WO2023105697A1 - 変換装置、変換方法及び変換プログラム - Google Patents
変換装置、変換方法及び変換プログラム Download PDFInfo
- Publication number
- WO2023105697A1 WO2023105697A1 PCT/JP2021/045222 JP2021045222W WO2023105697A1 WO 2023105697 A1 WO2023105697 A1 WO 2023105697A1 JP 2021045222 W JP2021045222 W JP 2021045222W WO 2023105697 A1 WO2023105697 A1 WO 2023105697A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- conversion
- statistical information
- switching
- cores
- statistical
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/04—Processing captured monitoring data, e.g. for logfile generation
Definitions
- the present invention relates to a conversion device, a conversion method, and a conversion program.
- encapsulated packets For packets obtained from networks using encapsulation technology (hereafter referred to as encapsulated packets), the packet headers (capsule inner/outer) of the input encapsulated packets are analyzed, and statistical information is calculated and statistically typed.
- format conversion technology to generate and transmit xFlow packets.
- Patent Literature 1 Non-Patent Literature 1
- Non-Patent Literature 2 As conventional techniques related to format conversion technology.
- Patent Document 1 for header samples of encapsulated packets, statistical information is calculated based on the inner header inside the capsule, statistical xFlow packets, etc. are generated and transmitted to existing analysis devices.
- FIG. 8 is a diagram for explaining Patent Document 1.
- the conversion device 10 of Patent Document 1 has a separation section 10a, a decapsulation section 10b, and a conversion section 10c. Header samples xFlow of encapsulated packets are input to the converter 10 from various NW devices.
- the conversion unit 10c calculates the statistical information of the input encapsulated packets and sums up the statistical information for each flow until the output conditions are met.
- the converter 10c generates a statistical xFlow packet containing statistical information about the flow satisfying the output condition, and transmits it to an external analysis device.
- the output condition used by the conversion unit 10c is, for example, that the maximum non-communication time has passed since the time when the last encapsulated packet was received for each flow, and that the maximum communication time has passed since the time when the first encapsulated packet was received. is.
- the functions of the conversion unit 10c can be distributed to the conversion cores #1 to #N, and the processes can be executed in parallel. Based on information such as 5tuple, encapsulated packets of the same flow are distributed to the same conversion core.
- FIG. 9 is a diagram for explaining Non-Patent Document 2.
- the conversion device 11 of Non-Patent Document 2 has a protocol analysis unit 11a, a grouping unit 11b, and an information shaping unit 11c.
- the conversion device 11 receives the mirrored encapsulated packet and the header sample xFlow of the encapsulated packet.
- the protocol analysis unit 11a performs protocol analysis on the input encapsulated packet to identify the Inner/Outer/(xFlow) header.
- the grouping unit 11b groups the encapsulated packets based on the Inner/Outer/(xFlow) headers identified by the protocol analysis unit 11a and conditions prepared in advance.
- the information shaping unit 11c acquires the grouping result of the grouping unit 11b, performs processing defined for each group, generates statistical xFlow packets and the like, and transmits them to the analysis devices 12A and 12B.
- the converting unit 10c described with reference to FIG. 8 and the information shaping unit 11c described with reference to FIG. There is a function to generate and send statistical xFlow packets containing Such a function increases the processing load when managing whether or not the output condition is satisfied for each flow.
- Non-Patent Document 3 describes a technique for generating and transmitting statistical xFlow packets using two statistical information cache tables for registering statistical information.
- FIG. 10 is a diagram for explaining Non-Patent Document 3. As shown in FIG. 10 , the conversion device 20 of Non-Patent Document 3 has a conversion core 21 .
- the conversion core 21 has a registration table 22 , an output table 23 , a statistical information generation processing section 24 , a table switching monitoring section 25 and a switching processing section 26 .
- the statistical information cache table A is set in the registration table 22 and the statistical information cache table B is set in the output table 23 .
- the statistical information generation processing unit 24 executes the statistical information generation processing described below based on the header sample of the encapsulated packet.
- the statistical information generation processing unit 24 identifies the flow based on the header sample of the encapsulated packet.
- the statistical information generation processing unit 24 determines whether to newly register or update the statistical information cache table A based on the flow identification result. For example, if the statistical information corresponding to the identified flow has already been registered in the statistical information cache table A, the statistical information generation processing unit 24 determines to perform the update. On the other hand, if the statistical information corresponding to the identified flow is not registered in the statistical information cache table A, the statistical information generation processing unit 24 determines to perform new registration.
- the statistical information generation processing unit 24 calculates statistical information from the header samples in the same manner as the methods described in Patent Document 1, Non-Patent Documents 1 and 2.
- the statistical information generation processing unit 24 updates the statistical information of the corresponding flow registered in the statistical information cache table A when it is determined by the above process that the update is to be performed. On the other hand, the statistical information generation processing unit 24 registers the statistical information for the flow in the statistical information cache table A when determining to perform new registration.
- the statistical information generation processing unit 24 repeatedly executes the above statistical information generation processing.
- the table switching monitoring unit 25 transmits switching instructions to the switching processing unit 26 at predetermined time intervals.
- the switching processing unit 26 Upon receiving a switching instruction from the table switching monitoring unit 25, the switching processing unit 26 executes the switching processing described below.
- the switching processing unit 26 initializes the statistical information cache table B set in the output table 23.
- the switching processing unit 26 switches between the statistical information cache table A of the registration table 22 and the statistical information cache table B of the output table 23 .
- the statistical information cache table B is set in the registration table 22 and the statistical information cache table A is set in the output table 23 .
- the switching processing unit 26 acquires statistical information of all flows from the statistical information cache table A.
- the switching processing unit 26 generates statistical xFlow packets based on the acquired statistical information and transmits them to the analysis device 12C.
- the switching processing unit 26 continuously generates and transmits statistical xFlow packets containing statistical information of all flows held in the output table 23 .
- Non-Patent Document 3 if the functions of Non-Patent Document 3 are provided in the conversion cores #1 to #N and processing is executed in parallel, all the cores At the same time, the statistics information cache table is switched. Then, at the switching timing, statistical xFlow packets generated by all the cores are output to the analysis device in bursts.
- FIG. 11 is a diagram for explaining the problems of the conventional technology.
- the horizontal axis of the graph in FIG. 11 corresponds to time, and the vertical axis indicates the amount of output statistical xFlow packets.
- the statistical information cache table is switched at t1, t2, and t3, and statistical xFlow packets are simultaneously output from conversion cores #1 to #N.
- the present invention has been made in view of the above, and it is an object of the present invention to provide a conversion device, a conversion method, and a conversion program that can significantly reduce the amount of packets simultaneously output from the conversion device.
- a conversion device repeatedly executes a process of transmitting a switching instruction to a plurality of conversion cores and some of the plurality of conversion cores. and a management department.
- Each of the plurality of conversion cores has a storage unit that stores two statistical information cache tables divided into a registration table and an output table; a statistical information generation processing unit that registers information in the statistical information cache table set in the registration table; a switching processor that switches between the statistical information cache table, generates a statistical xFlow packet containing the statistical information registered in the statistical information cache table of the output table, and transmits the generated statistical xFlow packet.
