況表示領域61は、データネットワーク2におけるミラーリングの取得状況を表示するための領域であり、ミラーポート通信量表示領域62は、データネットワーク2においてミラー位置として設定されている通信装置4のミラーポートMPの通信量を表示するための領域である。 The mirroring status display screen 60 includes a mirror acquisition status display area 61 and a mirror port traffic display area 62. The mirror acquisition status display area 61 is an area for displaying the mirroring acquisition status in the data network 2, and the mirror port traffic display area 62 is a mirror of the communication device 4 set as the mirror position in the data network 2. This is an area for displaying the traffic of the port MP.
 ミラー取得状況表示領域61には、1又は複数の通信装置アイコン70、1又は複数の対象トラヒック線71、1又は複数のミラー位置アイコン72及び凡例73が表示される。通信装置アイコン70は、それぞれデータネットワーク2を構成する通信装置4に対応させて表示される。また対象トラヒック線71は、それぞれミラーリングを行っているトラヒック(対象トラヒック)の経路を表しており、ミラー位置アイコン72は、対象トラヒックをミラーリングしている通信装置4の通信装置アイコン70に対応させて表示される。対象トラヒック線71は、ミラー位置要求17(要求ID)ごとに異なる色や線種(実線又は破線など)で表示され、対象トラヒックと対象トラヒック線71との対応関係が凡例73に表示される。 In the mirror acquisition status display area 61, one or more communication device icons 70, one or more target traffic lines 71, one or more mirror position icons 72, and a legend 73 are displayed. The communication device icons 70 are displayed in correspondence with the communication devices 4 constituting the data network 2. The target traffic line 71 represents a path of traffic (target traffic) that is mirrored, and the mirror position icon 72 corresponds to the communication device icon 70 of the communication device 4 that is mirroring the target traffic. Is displayed. The target traffic line 71 is displayed in a different color or line type (solid line or broken line) for each mirror position request 17 (request ID), and the correspondence between the target traffic and the target traffic line 71 is displayed in the legend 73.
 ミラーポート通信量表示領域62には、縦軸に通信量、横軸に時間をとった二次元座標80が表示される。そしてユーザがミラー取得状況表示領域61内の特定の通信装置アイコン70(ミラー位置に設定されている通信装置4に対応する通信装置アイコン70)を選択すると、その通信装置アイコン70に対応する通信装置4のミラーポートMPにおける個々の対象トラヒックの通信量をそれぞれ表す1又は複数のグラフ81が二次元座標80内に積上げグラフ形式で表示される。また二次元座標80上には、そのミラーポートMPの通信量の閾値を表す閾値線82も表示される。 In the mirror port traffic volume display area 62, two-dimensional coordinates 80 are displayed with the traffic volume on the vertical axis and the time on the horizontal axis. When the user selects a specific communication device icon 70 (communication device icon 70 corresponding to the communication device 4 set at the mirror position) in the mirror acquisition status display area 61, the communication device corresponding to the communication device icon 70 is displayed. One or a plurality of graphs 81 each representing the traffic amount of each target traffic in the four mirror ports MP are displayed in a two-dimensional coordinate 80 in a stacked graph format. On the two-dimensional coordinate 80, a threshold line 82 indicating the threshold of the traffic amount of the mirror port MP is also displayed.
 二次元座標80における対象トラヒックごとのグラフ81は、図6(B)について上述した経路管理テーブル33Bのその対象トラヒックのその通信装置4に対応する行の通信量欄33BC(図6(B))に格納された通信量に基づいて生成され、閾値線82は、図5について上述したネットワークトポロジ情報テーブル32に登録されているその通信装置4のミラーポート閾値に基づいて生成される。 The graph 81 for each target traffic in the two-dimensional coordinate 80 is a traffic volume column 33BC in the row corresponding to the communication device 4 of the target traffic in the path management table 33B described above with reference to FIG. 6B (FIG. 6B). The threshold line 82 is generated based on the mirror port threshold value of the communication device 4 registered in the network topology information table 32 described above with reference to FIG.
(1-4)本実施の形態の効果
 以上の構成を有する本実施の形態の管理装置8では、ミラー位置候補列挙部42において、対象トラフィックが通過するすべての通信装置4を特定し、特定したこれら通信装置4のすべての組合せをミラー位置候補として列挙し、この後、充足組合せ選定部43において、ミラー位置候補列挙部42により列挙されたミラー位置候補の中から、そのミラー位置候補を構成するすべての通信装置4について、ミラーポートMPの通信量が後述するミラーポート閾値以下となるミラー位置候補を1つ選択し、これをミラー位置の選定結果としてミラー位置選定部41に通知する。
(1-4) Effects of the present embodiment In the management device 8 of the present embodiment having the above configuration, the mirror position candidate enumeration unit 42 identifies and identifies all the communication devices 4 through which the target traffic passes. All combinations of these communication devices 4 are listed as mirror position candidates, and thereafter, in the satisfaction combination selection unit 43, the mirror position candidates are configured from the mirror position candidates listed by the mirror position candidate listing unit 42. For all the communication devices 4, one mirror position candidate whose communication amount of the mirror port MP is equal to or less than a mirror port threshold value to be described later is selected, and this is notified to the mirror position selection unit 41 as a mirror position selection result.
