Flow monitoring method, device and system
A traffic monitoring and traffic monitoring technology, which is applied in the communication field, can solve problems such as incomplete application layer information and inability to monitor abnormal traffic behavior at the application layer, and achieve the effect of improving the monitoring effect
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0031] Embodiments of the present invention will be described from the perspective of a flow monitoring device, which may be integrated in a monitoring server.
[0032] A traffic monitoring method, comprising: obtaining the data flow entering and leaving the server, and mirroring the data flow to obtain the mirrored data flow, distinguishing the mirrored data flow, obtaining the mirrored data flow and the mirrored data flow, according to the TCP protocol The mirrored out data flow and the mirrored inbound data flow are reorganized to obtain a reorganized data flow, and application layer traffic monitoring is performed on the reorganized data flow.
[0033] like figure 1 As shown, the specific flow of the flow monitoring method can be as follows:
[0034] 101. Obtain the data flow entering and leaving the server, and mirror the data flow to obtain the mirrored data flow.
[0035] Wherein, the data stream may carry information such as a Media Access Control (MAC, Media Access ...
Embodiment 2
[0051] According to the method described in Embodiment 1, an example will be given below for further detailed description.
[0052] see Figure 2a and Figure 2b , the figure is the scenario application diagram of traffic monitoring. Based on this scenario, it can be seen that the operator network can exchange data with the server through the core switch. Among them, the server and the core switch may also include an intermediate layer, which will not be described in detail here. Before the data flows into and out of the core switch, a copy will be mirrored by the splitter switch and sent to the traffic monitoring device for traffic analysis and monitoring.
[0053] like Figure 2aAs shown, the traffic monitoring device may include a receiving module, a four-layer processing module, a seven-layer processing module, an analysis module and an alarm output module, as follows:
[0054] (1) receiving module;
[0055] The receiving module is used to obtain the mirrored data flow...
Embodiment 3
[0088] In order to better implement the above method, the implementation of the present invention also provides a flow monitoring device, such as Figure 3a As shown, the flow monitoring device includes an acquisition unit 301, a distinction unit 302, a reorganization unit 303 and a first monitoring unit, as follows:
[0089] The acquiring unit 301 is configured to acquire data streams entering and leaving the server, and perform mirror mapping on the data streams to obtain mirrored data streams.
[0090] Wherein, the data flow may carry information such as a MAC address.
[0091] A distinguishing unit 302, configured to distinguish the mirrored data stream to obtain a mirrored data stream and a mirrored data stream;
[0092] For example, the distinguishing unit 302 may be specifically configured to distinguish the mirrored data flow according to the MAC address, to obtain the outgoing data flow and incoming data flow of the server.
[0093] The reorganization unit 303 is us...
PUM

Abstract
Description
Claims
Application Information

- Generate Ideas
- Intellectual Property
- Life Sciences
- Materials
- Tech Scout
- Unparalleled Data Quality
- Higher Quality Content
- 60% Fewer Hallucinations
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2025 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com