- the amount of packets simultaneously output from the conversion device can be significantly reduced.
- FIG. 1 is a diagram showing the relationship between the table switching time and the amount of packets in the conversion device according to the first embodiment.
- FIG. 2 is a functional block diagram showing the configuration of the conversion device according to the first embodiment.
- FIG. 3 is a flowchart of a processing procedure of a switching management unit according to the first embodiment;
- FIG. 4 is a functional block diagram showing the configuration of the conversion device according to the second embodiment.
- FIG. 5 is a diagram for explaining the timing at which the conversion device according to the third embodiment transmits the switching notification.
- FIG. 6 is a functional block diagram showing the configuration of the conversion device according to the third embodiment.
- FIG. 7 is a diagram illustrating an example of a computer that executes a conversion program;
- FIG. 8 is a diagram for explaining Patent Document 1.
- FIG. FIG. 9 is a diagram for explaining Non-Patent Document 2.
- FIG. 10 is a diagram for explaining Non-Patent Document 3.
- As shown in FIG. FIG. 11 is a diagram for explaining the
- the conversion device deploys the functions of Non-Patent Document 3 to a plurality of conversion cores to perform parallel processing.
- the conversion device manages the timing of switching between the statistical information cache table set in the registration table and the statistical information cache table set in the output table for each conversion core. Execute switching of the statistical information cache table with a time lag.
- switching between the statistical information cache table set in the registration table and the statistical information cache table set in the output table is referred to as "table switching".
- FIG. 1 is a diagram showing the relationship between the table switching time of the conversion device according to the first embodiment and the amount of packets.
- the horizontal axis of the graph in FIG. 1 corresponds to time, and the vertical axis indicates the amount of output statistical xFlow packets.
- the transform core #1 outputs statistical xFlow packets at t1, t4, and t7.
- transform core #2 outputs statistical xFlow packets.
- transform core #N outputs statistical xFlow packets.
- N is the total number of transform cores.
- FIG. 2 is a functional block diagram showing the configuration of the conversion device according to the first embodiment.
- this conversion device 100 has a packet allocation section 110, a switching management section 120, and conversion cores #1 to #N.
- the conversion device 100 receives the mirrored encapsulated packet and the header sample xFlow of the encapsulated packet.
- the packet distribution unit 110 distributes the header samples of the encapsulated packet to the conversion cores #1 to #N based on the 5tuple of the inner/outer header of the encapsulated packet.
- packet distribution section 110 distributes header samples to conversion cores #1 to #N, for example, header samples for which the pair of the destination/source address of the Inner header and the destination/source address of the Outer header are the same. are distributed to the same conversion core.
- the packet distribution unit 110 has a load balancer function, and distributes header samples to the conversion cores #1 to #N so that loads are not concentrated on the same conversion core.
- Header samples are input to the packet distribution unit 110 .
- the protocol analysis unit 11a and the grouping unit 11b perform processing on the encapsulated packet and the header sample xFlow of the encapsulated packet, and the processing result is is input to the packet sorting unit 110 .
- the switching management unit 120 transmits a switching notification in order of the conversion cores #1 to #N every switching notification transmission time interval (T). Conversion cores #1 to #N receive a switching notification every N ⁇ T time.
- Conversion core #1 will be explained.
- the description of conversion cores #2 to #N is the same as that of conversion core #1.
- Conversion core # 1 has a registration table 50 , an output table 51 , a statistical information generation processing section 52 and a switching processing section 53 .
- the statistical information cache table A is set in the registration table 50 and the statistical information cache table B is set in the output table 51 .
- the statistical information generation processing unit 52 executes the statistical information generation processing described below based on the header sample of the encapsulated packet.
- the statistical information generation processing unit 52 identifies flows and groups based on header samples of encapsulated packets. A flow is identified based on 5tuple, etc. of the Inner/Outer header of the encapsulated packet. Note that the statistical information generation processing unit 52 performs only flow identification and does not perform group identification when a group identifier is not assigned.
- the grouping unit 11b described with reference to FIG. 9 groups encapsulated packets based on Inner/Outer/(xFlow) headers identified by the protocol analysis unit 11a and conditions prepared in advance, and divides the encapsulated packets into Assign a group identifier.
- the statistical information generation processing unit 52 identifies groups of encapsulated packets based on group identifiers assigned to the encapsulated packets.
- the statistical information generation processing unit 52 determines whether to newly register or update the statistical information cache table A based on the flow and group identification results. For example, if the statistical information corresponding to the identified flow has already been registered in the statistical information cache table A, the statistical information generation processing unit 52 determines to perform the update. On the other hand, if the statistical information corresponding to the identified flow is not registered in the statistical information cache table A, the statistical information generation processing unit 52 determines to perform new registration.
- the statistical information generation processing unit 52 calculates statistical information from the header samples in the same manner as the methods described in Non-Patent Documents 1 and 2.
- the statistical information is information such as the number of encapsulated packets and the amount of data.
- the statistical information generation processing unit 52 updates the statistical information of the corresponding flow registered in the statistical information cache table A when it is determined by the above process that the update is to be performed. On the other hand, the statistical information generation processing unit 52 registers the statistical information for the flow in the statistical information cache table A when determining to perform new registration.
- the statistical information generation processing unit 52 repeatedly executes the above statistical information generation processing.
- the switching processing section 53 Upon receiving a switching instruction from the switching management section 120, the switching processing section 53 executes switching processing described below.
- the switching processing unit 53 initializes the statistical information cache table B set in the output table 51 .
- the switching processing unit 53 switches between the statistical information cache table A of the registration table 50 and the statistical information cache table B of the output table 51 .
- the statistical information cache table B is set in the registration table 50 and the statistical information cache table A is set in the output table 51 .
- the switching processing unit 53 acquires statistical information for all flows from the statistical information cache table A, generates a statistical xFlow packet containing the acquired statistical information, and transmits it to an external analysis device.
- the switching processing unit 53 of each of the conversion cores #1 to #N has a function of generating a statistical xFlow packet including statistical information and transmitting it to an external analysis device.
- a common packet generation unit is arranged outside the conversion cores #1 to #N, and the packet generation unit acquires statistical information from the conversion cores #1 to #N and generates statistical xFlow packets. may be sent to an external analysis device.
- FIG. 3 is a flowchart of a processing procedure of a switching management unit according to the first embodiment;
- n indicates a core number that identifies a conversion core.
- step S105 Yes
- conversion apparatus 100 When executing parallel processing of conversion cores #1 to #N, conversion apparatus 100 transmits switching notifications in order of conversion cores #1 to #N at each switching notification transmission time interval (T). As a result, statistical xFlow packets are not simultaneously output based on the statistical information generated by a plurality of conversion cores #1 to #N, so the amount of packets output simultaneously from conversion device 100 can be reduced.
- the conversion device transmits a switching request from the conversion core to the switching management unit when traffic increases rapidly and the number of flows registered in the registration table exceeds the threshold.