 従って、本管理装置8によれば、ミラーポートMPにおいて輻輳を発生しない通信装置4をミラー位置として選定することができ、かくしてミラーリングしたトラフィックが破棄されることなくポートミラーリングを実行可能なミラー位置(通信装置4)を迅速に選定することができる。 Therefore, according to the present management device 8, the communication device 4 that does not cause congestion in the mirror port MP can be selected as the mirror position, and thus the mirror position (where the mirrored traffic can be executed without discarding the mirrored traffic) The communication device 4) can be selected quickly.
(2)第2の実施の形態
 図1~図4との対応に同一符号を示す図18は、第2の実施の形態による通信システム90の論理構成を示す。この通信システム90は、通信装置91のミラーポートMP(図1)の空き帯域が一定量以下になった場合にミラー位置の再選定を行う点と、ミラー位置の再選定が不要な場合にはそのような再選定を行わないように利用者等が設定できる点とを特徴とする。なお、本実施の形態による通信システム90のハードウェア構成及び他の機能は第1の実施の形態による通信システム1と同様であるため、ここでの説明は省略する。
(2) Second Embodiment FIG. 18, which shows the same reference numerals corresponding to FIGS. 1 to 4, shows a logical configuration of a communication system 90 according to the second embodiment. This communication system 90 performs the reselection of the mirror position when the free bandwidth of the mirror port MP (FIG. 1) of the communication device 91 is below a certain amount, and when the reselection of the mirror position is unnecessary. It is characterized in that a user or the like can be set so as not to perform such reselection. Note that the hardware configuration and other functions of the communication system 90 according to the present embodiment are the same as those of the communication system 1 according to the first embodiment, and a description thereof will be omitted here.
 実際上、本通信システム90では、通信装置91に転送機能10、ミラーリング機能11及び通信情報通知機能12に加えて、帯域情報出力機能92が搭載されている。この帯域情報出力機能92は、予め設定された一定時間間隔でその通信装置91のミラーポートMPの現在の使用帯域(以下、これをミラーポート使用帯域と呼ぶ)をミラーポート帯域情報93として制御ネットワーク7を介して管理装置94に送信する機能である。このような機能は公知であり、例えば一般的な通信装置が備えるSNNP(Simple Network Management Protocol)エージェントの機能を適用することができる。 Actually, in the communication system 90, in addition to the transfer function 10, the mirroring function 11, and the communication information notification function 12, a band information output function 92 is installed in the communication device 91. This band information output function 92 uses the current use band of the mirror port MP of the communication device 91 (hereinafter referred to as the mirror port use band) as mirror port band information 93 at a predetermined time interval set as a control network. 7 is a function of transmitting to the management apparatus 94 via 7. Such a function is publicly known, and for example, a function of an SNNP (Simple Network Management Protocol) agent provided in a general communication apparatus can be applied.
 管理装置94は、ミラーポート帯域監視部100を備える点と、ミラー位置選定部101の機能が異なる点と、ミラー位置要求管理テーブル102の構成が異なる点とを除いて第1の実施の形態の管理装置8と同様に構成されている。ミラーポート帯域監視部100及び本実施の形態によるミラー位置選定部101は、管理装置8のプロセッサが主記憶装置22に格納された本実施の形態の管理プログラム103(図3)を実行することにより具現化される機能である。 The management device 94 is the same as that of the first embodiment except that the mirror port bandwidth monitoring unit 100 is provided, the function of the mirror position selection unit 101 is different, and the configuration of the mirror position request management table 102 is different. The configuration is the same as that of the management device 8. The mirror port bandwidth monitoring unit 100 and the mirror position selection unit 101 according to the present embodiment execute the management program 103 (FIG. 3) of the present embodiment stored in the main storage device 22 by the processor of the management device 8. It is a function that is embodied.
 このミラーポート帯域監視部100は、データネットワーク2を構成する各通信装置91からそれぞれ送信されてくる上述のミラーポート帯域情報93に基づいて、各通信装置91のミラーポート使用帯域を監視する処理を実行する。 The mirror port bandwidth monitoring unit 100 performs processing for monitoring the mirror port usage bandwidth of each communication device 91 based on the above-described mirror port bandwidth information 93 transmitted from each communication device 91 constituting the data network 2. Execute.
 具体的に、ミラーポート帯域監視部100は、管理装置94が通信装置91からのミラーポート帯域情報93を受信すると、ネットワークトポロジ情報テーブル32(図5)を参照して、そのミラーポート帯域情報93に含まれる送信元の通信装置91の通信装置IDと同じ通信装置IDが通信装置ID欄32A(図5)に格納されているレコードを特定し、そのレコードのミラーポート閾値欄32D(図5)からその通信装置91のミラーポート閾値を取得する。 Specifically, when the management device 94 receives the mirror port bandwidth information 93 from the communication device 91, the mirror port bandwidth monitoring unit 100 refers to the network topology information table 32 (FIG. 5) and the mirror port bandwidth information 93. Is specified in the communication device ID column 32A (FIG. 5), and the mirror port threshold column 32D (FIG. 5) of the record is specified. From this, the mirror port threshold value of the communication device 91 is acquired.
