Multi-domain net packet classifying method based on network flow

A network traffic and multi-domain network technology, applied in the field of network filtering and monitoring, can solve problems such as difficulty in getting updates, inability to solve complexity, and increase in the complexity of network packet classification problems

Active Publication Date: 2006-08-23
CERTUS NETWORK TECHNANJING
View PDF0 Cites 20 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0004] However, the existing solutions only use the characteristics of the classification rules themselves in the design, and do not take into account the statistical characteristics of network traffic
In the practical application of network packet classification, the following problems usually occur: the vast majority of network packets only match the rules in a certain subset of the rule set, and there are quite a few rules that only match a very small number of network packets
Since the formulation of the rules is often not optimized for a specific network, and it is difficult to get timely updates, a considerable part of the rules in the rule base that usually exists in the network packet classification device can rarely be matched, that is, Some rules rarely participate in the actual network packet classification process when the network is running normally, but the existence of these rules itself greatly increases the complexity of the network packet classification problem
Several existing network packet classification methods fail to take into account the reality related to the statistical characteristics of network traffic, so they cannot solve the problem of network packet classification itself caused by useless rules (rules that rarely match) under specific traffic conditions. The complexity that comes, so that the average transmission rate of the network cannot be further improved

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Multi-domain net packet classifying method based on network flow
  • Multi-domain net packet classifying method based on network flow
  • Multi-domain net packet classifying method based on network flow

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0109] Combine below figure 2 , introduce the hardware structure of the present invention:

[0110] A receiving unit

[0111] Main tasks: receive network packets, parse network packet headers (five domains), and cache network packets, header information, and network packet content into the processing queue.

[0112] Related equipment: network card, cache (DRAM)

[0113] Input and output: input and arrive at the network packet from the network card, and output the packet header information network packet content to the cache queue.

[0114] B sampling unit

[0115] The main task: according to the sampling interval to make statistics on the header information of the arriving network packets, and normalize the statistical information according to the update time, and provide the flow prior distribution for the calculation unit. (Note: The sampling interval is defined as sampling every N arriving network packets, that is, each sampling records the packet header information of...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

Present invention relates to network filtering and monitoring technology field. It includes following steps: receiving reached network package, collecting network package head information, statistics and normalization network flow property, computing element obtaining network package classifying structure according to configured rule congregation and network flow statistical property, network package classifying unit obtaining network package head information and classifying network package through sorter data structure obtained by calculating unit, transmitting unit transmitting network package in output queue according to classifying result. Present invention is realized based on microprocessor universal platform or network processing unit special platform, combined network flow dynamic statistics property and rule aggregative static structure property, optimizing network package classification method, raising 80-400 per cent average classifying rate than current both abroad and home same class of method, and reducing memory requirements by 30-600 per cent.

Description

technical field [0001] The invention relates to the technical field of network filtering and monitoring. Background technique [0002] In many policy-based network filtering and monitoring applications such as layer 4 switches, state inspection firewalls, QoS routers, and load balancing, multi-domain network packet classification methods are the key components and core technologies of system performance. Compared with traditional layer-2 switching and layer-3 routing, multi-domain network packet classification not only checks and processes Ethernet and IP headers, but also checks and processes headers of higher-level network protocols such as TCP and UDP. The multi-domain network packet classification problem is an example of the best matching filter rule problem. For the common classification of network packets below the fourth layer, there are 7 domains that can be selected as domains for filtering rules: source / destination network layer address (32 bits each), source / des...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L12/56H04L29/06H04L12/861
Inventor 亓亚烜李军
Owner CERTUS NETWORK TECHNANJING
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products