- the switching management unit changes the switching notification transmission time interval (T).
- FIG. 4 is a functional block diagram showing the configuration of the conversion device according to the second embodiment. As shown in FIG. 4, this conversion device 200 has a packet allocation section 110, a switching management section 210, and conversion cores #1 to #N. The conversion device 200 receives the mirrored encapsulated packet and the header sample xFlow of the encapsulated packet.
- the description of the packet distribution unit 110 is the same as the content described with reference to FIG.
- the switching management unit 210 first transmits a switching notification in order of the conversion cores #1 to #N every switching notification transmission time interval (T).
- the switching management unit 210 sets the notification level to "0" when no switching request is received from any conversion core.
- the switching management unit 210 calculates the switching notification transmission time interval (T) based on the equation (1) while the notification level is "0".
- TA indicates the cycle for transmitting switching notifications.
- N indicates the number of conversion cores #1 to #N.
- the switching management unit 210 When the switching management unit 210 receives a switching request from any one of the conversion cores #1 to #N, it updates the notification level to "1". The switching management unit 210 calculates the switching notification transmission time interval (T) based on the equation (2) while the notification level is "1". In equation (2), the value of ⁇ is set in the range of 0 ⁇ 1.
- the switching management unit 210 updates the current notification level to "0" when a predetermined time has passed since the last switching request was received.
- Conversion core #1 will be explained.
- the description of conversion cores #2 to #N is the same as that of conversion core #1.
- Conversion core # 1 has a registration table 50 , an output table 51 , a statistical information generation processing section 52 , a switching processing section 53 and a notification section 54 .
- the notification unit 54 receives count information from the statistical information generation processing unit 52 .
- the statistical information generation processing unit 52 counts the number of flows registered in the statistical information cache table (initially, the statistical information cache table A) set in the registration table 50, and transmits the count information to the notification unit 54. .
- the notification unit 54 transmits a switching request to the switching management unit 210 when the number of flows exceeds the threshold (NF).
- NF is set to 90% of the upper limit of the number of flows that can be registered in the registration table 50 .
- the statistical information generation processing unit 52 sets the count information of the number of flows registered in the registration table 50 to 0 at the time of table switching.
- the conversion device 200 transmits a switching request from the conversion core to the switching management unit 210 .
- switching management section 210 changes the switching notification transmission time interval (T) based on equation (2), thereby shortening the cycle of transmitting the switching request to conversion cores #1 to #N. .
- T switching notification transmission time interval
- the conversion device transmits a switching request from the conversion core to the switching management unit when the number of flows registered in the registration table exceeds the threshold due to a rapid increase in traffic.
- the switching request includes a core number that identifies the conversion core that is the source of the switching request.
- the switching management unit transmits a switching notification to the conversion cores #1 to #N in order at each switching notification transmission time interval (T), and to the conversion cores that have transmitted the switching request. to send a switching notification.
- the switching management unit transmits the switching notification after a predetermined guard time or longer so that the outputs of the statistical xFlow packets from the conversion cores #1 to #N do not overlap.
- FIG. 5 is a diagram for explaining the timing at which the conversion device according to the third embodiment transmits the switching notification.
- the switching manager of the conversion device transmits a switching notification to conversion core #1 at time t1.
- the switching management unit receives a switching request from conversion core #3 at time t2 before the switching notification transmission time interval (T) elapses from time t1, it transmits a switching notification to conversion core #3. do.
- the switching management unit transmits a switching notification to conversion core #2 at time t3 after the switching notification transmission time interval (T) has elapsed from time t1.
- the switching management unit transmits a switching notification to conversion core #3 at time t4 after the switching notification transmission time interval (T) has elapsed from time t3.
- the switching management unit sets a guard time before and after the time when the switching notification is sent, and transmits the switching notification after a period equal to or longer than the guard time. For example, the switching management unit transmits a switching notification to conversion core #1 at time t1, and then receives a switching request from conversion core #3 at time t3. transmits a switching notification to the conversion core #3 after the guard time has passed.
- the switching management unit similarly sets guard times for times t2, t3, and t4 in FIG. Then, immediately after the guard time has elapsed, a switching notification is transmitted to the conversion core that is the transmission source of the switching request.
- FIG. 6 is a functional block diagram showing the configuration of the conversion device according to the third embodiment. As shown in FIG. 6, this conversion device 300 has a packet allocation section 110, a switching management section 310, and conversion cores #1 to #N. The conversion device 300 receives the mirrored encapsulated packet and the header sample xFlow of the encapsulated packet.
- the description of the packet distribution unit 110 is the same as the content described with reference to FIG.
- Switching management section 310 transmits switching notifications to conversion cores #1 to #N in order at every switching notification transmission time interval (T), and transmits switching notifications to conversion cores that have transmitted switching requests. .
- the switching management unit 311 transmits the switching notification after a predetermined guard time or longer so that the outputs of the statistical xFlow packets from the conversion cores #1 to #N do not overlap.
- the explanation regarding the switching management unit 310 is the same as the explanation given in FIG.
- Conversion apparatus 300 transmits switching notifications to conversion cores #1 to #N in order at every switching notification transmission time interval (T), and also transmits switching notifications to conversion cores that have transmitted switching requests. Conversion apparatus 300 transmits a switch notification after a predetermined guard time or longer so that the outputs of statistical xFlow packets from conversion cores #1 to #N do not overlap. As a result, it is possible to avoid a situation in which statistical information overflows from the registration table 50 of a specific conversion core due to a rapid increase in traffic.
- FIG. 7 is a diagram illustrating an example of a computer that executes a conversion program.
- Computer 1000 has, for example, memory 1010 , CPU 1020 , hard disk drive interface 1030 , disk drive interface 1040 , serial port interface 1050 , video adapter 1060 and network interface 1070 . These units are connected by a bus 1080 .
- the memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM 1012 .
- the ROM 1011 stores a boot program such as BIOS (Basic Input Output System).
- BIOS Basic Input Output System
- Hard disk drive interface 1030 is connected to hard disk drive 1031 .
- Disk drive interface 1040 is connected to disk drive 1041 .
- a removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1041, for example.
- a mouse 1051 and a keyboard 1052 are connected to the serial port interface 1050, for example.
- a display 1061 is connected to the video adapter 1060 .
- the hard disk drive 1031 stores an OS 1091, application programs 1092, program modules 1093 and program data 1094, for example. Each piece of information described in the above embodiment is stored in the hard disk drive 1031 or memory 1010, for example.
- the conversion program is stored in the hard disk drive 1031 as a program module 1093 in which commands to be executed by the computer 1000 are written, for example.
- the hard disk drive 1031 stores a program module 1093 in which each process for executing the packet distribution unit 110, the switching management unit 120, and the conversion cores #1 to #N described in the above embodiment is described. .
- Data used for information processing by the conversion program is stored as program data 1094 in the hard disk drive 1031, for example. Then, the CPU 1020 reads out the program module 1093 and the program data 1094 stored in the hard disk drive 1031 to the RAM 1012 as necessary, and executes each procedure described above.