 またミラーポート帯域監視部100は、取得したミラーポート閾値と、ミラーポート帯域情報93に格納されている現在のミラーポート使用帯域とを比較し、当該ミラーポート使用帯域が当該ミラーポート閾値よりも大きい場合には、ミラー位置再選定要求をミラー位置選定部101に与える。 The mirror port bandwidth monitoring unit 100 compares the acquired mirror port threshold value with the current mirror port usage bandwidth stored in the mirror port bandwidth information 93, and the mirror port usage bandwidth is greater than the mirror port threshold value. In this case, a mirror position reselection request is given to the mirror position selection unit 101.
 一方、本実施の形態による通信システム90では、操作元9から管理装置94に送信されるミラー位置要求103が、通信要件及びミラー位置通信装置IDの1つ以上の組合せに加えて、ミラー位置固定フラグを含む点が第1の実施の形態の通信システム1と相違する。 On the other hand, in the communication system 90 according to the present embodiment, the mirror position request 103 transmitted from the operation source 9 to the management apparatus 94 is fixed to the mirror position in addition to one or more combinations of communication requirements and mirror position communication apparatus ID. It differs from the communication system 1 of the first embodiment in that a flag is included.
 ミラー位置固定フラグは、対象トラヒックのミラー位置を一度設定した通信装置91から他の通信装置91に変更可能か否かを示すブール値であり、「true(変更不可)」又は「false(変更可能)」のいずれかの値をとる。 The mirror position fixing flag is a Boolean value indicating whether the mirror position of the target traffic can be changed from the communication apparatus 91 once set to another communication apparatus 91, and is “true (cannot be changed)” or “false (changeable). ) ”.
 このため本実施の形態のミラー位置要求管理テーブル102は、図19に示すように、図7について上述した第1の実施の形態のミラー位置要求管理テーブル34の要求ID欄34A、通信要件欄34B及びミラー位置通信装置ID欄34Cと同様機能及び構成を有する要求ID欄102A、通信要件欄102B及びミラー位置通信装置ID欄102Cに加えて、ミラー位置固定フラグ欄102Dが設けられており、ミラー位置選定部101が受信したミラー位置要求103に含まれるミラー位置固定フラグがこのミラー位置固定フラグ欄102Dに格納されて管理される。 For this reason, as shown in FIG. 19, the mirror position request management table 102 of the present embodiment has a request ID column 34A and a communication requirement column 34B of the mirror position request management table 34 of the first embodiment described above with reference to FIG. In addition to the request ID column 102A, the communication requirement column 102B, and the mirror position communication device ID column 102C having the same function and configuration as the mirror position communication device ID column 34C, a mirror position fixing flag column 102D is provided. The mirror position fixing flag included in the mirror position request 103 received by the selection unit 101 is stored and managed in this mirror position fixing flag column 102D.
 ミラー位置選定部101は、第1の実施の形態のミラー位置選定部41(図4)と同様の機能に加えて、ミラー位置要求103に含まれているミラー位置固定フラグが「false」であった場合に、ミラー位置を変更させないための処理を実行する機能と、ミラーポート帯域監視部100から上述のミラー位置再選定要求が与えられた場合にミラー位置を再選定するための処理を実行する機能とが搭載されている。 In addition to the same function as the mirror position selection unit 41 (FIG. 4) of the first embodiment, the mirror position selection unit 101 has a mirror position fixing flag included in the mirror position request 103 of “false”. If the mirror port bandwidth monitoring unit 100 gives the above-described mirror position reselection request, the function for re-selecting the mirror position is executed. It is equipped with functions.
 実際上、ミラー位置選定部101は、操作元9からミラー位置要求103が与えられた場合、第1の実施の形態のミラー位置選定部41と同様に、これをミラー位置要求管理テーブル102に登録すると共に、所定のタイミングでミラー位置候補列挙部42にミラー位置候補列挙要求を与える。そしてミラー位置選定部101は、この結果として充足組合せ選定部43からミラー位置の選定結果が通知されると、ミラー位置要求管理テーブル102上で、この通知(ミラー位置の選定結果)に含まれる要求IDと同じ要求IDが要求ID欄102A(図19)に格納されたレコードを検索し、この検索により検出したレコードのミラー位置固定フラグ欄102D(図19)に格納されたミラー位置固定フラグを取得する。 In practice, when the mirror position request 103 is given from the operation source 9, the mirror position selection unit 101 registers this in the mirror position request management table 102 as in the case of the mirror position selection unit 41 of the first embodiment. At the same time, a mirror position candidate enumeration request is given to the mirror position candidate enumeration unit 42 at a predetermined timing. When the mirror position selection unit 101 is notified of the mirror position selection result from the satisfaction combination selection unit 43 as a result, the request included in this notification (mirror position selection result) on the mirror position request management table 102. A record in which the same request ID as the ID is stored in the request ID column 102A (FIG. 19) is searched, and the mirror position fixing flag stored in the mirror position fixing flag column 102D (FIG. 19) of the record detected by this search is acquired. To do.
 そしてミラー位置選定部101は、このとき取得したミラー位置固定フラグが「true」であった場合には、ミラー位置候補管理テーブル群35の候補位置管理テーブル35B(図8(B))のレコードの中から、かかるミラー位置の選定結果に含まれる候補IDと同じ候補IDが候補ID欄35BA(図8(B))に格納されたレコードを検出し、そのレコードの通信装置ID欄35BB(図8(B))に格納された通信装置ID(以下、これを候補通信装置IDと呼ぶ)を取得する。 When the mirror position fixing flag acquired at this time is “true”, the mirror position selection unit 101 stores the record of the candidate position management table 35B (FIG. 8B) in the mirror position candidate management table group 35. A record in which the same candidate ID as the candidate ID included in the mirror position selection result is stored in the candidate ID column 35BA (FIG. 8B) is detected, and the communication device ID column 35BB (FIG. 8) of the record is detected. The communication device ID stored in (B)) (hereinafter referred to as a candidate communication device ID) is acquired.
