DNS log compression method and device
A technology of compression method and compression device, which is applied in the Internet field, can solve problems such as impracticability, and achieve good technical effects
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0044] This technical solution relies on the Hadoop big data storage and computing platform, and relies on 2.6 million domain names, original DNS logs, and original Radius logs. The following are related instructions.
[0045] DNS original log:
[0046] When a user accesses a website through a domain name (www.baidu.com), since the Ethernet transmission process is addressed according to the IP address, the DNS client will first query the DNS server for the IP address corresponding to the domain name. Correspondingly, DNS The server will generate a request log (the parsing result field in the request log is empty, and the parsing time field corresponds to the request time), as follows:
[0047] Source IP|Source Port|Destination IP|Destination Port|ID|Domain Name|Request Type|Analysis Result|Analysis Time|Status Code|Request
[0048] 219.141.159.146|11764|219.141.159.146|53|11616|www.baidu.com|A||20151028141117.176|0|q
[0049] Radius log:
[0050] When the user's terminal is...
Embodiment 2
[0073] Preferably, in step 2), when the request port of the DNS information corresponds to the start and end port of the Radius log is 0, it means that this IP address uses all ports of the external network IP, and directly saves the DNS information.
[0074] And, in step 4), the DNS retention log specifically includes:
[0075] User account, domain name, PV, access time point average, access time point variance.
[0076] Further, it is preferred that step 4) further includes: for a certain user, only one record is reserved through the splicing of domain name access information, that is, through the filtering of repeated information.
[0077] Further, preferably, in step 4), calculating the PV, the mean value of the visit time point, and the variance of the visit time point specifically includes:
[0078] The PV value corresponds to the number of times a user visits a certain website;
[0079] The average value is the sum of the minutes from 00:00 of the day to each user’s v...
Embodiment 3
[0082] In a specific embodiment, the method specifically includes:
[0083] According to the source IP address and request port in DNS matching the authentication information of the IP address in the Radius log, only the DNS request port is within the range of the start and end ports of Radius (when the start and end ports of Radius are both 0, it means The IP address uses all the ports of the external network IP), and the DNS information is valid. Taking user A as an example, user A has 12 requests for DNS logs for the domain name "www.baidu.com" within one day, and the time interval is 1 hour, from 8 am to 5 pm, as follows.
[0084] 219.141.159.146|11764|219.141.159.146|53|11616|www.baidu.com|A||20151028080000.176|0|q
[0085] 219.141.159.146|11764|219.141.159.146|53|11736|www.baidu.com|A||20151028090000.321|0|q
[0086] 219.141.159.146|11764|219.141.159.146|53|13211|www.baidu.com|A||20151028100000.390|0|q
[0087] 219.141.159.146|11764|219.141.159.146|53|17141|www.baidu....
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com