- program module 1093 and program data 1094 related to the conversion program are not limited to being stored in the hard disk drive 1031.
- they are stored in a removable storage medium and read by the CPU 1020 via the disk drive 1041 or the like.
- the program module 1093 and program data 1094 related to the conversion program are stored in another computer connected via a network such as LAN or WAN (Wide Area Network), and are read out by the CPU 1020 via the network interface 1070.
Landscapes
- Engineering & Computer Science (AREA)
- Data Mining & Analysis (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
変換装置(100)は、複数の変換コアを備える。変換装置(100)は、複数の変換コアのうち、一部の変換コアに対して切替指示を送信する処理を繰り返し実行する切替管理部(120)を備える。
Description
本発明は、変換装置、変換方法及び変換プログラムに関する。
カプセル化技術が用いられるネットワークから得たパケット(以下、カプセル化パケットと表記)について、入力されたカプセル化パケットのパケットヘッダ(カプセルのInner/Outer)を解析し、統計情報を算出して統計型xFlowパケットを生成・送信するフォーマット変換技術がある。たとえば、フォーマット変換技術に関する従来技術として、特許文献1、非特許文献1、非特許文献2がある。
特許文献1(非特許文献1)では、カプセル化パケットのヘッダサンプルについて、カプセル内側のInnerヘッダに基づいて統計情報を算出し、統計型xFlowパケット等を生成して既存の分析装置へ送信する。
図8は、特許文献1を説明するための図である。図8に示すように、特許文献1の変換装置10は、分離部10a、デカプセル部10b、変換部10cを有する。変換装置10には、各種NW装置から、カプセル化パケットのヘッダサンプルxFlowが入力される。
変換部10cは、入力されたカプセル化パケットの統計情報を算出し、出力条件を満たすまで、フロー毎に統計情報を合算する。変換部10cは、出力条件を満たしたフローについての統計情報を含む統計型xFlowパケットを生成し、外部の分析装置へ送信する。
変換部10cが用いる出力条件は、たとえば、各フローについて最後にカプセル化パケットを受信した時間から最大無通信時間が経過したこと、最初にカプセル化パケットを受信した時間から最大通信時間が経過したことである。
なお、変換部10cの機能は、変換コア♯1~♯Nに分散して配備され、処理が並列に実行することもできる。5tupleなどの情報によって、同一フローのカプセル化パケットは、同一の変換コアに振り分けられる。
続いて、非特許文献2について説明する。図9は、非特許文献2を説明するための図である。非特許文献2の変換装置11は、プロトコル解析部11a、グルーピング部11b、情報整形部11cを有する。変換装置11には、ミラーリングされたカプセル化パケットと、カプセル化パケットのヘッダサンプルxFlowとが入力される。
プロトコル解析部11aは、入力されたカプセル化パケットのプロトコル解析を行ってInner/Outer/(xFlow)ヘッダを識別する。
グルーピング部11bは、プロトコル解析部11aによって識別されたInner/Outer/(xFlow)ヘッダと、事前に用意された条件に基づいてカプセル化パケットをグルーピングする。
情報整形部11cは、グルーピング部11bのグルーピング結果を取得し、グループ毎に定義された処理を実施し、統計型xFlowパケット等を生成して分析装置12A,12Bへ送信する。
ここで、図8で説明した変換部10cや、図9で説明した情報整形部11cには、入力されたカプセル化パケットの統計情報をフロー毎に合算し、出力条件を満たしたフローの統計情報を格納した統計型xFlowパケットを生成して送信する機能がある。かかる機能は、出力条件を満たすか否かをフロー毎に管理する場合、処理負荷が大きくなってしまう。
上記の機能に関して、非特許文献3では、統計情報を登録する統計情報キャッシュテーブルを二つ用いて、統計型xFlowパケットを生成して送信する技術が記載されている。
図10は、非特許文献3を説明するための図である。図10に示すように、非特許文献3の変換装置20は、変換コア21を有する。
変換コア21は、登録用テーブル22、出力用テーブル23、統計情報生成処理部24、テーブル切替監視部25、切替処理部26を有する。最初は、登録用テーブル22に、統計情報キャッシュテーブルAが設定され、出力用テーブル23に、統計情報キャッシュテーブルBが設定される。
統計情報生成処理部24は、カプセル化パケットのヘッダサンプルを基にして、以下に説明する統計情報生成処理を実行する。
統計情報生成処理部24は、カプセル化パケットのヘッダサンプルを基にして、フローを識別する。
統計情報生成処理部24は、フローの識別結果を基にして、統計情報キャッシュテーブルAに、新規登録を行うか、更新を行うかの判定を行う。たとえば、統計情報生成処理部24は、識別したフローに対応する統計情報が、統計情報キャッシュテーブルAに既に登録されている場合には、更新を行うと判定する。一方、統計情報生成処理部24は、識別したフローに対応する統計情報が、統計情報キャッシュテーブルAに登録されていない場合には、新規登録を行うと判定する。
統計情報生成処理部24は、特許文献1、非特許文献1、2に記載された方法と同様にして、ヘッダサンプルから、統計情報を算出する。
統計情報生成処理部24は、上記の処理によって、更新を行うと判定している場合には、統計情報キャッシュテーブルAに登録された、該当するフローの統計情報を更新する。一方、統計情報生成処理部24は、新規登録を行うと判定している場合には、フローに対する統計情報を、統計情報キャッシュテーブルAに登録する。
統計情報生成処理部24は、上記の統計情報生成処理を繰り返し実行する。
テーブル切替監視部25は、所定の時間間隔で、切替指示を切替処理部26に送信する。
切替処理部26は、テーブル切替監視部25から切替指示を取得した場合に、以下に説明する切替処理を実行する。
切替処理部26は、出力用テーブル23に設定された統計情報キャッシュテーブルBを初期化する。
切替処理部26は、登録用テーブル22の統計情報キャッシュテーブルAと、出力用テーブル23の統計情報キャッシュテーブルBとを切り替える。これによって、登録用テーブル22には、統計情報キャッシュテーブルBが設定され、出力用テーブル23には、統計情報キャッシュテーブルAが設定される。
切替処理部26は、統計情報キャッシュテーブルAから全フローの統計情報を取得する。切替処理部26は、取得した統計情報を基にして、統計型xFlowパケットを生成し、分析装置12Cに送信する。
三好、他「xFlowパケット内のヘッダサンプルフォーマット変換方式」(電子情報通信学会 2020年3月 総合大会 B-6-36)
西岡、他「複数事業者を収容するキャリア網のトラヒックを可視化するFast xFlow Proxyの提案」(電子情報通信学会 2021年3月 総合大会 B-6-33)
森岡、他「フォーマット変換システムにおけるフロー統計情報送出方式の検討」(電子情報通信学会 2021年3月 総合大会 B-6-73)
上記の非特許文献3の技術は、切替処理部26によって、出力用テーブル23に保持されている全フローの統計情報を含む統計型xFlowパケットを連続して生成し、送信する。