 この後、ミラー位置選定部101は、ミラー位置要求管理テーブル102のレコードのうち、充足組合せ選定部43から与えられたミラー位置の選定結果に含まれる要求IDと同じ要求IDが要求ID欄102A(図19)に格納されたレコードを検出し、そのレコードのミラー位置通信装置ID欄102C(図19)に、上述のようにして取得した候補通信装置IDを格納する。ただし、ミラー位置選定部101は、かかるミラー位置通信装置ID欄102Cに既に値(通信装置ID)が格納されている場合には、その値を更新しない。この他の処理は第1の実施の形態について上述した図9のステップSP9以降の処理と同様である。 Thereafter, the mirror position selection unit 101 has the same request ID as the request ID included in the mirror position selection result given from the satisfaction combination selection unit 43 among the records in the mirror position request management table 102. The record stored in FIG. 19) is detected, and the candidate communication device ID acquired as described above is stored in the mirror position communication device ID column 102C (FIG. 19) of the record. However, when a value (communication device ID) is already stored in the mirror position communication device ID column 102C, the mirror position selection unit 101 does not update the value. The other processes are the same as the processes after step SP9 in FIG. 9 described above for the first embodiment.
 またミラー位置選定部101は、上述のようにして取得したミラー位置固定フラグが「false」であった場合には、第1の実施の形態のミラー位置選定部41(図4)と同様の処理を行う。 Further, when the mirror position fixing flag acquired as described above is “false”, the mirror position selection unit 101 performs the same processing as the mirror position selection unit 41 (FIG. 4) of the first embodiment. I do.
 さらにミラー位置選定部101は、ミラーポート帯域監視部100からミラー位置再選定要求が与えられると、上述した操作元9からミラー位置要求103が与えられた場合と同様の処理を実行する。 Further, when the mirror position reselection request is given from the mirror port bandwidth monitoring unit 100, the mirror position selection unit 101 executes the same process as when the mirror position request 103 is given from the operation source 9 described above.
 これにより本実施の形態の通信システム90では、通信装置91のミラーポート使用帯域がそのミラーポートMPについて設定された閾値(ミラーポート閾値)を超えた場合に自動的にミラー位置の再選定が行われてその結果が操作元9にミラー位置応答18として通知される。 As a result, in the communication system 90 according to the present embodiment, the mirror position is automatically reselected when the mirror port bandwidth of the communication device 91 exceeds the threshold value (mirror port threshold value) set for the mirror port MP. The result is notified to the operation source 9 as a mirror position response 18.
 以上の構成を有する本実施の形態の通信システム1では、通信装置91のミラーポート使用帯域が予め定められたミラーポート閾値を超えた場合(つまりミラーポートMPの空帯域が一定量未満となった場合)にミラー位置の再選定が行われるため、ミラー位置に設定された通信装置4においてミラーポートの輻輳が発生し、ミラーリングしたトラフィックが破棄される事態が発生するのを未然に防止することができる。 In the communication system 1 of the present embodiment having the above configuration, when the mirror port use band of the communication device 91 exceeds a predetermined mirror port threshold (that is, the empty band of the mirror port MP is less than a certain amount). In this case, the mirror position is reselected, so that it is possible to prevent the occurrence of a situation in which the mirror port congestion occurs in the communication device 4 set at the mirror position and the mirrored traffic is discarded. it can.
 また本実施の形態の通信システム90では、ミラー位置要求において、ミラー位置固定フラグを「true」に設定することによりミラー位置の固定化が可能となるため、重要なトラヒックについて、ミラー位置を変更することによるトラヒック収集の瞬断を防ぐことができる。 Further, in the communication system 90 according to the present embodiment, the mirror position can be fixed by setting the mirror position fixing flag to “true” in the mirror position request. Therefore, the mirror position is changed for important traffic. It is possible to prevent a momentary interruption of traffic collection.
(3)他の実施の形態
 なお上述の第1及び第2の実施の形態においては、管理装置8,94のネットワーク情報解析部40、ミラー位置選定部41、ミラー位置候補列挙部42及び充足組合せ選定部43並びにミラーポート帯域監視部100をソフトウェア構成とするようにした場合について述べたが、本発明はこれに限らず、これらの一部又は全部をハードウェア構成とするようにしても良い。
(3) Other Embodiments In the first and second embodiments described above, the network information analysis unit 40, the mirror position selection unit 41, the mirror position candidate listing unit 42, and the satisfaction combination of the management devices 8 and 94 are provided. Although the case where the selection unit 43 and the mirror port bandwidth monitoring unit 100 are configured as software has been described, the present invention is not limited to this, and some or all of these may be configured as hardware.