ここで、特許文献1の技術を適用した変換コア♯1~♯Nのように、非特許文献3の機能を変換コア♯1~♯Nに配備して処理を並行に実行すると、全てのコアで同時に統計情報キャッシュテーブルが切替えられる。そうすると、切替えられたタイミングで、全てのコアで生成された統計型xFlowパケットがバーストで分析装置に出力されてしまう。
図11は、従来技術の課題を説明するための図である。図11のグラフの横軸は時間に対応し、縦軸は出力される統計型xFlowパケットのパケット量を示す。図11に示す例では、t1、t2、t3において、統計情報キャッシュテーブルの切替が行われてり、変換コア♯1~♯Nから、統計型xFlowパケットが同時に出力されている。
図11のように、統計型xFlowパケットが同時に分析装置へ出力されると、分析装置の受信容量を超えてしまい、パケットロスが生じる。パケットロスによって、統計情報が不足し、分析装置の分析精度が低下する。
本発明は、上記に鑑みてなされたものであって、変換装置から同時に出力されるパケット量を大幅に削減することができる変換装置、変換方法及び変換プログラムを提供することを目的とする。
上述した課題を解決し、目的を達成するために、変換装置は、複数の変換コアと、複数の変換コアのうち、一部の変換コアに対して切替指示を送信する処理を繰り返し実行する切替管理部とを備える。複数の変換コアはそれぞれ、二つの統計情報キャッシュテーブルを、登録用テーブルと出力用テーブルに分けて記憶する記憶部と、カプセル化パケットの統計情報をフロー毎に生成し、生成したフロー毎の統計情報を、登録用テーブルに設定された統計情報キャッシュテーブルに登録する統計情報生成処理部と、切替管理部から切替指示を受信した場合に、登録用テーブルの統計情報キャッシュテーブルと、出力用テーブルの統計情報キャッシュテーブルとを切替え、出力用テーブルの統計情報キャッシュテーブルに登録された統計情報を含む統計型xFlowパケットを生成し、生成した統計型xFlowパケットを送信する切替処理部とを備える。
本発明によれば、変換装置から同時に出力されるパケット量を大幅に削減することができる。
以下に、本願の開示する変換装置、変換方法及び変換プログラムの実施例を図面に基づいて詳細に説明する。なお、この実施例によりこの発明が限定されるものではない。
本実施例1に係る変換装置の処理の概要について説明する。変換装置は、非特許文献3の機能を複数の変換コアに配備して並列処理を実行する。変換装置は、各変換コアに対して、登録用テーブルに設定された統計情報キャッシュテーブルおよび出力用テーブルに設定された統計情報キャッシュテーブルを切替えるタイミングを、装置全体で管理し、各変換コアの各統計情報キャッシュテーブルの切替を時間差をつけて実行する。以下の説明では、登録用テーブルに設定された統計情報キャッシュテーブルおよび出力用テーブルに設定された統計情報キャッシュテーブルを切替えることを「テーブル切替」と表記する。
図1は、本実施例1に係る変換装置のテーブル切替の時間とパケット量との関係を示す図である。図1のグラフの横軸は時間に対応し、縦軸は出力される統計型xFlowパケットのパケット量を示す。たとえば、図1に示す例では、t1、t4、t7において、変換コア♯1から、統計型xFlowパケットが出力される。t2、t5、t8において、変換コア♯2から、統計型xFlowパケットが出力される。t3、t6、t9において、変換コア♯Nから、統計型xFlowパケットが出力される。Nは、変換コアの総数である。
図1に示すように、複数の変換コア♯1~♯Nで生成された統計型xFlowパケットが同時に出力されないため、変換装置から同時に出力されるパケット量を削減することができる。
次に、本実施例1に係る変換装置の構成例について説明する。図2は、本実施例1に係る変換装置の構成を示す機能ブロック図である。図2に示すように、この変換装置100は、パケット振分部110と、切替管理部120と、変換コア♯1~♯Nを有する。変換装置100は、ミラーリングされたカプセル化パケットと、カプセル化パケットのヘッダサンプルxFlowとが入力される。
パケット振分部110は、カプセル化パケットのInner/Outerヘッダの5tuple等を基にして、カプセル化パケットのヘッダサンプルを、変換コア♯1~♯Nに振り分ける。パケット振分部110は、ヘッダサンプルを変換コア♯1~♯Nに振り分ける際に、たとえばInnerヘッダの宛先・送信元アドレスと、Outerヘッダの宛先・送信元アドレスとの組が同一となるヘッダサンプルが、同一の変換コアに振り分けられるように、制御する。
パケット振分部110は、ロードバランサの機能を有し、同一の変換コアに負荷が集中しないように、ヘッダサンプルを、変換コア♯1~♯Nに振り分ける。
ここで、本発明を、図8で説明した変換装置10に実装する場合には、カプセル化パケットのヘッダサンプルxFlowに対して、分離部10aおよびデカプセル部10bが処理を実行し、処理結果となるヘッダサンプルが、パケット振分部110に入力される。
本発明を、図9で説明した変換装置11に実装する場合には、カプセル化パケットとカプセル化パケットのヘッダサンプルxFlowに対して、プロトコル解析部11aおよびグルーピング部11bが処理を実行し、処理結果となるヘッダサンプルが、パケット振分部110に入力される。
切替管理部120は、切替通知送信時間間隔(T)毎に、変換コア♯1~♯Nの順に、切替通知を送信する。変換コア♯1~♯Nは、N×T時間毎に、切替通知を受信する。
変換コア♯1について説明する。変換コア♯2~♯Nに関する説明は、変換コア♯1と同様である。変換コア♯1は、登録用テーブル50、出力用テーブル51、統計情報生成処理部52、切替処理部53を有する。最初は、登録用テーブル50に、統計情報キャッシュテーブルAが設定され、出力用テーブル51に、統計情報キャッシュテーブルBが設定される。
統計情報生成処理部52は、カプセル化パケットのヘッダサンプルを基にして、以下に説明する統計情報生成処理を実行する。
統計情報生成処理部52は、カプセル化パケットのヘッダサンプルを基にして、フローおよびグループを識別する。フローは、カプセル化パケットのInner/Outerヘッダの5tuple等を基に識別される。なお、統計情報生成処理部52は、グループ識別子が付与されていない場合には、フロー識別のみを実行し、グループ識別を実行しない。
グループについて説明する。たとえば、図9で説明したグルーピング部11bは、プロトコル解析部11aによって識別されたInner/Outer/(xFlow)ヘッダと、事前に用意された条件に基づいてカプセル化パケットをグルーピングし、カプセル化パケットにグループ識別子を付与する。統計情報生成処理部52は、カプセル化パケットに付与されたグループ識別子を基にして、カプセル化パケットのグループを識別する。
統計情報生成処理部52は、フローおよびグループの識別結果を基にして、統計情報キャッシュテーブルAに、新規登録を行うか、更新を行うかの判定を行う。たとえば、統計情報生成処理部52は、識別したフローに対応する統計情報が、統計情報キャッシュテーブルAに既に登録されている場合には、更新を行うと判定する。一方、統計情報生成処理部52は、識別したフローに対応する統計情報が、統計情報キャッシュテーブルAに登録されていない場合には、新規登録を行うと判定する。
統計情報生成処理部52は、非特許文献1、2に記載された方法と同様にして、ヘッダサンプルから、統計情報を算出する。統計情報は、カプセル化パケットの数や、データ量等の情報である。
統計情報生成処理部52は、上記の処理によって、更新を行うと判定している場合には、統計情報キャッシュテーブルAに登録された、該当するフローの統計情報を更新する。一方、統計情報生成処理部52は、新規登録を行うと判定している場合には、フローに対する統計情報を、統計情報キャッシュテーブルAに登録する。
統計情報生成処理部52は、上記の統計情報生成処理を繰り返し実行する。
切替処理部53は、切替管理部120から切替指示を受信した場合に、以下に説明する切替処理を実行する。
切替処理部53は、出力用テーブル51に設定された統計情報キャッシュテーブルBを初期化する。
切替処理部53は、登録用テーブル50の統計情報キャッシュテーブルAと、出力用テーブル51の統計情報キャッシュテーブルBとを切り替える。これによって、登録用テーブル50には、統計情報キャッシュテーブルBが設定され、出力用テーブル51には、統計情報キャッシュテーブルAが設定される。
切替処理部53は、統計情報キャッシュテーブルAから全フローについて統計情報を取得し、取得した統計情報を含む統計型xFlowパケットを生成し、外部の分析装置に送信する。
ところで、図2に示した例では、変換コア♯1~♯Nの各切替処理部53が、統計情報を含む統計型xFlowパケットを生成し、外部の分析装置に送信する機能を有する場合について説明したが、これに限定されるものではない。たとえば、変換コア♯1~♯Nの外部に、共通のパケット生成部を配置し、かかるパケット生成部が、変換コア♯1~♯Nから、統計情報を取得し、統計型xFlowパケットを生成して、外部の分析装置に送信してもよい。
次に、本実施例1に係る切替管理部120の処理手順の一例について説明する。図3は、本実施例1に係る切替管理部の処理手順を示すフローチャートである。図3において、tは、t=0からの経過時間を示す。n(n=1~N)は、変換コアを識別するコア番号を示す。図3に示すように、変換装置100の切替管理部120は、n=1に設定する(ステップS101)。
切替管理部120は、t=0に設定し、経過時間tの監視を開始する(ステップS102)。切替管理部120は、t≧Tとならない場合には(ステップS103,No)、再度、ステップS103に移行する。一方、切替管理部120は、t≧Tとなる場合には(ステップS103,Yes)、変換コア♯nへ切替通知を送信する(ステップS104)。
切替管理部120は、n<Nとなる場合には(ステップS105,Yes)、n=n+1に設定し(ステップS106)、ステップS102に移行する。一方、切替管理部120は、n<Nとならない場合には(ステップS105,No)、n=1に設置し(ステップS107)、ステップS102に移行する。
次に、本実施例1に係る変換装置100の効果について説明する。変換装置100は、変換コア♯1~♯Nの並列処理を実行させる場合に、切替通知送信時間間隔(T)毎に、変換コア♯1~♯Nの順に、切替通知を送信する。これによって、複数の変換コア♯1~♯Nで生成された統計情報に基づいて、統計型xFlowパケットが同時に出力されないため、変換装置100から同時に出力されるパケット量を削減することができる。
本実施例2に係る変換装置は、トラヒックが急増して登録用テーブルに登録されたフロー数が閾値を超えた場合に、変換コアから切替管理部へ、切替要求を送信する。切替管理部は、切替要求を受信すると、切替通知送信時間間隔(T)を変更する。
図4は、本実施例2に係る変換装置の構成を示す機能ブロック図である。図4に示すように、この変換装置200は、パケット振分部110と、切替管理部210と、変換コア♯1~♯Nを有する。変換装置200は、ミラーリングされたカプセル化パケットと、カプセル化パケットのヘッダサンプルxFlowとが入力される。
パケット振分部110に関する説明は、図2で説明した内容と同様である。
切替管理部210は、最初は、切替通知送信時間間隔(T)毎に、変換コア♯1~♯Nの順に、切替通知を送信する。切替管理部210は、いずれの変換コアからも切替要求を受信していない場合、通知レベルを「0」に設定する。切替管理部210は、通知レベル「0」の間は、式(1)に基づいて、切替通知送信時間間隔(T)を算出する。式(1)において、TAは、切替通知を送信する周期を示す。Nは、変換コア♯1~♯Nの数を示す。
T=TA/N・・・(1)
切替管理部210は、変換コア♯1~♯Nのうち、何れかの変換コアから、切替要求を受信すると、通知レベルを「1」に更新する。切替管理部210は、通知レベル「1」の間は、式(2)に基づいて、切替通知送信時間間隔(T)を算出する。式(2)において、αの値は、0<α<1の範囲に設定される。
T=α×TA/N・・・(2)
切替管理部210は、最後に切替要求を受信してから、所定時間経過した場合に、現在の通知レベルを「0」に更新する。
変換コア♯1について説明する。変換コア♯2~♯Nに関する説明は、変換コア♯1と同様である。変換コア♯1は、登録用テーブル50、出力用テーブル51、統計情報生成処理部52、切替処理部53、通知部54を有する。
登録用テーブル50、出力用テーブル51、統計情報生成処理部52、切替処理部53に関する説明は、図2で説明した内容と同様である。
通知部54は、統計情報生成処理部52から、カウント情報を受信する。統計情報生成処理部52は、登録用テーブル50に設定された統計情報キャッシュテーブル(最初は、統計情報キャッシュテーブルA)に登録されたフロー数をカウントし、カウント情報として、通知部54に送信する。通知部54は、カウント情報に基づき、フロー数が閾値(NF)を超過した場合に、切替要求を、切替管理部210に送信する。たとえば、NFには、登録用テーブル50に登録可能なフロー数の上限の90%の値が設定される。なお、統計情報生成処理部52は、テーブル切替時において、登録用テーブル50に登録したフロー数のカウント情報はテーブル切替時において0に設定される。
次に、本実施例2に係る変換装置200の効果について説明する。変換装置200は、登録用テーブル50に登録されたフロー数が閾値を超えた場合に、変換コアから切替管理部210へ、切替要求を送信する。切替管理部210は、切替要求を受信すると、切替通知送信時間間隔(T)を式(2)に基づいて変更することで、変換コア♯1~♯Nに切替要求を送信する周期を短縮する。これによって、トラヒックが急増した場合でも、登録用テーブル50から統計情報が溢れてしまう状況を回避することができる。
本実施例3に係る変換装置は、トラヒックが急増して登録用テーブルに登録されたフロー数が閾値を超えた場合に、変換コアから切替管理部へ、切替要求を送信する。切替要求には、切替要求元の変換コアを識別するコア番号が含まれる。
切替管理部は、実施例1と同様にして、切替通知送信時間間隔(T)毎に、変換コア♯1~♯Nの順に、切替通知を送信しつつ、切替要求を送信した変換コアに対して、切替通知を送信する。切替管理部は、変換コア♯1~♯Nからの統計型xFlowパケットの出力が重ならないように、所定のガードタイム以上の時間をあけて、切替通知を送信する。
図5は、本実施例3に係る変換装置が切替通知を送信するタイミングを説明するための図である。変換装置の切替管理部は、時間t1において、切替通知を変換コア♯1へ送信する。切替管理部は、時間t1から、切替通知送信時間間隔(T)経過する前の時間t2において、変換コア♯3から、切替要求を受信した場合には、切替通知を、変換コア♯3へ送信する。
切替管理部は、時間t1から、切替通知送信時間間隔(T)経過した時間t3において、切替通知を変換コア♯2へ送信する。切替管理部は、時間t3から、切替通知送信時間間隔(T)経過した時間t4において、切替通知を変換コア♯3へ送信する。
ここで、切替管理部は、切替通知を行った時間の前後にガードタイムを設定し、ガードタイム以上の時間をあけて、切替通知を送信する。たとえば、切替管理部は、時間t1において、切替通知を変換コア♯1へ送信した後、変換コア♯3から切替要求を受信した時間t3が、時間t1を基準とするガードタイムに含まれる場合には、かかるガードタイムを経過した後に、変換コア♯3へ、切替通知を送信する。
切替管理部は、図5において、時刻t2、t3、t4についても、同様にして、ガードタイムを設定し、上記の説明と同様にして、ガードタイムを経過する前に、切替要求を受信した場合に、ガードタイムを経過した直後に、切替要求の送信元となる変換コアへ、切替通知を送信する。
図6は、本実施例3に係る変換装置の構成を示す機能ブロック図である。図6に示すように、この変換装置300は、パケット振分部110と、切替管理部310と、変換コア♯1~♯Nを有する。変換装置300は、ミラーリングされたカプセル化パケットと、カプセル化パケットのヘッダサンプルxFlowとが入力される。
パケット振分部110に関する説明は、図2で説明した内容と同様である。
切替管理部310は、切替通知送信時間間隔(T)毎に、変換コア♯1~♯Nの順に、切替通知を送信しつつ、切替要求を送信した変換コアに対して、切替通知を送信する。切替管理部311は、変換コア♯1~♯Nからの統計型xFlowパケットの出力が重ならないように、所定のガードタイム以上の時間をあけて、切替通知を送信する。切替管理部310に関する説明は、図5で行った説明と同様である。