 また上述の第1及び第2の実施の形態においては、データネットワーク2及び制御ネットワーク7を別個のネットワークとする場合について述べたが、本発明はこれに限らず、これらを同一のネットワークにより構成するようにしても良い。 In the above-described first and second embodiments, the case where the data network 2 and the control network 7 are separate networks has been described. However, the present invention is not limited to this, and these are configured by the same network. You may do it.
 さらに上述の第1及び第2の実施の形態においては、充足組合せ選定部43により実行される充足組合せ選定処理(図16)において、ミラー位置候補列挙部42が列挙したミラー位置候補の中から1つのミラー位置を選定する方法として、単純なしらみつぶし探索を行う場合について述べたが、本発明はこれに限らず、遺伝的アルゴリズムなどの公知のメタヒューリステックアルゴリズムを用いて行うようにしても良い。 Furthermore, in the first and second embodiments described above, in the satisfaction combination selection process (FIG. 16) executed by the satisfaction combination selection unit 43, one of the mirror position candidates listed by the mirror position candidate enumeration unit 42. As a method of selecting two mirror positions, the case of performing a simple exhaustive search has been described. However, the present invention is not limited to this, and a known metaheuristic algorithm such as a genetic algorithm may be used. .
 さらに上述の第1及び第2の実施の形態においては、図17について上述したミラーリング状況表示画面60において、データネットワーク2を流れるトラヒックのうち、ミラー位置が設定されたトラヒックのミラーリングの状況と、ミラー位置に設定された各通信装置4におけるそのトラヒックのミラーポートMPにおける通信量とのみをユーザに提示するようにした場合について述べたが、本発明はこれに限らず、例えば、ミラーリング状況表示画面60を用いて、ミラーリングを行っているトラヒックを追加したり、ミラー位置を指定したり、ユーザごとのアクセス制御を行うことができるようにしても良い。 Further, in the first and second embodiments described above, in the mirroring status display screen 60 described above with reference to FIG. 17, among the traffic flowing through the data network 2, the status of mirroring of the traffic whose mirror position is set, and the mirror Although the case where only the traffic amount at the mirror port MP of the traffic in each communication device 4 set at the position is presented to the user has been described, the present invention is not limited to this, for example, the mirroring status display screen 60 May be used to add traffic that is being mirrored, specify a mirror position, and perform access control for each user.
 さらに上述の第1及び第2の実施の形態においては、通信解析情報やネットワークトポロジ情報などの情報を保持する形式としてテーブル形式を適用するようにした場合について述べたが、本発明はこれに限らず、この他種々の形式を広く適用することができる。 Further, in the first and second embodiments described above, the case where the table format is applied as the format for holding information such as communication analysis information and network topology information has been described, but the present invention is not limited to this. However, various other formats can be widely applied.
 さらに上述の第1及び第2の実施の形態においては、本発明のミラー位置選定機能を、システム管理者がデータネットワーク2の管理に用いる管理装置8,94に搭載するようにした場合について述べたが、本発明はこれに限らず、システム管理者がデータネットワーク2の管理に用いる管理装置とは別に専用の装置を設け、かかるミラー位置選定機能を当該専用装置に搭載するようにしても良い。 Furthermore, in the above-described first and second embodiments, the case where the system administrator installs the mirror position selection function of the present invention in the management devices 8 and 94 used for management of the data network 2 has been described. However, the present invention is not limited to this, and a dedicated device may be provided separately from the management device used by the system administrator for managing the data network 2, and such a mirror position selection function may be installed in the dedicated device.
 本発明は、種々の通信システムに広く適用することができる。 The present invention can be widely applied to various communication systems.
 1,90……通信システム、2……データネットワーク、3,3U~3W……電子計算機、4,4A~4D,91……通信装置、7……制御ネットワーク、8,94……管理装置、9……操作元、13……通知情報、17,103……ミラー位置要求、18……ミラー位置応答、21……プロセッサ、31,103……管理プログラム、32……ネットワークトポロジ情報テーブル、33……通信解析情報テーブル群、33A……通信管理テーブル、33B……経路管理テーブル、34,102……ミラー位置要求管理テーブル、35……ミラー位置候補管理テーブル群、35A……候補管理テーブル、35B……候補位置管理テーブル、40……ネットワーク情報解析部、41,101……ミラー位置選定部、42……ミラー位置候補列挙部、43……充足組合せ選定部、60……ミラーリング状況表示画面、92……帯域情報出力機能、93……ミラーポート帯域情報、100……ミラーポート帯域監視部、MP……ミラーポート。 DESCRIPTION OF SYMBOLS 1,90 ... Communication system, 2 ... Data network, 3, 3U-3W ... Electronic computer, 4, 4A-4D, 91 ... Communication apparatus, 7 ... Control network, 8, 94 ... Management apparatus, 9 …… Operator, 13 …… Notification information, 17, 103 …… Mirror position request, 18 …… Mirror position response, 21 …… Processor, 31, 103 …… Management program, 32 …… Network topology information table, 33 Communication analysis information table group 33A Communication management table 33B Route management table 34, 102 Mirror position request management table 35 Mirror position candidate management table group 35A Candidate management table 35B: Candidate position management table, 40: Network information analysis unit, 41, 101: Mirror position selection unit, 42: Mirror position candidate string Parts, 43 ...... sufficiency combination selecting unit, 60 ...... mirroring status display screen, 92 ...... band information output function, 93 ...... mirror port bandwidth information 100 ...... mirror port bandwidth monitor, MP ...... mirror port.

Claims (10)

  1.  複数の通信装置から構成されるネットワークを流れるトラヒックのポートミラーリングを行うべき前記通信装置を選定する情報処理装置において、
     前記通信装置を通過する各前記トラヒックに関する所定のトラヒック情報を各前記通信装置からそれぞれ取得し、取得した各前記トラヒック情報をそれぞれ解析することにより、前記ネットワークを流れる各前記トラヒックがそれぞれ通過する前記通信装置を特定するネットワーク情報解析部と、
     前記ネットワーク情報解析部の解析結果に基づいて、前記ポートミラーリングの対象とすべき前記トラヒックを特定し、特定した当該トラフィックが通過するすべての前記通信装置を特定し、特定した各前記通信装置でポートミラーリングを行う前記通信装置の組合せを列挙するミラー位置候補列挙部と、
     前記ミラー位置候補列挙部により列挙された前記通信装置の組合せの中から、当該組合せを構成する前記通信装置において、当該通信装置の前記ポートミラーリングを行うミラーポートにおいて輻輳が発生しない組合せを選定する充足組合せ選定部と
     を備えることを特徴とする情報処理装置。
    In the information processing apparatus for selecting the communication apparatus that should perform port mirroring of traffic flowing through a network composed of a plurality of communication apparatuses,
    The communication through which each of the traffic flowing through the network passes by acquiring predetermined traffic information regarding each of the traffic passing through the communication device from each of the communication devices, and analyzing each of the acquired traffic information. A network information analysis unit for identifying a device;
    Based on the analysis result of the network information analysis unit, the traffic to be subjected to the port mirroring is specified, all the communication devices through which the specified traffic passes are specified, and the port of each specified communication device is specified. Mirror position candidate enumeration unit that enumerates combinations of the communication devices that perform mirroring;
    Satisfaction of selecting a combination that does not cause congestion in a mirror port that performs the port mirroring of the communication device, in the communication device that constitutes the combination, from the combinations of the communication devices listed by the mirror position candidate enumeration unit. An information processing apparatus comprising: a combination selection unit.
  2.  前記ミラー位置候補列挙部は、
     外部から与えられるミラー位置要求に基づいて、前記ポートミラーリングの対象とすべき前記トラヒックを特定する
     ことを特徴とする請求項1に記載の情報処理装置。
    The mirror position candidate enumeration unit
    2. The information processing apparatus according to claim 1, wherein the traffic to be subjected to the port mirroring is specified based on a mirror position request given from outside.
  3.  前記ミラー位置要求では、前記ポートミラーリングの対象とすべき前記トラヒックの5タプルのうちの少なくとも1つの項目の値が指定され、
     各前記トラヒック情報には、対応する前記通信装置を通過する前記トラヒックごとの前記5タプルの各項目の値がそれぞれ格納され、
     前記ネットワーク情報解析部は、
     各前記トラヒック情報から、前記ネットワークを流れる各前記トラヒックの5タプルの各項目の値をそれぞれ取得し、
     前記ミラー位置候補列挙部は、
     前記5タプルのうちの前記ミラー位置要求において指定された前記項目の値と、前記ネットワーク情報解析部により取得された各前記トラヒックの前記5タプルの各前記項目の値とを比較して、前記ポートミラーリングの対象とすべき前記トラヒックを特定する
     ことを特徴とする請求項2に記載の情報処理装置。
    In the mirror position request, a value of at least one item of the five tuples of the traffic to be subjected to the port mirroring is specified,
    Each of the traffic information stores a value of each item of the 5-tuple for each of the traffic passing through the corresponding communication device,
    The network information analysis unit
    From each of the traffic information, obtain the value of each item of 5 tuples of each of the traffic flowing through the network,
    The mirror position candidate enumeration unit
    The value of the item specified in the mirror position request among the five tuples is compared with the value of each item of the five tuples of the traffic acquired by the network information analysis unit, and the port The information processing apparatus according to claim 2, wherein the traffic to be mirrored is specified.
  4.  前記ミラー位置要求では、
     前記ポートミラーリングを行うべき前記通信装置が必要に応じて指定され、
     前記ミラー位置候補列挙部は、
     前記ポートミラーリングの対象とすべき前記トラヒックが、前記ミラー位置要求において指定された前記通信装置を通過するか否かを判定し、
     当該トラフィックが当該通信装置を通過しない場合には、エラー処理を実行する
     ことを特徴とする請求項2に記載の情報処理装置。
    In the mirror position request,
    The communication device to perform the port mirroring is designated as necessary,
    The mirror position candidate enumeration unit
    Determining whether the traffic to be subject to port mirroring passes through the communication device specified in the mirror position request;
    The information processing apparatus according to claim 2, wherein error processing is executed when the traffic does not pass through the communication apparatus.
  5.  前記ネットワークを構成する各前記通信装置における前記ミラーポートの使用帯域を監視するミラーポート帯域監視部を備え、
     前記ミラーポート帯域監視部は、
     いずれの前記通信装置における前記ミラーポートの使用帯域が当該ミラーポートについて予め設定された閾値を超えた場合に、対象とする前記トラヒックの前記ポートミラーリングを行うべき前記通信装置を再選定するための処理を実行する
     ことを特徴とする請求項1に記載の情報処理装置。
    A mirror port bandwidth monitoring unit for monitoring a bandwidth used by the mirror port in each of the communication devices constituting the network;
    The mirror port bandwidth monitoring unit
    Processing for reselecting the communication device to be subjected to the port mirroring of the target traffic when the use band of the mirror port in any of the communication devices exceeds a preset threshold for the mirror port The information processing apparatus according to claim 1, wherein:
  6.  複数の通信装置から構成されるネットワークを流れるトラヒックのポートミラーリングを行うべき前記通信装置を選定する情報処理装置により実行されるポートミラーリング位置選定方法において、
     情報処理装置が、前記通信装置を通過する各前記トラヒックに関する所定のトラヒック情報を各前記通信装置からそれぞれ取得し、取得した各前記トラヒック情報をそれぞれ解析することにより、前記ネットワークを流れる各前記トラヒックがそれぞれ通過する前記通信装置を特定する第1のステップと、