次に、本実施例3に係る変換装置300の効果について説明する。変換装置300は、切替通知送信時間間隔(T)毎に、変換コア♯1~♯Nの順に、切替通知を送信しつつ、切替要求を送信した変換コアに対して、切替通知を送信する。変換装置300は、変換コア♯1~♯Nからの統計型xFlowパケットの出力が重ならないように、所定のガードタイム以上の時間をあけて、切替通知を送信する。これによって、トラヒックが急増によって、特定の変換コアの登録用テーブル50から統計情報が溢れてしまう状況を回避することができる。
続いて、変換プログラムを実行するコンピュータの一例について説明する。図7は、変換プログラムを実行するコンピュータの一例を示す図である。コンピュータ1000は、たとえば、メモリ1010と、CPU1020と、ハードディスクドライブインタフェース1030と、ディスクドライブインタフェース1040と、シリアルポートインタフェース1050と、ビデオアダプタ1060と、ネットワークインタフェース1070とを有する。これらの各部は、バス1080によって接続される。
メモリ1010は、ROM(Read Only Memory)1011およびRAM1012を含む。ROM1011は、たとえば、BIOS(Basic Input Output System)等のブートプログラムを記憶する。ハードディスクドライブインタフェース1030は、ハードディスクドライブ1031に接続される。ディスクドライブインタフェース1040は、ディスクドライブ1041に接続される。ディスクドライブ1041には、たとえば、磁気ディスクや光ディスク等の着脱可能な記憶媒体が挿入される。シリアルポートインタフェース1050には、たとえば、マウス1051およびキーボード1052が接続される。ビデオアダプタ1060には、たとえば、ディスプレイ1061が接続される。
ここで、ハードディスクドライブ1031は、たとえば、OS1091、アプリケーションプログラム1092、プログラムモジュール1093およびプログラムデータ1094を記憶する。上記実施形態で説明した各情報は、たとえばハードディスクドライブ1031やメモリ1010に記憶される。
また、変換プログラムは、たとえば、コンピュータ1000によって実行される指令が記述されたプログラムモジュール1093として、ハードディスクドライブ1031に記憶される。具体的には、上記実施形態で説明したパケット振分部110、切替管理部120、変換コア♯1~♯Nを実行する各処理が記述されたプログラムモジュール1093が、ハードディスクドライブ1031に記憶される。
また、変換プログラムによる情報処理に用いられるデータは、プログラムデータ1094として、たとえば、ハードディスクドライブ1031に記憶される。そして、CPU1020が、ハードディスクドライブ1031に記憶されたプログラムモジュール1093やプログラムデータ1094を必要に応じてRAM1012に読み出して、上述した各手順を実行する。
なお、変換プログラムに係るプログラムモジュール1093やプログラムデータ1094は、ハードディスクドライブ1031に記憶される場合に限られず、たとえば、着脱可能な記憶媒体に記憶されて、ディスクドライブ1041等を介してCPU1020によって読み出されてもよい。あるいは、変換プログラムに係るプログラムモジュール1093やプログラムデータ1094は、LANやWAN(Wide Area Network)等のネットワークを介して接続された他のコンピュータに記憶され、ネットワークインタフェース1070を介してCPU1020によって読み出されてもよい。
以上、本発明者によってなされた発明を適用した実施形態について説明したが、本実施形態による本発明の開示の一部をなす記述および図面により本発明は限定されることはない。すなわち、本実施形態に基づいて当業者等によりなされる他の実施形態、実施例および運用技術等は全て本発明の範疇に含まれる。
50 登録用テーブル
51 出力用テーブル
52 統計情報生成処理部
53 切替処理部
54 通知部
100 変換装置
110 パケット振分部
120,210,310 切替管理部
51 出力用テーブル
52 統計情報生成処理部
53 切替処理部
54 通知部
100 変換装置
110 パケット振分部
120,210,310 切替管理部
Claims (6)
- 複数の変換コアと、
前記複数の変換コアのうち、一部の変換コアに対して切替指示を送信する処理を繰り返し実行する切替管理部とを有し、
前記複数の変換コアはそれぞれ、
二つの統計情報キャッシュテーブルを、登録用テーブルと出力用テーブルに分けて記憶する記憶部と、
カプセル化パケットの統計情報をフロー毎に生成し、生成したフロー毎の統計情報を、前記登録用テーブルに設定された統計情報キャッシュテーブルに登録する統計情報生成処理部と、
前記切替管理部から前記切替指示を受信した場合に、前記登録用テーブルの統計情報キャッシュテーブルと、前記出力用テーブルの統計情報キャッシュテーブルとを切替え、前記出力用テーブルの統計情報キャッシュテーブルに登録された統計情報を含む統計型xFlowパケットを生成し、生成した統計型xFlowパケットを送信する切替処理部とを有する
ことを特徴とする変換装置。 - 前記切替管理部は、所定の時間間隔毎に、前記複数の変換コアから一つの変換コアを順番に選択し、選択した変換コアに対して、前記切替指示を送信する請求項1に記載の変換装置。
- 前記複数の変換コアはそれぞれ、登録用テーブルに設定された統計情報キャッシュテーブルの統計情報のデータ量が閾値を超えた場合に、前記切替管理部に対して切替要求を送信する通知部を更に有し、
前記切替管理部は、前記切替要求を受信した場合に、前記所定の時間間隔を短くする処理を更に実行する請求項2に記載の変換装置。 - 前記切替管理部は、前記切替要求を受信した場合に、前回切替指示を送信したタイミングからガードタイム以上の時間をあけて、前記切替要求の送信元となる変換コアに、前記切替指示を送信する処理を更に実行する請求項3に記載の変換装置。
- 二つの統計情報キャッシュテーブルを、登録用テーブルと出力用テーブルに分けて記憶する記憶部と、
カプセル化パケットの統計情報をフロー毎に生成し、生成したフロー毎の統計情報を、前記登録用テーブルに設定された統計情報キャッシュテーブルに登録する統計情報生成処理部と、
切替指示を受信した場合に、前記登録用テーブルの統計情報キャッシュテーブルと、前記出力用テーブルの統計情報キャッシュテーブルとを切替え、前記出力用テーブルの統計情報キャッシュテーブルに登録された統計情報を含む統計型xFlowパケットを生成し、生成した統計型xFlowパケットを送信する切替処理部とを有する、複数の変換コアを有する変換装置が実行する変換方法であって、
前記複数の変換コアのうち、一部の変換コアに対して切替指示を送信する処理を繰り返し実行する切替管理工程、
を含んだことを特徴とする変換方法。 - コンピュータを、請求項1~4のいずれか一つに記載の変換装置として機能させるための変換プログラム。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2021/045222 WO2023105697A1 (ja) | 2021-12-08 | 2021-12-08 | 変換装置、変換方法及び変換プログラム |
| JP2023565791A JP7704215B2 (ja) | 2021-12-08 | 2021-12-08 | 変換装置、変換方法及び変換プログラム |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2021/045222 WO2023105697A1 (ja) | 2021-12-08 | 2021-12-08 | 変換装置、変換方法及び変換プログラム |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2023105697A1 true WO2023105697A1 (ja) | 2023-06-15 |
Family
ID=86729982