     情報処理装置が、解析結果に基づいて、前記ポートミラーリングの対象とすべき前記トラヒックを特定し、特定した当該トラフィックが通過するすべての前記通信装置を特定し、特定した各前記通信装置でポートミラーリングを行う前記通信装置の組合せを列挙する第2のステップと、
     情報処理装置が、列挙した前記通信装置の組合せの中から、当該組合せを構成する前記通信装置において、当該通信装置の前記ポートミラーリングを行うミラーポートにおいて輻輳が発生しない組合せを選定する第3のステップと
     を備えることを特徴とするポートミラーリング位置選定方法。
    In the port mirroring position selection method executed by the information processing apparatus that selects the communication apparatus that should perform port mirroring of traffic flowing in a network composed of a plurality of communication apparatuses,
    The information processing device acquires predetermined traffic information related to each traffic passing through the communication device from each communication device, and analyzes each acquired traffic information so that each traffic flowing through the network is A first step of identifying the communication devices that respectively pass;
    The information processing device identifies the traffic to be subjected to the port mirroring based on the analysis result, identifies all the communication devices through which the identified traffic passes, and performs port mirroring on each identified communication device A second step of enumerating combinations of the communication devices that perform:
    A third step in which the information processing apparatus selects, from the enumerated combinations of the communication apparatuses, a combination that does not cause congestion in a mirror port that performs the port mirroring of the communication apparatus in the communication apparatuses that form the combination; A port mirroring position selection method comprising: and.
  7.  前記第2のステップにおいて、前記情報処理装置は、
     外部から与えられるミラー位置要求に基づいて、前記ポートミラーリングの対象とすべき前記トラヒックを特定する
     ことを特徴とする請求項6に記載のポートミラーリング位置選定方法。
    In the second step, the information processing apparatus
    The port mirroring position selection method according to claim 6, wherein the traffic to be subjected to the port mirroring is specified based on a mirror position request given from outside.
  8.  前記ミラー位置要求では、前記ポートミラーリングの対象とすべき前記トラヒックの5タプルのうちの少なくとも1つの項目の値が指定され、
     各前記トラヒック情報には、対応する前記通信装置を通過する前記トラヒックごとの前記5タプルの各項目の値がそれぞれ格納され、
     前記第1のステップにおいて、前記情報処理装置は、
     各前記トラヒック情報から、前記ネットワークを流れる各前記トラヒックの5タプルの各項目の値をそれぞれ取得し、
     前記第2のステップにおいて、前記情報処理装置は、
     前記5タプルのうちの前記ミラー位置要求において指定された前記項目の値と、前記ネットワーク情報解析部により取得された各前記トラヒックの前記5タプルの各前記項目の値とを比較して、前記ポートミラーリングの対象とすべき前記トラヒックを特定する
     ことを特徴とする請求項7に記載のポートミラーリング位置選定方法。
    In the mirror position request, a value of at least one item of the five tuples of the traffic to be subjected to the port mirroring is specified,
    Each of the traffic information stores a value of each item of the 5-tuple for each of the traffic passing through the corresponding communication device,
    In the first step, the information processing apparatus
    From each of the traffic information, obtain the value of each item of 5 tuples of each of the traffic flowing through the network,
    In the second step, the information processing apparatus
    The value of the item specified in the mirror position request among the five tuples is compared with the value of each item of the five tuples of the traffic acquired by the network information analysis unit, and the port The port mirroring position selection method according to claim 7, wherein the traffic to be mirrored is specified.
  9.  前記ミラー位置要求では、
     前記ポートミラーリングを行うべき前記通信装置が必要に応じて指定され、
     前記第2のステップにおいて、前記情報処理装置は、
     前記ポートミラーリングの対象とすべき前記トラヒックが、前記ミラー位置要求において指定された前記通信装置を通過するか否かを判定し、
     当該トラフィックが当該通信装置を通過しない場合には、エラー処理を実行する
     ことを特徴とする請求項7に記載のポートミラーリング位置選定方法。
    In the mirror position request,
    The communication device to perform the port mirroring is designated as necessary,
    In the second step, the information processing apparatus
    Determining whether the traffic to be subject to port mirroring passes through the communication device specified in the mirror position request;
    The port mirroring position selection method according to claim 7, wherein error processing is executed when the traffic does not pass through the communication device.
  10.  前記情報処理装置は、
     前記ネットワークを構成する各前記通信装置における前記ミラーポートの使用帯域を監視し、
     いずれの前記通信装置における前記ミラーポートの使用帯域が当該ミラーポートについて予め設定された閾値を超えた場合に、対象とする前記トラヒックの前記ポートミラーリングを行うべき前記通信装置を再選定するための処理を実行する
     ことを特徴とする請求項6に記載のポートミラーリング位置選定方法。
    The information processing apparatus includes:
    Monitoring the bandwidth of use of the mirror port in each of the communication devices constituting the network;
    Processing for reselecting the communication device to be subjected to the port mirroring of the target traffic when the use band of the mirror port in any of the communication devices exceeds a preset threshold for the mirror port The port mirroring position selection method according to claim 6, wherein:
PCT/JP2015/056983 2015-03-10 2015-03-10 Information processing device and port mirroring position selection method WO2016143066A1 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
PCT/JP2015/056983 WO2016143066A1 (en) 2015-03-10 2015-03-10 Information processing device and port mirroring position selection method

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/JP2015/056983 WO2016143066A1 (en) 2015-03-10 2015-03-10 Information processing device and port mirroring position selection method

Publications (1)

Publication Number Publication Date
WO2016143066A1 true WO2016143066A1 (en) 2016-09-15

Family

ID=56878669

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2015/056983 WO2016143066A1 (en) 2015-03-10 2015-03-10 Information processing device and port mirroring position selection method

Country Status (1)

Country Link
WO (1) WO2016143066A1 (en)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2010245710A (en) * 2009-04-03 2010-10-28 Mitsubishi Electric Corp Network management device, communication system, network management method, and program
WO2011155510A1 (en) * 2010-06-08 2011-12-15 日本電気株式会社 Communication system, control apparatus, packet capture method and program
JP2014216991A (en) * 2013-04-30 2014-11-17 株式会社日立製作所 Analysis server and analysis method

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2010245710A (en) * 2009-04-03 2010-10-28 Mitsubishi Electric Corp Network management device, communication system, network management method, and program
WO2011155510A1 (en) * 2010-06-08 2011-12-15 日本電気株式会社 Communication system, control apparatus, packet capture method and program
JP2014216991A (en) * 2013-04-30 2014-11-17 株式会社日立製作所 Analysis server and analysis method

Similar Documents

Publication Publication Date Title
US11223512B2 (en) Configuring a network
US11689413B2 (en) Configuring system resources for different reference architectures
Kaur et al. A comprehensive survey of service function chain provisioning approaches in SDN and NFV architecture
US11876699B2 (en) Verifying service status
US7949882B2 (en) Storage session management system in storage area network
WO2020168356A2 (en) Systems and methods for cloud migration readiness
EP3432551B1 (en) Splitting network discovery payload based on degree of relationships between nodes
JP2017059991A (en) Network control device, network control method, and network control program
JP5530864B2 (en) Network system, management server, and management method
US11388046B2 (en) Port configuration for cloud migration readiness
US20180343162A1 (en) System management apparatus and system management method
WO2019163912A1 (en) Network system, topology management method, and program
US10313180B2 (en) Systems and methods for managing switching devices in an information handling system
US11520621B2 (en) Computational instance batching and automation orchestration based on resource usage and availability
WO2016143066A1 (en) Information processing device and port mirroring position selection method
US8041671B2 (en) Method and system for providing a homogeneous view of a distributed common information model (CIM) within a heterogeneous virtual system environment
WO2007086129A1 (en) Network management program, network management apparatus, and network management method
Chhikara et al. Towards OpenFlow based software defined networks

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15884558

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15884558

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: JP