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2021/045222 Ceased WO2023105697A1 (ja) | 2021-12-08 | 2021-12-08 | 変換装置、変換方法及び変換プログラム |
Country Status (2)
| Country | Link |
|---|---|
| JP (1) | JP7704215B2 (ja) |
| WO (1) | WO2023105697A1 (ja) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2025041350A1 (ja) * | 2023-08-24 | 2025-02-27 | 日本電信電話株式会社 | 変換装置 |
Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2021149245A1 (ja) * | 2020-01-24 | 2021-07-29 | 日本電信電話株式会社 | 変換装置、変換方法及び変換プログラム |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP6571883B2 (ja) | 2016-10-06 | 2019-09-04 | 日本電信電話株式会社 | フロー情報解析装置、フロー情報解析方法及びフロー情報解析プログラム |
-
2021
- 2021-12-08 WO PCT/JP2021/045222 patent/WO2023105697A1/ja not_active Ceased
- 2021-12-08 JP JP2023565791A patent/JP7704215B2/ja active Active
Patent Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2021149245A1 (ja) * | 2020-01-24 | 2021-07-29 | 日本電信電話株式会社 | 変換装置、変換方法及び変換プログラム |
Non-Patent Citations (1)
| Title |
|---|
| CHIHARU MORIOKA, YUHEI HAYASHI, YUKI MIYOSHI, TAKERO NISHIOKA, SEIHEI KAMAMURA: "B-6-73 A Study of Flow Statistical Information Transmission Method in Format Conversion System", PROCEEDINGS OF THE 2021 IEICE GENERAL CONFERENCE; MARCH 9-12, 2021, 23 February 2021 (2021-02-23), JP, pages 73, XP009546542, Retrieved from the Internet <URL:https://www.ieice-taikai.jp/2021general/jpn/webpro/_html/cs.html> * |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2025041350A1 (ja) * | 2023-08-24 | 2025-02-27 | 日本電信電話株式会社 | 変換装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| JPWO2023105697A1 (ja) | 2023-06-15 |
| JP7704215B2 (ja) | 2025-07-08 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US10838890B2 (en) | Acceleration resource processing method and apparatus, and network functions virtualization system | |
| KR101583325B1 (ko) | 가상 패킷을 처리하는 네트워크 인터페이스 장치 및 그 방법 | |
| US10230573B2 (en) | Management of network entity selection | |
| CA2938033A1 (en) | Reception packet distribution method, queue selector, packet processing device, and recording medium | |
| RU2610250C2 (ru) | Узел передачи и способ отчетности о статусе буфера | |
| WO2019072072A1 (zh) | 一种拥塞流识别方法及网络设备 | |
| EP3605975A1 (en) | Client service transmission method and device | |
| CN108471629A (zh) | 传输网络中业务服务质量的控制方法、设备及系统 | |
| CN105594158B (zh) | 资源的配置方法和装置 | |
| KR101639797B1 (ko) | 가상머신 패킷을 처리하는 네트워크 인터페이스 장치 및 그 방법 | |
| CN105159779B (zh) | 提高多核cpu数据处理性能的方法和系统 | |
| WO2016202158A1 (zh) | 一种报文传输方法、装置及计算机可读存储介质 | |
| US10476746B2 (en) | Network management method, device, and system | |
| WO2019165855A1 (zh) | 一种报文传输的方法及装置 | |
| US11271897B2 (en) | Electronic apparatus for providing fast packet forwarding with reference to additional network address translation table | |
| US12028255B2 (en) | Virtual channel setting method and apparatus for data flow | |
| CN105007200A (zh) | 网络数据包的分析方法及系统 | |
| WO2016206513A1 (zh) | 加速处理数据的方法、分配装置和交换机 | |
| CN115643558B (zh) | 数据处理方法、装置、电子设备及存储介质 | |
| JP6279427B2 (ja) | 仮想ネットワーク割当方法および装置 | |
| CN103269431B (zh) | 一种云转码实现方法及装置 | |
| US11256550B2 (en) | Estimating device and estimating method | |
| JP7704215B2 (ja) | 変換装置、変換方法及び変換プログラム | |
| WO2016132402A1 (ja) | 通信フレーム転送装置および通信システム | |
| JP2016127393A (ja) | 情報処理装置、方法およびプログラム |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 21967195 Country of ref document: EP Kind code of ref document: A1 |
|
| ENP | Entry into the national phase |
Ref document number: 2023565791 Country of ref document: JP Kind code of ref document: A |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 21967195 Country of ref document: EP Kind code of ref document: A1 |